If you copied any of these popular StackOverflow encryption code snippets, then you coded it wrong
https://ift.tt/3hBpm5R
Submitted September 16, 2021 at 05:34AM by ScottContini
via reddit https://ift.tt/2XmhyOn
https://ift.tt/3hBpm5R
Submitted September 16, 2021 at 05:34AM by ScottContini
via reddit https://ift.tt/2XmhyOn
Little Man In My Head
If you copied any of these popular StackOverflow encryption code snippets, then you coded it wrong
Security code reviews is a task that I do on a daily basis, and have been doing for the last thirteen and a half years. In this time, I have reviewed several hundred code bases, and have come acros…
RCE Proof of Concept for CVE-2021-38647 (OMIGOD)
https://ift.tt/2Z59vWX
Submitted September 16, 2021 at 04:26PM by scopedsecurity
via reddit https://ift.tt/2Xo1w6k
https://ift.tt/2Z59vWX
Submitted September 16, 2021 at 04:26PM by scopedsecurity
via reddit https://ift.tt/2Xo1w6k
Beyond rubber ducky: evil mass storage POC with AT90USBKEY2. malware-tool for offline system. USB composite device with keyboard + mass storage + exfiltration via radio.
https://ift.tt/3CkYLC0
Submitted September 17, 2021 at 12:37AM by Dreg_fr33project
via reddit https://ift.tt/3CoR3qN
https://ift.tt/3CkYLC0
Submitted September 17, 2021 at 12:37AM by Dreg_fr33project
via reddit https://ift.tt/3CoR3qN
Driverentry
evil mass storage - roapt v1 AT90USBKEY2 | DriverEntry
LAST UPDATE: 2021-09-15
WARNING: this is a DIY-POC just for fun and the code is pure crap x-), btw my english sucks and I am a hardware noob.
This is the official post to ask about this project.
my evill mass storage its a USB DEVICE with the following…
WARNING: this is a DIY-POC just for fun and the code is pure crap x-), btw my english sucks and I am a hardware noob.
This is the official post to ask about this project.
my evill mass storage its a USB DEVICE with the following…
Public SharePoint sites – the new open smb shares
https://ift.tt/39ayObZ
Submitted September 17, 2021 at 12:36AM by rikvduijn
via reddit https://ift.tt/2Xl5i0o
https://ift.tt/39ayObZ
Submitted September 17, 2021 at 12:36AM by rikvduijn
via reddit https://ift.tt/2Xl5i0o
Zolder - Applied Security Research
Public SharePoint sites - the new open shares | Zolder - Applied Security Research
During one of our engagements we were investigating a Microsoft 365 environment. My colleague Rik discovered that many SharePoint sites...
On Flask, Semgrep, and Secure Coding
https://ift.tt/3tTT5fl
Submitted September 17, 2021 at 01:20AM by iterablewords
via reddit https://ift.tt/2YV1io2
https://ift.tt/3tTT5fl
Submitted September 17, 2021 at 01:20AM by iterablewords
via reddit https://ift.tt/2YV1io2
Medium
On Flask, Semgrep, and Secure Coding
First steps with Flask and Static Code Analysis with Semgrep
Edition 8 talks about measurable alternatives to AppSec training (bonus: a mini-rant on AppSec standards)
https://ift.tt/3lCOIlc
Submitted September 19, 2021 at 06:37PM by jubbaonjeans
via reddit https://ift.tt/3nN2MLB
https://ift.tt/3lCOIlc
Submitted September 19, 2021 at 06:37PM by jubbaonjeans
via reddit https://ift.tt/3nN2MLB
VaultBoot: "Next-Gen" Firmware Security
https://ift.tt/2ZdTw95
Submitted September 19, 2021 at 09:38PM by hardenedvault
via reddit https://ift.tt/39k9hNG
https://ift.tt/2ZdTw95
Submitted September 19, 2021 at 09:38PM by hardenedvault
via reddit https://ift.tt/39k9hNG
ZeroTier Advisory - Multiple vulnerabilities allowing private network access
https://ift.tt/39pkWdK
Submitted September 20, 2021 at 08:22AM by MysteriousHotel3017
via reddit https://ift.tt/3u1oGf9
https://ift.tt/39pkWdK
Submitted September 20, 2021 at 08:22AM by MysteriousHotel3017
via reddit https://ift.tt/3u1oGf9
Pulse Security
Zerotier - Multiple Vulnerabilities
Zerotier - Multiple vulnerabilities leading to identity hijacking and unauthorised private network access.
Security: Bitwarden Desktop app grants RCE
https://ift.tt/35WfApZ
Submitted September 20, 2021 at 02:44PM by HiImAlexXD
via reddit https://ift.tt/2XtUSvt
https://ift.tt/35WfApZ
Submitted September 20, 2021 at 02:44PM by HiImAlexXD
via reddit https://ift.tt/2XtUSvt
GitHub
Security: Bitwarden Desktop app grants RCE to Bitwarden developers. · Issue #552 · bitwarden/desktop
Describe the Bug The Bitwarden Desktop app automatically downloads updates and replaces its own code with those updates, without user intervention, which is then executed on the next launch of the ...
Telegram is increasingly used for buying and selling data leaks because it’s user-friendly and not thoroughly moderated. - by Cyberint
https://ift.tt/3kp6ZmH
Submitted September 20, 2021 at 05:07PM by Affectionate-Fall520
via reddit https://ift.tt/3zplsmR
https://ift.tt/3kp6ZmH
Submitted September 20, 2021 at 05:07PM by Affectionate-Fall520
via reddit https://ift.tt/3zplsmR
List of Ransomware Vulnerabilities being actively targeted
https://ift.tt/3nOwkZe
Submitted September 20, 2021 at 06:44PM by SpawnDnD
via reddit https://ift.tt/3EzvS7i
https://ift.tt/3nOwkZe
Submitted September 20, 2021 at 06:44PM by SpawnDnD
via reddit https://ift.tt/3EzvS7i
TruffleHog The Chrome Extension
https://ift.tt/3hOwfkG
Submitted September 20, 2021 at 06:58PM by wifihack
via reddit https://ift.tt/3CtnVyn
https://ift.tt/3hOwfkG
Submitted September 20, 2021 at 06:58PM by wifihack
via reddit https://ift.tt/3CtnVyn
Tutorial: Return-to-libc
https://ift.tt/3nTdL68
Submitted September 21, 2021 at 01:33PM by Kondencuotaspienas
via reddit https://ift.tt/3EzxSfD
https://ift.tt/3nTdL68
Submitted September 21, 2021 at 01:33PM by Kondencuotaspienas
via reddit https://ift.tt/3EzxSfD
SSD Advisory – macOS Finder RCE: A vulnerability in macOS Finder system allows remote attackers to trick users into running arbitrary commands.
https://ift.tt/2VW9q6E
Submitted September 21, 2021 at 03:40PM by SSDisclosure
via reddit https://ift.tt/3tW0Wcr
https://ift.tt/2VW9q6E
Submitted September 21, 2021 at 03:40PM by SSDisclosure
via reddit https://ift.tt/3tW0Wcr
SSD Secure Disclosure
SSD Advisory – macOS Finder RCE - SSD Secure Disclosure
Find out how a vulnerability in macOS Finder system allows remote attackers to trick users into running arbitrary commands.
The First and Last Time AIM Was Hacked
https://ift.tt/3AwHq8J
Submitted September 21, 2021 at 06:40PM by endless
via reddit https://ift.tt/3CudGde
https://ift.tt/3AwHq8J
Submitted September 21, 2021 at 06:40PM by endless
via reddit https://ift.tt/3CudGde
Livejournal
the first and last time AIM was hacked
im an AOL hacker historian. no doubt about it. i remember intimate details about most of the major breaches that occurred between the mid 90s and 2000s. i was there and actively participating in most of it. america onlines security was being compromised nonstop.…
Google to Auto-Reset Inactive Android App Permissions for Billions of Devices
https://ift.tt/2XK5fvG
Submitted September 21, 2021 at 06:33PM by Affectionate-Fall520
via reddit https://ift.tt/2XPn9Ns
https://ift.tt/2XK5fvG
Submitted September 21, 2021 at 06:33PM by Affectionate-Fall520
via reddit https://ift.tt/2XPn9Ns
The 2021 National Internet Segment Reliability Research
https://ift.tt/3nUnlpy
Submitted September 21, 2021 at 09:06PM by shapelez
via reddit https://ift.tt/2XCsRlC
https://ift.tt/3nUnlpy
Submitted September 21, 2021 at 09:06PM by shapelez
via reddit https://ift.tt/2XCsRlC
blog.qrator.net
Blog — The 2021 National Internet Segment Reliability Research
Examining a case when an AS experiences network degradation, we want to answer the following question: “How many AS’s in the same region would lose connectivity with Tier-1 operators and their global availability along with it?”
OM I GOOD? We developed a flexible scanner you can use to inspect your Azure infrastructure and understand if you are exposed to OMIGOD, the OMI security vulnerabilities. Feedback and suggestions are welcome. Enjoy!
https://ift.tt/3Cxos2j
Submitted September 21, 2021 at 02:12PM by _marcosim_
via reddit https://ift.tt/3CzqaQM
https://ift.tt/3Cxos2j
Submitted September 21, 2021 at 02:12PM by _marcosim_
via reddit https://ift.tt/3CzqaQM
CVE-2021-38112: AWS WorkSpaces Remote Code Execution
https://ift.tt/3u2enaS
Submitted September 21, 2021 at 09:28PM by hackers_and_builders
via reddit https://ift.tt/3CDsczD
https://ift.tt/3u2enaS
Submitted September 21, 2021 at 09:28PM by hackers_and_builders
via reddit https://ift.tt/3CDsczD
Mama Always Told Me Not to Trust Strangers without Certificates (Moar Netgear Pwnage)
https://ift.tt/3ECG3rE
Submitted September 21, 2021 at 09:21PM by pocorgtfoftw
via reddit https://ift.tt/3hTAr2r
https://ift.tt/3ECG3rE
Submitted September 21, 2021 at 09:21PM by pocorgtfoftw
via reddit https://ift.tt/3hTAr2r
CVSS 9.8 vulnerabilities in vmware vCenter Server
https://ift.tt/2Z9j86U
Submitted September 22, 2021 at 01:49AM by Brumhartt
via reddit https://ift.tt/3nRtHpC
https://ift.tt/2Z9j86U
Submitted September 22, 2021 at 01:49AM by Brumhartt
via reddit https://ift.tt/3nRtHpC
VMware
VMSA-2021-0020.1
VMware vCenter Server updates address multiple security vulnerabilities