Режиссерская версия критических новостей из мира информационной безопасности 🌎 Основной канал: @cKure ☕️ или вопросы напишите нам 📨 [email protected]
This channel is part of the discussion
cKure Red appears in 6 event pages on TGList👩💻 Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities. Technical Summary: PoC: Overview: Thread: 🧵
💻😯Windows includes a file-system virtualization feature that can redirect one local path to another without modifying the original file or leaving a persistent filesystem artifact. It is implemented by bindflt.sys, the Bind Filter minifilter driver, and used legitimately by…
💀 The Eternal Jew rises with same tricks up the sleeve: ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
Exploiting CVE-2024-1065 via the Page Cache! A strategy for physical-page UAFs in MIGRATE_MOVABLE, where Dirty Pagetable and Dirty Cred don't apply. Demonstrated on the Mali GPU UAF found by Project Zero.
Exploiting CVE-2024-1065 via the Page Cache! A strategy for physical-page UAFs in MIGRATE_MOVABLE, where Dirty Pagetable and Dirty Cred don't apply. Demonstrated on the Mali GPU UAF found by Project Zero.
✅CVE-2026-63030: Unauthenticated SQL injection in WordPress core chaining to RCE. No credentials, no configuration. One endpoint: POST /wp-json/batch/v1. The REST batch endpoint builds two parallel arrays ($matches and $validation) that fall out of step when a sub-request path…