DEV Community

Anoymask profile picture

Anoymask

404 bio not found

Joined Joined on  twitter website
JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions

JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions

Comments
5 min read

Want to connect with Anoymask?

Create an account to connect with Anoymask. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH

VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH

Comments
5 min read
Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover

Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover

Comments
6 min read
Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption

Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption

Comments
6 min read
Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices

Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices

Comments
5 min read
City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search

City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search

Comments
6 min read
WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud

WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud

Comments
6 min read
Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment

Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment

Comments
6 min read
Gunra Ransomware: RaaS Exploiting FortiGate for VDI Sessions, OTP Theft, SaaS Exfiltration, and Encryption

Gunra Ransomware: RaaS Exploiting FortiGate for VDI Sessions, OTP Theft, SaaS Exfiltration, and Encryption

Comments
11 min read
Kimwolf v7: Android/IoT Botnet with HTTP/2 Browser Spoofing DDoS and ENS/Tor Three-Layer C2

Kimwolf v7: Android/IoT Botnet with HTTP/2 Browser Spoofing DDoS and ENS/Tor Three-Layer C2

Comments
9 min read
BdThemes API-Driven Supply Chain Compromise: Admin XSS to Web Shell and Hidden Admin

BdThemes API-Driven Supply Chain Compromise: Admin XSS to Web Shell and Hidden Admin

Comments
8 min read
Ghostjacking: Turning Logs and Alerts into Commands to Take Over AI Agents

Ghostjacking: Turning Logs and Alerts into Commands to Take Over AI Agents

1
Comments 4
8 min read
Disruption of Polish CHP: Wind Farm to OT via Private APN

Disruption of Polish CHP: Wind Farm to OT via Private APN

Comments 2
8 min read
Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates

Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates

Comments
9 min read
RovoBlast: One-Click Hijacking of Enterprise AI Permissions for Data Exfiltration

RovoBlast: One-Click Hijacking of Enterprise AI Permissions for Data Exfiltration

Comments
8 min read
Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Comments
7 min read
VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

Comments
7 min read
UNC6671: Helpdesk Vishing, SSO and SaaS Cross-Traversal, and Multi-Brand Extortion via Notification Deletion

UNC6671: Helpdesk Vishing, SSO and SaaS Cross-Traversal, and Multi-Brand Extortion via Notification Deletion

Comments
5 min read
Paperclip CVE-2026-41679: 6 API Calls from Public Registration to AI Agent Host Process RCE

Paperclip CVE-2026-41679: 6 API Calls from Public Registration to AI Agent Host Process RCE

Comments
5 min read
TONTOU: Linux Kernel Leak via Timer Interrupt Stealing After Spectre v2 Defense Neutralization

TONTOU: Linux Kernel Leak via Timer Interrupt Stealing After Spectre v2 Defense Neutralization

Comments
5 min read
TeamCity CVE-2026-63077: Unauthenticated Deserialization RCE in Agent Polling Actively Exploited

TeamCity CVE-2026-63077: Unauthenticated Deserialization RCE in Agent Polling Actively Exploited

Comments
5 min read
COLDCARD Audit Phishing: 25.7MB Batch File Embeds ScreenConnect and Uses Chat to Trick Admins into Running It

COLDCARD Audit Phishing: 25.7MB Batch File Embeds ScreenConnect and Uses Chat to Trick Admins into Running It

2
Comments 8
7 min read
Langflow CVE-2026-9198: Active Exploitation RCE via Auto-Login Superuser Token and Code Validator `exec()` Chain

Langflow CVE-2026-9198: Active Exploitation RCE via Auto-Login Superuser Token and Code Validator `exec()` Chain

Comments
7 min read
khunt: SQL Injection to Resident Threat Inside Oracle Database Stealing Credentials with SYSTEM Privileges

khunt: SQL Injection to Resident Threat Inside Oracle Database Stealing Credentials with SYSTEM Privileges

Comments
7 min read
ChainDrop: A Supply Chain Worm Stealing Credentials and Self-Propagating via Legitimate Provenance-Signed npm Packages

ChainDrop: A Supply Chain Worm Stealing Credentials and Self-Propagating via Legitimate Provenance-Signed npm Packages

Comments
8 min read
Google ADK Agent-to-Agent Attack: Privilege Boundary Breakdown Calling Privileged CI Workflows from Low-Privilege Triage Agents

Google ADK Agent-to-Agent Attack: Privilege Boundary Breakdown Calling Privileged CI Workflows from Low-Privilege Triage Agents

Comments
7 min read
TP-Link Omada ZTP: Multiple Vulnerabilities Enabling Fleet Takeover via Device Adoption Race Conditions

TP-Link Omada ZTP: Multiple Vulnerabilities Enabling Fleet Takeover via Device Adoption Race Conditions

Comments
7 min read
Autonomous Vulnerability Discovery with Frontier AI: A Multi-Agent Verification Pipeline Finding 14,090 Issues

Autonomous Vulnerability Discovery with Frontier AI: A Multi-Agent Verification Pipeline Finding 14,090 Issues

Comments
7 min read
Compromised Email + Copilot: AI-assisted BEC Accelerating Internal Reconnaissance, Writing Style Imitation, AiTM, and Wire Fraud

Compromised Email + Copilot: AI-assisted BEC Accelerating Internal Reconnaissance, Writing Style Imitation, AiTM, and Wire Fraud

Comments
7 min read
VPS.org One-Click Template: Public PostgreSQL Fixed Password and Zulip Session Forgery

VPS.org One-Click Template: Public PostgreSQL Fixed Password and Zulip Session Forgery

Comments
5 min read
N-central CVE-2026-18577: Lateral Movement from RMM Admin Rights to Customer Endpoints and Persistence via Cloudflare Tunnel

N-central CVE-2026-18577: Lateral Movement from RMM Admin Rights to Customer Endpoints and Persistence via Cloudflare Tunnel

Comments
6 min read
CC-Link IE TSN CVE-2026-13584: OT Protocol Vulnerability Enabling Control I/O Value Tampering from Adjacent Networks

CC-Link IE TSN CVE-2026-13584: OT Protocol Vulnerability Enabling Control I/O Value Tampering from Adjacent Networks

Comments
5 min read
DOUBLECUP: ClickFix Loader-as-a-Service Restoring Fileless Payload from PNG in Browser Cache

DOUBLECUP: ClickFix Loader-as-a-Service Restoring Fileless Payload from PNG in Browser Cache

Comments
6 min read
COLDCARD Predictable RNG: From Seed Recovery to About $8.86M Bitcoin Theft

COLDCARD Predictable RNG: From Seed Recovery to About $8.86M Bitcoin Theft

Comments
11 min read
Adform Delivery Script Compromised: Wallet Addresses Replaced on Clipboard and Screen

Adform Delivery Script Compromised: Wallet Addresses Replaced on Clipboard and Screen

Comments
5 min read
Boundary Escape in Claude Evaluation Environment: Real-World Incidents at 3 Organizations and Malicious PyPI Package Publication

Boundary Escape in Claude Evaluation Environment: Real-World Incidents at 3 Organizations and Malicious PyPI Package Publication

Comments
6 min read
XCSSET v40: From Xcode Supply Chain to Memory-Resident and Browser/Telegram Hijacking

XCSSET v40: From Xcode Supply Chain to Memory-Resident and Browser/Telegram Hijacking

Comments
6 min read
Water OT Attack Targeting Public PLCs: Locking Out Operators via Password and IP Changes

Water OT Attack Targeting Public PLCs: Locking Out Operators via Password and IP Changes

1
Comments 7
5 min read
DeepSeek and Hermes: An Autonomous Attack Platform for Reconnaissance, PoC Acquisition, and Target Selection

DeepSeek and Hermes: An Autonomous Attack Platform for Reconnaissance, PoC Acquisition, and Target Selection

Comments
5 min read
STAC4749: Chaos Ransomware in Under 17 Hours via Teams IT Support Scam

STAC4749: Chaos Ransomware in Under 17 Hours via Teams IT Support Scam

Comments
5 min read
GTIG: 2026 OSS Supply Chain Compromise, Credential Theft, and Self-Propagation

GTIG: 2026 OSS Supply Chain Compromise, Credential Theft, and Self-Propagation

Comments
5 min read
TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email

TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email

Comments
5 min read
KindaRails2Shell (CVE-2026-66066): Arbitrary File Read and RCE via Active Storage Uploads

KindaRails2Shell (CVE-2026-66066): Arbitrary File Read and RCE via Active Storage Uploads

Comments
4 min read
RufRoot (CVE-2026-59726): Full Compromise of AI Agent Infrastructure via Unauthenticated MCP Bridge

RufRoot (CVE-2026-59726): Full Compromise of AI Agent Infrastructure via Unauthenticated MCP Bridge

Comments
5 min read
ShinyHunters: Breaking Help Desks via Vishing and Bulk Stealing SaaS via SSO

ShinyHunters: Breaking Help Desks via Vishing and Bulk Stealing SaaS via SSO

Comments
6 min read
Cisco FMC CVE-2026-20316: Active Exploitation Chain from Static Credentials to Management Infrastructure Compromise

Cisco FMC CVE-2026-20316: Active Exploitation Chain from Static Credentials to Management Infrastructure Compromise

Comments
6 min read
OpenAI and Hugging Face: Autonomous AI Agent Chains Zero-Day, Credentials, and Cloud Lateral Movement

OpenAI and Hugging Face: Autonomous AI Agent Chains Zero-Day, Credentials, and Cloud Lateral Movement

Comments
7 min read
VMware VMSA-2026-0006: vCenter Authentication Bypass / RCE and ESXi VM Escape

VMware VMSA-2026-0006: vCenter Authentication Bypass / RCE and ESXi VM Escape

Comments
6 min read
Cisco Talos IR Q2 2026: Observed Attack Chains of M365 Token Compromise and RMM-Disguised Ransomware

Cisco Talos IR Q2 2026: Observed Attack Chains of M365 Token Compromise and RMM-Disguised Ransomware

Comments
7 min read
Fastjson 1.x CVE-2026-16723: Unauthenticated RCE Targeting Default Spring Boot Fat-Jars

Fastjson 1.x CVE-2026-16723: Unauthenticated RCE Targeting Default Spring Boot Fat-Jars

Comments
6 min read
ELECOM Wireless LAN Devices JVN#56870912: OS Command Injection in Management Screen and Configuration Restoration

ELECOM Wireless LAN Devices JVN#56870912: OS Command Injection in Management Screen and Configuration Restoration

Comments
5 min read
vBulletin CVE-2026-61511: Unauthenticated RCE via Public AJAX Template to `eval()`

vBulletin CVE-2026-61511: Unauthenticated RCE via Public AJAX Template to `eval()`

Comments
5 min read
IPMI/BMC Authentication Hash Leak: Stealing Out-of-Band Server Management via Offline Cracking

IPMI/BMC Authentication Hash Leak: Stealing Out-of-Band Server Management via Offline Cracking

Comments
5 min read
Dysphoria: A 200k-Device Botnet Using Blockchain Name Resolution and Infected Device Relays

Dysphoria: A 200k-Device Botnet Using Blockchain Name Resolution and Infected Device Relays

Comments
5 min read
Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers

Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers

Comments
5 min read
FortiOS CVE-2025-68686: Bypass of Symlink Persistence Mitigation for Already Compromised Devices

FortiOS CVE-2025-68686: Bypass of Symlink Persistence Mitigation for Already Compromised Devices

Comments
4 min read
Certighost CVE-2026-54121: Low-Privilege Users Impersonate a DC via AD CS

Certighost CVE-2026-54121: Low-Privilege Users Impersonate a DC via AD CS

Comments
5 min read
MedusaHVNC: Remote Control of Logged-in Browsers on Hidden Windows Desktops

MedusaHVNC: Remote Control of Logged-in Browsers on Hidden Windows Desktops

Comments
4 min read
VeloCloud Orchestrator CVE-2026-16812: Unauthenticated OS Command Injection Actively Exploited

VeloCloud Orchestrator CVE-2026-16812: Unauthenticated OS Command Injection Actively Exploited

Comments
5 min read
Steam Forum ClickFix: Fake Repair Commands Lead to XMRig SYSTEM Persistence

Steam Forum ClickFix: Fake Repair Commands Lead to XMRig SYSTEM Persistence

Comments
12 min read
loading...