Tutorial on finding and exploiting race condition bugs, with included 0days
https://ift.tt/3iLrwzI
Submitted July 28, 2021 at 01:40AM by 0daywizard
via reddit https://ift.tt/3zGRSK2
https://ift.tt/3iLrwzI
Submitted July 28, 2021 at 01:40AM by 0daywizard
via reddit https://ift.tt/3zGRSK2
0xFFFF@blog:~$
Winning the race: Signals, symlinks, and TOC/TOU
Introduction: So, before we dive right into things, just a few bits of advice; some programming knowledge, an understanding of what symbolic linking is within *nix and how it works, and also an und…
Revealin - Exploits a design flaw in Linkedin to uncover the fullname of a target when he has his name masked.
https://ift.tt/3x3I0bC
Submitted July 28, 2021 at 02:13PM by mxrchreborn
via reddit https://ift.tt/3BZbX0e
https://ift.tt/3x3I0bC
Submitted July 28, 2021 at 02:13PM by mxrchreborn
via reddit https://ift.tt/3BZbX0e
GitHub
GitHub - mxrch/revealin: Uncover the full name of a target on Linkedin.
Uncover the full name of a target on Linkedin. Contribute to mxrch/revealin development by creating an account on GitHub.
FACT SHEET: Biden Administration Announces Further Actions to Protect U.S. Critical Infrastructure | The White House
https://ift.tt/3iW7IcZ
Submitted July 28, 2021 at 07:47PM by HumanSuitcase
via reddit https://ift.tt/2UXL7Vt
https://ift.tt/3iW7IcZ
Submitted July 28, 2021 at 07:47PM by HumanSuitcase
via reddit https://ift.tt/2UXL7Vt
The White House
FACT SHEET: Biden Administration Announces Further Actions to Protect U.S. Critical Infrastructure
The Biden Administration continues to take steps to safeguard U.S. critical infrastructure from growing, persistent, and sophisticated cyber threats. Recent high-profile attacks on critical infrastructure around the world, including the ransomware attacks…
From Stolen Laptop to Inside the Company Network
https://ift.tt/3l1Qf5C
Submitted July 28, 2021 at 07:36PM by 312sec
via reddit https://ift.tt/3BPgMsF
https://ift.tt/3l1Qf5C
Submitted July 28, 2021 at 07:36PM by 312sec
via reddit https://ift.tt/3BPgMsF
Devtron - Opensource Kubernetes delivery Workflow for CI/CD with security features like Granular Hierarchical Security policy Management, Automatic Vulnerability management during CI as well as within cluster.
https://ift.tt/3l7jJyP
Submitted July 28, 2021 at 09:03PM by pghildiy
via reddit https://ift.tt/3rMeTIL
https://ift.tt/3l7jJyP
Submitted July 28, 2021 at 09:03PM by pghildiy
via reddit https://ift.tt/3rMeTIL
GitHub
devtron/security-features.md at main · devtron-labs/devtron
Software Delivery Workflow For Kubernetes. Contribute to devtron-labs/devtron development by creating an account on GitHub.
Detecting potential exploits of CVE-2021-33909 "Sequoia" with Falco - Linux FS privilege escalation
https://ift.tt/3l2Gap2
Submitted July 28, 2021 at 11:12PM by capitangolo
via reddit https://ift.tt/2WuUEDY
https://ift.tt/3l2Gap2
Submitted July 28, 2021 at 11:12PM by capitangolo
via reddit https://ift.tt/2WuUEDY
Sysdig
Mitigate CVE-2021-33909 Sequoia - Linux FS privilege escalation
CVE-2021-33909, codenamed Sequoia, affects Linux's file system and enables privilege escalation. Learn how to mitigate and detect it.
GitHub - DigeeX/raider: Web authentication testing framework
https://ift.tt/3rtDdyV
Submitted July 28, 2021 at 11:55PM by dgeex
via reddit https://ift.tt/378Cp9w
https://ift.tt/3rtDdyV
Submitted July 28, 2021 at 11:55PM by dgeex
via reddit https://ift.tt/378Cp9w
GitHub
GitHub - DigeeX/raider: Web authentication testing framework
Web authentication testing framework. Contribute to DigeeX/raider development by creating an account on GitHub.
ligolo-ng: An advanced, yet simple, tunneling tool that uses a TUN interface.
https://ift.tt/2URAnIm
Submitted July 28, 2021 at 07:28PM by TNPitsecurity
via reddit https://ift.tt/3BUlTI7
https://ift.tt/2URAnIm
Submitted July 28, 2021 at 07:28PM by TNPitsecurity
via reddit https://ift.tt/3BUlTI7
GitHub
GitHub - nicocha30/ligolo-ng: An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface. - nicocha30/ligolo-ng
Marketo marketplace leak personal data from the Homewood attack
https://ift.tt/3rFTjWw
Submitted July 29, 2021 at 07:18AM by MathematicianFit2805
via reddit https://ift.tt/3zQTalV
https://ift.tt/3rFTjWw
Submitted July 29, 2021 at 07:18AM by MathematicianFit2805
via reddit https://ift.tt/3zQTalV
British Columbia
Unknown number of British Columbians' personal information for sale online after health company extorted
CTV News has learned the personal information of British Columbians has been leaked online, with an unknown number of people and agencies potentially still vulnerable, after a data breach at a mental health services provider.
First stable release of isoalloc: general purpose memory allocator that mitigates memory safety issues while maintaining good performance
https://ift.tt/3urqgpO
Submitted July 29, 2021 at 11:28AM by 0xdea
via reddit https://ift.tt/3l47ALj
https://ift.tt/3urqgpO
Submitted July 29, 2021 at 11:28AM by 0xdea
via reddit https://ift.tt/3l47ALj
GitHub
GitHub - struct/isoalloc: A general purpose memory allocator that implements an isolation security strategy to mitigate memory…
A general purpose memory allocator that implements an isolation security strategy to mitigate memory safety issues while maintaining good performance - GitHub - struct/isoalloc: A general purpose m...
Detecting LDAP enumeration and Bloodhound‘s Sharphound collector using Deception via Active Directory Decoys
https://ift.tt/3BPBqch
Submitted July 29, 2021 at 02:05PM by PsychologicalLoss829
via reddit https://ift.tt/3BUvYEY
https://ift.tt/3BPBqch
Submitted July 29, 2021 at 02:05PM by PsychologicalLoss829
via reddit https://ift.tt/3BUvYEY
Medium
Detecting LDAP enumeration and Bloodhound‘s Sharphound collector using AD Decoys
Using deception and decoy accounts to detect threat actors
Introducing hallucinate: One-stop TLS traffic inspection and manipulation using dynamic instrumentation
https://ift.tt/2Vkud3j
Submitted July 29, 2021 at 05:35PM by 0xfffffg
via reddit https://ift.tt/3f9EUN4
https://ift.tt/2Vkud3j
Submitted July 29, 2021 at 05:35PM by 0xfffffg
via reddit https://ift.tt/3f9EUN4
SySS Tech Blog
Introducing hallucinate: One-stop TLS traffic inspection and manipulation using dynamic instrumentation
Understanding an application’s network communication is commonly one of the major tasks when performing grey or black box application security analyses. To make this process as efficient and convenient as possible, we developed hallucinate, a dynamic binary…
Adaptation of Shortest Path Algorithms for Dynamic Routing Problems
https://ift.tt/2TGbVZF
Submitted July 29, 2021 at 07:51PM by shapelez
via reddit https://ift.tt/3xeTJ7f
https://ift.tt/2TGbVZF
Submitted July 29, 2021 at 07:51PM by shapelez
via reddit https://ift.tt/3xeTJ7f
reddit
Adaptation of Shortest Path Algorithms for Dynamic Routing Problems
Posted in r/netsec by u/shapelez • 3 points and 0 comments
MeteorExpress | Mysterious Wiper Paralyzes Iranian Trains with Epic Troll
https://ift.tt/3ibiTPN
Submitted July 29, 2021 at 06:06PM by securehoney
via reddit https://ift.tt/3laWWlJ
https://ift.tt/3ibiTPN
Submitted July 29, 2021 at 06:06PM by securehoney
via reddit https://ift.tt/3laWWlJ
SentinelOne
MeteorExpress | Mysterious Wiper Paralyzes Iranian Trains with Epic Troll - SentinelLabs
In the midst of an epic troll on a country-wide railway system, we discovered a new threat actor and their reusable wiper called Meteor.
Root Cause Analysis of a Printer's Drivers Vulnerability CVE-2021-3438 - VoidSec
https://ift.tt/3ldjrXk
Submitted July 29, 2021 at 09:01PM by Void_Sec
via reddit https://ift.tt/3ib74Jt
https://ift.tt/3ldjrXk
Submitted July 29, 2021 at 09:01PM by Void_Sec
via reddit https://ift.tt/3ib74Jt
VoidSec
Root Cause Analysis of a Printer's Drivers Vulnerability CVE-2021-3438 - VoidSec
Analysis and Exploitability of a buffer overflow vulnerability present in printer's drivers (CVE-2021-3438).
Magnitude Exploit Kit: Still Alive and Kicking
https://ift.tt/3lanQKM
Submitted July 29, 2021 at 10:07PM by stashing_the_smack
via reddit https://ift.tt/3BSbZH9
https://ift.tt/3lanQKM
Submitted July 29, 2021 at 10:07PM by stashing_the_smack
via reddit https://ift.tt/3BSbZH9
Avast Threat Labs
Magnitude Exploit Kit: Still Alive and Kicking - Avast Threat Labs
The Magnitude exploit kit, originally known as PopAds, has been around since at least 2012, which is an unusually long lifetime for an exploit kit. However, it’s not the same exploit kit today that it was nine years ago. Pretty much every part of Magnitude…
Probably Are Gonna Need It: Application Security Edition
https://ift.tt/3yAvvFr
Submitted July 30, 2021 at 03:28AM by pimterry
via reddit https://ift.tt/2V6rfPX
https://ift.tt/3yAvvFr
Submitted July 30, 2021 at 03:28AM by pimterry
via reddit https://ift.tt/2V6rfPX
jacobian.org
Probably Are Gonna Need It: Application Security Edition - Jacob Kaplan-Moss
My list of “Probably Are Gonna Need It” security features for your web app – things that you should build up-front, not wait until you need them (when it’s already too late).
Malicious PyPI Packages Stealing Credit Cards and Injecting Code - Technical Analysis
https://ift.tt/3j6RZYu
Submitted July 30, 2021 at 02:09PM by securehoney
via reddit https://ift.tt/3C6eXrN
https://ift.tt/3j6RZYu
Submitted July 30, 2021 at 02:09PM by securehoney
via reddit https://ift.tt/3C6eXrN
JFrog
Python developers are being targeted with malicious packages on PyPI
JFrog finds a new supply chain attack targeting python developers using the PyPI repository
Attack AI systems in Machine Learning Evasion Competition | Microsoft Security Blog
https://ift.tt/374jNr8
Submitted July 30, 2021 at 02:47PM by AdmiralDoughnot
via reddit https://ift.tt/3zOWKge
https://ift.tt/374jNr8
Submitted July 30, 2021 at 02:47PM by AdmiralDoughnot
via reddit https://ift.tt/3zOWKge
Microsoft Security Blog
Attack AI systems in Machine Learning Evasion Competition | Microsoft Security Blog
Today, we are launching MLSEC.IO, a new machine learning security evasion competition as an educational effort for the AI and security communities to exercise their muscle to attack critical AI systems in a realistic setting.
The first 11 “Secure The Governement” vulnerability disclosure programs (DHS, FCC, UDSA, BOL, etc) are now live.
https://ift.tt/3zRbKKG
Submitted July 30, 2021 at 03:35PM by yesnet0
via reddit https://ift.tt/3fckSkS
https://ift.tt/3zRbKKG
Submitted July 30, 2021 at 03:35PM by yesnet0
via reddit https://ift.tt/3fckSkS
Bugcrowd
CISA Vulnerability Disclosure Programs | Bugcrowd | Bugcrowd
Find active vulnerability disclosure programs from the Cybersecurity & Infrastructure Security Agency. Start hunting today!
[CFP] Call for Papers for Hardwear.io Security Conference Netherlands 2021 is OPEN
https://ift.tt/3BWGKKR
Submitted July 30, 2021 at 05:20PM by hardweario
via reddit https://ift.tt/2UYUJ2q
https://ift.tt/3BWGKKR
Submitted July 30, 2021 at 05:20PM by hardweario
via reddit https://ift.tt/2UYUJ2q
hardwear.io
Hardwear.io Netherlands 2021