Sign in

cy//ective

@cyllective.bsky.social
86 followers 8 following 9 posts

IT Security Services - 🇨🇭🤖👨‍💻 cyllective.com

PostsRepliesMedia
cy//ective @cyllective.bsky.social · 01/04/2026
🎉 Our Burp Suite extension Quick-Update-Headers is now in the BApp Store - huge props to @rtfmkiesel.bsky.social! Instantly refresh Cookie, Authorization, + other headers in Repeater/Intruder using the latest values from your Proxy history. No more manual copy/paste ⚡️ Happy hacking!
github.com
GitHub - cyllective/Quick-Update-Headers: This Burp extension lets you quickly update the headers of a request inside a Repeater or Intruder tab to newer headers from the same host using the context m...
This Burp extension lets you quickly update the headers of a request inside a Repeater or Intruder tab to newer headers from the same host using the context menu - cyllective/Quick-Update-Headers
000
cy//ective @cyllective.bsky.social · 11/03/2026
Lenovo released all patches for the #Lenovo #Vantage #vulnerabilities, which we've reported earlier this year. Our blog now includes the full write‑ups for CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717. 🔗 cyllective.com/blog/posts/l...
cyllective.com
Vulnerabilities in Lenovo Vantage
A write-up of CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717
000
cy//ective @cyllective.bsky.social · 25/02/2026
No budget for an internal security team, but too complex for “we’ll just do it on the side”? 🔴 Have you met cyAssist? ✅ Dedicated cybersecurity experts ✅ Fair‑play & flexible time mgmt ✅ Scalable starting from 2h/month Security without the overhead 👉 cyllective.com/blog/posts/i...
cyllective.com
cyAssist - Cybersecurity Without the Overhead
We provide the continuous support you need to build a genuine security culture and baseline maturity.
000
cy//ective @cyllective.bsky.social · 13/02/2026
Two great follow‑ups expanding on our CVE‑2025‑13154 write‑up: 🔹 Manuel Kiesel (@rtfmkiesel.bsky.social)- "Roll with Advantage" 👉 mkiesel.ch/posts/lenovo... 🔹 Compass Security (@compass-security.com) - "From Folder Deletion to Admin" 👉 blog.compass-security.com/2026/02/from...
mkiesel.ch
roll with advantage: hacking lenovo vantage | mkiesel.ch
A technical deep dive into the lands of Lenovo Vantage and its add-ins, including tooling to help you hunt for vulnerabilities
020
cy//ective @cyllective.bsky.social · 03/02/2026
🚀 New blog post: How to Audit Plugin Ecosystems 🔧🔥 Our reusable 4‑step method helped us navigate 600+ Nextcloud/ownCloud plugins & find some vulns. cyllective.com/blog/posts/h... #CyberSecurity #AppSec #Nextcloud #ownCloud #infosec #pentest #SAST
cyllective.com
How To Audit Plugin Ecosystems
How we audit plugin ecosystems, using (Nextcloud|ownCloud) as an example
021
cy//ective @cyllective.bsky.social · 17/01/2026
🚨 New blog post! Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance. cyllective.com/blog/posts/l... #windows #cve #infosec #pentest
cyllective.com
Lenovo Vantage LPE/EoP (CVE-2025-13154)
A write-up of CVE-2025-13154, a privilege escalation vulnerability in Lenovo Vantage.
111
cy//ective @cyllective.bsky.social · 18/02/2025
The first CVEs of 2025 are live!🚨 We discovered ~10 vulnerabilities in Cordaware bestinformed, leading to 4 CVEs. They can be chained for an unauthenticated compromise of the server and all connected clients.👾 CVE-2025-042{2..5} cyllective.com/blog/posts/c... #blogpost #cybersecurity #CVE #infosec
cyllective.com
Vulnerabilities in Cordaware bestinformed
A write-up of CVE-2025-0422, CVE-2025-0423, CVE-2025-0424, and CVE-2025-0425
032
cy//ective @cyllective.bsky.social · 03/12/2024
🚀 New from cyllective: 𝐎𝐀𝐮𝐭𝐡 𝐋𝐚𝐛𝐬 🔒 🔑 Master OAuth 2.0 with hands-on Docker-based labs: - JWT signature flaws - Open redirect risks - Claim validation issues 💻 Devs & pentesters: sharpen your skills! 👉 cyllective.com/blog/posts/o... #OAuth #Cybersecurity #Training #InfoSec #Security
cyllective.com
OAuth Labs: OAuth 2.0 Vulnerabilites
Introducing our latest project: the OAuth Labs. A hands-on approach to OAuth 2.0 vulnerabilities
051