This media is not supported in your browser
VIEW IN TELEGRAM
1. Malware Analysis Toolkit for static and dynamic analysis Windows PE files
2. kramer_decryptor - Decrypt/deobfuscate compiled python scripts which have been encrypted/obfuscated by Kramer
3. Qu1cksc0pe - All-in-One malware analysis tool
#exploit #malware #toolkit
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
2. kramer_decryptor - Decrypt/deobfuscate compiled python scripts which have been encrypted/obfuscated by Kramer
3. Qu1cksc0pe - All-in-One malware analysis tool
#exploit #malware #toolkit
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
π2
1. CVE-2023-5717:
Linux Kernel Perf OOB write
https://u1f383.github.io/linux/2024/11/17/linux-kernel-perf-cve-2023-5717-quick-analysis.html
2. CVE-2023-32428:
macOS LPE via Malloc Stack Logging
https://gergelykalman.com/badmalloc-CVE-2023-32428-a-macos-lpe.html
]-> PoC
3. CVE-2024-44175:
macOS diskarbitrationd Symlink Validation (TOCTOU LPE)
https://hackyboiz.github.io/2024/11/27/clalxk/CVE-2024-44175
#exploit #CVE #Pentest
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
Linux Kernel Perf OOB write
https://u1f383.github.io/linux/2024/11/17/linux-kernel-perf-cve-2023-5717-quick-analysis.html
2. CVE-2023-32428:
macOS LPE via Malloc Stack Logging
https://gergelykalman.com/badmalloc-CVE-2023-32428-a-macos-lpe.html
]-> PoC
3. CVE-2024-44175:
macOS diskarbitrationd Symlink Validation (TOCTOU LPE)
https://hackyboiz.github.io/2024/11/27/clalxk/CVE-2024-44175
#exploit #CVE #Pentest
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
ComboDump.txt
414.5 KB
|Β€| New Post : Cβmbo list
|Β€| Line : 11K
|Β€| Type : Email | Password
|Β€| Country & Domain : Mix
#combo #crack #data #dump
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
|Β€| Line : 11K
|Β€| Type : Email | Password
|Β€| Country & Domain : Mix
#combo #crack #data #dump
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
β³Crafting Case-Style Target-Specific Wordlists
β’ You can use the following tool called wl to create your target-specific wordlist:
#infosec #cybersecurity #bugbounty #pentest #bugbountyTips #Wordlist #recon
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
Most developers stick to a consistent naming pattern for their endpoints, app routes, and parameters. When crafting a custom wordlist, ensure that the keywords match your target's naming convention.
β’ You can use the following tool called wl to create your target-specific wordlist:
go install -v github.com/s0md3v/wl/cmd/wl@latest
#infosec #cybersecurity #bugbounty #pentest #bugbountyTips #Wordlist #recon
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
π1
β³OSEP - PEN-300 Collection to Help You on Your Exam.
β’ OSEP_Reference
β’ OSEP_Checklist
β’ OSEP_Payloads
β’ OSEP_Bypass_Defender
β’ OSEP_Lateral_Movement
β’ OSEP_MSSQL
#BugBounty #CyberSecurity #Infosec #OSEP
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
β’ OSEP_Reference
β’ OSEP_Checklist
β’ OSEP_Payloads
β’ OSEP_Bypass_Defender
β’ OSEP_Lateral_Movement
β’ OSEP_MSSQL
#BugBounty #CyberSecurity #Infosec #OSEP
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
π₯1
π¨ CVE-2025-43929
π£ CVSS Score: 4.1 (MEDIUM)
π‘ Remotely Exploitable: False
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
https://cvefeed.io/vuln/detail/CVE-2025-43929
#bugBounty #CVE #Exploit
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
π£ CVSS Score: 4.1 (MEDIUM)
π‘ Remotely Exploitable: False
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
https://cvefeed.io/vuln/detail/CVE-2025-43929
#bugBounty #CVE #Exploit
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
Attacking Oracle with the Metasploit Framework.pdf
673.8 KB
π Attacking Oracle with the Metasploit Framework
#metasploit #oracle #attack #hacking
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
#metasploit #oracle #attack #hacking
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
π1
46k Usa.txt
1.4 MB
|Β€| New Post : Cβmbo Access
|Β€| Line : 46K
|Β€| Type : Email : Password
|Β€| Country : USA
|Β€| Domain : Mix
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
|Β€| Line : 46K
|Β€| Type : Email : Password
|Β€| Country : USA
|Β€| Domain : Mix
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
π1
π Bypassing UAC via Intel ShaderCache Directory
=> https://g3tsyst3m.github.io/uac%20bypass/Bypass-UAC-via-Intel-ShaderCache/
#bypassing #UAC
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
=> https://g3tsyst3m.github.io/uac%20bypass/Bypass-UAC-via-Intel-ShaderCache/
#bypassing #UAC
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
Media is too big
VIEW IN TELEGRAM
π Cybersecurity Roadmap 2025 | From Beginner to Advanced
Motasem Hamdan | Cyber Security & Tech
#RoadMap #Cybersecurity #Security
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
Motasem Hamdan | Cyber Security & Tech
#RoadMap #Cybersecurity #Security
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
C0mb0.txt
65.7 KB
|Β€| New Post : C0mb* list
|Β€| Line : 1782
|Β€| Type : Email : Password
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
|Β€| Line : 1782
|Β€| Type : Email : Password
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
β€2π1
Media is too big
VIEW IN TELEGRAM
π How to Hack Android in Kali Linux Full Course
#android #kali_linux #course #hack
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
#android #kali_linux #course #hack
- - - - - - - - - - -
πΉ @Old_Unclee
πΈ @PandoraCoreLab
[ EmbedPayloadInPng ]
β’ Embed a payload within a PNG file by splitting the payload across multiple IDAT sections. Each section is encrypted individually using its own 16-byte key with the RC4 encryption algorithm.
> https://github.com/Maldev-Academy/EmbedPayloadInPng
#Payload #RC4
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
β’ Embed a payload within a PNG file by splitting the payload across multiple IDAT sections. Each section is encrypted individually using its own 16-byte key with the RC4 encryption algorithm.
> https://github.com/Maldev-Academy/EmbedPayloadInPng
#Payload #RC4
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
[ Bad Sector Labs badsectorlabs ]
π’ Cobalt Strike for free!? Adaptix C2 hacker_ralf is the best open source C2 I've used since Havoc C5pider. SOCKS5, remote and local port forwards, and BOF support! Now it's easy to install the server + client, especially on πLudus with our new role:
π [ github ]
π₯ [ tweet ]
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
π’ Cobalt Strike for free!? Adaptix C2 hacker_ralf is the best open source C2 I've used since Havoc C5pider. SOCKS5, remote and local port forwards, and BOF support! Now it's easy to install the server + client, especially on πLudus with our new role:
π [ github ]
π₯ [ tweet ]
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
π₯3
IssueGuard_Secret_Leak_Prevention_Tool.pdf
1.2 MB
#SCA
#tools
#DevOps
"IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports", Feb. 2026.
]-> Repo/Tool
// IssueGuard - tool for real-time detection and prevention of secret leaks in issue reports. IssueGuard analyzes text as users type and combines regex-based candidate extraction with a fine-tuned CodeBERT model for contextual classification. IssueGuard integrates into the web interface and continuously analyzes the issue editor, presenting clear visual warnings to help users avoid submitting sensitive data
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
#tools
#DevOps
"IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports", Feb. 2026.
]-> Repo/Tool
// IssueGuard - tool for real-time detection and prevention of secret leaks in issue reports. IssueGuard analyzes text as users type and combines regex-based candidate extraction with a fine-tuned CodeBERT model for contextual classification. IssueGuard integrates into the web interface and continuously analyzes the issue editor, presenting clear visual warnings to help users avoid submitting sensitive data
- - - - - - - - - - -
πΉ @ZenithGhost
πΈ @PandoraCoreLab
π° Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies andβ¦
β€1
π° CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9. 4.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-19478
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9. 4.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-19478
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in . github/workflows/jiraissue.
π [Source](https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets0330881554.html)
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in . github/workflows/jiraissue.
π [Source](https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets0330881554.html)
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab