Brut Security
17.6K subscribers
1.13K photos
98 videos
360 files
1.23K links
βœ…DM: @wtf_brut
βœ…For Ad: https://tlmtr.io/p/2flAsc
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Rancher, 9.4 Rating πŸ”₯

An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/dtxM5
πŸ‘‰ Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"

Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
❀7
/etc/passwd ==> WAF restriction? Use these:

/e?c/?asswd
/e*c/*asswd
/??c/?asswd
/??c/?assw?

Doesn't work always, just give it a try. 🎯
#bugbountytip #bugbountytips #bugbounty
❀16πŸ‘Ž3
This media is not supported in your browser
VIEW IN TELEGRAM
🚨SploitScan - A sophisticated #cybersecurity utility designed to provide detailed information on vulnerabilities and associated proof-of-concept (PoC) exploits.
βœ…https://github.com/xaitax/SploitScan

#pentesting #redteam #bugbounty
Please open Telegram to view this post
VIEW IN TELEGRAM
❀5πŸ‘2
A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists, and a local VM practice lab. Built for disciplined, ethical hunting.

https://github.com/DevCop95/bugbounty-lab101
❀7πŸ‘3πŸ₯°1
🚨 Critical pre-auth RCE in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771)

Critical Vulnerability Alert!
Citrix NetScaler ADC and NetScaler Gateway is affected by CVE-2026-88771.

πŸ” Identify Targets via ZoomEye:

Search Dork: app="Citrix NetScaler"
Exposure: 239.2k instances identified globally.

ZoomEye Search Link:
πŸ‘‰ https://www.zoomeye.ai/searchResult?q=YXBwPSJDaXRyaXggTmV0U2NhbGVyIg%3D%3D

#Infosec #CyberSecurity #ZoomEye
❀2
Exploit β€’ Auto Sh3lls in MAGENTO 🟦

Modes πŸ’₯

βœ… Detect (default) fingerprint Magento + version, classify VULN/ASSUMED.

βœ… Exploit (--exploit) run the full chain, execute --code (or default id), verify via a fresh canary file written by the injected PHP.

πŸ”₯ Affecting +1kk Websites Magento Cms

DM  πŸ‘‰ @Mm_fit

Channel: https://t.me/fox_security_cve

#AD
❀8πŸ—Ώ3πŸ¦„2
🚨APKLeaks - Scanning APK file for URIs, endpoints & secrets.

βœ…https://github.com/dwisiswant0/apkleaks
❀10
🚨 CVE-2026-102489: Zammad Unauthenticated Remote Code Execution Exploited Zero-Day

Critical Vulnerability Alert!
Zammad (Zammad GmbH) is affected by CVE-2026-102489.

πŸ” Identify Targets via ZoomEye:

Search Dork: app="Zammad"
Exposure: 12k instances identified globally.

ZoomEye Search Link:
πŸ‘‰ https://www.zoomeye.ai/searchResult?q=YXBwPSJaYW1tYWQi

#ZoomEye #CyberSecurity #Zammad #CVE2026102489 #RCE #ZeroDay
❀6
CVE-2026-63292 and others: Multiple vulnerabilities in Apache HTTP Server, up to 9.8 rating ‍πŸ”₯

Apache Software Foundation disclosed 20 new vulnerabilities. The most severe can lead to RCE, arbitrary code execution via stack-based buffer overflow, and DoS/potential RCE via use-after-free. Memory corruption, privilege escalation, and info disclosure bugs were also patched.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/fFMkT
πŸ‘‰ Dork: tag.name:"apache"

Vendor's advisory:
https://httpd.apache.org/security/vulnerabilities_24.html
❀5πŸ‘1
1000+ CVE's in one release!!😱😱😱😱
https://lwn.net/Articles/1097401/
Please open Telegram to view this post
VIEW IN TELEGRAM
❀3🀯2❀‍πŸ”₯1πŸ₯°1
🚨 WatchGuard Firebox fingerd Pre-Authentication Stack Overflow (CVE-2026-81433) Allows Remote Code Execution

Critical Vulnerability Alert!
WatchGuard Fireware OS (Firebox) is affected by CVE-2026-81433.

πŸ” Identify Targets via ZoomEye:

Search Dork: title="WatchGuard"
Exposure: 105.5k instances identified globally.

ZoomEye Search Link:
πŸ‘‰ https://www.zoomeye.ai/searchResult?q=dGl0bGU9IldhdGNoR3VhcmQi

#CVE202681433 #WatchGuard #Firebox #FirewareOS #RCE #CyberSecurity
πŸ‘1