TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.32K
Photos
434
Videos
3
Links
575

Showing posts older than #355 · Back to latest

Older Posts 20 shown
Post #354 532
🚧 Planned Maintenance 🚧
Short-term interruptions in service provision are possible❗️

On the weekend of March 8-9, 2025, we will carry out work aimed at improving server stability and quality of service. All this time, the replicas will be disabled, which is why interruptions are possible in case of problems with the main server. We will do our best to complete it as quickly as possible.

Please remember to save your work before this time.
  • 👨‍💻 3
Post #353 621
CVE-2025-26776: Unrestricted Upload of File with Dangerous Type in Chaty Pro WordPress Plugin, 10.0 rating 🔥🔥🔥

The vulnerability allows an attacker to upload malicious files that can be used to take control of a website.

Search at Netlas.io:
👉 Link: https://nt.ls/DCwYC
👉 Dork: http.body:"plugins/chaty-pro"

Read more: https://patchstack.com/database/wordpress/plugin/chaty-pro/vulnerability/wordpress-chaty-pro-plugin-3-3-3-arbitrary-file-upload-vulnerability?_s_id=cve
  • 🔥 4
  • 👾 2
Post #352 784
CVE-2025-22224, -22225, -22226: Multiple vulnerabilities in VMware ESXi, 7.1 - 9.3 rating 🔥

Three vulnerabilities affecting several VMware products, including ESXi. Includes Code Exection, Sandbox Escape and Memory Leak.

Search at Netlas.io:
👉 Link: https://nt.ls/9Iw92
👉 Dork: http.title:"+ ID_EESX_Welcome +"

Vendor's advisory: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
  • 👾 4
  • 🔥 3
  • 👍 1
Post #351 552
CVE-2025-23388, -23389: DoS and Unauthorized Access in Rancher, 8.2 - 8.4 rating❗️

Two vulnerabilities, one of which allows an attacker to crash the Rancher server, and the second - to impersonate any other user by manipulating cookies.

Search at Netlas.io:
👉 Link: https://nt.ls/fCvlC
👉 Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b

Vendor's advisory: https://github.com/rancher/rancher/security/advisories/GHSA-mq23-vvg7-xfm4
  • 👾 3
  • 🔥 2
Post #349 672
CVE-2025-20029: Command Injection in F5 BIG-IP, 8.8 rating❗️

The vulnerability allows an attacker to escalate privileges, execute arbitrary commands, and manipulate system files. Not the latest vulnerability, but the PoC was published just recently!

Search at Netlas.io:
👉 Link: https://nt.ls/e17gN
👉 Dork: http.headers.server:"BigIP"

Vendor's advisory: https://my.f5.com/manage/s/article/K000148587
  • ❤ 3
  • 🔥 2
  • 👾 1
Post #347 602
CVE-2025-1128: RCE in Everest Forms WordPress Plugin, 9.8 rating 🔥

The vulnerability allows an unauthenticated attacker to perform a wide range of actions with the site: upload arbitrary files, RCE, delete config files.

Search at Netlas.io:
👉 Link: https://nt.ls/q6pgJ
👉 Dork: http.body:"plugins/everest-forms"

Read more: https://www.wordfence.com/blog/2025/02/100000-wordpress-sites-affected-by-arbitrary-file-upload-read-and-deletion-vulnerability-in-everest-forms-wordpress-plugin/
  • 🔥 3
  • 👾 2
  • 👍 1
Post #345
Netlas.io pinned «🔐 Track Adversary Infrastructure Challenge Join the challenge by Netlas and RST Cloud to improve your threat-hunting skills. - Learn to detect C2 servers and investigate real threats. - Compete for prizes: 🏆 $1000, 🥈 $500, 🥉 $250. - Top 10 winners receive…»
Post #343 653
🔐 Track Adversary Infrastructure Challenge
Join the challenge by Netlas and RST Cloud to improve your threat-hunting skills.

- Learn to detect C2 servers and investigate real threats.
- Compete for prizes: 🏆 $1000, 🥈 $500, 🥉 $250.
- Top 10 winners receive Netlas Annual Business Subscription and RST IoC Lookup Subscription.
- All participants get a certificate of completion.
- Free 1-month access to Netlas for practice.

💡 What’s included:
- Webinar on threat intelligence and C2 tracking.
- Hands-on challenge with Netlas and RST Cloud tools.
- Discord community for support and collaboration.

👉 Invite a friend to team up and participate: https://netlas.io/promo/ti-challenge/
netlas.io Track Adversary Infrastructure Challenge with Netlas & RST Cloud – Hunt, Learn, Win! - Netlas Join the ultimate threat intelligence challenge! Hunt hacker infrastructure with Netlas, win cash prizes, and get exclusive Netlas & RST Cloud subscriptions.
  • 👾 5
  • ❤ 4
  • 🔥 3
Post #342 567
CVE-2025-26465, -26466: Two vulnerabilities in OpenSSH, 6.8 rating❗️

MitM and DoS in OpenSSH. The severity level is medium, but the vulnerabilities cover many versions: from 2013 for -26465 and from 2023 for -26466.

Search at Netlas.io:
👉 Link: https://nt.ls/1TTrj
👉 Dork: ssh.server_key_exchange.client_to_server_compression:"zlib@openssh.com"

Read more: https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466
  • 🔥 3
  • 👍 2
  • 👾 1
Post #341 562
CVE-2024-12562: Deserialization of Untrusted Data in s2member Pro WordPress Plugin, 9.8 rating 🔥

The vulnerability allows attackers to inject PHP Object on all versions of the plugin, except the latest.

Search at Netlas.io:
👉 Link: https://nt.ls/GqND6
👉 Dork: http.body:"plugins/s2member"

Read more: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member-pro/s2member-pro-241216-unauthenticated-php-object-injection
  • 👍 2
  • 🔥 2
  • 👾 1
Post #339 639
CVE-2025-0376 and other: Multiple vulnerabilitites in GitLab, 4.2 - 8.7 rating❗️

With the new release, GitLab has disclosed several vulnerabilities, including XSS injection, DoS and others.

Search at Netlas.io:
👉 Link: https://nt.ls/50gFr
👉 Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"

Vendor's advisory: https://about.gitlab.com/releases/2025/02/12/patch-release-gitlab-17-8-2-released/
  • 🔥 3
  • 👾 3
  • 👍 1
Post #338 580
CVE-2025-22467: RCE in Ivanti Connect Secure, 9.9 rating 🔥🔥🔥

A stack-based buffer overflow in Ivanti Connect Secure allows a remote authenticated attacker to achieve remote code execution.

Search at Netlas.io:
👉 Link: https://nt.ls/WojuE
👉 Dork: http.body:"welcome.cgi?p=logo"

Vendor's advisory: https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US
  • 🔥 6
  • 👍 2
  • 👾 1
Post #337 597
CVE-2025-25064, -25065: Two vulnerabilities in Zimbra, 5.3 - 9.8 rating 🔥

Vulnerabilities include SQL injection and SSRF, which could potentially lead to RCE. We recommend installing the latest patches as soon as possible.

Search at Netlas.io:
👉 Link: https://nt.ls/nehV7
👉 Dork: http.favicon.hash_sha256:1afd891aacc433e75265e3ddc9cb4fc63b88259977811384426c535037711637 OR \*.banner:"Zimbra"

Vendor's advisory: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
  • 🔥 3
  • 👾 2
Post #336 591
Netlas vs Censys: A Comprehensive Analysis 🧮

A new article in our series of comparisons with competitors.

This time we evaluated the pros and cons of Censys, which proved to be the strongest of our opponents. However, we tried to evaluate both search engines as honestly as possible, using 10+ key indicators.

👉 Read now: https://netlas.io/blog/netlas_vs_censys/
netlas.io Netlas vs Censys: Platforms Comparison - Netlas Blog Compare IoT search engines Netlas and Censys, highlighting their features, strengths, and ideal use cases for security research.
  • 👍 4
  • 👾 4
  • ❤ 3
Post #335 508
🚧 Storage Maintenance 🚧

We are currently performing maintenance to scale up storage capacity. The private scanner may be unavailable for the next 24-48 hours. The Netlas team apologizes for the inconvenience.

We will do our best to complete it as quickly as possible.
  • 👌 2
  • 👨‍💻 2
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →