Visual Studio Code Jupyter Notebook RCE (CVE-2021-26437)
https://ift.tt/3ImKWHL
Submitted October 27, 2022 at 06:15PM by nibblesec
via reddit https://ift.tt/IQOrZ5n
https://ift.tt/3ImKWHL
Submitted October 27, 2022 at 06:15PM by nibblesec
via reddit https://ift.tt/IQOrZ5n
Doyensec
Visual Studio Code Jupyter Notebook RCE · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Open source automated Tailscale security best practices benchmark assessment just released by Steampipe.io
https://ift.tt/com1XG3
Submitted October 27, 2022 at 08:01PM by stevecio
via reddit https://ift.tt/13HP64j
https://ift.tt/com1XG3
Submitted October 27, 2022 at 08:01PM by stevecio
via reddit https://ift.tt/13HP64j
Steampipe Hub
Tailscale Compliance Mod for Steampipe
Run individual configuration, compliance and security controls or full compliance benchmarks for Tailscale.
control flow unflattening of an android rasp sdk
https://ift.tt/9MhZwaj
Submitted October 27, 2022 at 10:30PM by eybisi_
via reddit https://ift.tt/JwX3CIf
https://ift.tt/9MhZwaj
Submitted October 27, 2022 at 10:30PM by eybisi_
via reddit https://ift.tt/JwX3CIf
hedgehog's cave
Control Flow Unflattening
TargetRecently I have analyzed a RASP solution called Approov. Although there are some novel detection techniques, overall it’s not that interesting. Instead, I will focus on the obfuscation part of
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
https://ift.tt/KIfpqHS
Submitted October 28, 2022 at 12:43AM by karimhabush
via reddit https://ift.tt/RQGFXA7
https://ift.tt/KIfpqHS
Submitted October 28, 2022 at 12:43AM by karimhabush
via reddit https://ift.tt/RQGFXA7
GitHub
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark. - GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment agains...
Hexacon conference videos
https://www.youtube.com/channel/UCtzuVwPhBVFAQnes0NrqxBA/videos
Submitted October 27, 2022 at 05:45PM by gquere
via reddit https://ift.tt/zM6Tdkb
https://www.youtube.com/channel/UCtzuVwPhBVFAQnes0NrqxBA/videos
Submitted October 27, 2022 at 05:45PM by gquere
via reddit https://ift.tt/zM6Tdkb
reddit
Hexacon conference videos
Posted in r/netsec by u/gquere • 15 points and 1 comment
OpenSSL: CRITICAL vulnerability will be fixed in upcoming release
https://ift.tt/0cqfOsT
Submitted October 26, 2022 at 04:57PM by josephnoir
via reddit https://ift.tt/lMDXWOy
https://ift.tt/0cqfOsT
Submitted October 26, 2022 at 04:57PM by josephnoir
via reddit https://ift.tt/lMDXWOy
Towards the next generation of XNU memory safety: kalloc_type
https://ift.tt/Tw5x9zD
Submitted October 28, 2022 at 02:29AM by sanitybit
via reddit https://ift.tt/ACXzjnJ
https://ift.tt/Tw5x9zD
Submitted October 28, 2022 at 02:29AM by sanitybit
via reddit https://ift.tt/ACXzjnJ
Blog - Towards the next generation of XNU memory safety: kalloc_type - Apple Security Research
Improving software memory safety is a key security objective for engineering teams across the industry. Here we begin a journey into the XNU kernel at the core of iOS and explore the intricate work our engineering teams have done to harden the memory allocator…
One-Time Programs
https://ift.tt/vey3IYW
Submitted October 28, 2022 at 12:17AM by feross
via reddit https://ift.tt/qW9iYSN
https://ift.tt/vey3IYW
Submitted October 28, 2022 at 12:17AM by feross
via reddit https://ift.tt/qW9iYSN
A Few Thoughts on Cryptographic Engineering
One-Time Programs
One of the things I like to do on this blog is write about new research that has a practical angle. Most of the time (I swear) this involves writing about other folks’ research: it’s no…
TCP/IP Vulnerability CVE-2022–34718 PoC Restoration and Analysis
https://ift.tt/PA5RrJh
Submitted October 28, 2022 at 09:04AM by sanitybit
via reddit https://ift.tt/lo2qpXd
https://ift.tt/PA5RrJh
Submitted October 28, 2022 at 09:04AM by sanitybit
via reddit https://ift.tt/lo2qpXd
Medium
Analysis and Summary of TCP/IP Protocol Remote Code Execution Vulnerability CVE-2022–34718
An Analysis of Remote Code Execution Vulnerability CVE-2022–34718
Spartacus DLL Hijacking Discovery Tool - "all in one"
https://ift.tt/eIKawur
Submitted October 28, 2022 at 06:54PM by h0wlett
via reddit https://ift.tt/5ZctT1w
https://ift.tt/eIKawur
Submitted October 28, 2022 at 06:54PM by h0wlett
via reddit https://ift.tt/5ZctT1w
GitHub
GitHub - Accenture/Spartacus: Spartacus DLL Hijacking Discovery Tool
Spartacus DLL Hijacking Discovery Tool. Contribute to Accenture/Spartacus development by creating an account on GitHub.
EDR: Detections, Bypassess and other Shenanigans
https://ift.tt/becG4tZ
Submitted October 28, 2022 at 08:21PM by sciencestudent99
via reddit https://ift.tt/ukRp4SW
https://ift.tt/becG4tZ
Submitted October 28, 2022 at 08:21PM by sciencestudent99
via reddit https://ift.tt/ukRp4SW
FourCore
EDR: Detections, Bypassess and other Shenanigans
EDR or Endpoint Detection and Response refers to an integrated endpoint security solution which continuously monitors end-point user's devices and try to prevent anomalies like Malware, Ransomware by using automated rule based response method.
Dastardly - a free, lightweight web application security scanner for your CI/CD pipeline
https://ift.tt/mFelc15
Submitted October 28, 2022 at 11:26PM by Khryse
via reddit https://ift.tt/o6w0IRf
https://ift.tt/mFelc15
Submitted October 28, 2022 at 11:26PM by Khryse
via reddit https://ift.tt/o6w0IRf
PortSwigger Blog
Free: Dastardly from Burp Suite
Introducing Dastardly - a free, lightweight web application security scanner for your CI/CD pipeline, from the makers of Burp Suite. Secure web development ain't easy Ensuring your code is written sec
Hardware Trojans Under a Microscope
https://ift.tt/kYjhuLM
Submitted October 28, 2022 at 06:49AM by Ryancor
via reddit https://ift.tt/PjHNq34
https://ift.tt/kYjhuLM
Submitted October 28, 2022 at 06:49AM by Ryancor
via reddit https://ift.tt/PjHNq34
Medium
Hardware Trojans Under a Microscope
Table of Contents
CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities – Blog
https://ift.tt/lJZA2DB
Submitted October 28, 2022 at 10:58PM by spacedust65
via reddit https://ift.tt/SXUl1Fx
https://ift.tt/lJZA2DB
Submitted October 28, 2022 at 10:58PM by spacedust65
via reddit https://ift.tt/SXUl1Fx
A vulnerability in the Galaxy Store allows attackers through an XSS to cause the store to install and/or launch an application, allowing remote attackers to trigger a remote command execution in the phone.
https://ift.tt/Q0Fh4r8
Submitted October 27, 2022 at 06:58PM by SSDisclosure
via reddit https://ift.tt/toqHUJx
https://ift.tt/Q0Fh4r8
Submitted October 27, 2022 at 06:58PM by SSDisclosure
via reddit https://ift.tt/toqHUJx
SSD Secure Disclosure
SSD Advisory – Galaxy Store Applications Installation/Launching without User Interaction - SSD Secure Disclosure
TL;DR A vulnerability in the Galaxy Store allows attackers through an XSS to cause the store to install and/or launch an application, allowing […]
Australian organisations under increasing attack - Medibank and Optus were just part of an overall 81% increase in targeting
https://ift.tt/ZtHVUJb
Submitted October 29, 2022 at 12:28AM by SuaveHobo
via reddit https://ift.tt/ngXYr3B
https://ift.tt/ZtHVUJb
Submitted October 29, 2022 at 12:28AM by SuaveHobo
via reddit https://ift.tt/ngXYr3B
Substack
Australia in the Crosshairs
Preparing for increasing cyber attacks and enhanced regulatory obligations
Passkeys as a tool for user retention
https://ift.tt/162IzvA
Submitted October 29, 2022 at 01:22AM by Khryse
via reddit https://ift.tt/CHvnqgG
https://ift.tt/162IzvA
Submitted October 29, 2022 at 01:22AM by Khryse
via reddit https://ift.tt/CHvnqgG
Mat Duggan
Passkeys as a tool for user retention
With the release of iOS 16 and MacOS Ventura, we are now in the age of passkeys. This is happening through WebAuthn, a specification written by the W3C and FIDO with the involvement of all of the major vendors such as Google, Mozilla, etc. The basic premise…
RC4 Is Still Considered Harmful
https://ift.tt/27Jaozx
Submitted October 29, 2022 at 03:43AM by sanitybit
via reddit https://ift.tt/ih5DLpe
https://ift.tt/27Jaozx
Submitted October 29, 2022 at 03:43AM by sanitybit
via reddit https://ift.tt/ih5DLpe
Blogspot
RC4 Is Still Considered Harmful
By James Forshaw, Project Zero I've been spending a lot of time researching Windows authentication implementations, specifically Kerberos. I...
mitmproxy 9: WireGuard Mode and Raw UDP Support
https://ift.tt/XQzgtjN
Submitted October 29, 2022 at 06:19PM by mhils
via reddit https://ift.tt/JPeFUbX
https://ift.tt/XQzgtjN
Submitted October 29, 2022 at 06:19PM by mhils
via reddit https://ift.tt/JPeFUbX
GitHub - Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across all your GitHub assets
https://ift.tt/qUeDjhs
Submitted October 30, 2022 at 01:30AM by roy_6472
via reddit https://ift.tt/WRzi3Y4
https://ift.tt/qUeDjhs
Submitted October 30, 2022 at 01:30AM by roy_6472
via reddit https://ift.tt/WRzi3Y4
GitHub
GitHub - Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets - GitHub - Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across a...
Urgent: Patch OpenSSL on November 1 to avoid “Critical” Security Vulnerability - GlobalSign
https://ift.tt/NwXKhz7
Submitted October 30, 2022 at 04:07AM by c0r0n3r
via reddit https://ift.tt/tgKV3Ni
https://ift.tt/NwXKhz7
Submitted October 30, 2022 at 04:07AM by c0r0n3r
via reddit https://ift.tt/tgKV3Ni
GlobalSign
OpenSSL Release Patches Critical Vulnerability - GlobalSign
A critical vulnerability has been discovered in current versions of OpenSSL and will need to be patched immediately.