Archive

Archive

1481 bookmarks
Custom sorting
Klopatra: exposing a new Android banking trojan operation with roots in Turkey | Cleafy LABS
Klopatra: exposing a new Android banking trojan operation with roots in Turkey | Cleafy LABS
In late August 2025, Cleafy's Threat Intelligence team discovered Klopatra, a new, highly sophisticated Android malware currently targeting banking users primarily in Spain and Italy. The number of compromised devices has already exceeded 1,000. Read the report to learn more.
·cleafy.com·
Klopatra: exposing a new Android banking trojan operation with roots in Turkey | Cleafy LABS
CVE-2025-59489: Arbitrary Code Execution in Unity Runtime
CVE-2025-59489: Arbitrary Code Execution in Unity Runtime
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. In May 2025, I participated in the Meta Bug Bounty Researcher Conference 2025. During this event, I discovered a vulnerability (CVE-2025-59489) in the Unity Runtime that affects games and applications built on Unity 2017.1 and later. In this article, I will explain the technical aspects of this vulnerability and its impact. This vulnerability was disclosed to Unity following responsible disclosure practices. Unity has since released patches for Unity 2019.1 and later, as well as a Unity Binary Patch tool to address the issue, and I strongly encourage developers to download the updated versions of Unity, recompile affected games or applications, and republish as soon as possible.
·flatt.tech·
CVE-2025-59489: Arbitrary Code Execution in Unity Runtime
BYOVD to the next level (part 1) — exploiting a vulnerable driver (CVE-2025-8061) - Quarkslab's blog
BYOVD to the next level (part 1) — exploiting a vulnerable driver (CVE-2025-8061) - Quarkslab's blog
Bring Your Own Vulnerable Driver (BYOVD) is a well-known post-exploitation technique used by adversaries. This blog post is part of a series. We will see how to abuse a vulnerable driver to gain access to Ring-0 capabilities. In this first post we describe in detail the exploitation of vulnerabilities found in a signed Lenovo driver on Windows.
·blog.quarkslab.com·
BYOVD to the next level (part 1) — exploiting a vulnerable driver (CVE-2025-8061) - Quarkslab's blog
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
In June, 2025, Shubs Shah and I discovered a vulnerability in the online poker website ClubWPT Gold which would have allowed an attacker to fully access the core back office application that is used for all administrative site functionality.
·samcurry.net·
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
Roaring Access: Exploiting a Pre-Auth Root RCE on Sixnet RTUs | Claroty
Roaring Access: Exploiting a Pre-Auth Root RCE on Sixnet RTUs | Claroty
Team82 is publishing some details on two serious vulnerabilities in two Red Lion Sixnet remote terminal unit (RTU) products, and in the Sixnet Universal protocol. Both of the vulnerabilities were assessed a CVSS v3 score of 10.0, and users are urged to apply patches provided by Red Lion.
·claroty.com·
Roaring Access: Exploiting a Pre-Auth Root RCE on Sixnet RTUs | Claroty
The Whole App is a Blob
The Whole App is a Blob
I tried to prepare for life in French-speaking Canada by turning language drills into a Tamagotchi. It worked, as long as you don't ask me whether my coffee is for here or to go.
·drobinin.com·
The Whole App is a Blob
Racing and Fuzzing HTTP/3: Open-sourcing QuicDraw(H3)
Racing and Fuzzing HTTP/3: Open-sourcing QuicDraw(H3)
This blog post provides a dive into HTTP/3’s evolution for security engineers, an overview of our research journey, and what led us to develop the open-source tool QuicDraw, which can be used for...
·cyberark.com·
Racing and Fuzzing HTTP/3: Open-sourcing QuicDraw(H3)
How to Research & Reverse Web Vulnerabilities 101 — ProjectDiscovery Blog
How to Research & Reverse Web Vulnerabilities 101 — ProjectDiscovery Blog
Introduction This blog serves as a detailed methodology guide for analyzing, reversing, and researching web vulnerabilities, particularly those with CVEs assigned. The content outlines repeatable processes used to evaluate vague advisories, analyze vulnerable software, and ultimately recreate or validate security flaws. The objective is to establish a structured, replicable approach to web vulnerability research. Environment & Tools When approaching a new target for CVE research or reverse-e
·projectdiscovery.io·
How to Research & Reverse Web Vulnerabilities 101 — ProjectDiscovery Blog