‼️🚨 BREAKING: GitHub has been compromised by TeamPCP. GitHub has confirmed the internal breach. A poisoned VS Code extension on an employee device exfiltrated ~3,800 internal repositories.
TeamPCP is already selling the data on a cybercrime forum.
📛 commix
🧠 Commix is an open-source penetration testing tool that automates the detection and exploitation of command injection vulnerabilities, requiring Python to run.
🛠️ @commixproject
💻 Python
⭐ 4930
🍴 849
🔗 https://t.co/S5wh8PiWqO
🚨CVE ALERT!
While working with Nuclei @wiz_io, I discovered CVE-2024-43405, a vulnerability that bypasses template signature verification, potentially allowing malicious code execution on machines running Nuclei 🛡️
Here’s what you need to know: 🧵
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! https://t.co/7ygwWXY0pd
Highlights include:
⚡ Escaping from DocumentRoot to System Root
⚡ Bypassing built-in ACL/Auth with just a '?'
⚡ Turning XSS into RCE with legacy code from 1996
Want to scan for command injection vulnerabilities on auto-pilot? 😎️👇️
Commix is an open-source command injection scanner written in python to help you scan for these bugs easily! 🤑
Check it out! 👇️
https://t.co/rRhWeb6KkL
Want to scan for command injection vulnerabilities on auto-pilot? 😎️👇️
Commix is an open-source command injection scanner written in python to help you scan for these bugs easily!
https://t.co/4TCEvF75TG
#bugbountytips#bugbounty
PHP just fixed one of my RCE vulnerabilities, which affects XAMPP by default. Check to see if you are affected and update now! 🔥
https://t.co/EQdzNTihOm