Getting started with gVisor support in Falco
https://ift.tt/UtIdJey
Submitted September 15, 2022 at 08:01PM by vjjmiras
via reddit https://ift.tt/dzm64yk
https://ift.tt/UtIdJey
Submitted September 15, 2022 at 08:01PM by vjjmiras
via reddit https://ift.tt/dzm64yk
Falco
Getting started with gVisor support in Falco
Learn how to integrate gVisor and Falco on Docker
The Blind Spots of BloodHound
https://ift.tt/bYJOIKx
Submitted September 15, 2022 at 08:55PM by 0xfffffg
via reddit https://ift.tt/VkMv6Y9
https://ift.tt/bYJOIKx
Submitted September 15, 2022 at 08:55PM by 0xfffffg
via reddit https://ift.tt/VkMv6Y9
SySS Tech Blog
The Blind Spots of BloodHound
Let’s get one thing straight: This article is not at all a dig on BloodHound.
CVE North Stars: Leverage CVEs to kickstart your next vulnerability hunting adventure
https://ift.tt/ke6XOSa
Submitted September 15, 2022 at 10:26PM by onlinereadme
via reddit https://ift.tt/LC34EhD
https://ift.tt/ke6XOSa
Submitted September 15, 2022 at 10:26PM by onlinereadme
via reddit https://ift.tt/LC34EhD
CVE North Stars
Home
Leveraging CVE, patch diffing, and root cause analysis to kickstart your vulnerability hunting adventure.
NPM Malware Targeting HubSpot’s Bucky Client
https://ift.tt/gdumjNq
Submitted September 15, 2022 at 11:17PM by louis11
via reddit https://ift.tt/12LRlbX
https://ift.tt/gdumjNq
Submitted September 15, 2022 at 11:17PM by louis11
via reddit https://ift.tt/12LRlbX
blog.phylum.io
NPM Malware Targeting HubSpot’s Bucky Client
Our risk analysis platform recently alerted us to a malicious package in the NPM ecosystem targeting Bucky Client, a project owned by HubSpot.
Undermining Microsoft Teams Security by Mining Tokens
https://ift.tt/nd41k6R
Submitted September 16, 2022 at 06:46AM by flexibeast
via reddit https://ift.tt/TuxMgo8
https://ift.tt/nd41k6R
Submitted September 16, 2022 at 06:46AM by flexibeast
via reddit https://ift.tt/TuxMgo8
www.vectra.ai
Undermining Microsoft Teams Security by Mining Tokens
In August 2022, the Vectra Protect team identified an attack path that enables malicious actors with file system access to steal credentials for any Microsoft Teams user who is signed in.
Uber hacked, internal systems breached and vulnerability reports stolen
https://ift.tt/hYuqaIS
Submitted September 16, 2022 at 12:35PM by Fugitif
via reddit https://ift.tt/6ivjTYN
https://ift.tt/hYuqaIS
Submitted September 16, 2022 at 12:35PM by Fugitif
via reddit https://ift.tt/6ivjTYN
BleepingComputer
Uber hacked, internal systems breached and vulnerability reports stolen
Uber suffered a cyberattack Thursday afternoon with a hacker gaining access to vulnerability reports and sharing screenshots of the company's internal systems, email dashboard, and Slack server.
DylibHijackTest: Discover DYLD_INSERT_LIBRARIES hijacks on macOS
https://ift.tt/tf8KTnM
Submitted September 16, 2022 at 01:17PM by sanitybit
via reddit https://ift.tt/VZ1bok6
https://ift.tt/tf8KTnM
Submitted September 16, 2022 at 01:17PM by sanitybit
via reddit https://ift.tt/VZ1bok6
GitHub
GitHub - slyd0g/DylibHijackTest: Discover DYLD_INSERT_LIBRARIES hijacks on macOS
Discover DYLD_INSERT_LIBRARIES hijacks on macOS. Contribute to slyd0g/DylibHijackTest development by creating an account on GitHub.
A Basic Guide to iOS Testing in 2022
https://ift.tt/McRWDpm
Submitted September 16, 2022 at 01:14PM by sanitybit
via reddit https://ift.tt/1a9K3fj
https://ift.tt/McRWDpm
Submitted September 16, 2022 at 01:14PM by sanitybit
via reddit https://ift.tt/1a9K3fj
Bugcrowd
A Basic Guide to iOS Testing in 2022 | Bugcrowd
Get a close look at iOS testing with this guide by researcher Alxhh. Learn about the methods that allow you to test modern apps right away!
Jetty Features for Hacking Web Apps
https://ift.tt/RHcJSaU
Submitted September 16, 2022 at 01:12PM by sanitybit
via reddit https://ift.tt/2ELdFfb
https://ift.tt/RHcJSaU
Submitted September 16, 2022 at 01:12PM by sanitybit
via reddit https://ift.tt/2ELdFfb
PT SWARM
Jetty Features for Hacking Web Apps
To properly assess the security of a web application, it’s important to analyze it with regard to the server it will run on. Many things depend on the server, from processing user requests to the easiest way of achieving RCE. Armed with knowledge about the…
Staged Payloads from Kali Linux | PT Phone Home – DNS
https://ift.tt/xHpDuMr
Submitted September 16, 2022 at 12:57PM by sanitybit
via reddit https://ift.tt/FmMO32f
https://ift.tt/xHpDuMr
Submitted September 16, 2022 at 12:57PM by sanitybit
via reddit https://ift.tt/FmMO32f
OffSec
Staged Payloads from Kali Linux | PT Phone Home – DNS | OffSec
In part one of this post, Tristram teaches you how to use TXT records to stage payloads that can be retrieved through DNS lookups.
cloudvelo: An experimental Velociraptor implementation using cloud infrastructure
https://ift.tt/U3DSreN
Submitted September 17, 2022 at 01:03AM by sanitybit
via reddit https://ift.tt/qavl79s
https://ift.tt/U3DSreN
Submitted September 17, 2022 at 01:03AM by sanitybit
via reddit https://ift.tt/qavl79s
GitHub
GitHub - Velocidex/cloudvelo: An experimental Velociraptor implementation using cloud infrastructure
An experimental Velociraptor implementation using cloud infrastructure - GitHub - Velocidex/cloudvelo: An experimental Velociraptor implementation using cloud infrastructure
Practical Attacks against NTLMv1
https://ift.tt/GVKepHS
Submitted September 18, 2022 at 02:44AM by sanitybit
via reddit https://ift.tt/hoPNDVJ
https://ift.tt/GVKepHS
Submitted September 18, 2022 at 02:44AM by sanitybit
via reddit https://ift.tt/hoPNDVJ
TrustedSec
Practical Attacks against NTLMv1 - TrustedSec
TrustedSec's blog is an expert source of information on information security trends and best practices for strategic risk management.
LLVM Passes for Security: A Brief Introduction (Part 1/4)
https://ift.tt/ghkHdOJ
Submitted September 18, 2022 at 02:40AM by sanitybit
via reddit https://ift.tt/r6FBCZW
https://ift.tt/ghkHdOJ
Submitted September 18, 2022 at 02:40AM by sanitybit
via reddit https://ift.tt/r6FBCZW
Securing the Supply Chain of Nothing
https://ift.tt/C76gA9L
Submitted September 18, 2022 at 02:37AM by sanitybit
via reddit https://ift.tt/l9IdEhM
https://ift.tt/C76gA9L
Submitted September 18, 2022 at 02:37AM by sanitybit
via reddit https://ift.tt/l9IdEhM
Kelly Shortridge
Securing the Supply Chain of Nothing
This post is a rebuttal to the recent guide on “Securing the Software Supply Chain” published by CISA, ODNI, and the NSA.
requests-ip-rotator: A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.
https://ift.tt/mDGNFfj
Submitted September 18, 2022 at 07:26AM by sanitybit
via reddit https://ift.tt/FaPe3g9
https://ift.tt/mDGNFfj
Submitted September 18, 2022 at 07:26AM by sanitybit
via reddit https://ift.tt/FaPe3g9
GitHub
GitHub - Ge0rg3/requests-ip-rotator: A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo…
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing. - GitHub - Ge0rg3/requests-ip-rotator: A Python li...
Virtual FIDO is a virtual USB device that implements the FIDO2/U2F protocol (like a YubiKey) in order to support 2FA and WebAuthN.
https://ift.tt/iZbLeFW
Submitted September 18, 2022 at 06:51AM by sanitybit
via reddit https://ift.tt/vxd8yPe
https://ift.tt/iZbLeFW
Submitted September 18, 2022 at 06:51AM by sanitybit
via reddit https://ift.tt/vxd8yPe
GitHub
GitHub - bulwarkid/virtual-fido: A Virtual FIDO2 USB Device
A Virtual FIDO2 USB Device. Contribute to bulwarkid/virtual-fido development by creating an account on GitHub.
ldapnomnom: Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)
https://ift.tt/gs0RTMp
Submitted September 19, 2022 at 01:09AM by sanitybit
via reddit https://ift.tt/ciW2skt
https://ift.tt/gs0RTMp
Submitted September 19, 2022 at 01:09AM by sanitybit
via reddit https://ift.tt/ciW2skt
GitHub
GitHub - lkarlslund/ldapnomnom: Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping…
Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) - GitHub - lkarlslund/ldapnomnom: Anonymously bruteforce Active Directory usernames f...
GTA 6 source code and videos leaked after Rockstar Games hack
https://ift.tt/plGmv9s
Submitted September 19, 2022 at 12:32PM by CyberMasterV
via reddit https://ift.tt/B1ib6ae
https://ift.tt/plGmv9s
Submitted September 19, 2022 at 12:32PM by CyberMasterV
via reddit https://ift.tt/B1ib6ae
BleepingComputer
GTA 6 source code and videos leaked after Rockstar Games hack
Grand Theft Auto 6 gameplay videos and source code have been leaked after a hacker allegedly breached Rockstar Game's Slack server and Confluence wiki.
Vulnerabilities Identified in EZVIZ Smart Cams
https://ift.tt/PcDB7Nj
Submitted September 19, 2022 at 09:11PM by Turbulent-Ant-6813
via reddit https://ift.tt/ySlCIAw
https://ift.tt/PcDB7Nj
Submitted September 19, 2022 at 09:11PM by Turbulent-Ant-6813
via reddit https://ift.tt/ySlCIAw
Bitdefender Labs
Vulnerabilities Identified in EZVIZ Smart Cams
As the creator of the world’s first smart home cybersecurity hub, Bitdefender
regularly audits popular IoT hardware for vulnerabilities that might affect
customers if left unaddressed.
regularly audits popular IoT hardware for vulnerabilities that might affect
customers if left unaddressed.
Open Source Tool to Collect Volatile Data for Incident Response
https://ift.tt/nsqlJTV
Submitted September 20, 2022 at 09:15PM by 0x636f6f6c
via reddit https://ift.tt/eSUnGLZ
https://ift.tt/nsqlJTV
Submitted September 20, 2022 at 09:15PM by 0x636f6f6c
via reddit https://ift.tt/eSUnGLZ
GitHub
GitHub - cado-security/varc: Volatile Artifact Collector
Volatile Artifact Collector. Contribute to cado-security/varc development by creating an account on GitHub.
I'm Building a Self-Destructing USB Drive Part 2
https://ift.tt/fLlVSHn
Submitted September 19, 2022 at 10:18PM by Machinehum
via reddit https://ift.tt/d0ujpGF
https://ift.tt/fLlVSHn
Submitted September 19, 2022 at 10:18PM by Machinehum
via reddit https://ift.tt/d0ujpGF
Interrupt Labs Blog
I'm Building a Self-Destructing USB Drive Part 2
I’m building an open-source USB drive with a hidden self-destruct feature. Say goodbye to your data if you don’t lick your fingers before plugging it