İbrahim BALOĞLU - Siber Güvenlik Paylaşımları
前往频道在 Telegram
Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.
显示更多1 093
订阅者
+124 小时
+87 天
+1730 天
数据加载中...
相似频道
标签云
进出提及
---
---
---
---
---
---
吸引订阅者
七月 '26
七月 '26
+40
在0个频道中
六月 '26
+29
在0个频道中
Get PRO
五月 '26
+57
在0个频道中
Get PRO
四月 '26
+65
在0个频道中
Get PRO
三月 '26
+45
在0个频道中
Get PRO
二月 '26
+38
在1个频道中
Get PRO
一月 '26
+46
在0个频道中
Get PRO
十二月 '25
+30
在0个频道中
Get PRO
十一月 '250
在0个频道中
Get PRO
十月 '250
在0个频道中
Get PRO
九月 '250
在0个频道中
Get PRO
八月 '250
在0个频道中
Get PRO
七月 '250
在0个频道中
Get PRO
六月 '250
在0个频道中
Get PRO
五月 '250
在0个频道中
Get PRO
四月 '250
在0个频道中
Get PRO
三月 '250
在0个频道中
Get PRO
二月 '250
在0个频道中
Get PRO
一月 '250
在0个频道中
Get PRO
十二月 '240
在0个频道中
Get PRO
十一月 '24
+88
在0个频道中
Get PRO
十月 '24
+129
在0个频道中
Get PRO
九月 '24
+53
在0个频道中
Get PRO
八月 '24
+48
在0个频道中
Get PRO
七月 '24
+54
在0个频道中
Get PRO
六月 '24
+46
在0个频道中
Get PRO
五月 '24
+53
在0个频道中
Get PRO
四月 '24
+48
在0个频道中
Get PRO
三月 '24
+68
在0个频道中
Get PRO
二月 '24
+83
在0个频道中
Get PRO
一月 '24
+70
在0个频道中
Get PRO
十二月 '23
+264
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 27 七月 | +1 | |||
| 26 七月 | +1 | |||
| 25 七月 | 0 | |||
| 24 七月 | +2 | |||
| 23 七月 | +3 | |||
| 22 七月 | +4 | |||
| 21 七月 | +3 | |||
| 20 七月 | +1 | |||
| 19 七月 | 0 | |||
| 18 七月 | +4 | |||
| 17 七月 | 0 | |||
| 16 七月 | +2 | |||
| 15 七月 | 0 | |||
| 14 七月 | +1 | |||
| 13 七月 | 0 | |||
| 12 七月 | +2 | |||
| 11 七月 | 0 | |||
| 10 七月 | 0 | |||
| 09 七月 | +2 | |||
| 08 七月 | +2 | |||
| 07 七月 | +2 | |||
| 06 七月 | +2 | |||
| 05 七月 | +3 | |||
| 04 七月 | +1 | |||
| 03 七月 | +2 | |||
| 02 七月 | +1 | |||
| 01 七月 | +1 |
频道帖子
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events (July 18 - 25, 2026)
1⃣ Huggingface Hack
// The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline...
2⃣ Dark Elevator: Windows 11 InstallService LPE (CVE-2026-50343)
// PoC
3⃣ Dnsmasq DNS Remote Heap Buffalo
// CVE-2026-2291
4⃣ Chaos ransomware's msaRAT:
Living off the browser to build a covert C2 channel
5⃣ OpenAI and Hugging Face partner to address security incident during model evaluation
// The incident clearly demonstrates that advanced models CAN discover and exploit new attack vectors in real-world systems without access to source code
6⃣ Certighost (CVE-2026-54121) -
AD CS Domain Controller Impersonation
// tool to demonstrace CVE-2026-54121
7⃣ OPNsense 26.7 released
8⃣ Zero-Day Exploit Chain in Siemens ROX II
// CVE-2025-40948, CVE-2025-40947, CVE-2025-40949
| 2 | Redis
*
RCE PoC for 6.2.22, 7.4.9, 8.6.4, 8.8.0 | 338 |
| 3 | #AppSec
#Threat_Research
1⃣ OpenSSL HollowByte: A DoS Hiding in 11 Bytes
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes
2⃣ Windows AppResolver LPE:
From AppContainer to SYSTEM
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system
// PoC for an AppResolver authorization issue fixed in the July 2026 Windows security update and investigated in connection with CVE-2026-50454, a Windows User Interface Core EoP vulnerability
3⃣ wp2shell - Code Trace Deep Dive
https://blog.zsec.uk/wp2shell-code-trace-deep-dive
// wp2shell carries two CVEs (so far); CVE-2026-63030 & CVE-2026-60137 | 462 |
| 4 | 1⃣ RedLine Stealer
https://www.vmray.com/the-redline-thread-that-led-to-a-maritime-bec-infrastructure-cluster
2⃣ HelloNet campaign - new malicious modules launched through the ViPNet update system
https://securelist.com/tr/hellonet-vipnet/120700
3⃣ DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft
https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
4⃣ Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault
5⃣ OkoBot malware framework
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660 | 430 |
| 5 | #exploit
#Blue_Team_Techniques
LegacyHive: Windows user profile service arbitrary hive load EoP vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive
// The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root
]-> Detections (scripts) for LegacyHive exploitation
]-> BlueHammer (CVE-2026-33825) Yara/Sigma rules
]-> Sigma rule for MiniPlasma (CVE-2020-17103)
]-> Sigma rule for GreenPlasma (CVE-2026-45586)
]-> GreatXML detect rules
]-> RedSun (CVE-2026-41091), BlueHammer, UnDefend (CVE-2026-45498) Detection Pack | 457 |
| 6 | LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive
Original text: "LegacyHive — Windows user profile service arbitrary hive load elevation of privileges vulnerability" — Nightmare-Eclipse (GitHub handle MSNightmare), Project NightCrawler, July 14 2026. The proof-of-concept is published under the MIT License; all code below is reproduced verbatim with attribution.
Executive Summary
On 14 July 2026 — hours after Microsoft’s July Patch Tuesday —…
https://core-jmp.org/2026/07/legacyhive-windows-user-profile-service-hive-load-eop/ | 458 |
| 7 | #tools
#reversing
#Malware_analysis
"Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications", REcon 2025.
]-> gooMBA - Hex-Rays Decompiler plugin
]-> SiMBA - tool for simplification of linear MBAs expressions
// A presentation of a new mathematical plugin (v.1.3) for Binary Ninja that simplifies complex MBA (Mixed Boolean-Arithmetic) expressions on the fly, often used by malware authors to disguise algorithms. The document includes a code decompilation analysis and examples of corrupted disassembly | 469 |
| 8 | #NetSec
#AppSec
1⃣ CVE-2026-47291:
RCE in the Windows HTTP.sys
https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys
// Windows HTTP.sys vulnerability allowing DoS or kernel code execution via a 16-bit overflow in header parsing during TLS, exploitable through crafted HTTP/1.x requests with many headers over HTTPS
2⃣ Unpatched XRING Flaw in XQUIC
https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions
// A flaw in Alibaba's XQUIC (< 1.9.4) allows remote attackers to crash HTTP/3 servers via small, spec-compliant QPACK traffic due to a size calculation bug, with no patch available as of July 10 | 549 |
| 9 | #exploit
1⃣ Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359)
https://github.com/V4bel/Januscape
2⃣ Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639
]-> Tooling for extracting and clearing passwords from Dell BIOS flash
// Disclaimer | 502 |
| 10 | 🛑 One open directory exposed three Microsoft 365 phishing operations.
The operations used two paths into #Microsoft 365: Evilginx session theft and device code phishing. One campaign logged 218 captured accounts across 12 countries, 94% of them corporate mailboxes.
Read the full investigation: http://thehackernews.com/2026/07/misconfigured-server-reveals-three.html | 500 |
| 11 | #Malware_analysis
1⃣ The Gentlemen are knocking:
сustom backdoors and evolving tactics
https://securelist.com/the-gentlemen-raas/120447
2⃣ TONResolver RAT
https://www.trendmicro.com/en_us/research/26/f/tonresolver.html
3⃣ From Bing Search to Ransomware:
Bumblebee and AdaptixC2 Deliver Akira
https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3 | 802 |
| 12 | #Analytics
#Threat_Research
An analytical review of the main cybersecurity events (June 27 - July 04, 2026)
1⃣ Bad Epoll (CVE-2026-46242)
https://github.com/J-jaeyoung/bad-epoll
// race-condition UaF in the Linux kernel's epoll subsystem
2⃣ Mitigated API authentication bypass for python*org download metadata
https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org
3⃣ Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed
https://github.com/bikini/exploitarium
4⃣ Beware of the license manager:
how a Schneider Electric software vulnerability puts industrial facilities at risk
https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436
5⃣ Apple Hide My Email Vulnerability
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses
6⃣ DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
7⃣ Google Gemini CLI Vulnerability
https://github.com/advisories/GHSA-jj69-4grx-fqj5
// CVE-2026-12537
8⃣ Apache MINA Deserialization Bypass to RCE
https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce
// CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6 | 816 |
| 13 | #Whitepaper
"Capturing the Click: Process-Based Detection of Malicious Link Interactions", Apr. 2026.
// Web links remain one of the most reliably abused vectors in phishing attacks. However, defenders continue to depend on network-based monitoring and post-execution detection that activate only after an account has been compromised. This research validates the browser command-line flags used by Chrome, Edge, Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it | 962 |
| 14 | lost data ? hold my beer | 951 |
| 15 | #AppSec
#Threat_Research
PixelSmash - Critical FFmpeg Vulnerability
https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons
// CVE-2026-8461 - critical vulnerability in FFmpeg's MagicYUV decoder leads to RCE via a crafted media file | 877 |
| 16 | #Malware_analysis
1⃣ Interlock and Rhysida within the ransomware ecosystem
https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem
2⃣ Preliminary analysis of AUR malware
https://ioctl.fail/preliminary-analysis-of-aur-malware
3⃣ Analysis of APT37 NarwhalRAT
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat | 845 |
| 17 | #NetSec
#AppSec
1⃣ Squidbleed (CVE-2026-47729)
https://blog.calif.io/p/squidbleed-cve-2026-47729
// Heartbleed-style heap buffer overread in Squid Proxy's FTP parser that leaks internal memory, including HTTP request data, due to a C bug when parsing missing filenames
2⃣ Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
https://karmainsecurity.com/chaining-bugs-in-discuz-from-race-condition-to-rce
// A chain of vulns in Discuz! X5.0 enables unauthenticated access to RCE through AI-assisted CAPTCHA bypass, database race conditions, token reuse, and LFI exploits, culminating in persistent OS command execution
3⃣ CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones
https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed
// Vulnerable: VVX 150, 250, 350, and 450, as well as Trio IP Conference series (Trio 8800, 8500, 8300) | 828 |
| 18 | #NetSec
#Red_Team_Tactics
1⃣ Windows fileless latteral movement technique
https://github.com/synacktiv/DCOMIllusionist
2⃣ Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751)
https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751
3⃣ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack
https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html
4⃣ Using WinGet to proxy execution and evade detection
https://ipurple.team/2026/06/09/winget | 840 |
| 19 | #DFIR
1⃣ A deep technical analysis of Windows input pipelines, security telemetry, and why PuTTY, WinSCP, MySQL, SSH, and SFTP passwords may leak into system memory
https://hexderef.com/windows-11-passwords-in-memory-lsass-ctfmon-analysis
2⃣ Aether - Windows memory-forensics and threat hunting tool
https://github.com/0xsp-SRD/aether | 927 |
| 20 | #AppSec
#Threat_Research
1⃣ Click Or Trick (CVE-2025-59199):
Escaping the Sandbox with Windows URIs
https://www.safebreach.com/blog/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris
2⃣ Adobe Acrobat Reader Escript.api UAF RCE
https://blog.exodusintel.com/2026/06/01/adobe-acrobat-reader-escript-api-use-after-free-remote-code-execution
3⃣ Exploiting Windows Defender's Remediation Workflow for LPE
https://blog.calif.io/p/redsun-exploiting-windows-defenders | 872 |
