New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails
https://ift.tt/cmYBPAo
Submitted March 05, 2025 at 07:01AM by _PentesterLab_
via reddit https://ift.tt/1PCAa7y
https://ift.tt/cmYBPAo
Submitted March 05, 2025 at 07:01AM by _PentesterLab_
via reddit https://ift.tt/1PCAa7y
Elttam
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails - elttam
elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.
Case Study: Traditional CVSS scoring missed this actively exploited vulnerability (CVE-2024-50302)
https://ift.tt/nxUOZBk
Submitted March 05, 2025 at 09:01AM by skimfl925
via reddit https://ift.tt/25XHNbd
https://ift.tt/nxUOZBk
Submitted March 05, 2025 at 09:01AM by skimfl925
via reddit https://ift.tt/25XHNbd
EvilLoader: Yesterday was published PoC for unpatched Vulnerability affecting Telegram for Android
https://ift.tt/50fsDaA
Submitted March 05, 2025 at 01:22PM by barakadua131
via reddit https://ift.tt/PNWTg9O
https://ift.tt/50fsDaA
Submitted March 05, 2025 at 01:22PM by barakadua131
via reddit https://ift.tt/PNWTg9O
Mobile Hacker
EvilLoader: Unpatched Telegram for Android Vulnerability Disclosed
A newly disclosed in Telegram for Android, dubbed EvilLoader, allows attackers to disguise malicious APKs as video files, potentially leading to unauthorized malware installations on users' devices.
Case study - Getting access to the internal network through a physical pentest
https://ift.tt/umI2ZPo
Submitted March 05, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/IarwY1L
https://ift.tt/umI2ZPo
Submitted March 05, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/IarwY1L
Hackmosphere
Pentest physique en magasin : retour d’expérience sur un cas réel - Hackmosphere
Un pentest physique mené dans un magasin d’ameublement a permis de mettre au jour plusieurs failles de sécurité importantes.
Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue
https://ift.tt/bJZPqy8
Submitted March 05, 2025 at 06:34PM by bajk
via reddit https://ift.tt/X35NyWk
https://ift.tt/bJZPqy8
Submitted March 05, 2025 at 06:34PM by bajk
via reddit https://ift.tt/X35NyWk
AFINE - digitally secure
Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue - AFINE - digitally secure
The discovery of a DoS in the macOS NS_01 driver within Apple’s IONVMeFamily, offering insights into integer overflow detection, and crash analysis.
Understanding and Mitigating TOCTOU Vulnerabilities in C# Applications
https://ift.tt/spPqRfV
Submitted March 05, 2025 at 06:33PM by bajk
via reddit https://ift.tt/WJZ6HjR
https://ift.tt/spPqRfV
Submitted March 05, 2025 at 06:33PM by bajk
via reddit https://ift.tt/WJZ6HjR
AFINE - digitally secure
Understanding and Mitigating TOCTOU Vulnerabilities in C# Applications - AFINE - digitally secure
In this article, we explore TOCTOU vulnerabilities, subtle yet dangerous race conditions that occur when security checks and resource usage are not tightly coupled. In C# development on Windows, where file operations and dynamic code loading are common, understanding…
Multiple backdoors injected using frontend JS
https://ift.tt/kAOsbaC
Submitted March 05, 2025 at 08:35PM by unknownhad
via reddit https://ift.tt/2X1tPpz
https://ift.tt/kAOsbaC
Submitted March 05, 2025 at 08:35PM by unknownhad
via reddit https://ift.tt/2X1tPpz
cside
Thousands of websites hit by four backdoors in 3rd party JavaScript attack
While analyzing threats targeting WordPress frameworks, we found an attack where a single 3rd party JavaScript file was used to inject four separate backdoors into 1,000 compromised websites using cdn.csyndication[.]com/.
Security ROI Explained: “Why Investing in Penetration Testing Saves Your Business” - Laburity
https://ift.tt/XfvLONa
Submitted March 06, 2025 at 12:58PM by Ancient_Title_1860
via reddit https://ift.tt/jYMIyFv
https://ift.tt/XfvLONa
Submitted March 06, 2025 at 12:58PM by Ancient_Title_1860
via reddit https://ift.tt/jYMIyFv
Laburity - Cyber Security Services
Cybersecurity ROI Explained: “Why Investing in Penetration Testing Saves Your Business” - Laburity
Introduction: Cybersecurity has to be a major concern for businesses in light of the growing cyber threats and increased regulatory pressure. A single breach can cost a business dearly, financially, and reputation-wise. Investing in the operation of security…
Zen and the Art of Microcode Hacking
https://ift.tt/FNcmtVu
Submitted March 06, 2025 at 02:04PM by AlmondOffSec
via reddit https://ift.tt/yplg4Th
https://ift.tt/FNcmtVu
Submitted March 06, 2025 at 02:04PM by AlmondOffSec
via reddit https://ift.tt/yplg4Th
Google
Blog: Zen and the Art of Microcode Hacking
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
Sleeping Beauty Vulnerability: Bypassing CrowdStrike Falcon With One Simple Trick
https://ift.tt/JBNk9z8
Submitted March 06, 2025 at 03:25PM by Longjumping-Top2717
via reddit https://ift.tt/UcAWJTo
https://ift.tt/JBNk9z8
Submitted March 06, 2025 at 03:25PM by Longjumping-Top2717
via reddit https://ift.tt/UcAWJTo
SEC Consult
Sleeping Beauty: Taming CrowdStrike Falcon With One Simple Trick
Sitecore: Unsafe Deserialisation Again! (CVE-2025-27218)
https://ift.tt/y69GPvo
Submitted March 06, 2025 at 02:40PM by Mempodipper
via reddit https://ift.tt/rFHi8jC
https://ift.tt/y69GPvo
Submitted March 06, 2025 at 02:40PM by Mempodipper
via reddit https://ift.tt/rFHi8jC
Searchlight Cyber
Sitecore: Unsafe Deserialisation Again! (CVE-2025-27218) › Searchlight Cyber
Assetnote, now a searchlight cyber company, has uncovered a zero day REMOTE COMMAND EXECUTION VULNERABILITY in SITECORE EXPERIENCE PLATFORM new Sitecore vulnerabilities discovered
The Burn Notice, Part 2/5 | How We Uncovered a Critical Vulnerability in a Leading AI Agent Framework
https://ift.tt/NgwRfeu
Submitted March 06, 2025 at 08:16PM by we-we-we
via reddit https://ift.tt/Ba2xNdO
https://ift.tt/NgwRfeu
Submitted March 06, 2025 at 08:16PM by we-we-we
via reddit https://ift.tt/Ba2xNdO
Medium
The Burn Notice, Part 2/5 | AI Agents: When Everything Becomes an Attack Surface
We Manipulated an HR Agent to Betray Its Own Organization and Discovered a Critical Vulnerability in The Process (CVE-2025–26319)
Command Injection - Compressive Guide & Payloads | VeryLazyTech
https://ift.tt/EoQt7BC
Submitted March 06, 2025 at 09:20PM by Justin_coco
via reddit https://ift.tt/HbGqpCA
https://ift.tt/EoQt7BC
Submitted March 06, 2025 at 09:20PM by Justin_coco
via reddit https://ift.tt/HbGqpCA
Verylazytech
Command Injection | VeryLazyTech
Crxplorer.com is a great free tool for blue team to check overly permissive browser extensions
http://Crxplorer.com
Submitted March 07, 2025 at 06:01PM by kinso1338
via reddit https://ift.tt/pRbVe7l
http://Crxplorer.com
Submitted March 07, 2025 at 06:01PM by kinso1338
via reddit https://ift.tt/pRbVe7l
CRXPlorer
CRXPlorer - Analyze Chrome Extensions for Security & Performance
Scan and analyze Chrome extensions for security vulnerabilities, performance issues, and compliance. Get detailed reports and insights.
Reversing Samsung's H-Arx Hypervisor Framework (Part 1)
https://ift.tt/uJZvFA5
Submitted March 08, 2025 at 06:10PM by PM_ME_YOUR_SHELLCODE
via reddit https://ift.tt/Oyv93X8
https://ift.tt/uJZvFA5
Submitted March 08, 2025 at 06:10PM by PM_ME_YOUR_SHELLCODE
via reddit https://ift.tt/Oyv93X8
dayzerosec
Reversing Samsung's H-Arx Hypervisor Framework - Part 1
In many ways, mobile devices lead the security industry when it comes to defense-in-depth and mitigation. Over the years, it has been proven time and again that the kernel cannot be trusted to be secure. As such, there has been effort put into moving secrets…
Injecting domain expertise into your AI system
https://ift.tt/Gva8O0Z
Submitted March 09, 2025 at 05:39PM by boybeaid
via reddit https://ift.tt/JSGHzAX
https://ift.tt/Gva8O0Z
Submitted March 09, 2025 at 05:39PM by boybeaid
via reddit https://ift.tt/JSGHzAX
Medium
Injecting domain expertise into your AI system
How to connect the dots between AI technology and real life
FlippyR.AM: Large-Scale Rowhammer Study
https://flippyr.am/
Submitted March 10, 2025 at 05:01PM by citirix
via reddit https://ift.tt/vPhxqgy
https://flippyr.am/
Submitted March 10, 2025 at 05:01PM by citirix
via reddit https://ift.tt/vPhxqgy
Reddit
From the netsec community on Reddit: FlippyR.AM: Large-Scale Rowhammer Study
Posted by citirix - 32 votes and 20 comments
Azure’s Weakest Link? How API Connections Spill Secrets
https://ift.tt/34oBxw6
Submitted March 10, 2025 at 07:05PM by piraterapper
via reddit https://ift.tt/x9vNYud
https://ift.tt/34oBxw6
Submitted March 10, 2025 at 07:05PM by piraterapper
via reddit https://ift.tt/x9vNYud
Binary Security AS
Azure’s Weakest Link? How API Connections Spill Secrets
Binary Security found the undocumented APIs for Azure API Connections. In this post we examine the inner workings of the Connections allowing us to escalate privileges and read secrets in backend resources for services ranging from Key Vaults, Storage Blobs…
HOWTO: build ATF (Trusted Firmware ARM) and OPTEE for RK3588
https://ift.tt/YtcruXK
Submitted March 10, 2025 at 11:23PM by hardenedvault
via reddit https://ift.tt/JiERFKa
https://ift.tt/YtcruXK
Submitted March 10, 2025 at 11:23PM by hardenedvault
via reddit https://ift.tt/JiERFKa
hardenedvault.net
HOWTO: build ATF (Trusted Firmware ARM) and OPTEE for RK3588
HOWTO: build ATF (Trusted Firmware ARM) and OPTEE for RK3588 To better implement the protection of digital assets in embedded systems, we have chosen the RK3588 as the prototype platform.
If you are using Postgres you need to read it
https://ift.tt/zvVwb40
Submitted March 11, 2025 at 12:28AM by amitschenedel
via reddit https://ift.tt/qn4AYfa
https://ift.tt/zvVwb40
Submitted March 11, 2025 at 12:28AM by amitschenedel
via reddit https://ift.tt/qn4AYfa
ARMO
CVE-2025-1094: PostgreSQL SQL Injection Vulnerability - ARMO
Learn about CVE-2025-1094, a critical SQL injection vulnerability in PostgreSQL's escaping functions. Discover affected versions, mitigation strategies, and how to protect your systems.
Auvik Deal is back - Free Raspberry Pi 5 16GB Kit
https://ift.tt/bfTZc9u
Submitted March 11, 2025 at 12:21AM by freebie1234
via reddit https://ift.tt/2lMSQOs
https://ift.tt/bfTZc9u
Submitted March 11, 2025 at 12:21AM by freebie1234
via reddit https://ift.tt/2lMSQOs
Auvik
RRC Easy As Pi
Looking for network management that is effortless? Try Auvik for free, no credit card required and see how easy it is to use and manage. Try it free and get a Raspberry Pi 5 16GB Kit-on us!