Vulnerability and Exploit feeds
https://ift.tt/fco9ldS
Submitted October 31, 2022 at 01:33PM by AnyYak5018
via reddit https://ift.tt/yXSkYvL
https://ift.tt/fco9ldS
Submitted October 31, 2022 at 01:33PM by AnyYak5018
via reddit https://ift.tt/yXSkYvL
Baby steps into MITRE Stix/Taxii, Pandas, Graphs & Jupyter notebooks
https://ift.tt/mT1SwZb
Submitted October 31, 2022 at 01:14PM by DiabloHorn
via reddit https://ift.tt/bPuLfZE
https://ift.tt/mT1SwZb
Submitted October 31, 2022 at 01:14PM by DiabloHorn
via reddit https://ift.tt/bPuLfZE
DiabloHorn
Baby steps into MITRE Stix/Taxii, Pandas, Graphs & Jupyter notebooks
So there I was preparing a presentation with some pretty pictures and then I thought…after I give this presentation: How will the audience play with the data and see for themselves how these …
What I learnt from reading 217 subdomain takeover bug reports.
https://ift.tt/7pqBdVM
Submitted October 31, 2022 at 07:34PM by _nynan
via reddit https://ift.tt/Lp38EmU
https://ift.tt/7pqBdVM
Submitted October 31, 2022 at 07:34PM by _nynan
via reddit https://ift.tt/Lp38EmU
Medium
What I learnt from reading 217* Subdomain Takeover bug reports.
A comprehensive analysis of Subdomain Takeovers (SDTO), DNS Hijacking, Dangling DNS, CNAME misconfigurations…
A technical analysis of Pegasus for Android – Part 3
https://ift.tt/3RFySB1
Submitted October 31, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/6zqX7dZ
https://ift.tt/3RFySB1
Submitted October 31, 2022 at 07:32PM by CyberMasterV
via reddit https://ift.tt/6zqX7dZ
Abusing windows’ tokens to compromise active directory without touching lsass
https://ift.tt/T8LXEQH
Submitted October 31, 2022 at 11:22PM by sanitybit
via reddit https://ift.tt/Tfhql5n
https://ift.tt/T8LXEQH
Submitted October 31, 2022 at 11:22PM by sanitybit
via reddit https://ift.tt/Tfhql5n
Sensepost
SensePost | Abusing windows’ tokens to compromise active directory without touching lsass
Leaders in Information Security
New Microcorruption Challenges - Embedded Hardware Security CTF
https://ift.tt/CaBd2Io
Submitted October 31, 2022 at 11:17PM by sanitybit
via reddit https://ift.tt/jvBHcW2
https://ift.tt/CaBd2Io
Submitted October 31, 2022 at 11:17PM by sanitybit
via reddit https://ift.tt/jvBHcW2
NCC Group Research
Check out our new Microcorruption challenges!
Today we are releasing several new challenges for the embedded security CTF, Microcorruption. These challenges highlight types of vulnerabilities that NCC Group’s Hardware and Embedded Systems practice have discovered in real products. The new challenges…
A tale of a simple Apple kernel bug
https://ift.tt/fybPOeZ
Submitted November 01, 2022 at 12:45AM by JordyZomer
via reddit https://ift.tt/DNg0WXS
https://ift.tt/fybPOeZ
Submitted November 01, 2022 at 12:45AM by JordyZomer
via reddit https://ift.tt/DNg0WXS
pwning.systems
A tale of a simple Apple kernel bug
Earlier this year, I discovered a flaw in XNU, which is the kernel that Apple uses on both macOS and iOS. While it's not a particularly complicated flaw, I wanted to explain how I discovered it and how it works, both so that I can motivate others and so that…
Fugu15 - a semi-untethered permasigned jailbreak for iOS 15
https://ift.tt/Llk1IWA
Submitted November 01, 2022 at 01:39AM by _rs
via reddit https://ift.tt/eaIlHry
https://ift.tt/Llk1IWA
Submitted November 01, 2022 at 01:39AM by _rs
via reddit https://ift.tt/eaIlHry
GitHub
GitHub - pinauten/Fugu15: Fugu15 is a semi-untethered permasigned jailbreak for iOS 15
Fugu15 is a semi-untethered permasigned jailbreak for iOS 15 - GitHub - pinauten/Fugu15: Fugu15 is a semi-untethered permasigned jailbreak for iOS 15
No Hat 2022 Conference Recordings
https://www.youtube.com/playlist?list=PLHAChCRZgm7OIJwo5nse29UvrZu5Ow8Eu
Submitted November 01, 2022 at 03:45AM by Khryse
via reddit https://ift.tt/fpWMdgY
https://www.youtube.com/playlist?list=PLHAChCRZgm7OIJwo5nse29UvrZu5Ow8Eu
Submitted November 01, 2022 at 03:45AM by Khryse
via reddit https://ift.tt/fpWMdgY
YouTube
No Hat 2022 - YouTube
Exploiting Static Site Generators: When Static Is Not Actually Static
https://ift.tt/AseBfqY
Submitted November 01, 2022 at 12:43PM by Mempodipper
via reddit https://ift.tt/f6ljiFQ
https://ift.tt/AseBfqY
Submitted November 01, 2022 at 12:43PM by Mempodipper
via reddit https://ift.tt/f6ljiFQ
Assetnote
Exploiting Static Site Generators: When Static Is Not Actually Static
Application security issues found by Assetnote
List of (un)affected software OpenSSL vulnerability (still being updated)
https://ift.tt/yGNFJBE
Submitted November 01, 2022 at 05:31PM by Triyujin
via reddit https://ift.tt/4GwYUaf
https://ift.tt/yGNFJBE
Submitted November 01, 2022 at 05:31PM by Triyujin
via reddit https://ift.tt/4GwYUaf
GitHub
OpenSSL-2022/software at main · NCSC-NL/OpenSSL-2022
Operational information regarding CVE-2022-3602 and CVE-2022-3786, two vulnerabilities in OpenSSL 3 - NCSC-NL/OpenSSL-2022
OpenSSL Blog Post with FAQs - CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows
https://ift.tt/GHsuc57
Submitted November 01, 2022 at 09:41PM by Gallus
via reddit https://ift.tt/68OTAyo
https://ift.tt/GHsuc57
Submitted November 01, 2022 at 09:41PM by Gallus
via reddit https://ift.tt/68OTAyo
www.openssl.org
CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows - OpenSSL Blog
Today we published an
advisory about CVE-2022-3786
(“X.509 Email Address Variable Length Buffer Overflow”) and
CVE-2022-3602 (“X.509 Email Address 4- …
advisory about CVE-2022-3786
(“X.509 Email Address Variable Length Buffer Overflow”) and
CVE-2022-3602 (“X.509 Email Address 4- …
OpenSSL Security Advisory [01 November 2022] - CVE-2022-3786 CVE-2022-3602
https://ift.tt/VNy7WOM
Submitted November 01, 2022 at 09:37PM by Gallus
via reddit https://ift.tt/QypOUGl
https://ift.tt/VNy7WOM
Submitted November 01, 2022 at 09:37PM by Gallus
via reddit https://ift.tt/QypOUGl
OpenSSL version 3.0.7 published - Fixed two buffer overflows in punycode decoding functions
https://ift.tt/1w8zsrX
Submitted November 01, 2022 at 09:20PM by Gallus
via reddit https://ift.tt/9zkQANG
https://ift.tt/1w8zsrX
Submitted November 01, 2022 at 09:20PM by Gallus
via reddit https://ift.tt/9zkQANG
The OpenSSL punycode vulnerability (CVE-2022-3602): Overview, detection, exploitation, and remediation | Datadog Security Labs
https://ift.tt/I6wP3xF
Submitted November 01, 2022 at 10:27PM by RedTermSession
via reddit https://ift.tt/i82ujZ7
https://ift.tt/I6wP3xF
Submitted November 01, 2022 at 10:27PM by RedTermSession
via reddit https://ift.tt/i82ujZ7
Datadoghq
The OpenSSL punycode vulnerability (CVE-2022-3602): Overview, detection, exploitation, and remediation
Learn how the OpenSSL punycode vulnerability (CVE-2022-3602) works, how to detect it, and how it can be exploited.
Dozens More PyPI Packages Attempting to Deliver W4SP Stealer in Ongoing Supply-Chain Attack
https://ift.tt/QZzwX1n
Submitted November 02, 2022 at 02:50AM by louis11
via reddit https://ift.tt/fWX5bTU
https://ift.tt/QZzwX1n
Submitted November 02, 2022 at 02:50AM by louis11
via reddit https://ift.tt/fWX5bTU
blog.phylum.io
Phylum Discovers Dozens More PyPI Packages Attempting to Deliver W4SP Stealer in Ongoing Supply-Chain Attack
Last week, our automated risk detection platform alerted us to suspicious activity in dozens of newly published PyPI packages. Here's what we uncovered.
Awesome Security Newsletters
https://ift.tt/cfw0Jq6
Submitted November 02, 2022 at 04:30AM by mymalema
via reddit https://ift.tt/X4Ya8gC
https://ift.tt/cfw0Jq6
Submitted November 02, 2022 at 04:30AM by mymalema
via reddit https://ift.tt/X4Ya8gC
GitHub
GitHub - TalEliyahu/awesome-security-newsletters: Periodic cyber security newsletters that capture the latest news, summaries of…
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events, vulnerabilities, and analysis of trending threats and attac...
Symbolic Triage: Making the Best of a Good Situation — Atredis Partners
https://ift.tt/yCmH0xh
Submitted November 02, 2022 at 11:25AM by jeandrew
via reddit https://ift.tt/q4IiHRx
https://ift.tt/yCmH0xh
Submitted November 02, 2022 at 11:25AM by jeandrew
via reddit https://ift.tt/q4IiHRx
Atredis Partners
Symbolic Triage: Making the Best of a Good Situation — Atredis Partners
Symbolic Execution can get a bad rap. Generic symbex tools have a hard time proving their worth when confronted with a sufficiently complex target. However, I have found symbolic execution can be very helpful in certain targeted situations. One of those situations…
urlscan.io's SOAR spot: Chatty security tools leaking private data
https://ift.tt/RhEwyAP
Submitted November 02, 2022 at 06:28PM by mckirk_
via reddit https://ift.tt/DQob6uY
https://ift.tt/RhEwyAP
Submitted November 02, 2022 at 06:28PM by mckirk_
via reddit https://ift.tt/DQob6uY
positive.security
urlscan.io's SOAR spot: Chatty security tools leaking private data | Positive Security
We explore the security service urlscan.io and showcase through various "dorks" that their searchable scan database is a treasure trove of URLs pointing to sensitive user information, allowing account takeover, and much more. Part of the data has been leaked…
Steampipe: Getting Started. Using AWS, Github and Docker plugins
https://ift.tt/7BDKwuL
Submitted November 03, 2022 at 02:41AM by stevecio
via reddit https://ift.tt/swcVAne
https://ift.tt/7BDKwuL
Submitted November 03, 2022 at 02:41AM by stevecio
via reddit https://ift.tt/swcVAne
Anusha's Blog
Steampipe: Getting Started
About Steampipe
Steampipe organizes your cloud metadata into tables and fields that are easily discoverable and readable.
It is the universal interface to APIs. You can SQL to query cloud infrastructure, SaaS, code, logs, and more.
Painlessly joi...
Steampipe organizes your cloud metadata into tables and fields that are easily discoverable and readable.
It is the universal interface to APIs. You can SQL to query cloud infrastructure, SaaS, code, logs, and more.
Painlessly joi...
Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)
https://ift.tt/YjmBtZh
Submitted November 03, 2022 at 04:20AM by monoimpact
via reddit https://ift.tt/f2q4xXm
https://ift.tt/YjmBtZh
Submitted November 03, 2022 at 04:20AM by monoimpact
via reddit https://ift.tt/f2q4xXm
Sonarsource
Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)
We discovered multiple vulnerabilities in Checkmk, which can be chained together by an unauthenticated, remote attacker to fully take over a vulnerable server.