ar
Feedback
İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

الذهاب إلى القناة على Telegram

Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.

إظهار المزيد
1 093
المشتركون
+124 ساعات
+87 أيام
+1730 أيام
أرشيف المشاركات
#Analytics #Threat_Research An analytical review of the main cybersecurity events (July 18 - 25, 2026) 1⃣ Huggingface Hack // The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline... 2⃣ Dark Elevator: Windows 11 InstallService LPE (CVE-2026-50343) // PoC 3⃣ Dnsmasq DNS Remote Heap Buffalo // CVE-2026-2291 4⃣ Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel 5⃣ OpenAI and Hugging Face partner to address security incident during model evaluation // The incident clearly demonstrates that advanced models CAN discover and exploit new attack vectors in real-world systems without access to source code 6⃣ Certighost (CVE-2026-54121) - AD CS Domain Controller Impersonation // tool to demonstrace CVE-2026-54121 7⃣ OPNsense 26.7 released 8⃣ Zero-Day Exploit Chain in Siemens ROX II // CVE-2025-40948, CVE-2025-40947, CVE-2025-40949

#AppSec #Threat_Research 1⃣ OpenSSL HollowByte: A DoS Hiding in 11 Bytes https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes 2⃣ Windows AppResolver LPE: From AppContainer to SYSTEM https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system // PoC for an AppResolver authorization issue fixed in the July 2026 Windows security update and investigated in connection with CVE-2026-50454, a Windows User Interface Core EoP vulnerability 3⃣ wp2shell - Code Trace Deep Dive https://blog.zsec.uk/wp2shell-code-trace-deep-dive // wp2shell carries two CVEs (so far); CVE-2026-63030 & CVE-2026-60137

1⃣ RedLine Stealer https://www.vmray.com/the-redline-thread-that-led-to-a-maritime-bec-infrastructure-cluster 2⃣ HelloNet campaign - new malicious modules launched through the ViPNet update system https://securelist.com/tr/hellonet-vipnet/120700 3⃣ DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft 4⃣ Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault 5⃣ OkoBot malware framework https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660

#exploit #Blue_Team_Techniques LegacyHive: Windows user profile service arbitrary hive load EoP vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive // The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root ]-> Detections (scripts) for LegacyHive exploitation ]-> BlueHammer (CVE-2026-33825) Yara/Sigma rules ]-> Sigma rule for MiniPlasma (CVE-2020-17103) ]-> Sigma rule for GreenPlasma (CVE-2026-45586) ]-> GreatXML detect rules ]-> RedSun (CVE-2026-41091), BlueHammer, UnDefend (CVE-2026-45498) Detection Pack

LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive Original text: "LegacyHive — Windows
LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive Original text: "LegacyHive — Windows user profile service arbitrary hive load elevation of privileges vulnerability" — Nightmare-Eclipse (GitHub handle MSNightmare), Project NightCrawler, July 14 2026. The proof-of-concept is published under the MIT License; all code below is reproduced verbatim with attribution. Executive Summary On 14 July 2026 — hours after Microsoft’s July Patch Tuesday —… https://core-jmp.org/2026/07/legacyhive-windows-user-profile-service-hive-load-eop/

#tools #reversing #Malware_analysis "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications", REcon 2025. ]-> gooMBA - Hex-Rays Decompiler plugin ]-> SiMBA - tool for simplification of linear MBAs expressions // A presentation of a new mathematical plugin (v.1.3) for Binary Ninja that simplifies complex MBA (Mixed Boolean-Arithmetic) expressions on the fly, often used by malware authors to disguise algorithms. The document includes a code decompilation analysis and examples of corrupted disassembly

#NetSec #AppSec 1⃣ CVE-2026-47291: RCE in the Windows HTTP.sys https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys // Windows HTTP.sys vulnerability allowing DoS or kernel code execution via a 16-bit overflow in header parsing during TLS, exploitable through crafted HTTP/1.x requests with many headers over HTTPS 2⃣ Unpatched XRING Flaw in XQUIC https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions // A flaw in Alibaba's XQUIC (< 1.9.4) allows remote attackers to crash HTTP/3 servers via small, spec-compliant QPACK traffic due to a size calculation bug, with no patch available as of July 10

#exploit 1⃣ Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359) https://github.com/V4bel/Januscape 2⃣ Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639 ]-> Tooling for extracting and clearing passwords from Dell BIOS flash // Disclaimer

🛑 One open directory exposed three Microsoft 365 phishing operations. The operations used two paths into #Microsoft 365: Evi
🛑 One open directory exposed three Microsoft 365 phishing operations. The operations used two paths into #Microsoft 365: Evilginx session theft and device code phishing. One campaign logged 218 captured accounts across 12 countries, 94% of them corporate mailboxes. Read the full investigation: http://thehackernews.com/2026/07/misconfigured-server-reveals-three.html

#Malware_analysis 1⃣ The Gentlemen are knocking: сustom backdoors and evolving tactics https://securelist.com/the-gentlemen-raas/120447 2⃣ TONResolver RAT https://www.trendmicro.com/en_us/research/26/f/tonresolver.html 3⃣ From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3

#Analytics #Threat_Research An analytical review of the main cybersecurity events (June 27 - July 04, 2026) 1⃣  Bad Epoll (CVE-2026-46242) https://github.com/J-jaeyoung/bad-epoll // race-condition UaF in the Linux kernel's epoll subsystem 2⃣  Mitigated API authentication bypass for python*org download metadata https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org 3⃣ Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed https://github.com/bikini/exploitarium 4⃣  Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436 5⃣  Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses 6⃣  DNS Tricks to Load Malware into Cloned Repository https://0din.ai/blog/clone-this-repo-and-i-own-your-machine 7⃣  Google Gemini CLI Vulnerability https://github.com/advisories/GHSA-jj69-4grx-fqj5 // CVE-2026-12537 8⃣ Apache MINA Deserialization Bypass to RCE https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce // CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6

#Whitepaper "Capturing the Click: Process-Based Detection of Malicious Link Interactions", Apr. 2026. // Web links remain one of the most reliably abused vectors in phishing attacks. However, defenders continue to depend on network-based monitoring and post-execution detection that activate only after an account has been compromised. This research validates the browser command-line flags used by Chrome, Edge, Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it

lost data ? hold my beer

#AppSec #Threat_Research PixelSmash - Critical FFmpeg Vulnerability https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons // CVE-2026-8461 - critical vulnerability in FFmpeg's MagicYUV decoder leads to RCE via a crafted media file

#Malware_analysis 1⃣ Interlock and Rhysida within the ransomware ecosystem https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem 2⃣ Preliminary analysis of AUR malware https://ioctl.fail/preliminary-analysis-of-aur-malware 3⃣ Analysis of APT37 NarwhalRAT https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat

#NetSec #AppSec 1⃣ Squidbleed (CVE-2026-47729) https://blog.calif.io/p/squidbleed-cve-2026-47729 // Heartbleed-style heap buffer overread in Squid Proxy's FTP parser that leaks internal memory, including HTTP request data, due to a C bug when parsing missing filenames 2⃣ Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE https://karmainsecurity.com/chaining-bugs-in-discuz-from-race-condition-to-rce // A chain of vulns in Discuz! X5.0 enables unauthenticated access to RCE through AI-assisted CAPTCHA bypass, database race conditions, token reuse, and LFI exploits, culminating in persistent OS command execution 3⃣ CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed // Vulnerable: VVX 150, 250, 350, and 450, as well as Trio IP Conference series (Trio 8800, 8500, 8300)

#NetSec #Red_Team_Tactics 1⃣ Windows fileless latteral movement technique https://github.com/synacktiv/DCOMIllusionist 2⃣ Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751 3⃣ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html 4⃣ Using WinGet to proxy execution and evade detection https://ipurple.team/2026/06/09/winget

#DFIR 1⃣ A deep technical analysis of Windows input pipelines, security telemetry, and why PuTTY, WinSCP, MySQL, SSH, and SFTP passwords may leak into system memory https://hexderef.com/windows-11-passwords-in-memory-lsass-ctfmon-analysis 2⃣ Aether - Windows memory-forensics and threat hunting tool https://github.com/0xsp-SRD/aether

#AppSec #Threat_Research 1⃣ Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs https://www.safebreach.com/blog/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris 2⃣ Adobe Acrobat Reader Escript.api UAF RCE https://blog.exodusintel.com/2026/06/01/adobe-acrobat-reader-escript-api-use-after-free-remote-code-execution 3⃣ Exploiting Windows Defender's Remediation Workflow for LPE https://blog.calif.io/p/redsun-exploiting-windows-defenders