reverse engineering
3.6K subscribers
87 photos
11 videos
25 files
132 links
◉ A channel for learning and discussing about reverse engineering

◉ We aren't accepting any illegal works, we are here to help, learn and gain new skills
◉ Owner @Mohamed_Abozaid1
◉ Egypt 🇪🇬

Please don't PM ask in discussion group except in necessity
Download Telegram
Forwarded from Darksec
CVE-2026-21858 + CVE-2025-68613: n8n Ni8mare - Full Chain Exploit

Unauthenticated to Root RCE:
- LFI via Content-Type confusion
- Read /proc/self/environ to find HOME
- Steal encryption key + database
- Forge admin JWT token
- Expression injection sandbox bypass
- RCE as root

CVSS 10.0

https://github.com/Chocapikk/CVE-2026-21858
❤‍🔥5🔥4🥰1
It's time to change your Instagram Password
7😴4👀3
Well Discord seems to be banned in Egypt 🇪🇬

Unfortunately as everything has a good side it has a bad one as well 😔

https://eg.downdetector.com/status/discord/
7
This media is not supported in your browser
VIEW IN TELEGRAM
Be careful ! about what you are clicking these days
Don't click any usernames from untrusted sources because one click can expose your IP address to the attackers servers via a fake proxy initialized before by the attacker

Shared from https://www.facebook.com/Sir.MaTrix

@reverseengineer101
54👍4👨‍💻4
Claude AI is down

After what we saw from cloudflare at the end of 2025 will Claude be the same 😂
As some people say DaaS (Downtime As A Service)

Be updated on https://status.claude.com/
6😁5👎1
This must be a joke 😂

How to say our app can be a Trojan without saying 😁

Anyway that is why I always advise you not to install anything on your device
I don't have any personal issues with the app manufacture, but I had say my opinion from a security perspective
#stay_safe_stay_secure

@reverseengineer101
9😁2🤣1
Well thank you ❤️
8🫡3
BITNET an AI model can run locally introduced by Microsoft and it can run with limited resources (cpu, ram,...) people say you can run it using your old PC

https://github.com/microsoft/BitNet

Shared by @reverseengineer101
👍74👎1
Chinese hackers have hacked American Telecommunications Companies

In a process called Salt Typhoon, Chinese Hackers has intercepted some calls and compromised millions of metadata records after hacking the American Telecommunications Companies from 2 years before now unnoticed which make it one of the biggest security flaws have occurred.

Experts say it's mostly sponsored by the Chinese Government for spying and politics related reasons

Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications (American Congress)

@reverseengineer101
11
I have hit one of the dangerous mistakes a Developer can do

As you see here the API is rejecting all the requests without Authorization header but after adding a fake one it returns the data

This vulnerability is classified as BFLA/BOLA API1:2023
(Broken Function/Object Level Authorization) or a Broken Access Control (BAC) issue at all

You can read more about it on OWASP API Top 10

API1:2023 Broken Object Level Authorization

#API_Security

@reverseengineer101
8👍3😢3🤯2😁1
a Threat Actor called "quellostanco" claims that he has stolen a full EgyptAir database.

The database mentioned has 104K records related to HR section including sensitive employees data as he say

@reverseengineer101
6🤯5🤔4🤩1
Ramadan Kaream all ❤️
47👎2
Intigriti Challenge 0226

CTF solved ✓

The write up will be disclosed ASAP the challenge finishes 🏁

@reverseengineer101
8🔥1👏1