- Последний пост
- 09:48
- Последнее чтение
- 19:16
- Постов за неделю
- 12
- Всего постов
- 46
- Тип
- открытый
- Язык
- английский
- В каталоге с
- 12 авг.
- 1/24сутки в ленте
- 30
- 1/48двое суток
- 34
- 1/72трое суток
- 37
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
The coolest anti-surveillance tools at Defcon https://www.youtube.com/watch?v=-2uAsJ5EPAw
🔒 Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Unauthenticated heap overflow in SAML signature canonicalization. An oversized PrefixList inside the <ds:SignedInfo> InclusiveNamespaces element overflows a fixed-size buffer, corrupting adjacent nsb chunk metadata. This yields a write-what-where primitive (controlled memcpy src/dst), allowing overwrite of tx_pkt_complete_fptr and jump to attacker shellcode on the executable heap. Results in root RCE when NetScaler is configured as SAML SP or IdP. Affected: NetScaler ADC/Gateway 14.1 < 14.1-72.61 and 13.1 < 13.1-63.18 🔗 Research: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔗 Source: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 #citrix #netscaler #rce #preauth #saml #heapoverflow
SilentChrome-BOF SilentChrome-BOF demonstrates how modifying a Chromium profile can transform the browser itself into a persistent C2 agent with examples such as Ditto. Extensions provide the foundation for the C2 agent and IWAs or Native Messaging Hosts can expand its capabilities. Ditto Mythic payload type that builds a Chromium extension as the agent artifact. The built extension checks in to Mythic over HTTP(S) and currently supports browser-scoped tasking such as tab enumeration, cookie collection, screenshots, history search, DNS lookup, and runtime sleep changes. The extension's capabilities can include SOCKS if the IWA option is included, and if native messenger app is included, the extension can interact with the OS with coffexec. Blog: Attack of The Extensions Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft.
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident https://www.youtube.com/watch?v=87DyyMV0kCY
без подписи
PoC RELEASED: Public exploit code is now available for CVE-2026-47301, a CVSS 8.8 privilege escalation flaw in Microsoft Configuration Manager (SCCM). The vulnerability involves improper access control and can be exploited over the network https://github.com/omribaso/sccm-cve-2026-47301-remote-code-execution-exploit
без подписи
D7EAD/mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. https://github.com/D7EAD/mkPIVM 🎖@malwr
7z can be used to copy system hives bypassing EDR. https://hackers-arise.com/digital-forensics-attacking-sam-and-extracting-hashes-with-7z/
New exploit: xor dword [0xf80c2094], 1<<22 Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. https://github.com/xoreaxeaxeax/skitter-creek-bath-salts
без подписи
VHDVomit A tool to search SMB shares for VHD/VMDK/VHDX backup files, mount them and dump sensitive data including NTDS.dit, SYSTEM, and SAM hives. vbkVomit Extract hashes from Veeam .vbk backup. Reads the VBK directly, finds the NTFS volume inside, walks the MFT, reassembles ntds.dit + SAM/SECURITY/SYSTEM, and runs impacket secretsdump. VeeamThief Rogue vSphere server for capturing Veeam Backup & Replication credentials. Blog: https://adversaryco.com/blog/breaking-bad-backups
Plug & Pwn: Weaponizing Windows PnP Every time a USB device is plugged into a Windows machine, the operating system may silently download a package from Microsoft and execute vendor code as NT AUTHORITY\SYSTEM. That can happen without administrator privileges, without a logged-on user, and in some environments even remotely through RDP USB redirection.
Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) Blog: https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077/
без подписи
Two new logical flaws in Kerberos just dropped at Black Hat. Low-privileged user to full domain takeover, including domain admins. KerberLoss (CVE-2026-25177) and ResetNightmare (CVE-2026-27912). Both are logical bugs, not memory corruption. https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/
без подписи
без подписи
без подписи
Teardown of CrowdStrike Falcon Full reverse of the sensor, kernel callbacks, WFP, minifilter, detection engine; with blind spots https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/