Instagram uses expiring certificates as single day TLS certificates
https://ift.tt/2LeCsqN
Submitted July 04, 2025 at 02:43AM by tootac
via reddit https://ift.tt/6kKnGHw
https://ift.tt/2LeCsqN
Submitted July 04, 2025 at 02:43AM by tootac
via reddit https://ift.tt/6kKnGHw
Feedback Requested: DevSecOps Standard RFP from OMG
https://ift.tt/SrWF3Gz
Submitted July 04, 2025 at 05:45AM by DidoSolutionsSocial
via reddit https://ift.tt/naKM7Zr
https://ift.tt/SrWF3Gz
Submitted July 04, 2025 at 05:45AM by DidoSolutionsSocial
via reddit https://ift.tt/naKM7Zr
Google Docs
Reddit Feedback on DevSecOps Standard
Web Metadata search - search for headers, web apps, CMSs, and their versions
https://ift.tt/bJyIVKE?
Submitted July 04, 2025 at 09:33AM by rmddos
via reddit https://ift.tt/WidFERG
https://ift.tt/bJyIVKE?
Submitted July 04, 2025 at 09:33AM by rmddos
via reddit https://ift.tt/WidFERG
dnsarchive.net
Web Metadata Search
DNSArchive is a domain, DNS, RDNS and IP intelligence feed and DNS repository. We have over 220 million domains archived.
CVE-2025-32462: sudo: LPE via host option
https://ift.tt/iMKuPxB
Submitted July 04, 2025 at 02:07PM by ljulolsen
via reddit https://ift.tt/6MEo4WH
https://ift.tt/iMKuPxB
Submitted July 04, 2025 at 02:07PM by ljulolsen
via reddit https://ift.tt/6MEo4WH
Tokyo Ghoul — TryHackMe CTF Walkthrough | Web Exploitation & Privilege Escalation
https://ift.tt/s3LWuyN
Submitted July 04, 2025 at 07:21PM by insidemango_
via reddit https://ift.tt/Z9PesUh
https://ift.tt/s3LWuyN
Submitted July 04, 2025 at 07:21PM by insidemango_
via reddit https://ift.tt/Z9PesUh
Medium
Tokyo Ghoul — TryHackMe CTF Walkthrough | Web Exploitation & Privilege Escalation
🧠 What You’ll Learn
How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777) - watchTowr Labs
https://ift.tt/iQv7OCg
Submitted July 05, 2025 at 12:50AM by dx7r__
via reddit https://ift.tt/hFuJo48
https://ift.tt/iQv7OCg
Submitted July 05, 2025 at 12:50AM by dx7r__
via reddit https://ift.tt/hFuJo48
watchTowr Labs
How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)
Before you dive into our latest diatribe, indulge us and join us on a journey.
Sit in your chair, stand at your desk, lick your phone screen - close your eyes and imagine a world in which things are great. It’s sunny outside, the birds are chirping, and…
Sit in your chair, stand at your desk, lick your phone screen - close your eyes and imagine a world in which things are great. It’s sunny outside, the birds are chirping, and…
Schizophrenic ZIP file - Yet Another ZIP Trick Writeup
https://ift.tt/e2qGNVy
Submitted July 06, 2025 at 09:15PM by Beneficial_Cattle_98
via reddit https://ift.tt/IjGnzox
https://ift.tt/e2qGNVy
Submitted July 06, 2025 at 09:15PM by Beneficial_Cattle_98
via reddit https://ift.tt/IjGnzox
Husseinmuhaisen
Yet Another ZIP Trick Writeup
A detailed walkthrough of the 'Yet Another ZIP Trick' challenge from HackArcana, covering schizophrenic ZIP file creation and binary exploitation techniques.
This Linux boot flaw bypasses Secure Boot and full disk encryption but the fix is easy
https://ift.tt/NXSEaC5
Submitted July 07, 2025 at 01:04AM by brianfagioli
via reddit https://ift.tt/u2q6vMZ
https://ift.tt/NXSEaC5
Submitted July 07, 2025 at 01:04AM by brianfagioli
via reddit https://ift.tt/u2q6vMZ
NERDS.xyz
This overlooked Linux boot flaw defeats Secure Boot heres how to fix it
A Linux researcher at ERNW has demonstrated how attackers can bypass Secure Boot protections by modifying an unsigned initramfs. But a few kernel tweaks are all it takes to lock things down.
État de l’art sur le phishing Azure en 2025 (partie 2) – Étendre l’accès
https://ift.tt/8KBrGY6
Submitted July 07, 2025 at 03:10AM by MobetaSec
via reddit https://ift.tt/n5cbQag
https://ift.tt/8KBrGY6
Submitted July 07, 2025 at 03:10AM by MobetaSec
via reddit https://ift.tt/n5cbQag
Mobeta
État de l’art sur le phishing Azure en 2025 (partie 2) – Étendre l'accès | Mobeta
Découvrez comment étendre un accès après une attaque de phishing Azure via le PRT, jusqu’à générer une persistance avec Windows Hello.
CVE-2025-5777, aka CitrixBleed 2, Deep-Dive and Indicators of Compromise
https://ift.tt/y3n57la
Submitted July 07, 2025 at 07:03PM by scopedsecurity
via reddit https://ift.tt/SuO3NW5
https://ift.tt/y3n57la
Submitted July 07, 2025 at 07:03PM by scopedsecurity
via reddit https://ift.tt/SuO3NW5
Horizon3.ai
CVE-2025-5777: CitrixBleed 2 Exploit Deep Dive by Horizon3.ai
Explore the CVE-2025-5777 vulnerability in Citrix, dubbed CitrixBleed 2. Learn how it works, attack details, and defensive steps from Horizon3.ai experts.
How I Discovered a Libpng Vulnerability 11 Years After It Was Patched
https://ift.tt/uhlpCzS
Submitted July 07, 2025 at 08:02PM by unknownhad
via reddit https://ift.tt/NVUfXFK
https://ift.tt/uhlpCzS
Submitted July 07, 2025 at 08:02PM by unknownhad
via reddit https://ift.tt/NVUfXFK
Terminal
How I Discovered a Libpng Vulnerability 11 Years After It Was Patched
A beginner's journey into secure code review, and how I accidentally rediscovered an 11-year-old vulnerability in libpng.
Delete Yourself from the Internet: Why You Must—and Exactly How to Do It
https://ift.tt/umTZIPn
Submitted July 07, 2025 at 09:43PM by benaissa-4587
via reddit https://ift.tt/kUaBpV7
https://ift.tt/umTZIPn
Submitted July 07, 2025 at 09:43PM by benaissa-4587
via reddit https://ift.tt/kUaBpV7
EsstN
Delete Yourself from the Internet: Why You Must—and Exactly How to Do It - EsstN
Note on Paid Data Removal ServicesServices like DeleteMe, PrivacyBee, and Mozilla Monitor offer automated data removal from broker sites and people-search
The GPS Leak No One Talked About: Uffizio’s Silent Exposure
https://ift.tt/9bPByj7
Submitted July 07, 2025 at 10:52PM by Disscom
via reddit https://ift.tt/QOVCnPH
https://ift.tt/9bPByj7
Submitted July 07, 2025 at 10:52PM by Disscom
via reddit https://ift.tt/QOVCnPH
Medium
The GPS Leak No One Talked About: Uffizio’s Silent Exposure
Executive Summary
Microsoft hardens Windows 11 against file junction attacks
https://ift.tt/kJTce71
Submitted July 08, 2025 at 06:19AM by rkhunter_
via reddit https://ift.tt/7VTGbdv
https://ift.tt/kJTce71
Submitted July 08, 2025 at 06:19AM by rkhunter_
via reddit https://ift.tt/7VTGbdv
Offline blockchain governance with QR/USB sync? This project seems like it’s thinking about failure modes…
https://ift.tt/u2AdXyq
Submitted July 08, 2025 at 07:30AM by Shaggyehh
via reddit https://ift.tt/XC4Gh0U
https://ift.tt/u2AdXyq
Submitted July 08, 2025 at 07:30AM by Shaggyehh
via reddit https://ift.tt/XC4Gh0U
Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
https://ift.tt/hDriYWS
Submitted July 08, 2025 at 01:33PM by Mempodipper
via reddit https://ift.tt/3d5eDRh
https://ift.tt/hDriYWS
Submitted July 08, 2025 at 01:33PM by Mempodipper
via reddit https://ift.tt/3d5eDRh
Searchlight Cyber
Abusing .NET and Unicode Normalization to Exploit DNN | Searchlight
A pre-authentication vulnerability exists within DotNetNuke versions 6.0 to 10.0.1, assigned CVE-2025-52488, that allows attackers to steal NTLM hashes.
[CVE-2025-32461] Tiki Wiki CMS Groupware <= 28.3 Two SSTI Vulnerabilities
https://ift.tt/Zu2o0Ww
Submitted July 08, 2025 at 03:33PM by eg1x
via reddit https://ift.tt/hQwoqMW
https://ift.tt/Zu2o0Ww
Submitted July 08, 2025 at 03:33PM by eg1x
via reddit https://ift.tt/hQwoqMW
Karmainsecurity
Tiki Wiki CMS Groupware <= 28.3 Two Server-Side Template Injection Vulnerabilities | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Tool: SSCV Framework – Context-Aware, Open Source Vulnerability Risk Scoring
https://ift.tt/jHtUbsh
Submitted July 08, 2025 at 01:45AM by Ordinary_Usual_6710
via reddit https://ift.tt/iVgtqrX
https://ift.tt/jHtUbsh
Submitted July 08, 2025 at 01:45AM by Ordinary_Usual_6710
via reddit https://ift.tt/iVgtqrX
sscv-framework.org
SSCV Framework - Contextual Vulnerability Risk Scoring
Transform CVSS scores into accurate risk assessments. Calculate real vulnerability risk based on your system's security posture.
Resource for Those Who Need a Team for CTF
https://www.ctflfg.com
Submitted July 08, 2025 at 06:40AM by ctflfg
via reddit https://ift.tt/NF9Oj4A
https://www.ctflfg.com
Submitted July 08, 2025 at 06:40AM by ctflfg
via reddit https://ift.tt/NF9Oj4A
Reddit
From the netsec community on Reddit: Resource for Those Who Need a Team for CTF
Posted by ctflfg - 6 votes and 0 comments
Shellcode execution using MessageBox Dialog
https://ift.tt/t1yU8E5
Submitted July 08, 2025 at 04:43PM by flamedpt
via reddit https://ift.tt/PpM3wjv
https://ift.tt/t1yU8E5
Submitted July 08, 2025 at 04:43PM by flamedpt
via reddit https://ift.tt/PpM3wjv
ghostline.neocities.org
.Shellcode injection using MessageBox - Ghosts in the shell
Lateral Movement with code execution in the context of active user sessions
https://ift.tt/ra1Iu45
Submitted July 08, 2025 at 06:16PM by S3cur3Th1sSh1t
via reddit https://ift.tt/PA8ayo6
https://ift.tt/ra1Iu45
Submitted July 08, 2025 at 06:16PM by S3cur3Th1sSh1t
via reddit https://ift.tt/PA8ayo6
www.r-tec.net
r-tec Blog | Revisiting Cross Session Activation Attacks
This blog post revisits Cross Session Activation attacks