fa
Feedback
Bug bounty Tips

Bug bounty Tips

رفتن به کانال در Telegram

🛡️ Cybersecurity enthusiast | 💻 Helping secure the digital world | 🌐 Web App Tester | 🕵️‍♂️ OSINT Specialist Admin: @laazy_hack3r

نمایش بیشتر
5 779
مشترکین
+1024 ساعت
+887 روز
+41930 روز
آرشیو پست ها
#Kernel_Security #Malware_analysis DragonBreath: Dragon in the Kernel https://ransom-isac.org/blog/dragonbreath-dragon-in-the-kernel // A 0-day BYOVD vulnerability in dragoncore_k.sys signed by Zhengzhou 403 Network Technology, with shell company analysis, Dragon Breath APT-Q-27 attribution, and an APT31 / Wuhan Xiaoruizhi personnel nexus

#tools #RAG_Security "CleanBase: Detecting Malicious Documents in RAG Knowledge Databases", May 2026. // CleanBase - framework for detecting malicious documents in RAG systems’ knowledge database

#Offensive_security Bypassing Windows (11 24H2/Server 2025) authentication reflection mitigations for SYSTEM shells Part 1 (CVE-2025-33073) Part 2 (CVE-2026-26128) // Authentication relay (or reflection) attacks will persist as long as integrity mechanisms are not enforced by default on Windows services

#Research #Offensive_security GPT-5.5 vs Claude Opus 4.7 for Pentesting: A Practical Workflow-Based Comparison https://www.penligent.ai/hackinglabs/gpt-5-5-vs-claude-opus-4-7-for-pentesting-a-practical-workflow-based-comparison // A model that writes convincing exploit code is not automatically useful for pentesting. A model that explains a vulnerability clearly is not automatically able to verify it. A model that scores well on coding or agent benchmarks is not automatically safe to connect to scanners, browsers, shells, credentials, or production-like targets...

#AppSec #Tech_book #Cloud_Security "Container Security: Fundamental Technology Concepts that Protect Cloud Native Applications", 2026. // you will learn about many of the building block technologies and mechanisms that are commonly used in container-based systems and how they are constructed in Linux. We will dive deep into the underpinnings of how containers work and how they communicate so that you are well versed not just in the "what" of container security but also, and more importantly, in the "why"

#Hardware_Security "GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer", Apr. 2026. ]-> https://gpubreach.ca ]-> Repo // GPUBreach shows that GPU Rowhammer attacks can move beyond data corruption to real privilege escalation. By corrupting GPU page tables, an unprivileged CUDA kernel can gain arbitrary GPU memory read/write, and then chain that capability into CPU-side escalation by exploiting newly discovered memory-safety bugs in the NVIDIA driver. The result is system-wide compromise up to a root shell, without disabling IOMMU, unlike contemporary works, making GPUBreach a more potent threat

#NetSec "One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name Resolution", BlackHat Asia 2026. // we conducted the first systematic study of special character handling logic in DNS, reviewing DNS RFCs and analyzing 31 widely-used DNS software implementations through source code review and gray-box testing. Our systematic analysis reveals two new DNS logic vulnerabilities arising from inconsistencies and silent handling behaviors, leading to two classes of attacks that affect all DNS roles, including stub resolvers, forwarders, recursive resolvers, and authoritative nameservers See also: ]-> RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox (.pdf)

#IoT_Security #Automotive_Security "When Flash Reveals Its Secrets: Advanced Glitching Leveraging Hidden CPU-eMMC Behavior", BlackHat Asia 2026. ]-> https://github.com/xcatx9527/wfm_cmp // Complete process of successfully bypassing Secure Boot on real embedded devices using this method and reveal the physical leakage paths that exist between the CPU and peripheral storage during runtime

#Hardware_Security "Qualcomm BootROM: A journey through Sahara", BlackHat Asia 2026. // This Briefing will present a comprehensive analysis of new vulnerabilities found by our team at the BootROM level: vulnerabilities in Emergency Download Mode and its Sahara protocol, which allow bypassing cryptographic verification of Secondary Boot Loader images and subsequent boot stages See also: ]-> BlackHat Asia 2026 - ALL Briefings

#Analytics #Threat_Research An analytical review of the main cybersecurity events for the week (Apr.18-25, 2026) 1⃣  Hacking Safari with GPT 5.4 // A Safari WebAssembly memory bug combined with fetch cloning flaws enabled cross-origin data leaks 2⃣  PhantomRPC: A new privilege escalation technique in Windows RPC // PoC + Toolset 3⃣  Pentest Copilot // An open-source, AI-driven penetration testing agent 4⃣  Uncovering Global Telecom Exploitation by Covert Surveillance Actors // Weak screening of interconnect traffic allowed attackers to route surveillance messages through trusted operator pathways, enabling access to targeted networks 5⃣  Pack2TheRoot: Cross-Distro LPE Vulnerability // CVE-2026-41651 6⃣  P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet // Investigation Reveals Critical Security Gaps On Thousands of Servers Affecting Organisations Across Games, Healthcare, Finance, Government & More 7⃣  Kyber Ransomware Double Trouble // Kyber is a cross-platform ransomware family targeting Linux/ESXi and Windows environments 8⃣ Claude-Red-Skills // 38 offensive security skills for Claude 9⃣  WireGuard 1.0 for Windows ]-> Analytical review (Apr.11-18, 2026)

#MLSecOps #Threat_Research "The Mother of All AI Supply Chains: Critical, Systemic Vulnerability at the Core of Anthropic’s MCP", Apr. 2026. // Enables unauthorized access to sensitive user data, internal databases, and API keys. Affects 150M+ downloads across Python, TypeScript, Java, and Rust MCP SDKs. Verified Zero-Click Prompt Injection in Cursor and Windsurf, plus "poisoned" MCP registries. Impacting industry staples like LangChain, LiteLLM, and IBM’s LangFlow

Pentesting Guide.pdf18.90 MB

the pentester's playbook - codelivly.pdf1.75 MB

Cybersecurity Roadmap 2026.pdf24.89 MB