SSD Advisory – Chrome Turbofan Remote Code Execution – SecuriTeam Blogs
The Tale of SettingContent-ms Files – Posts By SpecterOps Team Members
As an attacker, initial access can prove to be quite the challenge against a hardened target. When selecting a payload for initial access…
Pentester's Windows NTFS Tricks Collection | SEC Consult
In this blog post René Freingruber (@ReneFreingruber) from the SEC Consult Vulnerability Lab shares different filesystem tricks which were collected over the
Vulnerability Discovery Against Apple Safari | Ret2 Systems Blog
Vulnerability discovery is the first stage of the exploit development lifecycle. The duration of this phase is open-ended because the search space, code qual...
XSS in Google Colaboratory workaround Content-Security-Policy
[messaging] Modern anti-spam and E2E crypto
I discovered a browser bug - JakeArchibald.com
I accidentally discovered a huge browser security bug. Here's what it does, and how I discovered it…
Unrestricted File Upload at Apple.com / Хабр
Внимание — это фривольный перевод заметки о том, как именно Jonathan Bouman нашёл публичный AWS S3, который использовался на одном из поддоменнов apple.com.
Exploiting Electron RCE in Exodus wallet – Hacker Noon
While browsing Twitter I’ve noticed ElectronJS remote code execution vulnerability in protocol handler. That sounds severe. As stated in…
Take Advantage of Out-of-Scope Domains in Bug Bounty Programs • Abdullah Hu
Last year, I got an invitation from a private bug bounty program on HackerOne platform. I said let’s give it a try since I had some free time and here is the...
G.-Geshev-and-Rob-Miller-Chainspotting.pdf
