TGViewer
Channel Public Channel
Proxy Bar

Proxy Bar

@proxy_bar

Exploits, Hacking and Leaks

Чат группы - https://t.me/

Связь с администрацией и реклама:
@NULL_vm

Поддержать проект:
BTC bc1qmrt229eghjyj9wqa7nmr9j8zuq6khz6km2pker
Subscribers
21.5K
Photos
1.7K
Videos
107
Links
1.8K

Showing posts older than #3572 · Back to latest

Older Posts 19 shown
Post #3571 5.57K
CVE-2026-58629: A Double-Free in dxgkrnl’s CreateAllocation Rollback

Original text: “July 2026 Patch Tuesday [CVE-2026-58629] Freeing the Wrong Allocation: a double-free in dxgkrnl’s CreateAllocation rollback” — gengstah, gengstah (personal blog), July 14, 2026. Disassembly, crash dumps and code below are reproduced verbatim with attribution captions.

Executive Summary

CVE-2026-58629 is a local elevation-of-privilege bug in dxgkrnl, the Windows Display Driver Model (WDDM) kernel component…

https://core-jmp.org/2026/07/cve-2026-58629-dxgkrnl-createallocation-double-free/
  • 🔥 3
Post #3569 8.13K
CVE-2026-63030 WordPress
*
wp2shell
  • 👍 13
  • 🔥 10
Post #3568 7.73K
CVE-2026-58532: An Integer Overflow in Windows tcpip.sys

Original text: “How I found an integer overflow in tcpip.sys (CVE-2026-58532)” — April Ivy (aprilpet), April Ivy’s Writing (aprl.pet), 17 July 2026. The prose below is a paraphrase; the call stack, code snippets and proof-of-concept are reproduced verbatim with attribution.

Executive Summary

Security researcher April Ivy discovered an unsigned 64-bit integer overflow in tcpip.sys, the…

https://core-jmp.org/2026/07/cve-2026-58532-tcpip-sys-integer-overflow/
  • 😱 4
  • 🔥 3
  • 👍 2
Post #3566 6.39K
Верное мнение из СССР

#onlyGNU
  • 🔥 27
  • 👍 8
  • 😱 7
Post #3565 5.28K
CVE-2026-58613: Use-After-Free in the Windows Cloud Files Mini Filter Driver (cldflt.sys)

Original text: “Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteRequest use-after-free vulnerability” — Marcin ‘Icewall’ Noga, Cisco Talos (July 17, 2026). Register dumps, decompiled listings and crash logs below are reproduced verbatim with attribution.

Executive Summary

Cisco Talos researcher Marcin ‘Icewall’ Noga disclosed CVE-2026-58613, a kernel-mode use-after-free in cldflt.sys — the Windows Cloud Files Mini…

https://core-jmp.org/2026/07/cve-2026-58613-cldflt-cloud-files-use-after-free/
  • 👍 3
  • 🔥 2
Post #3564 4.73K
Direct $MFT Parsing: Reading NTFS Below the Monitored API Layer

Original text: “Direct $MFT Parsing” — S12 — 0x12Dark Development, on Medium. This article summarises the technique in our own words for readers of core-jmp.org; the ASCII pipeline diagram and the short C++ excerpts below are reproduced with attribution to illustrate the discussion. For the complete C++17 header, main runner, and YARA rule, follow the…

https://core-jmp.org/2026/07/direct-mft-parsing-ntfs-raw-enumeration/
  • 🔥 3
Post #3563 4.92K
CVE-2026-58635: How the Windows Narrator Braille Bug Escalates a Standard User to SYSTEM

Original text: "CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation" (proof-of-concept) — DavidCarliez, GitHub (July 2026), released under the MIT License. Source code, scripts, tables and terminal output below are reproduced verbatim with attribution.

Executive Summary

CVE-2026-58635 is a local privilege-escalation vulnerability in an unlikely place: the Braille accessibility component that ships with Windows Narrator. Microsoft…

https://core-jmp.org/2026/07/cve-2026-58635-windows-narrator-braille-privilege-escalation/
  • 🔥 2
Post #3562 4.57K
Reverse Engineering CVE-2026-2796: How Claude Built a Firefox WebAssembly Exploit

Original text: "Reverse engineering Claude’s CVE-2026-2796 exploit" — Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, and Daniel Freeman, Anthropic Frontier Red Team (6 March 2026). The prose below is an independent technical summary; the code listings are reproduced verbatim from the source with attribution.

Executive Summary

In March 2026 Anthropic’s Frontier Red Team…

https://core-jmp.org/2026/07/cve-2026-2796-claude-firefox-webassembly-exploit/
  • 🔥 4
Post #3561 4.97K
CVE-2026-50343
InstallService StaticPluginMap EoP (Standard User to SYSTEM)
*
Exploit + WriteUP
  • 👍 6
  • 🔥 3
Post #3560 4.99K
LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive

Original text: "LegacyHive — Windows user profile service arbitrary hive load elevation of privileges vulnerability" — Nightmare-Eclipse (GitHub handle MSNightmare), Project NightCrawler, July 14 2026. The proof-of-concept is published under the MIT License; all code below is reproduced verbatim with attribution.

Executive Summary

On 14 July 2026 — hours after Microsoft’s July Patch Tuesday —…

https://core-jmp.org/2026/07/legacyhive-windows-user-profile-service-hive-load-eop/
  • 👍 2
  • 🔥 2
Post #3559 4.62K
The QNAP Pattern: Four Bugs and the Architecture That Keeps Producing Them

Original text: “The QNAP Pattern” — Runic Labs (May 17, 2026). Code and architecture diagrams below are reproduced with attribution.

Executive Summary

Runic Labs disassembled a full disclosure cycle against QNAP’s QTS operating system—four bugs across three App Center plugins (Notes Station 3, QmailAgent, QVPN) spanning two firmware releases—and found that the individual vulnerabilities matter…

https://core-jmp.org/2026/07/qnap-pattern-architecture-vulnerabilities/
  • 🔥 2
  • 👍 1
Post #3557 4.66K
NFC reader/skimmer bug-sweep for Flipper Zero.
*
Specter
  • 👍 6
  • 🔥 6
  • 😱 2
Post #3556 4.93K
The July 2026 Security Update Review

Original text: “The July 2026 Security Update Review” — Dustin Childs, Zero Day Initiative (July 14, 2026). Tables and figures are reproduced verbatim with attribution captions.

Executive Summary

July 2026 delivered a landmark month for security patches: Adobe released 88 CVEs across twelve products via their bimonthly cycle, while Microsoft disclosed 621 vulnerabilities—a volume that…

https://core-jmp.org/2026/07/july-2026-security-update-review/
  • 🔥 3
  • 👍 1
Post #3555 5.03K
понеслась
  • 🔥 25
  • 👍 8
  • 😱 2
Post #3554 5.25K
Имитация подмены железа хоста и криптоКонтейнер DENY
Увязать бы это с TPM 2.0 или YubiKey - вот тогда ломать это финансово уже не выгодно
  • 👍 12
  • 🔥 2
Post #3553 5.91K
Forgotten UEFI Shims Undermining Secure Boot

Original text: “Forgotten UEFI shims undermining Secure Boot” — Martin Smolár, ESET Research (July 14, 2026). Figures, code blocks, and technical diagrams below are reproduced verbatim with attribution captions.

Executive Summary

ESET researchers identified 11 old and forgotten UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot…

https://core-jmp.org/2026/07/forgotten-uefi-shims-undermining-secure-boot/
  • 🔥 7
  • 👍 3
Post #3552 5.13K
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining

Original text: “CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining” — Tiziano Marra, Tiziano’s Cybersecurity Blog (12 July 2026). Code blocks, tables, and figures below are reproduced verbatim with attribution captions.

Research published for educational and defensive purposes. Always obtain explicit written authorization before testing security techniques on any computer system. Unauthorized access is…

https://core-jmp.org/2026/07/cet-compliant-callstack-spoofing-thread-pool-enum/
  • 🔥 6
Post #3551 5.88K
Two Bytes to RCE: Chaining Rift + PoolSlip into an ASLR-Independent nginx 1.30.0 Exploit

Original text: “Two Bytes to RCE: Chaining Rift + PoolSlip” — y198, Verichains (Jun 06, 2026). Code, tables and figures below are reproduced verbatim with attribution captions. PoC: github.com/y198nt/Nginx-chain-Rift-Poolslip.

Executive Summary

A two-bug chain in nginx 1.30.0 achieves unauthenticated remote code execution without relying on ASLR breaks. The first bug, CVE-2026-42945 (“Rift”), is a forward…

https://core-jmp.org/2026/07/nginx-rce-rift-poolslip-aslr-independent/
  • 🔥 12
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →