NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks
https://ift.tt/3cae8m8
Submitted June 07, 2021 at 09:44PM by Cyberthere
via reddit https://ift.tt/2T5f4BR
https://ift.tt/3cae8m8
Submitted June 07, 2021 at 09:44PM by Cyberthere
via reddit https://ift.tt/2T5f4BR
SentinelOne
NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks - SentinelLabs
Nobelium – the new face of APT29 – deploys poisoned installers against Ukrainian government targets in a possible supply chain attack.
New Netcat Alternative Made In Rust
https://ift.tt/3fZRCio
Submitted June 07, 2021 at 03:45AM by robi0t
via reddit https://ift.tt/3pwpR3P
https://ift.tt/3fZRCio
Submitted June 07, 2021 at 03:45AM by robi0t
via reddit https://ift.tt/3pwpR3P
GitHub
robiot/rustcat
⚙️ Netcat Alternative . Contribute to robiot/rustcat development by creating an account on GitHub.
A community-curated Resource for Bug Bounty Hunting to search among thousands of technical infosec write-ups
https://ift.tt/2YIzGPz
Submitted June 07, 2021 at 11:13PM by payloadartist
via reddit https://ift.tt/3zd1b5c
https://ift.tt/2YIzGPz
Submitted June 07, 2021 at 11:13PM by payloadartist
via reddit https://ift.tt/3zd1b5c
Bugbountyhunting
BugBountyHunting.com - A community-curated Resource for Bug Bounty Hunting
BugBountyHunting.com collects writeups, resources and content related to bug bounty hunting to help you access them quickly.
It's goal is to help beginners starting in web application security to learn more about bug bounty hunting.
It's goal is to help beginners starting in web application security to learn more about bug bounty hunting.
Windows Kernel Debugging & Exploitation Part 2 - Stack Overflow
https://ift.tt/3pyhXHb
Submitted June 08, 2021 at 12:29PM by admiralarjun
via reddit https://ift.tt/3fZtjAT
https://ift.tt/3pyhXHb
Submitted June 08, 2021 at 12:29PM by admiralarjun
via reddit https://ift.tt/3fZtjAT
reddit
Windows Kernel Debugging & Exploitation Part 2 - Stack Overflow
Posted in r/netsec by u/admiralarjun • 76 points and 0 comments
Updated Mimikatz in Metasploit to play with recent features like RDP plaintext credential dumping
https://ift.tt/3xaUSgF
Submitted June 07, 2021 at 07:12PM by an0n_r0
via reddit https://ift.tt/3pwLfpF
https://ift.tt/3xaUSgF
Submitted June 07, 2021 at 07:12PM by an0n_r0
via reddit https://ift.tt/3pwLfpF
Medium
Updating Mimikatz in Metasploit
Mimikatz integrated in the current Metasploit Framework is a little bit outdated. If you want to use the recent features (like plaintext…
Qualcomm IPQ40xx: Breaking into QSEE using Fault Injection
https://ift.tt/3iqXvXe
Submitted June 08, 2021 at 02:14PM by tieknimmers
via reddit https://ift.tt/2Sgf4i4
https://ift.tt/3iqXvXe
Submitted June 08, 2021 at 02:14PM by tieknimmers
via reddit https://ift.tt/2Sgf4i4
Raelize
Qualcomm IPQ40xx: Breaking into QSEE using Fault Injection
Raelize company website!
Dockerfile-sec is a simple but powerful rules-based security checker for Dockerfiles
https://ift.tt/3zakoUX
Submitted June 08, 2021 at 03:08PM by cr0hn
via reddit https://ift.tt/2Rw45Rg
https://ift.tt/3zakoUX
Submitted June 08, 2021 at 03:08PM by cr0hn
via reddit https://ift.tt/2Rw45Rg
GitHub
cr0hn/dockerfile-security
Static security checker for Dockerfiles. Contribute to cr0hn/dockerfile-security development by creating an account on GitHub.
Let’s Encrypt Change Affects OpenSSL 1.0.x and CentOS 7
https://ift.tt/3iqug7a
Submitted June 08, 2021 at 02:49PM by ssh-bi
via reddit https://ift.tt/3fZPB5y
https://ift.tt/3iqug7a
Submitted June 08, 2021 at 02:49PM by ssh-bi
via reddit https://ift.tt/3fZPB5y
Medium
Let’s Encrypt change affects OpenSSL 1.0.x and CentOS 7
Default certificate chain to include an expired root certificate
How to: Find WordPress Plugin Vulnerabilities Free eBooK
https://ift.tt/3g2vcgs
Submitted June 08, 2021 at 04:43PM by ethicalhack3r
via reddit https://ift.tt/3z7yo1I
https://ift.tt/3g2vcgs
Submitted June 08, 2021 at 04:43PM by ethicalhack3r
via reddit https://ift.tt/3z7yo1I
NoSql Injection Cheatsheet
https://ift.tt/3g2qdfx
Submitted June 08, 2021 at 05:57PM by Charlie-B
via reddit https://ift.tt/353qrN2
https://ift.tt/3g2qdfx
Submitted June 08, 2021 at 05:57PM by Charlie-B
via reddit https://ift.tt/353qrN2
Null Sweep
NoSql Injection Cheatsheet
Learn how NoSQL Injection works, with example strings to inject to test for injections.
How much security gain do you get by implementing a NAC solution? The answers might suprise you.
https://ift.tt/3gh22sS
Submitted June 08, 2021 at 08:12PM by The-Luemmel
via reddit https://ift.tt/3puuiMM
https://ift.tt/3gh22sS
Submitted June 08, 2021 at 08:12PM by The-Luemmel
via reddit https://ift.tt/3puuiMM
luemmelsec.github.io
I got 99 problems but my NAC ain´t one
This post will be all about Network Access Control (NAC) solutions and how they might lull you into a sense of security.
Designed to keep rouge devices out of your network, I´ll show you ways around it, as well as ways to protect yourself.
From a pentester´s…
Designed to keep rouge devices out of your network, I´ll show you ways around it, as well as ways to protect yourself.
From a pentester´s…
Dead Ends in Cryptanalysis #2: Timing Side-Channels
https://ift.tt/35aCubP
Submitted June 08, 2021 at 07:58PM by Soatok
via reddit https://ift.tt/2T3VxS9
https://ift.tt/35aCubP
Submitted June 08, 2021 at 07:58PM by Soatok
via reddit https://ift.tt/2T3VxS9
Dhole Moments
Dead Ends in Cryptanalysis #2: Timing Side-Channels - Dhole Moments
Previously on Dead Ends in Cryptanalysis, we talked about length-extension attacks and precisely why modern hash functions like SHA-3 and BLAKE2 aren’t susceptible. The art and science of sid…
Your Microsoft Teams chats aren’t as private as you think..
https://ift.tt/3g15XuU
Submitted June 08, 2021 at 09:19PM by infinitelogins
via reddit https://ift.tt/3x7qHqo
https://ift.tt/3g15XuU
Submitted June 08, 2021 at 09:19PM by infinitelogins
via reddit https://ift.tt/3x7qHqo
Infinite Logins
Your Microsoft Teams chats aren’t as private as you think..
Encrypt and Anonymize Your Internet Connection for as Little as $3/mo with PIA VPN. Learn More Microsoft Teams is a proprietary business communication platform developed by Microsoft, as …
Hacker's guide to deep-learning side-channel attacks: code walkthrough
https://ift.tt/3whNgsJ
Submitted June 09, 2021 at 12:11AM by ebursztein
via reddit https://ift.tt/2T8KxTx
https://ift.tt/3whNgsJ
Submitted June 09, 2021 at 12:11AM by ebursztein
via reddit https://ift.tt/2T8KxTx
Elie Bursztein's site
Hacker's guide to deep-learning side-channel attacks: code walkthrough
Learn how to perform a deep-learning side-channels attack using TensorFlow to recover AES cryptographic keys from a hardware device power traces, step by step.
Fuzzing the Office Ecosystem - Check Point Research
https://ift.tt/3g20jZl
Submitted June 09, 2021 at 12:01AM by sagitz_
via reddit https://ift.tt/3gcqSd6
https://ift.tt/3g20jZl
Submitted June 09, 2021 at 12:01AM by sagitz_
via reddit https://ift.tt/3gcqSd6
Check Point Research
Fuzzing the Office Ecosystem - Check Point Research
Research By: Netanel Ben-Simon and Sagi Tzadik Introduction Microsoft Office is a very commonly used software that can be found on almost any standard computer. It is also integrated inside many products of the Microsoft / Windows ecosystem such as Office…
The Walls Have Ears - Compromising a Conference Table Microphone
https://ift.tt/2TTSfkU
Submitted June 09, 2021 at 12:07PM by pocorgtfoftw
via reddit https://ift.tt/3zbgNGf
https://ift.tt/2TTSfkU
Submitted June 09, 2021 at 12:07PM by pocorgtfoftw
via reddit https://ift.tt/3zbgNGf
Grimm-Co
The walls have ears
Introduction Modern business often relies heavily on the Internet and software resources such as Zoom or Skype to support daily operat...
ALPACA Attack
https://ift.tt/2TT9djn
Submitted June 09, 2021 at 06:01PM by shapelez
via reddit https://ift.tt/3w84I2C
https://ift.tt/2TT9djn
Submitted June 09, 2021 at 06:01PM by shapelez
via reddit https://ift.tt/3w84I2C
reddit
ALPACA Attack
Posted in r/netsec by u/shapelez • 21 points and 4 comments
Author spoofing in Google Colaboratory
https://ift.tt/3514BtV
Submitted June 09, 2021 at 06:50PM by zoh4rs
via reddit https://ift.tt/3pB27vC
https://ift.tt/3514BtV
Submitted June 09, 2021 at 06:50PM by zoh4rs
via reddit https://ift.tt/3pB27vC
Big Stages Implementation And Library Files
https://ift.tt/2TgjvJP
Submitted June 09, 2021 at 08:22PM by hlldz
via reddit https://ift.tt/3cMZJNl
https://ift.tt/2TgjvJP
Submitted June 09, 2021 at 08:22PM by hlldz
via reddit https://ift.tt/3cMZJNl
with knowledge comes power
Big Stages Implementation And Library Files
If you have a command & control server running a RAT, you should protect this server from possible detections. This is one of the golden rules for OPSEC. There has been a lot of content shared on this topic lately, and researchers are detecting command &…
Now Available: Impacket Release v0.9.23
https://ift.tt/2RFYubi
Submitted June 09, 2021 at 09:56PM by mgalloar
via reddit https://ift.tt/35aMBNr
https://ift.tt/2RFYubi
Submitted June 09, 2021 at 09:56PM by mgalloar
via reddit https://ift.tt/35aMBNr
On how to access (protected) networks
https://ift.tt/3zdZNz8
Submitted June 09, 2021 at 10:59PM by S3cur3Th1sSh1t
via reddit https://ift.tt/3g5ycsc
https://ift.tt/3zdZNz8
Submitted June 09, 2021 at 10:59PM by S3cur3Th1sSh1t
via reddit https://ift.tt/3g5ycsc
s3cur3th1ssh1t.github.io
On how to access (protected) networks | S3cur3Th1sSh1t
This post is about common misconfigurations and attack szenarios that enable an attacker to access separated networks with critical systems or sensitive data...