Search results

  1. Depov

    Zero byte broke PHP protection and opened the way to SQL injection

    Positive Technologies researchers found in PHP two errors at the junction of the usual code of web applications and low-level database drivers. One vulnerability opened the way to SQL injection in the Firebird driver through a zero byte in the row, and the other could drop the PHP process when...
  2. Depov

    Red Team for Business: ROI Framework and Pickname for CFO

    Why Businesses Don't Buy "14 Critical Vulnerabilities" Business management operates in three categories: revenue, costs and risks. Severity, CVSS score, lateral movement - none of these words fall into any of them. The result: red team is perceived as an item of expenditure without measurable...
  3. Depov

    CVE-2026-33032: Operation of Nginx UI vulnerability – from auth bypass to full server capture

    Business logic of attack: why the attacker Nginx UI Nginx UI is an open-source web interface for managing Nginx with an active community on GitHub and a decent number of downloads from Docker Hub. Through the panel, administrators rule the configuration of virtual hosts, manage SSL certificates...
  4. Depov

    Hacking for $ 2.4 million and closing the service. Ctrlet Wallet Skick Stops Working

    Cryptocosts rarely close in one day, but sometimes one vulnerability is enough for the service to decide to leave the market. Ctrl Wallet announced that it was shutting down a few weeks after the security incident, and asked users to withdraw the assets by August 3, 2026. The problems began on...
  5. Depov

    Today is a password module, tomorrow for databases. Iranian Hackers Build a Virus as a Designer

    Iranian hackers have turned the usual tools of system administrators into a path to secure networks. The Cavern Manticore group uses the new modular platform Cavern to attack Israeli government agencies and IT companies, Check Point experts have found. In some cases, the attackers first hacked...
  6. Depov

    Do you have an ASUS router? Check the firmware right now. We tell you how not to become a free intermediary in the dismantling of world special servic

    Cisco Talos specialists have revealed new details about the UAT-7810 group, which is developing the LapDogs ORB network and infects routers so that other groups associated with China can hide their own operations through them. According to Talos, the UAT-7810 does not just hack into...
  7. Depov

    I Hacked A Website With ONE Command

  8. Depov

    Your secret phrase was just guessed. Hackers began to clean crypto wallets with impunity

    The weak place of the crypto wallet is often hidden not in the blockchain, but in the moment when the user first receives the recovery phrase. Coinspect has described the vulnerability of Ill Bloom, which is already being used to withdraw funds from wallets created under certain conditions...
  9. Depov

    Blade attacks in seconds: MaxPatrol Carbon 26.2 accelerated the simulation by 20 times

    Positive Technologies has updated MaxPatrol Carbon to version 26.2 and focused on faster modeling of attacks in corporate infrastructures. The system now calculates the possible routes of the attacker 20 times faster and covers 81% of the technique of the MITRE ATT&CK matrix of version 15.1. For...
  10. Depov

    The developer has created a chess rating for the code – to catch the degradation from AI before it becomes late

    AI assistants are increasingly writing code for developers, but with convenience there is less noticeable risk: the usual skills can weaken without obvious signs. Indian developer Ashutos Rat proposed to check such degradation with the help of Atrophy, a new team line utility for regular...
  11. Depov

    Blade attacks in seconds: MaxPatrol Carbon 26.2 accelerated the simulation by 20 times

    Positive Technologies has updated MaxPatrol Carbon to version 26.2 and focused on faster modeling of attacks in corporate infrastructures. The system now calculates the possible routes of the attacker 20 times faster and covers 81% of the technique of the MITRE ATT&CK matrix of version 15.1. For...
  12. Depov

    The developer has created a chess rating for the code – to catch the degradation from AI before it becomes late

    AI assistants are increasingly writing code for developers, but with convenience there is less noticeable risk: the usual skills can weaken without obvious signs. Indian developer Ashutos Rat proposed to check such degradation with the help of Atrophy, a new team line utility for regular...
  13. Depov

    Google Dorks for reconnaissance external attack: from passive recon to pre-exploitation

    On the external pentest, the first critical find took 11 minutes. Not Nmap, not Burp - request site:target.com filetype:env "DB_PASSWORD" returned the file from credentials from the production base. Host ev-payments.target.com did not appear in the scough, because the customer forgot about it...
  14. Depov

    Data leakage via Zendesk: kill chain, detection gap and checklist for SOC

    Two major incidents in six months - Crunchyroll and Discord - and one vector: Zendesk. Not zero-day in code, not RCE, not something beautiful. Ordinary compromising the agency account through an outsourcer. In March 2026, Crunchyroll confirmed the leak. According to Have I Been Pwned, 1 195 684...
  15. Depov

    They broke one bot, captured the others. The vulnerability in Google Cloud gave hackers the correspondence of users

    The editing resolution of one chatbot turned out to be the key to the entire system: the vulnerability of Rogue Agent in Google Dialogflow CX allowed an attacker with access to one agent to intercept the rest of the agents with blocks of code in the same Google Cloud project. According to the...
  16. Depov

    Capture Kubernetes and drive out the neighbors. How the Brazen Cloud Worry of the Month Works Works

    The cloud infrastructure has become an arena of struggle not only between defenders and attackers, but also between the malicious groups themselves: the new CAI worm infects servers, steals accounts, mines cryptocurrency and removes competitors’ programs. Cloud AI Infrastructure Attack...
  17. Depov

    You hid the repository, but the AI assistant decided to publish its contents. Analysis of GitLost Vulnerability

    An ordinary application in the error tracking system can be a hidden team for AI. Experts Noma Labs showed how through one GitHub Issue force GitHub Agentic Workflows to disclose the contents of the closed repository in an open comment. GitHub Agentic Workflows combines GitHub Actions with a...
  18. Depov

    How Hackers Clone Your Voice

  19. Depov

    How Hackers Hack Phones

  20. Depov

    AI development of exploits: how LLM compress the time from CVE to work exploit

    wo years ago, the average time from disclosure to operation was 32 days. Now a third of exploits appear on the day of publication CVE or earlier. Below - how exactly AI compresses the path from CVE to the exploit, which workflow works in practice and where automation predictably breaks...
Top Bottom