Carlos Vieira's banner
Carlos Vieira's profile picture

Carlos Vieira

@carlos_crowsec3,183 subscribers

Founder @quimerax_intel | Partner @Hakaioffsec

Shorts

Our team has just successfully reproduced the IngressNightmare vulnerability (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) and created a custom exploit achieving RCE. It's a Pre-Auth RCE affecting Ingress NGINX that allows complete cluster takeover. We'll share our exploit soon. In the original post from the Wiz team, they didn't mention the path traversal technique used to load a malicious library via /proc. Hakai Offsec @quimerax_asm

Our team has just successfully reproduced the IngressNightmare vulnerability (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) and created a custom exploit achieving RCE. It's a Pre-Auth RCE affecting Ingress NGINX that allows complete cluster takeover. We'll share our exploit soon. In the original post from the Wiz team, they didn't mention the path traversal technique used to load a malicious library via /proc. Hakai Offsec @quimerax_asm

81,336 次观看

Videos

没有更多内容可加载