iOS Privacy: TikTok monitoring all keyboard inputs and taps
https://ift.tt/2U05QgK
Submitted August 19, 2022 at 02:16PM by CyberMasterV
via reddit https://ift.tt/nc1JGfM
https://ift.tt/2U05QgK
Submitted August 19, 2022 at 02:16PM by CyberMasterV
via reddit https://ift.tt/nc1JGfM
900+ SQL Injection variations from one attacker log
https://ift.tt/Em2dlDu
Submitted August 21, 2022 at 12:00AM by nykzhang
via reddit https://ift.tt/0sOyaEp
https://ift.tt/Em2dlDu
Submitted August 21, 2022 at 12:00AM by nykzhang
via reddit https://ift.tt/0sOyaEp
Trunc Logging
SQL Injection Attack Log
Trunc provides a list of SQLi attacks in the wild. Honeypots records over 900 SQL injection attempts.
Detection Engineering with MITRE Top Techniques & Atomic Red Team
https://ift.tt/kgyYON5
Submitted August 21, 2022 at 01:02AM by sciencestudent99
via reddit https://ift.tt/lvE8z7U
https://ift.tt/kgyYON5
Submitted August 21, 2022 at 01:02AM by sciencestudent99
via reddit https://ift.tt/lvE8z7U
FourCore
Detection Engineering with MITRE Top Techniques & Atomic Red Team - FourCore
Detection Engineering is the process of optimizing security controls to get the most value out of them. Therefore, it is essential to prioritize your efforts according to your organization's needs and requirements. Here we cover the methodology of Detection…
FreeBSD 11.0-13.0 LPE via aio_aqueue Kernel Refcount Bug
https://ift.tt/t2TP7iy
Submitted August 21, 2022 at 02:57PM by rwgd406
via reddit https://ift.tt/Movp9zd
https://ift.tt/t2TP7iy
Submitted August 21, 2022 at 02:57PM by rwgd406
via reddit https://ift.tt/Movp9zd
Replicant: Reproducing a Fault Injection Attack on the Trezor One
https://ift.tt/d4UuQTA
Submitted August 21, 2022 at 08:54PM by wrongbaud
via reddit https://ift.tt/bV7i9C5
https://ift.tt/d4UuQTA
Submitted August 21, 2022 at 08:54PM by wrongbaud
via reddit https://ift.tt/bV7i9C5
Voidstar Security Research Blog
Replicant: Reproducing a Fault Injection Attack on the Trezor One
Introduction to Fault Injection Attacks
Backdoor specially made for hardened networks which leverages NTP
https://ift.tt/hmcYFf4
Submitted August 21, 2022 at 04:53PM by Idov31
via reddit https://ift.tt/qPn1B7V
https://ift.tt/hmcYFf4
Submitted August 21, 2022 at 04:53PM by Idov31
via reddit https://ift.tt/qPn1B7V
GitHub
GitHub - Idov31/Sandman: Sandman is a NTP based backdoor for red team engagements in hardened networks.
Sandman is a NTP based backdoor for red team engagements in hardened networks. - GitHub - Idov31/Sandman: Sandman is a NTP based backdoor for red team engagements in hardened networks.
Trivy: Enhanced with AWS scan integration
https://ift.tt/VP6ivzd
Submitted August 22, 2022 at 12:39PM by Rewanth_Tammana
via reddit https://ift.tt/JeSz5oZ
https://ift.tt/VP6ivzd
Submitted August 22, 2022 at 12:39PM by Rewanth_Tammana
via reddit https://ift.tt/JeSz5oZ
Rewanth Tammana's Blog
Trivy: Enhanced with AWS scan integration
Trivy now supports scanning AWS resources for security misconfigurations
GitHub Cache Poisoning
https://ift.tt/BEr0vHD
Submitted August 22, 2022 at 12:24PM by BarakScribe
via reddit https://ift.tt/gYaxhzL
https://ift.tt/BEr0vHD
Submitted August 22, 2022 at 12:24PM by BarakScribe
via reddit https://ift.tt/gYaxhzL
Scribe Security
GitHub Cache Poisoning - Scribe Blog
Without a deep understanding of what happens under the hood of your CI, you might be vulnerable to innovative supply chain attacks
STRIDE Threat Modelling vs DREAD Threat Modelling
https://ift.tt/KaLmO1J
Submitted August 22, 2022 at 01:25PM by InformationSecurity
via reddit https://ift.tt/BlYk0nF
https://ift.tt/KaLmO1J
Submitted August 22, 2022 at 01:25PM by InformationSecurity
via reddit https://ift.tt/BlYk0nF
Haider's Infosec Blog
STRIDE Threat Modelling vs DREAD Threat Modelling - Haider
Stride Threat modelling, Dread Threat modelling, Threat modelling assessment, STRIDE methodology, DREAD methodology
Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
https://ift.tt/Q9KGwhY
Submitted August 22, 2022 at 02:23PM by Ex1v0r
via reddit https://ift.tt/8WIrLCb
https://ift.tt/Q9KGwhY
Submitted August 22, 2022 at 02:23PM by Ex1v0r
via reddit https://ift.tt/8WIrLCb
Modzero
Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor | mod%log
We found a security related issue in most recent CrowdStrike Falcon Sensor. The bug itself is not worth a blogpost, as the severity is pretty low. However, we'd like to shed some light on a vulnerability submission and disclosure process with CrowdStrike:…
“Useless” path traversals in Zyxel admin interface (CVE-2022-2030)
https://ift.tt/w8he7PK
Submitted August 22, 2022 at 05:46PM by 0xdea
via reddit https://ift.tt/8DRIQCw
https://ift.tt/w8he7PK
Submitted August 22, 2022 at 05:46PM by 0xdea
via reddit https://ift.tt/8DRIQCw
hn security
Useless path traversals in Zyxel admin interface (CVE-2022-2030) - hn security
During our analysis of Zyxel’s device […]
Vulnerability in the enforcement of group permissions in Linux containers (Docker, Kubernetes, etc.)
https://ift.tt/EXcnlIM
Submitted August 22, 2022 at 07:59PM by sjmurdoch
via reddit https://ift.tt/FiQNsAJ
https://ift.tt/EXcnlIM
Submitted August 22, 2022 at 07:59PM by sjmurdoch
via reddit https://ift.tt/FiQNsAJ
Bentham’s Gaze
Vulnerability in Linux containers – investigation and mitigation
Operating system access controls, that constrain which programs can open which files, have existed for almost as long as computers themselves. Access controls are still widely used and are more flexible and efficient when compared to cryptographically protecting…
Patch bypass for [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager
https://ift.tt/NGwEguV
Submitted August 22, 2022 at 09:00PM by vah_13
via reddit https://ift.tt/No9IfS3
https://ift.tt/NGwEguV
Submitted August 22, 2022 at 09:00PM by vah_13
via reddit https://ift.tt/No9IfS3
RedRays
Patch bypass for [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager
kyber-py: A pure python implementation of CRYSTALS-Kyber
https://ift.tt/f8CeJ0B
Submitted August 22, 2022 at 11:59PM by sanitybit
via reddit https://ift.tt/9Za30IU
https://ift.tt/f8CeJ0B
Submitted August 22, 2022 at 11:59PM by sanitybit
via reddit https://ift.tt/9Za30IU
GitHub
GitHub - jack4818/kyber-py: A pure python implementation of CRYSTALS-Kyber
A pure python implementation of CRYSTALS-Kyber. Contribute to jack4818/kyber-py development by creating an account on GitHub.
Information Security Checklist for Small to Medium Organizations
https://ift.tt/TdShIe8
Submitted August 23, 2022 at 04:31AM by InformationSecurity
via reddit https://ift.tt/0WScVGo
https://ift.tt/TdShIe8
Submitted August 23, 2022 at 04:31AM by InformationSecurity
via reddit https://ift.tt/0WScVGo
Haider's Infosec Blog
Information Security Checklist for Small to Medium Organizations
Information Security Checklist to protect small and medium sized organizations from emerging information security threats
CVE-2022-22715 PoC: Windows Dirty Pipe
https://ift.tt/eofE1ga
Submitted August 23, 2022 at 11:02AM by sanitybit
via reddit https://ift.tt/5qCbFpA
https://ift.tt/eofE1ga
Submitted August 23, 2022 at 11:02AM by sanitybit
via reddit https://ift.tt/5qCbFpA
Masky is a python library providing an alternative way to remotely dump domain users’ credentials
https://ift.tt/SpyJL06
Submitted August 23, 2022 at 10:59AM by sanitybit
via reddit https://ift.tt/UzamvdB
https://ift.tt/SpyJL06
Submitted August 23, 2022 at 10:59AM by sanitybit
via reddit https://ift.tt/UzamvdB
Zak’s blog
Masky release (v0.0.3)
Masky is a python library providing an alternative way to remotely dump domain users’ credentials thanks to an ADCS. A command line tool has been built on top of this library in order to easily harvest PFX, NT hashes and TGT on a larger scope.
HTTP header Blind SQL injection Example
https://ift.tt/Io7DFE8
Submitted August 23, 2022 at 12:17PM by InformationSecurity
via reddit https://ift.tt/ESRlqsB
https://ift.tt/Io7DFE8
Submitted August 23, 2022 at 12:17PM by InformationSecurity
via reddit https://ift.tt/ESRlqsB
Haider's Infosec Blog
HTTP header Blind SQL injection Example
HTTP header Blind SQL injection Example is explained in this article to show how to exploit SQL injection in HTTP headers.
[CVE-2020-2733] Technical overview and PoC of bypassing admin authentication of JD Edwards EnterpriseOne
https://ift.tt/9hmEGdc
Submitted August 23, 2022 at 05:40PM by vah_13
via reddit https://ift.tt/5qUj1O0
https://ift.tt/9hmEGdc
Submitted August 23, 2022 at 05:40PM by vah_13
via reddit https://ift.tt/5qUj1O0
RedRays
[CVE-2020-2733] JD Edwards EnterpriseOne Tools admin password not adequately protected
JD Edwards EnterpriseOne Tools 9.2 or lower versions allow unauthenticated attackers to bypass the authentication and get Administrator rights on the system.
Argument Injection in Visual Studio Code < 1.67.1 (CVE-2022-30129)
https://ift.tt/rzMN6OQ
Submitted August 23, 2022 at 07:09PM by monoimpact
via reddit https://ift.tt/DI9jVuM
https://ift.tt/rzMN6OQ
Submitted August 23, 2022 at 07:09PM by monoimpact
via reddit https://ift.tt/DI9jVuM
Sonarsource
Securing Developer Tools: Argument Injection in Visual Studio Code
In the third part of our Securing Developer Tools series, we look at a critical vulnerability that affects one of the most popular code editors: Visual Studio Code.
SBOM 101 - All the questions you were afraid to ask Software Bill of Materials
https://ift.tt/4cGzIha
Submitted August 23, 2022 at 08:36PM by MiguelHzBz
via reddit https://ift.tt/fatcrnR
https://ift.tt/4cGzIha
Submitted August 23, 2022 at 08:36PM by MiguelHzBz
via reddit https://ift.tt/fatcrnR
Sysdig
SBOM 101
SBOM is a key piece in securing the software supply chain and fundamental for vulnerability matching and management.