ππ€π€π©πππ
Open in Telegram
Free content of OFF-SEC, SANS, ec-council, INE, eLearnSecurity, udemy coupons and many more #Malware_analysis #RootSec
Show more1 772
Subscribers
+324 hours
+117 days
+2830 days
Posts Archive
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events (June 27 - July 04, 2026)
1β£ Bad Epoll (CVE-2026-46242)
https://github.com/J-jaeyoung/bad-epoll
// race-condition UaF in the Linux kernel's epoll subsystem
2β£ Mitigated API authentication bypass for python*org download metadata
https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org
3β£ Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed
https://github.com/bikini/exploitarium
4β£ Beware of the license manager:
how a Schneider Electric software vulnerability puts industrial facilities at risk
https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436
5β£ Apple Hide My Email Vulnerability
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses
6β£ DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
7β£ Google Gemini CLI Vulnerability
https://github.com/advisories/GHSA-jj69-4grx-fqj5
// CVE-2026-12537
8β£ Apache MINA Deserialization Bypass to RCE
https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce
// CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6
#Malware_analysis
1β£ RustDuck Botnet
https://blog.xlab.qianxin.com/rustduck-en
2β£ Glitch SPY Android RAT
https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app
3β£ TaskWeaver and Djinn Stealer
https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain
4β£ Lazarus-Linked npm Malware
https://research.jfrog.com/post/rollup-polyfill-masquerading
5β£ DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
#NetSec
#AppSec
1β£ Zero-Day Exploitation of Vulnerability in Cisco Catalyst SD-WAN Manager
https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager
// CVE-2026-20245 + PoC
2β£ Caught in the Octopus Trap:
Unauthenticated RCE in Argo CD with CodeQL
https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql
// unauthenticated arbitrary code execution in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain control over the underlying Kubernetes cluster, and introduces a tool for automating the attack
Spring_Security_Zero_Π΄Π»Ρ_ΠΌΠ°ΡΡΠ΅ΡΡΡΠ²Π°_Π²ΠΌΠ΅ΡΡΠ΅_Ρ_JWT,_OAUTH2_2026_001.zip3745.36 MB
Zero_Point_Security_Red_Team_Ops_II_CRTL_Retired_Free_Writeup_2025.html45.12 MB
eLearnSecurity_eMAPT_2025_Free_Retired_Report_shared_by_Tamarisk.pdf6.77 KB
Repost from Rootsec [Cracked Softwares]
Btmob 4.5.7 trial
Server : 157.66.81.68
Admin Key: Z3QC-A1ZO-F2FH-U9Q9
http://157.66.81.68/yaarsa/user/create3192.php
#DFIR
1β£ A deep technical analysis of Windows input pipelines, security telemetry, and why PuTTY, WinSCP, MySQL, SSH, and SFTP passwords may leak into system memory
https://hexderef.com/windows-11-passwords-in-memory-lsass-ctfmon-analysis
2β£ Aether - Windows memory-forensics and threat hunting tool
https://github.com/0xsp-SRD/aether
#DevOps
#Tech_book
#Cyber_Education
"Fundamentals of DevOps and Software Delivery:
A Hands-On Guide to Deploying and Managing Software in Production", 2025.
]-> Code samples
