Melis Platform CMS patched for critical RCE flaw (CVE-2022-39297)
https://ift.tt/5SDkjwJ
Submitted October 25, 2022 at 10:58PM by monoimpact
via reddit https://ift.tt/BDtEb9U
https://ift.tt/5SDkjwJ
Submitted October 25, 2022 at 10:58PM by monoimpact
via reddit https://ift.tt/BDtEb9U
The Daily Swig | Cybersecurity news and views
Melis Platform CMS patched for critical RCE flaw
POP chain crafted to demonstrate exploitability
4 Ways Conventional SIEM Advances into NextGen SIEM
https://ift.tt/u0KPsbW
Submitted October 26, 2022 at 12:36AM by Pale-Cobbler-4895
via reddit https://ift.tt/xfQmEHR
https://ift.tt/u0KPsbW
Submitted October 26, 2022 at 12:36AM by Pale-Cobbler-4895
via reddit https://ift.tt/xfQmEHR
Digitalconnectmag
4 Ways Conventional SIEM Advances into NextGen SIEM
An IDC study reveals that most organizations regard security information and event management (SIEM) as sacred. There appears to be a consensus that SIEM is a crucial part of cybersecurity. However, with the rapidly evolving nature of cyber threats, there…
The Secrets Behind Uber's Breach
https://ift.tt/3Db9zYU
Submitted October 26, 2022 at 01:36AM by Nashifa
via reddit https://ift.tt/C3KJm2Q
https://ift.tt/3Db9zYU
Submitted October 26, 2022 at 01:36AM by Nashifa
via reddit https://ift.tt/C3KJm2Q
Akeyless
The Secrets Behind Uber's Breach | Akeyless
Join our CEO Oded Hareven and Admiral Michael Rogers of Team8 as they discuss the implications behind the recent Uber breach.
topmostp: A simple CLI tool to retrieve the N top most used ports
https://ift.tt/1Vk2Yiq
Submitted October 26, 2022 at 01:21PM by deleee
via reddit https://ift.tt/bIyYSxB
https://ift.tt/1Vk2Yiq
Submitted October 26, 2022 at 01:21PM by deleee
via reddit https://ift.tt/bIyYSxB
GitHub
GitHub - cybersecsi/topmostp: A simple CLI tool to retrieve the N top most used ports
A simple CLI tool to retrieve the N top most used ports - GitHub - cybersecsi/topmostp: A simple CLI tool to retrieve the N top most used ports
Lateral Movement via AutodialDLL registry key abuse
https://ift.tt/fZ7rc02
Submitted October 26, 2022 at 04:08PM by gid0rah
via reddit https://ift.tt/et4Gr5P
https://ift.tt/fZ7rc02
Submitted October 26, 2022 at 04:08PM by gid0rah
via reddit https://ift.tt/et4Gr5P
MDSec
Autodial(DLL)ing Your Way - MDSec
The use of the AutodialDLL registry subkey (located in HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters) as a persistence method has been previously documented by @Hexacorn in his series Beyond good ol’ Run key, (Part 24)....
I took a look at the most active Github users who publish the most CVE's
https://ift.tt/9RWKr8V
Submitted October 26, 2022 at 03:52PM by DevOpsMuffin39
via reddit https://ift.tt/BCMF3gx
https://ift.tt/9RWKr8V
Submitted October 26, 2022 at 03:52PM by DevOpsMuffin39
via reddit https://ift.tt/BCMF3gx
GitHub
PoC_CVEs/cve_links_by_github_username.txt at main · tg12/PoC_CVEs
PoC_CVEs. Contribute to tg12/PoC_CVEs development by creating an account on GitHub.
Token handles abuse: One shell to HANDLE them all
https://ift.tt/I1YgpH8
Submitted October 26, 2022 at 04:58PM by gid0rah
via reddit https://ift.tt/5Z2DmpB
https://ift.tt/I1YgpH8
Submitted October 26, 2022 at 04:58PM by gid0rah
via reddit https://ift.tt/5Z2DmpB
Tarlogic Security
One shell to HANDLE them all
Introduction
During a Red Team engagement, the exploitation of vulnerabilities in web apps usually offers a good chance of
During a Red Team engagement, the exploitation of vulnerabilities in web apps usually offers a good chance of
Ring0VBA - Getting Ring0 Using a Goddamn Word Document
https://ift.tt/YvJUWOg
Submitted October 26, 2022 at 07:35PM by CyberMasterV
via reddit https://ift.tt/gEwqvpA
https://ift.tt/YvJUWOg
Submitted October 26, 2022 at 07:35PM by CyberMasterV
via reddit https://ift.tt/gEwqvpA
Hijacking AUR Packages by Searching for Expired Domains
https://ift.tt/GRx70lu
Submitted October 26, 2022 at 10:54PM by whisperingmime
via reddit https://ift.tt/kEbGq9f
https://ift.tt/GRx70lu
Submitted October 26, 2022 at 10:54PM by whisperingmime
via reddit https://ift.tt/kEbGq9f
Blog by Joren Vrancken
Hijacking AUR Packages by Searching for Expired Domains
The Arch User Repository (AUR) is a software repository for Arch Linux. It differs from the official Arch Linux repositories in that its packages are provided by its users and not officially supported by Arch Linux.
Ethernet ghosting & NAC bypass - A practical overview
https://ift.tt/Ry8za7q
Submitted October 27, 2022 at 09:18AM by Gallus
via reddit https://ift.tt/USqp4nc
https://ift.tt/Ry8za7q
Submitted October 27, 2022 at 09:18AM by Gallus
via reddit https://ift.tt/USqp4nc
🪄 wb - A wizard that brings old files from Wayback Machine.
https://ift.tt/cNrGa9K
Submitted October 27, 2022 at 12:38PM by rjz4
via reddit https://ift.tt/S1Rdu0z
https://ift.tt/cNrGa9K
Submitted October 27, 2022 at 12:38PM by rjz4
via reddit https://ift.tt/S1Rdu0z
GitHub
GitHub - riza/wb: Quickly fetches files from Wayback Machine.
Quickly fetches files from Wayback Machine. Contribute to riza/wb development by creating an account on GitHub.
Building a multifunctional red team dropbox for USB and Ethernet attacks
https://ift.tt/jTzcLRq
Submitted October 27, 2022 at 02:50PM by RoganDawes
via reddit https://ift.tt/Kag5nxC
https://ift.tt/jTzcLRq
Submitted October 27, 2022 at 02:50PM by RoganDawes
via reddit https://ift.tt/Kag5nxC
Sensepost
SensePost | Making the perfect red team dropbox (part 1)
Leaders in Information Security
Divin'n'phishin with executable filetypes on Windows
https://ift.tt/lniyuE2
Submitted October 27, 2022 at 03:36PM by ljulolsen
via reddit https://ift.tt/LnXgDG7
https://ift.tt/lniyuE2
Submitted October 27, 2022 at 03:36PM by ljulolsen
via reddit https://ift.tt/LnXgDG7
Rubrique-a-brac
Divin'n'phishin with executable filetypes on Windows
In order to find phishing payloads, one needs to understand how executable filetypes on Windows are handled, finding which ones can be delivered to mail clients, thus users, without being caught by mail defences in between and without requesting multiple…
Visual Studio Code Jupyter Notebook RCE (CVE-2021-26437)
https://ift.tt/3ImKWHL
Submitted October 27, 2022 at 06:15PM by nibblesec
via reddit https://ift.tt/IQOrZ5n
https://ift.tt/3ImKWHL
Submitted October 27, 2022 at 06:15PM by nibblesec
via reddit https://ift.tt/IQOrZ5n
Doyensec
Visual Studio Code Jupyter Notebook RCE · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Open source automated Tailscale security best practices benchmark assessment just released by Steampipe.io
https://ift.tt/com1XG3
Submitted October 27, 2022 at 08:01PM by stevecio
via reddit https://ift.tt/13HP64j
https://ift.tt/com1XG3
Submitted October 27, 2022 at 08:01PM by stevecio
via reddit https://ift.tt/13HP64j
Steampipe Hub
Tailscale Compliance Mod for Steampipe
Run individual configuration, compliance and security controls or full compliance benchmarks for Tailscale.
control flow unflattening of an android rasp sdk
https://ift.tt/9MhZwaj
Submitted October 27, 2022 at 10:30PM by eybisi_
via reddit https://ift.tt/JwX3CIf
https://ift.tt/9MhZwaj
Submitted October 27, 2022 at 10:30PM by eybisi_
via reddit https://ift.tt/JwX3CIf
hedgehog's cave
Control Flow Unflattening
TargetRecently I have analyzed a RASP solution called Approov. Although there are some novel detection techniques, overall it’s not that interesting. Instead, I will focus on the obfuscation part of
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
https://ift.tt/KIfpqHS
Submitted October 28, 2022 at 12:43AM by karimhabush
via reddit https://ift.tt/RQGFXA7
https://ift.tt/KIfpqHS
Submitted October 28, 2022 at 12:43AM by karimhabush
via reddit https://ift.tt/RQGFXA7
GitHub
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark. - GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment agains...
Hexacon conference videos
https://www.youtube.com/channel/UCtzuVwPhBVFAQnes0NrqxBA/videos
Submitted October 27, 2022 at 05:45PM by gquere
via reddit https://ift.tt/zM6Tdkb
https://www.youtube.com/channel/UCtzuVwPhBVFAQnes0NrqxBA/videos
Submitted October 27, 2022 at 05:45PM by gquere
via reddit https://ift.tt/zM6Tdkb
reddit
Hexacon conference videos
Posted in r/netsec by u/gquere • 15 points and 1 comment
OpenSSL: CRITICAL vulnerability will be fixed in upcoming release
https://ift.tt/0cqfOsT
Submitted October 26, 2022 at 04:57PM by josephnoir
via reddit https://ift.tt/lMDXWOy
https://ift.tt/0cqfOsT
Submitted October 26, 2022 at 04:57PM by josephnoir
via reddit https://ift.tt/lMDXWOy
Towards the next generation of XNU memory safety: kalloc_type
https://ift.tt/Tw5x9zD
Submitted October 28, 2022 at 02:29AM by sanitybit
via reddit https://ift.tt/ACXzjnJ
https://ift.tt/Tw5x9zD
Submitted October 28, 2022 at 02:29AM by sanitybit
via reddit https://ift.tt/ACXzjnJ
Blog - Towards the next generation of XNU memory safety: kalloc_type - Apple Security Research
Improving software memory safety is a key security objective for engineering teams across the industry. Here we begin a journey into the XNU kernel at the core of iOS and explore the intricate work our engineering teams have done to harden the memory allocator…
One-Time Programs
https://ift.tt/vey3IYW
Submitted October 28, 2022 at 12:17AM by feross
via reddit https://ift.tt/qW9iYSN
https://ift.tt/vey3IYW
Submitted October 28, 2022 at 12:17AM by feross
via reddit https://ift.tt/qW9iYSN
A Few Thoughts on Cryptographic Engineering
One-Time Programs
One of the things I like to do on this blog is write about new research that has a practical angle. Most of the time (I swear) this involves writing about other folks’ research: it’s no…