Don't have time to read the entire Conti leak? Read the summary and stay up to date.
https://ift.tt/oKlMgRN
Submitted March 02, 2022 at 07:16PM by jat0369
via reddit https://ift.tt/Igh9BaH
https://ift.tt/oKlMgRN
Submitted March 02, 2022 at 07:16PM by jat0369
via reddit https://ift.tt/Igh9BaH
Cyberark
Threat Research Blog
moodle 2nd order sqli 0-day
https://ift.tt/u5RkWvE
Submitted March 02, 2022 at 10:19PM by mufinnnnnnn
via reddit https://ift.tt/sKrYLvl
https://ift.tt/u5RkWvE
Submitted March 02, 2022 at 10:19PM by mufinnnnnnn
via reddit https://ift.tt/sKrYLvl
reddit
moodle 2nd order sqli 0-day
Posted in r/netsec by u/mufinnnnnnn • 1 point and 0 comments
Bypassing Google's Cloud Armor firewall with an 8 KB request
https://ift.tt/KO9LGqW
Submitted March 03, 2022 at 10:49AM by almostfamous
via reddit https://ift.tt/64MA8Gj
https://ift.tt/KO9LGqW
Submitted March 03, 2022 at 10:49AM by almostfamous
via reddit https://ift.tt/64MA8Gj
Kloudle
Piercing the Cloud Armor - The 8KB bypass in Google Cloud Platform WAF
Google Cloud Armor provides a rule-based policy framework that can be used by customers of the Google Cloud Platform to mitigate various types of common web application attacks. The Cloud Armor service has a documented limitation of 8 KB as the maximum size…
List of free relevant services offered to Ukrainians during the conflict
https://ift.tt/oXFxrjh
Submitted March 03, 2022 at 02:43PM by woja111
via reddit https://ift.tt/QW3aZmX
https://ift.tt/oXFxrjh
Submitted March 03, 2022 at 02:43PM by woja111
via reddit https://ift.tt/QW3aZmX
Google Docs
Free Cyber & Humanitarian Services for Ukraine
Sheet1
FREE Cybersecurity & Humanitarian Services for the Ukraine War
Est. 24 Feb 2022
⚠ This is a constant work in progress ⚠,<a href="https://ukrainestrong.tech/">ukrainestrong.tech</a>
Please Twitter DM (<a href="https://twitter.com/chrisculling">@c…
FREE Cybersecurity & Humanitarian Services for the Ukraine War
Est. 24 Feb 2022
⚠ This is a constant work in progress ⚠,<a href="https://ukrainestrong.tech/">ukrainestrong.tech</a>
Please Twitter DM (<a href="https://twitter.com/chrisculling">@c…
A Closer Look at the Russian Actors Targeting Organizations in Ukraine
https://ift.tt/pNjHT0m
Submitted March 03, 2022 at 10:50PM by CyberMasterV
via reddit https://ift.tt/9RbzDfT
https://ift.tt/pNjHT0m
Submitted March 03, 2022 at 10:50PM by CyberMasterV
via reddit https://ift.tt/9RbzDfT
LIFARS, a SecurityScorecard company
A Closer Look at the Russian Actors Targeting Organizations in Ukraine
In the context of the ongoing war between Russia and Ukraine, we have reviewed the cyberattacks against the Ukrainian organizations that occurred in A Closer Look at the Russian Actors Targeting Organizations in Ukraine
SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store
https://ift.tt/Xvi87YL
Submitted March 04, 2022 at 01:55AM by Goovscoov
via reddit https://ift.tt/V7BoG2Y
https://ift.tt/Xvi87YL
Submitted March 04, 2022 at 01:55AM by Goovscoov
via reddit https://ift.tt/V7BoG2Y
Fox-IT International blog
SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store
Authors: Alberto Segura, Malware analystRolf Govers, Malware analyst & Forensic IT Expert NCC Group, as well as many other researchers noticed a rise in Android malware last year, especillay An…
Analysing 3177 organisations to track the 10 most popular email spam and malware filters
https://ift.tt/wg4BIXx
Submitted March 04, 2022 at 04:51AM by Jumpy_Resolution3089
via reddit https://ift.tt/h6iOQYN
https://ift.tt/wg4BIXx
Submitted March 04, 2022 at 04:51AM by Jumpy_Resolution3089
via reddit https://ift.tt/h6iOQYN
Caniphish
The 10 Most Popular Secure Email Gateways 2022 | CanIPhish
Take a look at hard statistics on what the 10 most popular secure email gateways of 2022 are.
Finding an Authorization Bypass on my Own Website - SQL Injection in a Parameterized Query
https://ift.tt/pXS9ABI
Submitted March 04, 2022 at 12:19PM by mdulin2
via reddit https://ift.tt/dwK4ITW
https://ift.tt/pXS9ABI
Submitted March 04, 2022 at 12:19PM by mdulin2
via reddit https://ift.tt/dwK4ITW
reddit
Finding an Authorization Bypass on my Own Website - SQL Injection...
Posted in r/netsec by u/mdulin2 • 2 points and 0 comments
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
https://ift.tt/PWCB1Mn
Submitted March 04, 2022 at 07:04AM by YuvalAvra
via reddit https://ift.tt/fzOyvlj
https://ift.tt/PWCB1Mn
Submitted March 04, 2022 at 07:04AM by YuvalAvra
via reddit https://ift.tt/fzOyvlj
Unit42
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
CVE-2022-0492 is the third recent kernel vulnerability that allows malicious containers to escape. We offer root cause analysis and mitigations.
Hacking Hadoukens: Reverse Engineering a Street Fighter Two Cabinet
https://ift.tt/d0R1CIS
Submitted March 04, 2022 at 07:46PM by wrongbaud
via reddit https://ift.tt/TlG9t41
https://ift.tt/d0R1CIS
Submitted March 04, 2022 at 07:46PM by wrongbaud
via reddit https://ift.tt/TlG9t41
reddit
Hacking Hadoukens: Reverse Engineering a Street Fighter Two Cabinet
Posted in r/netsec by u/wrongbaud • 1 point and 0 comments
ICS & OT Risk and Vulnerability Report
https://ift.tt/JDniBWK
Submitted March 04, 2022 at 07:22PM by h4ck3dit
via reddit https://ift.tt/IkmCSsx
https://ift.tt/JDniBWK
Submitted March 04, 2022 at 07:22PM by h4ck3dit
via reddit https://ift.tt/IkmCSsx
Claroty
Claroty ICS Risk and Vulnerability Report for 2H 2021
Claroty's Biannual ICS Risk and Vulnerability Report provides an analysis of OT, ICS, and IoT vulnerabilities disclosed in the 2H of 2021.
The perils of the “real” client IP [or the many ways to use X-Forwarded-For for incorrectly]
https://ift.tt/786oCeD
Submitted March 05, 2022 at 04:20AM by yesyoucantrip
via reddit https://ift.tt/REGvWix
https://ift.tt/786oCeD
Submitted March 05, 2022 at 04:20AM by yesyoucantrip
via reddit https://ift.tt/REGvWix
reddit
The perils of the “real” client IP [or the many ways to use...
Posted in r/netsec by u/yesyoucantrip • 1 point and 0 comments
webOS Revisited - Even More Mistaken Identities · The Recurity Lablog
https://ift.tt/PBQXZFl
Submitted March 05, 2022 at 11:23PM by addelindh
via reddit https://ift.tt/GfU7d52
https://ift.tt/PBQXZFl
Submitted March 05, 2022 at 11:23PM by addelindh
via reddit https://ift.tt/GfU7d52
reddit
webOS Revisited - Even More Mistaken Identities · The Recurity Lablog
Posted in r/netsec by u/addelindh • 93 points and 6 comments
Escaping privileged containers for fun.
https://ift.tt/wmHcxkY
Submitted March 06, 2022 at 03:25PM by JordyZomer
via reddit https://ift.tt/21W0pYd
https://ift.tt/wmHcxkY
Submitted March 06, 2022 at 03:25PM by JordyZomer
via reddit https://ift.tt/21W0pYd
pwning.systems
Escaping privileged containers for fun
Despite the fact that it is not a 'real' vulnerability, escaping privileged Docker containers is nevertheless pretty funny. And because there will always be people who will come up with reasons or excuses to run a privileged container (even though you really…
Backdooring WordPress using PyShell
https://ift.tt/zoCidyS
Submitted March 07, 2022 at 12:06AM by jonas02
via reddit https://ift.tt/hSPkaI1
https://ift.tt/zoCidyS
Submitted March 07, 2022 at 12:06AM by jonas02
via reddit https://ift.tt/hSPkaI1
WPSec
Backdooring WordPress using PyShell - WPSec
PyShell is new tool made for bug bounty, ethical hacking, penetration testers or red-teamers. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells, the main goal of the tool is to use as little…
2021 Year In Review - Tools, TTPs, and more!
https://ift.tt/eGTRtkK
Submitted March 07, 2022 at 06:18PM by TheDFIRReport
via reddit https://ift.tt/7bAGlu3
https://ift.tt/eGTRtkK
Submitted March 07, 2022 at 06:18PM by TheDFIRReport
via reddit https://ift.tt/7bAGlu3
The DFIR Report
2021 Year In Review
As we come to the end of the first quarter of 2022, we want to take some time to look back over our cases from 2021, in aggregate, and look at some of the top tactics, techniques and procedures (TT…
Hi, I have updated the scodescanner v2.0 which has integration of semgrep and scans the pHP source code. I used this tool on 1000+ files and observed that number of SQL injections and XSSes were found along with SSRFs, Open redirection. Github - https://ift.tt/Rqdt6Dj
https://ift.tt/t6ZLc9r
Submitted March 07, 2022 at 07:03PM by agrawal7
via reddit https://ift.tt/tGx3RlW
https://ift.tt/t6ZLc9r
Submitted March 07, 2022 at 07:03PM by agrawal7
via reddit https://ift.tt/tGx3RlW
GitHub
GitHub - agrawalsmart7/scodescanner: SCodeScanner stands for Source Code scanner where the user can scans the source code for finding…
SCodeScanner stands for Source Code scanner where the user can scans the source code for finding the Critical Vulnerabilities. - GitHub - agrawalsmart7/scodescanner: SCodeScanner stands for Source...
Critical Cross-Account Vulnerability Found in Microsoft Azure Automation Service
https://ift.tt/XsDIM32
Submitted March 07, 2022 at 08:41PM by FoShizzleMyWeasle
via reddit https://ift.tt/7xs1i6D
https://ift.tt/XsDIM32
Submitted March 07, 2022 at 08:41PM by FoShizzleMyWeasle
via reddit https://ift.tt/7xs1i6D
Complete Cloud Security in Minutes - Orca Security
AutoWarp Microsoft Azure Automation Vulnerability - Orca Security
AutoWarp is a critical vulnerability in Microsoft Azure Automation Service that allows unauthorized access to other customer accounts using the service.
Kerbit, the Ethiopian firm that discovered multiple vulnerabilities on voip monitor last week, has now blogged about 3 vulnerabilities that are chained to a preauth RCE on Pascom Cloud phone systems. It is a must read, everything is detailed in the article.
https://ift.tt/5ZKqmUi
Submitted March 07, 2022 at 10:08PM by nathanAbejeM
via reddit https://ift.tt/g9G0cSW
https://ift.tt/5ZKqmUi
Submitted March 07, 2022 at 10:08PM by nathanAbejeM
via reddit https://ift.tt/g9G0cSW
reddit
Kerbit, the Ethiopian firm that discovered multiple...
Posted in r/netsec by u/nathanAbejeM • 0 points and 0 comments
The Dirty Pipe Vulnerability [CVE-2022-0847]
https://ift.tt/mWIwbed
Submitted March 07, 2022 at 08:14PM by moviuro
via reddit https://ift.tt/7VyXahH
https://ift.tt/mWIwbed
Submitted March 07, 2022 at 08:14PM by moviuro
via reddit https://ift.tt/7VyXahH
reddit
The Dirty Pipe Vulnerability [CVE-2022-0847]
Posted in r/netsec by u/moviuro • 2 points and 0 comments
PreAuth RCE in Passcom Cloud Phone Systems found by Kerbit Security Firm.
https://ift.tt/5ZKqmUi
Submitted March 08, 2022 at 01:30PM by nathanAbejeM
via reddit https://ift.tt/lrbXAsk
https://ift.tt/5ZKqmUi
Submitted March 08, 2022 at 01:30PM by nathanAbejeM
via reddit https://ift.tt/lrbXAsk
reddit
PreAuth RCE in Passcom Cloud Phone Systems found by Kerbit...
Posted in r/netsec by u/nathanAbejeM • 3 points and 0 comments