Knock! Knock! The postman is here! (abusing Mailslots and PortKnocking for connectionless shells)
https://ift.tt/2ShKeG2
Submitted June 21, 2021 at 12:57PM by gid0rah
via reddit https://ift.tt/3iXsef6
https://ift.tt/2ShKeG2
Submitted June 21, 2021 at 12:57PM by gid0rah
via reddit https://ift.tt/3iXsef6
reddit
Knock! Knock! The postman is here! (abusing Mailslots and...
Posted in r/netsec by u/gid0rah • 21 points and 0 comments
Phant0m | Windows Event Log Killer
https://ift.tt/2SNovpC
Submitted June 21, 2021 at 12:49PM by hlldz
via reddit https://ift.tt/3xGElBl
https://ift.tt/2SNovpC
Submitted June 21, 2021 at 12:49PM by hlldz
via reddit https://ift.tt/3xGElBl
GitHub
GitHub - hlldz/Phant0m: Windows Event Log Killer
Windows Event Log Killer. Contribute to hlldz/Phant0m development by creating an account on GitHub.
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
https://ift.tt/35DJduU
Submitted June 21, 2021 at 08:31PM by toyojuni
via reddit https://ift.tt/35Dk1ot
https://ift.tt/35DJduU
Submitted June 21, 2021 at 08:31PM by toyojuni
via reddit https://ift.tt/35Dk1ot
Medium
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
The Fault in Our Stars - Security Implications of AWS API Gateway Lambda Authorizers and IAM Wildcard Expansion
https://ift.tt/3qfSin6
Submitted June 22, 2021 at 08:39AM by Felipe-Pr0teus
via reddit https://ift.tt/3xLmklr
https://ift.tt/3qfSin6
Submitted June 22, 2021 at 08:39AM by Felipe-Pr0teus
via reddit https://ift.tt/3xLmklr
Linux marketplaces vulnerable to RCE and supply chain attacks
https://ift.tt/3xBox2y
Submitted June 22, 2021 at 07:27PM by breakingsystems
via reddit https://ift.tt/3wPE2nJ
https://ift.tt/3xBox2y
Submitted June 22, 2021 at 07:27PM by breakingsystems
via reddit https://ift.tt/3wPE2nJ
positive.security
Linux marketplaces vulnerable to RCE and supply chain attacks | Positive Security
We're disclosing patched vulnerabilities in KDE Discover and the Gnome Shell Extensions website, as well as unpatched vulnerabilities in the PlingStore app and Pling-based Linux marketplace websites (e.g. appimagehub.com, store.kde.org, gnome-look.org).
LEXSS: Bypassing Lexical Parsing Security Controls
https://ift.tt/3xItw1v
Submitted June 22, 2021 at 09:13PM by breach_house
via reddit https://ift.tt/3xCWekc
https://ift.tt/3xItw1v
Submitted June 22, 2021 at 09:13PM by breach_house
via reddit https://ift.tt/3xCWekc
Bishop Fox
LEXSS: Bypassing Lexical Parsing Security Controls
Technical details of achieving cross-site noscripting (XSS) attacks by using HTML parsing logic where lexical parsers are used to nullify dangerous content.
Attack Surface Analyzer helps you analyze your OS's security configuration, open-sourced by Microsoft
https://ift.tt/39XAh3c
Submitted June 22, 2021 at 09:11PM by beleeee_dat
via reddit https://ift.tt/3zL50i1
https://ift.tt/39XAh3c
Submitted June 22, 2021 at 09:11PM by beleeee_dat
via reddit https://ift.tt/3zL50i1
GitHub
GitHub - microsoft/AttackSurfaceAnalyzer: Attack Surface Analyzer can help you analyze your operating system's security configuration…
Attack Surface Analyzer can help you analyze your operating system's security configuration for changes during software installation. - GitHub - microsoft/AttackSurfaceAnalyzer: Attack Surf...
Introducing Semgrep for GitLab
https://ift.tt/3gSvMwt
Submitted June 22, 2021 at 10:41PM by pabloest
via reddit https://ift.tt/3xWerK3
https://ift.tt/3gSvMwt
Submitted June 22, 2021 at 10:41PM by pabloest
via reddit https://ift.tt/3xWerK3
r2c.dev
r2c blog — Introducing Semgrep for GitLab
Semgrep now has 1st-class integration into GitLab
D3FEND Matrix | MITRE D3FEND™
https://ift.tt/2UuqxeQ
Submitted June 22, 2021 at 11:26PM by malware_bender
via reddit https://ift.tt/3zLxvMB
https://ift.tt/2UuqxeQ
Submitted June 22, 2021 at 11:26PM by malware_bender
via reddit https://ift.tt/3zLxvMB
d3fend.mitre.org
MITRE D3FEND Knowledge Graph
D3FEND is a knowledge base of cybersecurity countermeasure techniques. In the simplest sense, it is a catalog of defensive cybersecurity techniques and their relationships to offensive/adversary techniques. The primary goal of the initial D3FEND release is…
Threat Detections for Container Lateral Movements and Container Escapes — This is How
https://ift.tt/3j76Rbg
Submitted June 22, 2021 at 11:22PM by rexguo1
via reddit https://ift.tt/2T02vbd
https://ift.tt/3j76Rbg
Submitted June 22, 2021 at 11:22PM by rexguo1
via reddit https://ift.tt/2T02vbd
Medium
Threat Detections for Container Lateral Movements and Container Escapes — This is How
Introduction
Basic hack 101, Poor password management
https://ift.tt/3gPUdKI
Submitted June 23, 2021 at 02:44PM by Embarrassed-Yam-3471
via reddit https://ift.tt/3jiQW9Z
https://ift.tt/3gPUdKI
Submitted June 23, 2021 at 02:44PM by Embarrassed-Yam-3471
via reddit https://ift.tt/3jiQW9Z
ETTelecom.com
Telecom News | Latest Telecom Industry News, Information and Update: ET Telecom
Find the latest telecom Industry news, online Industry information, views & updates. Get online news from the Indian Telecom Industry on ET Telecom.
I made 56874 calls to explore the telephone network. Here’s what I found.
https://ift.tt/3gMPOcU
Submitted June 23, 2021 at 02:38PM by ValtteriLe
via reddit https://ift.tt/3wT0MDb
https://ift.tt/3gMPOcU
Submitted June 23, 2021 at 02:38PM by ValtteriLe
via reddit https://ift.tt/3wT0MDb
Shufflingbytes
I made 56874 calls to explore the telephone network. Here's what I found
Post describing my research wardialing Finnish freephones.
Key differences Between TLS 1.2 and TLS 1.3
https://ift.tt/35l61Q1
Submitted June 23, 2021 at 04:02PM by Best_Cauliflowers
via reddit https://ift.tt/3vPvL1Q
https://ift.tt/35l61Q1
Submitted June 23, 2021 at 04:02PM by Best_Cauliflowers
via reddit https://ift.tt/3vPvL1Q
A10 Networks
Key differences Between TLS 1.2 and TLS 1.3 | Glossary | A10 Networks
The differences between TLS 1.2 and TLS 1.3 are extensive and significant, offering improvements in both performance and security.
Deal: PE Firm Silver Lake Invests $1B In Splunk
https://ift.tt/35KSf9p
Submitted June 23, 2021 at 05:20PM by The-Techie
via reddit https://ift.tt/3xMiZCA
https://ift.tt/35KSf9p
Submitted June 23, 2021 at 05:20PM by The-Techie
via reddit https://ift.tt/3xMiZCA
Thetechee
Deal: PE Firm Silver Lake Invests $1B In Splunk
Python static analysis comparison: Bandit vs Semgrep
https://ift.tt/3xDijiA
Submitted June 23, 2021 at 08:59PM by pabloest
via reddit https://ift.tt/3gVceYo
https://ift.tt/3xDijiA
Submitted June 23, 2021 at 08:59PM by pabloest
via reddit https://ift.tt/3gVceYo
r2c.dev
r2c blog — Python static analysis comparison: Bandit vs Semgrep
A deep dive tool comparison
AD CS relay attack - practical guide
https://ift.tt/3xKzX41
Submitted June 23, 2021 at 11:16PM by exandroiddev
via reddit https://ift.tt/2T2G3hv
https://ift.tt/3xKzX41
Submitted June 23, 2021 at 11:16PM by exandroiddev
via reddit https://ift.tt/2T2G3hv
Ex Android Dev
AD CS relay attack - practical guide
Unless you are living under the rock, you have seen that recently @harmj0y and @tifkin_ published their amazing research on Active Directory Certificate Services (AD CS). If you haven’t checked it out already read their post first.
Nearly 100% of Companies Experienced a Cloud Data Breach in Past 18 Months
https://ift.tt/3vQyOXp
Submitted June 24, 2021 at 12:47PM by Left-Check-1587
via reddit https://ift.tt/3qkK5Ou
https://ift.tt/3vQyOXp
Submitted June 24, 2021 at 12:47PM by Left-Check-1587
via reddit https://ift.tt/3qkK5Ou
Yahoo
Ermetic Reports Nearly 100% of Companies Experienced a Cloud Data Breach in Past 18 Months
PALO ALTO, Calif. & TEL AVIV, Israel, June 23, 2021--Nearly 60% of organizations said they consider lack of visibility and inadequate identity/access security a major threat to their cloud infrastructure
Installing ClamAV for File Scanning
https://ift.tt/3gSKO6u
Submitted June 24, 2021 at 01:50PM by Jeruselam
via reddit https://ift.tt/3gTpa29
https://ift.tt/3gSKO6u
Submitted June 24, 2021 at 01:50PM by Jeruselam
via reddit https://ift.tt/3gTpa29
Günce - Günlük Blog Yazıları
Installing ClamAV for File Scanning
Until this time, Linux has experienced only a small number of viruses. Some of these viruses still exist but aren’t active, and they certainly don’t propagate.
Pandora FMS 754 - Chained Exploit (XSS, File Upload, Remote Code Execution)
https://ift.tt/3ddoNNw
Submitted June 25, 2021 at 01:06AM by k4m1ll0
via reddit https://ift.tt/3xQkW0L
https://ift.tt/3ddoNNw
Submitted June 25, 2021 at 01:06AM by k4m1ll0
via reddit https://ift.tt/3xQkW0L
K4M1Ll0
Pandora FMS 754 - Chained Exploit (XSS, File Upload, Remote Code Execution)
Developers Under Attack - Leveraging Typosquatting for Crypto Mining
https://ift.tt/2T4IDnk
Submitted June 25, 2021 at 04:46PM by SRMish3
via reddit https://ift.tt/3jchJV7
https://ift.tt/2T4IDnk
Submitted June 25, 2021 at 04:46PM by SRMish3
via reddit https://ift.tt/3jchJV7
VDOO
Developers Under Attack - Leveraging Typosquatting for Crypto Mining
New security research on top of a novel detection of PyPI packages containing a crypto-miner. We present actionable solutions for developers and discuss automated detection and deobfuscate techincs.
Evasive Maneuvers | Massive IcedID Campaign Aims For Stealth with Benign Macros
https://ift.tt/3vUeTac
Submitted June 24, 2021 at 10:34PM by Cyberthere
via reddit https://ift.tt/3gTvuqc
https://ift.tt/3vUeTac
Submitted June 24, 2021 at 10:34PM by Cyberthere
via reddit https://ift.tt/3gTvuqc
SentinelLabs
Evasive Maneuvers | Massive IcedID Campaign Aims For Stealth with Benign Macros - SentinelLabs
A widespread phishing campaign in operation since May is using a mix of old and new evasion tricks to drop IcedID malware.