Seclog - #119


"Great results can be achieved by small teams focused on the correct actions" - The Art of Cyber War
๐ SecMisc
DOM Clobbering
Manipulating the DOM to bypass security controls or influence application logic.
Read MoreHackBench
Practice your offensive security skills in a gamified and competitive environment.
Read MoreFind Your Cybersecurity Degree or Certification
A curated list of cybersecurity degrees and certifications to advance your career.
Read More
๐ฐ SecLinks
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog
Details on the latest critical RCE vulnerabilities in Ingress NGINX for Kubernetes.
Read MoreDefeating Prompt Injections by Design
New research proposing architectural defenses against prompt injection attacks.
Read MoreReport on Paragon Spyware - Schneier on Security
Analysis of the Paragon spyware and its implications on surveillance.
Read MoreImproper Use of Private iOS APIs in Vietnamese Banking Apps
A technical analysis uncovering misuse of iOS APIs leading to potential security risks.
Read MoreExploring Javascript events & Bypassing WAFs via character normalization
Novel WAF bypass techniques using character normalization tricks.
Read MoreNVD Backlog Crisis
The NVD struggles to keep up with the surge in CVE disclosures.
Read MoreNext.js Middleware Bypass (CVE-2025-29927)
In-depth analysis of a critical vulnerability in Next.js middleware.
Read MoreHigh Agency Hacking
A personal journey on how initiative and agency shape great hackers.
Read MoreCrushFTP Authentication Bypass - CVE-2025-2825
Details of a critical auth bypass vulnerability affecting CrushFTP.
Read More
๐ฆ SecX
- Signal App Debunking Misinfo
Addressing widespread misinformation and educating users on secure messaging.
Watch Here
๐ฅ SecVideo
- CRITICAL 9.1 Severity Next.js Vulnerability
A video breakdown of the latest Next.js vulnerability and its real-world impact.
Watch Here
๐ป SecGit
Zouuup/landrun
Secure, unprivileged sandboxing for Linux processes using Landlock LSM.
Explore on GitHubsandumjacob/IngressNightmare-POCs
Public POC repository for CVE-2025-1974 - Ingress Nightmare.
Explore on GitHub
For suggestions and any feedback, please contact: securify@rosecurify.com
Subscribe to my newsletter
Read articles from Rosecurify directly inside your inbox. Subscribe to the newsletter, and don't miss out.
Written by
