reconcore
الذهاب إلى القناة على Telegram
#vulnerability #research #cve #rce #lpe #poc #tools #pentest #redteam #blueteam #offensivesecurity #technique #methods Educational use only. Content from public sources. Admin holds no liability for misuse. Users are solely responsible for their actions.
إظهار المزيد2 308
المشتركون
لا توجد بيانات24 ساعات
+87 أيام
+13130 أيام
جاري تحميل البيانات...
القنوات المماثلة
سحابة العلامات
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
يوليو '26
يوليو '26
+110
في 0 قنوات
يونيو '26
+159
في 1 قنوات
Get PRO
مايو '26
+92
في 2 قنوات
Get PRO
أبريل '26
+89
في 2 قنوات
Get PRO
مارس '26
+116
في 1 قنوات
Get PRO
فبراير '26
+145
في 1 قنوات
Get PRO
يناير '26
+157
في 2 قنوات
Get PRO
ديسمبر '25
+317
في 3 قنوات
Get PRO
نوفمبر '25
+170
في 0 قنوات
Get PRO
أكتوبر '25
+216
في 1 قنوات
Get PRO
سبتمبر '25
+125
في 2 قنوات
Get PRO
أغسطس '25
+118
في 5 قنوات
Get PRO
يوليو '25
+96
في 2 قنوات
Get PRO
يونيو '25
+51
في 1 قنوات
Get PRO
مايو '25
+68
في 3 قنوات
Get PRO
أبريل '25
+117
في 2 قنوات
Get PRO
مارس '25
+84
في 1 قنوات
Get PRO
فبراير '25
+108
في 1 قنوات
Get PRO
يناير '25
+73
في 2 قنوات
Get PRO
ديسمبر '24
+4
في 0 قنوات
Get PRO
نوفمبر '24
+127
في 0 قنوات
Get PRO
أكتوبر '24
+38
في 0 قنوات
Get PRO
سبتمبر '24
+37
في 0 قنوات
Get PRO
أغسطس '24
+328
في 0 قنوات
Get PRO
يوليو '240
في 0 قنوات
Get PRO
يونيو '24
+15
في 1 قنوات
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 29 يوليو | +2 | |||
| 28 يوليو | +1 | |||
| 27 يوليو | +4 | |||
| 26 يوليو | +5 | |||
| 25 يوليو | +1 | |||
| 24 يوليو | 0 | |||
| 23 يوليو | +2 | |||
| 22 يوليو | +1 | |||
| 21 يوليو | +1 | |||
| 20 يوليو | +3 | |||
| 19 يوليو | +1 | |||
| 18 يوليو | +1 | |||
| 17 يوليو | +2 | |||
| 16 يوليو | +3 | |||
| 15 يوليو | +4 | |||
| 14 يوليو | +1 | |||
| 13 يوليو | +3 | |||
| 12 يوليو | 0 | |||
| 11 يوليو | +3 | |||
| 10 يوليو | +2 | |||
| 09 يوليو | +5 | |||
| 08 يوليو | +2 | |||
| 07 يوليو | +9 | |||
| 06 يوليو | +2 | |||
| 05 يوليو | +3 | |||
| 04 يوليو | +4 | |||
| 03 يوليو | +9 | |||
| 02 يوليو | +12 | |||
| 01 يوليو | +24 |
منشورات القناة
| 2 | CVE-2026-42533 — nginx Heap Buffer Overflow PoC Exploit
Pre-Authentication Remote Code Execution via Two-Pass Capture Clobbering
#rce #nginx #poc @reconcore | 339 |
| 3 | The headless browser built from scratch for AI agents and automation.
Not a Chromium fork. Not a WebKit patch. A new browser, written in Zig.
#tools #browser #zig @reconcore | 323 |
| 4 | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Overview of Chaos ransomware
Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data. For a detailed breakdown of their tactics, techniques, and procedures (TTPs), please refer to our previous blog.
#research #rat #ransomware @reconcore | 456 |
| 5 | Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation
Low-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying cdc (Client DC) and rmd (Remote Domain) request attributes, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP.
The CA then blindly trusts the returned directory objects (objectSid + dNSHostName of a real DC) and issues a certificate containing strong identity mapping for the Domain Controller. This allows successful PKINIT authentication as the DC.
Research
#ad #adcs #smb #ldaap @reconcore | 514 |
| 6 | Redis Authenticated RCE (stream NACK double free + TDigest heap overflow)
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
#rce #poc @reconcore | 491 |
| 7 | HiveOracle
Raw NTFS volume oracle: locked-file read and offline SAM hashes without LSASS
#lsass @reconcore | 459 |
| 8 | CVE-2026-36425 : OPSWAT AppRemover Arbitrary Process Termination
A signed OPSWAT kernel driver that kills any process on demand. No admin rights needed, no privilege checks, no questions asked. Point it at an EDR, an antivirus, a PPL-protected process and it dies. Three different kill methods, all running from kernel mode, all triggered by a single IOCTL from any local user. 16 vulnerable driver variants identified, all validly signed.
Introducing CVE-2026–36425 | OPSWAT EDR Terminator
#byovd #edr #bypass #evasion @reconcore | 461 |
| 9 | Кто-то разобрал Claude Code почти до винтика
learn-coding-agent - репозиторий для тех, кто хочет понять, как устроены современные coding agents не на уровне промо-страниц, а на уровне архитектуры.
Автор собрал разбор Claude Code по публичным источникам: цикл агента, систему инструментов, разрешения, работу с контекстом, сессии, подпроцессы, MCP, удалённые настройки, телеметрию и скрытые флаги.
Получился не “гайд по использованию”, а карта внутренней логики CLI-агента: как он принимает решение, когда просит разрешение, как вызывает инструменты, как хранит историю и как расширяется через внешние интеграции.
https://github.com/justxor/Claudecourse/ | 58 |
| 10 | New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
#cybersecurity #c2 @reconcore | 522 |
| 11 | 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
#reports #ransomware @reconcore | 580 |
| 12 | WordPress Core "wp2shell" RCE
The attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
#cve #rce #wordpress @reconcore | 635 |
| 13 | WordPress Core "wp2shell" RCE
The attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x. | 1 |
| 14 | Do not send group join requests without a valid reason! Every new member must specify their area of focus and assign a tag to their group profile; otherwise, they will be blocked. | 163 |
| 15 | Channel posts have been suspended
Open to anyone wishing to join the channel group via the link | 183 |
| 16 | There and Back Again: An Operators Guide on NTLM Relaying Egress
This technique is especially impactful when escalation isn’t possible to bind to port 445/TCP for SMB relays or firewall rules are preventing a WebDAV relay when operating from C2. It involves coercing either SMB or WebDAV authentication outbound, catching the authentication using a cloud host on the internet, and relaying the traffic back through red team infrastructure into the target environment.
#smb #ldap #technique #C2 @reconcore | 716 |
| 17 | How I found an integer overflow in tcpip.sys
Or, why count * size needs checking too
Earlier this year, I found an integer overflow in tcpip.sys, Windows' network driver. It was fixed in the July 2026 security update and is now CVE-2026-58532.
#cve #overflow #network #driver @reconcore | 634 |
| 18 | CVE-2026-50343: InstallService StaticPluginMap EoP (Standard User to SYSTEM)
I independently discovered and reported the vulnerability now tracked as CVE-2026-50343. MSRC confirmed my submission as a duplicate of an earlier report from another researcher. A standard interactive user can write attacker-controlled plugin state underHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\InstallService\State. The Microsoft Store Install Service runs as NT AUTHORITY\SYSTEM, reads PlugInList and StaticPluginMap, and loads the mapped DLL after a publicAppInstallManager.SearchForAllUpdatesAsync() trigger. The result is local standard-user to SYSTEM code execution.
#vulnerability @reconcore | 686 |
| 19 | CyberMeowfia GhostLock — CVE-2026-43499
This is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
#vulnerability #linux #kernel #lpe #container #escape @reconcore | 648 |
| 20 | Vulnerabilities of Realtek SD Card Reader
Part 1 - Vulnerabilities in RtsPer*sys PoCs
Part 2 - DMA vulnerability PoC
CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, CVE-2024-40432, CVE-2024-25476
#poc #vulnerability #hardware #security @reconcore | 590 |
