Search results

  1. rottingcastle

    NEWS The hacker thought he stole the password, but actually called the police. GitHub teaches how to turn a hacker on emotions (and logs)

    Attackers have long been accustomed to classic defense, so more and more security teams are trying to play on the cheating field. Instead of just closing the holes, they put in baits that look like real secrets, access and services. The one who will fall for them almost certainly did not come...
  2. rottingcastle

    NEWS Press the number 3 to get robbed. Your super reliable two-factor is no longer a barrier for hackers

    Cynical politeness in the pipe has become the most effective tool of hacking. Attacks using social engineering continue to develop - now attackers use voice calls in combination with dynamic phishing sets, which allow real-time control of the victim’s actions in the browser. This is reported...
  3. rottingcastle

    NEWS The corporation warned about the threat of hacking through malicious Office documents.

    Microsoft urgently released unexpected security updates for Microsoft Office due to the dangerous zero-day vulnerability that is already being used in real attacks. The problem allows bypassing built-in protection mechanisms and can be used through a common malicious document if the user simply...
  4. rottingcastle

    Interesting Video Tutorial Don’t Study CYBERSECURITY – Just F**king Hack and Make Money!

    *** Hidden text: You do not have sufficient rights to view the hidden text. Visit the forum thread! ***
  5. rottingcastle

    Interesting Video Tutorial STOP WASTING YOUR TIME AND LEARN MORE HACKING!

    *** Hidden text: You do not have sufficient rights to view the hidden text. Visit the forum thread! ***
  6. rottingcastle

    NEWS Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media

    The fraudulent investment scheme known as Nomani has witnessed an increase by 62%, according to data from ESET, as campaigns distributing the threat have also expanded beyond Facebook to include other social media platforms, such as YouTube. The Slovak cybersecurity company said it blocked over...
  7. rottingcastle

    NEWS New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper

    Cybersecurity researchers have discovered a new variant of a macOS information stealer called MacSync that's delivered by means of a digitally signed, notarized Swift application masquerading as a messaging app installer to bypass Apple's Gatekeeper checks. "Unlike earlier MacSync Stealer...
  8. rottingcastle

    NEWS Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

    A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even influence large language model (LLM) responses through prompt injection. LangChain Core (i.e., langchain-core) is a core Python package that's part of the...
  9. rottingcastle

    NEWS CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2023-52163 (CVSS...
  10. rottingcastle

    NEWS Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

    Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS SSL VPN in the wild under certain configurations. The vulnerability in question is CVE-2020-12812 (CVSS score: 5.2), an improper authentication vulnerability in SSL VPN in FortiOS that could allow...
  11. rottingcastle

    NEWS LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

    The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master passwords to crack them open and drain cryptocurrency assets as recently as late 2025, according to new findings from TRM Labs. The blockchain intelligence firm said...
  12. rottingcastle

    NEWS U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme

    The U.S. Justice Department (DoJ) on Monday announced the seizure of a web domain and database that it said was used to further a criminal scheme designed to target and defraud Americans by means of bank account takeover fraud. The domain in question, web3adspanels[.]org, was used as a backend...
  13. rottingcastle

    NEWS INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty

    A law enforcement operation coordinated by INTERPOL has led to the recovery of $3 million and the arrest of 574 suspects by authorities from 19 countries, amidst a continued crackdown on cybercrime networks in Africa. The coordinated effort, named Operation Sentinel, took place between October...
  14. rottingcastle

    NEWS Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

    Cybersecurity researchers have discovered two malicious Google Chrome extensions with the same name and published by the same developer that come with capabilities to intercept traffic and capture user credentials. The extensions are advertised as a "multi-location network speed test plug-in"...
  15. rottingcastle

    Interesting Video Tutorial Hacking AI is TOO EASY (this should be illegal)

    *** Hidden text: You do not have sufficient rights to view the hidden text. Visit the forum thread! ***
  16. rottingcastle

    NEWS Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks

    Authorities in Nigeria have announced the arrest of three "high-profile internet fraud suspects" who are alleged to have been involved in phishing attacks targeting major corporations, including the main developer behind the RaccoonO365 phishing-as-a-service (PhaaS) scheme. The Nigeria Police...
  17. rottingcastle

    NEWS Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale

    Threat actors have been observed leveraging malicious dropper apps masquerading as legitimate applications to deliver an Android SMS stealer dubbed Wonderland in mobile attacks targeting users in Uzbekistan. "Previously, users received 'pure' Trojan APKs that acted as malware immediately upon...
  18. rottingcastle

    NEWS Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

    Cybersecurity researchers have disclosed details of a new malicious package on the npm repository that works as a fully functional WhatsApp API, but also contains the ability to intercept every message and link the attacker's device to a victim's WhatsApp account. The package, named...
  19. rottingcastle

    Interesting Video Tutorial how to hack website login pages | Brute Forcing with Hydra

    *** Hidden text: You do not have sufficient rights to view the hidden text. Visit the forum thread! ***
  20. rottingcastle

    Interesting Video Tutorial how hackers find location from ip address | Kali Linux

    *** Hidden text: You do not have sufficient rights to view the hidden text. Visit the forum thread! ***
Top Bottom