g3n3r4l14
-
0day.today Security Archive Database (0day-archive.fullhunt.io)
A searchable archive of security vulnerabilities and exploits. 0day.today
-
ZeroDay Cloud Hacking Competition (zeroday.cloud)
Details for the ZeroDay Cloud hacking competition focused on cloud security.
-
In Memory of Aaron Swartz (restincode.com)
A memorial page honoring the life and work of Aaron Swartz. Rest In Code
-
Tesla Telematics ADB Auth Bypass (nccgroup.com)
A technical advisory details an ADB auth bypass vulnerability in the Tesla Telematics Control Unit, allowing unauthorized access.
-
VMware Elevation of Privilege Vulnerability (blog.nviso.eu)
Analysis of CVE-2025-41244, a VMware elevates it vulnerability leading to local privilege escalation on Workstation and Fusion.
-
Abusing Notion AI Agent Data Theft (schneier.com)
A blog post discusses how Notion's AI Agent can be abused for data theft, extracting sensitive information from documents.
-
CSS Crimes for Fun and Profit (lyra.horse)
A slide deck presentation on committing CSS crimes for creative and potentially malicious web effects.
-
Shellshock Vulnerability Deep Dive (dwheeler.com)
An in-depth essay exploring the history and technical details of the Shellshock bash vulnerability.
-
Crypto Phishing Campaign Robots.txt Exposure (censys.com)
An investigation into a crypto phishing campaign that attempted to block security researchers via its robots.txt file.
-
Okta Identity Security Policies Guide (darkreading.com)
A security researcher's guide to understanding and navigating Okta Identity Security Policies.
-
Klopatra Android Banking Trojan Operation (cleafy.com)
Exposure of a new Android banking trojan operation named Klopatra, with roots in Turkey, targeting financial applications.
-
Gemini Vulnerabilities Private Data Exfiltration (tenable.com)
Three new Gemini vulnerabilities in Cloud Assist, Search Model, and Browsing allowed for private data exfiltration from Google's AI.
-
FreeWifi\Secure Killer Vulnerability Analysis (7h30th3r0n3.fr)
An analysis of the vulnerability that killed the FreeWifi\Secure service, detailing the security flaw and its impact.
-
Unity Runtime Arbitrary Code Execution (flatt.tech)
Details on CVE-2025-59489, an arbitrary code execution vulnerability within the Unity Runtime.
X1
-
Vulnerable Vibe-Coded App Audit (@S1r1u5_)
An audit of a "vibe-coded" application revealed an insane amount of vulnerabilities, including SQLi, SSRF, and command injection. Watch Here
y0utube1
-
The History of GREP Tool (youtube.com)
A video exploring the origins and history of the GREP command-line tool. Watch Here
g1thub12
-
Grep.app Command Line Utility (github.com)
A command line util for grep.app enabling powerful searches across a vast repository index directly from the terminal. Explore on GitHub
-
Adobe Experience Manager Hacking Toolkit (github.com)
Hopgoblin is an AEM hacking toolkit for security testing and exploiting Adobe Experience Manager instances. Explore on GitHub
-
N-day Exploit Collection Repository (github.com)
A collection of n-day exploits and related security research. Explore on GitHub
-
CI/CD Secret Extraction via Pipelines (github.com)
Nord Stream extracts secrets stored inside CI/CD environments by deploying malicious pipelines for Azure DevOps, GitHub, and GitLab. Explore on GitHub
-
ReDoS Vulnerability Finder Tool (github.com)
Regexploit finds regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service). Explore on GitHub
-
Tailscale SOCKS5 Proxy for Red Teams (github.com)
SockTail is a lightweight binary that joins a Tailscale network and exposes a local SOCKS5 proxy for red team operations. Explore on GitHub
-
Nmap Setuid Backdoor via Lua (github.com)
A backdoor that leverages Nmap with setuid permissions to execute commands as root through a Lua-loaded C library. Explore on GitHub
-
Multi-Architecture Emulation Platform (github.com)
Styx is a multi-architecture emulator designed for the modern era. Explore on GitHub
-
iOS Zero-Click RCE Attack Chain (github.com)
Exploits for CVE-2025-31200, a zero-click RCE in iOS CoreAudio, and CVE-2025-31201 for kernel escalation, triggered via iMessage. Explore on GitHub
-
Active Directory DNS Dumping Tool (github.com)
Adidnsdump allows Active Directory Integrated DNS dumping by any authenticated user. Explore on GitHub
-
Gemini API Key Exposure Scanner (github.com)
A scanner to check for exposed Gemini API keys in public sources. Explore on GitHub
-
Automated Firebase Security Scanner (github.com)
OpenFirebase is an automated scanner to check for unauthorized read and write access on Firestore, databases, and storage. Explore on GitHub