#privilegeescalation

2025-06-20

🔍 A new flaw in Udisks lets attackers escalate to root on major Linux distros. Local doesn’t mean low-risk—privilege escalation is still a key threat.
#LinuxSecurity #PrivilegeEscalation 🐧🚨

bleepingcomputer.com/news/linu

Rene Robichaudnerowild
2025-06-19
2025-06-19

🐧 Two new Linux flaws (CVE-2025-6018 & CVE-2025-6019) allow attackers to escalate from user to root in seconds—impacting major distros via PAM & udisks. Patch now.
#Vulnerability 🚨 #PrivilegeEscalation 🧨

thehackernews.com/2025/06/new-

2025-06-09

Windows Admins—Don’t Delete That Empty inetpub Folder!

Microsoft has released a PowerShell script to restore the C:\inetpub folder created by the April 2025 security update after many users mistakenly deleted it, not realizing it plays a critical role in mitigating a high-severity privilege escalation vulnerability (CVE-2025-21204).

This seemingly empty folder helps protect against attackers escalating privileges using symbolic link abuse, and deleting it can leave your organization vulnerable. If you have already deleted it, Microsoft has a restoration script.

Read the details: bleepingcomputer.com/news/micr

#WindowsSecurity #PowerShell #CVE202521204 #PrivilegeEscalation #PatchManagement #Cybersecurity #ITAdmin #Microsoft #CISO #Infosec #IT

2025-06-03

🔐 New Linux flaws allow attackers to extract password hashes from memory—even without root access. A serious wake-up call for sysadmins: patch fast, audit often. 🐧⚠️
#LinuxSecurity #PrivilegeEscalation

thehackernews.com/2025/05/new-

2025-05-28

🆕 New blog post! It's a rather short one, nothing crazy. Just wanted to share a random finding I made recently. 🤷‍♂️

'Hijacking the Windows "MareBackup" Scheduled Task for Privilege Escalation'

👉 blog.scrt.ch/2025/05/20/hijack

#pentest #pentesting #redteam #windows #privilegeescalation

2025-05-23

A critical vulnerability called BadSuccessor in Windows Server 2025 lets attackers with minimal permissions escalate privileges and take over any Active Directory user. It exploits flaws in delegated Managed Service Accounts (dMSAs) and affects systems even if dMSAs aren’t actively used.

#CyberSecurity #InfoSec #Microsoft #PrivilegeEscalation #ZeroDay #PatchManagement #ADSecurity #WindowsSecurity #TECHi

Read Full Article Here :- techi.com/windows-server-2025-

DeadSwitch @ T0m's 1T C4feTomsITCafe
2025-05-20
ccinfo.nlCCINL
2025-05-20

In januari 2025 werd de Technische Universiteit Eindhoven (TU/e) getroffen door een ernstige cyberaanval. Wat op het eerste gezicht een technologische crisis leek, werd al snel een belangrijk lesmoment voor de hele onderwijssector.

Podcast Spotify: open.spotify.com/episode/6QNXP

Artikel Cybercrimeinfo: ccinfo.nl/menu-onderwijs-ontwi

Lenin alevski 🕵️💻alevsk@infosec.exchange
2025-05-12

New Open-Source Tool Spotlight 🚨🚨🚨

Watson is a .NET tool for enumerating missing KBs on Windows systems and identifying privilege escalation vulnerabilities with associated exploits. Supported OS: Win10 (1507–2004), Server 2016 & 2019. Archived but still useful. #CyberSecurity #PrivilegeEscalation

🔗 Project link on #GitHub 👉 github.com/rasta-mouse/Watson

#Infosec #Cybersecurity #Software #Technology #News #CTF #Cybersecuritycareer #hacking #redteam #blueteam #purpleteam #tips #opensource #cloudsecurity

— ✨
🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴‍☠️

2025-04-21

Watch out with your Azure Automation Account / Runbooks.

  • they often include hard-coded credentials
  • their output is not protected. So attackers can see your results
  • they can use Shared Resources (i.e. credentials or certificates)
  • Hybrid Worker and Azure Arc allow access to your on-premise infrastructure

Dangerous stuff if not managed correctly!

#cloud #azure #knowledgedrop #dfir #pentesting #privilegeescalation

kriware :verified:kriware@infosec.exchange
2025-04-14

clownpertino - A simple macOS debugger detection trick

Analyzes a macOS vulnerability allowing privilege escalation via a flaw in the operating system's handling of certain system calls.

reverse.put.as/2025/04/04/clow

#macOS #PrivilegeEscalation

Schneier on Security RSSSchneier_rss@burn.capital
2025-03-05

CISA Identifies Five New Vulnerabilities Currently Being Exploited

Of the five, one is a Windows vulnerability, another is a Cisco vulnerability. We don’t have any details about who is exp... schneier.com/blog/archives/202

#privilegeescalation #vulnerabilities #Uncategorized

halil denizhalildeniz
2025-01-03

Hello everyone.
In today's article we are reviewing the DC-1 Capture The Flag Vulnhub Guide.

I wish everyone good hacking.
denizhalil.com/2025/01/03/dc-1

halil denizhalildeniz
2024-12-27

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst