Notes on OpenSSL remote memory corruption
https://ift.tt/d1mJinU
Submitted June 27, 2022 at 11:32AM by Gallus
via reddit https://ift.tt/AO5HID3
https://ift.tt/d1mJinU
Submitted June 27, 2022 at 11:32AM by Gallus
via reddit https://ift.tt/AO5HID3
Guido Vranken
Notes on OpenSSL remote memory corruption
OpenSSL version 3.0.4, released on June 21th 2022, is susceptible to remote memory corruption which can be triggered trivially by an attacker. BoringSSL, LibreSSL and the OpenSSL 1.1.1 branch are n…
VaultBoot: remote attestation
https://ift.tt/T84Nhwc
Submitted June 27, 2022 at 04:59PM by hardenedvault
via reddit https://ift.tt/ZHuBvro
https://ift.tt/T84Nhwc
Submitted June 27, 2022 at 04:59PM by hardenedvault
via reddit https://ift.tt/ZHuBvro
GitHub
GitHub - hardenedvault/vaultboot
Contribute to hardenedvault/vaultboot development by creating an account on GitHub.
Revive: from spyware to Android banking trojan | Cleafy Labs
https://ift.tt/iY4KW0c
Submitted June 27, 2022 at 07:19PM by f3d_0x0
via reddit https://ift.tt/DapCOl9
https://ift.tt/iY4KW0c
Submitted June 27, 2022 at 07:19PM by f3d_0x0
via reddit https://ift.tt/DapCOl9
Cleafy
Revive: from spyware to android banking trojan | Cleafy Labs
A new banking trojan targeting Europe has been discovered by Cleafy's Threat Intelligence Team. We dubbed it Revive and it is an evolution of simple spyware into a banking trojan, with the key capability of conducting Account Takeover attacks: here's the…
Intune hacking: when is a "wipe" not a wipe
https://ift.tt/RKern59
Submitted June 28, 2022 at 01:30PM by nopslider
via reddit https://ift.tt/Uc7nIVg
https://ift.tt/RKern59
Submitted June 28, 2022 at 01:30PM by nopslider
via reddit https://ift.tt/Uc7nIVg
Cyberis Limited
Intune hacking: when is a "wipe" not a wipe
In this blog post we explore privilege escalation to SYSTEM with Intune managed devices, and how an Intune "Wipe" is not really a wipe at all.
Hive Ransomware Decrypter Tool - KISA
https://ift.tt/YudXyOl
Submitted June 28, 2022 at 11:25PM by CyberMasterV
via reddit https://ift.tt/UPqjiCI
https://ift.tt/YudXyOl
Submitted June 28, 2022 at 11:25PM by CyberMasterV
via reddit https://ift.tt/UPqjiCI
CVE-2022-30522 - Apache httpd "mod_sed" DoS vulnerability
https://ift.tt/jYKB8L0
Submitted June 28, 2022 at 10:57PM by SRMish3
via reddit https://ift.tt/iLr9Ceq
https://ift.tt/jYKB8L0
Submitted June 28, 2022 at 10:57PM by SRMish3
via reddit https://ift.tt/iLr9Ceq
JFrog
CVE-2022-30522 - Apache httpd Denial of Service (DoS) vulnerability
CVE-2022-30522 is an Apache httpd vulnerability found by JFrog Security Research when analyzing the impact of a recent vulnerability patch. Read our analysis and guidance >
Zimbra unauthenticated RCE via unrar path traversal (CVE-2022-30333)
https://ift.tt/bZCo13y
Submitted June 29, 2022 at 02:49AM by monoimpact
via reddit https://ift.tt/o1SGwKR
https://ift.tt/bZCo13y
Submitted June 29, 2022 at 02:49AM by monoimpact
via reddit https://ift.tt/o1SGwKR
Sonarsource
Unrar Path Traversal Vulnerability affects Zimbra Mail
We discovered a vulnerability in Zimbra Enterprise Email that allows an unauthenticated, remote attacker fully take over Zimbra instances via a flaw in unrar.
Abusing Cloudflare Workers
https://ift.tt/mQf2XF3
Submitted June 29, 2022 at 04:07AM by thorn42
via reddit https://ift.tt/uXtEyP8
https://ift.tt/mQf2XF3
Submitted June 29, 2022 at 04:07AM by thorn42
via reddit https://ift.tt/uXtEyP8
Christophe Tafani-Dereeper
Abusing Cloudflare Workers - Christophe Tafani-Dereeper
An attacker compromising a Cloudflare account can abuse Workers to establish persistence and exfiltrate sensitive data.
How to Evade Windows Defender and Commercial AV with Msfvenom Payloads
https://ift.tt/sfyq7S5
Submitted June 29, 2022 at 08:11AM by entropydaemon6
via reddit https://ift.tt/3FEW6uX
https://ift.tt/sfyq7S5
Submitted June 29, 2022 at 08:11AM by entropydaemon6
via reddit https://ift.tt/3FEW6uX
GitHub
GitHub - RoseSecurity/Anti-Virus-Evading-Payloads: During the exploitation phase of a pen test or ethical hacking engagement, you…
During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system computers. Whether accomplished by phishing emails, ...
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
https://www.horizon3.ai/red-team-blog-cve-2022-28219/
Submitted June 29, 2022 at 06:57PM by scopedsecurity
via reddit https://ift.tt/Ycge10u
https://www.horizon3.ai/red-team-blog-cve-2022-28219/
Submitted June 29, 2022 at 06:57PM by scopedsecurity
via reddit https://ift.tt/Ycge10u
Horizon3.ai
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
CVE-2022-28219 is an unauthenticated remote code execution vulnerability affecting Zoho ManageEngine ADAudit Plus, a compliance tool used by enterprises to monitor changes to Active Directory.
Exploiting Intel Graphics Kernel Extensions on macOS to Escape the Safari Sandbox
https://ift.tt/lIspQDL
Submitted June 29, 2022 at 09:17PM by gaasedelen
via reddit https://ift.tt/Zhgei2G
https://ift.tt/lIspQDL
Submitted June 29, 2022 at 09:17PM by gaasedelen
via reddit https://ift.tt/Zhgei2G
RET2 Systems Blog
Exploiting Intel Graphics Kernel Extensions on macOS
To escape the Safari sandbox for our Pwn2Own 2021 submission, we exploited a vulnerability in the Intel graphics acceleration kernel extensions (drivers) on ...
CloudGoat detection_evasion Scenario: Avoiding AWS Security Detection and Response
https://ift.tt/mF7pdsy
Submitted June 29, 2022 at 08:58PM by hackers_and_builders
via reddit https://ift.tt/Qbamf8Y
https://ift.tt/mF7pdsy
Submitted June 29, 2022 at 08:58PM by hackers_and_builders
via reddit https://ift.tt/Qbamf8Y
Rhino Security Labs
CloudGoat Scenario: Avoiding AWS Security Detection and Response
This will walk through the CloudGoat AWS detection_evasion scenario, detailing how to avoid AWS security detection and response services, such as in Lambda
How to Steal Browser’s Autofill Credentials via Cross-Site Scripting (XSS)
https://ift.tt/gR9LDZr
Submitted June 29, 2022 at 06:36PM by obilodeau
via reddit https://ift.tt/o9ZKx8u
https://ift.tt/gR9LDZr
Submitted June 29, 2022 at 06:36PM by obilodeau
via reddit https://ift.tt/o9ZKx8u
GoSecure
Did You Know Your Browser’s Autofill Credentials Could Be Stolen via Cross-Site Scripting (XSS) - GoSecure
Firefox, Chrome, Edge, Opera, and Internet Explorer browsers could be leaking users' credentials where autofill usernames and passwords can be accessed by JavaScript.
Cryptographic failures in RF encryption allow stealing robotic devices | Cossack Labs
https://ift.tt/BbnGNVQ
Submitted June 29, 2022 at 10:13PM by evilsocket
via reddit https://ift.tt/JPV8CRu
https://ift.tt/BbnGNVQ
Submitted June 29, 2022 at 10:13PM by evilsocket
via reddit https://ift.tt/JPV8CRu
Cossack Labs
Cryptographic failures in RF encryption allow stealing robotic devices | Cossack Labs
Stunned by losing their robotic devices, [REDACTED] learnt that they were hijacked by attackers even with communication being encrypted. Having researched its firmware and found numerous cryptographic failures, we've crafted a few demos on how cryptography…
Golang code review notes by elttam
https://ift.tt/cp9BVza
Submitted June 30, 2022 at 10:34AM by Gallus
via reddit https://ift.tt/yWHUFzq
https://ift.tt/cp9BVza
Submitted June 30, 2022 at 10:34AM by Gallus
via reddit https://ift.tt/yWHUFzq
Elttam
Golang code review notes
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
What the 3 major data breaches can teach us
https://medium.com/cybersecurityspace/e82826fb6211
Submitted June 30, 2022 at 09:39PM by alertnoalert
via reddit https://ift.tt/HkYmusq
https://medium.com/cybersecurityspace/e82826fb6211
Submitted June 30, 2022 at 09:39PM by alertnoalert
via reddit https://ift.tt/HkYmusq
Medium
You Won’t Believe These Data Breaches (+ How They Did It)
Catch SOC Prime’s pick of top 3 most devastating data breaches that affected large businesses and left victims wondering: how they did it?
How to expose a potential cybercriminal due to misconfigurations
https://ift.tt/6kyr3nK
Submitted June 30, 2022 at 09:33PM by CyberMasterV
via reddit https://ift.tt/h71CroW
https://ift.tt/6kyr3nK
Submitted June 30, 2022 at 09:33PM by CyberMasterV
via reddit https://ift.tt/h71CroW
Toll fraud malware: How an Android application can drain your wallet
https://ift.tt/Bj3xyio
Submitted June 30, 2022 at 10:09PM by SCI_Rusher
via reddit https://ift.tt/dXZRGAp
https://ift.tt/Bj3xyio
Submitted June 30, 2022 at 10:09PM by SCI_Rusher
via reddit https://ift.tt/dXZRGAp
Microsoft Security Blog
Toll fraud malware: How an Android application can drain your wallet - Microsoft Security Blog
Toll fraud malware, a subcategory of billing fraud in which malicious applications subscribe users to premium services without their knowledge or consent, is one of the most prevalent types of Android malware – and it continues to evolve.
Cloudy with a Chance of Risk: Managing Risks in Cloud-Managed OT Networks
https://ift.tt/aBILiJ0
Submitted June 30, 2022 at 09:56PM by c_f13
via reddit https://ift.tt/8XjITv5
https://ift.tt/aBILiJ0
Submitted June 30, 2022 at 09:56PM by c_f13
via reddit https://ift.tt/8XjITv5
Medium
Cloudy with a Chance of Risk: Managing Risks in Cloud-Managed OT Networks
Digital transformation: Most of us have probably already heard this term, sometime, somewhere. It’s somewhat difficult to miss when…
Weaponizing and Abusing Hidden Functionalities Contained in Office Document Properties
https://ift.tt/Uxk9dlu
Submitted June 30, 2022 at 11:38PM by McLabraid
via reddit https://ift.tt/0svRzjb
https://ift.tt/Uxk9dlu
Submitted June 30, 2022 at 11:38PM by McLabraid
via reddit https://ift.tt/0svRzjb
Offensive-Security
Weaponizing and Abusing Hidden Functionalities Contained in Office Document Properties | Offensive Security
TJ shows us how adversaries use macro weaponization techniques to abuse hidden functionalities contained in Office document properties.
Flubot: the evolution of a notorious Android Banking Malware
https://ift.tt/lLOMTsp
Submitted July 01, 2022 at 02:47AM by Goovscoov
via reddit https://ift.tt/m3Ta8u0
https://ift.tt/lLOMTsp
Submitted July 01, 2022 at 02:47AM by Goovscoov
via reddit https://ift.tt/m3Ta8u0
Fox-IT International blog
Flubot: the evolution of a notorious Android Banking Malware
Authored by Alberto Segura (main author) and Rolf Govers (co-author) Summary Flubot is an Android based malware that has been distributed in the past 1.5 years inEurope, Asia and Oceania affecting …