MonitorsFour from @hackthebox_eu features PHP type juggling to dump users, CVE-2025-24367 for RCE in Cacti, and CVE-2025-9074 to abuse the Docker Desktop API and mount the Windows host drive for root. Beyond Root: a shell on Windows."
https://t.co/DtjU6qwqjB
Cracked by DrFarFar.
Quando tem isso escrito voce sabe que alem do seu pc entrar pra botnet iraniana o software que voce ta crackeando vai funcionar perfeitamente e de primeira.
#DrFarFar
Call of Duty Black Ops Decompliation is now released on GitHub!
Blog Entry: https://t.co/8F3MRoHxkR
GitHub: https://t.co/GA7ktrXmyP
#decomp#decompilation#cod#blops
Create a folder called (calc). Shift+Right click « Open PowerShell Window here » and boom you have a command injection.
@podalirius_ found two command injection vulnerabilities in Windows Explorer's context menus, both exploitable since 9 years. https://t.co/LNNTpKeDnJ
💥 Introducing "Dirty Frag"
A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail.
No race, no panic on failure, fully deterministic. ~9 years latent.
Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more.
Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation.
Details:
https://t.co/9nqku4svkY
200 root shell pra um bug escaneado. Nada mal pra 2026, me senti em 2017 de novo.
Melhor parte eh rippar e observar outros atacantes fazendo merda pelo terminal
to celebrate the release of Copy Fail and the professional way the embargo and disclosure was handled by all involved parties i have sacrificed my lunchbreak to do a quick C port (with aarch64 support and some other small things) of the original PoC
https://t.co/M08QEqVEwo