Ethical Hacking

Flashing Your Lights: CVE-2025-7202

A CSRF vulnerability in Elgato Key Lights let websites flash your lights remotely. Here’s how CVE-2025-7202 was discovered and fixed.

Leaking Secrets with AI: The Hidden Risks of ChatGPT’s Share Feature

Learn how ChatGPT’s ‘Share’ feature can accidentally expose sensitive data to Google. Discover hidden risks and how to protect your AI conversations.

When Metadata Goes Rogue: Lessons from the Tea App Breach

The Tea app breach exposed thousands of user selfies with sensitive location metadata, revealing key lessons on protecting privacy by stripping metadata from uploads.

How a Toreon ski-trip led to a CVE in MikroTik’s Wi-Fi Hotspot

During Toreon’s annual ski trip, Robbe opted out of skiing and hiking to explore the hotel’s Wi-Fi login page for security flaws. While others hit…

Toreon authorized by the CVE as a CVE Numbering Authority

Toreon is now an official CVE Numbering Authority (CNA), enabling formal disclosure of security vulnerabilities. This strengthens Toreon’s leadership in product and AI security, helping…

CVE-2024-28088: How URI Traversal in LangChain Led to API Token Theft and potentially Remote Code Execution

This is the story of how Robbe discovered CVE-2024-28088, a URI traversal vulnerability in LangChain’s configuration loading mechanism that led to full API token leakage,…

How I Discovered vulnerability CVE-2024-2912: Unveiling BentoML Pickle-Based Serialization

This is the story of how I found a remote code execution vulnerability CVE-2024-2912, in BentoML and what it can teach you about securing your…

Examining attack tree tools, how do they compare?

In this article we tackle two Attack Tree tools and comepare them. Are they worth using or not?

7-8/10/21 Toreon @ Brucon

Toreon is once again attending BruCON as a diamond sponsor!

Start typing and press Enter to search

Shopping Cart