Hejto.pl
Dodaj post

Wpisz coś do wyszukania (minimum 2 znaki)

#informatyka

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.14.md

Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover - https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/

WAF Bypasses via h2 framing - https://lab.ctbb.show/research/h2-WAF-Bypasses

AI Assisted Vulnerability Research on Embedded Targets - https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/

Defeating Windows DEP Using ROP Chains Leveraging VirtualAlloc - https://screetsec.com/blog/defeating-windows-dep-using-rop-chains-leveraging-virtualalloc

Hacking in the age of AI: LLMs, agentic CLIs and MCP servers for Bug Bounty hunters - https://www.yeswehack.com/learn-bug-bounty/llm-bug-bounty-hunting-agentic-cli

Osobistość

w Hydepark

0piorunów

Wyciekło bardzo ważne dane trzeba uciekac przed MySQL
Xd

Pokaż więcej komentarzy (4)

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.12.md

Trustfall: An RSA Heap Underwrite Into OP-TEE's Secure World - https://blog.byteray.co.uk/blog/optee-rsa-nopad-heap-underwrite.html

CVE-2026-45454 — Microsoft SharePoint Server Upload Page Folder Path Traversal to Remote Code Execution - https://aretiq.ai/research/vul260531-cve-2026-45454-microsoft-sharepoint-server-upload-page-folder-path-traversal/

LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs - https://netacoding.com/posts/lockbit5-analysis/

21 Bugs In The Linux Bluetooth Stack: Patch Watch, Part 1 - https://xchglabs.com/blog/bluez-zero-click.html

Malware development trick 61: Module stomping. Simple C example - https://cocomelonc.github.io/malware/2026/07/29/malware-tricks-61.html

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.10.md

The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 - https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2

ESC8s and Where to Find Them - https://www.abdulmhsblog.com/posts/esc8andfindingwebenrollmentendpoints/

The SQL Server Unicode problem: why your data might not be what you think it is? - https://www.synacktiv.com/en/publications/the-sql-server-unicode-problem-why-your-data-might-not-be-what-you-think-it-is

LockBit String Deobfuscation: Reversing Affine Cipher DLL Loading with Ghidra - https://ginomaihuiri.github.io/lockbit-string-deobfuscation

The BlueFrag Zero-Click: A System Replay - https://it4ch1-007.github.io/posts/Poc-CVE-2020-0022/

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.08.md

Security Incident INC-2026-07-28-01 UK AI Security Institute - https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf

Poisoning Claude Code: One GitHub Issue to Break the Supply Chain - https://flatt.tech/research/posts/poisoning-claude-code-one-github-issue-to-break-the-supply-chain/

Jellyfin remote code execution: Inconsistent validation leads to argument injection - https://www.sonarsource.com/blog/jellyfin-remote-code-execution/

Unauthenticated RCE as QSECOFR via IBM i Management Central - https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-via-ibm-i-management-central/

DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write - https://delphoslabs.com/blog/36142374-e1fe-80a9-9456-d3c64df81bd5/linux-rxgk-decrypt-mac/

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.06.md

Red Team Tactics: Utilizing Syscalls in C# - Writing The Code - https://jhalon.github.io/utilizing-syscalls-in-csharp-2/

Inside the Falcon How CrowdStrike Catches You - https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/

Jellyfin remote code execution: Inconsistent validation leads to argument injection - https://www.sonarsource.com/blog/jellyfin-remote-code-execution/

I Tried to Clone My Car Key… But It Didn’t Go to Plan! - https://www.youtube.com/watch?v=eYx7uxJ802I

Bringing Structure to Memory Forensics: A Five-Phase, MITRE ATT&CK-Aligned Workflow - https://reversea.me/index.php/bringing-structure-to-memory-forensics-a-five-phase-mitre-attck-aligned-workflow/

Zawodowiec

w Programowanie

5piorunów

Dlaczego NIE warto delegować kodowania agentom AI - devszczepaniak.pl

Delegowanie pisania kodu do AI ma ogrom zalet. W ciągu ostatnich dwóch lat, za sprawą narzędzi AI, wyprodukowałem wielokrotnie więcej kodu niż kiedykolwiek wcześniej. Przez ten czas zacząłem jednak dostrzegać sporo istotnych wad tego podejścia. O tym, jakie problemy dostrzegam w tym

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.04.md

Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp - https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm

ToolUsed: nRF Connect - https://darkmentor.com/bt.html

KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Rails - https://ethiack.com/info-hub/research/kindarails2shell-how-a-matlab-file-reads-your-secrets-and-pops-a-shell-on-ruby-on-rails

Who Runs Cl0p? Inside the Most Elusive Ransomware Operation in the World - https://rmoskovy.github.io/posts/who-runs-clop-ransomware-investigation/

Microsoft's Project Silica - https://blog.dshr.org/2026/07/microsofts-project-silica.html

Fenomen

w Hydepark

2piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.02.md

SakDriver: Reversing a Kernel Driver Rootkit - https://0xsec.gitbook.io/0xsec/malware-analysis/sakdriver-reversing-a-kernel-driver-rootkit

GAP - Ghost Anchor Persistence: Fileless Extension Persistence in Chromium Browsers - https://fir3n0x.github.io/posts/GAP-Ghost-Anchor-Persistence-Fileless-Extension-Persistence-in-Chromium-Browsers/

IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years - https://nebusec.ai/research/ionstack-part-2/

Turning Chrome Remote Desktop into Pure Red Team Ops - https://zerotracelab.com/blog/chrome-remote-desktop-red-ops

CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox - https://voidsec.com/cve-2026-40369-browser-sandbox-escape/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.31.md

Golang code review notes II - https://www.elttam.com/blog/golang-code-review-notes-ii

Now You See mi: Now You're Pwned - https://labs.taszk.io/articles/post/nowyouseemi/

ESC8s and Where to Find Them - https://www.abdulmhsblog.com/posts/esc8andfindingwebenrollmentendpoints/

1-Click GitHub Token Stealing via a VSCode Bug - https://blog.ammaraskar.com/github-token-stealing/

Introducing VulHunt: A High-Level Look at Binary Vulnerability Detection - https://www.binarly.io/blog/introducing-vulhunt-a-high-level-look-at-binary-vulnerability-detection

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.29.md

Defeating Windows DEP Using ROP Chains Leveraging VirtualAlloc - https://screetsec.com/blog/defeating-windows-dep-using-rop-chains-leveraging-virtualalloc

A Shell Is Worth a Thousand Images: Bing Images RCEs - https://xbow.com/blog/bing-images-rce-vulnerabilities

One of the many flaws of Phi untagging: CVE-2026-4447 - https://kqx.io/post/cve-2026-4447/

AI Assisted Vulnerability Research on Embedded Targets - https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/

Race Against The Patch: The Evolution of Four Exploit Chains in LiteLLM - https://starlabs.sg/blog/2026/05-race-against-the-patch-the-evolution-of-four-exploit-chains-in-litellm/

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.27.md

The Gold Mine Red Teamers Never Touch - https://www.abdulmhsblog.com/posts/useingthewindowssourcecode/

How harnesses and post-training close the open-weight bug-finding gap - https://vincenzoiozzo.com/blog/oss-models-vuln-research

Fit for Detection: Hunting U-Boot Vulnerabilities at Scale - https://www.binarly.io/blog/hunting-u-boot-at-scale

AI-Assisted Fuzzing: Generating Harnesses with a Local LLM - https://www.8ksec.io/ai-assisted-fuzzing-harness-local-llm/

Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver - https://lukasmaar.github.io/posts/qaic-page-uaf/index.html

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.25.md

Vulnerabilities of Realtek SD card reader driver, part 1 - https://zwclose.github.io/2024/10/14/rtsper1.html

How to Save Millions by Self-Hosting LLMs - https://cline.bot/blog/how-to-save-millions-by-self-hosting-llms

Pop a Calc: The Crystal Palace Way - https://kerekesha.com/blog/pop-a-calc-the-crystal-palace-way

GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security - https://www.varonis.com/blog/ghosttree-ntfs-trick

Advanced Module Stomping & Heap/Stack Encryption - https://labs.cognisys.group/posts/Advanced-Module-Stomping-and-Heap-Stack-Encryption/

Statysta

w LINUX

4piorunów

_Robię rzeczy z Linuxem i nie formatuję od razu_

Hej. Zajmuję się naprawą oprogramowania — głównie Linux, Steam Deck, też Windows jak trzeba. Systemy po aktualizacjach, konflikty, uszkodzone partycje, problemy z uruchamianiem.

Pracuję zdalnie albo stacjonarnie w Szczecinie. Podłączam się, troubleshootuję, naprawiam. Nie formatuję od razu — naprawiam.

Jak ktoś ma problem z Linuxem i nie wie co zrobić — pisz. Jak nie będę mógł pomóc, powiem szczerze. Bez ściemy.

WhatsApp: 508 302 053

Pokaż więcej komentarzy (19)

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.23.md

How I Found Open-Source 0-days with an LLM Multi-Agent Workflow - https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-days-with-an-LLM-Multi-Agent-Workflow

Building an AI-Based Vulnerability Detection Workflow - https://se1en.tistory.com/16

Mapping Virtual to Physical Addresses Using Superfetch - https://www.outflank.nl/blog/2023/12/14/mapping-virtual-to-physical-adresses-using-superfetch/

GDID: The Windows Global Device Identifier - https://zerotracelab.com/blog/gdid-windows-tracking

C111000: Race Against The Virtual Machine or how a SUID binary in VMware Fusion was raced to gain root privileges on macOS - https://therealcoiffeur.com/c111000.html

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.21.md

Hijacking the Windows "MareBackup" Scheduled Task for Privilege Escalation - https://itm4n.github.io/hijacking-the-windows-marebackup-scheduled-task-for-privilege-escalation/

oad balancing usage across multiple codex accounts - https://pepsipu.com/blog/2026-04-agent-scheduling/

TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere - https://labs.taszk.io/articles/post/tapocalypse/

In-depth Windows Telemetry - https://blog.otterpwn.com/research/In-depth-Windows-Telemetry

When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF - https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/

Zawodowiec

w Programowanie

4piorunów

EventCatalog - SKUTECZNA dokumentacja architektury Twojego systemu - devszczepaniak.pl

EventCatalog to narzędzie do dokumentowania architektury systemów w podejściu Documentation as Code. Pozwala opisywać zdarzenia, komendy, usługi, domeny i przepływy między nimi. Dzięki temu wiedza o architekturze trzymana jest blisko kodu i jest łatwiejsza w utrzymaniu.\ \ W najnowszym

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.19.md

I handed the epoll UAF to an agent - https://guysrd.github.io/epoll-uaf-agent

AI-FI: Giving Claude Code Glitch Skills for Bypassing Secure Boot - https://raelize.com/blog/ai-fi-giving-claude-code-glitch-skills-for-bypassing-secure-boot/

Patterns for Building Cybersecurity Evals - https://eugeneyan.com/writing/cybersecurity-evals/

BingusLdr: CET Compatible Stack Spoofing - https://bigbingus.com/posts/bingusldr-cet-stack-spoofing/

Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) - https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.17.md

Dan Guido - 200 Bugs/Week/Engineer: How We Rebuilt Trail of Bits Around AI | [un]prompted 2026 - https://www.youtube.com/watch?v=kgwvAyF7qsA

Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver - https://lukasmaar.github.io/posts/qaic-page-uaf/index.html

Lost in relocation: analysis of a new loader distributing CASTLESTEALER - https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer

AI-FI: Reproducing adb to root on Google's TV Streamer using Claude in less than 15 minutes - https://raelize.com/blog/ai-fi-reproducing-adb-to-root-on-googles-tv-streamer-using-claude/

futex: remove_waiter stack uaf - https://guysrd.github.io/rtmutex