ch
Feedback
PT SWARM

PT SWARM

前往频道在 Telegram

Positive Technologies Offensive Team: twitter.com/ptswarm This is the channel where we share articles/vulnerabilities/scripts/etc, not necessarily authored by us, that we find interesting

显示更多
6 782
订阅者
无数据24 小时
-47 天
-430 天

数据加载中...

标签云
无数据
有任何问题?请刷新页面或联系我们的客服
进出提及
---
---
---
---
---
---
吸引订阅者
十月 '25
十月 '25
+45
在2个频道中
九月 '25
+82
在1个频道中
Get PRO
八月 '25
+121
在1个频道中
Get PRO
七月 '25
+175
在9个频道中
Get PRO
六月 '25
+197
在7个频道中
Get PRO
五月 '25
+75
在0个频道中
Get PRO
四月 '25
+75
在1个频道中
Get PRO
三月 '25
+96
在2个频道中
Get PRO
二月 '25
+104
在1个频道中
Get PRO
一月 '25
+70
在1个频道中
Get PRO
十二月 '24
+152
在4个频道中
Get PRO
十一月 '24
+448
在5个频道中
Get PRO
十月 '24
+251
在1个频道中
Get PRO
九月 '24
+308
在5个频道中
Get PRO
八月 '24
+267
在6个频道中
Get PRO
七月 '24
+168
在0个频道中
Get PRO
六月 '24
+304
在3个频道中
Get PRO
五月 '24
+313
在4个频道中
Get PRO
四月 '24
+444
在10个频道中
Get PRO
三月 '24
+370
在10个频道中
Get PRO
二月 '24
+99
在3个频道中
Get PRO
一月 '24
+239
在6个频道中
Get PRO
十二月 '23
+122
在1个频道中
Get PRO
十一月 '23
+103
在0个频道中
Get PRO
十月 '23
+258
在2个频道中
Get PRO
九月 '23
+144
在0个频道中
Get PRO
八月 '23
+90
在0个频道中
Get PRO
七月 '23
+72
在0个频道中
Get PRO
六月 '23
+87
在0个频道中
Get PRO
五月 '23
+197
在0个频道中
Get PRO
四月 '23
+377
在0个频道中
Get PRO
三月 '23
+202
在0个频道中
Get PRO
二月 '23
+91
在0个频道中
Get PRO
一月 '23
+41
在0个频道中
Get PRO
十二月 '22
+18
在0个频道中
Get PRO
十一月 '22
+33
在0个频道中
Get PRO
十月 '22
+31
在0个频道中
Get PRO
九月 '22
+43
在0个频道中
Get PRO
八月 '22
+84
在0个频道中
Get PRO
七月 '22
+87
在0个频道中
Get PRO
六月 '22
+166
在0个频道中
Get PRO
五月 '22
+212
在0个频道中
Get PRO
四月 '22
+61
在0个频道中
Get PRO
三月 '22
+64
在0个频道中
Get PRO
二月 '22
+84
在0个频道中
Get PRO
一月 '22
+32
在0个频道中
Get PRO
十二月 '21
+43
在0个频道中
Get PRO
十一月 '21
+67
在0个频道中
Get PRO
十月 '21
+117
在0个频道中
Get PRO
九月 '21
+120
在0个频道中
Get PRO
八月 '21
+142
在0个频道中
Get PRO
七月 '21
+146
在0个频道中
Get PRO
六月 '21
+92
在0个频道中
Get PRO
五月 '21
+76
在0个频道中
Get PRO
四月 '21
+655
在0个频道中
日期
订阅者增长
提及
频道
22 十月+4
21 十月+2
20 十月0
19 十月+1
18 十月+2
17 十月+1
16 十月+4
15 十月0
14 十月+5
13 十月+2
12 十月+2
11 十月+5
10 十月+1
09 十月+4
08 十月+2
07 十月0
06 十月+2
05 十月+1
04 十月+1
03 十月0
02 十月+3
01 十月+3
频道帖子
🚨 We've launched dbugs.ptsecurity.com, a new home for vulnerabilities. More than CVEs. More than MITRE. ✅ Trends & Insights
🚨 We've launched dbugs.ptsecurity.com, a new home for vulnerabilities. More than CVEs. More than MITRE. ✅ Trends & Insights ✅ AI-generated, multi-source vulnerability descriptions ✅ Researcher credits Explore now: https://dbugs.ptsecurity.com

2
👑 Our researcher has discovered LPE in VMWare Tools (CVE-2025-22230 & CVE-2025-22247) via VGAuth! Write-up by the one who br
👑 Our researcher has discovered LPE in VMWare Tools (CVE-2025-22230 & CVE-2025-22247) via VGAuth! Write-up by the one who broke it: Sergey Bliznyuk https://swarm.ptsecurity.com/the-guest-who-could-exploiting-lpe-in-vmware-tools/
10 469
3
😈 Read the new article "Daemon Ex Plist: LPE via MacOS Daemons" by our researcher Egor Filatov. This research reveals a vulnerability affecting popular apps like Mozilla VPN, Tunnelblick & more. https://swarm.ptsecurity.com/daemon-ex-plist-lpe-via-macos-daemons/
3 720
4
🧠 Our researcher Sergey Tarasov discovered a vulnerability (CVE-2025-49689) in NTFS on MS Windows. The article dives into th
🧠 Our researcher Sergey Tarasov discovered a vulnerability (CVE-2025-49689) in NTFS on MS Windows. The article dives into the exploitation path, file system internals, VHD format, and more. 🔗 Read the article: https://swarm.ptsecurity.com/buried-in-the-log-exploiting-a-20-years-old-ntfs-vulnerability/
4 655
5
🦊 Mozilla Foundation fixed CVE-2025-6430, discovered by our researcher Daniil Satyaev! This vulnerability allows the Content
🦊 Mozilla Foundation fixed CVE-2025-6430, discovered by our researcher Daniil Satyaev! This vulnerability allows the Content-Disposition: attachment header to be ignored if the page is opened using <embed> or <object>, resulting in files being displayed instead of downloaded.
5 396
6
⚠️ We've reproduced CVE-2025-49113 in Roundcube. This vulnerability allows authenticated users to execute arbitrary commands
⚠️ We've reproduced CVE-2025-49113 in Roundcube. This vulnerability allows authenticated users to execute arbitrary commands via PHP object deserialization. If you're running Roundcube — update immediately!
10 410
7
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE 👤 by Egidio Romano The article analyzes a critical Una
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE 👤 by Egidio Romano The article analyzes a critical Unauthenticated Remote Code Execution vulnerability (CVE-2025-48827) in vBulletin, which becomes exploitable when running on PHP 8.1 or newer. The vulnerability stems from vBulletin’s misuse of ReflectionMethod::invoke(), which in PHP 8.1+ no longer blocks access to protected methods by default. As a result, attackers can remotely trigger sensitive internal functions originally meant to be inaccessible and achieve code execution on the server. 📝 Contents: ● The Vulnerability ● The vBulletin Vulnerability ● Exploiting vBulletin: Path to Pre-Auth RCE ● Conclusion https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce
3 961
8
Next.js and the corrupt middleware: the authorizing artifact 👤 by Rachid Allam & Yasser Allam Researchers have discovered a
Next.js and the corrupt middleware: the authorizing artifact 👤 by Rachid Allam & Yasser Allam Researchers have discovered a critical vulnerability in Next.js, a popular framework for building web applications. The flaw allows attackers to bypass middleware responsible for request processing, including authentication and path rewrites. By adding the x-middleware-subrequest header with a specific value, an attacker can completely ignore middleware execution, gaining unauthorized access to protected resources. Additionally, the vulnerability can be exploited for denial-of-service (DoS) attacks by poisoning the cache, leading to service disruption. Many versions of Next.js are affected, making this a widespread security concern. 📝 Contents: ● The Next.js middleware ● The authorizing artifact artifact: old code, 0ld treasure • Execution order and middlewareInfo.name ● The authorizing artifact: nostalgia has its charm, but living in the moment is better • /src directory • Max recursion depth ● Exploits • Authorization/Rewrite bypass • CSP bypass • DoS via Cache-Poisoning (what?) • Clarification ● Security Advisory - CVE-2025-29927 ● Disclaimer ● Conclusion https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware
2 176
9
🔥 The "impossible" XXE in PHP? Not so impossible anymore. Our researcher Aleksandr Zhurnakov discovered an interesting combi
🔥 The "impossible" XXE in PHP? Not so impossible anymore. Our researcher Aleksandr Zhurnakov discovered an interesting combination of PHP wrappers and a feature of XML parsing in libxml2 to exploit it. Read: https://swarm.ptsecurity.com/impossible-xxe-in-php/
3 668
10
📟 Our researcher a1exdandy has uncovered vulnerabilities in GD32 microcontrollers (GigaDevice) that bypass protection mechan
📟 Our researcher a1exdandy has uncovered vulnerabilities in GD32 microcontrollers (GigaDevice) that bypass protection mechanisms, allowing memory extraction. The article 👉 https://swarm.ptsecurity.com/gigavulnerability-readout-protection-bypass-on-gigadevice-gd32-mcus/
4 309
11
🎮 Xbox 360 security in details: the long way to RGH3. Read the exclusive story about the chipless and reliable Xbox 360 modd
🎮 Xbox 360 security in details: the long way to RGH3. Read the exclusive story about the chipless and reliable Xbox 360 modding method by 15432h 🔗https://swarm.ptsecurity.com/xbox-360-security-in-details-the-long-way-to-rgh3/
2 333
12
Exploiting SSTI in a Modern Spring Boot Application (3.3.4) 👤 by parzel The article explores exploiting a Server-Side Templa
Exploiting SSTI in a Modern Spring Boot Application (3.3.4) 👤 by parzel The article explores exploiting a Server-Side Template Injection (SSTI) vulnerability in a Spring Boot 3.3.4 application using Thymeleaf, leading to Remote Code Execution (RCE). It highlights the process of injecting malicious input to trigger Java reflection and bypass security defenses in modern framework. The post provides a detailed walkthrough of achieving RCE despite the robust safeguards present, emphasizing the complexity of exploiting such vulnerabilities in contemporary applications. 📝 Contents: ● Identifying the Bug ● Facing Problems ● Bypassing the Defenses ● Developing the Exploit https://modzero.com/en/blog/spring_boot_ssti/
3 886
13
🇻🇳 At the Positive Hack Talks in Hanoi, our blue team member naumovax shared valuable insights: 1️⃣ Architecture of an auto
🇻🇳 At the Positive Hack Talks in Hanoi, our blue team member naumovax shared valuable insights: 1️⃣ Architecture of an automation tool for detecting malware in the network 2️⃣ Key features you should add to your tool 3️⃣ Our refined Suricata rules Link 👉 https://static.ptsecurity.com/events/stratocaster-how-we-automated-the-routine-search-for-unknown-malware-in-the-network-traffic.pdf Link to our Suricata rules: https://rules.ptsecurity.com/
5 298
14
🇻🇳 The Positive Hack Talks in Vietnam has finished! Slides from our researcher Arseniy Sharoglazov: https://static.ptsecuri
🇻🇳 The Positive Hack Talks in Vietnam has finished! Slides from our researcher Arseniy Sharoglazov: https://static.ptsecurity.com/events/exch-vietnam.pdf Wordlist: https://github.com/mohemiv/dodgypass 🎁 Includes a PoC for MyQ Unauthenticated RCE! (CVE-2024-28059)
6 719
15
💾 Check out our latest publication on DMA attacks via SD cards! The article was written by our researcher Gesser. ➡️ https://swarm.ptsecurity.com/new-dog-old-tr
3 847
16
🎤✨ Our security researcher, Konstantin Polishin, presented “Red Team Social Engineering 2024: Initial Access TTP and Project
🎤✨ Our security researcher, Konstantin Polishin, presented “Red Team Social Engineering 2024: Initial Access TTP and Project Experience of Our Team” at #ROOTCON18 🚀 Recording: https://youtube.com/watch?v=6nnZJiL0Tgk
4 630
17
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) 👤 by Harsh Jaiswal & Rahul Maini In this blog post, authors will a
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) 👤 by Harsh Jaiswal & Rahul Maini In this blog post, authors will analyze CVE-2024-45409, a critical vulnerability impacting Ruby-SAML, OmniAuth-SAML libraries, which effectively affects GitLab. This vulnerability allows an attacker to bypass SAML authentication mechanisms and gain unauthorized access by exploiting a flaw in how SAML responses are handled. The issue arises due to weaknesses in the verification of the digital signature used to protect SAML assertions, allowing attackers to manipulate the SAML response and bypass critical security checks. 📝 Contents: ● Introduction ● SAML Message Verification • How SAML Signatures Work? • How digest and signature ensure integrity? ● Ruby-SAML Bypass • Bypassing Signature Validation ● Conclusion https://blog.projectdiscovery.io/ruby-saml-gitlab-auth-bypass/
2 690
18
🤠 A notorious RCE in Zimbra, CVE-2024-45519 – here’s our expert breakdown! High resolution
🤠 A notorious RCE in Zimbra, CVE-2024-45519 – here’s our expert breakdown! High resolution
3 506
19
ATTACKING UNIX SYSTEMS VIA CUPS, PART I 👤 by Simone Margaritelli A remote unauthenticated attacker can silently replace exis
ATTACKING UNIX SYSTEMS VIA CUPS, PART I 👤 by Simone Margaritelli A remote unauthenticated attacker can silently replace existing printers’ (or install new ones) IPP urls with a malicious one, resulting in arbitrary command execution (on the computer) when a print job is started (from that computer). Entry Points • WAN / public internet: a remote attacker sends an UDP packet to port 631. No authentication whatsoever. • LAN: a local attacker can spoof zeroconf / mDNS / DNS-SD advertisements and achieve the same code path leading to RCE. RCE chain • Force the target machine to connect back to our malicious IPP server. • Return an IPP attribute string that will inject controlled PPD directives to the temporary file. • Wait for a print job to be sent to our fake printer for the PPD directives, and therefore the command, to be executed. 📝 Contents: ● Summary ● Intro ● What is cups-browsed? ● Stack Buffer Overflows and Race Conditions ● Back to found_cups_printer ● Internet Printing Protocol ● PostScript Printer Description ● The problematic child: foomatic-rip ● Remote Command Execution chain ● Personal Considerations ● One More Thing https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
7 611
20
🔥 ESET fixed CVE-2024-7400 found by our researcher Dmitriy Zuzlov! This is an LPE that affects 13 ESET solutions and allows
🔥 ESET fixed CVE-2024-7400 found by our researcher Dmitriy Zuzlov! This is an LPE that affects 13 ESET solutions and allows a low-privileged attacker to delete arbitrary files, which can be used to obtain NT AUTHORITY\SYSTEM privileges! The advisory 👉 https://support.eset.com/en/ca8726-local-privilege-escalation-fixed-for-vulnerability-during-detected-file-removal-in-eset-products-for-windows
3 433