‼️🚨 CRITICAL: Palo Alto Networks has disclosed CVE-2026-0300, a buffer overflow in PAN-OS that is already being exploited in the wild.
CVSS 4.0 score: 9.3.
Unauthenticated attackers can hit the User-ID Authentication Portal (the Captive Portal service) with crafted packets and pop a root shell on the firewall.
The flaw is an out-of-bounds write (CWE-787) in PA-Series and VM-Series firewalls. Prisma Access, Cloud NGFW, and Panorama are not affected. The vulnerability only triggers when the User-ID Authentication Portal is enabled and reachable from untrusted networks.
Affected branches:
- PAN-OS 10.2 below 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
- PAN-OS 11.1 below 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15
- PAN-OS 11.2 below 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, 11.2.12
- PAN-OS 12.1 below 12.1.4-h5, 12.1.7
Patches roll out between May 13 and May 28, 2026. A Threat Prevention signature for PAN-OS 11.1 and above shipped on May 5.
Mitigations before patches roll out:
- Restrict Authentication Portal access to trusted internal IPs only
- Disable the User-ID Authentication Portal entirely if not needed
Compromising a perimeter firewall as root opens the door to lateral movement, traffic interception, credential harvesting, and full network takeover. Audit Device > User Identification > Authentication Portal Settings and treat any internet-exposed portal as an emergency.
https://security.paloaltonetworks.com/CVE-2026-0300
CVSS 4.0 score: 9.3.
Unauthenticated attackers can hit the User-ID Authentication Portal (the Captive Portal service) with crafted packets and pop a root shell on the firewall.
The flaw is an out-of-bounds write (CWE-787) in PA-Series and VM-Series firewalls. Prisma Access, Cloud NGFW, and Panorama are not affected. The vulnerability only triggers when the User-ID Authentication Portal is enabled and reachable from untrusted networks.
Affected branches:
- PAN-OS 10.2 below 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
- PAN-OS 11.1 below 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15
- PAN-OS 11.2 below 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, 11.2.12
- PAN-OS 12.1 below 12.1.4-h5, 12.1.7
Patches roll out between May 13 and May 28, 2026. A Threat Prevention signature for PAN-OS 11.1 and above shipped on May 5.
Mitigations before patches roll out:
- Restrict Authentication Portal access to trusted internal IPs only
- Disable the User-ID Authentication Portal entirely if not needed
Compromising a perimeter firewall as root opens the door to lateral movement, traffic interception, credential harvesting, and full network takeover. Audit Device > User Identification > Authentication Portal Settings and treat any internet-exposed portal as an emergency.
https://security.paloaltonetworks.com/CVE-2026-0300
Palo Alto Networks Product Security Assurance
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code wi...
❤1👎1
This media is not supported in your browser
VIEW IN TELEGRAM
Four individuals linked to Power Distribution Services (PDS) have been arrested by the Bureau of National Intelligence (BNI) in connection with ongoing investigations into the transfer of large sums of money believed to belong to the Electricity Company of Ghana (ECG).
The suspects have been identified as Philip Ayensu, Viraj Phat, Sophia Korkor, and Justice Menka-Premoh.
According to an official update, the arrests were carried out last week as part of efforts to probe the alleged financial transactions. The four have since been granted bail and are expected to assist with further investigations.
The suspects have been identified as Philip Ayensu, Viraj Phat, Sophia Korkor, and Justice Menka-Premoh.
According to an official update, the arrests were carried out last week as part of efforts to probe the alleged financial transactions. The four have since been granted bail and are expected to assist with further investigations.
👎1
This media is not supported in your browser
VIEW IN TELEGRAM
WARRP
~ A native radare2 plugin for the Binary Ninja's WARP signature format.
https://github.com/radareorg/warrp
#radare2
~ A native radare2 plugin for the Binary Ninja's WARP signature format.
https://github.com/radareorg/warrp
#radare2
GitHub
GitHub - radareorg/r2warp: A native radare2 plugin for the WARP signature format
A native radare2 plugin for the WARP signature format - radareorg/r2warp
👎1
This media is not supported in your browser
VIEW IN TELEGRAM
frida-agent compiler
~ lightweight, simple frida agent compiler & API
🎙️ GitHub | 📱Web
Q.) Why?
A.) Modern Frida versions require a tedious setup: initializing projects with
This project automates the entire workflow. Simply provide your script, and the tool handles project creation, dependency management, and compilation for you.
~ lightweight, simple frida agent compiler & API
🎙️ GitHub | 📱Web
Q.) Why?
A.) Modern Frida versions require a tedious setup: initializing projects with
frida-create, managing bridges (Starting with Frida 17.0.0, bridges are no longer bundled with Frida’s GumJS runtime), and manual compilation. These steps are often challenging (at the time of writing this) in environments like Termux, where frida-compile frequently fails.This project automates the entire workflow. Simply provide your script, and the tool handles project creation, dependency management, and compilation for you.
GitHub
GitHub - AbhiTheModder/frida-agent-api: lightweight, simple frida agent compiler & API
lightweight, simple frida agent compiler & API. Contribute to AbhiTheModder/frida-agent-api development by creating an account on GitHub.
👎1
This media is not supported in your browser
VIEW IN TELEGRAM
[METHOD] TENCENT CLOUD — VPS FOR 1 YEAR FOR $10 ⚡️🔥
Connecting Your Future, Empowering Your Growth.
STEPS:
🍁 Go to https://www.tencentcloud.com/act/pro/lighthouse
🪴 Click on "Buy Now."
🪴 Log in or create a new account.
🪴 Complete the payment to get your subscription (you can use your main card or a virtual card to complete the transaction).
🪴 You just got a high quality VPS for 1 year for cheap.
🪴 Enjoy
🪴 Send a screenshot in the comments. It's free.
NOTES ⚠️
– Use multiple accounts/devices to claim again if needed.
– Send a screenshot after you get it. ‼️
Connecting Your Future, Empowering Your Growth.
STEPS:
🍁 Go to https://www.tencentcloud.com/act/pro/lighthouse
🪴 Click on "Buy Now."
🪴 Log in or create a new account.
🪴 Complete the payment to get your subscription (you can use your main card or a virtual card to complete the transaction).
🪴 You just got a high quality VPS for 1 year for cheap.
🪴 Enjoy
🪴 Send a screenshot in the comments. It's free.
NOTES ⚠️
– Use multiple accounts/devices to claim again if needed.
– Send a screenshot after you get it. ‼️
👎2
This media is not supported in your browser
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
🏁 TON leads Layer-1 blockchains in finality time.
🔗 Sources: https://telegra.ph/Comparison-of-Layer-1-blockchains-by-finalization-time-05-01
🔗 Sources: https://telegra.ph/Comparison-of-Layer-1-blockchains-by-finalization-time-05-01
👍1👎1
Media is too big
VIEW IN TELEGRAM
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🏜 𝗗𝗘𝗫𝟮𝗖 - 𝗠𝗘𝗚𝗔 🏜
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🪲𝗙𝗨𝗟𝗟𝗬 𝗢𝗙𝗙𝗟𝗜𝗡𝗘 🪲
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🏜 𝗗𝗘𝗫𝟮𝗖 - 𝗠𝗘𝗚𝗔 🏜
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🪲𝗙𝗨𝗟𝗟𝗬 𝗢𝗙𝗙𝗟𝗜𝗡𝗘 🪲
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
👏3❤1👎1🔥1🥰1
Dex2c_Mega.apk
12.6 MB
━━━━━━━━━━━━━━━━━━
🛡 𝗗𝗲𝘅𝟮𝗰 𝗠𝗲𝗴𝗮 🛡
━━━━━━━━━━━━━━━━━━
🏜 𝗪𝗛𝗔𝗧 𝗜𝗧 𝗗𝗢𝗘𝗦 🏜
├ Converts DEX bytecode into real ARM64 native C++ code
├ Compiled methods become empty
├ No filter.txt, no zipping needed
│ Just open d APK & pick classes ,Select individual methods, whole classes, or protect everything
├ Control flow obfuscation
├ Stubs becomes uncoverable
├ Auto-strips bytecode from DEX
└ Rebuilds & signs the APK
📦 𝗗𝗘𝗣𝗘𝗡𝗗𝗘𝗡𝗖𝗜𝗘𝗦
├ 🐍 Python 3 Runtime
│ └ Termux Python 3.13 (6MB)
├ 🔨 NDK Compiler (clang-21)
│ └ termux-ndk r29 · (110mb)
└ 🧠 DEX & C++ Transpiler
└ codehasan/dex2c · full SSA pipeline_androguard 3.3.5
🌐 𝗡𝗢 𝗜𝗡𝗧𝗘𝗥𝗡𝗘𝗧 𝗥𝗘𝗤𝗨𝗜𝗥𝗘𝗗
├ One-time download of NDK
│ and Python 3 to set up
└ After that — fully offline,
forever. No servers, no cloud
💡 𝗜𝗡𝗦𝗣𝗜𝗥𝗘𝗗 𝗕𝗬 💡
Antik dex2cxx app inspired us to build Dex2c Mega. None of his tools was used , Dex2c Mega was built from scratch using open-source components only.
➖➖➖➖➖➖➖➖➖
🕹 Released By :
逆转 X 模组
🔗 Share To Support Us 🔗
➖➖➖➖➖➖➖➖➖
🛡 𝗗𝗲𝘅𝟮𝗰 𝗠𝗲𝗴𝗮 🛡
━━━━━━━━━━━━━━━━━━
🏜 𝗪𝗛𝗔𝗧 𝗜𝗧 𝗗𝗢𝗘𝗦 🏜
├ Converts DEX bytecode into real ARM64 native C++ code
├ Compiled methods become empty
├ No filter.txt, no zipping needed
│ Just open d APK & pick classes ,Select individual methods, whole classes, or protect everything
├ Control flow obfuscation
├ Stubs becomes uncoverable
├ Auto-strips bytecode from DEX
└ Rebuilds & signs the APK
📦 𝗗𝗘𝗣𝗘𝗡𝗗𝗘𝗡𝗖𝗜𝗘𝗦
├ 🐍 Python 3 Runtime
│ └ Termux Python 3.13 (6MB)
├ 🔨 NDK Compiler (clang-21)
│ └ termux-ndk r29 · (110mb)
└ 🧠 DEX & C++ Transpiler
└ codehasan/dex2c · full SSA pipeline_androguard 3.3.5
🌐 𝗡𝗢 𝗜𝗡𝗧𝗘𝗥𝗡𝗘𝗧 𝗥𝗘𝗤𝗨𝗜𝗥𝗘𝗗
├ One-time download of NDK
│ and Python 3 to set up
└ After that — fully offline,
forever. No servers, no cloud
💡 𝗜𝗡𝗦𝗣𝗜𝗥𝗘𝗗 𝗕𝗬 💡
Antik dex2cxx app inspired us to build Dex2c Mega. None of his tools was used , Dex2c Mega was built from scratch using open-source components only.
➖➖➖➖➖➖➖➖➖
🕹 Released By :
逆转 X 模组
🔗 Share To Support Us 🔗
➖➖➖➖➖➖➖➖➖
❤11🔥3⚡1👎1👏1🍾1
Reversal X Mods (бесплатные премиум-приложения для Android)
Dex2c_Mega.apk
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🏜 𝗗𝗘𝗫𝟮𝗖 - 𝗠𝗘𝗚𝗔 🏜
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
We've added 16 custom advanced layers on top of Dex2C. Any app you protect gets Dex2C + Omega 16 layers baked in...
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🐬 V8 dropping soon 🐬
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🏜 𝗗𝗘𝗫𝟮𝗖 - 𝗠𝗘𝗚𝗔 🏜
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
We've added 16 custom advanced layers on top of Dex2C. Any app you protect gets Dex2C + Omega 16 layers baked in...
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
🐬 V8 dropping soon 🐬
🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀🪀
⚡5🔥4🥰1😁1
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ You can't be serious. Ford is now charging 2026 Mustang Mach-E buyers $495 for the plastic tray that goes inside the frunk the car comes with.
❤2
This media is not supported in your browser
VIEW IN TELEGRAM