g3n3r4l18
-
TrailDiscover (traildiscover.cloud)
world of trails with TrailDiscover.
-
GoFetch (gofetch.fail)
GoFetch vulnerability that affects Apple Silicon processors.
-
Year 2038 Problem (wikiwand.com)
Learn about the Year 2038 problem that could affect Unix-based systems.
-
The Guides to (mostly) Harmless Hacking (web.archive.org)
A classic resource for understanding hacking from a beginner's perspective.
-
Vulnerability Reward Program: 2023 Year in Review (security.googleblog.com)
Google's review of its Vulnerability Reward Program for 2023.
-
Real-time, privacy-preserving URL protection (security.googleblog.com)
Google's approach to real-time, privacy-preserving URL protection.
-
New chip flaw hits Apple Silicon (tomshardware.com)
A vulnerability named 'GoFetch' attacks Apple M1, M2, M3 processors.
-
SQL Injection in Prepared Statement - CVE-2024–1597 (cyberatlas.co)
A security vulnerability involving SQL injection in prepared statements.
-
Incident report on March 13, 2024 - Mintlify (mintlify.com)
A report on an incident that occurred on March 13, 2024.
-
JPEG DCT text lossifizer (lcamtuf.coredump.cx)
A tool for lossy text compression using JPEG DCT.
-
Javascript deobfuscation the easy way (medium.com)
A guide to easy JavaScript deobfuscation.
-
DOM Purify - untrusted Node bypass (blog.slonser.info)
A discussion on a vulnerability in DOM Purify.
-
Read code like a pro with our weAudit VSCode extension (blog.trailofbits.com)
Introducing the weAudit VSCode extension for code analysis.
-
Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762 (assetnote.io)
An analysis of a remote code execution vulnerability in FortiGate.
-
SVG Files Abused in Emerging Campaigns (cofense.com)
A discussion on the abuse of SVG files in emerging cyber campaigns.
-
Fuzzing Ladybird with tools from Google Project Zero (awesomekling.substack.com)
An exploration of fuzzing the Ladybird browser with tools from Google Project Zero.
-
CVE-2024-1800 (CVSS 9.9): Critical RCE Flaw Found in Popular Reporting Platform (securityonline.info)
A critical remote code execution flaw found in a popular reporting platform.
-
Google's Advanced Protection Program is great, it's a shame the company rarely mentions it (glitchcat.xyz)
A discussion on Google's Advanced Protection Program.
X1
-
Marc Stevens on X (@realhashbreaker)
"Here is a 72-byte alphanum MD5 collision with 1-byte difference for fun."
y0utube2
-
Intro to Lockpicking! (youtube.com)
A beginner's guide to lockpicking. Watch Here
-
GitHub Advanced Security: Code scanning autofix (youtube.com)
An overview of GitHub's code scanning and autofix features. Watch Here
g1thub6
-
jsmug: A PoC code for JSON Smuggling (github.com)
A proof of concept for smuggling arbitrary files through JSON. Explore on GitHub
-
DNS-Tunnel-Keylogger (github.com)
A keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes. Explore on GitHub
-
uBlockOrigin-HUGE-AI-Blocklist (github.com)
A huge blocklist of sites containing AI-generated content for uBlock Origin & uBlacklist. Explore on GitHub
-
grok-1: Grok open release (github.com)
The open release of Grok. Explore on GitHub
-
TinyCheck (github.com)
A tool for capturing and analyzing network communications from smartphones and other devices. Explore on GitHub
-
SpyGuard (github.com)
A forked and enhanced version of TinyCheck. SpyGuard's main objective is to detect signs of compromise by monitoring network flows transmitted by a device. Explore on GitHub