Community version released - OSS Malware risk
https://ift.tt/i8r16SB
Submitted August 04, 2022 at 06:32PM by MoTownMeatballs
via reddit https://ift.tt/A7MObD6
https://ift.tt/i8r16SB
Submitted August 04, 2022 at 06:32PM by MoTownMeatballs
via reddit https://ift.tt/A7MObD6
QNAP Poisoned XML Command Injection (Silently Patched)
https://ift.tt/CYzfwd1
Submitted August 04, 2022 at 11:06PM by chicksdigthelongrun
via reddit https://ift.tt/7BRmKNd
https://ift.tt/CYzfwd1
Submitted August 04, 2022 at 11:06PM by chicksdigthelongrun
via reddit https://ift.tt/7BRmKNd
Rapid7
QNAP Poisoned XML Command Injection (Silently Patched) | Rapid7 Blog
In researching the mystery surrounding alleged exploitation in the wild of CVE-2020-2509, we found what make be an entirely new vulnerability.
Certipy 4.0: ESC9 & ESC10, BloodHound GUI, New Authentication and Request Methods — and more!
https://ift.tt/euTaSO8
Submitted August 04, 2022 at 11:57PM by ly4k_
via reddit https://ift.tt/mlVqbYj
https://ift.tt/euTaSO8
Submitted August 04, 2022 at 11:57PM by ly4k_
via reddit https://ift.tt/mlVqbYj
Medium
Certipy 4.0: ESC9 & ESC10, BloodHound GUI, New Authentication and Request Methods — and more!
A new version of Certipy has been released along with a forked BloodHound GUI that has PKI support! In this blog post, we will look at…
Cloudflare Implements Experimental Support for Post-Quantum Cryptography
https://ift.tt/Fi0JgOG
Submitted August 05, 2022 at 03:35AM by sanitybit
via reddit https://ift.tt/l4wuvrJ
https://ift.tt/Fi0JgOG
Submitted August 05, 2022 at 03:35AM by sanitybit
via reddit https://ift.tt/l4wuvrJ
Tool that automates the tedious process of searching leaks through format string vulnerabilities. It will allow you to find stack leaks, pie leaks and canary leaks, in each case indicating the payload that provides the leak.
https://ift.tt/CtJXlcN
Submitted August 04, 2022 at 06:51PM by Diego-AltF4
via reddit https://ift.tt/JxploUv
https://ift.tt/CtJXlcN
Submitted August 04, 2022 at 06:51PM by Diego-AltF4
via reddit https://ift.tt/JxploUv
GitHub
GitHub - Diego-AltF4/GLUFS: GLUFS allows you to automate the tedious process of finding leaks using format string vulnerabilities.
GLUFS allows you to automate the tedious process of finding leaks using format string vulnerabilities. - Diego-AltF4/GLUFS
Exploring the SameSite cookie attribute for preventing CSRF!
https://ift.tt/dtAYMf6
Submitted August 05, 2022 at 03:28AM by macropng
via reddit https://ift.tt/h9ba7Hw
https://ift.tt/dtAYMf6
Submitted August 05, 2022 at 03:28AM by macropng
via reddit https://ift.tt/h9ba7Hw
simonwillison.net
Exploring the SameSite cookie attribute for preventing CSRF
In reading Yan Zhu’s excellent write-up of the JSON CSRF vulnerability she found in OkCupid one thing puzzled me: I was under the impression that browsers these days default to …
How To Implement JSON Web Token (JWT) in Java Spring Boot
https://ift.tt/MHdKo9v
Submitted August 05, 2022 at 03:08AM by sanitybit
via reddit https://ift.tt/iXcP27t
https://ift.tt/MHdKo9v
Submitted August 05, 2022 at 03:08AM by sanitybit
via reddit https://ift.tt/iXcP27t
Medium
How To Implement JSON Web Token (JWT) in Java Spring Boot
A brief guide to this helpful feature
Azure Threat Research Matrix
https://ift.tt/HaOvGLX
Submitted August 05, 2022 at 04:29AM by sanitybit
via reddit https://ift.tt/aEcZu9U
https://ift.tt/HaOvGLX
Submitted August 05, 2022 at 04:29AM by sanitybit
via reddit https://ift.tt/aEcZu9U
HyperDbg: Reinventing Hardware-Assisted Debugging
https://hyperdbg.org/
Submitted August 05, 2022 at 04:01AM by sanitybit
via reddit https://ift.tt/zpFNMq9
https://hyperdbg.org/
Submitted August 05, 2022 at 04:01AM by sanitybit
via reddit https://ift.tt/zpFNMq9
reddit
HyperDbg: Reinventing Hardware-Assisted Debugging
Posted in r/netsec by u/sanitybit • 3 points and 1 comment
Sharpening Your Tools: Updating bulk_extractor for the 2020s
https://ift.tt/E2hKBVj
Submitted August 05, 2022 at 03:56AM by sanitybit
via reddit https://ift.tt/GIz3Wfe
https://ift.tt/E2hKBVj
Submitted August 05, 2022 at 03:56AM by sanitybit
via reddit https://ift.tt/GIz3Wfe
Elastic Open Sources Their Endpoint Security Protection YARA Ruleset
https://ift.tt/WdhB43m
Submitted August 05, 2022 at 04:53AM by sanitybit
via reddit https://ift.tt/RzWf0AL
https://ift.tt/WdhB43m
Submitted August 05, 2022 at 04:53AM by sanitybit
via reddit https://ift.tt/RzWf0AL
Elastic Blog
Continued leadership in open and transparent security
Elastic Security has long had open source roots. Learn how we're continuing to build on that foundation today by opening a new public repo, protection-artifacts.
PentesterLab - Bootcamp: Everything you need to get started in infosec
https://pentesterlab.com/bootcamp
Submitted August 05, 2022 at 10:24AM by Gallus
via reddit https://www.reddit.com/r/netsec/comments/wgmcsr/pentesterlab_bootcamp_everything_you_need_to_get/?utm_source=ifttt
https://pentesterlab.com/bootcamp
Submitted August 05, 2022 at 10:24AM by Gallus
via reddit https://www.reddit.com/r/netsec/comments/wgmcsr/pentesterlab_bootcamp_everything_you_need_to_get/?utm_source=ifttt
reddit
PentesterLab - Bootcamp: Everything you need to get started in infosec
Posted in r/netsec by u/Gallus • 0 points and 0 comments
fwd:cloudsec 2022 Conference Talk Recordings
https://youtube.com/playlist?list=PLCPCP1pNWD7N2SPaz4cmuS27xutaf32jy
Submitted August 05, 2022 at 11:28AM by sanitybit
via reddit https://ift.tt/yF6teEq
https://youtube.com/playlist?list=PLCPCP1pNWD7N2SPaz4cmuS27xutaf32jy
Submitted August 05, 2022 at 11:28AM by sanitybit
via reddit https://ift.tt/yF6teEq
YouTube
fwd:cloudsec 2022 - YouTube
Abusing container mount points and symlinks on MikroTik's RouterOS to gain code execution
https://ift.tt/oHBUYyG
Submitted August 05, 2022 at 02:20PM by crower
via reddit https://ift.tt/OTyh5Px
https://ift.tt/oHBUYyG
Submitted August 05, 2022 at 02:20PM by crower
via reddit https://ift.tt/OTyh5Px
nns.ee
Symlinks as mount portals: Abusing container mount points on MikroTik's RouterOS to gain code execution
RouterOS release 7.4beta4 introduced containers for MikroTik devices. From the changelog: container - added support for running Docker (TM) containers on AR...
A journey into IoT - Unknown Chinese alarm - Part 3 - Radio communications
https://ift.tt/9Sord3I
Submitted August 05, 2022 at 03:41PM by 0xdea
via reddit https://ift.tt/kHJbiNV
https://ift.tt/9Sord3I
Submitted August 05, 2022 at 03:41PM by 0xdea
via reddit https://ift.tt/kHJbiNV
hn security
A journey into IoT - Unknown Chinese alarm - Part 3 - Radio communications - hn security
Disclaimer: as many other security researchers […]
Tenable Engineer - Arlington VA, Hybrid
https://ift.tt/HVB8Mp9
Submitted August 05, 2022 at 08:16PM by Melodic_Society6217
via reddit https://ift.tt/64CWBwt
https://ift.tt/HVB8Mp9
Submitted August 05, 2022 at 08:16PM by Melodic_Society6217
via reddit https://ift.tt/64CWBwt
Exploiting a Linux kernel Use-After-Free in io_uring
https://ift.tt/iUEL6uO
Submitted August 05, 2022 at 10:40PM by awarau888
via reddit https://ift.tt/xHkfR4j
https://ift.tt/iUEL6uO
Submitted August 05, 2022 at 10:40PM by awarau888
via reddit https://ift.tt/xHkfR4j
Computer security and related topics
CVE-2022-29582
This post covers an interesting vulnerability we (Jayden and David) found in the io_uring subsystem of the Linux kernel.
New Era of Phishing Payloads After The Deprecation of Macros
https://ift.tt/mblGc9N
Submitted August 05, 2022 at 11:42PM by sciencestudent99
via reddit https://ift.tt/LQkUeGK
https://ift.tt/mblGc9N
Submitted August 05, 2022 at 11:42PM by sciencestudent99
via reddit https://ift.tt/LQkUeGK
FourCore
New Era of Phishing Payloads - FourCore
Post the Office macros deprecation, a new malware delivery method is on the rise. Container file formats like ISOs/RARs/ZIPs and LNKs/DLLs can bypass Mark-of-the-Web, Microsoft’s prime defence.
Reverse Engineering Windows Printer Drivers (Part 1)
https://ift.tt/9rTzA7y
Submitted August 05, 2022 at 11:26PM by sanitybit
via reddit https://ift.tt/fNo3umJ
https://ift.tt/9rTzA7y
Submitted August 05, 2022 at 11:26PM by sanitybit
via reddit https://ift.tt/fNo3umJ
Include Security Research Blog
Reverse Engineering Windows Printer Drivers (Part 1) - Include Security Research Blog
Note: This is Part 1 in a series of posts discussing security analysis of printer drivers extracted and installed from public resources. This part explains how we located publicly available drivers distributed by WeWork and conducted initial analysis. Part…
How Passwordless Works
https://ift.tt/19CQfTG
Submitted August 06, 2022 at 01:10AM by Blakebvhjjdd
via reddit https://ift.tt/01FDYwZ
https://ift.tt/19CQfTG
Submitted August 06, 2022 at 01:10AM by Blakebvhjjdd
via reddit https://ift.tt/01FDYwZ
Goteleport
How Passwordless Works
Learn how passwordless authentication works and how it's built using WebAuthn.
Repository of Adversarial Tactics That is Updated Daily
https://ift.tt/4oKjweC
Submitted August 06, 2022 at 01:04AM by entropydaemon8
via reddit https://ift.tt/rjsaHbt
https://ift.tt/4oKjweC
Submitted August 06, 2022 at 01:04AM by entropydaemon8
via reddit https://ift.tt/rjsaHbt
GitHub
GitHub - RoseSecurity/Red-Teaming-TTPs: Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike!
Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike! - GitHub - RoseSecurity/Red-Teaming-TTPs: Useful Techniques, Tactics, and Procedures for red teamers and defenders, ...