AfroSec
605 subscribers
316 photos
22 videos
6 files
161 links
hello friend
am AfroSec | AASTU dropout | cybersecurity enthusiast | CRTOM | CRTA | passionate abt Red Teaming :)))

portifolio : soon....
file : @Afr0Files
Download Telegram
Just a little "yapping time" with a dose of reality ๐Ÿ™ƒ

u know, I sometimes think back to how much I prayed to get to this stage โ€“ to be a uni student, a hacker, all of it. And now that I'm here, I'm honestly not always satisfied. I don't know if that's just human nature or what, but it got me thinking.

Life definitely has its mental breakdowns and tough spells, but even in those moments, we need to remember to be grateful.

I was literally thinking about this in class today. All those prayers in high school, just begging to get into uni. And here I am now: a uni student, a hacker โ€“ even if I'm not gobez temari, and things don't always go exactly as I planned, God always surprises me in amazing ways.

Seriously, I want to thank all of you for being here with me this whole time. I really, truly mean that.

Love you all,
and please don't forget to thank God! ๐Ÿ˜Š

@AfroSec
โค16โคโ€๐Ÿ”ฅ3๐Ÿฅฐ2๐Ÿ’‹2
Forwarded from The Hacker News
๐Ÿšจ A critical CVSS 9.8 flaw in "react-native-community/cli" let anyone run OS commands on your dev machineโ€”no login needed.

Itโ€™s patched now, but millions of React Native devs were exposed for months.

Check your version and lock down that dev server. โ†’ https://thehackernews.com/2025/11/critical-react-native-cli-flaw-exposed.html
โค3โšก1
Forwarded from Kiru
๐Ÿ”’ Security shouldn't slow your Vite dev flow but it does, right? Endless CSP tweaks, vuln hunts, audit fails killing indie MVPs?
Introducing Nalth V2.2: Zero-config security framework forked from Vite. Enterprise armor for JS/TS stacks, auto-HTTPS, real-time dashboard. React/Vue/Svelte? Seamless.
One command: npx create-nalth my-app --template nalth-react
โ€” CSP + headers auto-gen
โ€”Vuln scans & secure installs
โ€” SOC2/GDPR ready, no perf hit
Built for indie hackers shipping safe, devs ditching configs, startups scaling audits. join the fight! Link: https://www.nalthJS.com
Try: https://github.com/nalikiru-dev/nalth.js
๐Ÿ“ฆ NPM: https://www.npmjs.com/package/nalth https://www.npmjs.com/package/create-nalth
๐Ÿ’ฌ Feedback? Reply or DM. What's your biggest sec pain?
#WebDevelopment #JavaScript #Security #ViteJS #IndieHackers
๐Ÿ”ฅ4
would ya ? ๐Ÿ™ƒ๐Ÿ™ƒ

@AfroSec
๐Ÿ˜12๐Ÿค—2
Forwarded from The Hacker News
โšก Hackers turned Windows against itself.

Curly COMrades is using Microsoft's Hyper-V to run small Linux virtual machines inside Windows 10.

This is a sneaky way to get their malware past EDR tools.

Read the whole story โ†“ https://thehackernews.com/2025/11/hackers-weaponize-windows-hyper-v-to.html
๐Ÿ”ฅ2๐Ÿ‘1
#News

Owasp Top 10 Web Vulns 2025 are Out!!

Broken Acess Control is leading the way(SSRF is included in it), Injections are still around in 2025.

#geeztech @geeztechgroup
๐Ÿ‘2๐Ÿ˜Ž2
Forwarded from AASTU CSC (ใ…ค)
๐Ÿ”ฅ Saturday CYberNight is BACK!๐Ÿ”ฅ

Yo fam after a long break, our SaturdayCYber Night sessions are finally making a comeback tomorrow night at 8:30 PM (EAT)๐Ÿ˜Ž

And guess what? Weโ€™re kicking it off *big* this time โ€” with a special guest joining us, a real hacker & red team engineer whoโ€™s been deep in the trenches of offensive security. Expect raw stories, mindset talk, and some serious red team wisdom.

๐Ÿ“ Where: Here on Telegram
๐Ÿ•— When: Saturday, 8:30 PM EAT


Bring your snacks, your curiosity, and your questions โ€” itโ€™s gonna be one of those nights again ๐Ÿ’€
#Cybersecurity #RedTeam #HackerTalk

@AASTU_Cyberclub
๐Ÿ”ฅ4โคโ€๐Ÿ”ฅ2๐Ÿค—1
This media is not supported in your browser
VIEW IN TELEGRAM
kidame new zare hangout enaregalen ๐Ÿ˜‚๐Ÿ˜‚

lool the most azg music fr๐Ÿ˜‚

@Afrosec
๐Ÿคฃ11๐Ÿ˜3
sometimes i think then i forget ughh๐Ÿ˜ญ

@AfroSec
๐Ÿ˜11๐Ÿคฃ2๐Ÿ˜ญ2โค1
ep2
AASTU CSC
recorded session audio
enjoy ๐Ÿ˜Ž

@AASTU_Cyberclub
โšก2โค2๐Ÿณ1
AfroSec
AASTU CSC โ€“ ep2
do u think am a good host or ? eski check it out, cyber night session with ELIEZER (brutal panda) it was soo lit tho ๐Ÿ”ฅ๐Ÿ”ฅ

@AfroSec
๐Ÿ”ฅ5โค1๐Ÿ’ฏ1
was reading a course called control system cuz ur boi has mid exam and was trynna relate it wiz cybersec :)

From Blue Team perspective ๐Ÿ™ƒ
Control: Cybersecurity:
Sensor Measurements โ†โ†’ SIEM Logs/Telemetry
Controller Action โ†โ†’ Security Automation
Setpoint โ†โ†’ Security Policy
Disturbance โ†โ†’ Attack/Threat

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
SECURITY CONTROL LOOP

THREAT โ†’ DETECTION โ†’ RESPONSE โ†’
โ†‘ โ”‚
โ””โ”€โ”€โ”€ FEEDBACK โ†โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

like SOC team isn't just monitoring - it's running a massive feedback control system. Every alert is a sensor reading, every playbook is a control algorithm

@AfroSec
๐Ÿ”ฅ2๐Ÿ‘2๐Ÿ˜ญ1
Forwarded from Brut Security (DarkShadowโœจ ShellSec)
Hey Hunter's,
Darkshadow here back again, dropping a really very interesting Method.

๐Ÿ’€Web cache to RCE!๐Ÿ˜

While i normally visit the web application i noticed, the website actively makes cache file from clint side to store errors.

Now The idea is, if we able to make any custom error then it will be cached, and if any how the error execute on the system we might see the output.

โœ…Exploit to reproduce final RCE:

1. The webapp was sending request from client side in a array based parameter.

2. Change the valid Input to a PHP code using system function. Here we just try to making a error using the invalid input.

3. Now the web application is not able to handle this input and makes error and store in a cache file.

4. After visiting the cache file, The error message reflecting on the cache file.

5. But wait, it's also execute my PHP code and store the command output in the file. Means we can execute OS commands output in cache file via making error. Means RCE!

Follow me for more methods x.com/darkshadow2bd
โšก2๐Ÿ‘1
lately am jst addicted to this song besmeam wtf ๐Ÿ˜ฎโ€๐Ÿ’จ๐Ÿ˜ฎโ€๐Ÿ’จ

@AfroSec
โคโ€๐Ÿ”ฅ3โค1