Seclog - #129
"The art of cyber war is knowing when to strike⦠and when to reboot." - The Art of Cyber War
π SecMisc
Disclosed β€ Online β Directory that aggregates bug-bounty researcher profiles from HackerOne, Bugcrowd, GitHub, and more. (reddit.com)
Have I Been Squatted? β Fast typosquatting-discovery tool that maps look-alike domains and offers defence guidance. (haveibeensquatted.com)
π° SecLinks
On the 10th Anniversary of the Snowden Revelations β Updated retrospective on key NSA leaks and their continuing impact (updated 7 Apr 2025). (electrospaces.net)
Incident Response in AWS: Scoping Strategies β Fresh Medium post (6 days ago) showing how to pivot on CloudTrail artefacts for rapid scoping. (medium.com)
Covert Web-to-App Tracking via Localhost on Android β Research revealing Meta & Yandex apps quietly listening on fixed local ports for tracking. (localmess.github.io)
Roundcube β€ 1.6.10 Post-Auth RCE (CVE-2025-49113) β Deep dive into a PHP deserialization flaw that yields full remote code-execution. (fearsoff.org)
Analyzing IPv4 Trades with gnuplot β Demo project exploring IPv4 supply-and-demand trends during the IPv6 transition. (ipv4a-5539ad.gitlab.io)
The Ultimate Guide to JWT Vulnerabilities & Attacks β Hands-on PentesterLab guide to exploiting and defending JWT flaws. (pentesterlab.com)
AI bugSWAT in Tokyo & 2025 Hacker Roadshow β Google Bug Huntersβ inside look at their live AI hacking event and top findings. (x.com)
π¦ SecX
βI left a server online with VNC wide openβ¦β β James Woolley shares what attackers did when handed an exposed VNC box. (x.com)
π₯ SecVideo
Undercover Journalist Unpacks Essential Tools to Escape Detection β Practical OPSEC tips for reporters working in hostile environments. (youtube.com)
π» SecGit
frida-script-gen β CLI that scans Android APKs for root/SSL-pinning checks and auto-generates Frida bypass hooks. (github.com)
assetnote/surf β Go tool that filters massive host lists to surface cloud-based SSRF candidates for escalation. (github.com)
Enjoyed this post? Subscribe to Seclog for more in-depth security analysis and updates.
For any suggestions or feedback, please contact us at: [email protected]Subscribe to Seclog
Enjoyed this post? Subscribe for more in-depth security analysis and updates direct to your inbox.
No spam. Only high-security insights. Unsubscribe at any time.