January 29, 2024 at 11:19AM

■■■■□ ExecIT: DLL Shellcode self-inyector/runner based on HWSyscalls, ideally thought to be executed with rundll32. May grant fileless execution if victim endpoint has access to attacker-controlled SMB share. https://github.com/florylsk/ExecIT https://t.me/cKure/13438

January 29, 2024 at 08:38AM

Zero-Day: CVE-2023-45866 and CVE-2024-21306 exploitation. Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing. Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing https://youtu.be/dj1lGqL8lXo https://t.me/cKure/13434