👁️8,960
GitHubLinkedIn
Cybersecurity and Tech5 min read828 words

🚨 Security - Passkey Compromise Risks

👁️0reads (human + AI)🤖0AI ingestions
Direct Technical Summary

Passkeys are becoming increasingly popular as a more secure alternative to passwords. However, there is a risk of passkey compromise if not implemented correctly. Organizations sho

🚨 Security - Passkey Compromise Risks

Passkeys are becoming increasingly popular as a more secure alternative to passwords. However, there is a risk of passkey compromise if not implemented correctly. Organizations should be aware of this risk and update their security playbooks accordingly.

Key Points:
• Passkeys can be compromised if not implemented correctly.
• Organizations should update their security playbooks to account for this risk.
• Higher roles or automated responses may be necessary to mitigate the risk.

🔗 Resources:
https://x.com/NathanMcNulty/status/2095799439529316849 ↗ - Original source
Passkey Compromise Risks ↗ - Passkey compromise risks


🚨 Security - ANYRUN Updates

ANYRUN has released updates to its Connections experience in TI Lookup, which helps analysts uncover related infrastructure faster. Additionally, 656+ new rules and fresh research on active campaigns have been added.

Key Points:
• ANYRUN has updated its Connections experience in TI Lookup.
• The update helps analysts uncover related infrastructure faster.
• 656+ new rules and fresh research on active campaigns have been added.

🔗 Resources:
https://x.com/anyrun_app/status/2095785142207819814 ↗ - Original source
ANYRUN Updates ↗ - ANYRUN updates


🤖 Ciphey v0.12.1

Ciphey v0.12.1 is a tool that can automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes.

Key Points:
• Ciphey v0.12.1 can automatically decrypt encryptions.
• It can decode encodings and crack hashes.
• The tool is available for download.

🔗 Resources:
https://x.com/KitPloit/status/2095784281624715372 ↗ - Original source
• [Ciphey v0.12.1](https://kitploit.com/en/tools/githu ↗ b/bee-san/ciphey) - Ciphey v0.12.1


🚨 Security - Kubernetes Forensics

A Kubernetes cluster is compromised. Forensic investigation in Kubernetes cannot be improvised. Discover our training: Kubernetes Forensics.

Key Points:
• A Kubernetes cluster is compromised.
• Forensic investigation in Kubernetes cannot be improvised.
• Kubernetes Forensics training is available.

🔗 Resources:
https://x.com/Synacktiv/status/2095782088523809207 ↗ - Original source
Kubernetes Forensics ↗ - Kubernetes Forensics training


🤖 Blackstorm Security Research

Blackstorm Security has published 1,600+ pages of research for FREE. Windows kernel exploitation, driver reversing, patch diffing, Chrome / V8 / and more are covered.

Key Points:
• Blackstorm Security has published 1,600+ pages of research.
• The research covers Windows kernel exploitation, driver reversing, and more.
• The research is available for free.

🔗 Resources:
https://x.com/cr3ghost/status/2094408231980560508 ↗ - Original source
Blackstorm Security Research ↗ - Blackstorm Security research


🚨 Security - Prince of Persia

Prince of Persia: mapping the backend, and a reserve of domains staged for what comes next. IOC, reports, and attachments are available.

Key Points:
• Prince of Persia: mapping the backend.
• A reserve of domains is staged for what comes next.
• IOC, reports, and attachments are available.

🔗 Resources:
https://x.com/blackorbird/status/2095775120178745408 ↗ - Original source
• [Prince of Persia](https://whisper.security/resources/blog ↗ /prince-of-persia-mapping-the-backend-and-a-reserve-of-domains-staged-for-what-comes-next) - Prince of Persia mapping


🚨 Security - APT36

#APT #APT36 #TransparentTribe #CrimsonRAT #threat #malware. APT36 uses phishing, ISO, ZIP, LNK, BAT, cmd.exe, PowerShell, fake PDF and .txt, RegKey, and more.

Key Points:
• APT36 uses phishing, ISO, ZIP, LNK, BAT, cmd.exe, PowerShell, fake PDF and .txt, RegKey, and more.
• The attack involves multiple stages.
• APT36 is a threat actor.

🔗 Resources:
https://x.com/RexorVc0/status/2095764790052327619 ↗ - Original source
APT36 ↗ - APT36 threat actor


🚨 Security - TTP

#TTP 📩[T1566.001] Spear-Phishing 💿[T1553.005] ISO 📇[T1204.002] Mal LNK ⚙️[T1059.003] BAT + cmd.exe 📜[T1059.001] PowerShell 🎭[T1036] Fake PDF and .txt ⚓️[T1547.001] RegKey + Startup Persistence 🧹[T1070.004] Self-delete files 📂[T1083] File & Dir Discovery 📤[T1041] Exfil.

Key Points:
• Spear-phishing is used.
• ISO, Mal LNK, BAT, cmd.exe, PowerShell, fake PDF and .txt, RegKey, and more are used.
• The attack involves multiple stages.

🔗 Resources:
https://x.com/RexorVc0/status/2095764793726468176 ↗ - Original source
TTP ↗ - TTP threat actor


🎮 TheSAS2026

Another #TheSAS2026 sneak peek, because it’s Friday and games feel appropriate. But running Doom on tractors is so 2022. Running Linux on a PS5 after a full hypervisor defeat? Better.

Key Points:
• Running Linux on a PS5 after a full hypervisor defeat is possible.
• TheSAS2026 will cover the PS5 security architecture.
• Andy Nguyen will walk through the PS5 security architecture.

🔗 Resources:
https://x.com/TheSAScon/status/2095762031227846801 ↗ - Original source
TheSAS2026 ↗ - TheSAS2026


🚨 Security - Malware

Last time on Dragon Ball Z > be me > get DM > "smelly i found goop" > wtf i love goop (malware) > download > look inside > malware masquerading as Pokemon Map Loader > bonk bonk > installer -> nodejs goop -> java goop > java obfuscated with qProtect 2.0 > annoying > uses.

Key Points:
• Malware is masquerading as Pokemon Map Loader.
• The malware uses nodejs and java.
• The malware is obfuscated with qProtect 2.0.

🔗 Resources:
https://x.com/vxunderground/status/2095754588431294671 ↗ - Original source
Malware ↗ - Malware

📂Source / Implementation:Cybersecurity and Tech / resources-202.md
GitHub Repository

Related Cybersecurity and Tech Breakdowns

Drishtant Ghosh (Drix10)
Drishtant Ghosh (Drix10)Author & Engineer

Technical founder and engineer working across AI systems, developer infrastructure, and cybersecurity.