Search
Items tagged with: security
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
GitHub - berabuddies/redis-poc: RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0. Contribute to berabuddies/redis-poc development by creating an account on GitHub.GitHub
My security camera shipped a GitHub admin token in its login page
My security camera shipped a GitHub admin token in its login page
i dissected some firmware for a Hanwha Wisenet XNP-9300RW and found that it had github admin tokens in it, also miltech is weirdhhh.hn
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: bobdahacker.com/blog/click-to-…
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
How I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope's official prayer app, with a single GET request. Reported January 3rd. Still live six months later.bobdahacker.com
Vulnerability-Lookup 5.5.0 released
Add Rocky Linux OSV feeder by adulau · Pull Request #482 · vulnerability-lookup/vulnerability-lookup
Motivation Ingest OSV advisories published by Rocky Linux's Apollo service where no git repo/dump is available by consuming the Apollo paginated OSV API and mapping records into the existing O...GitHub
#OpenAI says its #AI went #rogue and launched 'unprecedented' cyber-attack
source: bbc.com/news/articles/c3ek3gvd…
The #ChatGPT-maker said its agent - an AI #system which can operate alone after human instruction – was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits.They targeted #Hugging Face, one of the world's largest hubs for sharing AI models, gaining access to some internal company systems.
#news #cybersecurity #technology #test #security #economy #control #internet #problem #fail #hack #cyberattack #attack #skynet
New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
krebsonsecurity.com/2026/07/lg…
#smarttv #lg #residentialproxies #spur #security
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers…krebsonsecurity.com
A website to help selecting a #smartphone with a Google-free #Android
source: sustaphones.com
#news #google #googlefreeandroid #googlefree #android #phone #cybersecurity #security #surveillance #spy #tracking #help #choose #bigtech #technology #hardware #freedom #foss #floss #opensource #software #humanrights #economy
sustaphones
Website to recommend #tools to avoid supporting #ChatControl (available in EN, FR, DE and NL)
source: exitchatcontrol.org
#tool #utility #software #encryption #communication #eu #europe #law #surveillance #spy #chat #messenger #freedom #humanrights #democracy #politics #society #help #support #tutorial #knowhow #knowledge #security #cybersecurity #news
Exit Chat Control · Become Ungovernable
DNS4EU is a privacy-first DNS resolver by the European Union and Whalebone, available for free to all European citizens under the GDPR.
The service is anonymized and offers child protection, ad blocking, DNSSEC, IPv4, IPv6, DoH, DoT, and anycast, ensuring excellent privacy and minimal latency regardless of your location.
Your browsing data stays within the EU and is protected from cyber threats without being monetized!
#dns #browser #security #privacy #eu #europe
Official site of the DNS4EU project
Experience DNS4EU, the European security ecosystem led by Whalebone. Access our free Public Service for private browsing or upgrade to DNS4GOV for professional-grade government and critical infrastructure protection.joindns4.eu
We all know the APT numbers for #FancyBear and #CozyBear — #APT28 and #APT29. Both are attributed to Russian #intelligence. #APT1 through 27 are all from #China. Only the #EquationGroup doesn’t have an official APT number? Wake up, you sleeping sheep—we’re being thoroughly taken for a ride here. The Equation Group—run by the #NSA or #CIA — is probably the most dangerous group in the world, and yet it’s the one that doesn’t appear under any number on the #APT list? Who are you trying to fool here when it comes to #cybersecurity?
see: attack.mitre.org/groups/index.…
#news #conspiracy #snowden #surveillance #spy #usa #russia #thread #danger #warning #fail #security #cybersecurity #internet #online #hack #hacker #software #exploit #cyberattack #cybercrime #world #worldorder #censorship #deepstate
#meme #cybersecurity #chat #chatcontrol #security #eu# europe #politics #message #technology #spy #surveillance #problem #freedom #privacy #parliament #democracy #vote #ethics #future
EasyOptOuts and 404 Media discovered that Apple's Hide My Email, a popular iCloud feature that allows users to receive emails without revealing their personal email address, has a vulnerability which makes the real email address publicly discoverable.
The vulnerability has been reported a year ago and is still present.💔
Source: mashable.com/tech/apple-hide-m…
#privacy #apple #cloud #email #security #software #vulnerability #exploit #tracking #hacking #mac #macos #ios #iphone #communication
Apple’s ‘Hide My Email’ feature is reportedly leaking email addresses
The exploit has reportedly existed for more than a year.Matt Binder (Mashable)
Stegano 2.5.0: reversible data hiding technique based on histogram shifting
Stegano 2.5.0 is out! 🎉
This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.
Thanks to Eesh Saxena for the contribution!
github.com/cedricbonhomme/Steg…
Release Release 2.5.0 · cedricbonhomme/Stegano
Added a reversible data hiding technique based on histogram shifting (stegano.rdh), with a stegano-rdh command line tool. Unlike LSB, the original cover image can be recovered exactly after the mes...GitHub
🚀 Vulnerability-Lookup 5.4.0 is out — and it speaks VEX!
GitHub - vulnerability-lookup/vulnerability-lookup: Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD).
Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure ...GitHub
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository…Sasi Levi (Noma Security)
Any signed GitHub commit can be copied, without the author's secret key, creating a distinct commit with an identical tree, metadata, a valid signature, and a "Verified" badge
New Research: A "Verified" GitHub Commit Is NOT Unique
Git identifies every object by a hash of its contents, and for a commit that hash covers the tree, the metadata, the message, and the raw bytes of any signature.International Cyber Digest
If you use windows. Stop
youtube.com/shorts/kOoP4BSATJs
#security #privacy #windows #microsoft
- YouTube
Bekijk je favoriete video's, luister naar de muziek die je leuk vindt, upload originele content en deel alles met vrienden, familie en anderen op YouTube.www.youtube.com
Vulnerability-Lookup 5.3.0 released
Bug: /api/kev/ pagination returns intermittent 500 for some page/per_page combinations and duplicate KEV UUIDs compared to metadata.count
Actual behavior When downloading KEV catalogs from the public Vulnerability-Lookup instance using: GET /api/kev/?vulnerability_lookup_origin=&page=N&per_page=M we are seeing two related issue...lordraiden (GitHub)
Politician who investigated spyware abuses had his phone hacked with Pegasus spyware
Politician who investigated spyware abuses had his phone hacked with Pegasus spyware | TechCrunch
A government customer of NSO Group used the company's Pegasus spyware to hack into the phone of a European politician, who at the time was serving on an EU committee tasked with investigating the spyware industry.Zack Whittaker (TechCrunch)
A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers
A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers
The news outlet changed its tip line this week, but has not informed potential sources or the public of the breach.Murtaza Hussain (Drop Site News)
Vulnerability Report - June 2026
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
The digital economy runs on Open Source Software (OSS), with an estimated 90\% of modern applications containing open-source components.arXiv.org
RustDuck: An In-Depth Analysis of a Two-Stage Botnet
RustDuck: An In-Depth Analysis of a Two-Stage Botnet
Overview Since February 2026, the XLAB large-scale network threat perception system has detected a new malware family active in cyberspace that adopts a Loader + Core (two-stage loading) architecture.Wang Hao (奇安信 X 实验室)
A new KEV Catalog built from real-world exploitation data !
We are excited to share the result of a fruitful collaboration with The Shadowserver Foundation: a new Known Exploited Vulnerabilities (KEV) Catalog (BCP-07 compliant) built directly from their global honeypot telemetry.
Most KEV catalogs tell you what is being exploited. This one is grounded in observed exploitation attempts captured across Shadowserver's worldwide honeypot sensor network. When a vulnerability is exploited against one of their honeypots, it becomes an attributable, structured GCVE-EU BCP-07 KEV assertion, complete with evidence typing (honeypot), exploitation signals (in_the_wild_attempts), and timestamps indicating when exploitation was first and last observed.
A huge thank-you to the Shadowserver team, and especially to Piotr Kijewski, for their support and collaboration.
Vulnerability-Lookup
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.vulnerability.circl.lu
We Can Still Stop California’s 3D Printer Surveillance Scheme
eff.org/deeplinks/2026/06/we-c…
#tech #technology #news #technews #security #privacy #3dprinting #Surveillance
We Can Still Stop California’s 3D Printer Surveillance Scheme
Ignoring EFF’s warnings about the dangers and impossibility of implementing a new mandate for 3D print surveillance software, the California State Assembly has signed off on legislation to do just that.Electronic Frontier Foundation
🚨 They are bringing back #ChatControl 🚨
Metsola doesn't understand that no means no.
Discussion is scheduled for Monday, so act now: fightchatcontrol.eu/
#No2Surveillance #Privacy #Security
Fight Chat Control - Protect Digital Privacy in the EU
Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.fightchatcontrol.eu
FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances - SecurityWeek
PixelSmash is a vulnerability in the FFmpeg framework that can be exploited via crafted media files for remote code execution.Ionut Arghire (SecurityWeek)
«A #security notice sent out Monday said that the exposed data included employee’s full AI prompts and transcriptions, performance data, and even private conversations. The leak allowed the data to be accessible to any employee inside the company»
Even internally they leak data like it's a sport, because privacy don't matter. #Meta just keeps screwing company morale.
Meta's Program That Spies on Every Employee's Computer Just Blew Up in Its Face in Spectacular Fashion
futurism.com/artificial-intell…
Meta's Program That Spies on Every Employee's Computer Just Blew Up in Its Face in Spectacular Fashion
A Meta initiative to spy on employee's computers to gather data for training has caused an internal leak at the company.Frank Landymore (Futurism)
