Found 1481 bookmarks
Newest
Stack Overflows, Heap Overflows, and Existential Dread (SonicWall SMA100 CVE-2025-40596, CVE-2025-40597 and CVE-2025-40598)
Stack Overflows, Heap Overflows, and Existential Dread (SonicWall SMA100 CVE-2025-40596, CVE-2025-40597 and CVE-2025-40598)
It’s 2025, and at this point, we’re convinced there’s a secret industry-wide pledge: every network appliance must include at least one trivially avoidable HTTP header parsing bug - preferably pre-auth. Bonus points if it involves sscanf. If that’s the case, well done! SonicWall’s SMA100
·labs.watchtowr.com·
Stack Overflows, Heap Overflows, and Existential Dread (SonicWall SMA100 CVE-2025-40596, CVE-2025-40597 and CVE-2025-40598)
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` · Advisory · go-gitea/gitea
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` · Advisory · go-gitea/gitea
Hi guys, I would like to file a vulnerability I found in the default Gitea docker image, which allows impersonation of users with a single header # Summary The Gitea Docker images ship an `ap...
·github.com·
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` · Advisory · go-gitea/gitea
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.
·nebusec.ai·
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
ClickFix: The Gift That Keeps On Giving
ClickFix: The Gift That Keeps On Giving
Technical deep dive into ClickFix tradecraft, a sophisticated social engineering driven initial access technique. Covers delivery methods, execution specializations, payload analysis, and detection strategies based on OrangeCon 2026 research.
·kqlquery.com·
ClickFix: The Gift That Keeps On Giving
Reverse engineering Malwarebytes Browser Guard | msil.re
Reverse engineering Malwarebytes Browser Guard | msil.re
Static analysis of Browser Guard 3.1.5 (15M+ installs): Zstd-encoded on-disk databases, the heuristic rule engine that scans the live DOM, the Hubble false-positive service, the package update protocol, and a debug URL interface left in production. With reimplementations in C# and Python.
·msil.re·
Reverse engineering Malwarebytes Browser Guard | msil.re