CVE-2026-21508 - Windows LPE via arbitrary COM object initialization
The vulnerability essentially works by forcing a process running as system and that uses the undocumented function Windows_Storage!_SHCoCreateInstance, to create an arbitrary COM object of our choice. For this to happen the object must be associated with an already registered COM class that supports CLSCTX_INPROC_SERVER. Arbitrary COM object creation is archived by manipulating a CoCreateInstance call first argument
@GoSecurity
#CVE #LPE #DFIR #blueteam
The vulnerability essentially works by forcing a process running as system and that uses the undocumented function Windows_Storage!_SHCoCreateInstance, to create an arbitrary COM object of our choice. For this to happen the object must be associated with an already registered COM class that supports CLSCTX_INPROC_SERVER. Arbitrary COM object creation is archived by manipulating a CoCreateInstance call first argument
@GoSecurity
#CVE #LPE #DFIR #blueteam
A custom Linux beacon for Cobalt Strike
While official Cobalt Strike does not natively support generating Linux beacons, the author says that it is possible to build custom implants for Cobalt Strike on virtually any platform. The only requirement is that the implant communicates correctly with the teamserver
https://github.com/EricEsquivel/CobaltStrike-Linux-Beacon
@GoSecurity
#dfir #blueteam #threathunting #c2 #redteam #cobalt
While official Cobalt Strike does not natively support generating Linux beacons, the author says that it is possible to build custom implants for Cobalt Strike on virtually any platform. The only requirement is that the implant communicates correctly with the teamserver
https://github.com/EricEsquivel/CobaltStrike-Linux-Beacon
@GoSecurity
#dfir #blueteam #threathunting #c2 #redteam #cobalt
GitHub
GitHub - EricEsquivel/CobaltStrike-Linux-Beacon: Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons
Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons - EricEsquivel/CobaltStrike-Linux-Beacon
A comprehensive systems programming toolkit implementing low-level concepts in C, from memory management to OS internals. Features practical implementations of computer architecture concepts with a focus on performance and hardware interaction.
https://github.com/mohitmishra786/BitsAndBytes
@GoSecurity
#C #toolkit #memory
https://github.com/mohitmishra786/BitsAndBytes
@GoSecurity
#C #toolkit #memory
A credential extraction BOF for Veeam Backup and Replication and Veeam One
https://github.com/MWR-CyberSec/VeeamDumper-BOF
@GoSecurity
#BOF
https://github.com/MWR-CyberSec/VeeamDumper-BOF
@GoSecurity
#BOF
GitHub
GitHub - MWR-CyberSec/VeeamDumper-BOF: A credential extraction BOF for Veeam Backup and Replication and Veeam One
A credential extraction BOF for Veeam Backup and Replication and Veeam One - MWR-CyberSec/VeeamDumper-BOF
Forwarded from vx-underground
Hello
I have collected more malware. It's like, ... 200,000 malware, I think. I don't know. I've stopped counting.
It is enough malware for your friends, family, extended family, neighbors, and co-workers.
Please download it. The malware is lonely.
https://vx-underground.org/Updates
I have collected more malware. It's like, ... 200,000 malware, I think. I don't know. I've stopped counting.
It is enough malware for your friends, family, extended family, neighbors, and co-workers.
Please download it. The malware is lonely.
https://vx-underground.org/Updates
ReverseShell with AI behaviour analysis bypass (prompt injection targeting sandbox analysis).
https://github.com/tihanyin/PSSW100AVB/blob/main/ReverseShell_2026_05.ps1
@GoSecurity
https://github.com/tihanyin/PSSW100AVB/blob/main/ReverseShell_2026_05.ps1
@GoSecurity
درود به همه🌹
خواستم بگم خودتونو دست کم نگیرید و خودتونو نبازید، ادامه بدید و مطمئن باشید یه روزی یه اتفاق مثبت میفته و مسیر زندگیتون تغییر خواهد کرد.
الان در برههایی از تاریخ هستیم که تقریبا یادگیری و آموزش به حداقلترین حالت خودش رسیده، سعی کنید خودتونو اپدیت نگه دارید و چیزای جدید یادبگیرید.
ارادت❤️
خواستم بگم خودتونو دست کم نگیرید و خودتونو نبازید، ادامه بدید و مطمئن باشید یه روزی یه اتفاق مثبت میفته و مسیر زندگیتون تغییر خواهد کرد.
الان در برههایی از تاریخ هستیم که تقریبا یادگیری و آموزش به حداقلترین حالت خودش رسیده، سعی کنید خودتونو اپدیت نگه دارید و چیزای جدید یادبگیرید.
ارادت❤️
Orange Tsai (https://x.com/orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange
https://x.com/thezdi/status/2055281643984683475?s=46
#Pwn20wn #Tournament #zdi
@GoSecurity
https://x.com/thezdi/status/2055281643984683475?s=46
#Pwn20wn #Tournament #zdi
@GoSecurity
اطلاعاتی راجب بدافزار FAST 16 که برای آسیب زدن به برنامه هستهایی ایران ساخته شده رو میتونید از توییتر آقای حمید کشفی بخونید.
https://x.com/hkashfi/status/2055756694387335420?s=46
#fast16 #malware #iran
@GoSecurity
https://x.com/hkashfi/status/2055756694387335420?s=46
#fast16 #malware #iran
@GoSecurity
X (formerly Twitter)
Hamid Kashfi (@hkashfi) on X
شرکت Symantec گزارش تکمیلی خودش رو در مورد بدافزار پیشرفته که اخیرا و تحت عنوان Fast16 بصورت عمومی منتشر شده، ارایه کرده.
در این گزارش عنوان شده که بر اساس شواهد فنی، احتمال قریب به یقین هدف اصلی این بدافزار دستکاری محاسبات شبیه سازی انفجار اورانیوم، و برنامه…
در این گزارش عنوان شده که بر اساس شواهد فنی، احتمال قریب به یقین هدف اصلی این بدافزار دستکاری محاسبات شبیه سازی انفجار اورانیوم، و برنامه…
Understanding Integer Overflow in Windows Kernel Exploitation
https://whiteknightlabs.com/2025/05/27/understanding-integer-overflow-in-windows-kernel-exploitation/
@GoSecurity
#windows #kernel #exploit
https://whiteknightlabs.com/2025/05/27/understanding-integer-overflow-in-windows-kernel-exploitation/
@GoSecurity
#windows #kernel #exploit
White Knight Labs
Understanding Integer Overflow in Windows Kernel Exploitation | White Knight Labs
In this blog post, we will explore integer overflows in Windows kernel drivers and cover how arithmetic operations can lead to security vulnerabilities. We
leaker is a leak discovery tool that returns valid credential leaks using passive online sources. It supports searching by email, username, domain, keyword, and phone number.
https://github.com/vflame6/leaker
@GoSecurity
#Osint #Leaker #Recon
https://github.com/vflame6/leaker
@GoSecurity
#Osint #Leaker #Recon
GitHub
GitHub - vflame6/leaker: Passive leak enumeration tool.
Passive leak enumeration tool. Contribute to vflame6/leaker development by creating an account on GitHub.
This media is not supported in your browser
VIEW IN TELEGRAM
Whats the best piece of advice you've ever received?
New banking malware campaigns are targeting both Windows and Android users.
Researchers uncovered updated versions of the Grandoreiro banking trojan and the BTMOB Android RAT, capable of stealing banking credentials, abusing Accessibility services, keylogging, and remotely controlling infected devices.
The malware spreads through phishing emails, fake apps, and DLL side-loading techniques, showing how financial cyberattacks are becoming more automated and cross-platform.
Read more:
https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html
@GoSecurity
#Malware #AndroidSecurity #WindowsSecurity #BankingTrojan #InfoSec
Researchers uncovered updated versions of the Grandoreiro banking trojan and the BTMOB Android RAT, capable of stealing banking credentials, abusing Accessibility services, keylogging, and remotely controlling infected devices.
The malware spreads through phishing emails, fake apps, and DLL side-loading techniques, showing how financial cyberattacks are becoming more automated and cross-platform.
Read more:
https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html
@GoSecurity
#Malware #AndroidSecurity #WindowsSecurity #BankingTrojan #InfoSec
Successful backups don’t always mean safe ransomware recovery.
Security experts warn that restoring infected backups can bring malware back into the network. The report recommends testing recovery in isolated environments and validating backups before restoration.
Read more:
https://thehackernews.com/expert-insights/2026/05/how-to-test-ransomware-recovery-without.html
@GoSecurity
#Ransomware #BackupSecurity #DataRecovery #InfoSec
Security experts warn that restoring infected backups can bring malware back into the network. The report recommends testing recovery in isolated environments and validating backups before restoration.
Read more:
https://thehackernews.com/expert-insights/2026/05/how-to-test-ransomware-recovery-without.html
@GoSecurity
#Ransomware #BackupSecurity #DataRecovery #InfoSec