tgindex
RME-DisCo @ UNIZAR [www.reversea.me]

RME-DisCo @ UNIZAR [www.reversea.me]

Статистика

Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see" Link to the channel: https://t.me/reverseame

Последний пост
3 авг.
Последнее чтение
09:21
Постов за неделю
0
Всего постов
263
Тип
открытый
Язык
английский
Категория
Образование
В каталоге с
12 авг.
Подписчики
3 462
+1 за 3 дн.
Сутки
−1
−0,03%
Неделя
 
Месяц
 
Просмотров на пост
805
40 постов
Вовлечённость
23,3%
к подписчикам
Постов в день
0,0
всего 263
Упоминаний
0
каналов
Охват размещения
оценка
1/24сутки в ленте
422
1/48двое суток
483
1/72трое суток
521

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • New post: a five-phase, MITRE ATT&CK-aligned workflow for mem forensics, from evidence preservation to binary analysis. We also flag 4 issues that bias mem evidence: paging, demand paging, smearing, and binary transforms #ICDF2C25 https://reversea.me/index.php/bringing-structure-to-memory-forensics-a-five-phase-mitre-attck-aligned-workflow/ https://webdiis.unizar.es/~ricardo/files/papers/Rodriguez-ICDF2C-27.pdf

  • 6 июл.1 209110

    New on the blog: MARISSA reverse-engineers network protocol formats straight from PCAPs: no specs, no delimiters. Will be presented at @IEEEEUROSP 2026, come and say hi! https://reversea.me/index.php/inferring-network-protocols-from-traffic-with-marissa/ tool: https://github.com/reverseame/MARISSA

  • 1 июл.1 2418

    New blog post! The simpler, the stealthier: we benchmarked 4 adversarial DGA models. The 2 simplest evade ML detectors >75% of the time and train in under 2s. Open-source: http://github.com/reverseame/adversarial-dga-framework, blog post: https://reversea.me/index.php/the-simpler-the-stealthier-benchmarking-adversarial-dga-models-in-a-unified-framework/ #DGA #MachineLearning #CyberSecurity #DIMVA2026

  • 21 июн.1 3126

    Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) #IvantiEPMM #PreAuthRCE #BashExploit #ArithmeticExpansion #ActivelyExploited https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/

  • 20 июн.1 0387

    How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key - Leaked Twice #QodoSecurity #RCEAWSAdminKey #PRCommentExploit #SupplyChainAttack #VulnerabilityBypass https://kudelskisecurity.com/research/qodo-dynaconf-aws-admin-key-leaked-twice

  • 5 июн.1 2308

    Exploiting a PHP Object Injection in Profile Builder Pro in the era of AI #PHPObjectInjection #ProfileBuilderPro #WordPressSecurity #RemoteCodeExecution #AIAssistedExploit https://blog.sicuranext.com/exploiting-a-php-object-injection-in-profile-builder-pro-in-the-era-of-ai/

  • 3 июн.1 0597

    Cybersecurity AI: A Game-Theoretic AI for Guiding Attack and Defense #CybersecurityAI #GameTheoretic #AttackDefense #LLMGuidance #StrategicAI https://arxiv.org/abs/2601.05887

  • One-click RCE on OpenClaw in under 2 hours with an Autonomous Hacking Agent https://ethiack.com/news/blog/one-click-rce-openclaw

  • ZK credential sharing #ShareMyLogin #ZeroKnowledge #CredentialSharing #SecureSharing #PrivacyTech https://sharemylogin.com/

  • General Graboids: Worms and Remote Code Execution in Command & Conquer #CommandAndConquer #GameVulnerabilities #RemoteCodeExecution #P2PWorm #SecurityResearch https://www.atredis.com/blog/2026/1/26/generals

  • CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue #SolarWindsWHD #RCEVulnerability #DeserializationIssue #PatchBypass #CVE202540551 https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

  • Blind Boolean-Based Prompt Injection https://medium.com/@danielhammon1/blind-boolean-based-prompt-injection-62a3bfc38101

  • Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals #Swarmer #WindowsPersistence #EDREvasion #OfflineRegistry #MandatoryProfiles https://www.praetorian.com/blog/corrupting-the-hive-mind-persistence-through-forgotten-windows-internals/

  • Bypassing Windows Administrator Protection #WindowsSecurity #AdministratorProtection #UACBypass #ProjectZero #KernelVulnerability https://projectzero.google/2026/26/windows-administrator-protection.html

  • Certificate Transparency as Communication Channel #CertificateTransparency #HiddenData #CovertChannel #RSAKeys #ImmutableLogs https://latedeployment.github.io/posts/certificate-transparency-as-communication-channel/

  • ISC BIND vulnerability discovered and disclosed by Marlink Cyber #MarlinkCyber #ISCBIND #DenialOfService #DNS #SecurityPatch https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/

  • Malware Analysis, Phishing, and Email Scams #PhishingScam #PNBMetLife #FinancialFraud #CredentialHarvesting #TelegramBots https://malwr-analysis.com/2026/01/21/fake-pnb-metlife-payment-gateway-page-stealing-customer-details-and-redirecting-victims-to-upi-payments/

  • When The Gateway Becomes The Doorway: Pre-Auth RCE in API Management . #APIGateway #PreAuthRCE #JavaDeserialization #BugBounty #SecurityResearch https://principlebreach.com/lab/when-the-gateway-becomes-the-doorway-pre-auth-rce-in-api-management

  • Billion-Dollar Bait & Switch: Exploiting a Race Condition in Blockchain Infrastructure #BlockchainVulnerability #RaceCondition #BaitAndSwitchExploit #EthereumSecurity #ArbitrageHeist https://mavlevin.com/2026/01/18/flashbots-mev-relay-race-condition-vulnerability

  • Successful Errors: New Code Injection and SSTI Techniques #SSTIResearch #CodeInjection #ErrorBasedTechniques #BlindExploitation #SSTImapTool https://github.com/vladko312/Research_Successful_Errors

RME-DisCo @ UNIZAR [www.reversea.me] — tgindex