The Anatomy of a Malicious Package
https://ift.tt/fLJBElD
Submitted September 12, 2022 at 09:06AM by ambray_
via reddit https://ift.tt/9Vpc4Lt
https://ift.tt/fLJBElD
Submitted September 12, 2022 at 09:06AM by ambray_
via reddit https://ift.tt/9Vpc4Lt
blog.phylum.io
The Anatomy of a Malicious Package
What does a malicious package actually look like in practice? We'll walk through some hypothetical exercises to see how malware generally works, and what sort of functions we might expect, from relatively simple and temporary, to complex.
Data-Centric Security: Threat Hunting based on Zipf’s Law
https://ift.tt/KiCBmgX
Submitted September 12, 2022 at 11:50AM by ditrizna
via reddit https://ift.tt/1Aa9Im3
https://ift.tt/KiCBmgX
Submitted September 12, 2022 at 11:50AM by ditrizna
via reddit https://ift.tt/1Aa9Im3
Medium
Security Data Science: Threat Hunting based on Zipf’s Law
Anomaly detection engineering based on ubiquitous Zipfian distribution in enterprise security telemetry.
Redeye is a platform to cover all aspects of red team engagement (data management, red team operation management, etc.)
https://ift.tt/FBSzTHh
Submitted September 12, 2022 at 08:09PM by Idov31
via reddit https://ift.tt/uTLVfos
https://ift.tt/FBSzTHh
Submitted September 12, 2022 at 08:09PM by Idov31
via reddit https://ift.tt/uTLVfos
GitHub
GitHub - redeye-framework/Redeye: Redeye is a tool intended to help you manage your data during a pentest operation
Redeye is a tool intended to help you manage your data during a pentest operation - redeye-framework/Redeye
How a Script Kiddie and 25 Lines of Python Could Theoretically Devastate America’s Gas Stations
https://ift.tt/lVXL9ZA
Submitted September 12, 2022 at 11:01PM by entropydaemon9
via reddit https://ift.tt/ls3Zbei
https://ift.tt/lVXL9ZA
Submitted September 12, 2022 at 11:01PM by entropydaemon9
via reddit https://ift.tt/ls3Zbei
Medium
A Theoretically Devastating Cyber Attack on America’s Gas Stations:
The Internet of Gas Station Tank Gauges:
The seventh way to call a JavaScript function without parentheses
https://ift.tt/JfdxpSN
Submitted September 12, 2022 at 11:57PM by 0xdea
via reddit https://ift.tt/RJkqgHC
https://ift.tt/JfdxpSN
Submitted September 12, 2022 at 11:57PM by 0xdea
via reddit https://ift.tt/RJkqgHC
PortSwigger Research
The seventh way to call a JavaScript function without parentheses
I thought I knew all the ways to call functions without parentheses: alert`1337` throw onerror=alert,1337 Function`x${'alert\x281337\x29'}x``` 'alert\x281337\x29'instanceof{[Symbol['hasInstance']]:eva
GitHub - thiagopeixoto/massayo: Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL by loading a freshy copy from disk and replacing the .text section of the currently loaded DLL
https://ift.tt/6RrH4Ph
Submitted September 13, 2022 at 03:07AM by thewatcher_
via reddit https://ift.tt/OqLZK0A
https://ift.tt/6RrH4Ph
Submitted September 13, 2022 at 03:07AM by thewatcher_
via reddit https://ift.tt/OqLZK0A
GitHub
GitHub - thiagopeixoto/massayo: Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL
Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL - GitHub - thiagopeixoto/massayo: Massayo is a small proof-of-concept Rust library which removes AV...
Let’s Encrypt is turning on new infrastructure to support revoking certificates via Certificate Revocation Lists
https://ift.tt/Zy60vhW
Submitted September 12, 2022 at 06:19PM by c0r0n3r
via reddit https://ift.tt/wDLG7mZ
https://ift.tt/Zy60vhW
Submitted September 12, 2022 at 06:19PM by c0r0n3r
via reddit https://ift.tt/wDLG7mZ
letsencrypt.org
A New Life for Certificate Revocation Lists
This month, Let’s Encrypt is turning on new infrastructure to support revoking certificates via Certificate Revocation Lists. Despite having been largely supplanted by the Online Certificate Status Protocol for over a decade now, CRLs are gaining new life…
The magic about how modern OS boot
https://ift.tt/xYn9ytl
Submitted September 13, 2022 at 03:58PM by hardenedvault
via reddit https://ift.tt/pWgY8HT
https://ift.tt/xYn9ytl
Submitted September 13, 2022 at 03:58PM by hardenedvault
via reddit https://ift.tt/pWgY8HT
hardenedvault.net
The magic about how modern OS boot
Linux kernel Under x86/amd64 architecture, Linux kernel is usually packed into bzImage format, which contains a partially-filled data structure for boot parameter, and multiple entry points of stages for 16-bit real mode, 32-bit protected mode, and 64-bit…
Request for Contribution: List of all Security Blogs on the Internet
https://ift.tt/z4W3nRC
Submitted September 13, 2022 at 05:25PM by si9int
via reddit https://ift.tt/F0xDyGl
https://ift.tt/z4W3nRC
Submitted September 13, 2022 at 05:25PM by si9int
via reddit https://ift.tt/F0xDyGl
Introducing CloudFox: Automating situational awareness for cloud penetration tests
https://ift.tt/L5lwtgh
Submitted September 13, 2022 at 08:26PM by sethsec
via reddit https://ift.tt/C49LQM3
https://ift.tt/L5lwtgh
Submitted September 13, 2022 at 08:26PM by sethsec
via reddit https://ift.tt/C49LQM3
Bishop Fox
Introducing Bishop Fox Security Tool: CloudFox
Introducing CloudFox, a command line security tool created to help offensive security professionals find exploitable attack paths in cloud infrastructure.
How Cymulate Discovered an Abuse Risk in Google Cloud Platform (GCP)
https://ift.tt/IHOFajY
Submitted September 14, 2022 at 01:34PM by cutboxhe
via reddit https://ift.tt/ezYO1qN
https://ift.tt/IHOFajY
Submitted September 14, 2022 at 01:34PM by cutboxhe
via reddit https://ift.tt/ezYO1qN
Cymulate
How Cymulate Discovered an Abuse Risk in Google Cloud Platform (GCP)
Cymulate recently uncovered an abuse risk in Google Cloud Platform's 'google-guest-agent'. Here is the roadmap to that discovery.
Hacking Unity Games with Malicious GameObjects, Part 2
https://ift.tt/jZ0uYNb
Submitted September 13, 2022 at 10:32PM by haxboxone
via reddit https://ift.tt/9gjAeKm
https://ift.tt/jZ0uYNb
Submitted September 13, 2022 at 10:32PM by haxboxone
via reddit https://ift.tt/9gjAeKm
Include Security Research Blog
Hacking Unity Games with Malicious GameObjects, Part 2 - Include Security Research Blog
In my last post I talked about a way I found to execute arbitrary code in Unity using no custom noscripts, only built-in components. This allowed potential attacks against Unity games that load AssetBundles from untrusted sources since, although AssetBundles…
Attacking the Android kernel using the Qualcomm TrustZone
https://ift.tt/oU2rBwv
Submitted September 14, 2022 at 03:14PM by jeandrew
via reddit https://ift.tt/xWgZ2HQ
https://ift.tt/oU2rBwv
Submitted September 14, 2022 at 03:14PM by jeandrew
via reddit https://ift.tt/xWgZ2HQ
Tamir Zahavi-Brunner’s Blog
Attacking the Android kernel using the Qualcomm TrustZone
In this post I describe a somewhat unique Android kernel exploit, which utilizes the TrustZone in order to compromise the kernel.
Bypassing IP based brute force protection with IPv6 temporary addresses
https://ift.tt/gI6713i
Submitted September 14, 2022 at 06:50PM by nopslider
via reddit https://ift.tt/2NpFlyg
https://ift.tt/gI6713i
Submitted September 14, 2022 at 06:50PM by nopslider
via reddit https://ift.tt/2NpFlyg
Cyberis Limited
Bypassing IP based brute force protection with IPv6
Brute-force protections – designed to protect against attacks like password guessing – need to be carefully pitched and have associated pros and cons. Many popular protections these days rely upon monitoring and blocking malicious activity based on source…
Edgeless Systems debuts open-source, runtime-encrypted Kubernetes distribution
https://ift.tt/KGlsoNp
Submitted September 14, 2022 at 06:37PM by laramontoyalaske
via reddit https://ift.tt/hR3U6PC
https://ift.tt/KGlsoNp
Submitted September 14, 2022 at 06:37PM by laramontoyalaske
via reddit https://ift.tt/hR3U6PC
SiliconANGLE
Edgeless Systems debuts open-source, runtime-encrypted Kubernetes distribution - SiliconANGLE
135 is the new 445: PsExec over Remote Procedure Calls
https://ift.tt/0q32g6d
Submitted September 14, 2022 at 08:27PM by 0xdea
via reddit https://ift.tt/orDbnCG
https://ift.tt/0q32g6d
Submitted September 14, 2022 at 08:27PM by 0xdea
via reddit https://ift.tt/orDbnCG
Pentera
135 is the new 445 - Pentera
If it was possible to nominate a command-line utility for an award, PsExec would definitively win the most useful category. This tool allows
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
https://ift.tt/x9tXCWg
Submitted September 14, 2022 at 08:27PM by albinowax
via reddit https://ift.tt/XF6fiVO
https://ift.tt/x9tXCWg
Submitted September 14, 2022 at 08:27PM by albinowax
via reddit https://ift.tt/XF6fiVO
Codecepticon - An offensive security obfuscator for C#, VBA, and PowerShell
https://ift.tt/TevYHgN
Submitted September 14, 2022 at 11:52PM by h0wlett
via reddit https://ift.tt/ODcKoPr
https://ift.tt/TevYHgN
Submitted September 14, 2022 at 11:52PM by h0wlett
via reddit https://ift.tt/ODcKoPr
GitHub
GitHub - Accenture/Codecepticon
Contribute to Accenture/Codecepticon development by creating an account on GitHub.
It pays to be Circomspect
https://ift.tt/uPaRmbZ
Submitted September 15, 2022 at 09:31AM by Gallus
via reddit https://ift.tt/h4VcBws
https://ift.tt/uPaRmbZ
Submitted September 15, 2022 at 09:31AM by Gallus
via reddit https://ift.tt/h4VcBws
Trail of Bits Blog
It pays to be Circomspect
By Fredrik Dahlgren, Staff Security Engineer In October 2019, a security researcher found a devastating vulnerability in Tornado.cash, a decentralized, non-custodial mixer on the Ethereum network. …
Traces of Windows remote command execution
https://ift.tt/XZj9FBm
Submitted September 15, 2022 at 10:21AM by jeandrew
via reddit https://ift.tt/Ra82F9T
https://ift.tt/XZj9FBm
Submitted September 15, 2022 at 10:21AM by jeandrew
via reddit https://ift.tt/Ra82F9T
Synacktiv
Traces of Windows remote command execution
A real ninja leaves no traces.
Security Advisory: NETGEAR Routers FunJSQ Vulnerabilities
https://ift.tt/nDg36St
Submitted September 15, 2022 at 02:27PM by g_e_r_h_a_r_d
via reddit https://ift.tt/nRZiApq
https://ift.tt/nDg36St
Submitted September 15, 2022 at 02:27PM by g_e_r_h_a_r_d
via reddit https://ift.tt/nRZiApq
ONEKEY
Several problems in FunJSQ on NETGEAR Routers & Orbi WiFi Systems.
Get more information about the detailed vulnerability analysis - Read latest Advisory!