⤷ Title: Konfety Malware Evolves: New Android Variant Uses Malformed ZIPs & Encrypted Code to Evade Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 03:05:26 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #CaramelAds #cybersecurity #Dynamic Loading #Konfety #Malware Evasion #mobile security #ZIP Manipulation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 03:05:26 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #CaramelAds #cybersecurity #Dynamic Loading #Konfety #Malware Evasion #mobile security #ZIP Manipulation
Penetration Testing Tools
Konfety Malware Evolves: New Android Variant Uses Malformed ZIPs & Encrypted Code to Evade Detection
Zimperium zLabs reveals a new Konfety Android malware variant using unique ZIP archive manipulation and encrypted, runtime-loaded code to bypass analysis tools and stay hidden.
⤷ Title: PyPI Rejects Malicious ZIP Archives to Block “Parser Confusion” Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 00:09:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Parser Confusion #PyPI #PyPI Blog #Python #security #supply chain attack #Wheel #ZIP Archives
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 00:09:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Parser Confusion #PyPI #PyPI Blog #Python #security #supply chain attack #Wheel #ZIP Archives
Daily CyberSecurity
PyPI Rejects Malicious ZIP Archives to Block “Parser Confusion” Attacks
The Python Package Index (PyPI) has announced a set of new upload restrictions aimed at protecting Python package installers and inspection tools from ZIP parser confusion attacks. This move follo…
⤷ Title: Zip Smuggling: The Stealthy Way to Hide Data in Plain Sight
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 Aug 2025 01:49:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #data concealment #hidden data #LNK file #PowerShell #zip smuggling
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 Aug 2025 01:49:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #data concealment #hidden data #LNK file #PowerShell #zip smuggling
Penetration Testing Tools
Zip Smuggling: The Stealthy Way to Hide Data in Plain Sight
This article explores zip smuggling, a stealthy technique that embeds hidden data within a zip file using a Windows LNK file. Learn how it works.
⤷ Title: Malicious ZIP Files Use Windows Shortcuts to Drop Malware
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 02 Oct 2025 10:19:09 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Blackpoint Cyber #Cyber Attack #Cybersecurity #Fraud #Phishing #PowerShell #Scam #Windows #zip
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 02 Oct 2025 10:19:09 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Blackpoint Cyber #Cyber Attack #Cybersecurity #Fraud #Phishing #PowerShell #Scam #Windows #zip
Hackread
Malicious ZIP Files Use Windows Shortcuts to Drop Malware
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Two 7-Zip Flaws Allow Code Execution via Malicious ZIP Files (CVE-2025-11001 & CVE-2025-11002)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 11 Oct 2025 11:14:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #7_Zip #Compression Utility #CVE_2025_11001 #Directory Traversal #rce #Zero Day Initiative #ZIP File
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 11 Oct 2025 11:14:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #7_Zip #Compression Utility #CVE_2025_11001 #Directory Traversal #rce #Zero Day Initiative #ZIP File
Daily CyberSecurity
Two 7-Zip Flaws Allow Code Execution via Malicious ZIP Files (CVE-2025-11001 & CVE-2025-11002)
⤷ Title: Critical 7-Zip Flaws Allow Remote Code Execution via Malicious ZIP Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:44:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #Compression Utility #CVE_2025_11002 #Directory Traversal #RCE #vulnerability #ZIP File
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:44:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #Compression Utility #CVE_2025_11002 #Directory Traversal #RCE #vulnerability #ZIP File
Penetration Testing Tools
Critical 7-Zip Flaws Allow Remote Code Execution via Malicious ZIP Files
Critical flaws (CVE-2025-11001 & CVE-2025-11002) in 7-Zip allow unauthenticated RCE when extracting malicious ZIP files. Attackers can overwrite system files via directory traversal. Update to v25.00.
⤷ Title: Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
Penetration Testing Tools
Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
NHS Digital warns that a high-severity 7-Zip symbolic link flaw (CVE-2025-11001) is being actively weaponized to execute arbitrary code. Update to 7-Zip 25.00 now!
⤷ Title: Cracking the ZIP — A Digital Forensics Challenge
════════════════════════
𐀪 Author: Siphiwe
════════════════════════
ⴵ Time: Sun, 28 Dec 2025 12:27:17 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #hacking #tutorial #digital_forensics #zip_cracking
════════════════════════
𐀪 Author: Siphiwe
════════════════════════
ⴵ Time: Sun, 28 Dec 2025 12:27:17 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #hacking #tutorial #digital_forensics #zip_cracking
Medium
Cracking the ZIP — A Digital Forensics Challenge
Introduction
⤷ Title: CVE-2026-0866: Malformed ZIP Headers Allow Malware to Slip Past EDR Scanners
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:15:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Antivirus Evasion #CVE_2026_0866 #cybersecurity #EDR Bypass #False Negatives #infosec #Malware Analysis #Shadow Archives #threat intelligence #ZIP Metadata
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:15:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Antivirus Evasion #CVE_2026_0866 #cybersecurity #EDR Bypass #False Negatives #infosec #Malware Analysis #Shadow Archives #threat intelligence #ZIP Metadata
Daily CyberSecurity
CVE-2026-0866: Malformed ZIP Headers Allow Malware to Slip Past EDR Scanners
Discover how attackers use shadow archives (CVE-2026-0866) to bypass AV and EDR by malforming ZIP metadata, keeping malware hidden but executable.
⤷ Title: The Living Dead: How “Zombie ZIP” Headers Trick 50 Mainstream Antivirus Engines
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:30:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #Antivirus Bypass #Archive Security #Bombadil Systems #Chris Aziz #CVE_2026_0866 #Cyber Security 2026 #DEFLATE #EICAR #malware obfuscation #VirusTotal #ZIP Header Manipulation #Zombie ZIP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:30:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #Antivirus Bypass #Archive Security #Bombadil Systems #Chris Aziz #CVE_2026_0866 #Cyber Security 2026 #DEFLATE #EICAR #malware obfuscation #VirusTotal #ZIP Header Manipulation #Zombie ZIP
Penetration Testing Tools
The Living Dead: How "Zombie ZIP" Headers Trick 50 Mainstream Antivirus Engines
Investigators have directed their scrutiny toward a novel artifice for obfuscating malignant code within ZIP archives. Christened “Zombie
⤷ Title: Critical OpenMRS Flaws Enable Patient Data Theft and Remote Server Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 12:55:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Velocity #CVE_2026_41258 #cybersecurity #EMR Security #Healthcare IT #infosec #Medical Data Breach #OpenMRS #PHI Protection #rce #ssti #Zip Slip
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 12:55:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Velocity #CVE_2026_41258 #cybersecurity #EMR Security #Healthcare IT #infosec #Medical Data Breach #OpenMRS #PHI Protection #rce #ssti #Zip Slip
Daily CyberSecurity
Critical OpenMRS Flaws Enable Patient Data Theft and Remote Server Takeover
OpenMRS v2.8.6 fixes a critical 9.1 CVSS SSTI flaw and Zip Slip RCE. Protect global patient health records and upgrade your EMR infrastructure immediately!
⤷ Title: Solving YWH Dojo #51 — DeadBolt: From Zip Slip to Remote Code Execution
════════════════════════
𐀪 Author: 0xZeus
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 09:53:34 GMT
════════════════════════
⌗ Tags: #yeswehack #rce #zip_slip #ctf #licence_bypass
════════════════════════
𐀪 Author: 0xZeus
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 09:53:34 GMT
════════════════════════
⌗ Tags: #yeswehack #rce #zip_slip #ctf #licence_bypass
Medium
Solving YWH Dojo #51 — DeadBolt: From Zip Slip to Remote Code Execution
Introduction
⤷ Title: HackTheBox Walkthrough — Nanocorp
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 04:58:19 GMT
════════════════════════
⌗ Tags: #zip_file_upload #htb_nanocorp_writeup #checkmk_agent_exploit #ethical_hacking #ntlm_coercion
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 04:58:19 GMT
════════════════════════
⌗ Tags: #zip_file_upload #htb_nanocorp_writeup #checkmk_agent_exploit #ethical_hacking #ntlm_coercion
Medium
HackTheBox Walkthrough — Nanocorp
#Windows-Domain-Controller #Zip-file-upload-vulnerability #NTLM-coercion #library-ms #bloodyAD #Kerberos #Checkmk-agent #CVE-2024–0670…
⤷ Title: Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 02:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #notepad++ #Path Traversal #Zip Slip
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 02:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #notepad++ #Path Traversal #Zip Slip
Daily CyberSecurity
Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code
TL;DR Notepad++ v8.9.7 fixes five security flaws in the popular Windows editor. Technical details and proof-of-concept exploit code for all five Notepad++ vulnerabilities are public in the project…
⤷ Title: The Hollow Shell | Hacker Holidays Day 10 | TryHackMe Writeup
════════════════════════
𐀪 Author: Debmalya Mondal
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 22:36:52 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #zip_slip_vulnerability #tryhackme_writeup #tryhackme #local_file_inclusion
════════════════════════
𐀪 Author: Debmalya Mondal
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 22:36:52 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #zip_slip_vulnerability #tryhackme_writeup #tryhackme #local_file_inclusion
Medium
The Hollow Shell | Hacker Holidays Day 10 | TryHackMe Writeup
Exploiting Local File Inclusion and a Zip Slip Vulnerability to Gain Remote Code Execution on the Target Server
⤷ Title: The Hollow Shell TryHackMe walkthrough
════════════════════════
𐀪 Author: Crystalcascade14
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 22:11:22 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #hacker_holidays_2026 #zip_slip_vulnerability #tryhackme
════════════════════════
𐀪 Author: Crystalcascade14
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 22:11:22 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #hacker_holidays_2026 #zip_slip_vulnerability #tryhackme
Medium
The Hollow Shell TryHackMe walkthrough
During our Day 10 of Hacker’s Holidays we’ll exploit a Zip Slip vulnerability in a hotel’s file upload portal, using path traversal to drop…
⤷ Title: Hacker Holidays 2026 — Day 10: The Hollow Shell
════════════════════════
𐀪 Author: Piyush Manghnani
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 16:40:53 GMT
════════════════════════
⌗ Tags: #hacker_holidays_2026 #zip_slip #tryhackme #the_hollow_shell
════════════════════════
𐀪 Author: Piyush Manghnani
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 16:40:53 GMT
════════════════════════
⌗ Tags: #hacker_holidays_2026 #zip_slip #tryhackme #the_hollow_shell
Medium
Hacker Holidays 2026 — Day 10: The Hollow Shell
Room: The Hollow Shell Category: Web Difficulty: Medium Platform: TryHackMe