RME-DisCo @ UNIZAR [www.reversea.me]
前往频道在 Telegram
Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see" Link to the channel: https://t.me/reverseame
显示更多3 478
订阅者
+424 小时
+87 天
+6630 天
帖子存档
Proofs, Arguments, and Zero-Knowledge #ZeroKnowledge #ZKP #Crypto https://people.cs.georgetown.edu/jthaler/ProofsArgsAndZK.pdf
Kernel-Level Stealthy Observation of TTY Streams #LinuxKernel #TTYSubsystem #PseudoTerminal #KernelModule #SSHMonitoring https://blog.cybervelia.com/p/kernel-level-stealthy-observation-of-tty-streams
Persistent, Sandboxed, Single-Site Browser (firejail and proxychains) #SingleSiteBrowser #Firejail #Proxychains #AccountLockouts #PrivacyOpSec https://tech.michaelaltfield.net/2026/02/03/single-site-browser-firejail-proxychains/
GatewayToHeaven: Finding a Critical Cross-Tenant Exploit in GCP's Apigee #ApigeeSecurity #CrossTenantExploit #CVE202513292 #CloudVulnerability #GCPResearch https://omeramiad.com/posts/gatewaytoheaven-gcp-cross-tenant-vulnerability/
Auditing Outline. Firsthand lessons from comparing manual testing and AI security platforms #OutlineSecurityAudit #AISecurityPlatforms #FalsePositives #XSSAndSSRF #ManualPentesting https://blog.doyensec.com/2026/02/03/outline-audit-q32025.html
How LLMs Feed Your RE Habit: Following the Use-After-Free Trail in CLFS #ReverseEngineering #LLM #CLFS #UseAfterFree #PyghidraMCP https://clearbluejar.github.io/posts/how-llms-feed-your-re-habit-following-the-uaf-trail-in-clfs/
Exploiting CVE-2025-49825 #Teleport #CVE202549825 #AuthenticationBypass #SSHCertificate #ExploitDevelopment https://blog.offensive.af/posts/exploiting-cve-2025-49825/
Malicious Websites Can Exploit Openclaw (aka Clawdbot) To Steal Credentials #Openclaw #ClawdbotSecurity #CDPExploit #SessionHijacking #ZeroPath https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability
WhatsApp Encryption, a Lawsuit, and a Lot of Noise #WhatsApp #EndToEndEncryption #MetaLawsuit #SignalProtocol #MessagingPrivacy https://blog.cryptographyengineering.com/2026/02/02/whatsapp-encryption-a-lawsuit-and-a-lot-of-noise/
AppLocker Rules Abuse #EDRBlocking #AppLocker #GhostLocker #DefenseEvasion #PurpleTeam https://ipurple.team/2026/02/02/applocker-rules-abuse/
Your Phone Silently Sends GPS to Your Carrier — Here's How #BasebandPrivacy #RRLP #LPPProtocol #CarrierTracking #LocationSurveillance https://fumics.in/posts/2026-02-01-phone-gps-carrier-tracking
Notepad++ Hijacked by State-Sponsored Hackers #NotepadPlusPlus #SupplyChainAttack #StateSponsoredHackers #HostingCompromise #UpdateVerification https://notepad-plus-plus.org/news/hijacked-incident-info-update/
New post: a five-phase, MITRE ATT&CK-aligned workflow for mem forensics, from evidence preservation to binary analysis. We also flag 4 issues that bias mem evidence: paging, demand paging, smearing, and binary transforms #ICDF2C25 https://reversea.me/index.php/bringing-structure-to-memory-forensics-a-five-phase-mitre-attck-aligned-workflow/ https://webdiis.unizar.es/~ricardo/files/papers/Rodriguez-ICDF2C-27.pdf
New on the blog: MARISSA reverse-engineers network protocol formats straight from PCAPs: no specs, no delimiters. Will be presented at @IEEEEUROSP 2026, come and say hi! https://reversea.me/index.php/inferring-network-protocols-from-traffic-with-marissa/ tool: https://github.com/reverseame/MARISSA
New blog post! The simpler, the stealthier: we benchmarked 4 adversarial DGA models. The 2 simplest evade ML detectors >75% of the time and train in under 2s. Open-source: http://github.com/reverseame/adversarial-dga-framework, blog post: https://reversea.me/index.php/the-simpler-the-stealthier-benchmarking-adversarial-dga-models-in-a-unified-framework/ #DGA #MachineLearning #CyberSecurity #DIMVA2026
Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) #IvantiEPMM #PreAuthRCE #BashExploit #ArithmeticExpansion #ActivelyExploited https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/
