TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.32K
Photos
434
Videos
3
Links
575

Showing posts older than #478 · Back to latest

Older Posts 20 shown
Post #476 717
CVE-2025-5821: Authentication Bypass in Case Theme for WordPress, 9.8 rating 🔥

The vulnerability allows an unauthenticated user to gain access to any account on the site, including the administrator account. Already exploited in the wild!

Search at Netlas.io:
👉 Link: https://nt.ls/Pcezp
👉 Dork: http.body:"plugins/case-theme-user"

Read more: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/case-theme-user/case-theme-user-103-authentication-bypass-via-social-login
  • 👾 3
Post #475 850
Bug Bounty + Recon Toolkit: Stop Hunting Blind 🧭

Still brute-forcing in the dark? Bring a map.

In our new article, we lay out a practical, start-to-finish recon flow - from passive OSINT to active probing - with copy-paste commands, tool picks, and workflow tips to turn noise into findings.

👉 Read now: https://netlas.io/blog/best_recon_tools_for_bug_bounty/
netlas.io Bug Bounty 101: Top 10 Reconnaissance Tools - Netlas Blog Essential bug bounty recon tools for asset discovery, OSINT, automation, and vulnerability research. Boost your security testing workflow.
  • 🔥 4
  • 👍 3
  • 👾 2
Post #474 1.03K
CVE-2025-42944, -42922, -27500 and other: Multiple vulnerabilities in SAP NetWeaver, 3.1 - 10.0 rating 🔥🔥🔥

In the September patch, SAP reported 21 vulnerabilities, including Path Traversal, Missing Authentication check, Insecure File Operations, and RCE with the highest severity score!

Search at Netlas.io:
👉 Link: https://nt.ls/wFC1w
👉 Dork: http.headers.server:"NetWeaver"

Vendor's advisory: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2025.html
  • 👾 4
  • ❤ 3
Post #472 1.01K
Mapping Dark Web Infrastructure 💀

In latest article we break down practical techniques investigators use to trace hidden services — clearnet resource leaks, header fingerprints, certificate reuse, and bulletproof hosting overlaps.

Real examples and ethical do’s & don’ts included.

👉 Read now: https://netlas.io/blog/mapping_dark_web/
netlas.io Mapping Dark Web Infrastructure - Netlas Blog Explore how investigators trace dark web infrastructure through clues and errors that exposed AlphaBay, Hansa, and other hidden services.
  • 🔥 5
  • 👻 4
  • ❤ 2
Post #470 816
Vibe-Coding Security Risks: When AI Ships Insecurity ⚠️

AI helps you ship code fast — and sometimes ships vulnerabilities faster.

In our latest article, learn how vibe-coding introduces issues like package hallucination, typosquatting, weak auth, and exposed configs, see real-world fallout, and get practical steps to secure AI-generated code.

👉 Read now: https://netlas.io/blog/vibe-coding-security-risks/
netlas.io Top Vibe-Coding Security Risks - Netlas Blog Why can vibe-coding with AI cause costly breaches that developers may miss? Let's find out!
  • ❤ 5
  • 👾 2
  • 👏 1
Post #469 996
CVE-2025-57819: Authentication Bypass in FreePBX Administrator, 10.0 rating 🔥🔥🔥

A critical zero-day vulnerability in FreePBX could allow an attacker to perform SQL injection and RCE. Exploitation has already been observed in the wild!

Search at Netlas.io:
👉 Link: https://nt.ls/ebwk9
👉 Dork: http.favicon.hash_sha256:dfc3cc989bec09d968e978cde336709c655fa85469fd482ac10e17942da80be9

Vendor's advisory: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h
  • 🔥 4
  • 👾 3
Post #467 749
⚠️ Today, 2025-08-22, starting from 04:30 UTC, we began experiencing a major service outage.

The issue has been localized to a problem within our database cluster. Our engineering team is actively working to resolve the issue and restore full service as quickly as possible. We will continue to provide updates as we make progress.
  • 💊 6
  • 👍 1
Post #466 779
🚀 Netlas v1.3.0 is live!

This update doubles the number of scanned ports, adds protocol detection to public scans, boosts vulnerability coverage, and makes downloads lightning-fast.

Explore what’s new 👉 https://docs.netlas.io/changelog/#netlas-v1-3-0
docs.netlas.io Changelog - Netlas Docs Explore the latest updates, enhancements, and fixes on the Netlas platform. Stay informed with our Changelog for all product and feature developments.
  • 🔥 5
  • ❤‍🔥 1
  • 🙏 1
Post #465 855
Meet Kanvas — an open-source incident response tool that turns chaos into clarity with built-in visualizations, intel lookups, and teamwork-friendly features.

This post, written by an experienced security analyst for fellow security analysts, breaks down how Kanvas can supercharge your IR workflow.

👉 Read the post: https://netlas.io/blog/kanvas/
netlas.io From Chaos to Control: Kanvas Incident Management Tool - Netlas Blog Kanvas: Open-source DFIR case management that streamlines incident response, turning Spreadsheet of Doom chaos into organized, efficient investigations.
  • 👍 3
  • 🔥 3
Post #464 709
CVE-2025-20265 — Critical RCE in Cisco Secure Firewall Management Center (CVSS 10).

Exploitable by unauthenticated attackers when RADIUS authentication is enabled; affects FMC 7.0.7 & 7.7.0. We see <200 internet-exposed on-prem FMCs (cloud-hosted cdFMC excluded).

🔍 Netlas: https://nt.ls/E5j8D
ℹ️ Advisory: https://nt.ls/C3hPx
  • 🔥 5
  • ❤ 1
Post #463 695
CVE-2025-27210 – High Severity Path Traversal in Node.js (Windows)

One of our Netlas users identified a serious flaw in Windows builds of Node.js and asked us to inform the community. Any web app running Node.js 20.x before 20.19.4, 22.x before 22.17.1, or 24.x before 24.4.1 on Windows may be at risk of unauthorized file access through path traversal.

⚡️ Update immediately
ℹ️ Advisory: https://nt.ls/YX7xc
  • ❤ 3
  • 👍 2
  • 🔥 1
Post #462 595
CVE-2025-7384: Critical PHP Object Injection in WordPress Plugin

A critical vulnerability has been found in the Database for Contact Form 7, WPForms, and Elementor forms WordPress plugin. Since this is a backend-only plugin, it is not directly detectable through standard search dorks. Supported frontend plugins could help determine the scope. However, only about 1% of hosts identified this way are actually vulnerable.

🔍 Netlas: https://nt.ls/Be3g6
ℹ️ Advisory: https://nt.ls/RoI8t
  • 🔥 4
  • 👾 2
  • 👍 1
  • 🥰 1
Post #459 660
I, Robot + NIST AI RMF: Prevent the Great Robot Uprising 🤖

Thinking your toaster couldn’t lead an army? Think again.

In our latest article, we use classic scenes from I, Robot to break down the NIST AI Risk Management Framework’s four pillars — Map, Measure, Manage, Govern — so you can keep your AIs on task (and off the march).

👉 Read now: https://netlas.io/blog/nist_ai_rmf/
netlas.io I, Robot + NIST AI RMF = Complete Guide on Preventing Robot Rebellion - Netlas Blog A funny way to learn NIST AI Risk Management Framework through classic movie examples. Discover AI safety concepts via I, Robot's memorable scenes and real cases.
  • 😁 3
  • 👾 3
  • 👍 2
  • 🔥 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →