ar
Feedback
İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

الذهاب إلى القناة على Telegram

Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.

إظهار المزيد
1 072
المشتركون
لا توجد بيانات24 ساعات
+47 أيام
+2130 أيام
أرشيف المشاركات
#Analytics #Threat_Research An analytical review of the main cybersecurity events for the week (Jan.03-10, 2026) 1⃣  Cisco DNS Bug Reboot // The issue appears to be related to a change Cloudflare made in the order of CNAME records. Only users using 1 1 1 1 as a recursive resolver appear to be affected 2⃣  n8n vulnerabilities // In recent days, several new n8n vulnerabilities were disclosed. Ensure that you update any on-premises installations and carefully consider what to use n8n for 3⃣  D-Link DSL Command Injection // A new vulnerability in very old D-Link DSL modems is currently being exploited 4⃣  ESXi Exploitation in the Wild // In Dec. 2025, sophisticated attackers exploited VMware ESXi vulns via a multi-stage, stealthy attack leveraging 0-days and custom backdoors, leading to full hypervisor control, emphasizing urgent patching and detection see 5⃣  EDR Startup Process Blocker // The article details a method using Windows Bindlink API and "bindflt.sys" to hijack DLL loading via EDRStartupHinder, preventing EDR/antivirus startup by redirecting DLLs and exploiting PPL protections, with recommendations for detection and defense 6⃣  GnuPG Vulnerabilities // Several vulnerabilities in GnuPG were disclosed during a recent talk at the CCC congress 7⃣ YARA-X v1.11.0 ]-> Analytical review (Dec.27-Jan.03, 2026)

#tools #exploit #Red_Team_Tactics 1⃣ BOF Cocktails // Crystal Palace enables direct API hooking within BOFs for evasion, offering a flexible alternative to Beacon-based hooks with ongoing enhancements 2⃣ Exploiting a private API for VoiceOver // CVE-2025-43530 - macOS VoiceOver API vulnerability allowing bypass of privacy protections via trust verification flaws, enabling arbitrary AppleScript execution and AppleEvent sending, with a fix in macOS 26.2 requiring specific entitlements 3⃣ Using ADCS to Attack HTTPS-Enabled WSUS Clients // While vulnerabilities in the configuration of ADCS itself have been researched extensivly, combining other services with ADCS can still lead to new attack paths

#tools #exploit #Red_Team_Tactics 1⃣ BOF Cocktails // Crystal Palace enables direct API hooking within BOFs for evasion, offering a flexible alternative to Beacon-based hooks with ongoing enhancements 2⃣ Exploiting a private API for VoiceOver // CVE-2025-43530 - macOS VoiceOver API vulnerability allowing bypass of privacy protections via trust verification flaws, enabling arbitrary AppleScript execution and AppleEvent sending, with a fix in macOS 26.2 requiring specific entitlements 3⃣ Using ADCS to Attack HTTPS-Enabled WSUS Clients // While vulnerabilities in the configuration of ADCS itself have been researched extensivly, combining other services with ADCS can still lead to new attack paths

#DFIR #Blue_Team_Techniques From Code to Coverage: Part 1 - The OID Transformation That Hinders LDAP Detection // ..we learned to think like an attacker—understanding how Impacket tools construct their LDAP queries Part 2 - The Whitespace Nightmare: Writing Sigma Rules That Actually Match // ..we learned to think like a log parser having an existential crisis - handling every possible variation those queries might take after going through the transformation gauntlet

CVE-2025-6023 * Grafana Bypass: A Technical Deep Dive
CVE-2025-6023 * Grafana Bypass: A Technical Deep Dive

#Tech_book #Offensive_security "Bash Shell Scripting for Pentesters: Master the art of command-line exploitation and enhance your penetration testing workflows", 2024. // This book provides a comprehensive guide to mastering Bash scripting specifically for pentesting, covering everything from basic scripting concepts to advanced techniques for evading detection and integrating with modern technologies such as AI

SANS_Linux_Incident_Response_1766732202.pdf1.98 MB

#exploit #Kernel_Security "Exploiting a Linux Kernel 0-day Through Red-Black Tree Transformations", HexaCon 2025. ]-> Linux HFSC Eltree UAF - Debian 12 PoC // CVE-2025-38001 Analysis + RbTree Attack Against LTS/COS + Mitigations Exploit See also: ]-> EntryBleed: A Universal KASLR Bypass against KPTI on Linux (2023)

Arsenal-Image-Mounter-v3.12.331.rar174.56 MB

Siber Kulüplerin organize ettiği eğitimlere kayıt yaptırabilirsiniz.

Siber Kulüplerin organize ettiği eğitimlere kayıt yaptırabilirsiniz.

#Analytics #Threat_Research An analytical review of the main cybersecurity events for the week (December 13-20, 2025) 1⃣  Critical OneView Vulnerablity // HPs OneView Software allows for unauthenticated code execution 2⃣ Wireshark 4.4.12 Released // Release notes + download page 3⃣ FortiCloud SSO Login Vuln Exploited // FortiGate CVE-2025-59718, CVE-2025-59719 4⃣ AI-Powered Reverse Engineering with Ghidra // OGhidra bridges LLMs via Ollama with the Ghidra reverse engineering platform, enabling AI-driven binary analysis through natural language 5⃣ When Ads Become Profiles: Uncovering the Invisible Risk of Web Advertising at Scale with LLMs // An interesting study (and practical implementation) of the problem of passive digital footprint in advertising flows 6⃣ PCIe IDE TLP Reordering Vulnerabilities // CVE-2025-9612, CVE-2025-9613, CVE-2025-9614 7⃣ ClamAV Signature Retirement ]-> Analytical review (Dec.06-13, 2025)

+1
DVR EXAMINER_3.19_Crack.zip1.47 MB

#tools #Malware_analysis "From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis", Dec. 2025 (NDSS 2026). ]-> Artifacts ]-> JSimplifier - deobfuscation and simplification tool using LLMs/AST transformations // Existing tools struggle with diverse input formats, address only specific obfuscation types, and produce cryptic output that impedes human analysis. To address these challenges, we present JSIMPLIFIER, a comprehensive deobfuscation tool using a multi-stage pipeline with preprocessing, abstract syntax tree-based static analysis, dynamic execution tracing, and LLM-enhanced identifier renaming

BurpSuite PRO version 2025.10.04

WhatsApp activity tracker https://github.com/Xh4H/WhatsApp-device-activity-tracker: 1. This project implements the research f
WhatsApp activity tracker https://github.com/Xh4H/WhatsApp-device-activity-tracker: 1. This project implements the research from the paper "Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers" by Gabriel K. Gegenhuber, Maximilian Günther, Markus Maier, Aljosha Judmayer, Florian Holzbauer, Philipp É. Frenzel, and Johanna Ullrich (University of Vienna & SBA Research). 2. Example Output: The tracker sends probe messages and measures the Round-Trip Time (RTT) to detect device activity. 3. However, WhatsApp does not disclose what “high volume” means, so this does not fully prevent an attacker from sending a significant number of probe reactions before rate-limiting kicks in. @secharvester