
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…
command-and-controldata-exfiltrationinformation-gathering+8
481

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Telegram Desktop Session Stealer

Public writeup for CVE-2025-55996 (Viber Desktop HTML Injection)

Proof-of-concept exploit for CVE-2025-23040 demonstrating credential exfiltration from GitHub Desktop (< 3.4.12) via malicious repository clone URLs,…

Spoof file icons and extensions in Windows