Authentication Bypass and Arbitrary File Upload (leading to remote code execution) on Cisco Data Center Network Manager
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/cisco-dcnm-rce.txt
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/cisco-dcnm-rce.txt
Android malware hidden inside VirtualApp sandbox.
#chinese
http://blog.avlsec.com/2019/07/5393/virtualapp%e6%8a%80%e6%9c%af%e5%ba%94%e7%94%a8%e5%8f%8a%e5%ae%89%e5%85%a8%e5%88%86%e6%9e%90%e6%8a%a5%e5%91%8a/
#chinese
http://blog.avlsec.com/2019/07/5393/virtualapp%e6%8a%80%e6%9c%af%e5%ba%94%e7%94%a8%e5%8f%8a%e5%ae%89%e5%85%a8%e5%88%86%e6%9e%90%e6%8a%a5%e5%91%8a/
Mozilla releases Grizzly, a cross-platform browser fuzzing framework designed to allow fuzzer developers to focus solely on writing fuzzers and not worry about the overhead of creating tools and noscripts
https://github.com/MozillaSecurity/grizzly
Supported by Linux, MacOS and Windows are supported
https://github.com/MozillaSecurity/grizzly
Supported by Linux, MacOS and Windows are supported
GitHub
GitHub - MozillaSecurity/grizzly: A cross-platform browser fuzzing framework
A cross-platform browser fuzzing framework. Contribute to MozillaSecurity/grizzly development by creating an account on GitHub.
Forwarded from CTF Community | Hints
module 1- Introduction to WAFs, WAF types and WAF Bypassing.pdf
481.3 KB
Introduction to WAFs, WAF types and WAF Bypassing #Web
Unofficial Telegram App Secretly Loads Infinite Malicious Sites
MobonoGram 2019 app was downloaded more than 100,000 times and performed adfraud clicks.
https://www.symantec.com/blogs/threat-intelligence/unofficial-telegram-app-malicious-sites
MobonoGram 2019 app was downloaded more than 100,000 times and performed adfraud clicks.
https://www.symantec.com/blogs/threat-intelligence/unofficial-telegram-app-malicious-sites
Forwarded from P0SCon
💻 P0SCon2019
Join P0SCon2019 and send your abstract of speech or workshop to be a speaker at P0SCon.
More information:
http://poscon.ir
Deadline:
11 Sep 2019
Conference Date:
12 Oct 2019
Urmia University of Technology
Join P0SCon2019 and send your abstract of speech or workshop to be a speaker at P0SCon.
More information:
http://poscon.ir
Deadline:
11 Sep 2019
Conference Date:
12 Oct 2019
Urmia University of Technology
Researchers Claim They Bypassed Cylance's AI-Based Antivirus
Researchers at Australia-based cybersecurity firm Skylight claim to have found a way to trick Cylance’s AI-based antivirus engine into classifying malicious files as benign.
Cylance, which last year was acquired by BlackBerry and is now called BlackBerry Cylance, told SecurityWeek it has launched an investigation to determine if the researchers’ findings are valid or if their method works as a result of a misconfiguration of the product.
https://www.securityweek.com/researchers-claim-they-bypassed-cylances-ai-based-antivirus
Researchers at Australia-based cybersecurity firm Skylight claim to have found a way to trick Cylance’s AI-based antivirus engine into classifying malicious files as benign.
Cylance, which last year was acquired by BlackBerry and is now called BlackBerry Cylance, told SecurityWeek it has launched an investigation to determine if the researchers’ findings are valid or if their method works as a result of a misconfiguration of the product.
https://www.securityweek.com/researchers-claim-they-bypassed-cylances-ai-based-antivirus
SecurityWeek
Researchers Claim They Bypassed Cylance’s AI-Based Antivirus
Researchers at Australia-based cybersecurity firm Skylight claim to have found a way to trick Cylance’s AI-based antivirus engine into classifying malicious files as benign.