00:00 - Introduction
00:40 - Start of nmap
03:00 - Logging into zoneminder with default credentials, flailing around trying to find the date this version was released
10:55 - Looking into the SQL Injection, lots of weird confusion around the date this was released... should of prepared more
13:30 - Getting this into SQLMap to test the injection, discovering it finds Time Based Blind which is really slow and unreliable
16:00 - Playing with the SQL Injection to get it to turn this into Boolean Based which is much better than time based
19:50 - Getting SQLMap to exploit this with boolean using prefix and suffix
24:10 - Cracking the password
30:00 - Got marks credentials, can login now
32:30 - Forwarding port 8765 back to us and accessing the MotionEye webserver, looking at configs and getting an admin password that lets us login
37:00 - RootPath1: Looking at public exploits, finding a command injection, testing it out and getting a shell
42:00 - RootPath2: Talk to the Web Control Port directly, poison that config and get command injection. Misspeak when i say camera, mean web control port
48:30 - Intended path to sa_mark, can tcpdump, capture packets get a credential and login
58:00 - Beyond Root: Using Claude to help me turn the blind injection into boolean.
CISA has disclosed its incident response procedures following the exposure of AWS GovCloud credentials and internal data in a publicly accessible GitHub repository. The agency's detailed account provides insights into how a government cybersecurity organization handles the discovery and remediation of compromised cloud infrastructure access and sensitive information.
Microsoft has identified a new malware called GigaWiper that functions as a multi-purpose backdoor capable of supporting both espionage and destructive operations. The malware's dual functionality allows attackers to conduct covert intelligence gathering before escalating to file-wiping attacks, combining reconnaissance and destructive capabilities in a single tool.
A remote code execution vulnerability in Windows HTTP.sys allows unauthenticated attackers to send specially crafted HTTP/1.x requests over TLS connections to trigger a kernel pool heap buffer overflow, potentially resulting in denial of service or arbitrary kernel-level code execution. The vulnerability stems from an integer overflow in the buffer reference array capacity field during HTTP header parsing, which can be exploited by encapsulating each header line in a separate TLS record to accumulate the required 65,536 buffer references. Microsoft patched this vulnerability in the June 2026 release cycle, and organizations can mitigate risk by keeping the MaxRequestBytes registry value at or below 65,535 bytes or deploying the vendor patch.
Researchers from the AI Now Institute have developed a proof-of-concept exploit demonstrating that security tools from major AI providers could potentially be weaponized by attackers. The findings suggest that common AI-based security tools may inadvertently create new attack vectors when misused, raising concerns about the dual-use nature of these platforms.
GodDamn ransomware leverages a remote desktop application to covertly traverse networks and deploy the PoisonX kernel driver, which disables cybersecurity protections on targeted systems. This combination of lateral movement and driver-based defense evasion represents an escalation in ransomware sophistication, allowing attackers to bypass security controls before executing their encryption payloads.
NIST is advancing nine new post-quantum signature algorithms toward standardization, but their timeline remains uncertain. Cloudflare argues that organizations should adopt ML-DSA immediately rather than wait for future candidates, as it represents the most mature and practical option currently available for post-quantum cryptography deployment.
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read more in my article on the Hot for Security blog.
A survey by MetaCompliance reveals significant communication gaps between cybersecurity leaders and corporate boards, with three-quarters of CISOs concerned that executives lack understanding of the cyber risks threatening their workforce. The findings highlight a broader disconnect where many board members appear disengaged from the evolving nature of cybersecurity threats facing employees across their organizations.
Operation First Light 2026, a Chinese-government-funded Interpol initiative, has resulted in 5,811 arrests in a coordinated cybercrime crackdown. The operation demonstrates international law enforcement collaboration against cyber threats, with China providing financial backing for the large-scale enforcement action.
Over 70 cybersecurity organizations have endorsed the CREST AI Charter, establishing guidelines for the responsible deployment of artificial intelligence in security operations. The charter represents industry consensus on best practices for leveraging AI capabilities while maintaining ethical standards and security integrity.
Zimperium has discovered RedWing, an Android spyware operation being monetized as a service through Telegram channels, primarily targeting banking applications. The malware-as-a-service model enables threat actors to purchase access to the spyware capabilities for financial fraud and data theft purposes.
Cisco Talos has identified China-linked APT UAT-7810 expanding its infrastructure through the development of new malware designed to augment its proxy relay network. This expansion suggests the threat actor is strengthening its capabilities for obfuscating command-and-control communications and maintaining persistent access to compromised systems.