VaultFuzzer: A state-based approach for Linux kernel
https://ift.tt/3E6XUGZ
Submitted September 13, 2021 at 05:57PM by hardenedvault
via reddit https://ift.tt/3AaMYWh
https://ift.tt/3E6XUGZ
Submitted September 13, 2021 at 05:57PM by hardenedvault
via reddit https://ift.tt/3AaMYWh
Frans Rosen does it again: "Hacking CloudKit - How I accidentally deleted your Apple Shortcuts"
https://ift.tt/3k4IiLV
Submitted September 13, 2021 at 07:47PM by intheclairdelune
via reddit https://ift.tt/38ZPzXj
https://ift.tt/3k4IiLV
Submitted September 13, 2021 at 07:47PM by intheclairdelune
via reddit https://ift.tt/38ZPzXj
Vermilion Strike: Linux and Windows Re-implementation of Cobalt Strike
https://ift.tt/3hoOJYA
Submitted September 13, 2021 at 10:47PM by notemaker
via reddit https://ift.tt/3A7L6xG
https://ift.tt/3hoOJYA
Submitted September 13, 2021 at 10:47PM by notemaker
via reddit https://ift.tt/3A7L6xG
Easily Exploitable Critical Vulnerability in ProfilePress Plugin of WordPress CVE-2021-34621
https://ift.tt/3lnFV6j
Submitted September 13, 2021 at 10:44PM by SL7reach
via reddit https://ift.tt/2XduaHx
https://ift.tt/3lnFV6j
Submitted September 13, 2021 at 10:44PM by SL7reach
via reddit https://ift.tt/2XduaHx
Penetration Testing and CyberSecurity Solution - SecureLayer7
Easily Exploitable Critical Vulnerability in ProfilePress Plugin of WordPress CVE-2021-34621
Understanding the Vulnerability ProfilePress, formerly WP User Avatar, a WordPress plugin installed on over 400,000 sites made it possible for an attacker to upload arbitrary files to a vulnerable site and register as an administrator on sites even if user…
Account Persistence – Certificates
https://ift.tt/3C98XO8
Submitted September 14, 2021 at 12:33AM by netbiosX
via reddit https://ift.tt/3919Dsc
https://ift.tt/3C98XO8
Submitted September 14, 2021 at 12:33AM by netbiosX
via reddit https://ift.tt/3919Dsc
Penetration Testing Lab
Account Persistence – Certificates
It is not uncommon organizations to implement an internal certification authority in order to establish trust between entities (users, computers etc.) or utilize it for user authentication. Impleme…
FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild - The Citizen Lab
https://ift.tt/2XdSRDJ
Submitted September 14, 2021 at 01:21AM by kickinitlegit
via reddit https://ift.tt/3nuj9wr
https://ift.tt/2XdSRDJ
Submitted September 14, 2021 at 01:21AM by kickinitlegit
via reddit https://ift.tt/3nuj9wr
The Citizen Lab
FORCEDENTRY
While analyzing the phone of a Saudi activist infected with NSO Group’s Pegasus spyware, we discovered a zero-day zero-click exploit against iMessage. The exploit, which we call FORCEDENTRY, targets Apple’s image rendering library, and was effective against…
The Show Must Go On: Securing Netflix Studios At Scale
https://ift.tt/3z7fzL0
Submitted September 14, 2021 at 03:34AM by WaffleLight
via reddit https://ift.tt/3AcKQxa
https://ift.tt/3z7fzL0
Submitted September 14, 2021 at 03:34AM by WaffleLight
via reddit https://ift.tt/3AcKQxa
Medium
The Show Must Go On: Securing Netflix Studios At Scale
A Journey About Productizing Security
How to Defend Yourself Against NSO Spyware Like Pegasus
https://ift.tt/371p2aY
Submitted September 14, 2021 at 08:03AM by moxofoxo
via reddit https://ift.tt/394tc2R
https://ift.tt/371p2aY
Submitted September 14, 2021 at 08:03AM by moxofoxo
via reddit https://ift.tt/394tc2R
The Intercept
How to Defend Yourself Against the Powerful New NSO Spyware Attacks Discovered Around the World
Even iPhones were vulnerable to the surveillance software, which appears to have been used against activists, journalists, and others.
Silently Unmasking Virgin Media VPN Users in Seconds (CVE-2019-16651)
https://ift.tt/3Cd7sy7
Submitted September 14, 2021 at 03:31PM by kurtisebear
via reddit https://ift.tt/3Cd7t59
https://ift.tt/3Cd7sy7
Submitted September 14, 2021 at 03:31PM by kurtisebear
via reddit https://ift.tt/3Cd7t59
Pardus 21 Linux Distro – Remote Code Execution due to Insecure Tar Extraction
https://ift.tt/3hraHKB
Submitted September 14, 2021 at 05:05PM by wtfse
via reddit https://ift.tt/3z9FVfa
https://ift.tt/3hraHKB
Submitted September 14, 2021 at 05:05PM by wtfse
via reddit https://ift.tt/3z9FVfa
Unauthenticated Remote Code Execution in Motorola Baby Monitors [FIXED]
https://ift.tt/3AeOR4j
Submitted September 14, 2021 at 05:47PM by rwestergren
via reddit https://ift.tt/3EjkaNJ
https://ift.tt/3AeOR4j
Submitted September 14, 2021 at 05:47PM by rwestergren
via reddit https://ift.tt/3EjkaNJ
Randy Westergren
Unauthenticated Remote Code Execution in Motorola Baby Monitors - Randy Westergren
When my wife and I were expecting our first child, a good baby monitor was one of the top items on our shopping list. Most of the available options of course now include Wi-Fi, a mobile app, and cloud integration. When we decided on the Motorola Halo+, I…
Discovering Vulnerabilities in Avaya Aura | Accenture
https://ift.tt/2VEPlBI
Submitted September 14, 2021 at 07:09PM by rkornmeyer
via reddit https://ift.tt/3lphwxu
https://ift.tt/2VEPlBI
Submitted September 14, 2021 at 07:09PM by rkornmeyer
via reddit https://ift.tt/3lphwxu
Patch Tuesday: Critical Vulnerabilities in OMI Affecting Countless Azure Customers
https://ift.tt/3tGaMih
Submitted September 15, 2021 at 12:13AM by sagitz_
via reddit https://ift.tt/3tHDBv1
https://ift.tt/3tGaMih
Submitted September 15, 2021 at 12:13AM by sagitz_
via reddit https://ift.tt/3tHDBv1
Meterpreter spotted via real-time kernel monitoring
https://ift.tt/2X0SbBW
Submitted September 15, 2021 at 12:02AM by 0xDangerous_bit
via reddit https://ift.tt/3kblTNb
https://ift.tt/2X0SbBW
Submitted September 15, 2021 at 12:02AM by 0xDangerous_bit
via reddit https://ift.tt/3kblTNb
CounterCraft
Shellcode Detection Using Real-time Kernel Monitoring
Looking at how to use real time kernel monitoring for shellcode detection. Alonso Candado discusses the challenges faced when trying to detect shellcode at runtime, usin the examples of hooking syscalls via hypervisor EPT feature and detecting shellcodes…
Kali Linux 2021.3 Release
https://ift.tt/3hrG5sr
Submitted September 15, 2021 at 12:48AM by eikendev
via reddit https://ift.tt/3EeVIx3
https://ift.tt/3hrG5sr
Submitted September 15, 2021 at 12:48AM by eikendev
via reddit https://ift.tt/3EeVIx3
Kali Linux
Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch) | Kali Linux Blog
Today we have released the newest version of Kali Linux, 2021.3 (quarter #3), which is now ready for download or updating.
A summary of the changes since the 2021.2 release from June are:
OpenSSL - Wide compatibility by default - Keep reading for what that…
A summary of the changes since the 2021.2 release from June are:
OpenSSL - Wide compatibility by default - Keep reading for what that…
Obfuscating Malicious, Macro-Enabled Word Docs
https://ift.tt/3tEMuoS
Submitted September 15, 2021 at 01:13AM by fang0654
via reddit https://ift.tt/3k668XL
https://ift.tt/3tEMuoS
Submitted September 15, 2021 at 01:13AM by fang0654
via reddit https://ift.tt/3k668XL
Depthsecurity
Obfuscating Malicious, Macro-Enabled Word Docs
Overview
I was working on my OSEP certification when I was inspired to stop studying for a bit to deep-dive into malicious word documents. The OSEP certification inspired a lot of the content you
I was working on my OSEP certification when I was inspired to stop studying for a bit to deep-dive into malicious word documents. The OSEP certification inspired a lot of the content you
Research Programmer - Information Trust Institute, The Grainger College of Engineering, University of Illinois Urbana-Champaign
https://ift.tt/3zclr5E
Submitted September 15, 2021 at 02:20AM by uiuc_coe
via reddit https://ift.tt/3nxM2If
https://ift.tt/3zclr5E
Submitted September 15, 2021 at 02:20AM by uiuc_coe
via reddit https://ift.tt/3nxM2If
DOM-Fuzzing in a online browser-based environment with domato from Google
https://ift.tt/3z6LURT
Submitted September 15, 2021 at 02:56AM by Human_Readable
via reddit https://ift.tt/2XhLg7z
https://ift.tt/3z6LURT
Submitted September 15, 2021 at 02:56AM by Human_Readable
via reddit https://ift.tt/2XhLg7z
PetitPotam – NTLM Relay to AD CS
https://ift.tt/3CcEtuw
Submitted September 15, 2021 at 09:19PM by netbiosX
via reddit https://ift.tt/3kbqrD3
https://ift.tt/3CcEtuw
Submitted September 15, 2021 at 09:19PM by netbiosX
via reddit https://ift.tt/3kbqrD3
Penetration Testing Lab
PetitPotam – NTLM Relay to AD CS
Deployment of an Active Directory Certificate Services (AD CS) on a corporate environment could allow system administrators to utilize it for establishing trust between different directory objects.…
Deus x64: a new series of binary exploitation challenges by RET2 Systems
https://deusx64.ai/
Submitted September 15, 2021 at 10:07PM by gaasedelen
via reddit https://ift.tt/3Cu5c67
https://deusx64.ai/
Submitted September 15, 2021 at 10:07PM by gaasedelen
via reddit https://ift.tt/3Cu5c67
Deus x64 | RET2 Systems
Deus x64 is an upcoming computer security and binary exploitation wargame by RET2 Systems
Penelope Shell Handler: A single noscript that automatically upgrades plain shells to TTY and also does much more.
https://ift.tt/3hyqYgN
Submitted September 14, 2021 at 09:43PM by therealbrightio
via reddit https://ift.tt/2Z5kC2h
https://ift.tt/3hyqYgN
Submitted September 14, 2021 at 09:43PM by therealbrightio
via reddit https://ift.tt/2Z5kC2h
GitHub
GitHub - brightio/penelope: Penelope Shell Handler
Penelope Shell Handler. Contribute to brightio/penelope development by creating an account on GitHub.