g3n3r4l11
-
Hacking Kerio Control via CVE-2024-52875: from CRLF Injection to 1-click RCE (karmainsecurity.com)
Exploring how CRLF Injection leads to remote code execution vulnerabilities in Kerio Control.
-
How to build an offensive AI security agent (anshumanbhartiya.com)
A guide to crafting AI-powered agents for offensive security operations.
-
Home Assistant can not be secured for internet access (frederikbraun.de)
A critical analysis of Home Assistant's internet access vulnerabilities.
-
Tic TAC - Beware of your scan (partywave.site)
Insights into security risks during scanning processes.
-
The Role of Fuzzy Hashes in Security Operations (blog.ecapuano.com)
Uncovering the potential of fuzzy hashes in identifying security threats.
-
I’m Lovin’ It: Exploiting McDonald’s APIs (eaton-works.com)
Examining vulnerabilities in McDonald’s API that allow delivery hijacking and penny orders.
-
Django security hardenings that are not happening (blog.hartwork.org)
A detailed review of missed security enhancements in Django.
-
Lesser known techniques for large-scale subdomain enum (docs.google.com)
Advanced techniques for subdomain enumeration.
-
How an obscure PHP footgun led to RCE in Craft CMS (assetnote.io)
Investigating a PHP vulnerability that caused remote code execution in Craft CMS.
-
Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150 (pentesterlab.com)
Discovering a JWT algorithm confusion vulnerability.
-
Web Hacking Service ‘Araneida’ Tied to Turkish IT Firm (krebsonsecurity.com)
Analysis of the Araneida hacking service and its links to Turkish IT firms.
X1
-
Advanced LLM capabilities in identifying and exploiting Linux vulnerabilities.
g1thub2
-
TrustedSec - Hate Crack (github.com)
A tool for automating cracking methodologies through Hashcat. Explore on GitHub
-
FindMy.py (github.com)
A comprehensive tool to query Apple's FindMy network. Explore on GitHub