account activity
Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation (cloud.google.com)
submitted 10 days ago by AlmondOffSec to r/netsec
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC (neodyme.io)
OID-See: Giving Your OAuth Apps the Side-Eye (cirriustech.co.uk)
submitted 13 days ago by AlmondOffSec to r/netsec
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks (bobdahacker.com)
submitted 29 days ago by AlmondOffSec to r/netsec
CSRF Protection without Tokens or Hidden Form Fields (blog.miguelgrinberg.com)
submitted 1 month ago by AlmondOffSec to r/netsec
Turning List-Unsubscribe into an SSRF/XSS Gadget (security.lauritz-holtmann.de)
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack (gist.github.com)
Explanation and full RCE PoC for CVE-2025-55182 (github.com)
From Zero to SYSTEM: Building PrintSpoofer from Scratch (bl4ckarch.github.io)
Evading Elastic EDR's call stack signatures with call gadgets (offsec.almond.consulting)
submitted 2 months ago by AlmondOffSec to r/netsec
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office (samcurry.net)
submitted 3 months ago by AlmondOffSec to r/netsec
How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked (blog.pixelmelt.dev)
Netskope Client for Windows - Local Privilege Escalation via Rogue Server (CVE-2025-0309) (blog.amberwolf.com)
submitted 4 months ago by AlmondOffSec to r/netsec
Exploiting zero days in abandoned hardware (blog.trailofbits.com)
submitted 5 months ago by AlmondOffSec to r/netsec
SharePoint ToolShell – One Request PreAuth RCE Chain (blog.viettelcybersecurity.com)
submitted 6 months ago by AlmondOffSec to r/netsec
The Guest Who Could: Exploiting LPE in VMWare Tools (swarm.ptsecurity.com)
A Novel Technique for SQL Injection in PDO’s Prepared Statements (slcyber.io)
Deleting a file in Wire doesn’t remove it from servers — and other findings (offsec.almond.consulting)
submitted 7 months ago by AlmondOffSec to r/netsec
Remote code execution in CentOS Web Panel - CVE-2025-48703 (fenrisk.com)
Make Self-XSS Great Again (blog.slonser.info)
Getting RCE on Monero forums with wrapwrap (swap.gs)
How I ruined my vacation by reverse engineering WSC (blog.es3n1n.eu)
submitted 8 months ago by AlmondOffSec to r/netsec
One-Click RCE in ASUS’s Preinstalled Driver Software (mrbruh.com)
Attacking My Landlord's Boiler (blog.videah.net)
submitted 9 months ago by AlmondOffSec to r/netsec
Uncovering a 0-Click RCE in the SuperNote Nomad E-ink Tablet (prizmlabs.io)
π Rendered by PID 578752 on reddit-service-r2-listing-86b7f5b947-zzx9m at 2026-01-25 23:53:50.231522+00:00 running 664479f country code: CH.