tgindex
zerodayalpha

Official Telegram channel of Zero Day Engineering Research & Intelligence - zerodayengineering.com

Последний пост
13 авг.
Последнее чтение
13 авг.
Постов за неделю
2
Всего постов
21
Тип
открытый
Язык
und
Категория
Новости и СМИ (по похожим)
В каталоге с
13 авг.
Подписчики
1 398
+4 за 2 дн.
Сутки
+1
+0,07%
Неделя
 
Месяц
 
Просмотров на пост
866
21 постов
Вовлечённость
61,9%
к подписчикам
Постов в день
0,3
всего 21
Упоминаний
1
каналов
Охват размещения
оценка
1/24сутки в ленте
168
1/48двое суток
192
1/72трое суток
207

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • видео или голосовое, без подписи

  • ⚡️ 0-Day Alert: IBM LangFlow OSS RCE LangFlow deployments have been under active exploitation since May. CVE-2025-34291: CORS misconfiguration + SameSite=None CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist. Majority pattern: takes input from an API endpoint variable and executes it directly on the OS. Attack pattern suggests that LangFlow has not seen appropriate security hardening from the vendor, and shouldn't be deployed in environments where an arbitrary code execution poses a risk. * Attached: 33017 diff and code trace to exec()

  • 5 авг.656156

    "In an era where autonomous AI agents are increasingly being used for vulnerability hunting, this course was a great reminder that deep vulnerability research still depends on a unique methodology, analytical thinking, and understanding systems at their core not just automation." – Malik Kurbanov, Founder & CEO

  • видео или голосовое, без подписи

  • ⚡️ Linux Kernel just issued a single-fix security update for stable LTS branches, addressing CVE-2026-64560. We were able to exploit the bug and independently confirm that it's serious. The impact is kernel code execution and EoP from unpriveleged user with no CAPs/userns, io_uring disable + BPF JIT hardening. The use-after-free primitive is reliable despite the race (<1m to exploit). No wild attacks were seen yet. They are likely, given our technical picture. Majority of Android devices are affected. Exploitability on Android wasn't empirically confirmed yet.

  • VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors: 1. Remote attack on vCenter – CVE-2026-59309: auth bypass via network access CVE-2026-59310: directory traversal RCE An exploit would allow…

  • VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors: 1. Remote attack on vCenter – CVE-2026-59309: auth bypass via network access CVE-2026-59310: directory traversal RCE An exploit would allow control of entire ESXi infrastructure. 2. A VM-escapable set of two bugs – CVE-2026-59310: vmxnet3 OOBW CVE-2026-41703: core OOBR These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user. Diffing and exploiting (1) is straightforward and should be patched promptly.

  • New training: Chrome Full Chain Exploit Engineering @alisaesage Public online cohort on August 25-28, 2026 open for booking: https://zerodayengineering.com/training/chrome-full-chain/

  • 26 июн.1 0022

    "About three months ago I started the Browser Exploit Design training of Zero Day Engineering. A very interesting self-paced course where a combination of browser internals, realistic exploit development workflows and hands-on exercises based on modern browser 0-days is discussed. It includes topics such as DOM use-after-free bugs, JavaScript engine type confusion and sandbox escapes in Chrome, Firefox and Safari/WebKit. It is without a doubt the most challenging course I have followed so far in the field of (browser) exploitation. And I still have a lot to learn in this. But much more insight into how browsers work and how browser exploits are done in practice. To be continued." – Ian van der Wurff, Hacker || OSCE3 | OSCP

  • New Certification System https://zerodayengineering.com/training/certification/ Zero Day Engineering now issues a Certificate of Competence — proof of integrating the training and applying it to current frontier challenges in scope. Project-based, evaluated for honest merit.

  • "Highly recommended for anyone looking to deepen their understanding of browser security internals and the full exploit lifecycle" – Bruno Eligio Pavesi, Red Team Operator, Penetration Tester Browser Exploit Design course: https://zerodayengineering.com/training/browser-exploit-design.html

  • видео или голосовое, без подписи

  • New course review: "Probably the best use of my time and effort I have made in some time." – Vikram Hegde, ML Engineer & Data Scientist, CA, US Vikram took Browser Exploit Design course after building his foundation with Zero Day Vulnerability Research course: 1- https://zerodayengineering.com/training/universal-vulnerability-research.html 2- https://zerodayengineering.com/training/browser-exploit-design.html

  • Now available: Alpha Exploit Intelligence https://zerodayengineering.com/intelligence/index.html Curated zero-day and exploit intelligence, delivered as a quarterly membership. For decision-makers operating where the offensive landscape matters.

  • 2 июн.1 23347

    New Zero Day Engineering research: Chrome Exploit Mitigations (by @alisaesage) https://zerodayengineering.com/research/chrome-exploit-mitigations/

  • Summer Bundles https://zerodayengineering.com/promo

  • 2 апр.1 54510

    видео или голосовое, без подписи

  • 2 апр.1 38510

    видео или голосовое, без подписи

  • 2 апр.1 530110

    ⚡️0-Day Alert: Google Chrome GPU Remote to Elevation of Privilege exploit in the wild CVE-2026-5281: Dawn Server Use-after-free due to improper clearing of callbacks upon object destruction 🔒Issue: https://issues.chromium.org/issues/491518608 The bug is interesting: a partial EoP that can potentially be triggered remotely via WebGPU API calls. Normally this chain of impact requires at least 2-3 separate bugs. The fact that it was cherry-picked to M146 confirms high-to-critical impact. Patched in 146.0.7680.177/178 for Windows/Mac and 146.0.7680.177 for Linux on 31st March

  • 26 мар.1 3193

    видео или голосовое, без подписи

zerodayalpha — tgindex