Advisory: Cisco ATA19X Privilege Escalation and RCE - IoT Inspector
https://ift.tt/3BkV53l
Submitted October 07, 2021 at 04:16PM by g_e_r_h_a_r_d
via reddit https://ift.tt/2ZYJ6ud
https://ift.tt/3BkV53l
Submitted October 07, 2021 at 04:16PM by g_e_r_h_a_r_d
via reddit https://ift.tt/2ZYJ6ud
IoT Inspector
Advisory: Cisco ATA19X Privilege Escalation and RCE - IoT Inspector
We found lacking user privilege separation enforcement and post-authentication command injection remote code execution within Cisco ATA19X firmware.
Introducing Shisho Cloud: Autofixes for Your Infrastructure as Code are Just a Click Away - Shisho Blog
https://ift.tt/3Di7uWk
Submitted October 07, 2021 at 04:48PM by oigong
via reddit https://ift.tt/3DhfarK
https://ift.tt/3Di7uWk
Submitted October 07, 2021 at 04:48PM by oigong
via reddit https://ift.tt/3DhfarK
Shisho Cloud - IaC security automation for developers
Introducing Shisho Cloud: Autofixes for Your Infrastructure as Code are Just a Click Away - Shisho Blog
Today we are introducing Shisho Cloud, a SaaS solution that supports an entire process of improving your infrastructure-as-code security with intelligent autofixes of security issues.Securing Infrastr...
Announcing osquery 5: Now with EndpointSecurity on macOS
https://ift.tt/3ljFLOR
Submitted October 07, 2021 at 06:51PM by yossarian_flew_away
via reddit https://ift.tt/3llTPHE
https://ift.tt/3ljFLOR
Submitted October 07, 2021 at 06:51PM by yossarian_flew_away
via reddit https://ift.tt/3llTPHE
The Trail of Bits Blog
Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and products. We combine high-end security research with a real world attacker mentality to reduce risk and fortify code.
Kape Technologies and ExpressVPN's new owner Teddy Sagi avoids assassination by the Russian mafia
https://ift.tt/3Fe18ZS
Submitted October 07, 2021 at 09:04PM by MaleficentYellow3
via reddit https://ift.tt/3Afdmh2
https://ift.tt/3Fe18ZS
Submitted October 07, 2021 at 09:04PM by MaleficentYellow3
via reddit https://ift.tt/3Afdmh2
The Jerusalem Post
Israeli businessmen targeted by attempted assassinations in Cyprus
Israeli businessmen were reportedly targeted by an assassin in Cyprus who was caught. Targeted Israeli businessman Teddy Sagi's company has called the incident Iranian terror.
weggli: fast and robust semantic search tool for C and C++ codebases
https://ift.tt/3zR0wp7
Submitted October 07, 2021 at 09:45PM by 0xdea
via reddit https://ift.tt/3FtQq18
https://ift.tt/3zR0wp7
Submitted October 07, 2021 at 09:45PM by 0xdea
via reddit https://ift.tt/3FtQq18
GitHub
GitHub - weggli-rs/weggli: weggli is a fast and robust semantic search tool for C and C++ codebases. It is designed to help security…
weggli is a fast and robust semantic search tool for C and C++ codebases. It is designed to help security researchers identify interesting functionality in large codebases. - weggli-rs/weggli
kdigger: a Context Discovery Tool for Kubernetes Security Audits
https://ift.tt/2ZW31tM
Submitted October 07, 2021 at 10:58PM by guedou
via reddit https://ift.tt/3mzDbUg
https://ift.tt/2ZW31tM
Submitted October 07, 2021 at 10:58PM by guedou
via reddit https://ift.tt/3mzDbUg
Quarkslab
kdigger: a Context Discovery Tool for Kubernetes
The Security Engineer Handbook
https://ift.tt/3tuharu
Submitted October 08, 2021 at 01:09AM by davidw_-
via reddit https://ift.tt/3uTfOc8
https://ift.tt/3tuharu
Submitted October 08, 2021 at 01:09AM by davidw_-
via reddit https://ift.tt/3uTfOc8
reddit
The Security Engineer Handbook
Posted in r/netsec by u/davidw_- • 0 points and 1 comment
Fleet 4.4.0 releases aggregated software inventory, team policies, and improved team scheduling.
https://ift.tt/3uPgBe1
Submitted October 08, 2021 at 04:10AM by Silly-Pop-7437
via reddit https://ift.tt/3ak8j4c
https://ift.tt/3uPgBe1
Submitted October 08, 2021 at 04:10AM by Silly-Pop-7437
via reddit https://ift.tt/3ak8j4c
Medium
Fleet 4.4.0 releases aggregated software inventory, team policies, and improved team scheduling.
Today we are excited to announce the release of Fleet 4.4.0 which brings new and improved features for our osquery and Fleet users.
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.51 (incomplete fix of CVE-2021-41773)
https://ift.tt/3lkb9MY
Submitted October 08, 2021 at 06:18AM by Gallus
via reddit https://ift.tt/3mCl3sC
https://ift.tt/3lkb9MY
Submitted October 08, 2021 at 06:18AM by Gallus
via reddit https://ift.tt/3mCl3sC
httpd.apache.org
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
CTO (Call Tree Overviewer): An IDA plugin for creating a simple and efficient function call tree graph
https://ift.tt/3lpqoEB
Submitted October 08, 2021 at 02:57PM by Titokhan
via reddit https://ift.tt/2YtfHI6
https://ift.tt/3lpqoEB
Submitted October 08, 2021 at 02:57PM by Titokhan
via reddit https://ift.tt/2YtfHI6
GitHub
GitHub - herosi/CTO: Call Tree Overviewer
Call Tree Overviewer. Contribute to herosi/CTO development by creating an account on GitHub.
Reverse engineering and decrypting CyberArk vault credential files
https://ift.tt/3FtKWUj
Submitted October 09, 2021 at 12:13AM by digicat
via reddit https://ift.tt/3iKbFlM
https://ift.tt/3FtKWUj
Submitted October 09, 2021 at 12:13AM by digicat
via reddit https://ift.tt/3iKbFlM
NCC Group Research
Reverse engineering and decrypting CyberArk vault credential files
This blog will be a technical deep-dive into CyberArk credential files and how the credentials stored in these files are encrypted and decrypted. I discovered it was possible to reverse engineer the encryption and key generation algorithms and decrypt the…
HOW TO DEFEAT THE RUSSIAN DUKES: A STEP-BY-STEP ANALYSIS OF MINIDUKE USED BY APT29/COZY BEAR
https://ift.tt/3BtFm1S
Submitted October 09, 2021 at 11:16PM by CyberMasterV
via reddit https://ift.tt/3ADky6Z
https://ift.tt/3BtFm1S
Submitted October 09, 2021 at 11:16PM by CyberMasterV
via reddit https://ift.tt/3ADky6Z
Made a small suite of tools for generating personalized wordlists for password attacks
https://ift.tt/2YAcNkx
Submitted October 10, 2021 at 02:06PM by antfigunio
via reddit https://ift.tt/2YyrzZo
https://ift.tt/2YAcNkx
Submitted October 10, 2021 at 02:06PM by antfigunio
via reddit https://ift.tt/2YyrzZo
reddit
Made a small suite of tools for generating personalized wordlists...
Posted in r/netsec by u/antfigunio • 163 points and 6 comments
Understanding CVE-2019-9053
https://ift.tt/3Dn7PH4
Submitted October 10, 2021 at 10:06PM by pythonpsycho1337
via reddit https://ift.tt/302nblV
https://ift.tt/3Dn7PH4
Submitted October 10, 2021 at 10:06PM by pythonpsycho1337
via reddit https://ift.tt/302nblV
CVE Analyses
CVE-2019-9053
Background This weekend I was doing some HTB machines to prepare for the OSWE certification. One of the recommended machines was Writeup. This machine is vulnerable to CVE-2019-9053 which has a corresponding exploit on Exploit-DB.
Trying something new. Starting today, will try and write a primer on SAST for the next 4 weeks. Today's edition is an overview of what SAST is and why need it.
https://ift.tt/3ltedqk
Submitted October 10, 2021 at 11:33PM by jubbaonjeans
via reddit https://ift.tt/2YzfxiP
https://ift.tt/3ltedqk
Submitted October 10, 2021 at 11:33PM by jubbaonjeans
via reddit https://ift.tt/2YzfxiP
Substack
Edition 11: AppSec Primer - SAST - Part 1
First in a four part primer on Static Application Security Testing (SAST). This edition talks about what SAST is and why it's needed.
Pithus: A free and open-source mobile threat intelligence platform
https://ift.tt/3FB0jdB
Submitted October 11, 2021 at 02:52PM by Titokhan
via reddit https://ift.tt/3DqM5dx
https://ift.tt/3FB0jdB
Submitted October 11, 2021 at 02:52PM by Titokhan
via reddit https://ift.tt/3DqM5dx
Reddit
From the netsec community on Reddit: Pithus: A free and open-source mobile threat intelligence platform
Posted by Titokhan - 164 votes and 0 comments
EDRHunt: Detect EDRs installed on Windows endpoints.
https://ift.tt/3AqOTp2
Submitted October 11, 2021 at 04:55PM by FourCoreLabs
via reddit https://ift.tt/2X1jLyK
https://ift.tt/3AqOTp2
Submitted October 11, 2021 at 04:55PM by FourCoreLabs
via reddit https://ift.tt/2X1jLyK
GitHub
GitHub - FourCoreLabs/EDRHunt: Scan installed EDRs and AVs on Windows
Scan installed EDRs and AVs on Windows. Contribute to FourCoreLabs/EDRHunt development by creating an account on GitHub.
GHSL-2021-1012: Poor random number generation in keypair - CVE-2021-41117
https://ift.tt/3BwMcnn
Submitted October 11, 2021 at 11:21PM by Photogurt
via reddit https://ift.tt/3oMiaIG
https://ift.tt/3BwMcnn
Submitted October 11, 2021 at 11:21PM by Photogurt
via reddit https://ift.tt/3oMiaIG
GitHub Security Lab
GHSL-2021-1012: Poor random number generation in keypair - CVE-2021-41117
keypair implements a lot of cryptographic primitives on its own or by borrowing from other libraries where possible, including node-forge. An issue was discovered where this library was generating identical RSA keys used in SSH. This would mean that the library…
How cyberattacks are changing according to new Microsoft Digital Defense Report
https://ift.tt/3mIKclD
Submitted October 12, 2021 at 02:01AM by SCI_Rusher
via reddit https://ift.tt/3AAGfnU
https://ift.tt/3mIKclD
Submitted October 12, 2021 at 02:01AM by SCI_Rusher
via reddit https://ift.tt/3AAGfnU
Search - Microsoft Bing
Where cultures converge
The Mosque-Cathedral of Córdoba is a chronicle of
Hacking YouTube with a MP4
https://ift.tt/3oSA2l2
Submitted October 12, 2021 at 09:08AM by Gallus
via reddit https://ift.tt/3oT39oz
https://ift.tt/3oSA2l2
Submitted October 12, 2021 at 09:08AM by Gallus
via reddit https://ift.tt/3oT39oz
realkeyboardwarrior.github.io
Keyboard Warrior - Breaking software is just finding unintended features, right?
Keyboard Warrior, Breaking software is just finding unintended features, right?
Relational databases aren’t dinosaurs, they’re sharks
https://ift.tt/3s3Is92
Submitted October 12, 2021 at 01:50PM by thetughum
via reddit https://ift.tt/3v1vCtk
https://ift.tt/3s3Is92
Submitted October 12, 2021 at 01:50PM by thetughum
via reddit https://ift.tt/3v1vCtk
Simple Thread
Relational Databases Aren’t Dinosaurs, They’re Sharks
Oh relational databases, that tired old relic of another age. Codd and friends were great in their time, but serious software engineers need to move on. People building Web Scale™ software You’ve probably heard a similar sentiment at some point. That relational…