ch
Feedback
İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

前往频道在 Telegram

Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.

显示更多
1 093
订阅者
+124 小时
+87
+1730
吸引订阅者
七月 '26
七月 '26
+40
在0个频道中
六月 '26
+29
在0个频道中
Get PRO
五月 '26
+57
在0个频道中
Get PRO
四月 '26
+65
在0个频道中
Get PRO
三月 '26
+45
在0个频道中
Get PRO
二月 '26
+38
在1个频道中
Get PRO
一月 '26
+46
在0个频道中
Get PRO
十二月 '25
+30
在0个频道中
Get PRO
十一月 '250
在0个频道中
Get PRO
十月 '250
在0个频道中
Get PRO
九月 '250
在0个频道中
Get PRO
八月 '250
在0个频道中
Get PRO
七月 '250
在0个频道中
Get PRO
六月 '250
在0个频道中
Get PRO
五月 '250
在0个频道中
Get PRO
四月 '250
在0个频道中
Get PRO
三月 '250
在0个频道中
Get PRO
二月 '250
在0个频道中
Get PRO
一月 '250
在0个频道中
Get PRO
十二月 '240
在0个频道中
Get PRO
十一月 '24
+88
在0个频道中
Get PRO
十月 '24
+129
在0个频道中
Get PRO
九月 '24
+53
在0个频道中
Get PRO
八月 '24
+48
在0个频道中
Get PRO
七月 '24
+54
在0个频道中
Get PRO
六月 '24
+46
在0个频道中
Get PRO
五月 '24
+53
在0个频道中
Get PRO
四月 '24
+48
在0个频道中
Get PRO
三月 '24
+68
在0个频道中
Get PRO
二月 '24
+83
在0个频道中
Get PRO
一月 '24
+70
在0个频道中
Get PRO
十二月 '23
+264
在0个频道中
日期
订阅者增长
提及
频道
27 七月+1
26 七月+1
25 七月0
24 七月+2
23 七月+3
22 七月+4
21 七月+3
20 七月+1
19 七月0
18 七月+4
17 七月0
16 七月+2
15 七月0
14 七月+1
13 七月0
12 七月+2
11 七月0
10 七月0
09 七月+2
08 七月+2
07 七月+2
06 七月+2
05 七月+3
04 七月+1
03 七月+2
02 七月+1
01 七月+1
频道帖子
#Analytics #Threat_Research An analytical review of the main cybersecurity events (July 18 - 25, 2026) 1⃣ Huggingface Hack // The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline... 2⃣ Dark Elevator: Windows 11 InstallService LPE (CVE-2026-50343) // PoC 3⃣ Dnsmasq DNS Remote Heap Buffalo // CVE-2026-2291 4⃣ Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel 5⃣ OpenAI and Hugging Face partner to address security incident during model evaluation // The incident clearly demonstrates that advanced models CAN discover and exploit new attack vectors in real-world systems without access to source code 6⃣ Certighost (CVE-2026-54121) - AD CS Domain Controller Impersonation // tool to demonstrace CVE-2026-54121 7⃣ OPNsense 26.7 released 8⃣ Zero-Day Exploit Chain in Siemens ROX II // CVE-2025-40948, CVE-2025-40947, CVE-2025-40949

2
Redis * RCE PoC for 6.2.22, 7.4.9, 8.6.4, 8.8.0
Redis * RCE PoC for 6.2.22, 7.4.9, 8.6.4, 8.8.0
338
3
#AppSec #Threat_Research 1⃣ OpenSSL HollowByte: A DoS Hiding in 11 Bytes https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes 2⃣ Windows AppResolver LPE: From AppContainer to SYSTEM https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system // PoC for an AppResolver authorization issue fixed in the July 2026 Windows security update and investigated in connection with CVE-2026-50454, a Windows User Interface Core EoP vulnerability 3⃣ wp2shell - Code Trace Deep Dive https://blog.zsec.uk/wp2shell-code-trace-deep-dive // wp2shell carries two CVEs (so far); CVE-2026-63030 & CVE-2026-60137
462
4
1⃣ RedLine Stealer https://www.vmray.com/the-redline-thread-that-led-to-a-maritime-bec-infrastructure-cluster 2⃣ HelloNet campaign - new malicious modules launched through the ViPNet update system https://securelist.com/tr/hellonet-vipnet/120700 3⃣ DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft 4⃣ Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault 5⃣ OkoBot malware framework https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660
430
5
#exploit #Blue_Team_Techniques LegacyHive: Windows user profile service arbitrary hive load EoP vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive // The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root ]-> Detections (scripts) for LegacyHive exploitation ]-> BlueHammer (CVE-2026-33825) Yara/Sigma rules ]-> Sigma rule for MiniPlasma (CVE-2020-17103) ]-> Sigma rule for GreenPlasma (CVE-2026-45586) ]-> GreatXML detect rules ]-> RedSun (CVE-2026-41091), BlueHammer, UnDefend (CVE-2026-45498) Detection Pack
457
6
LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive Original text: "LegacyHive — Windows
LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive Original text: "LegacyHive — Windows user profile service arbitrary hive load elevation of privileges vulnerability" — Nightmare-Eclipse (GitHub handle MSNightmare), Project NightCrawler, July 14 2026. The proof-of-concept is published under the MIT License; all code below is reproduced verbatim with attribution. Executive Summary On 14 July 2026 — hours after Microsoft’s July Patch Tuesday —… https://core-jmp.org/2026/07/legacyhive-windows-user-profile-service-hive-load-eop/
458
7
#tools #reversing #Malware_analysis "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications", REcon 2025. ]-> gooMBA - Hex-Rays Decompiler plugin ]-> SiMBA - tool for simplification of linear MBAs expressions // A presentation of a new mathematical plugin (v.1.3) for Binary Ninja that simplifies complex MBA (Mixed Boolean-Arithmetic) expressions on the fly, often used by malware authors to disguise algorithms. The document includes a code decompilation analysis and examples of corrupted disassembly
469
8
#NetSec #AppSec 1⃣ CVE-2026-47291: RCE in the Windows HTTP.sys https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys // Windows HTTP.sys vulnerability allowing DoS or kernel code execution via a 16-bit overflow in header parsing during TLS, exploitable through crafted HTTP/1.x requests with many headers over HTTPS 2⃣ Unpatched XRING Flaw in XQUIC https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions // A flaw in Alibaba's XQUIC (< 1.9.4) allows remote attackers to crash HTTP/3 servers via small, spec-compliant QPACK traffic due to a size calculation bug, with no patch available as of July 10
549
9
#exploit 1⃣ Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359) https://github.com/V4bel/Januscape 2⃣ Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639 ]-> Tooling for extracting and clearing passwords from Dell BIOS flash // Disclaimer
502
10
🛑 One open directory exposed three Microsoft 365 phishing operations. The operations used two paths into #Microsoft 365: Evi
🛑 One open directory exposed three Microsoft 365 phishing operations. The operations used two paths into #Microsoft 365: Evilginx session theft and device code phishing. One campaign logged 218 captured accounts across 12 countries, 94% of them corporate mailboxes. Read the full investigation: http://thehackernews.com/2026/07/misconfigured-server-reveals-three.html
500
11
#Malware_analysis 1⃣ The Gentlemen are knocking: сustom backdoors and evolving tactics https://securelist.com/the-gentlemen-raas/120447 2⃣ TONResolver RAT https://www.trendmicro.com/en_us/research/26/f/tonresolver.html 3⃣ From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3
802
12
#Analytics #Threat_Research An analytical review of the main cybersecurity events (June 27 - July 04, 2026) 1⃣  Bad Epoll (CVE-2026-46242) https://github.com/J-jaeyoung/bad-epoll // race-condition UaF in the Linux kernel's epoll subsystem 2⃣  Mitigated API authentication bypass for python*org download metadata https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org 3⃣ Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed https://github.com/bikini/exploitarium 4⃣  Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436 5⃣  Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses 6⃣  DNS Tricks to Load Malware into Cloned Repository https://0din.ai/blog/clone-this-repo-and-i-own-your-machine 7⃣  Google Gemini CLI Vulnerability https://github.com/advisories/GHSA-jj69-4grx-fqj5 // CVE-2026-12537 8⃣ Apache MINA Deserialization Bypass to RCE https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce // CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6
816
13
#Whitepaper "Capturing the Click: Process-Based Detection of Malicious Link Interactions", Apr. 2026. // Web links remain one of the most reliably abused vectors in phishing attacks. However, defenders continue to depend on network-based monitoring and post-execution detection that activate only after an account has been compromised. This research validates the browser command-line flags used by Chrome, Edge, Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it
962
14
lost data ? hold my beer
lost data ? hold my beer
951
15
#AppSec #Threat_Research PixelSmash - Critical FFmpeg Vulnerability https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons // CVE-2026-8461 - critical vulnerability in FFmpeg's MagicYUV decoder leads to RCE via a crafted media file
877
16
#Malware_analysis 1⃣ Interlock and Rhysida within the ransomware ecosystem https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem 2⃣ Preliminary analysis of AUR malware https://ioctl.fail/preliminary-analysis-of-aur-malware 3⃣ Analysis of APT37 NarwhalRAT https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
845
17
#NetSec #AppSec 1⃣ Squidbleed (CVE-2026-47729) https://blog.calif.io/p/squidbleed-cve-2026-47729 // Heartbleed-style heap buffer overread in Squid Proxy's FTP parser that leaks internal memory, including HTTP request data, due to a C bug when parsing missing filenames 2⃣ Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE https://karmainsecurity.com/chaining-bugs-in-discuz-from-race-condition-to-rce // A chain of vulns in Discuz! X5.0 enables unauthenticated access to RCE through AI-assisted CAPTCHA bypass, database race conditions, token reuse, and LFI exploits, culminating in persistent OS command execution 3⃣ CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed // Vulnerable: VVX 150, 250, 350, and 450, as well as Trio IP Conference series (Trio 8800, 8500, 8300)
828
18
#NetSec #Red_Team_Tactics 1⃣ Windows fileless latteral movement technique https://github.com/synacktiv/DCOMIllusionist 2⃣ Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751 3⃣ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html 4⃣ Using WinGet to proxy execution and evade detection https://ipurple.team/2026/06/09/winget
840
19
#DFIR 1⃣ A deep technical analysis of Windows input pipelines, security telemetry, and why PuTTY, WinSCP, MySQL, SSH, and SFTP passwords may leak into system memory https://hexderef.com/windows-11-passwords-in-memory-lsass-ctfmon-analysis 2⃣ Aether - Windows memory-forensics and threat hunting tool https://github.com/0xsp-SRD/aether
927
20
#AppSec #Threat_Research 1⃣ Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs https://www.safebreach.com/blog/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris 2⃣ Adobe Acrobat Reader Escript.api UAF RCE https://blog.exodusintel.com/2026/06/01/adobe-acrobat-reader-escript-api-use-after-free-remote-code-execution 3⃣ Exploiting Windows Defender's Remediation Workflow for LPE https://blog.calif.io/p/redsun-exploiting-windows-defenders
872