Forwarded from exploit.org
SECURITY ALERT ⚠️
Possible RCE was detected in Telegram's media processing in Telegram Desktop application.
This issue expose users to malicious attacks through specially crafted media files, such as images or videos.
For security reasons disable auto-download feature. Please follow these steps:
1. Go to Settings.
2. Tap on "Advanced".
3. Under the "Automatic Media Download" section, disable auto-download for "Photos", "Videos", and "Files" across all chat types (Private chats, groups, and channels).
We are currently investigating this vulnerability.
Possible RCE was detected in Telegram's media processing in Telegram Desktop application.
This issue expose users to malicious attacks through specially crafted media files, such as images or videos.
For security reasons disable auto-download feature. Please follow these steps:
1. Go to Settings.
2. Tap on "Advanced".
3. Under the "Automatic Media Download" section, disable auto-download for "Photos", "Videos", and "Files" across all chat types (Private chats, groups, and channels).
We are currently investigating this vulnerability.
I ported THOUSANDS of apps to Windows 95
https://www.youtube.com/watch?v=CTUMNtKQLl8
Backport of .NET 2.0 - 3.5 to Windows 9x
GitHub Repo
https://www.youtube.com/watch?v=CTUMNtKQLl8
Backport of .NET 2.0 - 3.5 to Windows 9x
GitHub Repo
YouTube
I ported THOUSANDS of apps to Windows 95
▶VOTE for my NEXT PROJECT: https://www.patreon.com/posts/march-2024-poll-101363953
▶dotnet9x on GitHub: https://github.com/itsmattkc/dotnet9x
▶FOLLOW on Twitter: https://twitter.com/itsmattkc
▶FOLLOW on Twitch: https://twitch.tv/mattkclive
▶FOLLOW on…
▶dotnet9x on GitHub: https://github.com/itsmattkc/dotnet9x
▶FOLLOW on Twitter: https://twitter.com/itsmattkc
▶FOLLOW on Twitch: https://twitch.tv/mattkclive
▶FOLLOW on…
⚠ PuTTY CVE-2024-31497
📰Brief: attacker can gain access to private key with public key and some signed messages on hand via forged identification signature of legitimate user. Signed messages may be publicly visible due to storage in public Git.
🚩Possibilities: login into any servers key was used in, supply chain attacks software maintained git, etc.
📗Affected versions: 0.80 and prior.
📚Full description: https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html
📰Brief: attacker can gain access to private key with public key and some signed messages on hand via forged identification signature of legitimate user. Signed messages may be publicly visible due to storage in public Git.
🚩Possibilities: login into any servers key was used in, supply chain attacks software maintained git, etc.
📗Affected versions: 0.80 and prior.
📚Full description: https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html
Awhile back we heard rumors of a Telegram RCE 0day. We brushed it off as silly memes. Turns out the 0day was 100% real and you're all probably pwned.
It was unveiled on XSS. Nerds celebrated
(joking about pwned part... kind of)
More information: https://www.bleepingcomputer.com/news/security/telegram-fixes-windows-app-zero-day-used-to-launch-python-scripts/
It was unveiled on XSS. Nerds celebrated
(joking about pwned part... kind of)
More information: https://www.bleepingcomputer.com/news/security/telegram-fixes-windows-app-zero-day-used-to-launch-python-scripts/
BleepingComputer
Telegram fixes Windows app zero-day used to launch Python scripts
Telegram fixed a zero-day vulnerability in its Windows desktop application that could be used to bypass security warnings and automatically launch Python scripts.
On 17th April, a group named 66slavs claimed to have breached the United States National Energy Research Scientific Computing Center (NERSC).
* We have not reviewed the data
* Yes, they watermarked a data breach
* We have not reviewed the data
* Yes, they watermarked a data breach
13-year-old Marco Liberale has created a proof-of-concept PasteBin C2 botnet in Go. It is fully cross platform working on Windows, Linux, and Mac.
We are very happy to see such a young person contributing to this research space.
Check it out here: https://github.com/marco-liberale/PasteBomb
We are very happy to see such a young person contributing to this research space.
Check it out here: https://github.com/marco-liberale/PasteBomb
GitHub
GitHub - marco-liberale/PasteBomb: PasteBomb C2-less RAT
PasteBomb C2-less RAT. Contribute to marco-liberale/PasteBomb development by creating an account on GitHub.
Ask HN: High quality Python scripts or small libraries to learn from
Article, Comments
https://www.dabeaz.com/tutorials.html
https://docs.astral.sh/ruff/
https://docs.astral.sh/ruff/rules/future-rewritable-type-annotation/#flake8-executable-exe
https://github.com/simonw/datasette
https://github.com/simonw/sqlite-utils
Article, Comments
https://www.dabeaz.com/tutorials.html
https://docs.astral.sh/ruff/
https://docs.astral.sh/ruff/rules/future-rewritable-type-annotation/#flake8-executable-exe
https://github.com/simonw/datasette
https://github.com/simonw/sqlite-utils
The Microsoft Fabric community (?) forum is old and allows unchecked HTML on posts.
- Link attached, don't click the silly button
- Thanks to rari_teh for sharing this with us
Behold:
https://ideas.fabric.microsoft.com/ideas/idea/?ideaid=908a0c5d-95fe-ee11-a73c-000d3ae45d44
mklink link:
- Link attached, don't click the silly button
- Thanks to rari_teh for sharing this with us
Behold:
https://ideas.fabric.microsoft.com/ideas/idea/?ideaid=908a0c5d-95fe-ee11-a73c-000d3ae45d44
mklink link:
mklink /D UE_5.4 "C:\Program Files\Epic Games\Unreal\UE_5.4"