September 25, 2021 at 12:25PM

■■■■■ This is one of the entries to the BGGP 2021 Polyglot File challenge. It uses a novel technique of directly embedding data within the compressed image data stream of a PNG. This means you can literally see the bytes of the embedded files! ● It literally took about a minute for me to understand.…

September 25, 2021 at 11:38AM

■■■■□ CVE-2021-37973: Chrome Update Released to Patch Actively Exploited Zero-Day Vulnerability. Use after free in Portals. Reported by Clément Lecigne from Google TAG, with technical assistance from Sergei Glazunov and Mark Brand from Google Project Zero on 2021-09-21 (https://bugs.chromium.org/p/chromium/issues/detail?id=1251727) https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_24.html https://thehackernews.com/2021/09/urgent-chrome-update-released-to-patch.html https://t.me/cKure/9491

September 25, 2021 at 03:39AM

■■■□□ CVE-2021-26084: Details on the recently exploited atlassian confluence OGNL injection bug. https://www.zerodayinitiative.com/blog/2021/9/21/cve-2021-26084-details-on-the-recently-exploited-atlassian-confluence-ognl-injection-bug https://t.me/cKure/9486

September 25, 2021 at 02:18AM

■■□□□ Declassified: The cyberattack on the largest bank in Venezuela, Banco de Venezuela, was carried out from the United States. This was announced on September 22 by the Executive Vice President of the Republic of South America Delsi Rodriguez on the air of the Venezolana de Television channel. https://cyberthreatintelligence.com/news/venezuela-reveals-the-origin-of-the-cyberattack-on-the-countrys-largest-bank/ https://t.me/cKure/9485