OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).
Both have a very high CVSS and are likely to be exploited.
https://onapsis.com/blog/sap-overpass-remediation/
https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
Hey everyone! ๐น
> Lalu here: Openly sharing @entrypoint_fr 's open CFP & registration to help them kick-start nicely this new cool and red-focused event!
> Finding the right speakers and audience is hard, even more now that AI makes things feel "less special",. But some people are still making this happen, let's join forces! ๐
---
Join & Apply to Entrypoint by @synacktiv a conference entirely dedicated to **Red Teaming**, coming to Paris on March 19โ20, 2027 at Le Dernier รtage.
Expecting 500 attendees from around the world, all talks will be delivered in **English** to bring together as many international profiles as possible ๐
๐ Venue & Details:
- Event page: https://entrypoint.fr/
- Location: https://ledernieretage.paris/
๐ค Call for Papers
If you have a compelling topic to share, we'd love to hear from you. Submissions are open on the following tracks:
- Advanced Pentesting & Red Teaming : ActiveDirectory, Cloud (AWS/Azure/GCP) exploitation, container escapes, lessons learned (full scenario analysis).
- Supply Chain Attacks : Attacks targeting dependency managers (npm, pip, composer), secrets leaked on public platforms (GitHub).
- CI/CD : Advanced pipeline exploitation, loot techniques.
- Physical Intrusion : Methodologies to reach internal networks / target companies physically.
- Malware & C2 : Evasion techniques, obfuscation, custom C2 infrastructure, implant development.
- Post-Mortem Analysis : Analysis of threat actor exploitation methodologies, complex compromise chains.
- AI-assisted offensive security : Offensive use of AI including agentic red teaming, model-assisted vulnerability research, and AI-driven exploitation in real operations.
๐ Training Days
4 days of hands-on training (Monday, March 15 โ Thursday, March 18) covering the same themes.
๐ Speaker Perks
To make it as smooth as possible for speakers, here's what is covered:
- Travel expenses
- Accommodation : hotel booked for the duration of the conference
- Speaker dinner : a dedicated evening to hang out with fellow speakers
โ๏ธ Questions
Feel free to ping @_remsio_ on X/discord or official @entrypoint_fr accounts directly if you have any questions or need more details!
See you in Paris! ๐ซ๐ทโ๏ธ
๐ญ๐บ #Hungary has expelled 10 Russian diplomats who "were engaged in activities in Hungary that are unacceptable for diplomats under the Vienna Convention," Foreign Minister Anita Orbรกn said in a statement on Tuesday.
https://tvpworld.com/95280737/hungary-expels-10-russian-diplomats-foreign-minister-says
almost every idea iโve had in my life is better than this can i get a few million dollars of investment (also wtf is wrong with my instagram ads)
Please boost this for as much reach as possible.
Parton Kirk, where #physics genius James Clerk Maxwell is buried, is being put up for sale. The community is attempting a buy out to save this kirk for science and the local community. They have until 31st of October to secure the funds.
Here's the crowd funder link. You can help prevent this kirk from falling into private hands.
Hello London ๐ฌ๐ง
The Phrack team is here and we left our mark around the city.
If you can find any of these stickers, email us for a chance of getting a physical copy of Phrack 73 delivered to your doorstep.
Send proof to hunt@phrack.org and have fun!
Iโve factored the RSA keys of a Certificate Authority...
โฆ from the 90s.
docker compose up up down down left right left right b a start
Someone recreated the Windows 98 Disk Defragmenter in your browser.
Multiple drives, different speeds, mechanical HDD sounds, moving colored blocks...
And a Realistic mode where "Windows" occasionally touches the disk, forcing a rescan and losing some progress.
It's not true nostalgia unless you recreate the suffering too.
You have until the 8th at 23:59 to submit to unprompted! What are you waiting for?
This affects the Fediverse.
This affects the Internet.
This is the equivalent of the "rubber hose method" of decryption.
All technical solutions (read: all technology) is subject to politics. To political power. To political interactions.
You cannot rely on purely technical approaches. You have to have social approaches, too. Like. Actual policy and procedure geared around social and political group dynamics.
Like. How will we react when the US Govt requires that @jerry to shut off infosec.exchange servers.
Or how we'll react when a specific Mastodon server is declared part of a terrorist infrastructure. Will federating with it mean any other Mastodon server is now part of the officially designated terrorist network (what then of people that federate with a server that federates with a server that is classified as part of a terrorist network. And so on)
You cannot carry the conceit that tech alone or a purely technical approach will save you.
I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.
It was brought to my attention that Real Hack History, a youtube channel, has been uploading documents, audio and video related to hacking history to the Internet Archive and they deserve a little collection. I'm making them for them now but you can look at their excellent uploads immediately.
Really good stuff. Really well sourced.
Hot take:
a 20 kloc PR - even if it fixes the problem or adds the feature perfectly - is spam.
it is spam because it overwhelms the reviewer, who is then unable to reasonably perform their duty of actually comprehending and checking the code to make sure it does what it's supposed to.
Micropatches released for "ResetNightmare" Windows Kerberos Elevation of Privilege (CVE-2026-27912) https://0patch.com/blog/micropatches-released-for-resetnightmare-windows-kerberos-elevation-of-privilege
I'm launching a series of short posts about the tools I've built to automate
reverse-engineering workflows. I've used them to analyze protections such as
SafetyNet, DexProtector, iXGuard, and Arxan.
First up: MCStone, a clean & efficient assembler and disassembler built on LLVM's MC layer.
An interesting paper: Frontier Modelsโ Vulnerability Patches are Often
F.L.A.W.E.D.
https://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf