Seclog - #127
"The best defense is not only in strong encryption but in unpredictable behavior." - The Art of Cyber War
π SecMisc #
Tiny XSS Payloads β A curated list of tiny, minimalistic XSS payloads for testing and evasion.
Top CVE Trends & Expert Vulnerability Insights | cvemon β Real-time CVE trends and insights from vulnerability intelligence experts.
π° SecLinks #
Postman is logging all your secrets and environment variables β Discover how Postman may be exposing sensitive variables to logging systems.
Authentication Bypass to RCE in Versa Concerto (0-Day) β Full technical breakdown of a 0-day RCE in Versa Concerto.
Clipjacking: Hacked by copying text β A creative attack method leveraging clipboard copy-paste behavior.
Stored XSS in My Flow To RCE in Opera Browser #2 β Exploiting stored XSS to achieve RCE in Opera's My Flow feature.
Finding and Exploiting 20-year-old bugs in Web Browsers β Slides covering long-lived browser vulnerabilities and exploitation strategies.
Have I Been Pwned 2.0 is Now Live! β Major updates to Troy Huntβs breach notification platform.
Pressing Buttons with Popups (on Twitch, LinkedIn and more) β Abuse of popups to trigger unauthorized user actions.
Kusto-Mice: Optimizing Kusto joins β Performance tips for better join operations in Kusto Query Language.
Go Cryptography Security Audit β Detailed report on Go languageβs cryptographic libraries and audit findings.
The Single-Packet Shovel: Desync Tunnelling β Exploring HTTP request desync for covert tunneling techniques.
Deloitteβs Secure by Design Approach β with Wiz β Integrating secure design principles with modern cloud-native tools.
Donβt Call That βProtectedβ Method: vBulletin RCE β How a logic flaw in vBulletin led to full RCE.
Reverse Engineering iOS Shortcuts Deeplinks β Analysis of iOS Shortcuts deep linking for exploitation or automation.
π¦ SecX #
The Fake Ledger That Stole Everything | IOC β A gripping thread on a fake hardware wallet that led to total crypto loss.
#OffensiveCon25 videos now up! β Full archive of OffensiveCon 2025 talks now available.
π₯ SecVideo #
Web security is fun (or how I stole your Google Drive files) - Lyra Rebane β Entertaining and educational talk on exploiting cloud document features.
π» SecGit #
urbanadventurer/urlcrazy β Tool for generating typo variants of domain names to detect phishing.
c1phy/sqltimer β A lightweight and fast scanner for time-based SQL injection detection.
NightBloodz/CVE-2025-4123 β PoC for XSS and SSRF leading to data exfiltration in Grafana.
kapellos/LNKSmuggler β Tool to embed data in
.lnkfiles and wrap them into ZIPs for evasion.
curated-intel/Attribution-to-IP β Collection of methods for IP ownership and attribution analysis.
sw33tLie/uff β A supercharged version of
ffuffor fuzzing web directories and APIs.
cybrly/badsuccessor β An experimental project with unclear purpose β watch this one evolve.
Enjoyed this post? Subscribe to Seclog for more in-depth security analysis and updates.
For any suggestions or feedback, please contact us at: [email protected]Subscribe to Seclog
Enjoyed this post? Subscribe for more in-depth security analysis and updates direct to your inbox.
No spam. Only high-security insights. Unsubscribe at any time.