Trailing Danger: exploring HTTP Trailer parsing discrepancies
Pwning Supercomputers - A 20yo vulnerability in Munge
Exploiting Heap Buffer Overflow in the authentication daemon used by most High Performance Computer.
Datr cookie theft and AI leads to Facebook account takeover via trusted device recovery
Introduction Facebook relies on long-lived device identifiers to reduce friction for returning users and to distinguish legitimate activity from suspicious logins. Over time, devices that repeatedly authenticate to the same account are treated as trusted, allowing Facebook to relax certain security requirements during sensitive flows such as account recovery.
A Cryptocurrency Heist, Starring Your Web Browser
Beneath the surface, the modern web is made possible only through a growing labryinth of technology standards. Standards are designed to govern the interoper...
rebinding
How I Exposed Instagram's Private Posts by Blocking Users
Discover how a security loophole in Instagram's oEmbed feature enabled unauthorized access to private posts. Journey from BountyCon(Edu) to the vulnerability's discovery, exploitation, and resolution.
Trust Me, I’m a Shortcut
Windows’ primary mechanism for shortcuts, LNK files, is frequently abused by threat actors for payload delivery and persistence. This blog post introduces several new LNK file flaws that, amongst other things, allow attackers to fully spoof an LNK’s target. It also introduces lnk-it-up, a tool suite that can generate such deceptive LNK files, as well as detect anomalous ones.
How a single typo led to RCE in Firefox – kqx
Carbonara: The MediaTek exploit nobody served
Imagine this: You walk into a restaurant you only just discovered, the one rumored for serving the best dishes. It quickly becomes your go-to place for every meal. One day, something odd happens: a secret dish appears on the menu, Carbonara, no price, description, and most importantly, no way to order it. Only few people know the secret code that makes the chef cook it.
Is the Secure Kernel really secure? Diving into Apple's Exclave world with the GLx Research Platform
DKIM replay attacks: Apple and PayPal invoice abuse| Kaseya
Learn how cybercriminals abuse Apple and PayPal invoice emails to trick end users in DKIM replay attacks.
Bypassing the FortiGate Symlink Patch: The Double Slash Technique (CVE-2025-68686)
By Peter Gabaldon (X / LinkedIn) TL;DR In the previous analysis ( we detailed the persistence method where Threat Actors (TA) used a symbolic link in the FortiGate SSL-VPN /lang/custom directory to…
Account Takeover Vulnerability in Appsmith · Advisory · appsmithorg/appsmith · GitHub
### **Summary**
---
The server uses the `Origin` value from the request headers as the email link `baseUrl` without validation. If an attacker controls the `Origin`, password reset / email ve...
Ghidra bare metal firmware analysis
Reverse engineering firmware binaries often entails going through the datasheet, compiler headers to set up the base address and memory map correctly.
Not To Be Trusted - A Fiasco in Android TEEs
Trusted Execution Environments (TEEs) based on ARM TrustZone form the backbone
of modern Android devices' security architecture. The wor...
Authentication Downgrade Attacks: Deep Dive into MFA Bypass - IOActive
This research introduces two key contributions: first, the weaponization of Cloudflare Workers as a serverless transparent proxy platform that operates on trusted Content Delivery Network (CDN) infrastructure with zero forensic footprint; second, an Authentication Downgrade Attack technique that forces victims to fall back to phishable authentication methods (such as push notifications or OTPs) even when FIDO2 hardware keys are registered.
Fuzzing: From Zero 0-day #2 | Windows Application Fuzzing
1. 개요
Analysis of Missing Authorization Checks in Windows Error Reporting
1. 취약점 개요
Android Reverse Engineering book
@Android Internals Review
ConsentFix (a.k.a. AuthCodeFix): Detecting OAuth2 Authorization Code Phishing
Walkthrough the ConsentFix (a.k.a. AuthCodeFix) attack mechanics, and learn about mitigations and detections strategies.
ATO via Facebook OAuth Due Unsanitized Schema Allows to Steal OAuth Token
Exploiting OAuth flow to Takeover accounts via Login with FB
SDR (Signals Intelligence) for Hackers: Capturing Aircraft Signals – Hackers Arise
Endpoint Evasion Techniques (2020–2025): The Evolution of Attacks Bypassing EDR
This post analyzes the evolution of endpoint evasion techniques from 2020 to 2025. It covers BYOI, BYOVD, DLL hijacking, service tampering, and other sophisticated methods attackers use to bypass EDR and AV. Real-world ransomware cases and vendor impact are discussed, along with defensive insights.
Finding 0-Days with AI: Discovering Real Vulnerabilities in Products
For decades, many bug hunters and security pros have used manual testing, static analysis, and fuzzing to find vulnerabilities. Enter the age of AI. Many are skeptical, but when I look around I see more and more evidence that it's not "going to be" a...
Shaping Shadows: Breaking Down New ShadowSyndicate Methods and Infrastructure
One step closer to understanding the nature of the attacker: is ShadowSyndicate an Initial Access Broker, a ransomware affiliate or an underground hosting provider?
Parse and Parse: MIME Validation Bypass to XSS via Parser Differential
This research is an extension of Content-Type research from BlackFan. More specifically, the response Content-Type tricks. Unfortunately, the multiple Content-Type trick is not clearly explained by BlackFan. Therefore, I’ll explain and demonstrate how a single comma character can cause a parsing difference between the browser and different MIME type parser libraries.
A case study in PDF forensics: The Epstein PDFs – PDF Association
Agent-Based Anti-Jamming Techniques for UAV Communications in...
Unmanned Aerial Vehicle communications are encountering increasingly severe multi-source interference challenges in dynamic adversarial environments, which impose higher demands on their...
AppLocker Rules Abuse
AppLocker was introduced by Microsoft in Windows 7 to enable organizations to define which executables, scripts or installers are allowed to run in their environments. AppLocker can reduce the atta…
Click me if you can, Office social engineering with embedded objects
Securify provides reality checks to lower security risks and build up resilience against threats. Agile Security, Pentesting (scenario-based) and Red Teaming.
Example of Windows Warbird Encryption/Decryption
