reconcore
前往频道在 Telegram
#vulnerability #research #cve #rce #lpe #poc #tools #pentest #redteam #blueteam #offensivesecurity #technique #methods Educational use only. Content from public sources. Admin holds no liability for misuse. Users are solely responsible for their actions.
显示更多2 308
订阅者
无数据24 小时
+87 天
+13130 天
数据加载中...
吸引订阅者
七月 '26
七月 '26
+110
在0个频道中
六月 '26
+159
在1个频道中
Get PRO
五月 '26
+92
在2个频道中
Get PRO
四月 '26
+89
在2个频道中
Get PRO
三月 '26
+116
在1个频道中
Get PRO
二月 '26
+145
在1个频道中
Get PRO
一月 '26
+157
在2个频道中
Get PRO
十二月 '25
+317
在3个频道中
Get PRO
十一月 '25
+170
在0个频道中
Get PRO
十月 '25
+216
在1个频道中
Get PRO
九月 '25
+125
在2个频道中
Get PRO
八月 '25
+118
在5个频道中
Get PRO
七月 '25
+96
在2个频道中
Get PRO
六月 '25
+51
在1个频道中
Get PRO
五月 '25
+68
在3个频道中
Get PRO
四月 '25
+117
在2个频道中
Get PRO
三月 '25
+84
在1个频道中
Get PRO
二月 '25
+108
在1个频道中
Get PRO
一月 '25
+73
在2个频道中
Get PRO
十二月 '24
+4
在0个频道中
Get PRO
十一月 '24
+127
在0个频道中
Get PRO
十月 '24
+38
在0个频道中
Get PRO
九月 '24
+37
在0个频道中
Get PRO
八月 '24
+328
在0个频道中
Get PRO
七月 '240
在0个频道中
Get PRO
六月 '24
+15
在1个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 29 七月 | +2 | |||
| 28 七月 | +1 | |||
| 27 七月 | +4 | |||
| 26 七月 | +5 | |||
| 25 七月 | +1 | |||
| 24 七月 | 0 | |||
| 23 七月 | +2 | |||
| 22 七月 | +1 | |||
| 21 七月 | +1 | |||
| 20 七月 | +3 | |||
| 19 七月 | +1 | |||
| 18 七月 | +1 | |||
| 17 七月 | +2 | |||
| 16 七月 | +3 | |||
| 15 七月 | +4 | |||
| 14 七月 | +1 | |||
| 13 七月 | +3 | |||
| 12 七月 | 0 | |||
| 11 七月 | +3 | |||
| 10 七月 | +2 | |||
| 09 七月 | +5 | |||
| 08 七月 | +2 | |||
| 07 七月 | +9 | |||
| 06 七月 | +2 | |||
| 05 七月 | +3 | |||
| 04 七月 | +4 | |||
| 03 七月 | +9 | |||
| 02 七月 | +12 | |||
| 01 七月 | +24 |
频道帖子
| 2 | CVE-2026-42533 — nginx Heap Buffer Overflow PoC Exploit
Pre-Authentication Remote Code Execution via Two-Pass Capture Clobbering
#rce #nginx #poc @reconcore | 339 |
| 3 | The headless browser built from scratch for AI agents and automation.
Not a Chromium fork. Not a WebKit patch. A new browser, written in Zig.
#tools #browser #zig @reconcore | 323 |
| 4 | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Overview of Chaos ransomware
Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data. For a detailed breakdown of their tactics, techniques, and procedures (TTPs), please refer to our previous blog.
#research #rat #ransomware @reconcore | 456 |
| 5 | Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation
Low-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying cdc (Client DC) and rmd (Remote Domain) request attributes, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP.
The CA then blindly trusts the returned directory objects (objectSid + dNSHostName of a real DC) and issues a certificate containing strong identity mapping for the Domain Controller. This allows successful PKINIT authentication as the DC.
Research
#ad #adcs #smb #ldaap @reconcore | 514 |
| 6 | Redis Authenticated RCE (stream NACK double free + TDigest heap overflow)
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
#rce #poc @reconcore | 491 |
| 7 | HiveOracle
Raw NTFS volume oracle: locked-file read and offline SAM hashes without LSASS
#lsass @reconcore | 459 |
| 8 | CVE-2026-36425 : OPSWAT AppRemover Arbitrary Process Termination
A signed OPSWAT kernel driver that kills any process on demand. No admin rights needed, no privilege checks, no questions asked. Point it at an EDR, an antivirus, a PPL-protected process and it dies. Three different kill methods, all running from kernel mode, all triggered by a single IOCTL from any local user. 16 vulnerable driver variants identified, all validly signed.
Introducing CVE-2026–36425 | OPSWAT EDR Terminator
#byovd #edr #bypass #evasion @reconcore | 461 |
| 9 | Кто-то разобрал Claude Code почти до винтика
learn-coding-agent - репозиторий для тех, кто хочет понять, как устроены современные coding agents не на уровне промо-страниц, а на уровне архитектуры.
Автор собрал разбор Claude Code по публичным источникам: цикл агента, систему инструментов, разрешения, работу с контекстом, сессии, подпроцессы, MCP, удалённые настройки, телеметрию и скрытые флаги.
Получился не “гайд по использованию”, а карта внутренней логики CLI-агента: как он принимает решение, когда просит разрешение, как вызывает инструменты, как хранит историю и как расширяется через внешние интеграции.
https://github.com/justxor/Claudecourse/ | 58 |
| 10 | New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
#cybersecurity #c2 @reconcore | 522 |
| 11 | 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
#reports #ransomware @reconcore | 580 |
| 12 | WordPress Core "wp2shell" RCE
The attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
#cve #rce #wordpress @reconcore | 635 |
| 13 | WordPress Core "wp2shell" RCE
The attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x. | 1 |
| 14 | Do not send group join requests without a valid reason! Every new member must specify their area of focus and assign a tag to their group profile; otherwise, they will be blocked. | 163 |
| 15 | Channel posts have been suspended
Open to anyone wishing to join the channel group via the link | 183 |
| 16 | There and Back Again: An Operators Guide on NTLM Relaying Egress
This technique is especially impactful when escalation isn’t possible to bind to port 445/TCP for SMB relays or firewall rules are preventing a WebDAV relay when operating from C2. It involves coercing either SMB or WebDAV authentication outbound, catching the authentication using a cloud host on the internet, and relaying the traffic back through red team infrastructure into the target environment.
#smb #ldap #technique #C2 @reconcore | 716 |
| 17 | How I found an integer overflow in tcpip.sys
Or, why count * size needs checking too
Earlier this year, I found an integer overflow in tcpip.sys, Windows' network driver. It was fixed in the July 2026 security update and is now CVE-2026-58532.
#cve #overflow #network #driver @reconcore | 634 |
| 18 | CVE-2026-50343: InstallService StaticPluginMap EoP (Standard User to SYSTEM)
I independently discovered and reported the vulnerability now tracked as CVE-2026-50343. MSRC confirmed my submission as a duplicate of an earlier report from another researcher. A standard interactive user can write attacker-controlled plugin state underHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\InstallService\State. The Microsoft Store Install Service runs as NT AUTHORITY\SYSTEM, reads PlugInList and StaticPluginMap, and loads the mapped DLL after a publicAppInstallManager.SearchForAllUpdatesAsync() trigger. The result is local standard-user to SYSTEM code execution.
#vulnerability @reconcore | 686 |
| 19 | CyberMeowfia GhostLock — CVE-2026-43499
This is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
#vulnerability #linux #kernel #lpe #container #escape @reconcore | 648 |
| 20 | Vulnerabilities of Realtek SD Card Reader
Part 1 - Vulnerabilities in RtsPer*sys PoCs
Part 2 - DMA vulnerability PoC
CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, CVE-2024-40432, CVE-2024-25476
#poc #vulnerability #hardware #security @reconcore | 590 |
