CVE-2025-2945 pgAdmin
WriteUP + Video + RCE POC
This post provides a technical explanation of a Remote Code Execution (RCE) vulnerability discovered in pgAdmin (โค9.1), a widely used administration tool for PostgreSQL databases.
WriteUP + Video + RCE POC
Three bypasses of Ubuntu's unprivileged user namespace restrictions
read TXT
read TXT
(advisory is sent to the Ubuntu Security Team on January 15, 2025)
CVE-2025-22457
Ivanti Zero-Day
Ivanti Zero-Day
A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways
New Vulnerability in GitHub Copilot, Cursor: Hackers Can Weaponize Code Agents
๐ฌ comments
๐ธPillar Security researchers discovered a new supply chain attack called "Rules File Backdoor" that compromises AI-generated code by injecting malicious instructions into configuration files used by Cursor and GitHub Copilot. This attack remains virtually invisible to developers and security teams, allowing malicious code to silently propagate through projects.
๐ฌ comments
Do It by Code
@music banned for copyright infringement Update: it's restored now
also, the bot @getSendGiftsbot was blocked overnight.
the bot generated statistics on gifts and collected public information on them (for example, previous owners of a certain gift).
the bot generated statistics on gifts and collected public information on them (for example, previous owners of a certain gift).
Do It by Code
also, the bot @getSendGiftsbot was blocked overnight. the bot generated statistics on gifts and collected public information on them (for example, previous owners of a certain gift).
And also at night, almost all mirrors of the popular Funstat service were blocked.
This service collects information about users (their messages, which groups they are in, as well as their profile history).
This service collects information about users (their messages, which groups they are in, as well as their profile history).
This media is not supported in your browser
VIEW IN TELEGRAM
Google has released the AI function in Sheets.
You can now use AI in your spreadsheets to generate text, analyze sentiment, or summarize and categorize information.
Source
You can now use AI in your spreadsheets to generate text, analyze sentiment, or summarize and categorize information.
Source
4chan is hacked.
here are some details we know about this:
With all these things, 4chan will be down for a few days to clean things up, unless they are quick
here are some details we know about this:
- The source code is leaked. (we don't know what's inside of the source code, so please open it with caution, inside of a vm preferably)
- The source code is compact PHP code.
- we still don't know if the hacker exploited a 0-day vulnerability or not.
- The person behind this, leaked all the moderator's emails as well as the internal moderation board (although only the older stuff, since they moved to discord)
- He said he won't leak the user pass data (weren't they hashed?!?!)
- He said he has cleaned the source code a bit, but there are still some secrets (e.g. environment variables?) left that will need replacement
- He said "he won't be leaking any DB" and that he doesn't want to hurt the actual users blah blah blah, but yeah who knows, he might sell it later or something, we don't know
With all these things, 4chan will be down for a few days to clean things up, unless they are quick
GitHub suffers a cascading supply chain attack compromising CI/CD secrets (one month old btw)
Article, Comments
Article, Comments
InfoWorld
GitHub suffers a cascading supply chain attack compromising CI/CD secrets
CISA confirms cascading attack from reviewdog to tj-actions exposed sensitive credentials across 23,000+ repositories.