Archive

Archive

Unsafe at Any Speed: Abusing Python Exec for Unauth RCE in Langflow AI
Unsafe at Any Speed: Abusing Python Exec for Unauth RCE in Langflow AI
CVE-2025-3248 is a critical code injection vulnerability affecting Langflow, a popular tool used for building out agentic AI workflows. This vulnerability is easily exploitable and enables unauthenticated remote attackers to fully compromise Langflow servers. The issue is patched in Langflow 1.3.0.
·horizon3.ai·
Unsafe at Any Speed: Abusing Python Exec for Unauth RCE in Langflow AI
Is The Sofistication In The Room With Us? - X-Forwarded-For and Ivanti Connect Secure (CVE-2025-22457)
Is The Sofistication In The Room With Us? - X-Forwarded-For and Ivanti Connect Secure (CVE-2025-22457)
What's that Skippy? Another Ivanti Connect Secure vulnerability? At this point, regular readers will know all about Ivanti (and a handful of other vendors of the same class of devices), from our regular analysis. Do you know the fun things about these posts? We can copy text from previous posts
·labs.watchtowr.com·
Is The Sofistication In The Room With Us? - X-Forwarded-For and Ivanti Connect Secure (CVE-2025-22457)
Sekoia.io
Sekoia.io
Sekoia.io provides cyber teams with a SOC platform that can respond to security incidents, regardless of the attack surface.
·sekoia.io·
Sekoia.io
Bypassing Detections with Command-Line Obfuscation
Bypassing Detections with Command-Line Obfuscation
Defensive tools like AVs and EDRs rely on command-line arguments for detecting malicious activity. This post demonstrates how command-line obfuscation, a shell-independent technique that exploits executables’ parsing “flaws”, can bypass such detections. It also introduces ArgFuscator, a new tool that identifies obfuscation opportunities and generates obfuscated command lines.
·wietzebeukema.nl·
Bypassing Detections with Command-Line Obfuscation
Zimbra - Remote Command Execution (CVE-2024-45519) — ProjectDiscovery Blog
Zimbra - Remote Command Execution (CVE-2024-45519) — ProjectDiscovery Blog
Zimbra, a widely used email and collaboration platform, recently released a critical security update addressing a severe vulnerability in its postjournal service. This vulnerability, identified as CVE-2024-45519, allows unauthenticated attackers to execute arbitrary commands on affected Zimbra installations. In this blog post, we delve into the nature of this vulnerability, our journey in analyzing the patch, and the steps we took to exploit it manually. We also discuss the potential impact and
·projectdiscovery.io·
Zimbra - Remote Command Execution (CVE-2024-45519) — ProjectDiscovery Blog
Spamming Microsoft 365 Like It’s 1995 - Black Hills Information Security
Spamming Microsoft 365 Like It’s 1995 - Black Hills Information Security
I previously blogged about spoofing Microsoft 365 using the direct send feature enabled by default when creating a business 365 Exchange Online instance (https://www.blackhillsinfosec.com/spoofing-microsoft-365-like-its-1995/). Using the direct send feature, it […]
·blackhillsinfosec.com·
Spamming Microsoft 365 Like It’s 1995 - Black Hills Information Security