İbrahim BALOĞLU - Siber Güvenlik Paylaşımları
前往频道在 Telegram
Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.
显示更多1 107
订阅者
+224 小时
无数据7 天
+1330 天
帖子存档
Herkese selam,
Bugün saat 20.00’da, grubu takip eden aktif üyelerimize özel “Siber Olaylara Müdahale Eğitimi (Windows Forensics)” eğitimi için ücretsiz kayıt linkini paylaşacağım.
Yayınlanacak link üzerinden yalnızca ilk 9 kişi ücretsiz kayıt olabilecek.
Eğitim Udemy üzerinde yer almakta olup detaylarına aşağıdaki linkten ulaşabilirsiniz.
https://www.udemy.com/course/siber-olaylara-mudahale-egitimi-windows-forensics/
#Threat_Research
#WebApp_Security
Attack of The Extensions
https://specterops.io/blog/2026/08/13/chromium-extension-c2-persistence
// Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft
CVE-2026-18963 KeyCloak
*
reset-credentials bypass → unauthenticated account takeover
PoCexploit
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events (Aug 08 - 15, 2026)
0⃣ DEF CON 34
1⃣ Bypassing Android Hardware Attestation from the Analyst's Chair
2⃣ Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
3⃣ Rogue Inflight Wifi
4⃣ Why AI-generated vulnerability patches still require expert human review
5⃣ Gunra Ransomware
6⃣ Neo4J/GraphQL Vulnerability (CVE-2026-5423)
7⃣ Ruby 4.0 Universal RCE Deserialization Gadget Chain
8⃣ OpenSSH 10.5 released
9⃣ Citrix NetScaler Pre-Auth RCE (CVE-2026-8452)
🔟 SCTPhantom - vulnerability in the Linux kernel that allows root access and container escape
#tools
#Hardware_Security
CPU Privilege Escalation
https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii
]-> DEF CON 2026 - Weaponizing Uselessness (.pdf)
]-> Unlocking everything on the CPU with DRAM scrambling - PSP, C6, microcode, SMM, and anything else the specs left out
CVE-2026-41452 Krayin CRM
*
Auth Bypass → Admin Takeover
PoC
Продолжаем делиться интересным
*
DEFCON: New Red Team Tactic - EvilFontTool
#exploit
#Kernel_Security
#Mobile_security
IonStack Vulnerability Chain
Part 1 - Unsound IonBanana Peel in Ion Compiler, Slipping Through Firefox's SpiderMonkey JIT
// IonMonkey CVE-2026-10702
Part 2 - GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
// GhostLock (CVE-2026-43499) + CVE-2026-53166
Part 3 - Rooting Android 17 with GhostLock
// Using GhostLock to develop the world's first public root for Android 17
// Disclaimer
#tools
#WebApp_Security
#Offensive_security
"Can AI do novel security research? Meet the HTTP Terminator", Black Hat USA 2026.
]-> web version of the publication
]-> HTTP Terminator
]-> Burp Suite param-miner
]-> Burp Suite Turbo Intruder
]-> HTTP Request Smuggler (upd)
// The paper presents HTTP Terminator, an AI-driven system for autonomous security research that generates, evaluates, and weaponizes novel HTTP desync exploits, introduces the concept of Shared-Parser Confusion to expand attack surfaces, and offers practical tools and defense strategies
#AppSec
1⃣ Jellyfin RCE (CVE-2026-35033)
https://www.sonarsource.com/blog/jellyfin-remote-code-execution
2⃣ Exploiting Langflow's validate_code() Endpoint for RCE (CVE-2026-0770)
https://www.resecurity.com/blog/article/exploiting-langflows-validatecode-endpoint-for-remote-code-execution
3⃣ Cruising for Shells in Flowise: 6 RCEs
https://www.elttam.com/blog/cruising-for-shells-in-flowise
4⃣ Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events (July 25 - Aug 01, 2026)
1⃣ IPMI Admin Password Hash Leak
// Why BMC Compromise Is Especially Dangerous in AI Infrastructure
2⃣ Escaping Linux Sandboxes via PipeWire
// CVE-2026-5674
3⃣ SourTrade: Browser-Assembled Malware Delivered Through Malvertising
4⃣ Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316
// This vulnerability (CVE-2026-20316) is due to the presence of static user credentials for a low-privileged account
5⃣ OpenWRT Patch, odhcpd vulnerability CVE-2026-53921
// Stack buffer overflow in DHCPv6 IA reply serialization
6⃣ Foxit PDF Reader LPE
// exploit for CVE-2026-3775/CVE-2026-3780/ CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service
7⃣ ServiceNow RCE Mass Exploitation (CVE-2026-6875)
// A critical RCE vulnerability in the ServiceNow platform has become a global disaster
8⃣ PureLogs, PureRAT and misleading zgRAT
// Despite the similar names PureLogs and PureRAT are not the same type of malware
#Malware_analysis
1⃣ copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown
https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer
2⃣ Flying Eagle Android RAT
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
3⃣ PolinRider Caused Dozens of npm, Go, PHP Compromises
https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-go-compromises
#DFIR
#Whitepaper
"Reconstructing Deleted File Activity Using FSEvents from macOS", Jun 2026.
// This paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk
Bilgilendirme: Grup içerisinde görünen reklamlar telegram tarafından otomatik yayınlanmaktadır. İsteğim ve bilgim dışındadır.
