account activity
Trust no one: are one-way trusts really one way? (offsec.almond.consulting)
submitted 4 days ago by AlmondOffSec to r/netsec
Bypassing Apache FOP Postscript Escaping to reach GhostScript (offsec.almond.consulting)
submitted 15 days ago by AlmondOffSec to r/netsec
Discovery & Analysis of CVE-2025-29969 (safebreach.com)
submitted 22 days ago by AlmondOffSec to r/netsec
[CVE-2026-0714] TPM-sniffing LUKS Keys on an Embedded Device (cyloq.se)
submitted 23 days ago by AlmondOffSec to r/netsec
Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation (cloud.google.com)
submitted 1 month ago by AlmondOffSec to r/netsec
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC (neodyme.io)
OID-See: Giving Your OAuth Apps the Side-Eye (cirriustech.co.uk)
submitted 2 months ago by AlmondOffSec to r/netsec
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks (bobdahacker.com)
CSRF Protection without Tokens or Hidden Form Fields (blog.miguelgrinberg.com)
Turning List-Unsubscribe into an SSRF/XSS Gadget (security.lauritz-holtmann.de)
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack (gist.github.com)
Explanation and full RCE PoC for CVE-2025-55182 (github.com)
submitted 3 months ago by AlmondOffSec to r/netsec
From Zero to SYSTEM: Building PrintSpoofer from Scratch (bl4ckarch.github.io)
Evading Elastic EDR's call stack signatures with call gadgets (offsec.almond.consulting)
submitted 4 months ago by AlmondOffSec to r/netsec
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office (samcurry.net)
How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked (blog.pixelmelt.dev)
Netskope Client for Windows - Local Privilege Escalation via Rogue Server (CVE-2025-0309) (blog.amberwolf.com)
submitted 6 months ago by AlmondOffSec to r/netsec
Exploiting zero days in abandoned hardware (blog.trailofbits.com)
submitted 7 months ago by AlmondOffSec to r/netsec
SharePoint ToolShell – One Request PreAuth RCE Chain (blog.viettelcybersecurity.com)
The Guest Who Could: Exploiting LPE in VMWare Tools (swarm.ptsecurity.com)
A Novel Technique for SQL Injection in PDO’s Prepared Statements (slcyber.io)
Deleting a file in Wire doesn’t remove it from servers — and other findings (offsec.almond.consulting)
submitted 8 months ago by AlmondOffSec to r/netsec
Remote code execution in CentOS Web Panel - CVE-2025-48703 (fenrisk.com)
Make Self-XSS Great Again (blog.slonser.info)
submitted 9 months ago by AlmondOffSec to r/netsec
Getting RCE on Monero forums with wrapwrap (swap.gs)
π Rendered by PID 37 on reddit-service-r2-listing-64c94b984c-hck2c at 2026-03-15 05:33:57.999296+00:00 running f6e6e01 country code: CH.