May 9, 2024 at 10:33PM

■■■□□ Talos discloses multiple zero-day vulnerabilities, two of which could lead to code execution. https://blog.talosintelligence.com/vulnerability-roundup-zero-days-may-8-2024/ https://t.me/cKure/14003

May 9, 2024 at 03:39PM

■■■■■ Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246). https://medium.com/@elpepinillo/heap-heap-hooray-unveiling-glibc-heap-overflow-vulnerability-cve-2023-6246-0c6412423269 https://t.me/cKure/14002

May 8, 2024 at 12:14AM

■■■■□ AI enabled warfare. Technical details by VOX News of extermination of Muslims and Christians in Gaza, Palestine amid ongoing genocide using Gospel AI and modified version of it called Lavender AI. The same was covered by us in this post: https://t.me/ckuRED/432 https://t.me/cKure/13997

May 7, 2024 at 10:02PM

■□□□□ A tool to demonstrate how passwordless solutions such as Okta Verify’s FastPass or other FIDO2/WebAuthn type solutions can be abused once an authenticator endpoint has been compromised. https://github.com/CCob/okta-terrify https://t.me/cKure/13996

May 7, 2024 at 12:26PM

Zero-Day: Option 121 (DHCP) allows bypasses nearly all VPNs TunnelVision vulnerability has existed since 2002 and may already be known to attackers. https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ https://t.me/cKure/13991

May 7, 2024 at 08:35AM

■□□□□ Ransomware drama: Law enforcement seized Lockbit group’s website again. https://securityaffairs.com/162778/cyber-crime/law-enforcement-seized-lockbit-site-again.html https://t.me/cKure/13990