Bruteforcing the phone number of any Google user
https://ift.tt/Wl0jKMv
Submitted June 10, 2025 at 01:08AM by _vavkamil_
via reddit https://ift.tt/ULmfpZa
https://ift.tt/Wl0jKMv
Submitted June 10, 2025 at 01:08AM by _vavkamil_
via reddit https://ift.tt/ULmfpZa
brutecat.com
Bruteforcing the phone number of any Google user
From rate limits to no limits: How IPv6's massive address space and a crafty botguard bypass left every Google user's phone number vulnerable
Why Open Source ≠ Secure Code
https://ift.tt/CWbic4j
Submitted June 10, 2025 at 03:29PM by kobsoN
via reddit https://ift.tt/zuqCdhr
https://ift.tt/CWbic4j
Submitted June 10, 2025 at 03:29PM by kobsoN
via reddit https://ift.tt/zuqCdhr
New ISPConfig Authenticated Remote Code Execution Vulnerability
https://ift.tt/0CiHfBy
Submitted June 10, 2025 at 04:28PM by SSDisclosure
via reddit https://ift.tt/jMfE5K3
https://ift.tt/0CiHfBy
Submitted June 10, 2025 at 04:28PM by SSDisclosure
via reddit https://ift.tt/jMfE5K3
SSD Secure Disclosure
SSD Advisory - ISPConfig Authenticated Remote Code Execution - SSD Secure Disclosure
Summary The analysis conducted on the product: ISPConfig version: 3.2 build: 12p1 was carried out using the official installation package. The analysis identified primarily design flaws in the user creation/edit functionality, which allow a client user to…
CVE-2025-47934 - Spoofing OpenPGP.js signature verification
https://ift.tt/h6ZlTMc
Submitted June 10, 2025 at 07:21PM by ThomasRinsma
via reddit https://ift.tt/pw0feqU
https://ift.tt/h6ZlTMc
Submitted June 10, 2025 at 07:21PM by ThomasRinsma
via reddit https://ift.tt/pw0feqU
codeanlabs
CVE-2025-47934 - Spoofing OpenPGP.js signature verification - Codean Labs
CVE-2025-47934 allows attackers to spoof arbitrary signatures and encrypted emails that appear as valid in OpenPGP.js. The only requirement is access to a single valid signed message from the target author ("Alice"). Since this undermines the core principle…
Feedback - new secure doc sharing platform GetSafeDocs.com
https://getsafedocs.com
Submitted June 10, 2025 at 10:05PM by New-Arrival414
via reddit https://ift.tt/7VOKM8d
https://getsafedocs.com
Submitted June 10, 2025 at 10:05PM by New-Arrival414
via reddit https://ift.tt/7VOKM8d
Reddit
From the netsec community on Reddit: [ Removed by moderator ]
Posted by New-Arrival414 - 3 votes and 0 comments
Code execution from web browser using URL schemes handled by KDE's KTelnetService and Konsole (CVE-2025-49091)
https://ift.tt/NzDGwbj
Submitted June 10, 2025 at 11:16PM by 11d_space
via reddit https://ift.tt/8TOLjuW
https://ift.tt/NzDGwbj
Submitted June 10, 2025 at 11:16PM by 11d_space
via reddit https://ift.tt/8TOLjuW
proofnet.de
proofnet - Code execution from web browser using URL schemes handled by KDE's KTelnetService and Konsole (CVE-2025-49091)
proofnet ist spezialisiert auf Security PenTests im Connected Car Umfeld.
Research On Developing Secure AI Agents Using Google's A2A Protocol
https://ift.tt/90OpsLC
Submitted June 11, 2025 at 12:21AM by Artistic_Bee_2117
via reddit https://ift.tt/9WQogy8
https://ift.tt/90OpsLC
Submitted June 11, 2025 at 12:21AM by Artistic_Bee_2117
via reddit https://ift.tt/9WQogy8
Salesforce Industry Cloud(s) Security Whitepaper: 5 CVEs, 15+ Security Risks
https://ift.tt/U6pWNql
Submitted June 11, 2025 at 02:13AM by dantalion4040
via reddit https://ift.tt/aouL1wf
https://ift.tt/U6pWNql
Submitted June 11, 2025 at 02:13AM by dantalion4040
via reddit https://ift.tt/aouL1wf
AppOmni
Low-Code, High Stakes: Why Security Can’t Be an Afterthought for Customers Using Salesforce Industry Clouds
New research reveals critical security flaws in Salesforce Industry Cloud. Discover the risks and how to protect your organization now.
How to Setup Kali Linux on Docker + Create Custom Image & File Share
https://ift.tt/jZao1z3
Submitted June 11, 2025 at 09:43AM by kongwenbin
via reddit https://ift.tt/tLIe2zX
https://ift.tt/jZao1z3
Submitted June 11, 2025 at 09:43AM by kongwenbin
via reddit https://ift.tt/tLIe2zX
My Learning Journey
How to Setup Kali Linux on Docker + Create Custom Image & File Share
Learn how to set up Kali Linux on Docker with a custom image and file sharing. Great for bug bounty beginners and ethical hackers.
Best Open Source Security Tools in 2025
https://ift.tt/QJw5Pxb
Submitted June 11, 2025 at 10:58AM by mendy_06
via reddit https://ift.tt/UB7fWVz
https://ift.tt/QJw5Pxb
Submitted June 11, 2025 at 10:58AM by mendy_06
via reddit https://ift.tt/UB7fWVz
Medium
Best Open Source Security Tools in 2025
As security teams scale and diversify, open-source tools remain essential — whether for detection, response, threat intel, or automation…
CVE-2025-33073: A Look in the Mirror - The Reflective Kerberos Relay Attack
https://ift.tt/b2MYNjF
Submitted June 11, 2025 at 01:40PM by RedTeamPentesting
via reddit https://ift.tt/XPJVmyN
https://ift.tt/b2MYNjF
Submitted June 11, 2025 at 01:40PM by RedTeamPentesting
via reddit https://ift.tt/XPJVmyN
RedTeam Pentesting - Blog
A Look in the Mirror - The Reflective Kerberos Relay Attack
It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While researching relay attacks, the bane of Active …
Les comptes machines dans Active Directory
https://ift.tt/t14nASR
Submitted June 11, 2025 at 06:35PM by MobetaSec
via reddit https://ift.tt/jZ9nkCS
https://ift.tt/t14nASR
Submitted June 11, 2025 at 06:35PM by MobetaSec
via reddit https://ift.tt/jZ9nkCS
Mobeta
Les comptes machines dans Active Directory | Mobeta
Découvrez le rôle des comptes machines dans Active Directory en pentest et les attaques possibles (Shadow Credentials, RBCD, Silver Ticket).
Weaponized Google OAuth Triggers Malicious WebSocket
https://ift.tt/dhsqVPX
Submitted June 11, 2025 at 07:03PM by unknownhad
via reddit https://ift.tt/PXlbqQ8
https://ift.tt/dhsqVPX
Submitted June 11, 2025 at 07:03PM by unknownhad
via reddit https://ift.tt/PXlbqQ8
cside
Weaponized Google OAuth Triggers Malicious WebSocket
An attacker is using ‘Google.com’ to deliver and execute their own code in a weaponized Google OAuth attack.
Getting RCE on Monero forums with wrapwrap
https://ift.tt/vNrP4uK
Submitted June 11, 2025 at 06:46PM by AlmondOffSec
via reddit https://ift.tt/P1IH3cj
https://ift.tt/vNrP4uK
Submitted June 11, 2025 at 06:46PM by AlmondOffSec
via reddit https://ift.tt/P1IH3cj
swap.gs
Getting RCE on Monero forums with wrapwrap
breakpoint of no return
Stryker - Android pentesting app with premium access is now free until 2050
https://ift.tt/DusPUJW
Submitted June 12, 2025 at 03:18PM by barakadua131
via reddit https://ift.tt/hOzV5Ms
https://ift.tt/DusPUJW
Submitted June 12, 2025 at 03:18PM by barakadua131
via reddit https://ift.tt/hOzV5Ms
Mobile Hacker
Stryker App Goes Free: The Ultimate Mobile Pentesting Toolkit
Stryker is a powerful mobile app that transforms your Android device into a pentesting workspace. Designed to help you test networks and devices for common vulnerabilities without requiring specialized skills or extensive knowledge
Meta is able to track it’s users via WebRTC on Android including private mode and behind VPN
https://ift.tt/zkYTVmJ
Submitted June 12, 2025 at 05:45PM by dvrkcat
via reddit https://ift.tt/HmC932G
https://ift.tt/zkYTVmJ
Submitted June 12, 2025 at 05:45PM by dvrkcat
via reddit https://ift.tt/HmC932G
www.zeropartydata.es
“Localhost tracking” explained. It could cost Meta 32 billion.
You just can't finish off Zuckerberg.
Millions of Vulnerabilities: One Checklist to Kill The Noise
https://ift.tt/N56AUmr
Submitted June 12, 2025 at 08:56PM by pathetiq
via reddit https://ift.tt/W4OVnmB
https://ift.tt/N56AUmr
Submitted June 12, 2025 at 08:56PM by pathetiq
via reddit https://ift.tt/W4OVnmB
Security Autopsy
Millions of Vulnerabilities: One Checklist to Kill The Noise
One important subject to discuss when talking about vulnerability management is the day you open the valve on a code scanning tool that generates an enormous number of security findings. This has been a problem in information security since the early 2000s…
Introducing: GitHub Device Code Phishing
https://ift.tt/sHlh2QV
Submitted June 12, 2025 at 09:50PM by IrohsLotusTile
via reddit https://ift.tt/AIPD215
https://ift.tt/sHlh2QV
Submitted June 12, 2025 at 09:50PM by IrohsLotusTile
via reddit https://ift.tt/AIPD215
Praetorian
Introducing: GitHub Device Code Phishing
GitHub Device Code phishing: A new attack vector targeting developers. Learn how attackers abuse OAuth flows to compromise organizations and steal source code.
Influencing LLM Output using logprobs and Token Distribution
https://ift.tt/TAIluQK
Submitted June 12, 2025 at 11:46PM by theMiddleBlue
via reddit https://ift.tt/rPKZfAp
https://ift.tt/TAIluQK
Submitted June 12, 2025 at 11:46PM by theMiddleBlue
via reddit https://ift.tt/rPKZfAp
Sicuranext Blog
Influencing LLM Output using logprobs and Token Distribution
What if you could influence an LLM's output not by breaking its rules, but by bending its probabilities? In this deep-dive, we explore how small changes in user input (down to a single token) can shift the balance between “true” and “false”, triggering radically…
Batteries included collaborative knowledge management solution for threat intelligence researchers
https://cradle.sh/
Submitted June 13, 2025 at 10:31PM by small_talk101
via reddit https://ift.tt/yNSDIiR
https://cradle.sh/
Submitted June 13, 2025 at 10:31PM by small_talk101
via reddit https://ift.tt/yNSDIiR
cradle.sh
CRADLE Intelligence Hub
Latest version: v2.10.0 CRADLE Intelligence Hub Batteries included collaborative knowledge management solution for threat intelligence researchers.
Giving an LLM Command Line Access to Nmap
https://ift.tt/Wu1J6w8
Submitted June 14, 2025 at 03:49AM by thewanderer1999
via reddit https://ift.tt/DJP1KLH
https://ift.tt/Wu1J6w8
Submitted June 14, 2025 at 03:49AM by thewanderer1999
via reddit https://ift.tt/DJP1KLH
HackerTarget.com
Giving an LLM Command Line Access to Nmap | HackerTarget.com
What would it look like giving LLM's command line access to Nmap. Explore the possibilities in the security tools space.