Vulnerabilities Found in Preinstalled apps on Android Smartphones could perform factory reset of device, exfiltrate PIN code or inject an arbitrary intent with system-level privileges
https://ift.tt/tmiAJf1
Submitted June 02, 2025 at 04:52PM by barakadua131
via reddit https://ift.tt/B4nRqvy
https://ift.tt/tmiAJf1
Submitted June 02, 2025 at 04:52PM by barakadua131
via reddit https://ift.tt/B4nRqvy
Mobile Hacker
Security Issues Found in preinstalled apps on Android Smartphones
Security researchers have uncovered several critical vulnerabilities in applications preloaded on Ulefone and Krüger&Matz Android smartphones. These flaws, reported by CERT Polska and discovered by Szymon Chadam, expose users to significant risks, including…
Seeking Insights from Network Security Leaders at Large Companies on Vendor Selection and Challenges
https://www.zintro.com/
Submitted June 02, 2025 at 07:25PM by brutalgrace
via reddit https://ift.tt/9r2cZwR
https://www.zintro.com/
Submitted June 02, 2025 at 07:25PM by brutalgrace
via reddit https://ift.tt/9r2cZwR
Zintro
Market Research Agency: Expert Network Co & Participant Recruitment
Discover Zintro's experienced market research and expert network. Connect with experts and research participants to inform your reasearch.
Seeking Insights from Network Security Leaders at Large Companies on Vendor Selection and Challenges
https://www.zintro.com/
Submitted June 02, 2025 at 11:20PM by brutalgrace
via reddit https://ift.tt/k0VdRjt
https://www.zintro.com/
Submitted June 02, 2025 at 11:20PM by brutalgrace
via reddit https://ift.tt/k0VdRjt
Zintro
Market Research Agency: Expert Network Co & Participant Recruitment
Discover Zintro's experienced market research and expert network. Connect with experts and research participants to inform your reasearch.
Critical iOS Activation Infrastructure Vulnerability: Unauthenticated Provisioning Injection at Apple’s SIM Activation Endpoint
https://ift.tt/1xVDf03
Submitted June 03, 2025 at 04:46AM by Bright-Dependent2648
via reddit https://ift.tt/IqgTQHG
https://ift.tt/1xVDf03
Submitted June 03, 2025 at 04:46AM by Bright-Dependent2648
via reddit https://ift.tt/IqgTQHG
Substack
iOS Activation Infrastructure: Unauthenticated XML Payload Injection
A backend flaw in Apple’s iOS infrastructure enables stealth provisioning on iPhones before the user ever sees a home screen.
How to build a high-performance network fuzzer with LibAFL and libdesock
https://ift.tt/Bq0eNl5
Submitted June 03, 2025 at 05:20PM by martinclauss
via reddit https://ift.tt/cT2pjWs
https://ift.tt/Bq0eNl5
Submitted June 03, 2025 at 05:20PM by martinclauss
via reddit https://ift.tt/cT2pjWs
lolcads tech blog
How to build a high-performance network fuzzer with LibAFL and libdesock
We explain how we built a fuzzer for network applications that we tried to make as efficient and as effective as possible. We utilized custom mutators and input passing over shared memory and found that it gave us a huge speed and coverage boost compared…
Bypassing tamper protection and getting root shell access on a Worldline Yomani XR credit card terminal
https://ift.tt/bZJxP71
Submitted June 03, 2025 at 08:41PM by Titokhan
via reddit https://ift.tt/nirqdLb
https://ift.tt/bZJxP71
Submitted June 03, 2025 at 08:41PM by Titokhan
via reddit https://ift.tt/nirqdLb
[RFC Draft] Built mathematical solution for PKI's 'impossible' problem. Response time: months→2 hours. IETF interest level: ¯\(ツ)/¯
https://ift.tt/06OIVx5
Submitted June 04, 2025 at 02:08AM by keweonDNS
via reddit https://ift.tt/Ui0EC9N
https://ift.tt/06OIVx5
Submitted June 04, 2025 at 02:08AM by keweonDNS
via reddit https://ift.tt/Ui0EC9N
IETF Datatracker
Root CA Emergency Self-Termination Protocol (RTO-Extension)
This document defines a cryptographically secure mechanism for Root Certificate Authorities to perform emergency self-termination upon compromise detection. Current PKI architecture creates a mathematical impossibility: Root CAs cannot be cryptographically…
The Ultimate Guide to Windows Coercion Techniques in 2025
https://ift.tt/vNcxikJ
Submitted June 04, 2025 at 01:51PM by RedTeamPentesting
via reddit https://ift.tt/q5iYUBJ
https://ift.tt/vNcxikJ
Submitted June 04, 2025 at 01:51PM by RedTeamPentesting
via reddit https://ift.tt/q5iYUBJ
RedTeam Pentesting - Blog
The Ultimate Guide to Windows Coercion Techniques in 2025
Windows authentication coercion often feels like a magic bullet against the average Active Directory. With any old low-privileged account, it usually allows us to gain full administrative access to almost arbitrary Windows workstations and servers, …
So you want to rapidly run a BOF? Let's look at this 'cli4bofs' thing then
https://ift.tt/fxE9Z4j
Submitted June 04, 2025 at 05:15PM by mzet-
via reddit https://ift.tt/QwA13tG
https://ift.tt/fxE9Z4j
Submitted June 04, 2025 at 05:15PM by mzet-
via reddit https://ift.tt/QwA13tG
Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities
https://ift.tt/ypstm7q
Submitted June 04, 2025 at 09:52PM by hackers_and_builders
via reddit https://ift.tt/pS2g7Ch
https://ift.tt/ypstm7q
Submitted June 04, 2025 at 09:52PM by hackers_and_builders
via reddit https://ift.tt/pS2g7Ch
Rhino Security Labs
Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities
While performing research on Infoblox's NetMRI network automation and configuration management solution, we discovered 5 vulnerabilities.
Detailed research for Roundcube ≤ 1.6.10 Post-Auth RCE is out
https://ift.tt/lwBNyJ8
Submitted June 05, 2025 at 07:54AM by xIsis
via reddit https://ift.tt/5oDZxFk
https://ift.tt/lwBNyJ8
Submitted June 05, 2025 at 07:54AM by xIsis
via reddit https://ift.tt/5oDZxFk
fearsoff.org
Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization [CVE-2025-49113]
A deep technical breakdown of CVE-2025-49113, a critical Roundcube vulnerability involving PHP session serialization. Learn how the bug was discovered, exploited, and responsibly disclosed with full PoC and recommendations for defenders and developers. Kirill…
Analysis of Spyware That Helped to Compromise a Syrian Army from Within
https://ift.tt/R0ALECw
Submitted June 05, 2025 at 01:41PM by barakadua131
via reddit https://ift.tt/n6pHbe4
https://ift.tt/R0ALECw
Submitted June 05, 2025 at 01:41PM by barakadua131
via reddit https://ift.tt/n6pHbe4
Mobile Hacker
Analysis of Spyware That Helped to Compromise a Syrian Army from Within
This case demonstrates that effective smartphone espionage doesn't always require expensive zero-day exploits or the development of sophisticated, custom and undetected spyware. Instead, attackers can achieve significant intelligence gains using older, off…
The state of cloud runtime security - 2025 edition
https://ift.tt/dx51KRk
Submitted June 05, 2025 at 05:46PM by Swimming_Version_605
via reddit https://ift.tt/v1NBpUY
https://ift.tt/dx51KRk
Submitted June 05, 2025 at 05:46PM by Swimming_Version_605
via reddit https://ift.tt/v1NBpUY
ARMO
The State of Cloud Runtime Security 2025 - ARMO
Discover key challenges and the path forward. Learn about alert overload, tool sprawl, and the need for unified runtime security solutions.
Vulnerabilities in Anthropic’s MCP: Full-Schema Poisoning + Secret-Leaking Tool Attacks (PoC Inside)
https://ift.tt/idjo0RM
Submitted June 05, 2025 at 09:45PM by jat0369
via reddit https://ift.tt/cD7wpSL
https://ift.tt/idjo0RM
Submitted June 05, 2025 at 09:45PM by jat0369
via reddit https://ift.tt/cD7wpSL
Cyberark
Poison everywhere: No output from your MCP server is safe
The Model Context Protocol (MCP) is an open standard and open-source project from Anthropic that makes it quick and easy for developers to add real-world functionality — like sending emails or...
Tnok - Next Generation Port Security
https://ift.tt/CJrS5YO
Submitted June 05, 2025 at 11:37PM by Glad_Chest934
via reddit https://ift.tt/GNdBh3y
https://ift.tt/CJrS5YO
Submitted June 05, 2025 at 11:37PM by Glad_Chest934
via reddit https://ift.tt/GNdBh3y
Cards Are Still the Weakest Link
https://ift.tt/53lcbOr
Submitted June 06, 2025 at 03:23AM by alexlash
via reddit https://ift.tt/h1wR8Qk
https://ift.tt/53lcbOr
Submitted June 06, 2025 at 03:23AM by alexlash
via reddit https://ift.tt/h1wR8Qk
Substack
Cards Are Still the Weakest Link
Still Using Cards? You’re the Weakest Link in the Payment Chain
DroidGround: Elevate your Android CTF Challenges
https://ift.tt/4Rt7zLn
Submitted June 06, 2025 at 02:35AM by deleee
via reddit https://ift.tt/L4MCTkV
https://ift.tt/4Rt7zLn
Submitted June 06, 2025 at 02:35AM by deleee
via reddit https://ift.tt/L4MCTkV
Medium
DroidGround: Elevate your Android CTF Challenges
Ever felt that Android CTF challenges are too focused on reverse engineering, leaving out the thrill of real-world exploitation? I did too…
Transform Your Old Smartphone into a Pocket Palmtop-style Cyberdeck with Kali NetHunter
https://ift.tt/AyxwgJZ
Submitted June 06, 2025 at 12:14PM by barakadua131
via reddit https://ift.tt/zdL5WwO
https://ift.tt/AyxwgJZ
Submitted June 06, 2025 at 12:14PM by barakadua131
via reddit https://ift.tt/zdL5WwO
Mobile Hacker
Transform Your Old Smartphone into a Pocket Cyberdeck with Kali NetHunter
This setup serves as a convenient alternative to carrying a full-sized laptop or struggling with a smartphone’s virtual keyboard for complex technical tasks. It offers comfortable typing and an efficient portability.
Possible Malware in Official MicroDicom Installer (PDF + Hashes + Scan Results Included)
https://ift.tt/aMELwB3
Submitted June 07, 2025 at 02:14AM by Deeeee737
via reddit https://ift.tt/zj1lFd0
https://ift.tt/aMELwB3
Submitted June 07, 2025 at 02:14AM by Deeeee737
via reddit https://ift.tt/zj1lFd0
GitHub
GitHub - darnas11/MicroDicom-Incident-Report: Analysis of a suspicious binary found in MicroDicom Viewer installer
Analysis of a suspicious binary found in MicroDicom Viewer installer - darnas11/MicroDicom-Incident-Report
Riding The Time Machine: Journey Through An Old vBulletin PHP Object Injection
https://ift.tt/tgfC3Ha
Submitted June 07, 2025 at 07:31PM by eg1x
via reddit https://ift.tt/KSmv2zJ
https://ift.tt/tgfC3Ha
Submitted June 07, 2025 at 07:31PM by eg1x
via reddit https://ift.tt/KSmv2zJ
Karmainsecurity
Riding The Time Machine: Journey Through An Old vBulletin PHP Object Injection | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
HMAS Canberra accidentally blocks wireless internet and radio services in New Zealand
https://ift.tt/z6ecYwC
Submitted June 09, 2025 at 04:27AM by feint_of_heart
via reddit https://ift.tt/ao4mDyF
https://ift.tt/z6ecYwC
Submitted June 09, 2025 at 04:27AM by feint_of_heart
via reddit https://ift.tt/ao4mDyF
RNZ
HMAS Canberra accidentally blocks wireless internet and radio services in New Zealand
It happened earlier this week during a visit intended to celebrate the sister city relationship between Canberra and Wellington.