Found 1481 bookmarks
Newest
LibAFL
LibAFL
LibAFL # The LibAFL fuzzer implements features from AFL-based fuzzers like AFL++. Similarly to AFL++, LibAFL provides better fuzzing performance and more advanced features over libFuzzer. However, with LibAFL, all functionality is provided in a modular and customizable way—in fact, LibAFL is a library that can be used to implement custom fuzzers. Because LibAFL is a library, there is no single-line command to install LibAFL like there is with libFuzzer (apt install clang) and AFL++ (apt install afl++).
·appsec.guide·
LibAFL
Struts Devmode in 2025? Pre-Auth Bugs in AEM Forms | Searchlight
Struts Devmode in 2025? Pre-Auth Bugs in AEM Forms | Searchlight
Vulnerabilities in AEM Forms The Searchlight Cyber Research Team discovered and disclosed three critical vulnerabilities in Adobe Experience Manager Forms to Adobe in late April 2025. As of writing this research post, 90 days have passed since our disclosure to Adobe. During this time, Adobe has only released a patch for one of the three
·slcyber.io·
Struts Devmode in 2025? Pre-Auth Bugs in AEM Forms | Searchlight
ESXi Exploitation in the Wild | Huntress
ESXi Exploitation in the Wild | Huntress
Huntress outlines a complex, multi-step attack designed to break out of guest VMs and target the ESXi hypervisor, using potential zero-day vulnerabilities and sneaky VSOCK communication.
·huntress.com·
ESXi Exploitation in the Wild | Huntress
Is BGP safe yet? · Cloudflare
Is BGP safe yet? · Cloudflare
On the Internet, network devices exchange routes via a protocol called BGP (Border Gateway Protocol). Unfortunately, issues with BGP have led to malicious actors being able to hijack and misconfigure devices leading to security problems which have the potential to cause widespread problems. BGP security can be greatly improved by using technologies such as RPKI to sign Internet routes. This page attempts to track the progress of major Internet players (ISPs, transit operators, and content providers) in their progress to adopt RPKI and other technologies.
·isbgpsafeyet.com·
Is BGP safe yet? · Cloudflare
A closer look at a BGP anomaly in Venezuela
A closer look at a BGP anomaly in Venezuela
There has been speculation about the cause of a BGP anomaly observed in Venezuela on January 2. We take a look at BGP route leaks, and dive into what the data suggests caused the anomaly in question.
·blog.cloudflare.com·
A closer look at a BGP anomaly in Venezuela
Radar #16: Week of 01/05/2026
Radar #16: Week of 01/05/2026
The Low Orbit Security Radar is a weekly security newsletter from an offensive practitioner's perspective. One idea, curated news, and links worth your time. News: There Were BGP Anomalies During The Venezuela Blackout When watching the situation in Venezuela unfold, the phrase "It was dark, the lights of Caracas were largely turned off due to a certain expertise that we have" caught my attention. I do not wish to comment on the geopolitical situation other than to provide some insights withi
·loworbitsecurity.com·
Radar #16: Week of 01/05/2026
21 Lessons From 14 Years at Google
21 Lessons From 14 Years at Google
Lessons learned from 14 years of engineering at Google, focusing on what truly matters beyond just writing great code.
·addyosmani.com·
21 Lessons From 14 Years at Google
A Broken System Fueling Botnets
A Broken System Fueling Botnets
Synthient continues to track the Kimwolf DDoS and proxy botnet with this report, delivering significant findings on the inner workings, infection chain, and reliance on the residential proxy ecosystem. Kimwolf has been highly active since early August of 2025, with substantial growth over the past four months. The Synthient’s research team assesses with high confidence that the total number of infected devices has surpassed 2 million, primarily targeting Android devices running an exposed Android Debug Bridge (ADB) service via residential proxies. These findings further reveal an expansive network of compromised TV streaming devices used by providers to obtain large pools of IP addresses.Given Kimwolf's reliance on residential proxies for infections, we advise all proxy providers to block high-risk ports and restrict access to the local network. Users should check whether they are affected by visiting synthient.com/check. Infected TV boxes should be wiped or destroyed. Organizations should block connections to the referenced C2 servers and domains, and monitor network traffic for suspicious activity.Synthient expects to observe a growing interest among threat actors in gaining unrestricted access to proxy networks to infect devices, obtain network access, or access sensitive information. Kimwolf highlights the risks posed by unsecured proxy networks and their viability as an attack vector.
·synthient.com·
A Broken System Fueling Botnets
CVE-2025-20362 | AttackerKB
CVE-2025-20362 | AttackerKB
On September 25, 2025, Cisco published advisories for two new vulnerabilities, CVE-2025-20362, and CVE-2025-20333, which are known to be exploited in-the-wild …
·attackerkb.com·
CVE-2025-20362 | AttackerKB
0day .ICS attack in the wild
0day .ICS attack in the wild
Earlier in 2025, an apparent sender from 193.29.58.37 spoofed the Libyan Navy’s Office of Protocol to send a then-zero-day exploit in Zimbra’s Collaboration Suite, CVE-2025-27915, targeting Brazil’s military.
·strikeready.com·
0day .ICS attack in the wild
Exploiting the Synology TC500 at Pwn2Own Ireland 2024
Exploiting the Synology TC500 at Pwn2Own Ireland 2024
IntroductionIn October 2024, InfoSect participated in Pwn2Own – a bug bounty competition against embedded devices such as cameras, NAS’, and smart speakers. In this blog, I’ll dis…
·blog.infosectcbr.com.au·
Exploiting the Synology TC500 at Pwn2Own Ireland 2024
More Fun With WMI - SpecterOps
More Fun With WMI - SpecterOps
TL;DR: Win32_Process has long been the go-to WMI class for remote command execution. In this post we cover MSFT_MTProcess — a newer WMI class that functions like Win32_Process but also offers additional capabilities, including remote process creation and process-dumping on Windows Server 2016 and newer (and on workstations if the provider is installed). From time to time, across different versions […]
·specterops.io·
More Fun With WMI - SpecterOps
RCE Vulnerability Discovered in ETQ Reliance | Searchlight Cyber
RCE Vulnerability Discovered in ETQ Reliance | Searchlight Cyber
Note: In correspondence with Hexagon while disclosing the bugs below, they informed us that any sharing of source code would be considered a violation of their terms and license. The Java code has been replaced with similar code that illustrates the flow of the application and names have been changed. It seems that vulnerability research
reliance/rel
·slcyber.io·
RCE Vulnerability Discovered in ETQ Reliance | Searchlight Cyber