ππ€π€π©πππ
Open in Telegram
Free content of OFF-SEC, SANS, ec-council, INE, eLearnSecurity, udemy coupons and many more #Malware_analysis #RootSec
Show more1 774
Subscribers
+224 hours
+127 days
+2830 days
Posts Archive
#info
#Threat_Research
The Dangers of Reusing Protobuf Definitions:
Critical Code Execution in protobuf.js
https://www.endorlabs.com/learn/the-dangers-of-reusing-protobuf-definitions-critical-code-execution-in-protobuf-js-ghsa-xq3m-2v4x-88gg
// The vulnerability has a critical severity score (CVSS 9.4) and affects protobufjs β€ 8.0.0 and β€ 7.5.4. Patches are available in 8.0.1 and 7.5.5
#exploit
#AppSec
1β£ MAD Bugs: Even "cat readme.txt" is not safe
https://blog.calif.io/p/mad-bugs-even-cat-readmetxt-is-not
// iTerm2's SSH protocol integration is vulnerable to impersonation via malicious terminal escape sequences, enabling arbitrary code execution
2β£ Windows Event Tracing Insufficient Validation Leading to EoP
https://starlabs.sg/advisories/25/25-47985
// CVE-2025-47985
3β£ Remote Unauth'd RCE-to-root Chain in CUPS
https://heyitsas.im/posts/cups
// CVE-2026-34980, CVE-2026-34990
4β£ Unauthenticated RCE in FortiSandbox
https://github.com/samu-delucas/CVE-2026-39808
// CVE-2026-39808
#AIOps
"Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents", 2026.
// Environment-injected Trajectory-based Agent Memory Poisoning (eTAMP), the first attack to achieve cross-session, cross-site compromise without requiring direct memory access
#Research
#cryptography
"Automated formal analysis of Signalβs Double Ratchet: attacks, fixes and security proofs", 2026.
// The Double Ratchet protocol is a core security component of several end-to-end encrypted communications services, primarily Signal Messenger, WhatsApp, and Facebook Messenger, servicing billions of users. We provide the first formal analysis of the DR covering all of its features, including out-of-order message arrivals
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events for the week (Apr.11-18, 2026)
1β£ Windows Defender 0-Day (RedSun)
// LPE technique that abuses Windows Defenderβs cloud file rollback mechanism
2β£ Proxy Execution via WebView2
// WebView2 Runtime is vulnerable to DLL sideloading attacks due to reliance on a vulnerable DLL, enabling persistent arbitrary code execution in Windows apps, with no current fix from Microsoft...
3β£ RCE in Apache ActiveMQ
// CVE-2026-34197, exploited in the wild
4β£ Internet Protocol Version 8 (IPv8)
// Managed network protocol suite that transforms how networks of every scale are operated, secured, and monitored
5β£ CPUID Compromise
// The trojanized software was distributed both as ZIP archives and as standalone installers
6β£ Current Threats Against Kubernetes
// Modern threat actors continue to evolve their techniques for misusing Kubernetes environments...
7β£ Clearwing 1.0.0
// The challenge: Produce similar results as Glasswing - using models everyone has access to
8β£ ClickFix-style attack on macOS
// The discovered variant uses a browser-triggered workflow to launch Script Editor
9β£ OpenSSL 4.0.0 Final Release
channel:https://t.me/Rootsec_2
Channel :https://t.me/rootsec_p2
Coding :https://t.me/Root_cod3r
Chat :https://t.me/rootsec_chat
Rootsec backup 2 :https://t.me/Rootsec_backup
#Kernel_Security
From Kernel Snitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks
https://lukasmaar.github.io/posts/heap-kaslr-leak/index.html
]-> KernelSnitch + CrossCache Reuse Lab Workspace
// A practical heap KASLR leak that does not rely on a memory-safety vulnerability. Because the attack recovers valid kernel pointers without triggering invalid accesses, it remains exploitable on systems with MTE. More importantly, when the leaked mm_struct pointer is tagged (e.g., on Google Pixels), KernelSnitch can recover its logical tag as well, highlighting its potential as a tag oracle for the leaked object
#AppSec
#Threat_Research
1β£ Node.js Trust Falls:
Dangerous Module Resolution on Windows
https://www.zerodayinitiative.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows
2β£ Windows: Choose Where To Get Apps
https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps
3β£ Abusing WinML for In-Memory Staging and EDR Evasion
https://core-jmp.org/2026/04/abusing-winml-for-in-memory-staging-and-edr-evasion
#DFIR
#Whitepaper
"Windows Forensic Analysis Playbook",
Ver.2, Mar. 2026.
// 6 Critical Windows Artifacts: Jump Lists, LNK Files, RecentDocs/OpenSave MRU, Prefetch, SRUM, Windows Event Logs
#DFIR
"Metrics for the Computer Security Incident Response Team Services Framework", v.1.0, Jan. 2026.
// Its purpose is to define a practical, structured set of quantitative and qualitative metrics that organisations can use to assess, track, and improve the services described in the FIRST Framework. The metrics do not alter or reinterpret the underlying framework; instead, they build upon it by adding measurable indicators that align directly with each service function
#Cloud_Security
#Threat_Research
Avoid Entra Conditional Access
using alternative token broker
https://cloudbrothers.info/en/avoid-entra-conditional-access-sccauth
// With phishing-resistant authentication on the (slow) rise in enterprise environments attackers shift their focus away from AiTM or even more opportunistic password based attacks. They try to convince the user to download and execute info stealer malware to get ahold of the already forged tokens, directly from the endpoint
#Research
#WLAN_Security
"Beamforming Feedback as a Novel Attack Surface for Wi-Fi Physical-Layer Security", Apr. 2026.
// BFIAttack - new attack that exploits Beamforming Feedback Information to reconstruct the CSI of a legitimate user or device, thereby compromising Wi-Fi-based physical-layer security
#exploit
#5G_Network_Security
"Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities", Arp. 2026.
]-> Artifacts
// Syntactically valid but semantically inconsistent messages, which violate specification-level field constraints or cross-field dependencies, can drive baseband implementations into invalid states, triggering assertion failures or modem crashes
#NetSec
"Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNs", Apr. 2026.
// We present three session manipulation attacks targeting TCP and UDP traffic tunneled through VPNs. The attacker who only connects to the same VPN server can launch DoS attacks, hijack TCP connections of other clients, or inject forged DNS responses into their queries
#Research
#Kernel_Security
#Mobile_security
"Unveiling the Global Landscape of Android Security Updates", 2026.
// The study demonstrates that approximately 89.7% of vulnerabilities in unpatched Android devices (incl. the kernel and drivers) can be exploited remotely. The report analyzes vendor delays in delivering kernel patches for specific device models
#WLAN_Security
#Mobile_Security
"LightGuard: Transparent WiFi Security via Physical-Layer LiFi Key Bootstrapping", Apr. 2026.
]-> https://github.com/Dorian47/Lightguard
// cryptographic key establishment can be offloaded from WiFi to a physically confined LiFi channel to mitigate the risk of key exposure over RF
#tools
#AIOps
#MLSecOps
#Offensive_security
Recursive Autonomous Penetration Testing and Observation Robot
https://github.com/gadievron/raptor
// Autonomous Offensive/Defensive Security Research Framework, based on Claude Code
#info
#Cyber_Education
An interactive reference guide to cybersecurity training, careers, and certifications
https://okurrrr.dev
// 667 Certifications, 5 NICE Categories, 41 Work Roles, 1360 Learning Resources, 10170 NIST Glossary, 944 CWE Weaknesses, 28 Threat Reports, 47 Organizations, 558 CAPEC Attacks, 156 Conferences
#book
"Hacks, Leaks, and Revelations:
The Art of Analyzing Hacked and Leaked Data", 2024.
// Unlike any other point in history, hackers, whistleblowers, and archivists now routinely make off with terabytes of data from governments, corporations, and extremist groups. These datasets often contain gold mines of revelations in the public interest, and in many cases are freely available for anyone to download. Yet these digital tomes can prove extremely difficult to analyze or interpret, and few people today have the skills to do so...
