October 28, 2024 at 04:05AM

■□□□□ Mandiant tracking wild exploitation of CVE-2024-47575 (FortiManager) wild exploitation due to missing authentication on ‘fgfmd’ daemon ( dubbed FortiJump). https://cloud.google.com/blog/topics/threat-intelligence/fortimanager-zero-day-exploitation-cve-2024-47575 https://t.me/cKure/14831

October 26, 2024 at 09:14PM

■■■■□ Fully working VAC kernel-mode bypass, it makes use of either SSDT hooks or Infinityhook to intercept VAC syscalls and ultimately spoof the results in order to bypass the memory integrity checks. https://github.com/crvvdev/vac-bypass-kernel https://t.me/cKure/14826

October 22, 2024 at 07:51PM

Escaping the Chrome Sandbox Through DevTools. https://ading.dev/blog/posts/chrome_sandbox_escape.html A POC exploit for CVE-2024-5836 and CVE-2024-6778, allowing for a sandbox escape from a Chrome extension. https://github.com/ading2210/CVE-2024-6778-POC https://t.me/cKure/14819