Series 2: Implementing the WPA in RAWPA - Part 2
https://ift.tt/KXpEmPu
Submitted June 22, 2025 at 04:47AM by Dark-stash
via reddit https://ift.tt/Rj9wFHV
https://ift.tt/KXpEmPu
Submitted June 22, 2025 at 04:47AM by Dark-stash
via reddit https://ift.tt/Rj9wFHV
Rodney’s Intuition
Series 2: Implementing the WPA in RAWPA - Part 2
What’s up, everyone? I’m back with Part 2 on implementing the Web Penetration Assistant (WPA) logic in RAWPA. Last time, we talked about the initial steps, and now, I’ve got some major updates to share.
Just casually broke bunq’s sandbox with 0day-level spoofing, and nobody seems to care 🇳🇱
https://ift.tt/Eyt1XYi
Submitted June 22, 2025 at 08:12AM by ficu71
via reddit https://ift.tt/WTLc53I
https://ift.tt/Eyt1XYi
Submitted June 22, 2025 at 08:12AM by ficu71
via reddit https://ift.tt/WTLc53I
PrivateBin
Encrypted note on PrivateBin
Visit this link to see the note. Giving the URL to anyone allows them to access the note, too.
RAWPA - hierarchical methodology, comprehensive toolkits, and guided workflows
https://ift.tt/ne1OPi7
Submitted June 23, 2025 at 05:35AM by Dark-stash
via reddit https://ift.tt/jeuVfDa
https://ift.tt/ne1OPi7
Submitted June 23, 2025 at 05:35AM by Dark-stash
via reddit https://ift.tt/jeuVfDa
Novel SSRF Technique Involving HTTP Redirect Loops
https://ift.tt/RwLGbl4
Submitted June 23, 2025 at 04:35PM by Mempodipper
via reddit https://ift.tt/1eV062y
https://ift.tt/RwLGbl4
Submitted June 23, 2025 at 04:35PM by Mempodipper
via reddit https://ift.tt/1eV062y
Searchlight Cyber
Novel SSRF Technique Involving HTTP Redirect Loops › Searchlight Cyber
It's difficult to show impact for Server-Side Request Forgery (SSRF) vulnerabilities when you cannot see the full HTTP response. Our research team details a novel technique that allowed for us to leak the full HTTP response, even though the SSRF seemed like…
What secures LLMs calling APIs via MCP? A stack of OAuth specs—here’s how they fit together
https://ift.tt/tHhIjMZ
Submitted June 23, 2025 at 08:25PM by Smooth-Loquat-4954
via reddit https://ift.tt/qP0TRo6
https://ift.tt/tHhIjMZ
Submitted June 23, 2025 at 08:25PM by Smooth-Loquat-4954
via reddit https://ift.tt/qP0TRo6
Workos
MCP Authorization in 5 easy OAuth specs — WorkOS
Behind every secure MCP integration is a stack of OAuth standards working in harmony. Learn how they combine to deliver seamless authorization for LLMs.
haveibeenpwned.watch - Open-source, no-fluff charts showcasing haveibeenpwned.com's pwned account data
https://ift.tt/96QWORj
Submitted June 23, 2025 at 09:29PM by iosifache
via reddit https://ift.tt/BPl7C6j
https://ift.tt/96QWORj
Submitted June 23, 2025 at 09:29PM by iosifache
via reddit https://ift.tt/BPl7C6j
Threat Hunting Introduction: Cobalt Strike
https://ift.tt/vUo4dT8
Submitted June 23, 2025 at 10:13PM by rushter_
via reddit https://ift.tt/qQlNhge
https://ift.tt/vUo4dT8
Submitted June 23, 2025 at 10:13PM by rushter_
via reddit https://ift.tt/qQlNhge
Artem Golubin
Threat Hunting Introduction: Cobalt Strike | Artem Golubin
An introduction to Threat Hunting and Cobalt Strike
Iran's Internet: A Censys Perspective
https://ift.tt/nJPXtwY
Submitted June 24, 2025 at 02:30AM by _Invalid_User_Token_
via reddit https://ift.tt/7GYdi3j
https://ift.tt/nJPXtwY
Submitted June 24, 2025 at 02:30AM by _Invalid_User_Token_
via reddit https://ift.tt/7GYdi3j
Censys
Iran's Internet: A Censys Perspective
Inside Iran’s online landscape, what Censys sees in access, control, and exposure across the country’s internet.
Remote Code Execution on 40,000 WiFi alarm clocks
https://ift.tt/n4sqj57
Submitted June 24, 2025 at 02:09AM by Sw2Bechu
via reddit https://ift.tt/caAbCJs
https://ift.tt/n4sqj57
Submitted June 24, 2025 at 02:09AM by Sw2Bechu
via reddit https://ift.tt/caAbCJs
iank.org
Remote Code Execution on 40,000 WiFi alarm clocks
While looking for an API to use with Home Assistant, I found a remote code execution vulnerability in a popular WiFi-connected alarm clock.
FileFix – New Alternative to ClickFix Attack
https://ift.tt/P8RIGEZ
Submitted June 24, 2025 at 08:13PM by barakadua131
via reddit https://ift.tt/vr0j8Cs
https://ift.tt/P8RIGEZ
Submitted June 24, 2025 at 08:13PM by barakadua131
via reddit https://ift.tt/vr0j8Cs
Mobile Hacker
Introducing FileFix – A New Alternative to ClickFix Attacks
A new browser attack vectors just dropped, and it’s called FileFix — an alternative to the well-known ClickFix attack. This method, discovered and shared by mrd0x, shows how attackers can to execute commands right from browser, without requesting target to…
Remote code execution in CentOS Web Panel - CVE-2025-48703
https://ift.tt/sjryc7b
Submitted June 24, 2025 at 07:34PM by AlmondOffSec
via reddit https://ift.tt/BoAKgL8
https://ift.tt/sjryc7b
Submitted June 24, 2025 at 07:34PM by AlmondOffSec
via reddit https://ift.tt/BoAKgL8
Fenrisk
Remote code execution in CentOS Web Panel - CVE-2025-48703
Security experts
New Kerio Control Advisory!
https://ift.tt/7YEAZGg
Submitted June 24, 2025 at 11:33PM by Straight-Zombie-646
via reddit https://ift.tt/hfxqdQl
https://ift.tt/7YEAZGg
Submitted June 24, 2025 at 11:33PM by Straight-Zombie-646
via reddit https://ift.tt/hfxqdQl
SSD Secure Disclosure
SSD Advisory - Kerio Control Authentication Bypass and RCE - SSD Secure Disclosure
Summary An analysis primarily of Kerio Control revealed a design flaw in the implementation of the communication with GFI AppManager, leading to an authentication bypass vulnerability in the product under audit. Once the authentication bypass is achieved…
TrashTalk.me - A new secure way to chat
https://trashtalk.me
Submitted June 24, 2025 at 11:14PM by merklerkmanitee
via reddit https://ift.tt/i5Xlo8z
https://trashtalk.me
Submitted June 24, 2025 at 11:14PM by merklerkmanitee
via reddit https://ift.tt/i5Xlo8z
Reddit
From the netsec community on Reddit: TrashTalk.me - A new secure way to chat
Posted by merklerkmanitee - 0 votes and 2 comments
Cryptominers’ Anatomy: Shutting Down Mining Botnets
https://ift.tt/LEZo1sJ
Submitted June 24, 2025 at 11:10PM by Narrow_Rooster_630
via reddit https://ift.tt/XOdWbrL
https://ift.tt/LEZo1sJ
Submitted June 24, 2025 at 11:10PM by Narrow_Rooster_630
via reddit https://ift.tt/XOdWbrL
Akamai
Cryptominers’ Anatomy: Shutting Down Mining Botnets | Akamai
In the final installment of Cryptominers’ Anatomy, Akamai researchers analyze cryptominers and reveal a novel technique to shut down mining botnet campaigns.
Security Benchmarking Authorization Policy Engines
https://ift.tt/fXxNqzl
Submitted June 25, 2025 at 02:42PM by nibblesec
via reddit https://ift.tt/gM60OZN
https://ift.tt/fXxNqzl
Submitted June 25, 2025 at 02:42PM by nibblesec
via reddit https://ift.tt/gM60OZN
Goteleport
Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA & Teleport ACD
Explore how the Security Policy Evaluation Framework (SPEF) enables automated, dynamic security benchmarking of leading authorization engines—Rego, Cedar, OpenFGA, and Teleport ACD. Developed by Doyensec with support from Teleport, SPEF tests for vulnerabilities…
Deleting a file in Wire doesn’t remove it from servers — and other findings
https://ift.tt/CcOrZKg
Submitted June 25, 2025 at 03:24PM by AlmondOffSec
via reddit https://ift.tt/4WO3U8e
https://ift.tt/CcOrZKg
Submitted June 25, 2025 at 03:24PM by AlmondOffSec
via reddit https://ift.tt/4WO3U8e
How to Set Up Your Own WireGuard VPN on a VPS (Beginner-Friendly Tutorial)
https://ift.tt/KJXx0uB
Submitted June 25, 2025 at 08:14PM by kongwenbin
via reddit https://ift.tt/zxtuN1Q
https://ift.tt/KJXx0uB
Submitted June 25, 2025 at 08:14PM by kongwenbin
via reddit https://ift.tt/zxtuN1Q
My Learning Journey
How to Set Up Your Own WireGuard VPN on a VPS (Beginner-Friendly Tutorial)
Beginner-friendly Step-by-step guide to setting up a WireGuard VPN on a VPS. Ideal for bug bounty hunters and privacy-focused users.
We built a smart, searchable infosec library indexing 20+ years of resources
https://talkback.sh
Submitted June 26, 2025 at 10:16AM by elttam
via reddit https://ift.tt/enixObw
https://talkback.sh
Submitted June 26, 2025 at 10:16AM by elttam
via reddit https://ift.tt/enixObw
Talkback
Talkback is a smart infosec resource aggregator, designed to help security enthusiasts, practitioners and researchers be more productive.
Read “Windows Registry Manipulation“ by ONESithuation
https://ift.tt/aMdWmFY
Submitted June 26, 2025 at 10:07AM by Johny166xz
via reddit https://ift.tt/hN6L4zV
https://ift.tt/aMdWmFY
Submitted June 26, 2025 at 10:07AM by Johny166xz
via reddit https://ift.tt/hN6L4zV
Medium
Windows Registry Manipulation
Episode 01
Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork - Putting Millions at Risk
https://ift.tt/Tdj6bVm
Submitted June 26, 2025 at 04:43PM by Most-Anywhere-6651
via reddit https://ift.tt/ZYFaiSp
https://ift.tt/Tdj6bVm
Submitted June 26, 2025 at 04:43PM by Most-Anywhere-6651
via reddit https://ift.tt/ZYFaiSp
Medium
Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork; Putting Millions at Risk
TL;DR: We discovered a critical vulnerability in open-vsx.org — the open-source VS Code extension marketplace used by over 8,000,000…
Scanning Beyond the Patch: A Public-Interest Hunt for Hidden Shells
https://ift.tt/YMgyR2h
Submitted June 26, 2025 at 07:21PM by 0x5h4un
via reddit https://ift.tt/ukmlabS
https://ift.tt/YMgyR2h
Submitted June 26, 2025 at 07:21PM by 0x5h4un
via reddit https://ift.tt/ukmlabS
disclosing.observer
Scanning Beyond the Patch: A Public-Interest Hunt for Hidden Shells - Disclosing.Observer
Even after patching, many edge devices remain compromised. This post explores how to ethically scan for backdoors left behind.