Archive

Archive

1481 bookmarks
Custom sorting
Datr cookie theft and AI leads to Facebook account takeover via trusted device recovery
Datr cookie theft and AI leads to Facebook account takeover via trusted device recovery
Introduction Facebook relies on long-lived device identifiers to reduce friction for returning users and to distinguish legitimate activity from suspicious logins. Over time, devices that repeatedly authenticate to the same account are treated as trusted, allowing Facebook to relax certain security requirements during sensitive flows such as account recovery.
·ysamm.com·
Datr cookie theft and AI leads to Facebook account takeover via trusted device recovery
How I Exposed Instagram's Private Posts by Blocking Users
How I Exposed Instagram's Private Posts by Blocking Users
Discover how a security loophole in Instagram's oEmbed feature enabled unauthorized access to private posts. Journey from BountyCon(Edu) to the vulnerability's discovery, exploitation, and resolution.
·003random.com·
How I Exposed Instagram's Private Posts by Blocking Users
Trust Me, I’m a Shortcut
Trust Me, I’m a Shortcut
Windows’ primary mechanism for shortcuts, LNK files, is frequently abused by threat actors for payload delivery and persistence. This blog post introduces several new LNK file flaws that, amongst other things, allow attackers to fully spoof an LNK’s target. It also introduces lnk-it-up, a tool suite that can generate such deceptive LNK files, as well as detect anomalous ones.
·wietzebeukema.nl·
Trust Me, I’m a Shortcut
Carbonara: The MediaTek exploit nobody served
Carbonara: The MediaTek exploit nobody served
Imagine this: You walk into a restaurant you only just discovered, the one rumored for serving the best dishes. It quickly becomes your go-to place for every meal. One day, something odd happens: a secret dish appears on the menu, Carbonara, no price, description, and most importantly, no way to order it. Only few people know the secret code that makes the chef cook it.
·itssho.my·
Carbonara: The MediaTek exploit nobody served
Authentication Downgrade Attacks: Deep Dive into MFA Bypass - IOActive
Authentication Downgrade Attacks: Deep Dive into MFA Bypass - IOActive
This research introduces two key contributions: first, the weaponization of Cloudflare Workers as a serverless transparent proxy platform that operates on trusted Content Delivery Network (CDN) infrastructure with zero forensic footprint; second, an Authentication Downgrade Attack technique that forces victims to fall back to phishable authentication methods (such as push notifications or OTPs) even when FIDO2 hardware keys are registered.
·ioactive.com·
Authentication Downgrade Attacks: Deep Dive into MFA Bypass - IOActive
Endpoint Evasion Techniques (2020–2025): The Evolution of Attacks Bypassing EDR
Endpoint Evasion Techniques (2020–2025): The Evolution of Attacks Bypassing EDR
This post analyzes the evolution of endpoint evasion techniques from 2020 to 2025. It covers BYOI, BYOVD, DLL hijacking, service tampering, and other sophisticated methods attackers use to bypass EDR and AV. Real-world ransomware cases and vendor impact are discussed, along with defensive insights.
·windshock.github.io·
Endpoint Evasion Techniques (2020–2025): The Evolution of Attacks Bypassing EDR
Finding 0-Days with AI: Discovering Real Vulnerabilities in Products
Finding 0-Days with AI: Discovering Real Vulnerabilities in Products
For decades, many bug hunters and security pros have used manual testing, static analysis, and fuzzing to find vulnerabilities. Enter the age of AI. Many are skeptical, but when I look around I see more and more evidence that it's not "going to be" a...
·aivr.hashnode.dev·
Finding 0-Days with AI: Discovering Real Vulnerabilities in Products
Parse and Parse: MIME Validation Bypass to XSS via Parser Differential
Parse and Parse: MIME Validation Bypass to XSS via Parser Differential
This research is an extension of Content-Type research from BlackFan. More specifically, the response Content-Type tricks. Unfortunately, the multiple Content-Type trick is not clearly explained by BlackFan. Therefore, I’ll explain and demonstrate how a single comma character can cause a parsing difference between the browser and different MIME type parser libraries.
·lab.ctbb.show·
Parse and Parse: MIME Validation Bypass to XSS via Parser Differential
AppLocker Rules Abuse
AppLocker Rules Abuse
AppLocker was introduced by Microsoft in Windows 7 to enable organizations to define which executables, scripts or installers are allowed to run in their environments. AppLocker can reduce the atta…
·ipurple.team·
AppLocker Rules Abuse