𝙍𝙤𝙤𝙩𝙎𝙚𝙘
رفتن به کانال در Telegram
Free content of OFF-SEC, SANS, ec-council, INE, eLearnSecurity, udemy coupons and many more #Malware_analysis #RootSec
نمایش بیشتر1 764
مشترکین
+224 ساعت
+97 روز
+3030 روز
آرشیو پست ها
1 764
Repost from Rootsec [Cracked Softwares]
Burp Suite Professional v2026.7.2 + JDK 24
NOTE -
Run this version With Java SE JDK 24
Released Thursday 30 July 2026
#pentest #security1 764
Repost from Team BlackDragonSec 🇮🇳
+4
TARGET COMPROMISED 🇵🇰🐖🐖
We, Black Dragon Sec, have successfully conducted a cyber operation against Pakistani network infrastructure. During this operation,We have compromised 1,500+ routers across multiple targets.This operation is our response to what we view as continued cyber aggression against India Jai Hind 🇮🇳 Jai Bharat 🇮🇳 -- Indian Hackers Rulzz Threat Actor: Cryptic1337 & BlurryFace98
1 764
*🚀 Stop losing great ideas in endless open tabs! Meet BrainTab — your AI Second Brain. 🧠*
Instead of losing track of your research, *BrainTab* automatically captures, summarizes, and visually connects everything you read online.
Why you'll love it:
*Instant Auto-Summaries*: Get the core insights from any webpage instantly—no more reading huge walls of text.
*Visual Knowledge Graph*: See hidden connections between your topics and research mapped out beautifully.
*Chat with Kira AI*: Talk directly to your browsing history to find past research or ask questions.
*Smart Search*: Instantly rediscover that one article you read weeks ago.
*Privacy First*: Your data stays locally on your device.
Turn your messy browser history into a smart, searchable knowledge network today!
👉 Get it here: [https://chromewebstore.google.com/detail/dkbkdefcjdgnkokffcfkacaidojlekhb?utm_source=item-share-cb]
*#BrainTab* #Productivity *#AI #SecondBrain #Tech*
1 764
#reversing
#Mobile_security
"Beyond Conventional Triggers:
Auto-Contextualized Covert Triggers for Android Logic Bombs", Feb. 2026.
// A study (paper) on Android malware reverse engineering. The authors analyze the evolution of hidden triggers (logic bombs) in mobile apps that activate malicious functionality only when complex system contexts (battery status, geolocation, and the user launching specific utilities) coincide. This allows them to successfully evade detection in automated sandboxes
1 764
#tools
#Kernel_Security
#Malware_analysis
"KraKenGuard: Towards Fine-Grained eBPF Isolation", May 2026.
// A deep dive into the security of the kernel's eBPF subsystem, which is increasingly being exploited by attackers to create stealthy rootkits. The presentation describes a symbolic execution-based isolation architecture (KraKenGuard), which prevents host memory attacks from untrusted eBPF programs
1 764
#compilers
#Sec_code_review
"RUSTMIZAN: ACompilable, Contamination-Aware Benchmarking Framework for Rust Vulnerabilities",
Jul 2026.
]-> https://github.com/sfu-rsl/rust-mizan
// LLM agents are increasingly applied to vulnerability analysis, but existing benchmarks have not kept pace. They typically rely on small non-compilable snippets, focus on binary classification, and do not account for the risk that publicly-released datasets are part of model training corpora. RustMizan - framework for Rust vulnerability analysis that addresses these gaps
1 764
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events (June 27 - July 04, 2026)
1⃣ Bad Epoll (CVE-2026-46242)
https://github.com/J-jaeyoung/bad-epoll
// race-condition UaF in the Linux kernel's epoll subsystem
2⃣ Mitigated API authentication bypass for python*org download metadata
https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org
3⃣ Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed
https://github.com/bikini/exploitarium
4⃣ Beware of the license manager:
how a Schneider Electric software vulnerability puts industrial facilities at risk
https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436
5⃣ Apple Hide My Email Vulnerability
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses
6⃣ DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
7⃣ Google Gemini CLI Vulnerability
https://github.com/advisories/GHSA-jj69-4grx-fqj5
// CVE-2026-12537
8⃣ Apache MINA Deserialization Bypass to RCE
https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce
// CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6
1 764
#Malware_analysis
1⃣ RustDuck Botnet
https://blog.xlab.qianxin.com/rustduck-en
2⃣ Glitch SPY Android RAT
https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app
3⃣ TaskWeaver and Djinn Stealer
https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain
4⃣ Lazarus-Linked npm Malware
https://research.jfrog.com/post/rollup-polyfill-masquerading
5⃣ DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
1 764
#NetSec
#AppSec
1⃣ Zero-Day Exploitation of Vulnerability in Cisco Catalyst SD-WAN Manager
https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager
// CVE-2026-20245 + PoC
2⃣ Caught in the Octopus Trap:
Unauthenticated RCE in Argo CD with CodeQL
https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql
// unauthenticated arbitrary code execution in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain control over the underlying Kubernetes cluster, and introduces a tool for automating the attack
