Advertisement · 728 × 90

Posts by ocdsec

A nice workaround against my YARA rule.
kuwaitist.github.io/posts/Patchi...

2 months ago 9 2 0 0

A Chinese think tank has published a hit piece on seven cybersecurity and policy experts specializing in Chinese cyber operations

www.guancha.cn/xinzhiguanch...

4 months ago 5 4 1 0
Preview
Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors

Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors

4 months ago 4 1 0 0
Preview
GitHub - pard0p/LibIPC: LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes. LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes. - pard0p/LibIPC

LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes.

github.com/pard0p/LibIPC

5 months ago 5 4 1 0
Update on OpenBSD Networking Performance Improvements EuroBSDCon 2025 Since my previous talk about this topic in 2022 major improvements in the OpenBSD network stack have been achieved. The socket API has been unlocked in the kernel. This means that multiple userland ...

Slides from Alexander Bluhm (bluhm@)'s talk "Update on #OpenBSD Networking Performance Improvements" today at #EuroBSDcon 2025.

www.openbsd.org/papers/eurob...

6 months ago 1 2 0 0
Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543) - Help Net Security The CVE‑2025‑6543 NetScaler ADC vulnerability - patched in late June 2025 - has been exploited as a zero-day vulnerability since May 2025.

Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543)

8 months ago 1 1 0 1
Preview
New Batavia spyware targets Russian industrial enterprises Since March 2025, fake contract emails have been spreading Batavia spyware in targeted attacks on Russian organizations.

New Batavia spyware targets Russian industrial enterprises

9 months ago 2 2 0 0
Advertisement
Preview
Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User

Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User

10 months ago 3 2 0 0
Powershell: after 5 "type .\5\test.txt" calls, the test.txt file is a symlink to win.ini
CMD: A single "type .\6\test.txt" call results in every single file being printed, including the final win.ini symlink

Powershell: after 5 "type .\5\test.txt" calls, the test.txt file is a symlink to win.ini CMD: A single "type .\6\test.txt" call results in every single file being printed, including the final win.ini symlink

From over at the Bad Place:
There's an interesting NTFS symlink attack outlined here:
dfir.ru/2025/02/23/symlink-attac...

Basically, if an NTFS filesystem is corrupted in a way to provide duplicate file names, Windows will […]

[Original post on infosec.exchange]

1 year ago 16 13 1 0
cybercrime zeroday faded tee

cybercrime zeroday faded tee

cybercrime
but its bigger
and on both sides.

1 year ago 49 9 6 2
Preview
GitHub - DarkSpaceSecurity/RunAs-Stealer: RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging - DarkSpaceSecurity/RunAs-Stealer
1 year ago 3 1 0 0

Well there are lots of people who have been treating Google and many others like that for ages, and this is why the solutions are already out.

You lose convenience the deeper you go, but the solutions are there.

1 year ago 0 0 1 0

well they exist ^^

1 year ago 0 0 1 0
Post image

VulnCheck has extracted and made a list of all the CVEs mentioned in a recent leak from the internal Matrix chat server of the BlackBasta ransomware group.

The list includes 62 vulnerabilities.

VulnCheck says the group focuses on CVEs with already public exploits

vulncheck.com/blog/black-b...

1 year ago 26 8 1 0

I cannot overstate the value of being in community with other activists right now. It is what gives me the strength to get up in the morning and fight fascism.

1 year ago 1826 203 63 20
Preview
Fake GitHub projects distribute stealers in GitVenom campaign Kaspersky researchers discovered GitVenom campaign distributing stealers and open-source backdoors via fake GitHub projects.

"Over the course of the GitVenom campaign, the threat actors behind it have created hundreds of repositories on GitHub that contain fake projects with malicious code"

Campaign delivers an infostealer, obviously. The threat-du-jour these days

securelist.com/gitvenom-cam...

1 year ago 9 3 0 0
Preview
Detonating Beacons to Illuminate Detection Gaps — Elastic Security Labs Learn how Elastic Security leveraged open-source BOFs to achieve detection engineering goals during our most recent ON week.
1 year ago 3 1 0 0
Advertisement
Preview
GitHub - antitree/seccomp-diff Contribute to antitree/seccomp-diff development by creating an account on GitHub.

I just finished our #shmoocon talk on container security. Here's my seccomp bpf disassembler and diffing tool.

github.com/antitree/sec...

1 year ago 38 11 0 1
Post image

Diving into ADB protocol internals:

part 01: www.synacktiv.com/publications...

part 02: www.synacktiv.com/en/publicati...

#adb #mobile #protocol #informationsecurity #cybersecurity #reverseengineering

1 year ago 3 1 0 0
Preview
PentesterLab Blog: Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150 Discover how a code review uncovered a JWT algorithm confusion vulnerability (CVE-2024-54150). Learn key insights to enhance your security skills and spot vulnerabilities effectively.

These are some really nice blog posts regarding algo confusion bugs in JWT by @pentesterlab.com pentesterlab.com/blog/jwt-alg... & pentesterlab.com/blog/another... nice one @snyff.pentesterlab.com!

1 year ago 20 5 1 0
Preview
Курс рубля рухнет до 200 за доллар: экономист в РФ предупредил о приближении катастрофы – СМИ В России скопилась огромная рублёвая масса, которая уже вскоре хлынет на рынок и вызовет массовый спрос на валюту, это обвалит курс рубля как минимум до 200 за доллар.

Ruble to fall to 200 per dollar: Russian economist warns of approaching catastrophe – media

читайте подробнее на сайте "Диалог.UA": www.dialog.ua/business/306...

1 year ago 15 8 4 0
Preview
Weaponizing WDAC: Killing the Dreams of EDR
1 year ago 5 1 0 0
Preview
CVE-2024-51479: Next.js Authorization Bypass Vulnerability Affects Millions of Developers Find out about the Next.js vulnerability CVE-2024-51479 that could have exposed sensitive data. Take necessary measures to secure your Next.js application.

Wow, a fairly serious auth bypass in Next.js, a super popular frontend framework:

"If a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed."

securityonline.info/...

1 year ago 11 4 0 0

The #OpenBSD Foundation is currently at ~$230,280 (65%) raised of the $350,000 goal for their 2024 Fundraising Campaign, and it's nearly the end of December. 🐡

www.openbsdfoundation.org/campaign2024...

www.openbsdfoundation.org/donations.html

Donations fund events for developers, infra. costs.

1 year ago 1 1 0 1
Advertisement
Various Ways to Be an Asshole with Runtime PE Decryption I am currently procrastinating undoing the mess I made with CMake files for a bigger project I’m working on. It’s not hard– it’s just annoying, and I have no one to blame but myself. I did this intent...

I did a blog instead of working on my projects again. This time a maldev blog talkin' about PE runtime decryption and other ways to be an asshole to the analyst. amethyst.systems/blog/posts/v... #infosec #malware

1 year ago 26 10 0 0
Objective by the Sea v7.0 - Day 2
Objective by the Sea v7.0 - Day 2 YouTube video by Objective-See Foundation

The #OBTS day 2 livestream is on!

www.youtube.com/watch?v=Nm0z...

1 year ago 2 2 0 0