CVE-2023-7028
Account Takeover via Password Reset without user interactions
A critical vulnerability in GitLab CE/EE (CVE-2023-7028) can be easily exploited by attackers to reset GitLab user account passwords.
• https://t.co/c9aeUjkqOK
• https://t.co/Ip7YeIxkha
#cve #cybersecurity #infosec #pentesting #redteam #bugbounty
GitHub - machine1337/TelegramRAT: Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions https://t.co/m4roD2IOMt
A really cool writeup from @kevin_mizu about a bug in https://t.co/3nZMVhrLA2. It looks like the writeup has some of tricks learnt from my research! Super happy to see the real world applications of my techniques 😊 And thanks for the shout out!
https://t.co/6U6vyRSDLJ
@doctorthompson yes the same thing with polkit pkexec it has to be an old vulnerability but they bring this up now and the impact is pretty much the same.
The lowest user "nobody" could use this simple bash script and allows anybody to overwrite data in arbitrary read-only files (CVE-2022-0847)
It is similar to CVE-2016-5195 “Dirty Cow” but is easier to exploit. https://t.co/i8pO7EEHTx #infosec#CVE
We've posted some in-depth guidance on how to make Turbo Intruder attacks go as fast as possible. If you think we're missing any tricks, let us know!
https://t.co/Mi0gsmzYRv