Search results

  1. Depov

    Cisco SD-WAN Vulnerability: Auth bypass Chain and Detection for SOC

    Why APT Groups Attack SD-WAN Controllers The Cisco Catalyst SD-WAN Manager (formerly vManage) is the only control point of the entire SD-WAN factory. It centrally rolls up configurations on edge devices on Cisco IOS XE, sets routing policies through SD-WAN Controller (vSmart) and orchestras...
  2. Depov

    Counterfeiting for support and replacement of comments. Security researcher found a dangerous vulnerability in YouTube robot

    Ask Studio is built into YouTube Studio and helps the authors to disassemble the statistics of the channel, as well as briefly retell the comments of the audience. Javox checked what would happen if the comment contains no ordinary review, but an instruction for AI. After several attempts, the...
  3. Depov

    Ordinary HDMI cable and window antenna. To steal data from computers without the Internet learned scientists

    Even a fully insulated computer can transmit data outward through a regular video cable. Specialists from Shandong University and the Quan Cheng laboratory described the TrojPix method, in which malware imperceptibly changes individual pixels on the screen and causes an HDMI cable to emit...
  4. Depov

    Already on Thursday: OpenAI releases GPT-5.6 – a model that the US authorities detained because of too good ability to hack the code

    OpenAI said it would open public access to the new line of GPT-5.6 models on Thursday. For several weeks, they were available only to a limited number of partners, since the release was an additional check by the American authorities. Now the company has received permission to launch a wider...
  5. Depov

    How To Learn Hacking

  6. Depov

    Pentest LLM and AI systems: from OWASP LLM Top 10 to regulatory mapping finds

    On the project to test a bank chatbot built on the RAG architecture, system propt and API keys to the three internal microservices were pulled out in forty minutes - through a combination of direct injection prompt and a contextual window manipulation. Neither Burp Suite nor Nuclei nor OWASP ZAP...
  7. Depov

    ClickFix attack via SQL injection CMS: analysis of the Ghost CMS campaign (CVE-2026-26980) and detection equipment

    One HTTP request to the public Content API – and the attacker takes Admin API Key without a single credential. Do not crumble anything, do not need to tribute admin, do not even know that the site on Ghost. Just crafted request to the endpoint that sticks out by design. In the three months...
  8. Depov

    Every Way You're Being WATCHED In Incognito Mode

  9. Depov

    It works fine. More than 70% of WordPress sites use outdated PHP versions

    Hundreds of WordPress sites for years remain a convenient target not because of rare vulnerabilities, but because of older versions of PHP, forgotten extensions and settings that owners once left “by default”. Kensys specialists studied the WordPress installations opened on the Internet and...
  10. Depov

    One system file eats up to 500 GB: Microsoft recognized the bug Windows 11, unnoticed devouring disk

    Windows 11 can quietly take hundreds of gigabytes on a system drive, even if the user does not store too many games, videos or programs on the computer. The reason was the failure in the service of Capability Access Manager, which manages the permissions of applications in Windows. Because of...
  11. Depov

    WhatsApp chats and hidden server substitution. Researchers have found a critical vulnerability in Attested TLS

    Confidence in secure clouds begins with a question to whom the data is actually sent, and a new formal check showed that the Attested TLS protocol is not always able to give the right answer. Attested TLS combines a secure TLS connection with remote certification. The server must...
  12. Depov

    Rumors of death were premature. Flipper Zero moves to a model based on the community

    Mature software projects rarely stop developing one day, and the legendary Flipper Zero will be no exception. The developers of Flipper Devices reported that the official development of the firmware will continue by limited forces, but updates and patches will still be released, including thanks...
  13. Depov

    Capcha was a trap: how a fake check Cloudflare infected a computer of an industrial company

    Solar 4RAYS experts dismantled the attack, where the check of captcha led to the infection of the work station of the Russian industrial company. The employee was lured to the phishing page with animated Cloudflare and persuaded to execute the command through the Win+R window. After entering...
  14. Depov

    Zero detecting on VirusTotal, three weeks in the wild. Analysis of the new Linux backdoor for routers

    The malware library can hide among ordinary system files for years, and the new Linux backdoor uses just such an example to attack iKuai routers. The sample with zero detection level was found on VirusTotal on July 1 of this year, although the first file was downloaded from Japan on June 8...
  15. Depov

    Attacks on LLM systems: from prompt injection to compromising the AI agent

    Kill chain attack on LLM: from reconnaissance to exfiltration The business logic of the attack: an attacker gains access to data or functions that he has no direct rights to using LLM as an intermediary. A financial impact is from API key leak (a thousand dollars per compute) to extilting client...
  16. Depov

    CVE-2026-28318: Unautoified DoS in SolarWinds Serv-U via Content-Encoding: deflate

    Business logic: why an attacker refuses to maintain an FTP server An uncertified DoS on a enterprise-environmental server is not an abstract “availability problem.” Here is what happens in practice: Automated file exchanges between counterparties stand up. In the financial sector, delayed...
  17. Depov

    How The FBI Finds Your REAL IP Address

  18. Depov

    How To Check If Your PC Is Hacked

  19. Depov

    The Secret Hacking Tools Used by the CIA & NSA

  20. Depov

    How The FBI Hacks You

Top Bottom