EDR: Detections, Bypassess and other Shenanigans
https://ift.tt/becG4tZ
Submitted October 28, 2022 at 08:21PM by sciencestudent99
via reddit https://ift.tt/ukRp4SW
https://ift.tt/becG4tZ
Submitted October 28, 2022 at 08:21PM by sciencestudent99
via reddit https://ift.tt/ukRp4SW
FourCore
EDR: Detections, Bypassess and other Shenanigans
EDR or Endpoint Detection and Response refers to an integrated endpoint security solution which continuously monitors end-point user's devices and try to prevent anomalies like Malware, Ransomware by using automated rule based response method.
Dastardly - a free, lightweight web application security scanner for your CI/CD pipeline
https://ift.tt/mFelc15
Submitted October 28, 2022 at 11:26PM by Khryse
via reddit https://ift.tt/o6w0IRf
https://ift.tt/mFelc15
Submitted October 28, 2022 at 11:26PM by Khryse
via reddit https://ift.tt/o6w0IRf
PortSwigger Blog
Free: Dastardly from Burp Suite
Introducing Dastardly - a free, lightweight web application security scanner for your CI/CD pipeline, from the makers of Burp Suite. Secure web development ain't easy Ensuring your code is written sec
Hardware Trojans Under a Microscope
https://ift.tt/kYjhuLM
Submitted October 28, 2022 at 06:49AM by Ryancor
via reddit https://ift.tt/PjHNq34
https://ift.tt/kYjhuLM
Submitted October 28, 2022 at 06:49AM by Ryancor
via reddit https://ift.tt/PjHNq34
Medium
Hardware Trojans Under a Microscope
Table of Contents
CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities – Blog
https://ift.tt/lJZA2DB
Submitted October 28, 2022 at 10:58PM by spacedust65
via reddit https://ift.tt/SXUl1Fx
https://ift.tt/lJZA2DB
Submitted October 28, 2022 at 10:58PM by spacedust65
via reddit https://ift.tt/SXUl1Fx
A vulnerability in the Galaxy Store allows attackers through an XSS to cause the store to install and/or launch an application, allowing remote attackers to trigger a remote command execution in the phone.
https://ift.tt/Q0Fh4r8
Submitted October 27, 2022 at 06:58PM by SSDisclosure
via reddit https://ift.tt/toqHUJx
https://ift.tt/Q0Fh4r8
Submitted October 27, 2022 at 06:58PM by SSDisclosure
via reddit https://ift.tt/toqHUJx
SSD Secure Disclosure
SSD Advisory – Galaxy Store Applications Installation/Launching without User Interaction - SSD Secure Disclosure
TL;DR A vulnerability in the Galaxy Store allows attackers through an XSS to cause the store to install and/or launch an application, allowing […]
Australian organisations under increasing attack - Medibank and Optus were just part of an overall 81% increase in targeting
https://ift.tt/ZtHVUJb
Submitted October 29, 2022 at 12:28AM by SuaveHobo
via reddit https://ift.tt/ngXYr3B
https://ift.tt/ZtHVUJb
Submitted October 29, 2022 at 12:28AM by SuaveHobo
via reddit https://ift.tt/ngXYr3B
Substack
Australia in the Crosshairs
Preparing for increasing cyber attacks and enhanced regulatory obligations
Passkeys as a tool for user retention
https://ift.tt/162IzvA
Submitted October 29, 2022 at 01:22AM by Khryse
via reddit https://ift.tt/CHvnqgG
https://ift.tt/162IzvA
Submitted October 29, 2022 at 01:22AM by Khryse
via reddit https://ift.tt/CHvnqgG
Mat Duggan
Passkeys as a tool for user retention
With the release of iOS 16 and MacOS Ventura, we are now in the age of passkeys. This is happening through WebAuthn, a specification written by the W3C and FIDO with the involvement of all of the major vendors such as Google, Mozilla, etc. The basic premise…
RC4 Is Still Considered Harmful
https://ift.tt/27Jaozx
Submitted October 29, 2022 at 03:43AM by sanitybit
via reddit https://ift.tt/ih5DLpe
https://ift.tt/27Jaozx
Submitted October 29, 2022 at 03:43AM by sanitybit
via reddit https://ift.tt/ih5DLpe
Blogspot
RC4 Is Still Considered Harmful
By James Forshaw, Project Zero I've been spending a lot of time researching Windows authentication implementations, specifically Kerberos. I...
mitmproxy 9: WireGuard Mode and Raw UDP Support
https://ift.tt/XQzgtjN
Submitted October 29, 2022 at 06:19PM by mhils
via reddit https://ift.tt/JPeFUbX
https://ift.tt/XQzgtjN
Submitted October 29, 2022 at 06:19PM by mhils
via reddit https://ift.tt/JPeFUbX
GitHub - Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across all your GitHub assets
https://ift.tt/qUeDjhs
Submitted October 30, 2022 at 01:30AM by roy_6472
via reddit https://ift.tt/WRzi3Y4
https://ift.tt/qUeDjhs
Submitted October 30, 2022 at 01:30AM by roy_6472
via reddit https://ift.tt/WRzi3Y4
GitHub
GitHub - Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets - GitHub - Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across a...
Urgent: Patch OpenSSL on November 1 to avoid “Critical” Security Vulnerability - GlobalSign
https://ift.tt/NwXKhz7
Submitted October 30, 2022 at 04:07AM by c0r0n3r
via reddit https://ift.tt/tgKV3Ni
https://ift.tt/NwXKhz7
Submitted October 30, 2022 at 04:07AM by c0r0n3r
via reddit https://ift.tt/tgKV3Ni
GlobalSign
OpenSSL Release Patches Critical Vulnerability - GlobalSign
A critical vulnerability has been discovered in current versions of OpenSSL and will need to be patched immediately.
The Automated Penetration Testing Reporting System (APTRS). Pentester can easily maintain projects, customers, and vulnerabilities, and create PDF reports without needing to use traditional DOC files. The tool allows you to maintain a vulnerability database, so you won't need to repeat yourself.
https://ift.tt/6DSTFel
Submitted October 30, 2022 at 12:59PM by Ano_F
via reddit https://ift.tt/wIUzWdO
https://ift.tt/6DSTFel
Submitted October 30, 2022 at 12:59PM by Ano_F
via reddit https://ift.tt/wIUzWdO
GitHub
GitHub - APTRS/APTRS: Automated pentest reporting with custom Word templates, project tracking, and client management tools. Streamline…
Automated pentest reporting with custom Word templates, project tracking, and client management tools. Streamline your security workflows effortlessly! - APTRS/APTRS
Watch the Top 50 Security Conferences of 2022
https://ift.tt/EqsV1d2
Submitted October 30, 2022 at 04:23PM by mymalema
via reddit https://ift.tt/WCeif72
https://ift.tt/EqsV1d2
Submitted October 30, 2022 at 04:23PM by mymalema
via reddit https://ift.tt/WCeif72
GitHub
GitHub - TalEliyahu/awesome-cybersecurity-conferences: Watch the latest awesome security talks around the globe
Watch the latest awesome security talks around the globe - GitHub - TalEliyahu/awesome-cybersecurity-conferences: Watch the latest awesome security talks around the globe
Part 3 of Lord Of The Ring0 - Sailing to the land of the user (and debugging the ship)
https://ift.tt/L3wUOHo
Submitted October 30, 2022 at 05:39PM by Idov31
via reddit https://ift.tt/5AK9NJD
https://ift.tt/L3wUOHo
Submitted October 30, 2022 at 05:39PM by Idov31
via reddit https://ift.tt/5AK9NJD
idov31.github.io
Lord Of The Ring0 - Part 3 | Sailing to the land of the user (and debugging the ship) - Ido Veltzman - Security Blog
PrologueIn the last blog post, we understood what it is a callback routine, how to get basic information from user mode and for the finale created a driver t...
Vulnerability and Exploit feeds
https://ift.tt/fco9ldS
Submitted October 31, 2022 at 01:33PM by AnyYak5018
via reddit https://ift.tt/yXSkYvL
https://ift.tt/fco9ldS
Submitted October 31, 2022 at 01:33PM by AnyYak5018
via reddit https://ift.tt/yXSkYvL
Baby steps into MITRE Stix/Taxii, Pandas, Graphs & Jupyter notebooks
https://ift.tt/mT1SwZb
Submitted October 31, 2022 at 01:14PM by DiabloHorn
via reddit https://ift.tt/bPuLfZE
https://ift.tt/mT1SwZb
Submitted October 31, 2022 at 01:14PM by DiabloHorn
via reddit https://ift.tt/bPuLfZE
DiabloHorn
Baby steps into MITRE Stix/Taxii, Pandas, Graphs & Jupyter notebooks
So there I was preparing a presentation with some pretty pictures and then I thought…after I give this presentation: How will the audience play with the data and see for themselves how these …
What I learnt from reading 217 subdomain takeover bug reports.
https://ift.tt/7pqBdVM
Submitted October 31, 2022 at 07:34PM by _nynan
via reddit https://ift.tt/Lp38EmU
https://ift.tt/7pqBdVM
Submitted October 31, 2022 at 07:34PM by _nynan
via reddit https://ift.tt/Lp38EmU
Medium
What I learnt from reading 217* Subdomain Takeover bug reports.
A comprehensive analysis of Subdomain Takeovers (SDTO), DNS Hijacking, Dangling DNS, CNAME misconfigurations…
A technical analysis of Pegasus for Android – Part 3
https://ift.tt/3RFySB1
Submitted October 31, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/6zqX7dZ
https://ift.tt/3RFySB1
Submitted October 31, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/6zqX7dZ
Abusing windows’ tokens to compromise active directory without touching lsass
https://ift.tt/T8LXEQH
Submitted October 31, 2022 at 11:22PM by sanitybit
via reddit https://ift.tt/Tfhql5n
https://ift.tt/T8LXEQH
Submitted October 31, 2022 at 11:22PM by sanitybit
via reddit https://ift.tt/Tfhql5n
Sensepost
SensePost | Abusing windows’ tokens to compromise active directory without touching lsass
Leaders in Information Security
New Microcorruption Challenges - Embedded Hardware Security CTF
https://ift.tt/CaBd2Io
Submitted October 31, 2022 at 11:17PM by sanitybit
via reddit https://ift.tt/jvBHcW2
https://ift.tt/CaBd2Io
Submitted October 31, 2022 at 11:17PM by sanitybit
via reddit https://ift.tt/jvBHcW2
NCC Group Research
Check out our new Microcorruption challenges!
Today we are releasing several new challenges for the embedded security CTF, Microcorruption. These challenges highlight types of vulnerabilities that NCC Group’s Hardware and Embedded Systems practice have discovered in real products. The new challenges…
A tale of a simple Apple kernel bug
https://ift.tt/fybPOeZ
Submitted November 01, 2022 at 12:45AM by JordyZomer
via reddit https://ift.tt/DNg0WXS
https://ift.tt/fybPOeZ
Submitted November 01, 2022 at 12:45AM by JordyZomer
via reddit https://ift.tt/DNg0WXS
pwning.systems
A tale of a simple Apple kernel bug
Earlier this year, I discovered a flaw in XNU, which is the kernel that Apple uses on both macOS and iOS. While it's not a particularly complicated flaw, I wanted to explain how I discovered it and how it works, both so that I can motivate others and so that…