CVE-2024–12884 — E-Commerce Website SQLiSQLI in login.php of “E-Commerce-Website-Using-PHP”Dec 19, 2024Dec 19, 2024
The Rise of “GPT Kiddies”: A New Breed of Security “Researchers”In the early days of cybersecurity, the term “script kiddie” was coined to describe individuals who lacked genuine technical skills, yet…Dec 17, 2024Dec 17, 2024
CVE-2024–55889 — phpMyFAQ Triggering Unintended File DownloadsUnintended File Download Triggered by Embedded FramesDec 13, 2024Dec 13, 2024
CVE-2022–22659 — iOS “VPN On Demand”DGA-like outbound calls from iOS feature “VPN On Demand”Dec 9, 2024Dec 9, 2024
CVE-2024–54141 — phpMyFAQ Triggering the Exposure of DB CredsExposure of database (ie postgreSQL) server’s credential when connection to DB fails.Dec 9, 2024Dec 9, 2024
CVE-2024–53614 — Thinkware Decryption Keyhardcoded plaintext decryption key in Thinkware Cloud APKDec 3, 2024Dec 3, 2024
Penalized for Responsible DisclosureWhile researching a new attack vector (presented in BSides SG 2022), my associate and I discovered a misconfiguration in one of the Big…Oct 24, 2024Oct 24, 2024