Modus Operandi of Subtle Snail Espionage Group
https://ift.tt/vFAUQkK
Submitted September 19, 2025 at 09:54PM by small_talk101
via reddit https://ift.tt/M1zgnNK
https://ift.tt/vFAUQkK
Submitted September 19, 2025 at 09:54PM by small_talk101
via reddit https://ift.tt/M1zgnNK
TENET CTF
https://ift.tt/jVyGXxL
Submitted September 20, 2025 at 12:08AM by Pretend-Inevitable93
via reddit https://ift.tt/u04pWPy
https://ift.tt/jVyGXxL
Submitted September 20, 2025 at 12:08AM by Pretend-Inevitable93
via reddit https://ift.tt/u04pWPy
Unstop
Capture The Flag - 2025 | 1557733 // Unstop
Find out the best Capture The Flag that match your interests. Prove your mettle and win exciting prizes like job opportunities and cash rewards from leading ... | 2025 | 1557733
Quite cool, apk.sh supports direct bytecode manipulation with no decompilation, this avoids recompilation errors when patching an Android APK.
https://shorturl.cc/dJv
Submitted September 20, 2025 at 04:23AM by Happy_Youth_1970
via reddit https://ift.tt/bJp23Pq
https://shorturl.cc/dJv
Submitted September 20, 2025 at 04:23AM by Happy_Youth_1970
via reddit https://ift.tt/bJp23Pq
Linux Kernel Runtime Guard (LKRG) 1.0 first mature release + talk slides
https://ift.tt/2sPaxMg
Submitted September 21, 2025 at 04:58AM by solardiz
via reddit https://ift.tt/i4ASvNz
https://ift.tt/2sPaxMg
Submitted September 21, 2025 at 04:58AM by solardiz
via reddit https://ift.tt/i4ASvNz
Pentesting Weekly Digest second version
https://ift.tt/rzqoky5
Submitted September 21, 2025 at 07:06AM by Western-Fox-5184
via reddit https://ift.tt/cphYNAG
https://ift.tt/rzqoky5
Submitted September 21, 2025 at 07:06AM by Western-Fox-5184
via reddit https://ift.tt/cphYNAG
Substack
Pentesting Weekly Digest — September 13–19, 2025
Another week, another mix of hardware-level hacks, fresh zero-days, and even law-enforcement news. Let’s break down what mattered most.
EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State
https://ift.tt/uAW8CHJ
Submitted September 21, 2025 at 08:52AM by Cold-Dinosaur
via reddit https://ift.tt/5VWg6H1
https://ift.tt/uAW8CHJ
Submitted September 21, 2025 at 08:52AM by Cold-Dinosaur
via reddit https://ift.tt/5VWg6H1
Zerosalarium
EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State
EDR-Freeze exploits the vulnerability of WerFaultSecure to suspend the processes of EDRs and Antimalware, halting the operation of Antivirus and EDR
New Infostealer Campaign Targeting Mac Users via GitHub Pages Claiming to Offer LastPass Premium
https://ift.tt/vm82sig
Submitted September 22, 2025 at 08:13AM by shantanu14g
via reddit https://ift.tt/57TgzBP
https://ift.tt/vm82sig
Submitted September 22, 2025 at 08:13AM by shantanu14g
via reddit https://ift.tt/57TgzBP
Lastpass
Large-Scale Attack Targeting Macs via GitHub Pages Impersonating Companies to Attempt to Deliver Stealer Malware - The LastPass…
Were tracking an ongoing, widespread infostealer campaign targeting Mac users through fraudulent GitHub repositories.
Electron App Vulnerabilities testcases
https://blog.securelayer7.net/electron-app-security-risks/
Submitted September 22, 2025 at 10:52AM by Ok_Air_3932
via reddit https://ift.tt/j2Qo1kY
https://blog.securelayer7.net/electron-app-security-risks/
Submitted September 22, 2025 at 10:52AM by Ok_Air_3932
via reddit https://ift.tt/j2Qo1kY
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
Electron Research in Desktop apps [Part 1]
What's electron?, the design of electron desktop app, the story bug of the bug, the static code of the bug and how to find it, how to develop it and explain the code, explain how to discover it,...
The God Mode Vulnerability That Should Kill “Trust Microsoft” Forever
https://ift.tt/TVdEsFo
Submitted September 22, 2025 at 10:36AM by tidefoundation
via reddit https://ift.tt/dD1l2z5
https://ift.tt/TVdEsFo
Submitted September 22, 2025 at 10:36AM by tidefoundation
via reddit https://ift.tt/dD1l2z5
Medium
The God Mode Vulnerability That Should Kill “Trust Microsoft” Forever
Why vendors can’t and shouldn’t be trusted
Journeys in Hosting 1/x - Precomputed SSH Host Keys
https://ift.tt/ZPwrCXF
Submitted September 23, 2025 at 03:35AM by jtkchicago
via reddit https://ift.tt/t8BjuDS
https://ift.tt/ZPwrCXF
Submitted September 23, 2025 at 03:35AM by jtkchicago
via reddit https://ift.tt/t8BjuDS
dataplane.org
John Kristoff - Journeys in Hosting 1/x - Precomputed SSH Host Keys
BlackLock Ransomware: From Meteoric Rise to Sudden Disruption
https://ift.tt/TDgpobR
Submitted September 23, 2025 at 01:05PM by Koyaanisquatsi_
via reddit https://ift.tt/56LtDs4
https://ift.tt/TDgpobR
Submitted September 23, 2025 at 01:05PM by Koyaanisquatsi_
via reddit https://ift.tt/56LtDs4
Wealthari
BlackLock Ransomware: From Meteoric Rise to Sudden Disruption
BlackLock has quickly climbed the ranks in the global ransomware scene, setting new benchmarks for attack frequency and technical complexity. Emerging in March 2024 under the name El Dorado, t…
Image Forensics: Detecting AI Fakes with Compression Artifacts
https://ift.tt/SWn7AEL
Submitted September 23, 2025 at 10:17PM by Doch88
via reddit https://ift.tt/rPoThLs
https://ift.tt/SWn7AEL
Submitted September 23, 2025 at 10:17PM by Doch88
via reddit https://ift.tt/rPoThLs
Tea continued - Unauthenticated access to 150+ Firebase databases, storage buckets and secrets
https://ift.tt/5D06Evc
Submitted September 24, 2025 at 12:14AM by Woowowow91
via reddit https://ift.tt/CQHYdku
https://ift.tt/5D06Evc
Submitted September 24, 2025 at 12:14AM by Woowowow91
via reddit https://ift.tt/CQHYdku
ice0.blog
Tea continued - Unauthenticated access to 150+ Firebase databases, storage buckets and secrets
Introducing OpenFirebase - Time to clean up the Firebase mess
Learn to hack
https://ift.tt/AhVFp2o
Submitted September 24, 2025 at 03:07AM by wxnnerjx
via reddit https://ift.tt/aIp3jkL
https://ift.tt/AhVFp2o
Submitted September 24, 2025 at 03:07AM by wxnnerjx
via reddit https://ift.tt/aIp3jkL
Tiantong-1 and satphone security: Part 2
https://ift.tt/W2sVg6G
Submitted September 24, 2025 at 03:08PM by 2ROT13
via reddit https://ift.tt/JB4WvVK
https://ift.tt/W2sVg6G
Submitted September 24, 2025 at 03:08PM by 2ROT13
via reddit https://ift.tt/JB4WvVK
www.midnightblue.nl
Tiantong-1 and satphone security: part 2
We will delve into general satphone SIGINT capabilities, supply chain security, and security aspects of the latest Huawei Mate Tiantong-enabled smartphones.
New macOS threat abuses ads and social media to spread malware
https://ift.tt/L0k3E9O
Submitted September 24, 2025 at 07:09PM by Individual-Gas5276
via reddit https://ift.tt/MHdDOvV
https://ift.tt/L0k3E9O
Submitted September 24, 2025 at 07:09PM by Individual-Gas5276
via reddit https://ift.tt/MHdDOvV
Moonlock
Apple's new anti-spyware feature is out
Built-into all iPhone Air, iPhone 17 and 17 Pro.
Is This Bad? This Feels Bad. (GoAnywhere CVE-2025-10035) - watchTowr Labs
https://ift.tt/n1KOgue
Submitted September 24, 2025 at 06:34PM by dx7r__
via reddit https://ift.tt/Jm0KtVE
https://ift.tt/n1KOgue
Submitted September 24, 2025 at 06:34PM by dx7r__
via reddit https://ift.tt/Jm0KtVE
watchTowr Labs
Is This Bad? This Feels Bad. (Fortra GoAnywhere CVE-2025-10035)
File transfer used to be simple fun - fire up your favourite FTP client, log in to a glFTPd site, and you were done.
Fast forward to 2025, and the same act requires a procurement team, a web interface, and a vendor proudly waving their Secure by Design pledge.…
Fast forward to 2025, and the same act requires a procurement team, a web interface, and a vendor proudly waving their Secure by Design pledge.…
ReDisclosure: New technique for exploiting Full-Text Search in MySQL (myBB case study)
https://ift.tt/sx5qGjf
Submitted September 25, 2025 at 02:42AM by Difficult-Catch9885
via reddit https://ift.tt/HS4jQvY
https://ift.tt/sx5qGjf
Submitted September 25, 2025 at 02:42AM by Difficult-Catch9885
via reddit https://ift.tt/HS4jQvY
Exploit Azerbaijan
ReDisclosure: New technique for exploiting Full-Text Search in MySQL (myBB case study)
"Even a small key can open a big lock" Azerbaijani Proverb ---[ Index 1 - Introduction 2 - Tradition 2.1 - ReDoS, not the OS 2.2 - REGEXP, RLIKE and others 3 - How insecure, secure implementations are? 4 - Study Case: myBB 4.1 - Identification 4.2 - Perfect…
Why “contained” doesn’t mean “safe” in modern SOCs
https://ift.tt/9FYygKq
Submitted September 25, 2025 at 02:42PM by SuccessfulMountain64
via reddit https://ift.tt/i30ETMP
https://ift.tt/9FYygKq
Submitted September 25, 2025 at 02:42PM by SuccessfulMountain64
via reddit https://ift.tt/i30ETMP
Yet Another Random Story. VBScript's Randomize Internals.
https://ift.tt/23RTENl
Submitted September 25, 2025 at 04:20PM by nibblesec
via reddit https://ift.tt/1KeaW5q
https://ift.tt/23RTENl
Submitted September 25, 2025 at 04:20PM by nibblesec
via reddit https://ift.tt/1KeaW5q
Doyensec
Yet Another Random Story: VBScript's Randomize Internals
In one of our recent posts, Dennis shared an interesting case study of C# exploitation that rode on Random-based password-reset tokens. He demonstrated how to use the single-packet attack, or a bit of old-school math, to beat the game. Recently, I performed…
Hacking Furbo - A Hardware Research Project – Part 5: Exploiting BLE
https://ift.tt/Nc6SVbM
Submitted September 25, 2025 at 04:01PM by duduywn
via reddit https://ift.tt/ZXq9HLC
https://ift.tt/Nc6SVbM
Submitted September 25, 2025 at 04:01PM by duduywn
via reddit https://ift.tt/ZXq9HLC
Softwaresecured
Hacking Furbo - A Hardware Hacking Research Project – Part 5: Exploiting BLE
This post analyzes Furbo’s BLE communication, uncovering flaws that expose Wi-Fi credentials, allow device resets, and reveal hidden GATT data.