g3n3r4l19
-
InfoconDB Security Information Database (infocondb.org)
InfoconDB is a database and resource for security information and conference data. Explore
-
Bypassing CSP with JSONP Exploits (blackhillsinfosec.com)
Introducing JSONPeek and CSP B Gone tools to bypass Content Security Policies using JSONP endpoints, demonstrating a novel exploitation technique.
-
Zendesk Android App Mass Account Takeover (blog.voorivex.team)
Details a 0-click exploit granting access to all Zendesk tickets via the Android app, a critical account takeover vulnerability.
-
Malicious ghrc.io Domain Analysis (bmitch.net)
Investigation reveals the ghrc.io domain appears to be malicious, posing a potential supply chain threat to developers.
-
Apple DNG Vulnerability and Threat Detection (msuiche.com)
Deep dive into CVE-2025-43300's DNG processing flaw and detecting the ELEGANTBOUNCER threat without samples, highlighting advanced forensic techniques. msuiche.com
-
AI-Powered Ransomware Proof-of-Concept Emerges (theregister.com)
First spotted AI-powered ransomware PoC uses automated targeting and negotiation, marking a new evolution in cyber threats.
-
Microsoft Partner Leak Exposes Employee PII (blog.faav.top)
A leak from a Microsoft partner exposed employee PII and over 700 million partner records, a massive data exposure.
-
Vtenext 25.02 Multiple RCE Paths (blog.sicuranext.com)
Analysis reveals a three-way path to remote code execution in Vtenext 25.02, a critical software vulnerability.
-
The s1ngularity attack leaked secrets on GitHub, a significant supply chain incident affecting numerous projects.
-
PyPI Prevents Domain Resurrection Attacks (blog.pypi.org)
The Python Package Index implements measures for preventing domain resurrection attacks, enhancing ecosystem security.
-
RubyGems.org OSS Infrastructure Protection (blog.rubygems.org)
How RubyGems.org protects critical open-source infrastructure, detailing their security response and community safeguards.
-
Hunting postMessage Vulnerabilities Guide (blog.ryukudz.com)
First part of a guide on hunting postMessage vulnerabilities, a common client-side attack vector.
-
How to Rob a Hotel Physical Pentest (dmcxblue.net)
A story and analysis from a physical penetration test, illustrating how to rob a hotel.
-
SANS Notes Increase in ZIP File Searches (isc.sans.edu)
The SANS Internet Storm Center diaries note an increasing searches for ZIP files, a potential malware distribution trend.
-
Claude Code WebSocket Auth Bypass (securitylabs.datadoghq.com)
CVE-2025-52882 details a WebSocket authentication bypass in Claude Code extensions, a critical MCP vulnerability.
-
Anthropic Detects and Counters AI Misuse (anthropic.com)
August 2025 update on detecting and countering misuse of AI, outlining new threats and mitigation strategies from Anthropic.
-
Agentic Browser Indirect Prompt Injection (web.archive.org)
Investigate Agentic Browser Security vulnerabilities, specifically indirect prompt injection in Perplexity Comet. This highlights how AI agents can be manipulated through external content.
-
Perplexity Comet Indirect Prompt Injection (brave.com)
Brave Security Labs discusses Agentic Browser Security, focusing on indirect prompt injection in Perplexity Comet. This vulnerability allows for manipulation of AI agents via embedded content.
-
Inline Style Exfiltration Research (portswigger.net)
PortSwigger research on leaking data with chained CSS conditionals, a novel inline style exfiltration technique. Explore on GitHub
X4
-
Chrome Logic Sandbox Escape $250k Bounty (@zerodaytraining)
Bug spotlight on a Chrome Ipcz cross-process handle spoofing issue, a severe sandbox escape earning a $250,000 bounty. Watch Here
-
PromptLock Ransomware Uses Lua Scripts (@ESETresearch)
ESET Research details how PromptLock leverages cross-platform Lua scripts to enumerate, exfiltrate, and encrypt data on Windows, Linux, and macOS. Watch Here
-
Novel LLM System Prompt Insertion Jailbreak (@LLMSherpa)
A novel jailbreak using prompt insertion, not injection, into the actual system prompt, making defenses nearly impossible. Watch Here
-
YubiKey OATH App as File Storage (@RandomDhiraj)
The YubiKey OATH app allows naming accounts with base64, turning it into a tiny covert file storage for red teams. Watch Here
y0utube1
-
Hacking Google to Delete Search Results (youtube.com)
A video demonstrating a method for hacking Google to delete ANY search result, a significant SEO and reputation manipulation vulnerability. Watch Here
g1thub6
-
Exotic XSS Techniques Repository (github.com)
A GitHub repository dedicated to exotic XSS techniques, a resource for advanced web application security testing. Explore on GitHub
-
Phishing Template Workbench on GitHub (github.com)
The phishingclub/templates repo provides a phishing template workbench for security testing and awareness simulations. Explore on GitHub
-
CVE-2025-57752 GitHub Advisory (github.com)
GitHub Advisory for CVE-2025-57752, detailing a specific security vulnerability and its patches. Explore on GitHub
-
Phrack CTF Binary Exploitation Challenge (github.com)
The chompie1337/PhrackCTF repo contains a binary exploitation challenge from Phrack CTF. Explore on GitHub
-
Legba Multiprotocol Credentials Bruteforcer (github.com)
The evilsocket/legba tool is a fast multiprotocol credentials bruteforcer, password sprayer, and enumerator. Explore on GitHub
-
ChatGPT Dan Jailbreak Gist (gist.github.com)
A gist containing the ChatGPT-Dan-Jailbreak, a known method for bypassing AI content restrictions. Explore on GitHub