DEV Community

Anoymask profile picture

Anoymask

404 bio not found

Joined Joined on  twitter website
GiveWP CVE-2026-82222: RCE Chain from Unauthenticated Registration to PHP Object Injection

GiveWP CVE-2026-82222: RCE Chain from Unauthenticated Registration to PHP Object Injection

Comments
5 min read

Want to connect with Anoymask?

Create an account to connect with Anoymask. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
PaperCut Authentication Bypass and Dynamic Class Loading: Pre-authentication RCE Chain Actively Exploited

PaperCut Authentication Bypass and Dynamic Class Loading: Pre-authentication RCE Chain Actively Exploited

Comments
5 min read
Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

Comments
4 min read
Citrix NetScaler CVE-2026-8452: SAML Heap Overflow to Root RCE and Web Shell Deployment

Citrix NetScaler CVE-2026-8452: SAML Heap Overflow to Root RCE and Web Shell Deployment

Comments 2
7 min read
TA4922 PackClient Attacks: From Tax Documents to DLL Side-Loading and RAT Deployment

TA4922 PackClient Attacks: From Tax Documents to DLL Side-Loading and RAT Deployment

Comments 2
5 min read
SPEAKINGSTONE and DARKLANTERN in ZBT-Based White-Label Routers: WAN-Accessible Root Shell and DNS Hijacking

SPEAKINGSTONE and DARKLANTERN in ZBT-Based White-Label Routers: WAN-Accessible Root Shell and DNS Hijacking

Comments 2
5 min read
Safely Analyzing Obfuscated JavaScript: Step-by-Step Phishing Kit Restoration

Safely Analyzing Obfuscated JavaScript: Step-by-Step Phishing Kit Restoration

Comments 2
5 min read
Nearly 700 Rogue AI Agents Coordinated in the Hugging Face Attack: Lateral Movement from Artifactory Across Multiple Regions

Nearly 700 Rogue AI Agents Coordinated in the Hugging Face Attack: Lateral Movement from Artifactory Across Multiple Regions

Comments 2
5 min read
Attacks on Water OT: Over 100 Internet-Exposed Systems Targeted in July

Attacks on Water OT: Over 100 Internet-Exposed Systems Targeted in July

Comments
5 min read
When AI Infrastructure Becomes the Target: Attacks Observed on LiteLLM, RAGFlow, and Kestra

When AI Infrastructure Becomes the Target: Attacks Observed on LiteLLM, RAGFlow, and Kestra

Comments
6 min read
NovaCookies: Microsoft 365 AiTM Exploiting Trusted Docusign and Microsoft Redirects

NovaCookies: Microsoft 365 AiTM Exploiting Trusted Docusign and Microsoft Redirects

Comments
6 min read
Gitea CVE-2026-60004: Active Exploitation of RCE via diffpatch API to Install Git Hooks

Gitea CVE-2026-60004: Active Exploitation of RCE via diffpatch API to Install Git Hooks

Comments
5 min read
SharePoint Authentication Bypass and RCE Chain Attack Observed: CVE-2026-55040 / CVE-2026-63520

SharePoint Authentication Bypass and RCE Chain Attack Observed: CVE-2026-55040 / CVE-2026-63520

Comments
5 min read
Dark Caracal's New Malware GoCaracal: From SVG Phishing to Ethereum Backup C2

Dark Caracal's New Malware GoCaracal: From SVG Phishing to Ethereum Backup C2

Comments
6 min read
Unit 42: Real-World Prevalence of 405 AI-Related Malware Samples and Evaluation of Existing Defenses

Unit 42: Real-World Prevalence of 405 AI-Related Malware Samples and Evaluation of Existing Defenses

Comments
7 min read
Reconstructing JavaScript from HTML Tag Names: An XSS and WAF Blocklist Evasion Technique

Reconstructing JavaScript from HTML Tag Names: An XSS and WAF Blocklist Evasion Technique

Comments
6 min read
FURUNO FA-50: Hard-coded Credentials and Missing Authentication for Certain Settings (CVE-2026-59769 / CVE-2026-67578)

FURUNO FA-50: Hard-coded Credentials and Missing Authentication for Certain Settings (CVE-2026-59769 / CVE-2026-67578)

Comments
6 min read
CISA "A Tale of Two SOCs": Detection and Containment from Two Red Team Assessments

CISA "A Tale of Two SOCs": Detection and Containment from Two Red Team Assessments

Comments
6 min read
Active Exploitation of Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962

Active Exploitation of Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962

1
Comments 2
6 min read
Two Vulnerabilities Bypassing Signature Verification in miniOrange SAML SSO

Two Vulnerabilities Bypassing Signature Verification in miniOrange SAML SSO

1
Comments
10 min read
CVE-2026-75501: Calix Router WAN-side UPnP Exposes Internal Devices

CVE-2026-75501: Calix Router WAN-side UPnP Exposes Internal Devices

1
Comments
10 min read
ToxicPanda 2.0 Chains VPN, Accessibility, and ADB

ToxicPanda 2.0 Chains VPN, Accessibility, and ADB

Comments
11 min read
JarService / zhima Malware Entering via Insecure Android Car Head Unit Update Paths

JarService / zhima Malware Entering via Insecure Android Car Head Unit Update Paths

1
Comments
9 min read
E4del / PINHOLE Using FTP Banners for Command Retrieval

E4del / PINHOLE Using FTP Banners for Command Retrieval

Comments
5 min read
TrueConf Server Exploitation: PhantomCore Delivered via CVE-2026-72529 / 72530

TrueConf Server Exploitation: PhantomCore Delivered via CVE-2026-72529 / 72530

Comments
5 min read
Three Russian-Linked Clusters Abuse Legitimate Authentication Flows

Three Russian-Linked Clusters Abuse Legitimate Authentication Flows

Comments
6 min read
SynkLoader Deploying Multi-Stage Modules via Teams Phishing

SynkLoader Deploying Multi-Stage Modules via Teams Phishing

Comments
5 min read
JavaScript Sandbox Escape via Type Confusion in isolated-vm

JavaScript Sandbox Escape via Type Confusion in isolated-vm

Comments
5 min read
Rust Crate Tampering: Multi-Stage Info-Stealer Malware Launched via build.rs

Rust Crate Tampering: Multi-Stage Info-Stealer Malware Launched via build.rs

Comments
6 min read
MLflow CVE-2026-64849: Cloud Credential Theft via Webhook SSRF

MLflow CVE-2026-64849: Cloud Credential Theft via Webhook SSRF

Comments
6 min read
UAT-10147 AI-Assisted Intrusion and SPECTRE Malware

UAT-10147 AI-Assisted Intrusion and SPECTRE Malware

Comments
7 min read
Manic Android Malware: Information Theft via Transparent Overlays and Short-Range Device Relaying

Manic Android Malware: Information Theft via Transparent Overlays and Short-Range Device Relaying

Comments
6 min read
Zimbra CVE-2026-73570: Unauthenticated Command Injection via SMTP

Zimbra CVE-2026-73570: Unauthenticated Command Injection via SMTP

Comments
6 min read
SilkParasite: Cloud C2 and Multi-Language RATs Targeting Central Asia

SilkParasite: Cloud C2 and Multi-Language RATs Targeting Central Asia

Comments
6 min read
LSHIY: Large-Scale Password Spraying Abusing ROPC and IPv6

LSHIY: Large-Scale Password Spraying Abusing ROPC and IPv6

Comments
5 min read
Operation CameraSwarm: Over 14,000 Dahua Cameras Compromised via Three Attack Vectors

Operation CameraSwarm: Over 14,000 Dahua Cameras Compromised via Three Attack Vectors

Comments
6 min read
Active Exploitation of Windows IKE Extension RCE (CVE-2026-33824)

Active Exploitation of Windows IKE Extension RCE (CVE-2026-33824)

Comments
5 min read
AI-Generated Attack Tools Targeting Siemens S7 PLCs

AI-Generated Attack Tools Targeting Siemens S7 PLCs

Comments
5 min read
Forminator Forms (CVE-2026-15748): Unauthenticated RCE via Forged Upload Settings in Select Fields

Forminator Forms (CVE-2026-15748): Unauthenticated RCE via Forged Upload Settings in Select Fields

1
Comments
6 min read
Clop's Windchill Web Shell: From Credential Decryption to Design Data Theft Inside the App

Clop's Windchill Web Shell: From Credential Decryption to Design Data Theft Inside the App

1
Comments
6 min read
Two GitLab GraphQL Vulnerabilities: Unauthenticated Data Tampering and CSRF

Two GitLab GraphQL Vulnerabilities: Unauthenticated Data Tampering and CSRF

1
Comments
10 min read
F-RevoCRM CVE-2026-71368: Cross-Site Scripting Targeting Logged-in Users

F-RevoCRM CVE-2026-71368: Cross-Site Scripting Targeting Logged-in Users

1
Comments 8
6 min read
Microsoft's AI Defense Research: Generating Detection Test Logs from Attack Procedures

Microsoft's AI Defense Research: Generating Detection Test Logs from Attack Procedures

Comments
7 min read
CrowdStrike's AI Triage Research: How Well Can AI Automatically Judge SOC Alerts?

CrowdStrike's AI Triage Research: How Well Can AI Automatically Judge SOC Alerts?

Comments
6 min read
ShieldBreak (CVE-2026-69414): Unpatched Local Vulnerability for Privilege Escalation from Defender to SYSTEM

ShieldBreak (CVE-2026-69414): Unpatched Local Vulnerability for Privilege Escalation from Defender to SYSTEM

Comments
6 min read
Evooo1Bot: A Multi-Functional Linux Botnet That Turns Compromised Gateways into SOCKS5 Relays, SSH Spreaders, and DDoS Tools

Evooo1Bot: A Multi-Functional Linux Botnet That Turns Compromised Gateways into SOCKS5 Relays, SSH Spreaders, and DDoS Tools

1
Comments
10 min read
macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation

macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation

1
Comments
5 min read
GeoServer jsonArrayContains SQL Injection: Hundreds of Attempts Observed, RCE Conditions, and the 2023 CVE Gap

GeoServer jsonArrayContains SQL Injection: Hundreds of Attempts Observed, RCE Conditions, and the 2023 CVE Gap

1
Comments
10 min read
AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix

AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix

1
Comments
7 min read
SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE

SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE

1
Comments
5 min read
JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions

JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions

1
Comments
5 min read
VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH

VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH

1
Comments
5 min read
Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover

Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover

1
Comments
6 min read
Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption

Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption

1
Comments
6 min read
Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices

Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices

1
Comments
5 min read
City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search

City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search

1
Comments
6 min read
WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud

WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud

Comments
6 min read
Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment

Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment

Comments
6 min read
Gunra Ransomware: RaaS Exploiting FortiGate for VDI Sessions, OTP Theft, SaaS Exfiltration, and Encryption

Gunra Ransomware: RaaS Exploiting FortiGate for VDI Sessions, OTP Theft, SaaS Exfiltration, and Encryption

Comments
11 min read
Kimwolf v7: Android/IoT Botnet with HTTP/2 Browser Spoofing DDoS and ENS/Tor Three-Layer C2

Kimwolf v7: Android/IoT Botnet with HTTP/2 Browser Spoofing DDoS and ENS/Tor Three-Layer C2

Comments
9 min read
loading...