Quick and Dirty Analysis of Possible Oracle E-Business Suite Exploit Script (CVE-2025-61882), (Mon, Oct 6th)

This weekend, Oracle published a surprise security bulletin announcing an exploited vulnerability in Oracle E-Business Suite. As part of the announcement, which also included a patch, Oracle published IoC observed as part of the incident response [1].

Continue reading Quick and Dirty Analysis of Possible Oracle E-Business Suite Exploit Script (CVE-2025-61882), (Mon, Oct 6th)

Posted in Uncategorized

More .well-known Scans, (Thu, Oct 2nd)

I have been writing about the “.well-known” directory a few times before. Recently, about attackers hiding webshells &#;x26;#;x5b;1&#;x26;#;x5d;, and before that, about the purpose of the directory and why you should set up a “/.well-known/security.txt” file. But I noticed something else when I looked at today&#;x26;#;39;s logs on this web server. Sometimes you do not need a honeypot. Some attackers are noisy enough to be easily visible on a busy web server. This time, the attacker hit various URLs inside the “.well-known” directory. Here is a sample from the > 100 URLs hit:

Continue reading More .well-known Scans, (Thu, Oct 2nd)

Posted in Uncategorized

“user=admin”. Sometimes you don’t even need to log in., (Tue, Sep 30th)

One of the common infosec jokes is that sometimes, you do not need to “break” an application, but you have to log in. This is often the case for weak default passwords, which are common in IoT devices. However, an even easier method is to tell the application who you are. This does not even require a password&#;x26;#;x21; One of the sad recurring vulnerabilities is an HTTP cookie that contains the user&#;x26;#;39;s username or userid.

Continue reading “user=admin”. Sometimes you don’t even need to log in., (Tue, Sep 30th)

Posted in Uncategorized

Apple Patches Single Vulnerability CVE-2025-43400, (Mon, Sep 29th)

It is typical for Apple to release a “.0.1” update soon after releasing a major new operating system. These updates typically fix various functional issues, but this time, they also fix a security vulnerability. The security vulnerability not only affects the “26” releases of iOS and macOS, but also older versions. Apple released fixes for iOS 18 and 26, as well as for macOS back to Sonoma (14). Apple also released updates for WatchOS and tvOS, but these updates do not address any security issues. For visionOS, updates were only released for visionOS 26.

Continue reading Apple Patches Single Vulnerability CVE-2025-43400, (Mon, Sep 29th)

Posted in Uncategorized