Microsoft hardens Windows 11 against file junction attacks
https://ift.tt/kJTce71
Submitted July 08, 2025 at 06:19AM by rkhunter_
via reddit https://ift.tt/7VTGbdv
https://ift.tt/kJTce71
Submitted July 08, 2025 at 06:19AM by rkhunter_
via reddit https://ift.tt/7VTGbdv
Offline blockchain governance with QR/USB sync? This project seems like it’s thinking about failure modes…
https://ift.tt/u2AdXyq
Submitted July 08, 2025 at 07:30AM by Shaggyehh
via reddit https://ift.tt/XC4Gh0U
https://ift.tt/u2AdXyq
Submitted July 08, 2025 at 07:30AM by Shaggyehh
via reddit https://ift.tt/XC4Gh0U
Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
https://ift.tt/hDriYWS
Submitted July 08, 2025 at 01:33PM by Mempodipper
via reddit https://ift.tt/3d5eDRh
https://ift.tt/hDriYWS
Submitted July 08, 2025 at 01:33PM by Mempodipper
via reddit https://ift.tt/3d5eDRh
Searchlight Cyber
Abusing .NET and Unicode Normalization to Exploit DNN | Searchlight
A pre-authentication vulnerability exists within DotNetNuke versions 6.0 to 10.0.1, assigned CVE-2025-52488, that allows attackers to steal NTLM hashes.
[CVE-2025-32461] Tiki Wiki CMS Groupware <= 28.3 Two SSTI Vulnerabilities
https://ift.tt/Zu2o0Ww
Submitted July 08, 2025 at 03:33PM by eg1x
via reddit https://ift.tt/hQwoqMW
https://ift.tt/Zu2o0Ww
Submitted July 08, 2025 at 03:33PM by eg1x
via reddit https://ift.tt/hQwoqMW
Karmainsecurity
Tiki Wiki CMS Groupware <= 28.3 Two Server-Side Template Injection Vulnerabilities | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Tool: SSCV Framework – Context-Aware, Open Source Vulnerability Risk Scoring
https://ift.tt/jHtUbsh
Submitted July 08, 2025 at 01:45AM by Ordinary_Usual_6710
via reddit https://ift.tt/iVgtqrX
https://ift.tt/jHtUbsh
Submitted July 08, 2025 at 01:45AM by Ordinary_Usual_6710
via reddit https://ift.tt/iVgtqrX
sscv-framework.org
SSCV Framework - Contextual Vulnerability Risk Scoring
Transform CVSS scores into accurate risk assessments. Calculate real vulnerability risk based on your system's security posture.
Resource for Those Who Need a Team for CTF
https://www.ctflfg.com
Submitted July 08, 2025 at 06:40AM by ctflfg
via reddit https://ift.tt/NF9Oj4A
https://www.ctflfg.com
Submitted July 08, 2025 at 06:40AM by ctflfg
via reddit https://ift.tt/NF9Oj4A
Reddit
From the netsec community on Reddit: Resource for Those Who Need a Team for CTF
Posted by ctflfg - 6 votes and 0 comments
Shellcode execution using MessageBox Dialog
https://ift.tt/t1yU8E5
Submitted July 08, 2025 at 04:43PM by flamedpt
via reddit https://ift.tt/PpM3wjv
https://ift.tt/t1yU8E5
Submitted July 08, 2025 at 04:43PM by flamedpt
via reddit https://ift.tt/PpM3wjv
ghostline.neocities.org
.Shellcode injection using MessageBox - Ghosts in the shell
Lateral Movement with code execution in the context of active user sessions
https://ift.tt/ra1Iu45
Submitted July 08, 2025 at 06:16PM by S3cur3Th1sSh1t
via reddit https://ift.tt/PA8ayo6
https://ift.tt/ra1Iu45
Submitted July 08, 2025 at 06:16PM by S3cur3Th1sSh1t
via reddit https://ift.tt/PA8ayo6
www.r-tec.net
r-tec Blog | Revisiting Cross Session Activation Attacks
This blog post revisits Cross Session Activation attacks
New Attack on TLS: Opossum attack
https://ift.tt/t8wrdex
Submitted July 08, 2025 at 06:15PM by Electronic_Bite7709
via reddit https://ift.tt/EQqKxab
https://ift.tt/t8wrdex
Submitted July 08, 2025 at 06:15PM by Electronic_Bite7709
via reddit https://ift.tt/EQqKxab
Linux kernel double-free to LPE
https://ift.tt/ThOsjvx
Submitted July 08, 2025 at 05:41PM by SSDisclosure
via reddit https://ift.tt/5YBRD1Q
https://ift.tt/ThOsjvx
Submitted July 08, 2025 at 05:41PM by SSDisclosure
via reddit https://ift.tt/5YBRD1Q
SSD Secure Disclosure
SSD Advisory - Linux Kernel Pipapo Set Double Free LPE - SSD Secure Disclosure
Summary A critical double free vulnerability in the pipapo set module of the Linux kernel’s NFT subsystem has been discovered. An unprivileged attacker can exploit this vulnerability by sending a specially crafted netlink message, triggering double-free error…
Scanning for Post-Quantum Cryptographic Support
https://ift.tt/sRaUHpQ
Submitted July 08, 2025 at 09:42PM by tlxio
via reddit https://ift.tt/6tj1caH
https://ift.tt/sRaUHpQ
Submitted July 08, 2025 at 09:42PM by tlxio
via reddit https://ift.tt/6tj1caH
Anvil Secure
Scanning for Post-Quantum Cryptographic Support - Anvil Secure
CTO Vincent Berg introduces PQCscan, a free tool that checks SSH and TLS servers for post-quantum cryptography support.
Bitchat MITM Flaw
https://ift.tt/mq473Ld
Submitted July 08, 2025 at 09:21PM by supernetworks
via reddit https://ift.tt/A7Bn8Lz
https://ift.tt/mq473Ld
Submitted July 08, 2025 at 09:21PM by supernetworks
via reddit https://ift.tt/A7Bn8Lz
www.supernetworks.org
Identity Is A Bitchat Challenge (MITM Flaw) | SPR
The Intersection of Vibe Coding and Security
Privilege Escalation Using TPQMAssistant.exe on Lenovo
https://ift.tt/nv8RKlt
Submitted July 08, 2025 at 09:52PM by oddvarmoe
via reddit https://ift.tt/XqjwpMG
https://ift.tt/nv8RKlt
Submitted July 08, 2025 at 09:52PM by oddvarmoe
via reddit https://ift.tt/XqjwpMG
TrustedSec
CVE-2025-1729 - Privilege Escalation Using TPQMAssistant.exe
Exploring Delegated Admin Risks in AWS Organizations
https://ift.tt/CL82YND
Submitted July 10, 2025 at 09:22PM by Fun_Preference1113
via reddit https://ift.tt/mXEB1eS
https://ift.tt/CL82YND
Submitted July 10, 2025 at 09:22PM by Fun_Preference1113
via reddit https://ift.tt/mXEB1eS
Cymulate
Out of Sight, Beneath the Surface: Exploring Delegated Admin Risks in AWS Organizations
Discover how attackers abuse AWS delegated admin and a policy flaw to silently hijack entire organizations. Includes detection and mitigation tips.
Two critical credential vulnerabilities have been found in Kaseya's RapidFire Tools Network Detective
https://ift.tt/cvHbr2h
Submitted July 11, 2025 at 10:03AM by CodyKretsinger
via reddit https://ift.tt/EGIjhsq
https://ift.tt/cvHbr2h
Submitted July 11, 2025 at 10:03AM by CodyKretsinger
via reddit https://ift.tt/EGIjhsq
Galactic Advisors
Critical-Vulnerabilities-in-Network Detective
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257) - watchTowr Labs
https://ift.tt/5JMuWNZ
Submitted July 11, 2025 at 03:44PM by dx7r__
via reddit https://ift.tt/yeKPFld
https://ift.tt/5JMuWNZ
Submitted July 11, 2025 at 03:44PM by dx7r__
via reddit https://ift.tt/yeKPFld
watchTowr Labs
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
Welcome back to yet another day in this parallel universe of security.
This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That's a great question; no one knows.
For the uninitiated, or unjaded;
Fortinet’s…
This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That's a great question; no one knows.
For the uninitiated, or unjaded;
Fortinet’s…
FortiWeb Pre-Auth RCE (CVE-2025-25257)
https://ift.tt/Fv3zr1Z
Submitted July 11, 2025 at 06:43PM by pwntheplanet
via reddit https://ift.tt/Lfxn3IQ
https://ift.tt/Fv3zr1Z
Submitted July 11, 2025 at 06:43PM by pwntheplanet
via reddit https://ift.tt/Lfxn3IQ
( ͡◕ _ ͡◕)👌
FortiWeb Pre-Auth RCE (CVE-2025-25257)
Hey! and welcome to another THEY BURNED MY BUG episode. This time, we introduce CVE-2025-25257. An SQLi that I spotted back in Feb. in case someone burn them before i get my bragging rights8157d42995395ba0c0cfccce37b934ebb63d3d5740ba43eda7fa853f389bca2a8…
Bypassing Meta's Llama Firewall: A Case Study in Prompt Injection Vulnerabilities
https://ift.tt/kAMPbx3
Submitted July 11, 2025 at 08:05PM by vitalikmuskk
via reddit https://ift.tt/Cl6XNVF
https://ift.tt/kAMPbx3
Submitted July 11, 2025 at 08:05PM by vitalikmuskk
via reddit https://ift.tt/Cl6XNVF
Medium
Bypassing Meta’s Llama Firewall: A Case Study in Prompt Injection Vulnerabilities
How we bypassed Meta’s Llama Firewall in real-world tests at Trendyol
ZeroSeige - Live PvP Terminal Hack Battle
https://zeroseige.com/
Submitted July 12, 2025 at 03:43AM by playzeroseige
via reddit https://ift.tt/aF8iled
https://zeroseige.com/
Submitted July 12, 2025 at 03:43AM by playzeroseige
via reddit https://ift.tt/aF8iled
Reddit
From the netsec community on Reddit: ZeroSeige - Live PvP Terminal Hack Battle
Posted by playzeroseige - 3 votes and 0 comments
I built a tool to track web exposure — screenshots, HTML/JS diff, and alerts
https://reconsnap.com
Submitted July 12, 2025 at 03:08PM by oppai_silverman
via reddit https://ift.tt/y4GQciv
https://reconsnap.com
Submitted July 12, 2025 at 03:08PM by oppai_silverman
via reddit https://ift.tt/y4GQciv
Reddit
From the netsec community on Reddit: I built a tool to track web exposure — screenshots, HTML/JS diff, and alerts
Posted by oppai_silverman - 14 votes and 0 comments
From Blind XSS to RCE: When Headers Became My Terminal
https://ift.tt/WLY0swX
Submitted July 13, 2025 at 06:05AM by General_Speaker9653
via reddit https://ift.tt/cVL5v7D
https://ift.tt/WLY0swX
Submitted July 13, 2025 at 06:05AM by General_Speaker9653
via reddit https://ift.tt/cVL5v7D
Medium
From Blind XSS to RCE: When Headers Became My Terminal
Hello,