New Attack on TLS: Opossum attack
https://ift.tt/t8wrdex
Submitted July 08, 2025 at 06:15PM by Electronic_Bite7709
via reddit https://ift.tt/EQqKxab
https://ift.tt/t8wrdex
Submitted July 08, 2025 at 06:15PM by Electronic_Bite7709
via reddit https://ift.tt/EQqKxab
Linux kernel double-free to LPE
https://ift.tt/ThOsjvx
Submitted July 08, 2025 at 05:41PM by SSDisclosure
via reddit https://ift.tt/5YBRD1Q
https://ift.tt/ThOsjvx
Submitted July 08, 2025 at 05:41PM by SSDisclosure
via reddit https://ift.tt/5YBRD1Q
SSD Secure Disclosure
SSD Advisory - Linux Kernel Pipapo Set Double Free LPE - SSD Secure Disclosure
Summary A critical double free vulnerability in the pipapo set module of the Linux kernel’s NFT subsystem has been discovered. An unprivileged attacker can exploit this vulnerability by sending a specially crafted netlink message, triggering double-free error…
Scanning for Post-Quantum Cryptographic Support
https://ift.tt/sRaUHpQ
Submitted July 08, 2025 at 09:42PM by tlxio
via reddit https://ift.tt/6tj1caH
https://ift.tt/sRaUHpQ
Submitted July 08, 2025 at 09:42PM by tlxio
via reddit https://ift.tt/6tj1caH
Anvil Secure
Scanning for Post-Quantum Cryptographic Support - Anvil Secure
CTO Vincent Berg introduces PQCscan, a free tool that checks SSH and TLS servers for post-quantum cryptography support.
Bitchat MITM Flaw
https://ift.tt/mq473Ld
Submitted July 08, 2025 at 09:21PM by supernetworks
via reddit https://ift.tt/A7Bn8Lz
https://ift.tt/mq473Ld
Submitted July 08, 2025 at 09:21PM by supernetworks
via reddit https://ift.tt/A7Bn8Lz
www.supernetworks.org
Identity Is A Bitchat Challenge (MITM Flaw) | SPR
The Intersection of Vibe Coding and Security
Privilege Escalation Using TPQMAssistant.exe on Lenovo
https://ift.tt/nv8RKlt
Submitted July 08, 2025 at 09:52PM by oddvarmoe
via reddit https://ift.tt/XqjwpMG
https://ift.tt/nv8RKlt
Submitted July 08, 2025 at 09:52PM by oddvarmoe
via reddit https://ift.tt/XqjwpMG
TrustedSec
CVE-2025-1729 - Privilege Escalation Using TPQMAssistant.exe
Exploring Delegated Admin Risks in AWS Organizations
https://ift.tt/CL82YND
Submitted July 10, 2025 at 09:22PM by Fun_Preference1113
via reddit https://ift.tt/mXEB1eS
https://ift.tt/CL82YND
Submitted July 10, 2025 at 09:22PM by Fun_Preference1113
via reddit https://ift.tt/mXEB1eS
Cymulate
Out of Sight, Beneath the Surface: Exploring Delegated Admin Risks in AWS Organizations
Discover how attackers abuse AWS delegated admin and a policy flaw to silently hijack entire organizations. Includes detection and mitigation tips.
Two critical credential vulnerabilities have been found in Kaseya's RapidFire Tools Network Detective
https://ift.tt/cvHbr2h
Submitted July 11, 2025 at 10:03AM by CodyKretsinger
via reddit https://ift.tt/EGIjhsq
https://ift.tt/cvHbr2h
Submitted July 11, 2025 at 10:03AM by CodyKretsinger
via reddit https://ift.tt/EGIjhsq
Galactic Advisors
Critical-Vulnerabilities-in-Network Detective
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257) - watchTowr Labs
https://ift.tt/5JMuWNZ
Submitted July 11, 2025 at 03:44PM by dx7r__
via reddit https://ift.tt/yeKPFld
https://ift.tt/5JMuWNZ
Submitted July 11, 2025 at 03:44PM by dx7r__
via reddit https://ift.tt/yeKPFld
watchTowr Labs
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
Welcome back to yet another day in this parallel universe of security.
This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That's a great question; no one knows.
For the uninitiated, or unjaded;
Fortinet’s…
This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That's a great question; no one knows.
For the uninitiated, or unjaded;
Fortinet’s…
FortiWeb Pre-Auth RCE (CVE-2025-25257)
https://ift.tt/Fv3zr1Z
Submitted July 11, 2025 at 06:43PM by pwntheplanet
via reddit https://ift.tt/Lfxn3IQ
https://ift.tt/Fv3zr1Z
Submitted July 11, 2025 at 06:43PM by pwntheplanet
via reddit https://ift.tt/Lfxn3IQ
( ͡◕ _ ͡◕)👌
FortiWeb Pre-Auth RCE (CVE-2025-25257)
Hey! and welcome to another THEY BURNED MY BUG episode. This time, we introduce CVE-2025-25257. An SQLi that I spotted back in Feb. in case someone burn them before i get my bragging rights8157d42995395ba0c0cfccce37b934ebb63d3d5740ba43eda7fa853f389bca2a8…
Bypassing Meta's Llama Firewall: A Case Study in Prompt Injection Vulnerabilities
https://ift.tt/kAMPbx3
Submitted July 11, 2025 at 08:05PM by vitalikmuskk
via reddit https://ift.tt/Cl6XNVF
https://ift.tt/kAMPbx3
Submitted July 11, 2025 at 08:05PM by vitalikmuskk
via reddit https://ift.tt/Cl6XNVF
Medium
Bypassing Meta’s Llama Firewall: A Case Study in Prompt Injection Vulnerabilities
How we bypassed Meta’s Llama Firewall in real-world tests at Trendyol
ZeroSeige - Live PvP Terminal Hack Battle
https://zeroseige.com/
Submitted July 12, 2025 at 03:43AM by playzeroseige
via reddit https://ift.tt/aF8iled
https://zeroseige.com/
Submitted July 12, 2025 at 03:43AM by playzeroseige
via reddit https://ift.tt/aF8iled
Reddit
From the netsec community on Reddit: ZeroSeige - Live PvP Terminal Hack Battle
Posted by playzeroseige - 3 votes and 0 comments
I built a tool to track web exposure — screenshots, HTML/JS diff, and alerts
https://reconsnap.com
Submitted July 12, 2025 at 03:08PM by oppai_silverman
via reddit https://ift.tt/y4GQciv
https://reconsnap.com
Submitted July 12, 2025 at 03:08PM by oppai_silverman
via reddit https://ift.tt/y4GQciv
Reddit
From the netsec community on Reddit: I built a tool to track web exposure — screenshots, HTML/JS diff, and alerts
Posted by oppai_silverman - 14 votes and 0 comments
From Blind XSS to RCE: When Headers Became My Terminal
https://ift.tt/WLY0swX
Submitted July 13, 2025 at 06:05AM by General_Speaker9653
via reddit https://ift.tt/cVL5v7D
https://ift.tt/WLY0swX
Submitted July 13, 2025 at 06:05AM by General_Speaker9653
via reddit https://ift.tt/cVL5v7D
Medium
From Blind XSS to RCE: When Headers Became My Terminal
Hello,
LLM crawlers continue to DDoS SourceHut
https://ift.tt/zlhTM1D
Submitted July 13, 2025 at 03:06PM by innpattag
via reddit https://ift.tt/Olg1Pny
https://ift.tt/zlhTM1D
Submitted July 13, 2025 at 03:06PM by innpattag
via reddit https://ift.tt/Olg1Pny
status.sr.ht
LLM crawlers continue to DDoS SourceHut | sr.ht status
We have deployed Anubis to git.sr.ht.
After some internal discussions we have ultimately decided that the best course
of action to protect git.sr.ht from LLM crawlers is to deploy Anubis. This
software presents some users with a proof-of-work challenge which…
After some internal discussions we have ultimately decided that the best course
of action to protect git.sr.ht from LLM crawlers is to deploy Anubis. This
software presents some users with a proof-of-work challenge which…
Historical Analysis of Reflected Vulnerabilities:The Evolution of Windows Defender Defenses
https://ift.tt/mCVRF2A
Submitted July 13, 2025 at 04:11PM by Chenn22
via reddit https://ift.tt/0bXaxG9
https://ift.tt/mCVRF2A
Submitted July 13, 2025 at 04:11PM by Chenn22
via reddit https://ift.tt/0bXaxG9
Zenodo
Historical Analysis of Reflected Vulnerabilities: The Evolution of Windows Defender Defenses
This report analyzes a historical class of security flaws known as “reflected vulnerabilities,”which were once potent zero-day attack vectors targeting early Windows versions and antivirussoftware. We examine classic exploitation techniques, such as parser…
Hello, excuse my intrusion, but I need help surfing the Internet. I found an encrypted code and it seems to contain some kind of page. I suppose because they give a password below, but I don't know what it is, could you help me please? I'll give you the link to the post in case you can help me https
https://ift.tt/eVvaUyz
Submitted July 14, 2025 at 01:32AM by No-Investigator-3445
via reddit https://ift.tt/egKUJhE
https://ift.tt/eVvaUyz
Submitted July 14, 2025 at 01:32AM by No-Investigator-3445
via reddit https://ift.tt/egKUJhE
KongTuke FileFix Leads to New Interlock RAT Variant
https://ift.tt/mS4hQz0
Submitted July 14, 2025 at 07:07AM by TheDFIRReport
via reddit https://ift.tt/2EBUfyq
https://ift.tt/mS4hQz0
Submitted July 14, 2025 at 07:07AM by TheDFIRReport
via reddit https://ift.tt/2EBUfyq
The DFIR Report
KongTuke FileFix Leads to New Interlock RAT Variant
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware,…
[CVE-2024-58258] SugarCRM <= 14.0.0 (css/preview) LESS Code Injection Vulnerability
https://ift.tt/hpS69Ur
Submitted July 14, 2025 at 01:30PM by eg1x
via reddit https://ift.tt/A5B3079
https://ift.tt/hpS69Ur
Submitted July 14, 2025 at 01:30PM by eg1x
via reddit https://ift.tt/A5B3079
Karmainsecurity
SugarCRM <= 14.0.0 (css/preview) LESS Code Injection Vulnerability | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Revisiting automating MS-RPC vulnerability research and making the tool open source
https://ift.tt/JDeck6g
Submitted July 14, 2025 at 02:01PM by TangeloPublic9554
via reddit https://ift.tt/dP7w1M2
https://ift.tt/JDeck6g
Submitted July 14, 2025 at 02:01PM by TangeloPublic9554
via reddit https://ift.tt/dP7w1M2
Remco van der Meer
Revisiting automating MS-RPC vulnerability research and releasing the tool
Partially solving the problem for procedures that need valid complex parameter types to fuzz, and open sourcing the tool
Fooling the Sandbox: A Chrome-atic Escape
https://ift.tt/p4K53WV
Submitted July 14, 2025 at 04:13PM by rkhunter_
via reddit https://ift.tt/LUqb198
https://ift.tt/p4K53WV
Submitted July 14, 2025 at 04:13PM by rkhunter_
via reddit https://ift.tt/LUqb198
STAR Labs
Fooling the Sandbox: A Chrome-atic Escape
For my internship, I was tasked by my mentor Le Qi to analyze CVE-2024-30088, a double-fetch race condition bug in the Windows Kernel Image ntoskrnl.exe. A public POC demonstrating EoP from Medium Integrity Level to SYSTEM is available on GitHub here.
Additionally…
Additionally…
New OpenSecurityTraining2 class: "Debuggers 1103: Introductory Binary Ninja"
https://ift.tt/SQ6FlOf
Submitted July 14, 2025 at 04:10PM by OpenSecurityTraining
via reddit https://ift.tt/nAQ3pqL
https://ift.tt/SQ6FlOf
Submitted July 14, 2025 at 04:10PM by OpenSecurityTraining
via reddit https://ift.tt/nAQ3pqL
p.ost2.fyi
Debuggers 1103: Introductory Binary Ninja
This course teaches you how to use the Binary Ninja debugger well enough to use it in classes that depend on it.