flomb - @fl0mb.bsky.social

57 posts

flomb - @fl0mb.bsky.social

flomb - @fl0mb.bsky.social

@flomb_

https://t.co/EaIY9AfpBu

Katılım Mart 2019
1.9K Takip Edilen158 Takipçiler
flomb - @fl0mb.bsky.social retweetledi
pfiatde
pfiatde@pfiatde·
Sometimes a stupid idea get stuck in your head. And will not disappear after a while. Anyway, here is a new blogpost, just a little hoax this time. badoption.eu/blog/2026/02/2…
pfiatde tweet media
English
1
4
12
704
flomb - @fl0mb.bsky.social retweetledi
OmerAF
OmerAF@omer_asfu·
👼GatewayToHeaven (CVE-2025-13292). I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users). Below is the full breakdown of the exploit chain⛓️
OmerAF tweet mediaOmerAF tweet media
English
12
112
564
61.5K
flomb - @fl0mb.bsky.social retweetledi
CODE WHITE GmbH
CODE WHITE GmbH@codewhitesec·
You like technical deep dives into binary exploitation and crazy heap wizardry? Then you'll like our blog post by @0xor_solo about unauth'ed RCE in NetSupport Manager aka CVE-2025-34164 & CVE-2025-34165 code-white.com/blog/2026-01-n…
English
0
52
140
17.9K
flomb - @fl0mb.bsky.social retweetledi
CODE WHITE GmbH
CODE WHITE GmbH@codewhitesec·
Our 2024 applicants challenge is officially #roasted: the full BeanBeat × Maultaschenfabrikle walkthrough is now online. Unwrap the write-up at apply-if-you-can.com/walkthrough/20… and revisit the hacks that escalated from cold brew to full breach.
English
0
12
34
2.5K
flomb - @fl0mb.bsky.social retweetledi
m1tz
m1tz@_m1tZ·
Did you encounter the Supabase? Might wanna try my newest tooling or have a read about quickwins? There you go: blog.m1tz.com/posts/2025/10/…
English
0
4
7
468
flomb - @fl0mb.bsky.social retweetledi
Solar Designer
Solar Designer@solardiz·
Just out of stealth mode last week, @TeamCyata reports on their "deliberate, weeks-long effort [...] to uncover logic-level vulnerabilities" in HashiCorp Vault and CyberArk Conjur. And uncover they did. cyata.ai/blog/cracking-… cyata.ai/blog/exploitin…
Cyata@TeamCyata

Vaults are trusted by default. We found 14 zero-days that challenge that trust. RCEs. Auth bypass. Root token theft. 🔎Read the disclosure: cyata.ai 🎙️ See us at #BlackHat2025 Booth 6316 #VaultFault #Cybersecurity #ZeroDay #CISO #HashiCorpVault #CyberArk #Infosec

English
1
5
9
1.7K
flomb - @fl0mb.bsky.social retweetledi
xEHLE
xEHLE@xEHLE_·
New writeup: Early last month, @samwcyo, @sshell_, and I found a Django ORM injection in an online shooter game that let us steal cryptocurrency from the game's wallet. Read the blog post here: blog.p1.gs/writeup/2025/0…
English
35
77
269
19.7K
flomb - @fl0mb.bsky.social retweetledi
Source Incite
Source Incite@sourceincite·
Here is a really cool blog post by wasamasa whos is a past student of our FSWA class: emacsninja.com/posts/cve-2025…. You can find them on Mastodon: @wasamasa/" target="_blank" rel="nofollow noopener">lonely.town/@wasamasa/
English
0
10
26
5.9K
flomb - @fl0mb.bsky.social retweetledi
James Kettle
James Kettle@albinowax·
"Funky chunks: abusing ambiguous chunk line terminators for request smuggling" - quality research by @__w4ke! Also thankfully it doesn't overlap with my upcoming presentation 😅 w4ke.info/2025/06/18/fun…
English
1
45
203
13.9K
flomb - @fl0mb.bsky.social retweetledi
frycos
frycos@frycos·
A quick-and-dirty late night blog post on discovering an nday variant in Zyxel NWA50AX Pro devices frycos.github.io/vulns4free/202…
English
2
23
56
8.3K
flomb - @fl0mb.bsky.social retweetledi
Trail of Bits
Trail of Bits@trailofbits·
Three unexpected attack scenarios: 1. Marshaling private data with misconfigured tags 2. Parser differentials in a microservices architecture 3. Cross-format confusion attacks (JSON→XML) blog.trailofbits.com/2025/06/17/une…
English
2
35
135
21.2K
flomb - @fl0mb.bsky.social retweetledi
MrBruh
MrBruh@mister_bruz·
One-Click RCE in ASUS’s Preinstalled Driver Software mrbruh.com/asusdriverhub/
English
2
20
82
21.1K
flomb - @fl0mb.bsky.social retweetledi
c1sc0
c1sc0@C1sc01·
Here is a short writeup for my recently discovered CVE: hesec.de/posts/cve-2025…
English
1
2
15
425
flomb - @fl0mb.bsky.social retweetledi
CODE WHITE GmbH
CODE WHITE GmbH@codewhitesec·
Yes, we're beating a dead horse. But that horse still runs in corporate networks - and quietly gives attackers the keys to the kingdom. We're publishing what’s long been exploitable. Time to talk about it. #DSM #Ivanti code-white.com/blog/ivanti-de…
English
0
50
108
16.3K