Zimbra Email - Stealing Clear-Text Credentials via Memcache injection
https://ift.tt/mXvlHfN
Submitted June 14, 2022 at 09:50PM by 0xdea
via reddit https://ift.tt/nbXemNT
https://ift.tt/mXvlHfN
Submitted June 14, 2022 at 09:50PM by 0xdea
via reddit https://ift.tt/nbXemNT
Sonarsource
Zimbra Email - Stealing Clear-Text Credentials via Memcache injection
We discovered flaws in Zimbra, an enterprise email solution, that allow attackers to steal credentials of users and gain access to their email accounts.
CVE-2022-25845 – Analyzing the Fastjson “Auto Type Bypass” RCE vulnerability
https://ift.tt/gST6anl
Submitted June 14, 2022 at 09:08PM by SRMish3
via reddit https://ift.tt/dbXscfy
https://ift.tt/gST6anl
Submitted June 14, 2022 at 09:08PM by SRMish3
via reddit https://ift.tt/dbXscfy
JFrog
CVE-2022-25845 - Fastjson RCE vulnerability analysis
CVE-2022-25845 has a high potential impact but conditions for attack are not trivial. Read technical analysis and mitigation guidance of the Fastjson RCE vulnerability
What if you don't secure SSH on EC2? - Analysis of the real threats
https://ift.tt/SaAZDuP
Submitted June 14, 2022 at 08:55PM by capitangolo
via reddit https://ift.tt/gaw4YPs
https://ift.tt/SaAZDuP
Submitted June 14, 2022 at 08:55PM by capitangolo
via reddit https://ift.tt/gaw4YPs
Sysdig
Securing SSH on EC2: What are the real threats?
Securing SSH is one of the main controls of CIS Benchmark, but what are the real threats to ssh exposure? Brute force, credential leaks, ...
Oblivious HTTP
https://ift.tt/nyEDsWp
Submitted June 14, 2022 at 11:24PM by nangaparbat
via reddit https://ift.tt/9HJTlte
https://ift.tt/nyEDsWp
Submitted June 14, 2022 at 11:24PM by nangaparbat
via reddit https://ift.tt/9HJTlte
www.ietf.org
Oblivious HTTP
This document describes a system for the forwarding of encrypted HTTP messages.
This allows a client to make multiple requests of a server without the server being able
to link those requests to the client or to identify the requests as having come
from the…
This allows a client to make multiple requests of a server without the server being able
to link those requests to the client or to identify the requests as having come
from the…
Hertzbleed - a new family of side-channel attacks
https://ift.tt/cEfmOvK
Submitted June 15, 2022 at 12:51AM by CyberMasterV
via reddit https://ift.tt/BwcHbzs
https://ift.tt/cEfmOvK
Submitted June 15, 2022 at 12:51AM by CyberMasterV
via reddit https://ift.tt/BwcHbzs
Hertzbleed
Hertzbleed Attack
Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86
TPM Sniffing Attacks Against Non-Bitlocker Targets
https://ift.tt/CZsHQc0
Submitted June 15, 2022 at 06:59AM by Gallus
via reddit https://ift.tt/C6FXNLB
https://ift.tt/CZsHQc0
Submitted June 15, 2022 at 06:59AM by Gallus
via reddit https://ift.tt/C6FXNLB
English
TPM Sniffing Attacks Against Non-Bitlocker Targets | Secura
Preboot passwords are important when using BitLocker to prevent all kinds of attacks. One of those attacks is the ability to sniff the TPM chip communication and recover the decryption key. This article shows you how to attack Linux disk encryption and provides…
Bypassing CSP with dangling iframes
https://ift.tt/uLGfStT
Submitted June 15, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/5ur87a1
https://ift.tt/uLGfStT
Submitted June 15, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/5ur87a1
PortSwigger Research
Bypassing CSP with dangling iframes
Introduction Our Web Security Academy has a topic on dangling markup injection - a technique for exploiting sites protected by CSP. But something interesting happened when we came to update to Chrome
Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup
https://ift.tt/sErC2lI
Submitted June 15, 2022 at 11:29AM by alain_proviste
via reddit https://ift.tt/PzF31mR
https://ift.tt/sErC2lI
Submitted June 15, 2022 at 11:29AM by alain_proviste
via reddit https://ift.tt/PzF31mR
doar-e.github.io
Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup
Quick Malware Analysis: TA578 Thread-hijacked email, Bumblebee, and Cobalt Strike pcap from 2022-06-14
https://ift.tt/iq1vB0z
Submitted June 15, 2022 at 07:35PM by dougburks
via reddit https://ift.tt/fcTEe1n
https://ift.tt/iq1vB0z
Submitted June 15, 2022 at 07:35PM by dougburks
via reddit https://ift.tt/fcTEe1n
blog.securityonion.net
Quick Malware Analysis: TA578 Thread-hijacked email, Bumblebee, and Cobalt Strike pcap from 2022-06-14
Thanks to Brad Duncan for sharing this pcap! https://www.malware-traffic-analysis.net/2022/06/14/index.html We did a quick analysis of this ...
Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu
https://ift.tt/mrJkvWZ
Submitted June 15, 2022 at 07:29PM by Gallus
via reddit https://ift.tt/IynQhJK
https://ift.tt/mrJkvWZ
Submitted June 15, 2022 at 07:29PM by Gallus
via reddit https://ift.tt/IynQhJK
fred's notes
Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu
In this post, we attack the Nest Hub (2nd Gen), an always-connected smart home display from Google, in order to boot a custom OS. First, we explore both hardware and software attack surface in search of security vulnerabilities that could permit arbitrary…
Pulling MikroTik into the Limelight
https://ift.tt/4xWI2oX
Submitted June 16, 2022 at 01:48AM by 0xdea
via reddit https://ift.tt/tOPB4df
https://ift.tt/4xWI2oX
Submitted June 16, 2022 at 01:48AM by 0xdea
via reddit https://ift.tt/tOPB4df
Margin Research
Pulling MikroTik into the Limelight
A comprehensive guide to MikroTik internals, including IPC, hand-rolled cryptography, and a novel post-authentication jailbreak
fast and furious OSCP monkeys doing weird things - learn how to exploit validate suid
https://ift.tt/GmgC9fh
Submitted June 16, 2022 at 06:29AM by Dreg_fr33project
via reddit https://ift.tt/edJE3Nz
https://ift.tt/GmgC9fh
Submitted June 16, 2022 at 06:29AM by Dreg_fr33project
via reddit https://ift.tt/edJE3Nz
Medium
fast and furious OSCP monkeys doing weird things
disclaimer: these post series are just for fun and should not be readed by anyone
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://ift.tt/oGrJ5x7
Submitted June 16, 2022 at 09:42AM by cryptogram
via reddit https://ift.tt/eSOfwbF
https://ift.tt/oGrJ5x7
Submitted June 16, 2022 at 09:42AM by cryptogram
via reddit https://ift.tt/eSOfwbF
Volexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or […]
Think that a Ransomware cannot target your OneDrive and Sharepoint environments? Think again!
https://ift.tt/EFQuIa8
Submitted June 16, 2022 at 04:28PM by Environmental-Art446
via reddit https://ift.tt/OAfVohJ
https://ift.tt/EFQuIa8
Submitted June 16, 2022 at 04:28PM by Environmental-Art446
via reddit https://ift.tt/OAfVohJ
Proofpoint
Office 365 Allows Ransomware in OneDrive & SharePoint | Proofpoint US
Learn more about a potentially harmful Office 365 functionality that allows ransomware to encrypt files stored on SharePoint and OneDrive. Read more with Proofpoint.
Shadow Credentials - Red Teaming Experiments
https://ift.tt/RDpYmhk
Submitted June 16, 2022 at 04:13PM by Kondencuotaspienas
via reddit https://ift.tt/uxF6cfq
https://ift.tt/RDpYmhk
Submitted June 16, 2022 at 04:13PM by Kondencuotaspienas
via reddit https://ift.tt/uxF6cfq
www.ired.team
Shadow Credentials
Persistence, lateral movement
VED (Vault Exploit Defense): Open source implementation
https://ift.tt/xdUOl4X
Submitted June 16, 2022 at 06:58PM by hardenedvault
via reddit https://ift.tt/UbtJ79O
https://ift.tt/xdUOl4X
Submitted June 16, 2022 at 06:58PM by hardenedvault
via reddit https://ift.tt/UbtJ79O
hardenedvault.net
VED (Vault Exploit Defense): Open source implementation
VED - Linux kernel threat detection and prevention system LKM version of VED goes public finally.
Quick Malware Analysis Using Free Tools: Malware infection from Brazil malspam pcap from 2022-04-19
https://ift.tt/lTWXNPy
Submitted June 16, 2022 at 08:17PM by dougburks
via reddit https://ift.tt/Bu2s8Lr
https://ift.tt/lTWXNPy
Submitted June 16, 2022 at 08:17PM by dougburks
via reddit https://ift.tt/Bu2s8Lr
blog.securityonion.net
Quick Malware Analysis: Malware infection from Brazil malspam pcap from 2022-04-19
Thanks to Brad Duncan for sharing this pcap! https://www.malware-traffic-analysis.net/2022/04/19/index2.html We did a quick analysis of this...
The Android kernel mitigations obstacle race
https://ift.tt/ejsbQRV
Submitted June 16, 2022 at 09:51PM by 0xdea
via reddit https://ift.tt/bqVpsd8
https://ift.tt/ejsbQRV
Submitted June 16, 2022 at 09:51PM by 0xdea
via reddit https://ift.tt/bqVpsd8
The GitHub Blog
The Android kernel mitigations obstacle race | The GitHub Blog
In this post I’ll exploit CVE-2022-22057, a use-after-free in the Qualcomm gpu kernel driver, to gain root and disable SELinux from the untrusted app sandbox on a Samsung Z flip 3. I’ll look at various mitigations that are implemented on modern Android devices…
CVE-2022-23088: Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack
https://ift.tt/WZVIERw
Submitted June 16, 2022 at 11:23PM by Gallus
via reddit https://ift.tt/tcHCYwe
https://ift.tt/WZVIERw
Submitted June 16, 2022 at 11:23PM by Gallus
via reddit https://ift.tt/tcHCYwe
Zero Day Initiative
Zero Day Initiative — CVE-2022-23088: Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack
In April of this year, FreeBSD patched a 13-year-old heap overflow in the Wi-Fi stack that could allow network-adjacent attackers to execute arbitrary code on affected installations of FreeBSD Kernel. This bug was originally reported to the ZDI program by…
That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability
https://ift.tt/jycgpPs
Submitted June 17, 2022 at 12:37AM by jat0369
via reddit https://ift.tt/mXbGR1E
https://ift.tt/jycgpPs
Submitted June 17, 2022 at 12:37AM by jat0369
via reddit https://ift.tt/mXbGR1E
Cyberark
That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability
On January 11, 2022, we published a blog post describing the details of CVE-2022-21893, a Remote Desktop vulnerability that we found and reported to Microsoft. After analyzing the patch that fixed...
Analysing RTF files from SideWinder APT
https://ift.tt/wTNd6AV
Submitted June 17, 2022 at 12:17AM by OwnPreparation3424
via reddit https://ift.tt/xGbAwaj
https://ift.tt/wTNd6AV
Submitted June 17, 2022 at 12:17AM by OwnPreparation3424
via reddit https://ift.tt/xGbAwaj
Medium
404 — File still found
In early February 2022, we came across a tweet from ShadowChasing1 identifying a SideWinder-related word document which referenced a template URL. In this article, we share our insights from…