RSSAmplifier

Blog

Martin Kubečka

Recent content on Martin Kubečka

martinkubecka.skRSS feed ↗13 posts

Latest posts

Chinese UNC6384 Malware Campaign Exploits Cambodia Thailand Crisis

Diplomatic entities targeted in spearphishing campaign by UNC6384 cyber espionage.

Unsophisticated Phishing Delivering Sophisticated Malware

Deep dive analysis of an opportunistic phishing campaign delivering Katz Stealer and Remcos RAT.

CVE-2025-56683: DOM-based Cross-Site Scripting Leading to Remote Code Execution in Logseq Application

A DOM-based XSS vulnerability in Logseq version 0.10.9 allows Remote Code Execution by injecting malicious JavaScript through unsanitized plugin README content combined with insufficient protocol validation.

CVE-2023-47622: Multiple Reflected Cross-Site Scripting Vulnerabilities in IT Service Management Platform iTop

Reflected XSS vulnerability in multiple query parameters of Combodo iTop’s render endpoint allows JavaScript injection and execution.

About Me

I am a Cybersecurity Analyst with main interest in Cyber Defense, Cyber Threat Intelligence, Open-Source Intelligence Techniques and Social Engineering. I completed my Master’s degree at the Faculty of Electrical Engineering and Information Technology of the Slovak University of Technology in Bratislava, where I pursued Computer Science with a focus on the security of information…

My Latest Reading List

#21 : Evading EDR Subtitle: The Definitive Guide to Defeating Endpoint Detection Systems Author: Matt Hand Publication Date: September, 2023 Length: 312 Pages ISBN: 9781718503342 Publisher: No Starch Press #20 : Intelligence-Driven Incident Response Subtitle: Outwitting the Adversary, 2nd Edition Author: Rebekah Brown, Scott Roberts Publication Date: June, 2023 Length: 316 Pages ISBN:…

Self Hosting News Aggregator

Enhance your digital privacy with self-hosted news aggregator.

CVE-2021-41433: Authentication Bypass in Resumes Management by EGavilan Media

SQL injection vulnerability in EGavilan Media's Resumes Management and Job application allows unauthenticated attackers to bypass login authentication.

CVE-2021-41432: Stored Cross-Site Scripting Vulnerability in the Blog Content in FlatPress

Stored XSS vulnerability in FlatPress 1.2.1 allows arbitrary JavaScript execution via crafted post content.

CVE-2021-41434: Stored Cross-Site Scripting Vulnerability in Expense Management System by EGavilan Media

Stored XSS vulnerability in Expense Management System 1.0 allows arbitrary JavaScript execution via expense description input.

Setting Up Your Own Recursive DNS Server

Learn how to set up your own Recursive DNS Server at home on a Raspberry Pi 4.

CVE-2021-37413: Authentication Bypass in Content Management System Provided by GRANDCOM, s.r.o.

Unauthenticated SQL injection vulnerability in GRANDCOM CMS allows login bypass via crafted username.

Weaponizing Malicious Macros

Learn about crafting and analyzing Microsoft Excel malicious macros.