Backdooring Rust crates for fun and profit
https://ift.tt/3DrHE2n
Submitted November 18, 2021 at 10:16PM by Gallus
via reddit https://ift.tt/328fXOl
https://ift.tt/3DrHE2n
Submitted November 18, 2021 at 10:16PM by Gallus
via reddit https://ift.tt/328fXOl
Sylvain Kerkour
Backdooring Rust crates for fun and profit
Supply chains attacks are all the rage these days, whether to deliver RATs, cryptocurrencies miners, or credential stealers. In Rust, packages are called crates and are (most of the time) hosted on a central repository: https://crates.io for better discoverability.…
Python Malware Imitates Signed PyPI Traffic in Novel Exfiltration Technique
https://ift.tt/3oFlkMK
Submitted November 18, 2021 at 11:43PM by SRMish3
via reddit https://ift.tt/3cmYYdb
https://ift.tt/3oFlkMK
Submitted November 18, 2021 at 11:43PM by SRMish3
via reddit https://ift.tt/3cmYYdb
JFrog
Python Malware Imitates Signed PyPI Traffic in Novel Exfiltration Technique
Software supply chain security threat: automated scanning of Python packages in the PyPI repository uncovered stealthy malware and more. Find out about our latest findings.
How we protect our most sensitive secrets from the most determined attackers
https://ift.tt/3qNqGYK
Submitted November 19, 2021 at 12:14AM by BasedSweet
via reddit https://ift.tt/3csOr06
https://ift.tt/3qNqGYK
Submitted November 19, 2021 at 12:14AM by BasedSweet
via reddit https://ift.tt/3csOr06
CVE-2021-37580 Apache ShenYu 2.3.0/2.4.0 authentication bypass
https://ift.tt/3kN1a1V
Submitted November 19, 2021 at 10:59AM by 0x0021h
via reddit https://ift.tt/3nxUzKw
https://ift.tt/3kN1a1V
Submitted November 19, 2021 at 10:59AM by 0x0021h
via reddit https://ift.tt/3nxUzKw
Prevent Secrets Leaks at Scale in Repositories
https://ift.tt/3kS54qi
Submitted November 19, 2021 at 07:43PM by epiblas279
via reddit https://ift.tt/3nvN6f1
https://ift.tt/3kS54qi
Submitted November 19, 2021 at 07:43PM by epiblas279
via reddit https://ift.tt/3nvN6f1
All Roads Lead to OpenVPN: Pwning Industrial Remote Access Client
https://ift.tt/3CsiUWA
Submitted November 19, 2021 at 09:21PM by n0llbyte
via reddit https://ift.tt/3DAteNE
https://ift.tt/3CsiUWA
Submitted November 19, 2021 at 09:21PM by n0llbyte
via reddit https://ift.tt/3DAteNE
New ransomware actor uses password-protected archives to bypass encryption protection
https://ift.tt/3Cnjl4o
Submitted November 19, 2021 at 09:10PM by ksr_malware
via reddit https://ift.tt/3qTCWqI
https://ift.tt/3Cnjl4o
Submitted November 19, 2021 at 09:10PM by ksr_malware
via reddit https://ift.tt/3qTCWqI
Sophos News
New ransomware actor uses password-protected archives to bypass encryption protection
Calling themselves “Memento team”, actors use Python-based ransomware that they reconfigured after setbacks.
Why it is time to get rid of passwords in our infrastructure
https://ift.tt/3x5MPm8
Submitted November 20, 2021 at 12:11AM by Valien
via reddit https://ift.tt/2Z5jDiT
https://ift.tt/3x5MPm8
Submitted November 20, 2021 at 12:11AM by Valien
via reddit https://ift.tt/2Z5jDiT
Goteleport
Why it is time to get rid of passwords in our infrastructure
Passwordless is a phrase generating a lot of buzz in the consumer space. But our infrastructure is full of passwords too and that needs to stop.
Building WireGate: A WireGuard front to detect compromised keys
https://ift.tt/3CwaL3j
Submitted November 20, 2021 at 02:27AM by thinkst
via reddit https://ift.tt/3xioH05
https://ift.tt/3CwaL3j
Submitted November 20, 2021 at 02:27AM by thinkst
via reddit https://ift.tt/3xioH05
Thinkst Thoughts
Building WireGate: A WireGuard front to detect compromised keys
Earlier this year we released our WireGuard Canarytoken. This allows you to add a “fake” wireguard VPN endpoint on your device in seconds. The idea is that if your device is compromised, a knowledg…
Hadoop Yarn RPC RCE
https://ift.tt/3CB2tXO
Submitted November 20, 2021 at 10:39AM by 0x0021h
via reddit https://ift.tt/3FxW2a5
https://ift.tt/3CB2tXO
Submitted November 20, 2021 at 10:39AM by 0x0021h
via reddit https://ift.tt/3FxW2a5
GitHub
expbox/Hadoop Yarn RPC RCE.md at main · 0x0021h/expbox
Vulnerability Exploitation Code Collection Repository - expbox/Hadoop Yarn RPC RCE.md at main · 0x0021h/expbox
GitHub - mrexodia/dumpulator: An easy-to-use library for emulating code in minidump files.
https://ift.tt/3p5fIf1
Submitted November 21, 2021 at 04:40AM by mrexodia
via reddit https://ift.tt/3oTa4wq
https://ift.tt/3p5fIf1
Submitted November 21, 2021 at 04:40AM by mrexodia
via reddit https://ift.tt/3oTa4wq
GitHub
GitHub - mrexodia/dumpulator: An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction…
An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing). - mrexodia/dumpulator
CVE-2021-41277 MetaBase Arbitrary File Read
https://ift.tt/3CA2vzd
Submitted November 21, 2021 at 06:44AM by 0x0021h
via reddit https://ift.tt/3DJXp5a
https://ift.tt/3CA2vzd
Submitted November 21, 2021 at 06:44AM by 0x0021h
via reddit https://ift.tt/3DJXp5a
Command/Code injection prevention for Python
https://ift.tt/30OBYRu
Submitted November 22, 2021 at 06:35AM by inkz1
via reddit https://ift.tt/3nD9X8u
https://ift.tt/30OBYRu
Submitted November 22, 2021 at 06:35AM by inkz1
via reddit https://ift.tt/3nD9X8u
semgrep.dev
Command injection prevention for Python | Semgrep
Command injection prevention cheat sheet for Python.
Picky PPID Spoofing
https://ift.tt/32h6bJP
Submitted November 22, 2021 at 09:41AM by CaptMeelo
via reddit https://ift.tt/2Zfyes8
https://ift.tt/32h6bJP
Submitted November 22, 2021 at 09:41AM by CaptMeelo
via reddit https://ift.tt/2Zfyes8
Hack.Learn.Share
Picky PPID Spoofing
Performing PPID Spoofing by targeting a parent process with a specific integrity level.
Quick WAF "paranoid" Doctor Evaluation (WAFPARAN01D3 Tool)
https://ift.tt/3DI6dZ1
Submitted November 22, 2021 at 02:55PM by alt3kx
via reddit https://ift.tt/30KYmvM
https://ift.tt/3DI6dZ1
Submitted November 22, 2021 at 02:55PM by alt3kx
via reddit https://ift.tt/30KYmvM
GitHub
GitHub - alt3kx/wafparan01d3: Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool
Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool - GitHub - alt3kx/wafparan01d3: Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool
Tor v2 Deprecation Shifts Darknet Landscape | DarkOwl
https://ift.tt/3cBw4pH
Submitted November 22, 2021 at 05:08PM by MiguelHzBz
via reddit https://ift.tt/3DL2Rob
https://ift.tt/3cBw4pH
Submitted November 22, 2021 at 05:08PM by MiguelHzBz
via reddit https://ift.tt/3DL2Rob
DarkOwl | Dark Web Search Engine
Tor v2 Deprecation Shifts Darknet Landscape | DarkOwl
Hear the latest from our engineers who have been tracking the progress of the Tor Project's v2 Onion Services deprecation timeline.
The UNIX malware landscape - Reviewing the goods at MALWAREbazaar
https://ift.tt/3oPhUXR
Submitted November 22, 2021 at 06:34PM by timb_machine
via reddit https://ift.tt/3cBYkbN
https://ift.tt/3oPhUXR
Submitted November 22, 2021 at 06:34PM by timb_machine
via reddit https://ift.tt/3cBYkbN
GitHub
presentations/The UNIX malware landscape - Reviewing the goods at MALWAREbazaar v5.pdf at master · CiscoCXSecurity/presentations
Presentations from the CX Security Labs team. Contribute to CiscoCXSecurity/presentations development by creating an account on GitHub.
Unlocking the Vault: Unauthenticated Remote Code Execution against CommVault Command Center
https://ift.tt/3HLxqN2
Submitted November 22, 2021 at 10:39PM by scopedsecurity
via reddit https://ift.tt/3xagB9E
https://ift.tt/3HLxqN2
Submitted November 22, 2021 at 10:39PM by scopedsecurity
via reddit https://ift.tt/3xagB9E
Godaddy hacked - including admin passwords for both WordPress sites hosted on the platform, as well as passwords for sFTPs, databases and SSL private keys.
https://ift.tt/3CCW3aN
Submitted November 22, 2021 at 10:11PM by digicat
via reddit https://ift.tt/30M8eFc
https://ift.tt/3CCW3aN
Submitted November 22, 2021 at 10:11PM by digicat
via reddit https://ift.tt/30M8eFc
reddit
Godaddy hacked - including admin passwords for both WordPress...
Posted in r/netsec by u/digicat • 2 points and 0 comments
Achieve RCE or lateral movement by abusing WSUS to perform NTLM relay attacks
https://ift.tt/3oJYGTm
Submitted November 23, 2021 at 07:56PM by obilodeau
via reddit https://ift.tt/3cDB3WU
https://ift.tt/3oJYGTm
Submitted November 23, 2021 at 07:56PM by obilodeau
via reddit https://ift.tt/3cDB3WU
GoSecure
GoSecure Investigates Abusing Windows Server Update Services (WSUS) to Enable NTLM Relaying Attacks - GoSecure
WSUS client automatically authenticates with NTLM as the current user or the machine account, allowing relay for remote code execution or lateral movement.
Black Friday Deals 2021 - Compiled from Github Repo
https://ift.tt/2Zh5crX
Submitted November 23, 2021 at 09:19PM by halencarjunior
via reddit https://ift.tt/30OX2aH
https://ift.tt/2Zh5crX
Submitted November 23, 2021 at 09:19PM by halencarjunior
via reddit https://ift.tt/30OX2aH
bt0’s Security Blog
Black Friday Infosec Deals
Black Friday Deals - 2021 Deals Repository