Hiring Security Engineers/ Pen Testers at all levels for Security Innovation, apply below :)
https://ift.tt/34IO7Go
Submitted June 03, 2021 at 03:22AM by cheycat306
via reddit https://ift.tt/34O065v
https://ift.tt/34IO7Go
Submitted June 03, 2021 at 03:22AM by cheycat306
via reddit https://ift.tt/34O065v
Pinpointhq
Us Courts Penetration Tester
Job Opening: Us Courts Penetration Tester at Security Innovation in Seattle .
Why We Hash Passwords
https://ift.tt/3idsENO
Submitted June 03, 2021 at 06:23AM by dennisbyrne
via reddit https://ift.tt/2SQe707
https://ift.tt/3idsENO
Submitted June 03, 2021 at 06:23AM by dennisbyrne
via reddit https://ift.tt/2SQe707
dzone.com
Why We Hash Passwords - DZone Security
Learn about password hashing, salting, and key derivation functions in Python.
UI Security - Thinking Outside the Viewport
https://ift.tt/3vJVoBH
Submitted June 03, 2021 at 01:11PM by albinowax
via reddit https://ift.tt/3yY4sF4
https://ift.tt/3vJVoBH
Submitted June 03, 2021 at 01:11PM by albinowax
via reddit https://ift.tt/3yY4sF4
Microsoft Browser Vulnerability Research
UI Security - Thinking Outside the Viewport
Introduction
More macOS Installer Flaws
https://ift.tt/3fZchBG
Submitted June 03, 2021 at 06:33PM by dinobyt3s
via reddit https://ift.tt/3z862EL
https://ift.tt/3fZchBG
Submitted June 03, 2021 at 06:33PM by dinobyt3s
via reddit https://ift.tt/3z862EL
Medium
More macOS Installer Flaws
Unexpected “Expected” Behavior
WebLogic RCE Leads to XMRig
https://ift.tt/3x7X2xB
Submitted June 03, 2021 at 08:37PM by TheDFIRReport
via reddit https://ift.tt/3uIwNff
https://ift.tt/3x7X2xB
Submitted June 03, 2021 at 08:37PM by TheDFIRReport
via reddit https://ift.tt/3uIwNff
The DFIR Report
WebLogic RCE Leads to XMRig
This report will review an intrusion where the threat actor took advantage of a WebLogic remote code execution vulnerability (CVE-2020–14882) to gain initial access to the system before installing a coin miner (XMRig).
Automatically deploy only relevant security updates for Linux CentOS using Errata plugin from Vulners
https://ift.tt/2SVVJTy
Submitted June 03, 2021 at 09:30PM by redsailor
via reddit https://ift.tt/3pjoXb1
https://ift.tt/2SVVJTy
Submitted June 03, 2021 at 09:30PM by redsailor
via reddit https://ift.tt/3pjoXb1
Vulners
Free CentOS errata from Vulners – Vulners Blog
OSX/Hydromac: A new macOS malware leaked from a Flashcards app
https://ift.tt/2S6yki5
Submitted June 03, 2021 at 11:39PM by lordx64
via reddit https://ift.tt/3cdEtQi
https://ift.tt/2S6yki5
Submitted June 03, 2021 at 11:39PM by lordx64
via reddit https://ift.tt/3cdEtQi
Medium
OSX/Hydromac: A new macOS malware leaked from a Flashcards app
At @ConfiantIntel we had some “luck” finding a new malware targeting the new Apple flagship M1 computers. I put “luck” between quotes, as…
Open source CIS Benchmark scan for Zoom security and compliance
https://ift.tt/3wRUF1y
Submitted June 03, 2021 at 11:46PM by CloudSpout
via reddit https://ift.tt/3uObedo
https://ift.tt/3wRUF1y
Submitted June 03, 2021 at 11:46PM by CloudSpout
via reddit https://ift.tt/3uObedo
GitHub
GitHub - turbot/steampipe-mod-zoom-compliance: Run individual configuration, compliance and security controls or full compliance…
Run individual configuration, compliance and security controls or full compliance benchmarks for CIS for Zoom. - GitHub - turbot/steampipe-mod-zoom-compliance: Run individual configuration, complia...
Easy Hypervisor Heap Visualization with PyPANDA and HeapInspect
https://ift.tt/3vRJzcL
Submitted June 04, 2021 at 07:17AM by lacraig2
via reddit https://ift.tt/3yUSFHP
https://ift.tt/3vRJzcL
Submitted June 04, 2021 at 07:17AM by lacraig2
via reddit https://ift.tt/3yUSFHP
reddit
Easy Hypervisor Heap Visualization with PyPANDA and HeapInspect
Posted in r/netsec by u/lacraig2 • 16 points and 0 comments
XSS in the AWS Console
https://ift.tt/34Iby2G
Submitted June 04, 2021 at 12:52AM by RedTermSession
via reddit https://ift.tt/3z4V0A6
https://ift.tt/34Iby2G
Submitted June 04, 2021 at 12:52AM by RedTermSession
via reddit https://ift.tt/3z4V0A6
Frichetten
XSS in the AWS Console
Writeup for a cross-site noscripting bug I found in the AWS Console.
ASP.NET Cryptography for Pentesters
https://ift.tt/3cgfoo6
Submitted June 04, 2021 at 02:28AM by L1QU1DF1R3
via reddit https://ift.tt/34L7XRx
https://ift.tt/3cgfoo6
Submitted June 04, 2021 at 02:28AM by L1QU1DF1R3
via reddit https://ift.tt/34L7XRx
Paul Mueller (@paulmmueller)
ASP.NET Cryptography for Pentesters
If you are coming back, and just here for the cheatsheet, you can find that here. If it’s your first time, hopefully you’ll read through the whole thing. Note: For my own sanity, I have inten…
Froala Editor Version 3.2.6 - High-Risk XSS Bug
https://ift.tt/2TB9rLH
Submitted June 02, 2021 at 09:55PM by breach_house
via reddit https://ift.tt/3wXcjBe
https://ift.tt/2TB9rLH
Submitted June 02, 2021 at 09:55PM by breach_house
via reddit https://ift.tt/3wXcjBe
Bishopfox
Froala Editor Version 3.2.6
One high risk XSS vulnerability was identified within the Froala application.
Honeypot Journals: Credential Attacks and Lessons from Recent Honeynet Incursions
https://ift.tt/3g8mRGV
Submitted June 02, 2021 at 09:55PM by kernelv0id
via reddit https://ift.tt/3uL2lRH
https://ift.tt/3g8mRGV
Submitted June 02, 2021 at 09:55PM by kernelv0id
via reddit https://ift.tt/3uL2lRH
CUJO AI
Honeypot Journals: Credential Attacks and Lessons from Recent Honeynet Incursions
This is a write-up of the recent trends in credential stuffing attacks that the CUJO AI Labs detected in our honeypots. Find out what password brute-force techniques and tools attackers are using in 2021.
SSRF Cheat Sheet & Bypass Techniques
https://ift.tt/34Oinjb
Submitted June 04, 2021 at 02:39PM by HighOnCoffee
via reddit https://ift.tt/3wZmRzs
https://ift.tt/34Oinjb
Submitted June 04, 2021 at 02:39PM by HighOnCoffee
via reddit https://ift.tt/3wZmRzs
highon.coffee
SSRF Cheat Sheet & Bypass Techniques
SSRF explained and the techniques to indentify, and bypass server side SSRF filtering.
iOS User Enrollment and Trusted Certificates - or how BYOD can lead to certificates being trusted by your personal apps..
https://ift.tt/3z23urA
Submitted June 05, 2021 at 12:02AM by digicat
via reddit https://ift.tt/3x3xzW1
https://ift.tt/3z23urA
Submitted June 05, 2021 at 12:02AM by digicat
via reddit https://ift.tt/3x3xzW1
NCC Group Research
iOS User Enrollment and Trusted Certificates
The User Enrollment MDM option added with iOS 13 does not restrict MDM-deployed certificates to MDM-deployed applications, and in the absence of additional controls such as certificate pinning these certificates are, surprisingly, trusted by personally installed…
QNAP Q’center Post-Auth Remote Code Execution via QPKG
https://ift.tt/3ijq6h6
Submitted June 04, 2021 at 11:54PM by smaury
via reddit https://ift.tt/34PqlsA
https://ift.tt/3ijq6h6
Submitted June 04, 2021 at 11:54PM by smaury
via reddit https://ift.tt/34PqlsA
Shielder
Shielder - QNAP Q'center Post-Auth Remote Code Execution via QPKG
A privileged user can obtain remote code execution on Q'center through a manipulated QPKG installation package.
Kubernetes Goat - Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security
https://ift.tt/2C3v66v
Submitted June 05, 2021 at 04:56AM by madhuakula
via reddit https://ift.tt/3cha7MO
https://ift.tt/2C3v66v
Submitted June 05, 2021 at 04:56AM by madhuakula
via reddit https://ift.tt/3cha7MO
GitHub
GitHub - madhuakula/kubernetes-goat: Kubernetes Goat 🐐 is a "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally…
Kubernetes Goat 🐐 is a "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security 🔐 - Git...
An In-memory Embedding of CPython with SCYTHE
https://ift.tt/3gaDfqi
Submitted June 05, 2021 at 11:23AM by 0xdea
via reddit https://ift.tt/3fTogSF
https://ift.tt/3gaDfqi
Submitted June 05, 2021 at 11:23AM by 0xdea
via reddit https://ift.tt/3fTogSF
www.scythe.io
SCYTHE Library: An In-memory Embedding of CPython with SCYTHE
In this blog we discuss a project we are open sourcing: An In-memory Embedding of CPython. We provide a brief overview of this research and also share our results with the community. A paper [1] on this research was accepted in the USENIX Workshop on Offensive…
Dynamic payload generation with mingw
https://ift.tt/3powTHT
Submitted June 05, 2021 at 08:23PM by cysboy
via reddit https://ift.tt/3pmH6ot
https://ift.tt/3powTHT
Submitted June 05, 2021 at 08:23PM by cysboy
via reddit https://ift.tt/3pmH6ot
hashlookup.circl.lu - public ReST API to lookup hash values against known database of files (NSRL NDS)
https://ift.tt/3vZqaXm
Submitted June 06, 2021 at 02:24AM by adulau
via reddit https://ift.tt/3g96SIE
https://ift.tt/3vZqaXm
Submitted June 06, 2021 at 02:24AM by adulau
via reddit https://ift.tt/3g96SIE
reddit
hashlookup.circl.lu - public ReST API to lookup hash values...
Posted in r/netsec by u/adulau • 2 points and 0 comments
Password Managers.
https://ift.tt/3ikGrST
Submitted June 06, 2021 at 10:06AM by ScottContini
via reddit https://ift.tt/3uQpMt7
https://ift.tt/3ikGrST
Submitted June 06, 2021 at 10:06AM by ScottContini
via reddit https://ift.tt/3uQpMt7
Cmpxchg8B
Password Managers.