A few months after the initial release of the Beerus Framework, we are publishing version v1.1, a minor update that brings support for new root environments, a relevant architectural change in data transport, integrated auto-update, and a set of accumulated fixes since the first release.
In this post, we detail each change included in this version, the technical context behind each decision, and what it means in practice for those who use Beerus in their day-to-day Android testing.
Authors @_tricta and @d3vchac
Check it out https://t.co/AhgFvnRbnK
In this analysis, we explore CVE-2026-44706, a high-severity SQL injection (SQLi) vulnerability in Chatwoot.
The flaw allows an attacker to execute arbitrary SQL commands against the application's database by exploiting unsanitized parameters controlled by a low-privilege user, paving the way for access to and exfiltration of sensitive data.
EN: https://t.co/6DI7Qxwv9q
We just received a bounty reward from UniFi for reporting a vulnerability affecting UniFi OS devices.
As part of the Hakai Labs (@HakaiOffsec) research team at @quimerax_intel, we independently identified a Path Traversal vulnerability (CVE-2026-34911) that allowed an attacker with network access to access internal routes on the underlying system without a valid token, exposing a sensitive information.
Our research was conducted independently, but the vulnerability we reported could be chained with other vulnerabilities disclosed during the same period, including Improper Access Control and Command Injection flaws reported by other researchers. When combined, these issues lead to a pre-auth RCE affecting multiple UniFi OS products.
Affected products include UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max, UCG-Fiber, and several other UniFi OS devices.
We strongly recommend updating affected systems to the latest available version. Technical details remain under coordinated disclosure, and the only public information currently available is UniFi’s Security Advisory Bulletin.
https://t.co/eXN3GIWOjw
Reverse engineering SmartLoader from a malware-developer perspective.
SmartLoader is a commodity loader in active deployment, recently tied to LummaStealer delivery. It's interesting less for any single primitive and more for what it reveals about how modern MaaS tooling is actually built.
The post walks through each layer as an engineering choice, why the malware is built the way it is and what that says about the constraints the developer was working under, then compares the result against where operational red-team tooling is going. Two different optimization surfaces, same underlying primitives.
Author: Alice Duarte
Check out the article:
https://t.co/RGmWgfXbtj
Um único caractere pode ser suficiente para comprometer uma conta. Neste artigo, exploramos como o uso de Punycode e caracteres Unicode visualmente semelhantes pode levar a cenários de 0-Click Account Takeover, onde um atacante assume o controle de uma conta sem qualquer interação da vítima.
Autor: Maiky Jhony - @vert16x
Confira o artigo:
https://t.co/QWCjQ6pYd0
In this research, Hakai Security Research Team has identified a critical Remote Code Execution (RCE) vulnerability in Wazuh versions up to 4.14.1 that allows arbitrary command execution on the master node through insecure deserialization in the cluster communication protocol.
Written by Texugo
https://t.co/ZIhioa0OjS
Em uma pesquisa de segurança conduzida pelo time da Hakai, foram identificadas três vulnerabilidades críticas no Centreon Web e no módulo Open Tickets.
As falhas incluem SQL Injection, Path Traversal e Command Injection, permitindo desde a extração completa do banco de dados até a execução remota de comandos no servidor.
Todas as vulnerabilidades podem ser exploradas por qualquer usuário autenticado, sem necessidade de privilégios administrativos. Como resultado da pesquisa, foram atribuídos três identificadores CVE: CVE-2026-2749 (CVSS 9.9), CVE-2026-2750 (CVSS 9.1) e CVE-2026-2751 (CVSS 8.3).
O post irá demonstrar desde a análise técnica das vulnerabilidades, como realizar a exploração e a correção realizada pelo time do Centreon.
Autor: Gabriel Rodrigues - Texugo: @g.lllllllllllllllllllllllll
Confira o artigo:
https://t.co/dZYxcIvSzq - EN
https://t.co/E4JhcJ65vi - PT
The exploitation of Next.js (CVE-2025-66478) is not possible unless you can control the serverManifest.
Because of that, a Prototype Pollution primitive on the target is required in order to exploit this CVE.
Even in ejpir’s PoC (https://t.co/rYXFn3qFWf), the PoC explicitly allows the use of child_process and other dangerous modules.
This creates an intentionally vulnerable server. To achieve real RCE on an actual target, you would need some form of Prototype Pollution to overwrite the serverManifest.
Something like this:
{
"constructor": {
"prototype": {
"workers": {
"app/vuln/page": {
"moduleId": "child_process",
"async": false
}
}
}
}
}
So, real-world exploitation of Next.js is only possible when such conditions are met. This is likely what the Vercel Security Advisory means by "under specific conditions."
O Beerus Framework é uma ferramenta ofensiva mobile desenvolvida para facilitar todo o processo de pentest em dispositivos Android.
Com uma interface unificada diretamente no dispositivo, o Beerus permite realizar desde a instrumentação de aplicações de forma built-in no dispositivo com Frida Core, exfiltração de dados do sandbox, memory dumping, proxying, controle de módulos Magisk, manipulação de propriedades e muito mais.
Construído sobre Frida e Magisk, o Beerus é modular, extensível e projetado para testes em dispositivos com root, otimizando tarefas comuns de pentest e habilitando automações a partir de um único app.
Neste paper, exploramos as principais funcionalidades do framework, com foco especial em algumas delas. A proposta não é detalhar exaustivamente seu funcionamento, mas oferecer uma visão ampla do que ele abrange e do que é capaz.
Lembrando que o Beerus Framework já está disponível para download diretamente no repositório oficial no GitHub.
https://t.co/GHATbcgHVF
Autores: Tricta e Daniel Franca Lima
🎤"Não adivinhe, modele."
Descubra a modelagem de ameaça 🔐: identificar, categorizar e mitigar riscos antes do atacante agir.
👤 Lucas (AhNão!) da Hakai ⚔️ mostra como segurança é entendimento, estrutura e prevenção, não chute.
🌐 No #HackinRio, a galera da segurança e tecnologia do RJ
#ah_nao_tech #arcahub #hakaisecurity #cibersegurança #hacking
🚨 É AMANHÃ, BELÉM!
Dia 13/09 na @XibéSec, o @crd0x.49 Jonathan Coradi 🎤 chega pesado pra falar da real de um Red Team físico.
Nada de firula, é papo reto sobre como funciona de verdade.
Quem for, vai sair com a mente virada do avesso.🤯
Oh se eu quisesse hein…🏴☠
Chega de historinha bonita de relatório com screenshot do “Domain Admin”. Nessa talk eu vou jogar na mesa a realidade nua e crua de um RedTeam físico: a parte suja, as lições aprendidas e as verdades que ninguém gosta de contar ⚠.
Vou mostrar como é possível burlar segurança física e digital sem precisar de teatrinho de Engenharia Social elaborado — e como, às vezes, um detalhe esquecido vale mais do que qualquer exploit cheio de firula 🔓. Se você acha que RedTeam físico é sobre posar com lockpick e camiseta preta, vai doer escutar isso aqui 💥🖤
Huge thanks to one of our Silver Sponsors for DEF CON 33 — @HakaiOffsec! 🥈⚔️ Your support helps power the chaos, creativity, and community of Red Team Village. See you in Vegas! 🔥
Hackers!
Passando rapidinho para enviar uma imagem simples de lembrete para não perdermos a talk de nossos analistas na H2HC!!
Vai ser muito foda, contamos com todos!
👹 Novo White Paper: Afinal, o que é Ransomware? Saiba como ele opera e como se proteger! 👹
Entenda como prevenir, conter e recuperar de ataques cibernéticos.
📥 Acesse: https://t.co/3Z6ADOSj9X
#CyberSecurity#Ransomware
Our new blog post is on air!
💀 The Dark Side of JWT: Authentication tokens can become major vulnerabilities!
🔗 Read now: https://t.co/gaXQv5XTFC
#CyberSecurity#JWT#RedTeam#Pentest
A huge shoutout to our incredible diamond sponsor, @hakaioffsec, for supporting us at @h2hconference! 🎉💎 We’re beyond thrilled to have your amazing support—let’s make this event unforgettable together! 🚀✨ #H2HConference
🌐 Windows Admin-To-Kernel Elevation of Privilege(CVE-2024-21338)
No estudo mais recente publicado em nosso blog, @biscoitomesmo detalha a CVE-2024-21338
🔗 Leia o artigo completo aqui:
https://t.co/ItHDs2bZKY
[ Lembrete] : Nossa live começa em 1 hora!
Nosso Bate Papo será sobre alguns erros comuns no Active Directory e como abordá-los com uma mentalidade ofensiva
Essa será uma versão adaptada da mesma talk que nosso mestre Jessé apresentou na NullByte.
Esperamos você às 19:30