Neuigkeiten

Y-Security

Cover Image

Neuigkeiten

Y-Security 
Y-Security
Y-Securityhat einen Beitrag geschrieben.22. Januar
Our security team at Y-Security has identified multiple security vulnerabilities in TIM BPM Suite / TIM FLOW, exposing organizations to high-impact attack vectors such as authorization bypass, privilege escalation, and SQL/HQL injection. These vulnerabilities may lead to critical security consequences, including privilege escalation from an unauthenticated user to an authenticated service user, unauthorized access to password hashes stored using no or weak hashing algorithms, attacks against th...

TIM BPM Suite / TIM FLOW - Multiple Vulnerabilities - Y-Security GmbH

Multiple vulnerabilities affecting the TIM BPM Suite & TIM FLOW software by TIM Solutions GmbH.www.y-security.de
TIM BPM Suite / TIM FLOW - Multiple Vulnerabilities - Y-Security GmbH
Y-Security
Y-Securityhat einen Beitrag geschrieben.24. November 2025
Ticket für den German OWASP Day 2025 inklusive Übernachtung im Konferenzhotel zu verschenken. Vorabendevent: 25.11.2025 ab 18:00 Uhr Konferenz: 26.11.2025 ganztägig Bei Interesse schreibt uns einfach direkt eine E-Mail – first come, first served. Mehr Infos: https://god.owasp.de/2025/ Und wenn ihr bereits ein Ticket habt: Sprecht uns vor Ort an – wir sind mit dem Y-Security Team da und freuen uns auf den Austausch! #OWASP #GOD2025 #GOD

German OWASP Day 2025

god.owasp.de
Y-Security
Y-Securityhat einen Beitrag geschrieben.1. Oktober 2024
Today, we are excited to welcome Max to our team. Max will play a key role in driving the development and improvement of both our existing tools and upcoming innovations. Welcome aboard, Max! We’re excited to have you with us and can’t wait to see the impact you’ll make!
Y-Security
Y-Securityhat einen Beitrag geschrieben.15. August 2024
We have publicly released our internal tool StealthGuardian at Black Hat USA 2024. StealthGuardian is a middleware layer that can be combined with adversary simulation tools to verify the resistance, detection level and behaviour detection of executed actions against defined defence mechanisms. Based upon the results the tool decides if it would be safe to execute the action or let the Red Team know that the action has been detected. The tool has been developed to assist Red Teams during adversa...

StealthGuardian - Automatic TTP Analysis

This August we publicly released StealthGuardian at Black HAT USA 2024 Arsenal.www.y-security.de
StealthGuardian - Automatic TTP Analysis
Y-Security
Y-Securityhat einen Beitrag geschrieben.1. Juli 2024
Wir suchen derzeit zur Unterstützung Werkstudent:innen im Bereich Anwendungsentwicklung. Wenn du Lust auf ein innovatives Unternehmen mit flexiblen Arbeitsmöglichkeiten hast, dann freuen wir uns, von dir zu hören. #Werkstudent #Job #Germany #Business #Development
Posting
Y-Security
Y-Securityhat einen Beitrag geschrieben.17. Juni 2024
Are you taking steps towards a career as an Attack Simulation Specialist? Maybe you already have experience as a Penetration Tester or with platforms like Hack The Box or certifications like OSCP? If so, we would love to talk to you! At Y-Security, we are expanding our team and looking for talented individuals passionate about complex penetration tests and attack simulations. #job hashtag#redteam hashtag#pentest hashtag#security hashtag#germany
Posting
Y-Security
Y-Securityhat einen Beitrag geschrieben.4. Juni 2024
Unser Tool StealthGuardian wurde für die Black Hat ARSENAL USA 2024 Konferenz angenommen. Das Y-Security-Team wird in Las Vegas sein, um zu zeigen wie Red Team Payloads vor Blue Teams geschützt werden können. Interessiere? Weitere Informationen finden sich in den Kommentaren. https://www.y-security.de/news-en/black-hat-usa-2024-de/ #BlackHat #BHUSA #RedTeam #VegasBaby

Y-Security @ Black Hat ARSENAL USA 2024

The Y-Security team will be at the Black Hat ARSENAL USA 2024 on the 7th and 8th of August 2024 in Las Vegas, USA.www.y-security.de
Y-Security @ Black Hat ARSENAL USA 2024
Y-Security
Y-Securityhat einen Beitrag geschrieben.16. April 2024
Our team recently took the challenge of mastering the Red Team Ops I and Red Team Ops II exam offered by Zero-Point Security Ltd. After successful completion, we received both the Red Team Operator and Red Team Lead certifications. We have published a review about both exams in our recent post at https://www.y-security.de/news-en/red-team-ops-i-ii-review/ #RedTeam #RTO #Y #exam #review

Red Team Ops I & II Review

This spring we challenged ourselves by completing both Red Team certifications by Zero Point Security.www.y-security.de
Red Team Ops I & II Review
Y-Security
Y-Securityhat einen Beitrag geschrieben.14. Juni 2023
Check out our blog post by Thore on our Mobile Application Testing service utilizing Apple Silicon. Gain valuable insights into adopting a contemporary approach that leverages modern testing techniques and processes to avoid the hassle of managing multiple iOS jailbreaks. https://www.y-security.de/news-en/mobile-application-testing-on-apple-silicon/ #pentest #mobile #jailbreak #apple #ios #testing #m1 #ysecurity

Mobile Application Testing on Apple Silicon

In this blog post, we will show how to perform Mobile Application Test on Apple Silicon as an alternative to jailbroken iPhones.www.y-security.de
Mobile Application Testing on Apple Silicon
Y-Security
Y-Securityhat einen Beitrag geschrieben.16. Mai 2023
Today we're releasing two CVEs for plugins utilized by Atlassian Jira and Atlassian Confluence. These CVEs relate to stored Cross-Site Scripting vulnerabilities and can be tracked via CVE-2023-30453 and CVE-2023-30452: Reminder for Jira – Cross-Site Scripting (CVE-2023-30453) # https://www.y-security.de/news-en/reminder-for-jira-cross-site-scripting-cve-2023-30453/ EasyMind – Cross-Site Scripting (CVE-2023-30452) # https://www.y-security.de/news-en/easymind-cross-site-scripting-cve-2023-30452/ ...

Reminder for Jira - Cross-Site Scripting (CVE-2023-30453)

The Reminder for Jira plugin is vulnerable to a Cross-Site Scripting vulnerability (CVE-2023-30453) within the reminder overview section.www.y-security.de
Reminder for Jira - Cross-Site Scripting (CVE-2023-30453)