TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.32K
Photos
434
Videos
3
Links
575

Showing posts older than #415 · Back to latest

Older Posts 20 shown
Post #414 653
Netlas vs. Urlscan: In-Depth Comparison 🧮

In our new blog post, we stack Netlas against Urlscan to finally answer the question: are these tools similar?

Inside, you’ll discover:

- An in-depth look at each platform’s standout capabilities 🔍
- Similarities and differences between applications ⚖️
- Practical recommendations on when to choose one over the other 🤔

👉 Check it out here: https://netlas.io/blog/netlas_vs_urlscan/
netlas.io Netlas vs Urlscan: Tools Comparison - Netlas Blog At first glance, Netlas and Urlscan seem similar, but their core functions and use cases differ greatly. Discover which tool fits your needs.
  • 🔥 3
  • 👾 3
Post #413 665
🚧 Planned Maintenance 🚧
The application may be unavailable for a period of time❗️

On the weekend of June 7–8, 2025, we will carry out work aimed at improving server stability and quality of service. In case of problems, the application may be unavailable for up to two days. Our team will do everything possible to prevent this.

Please remember to save your work before this time.
  • 👍 2
  • 👨‍💻 2
  • 👌 1
Post #412 1.26K
CVE-2025-49113: RCE in Roundcube Webmail, 9.9 rating 🔥

A vulnerability in Roundcube allows attackers to perform RCE due to the lack of validation of the _from parameter, which leads to PHP objects deserialization.

Search at Netlas.io:
👉 Link: https://nt.ls/9M4Rh
👉 Dork: http.headers.set_cookie:"roundcube_sessid"

Read more: https://fearsoff.org/research/roundcube
  • 👾 3
  • 🔥 2
Post #411
Netlas.io pinned «Track Adversary Infrastructure Challenge Recap 🏆 Last week, a major event concluded: the Track Adversary Infrastructure Challenge, which we held together with our colleagues from RST Cloud. Participants gained practical experience, and we were able to draw…»
Post #410 721
Track Adversary Infrastructure Challenge Recap 🏆

Last week, a major event concluded: the Track Adversary Infrastructure Challenge, which we held together with our colleagues from RST Cloud. Participants gained practical experience, and we were able to draw many conclusions regarding Netlas’s functionality and the improvements needed.

Thank you all for participating, and special congratulations to the winners:

🥇 1st Place (tie): Daisuke Arai
🥇 1st Place (tie): Marc Nebout
🥈 2nd Place: Kishan Lal
🥉 3rd Place: Koushik Pal

👉 You can read a more detailed report on our blog: https://netlas.io/blog/track_advisory_infrastructure_challenge/
  • 🔥 5
  • 🎉 2
  • 👏 1
Post #409 751
CVE-2025-47577: Unrestricted Upload of File with Dangerous Type in TI WooCommerce Wishlist Plugin, 10.0 rating 🔥🔥🔥

Failure to check the types of uploaded files allows attackers to upload a web shell to the server and perform RCE.

Search at Netlas.io:
👉 Link: https://nt.ls/jYyss
👉 Dork: http.body:"plugins/ti-woocommerce-wishlist"

Read more: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ti-woocommerce-wishlist/ti-woocommerce-wishlist-292-unauthenticated-arbitrary-file-upload
  • 👍 3
  • 🔥 3
  • ❤ 2
  • 👾 1
Post #408 718
Account Takeover in Grafana – PoC by Chirag Artani 🔥

Our friend’s channel has posted a new video dedicated to exploiting a recent vulnerability. The guide includes finding targets in Netlas, as well as further exploitation. Don’t miss it!

We also recommend checking out Chirag Artani’s website and Twitter for more cybersecurity insights:

👉 Website: 3rag.com
👉 Twitter: x.com/Chirag99Artani
YouTube Grafana CVE-2025-4123 Exploit Demo Open Redirect | XSS + SSRF + Account Takeover | Security POC Description: ⚠️ HIGH SEVERITY ALERT ⚠️ One-click Grafana scanner: https://nt.ls/T5Akf (Netlas.io) 40000+ targets In this video, I demonstrate the exploitation of CVE-2025-4123, a critical security vulnerability in Grafana with a CVSS score of 7.6. This…
  • 🔥 7
  • 👍 4
Post #407 580
Authorization Error Fixed 🛠

Over the weekend, some of our users encountered problems with authorization through third-party resources. This issue has now been fixed, and you can return to your projects!

The Netlas team apologizes for the inconvenience.
  • 🥰 3
  • 👍 2
  • ❤ 1
  • 👀 1
Post #405 632
CVE-2025-4123: 0-day in Grafana, 7.6 rating❗️

Grafana Labs has released an unscheduled update that fixes an XSS injection vulnerability in all supported versions. This vulnerability does not require privileges and can be executed if anonymous access is present.

Search at Netlas.io:
👉 Link: https://nt.ls/BVyZk
👉 Dork: http.favicon.hash_sha256:80a7f87a79169cf0ac1ed3250d7c509368190a97bc7182cd4705deb8f8c70174 AND http.title:"Grafana"

Vendor's advisory: https://grafana.com/blog/2025/05/21/grafana-security-release-high-severity-security-fix-for-cve-2025-4123/
  • 🔥 2
  • 👾 2
  • 👍 1
  • 👏 1
Post #404
Netlas.io pinned «Netlas 1.2.0 is Live! 🚀 What's new: 📑 OpenAPI 3.1 Support 🛠 Docs Portal Rebuild 🔖 Field types added in Mapping View 🕵️‍♂️ New “Tracker” Node (Google Tags, Facebook Pixels) into Attack Surface Discovery tool Dive into the full changelog 👉 https://docs.…»
Post #403 578
Netlas 1.2.0 is Live! 🚀

What's new:

📑 OpenAPI 3.1 Support
🛠 Docs Portal Rebuild
🔖 Field types added in Mapping View
🕵️‍♂️ New “Tracker” Node (Google Tags, Facebook Pixels) into Attack Surface Discovery tool

Dive into the full changelog 👉 https://docs.netlas.io/changelog/
docs.netlas.io Changelog - Netlas Docs Explore the latest updates, enhancements, and fixes on the Netlas platform. Stay informed with our Changelog for all product and feature developments.
  • 🔥 7
Post #402 490
💯 Planned Maintenance Completed 💯

Our team apologizes that this process took longer than expected.
Netlas is fully online again, and you can get back to your projects! 👾
  • 👾 3
  • 👀 2
  • 😭 1
Post #401 530
🚧 Planned Maintenance 🚧
The application will be unavailable for a period of time❗️

The maintenance is scheduled to start today at 09:00 UTC ⏰. It is expected to take about ten minutes, but may take up to half an hour. We will do our best to complete it as quickly as possible.

Please remember to save your work before this time.
  • ❤ 2
  • 🆒 2
  • 💊 1
Post #399 507
CVE-2024-57273, -54779, 54780: Multiple vulnerabilities in pfSense, 5.4 - 8.8 rating❗️

The three newly disclosed vulnerabilities include Stored XSS, Command Injection and XML Injection.
Since the details of the vulnerabilities have already been disclosed, we recommend that anyone involved update their software.

Search at Netlas.io:
👉 Link: https://nt.ls/DOmg1
👉 Dork: http.title:"pfSense - Login"

Read more: https://blog.brillantit.com/exploiting-pfsense-xss-command-injection-cloud-hijack/
  • 👾 4
  • 👍 2
  • 🔥 2
Post #398 475
Netlas vs. IPinfo: A Comprehensive Analysis 🧮

Our latest article puts Netlas head-to-head with one of its indirect competitors, IPinfo.

Inside, you’ll find:
- Deep dive into each tool’s core features 🔍
- Clear, side-by-side pricing comparison 💸
- Actionable insights on where each platform shines 🤔

👉 Read the article here: https://netlas.io/blog/netlas_vs_ipinfo/
netlas.io Netlas vs IPinfo: Tools Comparison - Netlas Blog Explore the features, strengths, pricing, and automation options of Netlas and IPinfo to choose the best IP intelligence tool for your cybersecurity or research needs.
  • 👾 3
  • 🔥 2
  • 👍 1
Post #396 604
CVE-2025-22252: Bypass Authentication in FortiOS/FortiProxy, 9.0 rating 🔥

Systems configured to use TACACS+ with ASCII authentication may be affected by a vulnerability that could allow an attacker to bypass authentication and gain administrative privileges.

Search at Netlas.io:
👉 Link: https://nt.ls/JYafs
👉 Dork: http.favicon.hash_sha256:d18b3c9feb76c3c1cfdcc51c732f113327e3c33fb3f63b479951f7da6ed1216f

Vendor's advisory: https://fortiguard.fortinet.com/psirt/FG-IR-24-472
  • 🔥 2
  • 👾 2
Post #395 552
CVE-2025-42999: Deserialization of Untrusted Data in SAP NetWeaver, 9.1 rating 🔥

A vulnerability in SAP NetWeaver Visual Composer Metadata Uploader allows a privileged attacker to upload arbitrary content that could compromise the confidentiality and integrity of the system.

Search at Netlas.io:
👉 Link: https://nt.ls/QzmGI
👉 Dork: http.body:"This error page was generated by SAP Web Dispatcher!"

Read more: https://www.bleepingcomputer.com/news/security/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/
  • 👾 3
  • 🔥 2
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →