LSASS Dump – Windows Error Reporting
https://ift.tt/O9UZu5W
Submitted November 18, 2025 at 10:47PM by netbiosX
via reddit https://ift.tt/VyGjqwT
https://ift.tt/O9UZu5W
Submitted November 18, 2025 at 10:47PM by netbiosX
via reddit https://ift.tt/VyGjqwT
Purple Team
LSASS Dump – Windows Error Reporting
The Windows Error Reporting is a feature that is responsible for the collection of information about system and application crashes and reporting this information to Microsoft. Windows are shipped …
Threat Actor "888" Claims LG Electronics Data Breach - Source Code and Hardcoded Credentials Allegedly Leaked [Unconfirmed]
https://ift.tt/Qbnde52
Submitted November 18, 2025 at 10:42PM by bagguheroine
via reddit https://ift.tt/JPFhAWR
https://ift.tt/Qbnde52
Submitted November 18, 2025 at 10:42PM by bagguheroine
via reddit https://ift.tt/JPFhAWR
Cyber Updates 365
LG Data Leak Claim: Threat Actor "888" Dumps Source Code - Cyber Updates 365
Threat actor "888" claims LG Electronics data leak with source code and credentials exposed. Analysis and security recommendations.
I analyzed Python packages that can be abused to build surveillance tools — here’s what I found
https://ift.tt/BacfwQi
Submitted November 19, 2025 at 05:56AM by kryakrya_it
via reddit https://ift.tt/4N7B0sF
https://ift.tt/BacfwQi
Submitted November 19, 2025 at 05:56AM by kryakrya_it
via reddit https://ift.tt/4N7B0sF
BlockHacks
Python packages to create extensive spy program
This article dives deep into the emerging threat of covert audio‑and‑video exfiltration hidden inside seemingly harmless PDF attachments and lightweight Python noscripts. It explains how attackers embed microphone listeners, webcam recorders, and motion‑triggered…
SupaPwn: Hacking Our Way into Lovable's Office and Helping Secure Supabase
https://ift.tt/TnYBZ7m
Submitted November 19, 2025 at 08:20AM by Mohansrk
via reddit https://ift.tt/na1c457
https://ift.tt/TnYBZ7m
Submitted November 19, 2025 at 08:20AM by Mohansrk
via reddit https://ift.tt/na1c457
Hacktron AI
SupaPwn: Hacking Our Way into Lovable's Office and Helping Secure Supabase
We hacked our way into Lovable's office by demoing SupaPwn — a chain that could potentially enable region-wide tenant takeover: event-trigger privilege window, DB superuser, host RCE, SUID escalation, exposed configs, orchestration takeover
request suggestions to detect bgp hijack events
http://ipiphistory.com
Submitted November 19, 2025 at 07:57AM by Gloomy-Initiative-80
via reddit https://ift.tt/QeITNGY
http://ipiphistory.com
Submitted November 19, 2025 at 07:57AM by Gloomy-Initiative-80
via reddit https://ift.tt/QeITNGY
Ipiphistory
Network IP Address, Asn isp Denoscription Search BGP HiJack BGP Routes RouteViews Ripe Data
IP, Prefix, Asn, isp denoscription, BGP Routes, BGP HiJack Search. All data comes from RouteViews and Ripe
Required Founding Expertise:
https://ift.tt/FBKztqP
Submitted November 19, 2025 at 10:28PM by RicanNative80
via reddit https://ift.tt/y7W86tx
https://ift.tt/FBKztqP
Submitted November 19, 2025 at 10:28PM by RicanNative80
via reddit https://ift.tt/y7W86tx
RCE via a malicious SVG in mPDF
https://ift.tt/EVmUuGS
Submitted November 20, 2025 at 01:18AM by ZoltyLis
via reddit https://ift.tt/PzewrH7
https://ift.tt/EVmUuGS
Submitted November 20, 2025 at 01:18AM by ZoltyLis
via reddit https://ift.tt/PzewrH7
Medium
RCE via a malicious SVG in mPDF
Bypassing a PHP stream wrapper blacklist
Exploiting A Pre-Auth RCE in W3 Total Cache For WordPress (CVE-2025-9501)
https://ift.tt/9A3kKFU
Submitted November 20, 2025 at 12:48AM by MrTuxracer
via reddit https://ift.tt/rMyN2Vq
https://ift.tt/9A3kKFU
Submitted November 20, 2025 at 12:48AM by MrTuxracer
via reddit https://ift.tt/rMyN2Vq
LITE XL RCE (CVE-2025-12121)
https://bend0us.github.io/vulnerabilities/lite-xl-rce/
Submitted November 20, 2025 at 04:08AM by LumpyElk1604
via reddit https://ift.tt/9gswTt5
https://bend0us.github.io/vulnerabilities/lite-xl-rce/
Submitted November 20, 2025 at 04:08AM by LumpyElk1604
via reddit https://ift.tt/9gswTt5
BEND0US Offensive Security Notes
Lite XL — Arbitrary Code & Remote Code Execution (CVE-2025-12120 & CVE-2025-12121)
Lite XL versions 2.1.8 and earlier contain vulnerabilities that allow arbitrary code execution and can lead to Remote Code Execution.
HelixGuard uncovers malicious "spellchecker" packages on PyPI using multi-layer encryption to steal crypto wallets.
https://ift.tt/B9DA8GO
Submitted November 20, 2025 at 09:06AM by Fit_Wing3352
via reddit https://ift.tt/Z6WXFRV
https://ift.tt/B9DA8GO
Submitted November 20, 2025 at 09:06AM by Fit_Wing3352
via reddit https://ift.tt/Z6WXFRV
Breaking Oracle’s Identity Manager: Pre-Auth RCE (CVE-2025-61757)
https://ift.tt/c0lorQU
Submitted November 20, 2025 at 08:48AM by Mempodipper
via reddit https://ift.tt/jRCzcSv
https://ift.tt/c0lorQU
Submitted November 20, 2025 at 08:48AM by Mempodipper
via reddit https://ift.tt/jRCzcSv
Searchlight Cyber
Breaking Oracle’s Identity Manager: Pre-Auth RCE (CVE-2025-61757) › Searchlight Cyber
Intro Earlier this year, in January, Oracle Cloud's login service (login.us2.oraclecloud.com) was breached—this led to the compromise of 6M records and over 140k Oracle Cloud tenants. Analysis showed that the threat actor had exploited an older CVE (CVE-2021…
Third-party failures are becoming the real threat to your security
https://ift.tt/3uCziN4
Submitted November 20, 2025 at 01:16PM by Reddit_INDIA_MOD
via reddit https://ift.tt/HCj4yP3
https://ift.tt/3uCziN4
Submitted November 20, 2025 at 01:16PM by Reddit_INDIA_MOD
via reddit https://ift.tt/HCj4yP3
Futurism Technologies
What the Cloudflare Outage Teaches Us About Cyber Resilience
On November 18, 2025, the digital world was shaken by an unexpected incident the Cloudflare outage. Cloudflare, one of the largest Content Delivery Networks (CDNs) in the world, suffered a major service disruption that impacted millions of websites and applications…
When Updates Backfire: RCE in Windows Update Health Tools
https://ift.tt/mBSefR0
Submitted November 20, 2025 at 12:46PM by vaizor
via reddit https://ift.tt/1EnUAuY
https://ift.tt/mBSefR0
Submitted November 20, 2025 at 12:46PM by vaizor
via reddit https://ift.tt/1EnUAuY
Eye Research
When Updates Backfire: RCE in Windows Update Health Tools
We discovered a remote code execution vulnerability in Microsoft's Update Health Tools (KB4023057) through an abandoned Azure Blob. Here’s how we found it, how it worked, and what it means for your Windows environment.
Unquoted Paths: The Decades-Old Windows Flaw Still Enabling Hidden Code Execution
https://ift.tt/T0SE964
Submitted November 21, 2025 at 01:17AM by runtimesec
via reddit https://ift.tt/cgaStvW
https://ift.tt/T0SE964
Submitted November 21, 2025 at 01:17AM by runtimesec
via reddit https://ift.tt/cgaStvW
Spektion
Unquoted Paths: The Decades-Old Flaw Still Enabling Hidden Code Execution
Unquoted paths (CWE-428) remain a hidden threat in today’s software. See how runtime visibility exposes what legacy vulnerability tools overlook
Esbuild XSS Bug That Survived 5B Downloads and Bypassed HTML Sanitization
https://ift.tt/OWvEufj
Submitted November 21, 2025 at 05:33AM by va_start
via reddit https://ift.tt/oHN6lKS
https://ift.tt/OWvEufj
Submitted November 21, 2025 at 05:33AM by va_start
via reddit https://ift.tt/oHN6lKS
Depthfirst
depthfirst | Esbuild's XSS Bug that Survived 5 Billion Downloads and Bypassed HTML Sanitization
In 2022, a subtle XSS bug slipped into esbuild, one of the most widely used JavaScript bundlers on the planet. Despite billions of downloads, it remained unnoticed, hiding inside a function that appeared to safely escape HTML. But a missing quote escape created…
Smooth upgrading of OWASP CRS3 to CRS4
https://ift.tt/QFVecNJ
Submitted November 21, 2025 at 02:42PM by dune73
via reddit https://ift.tt/j4CBYZP
https://ift.tt/QFVecNJ
Submitted November 21, 2025 at 02:42PM by dune73
via reddit https://ift.tt/j4CBYZP
Sliver C2 vulnerability enables attack on C2 operators through insecure Wireguard network
https://ift.tt/P8vc0nu
Submitted November 21, 2025 at 06:49PM by catmandx
via reddit https://ift.tt/A0B28kO
https://ift.tt/P8vc0nu
Submitted November 21, 2025 at 06:49PM by catmandx
via reddit https://ift.tt/A0B28kO
Hoang Nguyen
Sliver C2 Insecure Default Network Policy (CVE-2025-27093)
Summary Sliver is a powerful command and control (C2) framework designed to provide advanced capabilities for covertly managing and controlling remote systems.
Hitchhiker's Guide to Attack Surface Management
https://ift.tt/spULjDE
Submitted November 23, 2025 at 08:42AM by alt69785
via reddit https://ift.tt/WzY3aVP
https://ift.tt/spULjDE
Submitted November 23, 2025 at 08:42AM by alt69785
via reddit https://ift.tt/WzY3aVP
devansh
Hitchhiker's Guide to Attack Surface Management
I first heard about the word "ASM" (i.e., Attack Surface Management) probably in late 2018, and I thought it must be some complex infrastructure for tr...
[Tool] Native JSONL viewer for analyzing massive security logs (Suricata, Zeek, EDR) without infrastructure overhead
https://ift.tt/4HBpJnQ
Submitted November 23, 2025 at 12:17PM by hilti
via reddit https://ift.tt/8gqnZXJ
https://ift.tt/4HBpJnQ
Submitted November 23, 2025 at 12:17PM by hilti
via reddit https://ift.tt/8gqnZXJ
iotdata.systems
JSONL Viewer Pro - Fast Desktop Viewer for Security Logs & Large JSONL Files
The fastest way to explore and analyze JSONL files on your desktop. Perfect for security analysts, SOC teams, and DevOps engineers.
NocturneNotes — Secure Rust + GTK4 note‑taking with AES‑256‑GCM
http://www.jegly.xyz
Submitted November 23, 2025 at 04:34PM by reallylonguserthing
via reddit https://ift.tt/wP7HaWF
http://www.jegly.xyz
Submitted November 23, 2025 at 04:34PM by reallylonguserthing
via reddit https://ift.tt/wP7HaWF
Reddit
[ Removed by moderator ] : r/netsec
541K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise — to provide value to security practitioners, students, researchers, and hackers…
I Analysed Over 3 Million Exposed Databases Using Netlas
https://ift.tt/xj3bqds
Submitted November 23, 2025 at 03:49PM by AnyThing5129
via reddit https://ift.tt/kURwalQ
https://ift.tt/xj3bqds
Submitted November 23, 2025 at 03:49PM by AnyThing5129
via reddit https://ift.tt/kURwalQ
netlas.io
I Analysed Over 3 Million Exposed Databases Using Netlas - Netlas Blog
Analysing 3.2M exposed databases with Netlas to reveal global risks, failed controls, and exposure trends across major DB systems