GitHub - DigeeX/raider: Web authentication testing framework
https://ift.tt/3rtDdyV
Submitted July 28, 2021 at 11:55PM by dgeex
via reddit https://ift.tt/378Cp9w
https://ift.tt/3rtDdyV
Submitted July 28, 2021 at 11:55PM by dgeex
via reddit https://ift.tt/378Cp9w
GitHub
GitHub - DigeeX/raider: Web authentication testing framework
Web authentication testing framework. Contribute to DigeeX/raider development by creating an account on GitHub.
ligolo-ng: An advanced, yet simple, tunneling tool that uses a TUN interface.
https://ift.tt/2URAnIm
Submitted July 28, 2021 at 07:28PM by TNPitsecurity
via reddit https://ift.tt/3BUlTI7
https://ift.tt/2URAnIm
Submitted July 28, 2021 at 07:28PM by TNPitsecurity
via reddit https://ift.tt/3BUlTI7
GitHub
GitHub - nicocha30/ligolo-ng: An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface. - nicocha30/ligolo-ng
Marketo marketplace leak personal data from the Homewood attack
https://ift.tt/3rFTjWw
Submitted July 29, 2021 at 07:18AM by MathematicianFit2805
via reddit https://ift.tt/3zQTalV
https://ift.tt/3rFTjWw
Submitted July 29, 2021 at 07:18AM by MathematicianFit2805
via reddit https://ift.tt/3zQTalV
British Columbia
Unknown number of British Columbians' personal information for sale online after health company extorted
CTV News has learned the personal information of British Columbians has been leaked online, with an unknown number of people and agencies potentially still vulnerable, after a data breach at a mental health services provider.
First stable release of isoalloc: general purpose memory allocator that mitigates memory safety issues while maintaining good performance
https://ift.tt/3urqgpO
Submitted July 29, 2021 at 11:28AM by 0xdea
via reddit https://ift.tt/3l47ALj
https://ift.tt/3urqgpO
Submitted July 29, 2021 at 11:28AM by 0xdea
via reddit https://ift.tt/3l47ALj
GitHub
GitHub - struct/isoalloc: A general purpose memory allocator that implements an isolation security strategy to mitigate memory…
A general purpose memory allocator that implements an isolation security strategy to mitigate memory safety issues while maintaining good performance - GitHub - struct/isoalloc: A general purpose m...
Detecting LDAP enumeration and Bloodhound‘s Sharphound collector using Deception via Active Directory Decoys
https://ift.tt/3BPBqch
Submitted July 29, 2021 at 02:05PM by PsychologicalLoss829
via reddit https://ift.tt/3BUvYEY
https://ift.tt/3BPBqch
Submitted July 29, 2021 at 02:05PM by PsychologicalLoss829
via reddit https://ift.tt/3BUvYEY
Medium
Detecting LDAP enumeration and Bloodhound‘s Sharphound collector using AD Decoys
Using deception and decoy accounts to detect threat actors
Introducing hallucinate: One-stop TLS traffic inspection and manipulation using dynamic instrumentation
https://ift.tt/2Vkud3j
Submitted July 29, 2021 at 05:35PM by 0xfffffg
via reddit https://ift.tt/3f9EUN4
https://ift.tt/2Vkud3j
Submitted July 29, 2021 at 05:35PM by 0xfffffg
via reddit https://ift.tt/3f9EUN4
SySS Tech Blog
Introducing hallucinate: One-stop TLS traffic inspection and manipulation using dynamic instrumentation
Understanding an application’s network communication is commonly one of the major tasks when performing grey or black box application security analyses. To make this process as efficient and convenient as possible, we developed hallucinate, a dynamic binary…
Adaptation of Shortest Path Algorithms for Dynamic Routing Problems
https://ift.tt/2TGbVZF
Submitted July 29, 2021 at 07:51PM by shapelez
via reddit https://ift.tt/3xeTJ7f
https://ift.tt/2TGbVZF
Submitted July 29, 2021 at 07:51PM by shapelez
via reddit https://ift.tt/3xeTJ7f
reddit
Adaptation of Shortest Path Algorithms for Dynamic Routing Problems
Posted in r/netsec by u/shapelez • 3 points and 0 comments
MeteorExpress | Mysterious Wiper Paralyzes Iranian Trains with Epic Troll
https://ift.tt/3ibiTPN
Submitted July 29, 2021 at 06:06PM by securehoney
via reddit https://ift.tt/3laWWlJ
https://ift.tt/3ibiTPN
Submitted July 29, 2021 at 06:06PM by securehoney
via reddit https://ift.tt/3laWWlJ
SentinelOne
MeteorExpress | Mysterious Wiper Paralyzes Iranian Trains with Epic Troll - SentinelLabs
In the midst of an epic troll on a country-wide railway system, we discovered a new threat actor and their reusable wiper called Meteor.
Root Cause Analysis of a Printer's Drivers Vulnerability CVE-2021-3438 - VoidSec
https://ift.tt/3ldjrXk
Submitted July 29, 2021 at 09:01PM by Void_Sec
via reddit https://ift.tt/3ib74Jt
https://ift.tt/3ldjrXk
Submitted July 29, 2021 at 09:01PM by Void_Sec
via reddit https://ift.tt/3ib74Jt
VoidSec
Root Cause Analysis of a Printer's Drivers Vulnerability CVE-2021-3438 - VoidSec
Analysis and Exploitability of a buffer overflow vulnerability present in printer's drivers (CVE-2021-3438).
Magnitude Exploit Kit: Still Alive and Kicking
https://ift.tt/3lanQKM
Submitted July 29, 2021 at 10:07PM by stashing_the_smack
via reddit https://ift.tt/3BSbZH9
https://ift.tt/3lanQKM
Submitted July 29, 2021 at 10:07PM by stashing_the_smack
via reddit https://ift.tt/3BSbZH9
Avast Threat Labs
Magnitude Exploit Kit: Still Alive and Kicking - Avast Threat Labs
The Magnitude exploit kit, originally known as PopAds, has been around since at least 2012, which is an unusually long lifetime for an exploit kit. However, it’s not the same exploit kit today that it was nine years ago. Pretty much every part of Magnitude…
Probably Are Gonna Need It: Application Security Edition
https://ift.tt/3yAvvFr
Submitted July 30, 2021 at 03:28AM by pimterry
via reddit https://ift.tt/2V6rfPX
https://ift.tt/3yAvvFr
Submitted July 30, 2021 at 03:28AM by pimterry
via reddit https://ift.tt/2V6rfPX
jacobian.org
Probably Are Gonna Need It: Application Security Edition - Jacob Kaplan-Moss
My list of “Probably Are Gonna Need It” security features for your web app – things that you should build up-front, not wait until you need them (when it’s already too late).
Malicious PyPI Packages Stealing Credit Cards and Injecting Code - Technical Analysis
https://ift.tt/3j6RZYu
Submitted July 30, 2021 at 02:09PM by securehoney
via reddit https://ift.tt/3C6eXrN
https://ift.tt/3j6RZYu
Submitted July 30, 2021 at 02:09PM by securehoney
via reddit https://ift.tt/3C6eXrN
JFrog
Python developers are being targeted with malicious packages on PyPI
JFrog finds a new supply chain attack targeting python developers using the PyPI repository
Attack AI systems in Machine Learning Evasion Competition | Microsoft Security Blog
https://ift.tt/374jNr8
Submitted July 30, 2021 at 02:47PM by AdmiralDoughnot
via reddit https://ift.tt/3zOWKge
https://ift.tt/374jNr8
Submitted July 30, 2021 at 02:47PM by AdmiralDoughnot
via reddit https://ift.tt/3zOWKge
Microsoft Security Blog
Attack AI systems in Machine Learning Evasion Competition | Microsoft Security Blog
Today, we are launching MLSEC.IO, a new machine learning security evasion competition as an educational effort for the AI and security communities to exercise their muscle to attack critical AI systems in a realistic setting.
The first 11 “Secure The Governement” vulnerability disclosure programs (DHS, FCC, UDSA, BOL, etc) are now live.
https://ift.tt/3zRbKKG
Submitted July 30, 2021 at 03:35PM by yesnet0
via reddit https://ift.tt/3fckSkS
https://ift.tt/3zRbKKG
Submitted July 30, 2021 at 03:35PM by yesnet0
via reddit https://ift.tt/3fckSkS
Bugcrowd
CISA Vulnerability Disclosure Programs | Bugcrowd | Bugcrowd
Find active vulnerability disclosure programs from the Cybersecurity & Infrastructure Security Agency. Start hunting today!
[CFP] Call for Papers for Hardwear.io Security Conference Netherlands 2021 is OPEN
https://ift.tt/3BWGKKR
Submitted July 30, 2021 at 05:20PM by hardweario
via reddit https://ift.tt/2UYUJ2q
https://ift.tt/3BWGKKR
Submitted July 30, 2021 at 05:20PM by hardweario
via reddit https://ift.tt/2UYUJ2q
hardwear.io
Hardwear.io Netherlands 2021
You Really Shouldn't Roll Your Own Crypto: An Empirical Study of Vulnerabilities in Cryptographic Libraries
https://ift.tt/3iCYRg0
Submitted July 31, 2021 at 01:16PM by digicat
via reddit https://ift.tt/3fitM0i
https://ift.tt/3iCYRg0
Submitted July 31, 2021 at 01:16PM by digicat
via reddit https://ift.tt/3fitM0i
Several techniques on non-paged pool overflow exploitation including a poc for CVE-2020-17087 (Windows Kernel Cryptography Driver) and an off-by-one overflow.
https://ift.tt/3ieH6F3
Submitted July 31, 2021 at 06:49PM by lunasalmon
via reddit https://ift.tt/3ideTOH
https://ift.tt/3ieH6F3
Submitted July 31, 2021 at 06:49PM by lunasalmon
via reddit https://ift.tt/3ideTOH
GitHub
GitHub - vp777/Windows-Non-Paged-Pool-Overflow-Exploitation: Techniques based on named pipes for pool overflow exploitation targeting…
Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087 and an off-by-one overflow - GitHub - vp777/Win...
Rotten Apples MacOS Codesigning Translocation Vulnerability
https://ift.tt/3zVm702
Submitted July 30, 2021 at 01:16AM by gh0stlazers
via reddit https://ift.tt/3CbvCds
https://ift.tt/3zVm702
Submitted July 30, 2021 at 01:16AM by gh0stlazers
via reddit https://ift.tt/3CbvCds
Department of Justice Statement on SolarWinds Update
https://ift.tt/3xgr41N
Submitted July 31, 2021 at 10:43PM by hi5eyes
via reddit https://ift.tt/2VcLqf4
https://ift.tt/3xgr41N
Submitted July 31, 2021 at 10:43PM by hi5eyes
via reddit https://ift.tt/2VcLqf4
www.justice.gov
Department of Justice Statement on SolarWinds Update
Shadow Credentials: Abusing Key Trust Account Mapping for Takeover
https://ift.tt/3gSUnRE
Submitted August 01, 2021 at 12:21PM by disclosure5
via reddit https://ift.tt/3ig1i9B
https://ift.tt/3gSUnRE
Submitted August 01, 2021 at 12:21PM by disclosure5
via reddit https://ift.tt/3ig1i9B
Medium
Shadow Credentials: Abusing Key Trust Account Mapping for Account Takeover
The techniques for DACL-based attacks against User and Computer objects in Active Directory have been established for years. If we…
Github phath0m/JadedWraith - New light-weight ICMP backdoor for UNIX systems
https://ift.tt/3yhL7xT
Submitted August 01, 2021 at 12:35AM by unphath0mable
via reddit https://ift.tt/3llx72r
https://ift.tt/3yhL7xT
Submitted August 01, 2021 at 12:35AM by unphath0mable
via reddit https://ift.tt/3llx72r
GitHub
GitHub - phath0m/JadedWraith: Light-weight UNIX backdoor
Light-weight UNIX backdoor. Contribute to phath0m/JadedWraith development by creating an account on GitHub.