Hejto.pl
Dodaj post

Wpisz coś do wyszukania (minimum 2 znaki)

konik_polanowyFenomen

Dołączył/a:

  • 1438 wpisów
  • 155 komentarzy
  • 36 obserwujących

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.28.md

Two bytes to RCE: chaining rift + PoolSlip into an ASLR-independent nginx 1.30.0 exploit - https://blog.verichains.io/p/two-bytes-to-rce-chaining-rift-poolslip

Patterns and problems in emerging multiagent systems - https://www.anthropic.com/research/multiagent-systems

RoguePlanet: Defender Quarantine Pipeline LPE Zero-Day - https://www.offsitedark.com/signals/rogueplanet-defender-lpe-zero-day

Popping Microsoft’s Sandbox: Dataverse Security Risks in Plugin Containers - https://www.beyondtrust.com/blog/entry/dataverse-security-plugin-sandbox-risks

MmMapIoSpace Returns NULL: Tracing the Real Kernel Mechanism Through ntoskrnl - https://sibouzitoun.tech/articles/mmmapiospace-returns-null-tracing-the-real-kernel-mechanism-through-ntoskrnlexe/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.26.md

Awesome Vehicle Security - https://github.com/jaredthecoder/awesome-vehicle-security/

Static Devirtualization of Tencent VM - https://aftermathlabs.net/blog/31/07/2026/

The Bug Bounty Singularity: Our Hackbot - https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html

Local AI for Penetration Testing & Research - https://projectblack.io/blog/local-ai-for-cyber-security/

Client Connector App Release Summary (2026) - https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.24.md

The QNAP Pattern - https://runiclabs.io/research/qnap-architecture/

SynkLoader: when you throw in everything but the kitchen sink - https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/

When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF - https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/

Fantastic clear-text passwords and where to collect them (Part 2 - Windows) - https://dfir.ch/posts/fantastic_passwords_windows/

CrystalPotato - GodPotato in Crystal - https://ricardojoserf.github.io/crystalpotato/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.22.md

Vulnerability and malware checks in uv - https://astral.sh/blog/uv-audit

Managing the cyber risk of agentic AI - https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai

Reading an offline ntds.dit with one binary - https://zaferbalkan.com/ditjson/

I found a KVM guest-to-host heap corruption bug and someone else got there first - https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/

SakDriver: Reversing a Kernel Driver Rootkit - https://0xsec.gitbook.io/0xsec/malware-analysis/sakdriver-reversing-a-kernel-driver-rootkit

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.20.md

IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years - https://nebusec.ai/research/ionstack-part-2/

Reverse engineering what HyperGuard monitors in ntoskrnl - https://fluxsec.red/what-does-hyperguard-skpg-monitor-vtl1-windows-internals-secure-kernel-patch-guard

WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking - https://www.varonis.com/blog/ws-trust-autologon-endpoint

IDT Table Hijacking under VBS/HVCI/kCET in Windows 11 - https://www.exploitpack.com/blogs/news/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11

Defenders Arise: Examining 7Zip data extraction with Registry analysis - https://thinkdfir.com/2026/08/18/defenders-arise-analysing-7zip-data-extraction-with-registry-analysis/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.18.md

TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere - https://labs.taszk.io/articles/post/tapocalypse/

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup - any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/

Modern implant design: position independent malware development - https://5pider.net/blog/2024/01/27/modern-shellcode-implant-design/

Mitigated API authentication bypass for python.org download metadata - https://pyfound.blogspot.com/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org.html

Windows 11 Hibernation on ARM64: the Boot Manager, winresume, and the hiberfil.sys Format - https://www.msuiche.com/posts/windows-11-arm64-hibernation/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.16.md

Is AI drinking the planet dry? - https://zeecka.fr/blog/ia_eau/

AI-Assisted Fuzzing: Generating Harnesses with a Local LLM - https://www.8ksec.io/ai-assisted-fuzzing-harness-local-llm/

Borrowing Windows Hello keys for authentication and persistence - https://dirkjanm.io/borrowing-windows-hello-keys/

Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router - https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/

A backdoor in a LinkedIn job offer - https://roman.pt/posts/linkedin-backdoor/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.14.md

Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover - https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/

WAF Bypasses via h2 framing - https://lab.ctbb.show/research/h2-WAF-Bypasses

AI Assisted Vulnerability Research on Embedded Targets - https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/

Defeating Windows DEP Using ROP Chains Leveraging VirtualAlloc - https://screetsec.com/blog/defeating-windows-dep-using-rop-chains-leveraging-virtualalloc

Hacking in the age of AI: LLMs, agentic CLIs and MCP servers for Bug Bounty hunters - https://www.yeswehack.com/learn-bug-bounty/llm-bug-bounty-hunting-agentic-cli

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.12.md

Trustfall: An RSA Heap Underwrite Into OP-TEE's Secure World - https://blog.byteray.co.uk/blog/optee-rsa-nopad-heap-underwrite.html

CVE-2026-45454 — Microsoft SharePoint Server Upload Page Folder Path Traversal to Remote Code Execution - https://aretiq.ai/research/vul260531-cve-2026-45454-microsoft-sharepoint-server-upload-page-folder-path-traversal/

LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs - https://netacoding.com/posts/lockbit5-analysis/

21 Bugs In The Linux Bluetooth Stack: Patch Watch, Part 1 - https://xchglabs.com/blog/bluez-zero-click.html

Malware development trick 61: Module stomping. Simple C example - https://cocomelonc.github.io/malware/2026/07/29/malware-tricks-61.html

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.10.md

The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 - https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2

ESC8s and Where to Find Them - https://www.abdulmhsblog.com/posts/esc8andfindingwebenrollmentendpoints/

The SQL Server Unicode problem: why your data might not be what you think it is? - https://www.synacktiv.com/en/publications/the-sql-server-unicode-problem-why-your-data-might-not-be-what-you-think-it-is

LockBit String Deobfuscation: Reversing Affine Cipher DLL Loading with Ghidra - https://ginomaihuiri.github.io/lockbit-string-deobfuscation

The BlueFrag Zero-Click: A System Replay - https://it4ch1-007.github.io/posts/Poc-CVE-2020-0022/

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.08.md

Security Incident INC-2026-07-28-01 UK AI Security Institute - https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf

Poisoning Claude Code: One GitHub Issue to Break the Supply Chain - https://flatt.tech/research/posts/poisoning-claude-code-one-github-issue-to-break-the-supply-chain/

Jellyfin remote code execution: Inconsistent validation leads to argument injection - https://www.sonarsource.com/blog/jellyfin-remote-code-execution/

Unauthenticated RCE as QSECOFR via IBM i Management Central - https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-via-ibm-i-management-central/

DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write - https://delphoslabs.com/blog/36142374-e1fe-80a9-9456-d3c64df81bd5/linux-rxgk-decrypt-mac/

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.06.md

Red Team Tactics: Utilizing Syscalls in C# - Writing The Code - https://jhalon.github.io/utilizing-syscalls-in-csharp-2/

Inside the Falcon How CrowdStrike Catches You - https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/

Jellyfin remote code execution: Inconsistent validation leads to argument injection - https://www.sonarsource.com/blog/jellyfin-remote-code-execution/

I Tried to Clone My Car Key… But It Didn’t Go to Plan! - https://www.youtube.com/watch?v=eYx7uxJ802I

Bringing Structure to Memory Forensics: A Five-Phase, MITRE ATT&CK-Aligned Workflow - https://reversea.me/index.php/bringing-structure-to-memory-forensics-a-five-phase-mitre-attck-aligned-workflow/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.04.md

Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp - https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm

ToolUsed: nRF Connect - https://darkmentor.com/bt.html

KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Rails - https://ethiack.com/info-hub/research/kindarails2shell-how-a-matlab-file-reads-your-secrets-and-pops-a-shell-on-ruby-on-rails

Who Runs Cl0p? Inside the Most Elusive Ransomware Operation in the World - https://rmoskovy.github.io/posts/who-runs-clop-ransomware-investigation/

Microsoft's Project Silica - https://blog.dshr.org/2026/07/microsofts-project-silica.html

Fenomen

w Hydepark

2piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.08.02.md

SakDriver: Reversing a Kernel Driver Rootkit - https://0xsec.gitbook.io/0xsec/malware-analysis/sakdriver-reversing-a-kernel-driver-rootkit

GAP - Ghost Anchor Persistence: Fileless Extension Persistence in Chromium Browsers - https://fir3n0x.github.io/posts/GAP-Ghost-Anchor-Persistence-Fileless-Extension-Persistence-in-Chromium-Browsers/

IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years - https://nebusec.ai/research/ionstack-part-2/

Turning Chrome Remote Desktop into Pure Red Team Ops - https://zerotracelab.com/blog/chrome-remote-desktop-red-ops

CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox - https://voidsec.com/cve-2026-40369-browser-sandbox-escape/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.31.md

Golang code review notes II - https://www.elttam.com/blog/golang-code-review-notes-ii

Now You See mi: Now You're Pwned - https://labs.taszk.io/articles/post/nowyouseemi/

ESC8s and Where to Find Them - https://www.abdulmhsblog.com/posts/esc8andfindingwebenrollmentendpoints/

1-Click GitHub Token Stealing via a VSCode Bug - https://blog.ammaraskar.com/github-token-stealing/

Introducing VulHunt: A High-Level Look at Binary Vulnerability Detection - https://www.binarly.io/blog/introducing-vulhunt-a-high-level-look-at-binary-vulnerability-detection

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.29.md

Defeating Windows DEP Using ROP Chains Leveraging VirtualAlloc - https://screetsec.com/blog/defeating-windows-dep-using-rop-chains-leveraging-virtualalloc

A Shell Is Worth a Thousand Images: Bing Images RCEs - https://xbow.com/blog/bing-images-rce-vulnerabilities

One of the many flaws of Phi untagging: CVE-2026-4447 - https://kqx.io/post/cve-2026-4447/

AI Assisted Vulnerability Research on Embedded Targets - https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/

Race Against The Patch: The Evolution of Four Exploit Chains in LiteLLM - https://starlabs.sg/blog/2026/05-race-against-the-patch-the-evolution-of-four-exploit-chains-in-litellm/

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.27.md

The Gold Mine Red Teamers Never Touch - https://www.abdulmhsblog.com/posts/useingthewindowssourcecode/

How harnesses and post-training close the open-weight bug-finding gap - https://vincenzoiozzo.com/blog/oss-models-vuln-research

Fit for Detection: Hunting U-Boot Vulnerabilities at Scale - https://www.binarly.io/blog/hunting-u-boot-at-scale

AI-Assisted Fuzzing: Generating Harnesses with a Local LLM - https://www.8ksec.io/ai-assisted-fuzzing-harness-local-llm/

Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver - https://lukasmaar.github.io/posts/qaic-page-uaf/index.html

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.25.md

Vulnerabilities of Realtek SD card reader driver, part 1 - https://zwclose.github.io/2024/10/14/rtsper1.html

How to Save Millions by Self-Hosting LLMs - https://cline.bot/blog/how-to-save-millions-by-self-hosting-llms

Pop a Calc: The Crystal Palace Way - https://kerekesha.com/blog/pop-a-calc-the-crystal-palace-way

GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security - https://www.varonis.com/blog/ghosttree-ntfs-trick

Advanced Module Stomping & Heap/Stack Encryption - https://labs.cognisys.group/posts/Advanced-Module-Stomping-and-Heap-Stack-Encryption/

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.23.md

How I Found Open-Source 0-days with an LLM Multi-Agent Workflow - https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-days-with-an-LLM-Multi-Agent-Workflow

Building an AI-Based Vulnerability Detection Workflow - https://se1en.tistory.com/16

Mapping Virtual to Physical Addresses Using Superfetch - https://www.outflank.nl/blog/2023/12/14/mapping-virtual-to-physical-adresses-using-superfetch/

GDID: The Windows Global Device Identifier - https://zerotracelab.com/blog/gdid-windows-tracking

C111000: Race Against The Virtual Machine or how a SUID binary in VMware Fusion was raced to gain root privileges on macOS - https://therealcoiffeur.com/c111000.html

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.07.21.md

Hijacking the Windows "MareBackup" Scheduled Task for Privilege Escalation - https://itm4n.github.io/hijacking-the-windows-marebackup-scheduled-task-for-privilege-escalation/

oad balancing usage across multiple codex accounts - https://pepsipu.com/blog/2026-04-agent-scheduling/

TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere - https://labs.taszk.io/articles/post/tapocalypse/

In-depth Windows Telemetry - https://blog.otterpwn.com/research/In-depth-Windows-Telemetry

When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF - https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/