May 21, 2025 at 02:32PM

β– β– β– β–‘β–‘ South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware. High-level government institutions in Sri Lanka, Bangladesh, and Pakistan have emerged as the target of a new campaign orchestrated by a threat actor known as SideWinder. https://www.acronis.com/en-us/cyber-protection-center/posts/from-banks-to-battalions-sidewinders-attacks-on-south-asias-public-sector/ https://thehackernews.com/2025/05/south-asian-ministries-hit-by.html

May 21, 2025 at 02:28PM

β– β– β– β– β–‘ Full-Blown SSRF to Gain Access to Millions of Users’ Records and Multiple Internal Panels. https://medium.com/@skycer_00/full-blown-ssrf-to-gain-access-to-millions-of-users-records-and-multiple-internal-panels-3719d9b802e9

May 21, 2025 at 02:02PM

β– β– β– β–‘β–‘ Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization. Threat hunters have exposed the tactics of a China-aligned threat actor called UnsolicitedBooker, which targeted an unnamed international organization in Saudi Arabia with a previously undocumented backdoor dubbed MarsSnake. https://thehackernews.com/2025/05/chinese-hackers-deploy-marssnake.html

May 20, 2025 at 10:41AM

β– β– β– β– β–‘ Pwnable.tw, a wargame site for hackers to test and expand their binary exploiting skills. https://pwnable.tw/ ●The co-founder of this site just got OSEE. Thought of sharing.

May 20, 2025 at 10:30AM

β– β– β– β– β–  Cache poisoning via race-condition in Next.js https://zhero-web-sec.github.io/research-and-things/eclipse-on-nextjs-conditioned-exploitation-of-an-intended-race-condition

May 20, 2025 at 12:39AM

β– β–‘β–‘β–‘β–‘ A Silicon Valley VC Says He Got the IDF Starlink Access Within Days of October 7 Attack. Sequoia Capital partner Shaun Maguire said in a webinar hosted by Israel’s Defense Ministry that he connected the IDF with SpaceX’s Starlink satellite internet far sooner than believed. https://www.wired.com/story/shaun-maguire-starlink-idf-israel-gaza/