SecList for CyberStudents
240 subscribers
589 photos
24 videos
211 files
900 links
Think outside the box
Download Telegram
Forwarded from Turan Security
⚠️ AuraAudit (AuraInspector): Salesforce Aura muhitidagi noto‘g‘ri sozlamalarni aniqlovchi ochiq manbali xavfsizlik vositasi

Kiberxavfsizlik sohasida yetakchi kompaniyalardan biri bo‘lgan Mandiant Salesforce platformasida xavfsizlikni kuchaytirishga qaratilgan yangi ochiq manbali vositani taqdim etdi. AuraInspector (ko‘pincha AuraAudit deb ham ataladi) — bu buyruqlar satrida ishlovchi (CLI) audit vositasi bo‘lib, Salesforce Aura framework’idagi kirish huquqlarining noto‘g‘ri sozlanishini aniqlash va tahlil qilish uchun mo‘ljallangan.

⚠️ Mazkur vosita, ayniqsa, Salesforce Experience Cloud muhitlarida tez-tez uchraydigan va jiddiy oqibatlarga olib kelishi mumkin bo‘lgan xavfsizlik bo‘shliqlarini aniqlashga yordam beradi.

📱 Batafsil

PS : UZCERTning rasmiy kanaliga a'zo bo'lishni maslahat qilamiz.

#AuraAudit #AuraInspector #Salesforce #Aura #xavfsizlik #vosita
🚀 UZCERT xizmatining rasmiy telegram sahifasiga a’zo bo‘ling!
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1🔥1
BrowserHistoryCapturer_v1.4.5.zip
3.3 MB
🔎Browser History Capturer
📝Инструмент, позволяющий легко собирать историю веб-браузеров на компьютере с Windows. Инструмент можно запускать с USB-накопителя для сбора истории из браузеров Chrome, Edge, Firefox и Internet Explorer.

#Windows #Forensic #Browser
Forwarded from Proxy Bar
CVE-2026-22812 OpenCode Unauthenticated RCE
*
OpenCode < 1.0.216
*
exploit
Sirius is an open-source comprehensive vulnerability scanner that leverages community-driven security intelligence and automated penetration testing capabilities. v0.4.0 introduces comprehensive system monitoring and observability features. Get started in minutes with our Docker-based setup.

Source: https://github.com/SiriusScan/Sirius
A little toolbox to play with Microsoft Kerberos in C

Source: https://github.com/gentilkiwi/kekeo

#RedTeam #Pentest #AD #kekeo
Read PostgreSQL data files without credentials - forensics, data recovery, and security research tool

Source: https://github.com/Chocapikk/pgread

#DFIR #Tool #PostgreSQL
Forwarded from JavaSec
Men Nvidiani buzgan birinchi o’zbekmanmi?

Bulletin

CVE - (not published yet)
JavaSec
Photo
Congratualtion bro I am happy for you 🔥🔥🔥🔥
3🔥2
Forwarded from Offensive Xwitter
📞 Microsoft fixed an authenticated RCE in Windows Telephony Service (CVE-2026-20931), discovered by researcher Sergey Bliznyuk.

Read the write-up:

🔗 https://swarm.ptsecurity.com/whos-on-the-line-exploiting-rce-in-windows-telephony-service/
🔗 https://habr.com/ru/companies/pt/articles/984934/