Sign in

ethicalhack3r

@ethicalhack3r.bsky.social
208 followers 137 following 134 posts

Founder of Damn Vulnerable Web App (DVWA) Founder of WPScan (acquired by Automattic) Check out my new project! kevintel.com

PostsRepliesMedia
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 11/06/2025
Unfortunately, CyberAlerts is not profitable as a business and it is time to shut it down. This has not been an easy decision. After 6+ months of costs and no income, it is not sustainable. Will be taken offline and your user data permanently deleted on June 30th, 2025.
001
ethicalhack3r @ethicalhack3r.bsky.social · 27/05/2025
Two CVEs have been assigned to the vulnerabilities in vBulletin 5.0.0 through 6.0.3 found by Karma(In)Security • CVE-2025-48827 • CVE-2025-48828 These vulnerabilities were detected being exploited in the wild by the KEVIntel sensors on May 26th.
011
ethicalhack3r @ethicalhack3r.bsky.social · 13/05/2025
Great news! Added an extra 29 historical WordPress KEVs to KEVIntel! If you have a Pro API subscription, these all have the "wordpress" tag. Also, have you noticed CISA's next incremental number? Who's betting they only add just one new KEV next time? 😅
000
ethicalhack3r @ethicalhack3r.bsky.social · 12/05/2025
This morning I added 190 historical KEVs to KEVIntel, bringing the total count of KEVs to 1648. At the time of writing, that's 313 more than CISA.
000
Reposted by ethicalhack3r
Javvad Malik @j4vv4d.com · 07/05/2025
Meta just landed a $167M verdict against NSO Group for their WhatsApp hack • NSO's Pegasus spyware infected 1,400 WhatsApp users • Zero-click attack (phone to be ON) • Damages awarded = 3x NSO's annual R&D budget • Meta's sharing court depositions publicly www.theregister.com/2025/05/06/n...
theregister.com
NSO Group must pay Meta $168M in WhatsApp spy case
: Don't f&#k with Zuck
144
ethicalhack3r @ethicalhack3r.bsky.social · 07/05/2025
Good morning! Two new KEVs this morning: - CVE-2024-6047 - CVE-2024-11120 Both Unauthenticated OS Command Injection affecting GeoVision EOL devices.
010
ethicalhack3r @ethicalhack3r.bsky.social · 06/05/2025
Top 5 Worst of Worst (WoW) vulnerabilities within the past month. What I would consider the most likely to be exploited (not including the prevalence of the product, which would make a big difference). You should definitely patch these!
010
ethicalhack3r @ethicalhack3r.bsky.social · 02/05/2025
“The cyber criminals claim to have the private information of 20 million people wo signed up to Co-op's membership scheme, but the firm would not confirm that number.” www.bbc.com/news/article...
bbc.com
Co-op hackers stole 'significant' amount of customer data
The firm previously said there was 'no evidence that customer data was compromised'.
000
ethicalhack3r @ethicalhack3r.bsky.social · 02/05/2025
Ha! Nice DVWA meme in latest WatchTowr blog post cc @digi.ninja
031
Reposted by ethicalhack3r
SteelCon @steelcon.info · 02/05/2025
Today is our last big ticket drop. 9am, 12pm, 7pm main event tickets 1pm kids track tickets ti.to/steelcon/2025 You can see our speaker list here: www.steelcon.info/the-event/ta... Workshops tickets will be next week once the dust settles.
steelcon.info
Talks | SteelCon
057
ethicalhack3r @ethicalhack3r.bsky.social · 01/05/2025
Two new KEVs on KEVIntel this morning - CVE-2024-38475 (Apache Software Foundation) - CVE-2023-44221 (SonicWall) kevintel.com
020
ethicalhack3r @ethicalhack3r.bsky.social · 30/04/2025
🚨 KEVIntel is live! Known Exploited Vulnerabilities Intel Open access via RSS, API, or CSV. Enriched with EPSS scores, exploits, PoCs, and more. Built for defenders. 🔗 Explore now: kevintel.com #infosec #cybersecurity #threatintel
kevintel.com
KEVIntel
000
ethicalhack3r @ethicalhack3r.bsky.social · 29/04/2025
Known Exploited Vulnerabilities Intel kevintel.com
000
ethicalhack3r @ethicalhack3r.bsky.social · 28/04/2025
New reading material
010
ethicalhack3r @ethicalhack3r.bsky.social · 28/04/2025
New reading material
020
ethicalhack3r @ethicalhack3r.bsky.social · 28/04/2025
Not a bad place to take a couple of hours break from coding
120
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 26/04/2025
CVE-2025-32432: Craft CMS Allows Remote Code Execution Marked as known exploited. Metasploit module also available. cyberalerts.io/vulnerabilit...
011
ethicalhack3r @ethicalhack3r.bsky.social · 25/04/2025
SAP NetWeaver missing authorization has been marked as known exploited in CyberAlerts KEV CVE-2025-31324 cyberalerts.io/kev
000
ethicalhack3r @ethicalhack3r.bsky.social · 24/04/2025
For anyone using T-Pot Honeypot, any cool tips/tricks/hacks I should know about?
110
ethicalhack3r @ethicalhack3r.bsky.social · 24/04/2025
“Recent public reporting inaccurately implied the program was at risk due to a lack of funding. To set the record straight, there was no funding issue, but rather a contract administration issue that was resolved prior to a contract lapse.“ - CISA www.cisa.gov/news-events/...
cisa.gov
Statement from Matt Hartman on the CVE Program | CISA
100
ethicalhack3r @ethicalhack3r.bsky.social · 23/04/2025
Verizon #DBIR 2025 is ready! Didn’t notice anything ground breaking from a quick skim through. What did stand out was 20% increase in breaches due to vulnerabilities. Anyone else find anything interesting or surprising? www.verizon.com/business/res...
verizon.com
2025 Data Breach Investigations Report
The 2025 Data Breach Investigations Report (DBIR) from Verizon is here! Get the latest updates on real-world breaches and help safeguard your organization from cybersecurity attacks.
100
ethicalhack3r @ethicalhack3r.bsky.social · 17/04/2025
Another great example of CyberAlerts.io early warning and alerting. In this case, we alerted our users 14 hours before CISA KEV, to an actively exploited Apple iOS vulnerability. We’ve also made changes so that this will be even earlier in the future! cyberalerts.io/vulnerabilit...
000
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 17/04/2025
🚨 CyberAlerts adds two Apple iOS Known Exploited Vulnerabilities (KEV) to their database not yet in CISA KEV - CVE-2025-31200 - CVE-2025-31201 Update to tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1 cyberalerts.io/kev
011
ethicalhack3r @ethicalhack3r.bsky.social · 16/04/2025
CVE Status Good! cyberalerts.io/cve_tracker
010
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 16/04/2025
CyberAlerts MITRE CVE Tracker 2025 Keep an eye on the CVE database cyberalerts.io/cve_tracker
cyberalerts.io
CyberAlerts
Stay one step ahead of the latest threats and vulnerabilities with vulnerability alerts and threat alerts. Cut through the noise and focus on what matters to your business with advanced alert filterin...
011
ethicalhack3r @ethicalhack3r.bsky.social · 15/04/2025
The MITRE CVE letter’s intentions is unclear and lacks context. The US government is making drastic cuts, and are bat shit crazy right now. But even so, I very much doubt anyone would scrap CVE with one days notice.
120
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 15/04/2025
We've just added an API endpoint for our CyberAlerts KEV! Completely free, just need to register for a token.
012
ethicalhack3r @ethicalhack3r.bsky.social · 15/04/2025
BreachForums is down!
021
ethicalhack3r @ethicalhack3r.bsky.social · 13/04/2025
What Open Source multi-protocol Honey Pot software is everyone using nowadays?
200
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 13/04/2025
New CyberAlerts KEV CVE-2025-3248: Langflow Unauthenticated RCE Patch now or be pwnd! Nuclei template available. Reference: isc.sans.edu/diary/31850 cyberalerts.io/vulnerabilit...
isc.sans.edu
Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248) - SANS Internet Storm Center
Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248), Author: Johannes Ullrich
012
ethicalhack3r @ethicalhack3r.bsky.social · 11/04/2025
Taking bets for how long until spotted exploited in the wild: cyberalerts.io/vulnerabilit...
cyberalerts.io
CVE-2025-2636: InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parame...
000
ethicalhack3r @ethicalhack3r.bsky.social · 10/04/2025
cyberalerts.io/vulnerabilit...
001
ethicalhack3r @ethicalhack3r.bsky.social · 10/04/2025
New "Show Not in CISA KEV" toggle in CyberAlerts KEV
010
ethicalhack3r @ethicalhack3r.bsky.social · 10/04/2025
CISA added 2 of them yesterday. Seems we were just ahead of them for these 2. - CVE-2024-53150 - CVE-2024-53197
010
ethicalhack3r @ethicalhack3r.bsky.social · 09/04/2025
Since we started collecting data (around 4 months ago), the CyberAlerts KEV includes 6 vulnerabilities exploited in the wild, not listed in CISA KEV. We expect this to be around 12 or more by the end of the year. blog.cyberalerts.io/cyberalerts-...
blog.cyberalerts.io
CyberAlerts Known Exploited Vulnerabilities (KEV)
Since November 3rd, 2021, Cybersecurity and Infrastructure Security Agency (CISA) have published a public list of Known Exploited Vulnerabilities (KEV). Over that time, at the time of writing (April 9...
232
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 08/04/2025
Introducing the CyberAlerts Known Exploited Vulnerabilities (KEV)! We use a many sources and a variety of methods to determine if a vulnerability is exploited in the wild. Check it out and let me know what you think! cyberalerts.io/kev
021
ethicalhack3r @ethicalhack3r.bsky.social · 08/04/2025
Looking to keep an eye on actively exploited vulnerabilities? The "worst of the worst" in terms of risk? 👉 cyberalerts.io/vulnerabilit...
cyberalerts known exploited
010
Reposted by ethicalhack3r
Ross Morsali @ross-m.bsky.social · 08/04/2025
Ok this worked out great last time, let's see if it works again! I'm looking for another support engineer for my WordPress plugin - Search & Filter - fully remote. Please share for reach 😁
169
ethicalhack3r @ethicalhack3r.bsky.social · 07/04/2025
🚨 Reported Data Breach 🚨 🇨🇭 Switzerland - Brack.CH User Dulnex claims to be selling the full database of brack.ch, one of the most well-known online stores in Switzerland. The database allegedly contains phone number, email, firstname, lastname, invoice, item purchased, unpaid item, and more.
000
Reposted by ethicalhack3r
Catalin Cimpanu @campuscodi.risky.biz · 06/04/2025
There's a ransomware group named DragonForce going around hacking its rivals. After Mamona and BlackLock, the group has now hacked RansomHub—a major RaaS platform and one of the most active groups today.
2165
ethicalhack3r @ethicalhack3r.bsky.social · 03/04/2025
Looks like this could be a serious one! 🟣 Critical - Ivanti unauthenticated stack-based buffer overflow CVE-2025-22457 cyberalerts.io/vulnerabilit... #CyberSecurity #Vulnerability #Cyber
cyberalerts.io
CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA...
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenti...
010
ethicalhack3r @ethicalhack3r.bsky.social · 03/04/2025
Automattic 16% workforce reduction They also lost 8% last year in the buyouts automattic.com/2025/04/02/r... #WordPress
automattic.com
Restructuring Announcement
Earlier today, CEO Matt Mullenweg shared with Automattic employees the following message.
010
ethicalhack3r @ethicalhack3r.bsky.social · 01/04/2025
“As of February 24, 2025, there were no new CVE Records from 128 CNAs in the last 365 days” cve.mitre.org/community/bo... #CVE
cve.mitre.org
000
ethicalhack3r @ethicalhack3r.bsky.social · 31/03/2025
CyberAlerts Threat and Vulnerability Database 🔒 Excited to announce our new public Threat and Vulnerability Database: Further details here: blog.cyberalerts.io/threat-and-v... #ciso #cyber #vulnerability #vulnerabilitymanagement #cybersecurity
blog.cyberalerts.io
Threat and Vulnerability Intelligence Database by CyberAlerts
Every month, on average, we collect over 10,000 vulnerabilities, security advisories, news stories, vendor advisories and more. And, as we continuously add more sources, the amount of data we collect ...
022
ethicalhack3r @ethicalhack3r.bsky.social · 31/03/2025
Cisco Talos is actively tracking an ongoing campaign from Russian threat actor Gamaredon targeting users in Ukraine with malicious LNK files, which run a PowerShell downloader, since at least November 2024 blog.talosintelligence.com/gamaredon-ca... #Ukraine #CyberSecurity #Threat
010
Reposted by ethicalhack3r
CyberAlerts @cyberalerts.bsky.social · 28/03/2025
We're happy to offer Free Vulnerability Intelligence to organisations founded in Ukraine! 🇺🇦 No strings attached. blog.cyberalerts.io/vulnerabilit... #Ukraine #VulnerabilityManagament #VulnerabilityIntelligence
blog.cyberalerts.io
Free Vulnerability Intelligence Support for Ukraine
We want to offer our service, CyberAlerts.io, for free, for any organisations founded in Ukraine. We want to do this to show public support for Ukraine, and help protect Ukrainian organisations from ...
011
Reposted by ethicalhack3r
The Tennessee Holler @thetnholler.bsky.social · 26/03/2025
Founder of Signal 👀 🔥
353251984741
Reposted by ethicalhack3r
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️‍🌈 @hrbrmstr.dev · 25/03/2025
"Have I Been Pwnd" was…pwnd… www.troyhunt.com/a-sneaky-phi... Hunt should add a "YES" to the end of the site's title—now.
troyhunt.com
A Sneaky Phish Just Grabbed my Mailchimp Mailing List
You know when you're really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That's me right now, and the penny has just dropped that a Mailchimp phish h...
2156
ethicalhack3r @ethicalhack3r.bsky.social · 25/03/2025
🤦‍♂️
000
Reposted by ethicalhack3r
SteelCon @steelcon.info · 24/03/2025
What's that, you have a talk or workshop you would like to submit to Sheffield's best security conference happening between July 11 and 13 2025? Well, you are in luck, our CFP has just opened, throw your details in here: docs.google.com/forms/d/e/1F... If you have any questions, let us know.
docs.google.com
SteelCon Call For Papers 2025
Same as every year, we are looking for cool talks and workshops to amaze and entertain our delightful audience. We are interested in topics related to security and hacking in some way however they don...
31413