g3n3r4l9
-
The widely used GitHub Action was compromised, causing affected repositories to leak secrets in logs, tracked as CVE-2025-30066. -
-
NEW No-Click Critical Vulnerability in Microsoft Windows: CVE-2025-21298 (hackers-arise.com)
A critical vulnerability in Microsoft Windows that doesn't require user interaction. -
-
In-Depth Technical Analysis of the Bybit Hack (nccgroup.com)
NCC Group provides a detailed technical breakdown of the Bybit cryptocurrency exchange hack. -
-
PostgreSQL Exploit (offsec.com)
OffSec details a new exploitation technique for PostgreSQL databases. -
-
Harden-Runner detection: tj-actions/changed-files action is compromised (stepsecurity.io)
StepSecurity's report on the compromised GitHub action and detection methods. -
-
Bypassing Web Filters Part 1: SNI Spoofing (blog.compass-security.com)
Compass Security explores techniques to bypass web filters using SNI spoofing. -
-
Detailed analysis of a remote code execution vulnerability in Apache Tomcat. -
-
Welcome to Security Week 2025 (blog.cloudflare.com)
Cloudflare announces its annual Security Week event for 2025. -
-
'\\a\\l\\ert' (perplexity.ai)
One leveraging invalid escapes - XSS payload technique using invalid escapes: parent - Go X
g1thub3
-
akamai/CVE-2025-27636-Apache-Camel-PoC (github.com)
Proof of concept for exploiting a vulnerability in Apache Camel. - Explore on GitHub
-
wh1ant/vulnjs (github.com)
A collection of vulnerable JavaScript code samples for security testing and education. - Explore on GitHub
-
t0sche/cvss-bt (github.com)
A tool for enriching the NVD CVSS scores to include Temporal & Threat Metrics. - Explore on GitHub