<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>News on &gt;_ majix.site</title><link>https://maajix.github.io/news/</link><description>Disclosure log: CVEs, bug bounty reports and payouts, CTF results and other things as they happen.</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>max.randhahn@yahoo.de (Max)</managingEditor><lastBuildDate>Sun, 12 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://maajix.github.io/news/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-77386: OIDC login token can be redirected to an attacker-controlled URL</title><link>https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><category>cve</category><guid isPermaLink="false">https://maajix.github.io/news/#2026-07-12-cve-2026-77386</guid><description>The OIDC login flow accepted an attacker-supplied redirect target, handing the issued token to a URL outside the application.</description></item><item><title>CVE-2026-77385: Transcoder serves uncataloged files from the media directory</title><link>https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><category>cve</category><guid isPermaLink="false">https://maajix.github.io/news/#2026-07-12-cve-2026-77385</guid><description>The transcoder streamed any file under the media directory, including files never added to the library.</description></item><item><title>YekCity</title><link>https://maajix.github.io/posts/yekcity/</link><pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate><category>project</category><guid isPermaLink="false">https://maajix.github.io/news/#2026-06-24-yekcity</guid><description>A physical OT security demonstrator that makes cyberattacks visible when the city goes dark.</description></item><item><title>Securinets CTF 2025</title><link>https://maajix.github.io/ctfs/securinets/</link><pubDate>Sun, 05 Oct 2025 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-10-05-securinets-ctf-2025</guid><description>Chaining a username SQL injection, an SSRF and a broken collaboration-request check into admin access, plus the MD7 misc challenge.</description></item><item><title>CrewCTF 2025</title><link>https://maajix.github.io/ctfs/crewctf-2025/</link><pubDate>Fri, 19 Sep 2025 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-09-19-crewctf-2025</guid><description>Getting XSS past a strict Content Security Policy and exfiltrating the result to a Burp Collaborator callback.</description></item><item><title>FortID CTF 2025</title><link>https://maajix.github.io/ctfs/fortid/</link><pubDate>Sun, 14 Sep 2025 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-09-14-fortid-ctf-2025</guid><description>Abusing the target_user parameter on the admin upload endpoint to plant files as another user, plus reversing and misc.</description></item><item><title>Nullcon CTF 2025</title><link>https://maajix.github.io/ctfs/nullcon-2025/</link><pubDate>Sat, 06 Sep 2025 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-09-06-nullcon-ctf-2025</guid><description>Brute forcing grandmas_notes character by character through a password oracle, and pwgen leaking its source via ?source=1.</description></item><item><title>TFCCTF 2025</title><link>https://maajix.github.io/ctfs/tfcctf-2025/</link><pubDate>Sun, 31 Aug 2025 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-08-31-tfcctf-2025</guid><description>SLIPPY abuses a ZIP symlink for arbitrary file read, DOM NOTIFY uses DOM clobbering against a Puppeteer admin bot.</description></item><item><title>HTB Cyber Apocalypse 2025</title><link>https://maajix.github.io/ctfs/cyber-apocalypse/</link><pubDate>Thu, 20 Mar 2025 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-03-20-htb-cyber-apocalypse-2025</guid><description>The Trial by Fire and Whispers of the Moonbeam web challenges, SealedRune reversing and Echoes in Stone OSINT.</description></item><item><title>ACECTF 2025</title><link>https://maajix.github.io/ctfs/acectf/</link><pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-02-27-acectf-2025</guid><description>WebCrypto, JWT forgery in Token of Trust, an S3 bucket misconfiguration, plus reversing and XOR keystream reuse crypto.</description></item><item><title>Car hacking demonstrator</title><link>https://maajix.github.io/posts/demonstrator/v1/</link><pubDate>Fri, 21 Feb 2025 00:00:00 +0000</pubDate><category>project</category><guid isPermaLink="false">https://maajix.github.io/news/#2025-02-21-car-hacking-demonstrator</guid><description>Emulating real CAN bus communication to train automotive attack and defense hands-on.</description></item><item><title>1337UP CTF 2024</title><link>https://maajix.github.io/ctfs/1337up-2024/</link><pubDate>Sat, 16 Nov 2024 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2024-11-16-1337up-ctf-2024</guid><description>Solving Cold Storage by unwinding the XOR and RSA layers protecting the key, plus the OSINT challenges.</description></item><item><title>Glacier CTF 2024</title><link>https://maajix.github.io/ctfs/glacier-2024/</link><pubDate>Wed, 23 Oct 2024 00:00:00 +0000</pubDate><category>ctf</category><guid isPermaLink="false">https://maajix.github.io/news/#2024-10-23-glacier-ctf-2024</guid><description>Using peepdf to inspect PDF object streams and recover a PNG image embedded inside the document.</description></item></channel></rss>