Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE
https://ift.tt/9Wbmite
Submitted May 23, 2025 at 07:02PM by eg1x
via reddit https://ift.tt/NrPY8Jz
https://ift.tt/9Wbmite
Submitted May 23, 2025 at 07:02PM by eg1x
via reddit https://ift.tt/NrPY8Jz
Karmainsecurity
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
BadUSB Attack Explained: From Principles to Practice and Defense
https://ift.tt/zacHWpv
Submitted May 25, 2025 at 10:48AM by repoog
via reddit https://ift.tt/ucngTDR
https://ift.tt/zacHWpv
Submitted May 25, 2025 at 10:48AM by repoog
via reddit https://ift.tt/ucngTDR
Medium
BadUSB Attack Explained: From Principles to Practice and Defense
Discover how to implement it with Arduino UNO, and what security measures can protect your system.
Threat of TCC Bypasses on macOS
https://ift.tt/qKYiTRu
Submitted May 26, 2025 at 03:54PM by bajk
via reddit https://ift.tt/RhWPDoq
https://ift.tt/qKYiTRu
Submitted May 26, 2025 at 03:54PM by bajk
via reddit https://ift.tt/RhWPDoq
AFINE - digitally secure
Threat of TCC Bypasses on macOS - AFINE - digitally secure
TCC on macOS isn't just an annoying prompt—it's the last line of defense between malware and your private data. Read this article to learn why.
Unauthenticated RCE on Smartbedded MeteoBridge (CVE-2025-4008)
https://ift.tt/olfCpLW
Submitted May 26, 2025 at 06:30PM by g_e_r_h_a_r_d
via reddit https://ift.tt/fCRd6yS
https://ift.tt/olfCpLW
Submitted May 26, 2025 at 06:30PM by g_e_r_h_a_r_d
via reddit https://ift.tt/fCRd6yS
Onekey
Security Advisory: Remote Command Execution on Smartbedded MeteoBridge (CVE-2025-4008) | ONEKEY Research | Research | ONEKEY
Explore ONEKEY Research Lab's security advisory detailing a critical vulnerability in Smartbedded MeteoBridge. Learn about the risks and recommended actions.
Firefox Security Response to pwn2own 2025
https://ift.tt/FJf2w0k
Submitted May 27, 2025 at 12:20PM by mozfreddyb
via reddit https://ift.tt/A6Yu4lT
https://ift.tt/FJf2w0k
Submitted May 27, 2025 at 12:20PM by mozfreddyb
via reddit https://ift.tt/A6Yu4lT
Mozilla Security Blog
Firefox Security Response to pwn2own 2025
At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...
GitHub MCP Exploited: Accessing private repositories via MCP
https://ift.tt/IYUx9M2
Submitted May 27, 2025 at 01:18PM by Proofix
via reddit https://ift.tt/koPM7Bg
https://ift.tt/IYUx9M2
Submitted May 27, 2025 at 01:18PM by Proofix
via reddit https://ift.tt/koPM7Bg
invariantlabs.ai
GitHub MCP Exploited: Accessing private repositories via MCP
We showcase a critical vulnerability with the official GitHub MCP server, allowing attackers to access private repository data. The vulnerability is among the first discovered by Invariant's security analyzer for detecting toxic agent flows.
Top 12 Docker Alternatives in 2025: Features & Comparisons
https://ift.tt/zdxy3Ui
Submitted May 27, 2025 at 01:04PM by sadyetfly11
via reddit https://ift.tt/BISUmxo
https://ift.tt/zdxy3Ui
Submitted May 27, 2025 at 01:04PM by sadyetfly11
via reddit https://ift.tt/BISUmxo
Groundcover
Top 12 Docker Alternatives in 2025: Features & Comparisons
Explore the 12 best Docker alternatives in 2025. Compare tools for container orchestration, image building, runtime security, and resource optimization.
New graph capabilities and MCP server for CTI / OSINT analysis
https://ift.tt/BukHYC6
Submitted May 27, 2025 at 03:25PM by stan_frbd
via reddit https://ift.tt/09BkxGq
https://ift.tt/BukHYC6
Submitted May 27, 2025 at 03:25PM by stan_frbd
via reddit https://ift.tt/09BkxGq
The Single-Packet Shovel: Digging for Desync-Powered Request Tunnelling
https://ift.tt/cANaUf8
Submitted May 27, 2025 at 06:12PM by t0xodile
via reddit https://ift.tt/BIH36zy
https://ift.tt/cANaUf8
Submitted May 27, 2025 at 06:12PM by t0xodile
via reddit https://ift.tt/BIH36zy
Assured AB
The Single-Packet Shovel: Digging for Desync-Powered Request Tunnelling
In this paper I will reveal the discovery of wide-spread cases of request tunnelling in applications powered by popular servers including IIS, Azure Front Door and AWS' application load balancer including the creation of a novel detection technique that combined…
Have I Been Squatted — Analyze (open beta, free)
https://ift.tt/CdVSjA9
Submitted May 27, 2025 at 06:03PM by JDBHub
via reddit https://ift.tt/LMw2chC
https://ift.tt/CdVSjA9
Submitted May 27, 2025 at 06:03PM by JDBHub
via reddit https://ift.tt/LMw2chC
Haveibeensquatted
Have I Been Squatted? — Check if your domain has been typosquatted
A fast domain and typosquatting discovery tool
Remote Prompt Injection in GitLab Duo Leads to Source Code Theft
https://ift.tt/baT4s0j
Submitted May 27, 2025 at 01:53PM by Proofix
via reddit https://ift.tt/jzoBYy4
https://ift.tt/baT4s0j
Submitted May 27, 2025 at 01:53PM by Proofix
via reddit https://ift.tt/jzoBYy4
Legitsecurity
Remote Prompt Injection in GitLab Duo Leads to Source Code Theft
The Legit research team unearthed vulnerabilities in GitLab Duo.
Remote Code Execution on Evertz SDVN (CVE-2025-4009 - Full Disclosure)
https://ift.tt/J4vfWaG
Submitted May 28, 2025 at 02:42PM by g_e_r_h_a_r_d
via reddit https://ift.tt/jpCZgrS
https://ift.tt/J4vfWaG
Submitted May 28, 2025 at 02:42PM by g_e_r_h_a_r_d
via reddit https://ift.tt/jpCZgrS
Onekey
Security Advisory: Remote Code Execution on Evertz SDVN (CVE-2025-4009) | ONEKEY Research | Research | ONEKEY
Explore ONEKEY Research Lab's security advisory detailing a critical vulnerability in Evertz SDVN. Learn about the risks and recommended actions.
Open-source red teaming for AI, Kubernetes, APIs
https://ift.tt/To5YzDZ
Submitted May 28, 2025 at 06:02PM by whyhatcry
via reddit https://ift.tt/oYtqnFz
https://ift.tt/To5YzDZ
Submitted May 28, 2025 at 06:02PM by whyhatcry
via reddit https://ift.tt/oYtqnFz
Help Net Security
Woodpecker: Open-source red teaming for AI, Kubernetes, APIs
Woodpecker is an open-source tool that automates red teaming, making advanced security testing easier and more accessible. It helps teams find and fix
Decoding TCP SYN for Stronger Network Security
https://ift.tt/HiLfDou
Submitted May 28, 2025 at 07:14PM by jtkchicago
via reddit https://ift.tt/uZ2b4R5
https://ift.tt/HiLfDou
Submitted May 28, 2025 at 07:14PM by jtkchicago
via reddit https://ift.tt/uZ2b4R5
NETSCOUT
Decoding TCP SYN for Stronger Network Security | NETSCOUT
Executive SummaryAnalyzing transmission control protocol (TCP) SYN segments,
The post you couldn’t scan for is back.
https://ift.tt/l5gTBuD
Submitted May 28, 2025 at 11:22PM by CLKnDGGR
via reddit https://ift.tt/HENJ4yl
https://ift.tt/l5gTBuD
Submitted May 28, 2025 at 11:22PM by CLKnDGGR
via reddit https://ift.tt/HENJ4yl
Medium
The Threat You Can’t Scan For: Why I Built Veriduct
How a solo inventor, a storage experiment, and a refusal to accept “encrypted” as good enough led to a new kind of data defense.
How to reverse a game and build a cheat from scratch (External/Internal)
https://ift.tt/ciK8x1m
Submitted May 29, 2025 at 12:16AM by AProudMotherOf4
via reddit https://ift.tt/wCDP7kX
https://ift.tt/ciK8x1m
Submitted May 29, 2025 at 12:16AM by AProudMotherOf4
via reddit https://ift.tt/wCDP7kX
adminions.ca
Part 2 - From Reverse ... | ADMinions
Introduction
In this guide, we’ll walk step-by-step through building a fully functional internal che...
In this guide, we’ll walk step-by-step through building a fully functional internal che...
Pakistan Telecommunication Company (PTCL) Targeted by Bitter APT During Heightened Regional Conflict
https://ift.tt/lzD2NR4
Submitted May 28, 2025 at 11:20PM by Malwarebeasts
via reddit https://ift.tt/5i20cf1
https://ift.tt/lzD2NR4
Submitted May 28, 2025 at 11:20PM by Malwarebeasts
via reddit https://ift.tt/5i20cf1
InfoStealers
Pakistan Telecommunication Company (PTCL) Targeted by Bitter APT During Heightened Regional Conflict
EclecticIQ and Hudson Rock researchers assess that Bitter APT very likely used stolen email credentials from Pakistan’s Counter Terrorism Department (CTD) to carry out the attack. The spear phishing campaign targeted PTCL personnel in critical roles, including…
Deguard: turning a T480 into a coreboot laptop (10-min talk + live demo)
https://ift.tt/0AKnCyQ
Submitted May 29, 2025 at 03:55PM by 3mdeb
via reddit https://ift.tt/eR70ryh
https://ift.tt/0AKnCyQ
Submitted May 29, 2025 at 03:55PM by 3mdeb
via reddit https://ift.tt/eR70ryh
3Mdeb
Introduction to deguard Developers vPub 0xE
This talk will introduce the deguard utility, allowing to bypass Intel BootGuard and enabling coreboot development on previously locked down platforms.
🚀 Introducing XAttacker V50 Pro – Automated Web Exploitation Tool for Penetration Testers
https://ift.tt/LJ984jy
Submitted May 30, 2025 at 05:10AM by Alternative-One212
via reddit https://ift.tt/djbPlrp
https://ift.tt/LJ984jy
Submitted May 30, 2025 at 05:10AM by Alternative-One212
via reddit https://ift.tt/djbPlrp
www.xattackerv50.pro
XAttacker V50 Pro - Automated Web Exploitation Tool
Scan and exploit vulnerable web applications at scale with XAttacker V50 Pro — fast, reliable, and powerful.
Living of the file sharing systems
https://www.lolfs.app/
Submitted May 30, 2025 at 09:37AM by Equivalent-Elk-712
via reddit https://ift.tt/AJWpTlU
https://www.lolfs.app/
Submitted May 30, 2025 at 09:37AM by Equivalent-Elk-712
via reddit https://ift.tt/AJWpTlU
Reddit
From the netsec community on Reddit: [ Removed by moderator ]
Posted by Equivalent-Elk-712 - 8 votes and 2 comments
Questionnaire: Enhancing Edge Computing Security with Blockchain Technology
https://ift.tt/CiWxUKQ
Submitted May 30, 2025 at 12:11PM by Realistic-Sector6793
via reddit https://ift.tt/KvxTqw2
https://ift.tt/CiWxUKQ
Submitted May 30, 2025 at 12:11PM by Realistic-Sector6793
via reddit https://ift.tt/KvxTqw2
Google Docs
Questionnaire: Enhancing Edge Computing Security with Blockchain Technology
This questionnaire is part of a research study examining security vulnerabilities in edge computing environments and exploring Ethereum-based blockchain solutions to address these issues.
Your responses are anonymous and will be used solely for academic research…
Your responses are anonymous and will be used solely for academic research…