Abusing windows’ tokens to compromise active directory without touching lsass
https://ift.tt/T8LXEQH
Submitted October 31, 2022 at 11:22PM by sanitybit
via reddit https://ift.tt/Tfhql5n
https://ift.tt/T8LXEQH
Submitted October 31, 2022 at 11:22PM by sanitybit
via reddit https://ift.tt/Tfhql5n
Sensepost
SensePost | Abusing windows’ tokens to compromise active directory without touching lsass
Leaders in Information Security
New Microcorruption Challenges - Embedded Hardware Security CTF
https://ift.tt/CaBd2Io
Submitted October 31, 2022 at 11:17PM by sanitybit
via reddit https://ift.tt/jvBHcW2
https://ift.tt/CaBd2Io
Submitted October 31, 2022 at 11:17PM by sanitybit
via reddit https://ift.tt/jvBHcW2
NCC Group Research
Check out our new Microcorruption challenges!
Today we are releasing several new challenges for the embedded security CTF, Microcorruption. These challenges highlight types of vulnerabilities that NCC Group’s Hardware and Embedded Systems practice have discovered in real products. The new challenges…
A tale of a simple Apple kernel bug
https://ift.tt/fybPOeZ
Submitted November 01, 2022 at 12:45AM by JordyZomer
via reddit https://ift.tt/DNg0WXS
https://ift.tt/fybPOeZ
Submitted November 01, 2022 at 12:45AM by JordyZomer
via reddit https://ift.tt/DNg0WXS
pwning.systems
A tale of a simple Apple kernel bug
Earlier this year, I discovered a flaw in XNU, which is the kernel that Apple uses on both macOS and iOS. While it's not a particularly complicated flaw, I wanted to explain how I discovered it and how it works, both so that I can motivate others and so that…
Fugu15 - a semi-untethered permasigned jailbreak for iOS 15
https://ift.tt/Llk1IWA
Submitted November 01, 2022 at 01:39AM by _rs
via reddit https://ift.tt/eaIlHry
https://ift.tt/Llk1IWA
Submitted November 01, 2022 at 01:39AM by _rs
via reddit https://ift.tt/eaIlHry
GitHub
GitHub - pinauten/Fugu15: Fugu15 is a semi-untethered permasigned jailbreak for iOS 15
Fugu15 is a semi-untethered permasigned jailbreak for iOS 15 - GitHub - pinauten/Fugu15: Fugu15 is a semi-untethered permasigned jailbreak for iOS 15
No Hat 2022 Conference Recordings
https://www.youtube.com/playlist?list=PLHAChCRZgm7OIJwo5nse29UvrZu5Ow8Eu
Submitted November 01, 2022 at 03:45AM by Khryse
via reddit https://ift.tt/fpWMdgY
https://www.youtube.com/playlist?list=PLHAChCRZgm7OIJwo5nse29UvrZu5Ow8Eu
Submitted November 01, 2022 at 03:45AM by Khryse
via reddit https://ift.tt/fpWMdgY
YouTube
No Hat 2022 - YouTube
Exploiting Static Site Generators: When Static Is Not Actually Static
https://ift.tt/AseBfqY
Submitted November 01, 2022 at 12:43PM by Mempodipper
via reddit https://ift.tt/f6ljiFQ
https://ift.tt/AseBfqY
Submitted November 01, 2022 at 12:43PM by Mempodipper
via reddit https://ift.tt/f6ljiFQ
Assetnote
Exploiting Static Site Generators: When Static Is Not Actually Static
Application security issues found by Assetnote
List of (un)affected software OpenSSL vulnerability (still being updated)
https://ift.tt/yGNFJBE
Submitted November 01, 2022 at 05:31PM by Triyujin
via reddit https://ift.tt/4GwYUaf
https://ift.tt/yGNFJBE
Submitted November 01, 2022 at 05:31PM by Triyujin
via reddit https://ift.tt/4GwYUaf
GitHub
OpenSSL-2022/software at main · NCSC-NL/OpenSSL-2022
Operational information regarding CVE-2022-3602 and CVE-2022-3786, two vulnerabilities in OpenSSL 3 - NCSC-NL/OpenSSL-2022
OpenSSL Blog Post with FAQs - CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows
https://ift.tt/GHsuc57
Submitted November 01, 2022 at 09:41PM by Gallus
via reddit https://ift.tt/68OTAyo
https://ift.tt/GHsuc57
Submitted November 01, 2022 at 09:41PM by Gallus
via reddit https://ift.tt/68OTAyo
www.openssl.org
CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows - OpenSSL Blog
Today we published an
advisory about CVE-2022-3786
(“X.509 Email Address Variable Length Buffer Overflow”) and
CVE-2022-3602 (“X.509 Email Address 4- …
advisory about CVE-2022-3786
(“X.509 Email Address Variable Length Buffer Overflow”) and
CVE-2022-3602 (“X.509 Email Address 4- …
OpenSSL Security Advisory [01 November 2022] - CVE-2022-3786 CVE-2022-3602
https://ift.tt/VNy7WOM
Submitted November 01, 2022 at 09:37PM by Gallus
via reddit https://ift.tt/QypOUGl
https://ift.tt/VNy7WOM
Submitted November 01, 2022 at 09:37PM by Gallus
via reddit https://ift.tt/QypOUGl
OpenSSL version 3.0.7 published - Fixed two buffer overflows in punycode decoding functions
https://ift.tt/1w8zsrX
Submitted November 01, 2022 at 09:20PM by Gallus
via reddit https://ift.tt/9zkQANG
https://ift.tt/1w8zsrX
Submitted November 01, 2022 at 09:20PM by Gallus
via reddit https://ift.tt/9zkQANG
The OpenSSL punycode vulnerability (CVE-2022-3602): Overview, detection, exploitation, and remediation | Datadog Security Labs
https://ift.tt/I6wP3xF
Submitted November 01, 2022 at 10:27PM by RedTermSession
via reddit https://ift.tt/i82ujZ7
https://ift.tt/I6wP3xF
Submitted November 01, 2022 at 10:27PM by RedTermSession
via reddit https://ift.tt/i82ujZ7
Datadoghq
The OpenSSL punycode vulnerability (CVE-2022-3602): Overview, detection, exploitation, and remediation
Learn how the OpenSSL punycode vulnerability (CVE-2022-3602) works, how to detect it, and how it can be exploited.
Dozens More PyPI Packages Attempting to Deliver W4SP Stealer in Ongoing Supply-Chain Attack
https://ift.tt/QZzwX1n
Submitted November 02, 2022 at 02:50AM by louis11
via reddit https://ift.tt/fWX5bTU
https://ift.tt/QZzwX1n
Submitted November 02, 2022 at 02:50AM by louis11
via reddit https://ift.tt/fWX5bTU
blog.phylum.io
Phylum Discovers Dozens More PyPI Packages Attempting to Deliver W4SP Stealer in Ongoing Supply-Chain Attack
Last week, our automated risk detection platform alerted us to suspicious activity in dozens of newly published PyPI packages. Here's what we uncovered.
Awesome Security Newsletters
https://ift.tt/cfw0Jq6
Submitted November 02, 2022 at 04:30AM by mymalema
via reddit https://ift.tt/X4Ya8gC
https://ift.tt/cfw0Jq6
Submitted November 02, 2022 at 04:30AM by mymalema
via reddit https://ift.tt/X4Ya8gC
GitHub
GitHub - TalEliyahu/awesome-security-newsletters: Periodic cyber security newsletters that capture the latest news, summaries of…
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events, vulnerabilities, and analysis of trending threats and attac...
Symbolic Triage: Making the Best of a Good Situation — Atredis Partners
https://ift.tt/yCmH0xh
Submitted November 02, 2022 at 11:25AM by jeandrew
via reddit https://ift.tt/q4IiHRx
https://ift.tt/yCmH0xh
Submitted November 02, 2022 at 11:25AM by jeandrew
via reddit https://ift.tt/q4IiHRx
Atredis Partners
Symbolic Triage: Making the Best of a Good Situation — Atredis Partners
Symbolic Execution can get a bad rap. Generic symbex tools have a hard time proving their worth when confronted with a sufficiently complex target. However, I have found symbolic execution can be very helpful in certain targeted situations. One of those situations…
urlscan.io's SOAR spot: Chatty security tools leaking private data
https://ift.tt/RhEwyAP
Submitted November 02, 2022 at 06:28PM by mckirk_
via reddit https://ift.tt/DQob6uY
https://ift.tt/RhEwyAP
Submitted November 02, 2022 at 06:28PM by mckirk_
via reddit https://ift.tt/DQob6uY
positive.security
urlscan.io's SOAR spot: Chatty security tools leaking private data | Positive Security
We explore the security service urlscan.io and showcase through various "dorks" that their searchable scan database is a treasure trove of URLs pointing to sensitive user information, allowing account takeover, and much more. Part of the data has been leaked…
Steampipe: Getting Started. Using AWS, Github and Docker plugins
https://ift.tt/7BDKwuL
Submitted November 03, 2022 at 02:41AM by stevecio
via reddit https://ift.tt/swcVAne
https://ift.tt/7BDKwuL
Submitted November 03, 2022 at 02:41AM by stevecio
via reddit https://ift.tt/swcVAne
Anusha's Blog
Steampipe: Getting Started
About Steampipe
Steampipe organizes your cloud metadata into tables and fields that are easily discoverable and readable.
It is the universal interface to APIs. You can SQL to query cloud infrastructure, SaaS, code, logs, and more.
Painlessly joi...
Steampipe organizes your cloud metadata into tables and fields that are easily discoverable and readable.
It is the universal interface to APIs. You can SQL to query cloud infrastructure, SaaS, code, logs, and more.
Painlessly joi...
Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)
https://ift.tt/YjmBtZh
Submitted November 03, 2022 at 04:20AM by monoimpact
via reddit https://ift.tt/f2q4xXm
https://ift.tt/YjmBtZh
Submitted November 03, 2022 at 04:20AM by monoimpact
via reddit https://ift.tt/f2q4xXm
Sonarsource
Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)
We discovered multiple vulnerabilities in Checkmk, which can be chained together by an unauthenticated, remote attacker to fully take over a vulnerable server.
Gregor Samsa: Exploiting Java's XML Signature Verification
https://ift.tt/9U5IiPm
Submitted November 03, 2022 at 12:56AM by jp_bennett
via reddit https://ift.tt/8eFpfZH
https://ift.tt/9U5IiPm
Submitted November 03, 2022 at 12:56AM by jp_bennett
via reddit https://ift.tt/8eFpfZH
Blogspot
Gregor Samsa: Exploiting Java's XML Signature Verification
By Felix Wilhelm, Project Zero Earlier this year, I discovered a surprising attack surface hidden deep inside Java’s standard library: A cus...
CVE-2022-3602 & CVE-2022-3786 - OSS tools to detect susceptibility to the recent OpenSSL issues
https://ift.tt/gtL5fuj
Submitted November 03, 2022 at 04:38PM by SRMish3
via reddit https://ift.tt/6aDfjy2
https://ift.tt/gtL5fuj
Submitted November 03, 2022 at 04:38PM by SRMish3
via reddit https://ift.tt/6aDfjy2
GitHub
GitHub - jfrog/jfrog-openssl-tools
Contribute to jfrog/jfrog-openssl-tools development by creating an account on GitHub.
The below-OS for supply chain of critical infrastructure protection
https://ift.tt/tlLoy1F
Submitted November 03, 2022 at 08:17PM by hardenedvault
via reddit https://ift.tt/w4p3FE9
https://ift.tt/tlLoy1F
Submitted November 03, 2022 at 08:17PM by hardenedvault
via reddit https://ift.tt/w4p3FE9
hardenedvault.net
The below-OS for supply chain of critical infrastructure protection
Background The endless cyber “war” in the levels of OS
Threat Model Examples
https://ift.tt/T2NcRM4
Submitted November 03, 2022 at 10:26PM by hipver
via reddit https://ift.tt/jsNxMmP
https://ift.tt/T2NcRM4
Submitted November 03, 2022 at 10:26PM by hipver
via reddit https://ift.tt/jsNxMmP
GitHub
GitHub - TalEliyahu/Threat_Model_Examples: A collection of real-world threat model examples across various technologies, providing…
A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security risks. - GitHub - TalEliyahu/Threat_Model_Exampl...