Write-up of N-day exploit for CVE-2022-2586: Linux kernel nft_object UAF
https://ift.tt/ZyGupHY
Submitted August 30, 2022 at 01:51PM by gid0rah
via reddit https://ift.tt/JWsX6OK
https://ift.tt/ZyGupHY
Submitted August 30, 2022 at 01:51PM by gid0rah
via reddit https://ift.tt/JWsX6OK
CVE-2022-26113: FortiClient Arbitrary File Write As SYSTEM
https://ift.tt/wa0yNA1
Submitted August 30, 2022 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/fDOM235
https://ift.tt/wa0yNA1
Submitted August 30, 2022 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/fDOM235
Rhino Security Labs
CVE-2022-26113: FortiClient Arbitrary File Write As SYSTEM - Rhino Security Labs
CVE-2022-26113: Arbitrary file write as SYSTEM in Fortinet VPN, with privilege escalation implications.
hashcathelper: Convenience tool for hashcat - crack NT hashes by taking LM hashes into account; generate analytics for cracked passwords; visualize "SamePassword" clusters in Bloodhound
https://ift.tt/aAVpRew
Submitted August 30, 2022 at 11:45PM by 0xfffffg
via reddit https://ift.tt/4TIHvpz
https://ift.tt/aAVpRew
Submitted August 30, 2022 at 11:45PM by 0xfffffg
via reddit https://ift.tt/4TIHvpz
GitHub
GitHub - SySS-Research/hashcathelper: Convenience tool for hashcat
Convenience tool for hashcat . Contribute to SySS-Research/hashcathelper development by creating an account on GitHub.
Bootkitting Windows Sandbox
https://ift.tt/wjiNn0A
Submitted August 31, 2022 at 12:14AM by mrexodia
via reddit https://ift.tt/6rPjKZ5
https://ift.tt/wjiNn0A
Submitted August 31, 2022 at 12:14AM by mrexodia
via reddit https://ift.tt/6rPjKZ5
secret club
Bootkitting Windows Sandbox
Introduction & Motivation Windows Sandbox is a feature that Microsoft added to Windows back in May 2019. As Microsoft puts it: Windows Sandbox provides a lightweight desktop environment to safely run applications in isolation. Software installed inside the…
reinschauer - A PoC to remotely control Windows machines over Websockets.
https://ift.tt/TZe1MbB
Submitted August 31, 2022 at 04:30AM by sanitybit
via reddit https://ift.tt/Kgmt86T
https://ift.tt/TZe1MbB
Submitted August 31, 2022 at 04:30AM by sanitybit
via reddit https://ift.tt/Kgmt86T
GitHub
GitHub - ps1337/reinschauer: it is very good
it is very good. Contribute to ps1337/reinschauer development by creating an account on GitHub.
Going Atomic: The Strengths and Weaknesses of a Technique-centric Purple Teaming Approach
https://ift.tt/ANKUiCf
Submitted August 31, 2022 at 04:20AM by sanitybit
via reddit https://ift.tt/D7uGUrY
https://ift.tt/ANKUiCf
Submitted August 31, 2022 at 04:20AM by sanitybit
via reddit https://ift.tt/D7uGUrY
ajpc500
Blue Team Con: Going Atomic
The Strengths and Weaknesses of a Technique-centric Purple Teaming Approach
MATE: Interactive Program Analysis with Code Property Graphs
https://ift.tt/UtEOuyw
Submitted August 31, 2022 at 05:35AM by sanitybit
via reddit https://ift.tt/ItlKvSb
https://ift.tt/UtEOuyw
Submitted August 31, 2022 at 05:35AM by sanitybit
via reddit https://ift.tt/ItlKvSb
Galois, Inc.
MATE: Interactive Program Analysis with Code Property Graphs - Galois, Inc.
Galois is open-sourcing MATE, a suite of tools for interactive program analysis with a focus on hunting for bugs in C and C++ code. MATE unifies application-specific and low-level vulnerability analysis using code property graphs (CPGs), enabling the discovery…
Microsoft ports Windows SymCrypt to Linux, bringing a FIPS certified drop-in module to OpenSSL
https://ift.tt/hgbVd0a
Submitted August 31, 2022 at 05:25AM by sanitybit
via reddit https://ift.tt/TKNdvBy
https://ift.tt/hgbVd0a
Submitted August 31, 2022 at 05:25AM by sanitybit
via reddit https://ift.tt/TKNdvBy
GitHub
GitHub - microsoft/SymCrypt-OpenSSL: OpenSSL engine for use with SymCrypt cryptographic library
OpenSSL engine for use with SymCrypt cryptographic library - GitHub - microsoft/SymCrypt-OpenSSL: OpenSSL engine for use with SymCrypt cryptographic library
Announcing Google’s Open Source Software Vulnerability Rewards Program
https://ift.tt/EmjUFNd
Submitted August 31, 2022 at 05:13AM by sanitybit
via reddit https://ift.tt/Ks7AFEw
https://ift.tt/EmjUFNd
Submitted August 31, 2022 at 05:13AM by sanitybit
via reddit https://ift.tt/Ks7AFEw
Google Online Security Blog
Announcing Google’s Open Source Software Vulnerability Rewards Program
Posted by Francis Perron, Open Source Security Technical Program Manager, and Krzysztof Kotowicz, Information Security Engineer Today, we a...
Snakes on a Domain: An Analysis of a Python Malware Loader
https://ift.tt/u6K7ThH
Submitted August 31, 2022 at 04:59AM by sanitybit
via reddit https://ift.tt/7dlimXB
https://ift.tt/u6K7ThH
Submitted August 31, 2022 at 04:59AM by sanitybit
via reddit https://ift.tt/7dlimXB
Huntress
Snakes on a Domain: An Analysis of a Python Malware Loader
Join us on a threat analysis journey as we discover a very shady Python—and a very friendly RAT.
Digging into an NTLM Downgrade Attack
https://ift.tt/Cbfi710
Submitted August 31, 2022 at 10:36AM by 0xdea
via reddit https://ift.tt/9TiMpjO
https://ift.tt/Cbfi710
Submitted August 31, 2022 at 10:36AM by 0xdea
via reddit https://ift.tt/9TiMpjO
Praetorian
Digging into an NTLM Downgrade Attack - Praetorian
Overcoming version hurdles to perform an NTLM downgrade attack and obtain an NTLMv1 hash from a target computer during our ADFS research.
CVE-2021-38297 - Technical analysis of a Go WebAssembly vulnerability
https://ift.tt/tMlFcBL
Submitted August 31, 2022 at 01:00PM by SRMish3
via reddit https://ift.tt/bWgVx0S
https://ift.tt/tMlFcBL
Submitted August 31, 2022 at 01:00PM by SRMish3
via reddit https://ift.tt/bWgVx0S
JFrog
CVE-2021-38297 - Go Web Assembly Vulnerability
CVE-2021-38297 allows attackers to override an entire Wasm module & achieve WebAssembly code execution. Read technical analysis & mitigation from JFrog Security research >
From Onboarding to Offboarding - Securing GitHub Apps Integration
https://ift.tt/kr16TSX
Submitted August 31, 2022 at 04:46PM by Hefty_Knowledge_7449
via reddit https://ift.tt/yZf89qN
https://ift.tt/kr16TSX
Submitted August 31, 2022 at 04:46PM by Hefty_Knowledge_7449
via reddit https://ift.tt/yZf89qN
Cider Security Site
From Onboarding to Offboarding - Securing GitHub Apps Integration
GitHub officially recommends using GitHub Apps when integrating with GitHub, as they are easy to build and enjoy a rich and extensive API. Most of us GitHub users have probably installed at least a few GitHub Apps, but have you ever stopped and wondered…
Announcing the Open Sourcing of Paranoid's Library - Detect well-known weaknesses in large amounts of crypto artifacts, like public keys and digital signatures
https://ift.tt/cCkDUuN
Submitted August 31, 2022 at 06:01PM by _rs
via reddit https://ift.tt/2LcM7SG
https://ift.tt/cCkDUuN
Submitted August 31, 2022 at 06:01PM by _rs
via reddit https://ift.tt/2LcM7SG
Google Online Security Blog
Announcing the Open Sourcing of Paranoid's Library
Posted by Pedro Barbosa, Security Engineer, and Daniel Bleichenbacher, Software Engineer Paranoid is a project to detect well-known weaknes...
Restricting Libraries in JVM Compute Platforms - Security challenges with Scala and Java libraries
https://ift.tt/9v0O2Sx
Submitted August 31, 2022 at 05:59PM by _rs
via reddit https://ift.tt/YXUasHj
https://ift.tt/9v0O2Sx
Submitted August 31, 2022 at 05:59PM by _rs
via reddit https://ift.tt/YXUasHj
Databricks
Restricting Libraries in JVM Compute Platforms
Security challenges
Open source automated AWS CIS v1.5 benchmark assessment just released by Steampipe.io
https://ift.tt/DWYMJLZ
Submitted August 31, 2022 at 07:37PM by bobtbot
via reddit https://ift.tt/nsUPdQh
https://ift.tt/DWYMJLZ
Submitted August 31, 2022 at 07:37PM by bobtbot
via reddit https://ift.tt/nsUPdQh
Steampipe Hub
AWS Compliance Mod for Steampipe
Run individual configuration, compliance and security controls or full compliance benchmarks for CIS, FFIEC, PCI, NIST, HIPAA, RBI CSF, GDPR, SOC 2, Audit Manager Control Tower, FedRAMP, GxP and AWS Foundational Security Best Practices controls across all…
MemLabs: Learn Memory Forensics through CTF-styled labs
https://ift.tt/vDJVbma
Submitted August 31, 2022 at 11:02PM by sanitybit
via reddit https://ift.tt/a1wWzvq
https://ift.tt/vDJVbma
Submitted August 31, 2022 at 11:02PM by sanitybit
via reddit https://ift.tt/a1wWzvq
GitHub
GitHub - stuxnet999/MemLabs: Educational, CTF-styled labs for individuals interested in Memory Forensics
Educational, CTF-styled labs for individuals interested in Memory Forensics - GitHub - stuxnet999/MemLabs: Educational, CTF-styled labs for individuals interested in Memory Forensics
Vulnerability in TikTok Android app could lead to one-click account hijacking
https://ift.tt/hMktFVm
Submitted August 31, 2022 at 11:00PM by CyberMasterV
via reddit https://ift.tt/7FHoKa5
https://ift.tt/hMktFVm
Submitted August 31, 2022 at 11:00PM by CyberMasterV
via reddit https://ift.tt/7FHoKa5
Microsoft Security Blog
Vulnerability in TikTok Android app could lead to one-click account hijacking | Microsoft Security Blog
Microsoft discovered a high-severity vulnerability in the TikTok Android application, now identified as CVE-2022-28799 and fixed by TikTok, which could have allowed attackers to compromise users' accounts with a single click.
Linux Audit comes at a cost, is that where BPF steps in?
https://ift.tt/qpMrDfI
Submitted August 31, 2022 at 11:10PM by Blakebvhjjdd
via reddit https://ift.tt/3suzlTD
https://ift.tt/qpMrDfI
Submitted August 31, 2022 at 11:10PM by Blakebvhjjdd
via reddit https://ift.tt/3suzlTD
Goteleport
What You Need to Know About Linux Audit Framework
In this blog post, we'll deep-dive into Linux Audit Framework.
How I Met Your Beacon: Detection Strategies
https://ift.tt/yThR9X4
Submitted September 01, 2022 at 05:53AM by sanitybit
via reddit https://ift.tt/hLxNg32
https://ift.tt/yThR9X4
Submitted September 01, 2022 at 05:53AM by sanitybit
via reddit https://ift.tt/hLxNg32
MDSec
PART 1: How I Met Your Beacon - Overview - MDSec
Introduction Its no secret that MDSec provides a commercial command-and-control framework with a focus on evasion for covert operations. With this in mind, we are continuously performing on-going R&D in...
SETTLERS OF NETLINK: Exploiting a limited Use After Free in nf_tables (CVE-2022-32250) against the latest Ubuntu (22.04) and Linux kernel 5.15 -
https://ift.tt/uk9fqmt
Submitted September 01, 2022 at 02:38PM by digicat
via reddit https://ift.tt/Uh2gLq3
https://ift.tt/uk9fqmt
Submitted September 01, 2022 at 02:38PM by digicat
via reddit https://ift.tt/Uh2gLq3
NCC Group Research
SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)
Introduction netlink and nf_tables Overview Sets Expressions Set Expressions Stateful Expressions Expressions of Interest nft_lookup nft_dynset nft_connlimit Vulnerability Discovery CVE-2022-32250 …