Cyberwar Zone
رفتن به کانال در Telegram
✅CyberSecurity 👁🗨ThreatIntel ✖️APT 👾Malware 🔃RE 🐞Bug Bounty 🆙DevSecOps 🔎OSINT 💡Forensic 🔐Web Application Security 📲Mobile Security ⛓️BlockChain Security 🔝Tips & Tools Language : English & Farsi
نمایش بیشتر612
مشترکین
اطلاعاتی وجود ندارد24 ساعت
+27 روز
+230 روز
آرشیو پست ها
#منهای_امنیت
دلار 90 هزار تومنی و سکه 70 میلیون تومنی.
این سوی شهر مردمی با کمرهای خمیده و روزگاری سیاه شده، پدران شرمنده، کودکان کار، بازار فروش اعضای بدن، تن فروشان و و و . . .
آنسوی ماجرا؛ حاکمان بی مصرف با شکم های سیر از بیت المال، از کاخ های شمال شهر خود از مردم خواسته اند که مقاوم باشند!
قصه ی پر غصه ی مردم مظلوم #ایران
#ما_ژن_خوب_نیستیم
#دردا_و_دریغا_وطن_من_وطن_من
Introduction to Fuzzing Android Native Components: Strategies for Harness Creation
https://blog.convisoappsec.com/en/introduction-to-fuzzing-android-native-components-strategies-for-harness-creation
Secure by Design: Google's Blueprint for a High-Assurance Web Framework
https://bughunters.google.com/blog/6644316274294784/secure-by-design-google-s-blueprint-for-a-high-assurance-web-framework
Repost from club1337
Analysis on how CVE-2025-0411, a zero-day vulnerability in 7-Zip, is actively exploited to target Ukrainian organizations in a #SmokeLoader campaign involving homoglyph attacks
https://www.bleepingcomputer.com/news/security/7-zip-motw-bypass-exploited-in-zero-day-attacks-against-ukraine/
https://www.trendmicro.com/en_us/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html
@club31337
Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access
https://thehackernews.com/2025/02/malicious-go-package-exploits-module.html
Repost from digMeMore
خب لیست نهایی منتشر شد، مقاله امید جز ۱۰ تای برتر انتخاب شد، تبریک با ذوق فراوان به امید بابت این دستاورد مهم، واقعا حقت بود چون میدونم چقدر زحمت کشیدی براش، روش خلاقانه و قشنگی رو پیدا کردی و کارت عالی بود. ایشالا همیشه بدرخشی ❤️
https://portswigger.net/research/top-10-web-hacking-techniques-of-2024
AMD: Microcode Signature Verification Vulnerability
https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w
MasterCard DNS Error Went Unnoticed for Years🤯
گاهی آسیب پذیری روی سامانه های بزرگ اونقدر جلوی چشم هست که بهش توجه نمیشه و بعد از چند سال یهو اینطوری با یه dig ساده کشف میشه!
https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years/
Common OAuth Vulnerabilities
https://blog.doyensec.com/2025/01/30/oauth-common-vulnerabilities.html
Repost from SoheilSec
Ah shit, here we go again 🤔
https://x.com/jsrailton/status/1885517753295180248?s=19
CRLF injection via TryAddWithoutValidation in .NET
https://binarysecurity.no/posts/2025/01/tryaddwithoutvalidation
Exploiting Hardened .NET Deserialization by Piotr Bazydło
https://www.youtube.com/watch?v=_CJmUh0_uOM
Supply Chain Attacks in Web3: A New Era
https://osec.io/blog/2024-06-10-supply-chain-attacks-a-new-era
Next.js, cache, and chains: the stale elixir🧩
https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir
Attacks on Maven proxy repositories
https://github.blog/security/vulnerability-research/attacks-on-maven-proxy-repositories/
