Carlos Vieira's banner
Carlos Vieira's profile picture

Carlos Vieira

@carlos_crowsec3,183 subscribers

Founder @quimerax_intel | Partner @Hakaioffsec

Shorts

Our team has just successfully reproduced the IngressNightmare vulnerability (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) and created a custom exploit achieving RCE. It's a Pre-Auth RCE affecting Ingress NGINX that allows complete cluster takeover. We'll share our exploit soon. In the original post from the Wiz team, they didn't mention the path traversal technique used to load a malicious library via /proc. Hakai Offsec @quimerax_asm

Our team has just successfully reproduced the IngressNightmare vulnerability (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) and created a custom exploit achieving RCE. It's a Pre-Auth RCE affecting Ingress NGINX that allows complete cluster takeover. We'll share our exploit soon. In the original post from the Wiz team, they didn't mention the path traversal technique used to load a malicious library via /proc. Hakai Offsec @quimerax_asm

81,336 просмотров

Videos

Больше нет контента для загрузки