How to Evade Windows Defender and Commercial AV with Msfvenom Payloads
https://ift.tt/sfyq7S5
Submitted June 29, 2022 at 08:11AM by entropydaemon6
via reddit https://ift.tt/3FEW6uX
https://ift.tt/sfyq7S5
Submitted June 29, 2022 at 08:11AM by entropydaemon6
via reddit https://ift.tt/3FEW6uX
GitHub
GitHub - RoseSecurity/Anti-Virus-Evading-Payloads: During the exploitation phase of a pen test or ethical hacking engagement, you…
During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system computers. Whether accomplished by phishing emails, ...
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
https://www.horizon3.ai/red-team-blog-cve-2022-28219/
Submitted June 29, 2022 at 06:57PM by scopedsecurity
via reddit https://ift.tt/Ycge10u
https://www.horizon3.ai/red-team-blog-cve-2022-28219/
Submitted June 29, 2022 at 06:57PM by scopedsecurity
via reddit https://ift.tt/Ycge10u
Horizon3.ai
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
CVE-2022-28219 is an unauthenticated remote code execution vulnerability affecting Zoho ManageEngine ADAudit Plus, a compliance tool used by enterprises to monitor changes to Active Directory.
Exploiting Intel Graphics Kernel Extensions on macOS to Escape the Safari Sandbox
https://ift.tt/lIspQDL
Submitted June 29, 2022 at 09:17PM by gaasedelen
via reddit https://ift.tt/Zhgei2G
https://ift.tt/lIspQDL
Submitted June 29, 2022 at 09:17PM by gaasedelen
via reddit https://ift.tt/Zhgei2G
RET2 Systems Blog
Exploiting Intel Graphics Kernel Extensions on macOS
To escape the Safari sandbox for our Pwn2Own 2021 submission, we exploited a vulnerability in the Intel graphics acceleration kernel extensions (drivers) on ...
CloudGoat detection_evasion Scenario: Avoiding AWS Security Detection and Response
https://ift.tt/mF7pdsy
Submitted June 29, 2022 at 08:58PM by hackers_and_builders
via reddit https://ift.tt/Qbamf8Y
https://ift.tt/mF7pdsy
Submitted June 29, 2022 at 08:58PM by hackers_and_builders
via reddit https://ift.tt/Qbamf8Y
Rhino Security Labs
CloudGoat Scenario: Avoiding AWS Security Detection and Response
This will walk through the CloudGoat AWS detection_evasion scenario, detailing how to avoid AWS security detection and response services, such as in Lambda
How to Steal Browser’s Autofill Credentials via Cross-Site Scripting (XSS)
https://ift.tt/gR9LDZr
Submitted June 29, 2022 at 06:36PM by obilodeau
via reddit https://ift.tt/o9ZKx8u
https://ift.tt/gR9LDZr
Submitted June 29, 2022 at 06:36PM by obilodeau
via reddit https://ift.tt/o9ZKx8u
GoSecure
Did You Know Your Browser’s Autofill Credentials Could Be Stolen via Cross-Site Scripting (XSS) - GoSecure
Firefox, Chrome, Edge, Opera, and Internet Explorer browsers could be leaking users' credentials where autofill usernames and passwords can be accessed by JavaScript.
Cryptographic failures in RF encryption allow stealing robotic devices | Cossack Labs
https://ift.tt/BbnGNVQ
Submitted June 29, 2022 at 10:13PM by evilsocket
via reddit https://ift.tt/JPV8CRu
https://ift.tt/BbnGNVQ
Submitted June 29, 2022 at 10:13PM by evilsocket
via reddit https://ift.tt/JPV8CRu
Cossack Labs
Cryptographic failures in RF encryption allow stealing robotic devices | Cossack Labs
Stunned by losing their robotic devices, [REDACTED] learnt that they were hijacked by attackers even with communication being encrypted. Having researched its firmware and found numerous cryptographic failures, we've crafted a few demos on how cryptography…
Golang code review notes by elttam
https://ift.tt/cp9BVza
Submitted June 30, 2022 at 10:34AM by Gallus
via reddit https://ift.tt/yWHUFzq
https://ift.tt/cp9BVza
Submitted June 30, 2022 at 10:34AM by Gallus
via reddit https://ift.tt/yWHUFzq
Elttam
Golang code review notes
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
What the 3 major data breaches can teach us
https://medium.com/cybersecurityspace/e82826fb6211
Submitted June 30, 2022 at 09:39PM by alertnoalert
via reddit https://ift.tt/HkYmusq
https://medium.com/cybersecurityspace/e82826fb6211
Submitted June 30, 2022 at 09:39PM by alertnoalert
via reddit https://ift.tt/HkYmusq
Medium
You Won’t Believe These Data Breaches (+ How They Did It)
Catch SOC Prime’s pick of top 3 most devastating data breaches that affected large businesses and left victims wondering: how they did it?
How to expose a potential cybercriminal due to misconfigurations
https://ift.tt/6kyr3nK
Submitted June 30, 2022 at 09:33PM by CyberMasterV
via reddit https://ift.tt/h71CroW
https://ift.tt/6kyr3nK
Submitted June 30, 2022 at 09:33PM by CyberMasterV
via reddit https://ift.tt/h71CroW
Toll fraud malware: How an Android application can drain your wallet
https://ift.tt/Bj3xyio
Submitted June 30, 2022 at 10:09PM by SCI_Rusher
via reddit https://ift.tt/dXZRGAp
https://ift.tt/Bj3xyio
Submitted June 30, 2022 at 10:09PM by SCI_Rusher
via reddit https://ift.tt/dXZRGAp
Microsoft Security Blog
Toll fraud malware: How an Android application can drain your wallet - Microsoft Security Blog
Toll fraud malware, a subcategory of billing fraud in which malicious applications subscribe users to premium services without their knowledge or consent, is one of the most prevalent types of Android malware – and it continues to evolve.
Cloudy with a Chance of Risk: Managing Risks in Cloud-Managed OT Networks
https://ift.tt/aBILiJ0
Submitted June 30, 2022 at 09:56PM by c_f13
via reddit https://ift.tt/8XjITv5
https://ift.tt/aBILiJ0
Submitted June 30, 2022 at 09:56PM by c_f13
via reddit https://ift.tt/8XjITv5
Medium
Cloudy with a Chance of Risk: Managing Risks in Cloud-Managed OT Networks
Digital transformation: Most of us have probably already heard this term, sometime, somewhere. It’s somewhat difficult to miss when…
Weaponizing and Abusing Hidden Functionalities Contained in Office Document Properties
https://ift.tt/Uxk9dlu
Submitted June 30, 2022 at 11:38PM by McLabraid
via reddit https://ift.tt/0svRzjb
https://ift.tt/Uxk9dlu
Submitted June 30, 2022 at 11:38PM by McLabraid
via reddit https://ift.tt/0svRzjb
Offensive-Security
Weaponizing and Abusing Hidden Functionalities Contained in Office Document Properties | Offensive Security
TJ shows us how adversaries use macro weaponization techniques to abuse hidden functionalities contained in Office document properties.
Flubot: the evolution of a notorious Android Banking Malware
https://ift.tt/lLOMTsp
Submitted July 01, 2022 at 02:47AM by Goovscoov
via reddit https://ift.tt/m3Ta8u0
https://ift.tt/lLOMTsp
Submitted July 01, 2022 at 02:47AM by Goovscoov
via reddit https://ift.tt/m3Ta8u0
Fox-IT International blog
Flubot: the evolution of a notorious Android Banking Malware
Authored by Alberto Segura (main author) and Rolf Govers (co-author) Summary Flubot is an Android based malware that has been distributed in the past 1.5 years inEurope, Asia and Oceania affecting …
RanSim: a ransomware simulation noscript written in PowerShell. Useful for testing your defenses and backups in a controlled simulation. The same noscript is used for encryption and decryption.
https://ift.tt/50h7do4
Submitted July 01, 2022 at 02:18AM by doctormay6
via reddit https://ift.tt/SkGjzv6
https://ift.tt/50h7do4
Submitted July 01, 2022 at 02:18AM by doctormay6
via reddit https://ift.tt/SkGjzv6
GitHub
GitHub - lawndoc/RanSim: Ransomware simulation noscript written in PowerShell. Useful for testing your defenses and backups against…
Ransomware simulation noscript written in PowerShell. Useful for testing your defenses and backups against real ransomware-like activity in a controlled setting. - GitHub - lawndoc/RanSim: Ransomware...
Intel SGX deprecation review
https://ift.tt/BLvU2ip
Submitted July 01, 2022 at 04:38PM by hardenedvault
via reddit https://ift.tt/Q4n9afm
https://ift.tt/BLvU2ip
Submitted July 01, 2022 at 04:38PM by hardenedvault
via reddit https://ift.tt/Q4n9afm
hardenedvault.net
Intel SGX deprecation review
The rumors about Intel SGX deprecated in new processors has been confirmed, 12th generation processors (Workstation/Desktop/Laptop/embedded platforms) will deprecate SGX and the SGX will continue to support only in high-end Xeon CPU for server:
It’s Been Zero Days Since BIND9 Crashed
https://ift.tt/SzgbNAu
Submitted July 01, 2022 at 03:52PM by jen140
via reddit https://ift.tt/WTZNLQ3
https://ift.tt/SzgbNAu
Submitted July 01, 2022 at 03:52PM by jen140
via reddit https://ift.tt/WTZNLQ3
Please sign this open letter asking Intel to open-source their Firmware Support Package (FSP)
https://ift.tt/njy8aSp
Submitted July 01, 2022 at 05:51PM by hardenedvault
via reddit https://ift.tt/LWlvV8B
https://ift.tt/njy8aSp
Submitted July 01, 2022 at 05:51PM by hardenedvault
via reddit https://ift.tt/LWlvV8B
Building a scalable static analysis program at Razorpay
https://ift.tt/DXmCYby
Submitted July 01, 2022 at 07:09PM by jubbaonjeans
via reddit https://ift.tt/SMhxlod
https://ift.tt/DXmCYby
Submitted July 01, 2022 at 07:09PM by jubbaonjeans
via reddit https://ift.tt/SMhxlod
Medium
Building a SAST program at Razorpay’s scale
The inner workings of how we build a Static Application Security Testing program at Razorpay
Bulk Analysis of Cobalt Strike’s Beacon Configurations
https://ift.tt/ylzPbcq
Submitted July 02, 2022 at 08:09AM by DLLCoolJ
via reddit https://ift.tt/51W4QPp
https://ift.tt/ylzPbcq
Submitted July 02, 2022 at 08:09AM by DLLCoolJ
via reddit https://ift.tt/51W4QPp
Archcloudlabs
Bulk Analysis of Cobalt Stirke's Beacon Configurations
About The Project Security researcher Silas Cutler recently tweeted a link to a unique data set of Cobalt Strike Beacon payloads, and their extracted configurations (thanks Silas!). This is a fairly large data set going back to November of 2021, and containing…
Over 900k Kubernetes Clusters Were Found Exposed Online
https://ift.tt/JueKr4C
Submitted July 03, 2022 at 02:22PM by uleadiengwunn
via reddit https://ift.tt/K3bv7VR
https://ift.tt/JueKr4C
Submitted July 03, 2022 at 02:22PM by uleadiengwunn
via reddit https://ift.tt/K3bv7VR
ARMO
Over 900k Kubernetes Clusters Were Found Exposed Online | ARMO
Recent research showed that over 900,000 Kubernetes clusters were found exposed to the internet to potentially malicious scans
Code replay attack on the myGovID Scheme
https://ift.tt/osfFCw4
Submitted July 03, 2022 at 07:16PM by Gallus
via reddit https://ift.tt/PNiCx3S
https://ift.tt/osfFCw4
Submitted July 03, 2022 at 07:16PM by Gallus
via reddit https://ift.tt/PNiCx3S