g3n3r4l27
-
teXt0wnz Utility (text.0w.nz)
Introducing teXt0wnz, a utility for various text-based operations and potential security analyses. Go
-
Heatmap Diff Viewer for Code (0github.com)
Introducing A heatmap diff viewer designed to enhance code review processes by visualizing changes effectively. Go
-
https://docs.cloud.google.com/vertex-ai/generative-ai/docs/security-bulletinsgcp-2025-059 (docs.cloud.google.com)
China Vuln Research, OPSEC, Google Engineer Thinking – Explore China's changing vulnerability research, common OPSEC pitfalls for intelligence agencies, and gain insights into the mindset of a Google Security Engineer. Read More )
-
SessionReaper Exploit for Magento 2 (pentest-tools.com)
A detailed write-up on how an exploit was built for SessionReaper, CVE-2025-54236, affecting Magento 2 and Adobe Commerce environments.
-
CoPhish Attack on Copilot Studio (cyberupdates365.com)
Learn about the CoPhish Attack exploiting Microsoft Copilot Studio's OAuth for theft.
-
TOLLBOOTH IIS Mine Exploitation (elastic.co)
TOLLBOOTH research from Elastic Security Labs detailing exploitation of IIS.
-
WSO2 Arbitrary File Read Exploit (crnkovic.dev)
Uncover how a 404 error in WSO2 can be escalated to achieve an arbitrary file read vulnerability.
-
Hacking Team Back: Dante Spyware (securelist.com)
The Hacking Team is back! Investigate the resurgence of this APT group, now employing Dante spyware in "Mem3nt0 mori" attacks.
-
Benchmarking LLMs for Malware Analysis (ai.meta.com)
Meta's research introduces CyberSOCEval, a new benchmark for evaluating LLMs capabilities for malware analysis and threat intelligence reasoning.
-
It's Not Always DNS (notes.pault.ag)
A reflection on troubleshooting and the common misconception that network issues are always DNS.
-
Hacking India's Tata Motors (eaton-works.com)
A case study detailing the hacking of India's largest automaker, Tata Motors, exposing significant vulnerabilities.
-
Next.js Mutated Middleware Vulnerabilities (blog.rootsys.at)
Diving into vulnerabilities found in Next.js applications due to mutated middleware behavior.
-
Don't Leave Me Outdated (tuxplorer.com)
A critical reminder and guide to keeping systems and software updated, emphasizing, "Don't Leave Me Outdated!"
-
TRUfusion Enterprise Pre-Auth Vulnerabilities (rcesecurity.com)
Analysis of four critical pre-auth vulnerabilities found in TRUfusion Enterprise, highlighting how audits can sometimes fail.
-
TikTok RCE Android Pentesting (dphoeniixx.medium.com)
A practical case study on Android Pentesting, demonstrating a Remote Code Execution (RCE) vulnerability in TikTok.
-
Unlocking British Airways Free WiFi (saxrag.com)
A technical breakdown on the methods used for unlocking free WiFi services aboard British Airways flights.
-
Claude API Data Exfiltration (embracethered.com)
Detail on "Claude Pirate," an abuse of Anthropic's File API for data exfiltration by exploiting network access.
-
Attacking Self-Hosted GitLab CI/CD (risk3sixty.com)
Strategies for attacking and defending self-hosted GitLab CI/CD environments, offering insights for both red and blue teams.
-
DNS Rebinding in Chrome/Safari (intruder.io)
Advanced tricks for reliable split-second DNS rebinding exploits in Chrome and Safari browsers.
-
Exploiting Syntax Confusion Vulnerabilities (yeswehack.com)
"minefield between syntaxes" and how to exploit ambiguous parsing for syntax confusion vulnerabilities.
-
AI Browsers Cybersecurity Time Bomb (archive.fo)
A warning that AI browsers represent a significant cybersecurity time bomb due to inherent privacy and security risks.
-
Botnet Shifts, Zeus Coder Arrested (krebsonsecurity.com)
The Aisuru Botnet shifts from DDoS to residential proxies, while the alleged Jabber Zeus Coder 'MrICQ' is now in U.S. Custody.
-
Tricks, Treats, and Terabits (hackerfactor.com)
A blog post discussing various security tricks, treats, and terabits related to Halloween and cybersecurity.
-
DepiConf Dependency Confusion Checker (app.jsmon.sh)
DepiConf provides an online tool to easily check for potential dependency confusion vulnerabilities.
-
OpenAI Aardvark Security Researcher (openai.com)
OpenAI introduces Aardvark, an agentic security researcher designed to identify and mitigate vulnerabilities autonomously.
-
Understanding AI-Native SAST (parsiya.net)
A deep dive into the concept of "AI-Native SAST" and its implications for static application security testing.
-
Electronic Passport Cryptography Explained (blog.trailofbits.com)
An explanation of the complex cryptography behind electronic passports, detailing their security mechanisms.
y0utube1
-
Russia's Unit 29155 Spy Hotel (youtube.com)
An in-depth look into Russia's Spy Hotel and the activities of Unit 29155 in this episode. Watch Here
g1thub1
-
Kubernetes Attack Paths & Vulnerability Tools (github.com)
attack paths with KubeHound, tools for the Go vulnerability database, a TARmageddon CVE exploit, and a Terraform to Mermaid diagram utility. Explore on GitHub