Microsoft is aware of active attacks targeting on-premises SharePoint Server customers, exploiting a variant of CVE-2025-49706. This vulnerability has been assigned CVE-2025-53770.
We have outlined mitigations and detections in our blog. Our team is working urgently to release…
CASE CLOSED: CVE-2025-29824
0 public samples, 0 information
Suspect: Windows CLFS driver
Crime: UAF leading to Privilege Escalation
Status: ACTIVELY EXPLOITED ITW
Investigation: Debugged and documented
Case files: starlabs.sg/blog/2025/07-m…
Done by our intern, Ong How Chong
A pre-auth RCE combining 2 critical vulnerabilities on the Production Environment extension of the PHP low-code website generator ScriptCase has been found by @noraj_rawsec and cabir. No upstream fix yet, please apply the workaround.
synacktiv.com/advisories/scr…
Are we bleeding out? Enjoy our analysis of CitrixBleed 2, aka CVE-2025-5777 - the "new" Citrix NetScaler Memory Leak vulnerability.
We've been using this mechanism to identify vulnerable systems, and hope it helps the teams that need it.. enjoy!
labs.watchtowr.com/how-much-more-…
(CVE-2025-2783)[405143032][mojo] Google Chrome Sandbox Escape(exploited ITW) is now open(PoC & exploit are restricted🥲)
issues.chromium.org/issues/4051430…
Reported by @oct0xor@2igosha https://t.co/fpjZ1qjsvn
Today @rapid7 is disclosing 8 new printer vulnerabilities affecting 742 models across 4 vendors. After 13 months of coordinated disclosure with Brother Industries, Ltd, we're detailing all issues including a critical auth bypass. Full details here: rapid7.com/blog/post/mult…
85 Followers 162 FollowingSecurity Researcher of Android Ecosystem.Finding 500+ CVEs past years. Google 2022 top bughunter. BlackHat 2021 Europe/2022 Aisa/2022 USA Speaker.
3K Followers 469 FollowingDefend Tomorrow, Secure Today!
Official Computer Emergency Response Team (CERT) for the Democratic People's Republic of Korea
#NorthSide #NorthKoreaBestKorea
85 Followers 162 FollowingSecurity Researcher of Android Ecosystem.Finding 500+ CVEs past years. Google 2022 top bughunter. BlackHat 2021 Europe/2022 Aisa/2022 USA Speaker.
2K Followers 540 FollowingBuilding valuable, hands-on learning experiences for 2000+ #cybersecurity specialists from all over the world.
Join us to educate, secure & change the world!
187K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
282 Followers 160 FollowingTN Security is the Premium research hub and acquisition platform for zero-day exploits and vulnerability research. We offer the highest bounties
1K Followers 242 FollowingA premier gathering of offensive cybersecurity professionals, researchers, thought leaders and innovators from around the region.
988 Followers 26 FollowingA new DC hacker conference: Bringing together builders, breakers, and fixers to do cool shit. 🪩 Year 1: January 24-25, 2026 🪩
https://t.co/qYKu4hl0Uj