Hacking Google Drive Integrations
https://ift.tt/tZYmN1748
Submitted February 02, 2022 at 08:21PM by albinowax
via reddit https://ift.tt/DXIxslomr
https://ift.tt/tZYmN1748
Submitted February 02, 2022 at 08:21PM by albinowax
via reddit https://ift.tt/DXIxslomr
GitHub
writeups/Hacking-Google-Drive-Integrations.md at main · httpvoid/writeups
Contribute to httpvoid/writeups development by creating an account on GitHub.
Using Power Automate for Covert Data Exfiltration in Microsoft 365
https://ift.tt/wsPA3eLua
Submitted February 03, 2022 at 12:59AM by rsobers
via reddit https://ift.tt/wct1N6id5
https://ift.tt/wsPA3eLua
Submitted February 03, 2022 at 12:59AM by rsobers
via reddit https://ift.tt/wct1N6id5
Varonis
Using Power Automate for Covert Data Exfiltration in Microsoft 365
How threat actors can use Microsoft Power Automate to automate data exfiltration, C2 communication, lateral movement, and evade DLP solutions.
History of REvil: detailed report on the rise and fall of a Russian crime gang.
https://ift.tt/3DA6VIPWO
Submitted February 03, 2022 at 06:26AM by Jazzlike-Resource500
via reddit https://ift.tt/yQ5lM7hLR
https://ift.tt/3DA6VIPWO
Submitted February 03, 2022 at 06:26AM by Jazzlike-Resource500
via reddit https://ift.tt/yQ5lM7hLR
Analyst1
History of REvil - Analyst1
Jon DiMaggio dives in depth on the history of the REvil Ransomware Gang. While many researchers and media organizations have produced reports on REvil, most of the accounts detail specific attacks, telling only part of REvil’s story. The purpose of this white…
[CVE-2022-23602] Don't trust comments
https://ift.tt/13Nxmpi4o
Submitted February 03, 2022 at 03:51PM by crower
via reddit https://ift.tt/xcYdWI1P4
https://ift.tt/13Nxmpi4o
Submitted February 03, 2022 at 03:51PM by crower
via reddit https://ift.tt/xcYdWI1P4
nns.ee
Don't trust comments
And habitually review the third party code you're using - even when it's in thestandard library.
NTLM Relaying - A comprehensive guide
https://ift.tt/d3W1MiJpS
Submitted February 03, 2022 at 08:28PM by jeanc0re
via reddit https://ift.tt/ZhtCXFHpk
https://ift.tt/d3W1MiJpS
Submitted February 03, 2022 at 08:28PM by jeanc0re
via reddit https://ift.tt/ZhtCXFHpk
TrustedSec
I’m bringing relaying back: A comprehensive guide on relaying anno 2022 - TrustedSec
The first comprehensive resource about relaying that will walk you through the attack primitives that continue to work today including some lesser known attacks.
A detailed analysis of Lazarus malware disguised as Notepad++ Shell Extension
https://ift.tt/w2sXl7mLZ
Submitted February 04, 2022 at 12:58AM by CyberMasterV
via reddit https://ift.tt/oxRr8hmJv
https://ift.tt/w2sXl7mLZ
Submitted February 04, 2022 at 12:58AM by CyberMasterV
via reddit https://ift.tt/oxRr8hmJv
reddit
A detailed analysis of Lazarus malware disguised as Notepad++...
Posted in r/netsec by u/CyberMasterV • 37 points and 10 comments
Compromising out-of-bound secrets on Argo CD platform utilizing a malicious Kubernetes Helm Chart (CVE-2022-24348)
https://ift.tt/K4nfPD6
Submitted February 04, 2022 at 12:37PM by dalmoz
via reddit https://ift.tt/BZlgh3F
https://ift.tt/K4nfPD6
Submitted February 04, 2022 at 12:37PM by dalmoz
via reddit https://ift.tt/BZlgh3F
Apiiro | Deep Application Security Posture Management (ASPM)
Malicious Kubernetes Helm charts can be used to steal sensitive information from Argo CD deployments
Apiiro's Security Research team has discovered a major vulnerability in Argo CD platform (CVE-2022-24348).
Silly proof of concept: Anti-phishing using perceptual hashing algorithms
https://ift.tt/fvHuZcj
Submitted February 04, 2022 at 07:24PM by anvilventures
via reddit https://ift.tt/YK6laZP
https://ift.tt/fvHuZcj
Submitted February 04, 2022 at 07:24PM by anvilventures
via reddit https://ift.tt/YK6laZP
Anvil Secure
Silly proof of concept: Anti-phishing using perceptual hashing algorithms - Anvil Secure
by Diego Freijo Welcome to the first dispatch coming out of the Ministry of Silly Ideas! It’s a space we’ve got inside Anvil where we encourage ourselves to come up with interesting-even-if-sounding-silly-at-first-glance ideas around security or IT in general.…
Multiple vulnerabilities in Nooie baby monitor
https://ift.tt/BtvHdAX
Submitted February 04, 2022 at 09:43PM by jaymzu
via reddit https://ift.tt/BU4EkaX
https://ift.tt/BtvHdAX
Submitted February 04, 2022 at 09:43PM by jaymzu
via reddit https://ift.tt/BU4EkaX
Bitdefender Labs
Vulnerabilities Identified in Nooie Baby Monitor
At Bitdefender, we care deeply about security, so we’ve been working with media
partners and IoT devices manufacturers to identify vulnerabilities in the
world’s best-selling connected devices.
partners and IoT devices manufacturers to identify vulnerabilities in the
world’s best-selling connected devices.
Rooting Gryphon Routers via Shared VPN : 🎵 This LAN is your LAN, this LAN is my LAN 🎵
https://ift.tt/R6z2qp7
Submitted February 05, 2022 at 12:16AM by stargravy
via reddit https://ift.tt/UvYn7Lc
https://ift.tt/R6z2qp7
Submitted February 05, 2022 at 12:16AM by stargravy
via reddit https://ift.tt/UvYn7Lc
Medium
Rooting Gryphon Routers via Shared VPN
🎵 This LAN is your LAN, this LAN is my LAN 🎵
Linux | Madaidan's Insecurities
https://ift.tt/v1lcm04
Submitted February 05, 2022 at 01:35AM by Nhamatanda
via reddit https://ift.tt/Qec120y
https://ift.tt/v1lcm04
Submitted February 05, 2022 at 01:35AM by Nhamatanda
via reddit https://ift.tt/Qec120y
Reddit
From the netsec community on Reddit: Linux | Madaidan's Insecurities
Posted by Nhamatanda - 2 votes and 11 comments
CISSP Domain 1 - Episode 4 - Business Case, Types of Project Plans, Organizational Process, Change Management and Data Classification by Get Set CISSP
https://ift.tt/BzfoK4g
Submitted February 05, 2022 at 12:56PM by Tradition_Wonderful
via reddit https://ift.tt/COa8Rb1
https://ift.tt/BzfoK4g
Submitted February 05, 2022 at 12:56PM by Tradition_Wonderful
via reddit https://ift.tt/COa8Rb1
Anchor
CISSP Domain 1 - Episode 4 - Business Case, Types of Project Plans, Organizational Process, Change Management and Data Classification…
In this episode I talk about the concept of Business Case, Types of Project Plans, Organizational Process, Change Management and Data Classification which are essentials from an exam and real life security practice perspective.
If you like this episode do…
If you like this episode do…
Testing Infrastructure-as-Code Using Dynamic Tooling
https://ift.tt/NFE39Lr
Submitted February 05, 2022 at 05:40PM by digicat
via reddit https://ift.tt/xYO7kMP
https://ift.tt/NFE39Lr
Submitted February 05, 2022 at 05:40PM by digicat
via reddit https://ift.tt/xYO7kMP
NCC Group Research Blog
Testing Infrastructure-as-Code Using Dynamic Tooling
Erik Steringer, NCC Group Overview TL;DR: Go check out As public cloud service consumption has grown, engineering and security professionals have responded with different tools and techniques to ac…
CVE-2022-24348 Argo CD Vulnerability and its impact on Kubernetes
https://ift.tt/GnZfwuN
Submitted February 06, 2022 at 02:44PM by rippatpop
via reddit https://ift.tt/nYzqyFC
https://ift.tt/GnZfwuN
Submitted February 06, 2022 at 02:44PM by rippatpop
via reddit https://ift.tt/nYzqyFC
ARMO
CVE-2022-24348 Argo CD Vulnerability and its impact on Kubernetes
A major software supply chain critical vulnerability CVE-2022-24348 was discovered in the popular open-source CD platform Argo CD. See its impact on Kubernetes here
Software Defined Radio, Part 6: Building a Cellphone IMSI Catcher (Stingray)
https://ift.tt/p6Bsej8
Submitted February 06, 2022 at 03:18PM by digicat
via reddit https://ift.tt/B8j9x2Z
https://ift.tt/p6Bsej8
Submitted February 06, 2022 at 03:18PM by digicat
via reddit https://ift.tt/B8j9x2Z
Reddit
From the netsec community on Reddit: Software Defined Radio, Part 6: Building a Cellphone IMSI Catcher (Stingray)
Posted by digicat - 210 votes and 14 comments
GUARDARA, a software quality assurance platform to identify bugs and zero-day vulnerabilities at scale, is now free for individual security researchers and non-commercial open-source projects.
https://guardara.com
Submitted February 06, 2022 at 10:34PM by JohnKeymanUK
via reddit https://ift.tt/Gan2Iqb
https://guardara.com
Submitted February 06, 2022 at 10:34PM by JohnKeymanUK
via reddit https://ift.tt/Gan2Iqb
Guardara
Build secure, rock-solid software | Build secure, rock-solid software
The most comprehensive negative testing / fuzz testing platform to hunt down bugs and zero-day vulnerabilities.
OSCP preparation - Buffer Overflow: VANILLA EIP OVERWRITE AND SEH
https://ift.tt/dyiaKfL
Submitted February 06, 2022 at 10:53PM by CyberMasterV
via reddit https://ift.tt/adXO3GP
https://ift.tt/dyiaKfL
Submitted February 06, 2022 at 10:53PM by CyberMasterV
via reddit https://ift.tt/adXO3GP
Reddit
From the netsec community on Reddit: OSCP preparation - Buffer Overflow: VANILLA EIP OVERWRITE AND SEH
Posted by CyberMasterV - No votes and no comments
#Phishing like early 90's. Spoofing emails when DMARC isn't available or commonly known as "SPF-BYPASS".
https://ift.tt/7T1VJOE
Submitted February 07, 2022 at 07:57AM by intruderK
via reddit https://ift.tt/iE3U8XZ
https://ift.tt/7T1VJOE
Submitted February 07, 2022 at 07:57AM by intruderK
via reddit https://ift.tt/iE3U8XZ
www.redteam.cafe
Long Live DMARC - Email Spoof issues | Intruder
Spoof emails when SPF is present but DMARC is not allowing you to spoof the sender
Linux Persistence using Systemd Generators. They will run early at boot and can be used to create services and disable other services before they start.
https://ift.tt/V3X2ZyW
Submitted February 07, 2022 at 01:44PM by dashboard_monkey
via reddit https://ift.tt/1GLC4WX
https://ift.tt/V3X2ZyW
Submitted February 07, 2022 at 01:44PM by dashboard_monkey
via reddit https://ift.tt/1GLC4WX
pepe berba
Hunting for Persistence in Linux (Part 5): Systemd Generators
How attackers can insert backdoors early in the boot process using systemd generators
UEFI firmware vulnerabilities affect at least 25 computer vendors
https://ift.tt/wpJAnEa
Submitted February 07, 2022 at 02:58PM by TryptamineEntity
via reddit https://ift.tt/qiGCBnZ
https://ift.tt/wpJAnEa
Submitted February 07, 2022 at 02:58PM by TryptamineEntity
via reddit https://ift.tt/qiGCBnZ
Reddit
From the netsec community on Reddit: UEFI firmware vulnerabilities affect at least 25 computer vendors
Explore this post and more from the netsec community
A deeper dive into CVE-2021-39137 – a Golang security bug that Rust would have prevented
https://ift.tt/Bzl6ZQF
Submitted February 07, 2022 at 06:49PM by digicat
via reddit https://ift.tt/gOiWZkY
https://ift.tt/Bzl6ZQF
Submitted February 07, 2022 at 06:49PM by digicat
via reddit https://ift.tt/gOiWZkY
NCC Group Research
A deeper dive into CVE-2021-39137 – a Golang security bug that Rust would have prevented
This blog post discusses two erroneous computation patterns in Golang. By erroneous computation we mean simply that given certain input, a computer program with certain state returns incorrect output or enters an incorrect state. While clearly there are no…