Awesome CISO Maturity Models
https://ift.tt/vsLncbt
Submitted November 07, 2022 at 11:42PM by hipver
via reddit https://ift.tt/tPH30TR
https://ift.tt/vsLncbt
Submitted November 07, 2022 at 11:42PM by hipver
via reddit https://ift.tt/tPH30TR
GitHub
GitHub - TalEliyahu/awesome-CISO-maturity-models: Maturity models help integrate traditionally separate organizational functions…
Maturity models help integrate traditionally separate organizational functions, set process improvement goals and priorities, provide guidance for quality processes, and provide benchmark for appra...
Substation: data pipeline and transformation toolkit for security teams
https://ift.tt/JxdvleD
Submitted November 07, 2022 at 09:06PM by jshlbrd-brex
via reddit https://ift.tt/Rl15Scr
https://ift.tt/JxdvleD
Submitted November 07, 2022 at 09:06PM by jshlbrd-brex
via reddit https://ift.tt/Rl15Scr
GitHub
GitHub - brexhq/substation: Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.
Substation is a toolkit for routing, normalizing, and enriching security event and audit logs. - brexhq/substation
We’re Christian Mouchet, Jean-Philippe Bossuat, Kurt Rohloff, Nigel Smart, Pascal Paillier, Rand Hindi, Wonkyung Jung, various researchers and library developers of homomorphic encryption to answer questions about homomorphic encryption and why it’s important for the future of data privacy! AMA
https://ift.tt/wCZUocq
Submitted November 08, 2022 at 06:17AM by carrotcypher
via reddit https://ift.tt/gzFN35a
https://ift.tt/wCZUocq
Submitted November 08, 2022 at 06:17AM by carrotcypher
via reddit https://ift.tt/gzFN35a
Reddit
r/privacy on Reddit: We’re Christian Mouchet, Jean-Philippe Bossuat, Kurt Rohloff, Nigel Smart, Pascal Paillier, Rand Hindi, Wonkyung…
Posted by u/carrotcypher - 372 votes and 241 comments
DefCon 30: Exploitation in the era of formal verification [video]
https://www.youtube.com/watch?v=TcIaZ9LW1WE
Submitted November 08, 2022 at 10:51AM by Adam_pi3
via reddit https://ift.tt/7MLmV0y
https://www.youtube.com/watch?v=TcIaZ9LW1WE
Submitted November 08, 2022 at 10:51AM by Adam_pi3
via reddit https://ift.tt/7MLmV0y
YouTube
DEF CON 30 - Adam Zabrocki, Alex Tereshkin - Exploitation in the era of Formal Verification
For decades, software vulnerabilities have remained an unsolvable security problem regardless of years of investment in various mitigations, hardening and fuzzing strategies. In the last years there have been moves to formal methods as a path toward better…
Shennina Framework - Automating Host Exploitation with AI
https://ift.tt/q2UX1lv
Submitted November 08, 2022 at 02:42PM by mazen160
via reddit https://ift.tt/PhEcFwe
https://ift.tt/q2UX1lv
Submitted November 08, 2022 at 02:42PM by mazen160
via reddit https://ift.tt/PhEcFwe
Mazin Ahmed
Shennina Framework - Automating Host Exploitation with AI
Shennina Framework - Automating Host Exploitation with AI.
We sign code now | Trail of Bits Blog
https://ift.tt/v4bUZOH
Submitted November 08, 2022 at 06:42PM by D4r1
via reddit https://ift.tt/itR5rJu
https://ift.tt/v4bUZOH
Submitted November 08, 2022 at 06:42PM by D4r1
via reddit https://ift.tt/itR5rJu
The Trail of Bits Blog
We sign code now
Sigstore announced the general availability of its free and ecosystem-agnostic software signing service two weeks ago, giving developers a way to sign, verify and protect their software projects and the dependencies they rely on. Trail of Bits is absolutely…
Jit-Picking: Differential Fuzzing of JavaScript Engines [PDF]
https://ift.tt/KuArbdB
Submitted November 08, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/PzxNWB7
https://ift.tt/KuArbdB
Submitted November 08, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/PzxNWB7
New updated IceXLoader claims thousands of victims around the world
https://ift.tt/TF720oe
Submitted November 08, 2022 at 08:04PM by woja111
via reddit https://ift.tt/kLjKVc9
https://ift.tt/TF720oe
Submitted November 08, 2022 at 08:04PM by woja111
via reddit https://ift.tt/kLjKVc9
Minerva Labs
New updated IceXLoader claims thousands of victims around the world - Minerva Labs
This commercial malware is used to download and deploy additional malware and ransomware on infected machines. We analyzed the latest version
#ShortAndMalicious: StrelaStealer aims for mail credentials
https://ift.tt/6BZviQy
Submitted November 08, 2022 at 07:52PM by OwnPreparation3424
via reddit https://ift.tt/BjDdZQ7
https://ift.tt/6BZviQy
Submitted November 08, 2022 at 07:52PM by OwnPreparation3424
via reddit https://ift.tt/BjDdZQ7
Medium
#ShortAndMalicious: StrelaStealer aims for mail credentials
Quick look at a new stealer utilizing polyglot files
Research on Flow Computers Used in Oil and Gas
https://ift.tt/pwYiejN
Submitted November 08, 2022 at 10:30PM by derp6996
via reddit https://ift.tt/9v1y3xW
https://ift.tt/pwYiejN
Submitted November 08, 2022 at 10:30PM by derp6996
via reddit https://ift.tt/9v1y3xW
Claroty
An Oil and Gas Weak Spot: Flow Computers
How to deal with ransomware on Azure
https://ift.tt/N7DuT41
Submitted November 08, 2022 at 11:08PM by MiguelHzBz
via reddit https://ift.tt/ziESCYV
https://ift.tt/N7DuT41
Submitted November 08, 2022 at 11:08PM by MiguelHzBz
via reddit https://ift.tt/ziESCYV
Sysdig
How to deal with ransomware on Azure – Sysdig
Dig deeper into the techniques used by attackers and the mitigations you should implement when ransomware on Azure affects you.
SimpleX Chat: security assessment by Trail of Bits and v4.2 released
https://ift.tt/4mkz87H
Submitted November 08, 2022 at 11:58PM by epoberezkin
via reddit https://ift.tt/CfMkvY9
https://ift.tt/4mkz87H
Submitted November 08, 2022 at 11:58PM by epoberezkin
via reddit https://ift.tt/CfMkvY9
simplex.chat
Security assessment by Trail of Bits, the new website and v4.2 released
SpyGuard:: a forked and enhanced version of TinyCheck. The main objective is to detect signs of compromise by monitoring network flows transmitted by a device.
https://ift.tt/BZv16ST
Submitted November 08, 2022 at 10:49PM by lugh
via reddit https://ift.tt/jPeFum2
https://ift.tt/BZv16ST
Submitted November 08, 2022 at 10:49PM by lugh
via reddit https://ift.tt/jPeFum2
GitHub
GitHub - SpyGuard/SpyGuard: SpyGuard is a forked and enhanced version of TinyCheck. SpyGuard's main objective is to detect signs…
SpyGuard is a forked and enhanced version of TinyCheck. SpyGuard's main objective is to detect signs of compromise by monitoring network flows transmitted by a device. - SpyGuard/SpyGuard
Vulnerabilities in Tenda's W15Ev2 AC1200 Router
https://ift.tt/ZmLrwvM
Submitted November 08, 2022 at 10:57PM by WiseTuna
via reddit https://ift.tt/6FLXR7T
https://ift.tt/ZmLrwvM
Submitted November 08, 2022 at 10:57PM by WiseTuna
via reddit https://ift.tt/6FLXR7T
Boschko Security Blog
Vulnerabilities in Tenda's W15Ev2 AC1200 Router
CVE-2022-40843 CVE-2022-40845 CVE-2022-40847 CVE-2022-40844 CVE-2022-40846 CVE-2022-41395 CVE-2022-41396 CVE-2022-42053 CVE-2022-42058 CVE-2022-42060
Compromising Plesk via its REST API
https://ift.tt/8rfg0lb
Submitted November 09, 2022 at 01:46PM by adrian_rt
via reddit https://ift.tt/AaBH8Md
https://ift.tt/8rfg0lb
Submitted November 09, 2022 at 01:46PM by adrian_rt
via reddit https://ift.tt/AaBH8Md
Cyber Security Services - London
Compromising Plesk via its REST API
Compromising Plesk via its REST API, CSRF, CORS misconfiguration, add db user, add backdoor, add secret token, cookieless CSRF
Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)
https://ift.tt/ChvIry9
Submitted November 09, 2022 at 02:19PM by CyberMasterV
via reddit https://ift.tt/b52dpSw
https://ift.tt/ChvIry9
Submitted November 09, 2022 at 02:19PM by CyberMasterV
via reddit https://ift.tt/b52dpSw
BREAKDEV
Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)
Windows ZIP extraction bug (CVE-2022-41049) lets attackers craft ZIP files, which evade warnings on attempts to execute packaged files, even if ZIP file was downloaded from the Internet.
Checkmk: Remote Code Execution by Chaining Multiple Bugs (2/3)
https://ift.tt/8cGNVix
Submitted November 10, 2022 at 04:17AM by monoimpact
via reddit https://ift.tt/Pioh65R
https://ift.tt/8cGNVix
Submitted November 10, 2022 at 04:17AM by monoimpact
via reddit https://ift.tt/Pioh65R
Sonarsource
Checkmk: Remote Code Execution by Chaining Multiple Bugs (2/3)
The second article of this series outlines how an attacker can leverage the ability to forge arbitrary LQL queries to gain access to the NagVis component.
Write up for the API secure programming challenge that was inspired by the major security incident happened to second largest telco in Australia
https://ift.tt/Sgz9XlH
Submitted November 10, 2022 at 04:52AM by pi3ch
via reddit https://ift.tt/aogmlKI
https://ift.tt/Sgz9XlH
Submitted November 10, 2022 at 04:52AM by pi3ch
via reddit https://ift.tt/aogmlKI
Discuss
Technical analysis of Optus API security challenge - Three must to have API security controls
Tl;dr: Authentication alone could only hide API security weaknesses. Three security controls are required to address the root cause of Optus API secure programming challenge. This article is a technical analysis of nearly 40 submissions that we have received…
Capturing credentials from runZero (formerly Rumble.run) scanners
https://ift.tt/6Xo91y4
Submitted November 10, 2022 at 06:19AM by ss2342-
via reddit https://ift.tt/d6bwYno
https://ift.tt/6Xo91y4
Submitted November 10, 2022 at 06:19AM by ss2342-
via reddit https://ift.tt/d6bwYno
zxsecurity.co.nz
Running a runZero (rumble.run) Rumbler for Zero Dollars - ZX Security
Full spectrum IT security services
Integer overflow in xmlParseNameComplex (libxml2) - CVE-2022-40303
https://ift.tt/HQM3oam
Submitted November 10, 2022 at 06:54AM by Gallus
via reddit https://ift.tt/tKNgDLh
https://ift.tt/HQM3oam
Submitted November 10, 2022 at 06:54AM by Gallus
via reddit https://ift.tt/tKNgDLh
GitLab
[CVE-2022-40303] Integer overflow in xmlParseNameComplex (#381) · Issues · GNOME / libxml2 · GitLab
Libxml2 is vulnerable to an integer overflow in xmlParseNameComplex when an attribute list has a very long name (name is >= 2**32 characters).
PcapPlusPlus v22.11 released - C++ library for capturing and analyzing network packets
https://ift.tt/p4swx3G
Submitted November 10, 2022 at 01:51PM by seladb
via reddit https://ift.tt/ePjYhb6
https://ift.tt/p4swx3G
Submitted November 10, 2022 at 01:51PM by seladb
via reddit https://ift.tt/ePjYhb6
GitHub
Release November 2022 Release · seladb/PcapPlusPlus
November 2022 release of PcapPlusPlus (v22.11)
This package contains
Binaries compiled for Ubuntu 22.04 LTS, 20.04 LTS, 18.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bin...
This package contains
Binaries compiled for Ubuntu 22.04 LTS, 20.04 LTS, 18.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bin...