Security Reliks
-
1
Security 101: bitter sweet beginnings
-
2
/dev/tcp as a weapon
-
3
Enabling /dev/tcp on Backtrack 4r1(Ubuntu)
-
4
We have moved to SecureGossip!!!
-
5
Weaponizing cmd.exe – Ping Sweep
-
6
Weaponizing cmd.exe – DNS Reverse Lookup
-
7
Weaponizing cmd.exe – Enumerate users (inspite of RestrictAnonymous)
-
8
Weaponizing cmd.exe – UN/PW Guessing
-
9
Weaponizing cmd.exe – Port Scanning
-
10
We Moved to SecureGossip!
UX Planet
-
1
Can GPT-6 Actually Do UX Design?
-
2
Design Critique with Claude Code
-
3
GPT-6 Astra for Web Design
-
4
GPT-6 Astra vs Opus 5: Which one is better for product design?
-
5
GPT-6 Astra for UI Design
-
6
Figma Design Critique Using Claude Code
-
7
Fable 5.1 for Product Designers
-
8
How to Audit and Extend Your Figma Design System with Claude Code
-
9
We Don’t Need AI-First Designers. We Need AI-First Managers.
-
10
Claude Code’s New Design Plugin Is a Big Deal for Product Designers
DoomsDay Vault – Articles
-
1
Loading "fileless" Shared Objects (memfd_create + dlopen)
-
2
Writeup (CTF) - ImpelDown CodeGate PreQuals 2018 (MISC)
-
3
JavaScript AntiDebugging Tricks
-
4
Parasiting web server process with webshells in permissive environments
-
5
Defeating WordPress Security Plugins (Revisited)
-
6
Beyond pty.spawn - use pseudoterminals in your reverse shells (DNScat2 example)
-
7
Exfiltrating credentials via PAM backdoors & DNS requests
-
8
Hacking a game to learn FRIDA basics (Pwn Adventure 3)
-
9
Improving PHP extensions as a persistence method
-
10
Vulnerability in Swoole PHP extension [CVE-2018-15503]
Flanker Sky
-
1
Galaxy Leapfrogging: Pwning the Galaxy S8
-
2
Galaxy Leapfrogging盖乐世蛙跳: Pwning the Galaxy S8
-
3
Examining and exploiting android vendor binder services – part 1
-
4
Examining and exploiting android vendor binder services – part1
-
5
Text-To-Speech speaks pwned
-
6
Fuzzing战争: 从刀剑弓斧到星球大战
-
7
Fuzzing战争系列之二:不畏浮云遮望眼
-
8
魔形女再袭?最新Android通杀漏洞CVE-2024-31317分析与利用研究
-
9
The Return of Mystique? Possibly the most valuable userspace Android vulnerability in recent years: CVE-2024-31317
-
10
OpenCyvis: An Open-Source AI Phone
Securelist
-
1
Angry Birds: Toy Ghouls’ new toys
-
2
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
-
3
ValleyRAT masquerading as adware
-
4
Threat landscape for industrial automation systems. Q2 2026
-
5
Exploits and vulnerabilities in Q2 2026
-
6
The invisible passenger in your car
-
7
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
-
8
Armored Likho expands its cyber-espionage toolkit
-
9
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
-
10
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants