2026-08-26 05:18:13 UTC
live · 0 feeds · 0 degraded
sort: KEVCRITNEW
auto · no filters · all actual
▲ CRITICAL · KEV · 0DAY · last 7d 8 pinned
▶ EXPLOITS & POCs 9
6h ago ▶ EXP
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`. CRIT KEVPOC
CVE-2026-60004 is a critical vulnerability in Gitea that allows remote code execution without authentication.
github ·#CVE-2026-60004
48m ago ▶ EXP
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc) KEVPOC
Exploits an unauthenticated OS command injection in Zimbra's SNMP notification via crafted SMTP commands.
github ·#CVE-2026-73570#Zimbra
1h ago ▶ EXP
🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment. KEVPOC
Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.
github ·#CVE-2025-32463
3h ago ▶ EXP
jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain KEVPOC
Exploitation tools for CVE-2026-5281 and CVE-2026-11057 full chain vulnerabilities.
github ·#CVE-2026-5281#CVE-2026-11057
5h ago ▶ EXP
CVE-2026-73570 PoC KEVPOC
CVE-2026-73570 is a vulnerability with a proof of concept.
github ·#CVE-2026-73570
6h ago ▶ EXP
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server. KEVPOC
Educational demo showing mitigation and detection techniques for the critical Code Injection and Sandbox Escape vulnerability CVE-2026-72530 in TrueConf Server.
github ·#CVE-2026-72530
9h ago ▶ EXP
CVE-2026-73570 KEVPOC
No information available for this entry.
github ·#CVE-2026-73570
9h ago ▶ EXP
CVE-2026-35273 KEVPOC
Analyzes the details and impact of CVE‑2026‑35273.
github ·#CVE-2026-35273
10h ago ▶ EXP
CVE-2026-68820 — Mass Exploit Framework Edition. KEVPOC
This vulnerability allows attackers to use the Mass Exploit Framework to launch automated attacks against multiple targets.
github ·#CVE-2026-68820
◊ LABS & RESEARCH 9
6d ago ◇ LAB
Web fuzzing for hackers HIGH
Web fuzzing uncovers hidden endpoints and logic flaws that can be leveraged for privilege escalation or data exfiltration.
Intigriti
-1975m ago ◇ LAB
Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk
This report on cyber priorities and AI risk from the ASD may provide insight into potential vulnerabilities and attack vectors for red-teamers to exploit.
Huntress
6m ago ◇ LAB
Hack The Box : Cohort Full Walkthrough ( Linux ; Very Easy )
This walkthrough provides a step-by-step guide on exploiting a Linux machine, useful for red-teamers to practice and improve their skills.
InfoSec Writeups ·#Linux
7m ago ◇ LAB
The WAF Blocked My XSS — So I Rotated What It Was Reading
This article explains how to bypass WAF protections to successfully execute XSS attacks, a valuable technique for red-teamers to test web application security.
InfoSec Writeups
8m ago ◇ LAB
Bypassing AI Scanner Defenses to Exfiltrate Sensitive Information — PortSwigger Web Security…
This article discusses methods to evade AI-powered scanner defenses, allowing red-teamers to develop strategies for exfiltrating sensitive information and testing AI-driven security controls.
InfoSec Writeups
6h ago ◇ LAB
For all the uncertainty they cause, LLMs are pretty terrible at creating slides of question marks doing the conga
This matters because it highlights the limitations of Large Language Models in generating creative or meaningful content, which could be exploited by red-teamers to identify AI-generated material.
@natashenka.bsky.social
7h ago ◇ LAB
more than any other tech baron, sergey brin’s full heel turn has been sort of impossible to understand
This matters because understanding the motivations and actions of tech barons like Sergey Brin can provide insight into potential vulnerabilities or areas of influence that red-teamers can leverage.
@golikehellmachine.com
9h ago ◇ LAB
nitter.net is down. xcancel.com may go soon, too. all the respect to the folks at nitter for their services so far, but to be honest, X completely locking itself out of the web is probably a net positive for us all in the long term
This matters because the potential loss of alternative social media platforms like Nitter and Xcancel could impact the ability of red-teamers to gather intelligence or conduct operations on these platforms.
@patak.cat
13h ago ◇ LAB
C2PA Cameras Do Not Survive Contact With Reality
C2PA cameras fail under real-world conditions, meaning provenance metadata can be unreliable and adversaries could forge or tamper with media without detection.
Lobsters
☣ MALWARE 0
☣ RANSOM 6
★ NEWS 7
6d ago ◇ LAB
Web fuzzing for hackers HIGH
Web fuzzing uncovers hidden endpoints and logic flaws that can be leveraged for privilege escalation or data exfiltration.
Intigriti
6m ago ◇ LAB
Hack The Box : Cohort Full Walkthrough ( Linux ; Very Easy )
This walkthrough provides a step-by-step guide on exploiting a Linux machine, useful for red-teamers to practice and improve their skills.
InfoSec Writeups ·#Linux
7m ago ◇ LAB
The WAF Blocked My XSS — So I Rotated What It Was Reading
This article explains how to bypass WAF protections to successfully execute XSS attacks, a valuable technique for red-teamers to test web application security.
InfoSec Writeups
8m ago ◇ LAB
Bypassing AI Scanner Defenses to Exfiltrate Sensitive Information — PortSwigger Web Security…
This article discusses methods to evade AI-powered scanner defenses, allowing red-teamers to develop strategies for exfiltrating sensitive information and testing AI-driven security controls.
InfoSec Writeups
5h ago ◈ RAN
[Orova] Central Florida Civil LLC (US)
ransomlive
6h ago ◇ LAB
For all the uncertainty they cause, LLMs are pretty terrible at creating slides of question marks doing the conga
This matters because it highlights the limitations of Large Language Models in generating creative or meaningful content, which could be exploited by red-teamers to identify AI-generated material.
@natashenka.bsky.social
7h ago ◇ LAB
more than any other tech baron, sergey brin’s full heel turn has been sort of impossible to understand
This matters because understanding the motivations and actions of tech barons like Sergey Brin can provide insight into potential vulnerabilities or areas of influence that red-teamers can leverage.
@golikehellmachine.com
◈ PULSE & WATCH 24h
-24h-12hnow
#Fortinet 0
#Ivanti 0
#Citrix 1
#Chrome 0
#Kubernetes 0
#VMware 0
#OpenSSL 0
#Linux-Kernel 0