⤷ Title: PHP Flaws: CVE-2025-1735 (SQLi/Crash) & CVE-2025-6491 (SOAP DoS) Threaten PHP Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:46:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_1735 #CVE_2025_6491 #cybersecurity #Denial of Service #dos #Null Pointer Dereference #pgsql #php #PostgreSQL #SOAP #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:46:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_1735 #CVE_2025_6491 #cybersecurity #Denial of Service #dos #Null Pointer Dereference #pgsql #php #PostgreSQL #SOAP #sql injection
Daily CyberSecurity
PHP Flaws: CVE-2025-1735 (SQLi/Crash) & CVE-2025-6491 (SOAP DoS) Threaten PHP Apps
PHP patches two flaws: CVE-2025-1735 allows SQL injection/crashes in pgsql, and CVE-2025-6491 enables DoS in SOAP via oversized XML. Update immediately!
⤷ Title: Critical Wing FTP Server RCE (CVE-2025-47812) Actively Exploited In The Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:38:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:38:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
Daily CyberSecurity
Critical Wing FTP Server RCE (CVE-2025-47812) Actively Exploited In The Wild
Huntress witnessed active exploitation of a critical RCE flaw (CVE-2025-47812) in Wing FTP Server, allowing root/SYSTEM access via null byte injection and Lua code execution.
⤷ Title: CISA Warns of Active Exploitation of Wing FTP Server Flaw (CVE-2025-47812), CVSS 10
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:55:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:55:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
Daily CyberSecurity
CISA Warns of Active Exploitation of Wing FTP Server Flaw (CVE-2025-47812), CVSS 10
CISA adds critical Wing FTP Server RCE flaw (CVE-2025-47812, CVSS 10.0) to KEV. Actively exploited via null byte and Lua code injection; patch to 7.4.4 immediately!
⤷ Title: $500 Bounty: Unauthorized Folder Creation with Null Name
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Sat, 25 Oct 2025 13:31:13 GMT
════════════════════════
⌗ Tags: #hacking #infosec #null_safety #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Sat, 25 Oct 2025 13:31:13 GMT
════════════════════════
⌗ Tags: #hacking #infosec #null_safety #bug_bounty #cybersecurity
Medium
$500 Bounty: Unauthorized Folder Creation with Null Name
Hey everyone, In this write-up, I’ll share a simple but impactful bug I found in a SaaS recruitment platform that allowed me to create a…
⤷ Title: CORS Vulnerability with Trusted Null Origin
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sat, 08 Nov 2025 02:01:55 GMT
════════════════════════
⌗ Tags: #cors_attack #bug_bounty #cors_exploit #null_origin_attack #cors_misconfiguration
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sat, 08 Nov 2025 02:01:55 GMT
════════════════════════
⌗ Tags: #cors_attack #bug_bounty #cors_exploit #null_origin_attack #cors_misconfiguration
Medium
CORS Vulnerability with Trusted Null Origin
Discover how a simple CORS misconfiguration can leak sensitive data across origins.
⤷ Title: CORS Vulnerability with Trusted Null Origin
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:34:10 GMT
════════════════════════
⌗ Tags: #cors_attack #bug_bounty #cors_exploit #null_origin_attack #cors_misconfiguration
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:34:10 GMT
════════════════════════
⌗ Tags: #cors_attack #bug_bounty #cors_exploit #null_origin_attack #cors_misconfiguration
Medium
CORS Vulnerability with Trusted Null Origin
Discover how a simple CORS misconfiguration can leak sensitive data across origins.
⤷ Title: File Path Traversal, Validation of File Extension with Null Byte Bypass
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sat, 10 Jan 2026 05:52:55 GMT
════════════════════════
⌗ Tags: #directory_traversal #file_path_traversal #bug_bounty #bypass_extension_file #null_byte_bypass
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sat, 10 Jan 2026 05:52:55 GMT
════════════════════════
⌗ Tags: #directory_traversal #file_path_traversal #bug_bounty #bypass_extension_file #null_byte_bypass
Medium
File Path Traversal, Validation of File Extension with Null Byte Bypass
How weak filename checks lead to arbitrary file reads in web applications.
⤷ Title: Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
Daily CyberSecurity
Hidden in Plain Sight: TA584 Deploys "Tsundere Bot" & Invisible Registry Keys
TA584 triples activity with new "Tsundere Bot" malware. Attackers use invisible Registry keys to hide persistence. Read the Proofpoint analysis.
⤷ Title: Null Byte Nightmare: Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 02:47:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Upload #CVE_2026_1357 #Lucas Montes #Null Byte Key #Patch Alert #Plugin Vulnerability #Remote Code Execution #site takeover #wordpress security #WPvivid Backup
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 02:47:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Upload #CVE_2026_1357 #Lucas Montes #Null Byte Key #Patch Alert #Plugin Vulnerability #Remote Code Execution #site takeover #wordpress security #WPvivid Backup
Daily CyberSecurity
Null Byte Nightmare: Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites
Critical WPvivid Backup flaw CVE-2026-1357 (CVSS 9.8) allows unauthenticated file upload via null byte key. Update to v0.9.124 to prevent RCE.
⤷ Title: Predictable Secrets: The “Null Key” Flaw in Matrix’s Vodozemac Library That Could Expose Conversational History
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 07:17:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #cryptographic audit #end_to_end encryption #Matrix #null key attack #Olm #protocol downgrade #Rust security #Soatok #Tech News 2026 #Vodozemac #X25519
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 07:17:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #cryptographic audit #end_to_end encryption #Matrix #null key attack #Olm #protocol downgrade #Rust security #Soatok #Tech News 2026 #Vodozemac #X25519
Penetration Testing Tools
Predictable Secrets: The "Null Key" Flaw in Matrix’s Vodozemac Library That Could Expose Conversational History
The proprietor of the Soatok weblog has promulgated an exhaustive exposition detailing the vulnerabilities within Vodozemac, the Rust-based