AD CS relay attack - practical guide
https://ift.tt/3xKzX41
Submitted June 23, 2021 at 11:16PM by exandroiddev
via reddit https://ift.tt/2T2G3hv
https://ift.tt/3xKzX41
Submitted June 23, 2021 at 11:16PM by exandroiddev
via reddit https://ift.tt/2T2G3hv
Ex Android Dev
AD CS relay attack - practical guide
Unless you are living under the rock, you have seen that recently @harmj0y and @tifkin_ published their amazing research on Active Directory Certificate Services (AD CS). If you haven’t checked it out already read their post first.
Nearly 100% of Companies Experienced a Cloud Data Breach in Past 18 Months
https://ift.tt/3vQyOXp
Submitted June 24, 2021 at 12:47PM by Left-Check-1587
via reddit https://ift.tt/3qkK5Ou
https://ift.tt/3vQyOXp
Submitted June 24, 2021 at 12:47PM by Left-Check-1587
via reddit https://ift.tt/3qkK5Ou
Yahoo
Ermetic Reports Nearly 100% of Companies Experienced a Cloud Data Breach in Past 18 Months
PALO ALTO, Calif. & TEL AVIV, Israel, June 23, 2021--Nearly 60% of organizations said they consider lack of visibility and inadequate identity/access security a major threat to their cloud infrastructure
Installing ClamAV for File Scanning
https://ift.tt/3gSKO6u
Submitted June 24, 2021 at 01:50PM by Jeruselam
via reddit https://ift.tt/3gTpa29
https://ift.tt/3gSKO6u
Submitted June 24, 2021 at 01:50PM by Jeruselam
via reddit https://ift.tt/3gTpa29
Günce - Günlük Blog Yazıları
Installing ClamAV for File Scanning
Until this time, Linux has experienced only a small number of viruses. Some of these viruses still exist but aren’t active, and they certainly don’t propagate.
Pandora FMS 754 - Chained Exploit (XSS, File Upload, Remote Code Execution)
https://ift.tt/3ddoNNw
Submitted June 25, 2021 at 01:06AM by k4m1ll0
via reddit https://ift.tt/3xQkW0L
https://ift.tt/3ddoNNw
Submitted June 25, 2021 at 01:06AM by k4m1ll0
via reddit https://ift.tt/3xQkW0L
K4M1Ll0
Pandora FMS 754 - Chained Exploit (XSS, File Upload, Remote Code Execution)
Developers Under Attack - Leveraging Typosquatting for Crypto Mining
https://ift.tt/2T4IDnk
Submitted June 25, 2021 at 04:46PM by SRMish3
via reddit https://ift.tt/3jchJV7
https://ift.tt/2T4IDnk
Submitted June 25, 2021 at 04:46PM by SRMish3
via reddit https://ift.tt/3jchJV7
VDOO
Developers Under Attack - Leveraging Typosquatting for Crypto Mining
New security research on top of a novel detection of PyPI packages containing a crypto-miner. We present actionable solutions for developers and discuss automated detection and deobfuscate techincs.
Evasive Maneuvers | Massive IcedID Campaign Aims For Stealth with Benign Macros
https://ift.tt/3vUeTac
Submitted June 24, 2021 at 10:34PM by Cyberthere
via reddit https://ift.tt/3gTvuqc
https://ift.tt/3vUeTac
Submitted June 24, 2021 at 10:34PM by Cyberthere
via reddit https://ift.tt/3gTvuqc
SentinelLabs
Evasive Maneuvers | Massive IcedID Campaign Aims For Stealth with Benign Macros - SentinelLabs
A widespread phishing campaign in operation since May is using a mix of old and new evasion tricks to drop IcedID malware.
Inside commercial malware sandboxes
https://ift.tt/3ddqWZG
Submitted June 25, 2021 at 08:16PM by bonobolol
via reddit https://ift.tt/2TWsAYN
https://ift.tt/3ddqWZG
Submitted June 25, 2021 at 08:16PM by bonobolol
via reddit https://ift.tt/2TWsAYN
reddit
Inside commercial malware sandboxes
Posted in r/netsec by u/bonobolol • 58 points and 4 comments
Reserve Bank of India CSF Benchmark (75 opensource controls for AWS)
https://ift.tt/3h9RPip
Submitted June 25, 2021 at 08:52PM by CloudSpout
via reddit https://ift.tt/3jejRM4
https://ift.tt/3h9RPip
Submitted June 25, 2021 at 08:52PM by CloudSpout
via reddit https://ift.tt/3jejRM4
Steampipe Hub
AWS Compliance Mod for Steampipe
Browse the documentation for the Steampipe AWS Compliance mod rbi_cyber_security benchmark
Crackonosh: A New Malware Distributed in Cracked Software - Avast Threat Labs
https://ift.tt/3jaQSbW
Submitted June 26, 2021 at 06:54PM by _vavkamil_
via reddit https://ift.tt/35TCq0h
https://ift.tt/3jaQSbW
Submitted June 26, 2021 at 06:54PM by _vavkamil_
via reddit https://ift.tt/35TCq0h
Avast Threat Labs
Crackonosh: A New Malware Distributed in Cracked Software - Avast Threat Labs
New malware strain we discovered could be the reason why your antivirus doesn’t work anymore. Especially if you have installed some popular software from not so legal distribution recently
Microsoft signed a malicious Netfilter rootkit
https://ift.tt/3h4eNr7
Submitted June 27, 2021 at 10:14PM by AwareSupermarket3008
via reddit https://ift.tt/3vV2Gln
https://ift.tt/3h4eNr7
Submitted June 27, 2021 at 10:14PM by AwareSupermarket3008
via reddit https://ift.tt/3vV2Gln
Gdatasoftware
Microsoft signed a malicious Netfilter rootkit
What started as a false positive alert for a Microsoft signed file turns out to be a WFP application layer enforcement callout driver that redirects traffic to a Chinese IP. How did this happen?
Hack The Box: Spectra - Write-up by Khaotic
https://ift.tt/3dgurhX
Submitted June 26, 2021 at 08:30PM by Khaoticdude
via reddit https://ift.tt/3jhVygr
https://ift.tt/3dgurhX
Submitted June 26, 2021 at 08:30PM by Khaoticdude
via reddit https://ift.tt/3jhVygr
Khaotic Developments
Hack The Box: Spectra
Jump Ahead: Enum – Getting Initial Access – User – Root – Resources TL;DR; To solve this machine, we begin by enumerating open services – finding ports 22, 80, and 330…
IDOR - Insecure Direct Object Reference
https://ift.tt/3A5x0Nr
Submitted June 28, 2021 at 05:22PM by JustOr113
via reddit https://ift.tt/2TbRKm4
https://ift.tt/3A5x0Nr
Submitted June 28, 2021 at 05:22PM by JustOr113
via reddit https://ift.tt/2TbRKm4
Sayfer.io
IDOR - Insecure Direct Object Reference | Sayfer.io
Insecure Direct Object Reference or IDOR happens when an application inadvertently exposes private objects through user input.
SSRF in ColdFusion/CFML Tags and Functions
https://ift.tt/3A84Pxl
Submitted June 28, 2021 at 06:23PM by albinowax
via reddit https://ift.tt/2U27LLz
https://ift.tt/3A84Pxl
Submitted June 28, 2021 at 06:23PM by albinowax
via reddit https://ift.tt/2U27LLz
Blogspot
SSRF in ColdFusion/CFML Tags and Functions
TL;DR: Several ColdFusion/CFML tags and functions can process URLs as file path arguments -- including some tags and and functions that you...
Open source Salesforce object access auditor - which Profiles and Permissions Sets (with active users) have some combination of read/edit/delete permissions to ALL records for a given set of objects, based on their effective sharing and objects settings.
https://ift.tt/2SBWFwy
Submitted June 29, 2021 at 12:29AM by digicat
via reddit https://ift.tt/3dmUCne
https://ift.tt/2SBWFwy
Submitted June 29, 2021 at 12:29AM by digicat
via reddit https://ift.tt/3dmUCne
GitHub
GitHub - nccgroup/raccoon: Salesforce object access auditor
Salesforce object access auditor. Contribute to nccgroup/raccoon development by creating an account on GitHub.
Netsec eBooks Bundle by Packt
https://ift.tt/3h2b1Qg
Submitted June 29, 2021 at 12:26AM by reps_up
via reddit https://ift.tt/3x3CQ05
https://ift.tt/3h2b1Qg
Submitted June 29, 2021 at 12:26AM by reps_up
via reddit https://ift.tt/3x3CQ05
Medium
Make yourself digitally invulnerable with the Cybersecurity 2021 eBooks Bundle from Packt
Humble Book Bundle: Cybersecurity 2021 from Packt
Google Compute Engine (GCE) VM "remote" root exploit via DHCP flood
https://ift.tt/3y2ZFkx
Submitted June 29, 2021 at 01:40AM by xdavidhu
via reddit https://ift.tt/3joXWll
https://ift.tt/3y2ZFkx
Submitted June 29, 2021 at 01:40AM by xdavidhu
via reddit https://ift.tt/3joXWll
GitHub
GitHub - irsl/gcp-dhcp-takeover-code-exec: Google Compute Engine (GCE) VM takeover via DHCP flood - gain root access by getting…
Google Compute Engine (GCE) VM takeover via DHCP flood - gain root access by getting SSH keys added by google_guest_agent - irsl/gcp-dhcp-takeover-code-exec
Open source client for free Windscribe proxies
https://ift.tt/2TiyiEr
Submitted June 29, 2021 at 03:26AM by yarmak
via reddit https://ift.tt/3dpP9vP
https://ift.tt/2TiyiEr
Submitted June 29, 2021 at 03:26AM by yarmak
via reddit https://ift.tt/3dpP9vP
GitHub
GitHub - Snawoot/windscribe-proxy: Standalone client for proxies of Windscribe browser extension
Standalone client for proxies of Windscribe browser extension - Snawoot/windscribe-proxy
Databunker - an open-source secure vault
https://ift.tt/3sRsVsf
Submitted June 29, 2021 at 04:07AM by yulistr
via reddit https://ift.tt/3y2Bhzr
https://ift.tt/3sRsVsf
Submitted June 29, 2021 at 04:07AM by yulistr
via reddit https://ift.tt/3y2Bhzr
GitHub
GitHub - securitybunker/databunker: Secure Vault for Customer PII/PHI/PCI/KYC Records
Secure Vault for Customer PII/PHI/PCI/KYC Records. Contribute to securitybunker/databunker development by creating an account on GitHub.
ukncsc/Device-Security-Guidance-Configuration-Packs: This repository contains policy packs which can be used by system management software to configure device platforms (such as Windows 10 and iOS) in accordance with NCSC device security guidance.
https://ift.tt/2Tk9Dzl
Submitted June 29, 2021 at 03:31PM by joelgsamuel
via reddit https://ift.tt/3heRYkp
https://ift.tt/2Tk9Dzl
Submitted June 29, 2021 at 03:31PM by joelgsamuel
via reddit https://ift.tt/3heRYkp
GitHub
GitHub - ukncsc/Device-Security-Guidance-Configuration-Packs: This repository contains policy packs which can be used by system…
This repository contains policy packs which can be used by system management software to configure device platforms (such as Windows 10 and iOS) in accordance with NCSC device security guidance. Th...
Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464)
https://ift.tt/3jp5x3v
Submitted June 29, 2021 at 05:10PM by artsploit
via reddit https://ift.tt/35Zy8EB
https://ift.tt/3jp5x3v
Submitted June 29, 2021 at 05:10PM by artsploit
via reddit https://ift.tt/35Zy8EB
Beating layer 7 DDoS attacks for free, using CrowdSec+Cloudflare
https://ift.tt/3qwXrHA
Submitted June 29, 2021 at 07:25PM by philippe_crowdsec
via reddit https://ift.tt/3vYGDKM
https://ift.tt/3qwXrHA
Submitted June 29, 2021 at 07:25PM by philippe_crowdsec
via reddit https://ift.tt/3vYGDKM
The open-source & multiplayer security solution
How to beat application DDoS attacks with CrowdSec & Cloudflare
A simple guide explaining how to beat applicative-layer DDoS attacks using CrowdSec and Cloudflare.