๐ง๐ Hydroph0bia (CVE-2025-4275) – a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O. Secure Boot bypass for laptops, embedded and medical devices, and car ECUs: technical details and exploit. Security researcher Nikolaj Schlej shared yesterday a new and quite effective (even trivial) way to bypass Secure Boot in Insyde H20 UEFI BIOS. The…
All posts in Uncategorized
June 14, 2025 at 04:45PM
๐๐ Streaming Zero-Fi Shells to Your Smart Speaker. Exploiting the Sonos Era 300 with malicious HLS playlist. PwnยฒOwn Ireland ๐ฎ๐ช Exploit: https://github.com/ret2/Pwn2Own-Ireland2024-Sonos Reference: Sonos advisory https://www.sonos.com/en-us/security-advisory-2024-0002
June 14, 2025 at 03:16PM
โ โ โ โ โ ๐ป Windows SMB Client Zero-Day Vulnerability Exploited Using Reflective Kerberos Relay Attack. Windows SMB Client Zero-Day Vulnerability Exploited Using Reflective Kerberos Relay Attack
June 13, 2025 at 11:11PM
โ โ โ โ โก Israel vs. Iran war: Use of OSINT in kinetic war as Iran uses videos posted online (social media) to fine tune accuracy. https://t.me/Middle_East_Spectator/19567
June 13, 2025 at 10:03PM
โ โ โ โ โ #Intelligence: Israeli op as per their source. Mossad set up drone base in Iran; UAVs were activated overnight to strike surface-to-surface missile launchers aimed at Israel. https://www.timesofisrael.com/liveblog_entry/mossad-set-up-a-drone-base-in-iran-uavs-were-activated-overnight-to-strike-surface-to-surface-missile-launchers-aimed-at-israel/
June 13, 2025 at 07:57PM
โ โ โ โกโก Telegram, the FSB, and the Man in the Middle. The technical infrastructure that underpins Telegram is controlled by a man whose companies have collaborated with Russian intelligence services. An investigation by IStories https://storage.googleapis.com/istories/en/stories/2025/06/10/telegram-fsb/index.html
June 13, 2025 at 07:53PM
โ โกโกโกโก Google Cloud and Cloudflare hit by widespread service outages. https://www.bleepingcomputer.com/news/technology/google-cloud-and-cloudflare-hit-by-widespread-service-outages/
June 13, 2025 at 07:27PM
โ โ โกโกโก The FLOCKER Ransomware group claims on their Darkweb site that they have stolen data from the Department of Land and Real Estate Regulation in Ajman, United Arab Emirates ๐ฆ๐ช.
June 13, 2025 at 12:29PM
โ โ โ โ โ Apple just patched a zero-day under active attack. CVE-2025-24201 let hackers escape the WebKit sandbox-Apple calls the exploit extremely sophisticated.
June 13, 2025 at 12:26PM
โ โ โ โกโก The Pakistan Airports Authority (PAA) appears to have been compromised, their email infrastructure being used to distribute password-protected ZIP archives containing a previously undocumented malware. https://x.com/WhichbufferArda/status/1933300356370325981
