TA505 Group's TeslaGun In-Depth Analysis
https://ift.tt/UzDlwxr
Submitted September 06, 2022 at 03:43PM by wtfse
via reddit https://ift.tt/dNQsiM3
https://ift.tt/UzDlwxr
Submitted September 06, 2022 at 03:43PM by wtfse
via reddit https://ift.tt/dNQsiM3
Prodaft
[TA505] TA505 Group's TeslaGun In-Depth Analysis - PRODAFT
Prodaft is a cyber threat intelligence company helping organizations to mitigate cyber threats. Our expert engineers put forth proactive defense mechanisms to safeguard your business from cyber attacks.
I patched my Slack client to keep "Oops" messages others delete
https://ift.tt/5V9v1Hl
Submitted September 06, 2022 at 05:06AM by sh0n1z
via reddit https://ift.tt/BUZ0mXI
https://ift.tt/5V9v1Hl
Submitted September 06, 2022 at 05:06AM by sh0n1z
via reddit https://ift.tt/BUZ0mXI
GitHub
GitHub - SharonBrizinov/slack-anti-delete: I patched my Slack client to keep messages that others delete
I patched my Slack client to keep messages that others delete - GitHub - SharonBrizinov/slack-anti-delete: I patched my Slack client to keep messages that others delete
Hardware debug probes for JTAG debugging for Intel and AMD - Necrosys/x86-JTAG-Information
https://ift.tt/Z7XMGYp
Submitted September 06, 2022 at 06:39PM by Gallus
via reddit https://ift.tt/mxsW2MA
https://ift.tt/Z7XMGYp
Submitted September 06, 2022 at 06:39PM by Gallus
via reddit https://ift.tt/mxsW2MA
GitHub
GitHub - Necrosys/x86-JTAG-Information
Contribute to Necrosys/x86-JTAG-Information development by creating an account on GitHub.
How to turn security research into profit: a CL.0 case study
https://ift.tt/C8tdL4W
Submitted September 06, 2022 at 06:58PM by albinowax
via reddit https://ift.tt/crsKgAl
https://ift.tt/C8tdL4W
Submitted September 06, 2022 at 06:58PM by albinowax
via reddit https://ift.tt/crsKgAl
PortSwigger Research
How to turn security research into profit: a CL.0 case study
Have you ever seen a promising hacking technique, only to try it out and struggle to find any vulnerable systems or non-duplicate findings? In this post, I'll take a concise look at the most effective
Vulnerability Analysis of CVE-2018-12613 – phpMyAdmin 4.8.1 Remote Code Execution
https://ift.tt/40V6iDl
Submitted September 06, 2022 at 09:31PM by sandeep1337
via reddit https://ift.tt/QgjHoe8
https://ift.tt/40V6iDl
Submitted September 06, 2022 at 09:31PM by sandeep1337
via reddit https://ift.tt/QgjHoe8
Penetration Testing and CyberSecurity Solution - SecureLayer7
Vulnerability Analysis of CVE-2018-12613 – phpMyAdmin 4.8.1 Remote Code Execution
Vulnerability Analysis of CVE-2018-12613 is explained in the below blog post. PhpMyAdmin is a free and open-source administration tool for MySQL and MariaDB, providing us with a user-friendly...
23 year old Denial of Service bug in Curl
https://ift.tt/iFuT9f0
Submitted September 06, 2022 at 09:26PM by sanitybit
via reddit https://ift.tt/QP47sRd
https://ift.tt/iFuT9f0
Submitted September 06, 2022 at 09:26PM by sanitybit
via reddit https://ift.tt/QP47sRd
Unpatched Unauthenticated Blind SSRF in WordPress Core
https://ift.tt/0ODsqtW
Submitted September 06, 2022 at 09:12PM by monoimpact
via reddit https://ift.tt/tQiSM2H
https://ift.tt/0ODsqtW
Submitted September 06, 2022 at 09:12PM by monoimpact
via reddit https://ift.tt/tQiSM2H
Sonarsource
WordPress Core - Unauthenticated Blind SSRF
Our security researchers were surprised to discover a low-hanging code vulnerability in WordPress Core that we will discuss in this blog post.
Ryuk Ransomware: History, Timeline, and Adversary Simulation
https://ift.tt/K0B3GxY
Submitted September 06, 2022 at 10:43PM by achilles4828
via reddit https://ift.tt/uTqtp1x
https://ift.tt/K0B3GxY
Submitted September 06, 2022 at 10:43PM by achilles4828
via reddit https://ift.tt/uTqtp1x
FourCore
Ryuk Ransomware: History, Timeline, and Adversary Simulation - FourCore
Ryuk is ransomware attributed to the hacker group WIZARD SPIDER that has targeted governments, healthcare, manufacturing, and technology organizations. This article covers the Ryuk Attack, Threat Intel on Ryuk Ransomware, Attack Vectors involved, attack flow…
Sensitive Command Token - So much offense in my defense
https://ift.tt/wkc3Y2I
Submitted September 07, 2022 at 12:43AM by 0xdea
via reddit https://ift.tt/72bMuxU
https://ift.tt/wkc3Y2I
Submitted September 07, 2022 at 12:43AM by 0xdea
via reddit https://ift.tt/72bMuxU
Thinkst Thoughts
Sensitive Command Token – So much offense in my defense
Introduction: Many people have pointed out that there are a handful of commands that are overwhelmingly run by attackers on compromised hosts (and seldom ever by regular users/usage). Reliably aler…
SharkFest'21 Wireshark Conference Playlist - hours of free netsec and network analysis content
https://youtube.com/playlist?list=PLz_ZpPUgiXqPcQWL3uRIq81ONbO28Pbb3bO28Pbb3
Submitted September 07, 2022 at 12:41AM by haveitall
via reddit https://ift.tt/3hR8LFa
https://youtube.com/playlist?list=PLz_ZpPUgiXqPcQWL3uRIq81ONbO28Pbb3bO28Pbb3
Submitted September 07, 2022 at 12:41AM by haveitall
via reddit https://ift.tt/3hR8LFa
Reddit
SharkFest'21 Wireshark Conference Playlist - hours of free netsec and network analysis content : r/netsec
466K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to…
Vulnerability Management for Go
https://ift.tt/AJBMSzL
Submitted September 07, 2022 at 11:29AM by sanitybit
via reddit https://ift.tt/85N9sSg
https://ift.tt/AJBMSzL
Submitted September 07, 2022 at 11:29AM by sanitybit
via reddit https://ift.tt/85N9sSg
go.dev
Vulnerability Management for Go - The Go Programming Language
Announcing vulnerability management for Go, to help developers learn about known vulnerabilities in their dependencies.
Linux CONFIG_WATCH_QUEUE LPE
https://ift.tt/j5YEhdx
Submitted September 07, 2022 at 12:09PM by Gallus
via reddit https://ift.tt/szdB8iU
https://ift.tt/j5YEhdx
Submitted September 07, 2022 at 12:09PM by Gallus
via reddit https://ift.tt/szdB8iU
SSD Secure Disclosure
SSD Advisory – Linux CONFIG_WATCH_QUEUE LPE - SSD Secure Disclosure
Bad handling by Apple Safari allows attackers to use certain look-alike characters instead of the real ones allow attackers to confuse victims into thinking they are reach a certain site, while they are accessing another one.
Malicious reddit clickjacking
https://ift.tt/mQuf5rI
Submitted September 07, 2022 at 01:57PM by [deleted]
via reddit https://ift.tt/ctimIBS
https://ift.tt/mQuf5rI
Submitted September 07, 2022 at 01:57PM by [deleted]
via reddit https://ift.tt/ctimIBS
Groovy Template Engine Exploitation - Notes from a real case scenario
https://ift.tt/drsI4iB
Submitted September 07, 2022 at 03:59PM by 0xdea
via reddit https://ift.tt/VRzAgOf
https://ift.tt/drsI4iB
Submitted September 07, 2022 at 03:59PM by 0xdea
via reddit https://ift.tt/VRzAgOf
hn security
Groovy Template Engine Exploitation - Notes from a real case scenario - hn security
Java web applications are far from […]
OSCP 110 - My own cheat sheet
https://ift.tt/HRtrJiP
Submitted September 07, 2022 at 05:33PM by _kawhl
via reddit https://ift.tt/XMA7IGQ
https://ift.tt/HRtrJiP
Submitted September 07, 2022 at 05:33PM by _kawhl
via reddit https://ift.tt/XMA7IGQ
therealunicornsecurity.github.io
OSCP tips and tricks
How to pwn OSCP labs and exams ! (100 + 10 / 100 points)
evilgophish
https://ift.tt/ho90Cxq
Submitted September 07, 2022 at 06:44PM by edreatingmonkey
via reddit https://ift.tt/tn7rZvB
https://ift.tt/ho90Cxq
Submitted September 07, 2022 at 06:44PM by edreatingmonkey
via reddit https://ift.tt/tn7rZvB
GitHub
GitHub - fin3ss3g0d/evilgophish: evilginx2 + gophish
evilginx2 + gophish. Contribute to fin3ss3g0d/evilgophish development by creating an account on GitHub.
TTPs Associated With a New Version of the BlackCat Ransomware
https://ift.tt/mM6p8zR
Submitted September 07, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/anZ8JwS
https://ift.tt/mM6p8zR
Submitted September 07, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/anZ8JwS
SecurityScorecard
TTPs Associated With a New Version of the BlackCat Ransomware
Zero Day Initiative — CVE-2022-34715: More Microsoft Windows NFS v4 Remote Code Execution
https://ift.tt/6i8zhCR
Submitted September 07, 2022 at 03:00PM by jeandrew
via reddit https://ift.tt/KWO0SmF
https://ift.tt/6i8zhCR
Submitted September 07, 2022 at 03:00PM by jeandrew
via reddit https://ift.tt/KWO0SmF
Zero Day Initiative
Zero Day Initiative — CVE-2022-34715: More Microsoft Windows NFS v4 Remote Code Execution
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Quintin Crist and Dusan Stevanovic of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in the Microsoft Windows operating system…
BSidesLV 2022 Conference Recordings
View the talk schedule here, and then jump into the corresponding playlist:Breaking GroundCommon GroundGround FloorGround TruthHire GroundI Am The CavalryPasswords ConProving Ground
Submitted September 07, 2022 at 11:36PM by sanitybit
via reddit https://ift.tt/TNbC7dj
View the talk schedule here, and then jump into the corresponding playlist:Breaking GroundCommon GroundGround FloorGround TruthHire GroundI Am The CavalryPasswords ConProving Ground
Submitted September 07, 2022 at 11:36PM by sanitybit
via reddit https://ift.tt/TNbC7dj
bsideslv.org
- BSides Las Vegas
BSides Las Vegas is a nonprofit organization formed to stimulate the Information Security industry and community.
SharkFest'21 Wireshark Conference Playlist - hours of free netsec and network analysis content
https://youtube.com/playlist?list=PLz_ZpPUgiXqPcQWL3uRIq81ONbO28Pbb3
Submitted September 07, 2022 at 11:10PM by haveitall
via reddit https://ift.tt/wEQ8F9a
https://youtube.com/playlist?list=PLz_ZpPUgiXqPcQWL3uRIq81ONbO28Pbb3
Submitted September 07, 2022 at 11:10PM by haveitall
via reddit https://ift.tt/wEQ8F9a
YouTube
SF21VUS - Sessions - YouTube
Constant-Time Data Processing At a Secret Offset, Privacy and QUIC
https://ift.tt/4KwxpWZ
Submitted September 07, 2022 at 11:10PM by sanitybit
via reddit https://ift.tt/moPXEtB
https://ift.tt/4KwxpWZ
Submitted September 07, 2022 at 11:10PM by sanitybit
via reddit https://ift.tt/moPXEtB
NCC Group Research
Constant-Time Data Processing At a Secret Offset, Privacy and QUIC
NCC Group Cryptography Services team assessed security aspects of several implementations of the QUIC NCC Group Cryptography Services team assessed security aspects of several implementations of the QUIC protocol. During the course of their reviews, the team…