Flipper Zero eBook

472 posts

Flipper Zero eBook banner
Flipper Zero eBook

Flipper Zero eBook

@flipperzerobook

Hack Like A Pro With Flipper Zero. Author Peter Logan. Available at Amazon, Apple and Kobo.

Tham gia Eylül 2025
4.1K Đang theo dõi429 Người theo dõi
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@malmoeb Great research. The use of trusted runtimes can make detection significantly more difficult.
English
0
0
0
9
Stephan Berger
Stephan Berger@malmoeb·
We recently analyzed an interesting piece of malware that utilizes the legitimate JavaScript runtime, Deno. The malware was used as a first-stage implant after the user was tricked into downloading and running the malware. Read the full article here: labs.infoguard.ch/posts/anatomy_…
English
1
2
7
740
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@0x0SojalSec SSRF continues to prove that seemingly simple vulnerabilities can have serious consequences. 🔥
English
0
0
0
9
Md Ismail Šojal 🕷️
The entry point to a full RCE chain. It’s not just another SSRF. The real story behind the CVE-2026-35273 chaos: Critical Alert: CVE-2026-35273 (CVSS 9.8) Unauthenticated RCE via SSRF in Oracle PeopleSoft PeopleTools 8.61 & 8.62. If you run PeopleTools 8.61 or 8.62 to check for the emergency patch immediately , CVSS 9.8. Already exploited in the wild before disclosure, Oracle dropped an out-of-band patch.
watchTowr@watchtowrcyber

Noise, hysteria, confusion, and AI slop surround CVE-2026-35273 - we believe this is the first-stage SSRF in the Oracle PeopleSoft RCE chain being flung around. We will share the full chain when we feel the time is right, and when we're bored of the vibecoded PoCs. Speak soon.

English
1
2
7
1.9K
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@GithubProjects Interesting project. DPI has been a major topic in internet freedom and network engineering discussions for years.
English
0
0
0
43
GitHub Projects Community
GitHub Projects Community@GithubProjects·
SpoofDPI is a proxy tool designed to bypass internet censorship by neutralizing Deep Packet Inspection. - Simple proxy tool for neutralizing DPI techniques - Available through GitHub and official package managers - Inspired by Green Tunnel and GoodbyeDPI - Kernel based circumvention alternative available via DPIBreak Explore it here: osp.fyi/spoofdpi
GitHub Projects Community tweet media
English
4
46
342
16.4K
Winston Ighodaro
Winston Ighodaro@Officialwhyte22·
Another day to on Malware Analysis Labs
Winston Ighodaro tweet media
English
3
11
88
5.5K
David Bombal
David Bombal@davidbombal·
What is an IDOR? Google and Uber got hacked this way. Discover how a simple IDOR vulnerability can dump an entire database. Learn why this basic API bug still earns massive bug bounty payouts in 2026 from tech giants like Google and Meta. This video is sponsored by @ThreatLocker
English
3
14
79
3.8K
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@h4x0r_dz Great example of how similar vulnerability patterns can appear across completely different applications. 🔍
English
0
0
0
16
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@0x534c Prompt injection is becoming one of the most important AI security challenges. 🤖🔒
English
0
0
0
24
Steven Lim
Steven Lim@0x534c·
🚨 Detecting External Copilot Prompt Attacks 🚨 Varonis’ latest SearchLeak research shows how attackers can chain P2P injection, HTML injection, and SSRF to coerce enterprise Copilot into leaking sensitive data. varonis.com/blog/searchleak Although Microsoft has patched CVE‑2026‑42824, defenders now face a new reality: knowing the URL format that can trigger Copilot prompts means adversaries can weaponize links in email, Teams, and Office documents to break guardrails and exfiltrate data. To counter this, defenders must monitor for suspicious link activity that could coerce users into executing external Copilot prompts. Below is a KQL detection designed to surface potential external threats where attackers attempt to force Copilot into unsafe prompting behavior. github.com/SlimKQL/Detect… #Cybersecurity #CopilotPrompt #DataExfiltration
Steven Lim tweet media
English
1
21
91
5.4K
Code4 Cybersecurity
Code4 Cybersecurity@Code4_CyberSec·
Top 5 Free Tools Every Threat Hunter Should Have - Velociraptor - Sigma - Atomic Red Team - Loki - OSQuery </CODE4> #DFIR #SOC #L1 #L2
Code4 Cybersecurity tweet mediaCode4 Cybersecurity tweet mediaCode4 Cybersecurity tweet media
English
1
2
37
1.9K
The Hacker News
The Hacker News@TheHackersNews·
⚡ Developers are being targeted where they work: GitHub repos VS Code projects npm packages Packagist Crypto/Web3 lures Researchers say North Korea-linked activity sent 250+ phishing emails to targets at nearly 100 organizations, aiming to steal credentials, wallet data, keys, and access. Read ➝ thehackernews.com/2026/06/north-…
The Hacker News tweet media
English
5
9
36
7.5K
Anastasis Vasileiadis
Anastasis Vasileiadis@Anastasis_King·
📱💀 Your Phone Can Become a Cybersecurity Lab… Most people use Termux for basic commands… but few realize how powerful it can become. 👀 In this guide, I’m sharing 15 useful Termux tools that can help cybersecurity enthusiasts better understand networking, web security, automation, recon, and mobile learning workflows — all from a phone. ⚡ 🧠 Your smartphone might be more powerful than you think. ⚠️ Educational & authorized lab environments only. 💬 Comment “TERMUX” for the full list. #Termux #CyberSecurity #Android #Linux #InfoSec
Anastasis Vasileiadis tweet media
English
5
18
104
1.8K
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
💡 SSRF hides where devs don't expect outbound requests - Referer headers, SVG uploads, XML parsers. These sinks survive in production because nobody thought to protect them. We mapped them all 👇 yeswehack.com/learn-bug-boun…
English
1
12
69
2K
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@tom_doerr OSINT and digital footprint analysis continue to be invaluable for both security professionals and researchers.
English
0
0
0
9
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@three_cube Reconnaissance is usually the first step. Understanding what information is exposed is key to defending it.
English
0
0
0
11
OccupytheWeb
OccupytheWeb@three_cube·
Mobile Network Hacking: Reconnaissance on Your Local Mobile Network Hackers can gather information on your local mobile network to: 1. Intercept Your Mobile Traffic 2. Track Your Location 3. Deny Use Access to the Mobile Network (DoS)
OccupytheWeb tweet media
English
1
14
47
1.6K
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@Mandiant The most dangerous intrusions are often the ones that blend into normal administrative activity.
English
0
0
0
10
Mandiant (part of Google Cloud)
PRC-nexus actor UNC6508 targeted North American research, exploiting REDCap servers to deploy INFINITERED malware. The actor remained undetected for over a year and abused enterprise admin tools for covert data exfil. Analysis, guidance and IOCs ➔ cloud.google.com/blog/topics/th…
Mandiant (part of Google Cloud) tweet media
English
2
27
88
7K
Nextron Research ⚡️
Nextron Research ⚡️@nextronresearch·
We found a WHQL-signed kernel module that abuses Windows firmware table registration as a covert kernel↔user communication channel. Instead of exposing a device object and IOCTL interface, it registers a custom firmware provider ("BSBS"), allowing userland interaction through standard Windows firmware table APIs. The implementation is compact and stealthy, supporting memory allocation, memory copy operations, and indirect function dispatch from user mode into kernel context. An unusual example of firmware table registration being repurposed as a hidden ring3↔ring0 communication mechanism. Name: NewDriverMMM SHA256: 1d9224a72e64bb2aad289edc81ea0720c764511c3e2b5beb5d0d5ce82a719abd fdb3907ddda9ff9bd9ec4f8bd29aad823da77b5b3bf599813fecd034b0221189 SpcSpOpusInfo: 深圳市奥联信息安全技术有限公司 Telemetry: China 🇨🇳, Japan 🇯🇵
Nextron Research ⚡️ tweet mediaNextron Research ⚡️ tweet media
English
2
19
69
7.8K
Flipper Zero eBook
Flipper Zero eBook@flipperzerobook·
@co11ateral The most dangerous findings are often the small ones that can be chained together.
English
1
0
0
26
Co11ateral
Co11ateral@co11ateral·
Speeding up AD Pentests with ADScan and ADPulse Active Directory pentesting often starts with the same repetitive checks, but ADScan and ADPulse can help you automate them. The pentest does not always end with full domain compromise. Success is not measured by whether you obtain Domain Admin privileges, but by how well you identify and communicate risks that could impact the organization. Sometimes the most critical findings involve exposed data, weak configurations, or small mistakes that could later be chained into larger attacks. hackers-arise.com/offensive-secu… @three_cube @_aircorridor #pentesting #redteam
Co11ateral tweet media
English
1
23
110
3.5K