Ukrainian Security Researcher Leaks Conti Ransomware Gang Data
https://ift.tt/vRha7Po
Submitted February 28, 2022 at 10:54AM by ferrochron1
via reddit https://ift.tt/JmDX0kV
https://ift.tt/vRha7Po
Submitted February 28, 2022 at 10:54AM by ferrochron1
via reddit https://ift.tt/JmDX0kV
Databreachtoday
Ukrainian Researcher Leaks Conti Ransomware Gang Data
A Ukrainian cybersecurity researcher has released a huge batch of data that came from the internal systems of the Conti ransomware gang. The researcher released the
Prepare for a post-pandemic career in application security
https://ift.tt/7fWDR6w
Submitted February 28, 2022 at 05:19PM by saigopika
via reddit https://ift.tt/vRjuHmA
https://ift.tt/7fWDR6w
Submitted February 28, 2022 at 05:19PM by saigopika
via reddit https://ift.tt/vRjuHmA
AppSecEngineer
How to Prepare for A Post-Pandemic Career in Application Security
Are you looking for a career in application security in 2022? Here's what you need to know to land a job in a competitive tech landscape.
Alan c2 Framework v6.0: Alan + JavaScript = ♡
https://ift.tt/eCbYlEX
Submitted February 28, 2022 at 09:57PM by aparata_s4tan
via reddit https://ift.tt/0gpzSmU
https://ift.tt/eCbYlEX
Submitted February 28, 2022 at 09:57PM by aparata_s4tan
via reddit https://ift.tt/0gpzSmU
Blogspot
Alan c2 Framework v6.0: Alan + JavaScript = ♡
Twitter: @s4tan Download: https://github.com/enkomio/AlanFramework/releases/latest Documentation: https://github.com/enkomio/AlanFr...
Rouge RDP: New Initial Access Technique via RDP Bypassing Clients/Servers/Security Vendors
https://ift.tt/30VGIb9
Submitted February 28, 2022 at 10:03PM by ustayready
via reddit https://ift.tt/xDcbJpI
https://ift.tt/30VGIb9
Submitted February 28, 2022 at 10:03PM by ustayready
via reddit https://ift.tt/xDcbJpI
Black Hills Information Security, Inc.
Rogue RDP – Revisiting Initial Access Methods - Black Hills Information Security, Inc.
Mike Felch // The Hunt for Initial Access With the default disablement of VBA macros originating from the internet, Microsoft may be pitching a curveball to threat actors and red […]
Breaking Google’s ReCaptcha v2 using.. Google.. Again
https://ift.tt/qOsJ97W
Submitted March 01, 2022 at 12:10AM by n0llbyte
via reddit https://ift.tt/r9MvAOY
https://ift.tt/qOsJ97W
Submitted March 01, 2022 at 12:10AM by n0llbyte
via reddit https://ift.tt/r9MvAOY
East-Ee Security (By Yair Mizrahi)
Re-ReBreakCaptcha: Breaking Google’s ReCaptcha v2 using.. Google.. Again
TL;DR A logic vulnerability working 5 years later, dubbed ReBreakCaptcha, which lets you easily bypass Google’s ReCaptcha v2 anywhere on the web. ReCaptcha Overview Many of us know of ReCaptcha, Go…
Exploiting CVE-2021-26708 (Linux kernel) with sshd
https://ift.tt/ZnWzfAR
Submitted March 01, 2022 at 01:34PM by hardenedvault
via reddit https://ift.tt/75jKYp8
https://ift.tt/ZnWzfAR
Submitted March 01, 2022 at 01:34PM by hardenedvault
via reddit https://ift.tt/75jKYp8
Reddit
From the netsec community on Reddit: Exploiting CVE-2021-26708 (Linux kernel) with sshd
Explore this post and more from the netsec community
TeaBot is now spreading across the globe | Cleafy Labs
https://ift.tt/0JIifOc
Submitted March 01, 2022 at 04:47PM by f3d_0x0
via reddit https://ift.tt/pOmifCB
https://ift.tt/0JIifOc
Submitted March 01, 2022 at 04:47PM by f3d_0x0
via reddit https://ift.tt/pOmifCB
Cleafy
TeaBot is now spreading across the globe | Cleafy Labs
Since TeaBot first discovery in 2021, Cleafy's Threat Intelligence Team has been following this banking trojan's trails to understand how it acts against banks. To know more, read here our latest report.
Multiple vulnerabilities found in voip monitor by an Ethiopian Security firm
https://ift.tt/HkORNra
Submitted March 01, 2022 at 06:57PM by nathanAbejeM
via reddit https://ift.tt/w6beFio
https://ift.tt/HkORNra
Submitted March 01, 2022 at 06:57PM by nathanAbejeM
via reddit https://ift.tt/w6beFio
Reddit
From the netsec community on Reddit: Multiple vulnerabilities found in voip monitor by an Ethiopian Security firm
Posted by nathanAbejeM - 5 votes and no comments
Triaging A Malicious Docker Container
https://ift.tt/Z2hi1jE
Submitted March 01, 2022 at 10:04PM by MiguelHzBz
via reddit https://ift.tt/S7lMfVI
https://ift.tt/Z2hi1jE
Submitted March 01, 2022 at 10:04PM by MiguelHzBz
via reddit https://ift.tt/S7lMfVI
Sysdig
Triaging a Malicious Docker Container
We have outlined some steps for rapid triage of a malicious untrusted Docker container running in our environment.
5 New Vulnerabilities in PJSIP Multimedia Library, including RCE
https://ift.tt/sQAvIgm
Submitted March 02, 2022 at 12:23AM by SRMish3
via reddit https://ift.tt/qOt6iUl
https://ift.tt/sQAvIgm
Submitted March 02, 2022 at 12:23AM by SRMish3
via reddit https://ift.tt/qOt6iUl
JFrog
JFrog Discloses 5 Memory Corruption Vulnerabilities in PJSIP - A Popular Multimedia Library
JFrog Security disclosed 5 vulnerabilities in PJSIP, exposing applications to code execution or denial of service attacks. Learn who is impacted and how to fix >
Guardio security team discovered an active network of sophisticated crypto attacks targeting the MetaMask wallet
https://ift.tt/ESC1sBx
Submitted March 02, 2022 at 01:53PM by oldrobgin
via reddit https://ift.tt/RX7mF1w
https://ift.tt/ESC1sBx
Submitted March 02, 2022 at 01:53PM by oldrobgin
via reddit https://ift.tt/RX7mF1w
Medium
How to lose all your money in the Metaverse (before even getting started)
By Avihay Kain & Efrat Tabibi, Security Research at Guardio.
How to analyze malicious documents – Case study of an attack targeting Ukrainian Organizations
https://ift.tt/NEk1F2T
Submitted March 02, 2022 at 07:38PM by CyberMasterV
via reddit https://ift.tt/7LnVeOv
https://ift.tt/NEk1F2T
Submitted March 02, 2022 at 07:38PM by CyberMasterV
via reddit https://ift.tt/7LnVeOv
reddit
How to analyze malicious documents – Case study of an attack...
Posted in r/netsec by u/CyberMasterV • 2 points and 0 comments
Don't have time to read the entire Conti leak? Read the summary and stay up to date.
https://ift.tt/oKlMgRN
Submitted March 02, 2022 at 07:16PM by jat0369
via reddit https://ift.tt/Igh9BaH
https://ift.tt/oKlMgRN
Submitted March 02, 2022 at 07:16PM by jat0369
via reddit https://ift.tt/Igh9BaH
Cyberark
Threat Research Blog
moodle 2nd order sqli 0-day
https://ift.tt/u5RkWvE
Submitted March 02, 2022 at 10:19PM by mufinnnnnnn
via reddit https://ift.tt/sKrYLvl
https://ift.tt/u5RkWvE
Submitted March 02, 2022 at 10:19PM by mufinnnnnnn
via reddit https://ift.tt/sKrYLvl
reddit
moodle 2nd order sqli 0-day
Posted in r/netsec by u/mufinnnnnnn • 1 point and 0 comments
Bypassing Google's Cloud Armor firewall with an 8 KB request
https://ift.tt/KO9LGqW
Submitted March 03, 2022 at 10:49AM by almostfamous
via reddit https://ift.tt/64MA8Gj
https://ift.tt/KO9LGqW
Submitted March 03, 2022 at 10:49AM by almostfamous
via reddit https://ift.tt/64MA8Gj
Kloudle
Piercing the Cloud Armor - The 8KB bypass in Google Cloud Platform WAF
Google Cloud Armor provides a rule-based policy framework that can be used by customers of the Google Cloud Platform to mitigate various types of common web application attacks. The Cloud Armor service has a documented limitation of 8 KB as the maximum size…
List of free relevant services offered to Ukrainians during the conflict
https://ift.tt/oXFxrjh
Submitted March 03, 2022 at 02:43PM by woja111
via reddit https://ift.tt/QW3aZmX
https://ift.tt/oXFxrjh
Submitted March 03, 2022 at 02:43PM by woja111
via reddit https://ift.tt/QW3aZmX
Google Docs
Free Cyber & Humanitarian Services for Ukraine
Sheet1
FREE Cybersecurity & Humanitarian Services for the Ukraine War
Est. 24 Feb 2022
⚠ This is a constant work in progress ⚠,<a href="https://ukrainestrong.tech/">ukrainestrong.tech</a>
Please Twitter DM (<a href="https://twitter.com/chrisculling">@c…
FREE Cybersecurity & Humanitarian Services for the Ukraine War
Est. 24 Feb 2022
⚠ This is a constant work in progress ⚠,<a href="https://ukrainestrong.tech/">ukrainestrong.tech</a>
Please Twitter DM (<a href="https://twitter.com/chrisculling">@c…
A Closer Look at the Russian Actors Targeting Organizations in Ukraine
https://ift.tt/pNjHT0m
Submitted March 03, 2022 at 10:50PM by CyberMasterV
via reddit https://ift.tt/9RbzDfT
https://ift.tt/pNjHT0m
Submitted March 03, 2022 at 10:50PM by CyberMasterV
via reddit https://ift.tt/9RbzDfT
LIFARS, a SecurityScorecard company
A Closer Look at the Russian Actors Targeting Organizations in Ukraine
In the context of the ongoing war between Russia and Ukraine, we have reviewed the cyberattacks against the Ukrainian organizations that occurred in A Closer Look at the Russian Actors Targeting Organizations in Ukraine
SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store
https://ift.tt/Xvi87YL
Submitted March 04, 2022 at 01:55AM by Goovscoov
via reddit https://ift.tt/V7BoG2Y
https://ift.tt/Xvi87YL
Submitted March 04, 2022 at 01:55AM by Goovscoov
via reddit https://ift.tt/V7BoG2Y
Fox-IT International blog
SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store
Authors: Alberto Segura, Malware analystRolf Govers, Malware analyst & Forensic IT Expert NCC Group, as well as many other researchers noticed a rise in Android malware last year, especillay An…
Analysing 3177 organisations to track the 10 most popular email spam and malware filters
https://ift.tt/wg4BIXx
Submitted March 04, 2022 at 04:51AM by Jumpy_Resolution3089
via reddit https://ift.tt/h6iOQYN
https://ift.tt/wg4BIXx
Submitted March 04, 2022 at 04:51AM by Jumpy_Resolution3089
via reddit https://ift.tt/h6iOQYN
Caniphish
The 10 Most Popular Secure Email Gateways 2022 | CanIPhish
Take a look at hard statistics on what the 10 most popular secure email gateways of 2022 are.
Finding an Authorization Bypass on my Own Website - SQL Injection in a Parameterized Query
https://ift.tt/pXS9ABI
Submitted March 04, 2022 at 12:19PM by mdulin2
via reddit https://ift.tt/dwK4ITW
https://ift.tt/pXS9ABI
Submitted March 04, 2022 at 12:19PM by mdulin2
via reddit https://ift.tt/dwK4ITW
reddit
Finding an Authorization Bypass on my Own Website - SQL Injection...
Posted in r/netsec by u/mdulin2 • 2 points and 0 comments
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
https://ift.tt/PWCB1Mn
Submitted March 04, 2022 at 07:04AM by YuvalAvra
via reddit https://ift.tt/fzOyvlj
https://ift.tt/PWCB1Mn
Submitted March 04, 2022 at 07:04AM by YuvalAvra
via reddit https://ift.tt/fzOyvlj
Unit42
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
CVE-2022-0492 is the third recent kernel vulnerability that allows malicious containers to escape. We offer root cause analysis and mitigations.