Archive

Archive

1481 bookmarks
Custom sorting
One Bool. Six Shells. AMSI’s Design Problem.
One Bool. Six Shells. AMSI’s Design Problem.
A research study into the Anti-Malware Scan Interface (AMSI) combining Ghidra decompilation of amsi.dll, Frida dynamic instrumentation, and live bypass testing with Windows Defender active. Six techniques are documented that achieve full Invoke-Expression bypass and were each confirmed end-to-end with a live reverse shell payload (Nishang Invoke-PowerShellTcp) against a patched Windows 11 host.
·bl4ckarch.github.io·
One Bool. Six Shells. AMSI’s Design Problem.
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) › Searchlight Cyber
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) › Searchlight Cyber
Stay current: Get research alerts for newly disclosed vulnerabilities and exposures Times Are Changing These last few months have been super weird. We've ended up in a situation several times where we have learnt that an exploits life cycle has significantly been reduced due to the introduction of frontier models that are extremely capable at
·slcyber.io·
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) › Searchlight Cyber
Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory - Arctic Wolf
Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory - Arctic Wolf
Arctic Wolf reverse-engineered a recovered CyberStrike Harvester binary and connected it to the broader FortiBleed operator workflow, showing how exposed perimeter credentials can quickly become full internal-network exposure.
·arcticwolf.com·
Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory - Arctic Wolf
Dollar-Quote Bypass: Blind SQL Injection Against PostgreSQL
Dollar-Quote Bypass: Blind SQL Injection Against PostgreSQL
Dollar-quoting to bypass a regex sanitizer, scalar subquery injection through an unquoted column name, and zero-knowledge blind extraction against PostgreSQL PL/pgSQL.
·jrbusiness.github.io·
Dollar-Quote Bypass: Blind SQL Injection Against PostgreSQL
CVE-2026-45502 — Microsoft Exchange Server EWS InstallApp Server-Side Request Forgery
CVE-2026-45502 — Microsoft Exchange Server EWS InstallApp Server-Side Request Forgery
1. Overview A server-side request forgery (SSRF) vulnerability exists in Microsoft Exchange Server’s Exchange Web Services (EWS) InstallApp operation. When an authenticated user submits a ManifestUrl parameter via the InstallApp SOAP request, Exchange downloads the manifest from the supplied URL. The intranet address check that prevents SSRF is gated on the isBposUser flag, which is false for all on-premises Exchange deployments. This means the check is bypassed entirely in non-cloud environments, allowing an authenticated user to force the Exchange server to make HTTP requests to arbitrary internal or external URLs. Microsoft addressed this vulnerability in the June 2026 security update (KB5094139).
·aretiq.ai·
CVE-2026-45502 — Microsoft Exchange Server EWS InstallApp Server-Side Request Forgery
MeshHacks: Exploiting Linksys Intelligent Mesh from the Internet
MeshHacks: Exploiting Linksys Intelligent Mesh from the Internet
In this blog post, we describe multiple vulnerabilities we found in Linksys Wi-Fi routers, especially exploiting the “Intelligent Mesh™” functionality, which can be used to wirelessly link routers to act as a Wi-Fi mesh.
·blog.syss.com·
MeshHacks: Exploiting Linksys Intelligent Mesh from the Internet
CVE-2026-41873: Apache Pony Mail OAuth SSRF + Lua CRLF Smuggling = Unauthenticated Account Takeover
CVE-2026-41873: Apache Pony Mail OAuth SSRF + Lua CRLF Smuggling = Unauthenticated Account Takeover
STAR Labs’ advisory on CVE-2026-41873 in Apache Pony Mail by Li Jiantao and Tevel Sho (disclosed 28 April 2026). Two independent bugs reach the same outcome — full admin takeover — without any authentication. In the modern Foal (Python) build, an attacker-supplied "oauth_token" URL drives a blind SSRF against the local Elasticsearch SQL endpoint, leaking the admin session cookie character-by-character (CVSS 9.1). In the legacy Lua build (now retired, no patch), a single unescaped query parameter in "email.lua" lets the attacker inject CRLF bytes into the Elasticsearch HTTP request and smuggle a second request that creates an admin account outright.
·core-jmp.org·
CVE-2026-41873: Apache Pony Mail OAuth SSRF + Lua CRLF Smuggling = Unauthenticated Account Takeover
THC Tips, Tricks & Hacks Cheat Sheet
THC Tips, Tricks & Hacks Cheat Sheet
A static, single-page web mirror of THC's tips, tricks, and hacks cheat sheet for security research, Linux operations, SSH, networking, and practical command-line workflows.
·tips.hackerschoice.org·
THC Tips, Tricks & Hacks Cheat Sheet
Autonomous fuzzing process under LLM supervision
Autonomous fuzzing process under LLM supervision
The CCN project is co-financed by the European Regional Development Fund and the State Budget under the European Funds for Digital Development Programme 2021-2027. Fuzzing is an automated software testing technique that involves feeding random or deliberately malformed input data to detect bugs and security vulnerabilities. For years it has …
·cert.pl·
Autonomous fuzzing process under LLM supervision
Payload Fragmentation & Dynamic Assembly for AV Evasion
Payload Fragmentation & Dynamic Assembly for AV Evasion
Payload Fragmentation & Dynamic Assembly for AV Evasion Advanced Powershell Obfuscation for Offensive Security The Struggle Is Real Let me paint you a picture. It’s 2 AM. I’ve been fighting …
·medium.com·
Payload Fragmentation & Dynamic Assembly for AV Evasion
How I Discovered 23,000+ Leaked Records Through Google Dorking
How I Discovered 23,000+ Leaked Records Through Google Dorking
How I Discovered 23,000+ Leaked Records Through Google Dorking Hi, I’m mrx_w_ (Adem Ziane Berroudja), a bug bounty hunter on Bugcrowd. You can find me on Twitter and LinkedIn under mrx_w_ .In this …
·medium.com·
How I Discovered 23,000+ Leaked Records Through Google Dorking