's Avatar

@xc0py.bsky.social

61 Followers  |  143 Following  |  114 Posts  |  Joined: 06.02.2024  |  1.8136

Latest posts by xc0py.bsky.social on Bluesky

Preview
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits Trendβ„’ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts obse...

Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits www.trendmicro.com/en_us/resear...

17.10.2025 12:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
myF5

K000154696: F5 Security Incident my.f5.com/manage/s/art...

15.10.2025 19:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High On October 3, 2025, GreyNoise observed a ~500% increase in IPs scanning Palo Alto Networks login portals, the highest level recorded in the past 90 days.Β The activity was highly targeted and involved ...

GreyNoise observed a ~500% surge in IPs scanning Palo Alto Networks login portals on October 3, 2025 β€” the highest level we’ve seen in 90 days. Read our full analysis here πŸ‘‡ #PaloAltoNetworks #PaloAlto #GreyNoise #ThreatIntel #PANOS

03.10.2025 21:01 β€” πŸ‘ 4    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Cisco Event Response: Continued Attacks Against Cisco Firewalls

Cisco Event Response: Continued Attacks Against Cisco Firewalls sec.cloudapps.cisco.com/security/cen...

01.10.2025 02:07 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cisco Security Advisory: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privil...

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability sec.cloudapps.cisco.com/security/cen...

25.09.2025 12:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - TwoSevenOneT/EDR-Freeze: EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state. EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state. - TwoSevenOneT/EDR-Freeze

EDR-Freeze github.com/TwoSevenOneT...

23.09.2025 13:58 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages... Socket.dev found compromised various CrowdStrike npm packages, continuing the "Shai-Halud" supply-chain attack that previously hit `tinycolor`.

🚨 Multiple CrowdStrike packages trojanized in an ongoing npm supply chain attack: This is the same campaign that hit Tinycolor yesterday with identical malware.

Full list of compromised packages + mitigations β†’
socket.dev/blog/ongoing... #NodeJS #JavaScript

16.09.2025 11:00 β€” πŸ‘ 14    πŸ” 6    πŸ’¬ 0    πŸ“Œ 5
Preview
25,000 IPs Scanned Cisco ASA Devices β€” New Vulnerability Potentially Incoming GreyNoise observed two scanning surges against Cisco Adaptive Security Appliance (ASA) devices in late August including more than 25,000 unique IPs in a single burst. This activity represents a signif...

GreyNoise observed two scanning surges against Cisco ASA devices in late August, both representing significant elevations above baseline. This activity led to the discovery of a botnet cluster solely scanning for Cisco ASA on August 26.
#CiscoASA #Cisco #GreyNoise #Cybersecurity #ThreatIntel

04.09.2025 14:06 β€” πŸ‘ 5    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Original post on swecyb.com

Interesting write-up coming out of Lab52 where #APT28 (aka Fancy Bear) appear to be using a backdoor communicating through MAPI and Outlook, ie. using email as a C2-channel with base64 encoded instructions etc.

https://lab52.io/blog/analyzing-notdoor-inside-apt28s-expanding-arsenal/ […]

03.09.2025 08:31 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System | CISA The authoring agencies strongly urge network defenders to hunt for malicious activity and to apply the mitigations in this CSA to reduce the threat of Chinese state-sponsored and other malicious cyber...

Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System www.cisa.gov/news-events/...

29.08.2025 13:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cisco Security Advisory: Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that...

Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability sec.cloudapps.cisco.com/security/cen...

18.08.2025 01:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Lenovo Webcam Firmware Update Vulnerability CVE-2025-4371 support.lenovo.com/us/en/produc...

14.08.2025 00:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
BitUnlocker - Multiple 0-days to Bypass BitLocker and Extract All Protected Data Researchers have disclosed a series of critical zero-day vulnerabilities that completely bypass Windows BitLocker encryption, allowing attackers with physical access to extract all protected data from...

BitUnlocker – Multiple 0-days to Bypass BitLocker and Extract All Protected Data cybersecuritynews.com/bitunlocker-...

09.08.2025 14:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
New Lenovo UEFI firmware updates fix Secure Boot bypass flaws Lenovo is warning about high-severity BIOS flaws that could allow attackers to potentially bypass Secure Boot in all-in-one desktop PC models that use customized Insyde UEFI (Unified Extensible Firmwa...

New Lenovo UEFI firmware updates fix Secure Boot bypass flaws www.bleepingcomputer.com/news/securit...

02.08.2025 12:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Attackers abusing Proofpoint & Intermedia link wrapping to deliver phishing payloads Attackers are exploiting Proofpoint and Intermedia link wrapping to mask phishing payloads.

Attackers abusing Proofpoint & Intermedia link wrapping to deliver phishing payloads www.cloudflare.com/threat-intel...

01.08.2025 14:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
About the security content of iOS 18.6 and iPadOS 18.6 - Apple Support This document describes the security content of iOS 18.6 and iPadOS 18.6.

APPLE-SA-07-29-2025-1 iOS 18.6 and iPadOS 18.6 support.apple.com/en-us/124147

29.07.2025 23:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Sonicwall fixes critical flaw in SMA appliances, urges customers to check for compromise (CVE-2025-40599) - Help Net Security Sonicwall is asking customers SMA 100 Series devices to patch a newly uncovered vulnerability (CVE-2025-40599) as soon as possible.

Sonicwall fixes critical flaw in SMA appliances, urges customers to check for compromise (CVE-2025-40599)

πŸ“– Read more: www.helpnetsecurity.com/2025/07/24/s...

#cybersecurity #cybersecuritynews #vulnerability

24.07.2025 10:18 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

There's a new Microsoft SharePoint zero-day getting exploited right now: CVE-2025-53770

msrc.microsoft.com/blog/2025/07...

20.07.2025 15:19 β€” πŸ‘ 18    πŸ” 6    πŸ’¬ 1    πŸ“Œ 2
Preview
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 β€” nearly two weeks before a public proof-of-concept was released on July 4.

GreyNoise observed exploitation of CitrixBleed 2 (CVE-2025-5777) nearly two weeks before a public PoC was released. Full breakdown ⬇️
#GreyNoise #ThreatIntel #CitrixBleed #Citrix #NetScaler

16.07.2025 20:45 β€” πŸ‘ 7    πŸ” 8    πŸ’¬ 0    πŸ“Œ 0
Preview
Microsoft Patch Tuesday, July 2025 Edition Microsoft today released updates to fix at least 137 security vulnerabilities in its Windows operating systems and supported software. None of the weaknesses addressed this month are known to be activ...

Microsoft Patch Tuesday, July 2025 Edition krebsonsecurity.com/2025/07/micr...

09.07.2025 10:40 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cisco Security Advisory: Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying ...

Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/security/cen...

27.06.2025 12:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Another Wave: North Korean Contagious Interview Campaign Dro... North Korean threat actors linked to the Contagious Interview campaign return with 35 new malicious npm packages using a stealthy multi-stage malware ...

🚨 Contagious Interview returns:
North Korean threat actors just dropped 35 new malicious npm packages that use a HexEval loader to deploy BeaverTail malware.
These attacks target devs via fake job offers and coding tests laced with malware.

Full analysis: socket.dev/blog/north-k... #NodeJS

25.06.2025 02:45 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
KB4743: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 www.veeam.com/kb4743

19.06.2025 10:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Two Botnets, One Flaw: Mirai Spreads Through Wazuh Vulnerability www.akamai.com/blog/securit...

10.06.2025 22:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cisco Security Advisory: Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote at...

Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability sec.cloudapps.cisco.com/security/cen...

05.06.2025 10:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
CVE-2025-32756: Fortinet RCE Exploited in the Wild Analyze CVE-2025-32756, a Fortinet buffer overflow flaw under active attack, and see how NodeZero can validate exposure now.

CVE-2025-32756: Low-Rise Jeans are Back and so are Buffer Overflows horizon3.ai/attack-resea...

27.05.2025 16:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Support Content Notification - Support Portal - Broadcom support portal

VMware Tools update addresses an insecure file handling vulnerability (CVE-2025-22247) support.broadcom.com/web/ecx/supp...

19.05.2025 10:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Multiple Vulnerabilities In Ivanti Endpoint Manager Mobile (Ivanti EPMM) www.cyber.gov.au/about-us/vie...

15.05.2025 01:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws Today is Microsoft's May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities.

Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws www.bleepingcomputer.com/news/microso...

13.05.2025 23:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
the word corruption that is on a blue and yellow background ALT: the word corruption that is on a blue and yellow background
11.05.2025 19:23 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@xc0py is following 20 prominent accounts