A Technical Analysis of Royal Ransomware [PDF]
https://ift.tt/37DTGs8
Submitted November 14, 2022 at 08:34PM by CyberMasterV
via reddit https://ift.tt/GnVET7m
https://ift.tt/37DTGs8
Submitted November 14, 2022 at 08:34PM by CyberMasterV
via reddit https://ift.tt/GnVET7m
Security Scorecard
A Technical Analysis Of The Royal Ransomware
This malware encrypts files with the AES algorithm, either fully or partially. The extension of the affected files changes to “.royal”. Find out more in this technical analysis of the Royal Ransomware from SecurityScorecard’s Senior Malware Analyst, Vlad…
WonderCMS 3.1.3 Vulnerable to Authenticated Server-Side Request Forgery – CVE-2020-35313
https://ift.tt/hKxUEF0
Submitted November 15, 2022 at 12:14PM by SL7reach
via reddit https://ift.tt/zYKlSW7
https://ift.tt/hKxUEF0
Submitted November 15, 2022 at 12:14PM by SL7reach
via reddit https://ift.tt/zYKlSW7
Penetration Testing and CyberSecurity Solution - SecureLayer7
WonderCMS 3.1.3 Vulnerable to Authenticated Server-Side Request Forgery – CVE-2020-35313
Introduction: Robert wants to develop a basic content management system (CMS) because he became sick of all the bloated systems that had too many features and needed initial configurations. In...
DivestOS CVE Patcher - A tool for downloading, checking, and applying (CVE) patches to a (kernel) repository
https://ift.tt/3lOZ5ke
Submitted November 15, 2022 at 12:57PM by Gallus
via reddit https://ift.tt/Xwej8f6
https://ift.tt/3lOZ5ke
Submitted November 15, 2022 at 12:57PM by Gallus
via reddit https://ift.tt/Xwej8f6
GitLab
DivestOS Mobile / CVE Checker · GitLab
A tool for downloading, checking, and applying (CVE) patches to a repository.
Intro to AJP, AJPFuzzer and re-discovering Ghostcat
https://ift.tt/TlcWipU
Submitted November 15, 2022 at 04:18PM by nibblesec
via reddit https://ift.tt/9f1SA3Y
https://ift.tt/TlcWipU
Submitted November 15, 2022 at 04:18PM by nibblesec
via reddit https://ift.tt/9f1SA3Y
Doyensec
Let's speak AJP · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Hacking Salesforce-backed WebApps
https://ift.tt/OYLN3p5
Submitted November 15, 2022 at 04:59PM by albinowax
via reddit https://ift.tt/vLkem1o
https://ift.tt/OYLN3p5
Submitted November 15, 2022 at 04:59PM by albinowax
via reddit https://ift.tt/vLkem1o
www.hypn.za.net
Hacking Salesforce-backed WebApps - Hypn.za.net
A look at hacking insecure webapps that interact with Salesforce's API, and SQL-Injection like attacks in SoQL
ABI compatibility in Python: how hard could it be?
https://ift.tt/CQFXYT4
Submitted November 15, 2022 at 07:26PM by yossarian_flew_away
via reddit https://ift.tt/EBJVqgK
https://ift.tt/CQFXYT4
Submitted November 15, 2022 at 07:26PM by yossarian_flew_away
via reddit https://ift.tt/EBJVqgK
The Trail of Bits Blog
ABI compatibility in Python: How hard could it be?
TL;DR: Trail of Bits has developed abi3audit, a new Python tool for checking Python packages for CPython application binary interface (ABI) violations. We’ve used it to discover hundreds of inconsistently and incorrectly tagged package distributions, each…
Stealing passwords from infosec Mastodon - without bypassing CSP
https://ift.tt/hRDE0m7
Submitted November 15, 2022 at 08:17PM by albinowax
via reddit https://ift.tt/voIhqLH
https://ift.tt/hRDE0m7
Submitted November 15, 2022 at 08:17PM by albinowax
via reddit https://ift.tt/voIhqLH
PortSwigger Research
Stealing passwords from infosec Mastodon - without bypassing CSP
The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose
GuardDog: Identifying malicious PyPI packages using static code analysis and package metadata analysis
https://ift.tt/Q03Lm4y
Submitted November 15, 2022 at 09:39PM by thorn42
via reddit https://ift.tt/NAUMGXt
https://ift.tt/Q03Lm4y
Submitted November 15, 2022 at 09:39PM by thorn42
via reddit https://ift.tt/NAUMGXt
Datadoghq
Finding malicious PyPI packages through static code analysis: Meet GuardDog
GuardDog is an open-source tool to identify malicious PyPI packages through source code and metadata analysis
Checkmk: Remote Code Execution by Chaining Multiple Bugs (3/3)
https://ift.tt/clpmazJ
Submitted November 15, 2022 at 09:53PM by monoimpact
via reddit https://ift.tt/X152PJM
https://ift.tt/clpmazJ
Submitted November 15, 2022 at 09:53PM by monoimpact
via reddit https://ift.tt/X152PJM
Pixel 6 Bootloader: Exploitation (part 3)
https://ift.tt/nMPO92S
Submitted November 15, 2022 at 11:31PM by jeandrew
via reddit https://ift.tt/h4B5ipe
https://ift.tt/nMPO92S
Submitted November 15, 2022 at 11:31PM by jeandrew
via reddit https://ift.tt/h4B5ipe
Overview of SQLi and Access Flaws in Zendesk
https://ift.tt/dZ6LtTG
Submitted November 15, 2022 at 11:27PM by TotallyNotTeaPot
via reddit https://ift.tt/eFLduab
https://ift.tt/dZ6LtTG
Submitted November 15, 2022 at 11:27PM by TotallyNotTeaPot
via reddit https://ift.tt/eFLduab
Varonis
Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk
Varonis Threat Labs found a SQL injection vulnerability and a logical access flaw in Zendesk Explore, the reporting and analytics service in the popular customer service solution, Zendesk.
Hyperpom: An Apple Silicon Fuzzer for 64-bit ARM Binaries
https://ift.tt/8rF5hgE
Submitted November 15, 2022 at 11:14PM by jeandrew
via reddit https://ift.tt/mq9NwKy
https://ift.tt/8rF5hgE
Submitted November 15, 2022 at 11:14PM by jeandrew
via reddit https://ift.tt/mq9NwKy
Impalabs
Hyperpom: An Apple Silicon Fuzzer for 64-bit ARM Binaries
Impalabs is releasing Hyperpom, a 64-bit ARM binary fuzzer written in Rust and based on the Apple Silicon's hypervisor. It is mutation-based and coverage-guided. This article gives an overview of its internals, presents the different components it consists…
Distributed Identity aka Identity on the Blockchain - What it is and its vulnerable attack surfaces. (Part 1)
https://ift.tt/4vGArsP
Submitted November 16, 2022 at 12:47AM by CyberArkLabs
via reddit https://ift.tt/rKoIRBy
https://ift.tt/4vGArsP
Submitted November 16, 2022 at 12:47AM by CyberArkLabs
via reddit https://ift.tt/rKoIRBy
Cyberark
Decentralized Identity Attack Surface – Part 1
Introduction Who are you? That’s a hard question to answer. Many philosophers have been fascinated with this question for years. Who are you in cyberspace? Your digital identity is comprised of...
"Fangxiao: a Chinese Threat Actor" - by Cyjax researchers @nyxilar and @_nynan
https://ift.tt/GHFYOV5
Submitted November 16, 2022 at 04:00PM by _nynan
via reddit https://ift.tt/dmR829y
https://ift.tt/GHFYOV5
Submitted November 16, 2022 at 04:00PM by _nynan
via reddit https://ift.tt/dmR829y
CYJAX
Fangxiao: a Chinese threat actor
Phishing campaigns continue to increase globally. These operations offer an easy route for cybercriminals to generate revenue, steal...
HZ RAT goes China
https://ift.tt/pvjoyN5
Submitted November 16, 2022 at 08:29PM by OwnPreparation3424
via reddit https://ift.tt/i29gNrU
https://ift.tt/pvjoyN5
Submitted November 16, 2022 at 08:29PM by OwnPreparation3424
via reddit https://ift.tt/i29gNrU
Medium
HZ RAT goes China
Walking down the Royal Road as we did in one of our previous posts, another by-catch of our Yara rule caught our attention. Turns out we…
Root RCE via CSRF (and other vulns) in F5 Big-IP devices [my original research]
https://ift.tt/D5HViEU
Submitted November 17, 2022 at 03:57AM by iagox86
via reddit https://ift.tt/bcMpHQi
https://ift.tt/D5HViEU
Submitted November 17, 2022 at 03:57AM by iagox86
via reddit https://ift.tt/bcMpHQi
Rapid7
CVE-2022-41622 and CVE-2022-41800 (FIXED): F5 BIG-IP and iControl REST Vulnerabilities and Exposures | Rapid7 Blog
Infosys leaked FullAdminAccess AWS keys on PyPi for over a year
https://ift.tt/GAg1l9E
Submitted November 17, 2022 at 05:39AM by Most-Loss5834
via reddit https://ift.tt/bDh8ctv
https://ift.tt/GAg1l9E
Submitted November 17, 2022 at 05:39AM by Most-Loss5834
via reddit https://ift.tt/bDh8ctv
tomforb.es
Infosys leaked FullAdminAccess AWS keys on PyPi for over a year
Infosys has a lot to say about security You can check out their website for a lot of buzwords , but it’s clear from all the stock photos that they take security Very Seriously Indeed ™️.
However, from what I’ve found recently, it seems that InfoSys follow…
However, from what I’ve found recently, it seems that InfoSys follow…
Parsing atop files with python dissect.cstruct
https://ift.tt/dBg9OGj
Submitted November 17, 2022 at 05:16AM by DiabloHorn
via reddit https://ift.tt/TRH8WnC
https://ift.tt/dBg9OGj
Submitted November 17, 2022 at 05:16AM by DiabloHorn
via reddit https://ift.tt/TRH8WnC
DiabloHorn
Parsing atop files with python dissect.cstruct
Like you’ve probably read, Fox-IT released their incident response framework called dissect, but before that they released the cstruct part of their framework. Ever since they released it pub…
Packet Tuesday: New video series about in depth network traffic analysis
https://ift.tt/ZQESdFc
Submitted November 17, 2022 at 06:23AM by dentalfoss
via reddit https://ift.tt/8rsE063
https://ift.tt/ZQESdFc
Submitted November 17, 2022 at 06:23AM by dentalfoss
via reddit https://ift.tt/8rsE063
Is your VMware vSphere environment secure?
https://ift.tt/HoZN9ip
Submitted November 16, 2022 at 02:58PM by karimhabush
via reddit https://ift.tt/PHXZbEx
https://ift.tt/HoZN9ip
Submitted November 16, 2022 at 02:58PM by karimhabush
via reddit https://ift.tt/PHXZbEx
Medium
Is your VMware vSphere environment secure?
Assess your vSphere configuration in less than 10 minutes!
New Tool: Orpheus - Bypasses most Kerberoast Detections
https://ift.tt/SdGhaQT
Submitted November 17, 2022 at 07:47PM by ben0xa
via reddit https://ift.tt/Mnwmp9f
https://ift.tt/SdGhaQT
Submitted November 17, 2022 at 07:47PM by ben0xa
via reddit https://ift.tt/Mnwmp9f
TrustedSec
The Art of Bypassing Kerberoast Detections with Orpheus