urlscan.io's SOAR spot: Chatty security tools leaking private data
https://ift.tt/RhEwyAP
Submitted November 02, 2022 at 06:28PM by mckirk_
via reddit https://ift.tt/DQob6uY
https://ift.tt/RhEwyAP
Submitted November 02, 2022 at 06:28PM by mckirk_
via reddit https://ift.tt/DQob6uY
positive.security
urlscan.io's SOAR spot: Chatty security tools leaking private data | Positive Security
We explore the security service urlscan.io and showcase through various "dorks" that their searchable scan database is a treasure trove of URLs pointing to sensitive user information, allowing account takeover, and much more. Part of the data has been leaked…
Steampipe: Getting Started. Using AWS, Github and Docker plugins
https://ift.tt/7BDKwuL
Submitted November 03, 2022 at 02:41AM by stevecio
via reddit https://ift.tt/swcVAne
https://ift.tt/7BDKwuL
Submitted November 03, 2022 at 02:41AM by stevecio
via reddit https://ift.tt/swcVAne
Anusha's Blog
Steampipe: Getting Started
About Steampipe
Steampipe organizes your cloud metadata into tables and fields that are easily discoverable and readable.
It is the universal interface to APIs. You can SQL to query cloud infrastructure, SaaS, code, logs, and more.
Painlessly joi...
Steampipe organizes your cloud metadata into tables and fields that are easily discoverable and readable.
It is the universal interface to APIs. You can SQL to query cloud infrastructure, SaaS, code, logs, and more.
Painlessly joi...
Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)
https://ift.tt/YjmBtZh
Submitted November 03, 2022 at 04:20AM by monoimpact
via reddit https://ift.tt/f2q4xXm
https://ift.tt/YjmBtZh
Submitted November 03, 2022 at 04:20AM by monoimpact
via reddit https://ift.tt/f2q4xXm
Sonarsource
Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)
We discovered multiple vulnerabilities in Checkmk, which can be chained together by an unauthenticated, remote attacker to fully take over a vulnerable server.
Gregor Samsa: Exploiting Java's XML Signature Verification
https://ift.tt/9U5IiPm
Submitted November 03, 2022 at 12:56AM by jp_bennett
via reddit https://ift.tt/8eFpfZH
https://ift.tt/9U5IiPm
Submitted November 03, 2022 at 12:56AM by jp_bennett
via reddit https://ift.tt/8eFpfZH
Blogspot
Gregor Samsa: Exploiting Java's XML Signature Verification
By Felix Wilhelm, Project Zero Earlier this year, I discovered a surprising attack surface hidden deep inside Java’s standard library: A cus...
CVE-2022-3602 & CVE-2022-3786 - OSS tools to detect susceptibility to the recent OpenSSL issues
https://ift.tt/gtL5fuj
Submitted November 03, 2022 at 04:38PM by SRMish3
via reddit https://ift.tt/6aDfjy2
https://ift.tt/gtL5fuj
Submitted November 03, 2022 at 04:38PM by SRMish3
via reddit https://ift.tt/6aDfjy2
GitHub
GitHub - jfrog/jfrog-openssl-tools
Contribute to jfrog/jfrog-openssl-tools development by creating an account on GitHub.
The below-OS for supply chain of critical infrastructure protection
https://ift.tt/tlLoy1F
Submitted November 03, 2022 at 08:17PM by hardenedvault
via reddit https://ift.tt/w4p3FE9
https://ift.tt/tlLoy1F
Submitted November 03, 2022 at 08:17PM by hardenedvault
via reddit https://ift.tt/w4p3FE9
hardenedvault.net
The below-OS for supply chain of critical infrastructure protection
Background The endless cyber “war” in the levels of OS
Threat Model Examples
https://ift.tt/T2NcRM4
Submitted November 03, 2022 at 10:26PM by hipver
via reddit https://ift.tt/jsNxMmP
https://ift.tt/T2NcRM4
Submitted November 03, 2022 at 10:26PM by hipver
via reddit https://ift.tt/jsNxMmP
GitHub
GitHub - TalEliyahu/Threat_Model_Examples: A collection of real-world threat model examples across various technologies, providing…
A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security risks. - GitHub - TalEliyahu/Threat_Model_Exampl...
Release Ghidra 10.2 · NationalSecurityAgency/ghidra
https://ift.tt/sXFcBiC
Submitted November 04, 2022 at 04:22AM by mumbel
via reddit https://ift.tt/Jj2RqXi
https://ift.tt/sXFcBiC
Submitted November 04, 2022 at 04:22AM by mumbel
via reddit https://ift.tt/Jj2RqXi
GitHub
Release Ghidra 10.2 · NationalSecurityAgency/ghidra
What's New
Change History
Installation Guide
SHA-256: a5163f50bd6ce725c4c8638f7505b64bb603ea6bfe3f7d9ed4e403236716f787
Change History
Installation Guide
SHA-256: a5163f50bd6ce725c4c8638f7505b64bb603ea6bfe3f7d9ed4e403236716f787
Why Did the OpenSSL Punycode Vulnerability Happen
https://ift.tt/ZsmyX5b
Submitted November 04, 2022 at 03:56AM by ScottContini
via reddit https://ift.tt/rRFhUYL
https://ift.tt/ZsmyX5b
Submitted November 04, 2022 at 03:56AM by ScottContini
via reddit https://ift.tt/rRFhUYL
Filippo Valsorda
Why Did the OpenSSL Punycode Vulnerability Happen
We look at how fuzzing should have caught the OpenSSL Punycode vulnerability, and why that code was even necessary in the first place.
CVE-2022-33679 Windows Kerberos Elevation of Privilege
https://ift.tt/4MT2ReV
Submitted November 04, 2022 at 10:56AM by smokiesmk
via reddit https://ift.tt/trU2OJy
https://ift.tt/4MT2ReV
Submitted November 04, 2022 at 10:56AM by smokiesmk
via reddit https://ift.tt/trU2OJy
GitHub
GitHub - Bdenneu/CVE-2022-33679: One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html - GitHub - Bdenneu/CVE-2022-33679: One day based on https://googleprojectzero.blogspot.com/2022/...
MI-X - Determine whether your compute is truly vulnerable to a specific vulnerability
https://ift.tt/Ii4v85V
Submitted November 04, 2022 at 12:24PM by boutnaru
via reddit https://ift.tt/Kjku6qP
https://ift.tt/Ii4v85V
Submitted November 04, 2022 at 12:24PM by boutnaru
via reddit https://ift.tt/Kjku6qP
GitHub
GitHub - Rezilion/mi-x: Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors…
Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability (runtime execution, configuration, permissions, exi...
Reverse Branch Target Buffer Poisoning - new ASLR bypass technique using CPU vulnerabilities [PDF]
https://ift.tt/FT5QCRV
Submitted November 04, 2022 at 01:11PM by Gallus
via reddit https://ift.tt/4Y73XT0
https://ift.tt/FT5QCRV
Submitted November 04, 2022 at 01:11PM by Gallus
via reddit https://ift.tt/4Y73XT0
The Android Malware's Journey: From Google Play to banking fraud | Cleafy Labs
https://ift.tt/HsI4Chy
Submitted November 04, 2022 at 07:07PM by f3d_0x0
via reddit https://ift.tt/dznexTj
https://ift.tt/HsI4Chy
Submitted November 04, 2022 at 07:07PM by f3d_0x0
via reddit https://ift.tt/dznexTj
Cleafy
The Android Malware’s Journey: From Google Play to banking fraud | Cleafy Labs
The threat intelligence team of Cleafy analyzed the Android Malware Vultur and its journey from Google Play to banking fraud. Read here the technical analysis.
HRDevHelper - Decompiler Plugin for Hex-Rays by Dennis Elser
https://ift.tt/opTJkz9
Submitted November 05, 2022 at 06:03AM by Gallus
via reddit https://ift.tt/9oUCV7x
https://ift.tt/opTJkz9
Submitted November 05, 2022 at 06:03AM by Gallus
via reddit https://ift.tt/9oUCV7x
AWS Organizations Defaults - Hacking The Cloud
https://ift.tt/a4PzHNM
Submitted November 05, 2022 at 05:52AM by RedTermSession
via reddit https://ift.tt/Xfcv0UK
https://ift.tt/a4PzHNM
Submitted November 05, 2022 at 05:52AM by RedTermSession
via reddit https://ift.tt/Xfcv0UK
hackingthe.cloud
AWS Organizations Defaults - Hacking The Cloud
AWS Organizations is a common service to run into in AWS environments. It's default behavior can make it a target for attackers.
ThinkstScapes Quarterly | 2022.Q3 | Summary of a lot of conference talks
https://thinkst.com/ts
Submitted November 07, 2022 at 03:11AM by ffyns
via reddit https://ift.tt/apozVB0
https://thinkst.com/ts
Submitted November 07, 2022 at 03:11AM by ffyns
via reddit https://ift.tt/apozVB0
Thinkst
ThinkstScapes
Keeping up with security research is near impossible. ThinkstScapes helps with this. We scour through thousands of blog posts, tweets and conference proceedings to give you an overview of the work we think significantly moves the needle.
drgn - a debugger with an emphasis on programmability
https://ift.tt/bowKV34
Submitted November 07, 2022 at 08:35AM by Gallus
via reddit https://ift.tt/odNbkiJ
https://ift.tt/bowKV34
Submitted November 07, 2022 at 08:35AM by Gallus
via reddit https://ift.tt/odNbkiJ
GitHub
GitHub - osandov/drgn: Programmable debugger
Programmable debugger. Contribute to osandov/drgn development by creating an account on GitHub.
Malicious Python Packages Replace Crypto Addresses in Developer Clipboards
https://ift.tt/x3OQJiz
Submitted November 07, 2022 at 11:26AM by louis11
via reddit https://ift.tt/4HXatdw
https://ift.tt/x3OQJiz
Submitted November 07, 2022 at 11:26AM by louis11
via reddit https://ift.tt/4HXatdw
blog.phylum.io
Malicious Python Packages Replace Crypto Addresses in Developer Clipboards
Phylum uncovers a new campaign targeting Python developers. Malware authors surreptitiously replace cryptocurrency addresses in developer clipboards.
Awesome CISO Maturity Models
https://ift.tt/vsLncbt
Submitted November 07, 2022 at 11:42PM by hipver
via reddit https://ift.tt/tPH30TR
https://ift.tt/vsLncbt
Submitted November 07, 2022 at 11:42PM by hipver
via reddit https://ift.tt/tPH30TR
GitHub
GitHub - TalEliyahu/awesome-CISO-maturity-models: Maturity models help integrate traditionally separate organizational functions…
Maturity models help integrate traditionally separate organizational functions, set process improvement goals and priorities, provide guidance for quality processes, and provide benchmark for appra...
Substation: data pipeline and transformation toolkit for security teams
https://ift.tt/JxdvleD
Submitted November 07, 2022 at 09:06PM by jshlbrd-brex
via reddit https://ift.tt/Rl15Scr
https://ift.tt/JxdvleD
Submitted November 07, 2022 at 09:06PM by jshlbrd-brex
via reddit https://ift.tt/Rl15Scr
GitHub
GitHub - brexhq/substation: Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.
Substation is a toolkit for routing, normalizing, and enriching security event and audit logs. - brexhq/substation
We’re Christian Mouchet, Jean-Philippe Bossuat, Kurt Rohloff, Nigel Smart, Pascal Paillier, Rand Hindi, Wonkyung Jung, various researchers and library developers of homomorphic encryption to answer questions about homomorphic encryption and why it’s important for the future of data privacy! AMA
https://ift.tt/wCZUocq
Submitted November 08, 2022 at 06:17AM by carrotcypher
via reddit https://ift.tt/gzFN35a
https://ift.tt/wCZUocq
Submitted November 08, 2022 at 06:17AM by carrotcypher
via reddit https://ift.tt/gzFN35a
Reddit
r/privacy on Reddit: We’re Christian Mouchet, Jean-Philippe Bossuat, Kurt Rohloff, Nigel Smart, Pascal Paillier, Rand Hindi, Wonkyung…
Posted by u/carrotcypher - 372 votes and 241 comments