❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayHacking and InfoSec

Hack The Box: Silentium Machine Walkthrough – Easy Difficulity

By: darknite
12 September 2026 at 10:56

Completed another Hack The Box machine, Silentium.

Initial access was achieved by exploiting a password-reset vulnerability in the staging Flowise application, followed by abusing a custom MCP endpoint to obtain a root shell inside the Flowise container. Credentials exposed through the container environment were then used to SSH into the underlying host as ben and retrieve the flag.

For privilege escalation, an internal Gogs instance was discovered through local port forwarding. A malicious symlink was pushed and manipulated through the Gogs API to target /etc/sudoers.d/ben, allowing a passwordless sudo rule to be written and ultimately providing full root access.

#HackTheBox #HTB #CyberSecurity #PenetrationTesting #OffensiveSecurity #Linux #PrivilegeEscalation #WebSecurity #CTF …

Learn MoreHack The Box: Silentium Machine Walkthrough – Easy Difficulity

The post Hack The Box: Silentium Machine Walkthrough – Easy Difficulity appeared first on Threatninja.net.

Boston Scientific Cyberattack Disrupts Manufacturing and Product Shipments

By: Divya
1 September 2026 at 06:28

Boston Scientific is working to restore its manufacturing, order processing, and distribution capabilities following a cybersecurity incident that caused a network outage across certain internal IT systems. In an August 30 update, the medical device manufacturer reported that investigators had found no signs of unauthorized activity in its environment since August 25. The disruption is […]

The post Boston Scientific Cyberattack Disrupts Manufacturing and Product Shipments appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

By: Waqas
28 July 2026 at 06:50
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations
❌
❌