Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’ – Krebs on Security
https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/
TROOPERS25: Revisiting Cross Session Activation attacks - YouTube
https://m.youtube.com/watch?v=7bPzqEiO6Tk&list=PL1eoQr97VfJmSBNAP-n5cs81ScoZ0lKrF&index=33&pp=iAQB
How NTLM is being abused in 2025 cyberattacks | Securelist
https://securelist.com/ntlm-abuse-in-2025/118132/
Mythic for Developers - YouTube
https://www.youtube.com/playlist?list=PLJK0fZNGiFU_iJI2A8S5OdloTDexi5zs8
BGGP6: REVIVING RDOFF PART 1 | Netspooky's Blog
https://n0.lol/bggp6-rdoff/
The Wolf of Wall Steal: inside crypto traffer group operations — Anna Pham Huntress & Joan Garcia - YouTube
https://www.youtube.com/watch?v=ayXu5wToRNc
FBI Reports $262M in ATO Fraud as Researchers Cite Growing AI Phishing and Holiday Scams
https://thehackernews.com/2025/11/fbi-reports-262m-in-ato-fraud-as.html
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim 'Korean Leaks' Data Heist
https://thehackernews.com/2025/11/qilin-ransomware-turns-south-korean-msp.html
shell-exec - npm Package Security Analysis - Socket
https://socket.dev/npm/package/shell-exec/overview/1.1.3
ASUS warns of new critical auth bypass flaw in AiCloud routers
https://www.bleepingcomputer.com/news/security/asus-warns-of-new-critical-auth-bypass-flaw-in-aicloud-routers/
Russian Hackers Target US Engineering Firm Because of Work Done for Ukrainian Sister City - SecurityWeek
https://www.securityweek.com/russian-hackers-target-us-engineering-firm-because-of-work-done-for-ukrainian-sister-city/
Exploiting CVE-2025-21479 on a Samsung S23
https://xploitbengineer.github.io/CVE-2025-21479
FlexibleFerret: macOS Malware Deploys in Fake Job Scams
https://www.jamf.com/blog/flexibleferret-malware-continues-to-adapt/
In-Depth Analysis: Water Gamayun APT Multi-Stage Attack Uncovered
https://www.zscaler.com/blogs/security-research/water-gamayun-apt-attack
Bloody Wolf: A Blunt Crowbar Threat To Justice | Group-IB Blog
https://www.group-ib.com/blog/bloody-wolf/
Microsoft to secure Entra ID sign-ins from script injection attacks
https://www.bleepingcomputer.com/news/microsoft/microsoft-to-secure-entra-id-sign-ins-from-external-script-injection-attacks/
Microsoft: Security keys may prompt for PIN after recent updates
https://www.bleepingcomputer.com/news/microsoft/microsoft-fido2-security-keys-may-prompt-for-pin-after-recent-windows-updates/