Full Disclosure: by author

22 messages starting Oct 21 25 and ending Oct 18 25
Date index | Thread index | Author index


BSidesSF CFP via Fulldisclosure

BSidesSF 2026 CFP still open until October 28th BSidesSF CFP via Fulldisclosure (Oct 21)

Christopher Dickinson via Fulldisclosure

Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS) Christopher Dickinson via Fulldisclosure (Oct 13)

cve

Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a cve (Oct 18)

full

Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain → Secure Enclave Key Theft, Wormable RCE, Crypto Theft full (Oct 07)

Gynvael Coldwind

Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS) Gynvael Coldwind (Oct 15)

josephgoyd via Fulldisclosure

Re: [FD] Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain → Secure Enclave Key Theft, Wormable RCE, Crypto Theft josephgoyd via Fulldisclosure (Oct 07)
Re: [FD] : "Glass Cage" – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885) josephgoyd via Fulldisclosure (Oct 02)
Re: [FD] Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain → Secure Enclave Key Theft, Wormable RCE, Crypto Theft josephgoyd via Fulldisclosure (Oct 02)

malvuln

Malvuln - MISP compatible malware vulnerability intelligence feed now live malvuln (Oct 21)

Matteo Beccati

[REVIVE-SA-2025-002] Revive Adserver Vulnerability Matteo Beccati (Oct 25)
[REVIVE-SA-2025-001] Revive Adserver Vulnerability Matteo Beccati (Oct 25)

Matthias Deeg via Fulldisclosure

[SYSS-2025-016]: Verbatim Store 'n' Go Secure Portable SSD (security update v1.0.0.6) - Offline brute-force attack Matthias Deeg via Fulldisclosure (Oct 21)
[SYSS-2025-015]: Verbatim Keypad Secure (security update v1.0.0.6) - Offline brute-force attack Matthias Deeg via Fulldisclosure (Oct 21)
[SYSS-2025-017]: Verbatim Store 'n' Go Secure Portable HDD (security update v1.0.0.6) - Offline brute-force attack Matthias Deeg via Fulldisclosure (Oct 21)

Patrick via Fulldisclosure

apis.google.com - Insecure redirect via __lu parameter (exploited in the wild) Patrick via Fulldisclosure (Oct 18)

SBA Research Security Advisory via Fulldisclosure

[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal SBA Research Security Advisory via Fulldisclosure (Oct 13)
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files SBA Research Security Advisory via Fulldisclosure (Oct 13)

SEC Consult Vulnerability Lab via Fulldisclosure

SEC Consult SA-20251021-0 :: Multiple Vulnerabilities in EfficientLab WorkExaminer Professional (CVE-2025-10639, CVE-2025-10640, CVE-2025-10641) SEC Consult Vulnerability Lab via Fulldisclosure (Oct 21)

Security Explorations

Google Firebase hosting suspension / "malware distribution" bypass Security Explorations (Oct 21)

Seralys Research Team via Fulldisclosure

CVE-2025-59397 - Open Web Analytics SQL Injection Seralys Research Team via Fulldisclosure (Oct 08)

Stefan Kanthak via Fulldisclosure

Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFER whitelisting goes black on Windows 11 Stefan Kanthak via Fulldisclosure (Oct 07)

Thomas Weber | CyberDanube via Fulldisclosure

CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS Thomas Weber | CyberDanube via Fulldisclosure (Oct 18)