Posts of last few hours
Please support the site operations by clicking ads.
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
Checkov is a static code analysis tool for infrastructure as code (IaC) and also a softw
https://buaq.net/go-443425.html
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
https://darkwebinformer.com/daily-dose-of-dark-web-informer-september-18th-2026/
New releaseSep 19, 2026Hardware tool for RFID/NFC analysis, emulation, sniffing, and cloning. Suppor
https://buaq.net/go-443423.html
Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project
https://buaq.net/go-443424.html
A forum actor posting as ChimeraZ is selling what they claim are partial datasets associated with FFTIR, SIA and Armurerie Lavaux.
https://darkwebinformer.com/fftir-sia-and-armurerie-lavaux-dataset-claim-covers-120-158-people/
Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project
https://buaq.net/go-443421.html
JS-X-Ray is a JavaScript & TypeScript
https://buaq.net/go-443422.html
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
https://www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.
Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.
The flaws
https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html
Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project
https://buaq.net/go-443420.html
https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-942
https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-941
https://cyber.gc.ca/en/alerts-advisories/arista-networks-security-advisory-av26-940
Cloudflare's global network is immense but not limitless. As we look for small ways to trim our resource usage, we sometimes get lucky and we can cut significantly more. Here’s how we reduced one of our Pingora-based service's RAM usage with statistics.
https://blog.cloudflare.com/saving-100-tb-of-ram-with-math/
A forum actor posting as GoreSpiders has released what they claim is a database belonging to iChargePoint, a portable power-bank rental company operating automated charging-station services across the United Arab Emirates.
https://darkwebinformer.com/ichargepoint-dataset-claim-covers-154-944-user-accounts/
sslscan version 2 has now been released. This includes a major rewrite of the backend scanning code
https://buaq.net/go-443418.html
A forum actor using the handle "SaltMobile" is offering what they claim is a scraped customer dataset associated with Salt Mobile, a Swiss telecommunications provider.
https://darkwebinformer.com/salt-mobile-dataset-claim-covers-1-090-000-customer-records/
本文记录了 Hack The Box 靶机 Vintage 的完整攻防渗透过程。目标处于禁用 NTLM 的纯 Kerberos 环境下,作者从初始凭据出发,利用 Pre-Windows 2000 机器账户弱口令获取域计算机权限;随后通过 LDAP 提取并解析 gMSA 托管服务账号凭据,结合 ACL 权限为无 SPN 的服务账号手工赋予 SPN 并成功实施 Targeted Kerberoasti
https://xz.aliyun.com/news/92703
本文通过拆解六款智能渗透 Agent 的源码与真实执行链路,分析它们在状态管理、上下文控制、工具调用和证据约束上的工程设计与取舍。
https://xz.aliyun.com/news/92778
Latest Blog Posts
- 3 weeks 6 days ago
- 2 months 4 weeks ago
- 2 months 4 weeks ago
- 2 months 4 weeks ago
- 2 months 4 weeks ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago