💣 CLIXML #deserialization in #PowerShell isn't harmless…
At #PSConfEU 2025, Alexander Andersson showed how it enables:
✔ Lateral movement
✔ Privilege escalation
✔ Guest-to-host VM breakouts
🎟️ Early bird 2026 tickets → psconf.eu
#Security #CLIXML
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478):
slcyber.io/research-cen...
#exploit #exploitation #infosec #informationsecurity #cve #rce #hacking #deserialization
Making Serialization Gadgets by Hand - .NET:
www.vulncheck.com/blog/making-...
#dotnet #infosec #deserialization #hacking #programming #exploit #exploitation
Active exploitation observed for WSUS deserialization bug CVE-2025-59287; report from a customer alert on Windows Server Update Services noted by Bas van den Berg. Limited IoCs published. #CVE-2025-59287 #WSUS #deserialization https://bit.ly/49q0nhx
Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236):
slcyber.io/assetnote-se...
#infosec #cybersecurity #deserialization #rce #exploit #exploitation #cve
Critical Apache ActiveMQ Flaw Lets Attackers Run Code Remotely A flaw in Apache ActiveMQ’s .NET client lets attackers run code remotely, risking full system compromise for unpatched users. The po...
#News #Threats #.NET #security #Apache #ActiveMQ […]
[Original post on esecurityplanet.com]
SolarWinds logo over world map silhouette
🚨 Patch bypass alert for SolarWinds Web Help Desk. Unauth attackers can run commands via AjaxProxy deserialization — a new bypass of CVE-2024-28988 (itself a bypass of 28986). Patch fast and lock down access.
🔗 basefortify.eu/cve_reports/...
#SolarWinds #RCE #Deserialization
Leaked #secrets + a #ViewState weakness gave attackers a foothold to pivot and escalate inside Sitecore. It's a real-world example of App weakness exploitation in action 🧵2/4
#AppSec #DotNet #Deserialization
💣 CLIXML #deserialization in #PowerShell isn't harmless…
At #PSConfEU 2025, Alexander Andersson showed how it enables:
✔ Lateral movement
✔ Privilege escalation
✔ Guest-to-host VM breakouts
🎟️ Early bird 2026 tickets → psconf.eu
#Security #CLIXML
Using JsonPropertyName to map Json to Class C# Tip #42
How to use the JsonPropertyName attribute in C# to map mismatched JSON fields (like id) to class properties (like UniquePostId) during deserialization. #CSharp #JSON #Deserialization #HttpClient #JsonPropertyName #DataMapping #WebAPI #DotNet
[oss-security] CVE-2025-48734: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
www.openwall.com ->
I wonder if the now restricted behavior is useful for #deserialization gadgets (I
1/2
Serialization and Deserialization In Java — What is SerialVersionUID and When to Regenerate It #java #serialization #deserialization #serialversionuid #intellij #intellijidea senoritadeveloper.medium.com/serializatio...
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...
thecyberexpress.com/cisa-adds-cve-2017-3066-...
#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]
[Original post on thecyberexpress.com]
Is there a simple recursive analogue of this breadth-first binary tree deserialization function i...
stackoverflow.com/questions/79413187/is-th...
#haskell #functional-programming #deserialization #binary-tree […]
Is there a simple recursive analogue of this breadth-first binary tree deserialization function i...
stackoverflow.com/questions/79413187/is-th...
#haskell #functional-programming #deserialization #binary-tree […]
Built-in Way of Working with JSON in Unity Code #Unity #Programming #Tutorial #Json #Structure #Serialization #Deserialization #Arrays #Objects #Csharp #Development #Coding #Data #Format
I've just dropped a #Python tool to exploit #Django RCE by leveraging #deserialization in session cookies.
It forges a malicious cookie that executes system commands remotely.
🔗 Check it out here: github.com/Spix0r/djang...
#CyberSecurity #BugBountyTools #RCE #BugBounty #Exploit #BugBountyTips
The sorry state of Java deserialization
#deserialization #java
www.marginalia.nu/log/a...
Before the break, I started looking at CVE-2022-1471 in Confluence et al, which led me learn about SnakeYAML deserialization. It was quite the ride, full of open source drama and related vulns. I wrote it all up in this blog post!
#vuln #vulnerability #poc #java #deserialization #snakeyaml #yaml