Several powerful primitives for exploiting the macOS kernel may never get fixed
https://ift.tt/KX6EdQz
Submitted August 17, 2022 at 09:43PM by gaasedelen
via reddit https://ift.tt/cX2Mu1S
https://ift.tt/KX6EdQz
Submitted August 17, 2022 at 09:43PM by gaasedelen
via reddit https://ift.tt/cX2Mu1S
RET2 Systems Blog
The LDT, a Perfect Home for All Your Kernel Payloads
With the broad adoption of Kernel Address Space Layout Randomization (KASLR) by modern systems, obtaining an information leak is a necessary component of mos...
How to secure AWS S3 buckets with sensitive data
https://ift.tt/aevc8jA
Submitted August 18, 2022 at 03:50AM by cloudsecnerd
via reddit https://ift.tt/FtUfBIu
https://ift.tt/aevc8jA
Submitted August 18, 2022 at 03:50AM by cloudsecnerd
via reddit https://ift.tt/FtUfBIu
Kloudle
How to secure AWS S3 buckets with sensitive data
A lot of users, organizations and even nation states and governments utilize the versatility of Amazon’s S3 service. Any data that is stored on S3 needs to maintain the basic tenets of security, which include encryption of data at rest, in motion, authorization…
About Jenkins tokens
https://ift.tt/4BJxAgO
Submitted August 18, 2022 at 05:12PM by gquere
via reddit https://ift.tt/qSiEDK7
https://ift.tt/4BJxAgO
Submitted August 18, 2022 at 05:12PM by gquere
via reddit https://ift.tt/qSiEDK7
Hardware-based threat defense against increasingly complex cryptojackers
https://ift.tt/Y5RwBck
Submitted August 18, 2022 at 10:49PM by SCI_Rusher
via reddit https://ift.tt/HKtQeq5
https://ift.tt/Y5RwBck
Submitted August 18, 2022 at 10:49PM by SCI_Rusher
via reddit https://ift.tt/HKtQeq5
Microsoft Security Blog
Hardware-based threat defense against increasingly complex cryptojackers - Microsoft Security Blog
To provide advanced protection against increasingly complex and evasive cryptojackers, Microsoft Defender Antivirus integrates with Intel® Threat Detection Technology (TDT) that applies machine learning to low-level CPU telemetry in detecting cryptojackers…
Multiple Vulnerabilites Discovered in RPA Vendor Blue Prism.
https://ift.tt/FxEcWv8
Submitted August 18, 2022 at 11:59PM by jat0369
via reddit https://ift.tt/W6ahk14
https://ift.tt/FxEcWv8
Submitted August 18, 2022 at 11:59PM by jat0369
via reddit https://ift.tt/W6ahk14
Cyberark
Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets?
In our complicated and challenging enterprise world, trust is not just important — it’s a vital link in the long chain of enterprise success. If you’ve ever managed people who didn’t trust one...
Zero Day Initiative — But You Told Me You Were Safe: Attacking the Mozilla Firefox Renderer (Part 1)
https://ift.tt/ThqWmDp
Submitted August 19, 2022 at 09:11AM by sanitybit
via reddit https://ift.tt/YGQWcyX
https://ift.tt/ThqWmDp
Submitted August 19, 2022 at 09:11AM by sanitybit
via reddit https://ift.tt/YGQWcyX
Zero Day Initiative
Zero Day Initiative — But You Told Me You Were Safe: Attacking the Mozilla Firefox Renderer (Part 1)
Vulnerabilities and exploits in common targets like browsers are often associated with memory safety issues. Typically this involves either a direct error in memory management or a way to corrupt internal object state in the JavaScript engine. One way to…
Oh SSH-it, what's my fingerprint? A Large-Scale Analysis of SSH Host Key Fingerprint Verification Records in the DNS
https://ift.tt/ZsNSF4M
Submitted August 19, 2022 at 09:07AM by sanitybit
via reddit https://ift.tt/ZLj8QPU
https://ift.tt/ZsNSF4M
Submitted August 19, 2022 at 09:07AM by sanitybit
via reddit https://ift.tt/ZLj8QPU
A Lightweight Approach To Implement Secure Software Development LifeCycle (Secure SDLC)
https://ift.tt/teT906Y
Submitted August 19, 2022 at 11:53AM by sanitybit
via reddit https://ift.tt/2cJKUTj
https://ift.tt/teT906Y
Submitted August 19, 2022 at 11:53AM by sanitybit
via reddit https://ift.tt/2cJKUTj
GraphQL Security Testing Without a Schema
https://ift.tt/Jdcjy9T
Submitted August 19, 2022 at 11:44PM by alxjsn
via reddit https://ift.tt/RDP2YMT
https://ift.tt/Jdcjy9T
Submitted August 19, 2022 at 11:44PM by alxjsn
via reddit https://ift.tt/RDP2YMT
Forces Unseen Blog
GraphQL Security Testing Without a Schema — Forces Unseen Blog
One of the main obstacles of a black box GraphQL security review is getting good coverage of the exposed functionality. Anyone who has re...
Pitraix Botnet - Modern P2P Self-Modifying Botnet Cross-Platform Over TOR
https://ift.tt/qYmeH3C
Submitted August 19, 2022 at 11:13PM by United-General-2000
via reddit https://ift.tt/tSqVJWg
https://ift.tt/qYmeH3C
Submitted August 19, 2022 at 11:13PM by United-General-2000
via reddit https://ift.tt/tSqVJWg
GitHub
GitHub - ThrillQuks/Pitraix: Modern Cross-Platform Peer-to-Peer Botnet over TOR
Modern Cross-Platform Peer-to-Peer Botnet over TOR - GitHub - ThrillQuks/Pitraix: Modern Cross-Platform Peer-to-Peer Botnet over TOR
Bighuge BLS OSINT Tool - BBOT
https://ift.tt/AFQXqWd
Submitted August 20, 2022 at 12:45AM by aconite33
via reddit https://ift.tt/wlV3Knz
https://ift.tt/AFQXqWd
Submitted August 20, 2022 at 12:45AM by aconite33
via reddit https://ift.tt/wlV3Knz
GitHub
GitHub - blacklanternsecurity/bbot: OSINT automation for hackers.
OSINT automation for hackers. Contribute to blacklanternsecurity/bbot development by creating an account on GitHub.
iOS Privacy: TikTok monitoring all keyboard inputs and taps
https://ift.tt/2U05QgK
Submitted August 19, 2022 at 02:16PM by CyberMasterV
via reddit https://ift.tt/nc1JGfM
https://ift.tt/2U05QgK
Submitted August 19, 2022 at 02:16PM by CyberMasterV
via reddit https://ift.tt/nc1JGfM
900+ SQL Injection variations from one attacker log
https://ift.tt/Em2dlDu
Submitted August 21, 2022 at 12:00AM by nykzhang
via reddit https://ift.tt/0sOyaEp
https://ift.tt/Em2dlDu
Submitted August 21, 2022 at 12:00AM by nykzhang
via reddit https://ift.tt/0sOyaEp
Trunc Logging
SQL Injection Attack Log
Trunc provides a list of SQLi attacks in the wild. Honeypots records over 900 SQL injection attempts.
Detection Engineering with MITRE Top Techniques & Atomic Red Team
https://ift.tt/kgyYON5
Submitted August 21, 2022 at 01:02AM by sciencestudent99
via reddit https://ift.tt/lvE8z7U
https://ift.tt/kgyYON5
Submitted August 21, 2022 at 01:02AM by sciencestudent99
via reddit https://ift.tt/lvE8z7U
FourCore
Detection Engineering with MITRE Top Techniques & Atomic Red Team - FourCore
Detection Engineering is the process of optimizing security controls to get the most value out of them. Therefore, it is essential to prioritize your efforts according to your organization's needs and requirements. Here we cover the methodology of Detection…
FreeBSD 11.0-13.0 LPE via aio_aqueue Kernel Refcount Bug
https://ift.tt/t2TP7iy
Submitted August 21, 2022 at 02:57PM by rwgd406
via reddit https://ift.tt/Movp9zd
https://ift.tt/t2TP7iy
Submitted August 21, 2022 at 02:57PM by rwgd406
via reddit https://ift.tt/Movp9zd
Replicant: Reproducing a Fault Injection Attack on the Trezor One
https://ift.tt/d4UuQTA
Submitted August 21, 2022 at 08:54PM by wrongbaud
via reddit https://ift.tt/bV7i9C5
https://ift.tt/d4UuQTA
Submitted August 21, 2022 at 08:54PM by wrongbaud
via reddit https://ift.tt/bV7i9C5
Voidstar Security Research Blog
Replicant: Reproducing a Fault Injection Attack on the Trezor One
Introduction to Fault Injection Attacks
Backdoor specially made for hardened networks which leverages NTP
https://ift.tt/hmcYFf4
Submitted August 21, 2022 at 04:53PM by Idov31
via reddit https://ift.tt/qPn1B7V
https://ift.tt/hmcYFf4
Submitted August 21, 2022 at 04:53PM by Idov31
via reddit https://ift.tt/qPn1B7V
GitHub
GitHub - Idov31/Sandman: Sandman is a NTP based backdoor for red team engagements in hardened networks.
Sandman is a NTP based backdoor for red team engagements in hardened networks. - GitHub - Idov31/Sandman: Sandman is a NTP based backdoor for red team engagements in hardened networks.
Trivy: Enhanced with AWS scan integration
https://ift.tt/VP6ivzd
Submitted August 22, 2022 at 12:39PM by Rewanth_Tammana
via reddit https://ift.tt/JeSz5oZ
https://ift.tt/VP6ivzd
Submitted August 22, 2022 at 12:39PM by Rewanth_Tammana
via reddit https://ift.tt/JeSz5oZ
Rewanth Tammana's Blog
Trivy: Enhanced with AWS scan integration
Trivy now supports scanning AWS resources for security misconfigurations
GitHub Cache Poisoning
https://ift.tt/BEr0vHD
Submitted August 22, 2022 at 12:24PM by BarakScribe
via reddit https://ift.tt/gYaxhzL
https://ift.tt/BEr0vHD
Submitted August 22, 2022 at 12:24PM by BarakScribe
via reddit https://ift.tt/gYaxhzL
Scribe Security
GitHub Cache Poisoning - Scribe Blog
Without a deep understanding of what happens under the hood of your CI, you might be vulnerable to innovative supply chain attacks
STRIDE Threat Modelling vs DREAD Threat Modelling
https://ift.tt/KaLmO1J
Submitted August 22, 2022 at 01:25PM by InformationSecurity
via reddit https://ift.tt/BlYk0nF
https://ift.tt/KaLmO1J
Submitted August 22, 2022 at 01:25PM by InformationSecurity
via reddit https://ift.tt/BlYk0nF
Haider's Infosec Blog
STRIDE Threat Modelling vs DREAD Threat Modelling - Haider
Stride Threat modelling, Dread Threat modelling, Threat modelling assessment, STRIDE methodology, DREAD methodology
Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
https://ift.tt/Q9KGwhY
Submitted August 22, 2022 at 02:23PM by Ex1v0r
via reddit https://ift.tt/8WIrLCb
https://ift.tt/Q9KGwhY
Submitted August 22, 2022 at 02:23PM by Ex1v0r
via reddit https://ift.tt/8WIrLCb
Modzero
Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor | mod%log
We found a security related issue in most recent CrowdStrike Falcon Sensor. The bug itself is not worth a blogpost, as the severity is pretty low. However, we'd like to shed some light on a vulnerability submission and disclosure process with CrowdStrike:…