GitPhish: Automating Enterprise GitHub Device Code Phishing
https://ift.tt/16H2hRt
Submitted July 03, 2025 at 01:04AM by IrohsLotusTile
via reddit https://ift.tt/kGPudtT
https://ift.tt/16H2hRt
Submitted July 03, 2025 at 01:04AM by IrohsLotusTile
via reddit https://ift.tt/kGPudtT
Praetorian
GitPhish: Automating Enterprise GitHub Device Code Phishing
Introducing GitPhish: An open-source tool for automating GitHub Device Code phishing attacks with dynamic code generation and professional landing pages for red teams.
/r/netsec's Q3 2025 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted July 03, 2025 at 01:02AM by netsec_burn
via reddit https://ift.tt/hPr2e4I
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted July 03, 2025 at 01:02AM by netsec_burn
via reddit https://ift.tt/hPr2e4I
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
How Coinbase's $400M Problem Started in an Indian Call Center
https://ift.tt/BOlTmgR
Submitted July 03, 2025 at 01:48PM by vowskigin
via reddit https://ift.tt/MKUdVBt
https://ift.tt/BOlTmgR
Submitted July 03, 2025 at 01:48PM by vowskigin
via reddit https://ift.tt/MKUdVBt
Applocker bypass on Lenovo machines – The curious case of MFGSTAT.zip
https://ift.tt/pskXUvo
Submitted July 03, 2025 at 07:39PM by oddvarmoe
via reddit https://ift.tt/uELDThW
https://ift.tt/pskXUvo
Submitted July 03, 2025 at 07:39PM by oddvarmoe
via reddit https://ift.tt/uELDThW
Oddvar Moe's Blog
Applocker bypass on Lenovo machines – The curious case of MFGSTAT.zip
This blogpost is about a minor discovery I made regarding a writeable file inside the Windows folder that is present on Lenovo machines. Initially when I found it I thought it was only a handful of…
Instagram uses expiring certificates as single day TLS certificates
https://ift.tt/2LeCsqN
Submitted July 04, 2025 at 02:43AM by tootac
via reddit https://ift.tt/6kKnGHw
https://ift.tt/2LeCsqN
Submitted July 04, 2025 at 02:43AM by tootac
via reddit https://ift.tt/6kKnGHw
Feedback Requested: DevSecOps Standard RFP from OMG
https://ift.tt/SrWF3Gz
Submitted July 04, 2025 at 05:45AM by DidoSolutionsSocial
via reddit https://ift.tt/naKM7Zr
https://ift.tt/SrWF3Gz
Submitted July 04, 2025 at 05:45AM by DidoSolutionsSocial
via reddit https://ift.tt/naKM7Zr
Google Docs
Reddit Feedback on DevSecOps Standard
Web Metadata search - search for headers, web apps, CMSs, and their versions
https://ift.tt/bJyIVKE?
Submitted July 04, 2025 at 09:33AM by rmddos
via reddit https://ift.tt/WidFERG
https://ift.tt/bJyIVKE?
Submitted July 04, 2025 at 09:33AM by rmddos
via reddit https://ift.tt/WidFERG
dnsarchive.net
Web Metadata Search
DNSArchive is a domain, DNS, RDNS and IP intelligence feed and DNS repository. We have over 220 million domains archived.
CVE-2025-32462: sudo: LPE via host option
https://ift.tt/iMKuPxB
Submitted July 04, 2025 at 02:07PM by ljulolsen
via reddit https://ift.tt/6MEo4WH
https://ift.tt/iMKuPxB
Submitted July 04, 2025 at 02:07PM by ljulolsen
via reddit https://ift.tt/6MEo4WH
Tokyo Ghoul — TryHackMe CTF Walkthrough | Web Exploitation & Privilege Escalation
https://ift.tt/s3LWuyN
Submitted July 04, 2025 at 07:21PM by insidemango_
via reddit https://ift.tt/Z9PesUh
https://ift.tt/s3LWuyN
Submitted July 04, 2025 at 07:21PM by insidemango_
via reddit https://ift.tt/Z9PesUh
Medium
Tokyo Ghoul — TryHackMe CTF Walkthrough | Web Exploitation & Privilege Escalation
🧠 What You’ll Learn
How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777) - watchTowr Labs
https://ift.tt/iQv7OCg
Submitted July 05, 2025 at 12:50AM by dx7r__
via reddit https://ift.tt/hFuJo48
https://ift.tt/iQv7OCg
Submitted July 05, 2025 at 12:50AM by dx7r__
via reddit https://ift.tt/hFuJo48
watchTowr Labs
How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)
Before you dive into our latest diatribe, indulge us and join us on a journey.
Sit in your chair, stand at your desk, lick your phone screen - close your eyes and imagine a world in which things are great. It’s sunny outside, the birds are chirping, and…
Sit in your chair, stand at your desk, lick your phone screen - close your eyes and imagine a world in which things are great. It’s sunny outside, the birds are chirping, and…
Schizophrenic ZIP file - Yet Another ZIP Trick Writeup
https://ift.tt/e2qGNVy
Submitted July 06, 2025 at 09:15PM by Beneficial_Cattle_98
via reddit https://ift.tt/IjGnzox
https://ift.tt/e2qGNVy
Submitted July 06, 2025 at 09:15PM by Beneficial_Cattle_98
via reddit https://ift.tt/IjGnzox
Husseinmuhaisen
Yet Another ZIP Trick Writeup
A detailed walkthrough of the 'Yet Another ZIP Trick' challenge from HackArcana, covering schizophrenic ZIP file creation and binary exploitation techniques.
This Linux boot flaw bypasses Secure Boot and full disk encryption but the fix is easy
https://ift.tt/NXSEaC5
Submitted July 07, 2025 at 01:04AM by brianfagioli
via reddit https://ift.tt/u2q6vMZ
https://ift.tt/NXSEaC5
Submitted July 07, 2025 at 01:04AM by brianfagioli
via reddit https://ift.tt/u2q6vMZ
NERDS.xyz
This overlooked Linux boot flaw defeats Secure Boot heres how to fix it
A Linux researcher at ERNW has demonstrated how attackers can bypass Secure Boot protections by modifying an unsigned initramfs. But a few kernel tweaks are all it takes to lock things down.
État de l’art sur le phishing Azure en 2025 (partie 2) – Étendre l’accès
https://ift.tt/8KBrGY6
Submitted July 07, 2025 at 03:10AM by MobetaSec
via reddit https://ift.tt/n5cbQag
https://ift.tt/8KBrGY6
Submitted July 07, 2025 at 03:10AM by MobetaSec
via reddit https://ift.tt/n5cbQag
Mobeta
État de l’art sur le phishing Azure en 2025 (partie 2) – Étendre l'accès | Mobeta
Découvrez comment étendre un accès après une attaque de phishing Azure via le PRT, jusqu’à générer une persistance avec Windows Hello.
CVE-2025-5777, aka CitrixBleed 2, Deep-Dive and Indicators of Compromise
https://ift.tt/y3n57la
Submitted July 07, 2025 at 07:03PM by scopedsecurity
via reddit https://ift.tt/SuO3NW5
https://ift.tt/y3n57la
Submitted July 07, 2025 at 07:03PM by scopedsecurity
via reddit https://ift.tt/SuO3NW5
Horizon3.ai
CVE-2025-5777: CitrixBleed 2 Exploit Deep Dive by Horizon3.ai
Explore the CVE-2025-5777 vulnerability in Citrix, dubbed CitrixBleed 2. Learn how it works, attack details, and defensive steps from Horizon3.ai experts.
How I Discovered a Libpng Vulnerability 11 Years After It Was Patched
https://ift.tt/uhlpCzS
Submitted July 07, 2025 at 08:02PM by unknownhad
via reddit https://ift.tt/NVUfXFK
https://ift.tt/uhlpCzS
Submitted July 07, 2025 at 08:02PM by unknownhad
via reddit https://ift.tt/NVUfXFK
Terminal
How I Discovered a Libpng Vulnerability 11 Years After It Was Patched
A beginner's journey into secure code review, and how I accidentally rediscovered an 11-year-old vulnerability in libpng.
Delete Yourself from the Internet: Why You Must—and Exactly How to Do It
https://ift.tt/umTZIPn
Submitted July 07, 2025 at 09:43PM by benaissa-4587
via reddit https://ift.tt/kUaBpV7
https://ift.tt/umTZIPn
Submitted July 07, 2025 at 09:43PM by benaissa-4587
via reddit https://ift.tt/kUaBpV7
EsstN
Delete Yourself from the Internet: Why You Must—and Exactly How to Do It - EsstN
Note on Paid Data Removal ServicesServices like DeleteMe, PrivacyBee, and Mozilla Monitor offer automated data removal from broker sites and people-search
The GPS Leak No One Talked About: Uffizio’s Silent Exposure
https://ift.tt/9bPByj7
Submitted July 07, 2025 at 10:52PM by Disscom
via reddit https://ift.tt/QOVCnPH
https://ift.tt/9bPByj7
Submitted July 07, 2025 at 10:52PM by Disscom
via reddit https://ift.tt/QOVCnPH
Medium
The GPS Leak No One Talked About: Uffizio’s Silent Exposure
Executive Summary
Microsoft hardens Windows 11 against file junction attacks
https://ift.tt/kJTce71
Submitted July 08, 2025 at 06:19AM by rkhunter_
via reddit https://ift.tt/7VTGbdv
https://ift.tt/kJTce71
Submitted July 08, 2025 at 06:19AM by rkhunter_
via reddit https://ift.tt/7VTGbdv
Offline blockchain governance with QR/USB sync? This project seems like it’s thinking about failure modes…
https://ift.tt/u2AdXyq
Submitted July 08, 2025 at 07:30AM by Shaggyehh
via reddit https://ift.tt/XC4Gh0U
https://ift.tt/u2AdXyq
Submitted July 08, 2025 at 07:30AM by Shaggyehh
via reddit https://ift.tt/XC4Gh0U
Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
https://ift.tt/hDriYWS
Submitted July 08, 2025 at 01:33PM by Mempodipper
via reddit https://ift.tt/3d5eDRh
https://ift.tt/hDriYWS
Submitted July 08, 2025 at 01:33PM by Mempodipper
via reddit https://ift.tt/3d5eDRh
Searchlight Cyber
Abusing .NET and Unicode Normalization to Exploit DNN | Searchlight
A pre-authentication vulnerability exists within DotNetNuke versions 6.0 to 10.0.1, assigned CVE-2025-52488, that allows attackers to steal NTLM hashes.
[CVE-2025-32461] Tiki Wiki CMS Groupware <= 28.3 Two SSTI Vulnerabilities
https://ift.tt/Zu2o0Ww
Submitted July 08, 2025 at 03:33PM by eg1x
via reddit https://ift.tt/hQwoqMW
https://ift.tt/Zu2o0Ww
Submitted July 08, 2025 at 03:33PM by eg1x
via reddit https://ift.tt/hQwoqMW
Karmainsecurity
Tiki Wiki CMS Groupware <= 28.3 Two Server-Side Template Injection Vulnerabilities | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.