Blue Team - Black Friday Deals
https://ift.tt/3p7nhln
Submitted November 26, 2021 at 09:50PM by SnooGadgets2368
via reddit https://ift.tt/3xqD5Dm
https://ift.tt/3p7nhln
Submitted November 26, 2021 at 09:50PM by SnooGadgets2368
via reddit https://ift.tt/3xqD5Dm
GitHub
GitHub - lolnoscript/BlueTeam-BlackFriday-Deals
Contribute to lolnoscript/BlueTeam-BlackFriday-Deals development by creating an account on GitHub.
Vulnerability in the Insulet OmniPod Insulin Management System allows an attacker nearby to schedule or immediately inject insulin
https://ift.tt/3cS8chD
Submitted November 27, 2021 at 05:44PM by CommanderHutli
via reddit https://ift.tt/3xuL6ar
https://ift.tt/3cS8chD
Submitted November 27, 2021 at 05:44PM by CommanderHutli
via reddit https://ift.tt/3xuL6ar
Reddit
r/netsec on Reddit: Vulnerability in the Insulet OmniPod Insulin Management System allows an attacker nearby to schedule or immediately…
Posted by u/CommanderHutli - 543 votes and 62 comments
WordPress Plugin Confusion: How an update can get you pwned
https://ift.tt/3nPj5XK
Submitted November 25, 2021 at 09:38PM by _vavkamil_
via reddit https://ift.tt/3p6ba7Z
https://ift.tt/3nPj5XK
Submitted November 25, 2021 at 09:38PM by _vavkamil_
via reddit https://ift.tt/3p6ba7Z
Kamil Vavra @vavkamil
WordPress Plugin Confusion: How an update can get you pwned
tl;dr: Like the novel “Dependency Confusion” supply chain attack, it is possible to take over internally developed WordPress plugins unclaimed on the wordpress.org registry. Updating the plugin might result in the RCE or installing a PHP backdoor. You can…
Data Exfiltration via CSS + SVG Font
https://ift.tt/3cSjdQd
Submitted November 29, 2021 at 06:37AM by Gallus
via reddit https://ift.tt/319rvAS
https://ift.tt/3cSjdQd
Submitted November 29, 2021 at 06:37AM by Gallus
via reddit https://ift.tt/319rvAS
mksben.l0.cm
Data Exfiltration via CSS + SVG Font
This post will show that the SVG fonts and CSS can be used for reading the page's text contents. There are several known ways to read the pa...
How not to write an infosec report: Tardigrade - The Water Bear Malware that Wasn’t
https://ift.tt/3FS2s40
Submitted November 29, 2021 at 03:27PM by ifmush12xx
via reddit https://ift.tt/3FXhgOY
https://ift.tt/3FS2s40
Submitted November 29, 2021 at 03:27PM by ifmush12xx
via reddit https://ift.tt/3FXhgOY
Medium
The Water Bear that Wasn’t: Tardigrade
In mid November 2021 the world’s tech commentators including Wired, The Washington Post, Bleeping Computer and Tripwire lit up with news of…
CONTInuing the Bazar Ransomware Story
https://ift.tt/3FPzDVM
Submitted November 29, 2021 at 06:16PM by TheDFIRReport
via reddit https://ift.tt/3rfAoUd
https://ift.tt/3FPzDVM
Submitted November 29, 2021 at 06:16PM by TheDFIRReport
via reddit https://ift.tt/3rfAoUd
The DFIR Report
CONTInuing the Bazar Ransomware Story
In this report we will discuss a case from early August where we witnessed threat actors utilizing BazarLoader and Cobalt Strike to accomplish their mission of encrypting systems with Conti ransomw…
Unpatched Exchange servers distribute phishing links (squirrelwaffle)
https://ift.tt/3d2pxo6
Submitted November 29, 2021 at 09:28PM by ma-ni
via reddit https://ift.tt/314Smy7
https://ift.tt/3d2pxo6
Submitted November 29, 2021 at 09:28PM by ma-ni
via reddit https://ift.tt/314Smy7
reddit
Unpatched Exchange servers distribute phishing links (squirrelwaffle)
Posted in r/netsec by u/ma-ni • 90 points and 7 comments
Abusing Opera mini turbo servers for fraudulent VAS activation
https://ift.tt/3rj3jXv
Submitted November 30, 2021 at 04:04PM by esc0rp_
via reddit https://ift.tt/31anbRw
https://ift.tt/3rj3jXv
Submitted November 30, 2021 at 04:04PM by esc0rp_
via reddit https://ift.tt/31anbRw
www.inputzero.io
Play the Opera Please
CVE-201819825 - Opera Browser
Compromising the email supply chain of 190 Australian organisations through a single IT Managed Service Provider
https://ift.tt/3lp5Xah
Submitted December 01, 2021 at 01:26AM by Jumpy_Resolution3089
via reddit https://ift.tt/3lmKMWx
https://ift.tt/3lp5Xah
Submitted December 01, 2021 at 01:26AM by Jumpy_Resolution3089
via reddit https://ift.tt/3lmKMWx
Caniphish
Compromising Email Supply Chains | CanIPhish
Compromising the email supply chain of 190 Australian organisations through a single IT Managed Service Provider.
Discovering Full Read SSRF in Jamf (CVE-2021-39303 & CVE-2021-40809)
https://ift.tt/3d7LL8u
Submitted December 01, 2021 at 03:39AM by Mempodipper
via reddit https://ift.tt/3rp7Tn8
https://ift.tt/3d7LL8u
Submitted December 01, 2021 at 03:39AM by Mempodipper
via reddit https://ift.tt/3rp7Tn8
Assetnote
Discovering Full Read SSRF in Jamf (CVE-2021-39303 & CVE-2021-40809)
Application security issues found by Assetnote
How Data Breaches happen and why Secure by Default software is the future
https://ift.tt/3Ea5dNr
Submitted December 01, 2021 at 05:19AM by breadchris
via reddit https://ift.tt/3EcgtJg
https://ift.tt/3Ea5dNr
Submitted December 01, 2021 at 05:19AM by breadchris
via reddit https://ift.tt/3EcgtJg
www.lunasec.io
How Data Breaches happen and why Secure by Default software is the future | LunaSec
Your software delivery model is broken, but it's not your fault. Delivering on time while also protecting yourself from data breaches is a herculean task. It doesn't have to be though, and we'll show you why!
An Illustrated Guide to Elliptic Curve Cryptography Validation
https://ift.tt/3wXjLgT
Submitted December 01, 2021 at 12:28PM by Gallus
via reddit https://ift.tt/3rocEx7
https://ift.tt/3wXjLgT
Submitted December 01, 2021 at 12:28PM by Gallus
via reddit https://ift.tt/3rocEx7
NCC Group Research Blog
An Illustrated Guide to Elliptic Curve Cryptography Validation
Elliptic Curve Cryptography (ECC) has become the de facto standard for protecting modern communications. ECC is widely used to perform asymmetric cryptography operations, such as to establish share…
Tracking a P2P network related to TA505
https://ift.tt/31lo1L6
Submitted December 01, 2021 at 03:24PM by digicat
via reddit https://ift.tt/31l6nHp
https://ift.tt/31lo1L6
Submitted December 01, 2021 at 03:24PM by digicat
via reddit https://ift.tt/31l6nHp
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Active NFT marketplace cryptoscam used to steal victim's funds.
https://ift.tt/3I9qRDY
Submitted December 01, 2021 at 06:34PM by Seaerkin2
via reddit https://ift.tt/3rpkoyV
https://ift.tt/3I9qRDY
Submitted December 01, 2021 at 06:34PM by Seaerkin2
via reddit https://ift.tt/3rpkoyV
Guardyourdomain
NFT Support Scam, NFTishing | DomainGuard | Guard your Domain with Proactive Phishing and Fraud protection.
We guard your domain, so you have pace of mind. Domain Monitoring and Proactive Phishing Protection.
SonarSource's Code Security Advent Calendar starts today!
https://ift.tt/3xHJha5
Submitted December 01, 2021 at 07:41PM by monoimpact
via reddit https://ift.tt/3IcOqvA
https://ift.tt/3xHJha5
Submitted December 01, 2021 at 07:41PM by monoimpact
via reddit https://ift.tt/3IcOqvA
Sonarsource
Code Security Advent Calendar 2021
Our code security advent calendar is back for the sixth consecutive year. We will release daily challenges until December 24th, get ready to fill your bag of tricks!
The Re-Emergence of Emotet
https://ift.tt/3G2yOsM
Submitted November 30, 2021 at 10:05PM by ron_by
via reddit https://ift.tt/31i0zyG
https://ift.tt/3G2yOsM
Submitted November 30, 2021 at 10:05PM by ron_by
via reddit https://ift.tt/31i0zyG
Deep Instinct
The Re-Emergence of Emotet | Deep Instinct
Emotet, the malware botnet, has resurfaced after almost 10 months. The operation was originally taken down by multiple international law enforcement agencies this past January. These agencies took control of the infrastructure and scheduled an un-installation…
Unpacking and decryption tools for the Emotet malware
https://ift.tt/3xGCuO7
Submitted November 30, 2021 at 10:06PM by ron_by
via reddit https://ift.tt/3peninz
https://ift.tt/3xGCuO7
Submitted November 30, 2021 at 10:06PM by ron_by
via reddit https://ift.tt/3peninz
What does APT Activity Look Like on MacOS?
https://ift.tt/3rqf6mF
Submitted November 30, 2021 at 02:35AM by MiguelHzBz
via reddit https://ift.tt/3d6fmir
https://ift.tt/3rqf6mF
Submitted November 30, 2021 at 02:35AM by MiguelHzBz
via reddit https://ift.tt/3d6fmir
pip-audit: a tool for identifying Python packages with known vulnerabilities
https://ift.tt/3loAxRe
Submitted December 02, 2021 at 12:01AM by yossarian_flew_away
via reddit https://ift.tt/3GaQvqp
https://ift.tt/3loAxRe
Submitted December 02, 2021 at 12:01AM by yossarian_flew_away
via reddit https://ift.tt/3GaQvqp
Reverse engineering REST APIs/network communication in a process (12 part series)
https://ift.tt/3xLLhyo
Submitted December 02, 2021 at 02:38AM by cr0_
via reddit https://ift.tt/31nU5hQ
https://ift.tt/3xLLhyo
Submitted December 02, 2021 at 02:38AM by cr0_
via reddit https://ift.tt/31nU5hQ
This shouldn't have happened: A vulnerability postmortem
https://ift.tt/3lruxr4
Submitted December 02, 2021 at 05:33AM by DrinkMoreCodeMore
via reddit https://ift.tt/3G6W49b
https://ift.tt/3lruxr4
Submitted December 02, 2021 at 05:33AM by DrinkMoreCodeMore
via reddit https://ift.tt/3G6W49b
Blogspot
This shouldn't have happened: A vulnerability postmortem
Posted by Tavis Ormandy, Project Zero Introduction This is an unusual blog post. I normally write posts to highlight some hidden att...