Lenovo released all patches for the #Lenovo #Vantage #vulnerabilities, which we've reported earlier this year.
Our blog now includes the full writeโups for CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717.
๐ cyllective.com/blog/posts/l...
No budget for an internal security team, but too complex for โweโll just do it on the sideโ?
๐ด Have you met cyAssist?
โ
Dedicated cybersecurity experts
โ
Fairโplay & flexible time mgmt
โ
Scalable starting from 2h/month
Security without the overhead
๐ cyllective.com/blog/posts/i...
Two great followโups expanding on our CVEโ2025โ13154 writeโup:
๐น Manuel Kiesel (@rtfmkiesel.bsky.social)- "Roll with Advantage"
๐ mkiesel.ch/posts/lenovo...
๐น Compass Security (@compass-security.com) - "From Folder Deletion to Admin"
๐ blog.compass-security.com/2026/02/from...
First research in a while! Here's my brain dump on reverse-engineering and auditing Lenovo Vantage. In total, I found four (4) vulns. Check out the post and my custom tooling if you're interested.
mkiesel.ch/posts/lenovo...
๐ New blog post: How to Audit Plugin Ecosystems ๐ง๐ฅ
Our reusable 4โstep method helped us navigate 600+ Nextcloud/ownCloud plugins & find some vulns.
cyllective.com/blog/posts/h...
#CyberSecurity #AppSec #Nextcloud #ownCloud #infosec #pentest #SAST
The final stage would not have been possible without John Ostrowski from @compass-security.com thanks for the Swiss infosec collaboration! ๐ซ๐ค
๐จ New blog post!
Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance.
cyllective.com/blog/posts/l...
#windows #cve #infosec #pentest
The first CVEs of 2025 are live!๐จ
We discovered ~10 vulnerabilities in Cordaware bestinformed, leading to 4 CVEs. They can be chained for an unauthenticated compromise of the server and all connected clients.๐พ CVE-2025-042{2..5}
cyllective.com/blog/posts/c...
#blogpost #cybersecurity #CVE #infosec
๐ New from cyllective: ๐๐๐ฎ๐ญ๐ก ๐๐๐๐ฌ ๐
๐ Master OAuth 2.0 with hands-on Docker-based labs:
- JWT signature flaws
- Open redirect risks
- Claim validation issues
๐ป Devs & pentesters: sharpen your skills!
๐ cyllective.com/blog/posts/o...
#OAuth #Cybersecurity #Training #InfoSec #Security