Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
netsentryx — Updated!

An event-driven network monitoring platform that performs live packet capture (Npcap), low-latency traffic analytics, and unsupervised threat detection using a PyTorch Autoencoder, backed by an async multi-channel alert engine.
Read more...
nimux v1.0.5

Single-binary Nim toolkit for network enumeration, Active Directory operations, and remote execution.
Read more...
CVE-2026-0603 — Updated!

Hibernate ORM Second-Order SQL Injection
Read more...
CVE-2026-30951 — Updated!

Sequelize JSON Cast SQL Injection
Read more...
CVE-2026-41940 — Updated!

Mass authentication bypass exploit for CVE-2026-41940 with single-target and batch scanning modes. Automates password-based bypass testing across multiple web targets.
Read more...
Undocumented-RCE-in-PLY — Updated!

Undocumented RCE in PLY via `picklefile` Parameter
Read more...
ipmi — Updated!

IPMI stuff from DARPA work
Read more...
jmxbf — Updated!

A brute force program to test weak accounts configured to access a JMX Registry
Read more...
VCG — Updated!

VisualCodeGrepper - Code security scanning tool.
Read more...
CVE-2026-34220 — Updated!

SQL Injection vulnerability in MikroORM
Read more...
QuestStack — Updated!

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.
Read more...
CVE-2026-8347 — Updated!

CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
Read more...
CICD-Goat-Vapt-Writeup — Updated!

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
Read more...
kcmd — Updated!

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt commands/responses. This is a PoC project to demonstrate hijacking the socket and sniffing of kankun passwords. This will work on an Android device.
Read more...
CVE-2026-16723 — Updated!

A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
Read more...
Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation — Updated!

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check Point Security Gateway. Includes comprehensive SIEM analysis, firewall logs, raw web access log inspection (`/var/log/access.log`), IOCs, MITRE ATT&CK mapping, and post-exploitation validation.
Read more...
How I Discovered One of My Most Creative Bugs in Google’s Gemini AI Competition

Sometimes, a vulnerability starts with nothing more than a simple question: “Why is this happening?”Continue reading on Medium »
Read more...
ghostlock — Updated!

Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
Read more...
CVE-2026-59941 — Updated!

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Read more...
CVE-2026-39987 — Updated!

Simple POC for CVE-2026-39987
Read more...
ida\_kcpp — Updated!

An IDAPython module for enhancing c++ support on top of ida_kernelcache
Read more...