Introducing the OWASP Top 10:2025
owasp.org/Top10/2025/0...
@mariusavram.bsky.social
Cyber Security Enthusiast. Two sons' proud dad!
Introducing the OWASP Top 10:2025
owasp.org/Top10/2025/0...
Tenable Research has discovered seven vulnerabilities and attack techniques in ChatGPT, including unique indirect prompt injections, exfiltration of personal user information, persistence, evasion, and bypass of safety mechanisms. www.tenable.com/blog/hackedg...
05.11.2025 16:39 β π 0 π 0 π¬ 0 π 0Phrack 72 Has Been Published phrack.org/issues/72/1
19.08.2025 07:13 β π 0 π 0 π¬ 0 π 0IP data on compromised instances shared in our Compromised Website report tagged 'fortiweb-compromised': www.shadowserver.org/what-we-do/n...
IP data on exposed instances is in our Device ID report: www.shadowserver.org/what-we-do/n... (device model is set to FortiWeb Management Interface)
true legend!
11.07.2025 15:59 β π 1 π 0 π¬ 0 π 0opossum-attack.comΒ <-Β Opossum is a cross-protocol application layer desynchronization attack that affects TLS-based application protocols that rely on both opportunistic and implicit TLS. Among the affected protocols are HTTP, FTP, POP3, SMTP, LMTP and NNTP.
08.07.2025 16:08 β π 0 π 0 π¬ 0 π 0British Hacker βIntelBrokerβ Faces $25M Cybercrime Charges www.justice.gov/usao-sdny/pr...
26.06.2025 03:41 β π 1 π 0 π¬ 0 π 0Looks like old age finally finished the job and wiped out whatever was left of his brain, not that there was much to begin with. π¬
17.06.2025 09:52 β π 1 π 0 π¬ 0 π 0Free EC2 tool for pentesting or anything.
github.com/random-robbi...
Finding an SOQL Injection 0-Day in Salesforce mastersplinter.work/research/sal...
11.06.2025 06:20 β π 1 π 0 π¬ 0 π 0According to my sources, Cellebrite used to purchase iPhone prototypes (aka dev-fused devices), which had lower security features, to develop its zero-days.
Corellium's founder Chris Wade also purchased them back in the day, according to sources.
www.vice.com/en/article/t...
<img/src/onerror=window.onerror=eval;ReferenceError.prototype.name=';alert\x281\x29;var\x20Uncaught//';z>
This vector adds an onerror handler with eval, rewrites all ReferenceError names, then triggers an error to execute the payload. Just added it to the XSS cheat sheet. Credit to @0x999.net , inspired by @terjanq.me
portswigger.net/web-security...
Unmasking the Threat: A Deep Dive into the PDF Malicious labs.segura.blog/unmasking-th...
02.06.2025 16:26 β π 0 π 0 π¬ 0 π 0Finding SSRFs in Azure DevOps - Part 2 binsec.no/posts/2025/0...
30.05.2025 13:00 β π 0 π 0 π¬ 0 π 0π€¦ββοΈπ
30.05.2025 08:12 β π 1 π 0 π¬ 0 π 0Threat of TCC Bypasses on macOS afine.com/threat-of-tc...
26.05.2025 12:13 β π 0 π 0 π¬ 0 π 0Automating MS-RPC vulnerability research www.incendium.rocks/posts/Automa...
22.05.2025 12:23 β π 0 π 0 π¬ 0 π 0Bypass SharePoint Restricted View to exfiltrate data using Copilot AI and moreβ¦ www.pentestpartners.com/security-blo...
22.05.2025 06:35 β π 0 π 0 π¬ 0 π 0Of course, it's always wise to speak from ignorance, after all, globalist propaganda wouldn't work so flawlessly if people actually bothered to think. π€¦ββοΈ
19.05.2025 14:25 β π 1 π 0 π¬ 0 π 0Wellβ¦thank you for not doing this on a Friday.
This is hugeβ¦
via @bleepingcomputer.com
Β From SAST to CVE-2025-46337 xaliom.blogspot.com/2025/05/from...
05.05.2025 15:42 β π 1 π 0 π¬ 0 π 0#Skype shuts down TODAY.
Here's the link to download your contacts & chats. secure.skype.com/en/data-export
Agent of Chaos: Hijacking NodeJSβs Jenkins Agents
www.praetorian.com/blog/agent-o...
Think youβve seen every OS command injection trick?
Think again, read our latest blog post!
Link in the commentsπ
What about this? It was mentioned a month ago π³ www.euronews.com/my-europe/20...
28.04.2025 14:22 β π 0 π 0 π¬ 0 π 0Just posted to my blog for the first time in a little over 2 years π rambo.codes/posts/2025-0...
26.04.2025 17:04 β π 38 π 3 π¬ 1 π 0Research finds 12,000 βLiveβ API Keys and Passwords in DeepSeek's Training Data trufflesecurity.com/blog/researc...
23.04.2025 08:03 β π 0 π 0 π¬ 0 π 0