Cyberwar Zone
Open in Telegram
✅CyberSecurity 👁🗨ThreatIntel ✖️APT 👾Malware 🔃RE 🐞Bug Bounty 🆙DevSecOps 🔎OSINT 💡Forensic 🔐Web Application Security 📲Mobile Security ⛓️BlockChain Security 🔝Tips & Tools Language : English & Farsi
Show more612
Subscribers
No data24 hours
+27 days
+230 days
Posts Archive
Repost from Loc0m0 لوکومتیو توییتر
هر کسی یه زندگیای داره که توش بهدنیا میاد و یه زندگیای که خودش میسازه. دومی خیلی ارزش خیلی جنگیدن داره.
[Loc0m0]
whoAMI attack could allow remote code execution within AWS account
https://securityaffairs.com/174283/hacking/whoami-attack-rce-within-aws-account.html
How Wiz found a Critical NVIDIA AI vulnerability: Deep Dive into a container escape (CVE-2024-0132)
https://www.wiz.io/blog/nvidia-ai-vulnerability-deep-dive-cve-2024-0132
Repost from An Inspired Engineer
دیشب یه ویدیو از جادی دیدم در مورد "آرون سوارتس" و کاراش و دلیلی که خودش رو کشت لینک ویدیو
وقتی ویکی پدیاش رو خوندم دیدم ۱۳ سالگیش کار x رو انجام داده که به y ختم شده و این y رو توی معادله های بعدی زندگیش استفاده کرده، فکر کنین زندگی بقیمون هم همینه، شاید کاری که الان میکنیم کم ارزش باشه ولی ممکنه خروجیش توی مراحل بعدی زندگیمون به عنوان یه ورودی استفاده بشه.
کی میدونه شاید اگه آرون سوارتس خودش رو نکشته بود الان یکی از ادمایی بود که داشت بشریت رو به جلو شیفت میداد...
@knowpow
Patch-Gapping the Google Container-Optimized OS for $0
https://h0mbre.github.io/Patch_Gapping_Google_COS/
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2)
https://mizu.re/post/exploring-the-dompurify-library-hunting-for-misconfigurations
CSS Data Exfiltration to Steal OAuth Token
https://blog.voorivex.team/css-data-exfiltration-to-steal-oauth-token
Experts discovered PostgreSQL flaw chained with BeyondTrust zeroday in targeted attacks
https://securityaffairs.com/174218/hacking/postgresql-flaw-chained-with-beyondtrust-zeroday.html
تکنیک های جدید برای هک کردن برنامه نویس ها و حتی بچه های حوزه امنیت به شدت عجیب غریب شده. یکی از اونها رو اینجا میتونید بخونید:
https://x.com/destanuzeyirr/status/1889731893215584504
توضیحات بیشتر درباره اکسپلویت:
https://amalmurali.me/posts/git-rce/
Repost from SecCode
کتاب تست نفوذ اپلیکیشن های اندروید ( نسخه کامل و رایگان )
لینک دانلود :
https://cafenode.ir/Android_Application_Penetration_Testing.pdf
تالیف : میثم منصف
@SecCode
How We Hacked a Software Supply Chain for $50K
https://www.landh.tech/blog/20250211-hack-supply-chain-for-50k/
form-action Content-Security-Policy Bypass And Other Tactics For Dealing With The CSP
https://nzt-48.org/form-action-content-security-policy-bypass-and-other-tactics-for-dealing-with-the-csp
I Found a Game Exploit That Lets Hackers Take Over Your PC
https://shalzuth.com/Blog/IFoundAGameExploit
Go Supply Chain Attack: Malicious Package Exploits Go Module Proxy Caching for Persistence
https://socket.dev/blog/malicious-package-exploits-go-module-proxy-caching-for-persistence
Super-charging Bug Bounty Hunting with the Power of AI
https://blog.ethiack.com/blog/supercharging-bug-bounty-hunting-with-ai
Abusing libxml2 quirks to bypass SAML authentication on GitHub Enterprise (CVE-2025-23369)🔥
https://repzret.blogspot.com/2025/02/abusing-libxml2-quirks-to-bypass-saml.html
