The FreePBX Rabbit Hole: CVE-2025-66039 and others #FreePBX #Vulnerabilities #CVE202566039 #RCE #SQLInjection https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/
Horizon3.ai
CVE-2025-66039: FreePBX Rabbit Hole
Horizon3.ai uncovers FreePBX flaws, including CVE-2025-66039 auth bypass, SQL injection, and file upload RCE—and shows how NodeZero detects them.
The Fragile Lock: Novel Bypasses For SAML Authentication #SAML #AuthBypass #XMLSecurity #ParserFlaws #SignatureWrapping https://portswigger.net/research/the-fragile-lock
PortSwigger Research
The Fragile Lock: Novel Bypasses For SAML Authentication
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
HelioSphere: Concept and Project Presentation https://nextcloud.calzone-rivoluzione.de/s/pLoNrkgrerbSzfx
Nextcloud
concept.pdf
Nextcloud - a safe home for all your data
👍1
CVE-2025-64669: Uncovering Local Privilege Escalation Vulnerability in Windows Admin Center #CVE202564669 #WindowsAdminCenter #PrivilegeEscalation #CymulateResearch #Vulnerability https://cymulate.com/blog/cve-2025-64669-windows-admin-center/
Cymulate
CVE-2025-64669: Uncovering Local Privilege Escalation Vulnerability in Windows Admin Center
Cymulate Research Labs discovered CVE-2025-64669, a local privilege escalation flaw in Windows Admin Center enabling SYSTEM-level compromise.
Makop ransomware: GuLoader and privilege escalation in attacks against Indian businesses #MakopRansomware #RDPAccess #PrivilegeEscalation #GuLoader #IndianCyberattacks https://www.acronis.com/en/tru/posts/makop-ransomware-guloader-and-privilege-escalation-in-attacks-against-indian-businesses/
Acronis
Makop ransomware: GuLoader and privilege escalation in attacks against Indian businesses
Makop, a ransomware strain derived from Phobos, continues to exploit exposed RDP systems while adding new components such as local privilege escalation exploits and loader malware to its traditional toolkit.
😱1
Fight bad bot with Sec Fetch and Client Hints inconsistencies in headless browsers #BotDetection #HeadlessBrowsers #ClientHints #SecFetchHeaders #BrowserInconsistencies https://blog.sicuranext.com/sec-fetch-and-client-hints-a-powerful-tool-against-automation/
Sicuranext Blog
Fight bad bot with Sec Fetch and Client Hints inconsistencies in headless browsers
For many of our e-commerce customers the problem of bad bots it's a everyday problem and has evolved a lot in the last few years. A common approach is to "block" automated traffic with a JavaScript challenge, basically a small script that the browser must…
8 Million Users' AI Conversations Sold for Profit by "Privacy" Extensions #AIPrivacyBreach #BrowserExtensionScam #UrbanVPNSurveillance #DataBrokerage #GoogleEndorsementFail https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection
www.koi.ai
8 Million Users' AI Conversations Sold for Profit by "Privacy" Extensions
Privacy browser extensions misled users and sold 8 million AI chat logs, exposing sensitive conversations for profit without consent.
Attempting Cross Translation Unit Taint Analysis for Firefox #FirefoxSecurity #StaticAnalysis #TaintAnalysis #CTUAnalysis #ClangLimitations https://attackanddefense.dev/2025/12/16/attempting-cross-translation-unit-static-analysis.html
Attack & Defense
Attempting Cross Translation Unit Taint Analysis for Firefox
Preface
GeminiJack Challenge — Prompt Injection Challenge #GeminiJack #PromptInjection #RAGExploitation #LLMSecurity #DataExfiltration https://geminijack.securelayer7.net/
TruffleHog now detects JWTs with public-key signatures and verifies them for liveness #TruffleHog #JWTs #LiveVerification #SecretScanning #PublicKeySecurity https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness
Trufflesecurity
TruffleHog now detects JWTs with public-key signatures and verifies them for liveness ◆ Truffle Security Co.
TruffleHog now detects JWTs signed with public-key cryptography and verifies them for liveness. This new detector has already found hundreds of live JWTs for our customers.
Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096) #PostHog #RCEChain #SSRF #SQLInjection #Zeroday https://mehmetince.net/inside-posthog-how-ssrf-a-clickhouse-sql-escaping-0day-and-default-postgresql-credentials-formed-an-rce-chain-zdi-25-099-zdi-25-097-zdi-25-096/
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI…
It was yet another day at the office. Our team was internally discussing moving to a different platform analytics solution. Our team was really leaning more towards Posthog. It’s one of the brilliant -I personally believe it’s the best- products on the market.…
AI Model Safety: Emerging Threats Assessment #EmergingThreats #ThreatAssessment #2025Outlook #Cybersecurity #AIInsights https://24882480.fs1.hubspotusercontent-eu1.net/hubfs/24882480/Emerging%20Threats%20Risk%20Assessment%202025.pdf
JUMPSHOT: XM Cyber Uncovers Critical Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent https://xmcyber.com/blog/jumpshot-xm-cyber-uncovers-critical-local-privilege-escalation-cve-2025-34352-in-jumpcloud-agent/
XM Cyber
JUMPSHOT: XM Cyber Uncovers Critical Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent | XM Cyber
Learn more about JUMPSHOT: XM Cyber Uncovers Critical Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent . Read more on XM Cyber website.
Linearity of SHA-256 and Chaotic Systems
in Self-Defined Dimensions https://osf.io/6yrw8/files/wj9ze
in Self-Defined Dimensions https://osf.io/6yrw8/files/wj9ze
🤪1
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack #Vulnhalla #LLMSecurity #CodeQL #VulnerabilityResearch #FalsePositiveReduction https://www.cyberark.com/resources/threat-research-blog/vulnhalla-picking-the-true-vulnerabilities-from-the-codeql-haystack
Cyberark
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
In this blog post, we present our approach for uncovering vulnerabilities by combining LLM reasoning with static analysis. By layering an LLM on top of CodeQL, we significantly reduce the...
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack #SupplyChainAttack #XSS #Mintlify #CorporateSecurity #BugBounty https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Gist
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack - writeup.md
👍1
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 #AIAgentSecurity #OAuthFlaw #CVE20256514 #TrustInversion #CapabilityBasedAuth https://amlalabs.com/blog/oauth-cve-2025-6514/
Amla Labs
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs
A critical vulnerability in mcp-remote affected 558,846 downloads. The bug was client-side, but the attack exploited OAuth dynamic discovery—a trust assumption that breaks for autonomous agents.
Microsoft Brokering File System Elevation of Privilege Vulnerability #MicrosoftBFS #UseAfterFree #ElevationOfPrivilege #KernelVulnerability #CVE202529970 https://www.pixiepointsecurity.com/blog/nday-cve-2025-29970/
PixiePoint Security
Microsoft Brokering File System Elevation of Privilege Vulnerability | PixiePoint Security
About 2 years ago, Microsoft first released Win32-App-isolation which is a sandbox-like mechanism to further separate application access to resources on Windows clients. Brokering File System (BFS) was released around the same time to specifically …
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets #RustBotnet #ReverseEngineering #C2Honeypot #DockerExploit #DDoSMalware https://beelzebub.ai/blog/rust-ddos-botnet-honeypot-c2-decoding/
Beelzebub
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets | AI-Native security platform
AI-Native security platform: Deceive, Detect, Respond. “We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source framework, deceive attackers during lateral movement within the network. While intruders interact…
mediatek? more like media-rekt, amirite. #MediaTekRekt #WiFiVulnerabilities #KernelExploits #VendorDisclosure #CyberSecurity https://blog.coffinsec.com/0days/2025/12/15/more-like-mediarekt-amirite.html
hyprblog
mediatek? more like media-REKT, amirite.
A year-in-review going over 19+ bugs in Mediatek’s MT76xx/MT7915 (and others) wifi chipsets I reported this year, PoCs included!