PT-BR - Beerus Framework: iOS - O canivete suíço para iOS
Em julho deste ano, lançamos a v1.1 do Beerus Framework para Android. Agora, em setembro, damos mais um passo na evolução do projeto
No matching entries found.
Em julho deste ano, lançamos a v1.1 do Beerus Framework para Android. Agora, em setembro, damos mais um passo na evolução do projeto
This past July, we released v1.1 of the Beerus Framework for Android. Now, in September, we take another step in the project'
Resumo A equipe de pesquisa Yokai, da Hakai Security, identificou uma vulnerabilidade de Injeção de SQL nas versões do Cacti <= 1.2.30.
Summary The Yokai research team, from Hakai Security, identified a SQL Injection vulnerability in Cacti versions <= 1.2.30. The flaw allows an
Abstract Quanto de memória uma pequena requisição destinada a alterar a tag de um pacote deveria consumir? Em condições normais, apenas alguns bytes. Afinal,
Abstract How much memory should a small request intended to change a package's tag consume? Under normal conditions, just a few bytes.
Summary As the global autonomous vehicle market grows, the security of critical driver assistance systems may be hanging by a thread. Our recent research
Resumo Enquanto o mercado global de veículos autônomos cresce, a segurança de sistemas críticos de assistência à direção pode estar por um fio. Nossa
A few months after the initial release of the Beerus Framework, we are publishing version v1.1, a minor update that brings support for
Alguns meses após o lançamento inicial do Beerus Framework, estamos publicando a versão v1.1, uma atualização minor que traz suporte a novos ambientes
By Pedro "gankd" Cruz — Pentest Analyst and Vulnerability Researcher at Hakai Security. Almost every feature-rich application emits a PDF at some
* Por Pedro "gankd" Cruz — Pentest Analyst & Vulnerability Researcher na Hakai Security. Quase toda aplicação com diversas funcionalidades emite PDF em algum
Summary The Hakai Security Research Team has identified a critical SQL Injection vulnerability in Chatwoot versions <= 4.11.1 that allows any authenticated
Resumo A Equipe de Pesquisa da Hakai identificou uma vulnerabilidade crítica de Injeção de SQL nas versões do Chatwoot <= 4.11.1 que
Introduction SmartLoader is a commodity loader currently in active deployment, attributed to Malware-as-a-Service infrastructure that has been linked to LummaStealer delivery
A command injection vulnerability has been identified in Cockpit, discovered by Hakai's Research team. The flaw allows an authenticated user, even without
Foi identificada uma vulnerabilidade de injeção de comandos no Cockpit, descoberta pelo time de Research da Hakai. A falha permite que um usuário autenticado,
On March 24, 2026, a high-criticality vulnerability was identified in Metabase Enterprise leading to remote command execution, discovered by "Hacktron AI and
Em 24 de março de 2026, foi identificada uma vulnerabilidade de alta criticidade no Metabase Enterprise que leva à execução remota de comandos, descoberta
Abstract Applications developed with vibe coding platforms are significantly lowering the barrier to entry for software creation. Tools like Lovable allow users to build
Resumo Aplicações desenvolvidas com plataformas de vibe coding vêm reduzindo significativamente a barreira de entrada para a criação de software. Ferramentas como a Lovable
Introdução Em um mundo digital cada vez mais dinâmico e globalizado, a segurança das contas online é fundamental. Um dos vetores de ataque mais
Abstract In this research, Hakai Security Research Team has identified a critical Remote Code Execution (RCE) vulnerability in Wazuh versions up to 4.14.
Introdução Nesta pesquisa, foi identificada três vulnerabilidades críticas no Centreon Web e no módulo Centreon Open Tickets, que permitem desde a extração completa do
Summary In this research, three critical vulnerabilities were identified in Centreon Web and the Centreon Open Tickets module, allowing everything from full database extraction
With knowledge of how operating systems work, it is known that common systems are composed of a kernel (the central part of the system
Com o conhecimento sobre o funcionamento de sistemas operacionais, é sabido que os sistemas comuns são compostos de um kernel (parte central do sistema
With the widespread adoption of workflow automation platforms in corporate environments, these solutions have come to play a critical role in system integration and
Com a ampla adoção de plataformas de automação de fluxos em ambientes corporativos, essas soluções passaram a desempenhar um papel crítico na integração de
Your automation script or pentest tool works perfectly in the lab. Requests flow, data returns. But the moment you hit the real target, the
Seu script de automação ou ferramenta de pentest funciona perfeitamente no laboratório. As requisições fluem, os dados retornam. Mas no momento em que você
Em 20 de janeiro de 2026, foi identificada uma vulnerabilidade crítica de bypass de autenticação no serviço GNU telnetd, descoberta por Kyu Neushwaistein (Carlos
By: Lucas Hoffmann Revision: Thiago Bispo & Allan Kardec Technical Introduction Many modern corporations rely on Kerberos, a widely used network authentication protocol designed
Por: Lucas William ,Lucas Hoffmann e Thiago Bispo Introdução No segundo semestre de 2025 o time de DevSec da Hakai atuou em uma incursão
Por: Lucas William ,Lucas Hoffmann e Thiago Bispo Introduction In the second half of 2025, the Hakai DevSec team carried out an incursion into
Quando realizamos testes internos, é comum o uso do LDAP (Lightweight Directory Access Protocol), mas pouco se entende sobre sua real função, utilidade e
When performing internal tests, it's common to use LDAP (Lightweight Directory Access Protocol), but its true purpose, utility, and power are often
Abstract O Beerus Framework é uma ferramenta ofensiva mobile desenvolvida para facilitar todo o processo de pentest em dispositivos Android. Com uma interface unificada
Abstract The Beerus Framework is an offensive mobile tool developed to simplify the entire pentesting process on Android devices. With a unified interface directly
Abstract Trend Micro Mobile Security (TMMS) is widely deployed to protect Android fleets. This research shows how an attacker can subvert that trust. We
Abstract Trend Micro Mobile Security (TMMS) is widely deployed to protect Android fleets. This research shows how an attacker can subvert that trust. We
Resumo Nesta pesquisa conduzida por mim, e pelo Lucas Katashi, identificamos duas vulnerabilidades críticas no Checkmk Enterprise Edition 2.4.0p2, que permitem a
Abstract In this research conducted by me and Lucas Katashi, we identified two critical vulnerabilities in Checkmk Enterprise Edition 2.4.0p2 that allow
Recently, a vulnerability was discovered in the Roundcube webmail service that allows an authenticated user to obtain remote execution of commands on the server.
Recentemente, foi descoberta uma vulnerabilidade no serviço de webmail Roundcube que permite a um usuário autenticado obter execução remota de comandos no servidor. A
Introdução Na primeira parte do artigo sobre modelagem de ameaças, concentramos nossos esforços na fundamentação teórica, abordando o desenvolvimento e as metodologias distintas. Agora,
Introduction In the first blog post about threat modeling we focused our efforts on the theoretical basis, addressing the development and different methodologies. Now,
Abstract Este artigo examina o formato Windows Installer (MSI) sob a perspectiva da segurança da informação, explorando como sua estrutura e funcionalidades podem ser
Download final.wav We live in an era where technology is advancing at an incredibly fast pace. Tools that were once exclusive to laboratories
Download final.wav Vivemos em uma era onde a tecnologia avança em um ritmo muito rápido. Ferramentas que antes eram exclusivas de laboratórios e
Introdução Para profissionais de segurança da informação ou administradores de sistemas, a gestão de contas de usuários é sempre um desafio, e, quando se
Introduction For information security professionals or system administrators, user account management is always challenging. When it comes to service accounts, the problem becomes even
Muitas aplicações modernas utilizam JSON Web Tokens (JWTs) para autenticar e autorizar usuários em suas funcionalidades. Neste artigo, exploraremos vulnerabilidades em JWTs que podem
Many modern applications use JSON Web Tokens (JWTs) to authenticate and authorize users in their functionalities. In this article, we will explore vulnerabilities in
A modelagem de ameaças é um processo cíclico para evitar problemas de segurança futuros. Assim como escovar os dentes, que previne cáries, tártaro ou
Threat modeling is a cyclic process to avoid future problems. Just like brushing your teeth, that prevents decay, tartar or dental calculus, threat modeling
Key Findings * We analyzed over 590 million credentials from more than 20 million unique infected computers worldwide. * Brazil is one of the most affected
Constatações importantes * Analisamos mais de 590 milhões de credenciais provenientes de mais de 20 milhões de computadores únicos infectados em todo o mundo. * O
If you are a slightly above-average user – and you certainly are; otherwise, you wouldn't be reading this article =D – you'
Se você é um usuário um pouco acima do comum - certamente você é, caso contrário não estaria lendo esse artigo =D – já viu a
"Essa noite, eu tive um sonho de sonhadorMaluco que sou, eu sonheiCom o dia em que a Terra parouCom o dia em que
File uploads have become essential for numerous web applications, ranging from social media platforms to cloud storage services. They enable users to easily share
In my recent research, I identified a critical vulnerability in osCommerce v4, specifically a Remote Code Execution (RCE) vulnerability enabled by bypassing file upload
Saudações, queridos leitores! Como estão vocês? Que o deus do hacking esteja presente em suas vidas! Brincadeiras à parte, através deste artigo, que na
Existem diferentes metodologias propostas para definir as etapas de uma avaliação da Red team. Independentemente da metodologia escolhida, a maioria concorda com a importância
Pesquisa de vulnerabilidade 1Day pela Equipe de Pesquisa da Hakai Este post trata da jornada para criar uma Prova de Conceito sobre a CVE-
Eu sou Daniel França Lima e sou pentester Jr e pesquisador de vulnerabilidades na Hakai Offensive Security. Com o objetivo de ajudar a comunidade
Abstract On February 13th, 2024, during the patch Tuesday, Microsoft disclosed the CVE-2024-21338 based on the security report made by Jan Vojtěšek
In this article, we will discuss a case of SSRF in a GCP environment and how exploiting this vulnerability led to the idea and
Greetings to all, This article aims to provide insights and stories about vulnerabilities in web applications and their impacts. Throughout this text, I will
This post details the journey of our Research Team in uncovering a SQL Injection vulnerability in GLPI, an open-source ITSM tool predominantly used
It is widely recognized that information storage poses a security risk, especially in the context of mobile devices. In the analyses conducted by our
Nginx, a versatile web server pivotal to numerous internet infrastructures, has held a dominant market share since its inception in 2004, with widespread adoption
Abstract COFF stands for Common Object File Format, it is the file format generated by compilers after the code-generation stage, they typically only
Shalom Kravim Seebernetiyim! (Greetings cyber warriors) we are back to conclude our series in Reconnaissance Like a Cyber Scout. In this part, the author
Salutations fellas! I'm back for the second part of our series on perimeter reconnaissance. Remembering that we reached half of our content,
Greetings dear readers, how are you?! May the god of hacking be present in your lives! All kidding aside, through this article, which will
There are different methodologies proposed to define the stages of a Red Team assessment, regardless of the chosen methodology, most agree on the importance
1Day vulnerability research by Hakai - Research Team This post is about the journey to create a Proof-of-concept about CVE-2022-40684, this
I'm Daniel França Lima and i'm a penetration tester Jr and vulnerability researcher at Hakai Offensive Security. In order to