The Kubernetes (K8s) Network Security Effect
https://ift.tt/3HArZPT
Submitted January 05, 2022 at 02:16PM by catgoddim
via reddit https://ift.tt/3sW9zFd
https://ift.tt/3HArZPT
Submitted January 05, 2022 at 02:16PM by catgoddim
via reddit https://ift.tt/3sW9zFd
ARMO
The Kubernetes (K8s) Network Security Effect | ARMO
Learn everything about the Kubernetes (K8s) network security effect from Amir Kaushansky, ARMO's VP Product. Read this insightful blog post here!
We desperately need a way to rapidly notify people of high-impact vulnerabilities, so I built one
https://ift.tt/3EVLlNT
Submitted January 05, 2022 at 08:09PM by sullivanmatt
via reddit https://ift.tt/3mTEgqX
https://ift.tt/3EVLlNT
Submitted January 05, 2022 at 08:09PM by sullivanmatt
via reddit https://ift.tt/3mTEgqX
Matt's Life Bytes
We desperately need a way to rapidly notify people of high-impact vulnerabilities, so I built one: BugAlert.org
Introducing bugalert.org, a free and open-source service for alerting security and IT professionals of high-impact and 0day vulnerabilities by email, SMS, and phone calls (and via Twitter).
Best Practices for Securing SSH in 2022
https://ift.tt/3G0Q3Lt
Submitted January 06, 2022 at 12:04AM by old-gregg
via reddit https://ift.tt/331SnTV
https://ift.tt/3G0Q3Lt
Submitted January 06, 2022 at 12:04AM by old-gregg
via reddit https://ift.tt/331SnTV
Goteleport
5 Best Practices for Securing SSH | Teleport
This article explores 5 SSH best practices you should observe to boost the security of your infrastructure.
PPTShots - Unintentionally shared data in PowerPoint presentations
https://ift.tt/3eWcTId
Submitted January 06, 2022 at 02:13AM by df_works
via reddit https://ift.tt/3JVqLB0
https://ift.tt/3eWcTId
Submitted January 06, 2022 at 02:13AM by df_works
via reddit https://ift.tt/3JVqLB0
GitHub
GitHub - dfaram7/pptshots: Finding sensitive information in the trimmed parts of cropped images
Finding sensitive information in the trimmed parts of cropped images - GitHub - dfaram7/pptshots: Finding sensitive information in the trimmed parts of cropped images
SANS Christmas Challenge 2021 - Write-up
https://ift.tt/337rEoS
Submitted January 06, 2022 at 04:39PM by the-useless-one
via reddit https://ift.tt/3JHT9qd
https://ift.tt/337rEoS
Submitted January 06, 2022 at 04:39PM by the-useless-one
via reddit https://ift.tt/3JHT9qd
Tek Fog: An App for Online Troops to Automate Hate, Manipulate Trends
https://ift.tt/3zw0Evp
Submitted January 06, 2022 at 04:10PM by goodwallboy
via reddit https://ift.tt/3qNlPoW
https://ift.tt/3zw0Evp
Submitted January 06, 2022 at 04:10PM by goodwallboy
via reddit https://ift.tt/3qNlPoW
The Wire
Tek Fog: An App With BJP Footprints for Cyber Troops to Automate Hate, Manipulate Trends
The Wire investigates claims behind the use of ‘Tek Fog’, a highly sophisticated app used by online operatives to hijack major social media and encrypted messaging platforms and amplify right-wing propaganda to a domestic audience.
Asimov Security | Enterprise Ready Security Solutions For Robotics
https://ift.tt/3zuZj8n
Submitted January 06, 2022 at 07:44PM by Da5h_Solo
via reddit https://ift.tt/3eZrgM5
https://ift.tt/3zuZj8n
Submitted January 06, 2022 at 07:44PM by Da5h_Solo
via reddit https://ift.tt/3eZrgM5
Asimovsec
Asimov Security | Enterprise Ready Cyber Security For Robotics
Enterprise Ready Cyber Security For Robotics & Robotic Components
Announcing the first open source security tool for Heroku!
https://ift.tt/32SvUc8
Submitted January 06, 2022 at 11:48PM by cloud-defender
via reddit https://ift.tt/3q0SIPH
https://ift.tt/32SvUc8
Submitted January 06, 2022 at 11:48PM by cloud-defender
via reddit https://ift.tt/3q0SIPH
GitHub
GitHub - heroku/heroku-guardian: Easy to use CLI security checks for the Heroku platform. Validate baseline security configurations…
Easy to use CLI security checks for the Heroku platform. Validate baseline security configurations for your own Heroku deployments. - GitHub - heroku/heroku-guardian: Easy to use CLI security check...
Garlicshare - Private and secure file sharing over the Tor network
https://ift.tt/3qW6yC9
Submitted January 07, 2022 at 12:06AM by ILDVUCE
via reddit https://ift.tt/31vpVJE
https://ift.tt/3qW6yC9
Submitted January 07, 2022 at 12:06AM by ILDVUCE
via reddit https://ift.tt/31vpVJE
GitHub
GitHub - R4yGM/garlicshare: Private and self-hosted file sharing over the Tor network written in golang
Private and self-hosted file sharing over the Tor network written in golang - GitHub - R4yGM/garlicshare: Private and self-hosted file sharing over the Tor network written in golang
The JNDI Strikes Back – Unauthenticated RCE in H2 Database Console
https://ift.tt/3pZHISD
Submitted January 07, 2022 at 02:52AM by SRMish3
via reddit https://ift.tt/3F7bXeF
https://ift.tt/3pZHISD
Submitted January 07, 2022 at 02:52AM by SRMish3
via reddit https://ift.tt/3F7bXeF
JFrog
JNDI-Related Vulnerability Discovered in H2 Database Console
Critical JNDI-based vulnerability exploiting the same root cause of Log4Shell. Read more from the JFrog Security Research Team describing the attack vector >
PHP 7.3-8.1 disable_functions bypass using string concatenation (PoC)
https://ift.tt/33a2oyi
Submitted January 07, 2022 at 07:42AM by dradzenglor
via reddit https://ift.tt/3t9lrnt
https://ift.tt/33a2oyi
Submitted January 07, 2022 at 07:42AM by dradzenglor
via reddit https://ift.tt/3t9lrnt
GitHub
exploits/php-concat-bypass at master · mm0r1/exploits
Pwn stuff. Contribute to mm0r1/exploits development by creating an account on GitHub.
Lopsided routing, a stealthy hole punch into FortiGate
https://ift.tt/33fwv7P
Submitted January 07, 2022 at 11:18PM by oherrala
via reddit https://ift.tt/34piFQB
https://ift.tt/33fwv7P
Submitted January 07, 2022 at 11:18PM by oherrala
via reddit https://ift.tt/34piFQB
Medium
Lopsided routing, a stealthy hole punch into FortiGate
A critical infrastructure player found a way for traffic to leak out from their isolated network and asked us for help. They had updated…
Mutual Authentication: A Component of Zero Trust
https://ift.tt/32SZZIS
Submitted January 08, 2022 at 01:26AM by alexfornuto
via reddit https://ift.tt/3G5plS8
https://ift.tt/32SZZIS
Submitted January 08, 2022 at 01:26AM by alexfornuto
via reddit https://ift.tt/3G5plS8
Pomerium
Mutual Authentication | Pomerium
This page describes the concept of mutual authentication and why it's important.
NPM might be executing malicious code in your CI without your knowledge
https://ift.tt/3G2sHoO
Submitted January 08, 2022 at 03:39AM by words_are_sacred
via reddit https://ift.tt/3q7u2Fa
https://ift.tt/3G2sHoO
Submitted January 08, 2022 at 03:39AM by words_are_sacred
via reddit https://ift.tt/3q7u2Fa
Medium
NPM might be executing malicious code in your CI without your knowledge
How to tell if you are using NPM safely within your CI
Project to Regularly and Automatically Update Docker Images that contains a lot of NetSec related tools
https://ift.tt/33dL77I
Submitted January 08, 2022 at 07:53PM by deleee
via reddit https://ift.tt/31DZj9r
https://ift.tt/33dL77I
Submitted January 08, 2022 at 07:53PM by deleee
via reddit https://ift.tt/31DZj9r
GitHub
GitHub - cybersecsi/RAUDI: A repo to automatically generate and keep updated a series of Docker images through GitHub Actions.
A repo to automatically generate and keep updated a series of Docker images through GitHub Actions. - GitHub - cybersecsi/RAUDI: A repo to automatically generate and keep updated a series of Docker...
Scanning millions of domains and compromising the email supply chain of Australia's most respected institutions
https://ift.tt/3F9WM4w
Submitted January 10, 2022 at 01:55AM by Jumpy_Resolution3089
via reddit https://ift.tt/3GgpxxR
https://ift.tt/3F9WM4w
Submitted January 10, 2022 at 01:55AM by Jumpy_Resolution3089
via reddit https://ift.tt/3GgpxxR
Caniphish
Scanning millions of domains and compromising email supply chains | CanIPhish
Scanning millions of domains and compromising the email supply chain of Australia's most respected institutions.
ProtonVPN TCP Accleration SYN+ACK Spoofing Analysis
https://ift.tt/32YCAWv
Submitted January 10, 2022 at 08:19PM by netsecfriends
via reddit https://ift.tt/32WSQY1
https://ift.tt/32YCAWv
Submitted January 10, 2022 at 08:19PM by netsecfriends
via reddit https://ift.tt/32WSQY1
remyhax.xyz
ProtonVPN TCP Accleration SYN+ACK Spoofing Analysis
I was a Private Internet Access (PIA) customer for many, many years. Some recent changes spurred me to look for a new VPN provider and I ended up landing on ProtonVPN which I’ve been using for a few months now.
Domain Escalation – sAMAccountName Spoofing
https://ift.tt/3naUVq8
Submitted January 10, 2022 at 11:46PM by netbiosX
via reddit https://ift.tt/33nrvy1
https://ift.tt/3naUVq8
Submitted January 10, 2022 at 11:46PM by netbiosX
via reddit https://ift.tt/33nrvy1
Penetration Testing Lab
Domain Escalation – sAMAccountName Spoofing
Computer accounts have the $ sign appended at the end of their names in contrast with standard user accounts. By default Microsoft operating systems lack of security controls and hardening that wou…
Abusing terminal emulators with ANSI escape characters can lead to remote DDoS, character injection and more.
https://ift.tt/3qemT6m
Submitted January 11, 2022 at 12:04AM by jat0369
via reddit https://ift.tt/3f6RrjV
https://ift.tt/3qemT6m
Submitted January 11, 2022 at 12:04AM by jat0369
via reddit https://ift.tt/3f6RrjV
Cyberark
Don’t Trust This Title: Abusing Terminal Emulators with ANSI Escape Characters
One day, while I was working on OpenShift, a Kubernetes distribution by RedHat focused on developer experience and application security, I noticed that I was able to inject ANSI escape characters...
Domain Escalation - ShadowCoerce [MS-FSRVP]
https://ift.tt/3r6tbEj
Submitted January 11, 2022 at 05:38PM by netbiosX
via reddit https://ift.tt/3ngkhCW
https://ift.tt/3r6tbEj
Submitted January 11, 2022 at 05:38PM by netbiosX
via reddit https://ift.tt/3ngkhCW
Pentest Laboratories
ShadowCoerce
Coercing the domain controller machine account to authenticate to a host which is under the control of a threat actor could lead to domain compromise. The most notable technique which involves coer…
Writing an Exploit for CVE-2021-20038 (SonicWall SSL VPN)
https://ift.tt/3K2O8bG
Submitted January 11, 2022 at 07:44PM by chicksdigthelongrun
via reddit https://ift.tt/3raA3jM
https://ift.tt/3K2O8bG
Submitted January 11, 2022 at 07:44PM by chicksdigthelongrun
via reddit https://ift.tt/3raA3jM
AttackerKB
CVE-2021-20038 | AttackerKB
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to po…