05/26

Supercar Showdown - Supercar Showdown

https://hack-yourself-first.com/
Supercar Showdown - Supercar Showdown

Security Advisory: Remote Command Execution on Smartbedded MeteoBridge (CVE-2025-4008) | ONEKEY Research | Research | ONEKEY

https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008
Security Advisory: Remote Command Execution on Smartbedded MeteoBridge (CVE-2025-4008) | ONEKEY Research | Research | ONEKEY

Oracle VM VirtualBox - VM escape via VGA device · Advisory · google/security-research · GitHub

https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v
Oracle VM VirtualBox - VM escape via VGA device · Advisory · google/security-research · GitHub

Pentest-Tools-Collection/tools/ActiveDirectory/BadSuccessor.ps1 at main · LuemmelSec/Pentest-Tools-Collection · GitHub

https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1
Pentest-Tools-Collection/tools/ActiveDirectory/BadSuccessor.ps1 at main · LuemmelSec/Pentest-Tools-Collection · GitHub

⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs

https://thehackernews.com/2025/05/weekly-recap-apt-campaigns-browser.html
⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs

Nova Scotia Power Confirms Ransomware Attack, 280k Notified of Data Breach - SecurityWeek

https://www.securityweek.com/nova-scotia-power-confirms-ransomware-attack-280k-notified-of-data-breach/
Nova Scotia Power Confirms Ransomware Attack, 280k Notified of Data Breach - SecurityWeek

GitHub - cybrly/badsuccessor

https://github.com/cybrly/badsuccessor
GitHub - cybrly/badsuccessor

Google claims users find ads in AI search 'helpful'

https://www.bleepingcomputer.com/news/google/google-claims-users-find-ads-in-ai-search-helpful/
Google claims users find ads in AI search 'helpful'

Researchers claim ChatGPT o3 bypassed shutdown in controlled test

https://www.bleepingcomputer.com/news/artificial-intelligence/researchers-claim-chatgpt-o3-bypassed-shutdown-in-controlled-test/
Researchers claim ChatGPT o3 bypassed shutdown in controlled test

WhatsApp MCP Exploited: Exfiltrating your message history via MCP

https://invariantlabs.ai/blog/whatsapp-mcp-exploited
WhatsApp MCP Exploited: Exfiltrating your message history via MCP

Bypassing MTE with CVE-2025-0072 - The GitHub Blog

https://github.blog/security/vulnerability-research/bypassing-mte-with-cve-2025-0072/
Bypassing MTE with CVE-2025-0072 - The GitHub Blog

ChatGPT Deep Research can now pull data from Dropbox and Box

https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-deep-research-can-now-pull-data-from-dropbox-and-box/
ChatGPT Deep Research can now pull data from Dropbox and Box

物尽其用,摩诃草攻击武器复用肚脑虫基础设施

https://mp.weixin.qq.com/s/pJTPeK1Cam5n4RUElWzb2Q
物尽其用,摩诃草攻击武器复用肚脑虫基础设施

TrustedSec | Red Team Gold: Extracting Credentials from MDT Shares

https://trustedsec.com/blog/red-team-gold-extracting-credentials-from-mdt-shares
TrustedSec | Red Team Gold: Extracting Credentials from MDT Shares

Reversing for dummies - x86 assembly and C code (Beginner/ADHD friendly) · 0x44.cc

https://0x44.cc/reversing/2021/07/21/reversing-x86-and-c-code-for-beginners.html
Reversing for dummies - x86 assembly and C code (Beginner/ADHD friendly) · 0x44.cc

What I Learned From My First 100 HackerOne Reports | Evan Connelly

https://evanconnelly.com/post/my-first-100-hackerone-reports/
What I Learned From My First 100 HackerOne Reports | Evan Connelly