Cyber Guardians
СтатистикаRedTeaming TTPs Bug Hunting Web PenTest Web Security Binary Analysis Exploit DEV Malware DEV Malware Analysis BlueTeaming Threat Hunting SOC CSIRT FORENSICS Open-Source Intelligence(OSINT) Cybersec Tools
- Последний пост
- 12 авг.
- Последнее чтение
- 12:22
- Постов за неделю
- 1
- Всего постов
- 25
- Тип
- открытый
- Язык
- английский
- Категория
- Новости и СМИ (по похожим)
- В каталоге с
- 12 авг.
- 1/24сутки в ленте
- 936
- 1/48двое суток
- 1 072
- 1/72трое суток
- 1 156
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline. Blog: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ @IRCyberGuardians
Exploiting HTTP Parser Inconsistencies: ACL Bypasses, SSRF, and Cache Poisoning Original text: “Exploiting HTTP Parsers Inconsistencies” — Rafa, Rafa’s Security Researches (research conducted December 2021 – April 2022). Code blocks, tables and figures below are reproduced verbatim with attribution captions. Executive Summary HTTP is the connective tissue of the modern web, but the specification leaves enough ambiguity that no two parsers agree on every edge… https://core-jmp.org/2026/07/exploiting-http-parser-inconsistencies/ @IRCyberGuardians
Dnsmasq DNS Remote Heap Buffer Overflow (CVE-2026-2291) Original text: “Dnsmasq DNS Remote Heap Buffer Overflow” — David Barksdale, Exodus Intelligence (July 20, 2026). Code snippets, DNS responses, and exploitation details are reproduced verbatim with attribution. Executive Summary CVE-2026-2291 is a critical remote code execution vulnerability in dnsmasq, a widely deployed lightweight DNS and DHCP server used in embedded systems, routers, and Linux… https://core-jmp.org/2026/07/dnsmasq-dns-remote-heap-buffer-overflow-cve-2026-2291/ @IRCyberGuardians
KernelCallbackTable Process Injection Original text: “KernelCallbackTable Process Injection” — S12, Medium (2026). Code blocks and technical implementation details are reproduced verbatim with attribution. Executive Summary Windows message handling is everywhere. Every GUI application sits in a message loop waiting for user input and window events. But what happens when an attacker corrupts the callback table that decides which… https://core-jmp.org/2026/07/kernelcallbacktable-process-injection/ @IRCyberGuardians
GDID: The Windows Global Device Identifier Original text: “GDID: The Windows Global Device Identifier” — Smukx, ZeroTrace Lab (July 18, 2026). Code blocks, commands, tables, and technical specifications reproduced verbatim with attribution. Executive Summary Every Windows installation receives a unique 64-bit Global Device Identifier (GDID) that serves as Microsoft’s canonical device-level tracking mechanism. The GDID originates as a plaintext registry value… https://core-jmp.org/2026/07/gdid-windows-global-device-identifier/ @IRCyberGuardians
CVE-2026-49176 Exploit Development: WalletService to SYSTEM Original text: “CVE-2026-49176 Exploit Development: WalletService to SYSTEM” — David Carliez, 17 July 2026. Code blocks, tables, and technical diagrams are reproduced verbatim with attribution. Executive Summary CVE-2026-49176 represents a critical local privilege-escalation vulnerability affecting Windows WalletService, a LocalSystem-hosted service that manages wallet operations through the public Windows.ApplicationModel.Wallet WinRT API. The vulnerability emerges from a… https://core-jmp.org/2026/07/cve-2026-49176-walletservice-to-system/ @IRCyberGuardians
[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India) Original text: “[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)” — AI, 0day in {REA_TEAM} (July 13, 2026). Code blocks, tables, diagrams, and technical artefacts are reproduced verbatim with attribution captions. Executive Summary SolidPDFCreator.dll is a sophisticated stage-1 backdoor loader disguised as a legitimate SolidPDF product, attributed to Mustang Panda and targeting India. The… https://core-jmp.org/2026/07/solidpdfcreator-mustang-panda-stage-1-backdoor-india/ @IRCyberGuardians
CVE-2026-58629: A Double-Free in dxgkrnl’s CreateAllocation Rollback Original text: “July 2026 Patch Tuesday [CVE-2026-58629] Freeing the Wrong Allocation: a double-free in dxgkrnl’s CreateAllocation rollback” — gengstah, gengstah (personal blog), July 14, 2026. Disassembly, crash dumps and code below are reproduced verbatim with attribution captions. Executive Summary CVE-2026-58629 is a local elevation-of-privilege bug in dxgkrnl, the Windows Display Driver Model (WDDM) kernel component… https://core-jmp.org/2026/07/cve-2026-58629-dxgkrnl-createallocation-double-free/ @IRCyberGuardians
CVE-2026-58532: An Integer Overflow in Windows tcpip.sys Original text: “How I found an integer overflow in tcpip.sys (CVE-2026-58532)” — April Ivy (aprilpet), April Ivy’s Writing (aprl.pet), 17 July 2026. The prose below is a paraphrase; the call stack, code snippets and proof-of-concept are reproduced verbatim with attribution. Executive Summary Security researcher April Ivy discovered an unsigned 64-bit integer overflow in tcpip.sys, the… https://core-jmp.org/2026/07/cve-2026-58532-tcpip-sys-integer-overflow/ @IRCyberGuardians
Direct $MFT Parsing: Reading NTFS Below the Monitored API Layer Original text: “Direct $MFT Parsing” — S12 — 0x12Dark Development, on Medium. This article summarises the technique in our own words for readers of core-jmp.org; the ASCII pipeline diagram and the short C++ excerpts below are reproduced with attribution to illustrate the discussion. For the complete C++17 header, main runner, and YARA rule, follow the… https://core-jmp.org/2026/07/direct-mft-parsing-ntfs-raw-enumeration @IRCyberGuardians
CVE-2026-50343 InstallService StaticPluginMap EoP (Standard User to SYSTEM) Exploit + WriteUP @IRCyberGuardians
The QNAP Pattern: Four Bugs and the Architecture That Keeps Producing Them Original text: “The QNAP Pattern” — Runic Labs (May 17, 2026). Code and architecture diagrams below are reproduced with attribution. Executive Summary Runic Labs disassembled a full disclosure cycle against QNAP’s QTS operating system—four bugs across three App Center plugins (Notes Station 3, QmailAgent, QVPN) spanning two firmware releases—and found that the individual vulnerabilities matter… https://core-jmp.org/2026/07/qnap-pattern-architecture-vulnerabilities/ @IRCyberGuardians
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining Original text: “CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining” — Tiziano Marra, Tiziano’s Cybersecurity Blog (12 July 2026). Code blocks, tables, and figures below are reproduced verbatim with attribution captions. Research published for educational and defensive purposes. Always obtain explicit written authorization before testing security techniques on any computer system. Unauthorized access is… https://core-jmp.org/2026/07/cet-compliant-callstack-spoofing-thread-pool-enum/ @IRCyberGuardians
Two Bytes to RCE: Chaining Rift + PoolSlip into an ASLR-Independent nginx 1.30.0 Exploit Original text: “Two Bytes to RCE: Chaining Rift + PoolSlip” — y198, Verichains (Jun 06, 2026). Code, tables and figures below are reproduced verbatim with attribution captions. PoC: github.com/y198nt/Nginx-chain-Rift-Poolslip. Executive Summary A two-bug chain in nginx 1.30.0 achieves unauthenticated remote code execution without relying on ASLR breaks. The first bug, CVE-2026-42945 (“Rift”), is a forward… https://core-jmp.org/2026/07/nginx-rce-rift-poolslip-aslr-independent/ @IRCyberGuardians
Process Parameter Poisoning: EDR Evasion via Windows Process Startup Parameters Original text: “Process Parameter Poisoning” — Max Hirschberger & Ogulcan Ugur, SensePost / Orange Cyberdefense (6 July 2026). Code listings and figures are reproduced verbatim with attribution captions. Executive Summary Process Parameter Poisoning (P3) is a code injection technique that transfers shellcode into a foreign process via the startup parameters of CreateProcessW—specifically the lpCommandLine, lpEnvironment,… https://core-jmp.org/2026/07/process-parameter-poisoning-edr-evasion-windows/ @IRCyberGuardians
The Dark Side of WebAssembly: Cryptomining, Keyloggers, and Browser Exploitation Original text: “El lado oscuro de WebAssembly” — Carlos Ávila, Telefónica Tech Blog (September 16, 2020). Images are reproduced verbatim with attribution captions. Executive Summary WebAssembly (WASM) is an open binary instruction format — announced in 2015 and broadly supported by browsers from 2017 onward — designed to let code written in C, C++, Rust,… https://core-jmp.org/2026/07/dark-side-webassembly-cryptomining-keyloggers-browser-exploitation/ @IRCyberGuardians
Januscape: Guest-to-Host Escape in KVM/x86 PoC @IRCyberGuardians
CVE-2026-48282 Adobe ColdFusion's Remote Development Service (RDS) PoC @IRCyberGuardians
Ruby on Rails Active Storage Vips RCE (CVE-2026-66066) Target Software/Hardware: Ruby on Rails 6.0.6.1, 6.1.7.10, 8.0.5, and 8.0.5.1, Active Storage with Vips variant processor, Ruby 3.2, image_processing 1.14.0, ruby-vips ~> 2.2, libvips 8.16.1 built with -Dmatio=enabled @IRCyberGuardians
Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Authentication bypass via the SmartConsole login process using an application token. This affects Check Point Security Management Server and Multi-Domain Security Management Server (MDS). Metasploit module: https://github.com/rapid7/metasploit-framework/pull/21731 Blog: https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/ @IRCyberGuardians