BeyondTrust Microsoft Vulnerability Report 2025

The 2025 Microsoft Vulnerabilities Report reveals a record-breaking 1,360 total vulnerabilities in 2024, highlighting an 11% increase from the previous year, with a notable rise in Security Feature Bypass vulnerabilities. Despite the uptick in some areas, critical vulnerabilities continue to decline overall, though Microsoft Edge showed an unexpected increase. #MicrosoftVulnerabilities #SecurityFeatureBypass #MicrosoftEdge

Read More
BeyondTrust Microsoft Vulnerability Report 2025

The 2025 Global Mobile Threat Report highlights the increasing risks posed by mobile attacks like mishing, sideloaded apps, and outdated OS vulnerabilities, emphasizing the need for continuous app vetting, device attestation, and proactive vulnerability management. Key concerns include rising smishing attacks, spyware and Trojans growth, and insecure data communication within enterprise apps. #Mishing #SideloadedApps #Vultur #DeviceAttestation

Read More
Letโ€™s Defend: 314 โ€” SOC336 โ€” Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025โ€“21298)

The SOC investigated a Windows OLE zero-click remote code execution exploiting CVE-2025-21298 delivered via a malicious RTF attachment (mail.rtf, hash df993d037cdb77a435d6993a37e7750dbbb16b2df64916499845b56aa9194184) that resulted in a connection to a suspected C2 at 84[.]38.130.118. The endpoint was contained and escalated to Tier 2, with recommendations to apply January 2025 patches, disable RTF/OLE rendering…

Read More
HTTP/1.1 must die: the desync endgame | PortSwigger Research

HTTP/1.1’s weak request separation enables widespread HTTP request smuggling (desync) attacks that have been used to compromise user sessions, poison caches, and take over millions of sites by exploiting parser discrepancies across front-end/back-end chains. The paper documents multiple novel desync classes (including 0.CL, CL.0, H2.TE, Expect-based attacks), case studies affecting Akamai,…

Read More
Hacking a Crypto Game

Sam Curry and his team discovered a severe ORM injection vulnerability in a closed beta online game, which they exploited to gain admin access and drain in-game cryptocurrency wallets. The breach involved exploiting hidden admin panels, API errors, and email leakages to escalate privileges and move funds. #ORMInjection #CryptoWalletLeak…

Read More
The Real Reason Dev Teams Still Struggle to Catch High-Risk Vulnerabilities Early

Modern development teams often miss critical vulnerabilities due to limitations in traditional testing methods and tooling that lack real-time, context-aware insights. Improving visibility, automation, and collaboration across development, security, and operations is essential for identifying high-risk flaws in fast-paced CI/CD environments. #Veracode #ShiftLeft #BusinessLogicFlaws

Read More
Your Domain, My Playground: How I Created Links on Your Site Without Access

Googleโ€™s Dynamic Links API can be abused to create legitimate-looking short links on any domain, including those owned by attackers, without requiring authentication. This vulnerability was demonstrated through a bug bounty report leading to Googleโ€™s partial fix, though the metadata manipulation loophole still poses risks. #FirebaseDynamicLinks #GoogleVulnerability

Read More
Revenant: A Modern Full-Stack Reverse Shell C2 Framework From Payload Generation to Victim

Revenant is a lightweight, flexible C++ framework that transforms HTTP into a covert C2 infrastructure for remote control of victim devices. Its features include encrypted tunneling, multi-victim management, and stealthy communication, making it suitable for red team exercises and security testing. #Revenant #CommandAndControl #ReverseShell

Read More