When Hypervisor Met Snapshot Fuzzing
https://ift.tt/9AQRWaw
Submitted July 26, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/EOUBmYM
https://ift.tt/9AQRWaw
Submitted July 26, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/EOUBmYM
NULL@ROOT
When Hypervisor Met Snapshot Fuzzing
1. Introduction Hypervisor was known as hard target to fuzz over several years. Even though, lots of prior pioneers( Peter Hlavaty, Chaitin Tech, StarLabs, Peleg Hadar and Ophir Harpaz and many others ) doing amazing work to overcome this limit and found…
GitHub - InitRoot/wodat: Windows Oracle Database Attack Toolkit
https://ift.tt/TNlzAQs
Submitted July 26, 2022 at 10:36AM by InitRoot
via reddit https://ift.tt/MhHTQZ8
https://ift.tt/TNlzAQs
Submitted July 26, 2022 at 10:36AM by InitRoot
via reddit https://ift.tt/MhHTQZ8
GitHub
GitHub - InitRoot/wodat: Windows Oracle Database Attack Toolkit
Windows Oracle Database Attack Toolkit. Contribute to InitRoot/wodat development by creating an account on GitHub.
Bypass AMSI in local process hooking NtCreateSection
https://ift.tt/dN9oC5D
Submitted July 26, 2022 at 02:12PM by gid0rah
via reddit https://ift.tt/sBwJD6Q
https://ift.tt/dN9oC5D
Submitted July 26, 2022 at 02:12PM by gid0rah
via reddit https://ift.tt/sBwJD6Q
Waawaa Blog
[Malware] Bypass AMSI in local process hooking NtCreateSection
Hi everyone! Here suffering (again) the high temperatures and hoping winter to come back again.
Zyxel authentication bypass patch analysis (CVE-2022-0342)
https://ift.tt/pPaBC1U
Submitted July 26, 2022 at 03:09PM by 0xdea
via reddit https://ift.tt/CSARX6O
https://ift.tt/pPaBC1U
Submitted July 26, 2022 at 03:09PM by 0xdea
via reddit https://ift.tt/CSARX6O
hn security
Zyxel authentication bypass patch analysis (CVE-2022-0342) - hn security
A few months ago, new firmware […]
How to analyze Linux malware – A case study of Symbiote
https://ift.tt/VptHKx8
Submitted July 26, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/taBSd2r
https://ift.tt/VptHKx8
Submitted July 26, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/taBSd2r
CVE-2022-31813: Forwarding addresses is hard
https://ift.tt/gunKZom
Submitted July 26, 2022 at 08:14PM by 0xdea
via reddit https://ift.tt/DSY3zIx
https://ift.tt/gunKZom
Submitted July 26, 2022 at 08:14PM by 0xdea
via reddit https://ift.tt/DSY3zIx
Synacktiv
CVE-2022-31813: Forwarding addresses is hard
A few weeks ago, version 2.
Awesome Open-Source Adversary Simulation Tools
https://ift.tt/8Vn1lJ4
Submitted July 26, 2022 at 09:35PM by sciencestudent99
via reddit https://ift.tt/lcZM4gK
https://ift.tt/8Vn1lJ4
Submitted July 26, 2022 at 09:35PM by sciencestudent99
via reddit https://ift.tt/lcZM4gK
FourCore
Top 10 Awesome Open-Source Adversary Simulation Tools - FourCore
Breach and Attack Simulation (BAS) also known as Adversary Simulation is an emerging IT security technology equipping the proactive approach to the way we look at organizational security. Open-source BAS tools like Caldera and Atomic Red Team are utilised…
Malicious IIS extensions quietly open persistent backdoors into servers
https://ift.tt/BrOI684
Submitted July 26, 2022 at 10:37PM by SCI_Rusher
via reddit https://ift.tt/AM9Wc31
https://ift.tt/BrOI684
Submitted July 26, 2022 at 10:37PM by SCI_Rusher
via reddit https://ift.tt/AM9Wc31
Microsoft Security Blog
Malicious IIS extensions quietly open persistent backdoors into servers - Microsoft Security Blog
Attackers are increasingly leveraging managed IIS extensions as covert backdoors into servers, providing a durable persistence mechanism for attacks.
Hunting For Mass Assignment Vulnerabilities Using GitHub CodeSearch and grep.app
https://ift.tt/4S85Ief
Submitted July 26, 2022 at 11:36PM by l_tennant
via reddit https://ift.tt/nvtjbP2
https://ift.tt/4S85Ief
Submitted July 26, 2022 at 11:36PM by l_tennant
via reddit https://ift.tt/nvtjbP2
Include Security Research Blog
Hunting For Mass Assignment Vulnerabilities Using GitHub CodeSearch and grep.app - Include Security Research Blog
This post discusses the process of searching top GitHub projects for mass assignment vulnerabilities. This led to a fun finding in the #1 most starred GitHub project, freeCodeCamp, where I was able to acquire every coding certification – supposedly representing…
Inside Matanbuchus: A Quirky Loader
https://ift.tt/xLZt4De
Submitted July 27, 2022 at 07:50PM by jat0369
via reddit https://ift.tt/uLQPlTC
https://ift.tt/xLZt4De
Submitted July 27, 2022 at 07:50PM by jat0369
via reddit https://ift.tt/uLQPlTC
Cyberark
Inside Matanbuchus: A Quirky Loader
An in-depth analysis of Matanbuchus loader’s tricks and loading techniques Matanbuchus is a Malware-as-a-Service loader that has been sold on underground markets for more than one year....
Untangling KNOTWEED: European private-sector offensive actor using 0-day exploits
https://ift.tt/6A8tjDb
Submitted July 27, 2022 at 10:04PM by surrealisticpillow12
via reddit https://ift.tt/5k3MLZu
https://ift.tt/6A8tjDb
Submitted July 27, 2022 at 10:04PM by surrealisticpillow12
via reddit https://ift.tt/5k3MLZu
Microsoft Security Blog
Untangling KNOTWEED: European private-sector offensive actor using 0-day exploits - Microsoft Security Blog
MSTIC and MSRC disclose technical details of a private-sector offensive actor (PSOA) tracked as KNOTWEED using multiple Windows and Adobe 0-day exploits, including one for the recently patched CVE-2022-22047, in limited and targeted attacks against European…
Sternum Announces Free Security and Observability Platforms for OpenWrt IoT Devices
https://ift.tt/H13UFJx
Submitted July 27, 2022 at 09:54PM by mesok8
via reddit https://ift.tt/ZpHWB7X
https://ift.tt/H13UFJx
Submitted July 27, 2022 at 09:54PM by mesok8
via reddit https://ift.tt/ZpHWB7X
Sternum IoT
Announcing Sternum’s Free Security License for OpenWrt Devices | Sternum IoT
Strenum is a game changer, but don't take our word for it - try it out!
Corrupting memory without memory corruption
https://ift.tt/CAg41az
Submitted July 27, 2022 at 11:45PM by surrealisticpillow12
via reddit https://ift.tt/gu09qhm
https://ift.tt/CAg41az
Submitted July 27, 2022 at 11:45PM by surrealisticpillow12
via reddit https://ift.tt/gu09qhm
The GitHub Blog
Corrupting memory without memory corruption
In this post I’ll exploit CVE-2022-20186, a vulnerability in the Arm Mali GPU kernel driver and use it to gain arbitrary kernel memory access from an untrusted app on a Pixel 6. This then allows me to gain root and disable SELinux. This vulnerability highlights…
How the WordPress Gets Hacked in 2022 - Initial Reconnaissance
https://ift.tt/F3Tgy65
Submitted July 28, 2022 at 03:26AM by perezbox
via reddit https://ift.tt/5T1g6Ge
https://ift.tt/F3Tgy65
Submitted July 28, 2022 at 03:26AM by perezbox
via reddit https://ift.tt/5T1g6Ge
NOC CDN and WAF
How the WordPress Gets Hacked in 2022 - Initial Reconnaissance
This articles explains how the WordPress JSON API and XMLRPC can be used to attack WordPress website using Brute Force techniques.
US Government Review of the December 2021 Log4j Event
https://ift.tt/iHj2gmr
Submitted July 26, 2022 at 07:27AM by ScottContini
via reddit https://ift.tt/cv23M6K
https://ift.tt/iHj2gmr
Submitted July 26, 2022 at 07:27AM by ScottContini
via reddit https://ift.tt/cv23M6K
Spear Phishing on Modern Platforms
https://ift.tt/Rl6eAu4
Submitted July 28, 2022 at 09:22AM by sanitybit
via reddit https://ift.tt/5HGxL6i
https://ift.tt/Rl6eAu4
Submitted July 28, 2022 at 09:22AM by sanitybit
via reddit https://ift.tt/5HGxL6i
Optiv
Spear Phishing on Modern Platforms
Spear phishing is a social engineering activity intended to simulate a realistic attack scenario with the intent of bypassing technical security controls and persuading employees to perform various actions.
Passkeys: a push to take WebAuthn to the masses
https://ift.tt/T1X3rA4
Submitted July 28, 2022 at 09:14AM by sanitybit
via reddit https://ift.tt/mTfOUa1
https://ift.tt/T1X3rA4
Submitted July 28, 2022 at 09:14AM by sanitybit
via reddit https://ift.tt/mTfOUa1
www.imperialviolet.org
ImperialViolet - Passkeys
Scraping Login Credentials With XSS
https://ift.tt/NQZzcbm
Submitted July 28, 2022 at 09:05AM by sanitybit
via reddit https://ift.tt/cXqMxuU
https://ift.tt/NQZzcbm
Submitted July 28, 2022 at 09:05AM by sanitybit
via reddit https://ift.tt/cXqMxuU
TrustedSec
Scraping Login Credentials With XSS - TrustedSec
TrustedSec's blog is an expert source of information on information security trends and best practices for strategic risk management.
Railway cybersecurity in the era of interconnected systems
https://ift.tt/HqJwB5E
Submitted July 28, 2022 at 10:13AM by sanitybit
via reddit https://ift.tt/e0oNpld
https://ift.tt/HqJwB5E
Submitted July 28, 2022 at 10:13AM by sanitybit
via reddit https://ift.tt/e0oNpld
Vulnerable by Design: Azure Red Team Attack and Detect Workshop
https://ift.tt/dc9qAr3
Submitted July 28, 2022 at 10:05AM by sanitybit
via reddit https://ift.tt/fBMlWC7
https://ift.tt/dc9qAr3
Submitted July 28, 2022 at 10:05AM by sanitybit
via reddit https://ift.tt/fBMlWC7
GitHub
GitHub - mandiant/Azure_Workshop
Contribute to mandiant/Azure_Workshop development by creating an account on GitHub.
Abusing Duo Authentication Misconfigurations in Windows and Active Directory Environments
https://ift.tt/Xy79T6q
Submitted July 28, 2022 at 10:04AM by sanitybit
via reddit https://ift.tt/KpdL403
https://ift.tt/Xy79T6q
Submitted July 28, 2022 at 10:04AM by sanitybit
via reddit https://ift.tt/KpdL403
Mandiant
Abusing Duo Authentication Misconfigurations in Windows and Active Directory Environments | Mandiant