Recon

RECON

Updated 4m ago
High-Signal Security Intelligence

2026-02-04

Exploit-DB.com RSS Feed200IN STACK · 2026-02-04 00:00

[remote] windows 10/11 - NTLM Hash Disclosure Spoofing

windows 10/11 - NTLM Hash Disclosure Spoofing
Huntress Blog61 · 2026-02-04 15:00

They Got In Through SonicWall. Then They Tried to Kill | Huntress

Huntress responded to a 2026 intrusion using compromised SonicWall VPN credentials and a revoked EnCase forensic driver to terminate EDR processes via BYOVD.
Rob Zolkos27 · 2026-02-04 01:35

Deep Dive: How Claude Code’s /insights Command Works

The /insights command in Claude Code generates a comprehensive HTML report analyzing your usage patterns across all your Claude Code sessions. It’s designed to help you understand how you interact with Claude, what’s working well, where friction occurs, and how to improve your workflows. It’s output is really cool and I encourage you to try it and read it through! Command: /insights Description: “Generate a report analyzing your Claude Code sessions” Output: An interactive HTML report saved t...
Robin Wilson17 · 2026-02-04 14:10

Pharmacy late-night opening hours analysis featured in the Financial Times

Some data analysis I’ve done has been featured in the Financial Times today – see this article (the link may not work any more unless you have a FT subscription – sorry). The brief story is that I had terrible back pain over Christmas, and spoke to an out-of-hours GP on the phone who prescribed […]
Ray Wenderlich15 · 2026-02-04 16:00

An Introduction to Liquid Glass for iOS 26 [FREE]

Apple’s new Liquid Glass design language marks a major shift in iOS 26 UI design. Learn what Liquid Glass is, how it works across SwiftUI and UIKit, and what to watch out for when updating an existing iOS app.
exp库-打造中文最大exploit库15 · 2026-02-04 00:00

Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE

# Exploit Title: Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE # Date: 2025-10-07 # Exploit Author: Beatriz Fresno Naumova # Vendor Homepage: https://kubernetes.io # Software Link: https://github.com/kubernetes/ingress-nginx ......
exp库-打造中文最大exploit库14 · 2026-02-04 00:00

FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution

# Exploit Title: FortiWeb Fabric Connector 7.6.x - Pre-authentication SQL Injection to Remote Code Execution # Date: 2025-10-05 # Exploit Author: Milad Karimi (Ex3ptionaL) # Contact: miladgrayhat@gmail.com # Zone-H: www.zone-h.org/archive/notifi......
exp库-打造中文最大exploit库10 · 2026-02-04 00:00

Redis 8.0.2 - RCE

# Exploit Title: Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE # Date: 2025-10-07 # Exploit Author: Beatriz Fresno Naumova # Vendor Homepage: https://redis.io/ # Software Link: https://redis.io/ # Version: Affects :>= 8.0.......
exp库-打造中文最大exploit库10 · 2026-02-04 00:00

windows 10/11 - NTLM Hash Disclosure Spoofing

# Exploit Title: windows 10/11 - NTLM Hash Disclosure Spoofing # Date: 2025-10-06 # Exploit Author: Beatriz Fresno Naumova # Vendor Homepage: https://www.microsoft.com # Software Link: N/A # Version: Not applicable (this is a generic Windows lib......
exp库-打造中文最大exploit库10 · 2026-02-04 00:00

OctoPrint 1.11.2 - File Upload

# Exploit Title: OctoPrint 1.11.2 - File Upload # Date: 2025-09-28 # Exploit Author: prabhatverma.addada # Vendor Homepage: https://octoprint.org # Software Link: https://github.com/OctoPrint/OctoPrint # Affected Version(s): <= 1.11.2 # Patch......
exp库-打造中文最大exploit库10 · 2026-02-04 00:00

aiohttp 3.9.1 - directory traversal PoC

# Exploit Title: Python aiohttp directory traversal PoC (CVE-2024-23334) # Google Dork: N/A # Date: 2025-10-06 # Exploit Author: Beatriz Fresno Naumova # Vendor Homepage: https://www.aiohttp.org / https://www.python.org # Software Link: https://......
exp库-打造中文最大exploit库10 · 2026-02-04 00:00

Docker Desktop 4.44.3 - Unauthenticated API Exposure

# Exploit Title: Docker Desktop 4.44.3 - Unauthenticated API Exposure # Date: 2025-10-06 # Exploit Author: OilSeller2001 # Vendor Homepage: https://www.docker.com/ # Software Link: https://www.docker.com/products/docker-desktop/ # Version: Affe......
We Live Security » Languages » English8 · 2026-02-04 10:00

OfferUp scammers are out in force: Here’s what you should know

The mobile marketplace app has a growing number of users, but not all of them are genuine. Watch out for these common scams.
[DRAGNET]5 · 2026-02-04 08:00

Energy and utilities cyber threats escalate as ransomware and APT activity rise, Cyfirma reports

Energy and utilities cyber threats escalate as ransomware and APT activity rise, Cyfirma reports    Industrial Cyber
[DRAGNET]-40 · 2026-02-04 08:00

ValleyRAT Campaign Uses Trojanized LINE Setup To Harvest Credentials

ValleyRAT Campaign Uses Trojanized LINE Setup To Harvest Credentials    cyberpress.org