VM somenoe with exp
https://ift.tt/AwYvRQO
Submitted May 19, 2025 at 01:31AM by silentshadovvvvvv
via reddit https://ift.tt/0urk7H2
https://ift.tt/AwYvRQO
Submitted May 19, 2025 at 01:31AM by silentshadovvvvvv
via reddit https://ift.tt/0urk7H2
O2 VoLTE: locating any customer with a phone call
https://ift.tt/KZjf2Us
Submitted May 19, 2025 at 02:07AM by ChingDat
via reddit https://ift.tt/owT2BFL
https://ift.tt/KZjf2Us
Submitted May 19, 2025 at 02:07AM by ChingDat
via reddit https://ift.tt/owT2BFL
mastdatabase.co.uk
O2 VoLTE: locating any customer with a phone call
Privacy is dead: For multiple months, any O2 customer has had their location exposed to call initiators without their knowledge.
Apple downplays framework vuln
https://ift.tt/ydK52FG
Submitted May 19, 2025 at 03:57AM by dreadscandal
via reddit https://ift.tt/VJUvnH4
https://ift.tt/ydK52FG
Submitted May 19, 2025 at 03:57AM by dreadscandal
via reddit https://ift.tt/VJUvnH4
Apple Security Research
Hear about the latest advances in Apple security from our engineering teams, send us your own research, and work directly with us to be recognized and rewarded for helping keep our users safe.
Introducing EntraFalcon – A Tool to Enumerate Entra ID Objects and Assignments
https://ift.tt/KyI96eM
Submitted May 19, 2025 at 11:43AM by GonzoZH
via reddit https://ift.tt/e6yblPu
https://ift.tt/KyI96eM
Submitted May 19, 2025 at 11:43AM by GonzoZH
via reddit https://ift.tt/e6yblPu
Cache poisoning via race-condition in Next.js
https://ift.tt/B1rp9jO
Submitted May 19, 2025 at 01:25PM by albinowax
via reddit https://ift.tt/X0O7oPt
https://ift.tt/B1rp9jO
Submitted May 19, 2025 at 01:25PM by albinowax
via reddit https://ift.tt/X0O7oPt
zhero_web_security
Eclipse on Next.js: Conditioned exploitation of an intended race-condition
CVE-2025-32421
Finding Heap Overflows with AFL++ Unicorn Mode
https://ift.tt/dsAqCK3
Submitted May 19, 2025 at 07:13PM by cy1337
via reddit https://ift.tt/eiNFc3w
https://ift.tt/dsAqCK3
Submitted May 19, 2025 at 07:13PM by cy1337
via reddit https://ift.tt/eiNFc3w
Medium
Finding Heap Overflows with AFL++ Unicorn Mode
In my last post, I demonstrated a basic approach to fuzzing an RTOS firmware using AFL++’s Unicorn mode. The provided firmware for that…
New Vulnerabilities in Foscam X5
https://ift.tt/cS2Iaw4
Submitted May 20, 2025 at 05:29PM by SSDisclosure
via reddit https://ift.tt/YqE895D
https://ift.tt/cS2Iaw4
Submitted May 20, 2025 at 05:29PM by SSDisclosure
via reddit https://ift.tt/YqE895D
SSD Secure Disclosure
SSD Advisory - Multiple Foscam X5 Vulnerabilities - SSD Secure Disclosure
Summary Multiple Foscam X5 vulnerabilities have been discovered, the vulnerabilities allow a remote attacker to trigger code execution vulnerabilities in the product. Credit An independent security researcher working with SSD Secure Disclosure. Vendor Response…
How to extract useful info from Microsoft Deployment Toolkit (MDT) Shares on Red Teams
https://ift.tt/Pl0YVQ1
Submitted May 20, 2025 at 07:41PM by oddvarmoe
via reddit https://ift.tt/0GioN7C
https://ift.tt/Pl0YVQ1
Submitted May 20, 2025 at 07:41PM by oddvarmoe
via reddit https://ift.tt/0GioN7C
Varonis' Data Security Report Reveals 99% of Orgs Have Sensitive Information Exposed to AI
https://ift.tt/TAbm9xF
Submitted May 20, 2025 at 07:41PM by Varonis-Dan
via reddit https://ift.tt/FzN3qbo
https://ift.tt/TAbm9xF
Submitted May 20, 2025 at 07:41PM by Varonis-Dan
via reddit https://ift.tt/FzN3qbo
Varonis
Data Security Report Reveals 99% of Orgs Have Sensitive Information Exposed to AI
Varonis' 2025 State of Data Security Report shares findings from 1,000 real-world IT environments to uncover the dark side of the AI boom and what proactive steps orgs can take to secure critical information.
Malvertising's New Threat: Exploiting Trusted Google Domains
https://ift.tt/ReC2Wjz
Submitted May 21, 2025 at 02:41AM by moriya_pedael
via reddit https://ift.tt/flnjLNw
https://ift.tt/ReC2Wjz
Submitted May 21, 2025 at 02:41AM by moriya_pedael
via reddit https://ift.tt/flnjLNw
GeoEdge
Malvertising's New Threat: Exploiting Trusted Google Domains
A new malvertising scheme is turning legitimate e-commerce sites into phishing traps without the knowledge of site owners or advertisers. By exploiting the integrations with Google APIs, they are injecting malicious noscripts into ecommerce sites using JSONP…
Humans are Insecure Password Generators
https://ift.tt/rD18fjh
Submitted May 21, 2025 at 11:32AM by KingSupernova
via reddit https://ift.tt/mohHxXr
https://ift.tt/rD18fjh
Submitted May 21, 2025 at 11:32AM by KingSupernova
via reddit https://ift.tt/mohHxXr
outsidetheasylum.blog
Humans are Insecure Password Generators
EvilWorker: a new AiTM attack framework leveraging service workers — much more effective, autonomous, and adaptable than Evilginx2? 🎣
https://ift.tt/ot2VNQh
Submitted May 21, 2025 at 03:11PM by Sufficient-Ad8324
via reddit https://ift.tt/n16oPyi
https://ift.tt/ot2VNQh
Submitted May 21, 2025 at 03:11PM by Sufficient-Ad8324
via reddit https://ift.tt/n16oPyi
Medium
EvilWorker: a new AiTM attack framework based on leveraging service workers
EvilWorker is a new AiTM attack framework designed to conduct credential phishing campaigns.
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
https://ift.tt/Zs8SIBq
Submitted May 21, 2025 at 09:30PM by thewhippersnapper4
via reddit https://ift.tt/5kt7Q9f
https://ift.tt/Zs8SIBq
Submitted May 21, 2025 at 09:30PM by thewhippersnapper4
via reddit https://ift.tt/5kt7Q9f
Akamai
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
Akamai researchers found a privilege escalation vulnerability in Windows Server 2025 that allows attackers to compromise any user in Active Directory.
CVE-2025-26147: Authenticated RCE In Denodo Scheduler
https://ift.tt/6gm34VC
Submitted May 21, 2025 at 10:56PM by hackers_and_builders
via reddit https://ift.tt/hunBQHD
https://ift.tt/6gm34VC
Submitted May 21, 2025 at 10:56PM by hackers_and_builders
via reddit https://ift.tt/hunBQHD
Rhino Security Labs
CVE-2025-26147: Authenticated RCE In Denodo Scheduler
Rhino Security Labs found CVE-2025-26147 in Denodo Scheduler, an application administrators use to configure servers, databases, and specify forms of authentication.
CVE-2024-45332 brings back branch target injection attacks on Intel
https://ift.tt/rHvouAV
Submitted May 22, 2025 at 04:45AM by monster4210
via reddit https://ift.tt/qDM2o6m
https://ift.tt/rHvouAV
Submitted May 22, 2025 at 04:45AM by monster4210
via reddit https://ift.tt/qDM2o6m
How to Enumerate and Exploit CefSharp Thick Clients Using CefEnum
https://ift.tt/5t7OCnF
Submitted May 22, 2025 at 12:53PM by Moopanger
via reddit https://ift.tt/uei7YSF
https://ift.tt/5t7OCnF
Submitted May 22, 2025 at 12:53PM by Moopanger
via reddit https://ift.tt/uei7YSF
Authenticated Remote Code Execution in Netwrix Password Secure (CVE-2025-26817)
https://ift.tt/FhgbO6V
Submitted May 22, 2025 at 01:39PM by k8pf
via reddit https://ift.tt/9yCZH3d
https://ift.tt/FhgbO6V
Submitted May 22, 2025 at 01:39PM by k8pf
via reddit https://ift.tt/9yCZH3d
www.8com.de
cve-2025-26817 netwrix rce
Authenticated Remote Code Execution Vulnerability in Netwrix Password Secure
Automating MS-RPC vulnerability research
https://ift.tt/TLiqk2D
Submitted May 22, 2025 at 05:42PM by TangeloPublic9554
via reddit https://ift.tt/4n3VtdH
https://ift.tt/TLiqk2D
Submitted May 22, 2025 at 05:42PM by TangeloPublic9554
via reddit https://ift.tt/4n3VtdH
Incendium.rocks
Automating MS-RPC vulnerability research
Diving into the MS-RPC protocol and how to automate vulnerability research using a fuzzing approach.
Rare Code Base is a free and open-source learning platform for ethical hacking, programming, and more.
https://ift.tt/bPJaVHK
Submitted May 22, 2025 at 08:39PM by Hello_World_00001
via reddit https://ift.tt/8WOgS5c
https://ift.tt/bPJaVHK
Submitted May 22, 2025 at 08:39PM by Hello_World_00001
via reddit https://ift.tt/8WOgS5c
Rarecodebase
Rare Code Base
Rare Code Base offers free ethical hacking, programming tutorials, cybersecurity insights, and much more. Access expert resources to learn coding, master ethical hacking, explore tech trends, and stay ahead in the ever-evolving world of technology.
Live Forensic Collection from Ivanti EPMM Appliances (CVE-2025-4427 & CVE-2025-4428)
https://ift.tt/CaOTDPp
Submitted May 22, 2025 at 09:32PM by GelosSnake
via reddit https://ift.tt/WMCr4Uj
https://ift.tt/CaOTDPp
Submitted May 22, 2025 at 09:32PM by GelosSnake
via reddit https://ift.tt/WMCr4Uj
profero.io
Live Forensic Collection from Ivanti EPMM Appliances (CVE-2025-4427 & CVE-2025-4428)
Two newly discovered vulnerabilities (CVE-2025-4427 CVE-2025-4428) in Ivanti Endpoint Mobile Manager are being actively exploited leading to severe data breach
CVE-2025-32756: Write-Up of a Buffer Overflow in Various Fortinet Products
https://ift.tt/W1LnpBr
Submitted May 23, 2025 at 01:15AM by dinobyt3s
via reddit https://ift.tt/Zw0C9tu
https://ift.tt/W1LnpBr
Submitted May 23, 2025 at 01:15AM by dinobyt3s
via reddit https://ift.tt/Zw0C9tu
Horizon3.ai
CVE-2025-32756: Fortinet RCE Exploited in the Wild
Analyze CVE-2025-32756, a Fortinet buffer overflow flaw under active attack, and see how NodeZero can validate exposure now.