dns0 wyłonczyli, szybkie było i zdechło #dns #informatyka
dns0 wyłonczyli, szybkie było i zdechło #dns #informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.21.md
The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows - https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/
101 Chrome Exploitation — Part 1: Architecture - https://opzero.ru/en/press/101-chrome-exploitation-part-1-architecture/
BeaverTail and OtterCookie evolve with a new Javascript module - https://blog.talosintelligence.com/beavertail-and-ottercookie/
Lessons from the BlackBasta Ransomware Attack on Capita - https://blog.bushidotoken.net/2025/10/lessons-from-blackbasta-ransomware.html
A Brief Analysis of Chrome's 0day CVE-2025-6554 in the Wild - https://ti.qianxin.com/blog/articles/a-brief-analysis-of-chrome-0day-cve-2025-6554-en/
#informatyka
Zaloguj się aby komentować
Uwaga na ataki na konta Google
Chłop stracił konto prawdopodobnie na dobre.
To też dla tych wszystkich co śmieją się z babć wpwdajacych w pułapki phishingu czy telefonicznych oszustów
https://niebezpiecznik.pl/post/przejete-konto-google-gmail-jak-odzyskac-pomoc-suport-kontakt/
#informatyka #cybersecurity #ciekawostki
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.19.md
Abusing sAMAccountName Hijacking in "GPP: Local Users and Groups - https://www.cogiceo.com/en/whitepaper_gpphijacking/
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit - https://blog.kyntra.io/Singularity-A-final-boss-linux-kernel-rootkit
TLS NoVerify: Bypass All The Things - https://f0rw4rd.github.io/posts/tls-noverify-bypass-all-the-things/
Windows ARM64 Internals: Deconstructing Pointer Authentication - https://www.preludesecurity.com/blog/windows-arm64-internals-deconstructing-pointer-authentication
Unpacking the Microsoft Intune MDM and Entra ID Certificate - https://msendpointmgr.com/2024/10/12/unpacking-the-microsoft-intune-mdm-certificate/
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.17.md
[CVE-2025-38001 - https://syst3mfailure.io/rbtree-family-drama/
Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers - https://blog.quarkslab.com/nvidia_gpu_kernel_vmalloc_exploit.html
A Tour of eBPF in the Linux Kernel: Observability, Security and Networking - https://www.lucavall.in/blog/a-tour-of-ebpf-in-the-linux-kernel-observability-security-and-networking
Bypass AMSI in 2025 - https://www.r-tec.net/r-tec-blog-bypass-amsi-in-2025.html
No Alloc, No Problem: Leveraging Program Entry Points for Process Injection - https://bohops.com/2023/06/09/no-alloc-no-problem-leveraging-program-entry-points-for-process-injection/
#informatyka
Zaloguj się aby komentować
Hasła, manager haseł?
Zacznij korzystać z kontaktów w outlook jak managera haseł.
Twój .PST przez lata stał się świętością.
Outlook po updacie stwierdza "podaj mi hasło do account . microsoft . com albo się nie uruchomię".
Uświadom sobie że pass do ms'a sieci w outlooku (° ͜ʖ °)
Nie przetłumaczysz, wciąż używa.
#cyberbezpieczenstwo #cybersecurity #password #komputery #informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.15.md
OPSEC: Read the Code Before It Burns Your Op - https://blacksnufkin.github.io/posts/opsec-offensive-code-review/
Starting Chrome Exploitation with Type Confusion 101 - https://hackyboiz.github.io/2025/07/01/OUYA77/Chrome_part1/en/
Remote process DLL injection in Rust - https://fluxsec.red/remote-process-dll-injection
North Korea’s Contagious Interview Campaign Escalates: 338 Malicious npm Packages, 50,000 Downloads - https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages
Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W - https://mrt4ntr4.github.io/Windows-Heap-Exploitation-dadadb/
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.13.md
Breaking Disassembly — Abusing symbol resolution in Linux programs to obfuscate library calls - https://blog.elmo.sg/posts/breaking-disassembly-through-symbol-resolution/
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens - https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
A Deep Dive Into Malicious Direct Syscall Detection - https://www.paloaltonetworks.com/blog/security-operations/a-deep-dive-into-malicious-direct-syscall-detection/
Bootloader to Iris: A Security Teardown of a Hardware Wallet - https://hhj4ck.github.io/en/iris-wallet-security-teardown.html
Hiding In PlainSight - Proxying DLL Loads To Hide From ETWTI Stack Tracing - https://0xdarkvortex.dev/proxying-dll-loads-for-hiding-etwti-stack-tracing/
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.11.md
Exploiting the Synology TC500 at Pwn2Own Ireland 2024 - https://blog.infosectcbr.com.au/2025/08/01/exploiting-the-synology-tc500-at-pwn2own-ireland-2024/
Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days - https://www.willsroot.io/2025/09/ksmbd-0-click.html
Lets Create An EDR… And Bypass It! Part 1 - https://ethicalchaos.dev/2020/05/27/lets-create-an-edr-and-bypass-it-part-1/
Automating Operations with Nighthawk - https://www.nighthawkc2.io/automating-operations/
Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984) - https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984
#informatyka
Zaloguj się aby komentować

Ogromna wygrana dla cyfrowej prywatności! Głosowanie nad kontrowersyjną regulacją "Chat Control" zostało definitywnie wstrzymane z powodu braku wystarczającego poparcia. Niemcy, Polska, Austria i inne kraje twardo sprzeciwiły się masowej inwigilacji, co zablokowało inicjatywę. Mimo to,...
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.09.md
Module Stomping 101 - My Favorite Stomping Grounds - https://g3tsyst3m.com/process%20injection/Module-Stomping-101-My-Favorite-Stomping-Grounds/
Fundamental of Virtual Memory - https://nghiant3223.github.io/2025/05/29/fundamental_of_virtual_memory.html
Exploiting ZwMapViewOfSection in ASIO64.sys - https://bad-jubies.github.io/exploiting-asio64-sys
8kSec Frida Lab Solution - https://n0psn0ps.github.io/2025/07/13/8kSec-Frida-Lab-Solution/
Dirty Pageflags: Revisiting PTE Exploitation in Linux - https://ptr-yudai.hatenablog.com/entry/2025/09/14/180326
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.07.md
Bypassing Enrollment Restrictions to Break BYOD Barriers in Intune - https://temp43487580.github.io/intune/bypass-enrollment-restictions-to-break-byod-barriers-in-intune/
Playing with internal path traversal leads to a lot of fun - https://blog.hks.ec/posts/playing-with-internal-path-traversal-leads-to-lot-of-fun/
LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities - https://cyble.com/blog/lunobotnet-a-self-healing-linux-botnet/
A Thousand Sails, One Harbor - C2 Infra on Azure - https://0xdarkvortex.dev/c2-infra-on-azure/
Release of ERNW White Paper 73: Analyzing WinpMem Driver Vulnerabilities - https://insinuator.net/2025/10/white-paper-73-analyzing-winpmem-driver-vulnerabilities/
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.05.md
Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W - https://mrt4ntr4.github.io/Windows-Heap-Exploitation-dadadb/
Geedge & MESA Leak: Analyzing the Great Firewall’s Largest Document Leak - https://gfw.report/blog/geedge_and_mesa_leak/en/
PostgreSQL SQL injection: Updating data without UPDATE - https://adeadfed.com/posts/updating-postgresql-data-without-update/
Early Exception Handling - https://kr0tt.github.io/posts/early-exception-handling/
Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities - https://plaxidityx.com/blog/blog-post/is-your-memory-protecteduncovering-hidden-vulnerabilities-in-automotive-mpu-mechanisms/
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.03.md
SharePoint ToolShell – One Request PreAuth RCE Chain - https://blog.viettelcybersecurity.com/sharepoint-toolshell/
The Havoc framework - https://lorenzomeacci.com/the-havoc-framework
Executive Offense - Building AI Hackbots, Part 1 - https://executiveoffense.beehiiv.com/p/ai-hackbots-part-1
Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer - https://qriousec.github.io/post/oob-angle/
Domain Fronting is Dead. Long Live Domain Fronting! - https://www.praetorian.com/blog/domain-fronting-is-dead-long-live-domain-fronting/
#informatyka
Zaloguj się aby komentować

Pełen artykuł przeczytasz po kliknięciu tutaj:
25 listopada 2019 roku skończyły się wolne pule adresów IPv4 w Europie — ale internet pomimo tego jakoś nie eksplodował. Dlaczego? Bo inżynierowie sieci przez dekady łatali...
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.01.md
The art of self mutating malware - https://0xf00sec.github.io/0x48
CrushFTP RCE Explained - https://pwn.guide/free/web/crushftp
Getting Started With Malware Development - https://www.crow.rip/nest/mal/dev/getting-started
Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening? - https://nac-l.github.io/2025/01/25/lifting_0.html
nRF51 RBPCONF bypass for firmware dumping - https://lessonsec.com/posts/nrf51-bypass/
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.29.md
Turning Camera Surveillance on its Axis - https://claroty.com/team82/research/turning-camera-surveillance-on-its-axis
Quick-Skoping through Netskope SWG Tenants - CVE-2024-7401 - https://quickskope.com/
CPP / C++ Notes - Windows API Programming Win32 - https://caiorss.github.io/C-Cpp-Notes/WindowsAPI-cpp.html
Using Reflective Loaders to Replace LoadLibrary for Hot Swappable Modules in C++ - https://racoten.gitbook.io/red-team-developments-and-operations
More than you wanted to know about how Game Boy cartridges work - https://abc.decontextualize.com/more-than-you-wanted-to-know/
#informatyka
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.27.md
[CVE-2025-41243] Spring Cloud Gateway: complicating evaluation context - https://blog.z3r.ru/posts/spring-cloud-gateway-spel-vuln/
How to Unpack Malware with x64dbg - https://www.varonis.com/blog/x64dbg-unpack-malware
Fixing A FakeNet/-NG PCAP - https://packetsmith.ca/tutorial-fakenet/
How We Accidentally Discovered a Remote Code Execution Vulnerability in ETQ Reliance - https://slcyber.io/assetnote-security-research-center/how-we-accidentally-discovered-a-remote-code-execution-vulnerability-in-etq-reliance/
Invision Community <= 5.0.7 (oauth/callback) Reflected Cross-Site Scripting Vulnerability - https://karmainsecurity.com/KIS-2025-05
#informatyka
Zaloguj się aby komentować
Dlaczego mi wcześniej nie zapaliła się lampka? Po przejęciu przez NetArt hostingu netmark wywalili ceny w kosmos. Za przedłużenie domeny .pl wołają 295 brutto! Nie wspominając już o cenie za hosting... Czy ktoś ma do polecenia jakiś SPRAWDZONY hosting w normalnych pieniądzach?
Wymagania: 2 domeny (.pl i .eu), 3 subdomeny, MySQL, node.js + e-mail
#informatyka #hosting #cebula #kiciochpyta
@GitHub Firma istnieje od 2021 roku i nie jest partnerem NASK, czyli akredytowanym rejestratorem domen .pl, tylko robi to przez pośrednika.
Odważny wybór, ale cóż, obyś był zadowolony i żeby Ci nie podnieśli nagle cen o 200%
Zaloguj się aby komentować
Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.25.md
Silly EDR Bypasses and Where To Find Them - https://malwaretech.com/2023/12/silly-edr-bypasses-and-where-to-find-them.html
Direct Syscalls in Beacon Object Files - https://www.outflank.nl/blog/2020/12/26/direct-syscalls-in-beacon-object-files/
Inside Windows Sessions: A Deep Dive with Pavel - https://trainsec.net/library/windows-internals/inside-windows-sessions/
A Novel Technique for SQL Injection in PDO’s Prepared Statements - https://slcyber.io/assetnote-security-research-center/a-novel-technique-for-sql-injection-in-pdos-prepared-statements/
Creating a C2 infrastructure on AWS - https://lorenzomeacci.com/creating-a-c2-infrastructure-on-aws
#informatyka
Zaloguj się aby komentować