<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Public-Poc on CuraSec</title><link>https://curasec.metacog.co.kr/tags/public-poc/</link><description>Recent content in Public-Poc on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 13 Aug 2026 11:57:16 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/public-poc/index.xml" rel="self" type="application/rss+xml"/><item><title>Attackers exploit critical SharePoint vulnerability using public PoC</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public PoC is live and attackers are already exploiting this critical SharePoint flaw — patch SharePoint on-prem deployments immediately and audit SharePoint ULS and IIS logs for anomalous authentication or anonymous access patterns from the PoC release date forward.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active in-the-wild exploitation means an immediate hunt is warranted — query SIEM for unusual SharePoint authentication events, abnormal REST/SOAP API calls, or unexpected file-access patterns since Rapid7&amp;rsquo;s PoC publication date, and tune alerts on SharePoint edge access.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A critical SharePoint vulnerability with a public PoC and confirmed exploitation warrants confirming on-prem SharePoint exposure with your engineering team and ensuring an emergency patch window is scheduled this week if not already done.&lt;/li>
&lt;/ul></description></item><item><title>Certighost PoC enables AD Certificate Services domain hijack</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-new-certighost-poc-exploit-lets-attackers-hijack-windows-dom/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-new-certighost-poc-exploit-lets-attackers-hijack-windows-dom/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC now exists for a domain-hijack flaw in AD Certificate Services; audit your PKI templates for misconfigured enrollment permissions and apply any available patch or Microsoft-recommended mitigation immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build detections for anomalous certificate enrollment requests and CA template abuse (e.g., unusual Enrollee Supplies Subject flag usage); no confirmed active exploitation reported yet, but PoC availability shortens the runway.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A PoC for a Windows domain-compromise vulnerability is now public; no board-level action needed yet, but monitor for escalation to active exploitation that could affect enterprise AD environments.&lt;/li>
&lt;/ul></description></item><item><title>GitLab RCE PoC Published: Authenticated Users Can Execute Commands as Git</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-researcher-publishes-gitlab-rce-poc-letting-authenticated-us/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-researcher-publishes-gitlab-rce-poc-letting-authenticated-us/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A working public exploit now exists for this six-week-old GitLab flaw; any authenticated user with push access on an unpatched self-managed instance can achieve RCE. Upgrade to the patched version released June 10 immediately and verify no self-managed GitLab instances remain on 18.11.3.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> PoC publication on July 24 makes exploitation imminent; hunt for anomalous Jupyter notebook pushes followed by commit-diff access on self-managed GitLab instances, and look for unexpected git-process child execution in EDR telemetry as of that date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A public exploit for GitLab RCE elevates CI/CD pipeline compromise risk this week; confirm with engineering that all self-managed GitLab instances are on the June 10 patched release before this becomes an active incident requiring notification.&lt;/li>
&lt;/ul></description></item><item><title>FastJSON @JSONType RCE Lab: public exploit bypasses autoType=OFF</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-dinosn-fastjson-jsontype-rce-lab-106/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-dinosn-fastjson-jsontype-rce-lab-106/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public Docker lab with a working one-payload exploit now exists for fastjson 1.2.66–1.2.83; critically, autoType=OFF and parseObject binding are not effective mitigations. Audit your dependency tree for fastjson in this range and upgrade to 1.2.84+ (or fastjson2), treating autoType-disabled deployments as unprotected.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The public exploit lab lowers the bar for threat actors to weaponize this Spring Boot class-loading RCE chain. Build or tune detections for unexpected outbound SSRF from Java application hosts followed by remote class loading activity; the SSRF→defineClass pattern is a distinct behavioral signal to hunt for in proxy and EDR telemetry.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>