Bypassing CSP with dangling iframes
https://ift.tt/uLGfStT
Submitted June 15, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/5ur87a1
https://ift.tt/uLGfStT
Submitted June 15, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/5ur87a1
PortSwigger Research
Bypassing CSP with dangling iframes
Introduction Our Web Security Academy has a topic on dangling markup injection - a technique for exploiting sites protected by CSP. But something interesting happened when we came to update to Chrome
Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup
https://ift.tt/sErC2lI
Submitted June 15, 2022 at 11:29AM by alain_proviste
via reddit https://ift.tt/PzF31mR
https://ift.tt/sErC2lI
Submitted June 15, 2022 at 11:29AM by alain_proviste
via reddit https://ift.tt/PzF31mR
doar-e.github.io
Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup
Quick Malware Analysis: TA578 Thread-hijacked email, Bumblebee, and Cobalt Strike pcap from 2022-06-14
https://ift.tt/iq1vB0z
Submitted June 15, 2022 at 07:35PM by dougburks
via reddit https://ift.tt/fcTEe1n
https://ift.tt/iq1vB0z
Submitted June 15, 2022 at 07:35PM by dougburks
via reddit https://ift.tt/fcTEe1n
blog.securityonion.net
Quick Malware Analysis: TA578 Thread-hijacked email, Bumblebee, and Cobalt Strike pcap from 2022-06-14
Thanks to Brad Duncan for sharing this pcap! https://www.malware-traffic-analysis.net/2022/06/14/index.html We did a quick analysis of this ...
Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu
https://ift.tt/mrJkvWZ
Submitted June 15, 2022 at 07:29PM by Gallus
via reddit https://ift.tt/IynQhJK
https://ift.tt/mrJkvWZ
Submitted June 15, 2022 at 07:29PM by Gallus
via reddit https://ift.tt/IynQhJK
fred's notes
Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu
In this post, we attack the Nest Hub (2nd Gen), an always-connected smart home display from Google, in order to boot a custom OS. First, we explore both hardware and software attack surface in search of security vulnerabilities that could permit arbitrary…
Pulling MikroTik into the Limelight
https://ift.tt/4xWI2oX
Submitted June 16, 2022 at 01:48AM by 0xdea
via reddit https://ift.tt/tOPB4df
https://ift.tt/4xWI2oX
Submitted June 16, 2022 at 01:48AM by 0xdea
via reddit https://ift.tt/tOPB4df
Margin Research
Pulling MikroTik into the Limelight
A comprehensive guide to MikroTik internals, including IPC, hand-rolled cryptography, and a novel post-authentication jailbreak
fast and furious OSCP monkeys doing weird things - learn how to exploit validate suid
https://ift.tt/GmgC9fh
Submitted June 16, 2022 at 06:29AM by Dreg_fr33project
via reddit https://ift.tt/edJE3Nz
https://ift.tt/GmgC9fh
Submitted June 16, 2022 at 06:29AM by Dreg_fr33project
via reddit https://ift.tt/edJE3Nz
Medium
fast and furious OSCP monkeys doing weird things
disclaimer: these post series are just for fun and should not be readed by anyone
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://ift.tt/oGrJ5x7
Submitted June 16, 2022 at 09:42AM by cryptogram
via reddit https://ift.tt/eSOfwbF
https://ift.tt/oGrJ5x7
Submitted June 16, 2022 at 09:42AM by cryptogram
via reddit https://ift.tt/eSOfwbF
Volexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or […]
Think that a Ransomware cannot target your OneDrive and Sharepoint environments? Think again!
https://ift.tt/EFQuIa8
Submitted June 16, 2022 at 04:28PM by Environmental-Art446
via reddit https://ift.tt/OAfVohJ
https://ift.tt/EFQuIa8
Submitted June 16, 2022 at 04:28PM by Environmental-Art446
via reddit https://ift.tt/OAfVohJ
Proofpoint
Office 365 Allows Ransomware in OneDrive & SharePoint | Proofpoint US
Learn more about a potentially harmful Office 365 functionality that allows ransomware to encrypt files stored on SharePoint and OneDrive. Read more with Proofpoint.
Shadow Credentials - Red Teaming Experiments
https://ift.tt/RDpYmhk
Submitted June 16, 2022 at 04:13PM by Kondencuotaspienas
via reddit https://ift.tt/uxF6cfq
https://ift.tt/RDpYmhk
Submitted June 16, 2022 at 04:13PM by Kondencuotaspienas
via reddit https://ift.tt/uxF6cfq
www.ired.team
Shadow Credentials
Persistence, lateral movement
VED (Vault Exploit Defense): Open source implementation
https://ift.tt/xdUOl4X
Submitted June 16, 2022 at 06:58PM by hardenedvault
via reddit https://ift.tt/UbtJ79O
https://ift.tt/xdUOl4X
Submitted June 16, 2022 at 06:58PM by hardenedvault
via reddit https://ift.tt/UbtJ79O
hardenedvault.net
VED (Vault Exploit Defense): Open source implementation
VED - Linux kernel threat detection and prevention system LKM version of VED goes public finally.
Quick Malware Analysis Using Free Tools: Malware infection from Brazil malspam pcap from 2022-04-19
https://ift.tt/lTWXNPy
Submitted June 16, 2022 at 08:17PM by dougburks
via reddit https://ift.tt/Bu2s8Lr
https://ift.tt/lTWXNPy
Submitted June 16, 2022 at 08:17PM by dougburks
via reddit https://ift.tt/Bu2s8Lr
blog.securityonion.net
Quick Malware Analysis: Malware infection from Brazil malspam pcap from 2022-04-19
Thanks to Brad Duncan for sharing this pcap! https://www.malware-traffic-analysis.net/2022/04/19/index2.html We did a quick analysis of this...
The Android kernel mitigations obstacle race
https://ift.tt/ejsbQRV
Submitted June 16, 2022 at 09:51PM by 0xdea
via reddit https://ift.tt/bqVpsd8
https://ift.tt/ejsbQRV
Submitted June 16, 2022 at 09:51PM by 0xdea
via reddit https://ift.tt/bqVpsd8
The GitHub Blog
The Android kernel mitigations obstacle race | The GitHub Blog
In this post I’ll exploit CVE-2022-22057, a use-after-free in the Qualcomm gpu kernel driver, to gain root and disable SELinux from the untrusted app sandbox on a Samsung Z flip 3. I’ll look at various mitigations that are implemented on modern Android devices…
CVE-2022-23088: Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack
https://ift.tt/WZVIERw
Submitted June 16, 2022 at 11:23PM by Gallus
via reddit https://ift.tt/tcHCYwe
https://ift.tt/WZVIERw
Submitted June 16, 2022 at 11:23PM by Gallus
via reddit https://ift.tt/tcHCYwe
Zero Day Initiative
Zero Day Initiative — CVE-2022-23088: Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack
In April of this year, FreeBSD patched a 13-year-old heap overflow in the Wi-Fi stack that could allow network-adjacent attackers to execute arbitrary code on affected installations of FreeBSD Kernel. This bug was originally reported to the ZDI program by…
That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability
https://ift.tt/jycgpPs
Submitted June 17, 2022 at 12:37AM by jat0369
via reddit https://ift.tt/mXbGR1E
https://ift.tt/jycgpPs
Submitted June 17, 2022 at 12:37AM by jat0369
via reddit https://ift.tt/mXbGR1E
Cyberark
That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability
On January 11, 2022, we published a blog post describing the details of CVE-2022-21893, a Remote Desktop vulnerability that we found and reported to Microsoft. After analyzing the patch that fixed...
Analysing RTF files from SideWinder APT
https://ift.tt/wTNd6AV
Submitted June 17, 2022 at 12:17AM by OwnPreparation3424
via reddit https://ift.tt/xGbAwaj
https://ift.tt/wTNd6AV
Submitted June 17, 2022 at 12:17AM by OwnPreparation3424
via reddit https://ift.tt/xGbAwaj
Medium
404 — File still found
In early February 2022, we came across a tweet from ShadowChasing1 identifying a SideWinder-related word document which referenced a template URL. In this article, we share our insights from…
AWS Lambda Command Injection
https://ift.tt/z5KS7Pk
Submitted June 17, 2022 at 04:28PM by lormayna
via reddit https://ift.tt/XSTqh20
https://ift.tt/z5KS7Pk
Submitted June 17, 2022 at 04:28PM by lormayna
via reddit https://ift.tt/XSTqh20
www.safe.security
AWS Lambda Command Injection
The attack comprises of performing command injection vulnerability in Lambda Functions in order to steal the AWS keys and access AWS resources as the stolen keys of the IAM role.
Securing OT Network Management Systems: Siemens SINEC NMS
https://ift.tt/ibopXqK
Submitted June 17, 2022 at 08:27PM by derp6996
via reddit https://ift.tt/2Bp1eEJ
https://ift.tt/ibopXqK
Submitted June 17, 2022 at 08:27PM by derp6996
via reddit https://ift.tt/2Bp1eEJ
Claroty
Securing Network Management Systems (Part 3): Siemens SINEC NMS
Analyzing the latest version of Matanbuchus
https://ift.tt/adt9cZq
Submitted June 17, 2022 at 11:33PM by OwnPreparation3424
via reddit https://ift.tt/nN8Mj90
https://ift.tt/adt9cZq
Submitted June 17, 2022 at 11:33PM by OwnPreparation3424
via reddit https://ift.tt/nN8Mj90
Medium
A deal with the devil: Analysis of a recent Matanbuchus sample
Technical analysis of the Matanbuchus malware with focus on network traffic and commands
Quick Malware Analysis Using Free Tools: Matanbuchus with Cobalt Strike pcap from 2022-06-16
https://ift.tt/oRTtu1Q
Submitted June 17, 2022 at 10:59PM by dougburks
via reddit https://ift.tt/Bu39dqU
https://ift.tt/oRTtu1Q
Submitted June 17, 2022 at 10:59PM by dougburks
via reddit https://ift.tt/Bu39dqU
blog.securityonion.net
Quick Malware Analysis: Matanbuchus with Cobalt Strike pcap from 2022-06-16
Thanks to Brad Duncan for sharing this pcap! https://www.malware-traffic-analysis.net/2022/06/16/index.html We did a quick analysis of this ...
BRATA is evolving into an APT | Cleafy Labs
https://ift.tt/RJFrC4v
Submitted June 17, 2022 at 02:16PM by f3d_0x0
via reddit https://ift.tt/ym1ACEI
https://ift.tt/RJFrC4v
Submitted June 17, 2022 at 02:16PM by f3d_0x0
via reddit https://ift.tt/ym1ACEI
Cleafy
BRATA is evolving into an APT | Cleafy Labs
The mobile banking malware BRATA keeps evolving into an APT. Read here the new Technical Report, which explains in detail how it monitors banks' account and how to prevent it.
CSRF leads to account takeover in Yahoo!
https://ift.tt/xc9dsak
Submitted June 18, 2022 at 05:20AM by vinay737
via reddit https://ift.tt/bkzlwf5
https://ift.tt/xc9dsak
Submitted June 18, 2022 at 05:20AM by vinay737
via reddit https://ift.tt/bkzlwf5