Finding Heap Overflows with AFL++ Unicorn Mode
https://ift.tt/dsAqCK3
Submitted May 19, 2025 at 07:13PM by cy1337
via reddit https://ift.tt/eiNFc3w
https://ift.tt/dsAqCK3
Submitted May 19, 2025 at 07:13PM by cy1337
via reddit https://ift.tt/eiNFc3w
Medium
Finding Heap Overflows with AFL++ Unicorn Mode
In my last post, I demonstrated a basic approach to fuzzing an RTOS firmware using AFL++’s Unicorn mode. The provided firmware for that…
New Vulnerabilities in Foscam X5
https://ift.tt/cS2Iaw4
Submitted May 20, 2025 at 05:29PM by SSDisclosure
via reddit https://ift.tt/YqE895D
https://ift.tt/cS2Iaw4
Submitted May 20, 2025 at 05:29PM by SSDisclosure
via reddit https://ift.tt/YqE895D
SSD Secure Disclosure
SSD Advisory - Multiple Foscam X5 Vulnerabilities - SSD Secure Disclosure
Summary Multiple Foscam X5 vulnerabilities have been discovered, the vulnerabilities allow a remote attacker to trigger code execution vulnerabilities in the product. Credit An independent security researcher working with SSD Secure Disclosure. Vendor Response…
How to extract useful info from Microsoft Deployment Toolkit (MDT) Shares on Red Teams
https://ift.tt/Pl0YVQ1
Submitted May 20, 2025 at 07:41PM by oddvarmoe
via reddit https://ift.tt/0GioN7C
https://ift.tt/Pl0YVQ1
Submitted May 20, 2025 at 07:41PM by oddvarmoe
via reddit https://ift.tt/0GioN7C
Varonis' Data Security Report Reveals 99% of Orgs Have Sensitive Information Exposed to AI
https://ift.tt/TAbm9xF
Submitted May 20, 2025 at 07:41PM by Varonis-Dan
via reddit https://ift.tt/FzN3qbo
https://ift.tt/TAbm9xF
Submitted May 20, 2025 at 07:41PM by Varonis-Dan
via reddit https://ift.tt/FzN3qbo
Varonis
Data Security Report Reveals 99% of Orgs Have Sensitive Information Exposed to AI
Varonis' 2025 State of Data Security Report shares findings from 1,000 real-world IT environments to uncover the dark side of the AI boom and what proactive steps orgs can take to secure critical information.
Malvertising's New Threat: Exploiting Trusted Google Domains
https://ift.tt/ReC2Wjz
Submitted May 21, 2025 at 02:41AM by moriya_pedael
via reddit https://ift.tt/flnjLNw
https://ift.tt/ReC2Wjz
Submitted May 21, 2025 at 02:41AM by moriya_pedael
via reddit https://ift.tt/flnjLNw
GeoEdge
Malvertising's New Threat: Exploiting Trusted Google Domains
A new malvertising scheme is turning legitimate e-commerce sites into phishing traps without the knowledge of site owners or advertisers. By exploiting the integrations with Google APIs, they are injecting malicious noscripts into ecommerce sites using JSONP…
Humans are Insecure Password Generators
https://ift.tt/rD18fjh
Submitted May 21, 2025 at 11:32AM by KingSupernova
via reddit https://ift.tt/mohHxXr
https://ift.tt/rD18fjh
Submitted May 21, 2025 at 11:32AM by KingSupernova
via reddit https://ift.tt/mohHxXr
outsidetheasylum.blog
Humans are Insecure Password Generators
EvilWorker: a new AiTM attack framework leveraging service workers — much more effective, autonomous, and adaptable than Evilginx2? 🎣
https://ift.tt/ot2VNQh
Submitted May 21, 2025 at 03:11PM by Sufficient-Ad8324
via reddit https://ift.tt/n16oPyi
https://ift.tt/ot2VNQh
Submitted May 21, 2025 at 03:11PM by Sufficient-Ad8324
via reddit https://ift.tt/n16oPyi
Medium
EvilWorker: a new AiTM attack framework based on leveraging service workers
EvilWorker is a new AiTM attack framework designed to conduct credential phishing campaigns.
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
https://ift.tt/Zs8SIBq
Submitted May 21, 2025 at 09:30PM by thewhippersnapper4
via reddit https://ift.tt/5kt7Q9f
https://ift.tt/Zs8SIBq
Submitted May 21, 2025 at 09:30PM by thewhippersnapper4
via reddit https://ift.tt/5kt7Q9f
Akamai
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
Akamai researchers found a privilege escalation vulnerability in Windows Server 2025 that allows attackers to compromise any user in Active Directory.
CVE-2025-26147: Authenticated RCE In Denodo Scheduler
https://ift.tt/6gm34VC
Submitted May 21, 2025 at 10:56PM by hackers_and_builders
via reddit https://ift.tt/hunBQHD
https://ift.tt/6gm34VC
Submitted May 21, 2025 at 10:56PM by hackers_and_builders
via reddit https://ift.tt/hunBQHD
Rhino Security Labs
CVE-2025-26147: Authenticated RCE In Denodo Scheduler
Rhino Security Labs found CVE-2025-26147 in Denodo Scheduler, an application administrators use to configure servers, databases, and specify forms of authentication.
CVE-2024-45332 brings back branch target injection attacks on Intel
https://ift.tt/rHvouAV
Submitted May 22, 2025 at 04:45AM by monster4210
via reddit https://ift.tt/qDM2o6m
https://ift.tt/rHvouAV
Submitted May 22, 2025 at 04:45AM by monster4210
via reddit https://ift.tt/qDM2o6m
How to Enumerate and Exploit CefSharp Thick Clients Using CefEnum
https://ift.tt/5t7OCnF
Submitted May 22, 2025 at 12:53PM by Moopanger
via reddit https://ift.tt/uei7YSF
https://ift.tt/5t7OCnF
Submitted May 22, 2025 at 12:53PM by Moopanger
via reddit https://ift.tt/uei7YSF
Authenticated Remote Code Execution in Netwrix Password Secure (CVE-2025-26817)
https://ift.tt/FhgbO6V
Submitted May 22, 2025 at 01:39PM by k8pf
via reddit https://ift.tt/9yCZH3d
https://ift.tt/FhgbO6V
Submitted May 22, 2025 at 01:39PM by k8pf
via reddit https://ift.tt/9yCZH3d
www.8com.de
cve-2025-26817 netwrix rce
Authenticated Remote Code Execution Vulnerability in Netwrix Password Secure
Automating MS-RPC vulnerability research
https://ift.tt/TLiqk2D
Submitted May 22, 2025 at 05:42PM by TangeloPublic9554
via reddit https://ift.tt/4n3VtdH
https://ift.tt/TLiqk2D
Submitted May 22, 2025 at 05:42PM by TangeloPublic9554
via reddit https://ift.tt/4n3VtdH
Incendium.rocks
Automating MS-RPC vulnerability research
Diving into the MS-RPC protocol and how to automate vulnerability research using a fuzzing approach.
Rare Code Base is a free and open-source learning platform for ethical hacking, programming, and more.
https://ift.tt/bPJaVHK
Submitted May 22, 2025 at 08:39PM by Hello_World_00001
via reddit https://ift.tt/8WOgS5c
https://ift.tt/bPJaVHK
Submitted May 22, 2025 at 08:39PM by Hello_World_00001
via reddit https://ift.tt/8WOgS5c
Rarecodebase
Rare Code Base
Rare Code Base offers free ethical hacking, programming tutorials, cybersecurity insights, and much more. Access expert resources to learn coding, master ethical hacking, explore tech trends, and stay ahead in the ever-evolving world of technology.
Live Forensic Collection from Ivanti EPMM Appliances (CVE-2025-4427 & CVE-2025-4428)
https://ift.tt/CaOTDPp
Submitted May 22, 2025 at 09:32PM by GelosSnake
via reddit https://ift.tt/WMCr4Uj
https://ift.tt/CaOTDPp
Submitted May 22, 2025 at 09:32PM by GelosSnake
via reddit https://ift.tt/WMCr4Uj
profero.io
Live Forensic Collection from Ivanti EPMM Appliances (CVE-2025-4427 & CVE-2025-4428)
Two newly discovered vulnerabilities (CVE-2025-4427 CVE-2025-4428) in Ivanti Endpoint Mobile Manager are being actively exploited leading to severe data breach
CVE-2025-32756: Write-Up of a Buffer Overflow in Various Fortinet Products
https://ift.tt/W1LnpBr
Submitted May 23, 2025 at 01:15AM by dinobyt3s
via reddit https://ift.tt/Zw0C9tu
https://ift.tt/W1LnpBr
Submitted May 23, 2025 at 01:15AM by dinobyt3s
via reddit https://ift.tt/Zw0C9tu
Horizon3.ai
CVE-2025-32756: Fortinet RCE Exploited in the Wild
Analyze CVE-2025-32756, a Fortinet buffer overflow flaw under active attack, and see how NodeZero can validate exposure now.
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE
https://ift.tt/9Wbmite
Submitted May 23, 2025 at 07:02PM by eg1x
via reddit https://ift.tt/NrPY8Jz
https://ift.tt/9Wbmite
Submitted May 23, 2025 at 07:02PM by eg1x
via reddit https://ift.tt/NrPY8Jz
Karmainsecurity
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
BadUSB Attack Explained: From Principles to Practice and Defense
https://ift.tt/zacHWpv
Submitted May 25, 2025 at 10:48AM by repoog
via reddit https://ift.tt/ucngTDR
https://ift.tt/zacHWpv
Submitted May 25, 2025 at 10:48AM by repoog
via reddit https://ift.tt/ucngTDR
Medium
BadUSB Attack Explained: From Principles to Practice and Defense
Discover how to implement it with Arduino UNO, and what security measures can protect your system.
Threat of TCC Bypasses on macOS
https://ift.tt/qKYiTRu
Submitted May 26, 2025 at 03:54PM by bajk
via reddit https://ift.tt/RhWPDoq
https://ift.tt/qKYiTRu
Submitted May 26, 2025 at 03:54PM by bajk
via reddit https://ift.tt/RhWPDoq
AFINE - digitally secure
Threat of TCC Bypasses on macOS - AFINE - digitally secure
TCC on macOS isn't just an annoying prompt—it's the last line of defense between malware and your private data. Read this article to learn why.
Unauthenticated RCE on Smartbedded MeteoBridge (CVE-2025-4008)
https://ift.tt/olfCpLW
Submitted May 26, 2025 at 06:30PM by g_e_r_h_a_r_d
via reddit https://ift.tt/fCRd6yS
https://ift.tt/olfCpLW
Submitted May 26, 2025 at 06:30PM by g_e_r_h_a_r_d
via reddit https://ift.tt/fCRd6yS
Onekey
Security Advisory: Remote Command Execution on Smartbedded MeteoBridge (CVE-2025-4008) | ONEKEY Research | Research | ONEKEY
Explore ONEKEY Research Lab's security advisory detailing a critical vulnerability in Smartbedded MeteoBridge. Learn about the risks and recommended actions.
Firefox Security Response to pwn2own 2025
https://ift.tt/FJf2w0k
Submitted May 27, 2025 at 12:20PM by mozfreddyb
via reddit https://ift.tt/A6Yu4lT
https://ift.tt/FJf2w0k
Submitted May 27, 2025 at 12:20PM by mozfreddyb
via reddit https://ift.tt/A6Yu4lT
Mozilla Security Blog
Firefox Security Response to pwn2own 2025
At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...