İbrahim BALOĞLU - Siber Güvenlik Paylaşımları
الذهاب إلى القناة على Telegram
Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.
إظهار المزيد1 093
المشتركون
+124 ساعات
+87 أيام
+1730 أيام
جاري تحميل البيانات...
القنوات المماثلة
سحابة العلامات
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
يوليو '26
يوليو '26
+40
في 0 قنوات
يونيو '26
+29
في 0 قنوات
Get PRO
مايو '26
+57
في 0 قنوات
Get PRO
أبريل '26
+65
في 0 قنوات
Get PRO
مارس '26
+45
في 0 قنوات
Get PRO
فبراير '26
+38
في 1 قنوات
Get PRO
يناير '26
+46
في 0 قنوات
Get PRO
ديسمبر '25
+30
في 0 قنوات
Get PRO
نوفمبر '250
في 0 قنوات
Get PRO
أكتوبر '250
في 0 قنوات
Get PRO
سبتمبر '250
في 0 قنوات
Get PRO
أغسطس '250
في 0 قنوات
Get PRO
يوليو '250
في 0 قنوات
Get PRO
يونيو '250
في 0 قنوات
Get PRO
مايو '250
في 0 قنوات
Get PRO
أبريل '250
في 0 قنوات
Get PRO
مارس '250
في 0 قنوات
Get PRO
فبراير '250
في 0 قنوات
Get PRO
يناير '250
في 0 قنوات
Get PRO
ديسمبر '240
في 0 قنوات
Get PRO
نوفمبر '24
+88
في 0 قنوات
Get PRO
أكتوبر '24
+129
في 0 قنوات
Get PRO
سبتمبر '24
+53
في 0 قنوات
Get PRO
أغسطس '24
+48
في 0 قنوات
Get PRO
يوليو '24
+54
في 0 قنوات
Get PRO
يونيو '24
+46
في 0 قنوات
Get PRO
مايو '24
+53
في 0 قنوات
Get PRO
أبريل '24
+48
في 0 قنوات
Get PRO
مارس '24
+68
في 0 قنوات
Get PRO
فبراير '24
+83
في 0 قنوات
Get PRO
يناير '24
+70
في 0 قنوات
Get PRO
ديسمبر '23
+264
في 0 قنوات
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 27 يوليو | +1 | |||
| 26 يوليو | +1 | |||
| 25 يوليو | 0 | |||
| 24 يوليو | +2 | |||
| 23 يوليو | +3 | |||
| 22 يوليو | +4 | |||
| 21 يوليو | +3 | |||
| 20 يوليو | +1 | |||
| 19 يوليو | 0 | |||
| 18 يوليو | +4 | |||
| 17 يوليو | 0 | |||
| 16 يوليو | +2 | |||
| 15 يوليو | 0 | |||
| 14 يوليو | +1 | |||
| 13 يوليو | 0 | |||
| 12 يوليو | +2 | |||
| 11 يوليو | 0 | |||
| 10 يوليو | 0 | |||
| 09 يوليو | +2 | |||
| 08 يوليو | +2 | |||
| 07 يوليو | +2 | |||
| 06 يوليو | +2 | |||
| 05 يوليو | +3 | |||
| 04 يوليو | +1 | |||
| 03 يوليو | +2 | |||
| 02 يوليو | +1 | |||
| 01 يوليو | +1 |
منشورات القناة
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events (July 18 - 25, 2026)
1⃣ Huggingface Hack
// The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline...
2⃣ Dark Elevator: Windows 11 InstallService LPE (CVE-2026-50343)
// PoC
3⃣ Dnsmasq DNS Remote Heap Buffalo
// CVE-2026-2291
4⃣ Chaos ransomware's msaRAT:
Living off the browser to build a covert C2 channel
5⃣ OpenAI and Hugging Face partner to address security incident during model evaluation
// The incident clearly demonstrates that advanced models CAN discover and exploit new attack vectors in real-world systems without access to source code
6⃣ Certighost (CVE-2026-54121) -
AD CS Domain Controller Impersonation
// tool to demonstrace CVE-2026-54121
7⃣ OPNsense 26.7 released
8⃣ Zero-Day Exploit Chain in Siemens ROX II
// CVE-2025-40948, CVE-2025-40947, CVE-2025-40949
| 2 | Redis
*
RCE PoC for 6.2.22, 7.4.9, 8.6.4, 8.8.0 | 338 |
| 3 | #AppSec
#Threat_Research
1⃣ OpenSSL HollowByte: A DoS Hiding in 11 Bytes
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes
2⃣ Windows AppResolver LPE:
From AppContainer to SYSTEM
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system
// PoC for an AppResolver authorization issue fixed in the July 2026 Windows security update and investigated in connection with CVE-2026-50454, a Windows User Interface Core EoP vulnerability
3⃣ wp2shell - Code Trace Deep Dive
https://blog.zsec.uk/wp2shell-code-trace-deep-dive
// wp2shell carries two CVEs (so far); CVE-2026-63030 & CVE-2026-60137 | 462 |
| 4 | 1⃣ RedLine Stealer
https://www.vmray.com/the-redline-thread-that-led-to-a-maritime-bec-infrastructure-cluster
2⃣ HelloNet campaign - new malicious modules launched through the ViPNet update system
https://securelist.com/tr/hellonet-vipnet/120700
3⃣ DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft
https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
4⃣ Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault
5⃣ OkoBot malware framework
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660 | 430 |
| 5 | #exploit
#Blue_Team_Techniques
LegacyHive: Windows user profile service arbitrary hive load EoP vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive
// The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root
]-> Detections (scripts) for LegacyHive exploitation
]-> BlueHammer (CVE-2026-33825) Yara/Sigma rules
]-> Sigma rule for MiniPlasma (CVE-2020-17103)
]-> Sigma rule for GreenPlasma (CVE-2026-45586)
]-> GreatXML detect rules
]-> RedSun (CVE-2026-41091), BlueHammer, UnDefend (CVE-2026-45498) Detection Pack | 457 |
| 6 | LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive
Original text: "LegacyHive — Windows user profile service arbitrary hive load elevation of privileges vulnerability" — Nightmare-Eclipse (GitHub handle MSNightmare), Project NightCrawler, July 14 2026. The proof-of-concept is published under the MIT License; all code below is reproduced verbatim with attribution.
Executive Summary
On 14 July 2026 — hours after Microsoft’s July Patch Tuesday —…
https://core-jmp.org/2026/07/legacyhive-windows-user-profile-service-hive-load-eop/ | 458 |
| 7 | #tools
#reversing
#Malware_analysis
"Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications", REcon 2025.
]-> gooMBA - Hex-Rays Decompiler plugin
]-> SiMBA - tool for simplification of linear MBAs expressions
// A presentation of a new mathematical plugin (v.1.3) for Binary Ninja that simplifies complex MBA (Mixed Boolean-Arithmetic) expressions on the fly, often used by malware authors to disguise algorithms. The document includes a code decompilation analysis and examples of corrupted disassembly | 469 |
| 8 | #NetSec
#AppSec
1⃣ CVE-2026-47291:
RCE in the Windows HTTP.sys
https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys
// Windows HTTP.sys vulnerability allowing DoS or kernel code execution via a 16-bit overflow in header parsing during TLS, exploitable through crafted HTTP/1.x requests with many headers over HTTPS
2⃣ Unpatched XRING Flaw in XQUIC
https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions
// A flaw in Alibaba's XQUIC (< 1.9.4) allows remote attackers to crash HTTP/3 servers via small, spec-compliant QPACK traffic due to a size calculation bug, with no patch available as of July 10 | 549 |
| 9 | #exploit
1⃣ Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359)
https://github.com/V4bel/Januscape
2⃣ Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639
]-> Tooling for extracting and clearing passwords from Dell BIOS flash
// Disclaimer | 502 |
| 10 | 🛑 One open directory exposed three Microsoft 365 phishing operations.
The operations used two paths into #Microsoft 365: Evilginx session theft and device code phishing. One campaign logged 218 captured accounts across 12 countries, 94% of them corporate mailboxes.
Read the full investigation: http://thehackernews.com/2026/07/misconfigured-server-reveals-three.html | 500 |
| 11 | #Malware_analysis
1⃣ The Gentlemen are knocking:
сustom backdoors and evolving tactics
https://securelist.com/the-gentlemen-raas/120447
2⃣ TONResolver RAT
https://www.trendmicro.com/en_us/research/26/f/tonresolver.html
3⃣ From Bing Search to Ransomware:
Bumblebee and AdaptixC2 Deliver Akira
https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3 | 802 |
| 12 | #Analytics
#Threat_Research
An analytical review of the main cybersecurity events (June 27 - July 04, 2026)
1⃣ Bad Epoll (CVE-2026-46242)
https://github.com/J-jaeyoung/bad-epoll
// race-condition UaF in the Linux kernel's epoll subsystem
2⃣ Mitigated API authentication bypass for python*org download metadata
https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org
3⃣ Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed
https://github.com/bikini/exploitarium
4⃣ Beware of the license manager:
how a Schneider Electric software vulnerability puts industrial facilities at risk
https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436
5⃣ Apple Hide My Email Vulnerability
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses
6⃣ DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
7⃣ Google Gemini CLI Vulnerability
https://github.com/advisories/GHSA-jj69-4grx-fqj5
// CVE-2026-12537
8⃣ Apache MINA Deserialization Bypass to RCE
https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce
// CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6 | 816 |
| 13 | #Whitepaper
"Capturing the Click: Process-Based Detection of Malicious Link Interactions", Apr. 2026.
// Web links remain one of the most reliably abused vectors in phishing attacks. However, defenders continue to depend on network-based monitoring and post-execution detection that activate only after an account has been compromised. This research validates the browser command-line flags used by Chrome, Edge, Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it | 962 |
| 14 | lost data ? hold my beer | 951 |
| 15 | #AppSec
#Threat_Research
PixelSmash - Critical FFmpeg Vulnerability
https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons
// CVE-2026-8461 - critical vulnerability in FFmpeg's MagicYUV decoder leads to RCE via a crafted media file | 877 |
| 16 | #Malware_analysis
1⃣ Interlock and Rhysida within the ransomware ecosystem
https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem
2⃣ Preliminary analysis of AUR malware
https://ioctl.fail/preliminary-analysis-of-aur-malware
3⃣ Analysis of APT37 NarwhalRAT
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat | 845 |
| 17 | #NetSec
#AppSec
1⃣ Squidbleed (CVE-2026-47729)
https://blog.calif.io/p/squidbleed-cve-2026-47729
// Heartbleed-style heap buffer overread in Squid Proxy's FTP parser that leaks internal memory, including HTTP request data, due to a C bug when parsing missing filenames
2⃣ Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
https://karmainsecurity.com/chaining-bugs-in-discuz-from-race-condition-to-rce
// A chain of vulns in Discuz! X5.0 enables unauthenticated access to RCE through AI-assisted CAPTCHA bypass, database race conditions, token reuse, and LFI exploits, culminating in persistent OS command execution
3⃣ CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones
https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed
// Vulnerable: VVX 150, 250, 350, and 450, as well as Trio IP Conference series (Trio 8800, 8500, 8300) | 828 |
| 18 | #NetSec
#Red_Team_Tactics
1⃣ Windows fileless latteral movement technique
https://github.com/synacktiv/DCOMIllusionist
2⃣ Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751)
https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751
3⃣ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack
https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html
4⃣ Using WinGet to proxy execution and evade detection
https://ipurple.team/2026/06/09/winget | 840 |
| 19 | #DFIR
1⃣ A deep technical analysis of Windows input pipelines, security telemetry, and why PuTTY, WinSCP, MySQL, SSH, and SFTP passwords may leak into system memory
https://hexderef.com/windows-11-passwords-in-memory-lsass-ctfmon-analysis
2⃣ Aether - Windows memory-forensics and threat hunting tool
https://github.com/0xsp-SRD/aether | 927 |
| 20 | #AppSec
#Threat_Research
1⃣ Click Or Trick (CVE-2025-59199):
Escaping the Sandbox with Windows URIs
https://www.safebreach.com/blog/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris
2⃣ Adobe Acrobat Reader Escript.api UAF RCE
https://blog.exodusintel.com/2026/06/01/adobe-acrobat-reader-escript-api-use-after-free-remote-code-execution
3⃣ Exploiting Windows Defender's Remediation Workflow for LPE
https://blog.calif.io/p/redsun-exploiting-windows-defenders | 872 |
