๐๐ผ๐ถ๐ป ๐ผ๐๐ฟ ๐น๐ถ๐๐ฒ ๐๐ฒ๐ฏ๐ถ๐ป๐ฎ๐ฟ ๐ผ๐ป ๐ ๐ฎ๐ฟ๐ฐ๐ต ๐ฒ๐๐ต!
Discover how to eliminate debugging inefficiencies and accelerate vulnerability research with time travel analysis.
Register now ๐
https://www.linkedin.com/events/exploitingaroutervulnerabilityw7299810055170805761/
#cybersecurity #webinar #vulnerability #malware #reverseengineering
I wonder what the person who took that famous photo of the Doge Shiba Inu makes of all this now?
High level diff of iOS 18.4beta1 vs iOS18.4beta2 ๐
https://github.com/blacktop/ipsw-diffs/blob/main/18_4_22E5200s__vs_18_4_22E5216h/README.md
Adapt to removal of Windows Arm32 .NET debugging
> .NET support for Windows on Arm32 has ended. Debugging support for this platform will be removed from Visual Studio 2022 starting with the 17.14 update.
I'm excited to share CVE Crowd's Top 5 Vulnerabilities from February 25!
These five stood out among the 352 CVEs actively discussed across the Fediverse.
For each CVE, Iโve included a standout post from the community.
Enjoy exploring! ๐
#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking #CVE #CveCrowd
Listen, I'm not going to pretend that I'm even remotely surprised, but I will tell you that this is a slap in the face to every person in the infosec community that has worked to track and thwart Russian APTs for the last several decades.
https://www.theguardian.com/us-news/2025/feb/28/trump-russia-hacking-cyber-security
Happy #303day to all who celebrate.
It took me a whole year to finally upload last year's jam...
today, i have IP-blocked the entirety of alibaba cloudโs IPv4 range (47.80.0.0/13, 47.74.0.0/15, 47.76.0.0/14
). And you could ask - domi, what the hell, thatโs kinda sorta a lot of addresses?
fucking watch this: thatโs sakamoto Mk5, my Ryzen 9 7950X3D server. Never before have I seen forgejo taking this much CPU.
Theyโve generated 9GB of access logs (!) and 230GB of generated tarballs (!!!) before I got to my laptop, investigated and ip-banned them. Iโm positive that most forgejo deployments in existence wouldnโt survive this.
If you needed another reason to fuck generative AI today - hereโs one
So I didn't know, but Europe already has a backup of PubMed, the database of biomedical research publications. The US PubMed broke down over the weekend. And here is our alternative: https://europepmc.org/ #pubmed #pmc
@buherator kdnet has had support for the virtio NIC for years.
In Windows just configure kdnet as you would with any other supported NIC and, in QEMU, configure the virtual NIC as
-netdev user,id=net0 -device virtio-net,netdev=net0,disable-legacy=on
๐ New Blog & PoC Release: Abusing IDispatch for COM Object Access & PPL Injection ๐
I've developed a PoC exploit that demonstrates an interesting bug class in COM servers implementing IDispatch, allowing indirect object creation within the target process. Specifically, by leveraging the ability to instantiate STDFONTโa legacy COM class not designed for cross-process useโI was able to achieve code injection into a Windows PPL (Protected Process Light) process. This technique enables interaction with protected processes like LSASS.
This research builds on the work of @tiraniddo who identified how COM object manipulation via IDispatch can lead to unexpected process interactions. My PoC takes this concept further by demonstrating its practical impact through registry manipulation and .NET payload execution inside PPL processes.
๐ Blog Post: https://mohamed-fakroud.gitbook.io/red-teamings-dojo/abusing-idispatch-for-trapped-com-object-access-and-injecting-into-ppl-processes
๐ป PoC & Source Code: https://github.com/T3nb3w/ComDotNetExploit
Key Highlights:
๐น Exploiting IDispatch in OOP COM servers
๐น Abusing STDFONT instantiation for process injection
๐น Achieving code execution inside PPL and accessing LSASS
๐น Bypassing SEC_IMAGE integrity checks
๐น Leveraging OnlyUseLatestCLR for compatibility
I keep hearing that Sup shouldn't exist because X exists.
I made Sup to replace Snapchat and Facebook Messenger in my own friend group
I think it might be useful to other friend groups or families too, being that you can join with an email or Pixelfed/Loops or Mastodon account
Not only that, but Sup will be modular, allowing for rich integration with pretty much any other chat platform (Signal, Matrix, Delta, etc)
It's like Beeper, but federated and open source. ๐