■■■□□ How Google’s security engineering team handles rollouts at scale, so we can safely enforce Strict CSP, Trusted Types and other security features on 100s new services yearly. https://bughunters.google.com/blog/5896512897417216/a-recipe-for-scaling-security https://t.me/cKure/13421
All posts in Uncategorized
January 23, 2024 at 08:23AM
■■■■□ Domain Escalation – Backup Operator. https://pentestlab.blog/2024/01/22/domain-escalation-backup-operator/ https://t.me/cKure/13420
January 23, 2024 at 08:22AM
Building an Exploit for FortiGate Vulnerability CVE-2023-27997. https://bishopfox.com/blog/building-exploit-fortigate-vulnerability-cve-2023-27997 https://t.me/cKure/13419
January 22, 2024 at 02:28PM
■■■■■ New Outlook Flaw Let Attackers Access Hashed Passwords. New Outlook Flaw Let Attackers Access Hashed Passwords The headers that can be used for exploitation are, ● “Content-Class” = “Sharing” — tells Outlook that this email contains sharing content. ●“x-sharing-config-url” = \\(Attacker machine)\a.ics — points the victim’s Outlook to the attacker’s machine. https://t.me/cKure/13418
January 22, 2024 at 02:23PM
■■■■□ VMware confirms critical vCenter flaw now exploited in attacks. https://www.bleepingcomputer.com/news/security/vmware-confirms-critical-vcenter-flaw-now-exploited-in-attacks/ https://t.me/cKure/13417
January 20, 2024 at 11:23PM
■■■■■ Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution. https://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve-2024-0517-out-of-bounds-write-code-execution/ https://t.me/cKure/13416
January 17, 2024 at 02:33PM
■■■■■ A PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings. https://github.com/MlgmXyysd/Xiaomi-HyperOS-BootLoader-Bypass#xiaomi-hyperos-bootloader-bypass https://t.me/cKure/13414
January 17, 2024 at 10:31AM
■■■■■ Microsoft Teams Covert Channels Research. https://blog.compass-security.com/2024/01/microsoft-teams-covert-channels-research/ https://t.me/cKure/13413
January 13, 2024 at 12:07PM
■■■■■ PoC Script for CVE-2022-36553: Exploits an unauthenticated remote command injection vulnerability in Hytec Inter HWL-2511-SS device. https://github.com/0xNslabs/CVE-2022-36553-PoC https://t.me/cKure/13412
January 13, 2024 at 12:07PM
■■■□□ CVE-2024-20656: Windows LPE in the VSStandardCollectorService150 service. https://github.com/Wh04m1001/CVE-2024-20656 https://t.me/cKure/13411
