How we abused named pipes for smart-card hijacking, unauthorized file system access to client machines and more.
https://ift.tt/34AQXQZ
Submitted January 11, 2022 at 11:58PM by jat0369
via reddit https://ift.tt/3HWvrVq
https://ift.tt/34AQXQZ
Submitted January 11, 2022 at 11:58PM by jat0369
via reddit https://ift.tt/3HWvrVq
Cyberark
Attacking RDP from Inside: How we abused named pipes for smart-card hijacking, unauthorized file system access to client machines…
In this blog post we are going to discuss the details of a vulnerability in Windows Remote Desktop Services, which we recently uncovered. We reported the vulnerability to Microsoft in a...
[CFP] Call for Papers for Hardwear.io Security Conference USA 2022 is OPEN!
https://ift.tt/3GAX5al
Submitted January 12, 2022 at 03:35PM by hardweario
via reddit https://ift.tt/33qxsu6
https://ift.tt/3GAX5al
Submitted January 12, 2022 at 03:35PM by hardweario
via reddit https://ift.tt/33qxsu6
www.hardwear.io
Call for Papers | hardwear.io | USA 2022
hardwear.io USA 2022 - Hardware Security Conference & Training is seeking innovative research on attacks or mitigation on any hardware. Submit your research paper.
Ransomware Actor May Have Leaked Their Previous Victims
https://ift.tt/3tlUf5a
Submitted January 12, 2022 at 07:08PM by Acrobatic-Pen-9949
via reddit https://ift.tt/3KgmnwH
https://ift.tt/3tlUf5a
Submitted January 12, 2022 at 07:08PM by Acrobatic-Pen-9949
via reddit https://ift.tt/3KgmnwH
reddit
Ransomware Actor May Have Leaked Their Previous Victims
Posted in r/netsec by u/Acrobatic-Pen-9949 • 1 point and 0 comments
Researchers release final version of academic study testing 25 EDR and EPP vendors against attacks vectors via CPL, HTA, DLL and EXE
https://ift.tt/3FlTI5i
Submitted January 12, 2022 at 07:02PM by woja111
via reddit https://ift.tt/3Ieyqc3
https://ift.tt/3FlTI5i
Submitted January 12, 2022 at 07:02PM by woja111
via reddit https://ift.tt/3Ieyqc3
Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle's Shibboleth
https://ift.tt/3zPHjWl
Submitted January 12, 2022 at 08:03PM by albinowax
via reddit https://ift.tt/3ngysrt
https://ift.tt/3zPHjWl
Submitted January 12, 2022 at 08:03PM by albinowax
via reddit https://ift.tt/3ngysrt
Haxolot
Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle's Shibboleth
In our previous blogpost we have introduced a pre-auth RCE in Moodles Shibboleth plugin. This RCE could be triggered when Moodle was configured to store sessions in individual files which is the default configuration for new installations. However, Moodle…
Malicious modifications to open source projects affecting thousands
https://ift.tt/3Gq3eWs
Submitted January 12, 2022 at 09:35PM by MiguelHzBz
via reddit https://ift.tt/3qkMaf9
https://ift.tt/3Gq3eWs
Submitted January 12, 2022 at 09:35PM by MiguelHzBz
via reddit https://ift.tt/3qkMaf9
Sysdig
Malicious modifications to open source projects affecting thousands - Sysdig Secure – Sysdig
Two extremely popular JavaScript open source packages, colors.js, and faker.js, were maliciously modified to the point of being unusable.
Exploit Kits vs. Google Chrome
https://ift.tt/3zQsvGZ
Submitted January 12, 2022 at 10:38PM by stashing_the_smack
via reddit https://ift.tt/3K5BPLS
https://ift.tt/3zQsvGZ
Submitted January 12, 2022 at 10:38PM by stashing_the_smack
via reddit https://ift.tt/3K5BPLS
Gendigital
Exploit Kits vs. Google Chrome
Chromium Exploits Fail to Gain Traction
ThePhish is an open-source tool that automates the entire phishing email analysis process starting from the extraction of the observables from the header and the body of an email to the elaboration of a verdict which is final in most cases. It is based on TheHive, Cortex and MISP.
https://ift.tt/3DHbcc3
Submitted January 12, 2022 at 07:45PM by emalderson
via reddit https://ift.tt/33s9n6a
https://ift.tt/3DHbcc3
Submitted January 12, 2022 at 07:45PM by emalderson
via reddit https://ift.tt/33s9n6a
GitHub
GitHub - emalderson/ThePhish: ThePhish: an automated phishing email analysis tool
ThePhish: an automated phishing email analysis tool - GitHub - emalderson/ThePhish: ThePhish: an automated phishing email analysis tool
Exploiting URL Parsing Confusion Vulnerabilities
https://ift.tt/3tlqm4O
Submitted January 13, 2022 at 03:44AM by ScottContini
via reddit https://ift.tt/3zTTAJp
https://ift.tt/3tlqm4O
Submitted January 13, 2022 at 03:44AM by ScottContini
via reddit https://ift.tt/3zTTAJp
Claroty
Exploiting URL Parsing Confusion
Discover how inconsistencies in different libraries parse URLs can be abused by attackers with Team82 and Claroty.
HiddenWall is a tool to generate a custom Hidden firewall to run in Linux kernel.
https://ift.tt/33vwuwo
Submitted January 13, 2022 at 05:32PM by CoolerVoid
via reddit https://ift.tt/3GrtCPY
https://ift.tt/33vwuwo
Submitted January 13, 2022 at 05:32PM by CoolerVoid
via reddit https://ift.tt/3GrtCPY
This noscript analyses the Nmap XML scanning results, parses each CPE context and correlates to search CVE on NIST. You can use that to find public vulnerabilities in services.
https://ift.tt/3K81bsj
Submitted January 13, 2022 at 05:14PM by CoolerVoid
via reddit https://ift.tt/3I620QR
https://ift.tt/3K81bsj
Submitted January 13, 2022 at 05:14PM by CoolerVoid
via reddit https://ift.tt/3I620QR
GitHub
GitHub - CoolerVoid/Vision2: Nmap's XML result parse and NVD's CPE correlation to search CVE.
Nmap's XML result parse and NVD's CPE correlation to search CVE. - GitHub - CoolerVoid/Vision2: Nmap's XML result parse and NVD's CPE correlation to search CVE.
DNS records of 1% .fi domains exposed through Zone Transfers
https://ift.tt/3FrccBI
Submitted January 13, 2022 at 09:20PM by ValtteriLe
via reddit https://ift.tt/3Gpkifi
https://ift.tt/3FrccBI
Submitted January 13, 2022 at 09:20PM by ValtteriLe
via reddit https://ift.tt/3Gpkifi
Shufflingbytes
DNS records of 1% .fi domains exposed through Zone Transfers
Post describing my experiment of finding out how commonly nameservers are misconfigured to allow zone transfers
SSH Bastion Host Best Practices
https://ift.tt/3zYb9rz
Submitted January 13, 2022 at 11:22PM by old-gregg
via reddit https://ift.tt/3GqTHP7
https://ift.tt/3zYb9rz
Submitted January 13, 2022 at 11:22PM by old-gregg
via reddit https://ift.tt/3GqTHP7
Goteleport
SSH Bastion host best practices: How to Build and Deploy a Security-Hardened SSH Bastion Host
Learn best practices to build and deploy a security-hardened SSH bastion host based on OpenSSH server.
BreakingFormation: Orca Security Research Team Discovers AWS CloudFormation Vulnerability
https://ift.tt/33gXHTV
Submitted January 14, 2022 at 12:04AM by eberkut
via reddit https://ift.tt/33uhdfp
https://ift.tt/33gXHTV
Submitted January 14, 2022 at 12:04AM by eberkut
via reddit https://ift.tt/33uhdfp
Complete Cloud Security in Minutes | Orca Security
Orca Discovers AWS CloudFormation Vulnerability - Orca Security
Orca Security’s vulnerability researcher, Tzah Pahima, discovered a zero day AWS CloudFormation vulnerability, which AWS quickly mitigated within 6 days.
Forensics Analysis of the NSO Group’s Pegasus Spyware
https://ift.tt/3I66RSa
Submitted January 14, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/3rf8lme
https://ift.tt/3I66RSa
Submitted January 14, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/3rf8lme
LIFARS, Your Cyber Resiliency Partner
Forensics Analysis of the NSO Group’s Pegasus Spyware
NSO’s Group Pegasus spyware was mentioned multiple times during 2021 in the media. It has been heavily analyzed by organizations such as Amnesty Forensics Analysis of the NSO Group’s Pegasus Spyware
Propagating phishing via Slack webhooks
https://ift.tt/3rfqL6m
Submitted January 14, 2022 at 03:43AM by amirshk
via reddit https://ift.tt/3npQ0BI
https://ift.tt/3rfqL6m
Submitted January 14, 2022 at 03:43AM by amirshk
via reddit https://ift.tt/3npQ0BI
Medium
Propagating phishing via Slack webhooks
“Are slack webhooks a secret or not?”
A Deep Dive into The Grief Ransomware’s Capabilities
https://ift.tt/3rdlTyk
Submitted January 15, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/33wW30e
https://ift.tt/3rdlTyk
Submitted January 15, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/33wW30e
10 real-world stories of how we’ve compromised CI/CD pipelines
https://ift.tt/3Grpmjt
Submitted January 15, 2022 at 11:03AM by digicat
via reddit https://ift.tt/3qtcu6I
https://ift.tt/3Grpmjt
Submitted January 15, 2022 at 11:03AM by digicat
via reddit https://ift.tt/3qtcu6I
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
PinataHub: Exposing what developers push is OS projects
https://ift.tt/3Idz4qd
Submitted January 15, 2022 at 03:24PM by sp00kyphiss
via reddit https://ift.tt/3GzViSA
https://ift.tt/3Idz4qd
Submitted January 15, 2022 at 03:24PM by sp00kyphiss
via reddit https://ift.tt/3GzViSA
pinatahub.incognita.tech
PinataHub - Explore the world of leaked secrets in GitHub.
PinataHub is the most wide and comprehensive database of publicly leaked secrets from careless developers.
A Detailed Guide to cracking the OSWE Certification
https://ift.tt/3quPeVZ
Submitted January 15, 2022 at 07:56PM by YashitM
via reddit https://ift.tt/3tvIA3x
https://ift.tt/3quPeVZ
Submitted January 15, 2022 at 07:56PM by YashitM
via reddit https://ift.tt/3tvIA3x
reddit
A Detailed Guide to cracking the OSWE Certification
Posted in r/netsec by u/YashitM • 7 points and 2 comments
IndexedDB in Safari 15 leaks your browsing activity in real time
https://ift.tt/3A3ZMyk
Submitted January 15, 2022 at 09:57PM by Synchisis
via reddit https://ift.tt/3GCfGTd
https://ift.tt/3A3ZMyk
Submitted January 15, 2022 at 09:57PM by Synchisis
via reddit https://ift.tt/3GCfGTd
Fingerprintjs
Exploiting IndexedDB API information leaks in Safari 15
In this article we discuss a software bug introduced in Safari 15’s implementation of the IndexedDB API that lets any website track your internet activity and even reveal your identity.