fa
Feedback
Волосатый бублик

Волосатый бублик

رفتن به کانال در Telegram

All credits to authors.

نمایش بیشتر
7 523
مشترکین
اطلاعاتی وجود ندارد24 ساعت
اطلاعاتی وجود ندارد7 روز
+2330 روز
آرشیو پست ها
Unauthenticated SQL injection in GUI https://fortiguard.fortinet.com/psirt/FG-IR-25-151

PoC for CVE-2025-48799, an elevation of privilege vulnerability in Windows Update service. https://github.com/Wh04m1001/CVE-2
PoC for CVE-2025-48799, an elevation of privilege vulnerability in Windows Update service. https://github.com/Wh04m1001/CVE-2025-48799/

Ну и про аутлук почитайте, все равно вам нечего делать в укрытии ( я не читал, на ваш страх и риск ) Microsoft Outlook - Remote Code Execution (RCE) CVE-2025-47176 Date: 07/06/2025 Reference: - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47176 > - https://www.cloudflare.com/learning/security/what-is-remote-code-execution/ https://www.exploit-db.com/exploits/52356

CVE-2025-5777 (CitrixBleed 2) - Critical memory leak vulnerability affecting Citrix NetScaler ADC and Gateway devices. PoC: https://github.com/win3zz/CVE-2025-5777

#bugbounty [ VulnIndex ] VulnIndex (alpha) is a growing catalog of public bug bounty reports, security writeups, and research
#bugbounty [ VulnIndex ] VulnIndex (alpha) is a growing catalog of public bug bounty reports, security writeups, and research blogs. We're curating what matters to researchers and defenders. Here’s what you can do 👇 ✅ Filter by: • Technology • Language • CWE • Repro steps • Vulnerable code • Severity • Award size • Date ...and more. By one of our members. Read this post for more details. https://vulnindex.ys0.dev

...........
...........

[ Abusing Chrome Remote Desktop on Red Team Operations: A Practical Guide ] Chrome Remote Desktop can offer red teamers a sub
[ Abusing Chrome Remote Desktop on Red Team Operations: A Practical Guide ] Chrome Remote Desktop can offer red teamers a subtle way to bypass restriction — if they know how to use it. In this blog, Oddvar Moe reveals a practical guide to repurposing Chrome Remote Desktop on red team operations. Read it now! https://trustedsec.com/blog/abusing-chrome-remote-desktop-on-red-team-operations-a-practical-guide

CVE-2025-32463: sudo 1.9.14-1.9.17 LPE Blog + exploit: https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-ch
CVE-2025-32463: sudo 1.9.14-1.9.17 LPE Blog + exploit: https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot Patched: June 28, 2025 #lpe #linux #pentest #redteam

Arbitrary File Read in pfSense 2.8.0 (authenticated user) CVE ID: CVE-2025-53392 Ну там много ЕСЛИ, но всё же.... https://git
Arbitrary File Read in pfSense 2.8.0 (authenticated user) CVE ID: CVE-2025-53392 Ну там много ЕСЛИ, но всё же.... https://github.com/skraft9/pfsense-security-research

#kerberos #diamon #ticket [ Recutting the Kerberos Diamond Ticket ] «In this post, we’ll refine the understanding of the diam
#kerberos #diamon #ticket [ Recutting the Kerberos Diamond Ticket ] «In this post, we’ll refine the understanding of the diamond ticket, bringing its brilliance to light. By focusing on operational security (OPSEC), we aim to give this concept the precision and weight or "carat" it deserves to offer a more secure method of working with Kerberos ticket forgery. We’ll not only address these misconceptions but also introduce a more OPSEC-focused version for Ticket Granting Tickets (TGTs) and demonstrate how the concept can be applied to Service Tickets (STs).» ✅ /opsec for a more genuine flow ✅ /ldap to populate the PAC 🆕 Forge a diamond service ticket using an ST https://www.huntress.com/blog/recutting-the-kerberos-diamond-ticket

#phishing FileFix - A ClickFix Alternative https://mrd0x.com/filefix-clickfix-alternative/

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 Product: Veeam Backup & Replication: 12, 12.1, 12.2, 12.3, 12.3
Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 Product: Veeam Backup & Replication: 12, 12.1, 12.2, 12.3, 12.3.1 Veeam Agent for Microsoft Windows: 6.0, 6.1, 6.2, 6.3, 6.3.1 A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. CVE-2025-23121 Severity: Critical CVSS v3.0 Score: 9.9

PoC Exploit for the NTLM reflection SMB flaw. https://github.com/mverschu/CVE-2025-33073 На ваш страх и риск
PoC Exploit for the NTLM reflection SMB flaw. https://github.com/mverschu/CVE-2025-33073 На ваш страх и риск

POC: https://github.com/kn0x0x/CVE-2025-32756-POC Опять фортик, уже с эксплойтом в паблике. Уже даже не интересно как-то. Все
POC: https://github.com/kn0x0x/CVE-2025-32756-POC Опять фортик, уже с эксплойтом в паблике. Уже даже не интересно как-то. Все привыкли. Видимо программисты у гитлаба, фортика и майкрософта одни и те же. а) Регулярно обновляйтесь б) Когда пентестеры просят отключить тот или иной защитный механизм это не потому что "у них лапки", а потому что сегодня способа обойти его нет, а завтра есть. Они проверяют ваш продукт, то как вы настроили инфраструктуру, то как вы обновляетесь и придумываете пароли etc, а не ваш антивирус, впн или фаервол.

https://github.com/mbanyamer/CVE-2025-30397---Windows-Server-2025-JScript-RCE-Use-After-Free- Когда-то давно, когда деревья были маленькими, а компьютеры большими, подобные штуки не были чем то удивительным. Зашел на сайт - подцепил заразу. Сейчас подобное редкость, правда не потому что программисты стали писать лучше, а потому что цена на подобные штуки выросла. Спрос, знаете ли..

https://fearsoff.org/research/roundcube Удаленное выполнение кода Roundcube Webmail до версии 1.5.10 и 1.6.x до версии 1.6.11 CVE-2025-49113 CVSS 9,9 POC: https://github.com/fearsoff-org/CVE-2025-49113 https://github.com/hakaioffsec/CVE-2025-49113-exploit Обновляйтесь, POC уже в продаже видел.

https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/ In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the session being free'd. The handler for that connection could be in the smb2_sess_setup function which makes use of sess->user. ——— Как то я пропустил cve-2025-37899, ушел обновляться.