4:02
SEC Consult is the leading business consultancy for information security in Central Europe. SEC Consult is independent from ...
4:02
www.sec-consult.com ----------------------------- SEC Consult is the leading business consultancy for information security in Central ...
0:34
Dormakaba proof of concept opening a relay / door without authentication
Dormakaba exos 9300 was affected by a critical vulnerability (CVE-2025-59097) in the SOAP API which allowed attackers to open ...
4:50
SEC Technologies' CyberTrap is the first 100 % APT aware honeynet technology with a focus on post-exploitation on the market ...
0:50
Authentication Bypass in Governikus Autent SDK discovered by SEC Consult Vulnerability Lab
More infos: https://r.sec-consult.com/governikus The German government-issued identity card (nPA) allows German citizens to not ...
1:16
Command Injection in multiple Ubiquiti Networks products
The firmware of various Ubiquiti Networks devices contains a command injection vulnerability which can be exploited by luring an ...
1:05
Authentication bypass (SSRF) in Plex Media Server
The Plex Media Server proxy functionality fails to properly validate pre-authentication user requests. This allows unauthenticated ...
0:49
Authentication Bypass in eIDAS-Node (Proof of concept)
Due to insufficient certificate verification the European Commission eIDAS-Node accepted manipulated SAML messages, ...
1:37
Genua GenuGate Firewall Authentication Bypass Vulnerability
Full advisory: https://r.sec-consult.com/genua The Genua GenuGate High Resistance Firewall is affected by a critical ...
1:39
Zhuhai Suny Technologies vulnerability - Replay attack against ESL tags
Full SEC Consult Vulnerability Lab security advisory: https://r.sec-consult.com/suny The displayed information on the ESL / price ...
1:32
DNS Protocol Impersonation with Version Negotiation in QUIC
QUIC inherits a version negotiation mechanism that can be abused to achieve protocol impersonation for other UDP protocols, ...
2:02
Unauthenticated remote root buffer overflow in Zyxel devices
An unauthenticated buffer overflow was found in the proprietary zhttp web server by Zyxel. An attacker can take over the affected ...
1:08
Local Buffer Overflow vulnerability in SAS for Windows (Statistical Analysis System)
Attackers are able to completely compromise SAS clients when a malicious SAS program gets executed as the software "SAS for ...
1:09
Zhuhai Suny Technologies vulnerability - Displaying arbitrary tag contents
Full SEC Consult Vulnerability Lab security advisory: https://r.sec-consult.com/suny The ETAG-TECH protocol used by Zhuhai ...
0:56
Zhuhai Suny Technologies vulnerability - Receiving arbitrary ESL-TECH messages
Full SEC Consult Vulnerability Lab security advisory: https://r.sec-consult.com/suny The ETAG-TECH protocol used by Zhuhai ...
47:40
Finding security vulnerabilities with modern fuzzing techniques - Rene Freingruber (RuhrSec 2018)
Original published by Hackmanit GmbH on Jun 4, 2018 here: https://www.youtube.com/watch?v=KFmeHz_vxfo Permission ...
2:31
SAP Application Server for ABAP: Authentication Bypass and Remote Code Execution
Numerous releases and versions of SAP NetWeaver Application Server ABAP and ABAP Platform are affected by multiple critical ...
2:49
Top 5 of the simplest and most effective measures to prevent hacker attacks
No matter what type of cyber attacker you are dealing with, the steps from initial compromise to full domain domination follow the ...
3:33
Kerio Control contains multiple vulnerabilities which can be used by an attacker to obtain a reverse root shell to the internal ...
0:26
Microsoft OneDrive iOS APP URI schemes vulnerability
Insecure Handling Of URI Schemes in Microsoft OneDrive iOS App Due to the lack of URI scheme validation, any external URI ...