cy//ective

cy//ective

@cyllective.bsky.social

IT Security Services - ๐Ÿ‡จ๐Ÿ‡ญ๐Ÿค–๐Ÿ‘จโ€๐Ÿ’ป https://cyllective.com

82 Followers 8 Following 8 Posts Joined Nov 2024
1 day ago
Preview
Vulnerabilities in Lenovo Vantage A write-up of CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717

Lenovo released all patches for the #Lenovo #Vantage #vulnerabilities, which we've reported earlier this year.
Our blog now includes the full writeโ€‘ups for CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717.
๐Ÿ”— cyllective.com/blog/posts/l...

0 1 0 0
2 weeks ago
Preview
cyAssist - Cybersecurity Without the Overhead We provide the continuous support you need to build a genuine security culture and baseline maturity.

No budget for an internal security team, but too complex for โ€œweโ€™ll just do it on the sideโ€?

๐Ÿ”ด Have you met cyAssist?

โœ… Dedicated cybersecurity experts
โœ… Fairโ€‘play & flexible time mgmt
โœ… Scalable starting from 2h/month
Security without the overhead
๐Ÿ‘‰ cyllective.com/blog/posts/i...

0 0 0 0
3 weeks ago

Two great followโ€‘ups expanding on our CVEโ€‘2025โ€‘13154 writeโ€‘up:
๐Ÿ”น Manuel Kiesel (@rtfmkiesel.bsky.social)- "Roll with Advantage"
๐Ÿ‘‰ mkiesel.ch/posts/lenovo...
๐Ÿ”น Compass Security (@compass-security.com) - "From Folder Deletion to Admin"
๐Ÿ‘‰ blog.compass-security.com/2026/02/from...

2 0 0 0
1 month ago
Preview
roll with advantage: hacking lenovo vantage | mkiesel.ch A technical deep dive into the lands of Lenovo Vantage and its add-ins, including tooling to help you hunt for vulnerabilities

First research in a while! Here's my brain dump on reverse-engineering and auditing Lenovo Vantage. In total, I found four (4) vulns. Check out the post and my custom tooling if you're interested.

mkiesel.ch/posts/lenovo...

2 1 1 0
1 month ago
Preview
How To Audit Plugin Ecosystems How we audit plugin ecosystems, using (Nextcloud|ownCloud) as an example

๐Ÿš€ New blog post: How to Audit Plugin Ecosystems ๐Ÿ”ง๐Ÿ”ฅ
Our reusable 4โ€‘step method helped us navigate 600+ Nextcloud/ownCloud plugins & find some vulns.

cyllective.com/blog/posts/h...

#CyberSecurity #AppSec #Nextcloud #ownCloud #infosec #pentest #SAST

2 2 0 0
1 month ago

The final stage would not have been possible without John Ostrowski from @compass-security.com thanks for the Swiss infosec collaboration! ๐Ÿซ•๐Ÿค

3 2 1 0
1 month ago
Preview
Lenovo Vantage LPE/EoP (CVE-2025-13154) A write-up of CVE-2025-13154, a privilege escalation vulnerability in Lenovo Vantage.

๐Ÿšจ New blog post!

Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance.

cyllective.com/blog/posts/l...

#windows #cve #infosec #pentest

1 2 1 1
1 year ago
Preview
Vulnerabilities in Cordaware bestinformed A write-up of CVE-2025-0422, CVE-2025-0423, CVE-2025-0424, and CVE-2025-0425

The first CVEs of 2025 are live!๐Ÿšจ
We discovered ~10 vulnerabilities in Cordaware bestinformed, leading to 4 CVEs. They can be chained for an unauthenticated compromise of the server and all connected clients.๐Ÿ‘พ CVE-2025-042{2..5}
cyllective.com/blog/posts/c...

#blogpost #cybersecurity #CVE #infosec

3 2 0 0
1 year ago
Preview
OAuth Labs: OAuth 2.0 Vulnerabilites Introducing our latest project: the OAuth Labs. A hands-on approach to OAuth 2.0 vulnerabilities

๐Ÿš€ New from cyllective: ๐Ž๐€๐ฎ๐ญ๐ก ๐‹๐š๐›๐ฌ ๐Ÿ”’

๐Ÿ”‘ Master OAuth 2.0 with hands-on Docker-based labs:
- JWT signature flaws
- Open redirect risks
- Claim validation issues

๐Ÿ’ป Devs & pentesters: sharpen your skills!
๐Ÿ‘‰ cyllective.com/blog/posts/o...

#OAuth #Cybersecurity #Training #InfoSec #Security

5 1 0 2