Local #PrivilegeEscalation in Quanos SCHEMA ST4.
Vulnerabilities in the update service allow low-privileged users to execute code or overwrite files.
➡️ On‑premise versions affected
➡️ Workaround available – disable update service
➡️ SaaS not affected
👉 https://t.co/LSK6tin7KS
🚨 New advisory by @Kruxinator & Christian Hager: Local privilege escalation in @genetec 's #RabbitMQ deployment (#CVE-2026-25112)
Writable dir + missing binary + SeImpersonatePrivilege = SYSTEM via Rotten Potato 🥔
Patch available. Apply now!
🔗 https://t.co/B5vRETRqIq
#privesc
🚨 Critical vulns in dormakaba exos 9300! We’re sharing 20 CVEs in dormakaba’s physical access control system: doors can be opened without authentication with network access. Kudos to @dormakaba for excellent handling & patches.
👉 https://t.co/khdsG53EuN #ResponsibleDisclosure
The DNS Analyzer extension is now officially available in the BApp Store!
For more info on finding DNS vulnerabilities in web applications via Burp Suite, check out:
https://t.co/NLWS9ml5Pj
msldap got a public update v0.4.7(pip+github)
Added retrieval of gmsa user passwords and security descriptors
Did some fixes and other features I forgot about since the last release
Thx for @porchetta_ind supporters!
https://t.co/7vU54aO98P
Been working on some new features for PowerView, it's still a work in progress but just pushed a few, cert auth for LDAPS and StartTLS for Get-DomainObject, Get-DomainUser, Get-DomainComputer and Set-DomainObject 1/2
https://t.co/H9rrPiTZeD
And another one: Stacking of critical vulnerabilities allows unauthenticated attackers to hijack video streams in Poly's Eagle Eye Director II https://t.co/snDkxUbx4t Patch immediately! @PolyCompany#hybridworking#homeoffice#infosec@Kruxinator
Saving you 10 mins of googling. An .scr is just an .exe renamed:
copy C:\Windows\system32\calc.exe Desktop\calc.scr
rundll32.exe desk.cpl,InstallScreenSaver Desktop\calc.scr