Cisco Cert Giveaway
https://ift.tt/3BhJwsL
Submitted October 27, 2021 at 05:31AM by rockintrix
via reddit https://ift.tt/3nu8ekU
https://ift.tt/3BhJwsL
Submitted October 27, 2021 at 05:31AM by rockintrix
via reddit https://ift.tt/3nu8ekU
Cisco
Cybersecurity Giveaway
Calling all Cyber Defenders. Enter our Cybersecurity Giveaway now for your chance to win a training and exam bundle to get you ready for either Cisco Certified CyberOps Associate, CyberOps Professional or CCNP Security certifications.
How to exploit a double free vulnerability in 2021
https://ift.tt/3GoU9hh
Submitted October 27, 2021 at 03:03PM by vonadz
via reddit https://ift.tt/3Bgqpzb
https://ift.tt/3GoU9hh
Submitted October 27, 2021 at 03:03PM by vonadz
via reddit https://ift.tt/3Bgqpzb
GitHub
GitHub - stong/how-to-exploit-a-double-free: How to exploit a double free vulnerability in 2021. 'Use After Free for Dummies'
How to exploit a double free vulnerability in 2021. 'Use After Free for Dummies' - GitHub - stong/how-to-exploit-a-double-free: How to exploit a double free vulnerability in 2021. &...
Container security best practices: Comprehensive guide
https://ift.tt/3mQV5Sq
Submitted October 27, 2021 at 07:57PM by MiguelHzBz
via reddit https://ift.tt/3BmOGDP
https://ift.tt/3mQV5Sq
Submitted October 27, 2021 at 07:57PM by MiguelHzBz
via reddit https://ift.tt/3BmOGDP
Sysdig
Container security best practices: Comprehensive guide – Sysdig
Container security best practices include the full component stack used for building, distributing, and specifically executing the container.
GoCD pre-auth secret leakage
https://ift.tt/3be6tCn
Submitted October 27, 2021 at 10:11PM by websecdev
via reddit https://ift.tt/3BfGuFf
https://ift.tt/3be6tCn
Submitted October 27, 2021 at 10:11PM by websecdev
via reddit https://ift.tt/3BfGuFf
Sonarsource
Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD
We recently discovered critical security issues in the popular CI/CD solution GoCD that can be exploited by unauthenticated attackers
Writing a SQLMap tamper for Google Protobuf - @APTortellini
https://ift.tt/3bhfwCJ
Submitted October 28, 2021 at 01:38AM by last0x00
via reddit https://ift.tt/3GDsA3U
https://ift.tt/3bhfwCJ
Submitted October 28, 2021 at 01:38AM by last0x00
via reddit https://ift.tt/3GDsA3U
APT::WTF - APTortellini’s blog
Tortellini in Brodobuf
Home of the Advanced Persistent Tortellini - aka APTortellini, an Italian collective of hackers publishing technical research regarding offensive security.
Using Kerberos for Authentication Relay Attacks
https://ift.tt/3B3ELCT
Submitted October 28, 2021 at 11:08AM by 0xdea
via reddit https://ift.tt/3EnLPfH
https://ift.tt/3B3ELCT
Submitted October 28, 2021 at 11:08AM by 0xdea
via reddit https://ift.tt/3EnLPfH
Blogspot
Using Kerberos for Authentication Relay Attacks
Posted by James Forshaw, Project Zero This blog post is a summary of some research I've been doing into relaying Kerberos authentica...
Unauthenticated RCE vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)
https://ift.tt/3u393nv
Submitted October 28, 2021 at 12:40PM by Gallus
via reddit https://ift.tt/3nA4oGS
https://ift.tt/3u393nv
Submitted October 28, 2021 at 12:40PM by Gallus
via reddit https://ift.tt/3nA4oGS
Watchful_IP
Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)
This article has been written for a technical audience.
Finding gadgets like it's 2015: part 1
https://ift.tt/3pLXGA3
Submitted October 28, 2021 at 03:00PM by Gallus
via reddit https://ift.tt/2XVBTdW
https://ift.tt/3pLXGA3
Submitted October 28, 2021 at 03:00PM by Gallus
via reddit https://ift.tt/2XVBTdW
Synacktiv
Finding gadgets like it's 2015: part 1
We found a new Java gadget chain in the Mojarra library, one of the most used implementation of the JSF specification.
Impacket v0.9.24 Released 🎉
https://ift.tt/3jMIvCZ
Submitted October 28, 2021 at 07:23PM by mgalloar
via reddit https://ift.tt/3EmsGec
https://ift.tt/3jMIvCZ
Submitted October 28, 2021 at 07:23PM by mgalloar
via reddit https://ift.tt/3EmsGec
SecureAuth
Impacket v0.9.24 Released
Here at SecureAuth, we’re excited to announce the release of the latest version of Impacket, our collection of Python classes for working with network protocols, and much more. Impacket release 0.9.24 is available today and includes a lot of new features…
Solarmarker In-Depth Analysis
https://ift.tt/3pM7OsL
Submitted October 28, 2021 at 08:43PM by Egesploit
via reddit https://ift.tt/2Zy9Lyq
https://ift.tt/3pM7OsL
Submitted October 28, 2021 at 08:43PM by Egesploit
via reddit https://ift.tt/2Zy9Lyq
NGINX Custom Snippets CVE-2021-25742 Deep Dive
https://ift.tt/3w1nVE0
Submitted October 28, 2021 at 04:30PM by gafnita
via reddit https://ift.tt/3jGwuyY
https://ift.tt/3w1nVE0
Submitted October 28, 2021 at 04:30PM by gafnita
via reddit https://ift.tt/3jGwuyY
blog.lightspin.io
NGINX Custom Snippets CVE-2021-25742
Here's a deep dive into what high severity alert known as CVE-2021-25742 really is and what it means for today’s organizations.
DriverBuddyReloaded - IDA Python noscript to assist with the reverse engineering of Windows kernel drivers
https://ift.tt/3jCZYxN
Submitted October 28, 2021 at 08:56PM by Void_Sec
via reddit https://ift.tt/3jNLX0b
https://ift.tt/3jCZYxN
Submitted October 28, 2021 at 08:56PM by Void_Sec
via reddit https://ift.tt/3jNLX0b
VoidSec
Driver Buddy Reloaded - VoidSec
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks.
Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection
https://ift.tt/30ZoTVF
Submitted October 28, 2021 at 11:13PM by moviuro
via reddit https://ift.tt/3pJMdRN
https://ift.tt/30ZoTVF
Submitted October 28, 2021 at 11:13PM by moviuro
via reddit https://ift.tt/3pJMdRN
Microsoft Security Blog
Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection | Microsoft Security Blog
Microsoft found a vulnerability (CVE-2021-30892) that could allow an attacker to bypass System Integrity Protection (SIP) in macOS. We shared our findings with Apple via coordinated vulnerability disclosure, and a fix was released October 26.
Technical Advisory – Apple XAR – Arbitrary File Write (CVE-2021-30833)
https://ift.tt/3BiDJ6c
Submitted October 29, 2021 at 01:53AM by digicat
via reddit https://ift.tt/3moYIjz
https://ift.tt/3BiDJ6c
Submitted October 29, 2021 at 01:53AM by digicat
via reddit https://ift.tt/3moYIjz
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Spear phishing with Slackbot
https://ift.tt/3bbG0FP
Submitted October 29, 2021 at 09:01AM by buildingapcin2015
via reddit https://ift.tt/3mldkjY
https://ift.tt/3bbG0FP
Submitted October 29, 2021 at 09:01AM by buildingapcin2015
via reddit https://ift.tt/3mldkjY
Eric Bailey
Spear phishing with Slackbot for fun and profit
You can pretend to be Slackbot, and that’s not great..
Anatomy of a Linux Ransomware Attack | LinuxSecurity.com
https://ift.tt/316pHbj
Submitted October 29, 2021 at 12:48PM by c0r3dump3d
via reddit https://ift.tt/2ZG85mf
https://ift.tt/316pHbj
Submitted October 29, 2021 at 12:48PM by c0r3dump3d
via reddit https://ift.tt/2ZG85mf
Linux Security
Anatomy of a Linux Ransomware Attack | LinuxSecurity.com
Anatomy of a Linux Ransomware Attack - While 85% of ransomware attacks target Windows systems, Linux is becoming an increasingly popular ta
FormatFuzzer: a framework for high-efficiency, high-quality generation and parsing of binary inputs
https://ift.tt/2ZFjzqi
Submitted October 29, 2021 at 01:48PM by 0xdea
via reddit https://ift.tt/3Bsmn6O
https://ift.tt/2ZFjzqi
Submitted October 29, 2021 at 01:48PM by 0xdea
via reddit https://ift.tt/3Bsmn6O
Anatomy of a Linux Ransomware Attack | LinuxSecurity.com
https://ift.tt/316pHbj
Submitted October 29, 2021 at 02:48PM by c0r3dump3d
via reddit https://ift.tt/3pNS48x
https://ift.tt/316pHbj
Submitted October 29, 2021 at 02:48PM by c0r3dump3d
via reddit https://ift.tt/3pNS48x
Linux Security
Anatomy of a Linux Ransomware Attack | LinuxSecurity.com
Anatomy of a Linux Ransomware Attack - While 85% of ransomware attacks target Windows systems, Linux is becoming an increasingly popular ta
Network Capture with Process Name and PID on macOS
https://ift.tt/3GrmX8G
Submitted October 29, 2021 at 07:15PM by c0nsumer
via reddit https://ift.tt/3BlI4FT
https://ift.tt/3GrmX8G
Submitted October 29, 2021 at 07:15PM by c0nsumer
via reddit https://ift.tt/3BlI4FT
reddit
Network Capture with Process Name and PID on macOS
Posted in r/netsec by u/c0nsumer • 2 points and 0 comments
How to takedown a phishing site - this method has worked well for me.
https://ift.tt/3Eu5L0I
Submitted October 29, 2021 at 11:24PM by Seaerkin2
via reddit https://ift.tt/2ZyDAOO
https://ift.tt/3Eu5L0I
Submitted October 29, 2021 at 11:24PM by Seaerkin2
via reddit https://ift.tt/2ZyDAOO
Guardyourdomain
Phishing Site Takedown | DomainGuard | Guard your Domain with Proactive Phishing and Fraud protection.
We guard your domain, so you have pace of mind. Domain Monitoring and Proactive Phishing Protection.
I created a full stack open source web application to create Vulnerability Disclosure Programs. Check it out!
https://ift.tt/2ZAuOjb
Submitted October 29, 2021 at 10:52PM by Green_Same
via reddit https://ift.tt/3nGoD5F
https://ift.tt/2ZAuOjb
Submitted October 29, 2021 at 10:52PM by Green_Same
via reddit https://ift.tt/3nGoD5F
GitHub
GitHub - parikhakshat/openvdp: Open Source Vulnerability Disclosure Program
Open Source Vulnerability Disclosure Program. Contribute to parikhakshat/openvdp development by creating an account on GitHub.