Network Espionage – Using Russian Cameras as Proxies, Part 2 – Hackers Arise
ATO via Facebook OAuth Due Unsanitized Schema Allows to Steal OAuth Token
Exploiting OAuth flow to Takeover accounts via Login with FB
Hacking Next.js Targets: Advanced SSRF Exploitation Guide
Learn how to identify and hunt for SSRF vulnerabilities in Next.js targets using different testing methods. Read the article now!
Finding More IDORs – Tips and Tricks
Klopatra: exposing a new Android banking trojan operation with roots in Turkey | Cleafy LABS
In late August 2025, Cleafy's Threat Intelligence team discovered Klopatra, a new, highly sophisticated Android malware currently targeting banking users primarily in Spain and Italy. The number of compromised devices has already exceeded 1,000. Read the report to learn more.
CVE-2025-59489: Arbitrary Code Execution in Unity Runtime
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc.
In May 2025, I participated in the Meta Bug Bounty Researcher Conference 2025. During this event, I discovered a vulnerability (CVE-2025-59489) in the Unity Runtime that affects games and applications built on Unity 2017.1 and later.
In this article, I will explain the technical aspects of this vulnerability and its impact.
This vulnerability was disclosed to Unity following responsible disclosure practices.
Unity has since released patches for Unity 2019.1 and later, as well as a Unity Binary Patch tool to address the issue, and I strongly encourage developers to download the updated versions of Unity, recompile affected games or applications, and republish as soon as possible.
Code Vulnerabilities Put Proton Mails at Risk
The Sonar Research team discovered critical code vulnerabilities in Proton Mail, Skiff and Tutanota. This post covers the technical details of the XSS vulnerability in Proton Mail.
Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign
Threat actors behind the gift card fraud campaign Jingle Thief target retail via phishing and smishing, maintaining long-term access in cloud environments.
BYOVD to the next level (part 1) — exploiting a vulnerable driver (CVE-2025-8061) - Quarkslab's blog
Bring Your Own Vulnerable Driver (BYOVD) is a well-known post-exploitation technique used by adversaries. This blog post is part of a series. We will see how to abuse a vulnerable driver to gain access to Ring-0 capabilities. In this first post we describe in detail the exploitation of vulnerabilities found in a signed Lenovo driver on Windows.
Text Rendering Hates You - Faultlore
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
In June, 2025, Shubs Shah and I discovered a vulnerability in the online poker website ClubWPT Gold which would have allowed an attacker to fully access the core back office application that is used for all administrative site functionality.
Roaring Access: Exploiting a Pre-Auth Root RCE on Sixnet RTUs | Claroty
Team82 is publishing some details on two serious vulnerabilities in two Red Lion Sixnet remote terminal unit (RTU) products, and in the Sixnet Universal protocol. Both of the vulnerabilities were assessed a CVSS v3 score of 10.0, and users are urged to apply patches provided by Red Lion.
DOM XSS: Bypassing Server-side Cookie Overwrite, Chrome innerHTML Quirk, and JSON Injection
Hi everyone in this post I walk through three DOM-XSS findings I discovered while hunting on a bug-bounty program: a cookie-scoped bypass of server cookie overwrites, a Chrome innerHTML quirk, and …
Decrement by one to rule them all: AsIO3.sys driver exploitation
Cisco Talos uncovered and analyzed two critical vulnerabilities in ASUS' AsIO3.sys driver, highlighting serious security risks and the importance of robust driver design.
Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks
InsertScript
MacOS hacking part 9: shellcode injection via task_for_pid - thread hijacking. Simple C (Intel) example
﷽
Laravel: APP_KEY leakage analysis
Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154)
Learn about CVE-2025-50154 and its risk of NTLM attacks and RCE even after Microsoft’s fix for CVE-2025-24054.
Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed
An analysis of the Gentlemen ransomware group, which employs advanced, adaptive tactics, techniques, and procedure to target critical industries worldwide.
ClickFix Gets Creative: Malware Buried in Images | Huntress
Huntress uncovered an attack utilizing a ClickFix lure to initiate a multi-stage malware execution chain. This analysis reveals how threat actors use steganography to conceal infostealers like LummaC2 and Rhadamanthys within seemingly harmless PNGs.
Stopping redirects
Google Cloud Shell Container Escape
Step-by-step container escape from a privileged Docker environment using Linux kernel features, Kubernetes insights, and real exploitation techniques.
The Whole App is a Blob
I tried to prepare for life in French-speaking Canada by turning language drills into a Tamagotchi. It worked, as long as you don't ask me whether my coffee is for here or to go.
Phishing Campaigns "I Paid Twice" Targeting Booking.com Hotels and Customers
Sekoia.io exposes a Booking.com phishing campaign targeting hotels and customers using ClickFix and PureRAT malware.
Racing and Fuzzing HTTP/3: Open-sourcing QuicDraw(H3)
This blog post provides a dive into HTTP/3’s evolution for security engineers, an overview of our research journey, and what led us to develop the open-source tool QuicDraw, which can be used for...
Slack disclosed on HackerOne: TURN server allows TCP and UDP...
TURN server allowed proxying of TCP connections and UDP packets to internal Slack network and meta-data services on AWS.
How to Research & Reverse Web Vulnerabilities 101 — ProjectDiscovery Blog
Introduction
This blog serves as a detailed methodology guide for analyzing, reversing, and researching web vulnerabilities, particularly those with CVEs assigned. The content outlines repeatable processes used to evaluate vague advisories, analyze vulnerable software, and ultimately recreate or validate security flaws. The objective is to establish a structured, replicable approach to web vulnerability research.
Environment & Tools
When approaching a new target for CVE research or reverse-e
AWS penetration testing: A step-by-step guide
Looking to learn AWS penetration testing? Here are essential AWS pentesting techniques and tools to help you get started!
Exploiting A Pre-Auth RCE in W3 Total Cache For WordPress (CVE-2025-9501) | RCE Security
