⤷ Title: Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Mon, 10 Feb 2025 01:48:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #Code Injection Attacks #Godzilla #ViewState
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Mon, 10 Feb 2025 01:48:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #Code Injection Attacks #Godzilla #ViewState
Daily CyberSecurity
Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks
Discover the dangers of code injection attacks in web applications. Explore the vulnerability of ViewState and how to prevent remote code execution.
⤷ Title: ConnectWise Patches Critical ViewState RCE Vulnerability in ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 26 Apr 2025 00:20:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #code_injection #ConnectWise #CVE_2025_3935 #RCE ASP.NET #Remote Code Execution #ScreenConnect #security advisory #ViewState
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 26 Apr 2025 00:20:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #code_injection #ConnectWise #CVE_2025_3935 #RCE ASP.NET #Remote Code Execution #ScreenConnect #security advisory #ViewState
Daily CyberSecurity
ConnectWise Patches Critical ViewState RCE Vulnerability in ScreenConnect
ConnectWise addresses a critical ViewState code injection flaw in ScreenConnect. If machine keys are compromised, RCE is possible. Update immediately!
⤷ Title: Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
Penetration Testing Tools
Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
Gold Melody (Prophet Spider) is exploiting leaked ASP.NET machine keys to launch stealthy, memory-only attacks on global corporate systems.
⤷ Title: Mandiant Reveals Attack Exploiting a Publicly Known Sitecore Key
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 07 Sep 2025 02:13:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #hacking #Mandiant #remote code execution #Sitecore #ViewState #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 07 Sep 2025 02:13:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #hacking #Mandiant #remote code execution #Sitecore #ViewState #vulnerability
Penetration Testing Tools
Mandiant Reveals Attack Exploiting a Publicly Known Sitecore Key
A new report reveals attackers are exploiting an old, publicly available Sitecore key to achieve remote code execution and compromise legacy deployments.
⤷ Title: Exploited Zero-Day: Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11371 #Gladinet #lfi #local file inclusion #rce #Triofox #ViewState Deserialization #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11371 #Gladinet #lfi #local file inclusion #rce #Triofox #ViewState Deserialization #zero_day
Daily CyberSecurity
Exploited Zero-Day: Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
A Zero-Day LFI flaw (CVE-2025-11371) in Gladinet/Triofox is being actively exploited. Attackers retrieve the Web.config machine key to chain into an unauthenticated RCE exploit.
⤷ Title: PATCH NOW: Critical Gladinet RCE Flaw Exploits Hardcoded Crypto to Steal Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES #CentreStack #CVE_2025_30406 #cybersecurity #Gladinet #Hardcoded Key #Huntress #RCE #Triofox #ViewState Deserialization
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES #CentreStack #CVE_2025_30406 #cybersecurity #Gladinet #Hardcoded Key #Huntress #RCE #Triofox #ViewState Deserialization
Penetration Testing Tools
PATCH NOW: Critical Gladinet RCE Flaw Exploits Hardcoded Crypto to Steal Keys
Gladinet is facing fresh trouble once again: vulnerabilities have been uncovered in its CentreStack and Triofox products stemming
⤷ Title: Cryptographic Homogeneity and Supply-Chain Contamination: Deconstructing the CVE-2026-5426 Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:06:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASP.NET hardcoded machineKey exploit #BLUEBEAM Godzilla web shell #Cobalt Strike BEACON dropper #Digital Knowledge LMS breach #IIS w3wp.exe memory forensics #KnowledgeDeliver CVE_2026_5426 patch #Mandiant threat intelligence telemetry #ViewState deserialization vulnerability #watering hole cyber attack #Windows Event ID 1316 anomaly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:06:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASP.NET hardcoded machineKey exploit #BLUEBEAM Godzilla web shell #Cobalt Strike BEACON dropper #Digital Knowledge LMS breach #IIS w3wp.exe memory forensics #KnowledgeDeliver CVE_2026_5426 patch #Mandiant threat intelligence telemetry #ViewState deserialization vulnerability #watering hole cyber attack #Windows Event ID 1316 anomaly
Information Security News
KnowledgeDeliver CVE-2026-5426 Patch Fixes Critical RCE
Mandiant warns of CVE-2026-5426: a critical KnowledgeDeliver patch fixing hardcoded ASP.NET machine keys exploited to deploy BLUEBEAM web shells.