Securityblog's profile picture. There are 10 types of people in the world. Those who understand binary, and those who don't. All opinions and views are my own. #BsidesDub organizer

Securityblog

@Securityblog

There are 10 types of people in the world. Those who understand binary, and those who don't. All opinions and views are my own. #BsidesDub organizer

Securityblog รีโพสต์แล้ว

🔥 The Advent of Cyber warm-up is LIVE! From uncovering Suspicious Chocolate…to making a Chatbot confess 👀 We’ve dropped 10 prep-track challenges to get your skills fired up before AOC officially begins on December 1st. This is your pre-season training. Your bootcamp. Your…

tryhackme's tweet image. 🔥 The Advent of Cyber warm-up is LIVE!
From uncovering Suspicious Chocolate…to making a Chatbot confess 👀 

We’ve dropped 10 prep-track challenges to get your skills fired up before AOC officially begins on December 1st.

This is your pre-season training. Your bootcamp. Your…
tryhackme's tweet image. 🔥 The Advent of Cyber warm-up is LIVE!
From uncovering Suspicious Chocolate…to making a Chatbot confess 👀 

We’ve dropped 10 prep-track challenges to get your skills fired up before AOC officially begins on December 1st.

This is your pre-season training. Your bootcamp. Your…
tryhackme's tweet image. 🔥 The Advent of Cyber warm-up is LIVE!
From uncovering Suspicious Chocolate…to making a Chatbot confess 👀 

We’ve dropped 10 prep-track challenges to get your skills fired up before AOC officially begins on December 1st.

This is your pre-season training. Your bootcamp. Your…
tryhackme's tweet image. 🔥 The Advent of Cyber warm-up is LIVE!
From uncovering Suspicious Chocolate…to making a Chatbot confess 👀 

We’ve dropped 10 prep-track challenges to get your skills fired up before AOC officially begins on December 1st.

This is your pre-season training. Your bootcamp. Your…

Securityblog รีโพสต์แล้ว

Dumping juicy secrets from SAM/LSA is always nice right? I've added an implementation for the --sam and --lsa flags to the MSSQL protocol of NetExec🚀 No need for manual registry hive extraction anymore!

al3x_n3ff's tweet image. Dumping juicy secrets from SAM/LSA is always nice right?
I've added an implementation for the --sam and --lsa flags to the MSSQL protocol of NetExec🚀

No need for manual registry hive extraction anymore!

Securityblog รีโพสต์แล้ว

⚠️ A hacking group linked to China just pulled a big one. They used a marketing firm’s code to infect 1,000+ websites with a fake 🔔 Chrome update. Click it — and you get BADAUDIO, new malware made to spy for months. Full story ↓ thehackernews.com/2025/11/apt24-…


Securityblog รีโพสต์แล้ว

AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks. During a recent engagement, @_xpn_ found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths. 👀 Read the details ↓ ghst.ly/49ybl4W


Securityblog รีโพสต์แล้ว

🔒 Secure Bits 💡 We’re back with the next post in the 𝗘𝗦𝗖 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 series. Today, we’re diving into 𝗘𝗦𝗖𝟯 — one of the more overlooked but equally dangerous AD CS misconfigs. If you missed the previous ones, 𝗰𝗵𝗲𝗰𝗸 𝗼𝘂𝘁 𝗘𝗦𝗖𝟭 𝗮𝗻𝗱 𝗘𝗦𝗖𝟮 for…

horizon_secured's tweet image. 🔒 Secure Bits 💡
We’re back with the next post in the 𝗘𝗦𝗖 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 series.

Today, we’re diving into 𝗘𝗦𝗖𝟯 — one of the more overlooked but equally dangerous AD CS misconfigs. If you missed the previous ones, 𝗰𝗵𝗲𝗰𝗸 𝗼𝘂𝘁 𝗘𝗦𝗖𝟭 𝗮𝗻𝗱 𝗘𝗦𝗖𝟮 for…

Securityblog รีโพสต์แล้ว

After reporting the issue to @citrix, it’s great to see that they’ve updated their Citrix Endpoint Management guidance to address ESC1. They now explicitly instruct admins to revoke the "Enroll" permission from Domain Users. docs.citrix.com/en-us/citrix-e…

DebugPrivilege's tweet image. After reporting the issue to @citrix, it’s great to see that they’ve updated their Citrix Endpoint Management guidance to address ESC1. They now explicitly instruct admins to revoke the "Enroll" permission from Domain Users. docs.citrix.com/en-us/citrix-e…
DebugPrivilege's tweet image. After reporting the issue to @citrix, it’s great to see that they’ve updated their Citrix Endpoint Management guidance to address ESC1. They now explicitly instruct admins to revoke the "Enroll" permission from Domain Users. docs.citrix.com/en-us/citrix-e…
DebugPrivilege's tweet image. After reporting the issue to @citrix, it’s great to see that they’ve updated their Citrix Endpoint Management guidance to address ESC1. They now explicitly instruct admins to revoke the "Enroll" permission from Domain Users. docs.citrix.com/en-us/citrix-e…

Securityblog รีโพสต์แล้ว

Global Government Data Leaks: 2nd Week November 2025 [Overview] During the second week of November 2025, multiple government institutions across Asia, the Americas, Europe and the Middle East experienced data exposures. Threat actors operating on Tor hidden services, specialist…

stealthmole_int's tweet image. Global Government Data Leaks: 2nd Week November 2025

[Overview]

During the second week of November 2025, multiple government institutions across Asia, the Americas, Europe and the Middle East experienced data exposures. Threat actors operating on Tor hidden services, specialist…

[Weekly case] Government leaks on Darkweb/Deepweb in 2nd Week, November 2025 platform.stealthmole.com/cases/ba0614f6…

stealthmole_iol's tweet image. [Weekly case] Government leaks on Darkweb/Deepweb in 2nd Week, November 2025

platform.stealthmole.com/cases/ba0614f6…


Securityblog รีโพสต์แล้ว

🤓 Multiple new additions in PromptIntel: the database that tracks Adversarial Prompts (IoPC)! A short thread with the recent contributors 👇


Securityblog รีโพสต์แล้ว

Beware fake job platforms operated by the group behind "Contagious Interview." Our team found a surprisingly detailed lure site (lenvny[.]com) over the weekend with fake job listings for @AnthropicAI, @yugalabs, @Anchorage, and more. Analysis and IOCs: validin.com/blog/inside_dp…


Securityblog รีโพสต์แล้ว

Broadcom and A10 Networks have also been breached by Clop Ransomware. @Broadcom @A10Networks

AlvieriD's tweet image. Broadcom and A10 Networks have also been breached by Clop Ransomware.

@Broadcom @A10Networks

Securityblog รีโพสต์แล้ว

Every phone could be a way in for hackers. Samsung Galaxy devices check their security before they connect to your network. That means real Zero Trust—built into the device itself. Read ↓ thehackernews.com/2025/11/why-it…


Securityblog รีโพสต์แล้ว

Trustwave SpiderLabs researchers analyse Eternidade Stealer, a banking trojan distributed through WhatsApp hijacking and social engineering lures. trustwave.com/en-us/resource…

virusbtn's tweet image. Trustwave SpiderLabs researchers analyse Eternidade Stealer, a banking trojan distributed through WhatsApp hijacking and social engineering lures. trustwave.com/en-us/resource…

Securityblog รีโพสต์แล้ว

CVE-2025-50165 is a critical remote code execution vulnerability (CVSS 9.8) affecting the Windows Graphics Component (windowscodecs.dll). It was discovered by Zscaler ThreatLabz in May 2025. To aid in detection, I have developed a KQL query designed to identify potential…

0x534c's tweet image. CVE-2025-50165 is a critical remote code execution vulnerability (CVSS 9.8) affecting the Windows Graphics Component (windowscodecs.dll). It was discovered by Zscaler ThreatLabz in May 2025.

To aid in detection, I have developed a KQL query designed to identify potential…

Securityblog รีโพสต์แล้ว

Operation Endgame: Unmasking the Rhadamanthys Stealer Network Operation Endgame (Nov 2025) disrupted 1,025 servers and seized major darkweb services. Key targets included Rhadamanthys, VenomRAT, and the Elysium botnet. Our report focuses on Rhadamanthys and the actor…

stealthmole_int's tweet image. Operation Endgame: Unmasking the Rhadamanthys Stealer Network

Operation Endgame (Nov 2025) disrupted 1,025 servers and seized major darkweb services. Key targets included Rhadamanthys, VenomRAT, and the Elysium botnet. Our report focuses on Rhadamanthys and the actor…

Securityblog รีโพสต์แล้ว

🚨Alert🚨:CVE-2025-40601 : A Stack-based Buffer Overflow Vulnerability in the SonicOS SSLVPN Service 📊10.7K Services are found on the hunter.how yearly. 🔗Hunter Link:hunter.how/list?searchVal… 👇Query HUNTER : product.name="SonicOS"…

HunterMapping's tweet image. 🚨Alert🚨:CVE-2025-40601 : A Stack-based Buffer Overflow Vulnerability in the
SonicOS SSLVPN Service
📊10.7K Services are found on the hunter.how yearly.
🔗Hunter
Link:hunter.how/list?searchVal…
👇Query
HUNTER : product.name="SonicOS"…

Securityblog รีโพสต์แล้ว

🚨 A new FortiWeb vulnerability, CVE-2025-58034, has emerged just days after the previous Fortinet disclosure and is already being exploited in the wild. While medium in severity, early signals suggest it may be chained with CVE-2025-64446, though no official confirmation has…

censysio's tweet image. 🚨 A new FortiWeb vulnerability, CVE-2025-58034, has emerged just days after the previous Fortinet disclosure and is already being exploited in the wild. While medium in severity, early signals suggest it may be chained with CVE-2025-64446, though no official confirmation has…

Securityblog รีโพสต์แล้ว

Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287) | ShadowPad is a backdoor malware used by numerous Chinese APT groups. AhnLab Security intelligence Center (ASEC) asec.ahnlab.com/en/91166/

780thC's tweet image. Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287) | ShadowPad is a backdoor malware used by numerous Chinese APT groups. AhnLab Security intelligence Center (ASEC) asec.ahnlab.com/en/91166/

Securityblog รีโพสต์แล้ว

These guys published a great report on Operation DreamJob by the DPRK threat actor, and I can relate to how hard it is to build that malware relationship table. Kudos to the team!

unpacker's tweet image. These guys published a great report on Operation DreamJob by the DPRK threat actor, and I can relate to how hard it is to build that malware relationship table. Kudos to the team!

🔎Our CERT is releasing a new technical report on 🇰🇵Operation #DreamJob, focusing on recent evolution in its tooling. Following an IR engagement at a large manufacturing client based in 🇪🇺, we investigated artefacts we attribute to #UNC2970. ➡️Full blog: ow.ly/V4mr50Xug1l

CERTCyberdef's tweet image. 🔎Our CERT is releasing a new technical report on 🇰🇵Operation #DreamJob, focusing on recent evolution in its tooling. 
Following an IR engagement at a large manufacturing client based in 🇪🇺, we investigated artefacts we attribute to #UNC2970.
➡️Full blog: ow.ly/V4mr50Xug1l


Securityblog รีโพสต์แล้ว

🚨🚨CVE-2025-41115 (CVSS 10) – Grafana Privilege Escalation Grafana 12.x with SCIM enabled is vulnerable: a malicious SCIM client can create users with numeric externalIds, risking ID override and full privilege escalation. Search by vul.cve Filter👉vul.cve="CVE-2025-41115"…

zoomeye_team's tweet image. 🚨🚨CVE-2025-41115 (CVSS 10) – Grafana Privilege Escalation
Grafana 12.x with SCIM enabled is vulnerable: a malicious SCIM client can create users with numeric externalIds, risking ID override and full privilege escalation.

Search by vul.cve Filter👉vul.cve="CVE-2025-41115"…

Loading...

Something went wrong.


Something went wrong.