Get the playbook first—subscribe.
blog.alphahunt.io/triofox-expl...
#AlphaHunt #CyberSecurity #Triofox #CVE202512480
Get the playbook first—subscribe.
blog.alphahunt.io/triofox-expl...
#AlphaHunt #CyberSecurity #Triofox #CVE202512480
Try with Modat Magnify: Run → web.headers~"Set-Cookie: y-glad-state" magnify.modat.io
#ModatMagnify #CyberSecurity #RCE #CVE202530406 #ModatMagnify #CentreStack #Triofox #VulnerabilityAlert #PatchNow
Try with Modat Magnify: Run → web.headers~"Set-Cookie: y-glad-state" magnify.modat.io
#ModatMagnify #CyberSecurity #RCE #CVE202530406 #ModatMagnify #CentreStack #Triofox #VulnerabilityAlert #PatchNow
google cloud / mandiant blogged about a cool investigation that I got to pitch in on & had a small verse to contribute in the broader context of it. these are the things that remind me how much I enjoy what I do.
google cloud / mandiant blogged about a cool investigation that I got to pitch in on & had a small verse to contribute in the broader context of it. these are the things that remind me how much I enjoy what I do.
Attackers exploited it as a zero-day in March, hitting 7 orgs by April 11.
🔑 Root cause: Hardcoded crypto keys → enabled RCE via PowerShell + DLL sideloading
#Vulnerability
Attackers exploited it as a zero-day in March, hitting 7 orgs by April 11.
🔑 Root cause: Hardcoded crypto keys → enabled RCE via PowerShell + DLL sideloading
#Vulnerability
🚨 Hackers exploited a critical flaw in Gladinet’s Triofox (#CVE202512480), using the built-in antivirus feature for remote code execution with SYSTEM privileges. The auth bypass was caused by spoofing “localhost” in HTTP headers. #CyberSecurity #Infosec #RCE #Triofox
🚨 Hackers exploited a critical flaw in Gladinet’s Triofox (#CVE202512480), using the built-in antivirus feature for remote code execution with SYSTEM privileges. The auth bypass was caused by spoofing “localhost” in HTTP headers. #CyberSecurity #Infosec #RCE #Triofox
#gladinet #triofox #centrestack #RCEvulnerability #cybersecurity
#gladinet #triofox #centrestack #RCEvulnerability #cybersecurity
We've got some post exploitation and detection opportunities for you:
#DFIR #threatintel #CTI
www.huntress.com/blog/cve-202...
We've got some post exploitation and detection opportunities for you:
#DFIR #threatintel #CTI
www.huntress.com/blog/cve-202...
--Brave says its new AI browser is inherently dangerous,
--CISA orders GeoServer fix exploited in XML External Entity (XXE) injection attacks,
--Trump to withhold funding for states that regulate AI, 5/6
--Brave says its new AI browser is inherently dangerous,
--CISA orders GeoServer fix exploited in XML External Entity (XXE) injection attacks,
--Trump to withhold funding for states that regulate AI, 5/6
#CyberSecurity #Triofox #RCE #ThreatIntel
#CyberSecurity #Triofox #RCE #ThreatIntel
💭 How often do you think AV scanning features are overlooked in red-team assessments?
#CyberSecurity #Triofox #CVE202512480 #RCE #InfoSec #APT #Mandiant #ThreatIntel #Vulnerability
💭 How often do you think AV scanning features are overlooked in red-team assessments?
#CyberSecurity #Triofox #CVE202512480 #RCE #InfoSec #APT #Mandiant #ThreatIntel #Vulnerability
A temporary workaround is available while a patch is in development:
www.huntress.com/blog/gladine...
A temporary workaround is available while a patch is in development:
www.huntress.com/blog/gladine...
📖 Read more: www.helpnetsecurity.com/2025/11/11/g...
#cybersecurity #cybersecuritynews #0day @mandiant.com
📖 Read more: www.helpnetsecurity.com/2025/11/11/g...
#cybersecurity #cybersecuritynews #0day @mandiant.com