
0xMiddleware
CVE-2025-29927: Next.js Middleware Exploit
authenticationexploitationpenetration-testing+3

CVE-2025-29927: Next.js Middleware Exploit
Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

Technical Reference to multiple relay techniques

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.