Microsoft Teams: 1 feature, 4 vulnerabilities
https://ift.tt/3pgwNUs
Submitted December 22, 2021 at 03:29PM by breakingsystems
via reddit https://ift.tt/3EdMtMo
https://ift.tt/3pgwNUs
Submitted December 22, 2021 at 03:29PM by breakingsystems
via reddit https://ift.tt/3EdMtMo
positive.security
MS Teams: 1 feature, 4 vulnerabilities | Positive Security
Microsoft Team's link preview feature is susceptible to spoofing and vulnerable to Server-Side Request Forgery. Team's Android users can be DoS'ed and, in the past, their IP address could be leaked.
Responder and IPv6 attacks - Inject a DNS suffix on Active Directory via IPv6 DNSSL
https://ift.tt/3pkNpul
Submitted December 22, 2021 at 08:40AM by Gallus
via reddit https://ift.tt/3piMlH9
https://ift.tt/3pkNpul
Submitted December 22, 2021 at 08:40AM by Gallus
via reddit https://ift.tt/3piMlH9
Blogspot
Responder and IPv6 attacks
Responder 3.1.1.0 comes with full IPv6 support by default, which allows you to perform more attacks on IPv4 and IPv6 networks. As pointed b...
Cloud Web Application Firewall (WAF) CyberRisk Validation Comparative Report
https://ift.tt/3yOsFOs
Submitted December 22, 2021 at 09:00PM by markcartertm
via reddit https://ift.tt/3ySD2Ba
https://ift.tt/3yOsFOs
Submitted December 22, 2021 at 09:00PM by markcartertm
via reddit https://ift.tt/3ySD2Ba
Cross Examination: Unveiling JavaScript injection based browser fingerprint masking attempts
https://ift.tt/32pOjws
Submitted December 22, 2021 at 11:34PM by ziyahanalbeniz
via reddit https://ift.tt/3phXHva
https://ift.tt/32pOjws
Submitted December 22, 2021 at 11:34PM by ziyahanalbeniz
via reddit https://ift.tt/3phXHva
Elastic Security disrupts new BLISTER campaign leveraging code signing certificates.
https://ift.tt/3yUdGCH
Submitted December 22, 2021 at 11:09PM by expertsnowboarder
via reddit https://ift.tt/3yRVqdh
https://ift.tt/3yUdGCH
Submitted December 22, 2021 at 11:09PM by expertsnowboarder
via reddit https://ift.tt/3yRVqdh
www.elastic.co
Elastic Security uncovers BLISTER malware campaign — Elastic Security Labs
Elastic Security has identified active intrusions leveraging the newly identified BLISTER malware loader utilizing valid code-signing certificates to evade detection. We are providing detection guidance for security teams to protect themselves.
RF Bugs and their detection using Software-Defined Radio
https://ift.tt/32fQymv
Submitted December 23, 2021 at 11:18PM by sebazzen
via reddit https://ift.tt/3H9Elye
https://ift.tt/32fQymv
Submitted December 23, 2021 at 11:18PM by sebazzen
via reddit https://ift.tt/3H9Elye
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
https://ift.tt/3yX2MfI
Submitted December 23, 2021 at 11:17PM by sebazzen
via reddit https://ift.tt/3JdMXFU
https://ift.tt/3yX2MfI
Submitted December 23, 2021 at 11:17PM by sebazzen
via reddit https://ift.tt/3JdMXFU
Trend Micro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
Log4PowerShell - A CVE-2021-44228 Proof of Concept / Demo I wrote in PowerShell
https://ift.tt/3FpxiRC
Submitted December 24, 2021 at 11:31AM by aalex954
via reddit https://ift.tt/3yWAdih
https://ift.tt/3FpxiRC
Submitted December 24, 2021 at 11:31AM by aalex954
via reddit https://ift.tt/3yWAdih
GitHub
GitHub - aalex954/Log4PowerShell: A Log4j PoC written in PowerShell
A Log4j PoC written in PowerShell. Contribute to aalex954/Log4PowerShell development by creating an account on GitHub.
Blister malware can breach your devices in absolute stealth
https://ift.tt/3EuvENk
Submitted December 24, 2021 at 05:54PM by IT_band
via reddit https://ift.tt/3Fr5MDr
https://ift.tt/3EuvENk
Submitted December 24, 2021 at 05:54PM by IT_band
via reddit https://ift.tt/3Fr5MDr
The Cybersecurity Times
Blister malware can breach your devices in absolute stealth - The Cybersecurity Times
A new malicious campaign was discovered by security researchers that disguises malicious code as legitimate exe files. The researchers have figured out that there is a payload that is considered a novel threat and being distributed to Windows systems with…
Cloud Security Breaches and Vulnerabilities: 2021 in Review
https://ift.tt/3pjCukz
Submitted December 24, 2021 at 07:46PM by thorn42
via reddit https://ift.tt/3HbsRu6
https://ift.tt/3pjCukz
Submitted December 24, 2021 at 07:46PM by thorn42
via reddit https://ift.tt/3HbsRu6
Christophe Tafani-Dereeper
Cloud Security Breaches and Vulnerabilities: 2021 in Review
In this post, we look back on the 2021 cloud security data breaches and vulnerabilities in AWS, and showcase best practices to avoid them.
Make Your Pc Notify Your Phone Whenever There is Movement Around it
https://ift.tt/3Jf0LjF
Submitted December 25, 2021 at 02:18PM by MagicianPutrid5245
via reddit https://ift.tt/3yZ1C3l
https://ift.tt/3Jf0LjF
Submitted December 25, 2021 at 02:18PM by MagicianPutrid5245
via reddit https://ift.tt/3yZ1C3l
Medium
Make Your Pc Notify Your Phone Whenever There is Movement Around it
Money-free make your home more secure just using your pc
Router Management Practices: Web, App, and forcing to associate user home network with a vendor account
https://ift.tt/3HfWcUt
Submitted December 25, 2021 at 05:54PM by wkwrd
via reddit https://ift.tt/3Fxhf4k
https://ift.tt/3HfWcUt
Submitted December 25, 2021 at 05:54PM by wkwrd
via reddit https://ift.tt/3Fxhf4k
Dong Knows Tech
Web Interface: A Router's 100% Best Friend | Dong Knows Tech
Web interface vs mobile app router management, which is better? Find the answers here and tricks to get the former work fully in Linksys Wi-Fi 6/E routers.
What is a Watering Hole Attacks and How to Prevent Them
https://ift.tt/3tPJnc5
Submitted December 26, 2021 at 04:29PM by bee925p
via reddit https://ift.tt/3qsN9bQ
https://ift.tt/3tPJnc5
Submitted December 26, 2021 at 04:29PM by bee925p
via reddit https://ift.tt/3qsN9bQ
Cymulate
What is a Watering Hole Attacks and How to Prevent Them
A Watering Hole attack is an attack method in which the attacker seeks to compromise a specific group of end-users by infecting websites.
remote Chaos Computer Congress Streaming
https://ift.tt/3nS2aBJ
Submitted December 28, 2021 at 02:07AM by mubix
via reddit https://ift.tt/3EvMMT2
https://ift.tt/3nS2aBJ
Submitted December 28, 2021 at 02:07AM by mubix
via reddit https://ift.tt/3EvMMT2
streaming.media.ccc.de
Live-Streams – rC3 NOWHERE Streaming
Live streaming from the Remote Chaos Experience
A Deep Dive into DoubleFeature: Equation Group's Post-Exploitation Dashboard
https://ift.tt/3mx4Sh1
Submitted December 28, 2021 at 02:01AM by Megabeets
via reddit https://ift.tt/3z6J0OH
https://ift.tt/3mx4Sh1
Submitted December 28, 2021 at 02:01AM by Megabeets
via reddit https://ift.tt/3z6J0OH
Check Point Research
A Deep Dive into DoubleFeature, Equation Group's Post-Exploitation Dashboard - Check Point Research
Earlier this year, Check Point Research published the story of “Jian” — an exploit used by Chinese threat actor APT31 which was “heavily inspired by” an almost-identical exploit used by the Equation Group, made publicly known by the Shadow Brokers leak. The…
Winning the Impossible Race – An Unintended Solution for Includer’s Revenge / Counter (hxp 2021)
https://ift.tt/3qwtojA
Submitted December 28, 2021 at 03:04AM by Caustic66
via reddit https://ift.tt/3H7j3S2
https://ift.tt/3qwtojA
Submitted December 28, 2021 at 03:04AM by Caustic66
via reddit https://ift.tt/3H7j3S2
Guy Lewin's Blog
Winning the Impossible Race - An Unintended Solution for Includer’s Revenge / Counter (hxp 2021) - Guy Lewin's Blog
Unintended hxp CTF solution leading to wildcard exploit for PHP LFI with Nginx
Encoding.Tools (alternative to CyberChef and Burp Suite Encoder)
https://encoding.tools/
Submitted December 28, 2021 at 05:41AM by mehaase
via reddit https://ift.tt/3pzBGIt
https://encoding.tools/
Submitted December 28, 2021 at 05:41AM by mehaase
via reddit https://ift.tt/3pzBGIt
encoding.tools
Encoding Tools
Encoding tools is a graphical utility for performing common encoding, decoding, and hashing procedures on text or binary data.
V8 Heap pwn and /dev/memes - WebOS Root LPE
https://ift.tt/3qrAgPu
Submitted December 28, 2021 at 12:08PM by DavidBuchanan
via reddit https://ift.tt/3qsEd6f
https://ift.tt/3qrAgPu
Submitted December 28, 2021 at 12:08PM by DavidBuchanan
via reddit https://ift.tt/3qsEd6f
reddit
V8 Heap pwn and /dev/memes - WebOS Root LPE
Posted in r/netsec by u/DavidBuchanan • 17 points and 0 comments
PHP LFI with Nginx Assistance
https://ift.tt/3sA7oXT
Submitted December 28, 2021 at 02:29PM by dL2Hj4wR
via reddit https://ift.tt/3FBYtZx
https://ift.tt/3sA7oXT
Submitted December 28, 2021 at 02:29PM by dL2Hj4wR
via reddit https://ift.tt/3FBYtZx
bierbaumer.net
0xbb - PHP LFI with Nginx Assistance
New method to exploit PHP local file inclusion (LFI) vulnerabilities with Nginx assistance.
Pet surveillance with Falco
https://ift.tt/3pzvYGw
Submitted December 28, 2021 at 10:13PM by MiguelHzBz
via reddit https://ift.tt/3sN6tmO
https://ift.tt/3pzvYGw
Submitted December 28, 2021 at 10:13PM by MiguelHzBz
via reddit https://ift.tt/3sN6tmO
Sysdig
Pet surveillance with Falco - Home Security – Sysdig
Falco with plugin support is aiming to become the standard way to secure your infrastructure, the cloud one, and even the physical one.
Using laser speckle patterns to see keypresses etc.
https://ift.tt/3hoTVfd
Submitted December 28, 2021 at 10:06PM by anfractuosus
via reddit https://ift.tt/3mySRYH
https://ift.tt/3hoTVfd
Submitted December 28, 2021 at 10:06PM by anfractuosus
via reddit https://ift.tt/3mySRYH
Anfractuosity
Fun with speckle patterns
I recently came across a really fascinating video - https://www.youtube.com/watch?v=tYFLze9VwB0 where they make use of a micro laser projector to generate a speckle pattern on a surface and then photograph it with a DSLR. They then simply touch a surface…