In this research, we analyzed the vulnerability by comparing the vulnerable and patched versions of the package and created a Proof of Concept (PoC).
Shout out to the researchers involved in this research:
- Eternity
- tsakuyaiba
🫡
We recently published research on a cryptographic validation flaw in the widely used Python cryptography library (CVE-2026-26007). The package is extremely popular, with over 206 million downloads last week and 806 million downloads last month!
https://t.co/Je7lXwtk5L
We published research on CVE-2026-20700, a memory corruption bug in Apple’s dyld that is actively exploited and has been added to CISA’s KEV list, reportedly used with other CVEs in targeted attack.
Thanks to mintcocs for the research
Technical analysis:
https://t.co/k68KdZ5O0v
We just published our recent vulnerability research on a memory leak affecting the Jetty web server, one of the popular Java web servers, on our website.
Shout out to the researchers involved in this research:
- miraicantsleep
- daffainfo
Vuln Analysis:
https://t.co/JaOEhF3uJs
Minggu lalu, telah berlangsung babak final lomba Capture The Flag ARKAVIDIA 10.0 yang diadakan oleh Himpunan Mahasiswa Informatika ITB
Dengan rasa bangga, kami menyampaikan bahwa terdapat tim HCS berhasil menembus babak final dan meraih posisi sebagai juara 2!!
Official partner for @OOTBconf and also will be organising a CTF as a side event during the event together with @hcs_ctf
Details: https://t.co/a3aiKWa7kT
Minggu lalu berlangsung babak final INFENTRA 2025 oleh HMIF Telkom University Purwokerto, di mana tim HCS "[11/9, 17:49] bapak kost (mas merick): Assalamualaikum, temen2 yg blm bayar uang bulan ini iya, suwun" berhasil meraih juara pertama.
Minggu ini, pengumuman perlombaan GEMATIK V yang digelar oleh Fakultas Teknik dan Ilmu Komputer Universitas Teknokrat Indonesia telah selesai. Kami dengan bangga mengumumkan bahwa tim HCS berhasil meraih peringkat kedua dalam ajang perlombaan ini.
Bangga! Salah satu tim Heroes Cyber Security meraih predikat Harapan Nasional pada GEMASTIK 2025 yang diselenggarakan oleh Dit. Belmawa, Ditjen Dikti, Kemendiktisaintek. Selamat kepada tim "HCS - Infinits Park" atas pencapaian luar biasa ini!
For the first time, We published our first CVE research on our blog, analyzing CVE-2021-3122 — an unauthenticated RCE in the CMCAgent service used by Aloha POS/BOH systems. This vulnerability was exploited in 2021 and linked to credit card theft incidents.
We also contributed a Nuclei template that has been merged into @pdnuclei nuclei-templates repository and have submitted a Metasploit module to @metasploit metasploit-framework repository (still not merged).
Kemarin, babak final Wreck IT 6.0 yang diselenggarakan oleh Senat Korps Taruna Politeknik Siber dan Sandi Negara telah resmi berakhir. Kami dengan bangga mengumumkan bahwa tim “Manarul Ilmi Enjoyer” dari HCS berhasil meraih peringkat ketiga dalam ajang tersebut.
Minggu lalu, babak final HOLOGY 8.0 oleh Fakultas Ilmu Komputer UB telah berlangsung. Dua tim HCS, Tim "aduh telat daftar jir" dan Tim "mencari fine shyt malang", berhasil lolos ke final dan meraih juara 3 serta harapan 2!
Minggu lalu, final HackToday 2025 yang diselenggarakan HIMALKOM dan Departemen Ilmu Komputer IPB sukses digelar. Dua tim dari Heroes Cyber Security, HCS - https://t.co/pXZMcBZaTW dan HCS - linz & yqroo fans club, lolos ke final dan meraih juara 2 serta 3!
Give it up to the top detectives out there 👏
Huge congratulations to our Holmes CTF winners— your skills would make even Sherlock proud!
And huge kudos to the over 11,000 participants of the first-ever Blue #CTF from HTB. We had a blast, and we hope you did too 🔥
Join the after-party: https://t.co/7uAsWvT5tB
#HackTheBox ##HTB #CyberSecurity #BlueTeam #DigitalForensics #HolmesCTF #SOC #MalwareReversing
We are excited to announce that our team secured 2nd place out of 7,084 teams in the Holmes CTF 2025 competition organized by @hackthebox_eu . The event focused heavily on blue teaming, with challenges about threat intelligence, SOC, DFIR, and malware reversing