ar
Feedback

لا تقع ضحية للمخادعين! تيليمتريو يكتشف ويُميّز هذه القنوات 👉 إذا كنت تريد رؤية العلامة، اشترك 👈

İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

الذهاب إلى القناة على Telegram

Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.

إظهار المزيد
1 128
المشتركون
-124 ساعات
+27 أيام
+2130 أيام

جاري تحميل البيانات...

جذب المشتركين
أكتوبر '26
أكتوبر '26
+8
في 0 قنوات
سبتمبر '26
+46
في 0 قنوات
Get PRO
أغسطس '26
+43
في 0 قنوات
Get PRO
يوليو '26
+45
في 0 قنوات
Get PRO
يونيو '26
+29
في 0 قنوات
Get PRO
مايو '26
+57
في 0 قنوات
Get PRO
أبريل '26
+65
في 0 قنوات
Get PRO
مارس '26
+45
في 0 قنوات
Get PRO
فبراير '26
+38
في 1 قنوات
Get PRO
يناير '26
+46
في 0 قنوات
Get PRO
ديسمبر '25
+30
في 0 قنوات
Get PRO
نوفمبر '250
في 0 قنوات
Get PRO
أكتوبر '250
في 0 قنوات
Get PRO
سبتمبر '250
في 0 قنوات
Get PRO
أغسطس '250
في 0 قنوات
Get PRO
يوليو '250
في 0 قنوات
Get PRO
يونيو '250
في 0 قنوات
Get PRO
مايو '250
في 0 قنوات
Get PRO
أبريل '250
في 0 قنوات
Get PRO
مارس '250
في 0 قنوات
Get PRO
فبراير '250
في 0 قنوات
Get PRO
يناير '250
في 0 قنوات
Get PRO
ديسمبر '240
في 0 قنوات
Get PRO
نوفمبر '24
+88
في 0 قنوات
Get PRO
أكتوبر '24
+129
في 0 قنوات
Get PRO
سبتمبر '24
+53
في 0 قنوات
Get PRO
أغسطس '24
+48
في 0 قنوات
Get PRO
يوليو '24
+54
في 0 قنوات
Get PRO
يونيو '24
+46
في 0 قنوات
Get PRO
مايو '24
+53
في 0 قنوات
Get PRO
أبريل '24
+48
في 0 قنوات
Get PRO
مارس '24
+68
في 0 قنوات
Get PRO
فبراير '24
+83
في 0 قنوات
Get PRO
يناير '24
+70
في 0 قنوات
Get PRO
ديسمبر '23
+264
في 0 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
08 أكتوبر0
07 أكتوبر0
06 أكتوبر0
05 أكتوبر+1
04 أكتوبر+1
03 أكتوبر+2
02 أكتوبر+2
01 أكتوبر+2
منشورات القناة
2
#Malware_analysis 1⃣ SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch 2⃣ New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant 3⃣ HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2 4⃣ Neural Override - AI-Orchestrated RAT With SCADA Tasking https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-09-15-Neural-Override-AI-Orchestrated-RAT.txt
835
3
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 12-19, 2026) 1⃣ Thai Broadband Provider Targeted via FortiGate SSL-VPN and MeshCentral Persistence 2⃣ CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026 3⃣ Cisco Identity Services Engine Authentication Bypass Vulnerability // CVE-2026-76460 4⃣ PolarProxy 2.0.2 Released // PolarProxy can now tunnel outgoing connections through SOCKS proxies and supports environment variables as an alternative to CLI arguments 5⃣ Acronis LPE due to insecure file permissions // CVE-2026-87886 6⃣ Click2Shell: Preauth WP Core Theme Preview Injection to RCE Chain 7⃣ Attackers exploited MikroTik RouterOS vulnerabilities to perform an unauthenticated "MikroTik" administration takeover 8⃣ StyleSmuggler Attacks (Magento/Adobe Commerce) // CVE-2026-75650 9⃣  A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE) 🔟 Pipelock v.3.5.0 - Firewall for AI agents // DLP scanning, SSRF protection, bidirectional MCP scanning, tool poisoning detection, and workspace integrity monitoring
780
4
#tools #Malware_analysis #Blue_Team_Techniques RuleAutoPilot: Synthesizing Deployable Suricata Rules from Network Traffic", Sep 2026. // RuleAutoPilot - end-to-end agentic framework that generates deployable Suricata rules directly from malware network traffic, with no prior threat intelligence required. A key challenge is noise: network traffic captures often contain a small amount of security-relevant traffic mixed with large volumes of background traffic, which reduces LLM reasoning quality and increases cost. RuleAutoPilot addresses this challenge with a Benign Traffic Fingerprinting stage that removes known benign background flows before LLM processing
831
5
#Malware_analysis 1⃣ "Eye" spy: Cyclops Blink returns with extended capabilities https://www.sophos.com/en-gb/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities 2⃣ Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270 3⃣ REVSTEALER: analysis of up-and-coming infostealer https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer
661
6
Penetration-List https://github.com/AlbusSec/Penetration-List
602
7
#AppSec #Research #WebApp_Security "IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications", Sep 2026. ]-> https://github.com/GuanhangShiFDU/IDOR-GUARD // Cross-language IDOR reproduction and defense demo for Java, Python, Go, and PHP applications. Evaluated applications include XXL-Job, RuoYi, BootDo, wger, Gitea, Krayin, and Langflow
590
8
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability 3⃣ Next Nightmare Eclipse Vulnerability // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques 🔟 Beltdown: Escaping the Claude Code sandbox // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user
619
9
#reversing #Malware_analysis Malware Analysis Series (MAS): Article 10 - Linux, 2025. ]-> Article 09 - Shellcode (.pdf) ]-> Articles 01 - 08 // last article of MAS series.
734
10
#Threat_Research #Malware_analysis 1⃣ Robobox: Self driven malware creation and execution https://netaskari.substack.com/p/robobox-self-driven-malware-creation 2⃣ UpdraftPlus: PHP backdoor delivery attempts via CVE-2026-10795 https://offseq.com/en/research/the-backdoor-inside-the-backup-request 3⃣ Tengu: Reverse Engineering a Mirai-Style Linux/IoT Botnet https://app.reverser.space/p/duckie/tengu-reverse-engineering-a-mirai-style-linux-iot 4⃣ PEEP: A Chrome Extension RAT https://socradar.io/blog/peep-browser-rat-chrome-extension
749
11
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Aug 15 - Sep 05, 2026) 0⃣ nDPI 6.0 (Aug 2026) 1⃣ Attackers used BGP to spoof the Virtualizor update server and the Softaculous website 2⃣ Sleepwalker Malware 3⃣ Sangoma Switchvox Exploit 4⃣ Fronics Deploy Abuse 5⃣ Escaping Google Cloud Application Integration Sandbox: Straight into Borg 6⃣ VMware threat emulation techniques // A reproducible catalogue of 86 atomic actions against vCenter, ESXi, SDDC Manager, and the wider VCF ecosystem 7⃣ Log4J FilteredObjectInputStream Vulnerability // Research 8⃣ FTP Banners The New Dead Drop Resolver Delivering Novel RATs 9⃣ Android Car Malware 🔟 AliExpress WebAudio fingerprinting
747
12
#exploit #AppSec 1⃣ FalconFlank - Crowdstrike Falcon 0day Privilege Escalation Vulnerability https://github.com/MSNightmare/FalconFlank 2⃣ Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days https://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-raining-0days.html 3⃣ Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint https://www.mannulinux.org/2026/08/Privilege-escalation-from-IIS-AppPool-to-NT-AuthoritySYSTEM-via-AD-CS-RPC-endpoint.html ]-> Certi-Bhai - AD CS Exploitation Toolkit
673
13
https://www.udemy.com/course/siber-olaylara-mudahale-egitimi-windows-forensics/?couponCode=E489923CACD393A226B8
793
14
Herkese selam, Bugün saat 20.00’da, grubu takip eden aktif üyelerimize özel “Siber Olaylara Müdahale Eğitimi (Windows Forensics)” eğitimi için ücretsiz kayıt linkini paylaşacağım. Yayınlanacak link üzerinden yalnızca ilk 9 kişi ücretsiz kayıt olabilecek. Eğitim Udemy üzerinde yer almakta olup detaylarına aşağıdaki linkten ulaşabilirsiniz. https://www.udemy.com/course/siber-olaylara-mudahale-egitimi-windows-forensics/
738
15
#Threat_Research #WebApp_Security Attack of The Extensions https://specterops.io/blog/2026/08/13/chromium-extension-c2-persistence // Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft
653
16
CVE-2026-18963 KeyCloak * reset-credentials bypass → unauthenticated account takeover PoCexploit
CVE-2026-18963 KeyCloak * reset-credentials bypass → unauthenticated account takeover PoCexploit
706
17
CVE-2026-20217 File Drop to RCE * full WriteUP + PoC
CVE-2026-20217 File Drop to RCE * full WriteUP + PoC
813
18
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Aug 08 - 15, 2026) 0⃣ DEF CON 34 1⃣ Bypassing Android Hardware Attestation from the Analyst's Chair 2⃣ Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 3⃣ Rogue Inflight Wifi 4⃣ Why AI-generated vulnerability patches still require expert human review 5⃣ Gunra Ransomware 6⃣ Neo4J/GraphQL Vulnerability (CVE-2026-5423) 7⃣ Ruby 4.0 Universal RCE Deserialization Gadget Chain 8⃣ OpenSSH 10.5 released 9⃣ Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) 🔟 SCTPhantom - vulnerability in the Linux kernel that allows root access and container escape
988
19
#tools #Hardware_Security CPU Privilege Escalation https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii ]-> DEF CON 2026 - Weaponizing Uselessness (.pdf) ]-> Unlocking everything on the CPU with DRAM scrambling - PSP, C6, microcode, SMM, and anything else the specs left out
787
20
CVE-2026-41452 Krayin CRM * Auth Bypass → Admin Takeover PoC
CVE-2026-41452 Krayin CRM * Auth Bypass → Admin Takeover PoC
744