Tags • Page 2/2Ethical exploitationLearn about ethical ways to exploit systems to find and report vulnerabilities and enhance security posture. Detect and exploit Gitlab CE/EE RCE with Pentest-Tools.com (CVE-2021-22205)“Just patch it!” is the usual advice when a vulnerability hits (and it’s not a zero-day). But it’s never that simple in organizations that have to manage layers upon layers of infrastructure. When you have to deal with a critical CVE like the latest unauthenticated RCE in Gitlab (CVSSv3 10.0), the tangled, messy process of patching bubbles to the surface.Author(s)Daniel BecheneaPublished at05 Nov 2021Updated at12 Jul 2023Why Zerologon is the silent threat in your networkNo red flags. No alerts. Full-on compromise. The way cybercriminals are putting together various vulnerabilities within the Microsoft infrastructure, including Zerologon vulnerability (CVE-2020-1472), is more than a trending topic in the infosec community. It’s a massive threat for organizations small and large.Author(s)Cristian CorneaPublished at21 Oct 2020Updated at18 Jul 202312
Detect and exploit Gitlab CE/EE RCE with Pentest-Tools.com (CVE-2021-22205)“Just patch it!” is the usual advice when a vulnerability hits (and it’s not a zero-day). But it’s never that simple in organizations that have to manage layers upon layers of infrastructure. When you have to deal with a critical CVE like the latest unauthenticated RCE in Gitlab (CVSSv3 10.0), the tangled, messy process of patching bubbles to the surface.Author(s)Daniel BecheneaPublished at05 Nov 2021Updated at12 Jul 2023
Why Zerologon is the silent threat in your networkNo red flags. No alerts. Full-on compromise. The way cybercriminals are putting together various vulnerabilities within the Microsoft infrastructure, including Zerologon vulnerability (CVE-2020-1472), is more than a trending topic in the infosec community. It’s a massive threat for organizations small and large.Author(s)Cristian CorneaPublished at21 Oct 2020Updated at18 Jul 2023