#exploit
1⃣. Windows Session Hijacking via COM - github.com/3lp4tr0n/SessionH…
// This technique serves as an alternative to remote process injection or LSASS dumping for activities like keylogging, screenshots, or LDAP access
2⃣. CVE-2024-27822:
macOS PackageKit Privilege Escalation - khronokernel.com/macos/2024/…
// Currently, there is no patch...
3⃣. CVE-2025-67511:
Tricking a Security AI Agent Into Pwning Itself - hacktivesecurity.com/blog/20…
// Command injection vulnerability in cai-framework <=0.5.9. A patched release on PyPI is not yet available...
4⃣. CVE-2025-53772:
Microsoft Web Deploy RCE - github.com/sailay1996/CVE-20…
// RCE in Microsoft Web Deploy (msdeploy) caused by unsafe deserialization of HTTP header data
🚀 We've got another CVE (CVE-2025-67511) coming out of Hacktive Security thanks to
@edoardottt2
and the work done on Cybersecurity AI (CAI), framework for building and deploying AI-powered 📷 offensive and defensive automation. #AI#CyberSechacktivesecurity.com/blog/20…
If you are interested in using binwalk, qemu, bash/python scripting, dd, Binary Ninja, Ghidra, cross compiling and these topics, hope you will enjoy this post. #pwn2ownhacktivesecurity.com/index.p…
Not all stories end with the expected and hoped-for results, and this story is one of them. We’re releasing a three-part series detailing our unsuccessful #Pwn2Own 2024 attempt targeting two IP cameras.
hacktivesecurity.com/index.p…
(2/3)
If you want to scream at your monitor for 24h and blame us, sign up for the event: play.pwnx.io/#/event/fb765f3…, kindly hosted by @pwnx_official We're still collecting insults for the IFCTF23, feel free to send us your complaints. You will receive an autoreply from MarcoGPT
#HacktiveSecurity, GOLD Sponsor MOCA2024
@hacktivesec: an independent consulting company with 15 years of international experience in civil and military environments providing advanced #Cyber Security services.
Do you also want to be one of our sponsors?
moca.camp/en/call-for-sponso…