tgindex
Dark Army [Tutorials]

Dark Army [Tutorials]

Статистика
@DarkArmyChannelРазвлеченияпортугальский

Um canal dedicado a compartilhar informações, notícias, tutoriais de hacking, ferramentas do Termux, etc... Canal : @DarkArmyChannel Parceria = [ @fsocietyOficialBR, @theninjaway1337 ]

Последний пост
5 апр.
Последнее чтение
15 авг.
Постов за неделю
0
Всего постов
20
Тип
открытый
Язык
португальский
Категория
Развлечения (по похожим)
В каталоге с
13 авг.
Подписчики
1 507
−2 за 2 дн.
Сутки
−1
−0,07%
Неделя
 
Месяц
 
Просмотров на пост
868
20 постов
Вовлечённость
57,6%
к подписчикам
Постов в день
0,0
всего 20
Упоминаний
0
каналов
Охват размещения
оценка
1/24сутки в ленте
1/48двое суток
1/72трое суток

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • 5 апр.1 1125

    New Progress ShareFile Flaws Expose Servers to Unauthorized Remote Takeover Security researchers at watchTowr Labs have disclosed a critical exploit chain in the Progress ShareFile Storage Zone Controller. The vulnerabilities, tracked as CVE-2026-2699 and CVE-2026-2701, enable unauthenticated attackers to achieve Remote Code Execution (RCE) and completely compromise vulnerable servers. With roughly 30,000 instances exposed to the public internet, organizations are urged to patch immediately to prevent catastrophic data breaches. Managed file transfer (MFT) solutions remain a top target for advanced persistent threat (APT) groups and ransomware syndicates. Following historic breaches involving tools like MOVEit, Cleo Harmony, and GoAnywhere, threat actors continuously hunt for unpatched data-sharing gateways. See more here 👋

  • 🛑 OpenClaw AI agents can leak data via indirect prompt injection. A crafted URL generated by the agent triggers Telegram or Discord link previews that silently send sensitive data to attacker domains. China’s CNCERT warns organizations to isolate or restrict the tool. 🔗 Attack details → https://thehackernews.com/2026/03/openclaw-ai-agent-flaws-could-enable.html

  • 16 мар.1 1153

    🛑 OpenClaw AI agents can leak data via indirect prompt injection. A crafted URL generated by the agent triggers Telegram or Discord link previews that silently send sensitive data to attacker domains. China’s CNCERT warns organizations to isolate or restrict the tool. 🔗 Attack details → https://thehackernews.com/2026/03/openclaw-ai-agent-flaws-could-enable.html

  • 13 мар.1 05033

    #News #Phishing #BancoMaster #SGI Phishing Insider comprometido. Credenciais roubadas. Acesso quase em tempo real a investigações sigilosas da PF, do MPF e até da Interpol. Isso não é o roteiro ruim de mais uma série de streaming feita com orçamento de conserto de Fusca. É como a Polícia Federal descreveu a Operação Compliance Zero, que resultou na prisão do banqueiro Daniel Vorcaro nessa semana. Como a maioria dos ataques baseados em engenharia social, o esquema era simples na essência: páginas falsas idênticas ao portal oficial da PGR para capturar senhas de servidores, combinadas com um policial federal aposentado vendendo credenciais de colegas ainda na ativa. Custo mensal do operador principal: Estimado em R$ 1 milhão. Sob o prisma de cibersegurança, o caso é quase didático sobre por que as maiores ameaças raramente vêm de vulnerabilidades técnicas exóticas. Elas vêm de dois vetores que nenhum firewall resolve sozinho. See more here 🙋‍♂

  • 4 янв.1 4153

    видео или голосовое, без подписи

  • 4 янв.1 2781

    🦠Kaspersky researchers discovered preinstalled malware on certain models of tablets running Android – calling it Keenadu. It's a backdoor in 𝘭𝘪𝘣𝘢𝘯𝘥𝘳𝘰𝘪𝘥_𝘳𝘶𝘯𝘵𝘪𝘮𝘦.𝘴𝘰

  • 4 янв.1 0813

    Zero-Day: Zero-Click RCE on Apple iOS viz. decoding logic vulnerability in Apple's image parser. https://youtu.be/jJ2QwvMDf7k

  • Um poderoso plugin Ghidra que integra Large Language Models (LLMs) diretamente no Ghidra para aprimorar fluxos de trabalho de engenharia reversa com análise de código e recursos de aprimoramento. https://github.com/weirdmachine64/GhidraGPT

  • Smugglex is a security testing tool that detects HTTP Request Smuggling vulnerabilities in web applications. It tests for CL.TE, TE.CL, TE.TE, H2C, and H2 smuggling attacks. https://github.com/hahwul/smugglex

  • Critical RCE (CVSS 10) vulnerability affecting n8n instances: CVE-2025-68613. Detection script: https://github.com/rxerium/CVE-2025-68613/tree/main

  • > Golpistas subiram um site falso da caixa para apostar na mega da virada > Deixaram um endpoint exposto que consulta CPF > Aproveite para brincar https://searchapi.dnnl.live/consulta?token_api=3531&cpf=CPF_AQUI Créditos ao canal: LimonTec

  • Android mobile malware campaigns are converging on the same playbook. Wonderland in Uzbekistan, plus Cellik, Frogblight, and NexusRoute elsewhere, all use fake legit apps, droppers, and phishing to steal OTPs, bank data, and accounts. This marks a shift to scalable, MaaS-style fraud, not isolated scams. 🔗 Read details here → https://thehackernews.com/2025/12/android-malware-operations-merge.html

  • Microsoft Patches MSMQ Flaw That Affects IIS Web Servers Microsoft has released an out-of-band security update to address a significant vulnerability in Message Queuing (MSMQ) functionality that impacts Windows 10 systems running IIS web servers and enterprise environments. The flaw, discovered and documented in the December 9, 2025 update (KB5071546), affects Windows 10 version 22H2 and version 21H2. The Vulnerability The MSMQ bug causes severe operational disruptions, particularly in clustered MSMQ environments experiencing high loads. Organizations affected by this vulnerability have reported multiple critical symptoms including inactive message queues, insufficient resource errors, and applications unable to write to message queues. Veja mais aqui 🙋‍♂ Share and support us 🦊

  • Cisco AsyncOS 0-Day Allows Remote Execution of System Commands Cisco Talos has uncovered an active campaign exploiting a zero-day vulnerability in Cisco AsyncOS Software, affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The security flaw enables attackers to execute system-level commands remotely and deploy sophisticated backdoors on compromised systems. The threat actor behind this campaign, tracked as UAT-9686, is assessed with moderate confidence to be a Chinese-nexus advanced persistent threat group. Cisco became aware of the malicious activity on December 10, 2025, though evidence suggests attacks have been ongoing since at least late November 2025. Attack Methodology UAT-9686 deploys a custom persistence mechanism called “AquaShell,” a lightweight Python backdoor embedded into existing files within Python-based web servers algorithm combined with Base64 decoding before executing commands on the compromised appliance. Source : https://gbhackers.com/cisco-asyncos-0-day/

  • ■■■■□ Notepad++ Vulnerability Let Attackers Hijack Network Traffic to Install Malware via Updates. https://cybersecuritynews.com/notepad-vulnerability-exploited/

  • ⚠️ Hackers are still hitting Middle East governments. A group called WIRTE (Ashen Lepus) is expanding to Oman and Morocco with new malware named AshTag. It hides in fake political PDFs — open one, and it steals your files. 🔗 Read ↓ https://thehackernews.com/2025/12/wirte-leverages-ashenloader-sideloading.html

  • [New] React just found more bugs hiding in its last big patch. 🧩 CVE-2025-55184 & CVE-2025-67779 — can crash servers with one request. 🧩 CVE-2025-55183 — can leak source code from React Server Components. 👀 All discovered while testing the earlier CVE-2025-55182 fix. Update to versions 19.0.3, 19.1.4, or 19.2.3 now. 🔗 Read: https://thehackernews.com/2025/12/new-react-rsc-vulnerabilities-enable.html

  • 📱 React2Shell Ultimate - CVE-2025-66478 Scanner. https://github.com/hackersatyamrastogi/react2shell-ultimate

  • ■■■■□ React²Shell search query. → Censys (+270K assets): services.http.response.headers: (key: Vary and value.headers: RSC, Next-Router-State-Tree) → Shodan (+380K assets): "Vary: RSC, Next-Router-State-Tree" 𝕏 | 1ZRR4H

  • ■■■□□ NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools. https://cybersecuritynews.com/netreaper-offensive-security-toolkit/

Dark Army [Tutorials] — tgindex