A deep dive into the operations of the LockBit ransomware group
https://ift.tt/3cMhdt5
Submitted June 18, 2021 at 05:02PM by wtfse
via reddit https://ift.tt/3zDPww6
https://ift.tt/3cMhdt5
Submitted June 18, 2021 at 05:02PM by wtfse
via reddit https://ift.tt/3zDPww6
2 Factor Authentication: The Tester’s Edition
https://ift.tt/3gLZ6Ey
Submitted June 18, 2021 at 05:38PM by dipika_singh
via reddit https://ift.tt/2THOA9R
https://ift.tt/3gLZ6Ey
Submitted June 18, 2021 at 05:38PM by dipika_singh
via reddit https://ift.tt/2THOA9R
Testsigma Blog
2 Factor Authentication: The Tester’s Edition
Introduction 2 Factor Authentication is a subset of the multi factor authentication service that we see mainly in FinTech Apps. Some financial technology apps ask the user to enter a password, and MPIN, a TPIN, and finally another OTP based authentication…
Google Docs/Drive feature allows attackers to embed any custom (malicious) web page in an email's body. Attackers are using this trick to bypass email security solutions configured to allow Google Docs/Drive links.
https://ift.tt/2SMxMhz
Submitted June 18, 2021 at 06:41PM by Avanan_Security
via reddit https://ift.tt/3vx0kZW
https://ift.tt/2SMxMhz
Submitted June 18, 2021 at 06:41PM by Avanan_Security
via reddit https://ift.tt/3vx0kZW
Avanan
Attackers Take Advantage of New Google Docs Exploit
Avanan researchers have uncovered an attack that takes advantage of an exploit in Google Docs
Malware prevents its victims from going to illegal download sites
https://ift.tt/2TLpPJS
Submitted June 18, 2021 at 06:35PM by AmerBekic
via reddit https://ift.tt/2S6AM8a
https://ift.tt/2TLpPJS
Submitted June 18, 2021 at 06:35PM by AmerBekic
via reddit https://ift.tt/2S6AM8a
SwaCash | Internet Marketing News
Malware prevents its victims from going to illegal download sites
© Pirate Bay In a report, SophosLab said it learned of the existence of malware intended to prevent its victims from downloading illegally. Active between October 2020 and January 2021, this malwar…
Spear-phishing campaign tricks users to transfer money (TTPs & IOC)
https://ift.tt/2UXxTVq
Submitted June 19, 2021 at 01:11AM by FeelingFineRightNow
via reddit https://ift.tt/35xsA49
https://ift.tt/2UXxTVq
Submitted June 19, 2021 at 01:11AM by FeelingFineRightNow
via reddit https://ift.tt/35xsA49
blog.redteam.pl
Spear-phishing campaign tricks users to transfer money (TTPs & IOC)
red team, blue team, penetration testing, red teaming, threat hunting, digital forensics, incident response, cyber security, IT security
New Klingon RAT, Written in GO, Holding on for Dear Life
https://ift.tt/3gFbqYz
Submitted June 19, 2021 at 06:18PM by Milafasents
via reddit https://ift.tt/3iS7W6w
https://ift.tt/3gFbqYz
Submitted June 19, 2021 at 06:18PM by Milafasents
via reddit https://ift.tt/3iS7W6w
Intezer
Intezer - Klingon RAT Holding on for Dear Life
Technical analysis of an Antivirus killer RAT containing several methods of persistence and privilege escalation.
How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It
https://ift.tt/35z9GtE
Submitted June 20, 2021 at 12:07AM by laxmanmuthiyah
via reddit https://ift.tt/3wHdgO1
https://ift.tt/35z9GtE
Submitted June 20, 2021 at 12:07AM by laxmanmuthiyah
via reddit https://ift.tt/3wHdgO1
The Zero Hack
How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It - The Zero Hack
This article is about how I found a vulnerability on Apple forgot password endpoint that allowed me to takeover an iCloud account. The vulnerability is completely patched by Apple security team and it no longer works. Apple Security Team rewarded me $18,000…
Sale out your old cars and buy new one ,
https://ift.tt/3vIJ04j
Submitted June 20, 2021 at 03:01AM by faheemiqbal90
via reddit https://ift.tt/3cWKW2C
https://ift.tt/3vIJ04j
Submitted June 20, 2021 at 03:01AM by faheemiqbal90
via reddit https://ift.tt/3cWKW2C
Gari.PK
Used Vehicles for sale in Rawalpindi
Used Vehicles for sale in Rawalpindi 2021. Search good condition, cheap, discounted, well maintained, second hand vehicles for sale in Rawalpindi. Largest stock of genuine used vehicles trucks, buses, tractors, vans, riksha in Pakistan 2021 at Gari.pk.
Quick Analysis for the SSID Format String Bug
https://ift.tt/3zF0qSv
Submitted June 20, 2021 at 04:56PM by 0xdea
via reddit https://ift.tt/3wKBib0
https://ift.tt/3zF0qSv
Submitted June 20, 2021 at 04:56PM by 0xdea
via reddit https://ift.tt/3wKBib0
CodeColorist
Quick Analysis for the SSID Format String Bug
Days ago a twitter post revealed a bug in iOS Wi-Fi service:
Hidden parameters discovery suite - x8 v2.0.0
https://ift.tt/3vIKYBI
Submitted June 20, 2021 at 04:50PM by sh1yo_
via reddit https://ift.tt/2SELp2B
https://ift.tt/3vIKYBI
Submitted June 20, 2021 at 04:50PM by sh1yo_
via reddit https://ift.tt/2SELp2B
GitHub
Sh1Yo/x8
Hidden parameters discovery suite. Contribute to Sh1Yo/x8 development by creating an account on GitHub.
The weekly Console email just went out! This week we had an interview with Liam Galvin, the developer of Traitor, the automatic privilege escalation tool (as well as many many others)! I thought /r/netsec might be interested in checking it out! :)
https://ift.tt/35BK53l
Submitted June 20, 2021 at 09:12PM by binaryfor
via reddit https://ift.tt/3iUhBcM
https://ift.tt/35BK53l
Submitted June 20, 2021 at 09:12PM by binaryfor
via reddit https://ift.tt/3iUhBcM
Substack
The Economist, Traitor, and Serenity
An Introduction to Automating Open Source Intelligence Using SpiderFoot
https://ift.tt/3vJ2upx
Submitted June 20, 2021 at 10:34PM by Churppy
via reddit https://ift.tt/2TQ8Upg
https://ift.tt/3vJ2upx
Submitted June 20, 2021 at 10:34PM by Churppy
via reddit https://ift.tt/2TQ8Upg
Rogue Security
An Introduction to Automating Open Source Intelligence Using SpiderFoot
What Is OSINT? Open Source Intelligence (OSINT) is a methodology for collecting, analyzing, and decision-making using publicly available sources of data. According the Wikipedia, OSINT sources can …
Firewalls Gold vs Ubiquiti Dream Machine Pro
http://firewalla.com
Submitted June 21, 2021 at 12:09AM by Jsharp5680
via reddit https://ift.tt/3zIg3bK
http://firewalla.com
Submitted June 21, 2021 at 12:09AM by Jsharp5680
via reddit https://ift.tt/3zIg3bK
Firewalla
Firewalla: Cybersecurity Firewall For Your Family and Business
Firewalla is an all-in-one intelligent Firewall that connects to your router and secures all of your digital things. It can protect your family and business from cyber threats, block ads, control kids' internet usage, and even protects you when you are out…
Why mimicking a device is becoming almost impossible - Multilogin
https://ift.tt/3qfhWbv
Submitted June 21, 2021 at 03:12AM by ziyahanalbeniz
via reddit https://ift.tt/2SMPWzT
https://ift.tt/3qfhWbv
Submitted June 21, 2021 at 03:12AM by ziyahanalbeniz
via reddit https://ift.tt/2SMPWzT
Certified Red Team Professional (CRTP) Reflections
https://ift.tt/3gIcOd9
Submitted June 21, 2021 at 08:55AM by debifrank
via reddit https://ift.tt/3zFUokC
https://ift.tt/3gIcOd9
Submitted June 21, 2021 at 08:55AM by debifrank
via reddit https://ift.tt/3zFUokC
Medium
CRTP Reflections
Pentester Academy’s Beginner AD Bootcamp and CRTP examination experience
"Sloth - Tool to Fuzz Android Native libraries with libFuzzer + QEMU" blogpost by @ant4g0nist
https://ift.tt/2SPWE87
Submitted June 21, 2021 at 12:00PM by ant4g0nist
via reddit https://ift.tt/3xHAsMx
https://ift.tt/2SPWE87
Submitted June 21, 2021 at 12:00PM by ant4g0nist
via reddit https://ift.tt/3xHAsMx
Fuzzing Science
Fuzzing Android Native libraries with libFuzzer + QEMU
Fuzzing Android Native libraries with libFuzzer + QEMU 🦥 TL;DR In this blog post, I will go through the process of why and how I built a new framework called Sloth 🦥, using which, I was able to fuzz …
Knock! Knock! The postman is here! (abusing Mailslots and PortKnocking for connectionless shells)
https://ift.tt/2ShKeG2
Submitted June 21, 2021 at 12:57PM by gid0rah
via reddit https://ift.tt/3iXsef6
https://ift.tt/2ShKeG2
Submitted June 21, 2021 at 12:57PM by gid0rah
via reddit https://ift.tt/3iXsef6
reddit
Knock! Knock! The postman is here! (abusing Mailslots and...
Posted in r/netsec by u/gid0rah • 21 points and 0 comments
Phant0m | Windows Event Log Killer
https://ift.tt/2SNovpC
Submitted June 21, 2021 at 12:49PM by hlldz
via reddit https://ift.tt/3xGElBl
https://ift.tt/2SNovpC
Submitted June 21, 2021 at 12:49PM by hlldz
via reddit https://ift.tt/3xGElBl
GitHub
GitHub - hlldz/Phant0m: Windows Event Log Killer
Windows Event Log Killer. Contribute to hlldz/Phant0m development by creating an account on GitHub.
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
https://ift.tt/35DJduU
Submitted June 21, 2021 at 08:31PM by toyojuni
via reddit https://ift.tt/35Dk1ot
https://ift.tt/35DJduU
Submitted June 21, 2021 at 08:31PM by toyojuni
via reddit https://ift.tt/35Dk1ot
Medium
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
The Fault in Our Stars - Security Implications of AWS API Gateway Lambda Authorizers and IAM Wildcard Expansion
https://ift.tt/3qfSin6
Submitted June 22, 2021 at 08:39AM by Felipe-Pr0teus
via reddit https://ift.tt/3xLmklr
https://ift.tt/3qfSin6
Submitted June 22, 2021 at 08:39AM by Felipe-Pr0teus
via reddit https://ift.tt/3xLmklr
Linux marketplaces vulnerable to RCE and supply chain attacks
https://ift.tt/3xBox2y
Submitted June 22, 2021 at 07:27PM by breakingsystems
via reddit https://ift.tt/3wPE2nJ
https://ift.tt/3xBox2y
Submitted June 22, 2021 at 07:27PM by breakingsystems
via reddit https://ift.tt/3wPE2nJ
positive.security
Linux marketplaces vulnerable to RCE and supply chain attacks | Positive Security
We're disclosing patched vulnerabilities in KDE Discover and the Gnome Shell Extensions website, as well as unpatched vulnerabilities in the PlingStore app and Pling-based Linux marketplace websites (e.g. appimagehub.com, store.kde.org, gnome-look.org).