Ivan Ožić Bebek
obivan@infosec.exchange
<p>:hacker_h: :hacker_a: :hacker_c: :hacker_k: :hacker_e: :hacker_r: :hacker_m: :hacker_a: :hacker_n:</p>
Posts
-
View post
The firmware security analyzer https://github.com/e-m-b-a/emba
-
View post
Debian LPE PoC (CVE-2026-80714) https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-80714-Debian-6.12.101
-
View post
Apparently Windows 11 writes full WebAuthn assertions into the event log https://specterops.io/wp-content/uploads/sites/3/2026/08/Pass-the-Passkey_A4_v2.pdf
-
View post
Sophos Intercept X: A Technical Bypass https://yenn503.github.io/posts/sophos-intercept-x-bypass/
-
View post
Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/
-
View post
Borrowing Windows Hello keys for authentication and persistence https://dirkjanm.io/borrowing-windows-hello-keys/
-
View post
TLS Encryption and Compliance https://trustedsec.com/blog/tls-encryption-and-compliance
-
View post
Can we *really* automate with AI? https://blog.ninetailedf0x.com/posts/can-we-really-automate-with-ai-p2/
-
View post
The AI Pentesting Winners May Not Be AI Startups https://pentesterlab.com/blog/the-ai-pentesting-winners-may-not-be-ai-startups
-
View post
The Biggest HackRF Upgrade in Over a Decade https://www.youtube.com/watch?v=n-khaJyY50Y
-
View post
Clustered Points of Failure https://specterops.io/blog/2026/07/29/clustered-points-of-failure/#
-
View post
Authentication bypass for Check Point Security Management Server and Multi-Domain Security Management Server https://github.com/sfewer-r7/CVE-2026-16232
-
View post
CVE-2026-50469 - ProjFS File Delete https://bad-jubies.github.io/projected-file-system-file-delete-cve-2026-50469
-
View post
Pure-impacket parallel local-admin discovery via RBCD https://github.com/nnnnino/rbcdbrute
-
View post
Related to ESC17, this tool opens so many possibilities for man-in-the-middle and relay attacks in Active Directory https://github.com/qu35t-code/adecrypt
-
View post
ESC17 - Beyond WSUS https://research.qu35t.pw/en/series/esc17-beyond-wsus/
-
View post
Did an AI Really Hack Hugging Face? https://youtu.be/q2KCrmQz9WE
-
View post
Introducing Burp AT: agentic AI, built on two decades of Burp Suite https://portswigger.net/blog/introducing-burp-at
-
View post
PoC for CVE-2026-61511, unauthenticated vBulletin RCE https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
-
View post
This is interesting, I wasn't aware that clipboard inside of VM listens for host clipboard all the time. Same behaviour on VMware Workstation. https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
-
View post
Privacy-Perserving Attack Path Analysis for Bloodhound https://github.com/abhisek3122/HoundMasker
-
View post
The SID that wasn't there: bypassing KB5014754 to Domain Admin on a fully patched AD CS https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-bypass/
-
View post
Special Token Injection (STI) Attack Guide https://blog.sentry.security/special-token-injection-sti-attack-guide/
-
View post
PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) https://github.com/DepthFirstDisclosures/Nginx-Rift/
-
View post
FastJson 1.2.83 RCE (CVE-2026-16723) https://fearsoff.org/research/fastjson-1-2-83-rce
-
View post
GitLab Oj RCE PoC https://github.com/wupco/gitlab-rce-demo
-
View post
Open Weights and American AI Leadership https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/
-
View post
AdaptixC2 & Domain Trusts: Chained Compromise of a Multi-Forest Active Directory Environment https://medium.com/@Xotourliff/adaptixc2-domain-trusts-chained-compromise-of-a-multi-forest-active-directory-environment-8e9f9dfa2ff7
-
View post
Pentest and Red Team TTPs with RustPack https://www.msecops.de/blog/posts/rustpack-features/
-
View post
So OpenAI (Sol) hacked HuggingFace? https://openai.com/index/hugging-face-model-evaluation-security-incident/