Forwarded from Source Byte
< Scam Alert >
New Threat Actor steal famous "IrLeaks" telegram support ID & tuta mail after their support account been inactive for a while ( their accounts deleted automatically due to privacy policy ) , as i look at my archives this is previous accounts you can use to verify them :
[ + ] Exploit[.]in MemberID :
[ + ] BreachForums UserID :
[ + ] BreachForums Email address :
( Creation time:
[ + ] Telegram channel :
[ + ]Telegram Support : <deleted>
[ + ]Email address :
New Threat Actor steal famous "IrLeaks" telegram support ID & tuta mail after their support account been inactive for a while ( their accounts deleted automatically due to privacy policy ) , as i look at my archives this is previous accounts you can use to verify them :
[ + ] Exploit[.]in MemberID :
150525 ( Last visited : September 7, 2024 )[ + ] BreachForums UserID :
46196[ + ] BreachForums Email address :
irleaks@proton.me ( Creation time:
1696708552 , Last update: 1710784785 )[ + ] Telegram channel :
1948656476[ + ]
5128567513[ + ]
irleaks@tuta.io <deleted by tuta policy>❤9
Attack Classes & Bypass History
This page documents recurring attack classes that DOMPurify and other DOM-based HTML sanitizers have had to withstand: HTML parser mutation, namespace confusion, rawtext breakouts, depth-limit flattening, nesting-based mXSS, DOM clobbering, prototype pollution, template-expression reassembly, engine-deferred DOM mutation, and configuration foot-guns.
https://github.com/cure53/DOMPurify/wiki/Attack-Classes-&-Bypass-History
This page documents recurring attack classes that DOMPurify and other DOM-based HTML sanitizers have had to withstand: HTML parser mutation, namespace confusion, rawtext breakouts, depth-limit flattening, nesting-based mXSS, DOM clobbering, prototype pollution, template-expression reassembly, engine-deferred DOM mutation, and configuration foot-guns.
https://github.com/cure53/DOMPurify/wiki/Attack-Classes-&-Bypass-History
👍3❤1
Introducing usbliter8: A SecureROM Exploit for Apple A12 and A13
https://ps.tc/pages/blog-usbliter8.html?hl=en-US
https://ps.tc/pages/blog-usbliter8.html?hl=en-US
ps.tc
Paradigm Shift - Introducing usbliter8
This write-up details a novel iPhone BootROM vulnerability discovered and exploited by our team. It covers the underlying bug, the associated exploitation techniques, and the post-exploitation steps required...
❤4
Ai000 Cybernetics QLab
چرا در خاورمیانه همه کشورها در حال رشد، توسعه، مدرنشدن و سیستماتیکشدن هستند، ولی ما نه؟ واقعاً مشکل چیست؟
آیا توسعه یعنی پروژههای بیشتر، بودجههای بزرگتر و آمارهای درشتتر؟
یا یعنی امروز از دیروز بهتر باشیم؟
https://youtu.be/ZyFoGe93BDg
یا یعنی امروز از دیروز بهتر باشیم؟
https://youtu.be/ZyFoGe93BDg
👍8
OnHex
گروه باج افزاری RansomHouse، مدعی نفوذ به بخشی از مخزن سورس کد شرکت امنیت سایبری Trellix شده. شرکت این نفوذ رو تایید و اعلام کرده که در حال بررسی رخداد هستش و با مراجع قانونی در حال همکاری هستش. بر اساس تحقیقات شرکت تا به امروز، هیچ مدرکی مبنی بر تأثیرگذاری بر فرآیند انتشار یا توزیع سورس کدشون، یا اینکه سورش کدشون مورد سوء استفاده قرار گرفته، پیدا نکردن. Trellix یک شرکت بین المللی امنیت سایبری است که در نوامبر 2021، از ادغام McAfee Enterprise و FireEye تشکیل شده. این شرکت به بیش از ۵۰,۰۰۰ مشتری تجاری و دولتی در سراسر جهان خدمات ارائه میده.
lol , seems they payout them , they removed them as victim . anyone get sample they shared?
🗿5🥰1
Exploiting a “Simple” Vulnerability – Part 1.5 – The Info Leak
https://windows-internals.com/exploiting-a-simple-vulnerability-part-1-5-the-info-leak/
#CVE-2021-24107
https://windows-internals.com/exploiting-a-simple-vulnerability-part-1-5-the-info-leak/
#CVE-2021-24107
💘3
Forwarded from Go Library
The Go Compiler: A Deep Dive Into How Your Code Becomes a Binary
https://blog.gaborkoos.com/posts/2026-05-08-The-Go-Compiler-a-Deep-Dive-Into-How-Your-Code-Becomes-a-Binary
https://blog.gaborkoos.com/posts/2026-05-08-The-Go-Compiler-a-Deep-Dive-Into-How-Your-Code-Becomes-a-Binary
💘3
I made a useful MCP wrapper to help agents analyse multiple binaries in IDA in parallel, and easily switching them, check this out, if you will like it, it would be cool to get feedback and maybe a post in your channel 🙏
https://github.com/whoisqwerz/pocket_disasm
https://github.com/whoisqwerz/pocket_disasm
GitHub
GitHub - whoisqwerz/pocket_disasm: Multi-session IDALib MCP router for coding agents. Analyze multiple binaries in parallel with…
Multi-session IDALib MCP router for coding agents. Analyze multiple binaries in parallel with IDA-compatible reverse engineering tools. - whoisqwerz/pocket_disasm
👍6👎2
Source Byte
I made a useful MCP wrapper to help agents analyse multiple binaries in IDA in parallel, and easily switching them, check this out, if you will like it, it would be cool to get feedback and maybe a post in your channel 🙏 https://github.com/whoisqwerz/pocket_disasm
This media is not supported in your browser
VIEW IN TELEGRAM
👎5🥰5💅1💘1
👍5
Source Byte
https://zenodo.org/records/21348017
if you know assembly and have RE skills , then everything is open-source to you🥹
💅8👍2
Reverse Engineering a Ledger Nano X Hardware Implant
https://grandideastudio.com/portfolio/security/ledger-hardware-implant/
https://grandideastudio.com/portfolio/security/ledger-hardware-implant/
😈4🥰1
Alert
A new exploit has been discovered in Telegram that allows Japanese accounts to purchase 10,000 Stars for just $1.50, even though the normal price is $150.
Shortly after the exploit was discovered, many Chinese users began mass-buying expensive gifts with Stars obtained through the bug.
However, most of the gifts and Stars are expected to be refunded once Telegram fixes the exploit. Many accounts that abused the exploit have already been deactivated, and using it could result in your account being frozen or permanently banned.
This media is not supported in your browser
VIEW IN TELEGRAM
👾9
ODR: Internals of Microsoft's New Native MCP Registration
https://www.originhq.com/research/msft-odr-mcp
https://www.originhq.com/research/msft-odr-mcp
Origin Technology
ODR: Internals of Microsoft's New Native MCP Registration | Origin Technology
Reverse engineering Odr.exe reveals how Windows On-Device Registry runs MCP, via undocumented COM interfaces, a SQL-backed consent database, and ETW audit.
😈2