⚠️⚠️ CVE-2026-64633 (CVSS 10.0) + CVE-2026-58075 (CVSS 8.7): Unauthenticated RCE and arbitrary file read on Veeam ONE agent host
🔗FOFA Link: https://t.co/5rwRviZOqt
🎯1.1K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: title="Veeam ONE"
🔖Refer: https://t.co/GhQDWKDauu
#OSINT #FOFA #CyberSecurity #Vulnerability
⚠️⚠️ CVE-2026-68771 (CVSS 9.8): Unauthenticated RCE via unsafe pickle deserialization in ComfyUI v0.23.0.
🔗FOFA Link: https://t.co/A22dDvk4qZ
🎯419.2K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="ComfyUI"
🔖Refer: https://t.co/lQmeUNtawD #OSINT #FOFA #CyberSecurity #Vulnerability
🚨Anthropic just showed a 24-minute workshop on how to actually do prompts for Claude.
Taught by the people who built it.
Free. No registration. No paywall.
I've seen $300 courses that don't cover what they teach in the first 8 minutes.
Watch it and bookmark it now!
This is absurdly clever: there is a way you can cut Fable 5 costs by up to ~70%. Just turn Claude Code context into an image and make Fable OCR them. 😂
https://t.co/ewjdpf32yC
Stealth Browser MCP features 97 tools to bypass Cloudflare and other antibot systems.
Undetectable automation with full browser power:
- AI writes Dynamic network hooks
- Pixel-accurate element cloning
- 97 advanced tools
- https://t.co/bfKIsT0Fth
A 27B Uncensored model that built for specifically for offensive security tooling (need 12 GB)
- Fine-tuned on real bug bounty reports & CVEs
- Generates complete, ready-to-run Nuclei templates, Full CVE PoC script, Webshell upload bypass, and exploits, code reviews
- Zero refusals. Full artifacts every time.
trained with 2,541 of real bug bounty & offensive security reports.
Q6_K quant (21GB) for maximum quality on server-grade GPUs.
JWT Auth Bypass TestBed
https://t.co/qoYUYTxduT
Test your skills: 18 main tests with variations.
A proprietary tool with 40+ techniques for Brute One will be available this week to spot all these cases in the wild in a matter of seconds.
https://t.co/ThMs09G3Hp
#OPSEC365 024/365
Every Word document and PDF you create embeds your name, your computer's name, edit history, and sometimes the file path showing your folder structure.
Before you send a document to someone you don't fully trust, that metadata tells them more about you than the content does.
Right-click a document you've shared recently, check Properties or Get Info, and see what's embedded.
‼️An iOS exploit and C2 integrated attack panel called "iExploit Lab v1.0" is being advertised on a popular cybercrime forum, targeting iOS 13 through iOS 17.2.1 for $15,000.
‣ Threat Actor: OnarDev
‣ Category: Exploit / Tool
‣ Name: iExploit Lab v1.0
‣ Target: iOS 13 to iOS 17.2.1
‣ Developer: Zero Bound Workshop team
iExploit Lab is a visualized attack panel integrating C2 operations based on recent research on high-risk iOS vulnerabilities. It is not a traditional remote control tool but instead attacks iOS systems when a user visits a link via Safari.
Attack stages:
▪️ Stage 1 - Browser Attack (Stage1 terrorbird / Stage1 cassowary)
▪️ Stage 2 - PAC Bypass (Stage2 seedbell)
▪️ Stage 3 - Kernel Privilege Escalation (Stage3 Variant A / Stage3 Variant B)
Capabilities:
▪️ Break through system isolation and access all data on device
▪️ Theft of cryptocurrencies and bank information
▪️ Integrated HTTP vulnerability web server and C2 remote control server
▪️ Attack link auto-generated after server startup
▪️ Link delivered via social engineering, AirDrop, or other methods (one-click via Safari)
▪️ Connected device management panel
▪️ Operator console with real-time logging
The panel UI is in Chinese with a 5-step operational workflow: modify configuration, start services, set up connection, wait for callback, and control device. The actor notes that the two iOS 26 versions have already been patched. Proxy mode is available for earning dividends.
❗️Security researchers used a low-cost consumer satellite dish to intercept satellite signals and found massive amounts of unencrypted traffic.
Revealing:
📡 Military and government comms including GPS data
📡 Credit card transactions
📡 Phone calls and texts from remote cell towers
📡 In-flight Wi-Fi activity
Oh this is clean. A searchable, filterable RFID attack reference.
HID Prox, MIFARE, EM4100, animal tags, organized by frequency AND tool (Proxmark, Flipper, Chameleon...). This is the cheat sheet that used to live in your notes app.
Bookmark it!
you'll thank yourself on your next physical engagement.
https://t.co/XJL1B5tbkR
The Telegram Scraper script originally created by unnohwn has been updated for combined continuous scraping and message forwarding/copying. You can find the updated script here: https://t.co/qCWZiz5xRi. Option B is the new option. Option W is the new option from the previous release.