g3n3r4l11
-
Wiz CTF: Cloud Hacking Challenges (wiz.io)
Sharpens skills via cloud hacking scenarios; earn certificates and build infosec reputations.
-
Django IPv6 DoS Vulnerability Analysis (archive.md)
Exploits missing input limits in IPv6 validation (CVE-2024–56374), allowing oversized payloads to trigger resource exhaustion and DoS in Django's address fields.
-
FileFix: ClickFix Attack Alternative (mrd0x.com)
Introduces FileFix for social engineering via Run Dialog execution, diving into ClickFix techniques for phishing operations.
-
CentOS Web Panel RCE (CVE-2025-48703) (fenrisk.com)
Discloses a remote code execution flaw in CWP, tracing its evolution from CentOS-focused to supporting AlmaLinux/Rocky Linux.
-
AI Uncovers Dassault Delmia Apriso RCE (hacktron.ai)
Hacktron found a pre-auth RCE missed by audits, demonstrating AI’s speed in exposing critical vulnerabilities like unprotected .svc files.
-
OWASP AI Agent Security Framework (agenticsecurity.info)
Maps NIST AI RMF to OWASP standards, offering threat analysis for securing agentic systems.
-
Semgrep MCP for Agentic Era Security (mcp.semgrep.ai)
Launches beta tools addressing agentic era risks in AI systems.
-
Detecting IP KVMs with RunZero (runzero.com)
Identifies open-source IP KVMs like TinyPilot for remote control, common in labs/SMBs.
-
Malicious GitHub MCP Servers Study (blog.virustotal.com)
VirusTotal found 8% of MCP servers potentially malicious or vulnerable due to poor practices.
-
North Korean npm Supply Chain Attack (socket.dev)
Exposes supply chain attack using 35 malicious packages; 6 remain live with 4k+ downloads.
-
Make Self-XSS Great Again - Slonser Notes (blog.slonser.info)
X1
-
Agentic Ecosystem Achieves 1-Click RCE (@OctagonNetworks)
@pwndotai enabled 1-click RCE in Cluely via indirect prompt injection. Watch Here
g1thub4
-
stamparm/ipsum (github.com)
Daily feed of bad IPs (with blacklist-hit scores). Explore on GitHub
-
NHAS/reverse\ssh (github.com)
SSH-based reverse shell. Explore on GitHub
-
Cybr-Inc/reinforce-2025-summaries (github.com)
Summaries and key insights from AWS re:inforce 2025 talks. Explore on GitHub
-
ANG13T/skytrack (github.com)
Cybersecurity toolkit for various security tasks. Explore on GitHub