uk
Feedback
İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

Відкрити в Telegram

Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.

Показати більше
1 114
Підписники
-124 години
+27 днів
+930 днів
Архів дописів
#tools #Malware_analysis #Blue_Team_Techniques RuleAutoPilot: Synthesizing Deployable Suricata Rules from Network Traffic", Sep 2026. // RuleAutoPilot - end-to-end agentic framework that generates deployable Suricata rules directly from malware network traffic, with no prior threat intelligence required. A key challenge is noise: network traffic captures often contain a small amount of security-relevant traffic mixed with large volumes of background traffic, which reduces LLM reasoning quality and increases cost. RuleAutoPilot addresses this challenge with a Benign Traffic Fingerprinting stage that removes known benign background flows before LLM processing

#AppSec #Research #WebApp_Security "IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications", Sep 2026. ]-> https://github.com/GuanhangShiFDU/IDOR-GUARD // Cross-language IDOR reproduction and defense demo for Java, Python, Go, and PHP applications. Evaluated applications include XXL-Job, RuoYi, BootDo, wger, Gitea, Krayin, and Langflow

#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability 3⃣ Next Nightmare Eclipse Vulnerability // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques 🔟 Beltdown: Escaping the Claude Code sandbox // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user

#reversing #Malware_analysis Malware Analysis Series (MAS): Article 10 - Linux, 2025. ]-> Article 09 - Shellcode (.pdf) ]-> Articles 01 - 08 // last article of MAS series.

#Threat_Research #Malware_analysis 1⃣ Robobox: Self driven malware creation and execution https://netaskari.substack.com/p/robobox-self-driven-malware-creation 2⃣ UpdraftPlus: PHP backdoor delivery attempts via CVE-2026-10795 https://offseq.com/en/research/the-backdoor-inside-the-backup-request 3⃣ Tengu: Reverse Engineering a Mirai-Style Linux/IoT Botnet https://app.reverser.space/p/duckie/tengu-reverse-engineering-a-mirai-style-linux-iot 4⃣ PEEP: A Chrome Extension RAT https://socradar.io/blog/peep-browser-rat-chrome-extension

#exploit #AppSec 1⃣ FalconFlank - Crowdstrike Falcon 0day Privilege Escalation Vulnerability https://github.com/MSNightmare/FalconFlank 2⃣ Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days https://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-raining-0days.html 3⃣ Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint https://www.mannulinux.org/2026/08/Privilege-escalation-from-IIS-AppPool-to-NT-AuthoritySYSTEM-via-AD-CS-RPC-endpoint.html ]-> Certi-Bhai - AD CS Exploitation Toolkit

Herkese selam, Bugün saat 20.00’da, grubu takip eden aktif üyelerimize özel “Siber Olaylara Müdahale Eğitimi (Windows Forensics)” eğitimi için ücretsiz kayıt linkini paylaşacağım. Yayınlanacak link üzerinden yalnızca ilk 9 kişi ücretsiz kayıt olabilecek. Eğitim Udemy üzerinde yer almakta olup detaylarına aşağıdaki linkten ulaşabilirsiniz. https://www.udemy.com/course/siber-olaylara-mudahale-egitimi-windows-forensics/

#Threat_Research #WebApp_Security Attack of The Extensions https://specterops.io/blog/2026/08/13/chromium-extension-c2-persistence // Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft

CVE-2026-18963 KeyCloak * reset-credentials bypass → unauthenticated account takeover PoCexploit
CVE-2026-18963 KeyCloak * reset-credentials bypass → unauthenticated account takeover PoCexploit

CVE-2026-20217 File Drop to RCE * full WriteUP + PoC
CVE-2026-20217 File Drop to RCE * full WriteUP + PoC

#tools #Hardware_Security CPU Privilege Escalation https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii ]-> DEF CON 2026 - Weaponizing Uselessness (.pdf) ]-> Unlocking everything on the CPU with DRAM scrambling - PSP, C6, microcode, SMM, and anything else the specs left out

CVE-2026-41452 Krayin CRM * Auth Bypass → Admin Takeover PoC
CVE-2026-41452 Krayin CRM * Auth Bypass → Admin Takeover PoC

Продолжаем делиться интересным * DEFCON: New Red Team Tactic - EvilFontTool
Продолжаем делиться интересным * DEFCON: New Red Team Tactic - EvilFontTool

#exploit #Kernel_Security #Mobile_security IonStack Vulnerability Chain Part 1 - Unsound IonBanana Peel in Ion Compiler, Slip
#exploit #Kernel_Security #Mobile_security IonStack Vulnerability Chain Part 1 - Unsound IonBanana Peel in Ion Compiler, Slipping Through Firefox's SpiderMonkey JIT // IonMonkey CVE-2026-10702 Part 2 - GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years // GhostLock (CVE-2026-43499) + CVE-2026-53166 Part 3 - Rooting Android 17 with GhostLock // Using GhostLock to develop the world's first public root for Android 17 // Disclaimer