Windfall - Unauth RCE in Windmill & Nextcloud Flow (CVE-2026-29059)
Path traversal to credential leak to root shell. No authentication required on any deployment type, including behind Nextcloud's proxy. Metasploit modules + full toolkit included.
Also publishing a new technique for dumping PostgreSQL databases by reading heap files from disk. If you have filesystem access as root, you can extract every table without credentials or SQL access. Full binary parser with JSONB support.
Write-up: https://t.co/ylSXW0dtmn
PG heap dump technique: https://t.co/Se2dQJ761r
PG heap dump tool: https://t.co/E95f12mVZF
Exploit toolkit + labs: https://t.co/5dtsSR6Jvn
I've consumed more chocolate than any adult should, as such, it drove us to do a lot of cool stuff in RAPTOR this weekend and it's time to talk about it.
We now have
/understand,
/validate,
and /project
This was sent to me by a friend of the project today, and I wanted to share it with the rest of the community:
🐲Wishing you and your family a joyous and blessed Lunar New Year! May the Year of the #Kali (Dragon) bring you and your loved ones prosperity, and good health!
Get Some FREE Cybersecurity Hands-On Training with this Resources
1. TryHackMe
https://t.co/YV2gb0IWhK
2. Blue Team Labs
https://t.co/mFQvcJgifi
3. Hands-On SOC Analyst Training
https://t.co/W7aQ2A7B0L
4. Cybrary
https://t.co/q0lYu1l05d
Below is a link to access the following:
CompTIA Security+ | SY0-601 book
CompTIA security+ Past questions and answers
Security+ Practice Test
Network Basics for Hackers
https://t.co/a549H8FEHS
Do yourself a favor:
• Open your laptop
• Open YouTube
• Type HTML crash course
• Start learning
• Learn CSS alongside
• Ask questions to ChatGPT
• Build projects
• Push code to GitHub
• Share your progress on 𝕏
Don't think much.
This is the right time.
100 #redteam projects
A list of 100 projects that are worth a close look at the source code for someone who wants to become a high-level professional:
Advanced Network Attacks
Data analysis
Payloads
Cryptography
Reverse Engineering
Post exploitation
https://t.co/YOMzAwIzTu
To All Beginners in Cybersecurity
I’m here to inform you that
You don’t need a gaming laptop to begin the journey
This should help you get started
Core i5 or i7 CPU
8GB or 16GB RAM
500GB or 1TB HDD
Then, learn the basics
CompTIA A+, Network+ & Security+
Happy learning🤝
Build Your Own Network Intrusion Detection System with Snort!
Snort IDS for Hackers, Part 1-5
#snort#ids#cybersecurity#snort4hackers
https://t.co/oDwPvAxAoa