home.social

#exploit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #exploit, aggregated by home.social.

fetched live
  1. Microsoft Windows Cross Device Service Local Privilege Escalation packetstorm.news/files/228583 #exploit

  2. Novo exploit ShieldBreak é capaz de contornar a correção do Microsoft Defender com 100% de eficácia, afetando sistemas com Windows 11 25H2 e Windows Server 2025. A ferramenta foi publicada no ProjectNightCrawler. 🚨

    🔗 tugatech.com.pt/t89075-novo-ex

    #exploit #microsoft 

  3. Novo exploit ShieldBreak é capaz de contornar a correção do Microsoft Defender com 100% de eficácia, afetando sistemas com Windows 11 25H2 e Windows Server 2025. A ferramenta foi publicada no ProjectNightCrawler. 🚨

    🔗 tugatech.com.pt/t89075-novo-ex

    #exploit #microsoft 

  4. Telaeris XPressEntry 3.7.7454 SQL Injection / Remote Command Execution packetstorm.news/files/228484 #exploit

  5. Plixer Scrutinizer 19.7.0 SQL Injection / Remote Command Execution packetstorm.news/files/228483 #exploit

  6. Microsoft Defender enfrenta novo exploit ShieldBreak que contorna correção da empresa. Um novo exploit de dia zero, chamado ShieldBreak, foi tornado público após a atualização de segurança de agosto de 2026 da Microsoft, permitindo obter privilégios máximos do sistema (SYSTEM) em ambientes atualizados. 🚨

    🔗 tugatech.com.pt/t88988-microso

    #empresa #exploit #microsoft 

  7. Böse Screen-Sharing-Lücke in macOS: Exploit aus Apples Patch gebaut

    Wer Apples praktische Bildschirm-teilen-Funktion auf dem Mac nutzt, muss sein Betriebssystem aktualisieren. Ein Exploit ließ sich schnell entwickeln.

    heise.de/news/Boese-Screen-Sha

    #Exploit #Fernwartung #IT #Mac #macOS #Mobiles #news

  8. Ein Modder hat die Sperren des Cloud-Gaming-Dienstes #GeForceNow von #Nvidia ausgehebelt. Statt nur zu spielen, entsperrte er den zugrundeliegenden vollwertigen #Windows-#Desktop. #Exploit winfuture.de/news,160526.html?

  9. This bloke asked OpenClaw to book him into a gym class. In its effort to please, OpenClaw found an exploit in the booking system, hacked the waiting list and booted off the person ahead of him in the queue! 😂

    abc.net.au/news/2026-08-10/ai-

    #AL #ML #OpenClaw #exploit #autonomous

  10. Zapscape, CVE-2026-64561, a KVM x86 use after free in shadow MMU emulation. Requires nested virtualization enabled, and an AMD or Intel Ice-Lake-SP+ CPU. Apparently, without nested virtualization on, it doesn't apply.

    A tenant with root inside their own VM guest can escalate to root on the host. On a host that doesn't run VMs for tenants, an attacker (or a compromised website/process) can spin up a throwaway guest of their own and attack the host kernel from inside it. So even if you don't provide VMs, it isn't okay to skip if KVM/nested virt is enabled.

    Released fix along with SCTPhantom fix.

    #Selfhosting #InfoSec #Exploit

  11. I'm not at defcon. So...

    SCTPhantom, CVE-2026-64564, yet another "AI Found" kernel vuln, this time with coordinated (responsible) disclosure! It is a use-after-free bug in the Linux kernel's SCTP (Stream Control Transmission Protocol) ASCONF (Address Configuration Change) handling. Unprivileged local user to root, with container escape to the host in some configurations. The upside is that since it was a coordinated disclosure, fixes are out and have been backported to earlier kernel versions.

    #Selfhosting #InfoSec #Exploit

  12. Auf der Black Hat haben Forscher von Google Project Zero gezeigt, wie sich ein Pixel 10 ohne Nutzerinteraktion kompromittieren lässt. Die vorgestellte Exploit-Kette führt von einem eingehenden Inhalt bis zur vollständigen Kontrolle mit Root-Rechten.

    blackhat.com/us-26/briefings/s

    1/2

    #Android #Exploit #Pixel10 #KuketzAugust

  13. Woah this is neat. Pivot an Oracle SQL injection to OS command injection (without xp_commandshell, obviously).

    thehackernews.com/2026/08/atta

    #exploit #tricky

  14. This is fun. A Chinese company that makes fairly generic WiFi routers and sells them under its own (multiple) brands as well as white-labelling them for many other companies to sell as "theirs", has shipped a backdoor on what appears to be every version of every model they've sold.

    vulncheck.com/blog/zbt-endless

    The backdoor itself is also laughably insecure, easily taken over by anyone who can intercept packets between the router and its command-and-control server, or who can cause the hardcoded domain names it used to resolve to an IP address under their control. TL;DR: this is very easy to exploit.

    It is a deliberate remote root backdoor.

    The company says "oh no, there's no security issue, you misunderstand" to the researcher that found this. However, they've taken all their downloadable firmware images offline to be updated for the security issue their PR people say doesn't exist.

    And it is definitely, 100% deliberate and done in bad faith. The backdoor processes deliberately mislabel themselves as `kworker` processes to try to make anyone who sees them think they are Linux built-in kernel threads.

    Worth a read.

    #BackDoor #security #exploit #root #Chinesium #trust #network #hardware