CVE-2025-52665 - RCE in Unifi Access ($25,000)
https://www.catchify.sa/post/cve-2025-52665-rce-in-unifi-os-25-000
https://www.catchify.sa/post/cve-2025-52665-rce-in-unifi-os-25-000
Catchify
CVE-2025-52665 - $25K RCE in UniFi Access | Catchify
Technical writeup: Pre-auth RCE via command injection in Ubiquiti UniFi Access backup API. Discovered by Catchify Security.
👍3👎2
❤6
What’s That Coming Over The Hill? (Monsta FTP Remote Code Execution CVE-2025-34299)
https://labs.watchtowr.com/whats-that-coming-over-the-hill-monsta-ftp-remote-code-execution-cve-2025-34299/
https://labs.watchtowr.com/whats-that-coming-over-the-hill-monsta-ftp-remote-code-execution-cve-2025-34299/
watchTowr Labs
What’s That Coming Over The Hill? (Monsta FTP Remote Code Execution CVE-2025-34299)
Happy Friday, friends and.. others.
We’re glad/sorry to hear that your week has been good/bad, and it’s the weekend/but at least it’s almost the weekend!
What’re We Doing Today, Mr Fox?
Today, in a tale that seems all too familar at this point,
We’re glad/sorry to hear that your week has been good/bad, and it’s the weekend/but at least it’s almost the weekend!
What’re We Doing Today, Mr Fox?
Today, in a tale that seems all too familar at this point,
Infrastructure Collapse: How a Forgotten Folder in Coca-Cola’s Network Exposed Critical…
https://medium.com/legionhunters/infrastructure-collapse-how-a-forgotten-folder-in-coca-colas-network-exposed-critical-a4d9dc1ab8a6
https://medium.com/legionhunters/infrastructure-collapse-how-a-forgotten-folder-in-coca-colas-network-exposed-critical-a4d9dc1ab8a6
Medium
Infrastructure Collapse: How a Forgotten Folder in Coca-Cola’s Network Exposed Critical Administrative Data
Hello Bug Hunters!
👏2
At the forefront of ethical hacking: What’s Intigriti’s impact and position?
https://www.intigriti.com/blog/business-insights/at-the-forefront-of-ethical-hacking-what-s-intigriti-s-impact-and-position
https://www.intigriti.com/blog/business-insights/at-the-forefront-of-ethical-hacking-what-s-intigriti-s-impact-and-position
Intigriti
At the forefront of ethical hacking: What’s Intigriti’s impact and position?
Organizations are increasingly seeking platforms that prioritize quality over quantity, fast response times, and strict data compliance. Here are eight elements to consider when selecting your bug bounty provider.
Release v3.4.8 · projectdiscovery/nuclei
https://github.com/projectdiscovery/nuclei/releases/tag/v3.4.8
https://github.com/projectdiscovery/nuclei/releases/tag/v3.4.8
GitHub
Release v3.4.8 · projectdiscovery/nuclei
What's Changed
Features & Improvements
Remove singletons from Nuclei engine (continuation of #6210) (#6296) by @hdm
Address race conditions in http.Request and MemGuardian (#6321) by @hdm
...
Features & Improvements
Remove singletons from Nuclei engine (continuation of #6210) (#6296) by @hdm
Address race conditions in http.Request and MemGuardian (#6321) by @hdm
...
Exploiting JWT Vulnerabilities: Advanced Exploitation Guide
https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-jwt-vulnerabilities
https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-jwt-vulnerabilities
Intigriti
Exploiting JWT Vulnerabilities: Advanced Exploitation Guide
Learn how to identify and exploit JSON Web Token (JWT) vulnerabilities using several different testing methods. Read the article now!
Introducing Credential Monitoring — ProjectDiscovery Blog
https://projectdiscovery.io/blog/leaked-credential-monitoring
https://projectdiscovery.io/blog/leaked-credential-monitoring
ProjectDiscovery
Introducing Credential Monitoring — ProjectDiscovery Blog
Imagine discovering that your company's login credentials are sitting in plain sight on the internet, accessible to anyone who knows where to look. Unfortunately, this isn't hypothetical – it's happening right now to organizations worldwide through malware…
Release v3.4.6 · projectdiscovery/nuclei
https://github.com/projectdiscovery/nuclei/releases/tag/v3.4.6
https://github.com/projectdiscovery/nuclei/releases/tag/v3.4.6
GitHub
Release v3.4.6 · projectdiscovery/nuclei
What's Changed
Fixed context leak in flow by @tarunKoyalwar in #6282
Other Changes
fixed log level mismatch by @knakul853 in #6271
fixed hex dump issue by @knakul853 in #6273
fix(headless): ...
Fixed context leak in flow by @tarunKoyalwar in #6282
Other Changes
fixed log level mismatch by @knakul853 in #6271
fixed hex dump issue by @knakul853 in #6273
fix(headless): ...
Release v3.4.7 · projectdiscovery/nuclei
https://github.com/projectdiscovery/nuclei/releases/tag/v3.4.7
https://github.com/projectdiscovery/nuclei/releases/tag/v3.4.7
GitHub
Release v3.4.7 · projectdiscovery/nuclei
What's Changed
Other Changes
Fixed issue with go install (github.com/zmap/zgrab2 v0.2.0 => v0.1.8) by @dwisiswant0 in #6295
Full Changelog: v3.4.6...v3.4.7
Other Changes
Fixed issue with go install (github.com/zmap/zgrab2 v0.2.0 => v0.1.8) by @dwisiswant0 in #6295
Full Changelog: v3.4.6...v3.4.7
Introducing native Jira Cloud integration for SonarQube Cloud
https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/
https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/
Sonarsource
Introducing native Jira Cloud integration for SonarQube Cloud
We are excited to announce the release of our new, native Jira integration for SonarQube Cloud, available for Team and Enterprise plans. This integration streamlines the development workflow by allowing users to create Jira issues from SonarQube findings…
Introducing native Jira Cloud integration for SonarQube Cloud
https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/
https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/
Sonarsource
Introducing native Jira Cloud integration for SonarQube Cloud
We are excited to announce the release of our new, native Jira integration for SonarQube Cloud, available for Team and Enterprise plans. This integration streamlines the development workflow by allowing users to create Jira issues from SonarQube findings…
Practical Android Pentesting: A Case Study on TikTok RCE
https://dphoeniixx.medium.com/practical-android-pentesting-a-case-study-on-tiktok-rce-4a82e79cc7c6
https://dphoeniixx.medium.com/practical-android-pentesting-a-case-study-on-tiktok-rce-4a82e79cc7c6
Medium
Practical Android Pentesting: A Case Study on TikTok RCE
From Universal XSS to native library hijacking: A comprehensive guide to Android exploitation using WebViews, Intent abuse, and Zip Slip.
🤔1
Introducing native Jira Cloud integration for SonarQube Cloud
https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/
https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/
Sonarsource
Introducing native Jira Cloud integration for SonarQube Cloud
We are excited to announce the release of our new, native Jira integration for SonarQube Cloud, available for Team and Enterprise plans. This integration streamlines the development workflow by allowing users to create Jira issues from SonarQube findings…
How Android provides the most effective protection to keep you safe from mobile scams
http://security.googleblog.com/2025/10/how-android-protects-you-from-scams.html
http://security.googleblog.com/2025/10/how-android-protects-you-from-scams.html
Google Online Security Blog
How Android provides the most effective protection to keep you safe from mobile scams
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Ab...
❤1
Balancer hack analysis and guidance for the DeFi ecosystem
https://blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/
https://blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/
The Trail of Bits Blog
Balancer hack analysis and guidance for the DeFi ecosystem
A retrospective on the $100M Balancer hack that occurred in November 2025, including long-term, strategic guidance on how to avoid similar bugs.
❤1
Announcing SonarQube MCP Server: Bringing code quality into your AI workflow
https://www.sonarsource.com/blog/announcing-sonarqube-mcp-server/
https://www.sonarsource.com/blog/announcing-sonarqube-mcp-server/
Sonarsource
Announcing SonarQube MCP Server: Bringing code quality into your AI workflow
AI is transforming software development and turbocharging many aspects of a developer's daily work. But it’s also bringing new challenges to your teams: how do you maintain code quality and security standards as the volume of AI-generated code doubles, triples…
❤4
Announcing SonarQube MCP Server: Bringing code quality into your AI workflow
https://www.sonarsource.com/blog/announcing-sonarqube-mcp-server/
https://www.sonarsource.com/blog/announcing-sonarqube-mcp-server/
Sonarsource
Announcing SonarQube MCP Server: Bringing code quality into your AI workflow
AI is transforming software development and turbocharging many aspects of a developer's daily work. But it’s also bringing new challenges to your teams: how do you maintain code quality and security standards as the volume of AI-generated code doubles, triples…