■■■■■ CVE-2025-29810: Microsoft has disclosed a significant security vulnerability in Active Directory Domain Services that could allow attackers to elevate their privileges to the system level, potentially gaining complete control over affected systems. Windows Active Directory Domain Vulnerability Let Attackers Escalate Privileges
All posts by John Doe
April 10, 2025 at 06:23AM
■■■■■ WhatsApp flaw can let attackers run malicious code on Windows PCs. https://www.whatsapp.com/security/advisories/2025/ https://www.bleepingcomputer.com/news/security/whatsapp-flaw-can-let-attackers-run-malicious-code-on-windows-pcs/
April 9, 2025 at 10:06AM
■■■■■ 🔍 Google fixes two Android zero-day bugs actively exploited likely by state sponsored hackers. CVE-2024-53197 CVE-2024-53150 Google fixes two Android zero-day bugs actively exploited by hackers https://source.android.com/docs/security/bulletin/2025-04-01
April 9, 2025 at 09:43AM
📣 Oracle quietly confirms public cloud data breach, customer data stolen. The attacker exploited a vulnerability in Oracle Access Manager to breach Oracle-hosted servers. The vulnerability is tracked as CVE-2021-35587 and was assigned a critical severity score 9.8/10. It was patched in mid-January 2022, raising questions over whether Oracle kept its own servers vulnerable to…
April 9, 2025 at 12:56AM
■■□□□ Microsoft: Windows CLFS zero-day exploited by ransomware gang Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims’ systems. https://www.bleepingcomputer.com/news/security/microsoft-windows-clfs-zero-day-exploited-by-ransomware-gang/
April 7, 2025 at 08:41AM
■■■□□ Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring. Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring
April 5, 2025 at 03:42PM
■■■■□ QuickShell : Sharing is Caring About an RCE Attack Chain on Quick Share. https://i.blackhat.com/Asia-25/Asia-25-Yair-QuickShell-Sharing-is-Caring.pdf
April 5, 2025 at 03:42PM
■■■■■ RCE Attack Chain on Google’s – Quick Share. QuickShell: Sharing Is Caring about an RCE Attack Chain on Quick Share
April 4, 2025 at 10:04AM
■■□□□ Possible zero-day in Juniper product. On Wednesday, SANS Institute’s Johannes Ullrich said he noticed a surge in scans for the username “t128,” which, when accompanied by the password “128tRoutes,” is a well-known default account for Juniper’s Session Smart Networking products. “About 3,000 source IPs took part in these scans,” reported Ullrich, the dean of…
April 4, 2025 at 01:41AM
🎲🐬 Feberis Pro: The Ultimate 4-in-1 Expansion Board for Flipper Zero. www.mobile-hacker.com/2025/03/31/feberis-pro-the-ultimate-4-in-1-expansion-board-for-flipper
