cy//ective's Avatar

cy//ective

@cyllective

IT Security Services - ๐Ÿ‡จ๐Ÿ‡ญ๐Ÿค–๐Ÿ‘จโ€๐Ÿ’ป https://cyllective.com

82
Followers
8
Following
8
Posts
11.11.2024
Joined
Posts Following

Latest posts by cy//ective @cyllective

Preview
Vulnerabilities in Lenovo Vantage A write-up of CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717

Lenovo released all patches for the #Lenovo #Vantage #vulnerabilities, which we've reported earlier this year.
Our blog now includes the full writeโ€‘ups for CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717.
๐Ÿ”— cyllective.com/blog/posts/l...

11.03.2026 09:48 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
cyAssist - Cybersecurity Without the Overhead We provide the continuous support you need to build a genuine security culture and baseline maturity.

No budget for an internal security team, but too complex for โ€œweโ€™ll just do it on the sideโ€?

๐Ÿ”ด Have you met cyAssist?

โœ… Dedicated cybersecurity experts
โœ… Fairโ€‘play & flexible time mgmt
โœ… Scalable starting from 2h/month
Security without the overhead
๐Ÿ‘‰ cyllective.com/blog/posts/i...

25.02.2026 11:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Two great followโ€‘ups expanding on our CVEโ€‘2025โ€‘13154 writeโ€‘up:
๐Ÿ”น Manuel Kiesel (@rtfmkiesel.bsky.social)- "Roll with Advantage"
๐Ÿ‘‰ mkiesel.ch/posts/lenovo...
๐Ÿ”น Compass Security (@compass-security.com) - "From Folder Deletion to Admin"
๐Ÿ‘‰ blog.compass-security.com/2026/02/from...

13.02.2026 15:23 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
roll with advantage: hacking lenovo vantage | mkiesel.ch A technical deep dive into the lands of Lenovo Vantage and its add-ins, including tooling to help you hunt for vulnerabilities

First research in a while! Here's my brain dump on reverse-engineering and auditing Lenovo Vantage. In total, I found four (4) vulns. Check out the post and my custom tooling if you're interested.

mkiesel.ch/posts/lenovo...

09.02.2026 10:59 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
How To Audit Plugin Ecosystems How we audit plugin ecosystems, using (Nextcloud|ownCloud) as an example

๐Ÿš€ New blog post: How to Audit Plugin Ecosystems ๐Ÿ”ง๐Ÿ”ฅ
Our reusable 4โ€‘step method helped us navigate 600+ Nextcloud/ownCloud plugins & find some vulns.

cyllective.com/blog/posts/h...

#CyberSecurity #AppSec #Nextcloud #ownCloud #infosec #pentest #SAST

03.02.2026 13:12 ๐Ÿ‘ 2 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

The final stage would not have been possible without John Ostrowski from @compass-security.com thanks for the Swiss infosec collaboration! ๐Ÿซ•๐Ÿค

17.01.2026 13:36 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Lenovo Vantage LPE/EoP (CVE-2025-13154) A write-up of CVE-2025-13154, a privilege escalation vulnerability in Lenovo Vantage.

๐Ÿšจ New blog post!

Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance.

cyllective.com/blog/posts/l...

#windows #cve #infosec #pentest

17.01.2026 13:36 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 1
Preview
Vulnerabilities in Cordaware bestinformed A write-up of CVE-2025-0422, CVE-2025-0423, CVE-2025-0424, and CVE-2025-0425

The first CVEs of 2025 are live!๐Ÿšจ
We discovered ~10 vulnerabilities in Cordaware bestinformed, leading to 4 CVEs. They can be chained for an unauthenticated compromise of the server and all connected clients.๐Ÿ‘พ CVE-2025-042{2..5}
cyllective.com/blog/posts/c...

#blogpost #cybersecurity #CVE #infosec

18.02.2025 10:02 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
OAuth Labs: OAuth 2.0 Vulnerabilites Introducing our latest project: the OAuth Labs. A hands-on approach to OAuth 2.0 vulnerabilities

๐Ÿš€ New from cyllective: ๐Ž๐€๐ฎ๐ญ๐ก ๐‹๐š๐›๐ฌ ๐Ÿ”’

๐Ÿ”‘ Master OAuth 2.0 with hands-on Docker-based labs:
- JWT signature flaws
- Open redirect risks
- Claim validation issues

๐Ÿ’ป Devs & pentesters: sharpen your skills!
๐Ÿ‘‰ cyllective.com/blog/posts/o...

#OAuth #Cybersecurity #Training #InfoSec #Security

03.12.2024 14:14 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 2