Automatically deploy only relevant security updates for Linux CentOS using Errata plugin from Vulners
https://ift.tt/2SVVJTy
Submitted June 03, 2021 at 09:30PM by redsailor
via reddit https://ift.tt/3pjoXb1
https://ift.tt/2SVVJTy
Submitted June 03, 2021 at 09:30PM by redsailor
via reddit https://ift.tt/3pjoXb1
Vulners
Free CentOS errata from Vulners – Vulners Blog
OSX/Hydromac: A new macOS malware leaked from a Flashcards app
https://ift.tt/2S6yki5
Submitted June 03, 2021 at 11:39PM by lordx64
via reddit https://ift.tt/3cdEtQi
https://ift.tt/2S6yki5
Submitted June 03, 2021 at 11:39PM by lordx64
via reddit https://ift.tt/3cdEtQi
Medium
OSX/Hydromac: A new macOS malware leaked from a Flashcards app
At @ConfiantIntel we had some “luck” finding a new malware targeting the new Apple flagship M1 computers. I put “luck” between quotes, as…
Open source CIS Benchmark scan for Zoom security and compliance
https://ift.tt/3wRUF1y
Submitted June 03, 2021 at 11:46PM by CloudSpout
via reddit https://ift.tt/3uObedo
https://ift.tt/3wRUF1y
Submitted June 03, 2021 at 11:46PM by CloudSpout
via reddit https://ift.tt/3uObedo
GitHub
GitHub - turbot/steampipe-mod-zoom-compliance: Run individual configuration, compliance and security controls or full compliance…
Run individual configuration, compliance and security controls or full compliance benchmarks for CIS for Zoom. - GitHub - turbot/steampipe-mod-zoom-compliance: Run individual configuration, complia...
Easy Hypervisor Heap Visualization with PyPANDA and HeapInspect
https://ift.tt/3vRJzcL
Submitted June 04, 2021 at 07:17AM by lacraig2
via reddit https://ift.tt/3yUSFHP
https://ift.tt/3vRJzcL
Submitted June 04, 2021 at 07:17AM by lacraig2
via reddit https://ift.tt/3yUSFHP
reddit
Easy Hypervisor Heap Visualization with PyPANDA and HeapInspect
Posted in r/netsec by u/lacraig2 • 16 points and 0 comments
XSS in the AWS Console
https://ift.tt/34Iby2G
Submitted June 04, 2021 at 12:52AM by RedTermSession
via reddit https://ift.tt/3z4V0A6
https://ift.tt/34Iby2G
Submitted June 04, 2021 at 12:52AM by RedTermSession
via reddit https://ift.tt/3z4V0A6
Frichetten
XSS in the AWS Console
Writeup for a cross-site noscripting bug I found in the AWS Console.
ASP.NET Cryptography for Pentesters
https://ift.tt/3cgfoo6
Submitted June 04, 2021 at 02:28AM by L1QU1DF1R3
via reddit https://ift.tt/34L7XRx
https://ift.tt/3cgfoo6
Submitted June 04, 2021 at 02:28AM by L1QU1DF1R3
via reddit https://ift.tt/34L7XRx
Paul Mueller (@paulmmueller)
ASP.NET Cryptography for Pentesters
If you are coming back, and just here for the cheatsheet, you can find that here. If it’s your first time, hopefully you’ll read through the whole thing. Note: For my own sanity, I have inten…
Froala Editor Version 3.2.6 - High-Risk XSS Bug
https://ift.tt/2TB9rLH
Submitted June 02, 2021 at 09:55PM by breach_house
via reddit https://ift.tt/3wXcjBe
https://ift.tt/2TB9rLH
Submitted June 02, 2021 at 09:55PM by breach_house
via reddit https://ift.tt/3wXcjBe
Bishopfox
Froala Editor Version 3.2.6
One high risk XSS vulnerability was identified within the Froala application.
Honeypot Journals: Credential Attacks and Lessons from Recent Honeynet Incursions
https://ift.tt/3g8mRGV
Submitted June 02, 2021 at 09:55PM by kernelv0id
via reddit https://ift.tt/3uL2lRH
https://ift.tt/3g8mRGV
Submitted June 02, 2021 at 09:55PM by kernelv0id
via reddit https://ift.tt/3uL2lRH
CUJO AI
Honeypot Journals: Credential Attacks and Lessons from Recent Honeynet Incursions
This is a write-up of the recent trends in credential stuffing attacks that the CUJO AI Labs detected in our honeypots. Find out what password brute-force techniques and tools attackers are using in 2021.
SSRF Cheat Sheet & Bypass Techniques
https://ift.tt/34Oinjb
Submitted June 04, 2021 at 02:39PM by HighOnCoffee
via reddit https://ift.tt/3wZmRzs
https://ift.tt/34Oinjb
Submitted June 04, 2021 at 02:39PM by HighOnCoffee
via reddit https://ift.tt/3wZmRzs
highon.coffee
SSRF Cheat Sheet & Bypass Techniques
SSRF explained and the techniques to indentify, and bypass server side SSRF filtering.
iOS User Enrollment and Trusted Certificates - or how BYOD can lead to certificates being trusted by your personal apps..
https://ift.tt/3z23urA
Submitted June 05, 2021 at 12:02AM by digicat
via reddit https://ift.tt/3x3xzW1
https://ift.tt/3z23urA
Submitted June 05, 2021 at 12:02AM by digicat
via reddit https://ift.tt/3x3xzW1
NCC Group Research
iOS User Enrollment and Trusted Certificates
The User Enrollment MDM option added with iOS 13 does not restrict MDM-deployed certificates to MDM-deployed applications, and in the absence of additional controls such as certificate pinning these certificates are, surprisingly, trusted by personally installed…
QNAP Q’center Post-Auth Remote Code Execution via QPKG
https://ift.tt/3ijq6h6
Submitted June 04, 2021 at 11:54PM by smaury
via reddit https://ift.tt/34PqlsA
https://ift.tt/3ijq6h6
Submitted June 04, 2021 at 11:54PM by smaury
via reddit https://ift.tt/34PqlsA
Shielder
Shielder - QNAP Q'center Post-Auth Remote Code Execution via QPKG
A privileged user can obtain remote code execution on Q'center through a manipulated QPKG installation package.
Kubernetes Goat - Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security
https://ift.tt/2C3v66v
Submitted June 05, 2021 at 04:56AM by madhuakula
via reddit https://ift.tt/3cha7MO
https://ift.tt/2C3v66v
Submitted June 05, 2021 at 04:56AM by madhuakula
via reddit https://ift.tt/3cha7MO
GitHub
GitHub - madhuakula/kubernetes-goat: Kubernetes Goat 🐐 is a "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally…
Kubernetes Goat 🐐 is a "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security 🔐 - Git...
An In-memory Embedding of CPython with SCYTHE
https://ift.tt/3gaDfqi
Submitted June 05, 2021 at 11:23AM by 0xdea
via reddit https://ift.tt/3fTogSF
https://ift.tt/3gaDfqi
Submitted June 05, 2021 at 11:23AM by 0xdea
via reddit https://ift.tt/3fTogSF
www.scythe.io
SCYTHE Library: An In-memory Embedding of CPython with SCYTHE
In this blog we discuss a project we are open sourcing: An In-memory Embedding of CPython. We provide a brief overview of this research and also share our results with the community. A paper [1] on this research was accepted in the USENIX Workshop on Offensive…
Dynamic payload generation with mingw
https://ift.tt/3powTHT
Submitted June 05, 2021 at 08:23PM by cysboy
via reddit https://ift.tt/3pmH6ot
https://ift.tt/3powTHT
Submitted June 05, 2021 at 08:23PM by cysboy
via reddit https://ift.tt/3pmH6ot
hashlookup.circl.lu - public ReST API to lookup hash values against known database of files (NSRL NDS)
https://ift.tt/3vZqaXm
Submitted June 06, 2021 at 02:24AM by adulau
via reddit https://ift.tt/3g96SIE
https://ift.tt/3vZqaXm
Submitted June 06, 2021 at 02:24AM by adulau
via reddit https://ift.tt/3g96SIE
reddit
hashlookup.circl.lu - public ReST API to lookup hash values...
Posted in r/netsec by u/adulau • 2 points and 0 comments
Password Managers.
https://ift.tt/3ikGrST
Submitted June 06, 2021 at 10:06AM by ScottContini
via reddit https://ift.tt/3uQpMt7
https://ift.tt/3ikGrST
Submitted June 06, 2021 at 10:06AM by ScottContini
via reddit https://ift.tt/3uQpMt7
Cmpxchg8B
Password Managers.
Detecting Brightdata's (formerly Luminati Networks) Data Collector as a Bot
https://ift.tt/3ga7nCg
Submitted June 06, 2021 at 06:22PM by incolumitas
via reddit https://ift.tt/3fVVZL9
https://ift.tt/3ga7nCg
Submitted June 06, 2021 at 06:22PM by incolumitas
via reddit https://ift.tt/3fVVZL9
incolumitas.com
Detecting Brightdata's (formerly Luminati Networks) Data Collector as a Bot
In this blog article I demonstrate several bullet-proof ways how to detect Brightdata Data Collector as a bot without any doubt.
Volatile Memory Forensic Analysis: jackcr difr challenge
https://ift.tt/34S0q3l
Submitted June 06, 2021 at 08:54PM by thatmemforensicsguy
via reddit https://ift.tt/3v31igo
https://ift.tt/34S0q3l
Submitted June 06, 2021 at 08:54PM by thatmemforensicsguy
via reddit https://ift.tt/3v31igo
Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS - Skills that matter
Forensic Analysis: jackcr difr challenge - Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS
After completing Cridex Malware analysis decided to take up jackcr difr challenge for further learning . I will continue to use Volatility Open Source Framework for this analysis .Also, you can read, Cridex Malware analysis here Challenge The challenge consist…
reqstress - a benchmarking&stressing tool that can send raw HTTP requests
https://ift.tt/3inIRAa
Submitted June 06, 2021 at 11:16PM by utku1337
via reddit https://ift.tt/3cmwJvD
https://ift.tt/3inIRAa
Submitted June 06, 2021 at 11:16PM by utku1337
via reddit https://ift.tt/3cmwJvD
GitHub
utkusen/reqstress
a benchmarking&stressing tool that can send raw HTTP requests - utkusen/reqstress
The SaaS CTO Security Checklist Redux
https://ift.tt/2S2isxf
Submitted June 07, 2021 at 03:38AM by vikrum
via reddit https://ift.tt/3uZ7lSO
https://ift.tt/2S2isxf
Submitted June 07, 2021 at 03:38AM by vikrum
via reddit https://ift.tt/3uZ7lSO
Goldfiglabs
The SaaS CTO Security Checklist Redux - Gold Fig — Peace of mind for infrastructure teams
Learn how to protect your SaaS applications with the SaaS CTO security checklist. Doing the basics goes a long way in keeping your company and product secure.
Compromising Joomla by chaining a pass reset vulnerability & stored xss for Privesc
https://ift.tt/3fXE0E2
Submitted June 07, 2021 at 11:59AM by adrian_rt
via reddit https://ift.tt/3w2XXiv
https://ift.tt/3fXE0E2
Submitted June 07, 2021 at 11:59AM by adrian_rt
via reddit https://ift.tt/3w2XXiv
Cyber Security Services - London
Joomla password reset vulnerability and a stored XSS for full compromise - Cyber Security Services - London
Joomla password reset vulnerability and a stored XSS for full compromise. chaining a password reset vulnerability and a XSS for joomla RCE