Forensics Analysis of the NSO Group’s Pegasus Spyware
https://ift.tt/3I66RSa
Submitted January 14, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/3rf8lme
https://ift.tt/3I66RSa
Submitted January 14, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/3rf8lme
LIFARS, Your Cyber Resiliency Partner
Forensics Analysis of the NSO Group’s Pegasus Spyware
NSO’s Group Pegasus spyware was mentioned multiple times during 2021 in the media. It has been heavily analyzed by organizations such as Amnesty Forensics Analysis of the NSO Group’s Pegasus Spyware
Propagating phishing via Slack webhooks
https://ift.tt/3rfqL6m
Submitted January 14, 2022 at 03:43AM by amirshk
via reddit https://ift.tt/3npQ0BI
https://ift.tt/3rfqL6m
Submitted January 14, 2022 at 03:43AM by amirshk
via reddit https://ift.tt/3npQ0BI
Medium
Propagating phishing via Slack webhooks
“Are slack webhooks a secret or not?”
A Deep Dive into The Grief Ransomware’s Capabilities
https://ift.tt/3rdlTyk
Submitted January 15, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/33wW30e
https://ift.tt/3rdlTyk
Submitted January 15, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/33wW30e
10 real-world stories of how we’ve compromised CI/CD pipelines
https://ift.tt/3Grpmjt
Submitted January 15, 2022 at 11:03AM by digicat
via reddit https://ift.tt/3qtcu6I
https://ift.tt/3Grpmjt
Submitted January 15, 2022 at 11:03AM by digicat
via reddit https://ift.tt/3qtcu6I
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
PinataHub: Exposing what developers push is OS projects
https://ift.tt/3Idz4qd
Submitted January 15, 2022 at 03:24PM by sp00kyphiss
via reddit https://ift.tt/3GzViSA
https://ift.tt/3Idz4qd
Submitted January 15, 2022 at 03:24PM by sp00kyphiss
via reddit https://ift.tt/3GzViSA
pinatahub.incognita.tech
PinataHub - Explore the world of leaked secrets in GitHub.
PinataHub is the most wide and comprehensive database of publicly leaked secrets from careless developers.
A Detailed Guide to cracking the OSWE Certification
https://ift.tt/3quPeVZ
Submitted January 15, 2022 at 07:56PM by YashitM
via reddit https://ift.tt/3tvIA3x
https://ift.tt/3quPeVZ
Submitted January 15, 2022 at 07:56PM by YashitM
via reddit https://ift.tt/3tvIA3x
reddit
A Detailed Guide to cracking the OSWE Certification
Posted in r/netsec by u/YashitM • 7 points and 2 comments
IndexedDB in Safari 15 leaks your browsing activity in real time
https://ift.tt/3A3ZMyk
Submitted January 15, 2022 at 09:57PM by Synchisis
via reddit https://ift.tt/3GCfGTd
https://ift.tt/3A3ZMyk
Submitted January 15, 2022 at 09:57PM by Synchisis
via reddit https://ift.tt/3GCfGTd
Fingerprintjs
Exploiting IndexedDB API information leaks in Safari 15
In this article we discuss a software bug introduced in Safari 15’s implementation of the IndexedDB API that lets any website track your internet activity and even reveal your identity.
Free copy of The ssh Plumber's Handbook
https://ift.tt/3n9gw2V
Submitted January 16, 2022 at 11:44AM by markcartertm
via reddit https://ift.tt/3K9IIMh
https://ift.tt/3n9gw2V
Submitted January 16, 2022 at 11:44AM by markcartertm
via reddit https://ift.tt/3K9IIMh
GitHub
GitHub - opsdisk/the_cyber_plumbers_handbook: Free copy of The Cyber Plumber's Handbook
Free copy of The Cyber Plumber's Handbook. Contribute to opsdisk/the_cyber_plumbers_handbook development by creating an account on GitHub.
You're running untrusted code!
https://ift.tt/3FAwcBI
Submitted January 17, 2022 at 12:27AM by nfrankel
via reddit https://ift.tt/3qyWErt
https://ift.tt/3FAwcBI
Submitted January 17, 2022 at 12:27AM by nfrankel
via reddit https://ift.tt/3qyWErt
A Java geek
You're running untrusted code!
Last December, Log4Shell shortened the nights of many people in the JVM world. Worse, using the earthquake analogy caused many aftershocks after the initial quake. I immediately made the connection between Log4Shell and the Security Manager. At first, I didn’t…
Domain Persistence – Machine Account
https://ift.tt/3Fz2ptq
Submitted January 17, 2022 at 07:41PM by netbiosX
via reddit https://ift.tt/34RQtWR
https://ift.tt/3Fz2ptq
Submitted January 17, 2022 at 07:41PM by netbiosX
via reddit https://ift.tt/34RQtWR
Penetration Testing Lab
Domain Persistence – Machine Account
Machine accounts play a role in red team operations as in a number of techniques are utilized for privilege escalation, lateral movement and domain escalation. However, there are also cases which a…
Capturing RDP NetNTLMv2 Hashes: Attack details and a Technical How-To Guide - GoSecure
https://ift.tt/3Ib7yJM
Submitted January 18, 2022 at 12:25AM by obilodeau
via reddit https://ift.tt/3KiuNDy
https://ift.tt/3Ib7yJM
Submitted January 18, 2022 at 12:25AM by obilodeau
via reddit https://ift.tt/3KiuNDy
GoSecure
Capturing RDP NetNTLMv2 Hashes: Attack details and a Technical How-To Guide - GoSecure
We will explore RDP security modes and learn how NetNTLMv2 hash capture via monster-in-the-middle works, putting it into practice using PyRDP.
Stealing administrative JWT's through post auth SSRF - VMWare Workspace One Access (CVE-2021-22056)
https://ift.tt/3fwtoer
Submitted January 18, 2022 at 08:42AM by Mempodipper
via reddit https://ift.tt/3fPqPVb
https://ift.tt/3fwtoer
Submitted January 18, 2022 at 08:42AM by Mempodipper
via reddit https://ift.tt/3fPqPVb
Assetnote
Stealing administrative JWT's through post auth SSRF (CVE-2021-22056)
Application security issues found by Assetnote
Public exploit POC for critical windows http RCE impacting multiple windows versions
https://ift.tt/3fvhKjV
Submitted January 18, 2022 at 10:17AM by markcartertm
via reddit https://ift.tt/33tdHlR
https://ift.tt/3fvhKjV
Submitted January 18, 2022 at 10:17AM by markcartertm
via reddit https://ift.tt/33tdHlR
GitHub
GitHub - ZZ-SOCMAP/CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907 - ZZ-SOCMAP/CVE-2022-21907
An attempt to understand container runtime
https://ift.tt/3tzgKUj
Submitted January 18, 2022 at 01:11PM by alt-glitch
via reddit https://ift.tt/3A8JhRK
https://ift.tt/3tzgKUj
Submitted January 18, 2022 at 01:11PM by alt-glitch
via reddit https://ift.tt/3A8JhRK
computer insecurities
An attempt to understand container runtime
Demystifying containers with `containerd`
How to securely implement TLS certificate checking in Android apps
https://ift.tt/3FCgZjB
Submitted January 18, 2022 at 07:01PM by Masrepus
via reddit https://ift.tt/3A7EfFj
https://ift.tt/3FCgZjB
Submitted January 18, 2022 at 07:01PM by Masrepus
via reddit https://ift.tt/3A7EfFj
Guardsquare
Implementing TLS Certificate Checking in Android Apps | Guardsquare
Learn how you can avoid potential TLS certificate issues and secure your android app in cases where you need to deviate from the default approach.
Telenot Complex: Insecure AES Key Generation
https://ift.tt/3fA8P0F
Submitted January 18, 2022 at 09:39PM by 0xdea
via reddit https://ift.tt/3tDmR9W
https://ift.tt/3fA8P0F
Submitted January 18, 2022 at 09:39PM by 0xdea
via reddit https://ift.tt/3tDmR9W
X41 D-SEC
Telenot Complex: Insecure AES Key Generation
CVE-2021-34600: How predictable random numbers (literally) open the door for attackers: Our discovery of a flaw in the generation of AES keys, used for both physical and remote access, in a popular alarm system’s parameterization software. Includes a proof…
Dahua DVRs and Webcams bruteforcer at port 37777
https://ift.tt/3tIra49
Submitted January 18, 2022 at 09:33PM by falx1fer
via reddit https://ift.tt/3nBwgvc
https://ift.tt/3tIra49
Submitted January 18, 2022 at 09:33PM by falx1fer
via reddit https://ift.tt/3nBwgvc
GitHub
GitHub - d34db33f-1007/asleep_scanner: Dahua DVRs bruteforcer at port 37777
Dahua DVRs bruteforcer at port 37777. Contribute to d34db33f-1007/asleep_scanner development by creating an account on GitHub.
Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling all of web-forms, entry points, or links with data.
https://ift.tt/3tL4Bvk
Submitted January 18, 2022 at 09:27PM by falx1fer
via reddit https://ift.tt/3rs8d2S
https://ift.tt/3tL4Bvk
Submitted January 18, 2022 at 09:27PM by falx1fer
via reddit https://ift.tt/3rs8d2S
GitHub
GitHub - d34db33f-1007/fuzz300: Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling…
Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling all of web-forms, entry points, or links with data. - GitHub - d34db33f-1007/fuzz300: Robust and bl...
Vulnerable AWS Lambda function - Initial access in cloud attacks
https://ift.tt/3nD8JK3
Submitted January 18, 2022 at 09:53PM by MiguelHzBz
via reddit https://ift.tt/34Vi8Gl
https://ift.tt/3nD8JK3
Submitted January 18, 2022 at 09:53PM by MiguelHzBz
via reddit https://ift.tt/34Vi8Gl
Sysdig
Vulnerable AWS Lambda function - Initial access in cloud attacks – Sysdig
The security research team explains the attack scenario with a vulnerable AWS Lambda function could be used by attackers.
A Beginner’s guide into Router Hacking and Firmware Emulation
https://ift.tt/3tDqSLR
Submitted January 18, 2022 at 09:53PM by secnigma
via reddit https://ift.tt/3IhIqB2
https://ift.tt/3tDqSLR
Submitted January 18, 2022 at 09:53PM by secnigma
via reddit https://ift.tt/3IhIqB2
SecNigma
A Beginner’s guide into Router Hacking and Firmware Emulation
Prelude This post is about the personal experiences of me; A noobie hacker- who is super new into router reversing and the challenges I had to face, the research I did and the things I had learned …
Zooming in on Zero-click Exploits (Project Zero)
https://ift.tt/3KlkYEU
Submitted January 19, 2022 at 12:37AM by albinowax
via reddit https://ift.tt/33G0yWl
https://ift.tt/3KlkYEU
Submitted January 19, 2022 at 12:37AM by albinowax
via reddit https://ift.tt/33G0yWl
Blogspot
Zooming in on Zero-click Exploits
Posted by Natalie Silvanovich, Project Zero Zoom is a video conferencing platform that has gained popularity throughout the pandemic. U...