#EXPLOITS

2025-06-27

"CVE-2024-54085, as the vulnerability is tracked, allows for authentication bypasses by making a simple web request to a vulnerable BMC device over HTTP."

Which should be less useful-- assuming some miniscule amount of competence and commensurate rules.

But even that leaves another layer, the bribery route + poor vetting. How valuable are the secrets and who is on the segment?

#CVE202454085

#ITSecurity
#exploits
#monoculture

arstechnica.com/security/2025/

Ars Technica Newsarstechnica@c.im
2025-06-27

Actively exploited vulnerability gives extraordinary control over server fleets arstechni.ca/KVk5 #baseboardmanagementcontrollers #AMIMegaRAC #Security #exploits #Biz&IT #bmcs

Kevin Karhan :verified:kkarhan@infosec.space
2025-06-12

@GrapheneOS @thpar @chris @fairphone@lemmy.ml @fairphone@mas.to I don't have an #eOS device to run a tool like #SnoopSnitch that has a #Android #PatchLevel tester to check against common #exploits and #Security|Issues.

#Zelensky: “… #putin wants to continue killing and #exploits the lack of a strong response. They don’t listen to Washington. And that says a lot to the world – to everyone” 👇🏻

#Russia #Ukraine #UkraineRussiaWar

Ars Technica Newsarstechnica@c.im
2025-06-10

Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them. arstechni.ca/ndSq #vulnerabilities #microsoft #Security #exploits #Biz&IT #secure #boot

The Spamhaus Projectspamhaus@infosec.exchange
2025-06-02

This month Spamhaus' Exploits Blocklist reached 5 million IPs listed for use in third-party exploits! 🎉 For optimum filtering, apply at:

➡️ Initial connection – against the connecting IP
➡️ Once email data accepted – check IPs in received chain mail headers and IPs hosting resources in the body (e.g. URLs)

Learn more about this data set:
spamhaus.org/blocklists/exploi

#5million #Exploits #Blocklist

2025-06-01

📬 Exploit-Alarm bei Switch 2: Hacker berichten von Systemblockade
#Gaming #AntiPiracy #Exploits #Hacker #Jailbreak #Nintendo #Switch2 sc.tarnkappe.info/c92b38

Nintendo Connectnews@nintendo-connect.de
2025-06-01

Nintendo Switch 2: Erste Hacking-Versuche scheitern – Ist die neue Konsole „unhackbar“?

Nintendo hat aus der Vergangenheit gelernt – und scheint bei der Switch 2 besonders hart gegen potenzielle Hacks vorzugehen. Erste Berichte zeigen: Aktuell scheitern sämtliche Versuche. Nintendo vs. Hacker: Eine lange Geschichte Seit Jahrzehnten liefert sich Nintendo ein Katz-und-Maus-Spiel mit der Hacking-Szene. Spätestens seit der Wii versuchen Sicherheitsforscher und Tüftler, Schwachstellen in den Systemen zu finden – oft mit dem Ziel, Homebrew-Software oder Raubkopien […]

nintendo-connect.de/heimkonsol

≡ʀʀ🇵🇱errorman
2025-05-24

The story about chinese prison guards exploiting inmates by forcing them to do the world of warcraft gold farming... insane

Chema Alonso :verified:chemaalonso@ioc.exchange
2025-05-16

El lado del mal - Usar Deep Reasoning en GitHub para buscar ( y parchear ) Bugs en proyectos Open Source elladodelmal.com/2025/05/usar- #DeepSeek #Perplexity #GitHub #LLM #Bugs #Exploits #IA #AI #OpenSource

Marcus "MajorLinux" Summersmajorlinux@toot.majorshouse.com
2025-05-14

Time to go update yo shit again!

Microsoft Urges Immediate Action to Address Five Actively Exploited Windows Zero-Days

particle.news/share/PPocp

#Microsoft #Windows #ZeroDay #Security #InfoSec #Exploits #Tech

Schneier on Security RSSSchneier_rss@burn.capital
2025-05-13

Court Rules Against NSO Group

The case is over:
A jury has awarded WhatsApp $167 million in punitive damages in a case the company brought a... schneier.com/blog/archives/202

#Uncategorized #exploits #WhatsApp #hacking #courts #Israel

The Spamhaus Projectspamhaus@infosec.exchange
2025-05-12

With a +61% ⬆️ increase, 🇺🇸 US-based "charter.com" is #1 for hosting IPs associated with exploited devices: 193, 782 detections over the last 30 days....

....as well as 167 Spamhaus Blocklist (SBL) listings.

Spamhaus reputation statistics:
👉 spamhaus.org/reputation-statis

SBL listings:
👉 check.spamhaus.org/sbl/listing

#IPs #Exploits #Spamhaus #ReputationStatistics #ThreatIntel

Ars Technica Newsarstechnica@c.im
2025-05-07

Jury orders NSO to pay $167 million for hacking WhatsApp users arstechni.ca/2waYz #Security #exploits #nsogroup #whatsapp #pegasus #Biz&IT #Policy

MrsNo1SpecialMrsNo1Special
2025-05-05

Cybersecurity threats don’t always come from technical exploits — many originate from human psychology. Social engineering is the art of manipulating people into revealing confidential information, bypassing even the strongest security measures. But how do hackers do it? And why do even...

medium.com/@mrsno1special/the-

#

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2025-04-30

#Government #hackers are leading the use of attributed #zerodays
Google’s says number of #0day #exploits — flaws unknown to the software makers at the time hackers abused them — had dropped from 98 exploits in 2023 to 75 exploits in 2024. But the report noted that of the proportion of zero-days that Google could attribute — meaning identifying the hackers who were responsible for exploiting them — at least 23 zero-day exploits were linked to government-backed hackers.
techcrunch.com/2025/04/29/gove

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2025-04-30

Google: 97 #zeroday #exploits in #2024, over 50% in #spyware attacks
They noted that cyber-espionage threat actors—including government-backed groups and commercial #surveillance vendors' customers—were responsible for more than half of attributable #0day attacks in 2024.
End-user platforms and products (e.g., web browsers, mobile devices, and desktop operating systems) made up 56% of the tracked #zerodays.
bleepingcomputer.com/news/secu

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst