Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 11/06/2025Unfortunately, CyberAlerts is not profitable as a business and it is time to shut it down. This has not been an easy decision. After 6+ months of costs and no income, it is not sustainable. Will be taken offline and your user data permanently deleted on June 30th, 2025. 001
ethicalhack3r @ethicalhack3r.bsky.social · 27/05/2025Two CVEs have been assigned to the vulnerabilities in vBulletin 5.0.0 through 6.0.3 found by Karma(In)Security • CVE-2025-48827 • CVE-2025-48828 These vulnerabilities were detected being exploited in the wild by the KEVIntel sensors on May 26th. 011
ethicalhack3r @ethicalhack3r.bsky.social · 13/05/2025Great news! Added an extra 29 historical WordPress KEVs to KEVIntel! If you have a Pro API subscription, these all have the "wordpress" tag. Also, have you noticed CISA's next incremental number? Who's betting they only add just one new KEV next time? 😅 000
ethicalhack3r @ethicalhack3r.bsky.social · 12/05/2025This morning I added 190 historical KEVs to KEVIntel, bringing the total count of KEVs to 1648. At the time of writing, that's 313 more than CISA. 000
Reposted by ethicalhack3rJavvad Malik @j4vv4d.com · 07/05/2025Meta just landed a $167M verdict against NSO Group for their WhatsApp hack • NSO's Pegasus spyware infected 1,400 WhatsApp users • Zero-click attack (phone to be ON) • Damages awarded = 3x NSO's annual R&D budget • Meta's sharing court depositions publicly www.theregister.com/2025/05/06/n...theregister.comNSO Group must pay Meta $168M in WhatsApp spy case: Don't f&#k with Zuck 144
ethicalhack3r @ethicalhack3r.bsky.social · 07/05/2025Good morning! Two new KEVs this morning: - CVE-2024-6047 - CVE-2024-11120 Both Unauthenticated OS Command Injection affecting GeoVision EOL devices. 010
ethicalhack3r @ethicalhack3r.bsky.social · 06/05/2025Top 5 Worst of Worst (WoW) vulnerabilities within the past month. What I would consider the most likely to be exploited (not including the prevalence of the product, which would make a big difference). You should definitely patch these! 010
ethicalhack3r @ethicalhack3r.bsky.social · 02/05/2025“The cyber criminals claim to have the private information of 20 million people wo signed up to Co-op's membership scheme, but the firm would not confirm that number.” www.bbc.com/news/article...bbc.comCo-op hackers stole 'significant' amount of customer dataThe firm previously said there was 'no evidence that customer data was compromised'. 000
ethicalhack3r @ethicalhack3r.bsky.social · 02/05/2025Ha! Nice DVWA meme in latest WatchTowr blog post cc @digi.ninja 031
Reposted by ethicalhack3rSteelCon @steelcon.info · 02/05/2025Today is our last big ticket drop. 9am, 12pm, 7pm main event tickets 1pm kids track tickets ti.to/steelcon/2025 You can see our speaker list here: www.steelcon.info/the-event/ta... Workshops tickets will be next week once the dust settles.steelcon.infoTalks | SteelCon 057
ethicalhack3r @ethicalhack3r.bsky.social · 01/05/2025Two new KEVs on KEVIntel this morning - CVE-2024-38475 (Apache Software Foundation) - CVE-2023-44221 (SonicWall) kevintel.com 020
ethicalhack3r @ethicalhack3r.bsky.social · 30/04/2025🚨 KEVIntel is live! Known Exploited Vulnerabilities Intel Open access via RSS, API, or CSV. Enriched with EPSS scores, exploits, PoCs, and more. Built for defenders. 🔗 Explore now: kevintel.com #infosec #cybersecurity #threatintelkevintel.comKEVIntel 000
ethicalhack3r @ethicalhack3r.bsky.social · 29/04/2025Known Exploited Vulnerabilities Intel kevintel.com 000
ethicalhack3r @ethicalhack3r.bsky.social · 28/04/2025Not a bad place to take a couple of hours break from coding 120
Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 26/04/2025CVE-2025-32432: Craft CMS Allows Remote Code Execution Marked as known exploited. Metasploit module also available. cyberalerts.io/vulnerabilit... 011
ethicalhack3r @ethicalhack3r.bsky.social · 25/04/2025SAP NetWeaver missing authorization has been marked as known exploited in CyberAlerts KEV CVE-2025-31324 cyberalerts.io/kev 000
ethicalhack3r @ethicalhack3r.bsky.social · 24/04/2025For anyone using T-Pot Honeypot, any cool tips/tricks/hacks I should know about? 110
ethicalhack3r @ethicalhack3r.bsky.social · 24/04/2025“Recent public reporting inaccurately implied the program was at risk due to a lack of funding. To set the record straight, there was no funding issue, but rather a contract administration issue that was resolved prior to a contract lapse.“ - CISA www.cisa.gov/news-events/...cisa.govStatement from Matt Hartman on the CVE Program | CISA 100
ethicalhack3r @ethicalhack3r.bsky.social · 23/04/2025Verizon #DBIR 2025 is ready! Didn’t notice anything ground breaking from a quick skim through. What did stand out was 20% increase in breaches due to vulnerabilities. Anyone else find anything interesting or surprising? www.verizon.com/business/res...verizon.com2025 Data Breach Investigations ReportThe 2025 Data Breach Investigations Report (DBIR) from Verizon is here! Get the latest updates on real-world breaches and help safeguard your organization from cybersecurity attacks. 100
ethicalhack3r @ethicalhack3r.bsky.social · 17/04/2025Another great example of CyberAlerts.io early warning and alerting. In this case, we alerted our users 14 hours before CISA KEV, to an actively exploited Apple iOS vulnerability. We’ve also made changes so that this will be even earlier in the future! cyberalerts.io/vulnerabilit... 000
Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 17/04/2025🚨 CyberAlerts adds two Apple iOS Known Exploited Vulnerabilities (KEV) to their database not yet in CISA KEV - CVE-2025-31200 - CVE-2025-31201 Update to tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1 cyberalerts.io/kev 011
Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 16/04/2025CyberAlerts MITRE CVE Tracker 2025 Keep an eye on the CVE database cyberalerts.io/cve_trackercyberalerts.ioCyberAlertsStay one step ahead of the latest threats and vulnerabilities with vulnerability alerts and threat alerts. Cut through the noise and focus on what matters to your business with advanced alert filterin... 011
ethicalhack3r @ethicalhack3r.bsky.social · 15/04/2025The MITRE CVE letter’s intentions is unclear and lacks context. The US government is making drastic cuts, and are bat shit crazy right now. But even so, I very much doubt anyone would scrap CVE with one days notice. 120
Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 15/04/2025We've just added an API endpoint for our CyberAlerts KEV! Completely free, just need to register for a token. 012
ethicalhack3r @ethicalhack3r.bsky.social · 13/04/2025What Open Source multi-protocol Honey Pot software is everyone using nowadays? 200
Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 13/04/2025New CyberAlerts KEV CVE-2025-3248: Langflow Unauthenticated RCE Patch now or be pwnd! Nuclei template available. Reference: isc.sans.edu/diary/31850 cyberalerts.io/vulnerabilit...isc.sans.eduExploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248) - SANS Internet Storm CenterExploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248), Author: Johannes Ullrich 012
ethicalhack3r @ethicalhack3r.bsky.social · 11/04/2025Taking bets for how long until spotted exploited in the wild: cyberalerts.io/vulnerabilit...cyberalerts.ioCVE-2025-2636: InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File InclusionThe InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parame... 000
ethicalhack3r @ethicalhack3r.bsky.social · 10/04/2025New "Show Not in CISA KEV" toggle in CyberAlerts KEV 010
ethicalhack3r @ethicalhack3r.bsky.social · 10/04/2025CISA added 2 of them yesterday. Seems we were just ahead of them for these 2. - CVE-2024-53150 - CVE-2024-53197 010
ethicalhack3r @ethicalhack3r.bsky.social · 09/04/2025Since we started collecting data (around 4 months ago), the CyberAlerts KEV includes 6 vulnerabilities exploited in the wild, not listed in CISA KEV. We expect this to be around 12 or more by the end of the year. blog.cyberalerts.io/cyberalerts-...blog.cyberalerts.ioCyberAlerts Known Exploited Vulnerabilities (KEV)Since November 3rd, 2021, Cybersecurity and Infrastructure Security Agency (CISA) have published a public list of Known Exploited Vulnerabilities (KEV). Over that time, at the time of writing (April 9... 232
Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 08/04/2025Introducing the CyberAlerts Known Exploited Vulnerabilities (KEV)! We use a many sources and a variety of methods to determine if a vulnerability is exploited in the wild. Check it out and let me know what you think! cyberalerts.io/kev 021
ethicalhack3r @ethicalhack3r.bsky.social · 08/04/2025Looking to keep an eye on actively exploited vulnerabilities? The "worst of the worst" in terms of risk? 👉 cyberalerts.io/vulnerabilit... 010
Reposted by ethicalhack3rRoss Morsali @ross-m.bsky.social · 08/04/2025Ok this worked out great last time, let's see if it works again! I'm looking for another support engineer for my WordPress plugin - Search & Filter - fully remote. Please share for reach 😁 169
ethicalhack3r @ethicalhack3r.bsky.social · 07/04/2025🚨 Reported Data Breach 🚨 🇨🇭 Switzerland - Brack.CH User Dulnex claims to be selling the full database of brack.ch, one of the most well-known online stores in Switzerland. The database allegedly contains phone number, email, firstname, lastname, invoice, item purchased, unpaid item, and more. 000
Reposted by ethicalhack3rCatalin Cimpanu @campuscodi.risky.biz · 06/04/2025There's a ransomware group named DragonForce going around hacking its rivals. After Mamona and BlackLock, the group has now hacked RansomHub—a major RaaS platform and one of the most active groups today. 2165
ethicalhack3r @ethicalhack3r.bsky.social · 03/04/2025Looks like this could be a serious one! 🟣 Critical - Ivanti unauthenticated stack-based buffer overflow CVE-2025-22457 cyberalerts.io/vulnerabilit... #CyberSecurity #Vulnerability #Cybercyberalerts.ioCVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA...A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenti... 010
ethicalhack3r @ethicalhack3r.bsky.social · 03/04/2025Automattic 16% workforce reduction They also lost 8% last year in the buyouts automattic.com/2025/04/02/r... #WordPressautomattic.comRestructuring AnnouncementEarlier today, CEO Matt Mullenweg shared with Automattic employees the following message. 010
ethicalhack3r @ethicalhack3r.bsky.social · 01/04/2025“As of February 24, 2025, there were no new CVE Records from 128 CNAs in the last 365 days” cve.mitre.org/community/bo... #CVEcve.mitre.org 000
ethicalhack3r @ethicalhack3r.bsky.social · 31/03/2025CyberAlerts Threat and Vulnerability Database 🔒 Excited to announce our new public Threat and Vulnerability Database: Further details here: blog.cyberalerts.io/threat-and-v... #ciso #cyber #vulnerability #vulnerabilitymanagement #cybersecurityblog.cyberalerts.ioThreat and Vulnerability Intelligence Database by CyberAlertsEvery month, on average, we collect over 10,000 vulnerabilities, security advisories, news stories, vendor advisories and more. And, as we continuously add more sources, the amount of data we collect ... 022
ethicalhack3r @ethicalhack3r.bsky.social · 31/03/2025Cisco Talos is actively tracking an ongoing campaign from Russian threat actor Gamaredon targeting users in Ukraine with malicious LNK files, which run a PowerShell downloader, since at least November 2024 blog.talosintelligence.com/gamaredon-ca... #Ukraine #CyberSecurity #Threat 010
Reposted by ethicalhack3rCyberAlerts @cyberalerts.bsky.social · 28/03/2025We're happy to offer Free Vulnerability Intelligence to organisations founded in Ukraine! 🇺🇦 No strings attached. blog.cyberalerts.io/vulnerabilit... #Ukraine #VulnerabilityManagament #VulnerabilityIntelligenceblog.cyberalerts.ioFree Vulnerability Intelligence Support for UkraineWe want to offer our service, CyberAlerts.io, for free, for any organisations founded in Ukraine. We want to do this to show public support for Ukraine, and help protect Ukrainian organisations from ... 011
Reposted by ethicalhack3rThe Tennessee Holler @thetnholler.bsky.social · 26/03/2025Founder of Signal 👀 🔥 353251984741
Reposted by ethicalhack3rhrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️🌈 @hrbrmstr.dev · 25/03/2025"Have I Been Pwnd" was…pwnd… www.troyhunt.com/a-sneaky-phi... Hunt should add a "YES" to the end of the site's title—now.troyhunt.comA Sneaky Phish Just Grabbed my Mailchimp Mailing ListYou know when you're really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That's me right now, and the penny has just dropped that a Mailchimp phish h... 2156
Reposted by ethicalhack3rSteelCon @steelcon.info · 24/03/2025What's that, you have a talk or workshop you would like to submit to Sheffield's best security conference happening between July 11 and 13 2025? Well, you are in luck, our CFP has just opened, throw your details in here: docs.google.com/forms/d/e/1F... If you have any questions, let us know.docs.google.comSteelCon Call For Papers 2025Same as every year, we are looking for cool talks and workshops to amaze and entertain our delightful audience. We are interested in topics related to security and hacking in some way however they don... 31413