Introducing TEQNIX: An online collection of free pentesting tools. Recently added: Frida Gadget Injector, APK static analyser, XSS exploitation helper.
http://teqnix.io/#
Submitted November 11, 2021 at 03:07AM by maudits
via reddit https://ift.tt/3DhcdaQ
http://teqnix.io/#
Submitted November 11, 2021 at 03:07AM by maudits
via reddit https://ift.tt/3DhcdaQ
A Detailed Analysis of Lazarus’ RAT Called FALLCHILL
https://ift.tt/3D811xs
Submitted November 11, 2021 at 05:01PM by CyberMasterV
via reddit https://ift.tt/3F7su2U
https://ift.tt/3D811xs
Submitted November 11, 2021 at 05:01PM by CyberMasterV
via reddit https://ift.tt/3F7su2U
New World's Botting Problem
https://ift.tt/3F7Xe3O
Submitted November 11, 2021 at 07:50PM by dinobyt3s
via reddit https://ift.tt/3Hdn8F6
https://ift.tt/3F7Xe3O
Submitted November 11, 2021 at 07:50PM by dinobyt3s
via reddit https://ift.tt/3Hdn8F6
Medium
New World’s Botting Problem
New World, Amazon’s latest entry into the gaming world, is a plagued by bots that are ruining player experiences.
SharkBot: a new generation of Android Trojans is targeting banks in Europe
https://ift.tt/3n4DQyk
Submitted November 11, 2021 at 09:33PM by f3d_0x0
via reddit https://ift.tt/3D7vprR
https://ift.tt/3n4DQyk
Submitted November 11, 2021 at 09:33PM by f3d_0x0
via reddit https://ift.tt/3D7vprR
Cleafy
SharkBot: a new generation of Android Trojans is targeting banks in Europe | Cleafy Labs
SharkBot: a new generation of Android Trojans is targeting European banks. It has been discovered by the threat intelligence team of Cleafy: here's the technical analysis.
Bypass EDR Hooks by Faking Reentrancy
https://ift.tt/3qosiYW
Submitted November 11, 2021 at 09:53PM by Safficon
via reddit https://ift.tt/3D8TCOq
https://ift.tt/3qosiYW
Submitted November 11, 2021 at 09:53PM by Safficon
via reddit https://ift.tt/3D8TCOq
Deep Instinct
Evading EDR Detection with Reentrancy Abuse | Deep Instinct
In this blog, we’ll explore a new way to exploit reentrancy that can be used to evade the behavioral analysis of EDR and legacy antivirus products.
The Kerberos Key List Attack: The return of the Read Only Domain Controllers
https://ift.tt/3c5iQkW
Submitted November 11, 2021 at 11:11PM by mgalloar
via reddit https://ift.tt/3oe36Bu
https://ift.tt/3c5iQkW
Submitted November 11, 2021 at 11:11PM by mgalloar
via reddit https://ift.tt/3oe36Bu
SecureAuth
The Kerberos Key List Attack: The return of the Read Only Domain Controllers
Some time ago Microsoft released a very cool feature that caught our attention. That was a passwordless authentication functionality that provides seamless single sign-on (SSO) to on-premises resources, using security keys such as the famous FIDO2 keys. …
Analyzing a watering hole campaign using macOS exploits
https://ift.tt/3ohoxBX
Submitted November 12, 2021 at 01:38AM by digicat
via reddit https://ift.tt/30kVFRe
https://ift.tt/3ohoxBX
Submitted November 12, 2021 at 01:38AM by digicat
via reddit https://ift.tt/30kVFRe
Google
Analyzing a watering hole campaign using macOS exploits
To protect our users, TAG routinely hunts for 0-day vulnerabilities exploited in-the-wild. In late August 2021, TAG discovered watering hole attacks targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political…
CVE-2002-20001 - disable Diffie-Hellman (DHE) key exchange on everything
https://ift.tt/3qvxOsQ
Submitted November 12, 2021 at 03:19AM by Mydadpicksthefruit
via reddit https://ift.tt/3qukl4h
https://ift.tt/3qvxOsQ
Submitted November 12, 2021 at 03:19AM by Mydadpicksthefruit
via reddit https://ift.tt/3qukl4h
reddit
CVE-2002-20001 - disable Diffie-Hellman (DHE) key exchange on...
A community for technical news and discussion of information security and closely related topics.
Scanning Millions Of Publicly Exposed Docker Containers - Thousands Of Secrets Leaked
https://ift.tt/3CaYq4m
Submitted November 12, 2021 at 12:22PM by redhuntlabs
via reddit https://ift.tt/3Fcy1oC
https://ift.tt/3CaYq4m
Submitted November 12, 2021 at 12:22PM by redhuntlabs
via reddit https://ift.tt/3Fcy1oC
RedHunt Labs
Scanning Millions Of Publicly Exposed Docker Containers - Thousands Of Secrets Leaked (Wave 5) - RedHunt Labs
Docker is a popular tool that has become synonymous with containers. Docker can build images and run containers. The tool also allows its users to upload their docker images to Docker Hub - the container image registry from Docker Inc. that helps share images.…
Practical attacks against attribute-based encryption
https://ift.tt/3c3YLLF
Submitted November 12, 2021 at 07:47PM by tmlxs
via reddit https://ift.tt/3omGzTp
https://ift.tt/3c3YLLF
Submitted November 12, 2021 at 07:47PM by tmlxs
via reddit https://ift.tt/3omGzTp
Kudelski Security Research
Practical attacks against attribute-based encryption
This week at Black Hat Europe 2021, Marloes Venema (Radboud University Nijmegen) and me, presented our work on attacking attribute-based encryption implementations: Attribute-based encryption Attri…
New Threat Alert: Krane Malware
https://ift.tt/3C42Jys
Submitted November 12, 2021 at 06:58PM by kernelv0id
via reddit https://ift.tt/3F9sE9R
https://ift.tt/3C42Jys
Submitted November 12, 2021 at 06:58PM by kernelv0id
via reddit https://ift.tt/3F9sE9R
CUJO AI
New Threat Alert: Krane Malware
The discovery and analysis of a new threat: Krane malware – a cryptominer botnet that has the ability to spread laterally.
Spear Phishing And Subdomains Takeover
https://ift.tt/3C8gtIn
Submitted November 12, 2021 at 09:08PM by banginpadr
via reddit https://ift.tt/3H9IyTs
https://ift.tt/3C8gtIn
Submitted November 12, 2021 at 09:08PM by banginpadr
via reddit https://ift.tt/3H9IyTs
Medium
Spear Phishing And Subdomains Takeover
Familiarity is what makes spear phishing attacks successful.
TP-Link TLWR840N V5 EU router - Remote Code execution
https://ift.tt/3wEzRM2
Submitted November 12, 2021 at 10:45PM by k4m1ll0
via reddit https://ift.tt/3F27iv8
https://ift.tt/3wEzRM2
Submitted November 12, 2021 at 10:45PM by k4m1ll0
via reddit https://ift.tt/3F27iv8
K4M1Ll0
TP-Link TL-WR840N V5(EU) - RCE - CVE-2021-41653
exploit
RCE chain using Rails Active Storage XSS + ElectronJs Misconfigurations
https://ift.tt/3qMwAJZ
Submitted November 12, 2021 at 12:04AM by nibblesec
via reddit https://ift.tt/2YJRduC
https://ift.tt/3qMwAJZ
Submitted November 12, 2021 at 12:04AM by nibblesec
via reddit https://ift.tt/2YJRduC
fee - Execute ELF binaries without dropping files on disk
https://ift.tt/3qsvWky
Submitted November 13, 2021 at 12:43AM by crower
via reddit https://ift.tt/3wKoAKb
https://ift.tt/3qsvWky
Submitted November 13, 2021 at 12:43AM by crower
via reddit https://ift.tt/3wKoAKb
GitHub
GitHub - nnsee/fileless-elf-exec: Execute ELF files without dropping them on disk
Execute ELF files without dropping them on disk. Contribute to nnsee/fileless-elf-exec development by creating an account on GitHub.
[OPEN FOR 72HRS ONLY] - Private hacking / 0day dev / bug bounty community (Discord<->IRC bridge)
https://ift.tt/3DcS06e
Submitted November 13, 2021 at 05:02AM by 0x0MLT
via reddit https://ift.tt/3DcpuSh
https://ift.tt/3DcS06e
Submitted November 13, 2021 at 05:02AM by 0x0MLT
via reddit https://ift.tt/3DcpuSh
Discord
Discord - A New Way to Chat with Friends & Communities
Discord is the easiest way to communicate over voice, video, and text. Chat, hang out, and stay close with your friends and communities.
Israel Is Hacking the Phones of Palestinian NGOs and Palestinian Authority Officials
https://ift.tt/3cb17bC
Submitted November 14, 2021 at 04:43AM by richards1052
via reddit https://ift.tt/3FiqmFD
https://ift.tt/3cb17bC
Submitted November 14, 2021 at 04:43AM by richards1052
via reddit https://ift.tt/3FiqmFD
Jacobinmag
Israel Is Hacking the Phones of Palestinian NGOs
Israel has been caught hacking the phones of six Palestinian human rights staffers. It’s the latest incident in Israel’s larger web of blatantly undemocratic mass surveillance practices.
Exploiting CSP in Webkit to Break Authentication & Authorization
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 10:41AM by 1lastBr3ath
via reddit https://ift.tt/3ndVUGw
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 10:41AM by 1lastBr3ath
via reddit https://ift.tt/3ndVUGw
threatnix.io
Exploiting CSP in Webkit to Break Authentication & Authorization
This blog post will discuss our findings that we presented in our Blackhat Europe talk noscriptd "Exploiting CSP in Webkit to break Authentication/Authorization", a vulnerability that enabled us to takeover user accounts on most of the web applications out thereby…
Exploiting CSP in Webkit to Break Authentication & Authorization
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 04:20PM by antfigunio
via reddit https://ift.tt/3caABzm
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 04:20PM by antfigunio
via reddit https://ift.tt/3caABzm
threatnix.io
Exploiting CSP in Webkit to Break Authentication & Authorization
This blog post will discuss our findings that we presented in our Blackhat Europe talk noscriptd "Exploiting CSP in Webkit to break Authentication/Authorization", a vulnerability that enabled us to takeover user accounts on most of the web applications out thereby…
Revealing LAMBERTS/LONGHORN Malware Capabilities using a step-by-step approach
https://ift.tt/3wGCgpI
Submitted November 14, 2021 at 07:50PM by CyberMasterV
via reddit https://ift.tt/3Dinmbs
https://ift.tt/3wGCgpI
Submitted November 14, 2021 at 07:50PM by CyberMasterV
via reddit https://ift.tt/3Dinmbs
reddit
Revealing LAMBERTS/LONGHORN Malware Capabilities using a...
Posted in r/netsec by u/CyberMasterV • 26 points and 6 comments
Living Off Trusted Sites (LOTS) Project Attackers are using popular legitimate domains when conducting phishing, C&C, exfiltration and downloading tools to evade detection. The list of websites below allow attackers to use their domain or subdomain
https://ift.tt/3CjV52V
Submitted November 14, 2021 at 11:29PM by digicat
via reddit https://ift.tt/3orBhpI
https://ift.tt/3CjV52V
Submitted November 14, 2021 at 11:29PM by digicat
via reddit https://ift.tt/3orBhpI
reddit
Living Off Trusted Sites (LOTS) Project Attackers are using...
Posted in r/netsec by u/digicat • 153 points and 14 comments