■■■■■ In conducting a 0-day research project against #SharePoint, Rapid7 Labs discovered 2 new vulns that, when chained together, achieve RCE against a vulnerable server. Today, Rapid7 and Microsoft are disclosing CVE-2026-55040 – the first vuln in this chain: r-7.co/4f2HpQO (https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/)
All posts by John Doe
July 14, 2026 at 07:18PM
■■■□□ The world’s smallest Arduino-compatible USB-C board. Meet Moddo Pinch – The world’s smallest 32-bit Arduino-compatible board (2026 Edition) The moddo Pinch measures just 10.9 x 10.5 mm, and features a Microchip Technology Inc. SAMD11 Cortex-M0+ microcontroller with 4 KB SRAM and 16KB flash, an RGB LED, reset/bootloader button, 3.3 V LDO, and a total…
July 12, 2026 at 07:04PM
■■■■■ Using Claude to reproduce an ElectroMagnetic (EM) glitch privilege escalation attacks (x.com/raelizecom). https://raelize.com/blog/ai-fi-reproducing-adb-to-root-on-googles-tv-streamer-using-claude/
July 12, 2026 at 07:01PM
■■■□□ Unauthenticated RCE in Motorola’s MR2600 Router https://mrbruh.com/motorola/
July 9, 2026 at 06:44PM
■■□□□ Intruding thread on privacy. https://x.com/i/status/2075226136229863475
July 9, 2026 at 04:25PM
■■■□□ no-gdid: Read, understand, and silence the Windows Global Device Identifier (GDID) — the hidden per-account device ID that helped the FBI locate a suspect who was using a VPN. 👮 the best option is to switch Microsoft products out of environment completely. At ckure, we use Fedora. https://github.com/Korben00/no-gdid
July 9, 2026 at 11:46AM
■■■□□ Proxyware actor behind fake 7-Zip is bigger than most assumed. Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims
July 9, 2026 at 12:58AM
■■■■■ 💻 Windows kernel exploitation series. https://mdanilor.github.io/posts/hevd-0/ https://mdanilor.github.io/posts/hevd-1/ https://mdanilor.github.io/posts/hevd-2/ https://mdanilor.github.io/posts/hevd-3/ https://mdanilor.github.io/posts/hevd-4/
July 8, 2026 at 08:31PM
🎚 The Mosad Playbook: How One Alias Built a Cross-Platform Leak Network. https://stealthmole-intelligence-hub.blogspot.com/2026/07/the-mosad-playbook-how-one-alias-built.html
July 8, 2026 at 08:28PM
■■■■■ EvilTokens phishing can look clean during URL checks. The real page stays encrypted until it opens in the victim’s browser, then uses Microsoft device-code phishing to push toward Microsoft 365 account takeover. The blind spot is browser visibility, not just email scanning. https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html
