Magic/Tragic Email Links: Don't make them the only option
https://ift.tt/MKj74SN
Submitted January 08, 2025 at 07:46PM by gepeto42
via reddit https://ift.tt/dTQvDmq
https://ift.tt/MKj74SN
Submitted January 08, 2025 at 07:46PM by gepeto42
via reddit https://ift.tt/dTQvDmq
Recyclebin.zip
Magic/Tragic Email Links: Don't make them the only option
Subnoscription websites now like to use magic email links for login. They are extremely annoying.
Top 10 web hacking techniques of 2024: nominations open
https://ift.tt/FPNMx2X
Submitted January 09, 2025 at 01:56PM by nibblesec
via reddit https://ift.tt/i9lcE0p
https://ift.tt/FPNMx2X
Submitted January 09, 2025 at 01:56PM by nibblesec
via reddit https://ift.tt/i9lcE0p
PortSwigger Research
Top 10 web hacking techniques of 2024: nominations open
Nominations are now open for the top 10 new web hacking techniques of 2024! Every year, security researchers from all over the world share their latest findings via blog posts, presentations, PoCs, an
Bypassing File Upload Restrictions To Exploit Client-Side Path Traversal (CSPT, CSPT2CSRF)
https://ift.tt/zsRUZSF
Submitted January 09, 2025 at 01:55PM by nibblesec
via reddit https://ift.tt/rGZFt4a
https://ift.tt/zsRUZSF
Submitted January 09, 2025 at 01:55PM by nibblesec
via reddit https://ift.tt/rGZFt4a
Abuse a time-based SQL injection by customizing SQLMAP
https://ift.tt/0UL1Cp3
Submitted January 09, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/aIcgYVj
https://ift.tt/0UL1Cp3
Submitted January 09, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/aIcgYVj
Hackmosphere
Time-based Blind SQL Injection et modification de SQLMAP
Time-based blind SQL injection : Découvrez comment cette faille se distingue par sa capacité à exfiltrer des données sans activer d'alerte.
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
https://ift.tt/O3sXyxv
Submitted January 09, 2025 at 09:40PM by albinowax
via reddit https://ift.tt/fpmaE8N
https://ift.tt/O3sXyxv
Submitted January 09, 2025 at 09:40PM by albinowax
via reddit https://ift.tt/fpmaE8N
Orange Tsai
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
📌 This is a cross-post from DEVCORE. The research was first published at Black Hat Europe 2024. Personally, I would like to thank splitline, the co-author of this research & article, whose help
Do Secure-By-Design Pledges Come With Stickers? - Ivanti Connect Secure RCE (CVE-2025-0282) - watchTowr Labs
https://ift.tt/AkXehRK
Submitted January 10, 2025 at 07:05AM by dx7r__
via reddit https://ift.tt/Dsd54np
https://ift.tt/AkXehRK
Submitted January 10, 2025 at 07:05AM by dx7r__
via reddit https://ift.tt/Dsd54np
watchTowr Labs
Do Secure-By-Design Pledges Come With Stickers? - Ivanti Connect Secure RCE (CVE-2025-0282)
Did you have a good break? Have you had a chance to breathe? Wake up.
It’s 2025, and the chaos continues.
Haha, see what we did? We wrote the exact same thing in 2024 because 2024 was exactly the same.
As an industry, we are on GroundHog day -
It’s 2025, and the chaos continues.
Haha, see what we did? We wrote the exact same thing in 2024 because 2024 was exactly the same.
As an industry, we are on GroundHog day -
Exploiting SSTI in a Modern Spring Boot Application (3.3.4)
https://ift.tt/KwxzvGp
Submitted January 10, 2025 at 02:18PM by parzel
via reddit https://ift.tt/9ONDTJR
https://ift.tt/KwxzvGp
Submitted January 10, 2025 at 02:18PM by parzel
via reddit https://ift.tt/9ONDTJR
Modzero
Exploiting SSTI in a Modern Spring Boot Application (3.3.4) / modzero
How to jailbreak most/all LLMs using Assistant Prefill
https://ift.tt/iaTDkfg
Submitted January 10, 2025 at 08:53PM by Ok_Information1453
via reddit https://ift.tt/Q0MCHJn
https://ift.tt/iaTDkfg
Submitted January 10, 2025 at 08:53PM by Ok_Information1453
via reddit https://ift.tt/Q0MCHJn
Invicti
First Tokens: The Achilles’ Heel of LLMs
The Assistant Prefill feature available in many LLMs can open up models to jailbreaking, including the possibility of persistent prefills to bypass LLM safety alignments.
ACE up the sleeve: Hacking into Apple's new USB-C Controller
https://ift.tt/jRH3PGT
Submitted January 10, 2025 at 11:01PM by Titokhan
via reddit https://ift.tt/IrsTEPg
https://ift.tt/jRH3PGT
Submitted January 10, 2025 at 11:01PM by Titokhan
via reddit https://ift.tt/IrsTEPg
media.ccc.de
ACE up the sleeve:
With the iPhone 15 & iPhone 15 Pro, Apple switched their iPhone to USB-C and introduced a new USB-C controller: The ACE3, a powerful, ver...
Gayfemboy: A Botnet Deliver Through a Four-Faith Industrial Router 0-day Exploit.
https://ift.tt/czW2fXb
Submitted January 11, 2025 at 06:02AM by LordAlfredo
via reddit https://ift.tt/gHhw7fW
https://ift.tt/czW2fXb
Submitted January 11, 2025 at 06:02AM by LordAlfredo
via reddit https://ift.tt/gHhw7fW
奇安信 X 实验室
Gayfemboy: A Botnet Deliver Through a Four-Faith Industrial Router 0-day Exploit.
Overview
Countless noscript kiddies, dreaming of getting rich, rush into the DDoS black-market industry armed with Mirai source code, imagining they can make a fortune with botnets. Reality, however, is harsh—these individuals arrive full of ambition but…
Countless noscript kiddies, dreaming of getting rich, rush into the DDoS black-market industry armed with Mirai source code, imagining they can make a fortune with botnets. Reality, however, is harsh—these individuals arrive full of ambition but…
$2m laundered: the YouTube crypto tutorials’ huge scam (investigation)
https://ift.tt/Fn5pRof
Submitted January 12, 2025 at 02:03AM by WesternBest
via reddit https://ift.tt/NRty7ol
https://ift.tt/Fn5pRof
Submitted January 12, 2025 at 02:03AM by WesternBest
via reddit https://ift.tt/NRty7ol
Medium
$2m laundered: the YouTube crypto tutorials’ huge scam (investigation)
How 1 youtube video turned out to be a part of a million dollar scam scheme
Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282) - watchTowr Labs
https://ift.tt/8HvujdE
Submitted January 12, 2025 at 02:25PM by dx7r__
via reddit https://ift.tt/ohxFCDN
https://ift.tt/8HvujdE
Submitted January 12, 2025 at 02:25PM by dx7r__
via reddit https://ift.tt/ohxFCDN
watchTowr Labs
Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)
As we saw in our previous blogpost, we fully analyzed Ivanti’s most recent unauthenticated Remote Code Execution vulnerability in their Connect Secure (VPN) appliance. Specifically, we analyzed CVE-2025-0282.
Today, we’re going to walk through exploitation.…
Today, we’re going to walk through exploitation.…
Fireblocks Black Box Security Review
https://ift.tt/ku1EIqp
Submitted January 13, 2025 at 09:05PM by arrowflakes
via reddit https://ift.tt/nvxbMok
https://ift.tt/ku1EIqp
Submitted January 13, 2025 at 09:05PM by arrowflakes
via reddit https://ift.tt/nvxbMok
CoinFabrik
Fireblocks API Black Box Review | Findings Summary
Discover the new Fireblocks API Black Box review performed by CoinFabrik for a detailed analysis of its security and performance.
Threat actors exploit a probable 0-day in exposed management consoles of Fortinet FortiGate firewalls
https://ift.tt/qJBeHFX
Submitted January 14, 2025 at 03:30PM by liamnotrop
via reddit https://ift.tt/7SLVIvP
https://ift.tt/qJBeHFX
Submitted January 14, 2025 at 03:30PM by liamnotrop
via reddit https://ift.tt/7SLVIvP
Orangecyberdefense
0-day in exposed management consoles of Fortinet FortiGate firewalls
A recent campaign targeting FortiGate firewalls, where the devices’ management interfaces exposed to the Internet were compromised.
Over 5,000 WordPress sites caught in WP3.XYZ malware attack
https://ift.tt/A23YfaM
Submitted January 14, 2025 at 06:17PM by unknownhad
via reddit https://ift.tt/28uvcUn
https://ift.tt/A23YfaM
Submitted January 14, 2025 at 06:17PM by unknownhad
via reddit https://ift.tt/28uvcUn
cside
Over 5,000 WordPress sites caught in WP3[.]XYZ malware attack
We’ve uncovered a widespread malware campaign targeting WordPress websites, affecting over 5,000 sites globally.
The malicious domain: "https://wp3.xyz/plugin[.]php".
The malicious domain: "https://wp3.xyz/plugin[.]php".
Story of a Pentester Recruitment 2025
https://ift.tt/4VlcPiv
Submitted January 14, 2025 at 07:33PM by buherator
via reddit https://ift.tt/Gt4giUe
https://ift.tt/4VlcPiv
Submitted January 14, 2025 at 07:33PM by buherator
via reddit https://ift.tt/Gt4giUe
Silent Signal Techblog
Story of a Pentester Recruitment 2025
Because we can!
Millions of Accounts Vulnerable due to Google’s OAuth Flaw
https://ift.tt/XbTr7DH
Submitted January 14, 2025 at 10:14PM by wifihack
via reddit https://ift.tt/wDnFBAL
https://ift.tt/XbTr7DH
Submitted January 14, 2025 at 10:14PM by wifihack
via reddit https://ift.tt/wDnFBAL
Trufflesecurity
Millions of Accounts Vulnerable due to Google’s OAuth Flaw ◆ Truffle Security Co.
Millions of Americans can have their data stolen right now because of a deficiency in Google’s “Sign in with Google” authentication flow. If you’ve worked for a startup in the past - especially one that has since shut down - you might be vulnerable.
Command Line Underdog: WMIC in Action -- How to use wmic as an alternate shell in a pinch
https://ift.tt/VaycXuL
Submitted January 14, 2025 at 09:45PM by oddvarmoe
via reddit https://ift.tt/O3kI18R
https://ift.tt/VaycXuL
Submitted January 14, 2025 at 09:45PM by oddvarmoe
via reddit https://ift.tt/O3kI18R
New Microsoft OLE Vulnerability, Exploitable via Email
https://ift.tt/H1lnvUg
Submitted January 15, 2025 at 01:11AM by LordAlfredo
via reddit https://ift.tt/zkoUZE2
https://ift.tt/H1lnvUg
Submitted January 15, 2025 at 01:11AM by LordAlfredo
via reddit https://ift.tt/zkoUZE2
Laser Fault Injection on a Budget: RP2350 Edition
https://ift.tt/fSDtUC3
Submitted January 15, 2025 at 01:56AM by Titokhan
via reddit https://ift.tt/qVyCwlB
https://ift.tt/fSDtUC3
Submitted January 15, 2025 at 01:56AM by Titokhan
via reddit https://ift.tt/qVyCwlB
Courk's Blog
Laser Fault Injection on a Budget: RP2350 Edition
In August 2024, Raspberry Pi introduced the RP2350 microcontroller. This part iterates over the RP2040 and comes with numerous new features. These include security-related capabilities, such as a Secure Boot implementation. A couple of days after this announcement…
RCE in rsync, CVE-2024-12084 (and 5 more vulnerabilities)
https://ift.tt/qQ7zDES
Submitted January 15, 2025 at 04:06AM by thenickdude
via reddit https://ift.tt/N3JneSP
https://ift.tt/qQ7zDES
Submitted January 15, 2025 at 04:06AM by thenickdude
via reddit https://ift.tt/N3JneSP