See our official advisories for the details and remediation steps: www.rcesecurity.com/security-adv...
#security
See our official advisories for the details and remediation steps: www.rcesecurity.com/security-adv...
#security
docs.rocketsoftware.com/bundle/trufu...
#security
docs.rocketsoftware.com/bundle/trufu...
#security
Pre-auth path traversal, hard-coded crypto key allowing cookie forgery, arbitrary file write, and PII disclosure in TRUfusion Enterprise (CVE-2025-27222 to CVE-2025-27225) #security
www.rcesecurity.com/2025/09/when...
Pre-auth path traversal, hard-coded crypto key allowing cookie forgery, arbitrary file write, and PII disclosure in TRUfusion Enterprise (CVE-2025-27222 to CVE-2025-27225) #security
www.rcesecurity.com/2025/09/when...
Unfortunately, I had to postpone the disclosure because there are still too many vulnerable instances online and the vendor apparently needs to manually patch each one... 🤦♂️
#BugBounty #security
Unfortunately, I had to postpone the disclosure because there are still too many vulnerable instances online and the vendor apparently needs to manually patch each one... 🤦♂️
#BugBounty #security
This is it 💯
#privacy
Privacy, Proton and Pentesting
#bugbountytips #hacktheplanet #BugBounty monke.ie/p/monkehacks...
This is it 💯
#privacy
📖 Read more: www.helpnetsecurity.com/2025/07/11/c...
#cybersecurity #cybersecuritynews #exploit #filesharing @censys.bsky.social @rcesecurity.com @mrtuxracer.bsky.social
📖 Read more: www.helpnetsecurity.com/2025/07/11/c...
#cybersecurity #cybersecuritynews #exploit #filesharing @censys.bsky.social @rcesecurity.com @mrtuxracer.bsky.social
This helped a lot: european-alternatives.eu
This helped a lot: european-alternatives.eu
This helped a lot: european-alternatives.eu
#security #BugBounty
#security #BugBounty
www.rcesecurity.com/2025/06/what...
#security #BugBounty
Enjoy 🥷
#security #BugBounty
#security #BugBounty
www.rcesecurity.com/2025/06/what...
Enjoy 🥷
#security #BugBounty
I'm a bit nervous, TBH, because it potentially affects 15k systems on the internet. But, according to the vendor, most instances should've been updated already 😬
I'm a bit nervous, TBH, because it potentially affects 15k systems on the internet. But, according to the vendor, most instances should've been updated already 😬
2x RCE (one as root!),
Full SSRF,
Directory traversal,
Cookie forgery leading to auth bypass,
Multiple information disclosures incl. PII
Link injection leaking clear-text passwords
All pre-auth 🙃
#security #BugBounty
2x RCE (one as root!),
Full SSRF,
Directory traversal,
Cookie forgery leading to auth bypass,
Multiple information disclosures incl. PII
Link injection leaking clear-text passwords
All pre-auth 🙃
#security #BugBounty
Also: Triaged, fixed, and rewarded within 2 hours of submission 😎
Much cooler than a lame open redirect 🙃
Also: Triaged, fixed, and rewarded within 2 hours of submission 😎
Much cooler than a lame open redirect 🙃
Much cooler than a lame open redirect 🙃
labs.watchtowr.com/sysowned-you...
labs.watchtowr.com/sysowned-you...
Just sayin
Just sayin
I'm considering reposting my stuff there again for visibility; maybe with a delay to lure more users to Bluesky? 🤔
I'm considering reposting my stuff there again for visibility; maybe with a delay to lure more users to Bluesky? 🤔
www.rcesecurity.com/2025/04/sap-...
It's a shame I'll have to leave you soon 😢
It's a shame I'll have to leave you soon 😢