SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation | Cleafy
https://ift.tt/WKLq0sr
Submitted April 18, 2025 at 03:36PM by f3d_0x0
via reddit https://ift.tt/KtSlNhy
https://ift.tt/WKLq0sr
Submitted April 18, 2025 at 03:36PM by f3d_0x0
via reddit https://ift.tt/KtSlNhy
Cleafy
SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation | Cleafy
A new fraud campaign based on the Android malware "SuperCard X" and innovative NFC relay techniques is impacting Italian's banking. Read our latest report to learn more.
CVE-2025-25364: Speedify VPN MacOS privilege Escalation
https://ift.tt/zwVIL9Q
Submitted April 18, 2025 at 11:47PM by SL7reach
via reddit https://ift.tt/23HgFPp
https://ift.tt/zwVIL9Q
Submitted April 18, 2025 at 11:47PM by SL7reach
via reddit https://ift.tt/23HgFPp
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
CVE-2025-25364: Speedify VPN MacOS privilege Escalation
SecureLayer7 discovered CVE-2025-25364, which is a critical command injection vulnerability discovered in the me.connectify.SMJobBlessHelper XPC service, a privileged helper tool...
need help extracting firmware from a vr headset in a working state
https://ift.tt/shtOMY2
Submitted April 19, 2025 at 01:41PM by Shot_Morning2815
via reddit https://ift.tt/SbjD1J0
https://ift.tt/shtOMY2
Submitted April 19, 2025 at 01:41PM by Shot_Morning2815
via reddit https://ift.tt/SbjD1J0
Microsoft Store - Download apps, games & more for your Windows PC
Acer OJO 500 - Free download and install on Windows | Microsoft Store
Companion app for the Acer Windows Mixed Reality Headset - Acer OJO 500
b3rito/b3acon: b3acon - a mail-based C2 that communicates via an in-memory C# IMAP client dynamically compiled in memory using PowerShell.
https://ift.tt/14uVCyA
Submitted April 20, 2025 at 02:29AM by b3rito
via reddit https://ift.tt/aMct6El
https://ift.tt/14uVCyA
Submitted April 20, 2025 at 02:29AM by b3rito
via reddit https://ift.tt/aMct6El
Penetration Testing Tools
b3acon: In-Memory C# IMAP C2 over Email
Learn about b3acon, a mail-based C2 using an in-memory C# IMAP client and PowerShell for stealthy communication via email drafts.
BBRadar.io - The Bug Bounty Program Aggregator - Find the latest bug bounty programs from all major platforms.
https://bbradar.io
Submitted April 20, 2025 at 03:08AM by kleoz_
via reddit https://ift.tt/n2WJPZE
https://bbradar.io
Submitted April 20, 2025 at 03:08AM by kleoz_
via reddit https://ift.tt/n2WJPZE
bbradar.io
The Bug Bounty Radar - The Latest Public Bug Bounty Programs | The Bug Bounty Radar
The Bug Bounty Radar - Discover and explore the latest public bug bounty programs from top platforms. Find security research opportunities, compare rewards, and access the most comprehensive bug bounty database. 8 new programs added recently.
Everything You Need to Know About VPNs—Without the "affiliates"
https://ift.tt/OPhtzND
Submitted April 20, 2025 at 11:25AM by EmbarrassedFile5761
via reddit https://ift.tt/4c7kgFY
https://ift.tt/OPhtzND
Submitted April 20, 2025 at 11:25AM by EmbarrassedFile5761
via reddit https://ift.tt/4c7kgFY
Substack
VPNs Explained
The Ultimate Guide for Privacy-Conscious Users
IoT Network Security: Analyzing Decrypted Zigbee Traffic Data
https://ift.tt/pwCvgBP
Submitted April 21, 2025 at 04:40PM by Exchange-Internal
via reddit https://ift.tt/hXoknEP
https://ift.tt/pwCvgBP
Submitted April 21, 2025 at 04:40PM by Exchange-Internal
via reddit https://ift.tt/hXoknEP
Rackenzik
IoT Network Security: Analyzing Decrypted Zigbee Traffic Data - Rackenzik
Explore decrypted Zigbee traffic data for enhanced IoT network security, performance analysis, and smart home automation insights.
Wrote a blog explaining V8 parser workflow with a CVE as a case study.
https://ift.tt/G0HiRpk
Submitted April 21, 2025 at 06:39PM by w1redch4d
via reddit https://ift.tt/EGhXWzw
https://ift.tt/G0HiRpk
Submitted April 21, 2025 at 06:39PM by w1redch4d
via reddit https://ift.tt/EGhXWzw
Attacking My Landlord's Boiler
https://ift.tt/1SY04GL
Submitted April 22, 2025 at 12:27PM by AlmondOffSec
via reddit https://ift.tt/31KTSeg
https://ift.tt/1SY04GL
Submitted April 22, 2025 at 12:27PM by AlmondOffSec
via reddit https://ift.tt/31KTSeg
blog.videah.net
Attacking My Landlord's Boiler - videah's blog
Windows Defender antivirus bypass in 2025 - Part 2
https://ift.tt/DhB6JjS
Submitted April 22, 2025 at 01:10PM by Hackmosphere
via reddit https://ift.tt/tUnb6MA
https://ift.tt/DhB6JjS
Submitted April 22, 2025 at 01:10PM by Hackmosphere
via reddit https://ift.tt/tUnb6MA
Hackmosphere
Windows Defender antivirus bypass in 2025 - part 2
Discover how hackers bypass an antivirus such as Windows Defender, using advanced techniques such as direct syscalls and shellcode encryption
Line jumping: The silent backdoor in MCP
https://ift.tt/gi16Ry2
Submitted April 21, 2025 at 10:58PM by ChemicalImaginary319
via reddit https://ift.tt/cqARp0v
https://ift.tt/gi16Ry2
Submitted April 21, 2025 at 10:58PM by ChemicalImaginary319
via reddit https://ift.tt/cqARp0v
The Trail of Bits Blog
Jumping the line: How MCP servers can attack you before you ever use them
This post is about a vulnerability in the Model Context Protocol (MCP) called “Line Jumping,” where malicious servers can inject prompts through tool denoscriptions to manipulate AI model behavior without being explicitly invoked, effectively bypassing security…
Hack Your Way In - Web CTF Challenge
https://ift.tt/nGt1UL8
Submitted April 22, 2025 at 02:29PM by Winter_Chan
via reddit https://ift.tt/1AgEzR7
https://ift.tt/nGt1UL8
Submitted April 22, 2025 at 02:29PM by Winter_Chan
via reddit https://ift.tt/1AgEzR7
openprocessing.org
CTF - Hack Your Way In (CYBERSECURITY GAME) - Gopal Or
Hey there, code-cracker! I’m the (slightly sleep-deprived) dev who built this little portal to your inner hacker. You’ll be greeted by a pretty purple gradient, mood-setting particles, and an “UNLOCK” button that absolutely refuses to let you in—unless you…
How I made $64k from deleted files — a bug bounty story
https://ift.tt/VtPZSwb
Submitted April 22, 2025 at 09:17PM by sh0n1z
via reddit https://ift.tt/MexLR39
https://ift.tt/VtPZSwb
Submitted April 22, 2025 at 09:17PM by sh0n1z
via reddit https://ift.tt/MexLR39
Medium
How I made $64k from deleted files — a bug bounty story
TL;DR — I built an automation that cloned and scanned tens of thousands of public GitHub repos for leaked secrets. For each repository I…
New Pacu Module: Secret Enumeration in Elastic Beanstalk
https://ift.tt/5jXNica
Submitted April 22, 2025 at 10:01PM by hackers_and_builders
via reddit https://ift.tt/rGHM91N
https://ift.tt/5jXNica
Submitted April 22, 2025 at 10:01PM by hackers_and_builders
via reddit https://ift.tt/rGHM91N
Rhino Security Labs
New Pacu Module: Secret Enumeration in Elastic Beanstalk
Pacu's newest scenario, enumerating Elastic Beanstalk for Secrets, was built to save users hours of testing during an AWS penetration test.
Why RAG is Crucial For LLM Analysis Workflows
https://ift.tt/QmiO9Xq
Submitted April 22, 2025 at 10:54PM by peyton-cyber
via reddit https://ift.tt/jqi2tGa
https://ift.tt/QmiO9Xq
Submitted April 22, 2025 at 10:54PM by peyton-cyber
via reddit https://ift.tt/jqi2tGa
Substack
AI Agents: Why RAG is Crucial for Cyber Security Workloads
Cybersecurity analysts often rely on Google to find relevant information while performing analysis.
Glitching STM32 Read Out Protection - Anvil Secure
https://ift.tt/ThtL7yX
Submitted April 23, 2025 at 12:16AM by tlxio
via reddit https://ift.tt/BRuaiNW
https://ift.tt/ThtL7yX
Submitted April 23, 2025 at 12:16AM by tlxio
via reddit https://ift.tt/BRuaiNW
Anvil Secure
Glitching STM32 Read Out Protection - Anvil Secure
Security Engineer Luigi Fragale demonstrates how to glitch the STM32F401 to read protected memory using Python and fault injection.
Local privilege escalation on Zyxel USG FLEX H Series (CVE-2025-1731)
https://ift.tt/H3eFjAI
Submitted April 23, 2025 at 11:07AM by 0xdea
via reddit https://ift.tt/Bz9Heyd
https://ift.tt/H3eFjAI
Submitted April 23, 2025 at 11:07AM by 0xdea
via reddit https://ift.tt/Bz9Heyd
hn security
Local privilege escalation on Zyxel USG FLEX H Series (CVE-2025-1731) - hn security
“So we wait, this is our […]
XRP Supplychain attack: Official NPM package infected with crypto stealing backdoor
https://ift.tt/krtMqYg
Submitted April 22, 2025 at 05:22PM by DebugDucky
via reddit https://ift.tt/FLz3QmT
https://ift.tt/krtMqYg
Submitted April 22, 2025 at 05:22PM by DebugDucky
via reddit https://ift.tt/FLz3QmT
www.aikido.dev
XRP supply chain attack: Official NPM package infected with crypto stealing backdoor
The official XPRL (Ripple) NPM package was compromised by sophisticated attackers who put in a backdoor to steal cryptocurrency private keys and gain access to cryptocurrency wallets.
Authenticated Remote Code Execution on USG FLEX H Series (CVE-2025-1731 / CVE-2025-1732)
https://0xdeadc0de.xyz/blog/cve-2025-1731_cve-2025-1732
Submitted April 24, 2025 at 06:09AM by Advanced_Rough8330
via reddit https://ift.tt/98Gzu5v
https://0xdeadc0de.xyz/blog/cve-2025-1731_cve-2025-1732
Submitted April 24, 2025 at 06:09AM by Advanced_Rough8330
via reddit https://ift.tt/98Gzu5v
0xdeadc0de.xyz
0xdeadc0de Infosec
Fire In The Hole, We’re Breaching The Vault - Commvault Remote Code Execution (CVE-2025-34028) - watchTowr Labs
https://ift.tt/TNhE46Q
Submitted April 24, 2025 at 03:31PM by dx7r__
via reddit https://ift.tt/76sZ0hM
https://ift.tt/TNhE46Q
Submitted April 24, 2025 at 03:31PM by dx7r__
via reddit https://ift.tt/76sZ0hM
watchTowr Labs
Fire In The Hole, We’re Breaching The Vault - Commvault Remote Code Execution (CVE-2025-34028)
As we pack our bags and prepare for the adult-er version of BlackHat (that apparently doesn’t require us to print out stolen mailspoolz to hand to people at their talks), we want to tell you about a recent adventure - a heist, if you will.
No heist story…
No heist story…
GitHub potential leaking of private emails and Hacker One
https://ift.tt/m2C09ep
Submitted April 24, 2025 at 04:01PM by omarous
via reddit https://ift.tt/3hdigmD
https://ift.tt/m2C09ep
Submitted April 24, 2025 at 04:01PM by omarous
via reddit https://ift.tt/3hdigmD
Omar Abid - Personal Blog
GitHub potential leaking of private emails and Hacker One
TBD