tgindex
cyberschmutz
@cyberschmutzанглийский

your daily byte of cybersec

Последний пост
09:48
Последнее чтение
19:16
Постов за неделю
12
Всего постов
46
Тип
открытый
Язык
английский
В каталоге с
12 авг.
Подписчики
170
0 за 5 дн.
Сутки
0
0,00%
Неделя
 
Месяц
 
Просмотров на пост
65
40 постов
Вовлечённость
38,2%
к подписчикам
Постов в день
1,7
всего 46
Упоминаний
1
каналов
Охват размещения
оценка
1/24сутки в ленте
30
1/48двое суток
34
1/72трое суток
37

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • The coolest anti-surveillance tools at Defcon https://www.youtube.com/watch?v=-2uAsJ5EPAw

  • 🔒 Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Unauthenticated heap overflow in SAML signature canonicalization. An oversized PrefixList inside the <ds:SignedInfo> InclusiveNamespaces element overflows a fixed-size buffer, corrupting adjacent nsb chunk metadata. This yields a write-what-where primitive (controlled memcpy src/dst), allowing overwrite of tx_pkt_complete_fptr and jump to attacker shellcode on the executable heap. Results in root RCE when NetScaler is configured as SAML SP or IdP. Affected: NetScaler ADC/Gateway 14.1 < 14.1-72.61 and 13.1 < 13.1-63.18 🔗 Research: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔗 Source: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 #citrix #netscaler #rce #preauth #saml #heapoverflow

  • SilentChrome-BOF SilentChrome-BOF demonstrates how modifying a Chromium profile can transform the browser itself into a persistent C2 agent with examples such as Ditto. Extensions provide the foundation for the C2 agent and IWAs or Native Messaging Hosts can expand its capabilities. Ditto Mythic payload type that builds a Chromium extension as the agent artifact. The built extension checks in to Mythic over HTTP(S) and currently supports browser-scoped tasking such as tab enumeration, cookie collection, screenshots, history search, DNS lookup, and runtime sleep changes. The extension's capabilities can include SOCKS if the IWA option is included, and if native messenger app is included, the extension can interact with the OS with coffexec. Blog: Attack of The Extensions Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft.

  • Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident https://www.youtube.com/watch?v=87DyyMV0kCY

  • без подписи

  • PoC RELEASED: Public exploit code is now available for CVE-2026-47301, a CVSS 8.8 privilege escalation flaw in Microsoft Configuration Manager (SCCM). The vulnerability involves improper access control and can be exploited over the network https://github.com/omribaso/sccm-cve-2026-47301-remote-code-execution-exploit

  • без подписи

  • 15 авг.311из malwr

    D7EAD/mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. https://github.com/D7EAD/mkPIVM 🎖@malwr

  • 7z can be used to copy system hives bypassing EDR. https://hackers-arise.com/digital-forensics-attacking-sam-and-extracting-hashes-with-7z/

  • New exploit: xor dword [0xf80c2094], 1<<22 Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. https://github.com/xoreaxeaxeax/skitter-creek-bath-salts

  • без подписи

  • VHDVomit A tool to search SMB shares for VHD/VMDK/VHDX backup files, mount them and dump sensitive data including NTDS.dit, SYSTEM, and SAM hives. vbkVomit Extract hashes from Veeam .vbk backup. Reads the VBK directly, finds the NTFS volume inside, walks the MFT, reassembles ntds.dit + SAM/SECURITY/SYSTEM, and runs impacket secretsdump. VeeamThief Rogue vSphere server for capturing Veeam Backup & Replication credentials. Blog: https://adversaryco.com/blog/breaking-bad-backups

  • 9 авг.521из P0x3k_1N73LL1G3NC3

    Plug & Pwn: Weaponizing Windows PnP Every time a USB device is plugged into a Windows machine, the operating system may silently download a package from Microsoft and execute vendor code as NT AUTHORITY\SYSTEM. That can happen without administrator privileges, without a logged-on user, and in some environments even remotely through RDP USB redirection.

  • 8 авг.55из P0x3k_1N73LL1G3NC3

    Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) Blog: https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077/

  • без подписи

  • Two new logical flaws in Kerberos just dropped at Black Hat. Low-privileged user to full domain takeover, including domain admins. KerberLoss (CVE-2026-25177) and ResetNightmare (CVE-2026-27912). Both are logical bugs, not memory corruption. https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/

  • без подписи

  • без подписи

  • без подписи

  • Teardown of CrowdStrike Falcon Full reverse of the sensor, kernel callbacks, WFP, minifilter, detection engine; with blind spots https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/