uz
Feedback
CyberSecurityTechnologies

CyberSecurityTechnologies

Yopiq kanal

We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel

Ko'proq ko'rsatish

📈 Telegram kanali CyberSecurityTechnologies analitikasi

CyberSecurityTechnologies Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 34 096 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 3 842-o'rinni va AQSH mintaqasida 1 186-o'rinni egallagan.

📊 Auditoriya ko‘rsatkichlari va dinamika

невідомо sanasidan buyon loyiha tez o‘sib, 34 096 obunachiga ega bo‘ldi.

07 Oktabr, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni -403 ga, so‘nggi 24 soatda esa -8 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.

  • Tasdiqlash holati: Tasdiqlanmagan
  • Jalb etish (ER): Auditoriya o‘rtacha 5.87% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 2.94% ini tashkil etuvchi reaksiyalarni to‘playdi.
  • Post qamrovi: Har bir post o‘rtacha 2 003 marta ko‘riladi; birinchi sutkada odatda 1 003 ta ko‘rish yig‘iladi.
  • Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 5 ta reaksiya keladi.
  • Tematik yo‘nalishlar: Kontent cve-2025, attack, threat, detection, llm kabi asosiy mavzularga jamlangan.

📝 Tavsif va kontent siyosati

Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
“We have been working for YOU for more than 8 years!!! https://t.me/+9vdG4JOSgY8xMzdi See also: https://t.me/Cognitive_Security https://t.me/CyberSecurityOSINT https://t.me/Wireless_Cybersecurity For All Questions: in messages to the channel”

Yuqori yangilanish chastotasi (oxirgi ma’lumot 08 Oktabr, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.

34 096
Obunachilar
-824 soatlar
-827 kun
-40330 kun
Obunachilarni jalb qilish
Okt '26
Oktabr '260
1 kanalda
Sentabr '26
+9
8 kanalda
Get PRO
Avgust '26
+2
9 kanalda
Get PRO
Iyul '26
+8
4 kanalda
Get PRO
Iyun '26
+2
2 kanalda
Get PRO
May '26
+8
8 kanalda
Get PRO
Aprel '26
+5
5 kanalda
Get PRO
Mart '26
+6
6 kanalda
Get PRO
Fevral '26
+53
12 kanalda
Get PRO
Yanvar '26
+5
5 kanalda
Get PRO
Dekabr '25
+30
10 kanalda
Get PRO
Noyabr '25
+5
10 kanalda
Get PRO
Oktabr '25
+103
11 kanalda
Get PRO
Sentabr '25
+169
11 kanalda
Get PRO
Avgust '25
+181
14 kanalda
Get PRO
Iyul '25
+216
13 kanalda
Get PRO
Iyun '25
+140
8 kanalda
Get PRO
May '25
+80
4 kanalda
Get PRO
Aprel '25
+110
4 kanalda
Get PRO
Mart '25
+154
7 kanalda
Get PRO
Fevral '25
+150
7 kanalda
Get PRO
Yanvar '25
+153
10 kanalda
Get PRO
Dekabr '24
+614
6 kanalda
Get PRO
Noyabr '24
+2 694
9 kanalda
Get PRO
Oktabr '24
+3 905
8 kanalda
Get PRO
Sentabr '24
+3 114
4 kanalda
Get PRO
Avgust '24
+3 425
7 kanalda
Get PRO
Iyul '24
+3 738
2 kanalda
Get PRO
Iyun '24
+3 441
3 kanalda
Get PRO
May '24
+3 316
1 kanalda
Get PRO
Aprel '24
+3 222
4 kanalda
Get PRO
Mart '24
+3 443
6 kanalda
Get PRO
Fevral '24
+2 626
4 kanalda
Get PRO
Yanvar '24
+1 689
8 kanalda
Get PRO
Dekabr '23
+1 310
2 kanalda
Get PRO
Noyabr '23
+273
7 kanalda
Get PRO
Oktabr '23
+331
2 kanalda
Get PRO
Sentabr '23
+322
0 kanalda
Get PRO
Avgust '23
+197
0 kanalda
Get PRO
Iyul '23
+179
0 kanalda
Get PRO
Iyun '23
+148
0 kanalda
Get PRO
May '23
+149
0 kanalda
Get PRO
Aprel '23
+210
0 kanalda
Get PRO
Mart '23
+149
0 kanalda
Get PRO
Fevral '23
+149
0 kanalda
Get PRO
Yanvar '23
+141
0 kanalda
Get PRO
Dekabr '22
+187
0 kanalda
Get PRO
Noyabr '22
+288
0 kanalda
Get PRO
Oktabr '22
+140
0 kanalda
Get PRO
Sentabr '22
+192
0 kanalda
Get PRO
Avgust '22
+672
0 kanalda
Get PRO
Iyul '22
+174
0 kanalda
Get PRO
Iyun '22
+162
0 kanalda
Get PRO
May '22
+168
0 kanalda
Get PRO
Aprel '22
+129
0 kanalda
Get PRO
Mart '22
+163
0 kanalda
Get PRO
Fevral '22
+315
0 kanalda
Get PRO
Yanvar '22
+154
0 kanalda
Get PRO
Dekabr '21
+247
0 kanalda
Get PRO
Noyabr '21
+119
0 kanalda
Get PRO
Oktabr '21
+157
0 kanalda
Get PRO
Sentabr '21
+126
0 kanalda
Get PRO
Avgust '21
+346
0 kanalda
Get PRO
Iyul '21
+140
0 kanalda
Get PRO
Iyun '21
+409
0 kanalda
Get PRO
May '21
+97
0 kanalda
Get PRO
Aprel '21
+315
0 kanalda
Get PRO
Mart '21
+199
0 kanalda
Get PRO
Fevral '21
+220
0 kanalda
Get PRO
Yanvar '21
+211
0 kanalda
Get PRO
Dekabr '20
+2 406
0 kanalda
Sana
Obunachilarni jalb qilish
Esdaliklar
Kanallar
08 Oktabr0
07 Oktabr0
06 Oktabr0
05 Oktabr0
04 Oktabr0
03 Oktabr0
02 Oktabr0
01 Oktabr0
Kanal postlari
#exploit WordPress, ImageMagick and libheif unci RCE https://fortbridge.co.uk/research/wordpress-libheif-rce ]-> PoC // Reproducible WordPress/ImageMagick libheif unci RCE chain for exact Ubuntu and Debian builds, with HTTP-derived ASLR addresses // Disclaimer

2
#SCADA_Security "Bridge:Break: Vulnerabilities Thrive in Serial-to-Ethernet Converters", 2026. See also: ]-> Fooling the Master: Pepperl+Fuchs IO-Link Under Attack ]-> Chilling Discoveries: Unpacking Vulnerabilities in Copeland XWEB Pro Controllers
862
3
#AppSec #WebApp_Security #Offensive_security "CSS: the bomb inside your inbox", Aug. 2026. ]-> Repo ]-> Research paper ]-> Smashing the token limit with overlapping fragments // A graph-based technique enhances CSS-only token exfiltration by reconstructing tokens from overlapping fragments with high accuracy and reduced payload size, scalable to longer tokens, and automated via Burp AT
1 039
4
#NetSec #MLSecOps "Cooldown Landmines: Cross-Tenant Interference Attacks on LLM Gateways", Oct 2026. ]-> This repo contains the paper draft, experiments, and data for a cross-tenant vulnerability class in multi-tenant LLM gateways (LiteLLM, Portkey, Kong AI Gateway)
1 269
5
#Whitepaper Security Awareness Roadmap: Managing Your Human Risk, 2026. // Leverage this poster to quickly determine why your program may not be having the impact your want, proven steps you can take to mature your program, and how to communicate the value of the program to your leadership
1 207
6
#Research #Hardware_Security "TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows", 2026. ]-> https://github.com/MATCHA-MIT/TONTOU-Interrupt-Injection // The paper is devoted to a practical analysis of ARM's MTE (Memory Tagging Extension) hardware technology, which is widely used in modern mobile processors to protect memory. The researchers examine in detail the "windows" between threat mitigation and data exploitation, demonstrating the possibility of bypassing hardware barriers
1 286
7
#NetSec #Research #cryptography "Mind the Gap: Proving and Improving RPKI", 2026. ]-> https://github.com/shaycohen988/routinator-multi-resolver // This work presents the first rigorous security analysis of the Resource Public Key Infrastructure, an IETF standard for protecting inter-domain routing from basic yet effective attacks: prefix and subprefix hijacks. It focuses on rigorous, modular security specifications and analysis of RPKI, including its interactions with BGP and IP. It shows that existing RPKI deployments do not always meet these conditions, e.g., because of circular dependencies, and proposes standard-compliant improvements that restore them
1 420
8
#RAG_Security "Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM", Oct. 2026. ]-> https://github.com/Jisung-Pacific/HDI-GraphRAG-Attack // GraphRAG pipelines construct auxiliary structures during offline indexing - semantic summaries, hierarchical edges, and pre-computed scores - that determine how retrieval is prioritized at query time. Prior attacks target only instance-level components (nodes, edges, triples), overlooking these schema-level structures. This work formalizes the Auxiliary Schema-Level Entity as a novel attack surface and proposes the 3S Framework (Semantics, Structure, Scoring) for its systematic exploitation. Its Hop-Decayed Influence attack identifies high-impact targets through query-aware influence propagation and corrupts their auxiliary structures post-indexing
1 351
9
#Malware_analysis 1⃣ CloudSyncD: macOS backdoor hidden in a fake Zoom installer https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer 2⃣ knock-outd: an undetected port-knocking backdoor in the wild https://www.virlabs.ai/blog/knock-outd 3⃣ Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis https://github.com/Kavan00/Android-Projector-C2-Malware
1 449
10
#Tech_book #Offensive_security #Red_Team_Tactics "Red Team Engineering: The Art of Building Offensive Tools and Infrastructure", 2026. ]-> Various course materials, scripts, and configurations
2 603
11
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 26 - Oct 03, 2026) 1⃣ Here We Go Again: Citrix NetScaler DTLS Preauth Memory Overflow // CVE-2026-88772 2⃣ A Realistic Code Execution Exploit Chain in OpenBao and Vault 3⃣ Attackers abuse ChatGPT to deliver RAT via ClickFix 4⃣ Poper Blocker: The Adblocker That Spies on You 5⃣ PoC for macOS CoreServices Priv. Escalation // CVE-2026-43786 6⃣ PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 7⃣ CVE-2026-86950: The Great Glyph Grift // An in-the-wild iOS bug with a possible WhatsApp zero-click path 8⃣ Stopping a coordinated campaign to distill models 9⃣ nDPI TCP Fingerprint: A Stable, Patent-Free Way to Fingerprint TCP Stacks
1 723
12
#SCA #compilers #Kernel_Security "Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries", Oct. 2026. ]-> Repo ]-> BTR end-to-end exploit on cBPF // A new BTR (Branch Target Reuse) attack method has been developed, belonging to the Spectre-v2 class, allowing for the bypass of memory isolation mechanisms on systems with Intel, AMD, ARM processors. Memory leaks are initiated during speculative instruction execution during a BTR attack by manipulating JIT compilers. The feasibility of attacking through the cBPF JIT engines in the Linux kernel, Oracle GraalVM, and SpiderMonkey in Firefox has been analyzed
1 604
13
#SCA #Whitepaper "Invisible by Default: The Polyglot Smuggler", Sep 2026. // This paper demonstrates a novel data smuggling mechanism: Sub-Channel Steganography. By weaponizing uninspected MP4 subtitle tracks within a structurally compliant ISO base media file, adversaries can encapsulate malicious payloads and exfiltrate sensitive data. Utilizing entirely native LotL interpreters for bidirectional extraction, this polyglot methodology successfully circumvents network DLP and CDR systems while eliminating the forensic artifacts traditionally monitored by endpoint defenses
1 641
14
#AppSec 1⃣ Sender spoofing in Proton Mail via display-name homograph https://alonsovidales.github.io/protonmail-sender-spoofing 2⃣ Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610 https://www.intrinsec.com/cve-2026-50610-elevation-privileges-acer-nitrosense 3⃣ Spoofing Arbitrary Apple iCloud Identities https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities 4⃣ Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739) https://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html
1 598
15
#MLSecOps #Threat_Research #Malware_analysis "The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching", Oct. 2026. // In this paper, the authors demonstrate with LLMLeak a novel attack vector where malicious software that runs locally but cannot communicate directly with the internet abuses LLMs to establish a covert channel. While inputs that instruct the LLM to send data directly via generated code are easy to detect and network libraries are typically restricted, LLMLeak relies only on the LLM’s tool to fetch websites for further information
1 486
16
#NetSec JA4Scan: Active Server Fingerprinting for TLS and QUIC https://foxio.io/blog/introducing-ja4scan-active-server-finger
#NetSec JA4Scan: Active Server Fingerprinting for TLS and QUIC https://foxio.io/blog/introducing-ja4scan-active-server-fingerprinting-for-tls-and-quic // JA4Scan-TLS and JA4Scan-QUIC - latest additions to the JA4+ suite of fingerprinting methods. Together they fingerprint the TLS and QUIC libraries running on any given server, uncovering both the running TLS/QUIC stack and its configuration
1 579
17
#MLSecOps "CodeMimicry Exploiting Safety Generalization Lag in Large Language Models via Structured Code Completion", Sep 2026. ]-> https://github.com/lzzzr123/CodeMimicry // In this work, it identifies a previously underexplored failure mode - safety generalization lag - where alignment trained predominantly on natural language fails to transfer to the code domain. The work shows that this lag induces a code-completion blind spot, allowing malicious intent embedded within syntactically valid code to evade safety mechanisms
1 755
18
#NetSec #hardening Cisco Catalyst SD-WAN Hardening Guide https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide ]-> Cisco IOS XE Software Hardening Guide
1 632
19
#tools #Hardware_Security "Implementing Data Diodes Using Commodity Hardware and Open Source Software", Sep 2026. ]-> https://github.com/ClarkuCSCI/pydiode // The authors tested three existing open source programs for one-way data transfers: netcat, UDPcast, and lidi. Although these programs were unreliable in their default configurations, reliable configurations were identified for UDPcast and lidi. Finally, these findings were incorporated into pydiode, a cross-platform program for reliable one-way data transfers
1 934
20
#Threat_Research Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances ]-> How to Fix CVE-2026-88771 and CVE-2026-88772
1 848