🚨 New advisory was just published! 🚨
A vulnerability exists in processing IRP_MJ_CREATE requests in driver clfs.sys which could lead to privilege escalation:
ssd-disclosure.com/ssd-advisory-w…
Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn_ and @wil_fri3d.
synacktiv.com/publications/n…
New CS Blog - Revisiting the UDRL Part 3: cobaltstrike.com/blog/revisitin… If you like the idea of loading a custom c2 channel in your UDRL then this blog may be of interest 👀
23 new Windows endpoint behavior detections/protections added - covering a variety of TTPs (including #grimresource shellghost and more)
github.com/elastic/protec…
#يوم_عرفة 🤍
صيامه يكفر سنتين السنة الماضية والسنة القادمة فلا تنشغل عن هذا اليوم وأكثر من قول لا إله إلا الله وحده لا شريك له له الملك وله الحمد وهو على كل شيء قدير
كن سبب في تذكير غيرك فالدال على الخير كفاعله
reconFTW v2.9 is released!
New features:
- API leaks
- 3rd party misconfigurations
- JS source maps
- IIS Shortnames
- Mindmap updated
- p1radup added
- Nuclei fuzzing
As always, a ton of fixes and improvements :)
github.com/six2dez/reconf…#reconftw #bugbounty#hacking#recon
APK Url Grep
When gathering information about a company, it is worth researching not only its website, but also its mobile apps (to find subdomains of the main website and potentially related websites).
github.com/ndelphit/apkur…
Creator @gattardi#go
[CVE-2024-26229] Windows #LPE (PoC)
CWE-781: Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code in the csc.sys driver
github.com/varwara/CVE-20…
⚠️⚠️⚠️WARNING! Exploit Drop 🔥@watchtowrcyber does it again!💪 Here is the exploit🩸for the latest php-cgi RCE, shout out to @orange_8361 🍊 for always surprising the world with his top notch research ⭐️
⚠️⚠️⚠️WARNING! Exploit Drop 🔥@watchtowrcyber does it again!💪 Here is the exploit🩸for the latest php-cgi RCE, shout out to @orange_8361 🍊 for always surprising the world with his top notch research ⭐️
😲 Stephen Fewer of Rapid7 has shared the POC for my for Unauth RCE in Rejetto HTTP File Server 2.3m!
👉 github.com/rapid7/metaspl…
👉 mohemiv.com/all/rejetto-ht…
CVE: CVE-2024-23692
🚨 After an adjustment, RCE can now be achieved via SSRF without modifying the Host header! ⬇️
10 Followers 174 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/wZiXjzJDs2
113 Followers 1K Following💡 Panduan bijak mengharungi cabaran ekonomi.
📊 Tip kewangan, strategi krisis, & inspirasi untuk masa depan yang lebih teguh.
#BijakKrisis
1K Followers 6K Followinghttps://www.agicent.com- Mobile Apps development company for startups and enterprise, creating awesome iOS and Android Apps and websites.
1K Followers 2K FollowingSnoopGod #Linux it is a free #opensource community project with the aim of promoting the culture of #cybersecurity #pentesting and #ethicalhacking
161 Followers 19 FollowingPut your hacking skills to the test in this online cybersecurity competition. Win prizes while developing your computer science skills!
21K Followers 4 FollowingTeaching the next generation of web3 developers.
150+ hours of Smart Contract Development and Security Courses, completely for Free.
Powered by @cyfrinaudits
16K Followers 15 FollowingSecurity reviews and research that keep winners winning. We apply unmatched hacking talent to secure critical software for the most innovative teams.
1K Followers 1K FollowingCTFer / APT hunter / RedTeam / BlueTeam
the member of @r3kapig
the leader of @ShadowChasing1
CVE:CVE-2022-30190
pre account @CrazymanArmy