Bringing PAC to x86 with custom microcode
https://ift.tt/Y4Q3ilt
Submitted November 23, 2022 at 11:46AM by Gallus
via reddit https://ift.tt/kJ9Ge1A
https://ift.tt/Y4Q3ilt
Submitted November 23, 2022 at 11:46AM by Gallus
via reddit https://ift.tt/kJ9Ge1A
GitHub
x86 PAC · pietroborrello/CustomProcessingUnit@936a684
The first dynamic analysis framework for CPU microcode - x86 PAC · pietroborrello/CustomProcessingUnit@936a684
Nighthawk: An Up-and-Coming Pentest Tool Likely to Gain Threat Actor Notice
https://ift.tt/37jwrSN
Submitted November 23, 2022 at 02:25PM by CyberMasterV
via reddit https://ift.tt/M5KDrRA
https://ift.tt/37jwrSN
Submitted November 23, 2022 at 02:25PM by CyberMasterV
via reddit https://ift.tt/M5KDrRA
Proofpoint
What Is a Threat Actor? - Definition, Types & More | Proofpoint US
A threat actor is a term used to describe individuals whose purpose is to engage in cyber-related offenses. Learn the definition, types, motivations, and more.
A dive into Microsoft Defender for Identity
https://ift.tt/nEkV8Tx
Submitted November 23, 2022 at 09:16PM by jeandrew
via reddit https://ift.tt/ebHJq70
https://ift.tt/nEkV8Tx
Submitted November 23, 2022 at 09:16PM by jeandrew
via reddit https://ift.tt/ebHJq70
Synacktiv
A dive into Microsoft Defender for Identity
Investigating a backdoored PyPi package targeting FastAPI applications
https://ift.tt/ZcizOCg
Submitted November 24, 2022 at 02:18AM by thorn42
via reddit https://ift.tt/AU1kvqG
https://ift.tt/ZcizOCg
Submitted November 24, 2022 at 02:18AM by thorn42
via reddit https://ift.tt/AU1kvqG
Datadoghq
Investigating a backdoored PyPi package targeting FastAPI applications
In this post, we analyze a malicious PyPI package attempting to backdoor FastAPI applications.
2022 InfoSec Black Friday Deals
https://ift.tt/jMeAgR2
Submitted November 24, 2022 at 01:31PM by Fugitif
via reddit https://ift.tt/2WfXqp0
https://ift.tt/jMeAgR2
Submitted November 24, 2022 at 01:31PM by Fugitif
via reddit https://ift.tt/2WfXqp0
GitHub
GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
All the deals for InfoSec related software/tools this Black Friday - GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
Sigstore The Easy Way
https://ift.tt/2xOFRqN
Submitted November 24, 2022 at 04:58PM by Rewanth_Tammana
via reddit https://ift.tt/2i8VaS0
https://ift.tt/2xOFRqN
Submitted November 24, 2022 at 04:58PM by Rewanth_Tammana
via reddit https://ift.tt/2i8VaS0
Rewanthtammana
Sigstore The Easy Way
Software signing just got easier. Sigstore The Easy Way guide is the most straightforward way to geting started with software signing & securing software supply chains.
Containers: Rootful, Rootless, Privileged and Super Privileged
https://ift.tt/K61PaUt
Submitted November 25, 2022 at 09:12PM by fcano1
via reddit https://ift.tt/zTpGZwL
https://ift.tt/K61PaUt
Submitted November 25, 2022 at 09:12PM by fcano1
via reddit https://ift.tt/zTpGZwL
Exploiting CORS Misconfigurations
https://ift.tt/DdZtKfn
Submitted November 26, 2022 at 02:09PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/NQL5XFR
https://ift.tt/DdZtKfn
Submitted November 26, 2022 at 02:09PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/NQL5XFR
attack ships on fire
Exploiting CORS Misconfigurations
TL;DR If you can find an unrestricted CORS endpoint, that also responds to the HTTP override headers, then potentially you can use it to access endpoints that aren’t enabled for CORS, bypass CSRF protections, and also deliver an XST (which will give you access…
So, you want to get into bug bounties?
https://ift.tt/1FgJcEo
Submitted November 26, 2022 at 03:01PM by Mempodipper
via reddit https://ift.tt/JUi4Rem
https://ift.tt/1FgJcEo
Submitted November 26, 2022 at 03:01PM by Mempodipper
via reddit https://ift.tt/JUi4Rem
Shubham Shah
So, you want to get into bug bounties?
I've been doing bug bounties for over 10 years now and over time, I have grown fonder of the life changing effects it has had for me. From job prospects, to being able to financially support those around me and myself. I believe that if you're passionate…
Exploiting an N-day vBulletin PHP Object Injection Vulnerability
https://ift.tt/0bJFYQ7
Submitted November 26, 2022 at 10:51PM by eg1x
via reddit https://ift.tt/RxEBYnh
https://ift.tt/0bJFYQ7
Submitted November 26, 2022 at 10:51PM by eg1x
via reddit https://ift.tt/RxEBYnh
Hacking Smartwatches for Spear Phishing – Red Team Ops – Cybervelia
https://ift.tt/ok0a9uR
Submitted November 28, 2022 at 12:21AM by Necessary-Reality-80
via reddit https://ift.tt/gtce1RV
https://ift.tt/ok0a9uR
Submitted November 28, 2022 at 12:21AM by Necessary-Reality-80
via reddit https://ift.tt/gtce1RV
Heap_detective is an open-source static analysis tool that finds pitfalls in heap memory usage in C and C++.
https://ift.tt/O3Fa721
Submitted November 28, 2022 at 08:02AM by CoolerVoid
via reddit https://ift.tt/9BHvPNF
https://ift.tt/O3Fa721
Submitted November 28, 2022 at 08:02AM by CoolerVoid
via reddit https://ift.tt/9BHvPNF
GitHub
GitHub - CoolerVoid/heap_detective: The simple way to detect heap memory pitfalls in C++ and C. Beta.
The simple way to detect heap memory pitfalls in C++ and C. Beta. - GitHub - CoolerVoid/heap_detective: The simple way to detect heap memory pitfalls in C++ and C. Beta.
ransomwhere: a ransomware sample to test out your ransomware response strategy.
https://ift.tt/c1o67Ey
Submitted November 28, 2022 at 03:11PM by nindustries
via reddit https://ift.tt/yzC1QrP
https://ift.tt/c1o67Ey
Submitted November 28, 2022 at 03:11PM by nindustries
via reddit https://ift.tt/yzC1QrP
GitHub
GitHub - hazcod/ransomwhere: A PoC ransomware sample to test out your ransomware response strategy.
A PoC ransomware sample to test out your ransomware response strategy. - hazcod/ransomwhere
Exception(al) Failure - Breaking the STM32F1 Read-Out Protection
https://ift.tt/sTWhvmj
Submitted November 28, 2022 at 08:43PM by Gallus
via reddit https://ift.tt/czlvK3U
https://ift.tt/sTWhvmj
Submitted November 28, 2022 at 08:43PM by Gallus
via reddit https://ift.tt/czlvK3U
blog.zapb.de
Exception(al) Failure - Breaking the STM32F1 Read-Out Protection
The firmware of microcontrollers usually contains valuable data such as intellectual property and, in some cases, even cryptographic material.
In order to protect the confidentiality of these assets,
In order to protect the confidentiality of these assets,
subzuf – a smart DNS response-guided subdomain fuzzer
https://ift.tt/6GsbK48
Submitted November 29, 2022 at 12:33AM by feecle
via reddit https://ift.tt/H7AUCpe
https://ift.tt/6GsbK48
Submitted November 29, 2022 at 12:33AM by feecle
via reddit https://ift.tt/H7AUCpe
GitHub
GitHub - elceef/subzuf: a smart DNS response-guided subdomain fuzzer
a smart DNS response-guided subdomain fuzzer. Contribute to elceef/subzuf development by creating an account on GitHub.
Beating Plagiarism Checkers with a Custom Font
https://ift.tt/VFPwE7A
Submitted November 29, 2022 at 05:24AM by Exact-Practice-8658
via reddit https://ift.tt/3WLvq7P
https://ift.tt/VFPwE7A
Submitted November 29, 2022 at 05:24AM by Exact-Practice-8658
via reddit https://ift.tt/3WLvq7P
Medium
Beating Plagiarism Checkers for Science
TLDR; a custom font can be used to avoid a plagiarism checker while still being human readable.
The Art of Bypassing Kerberoast Detections with Orpheus
https://ift.tt/seRg69H
Submitted November 29, 2022 at 07:14AM by sanitybit
via reddit https://ift.tt/jypN8wV
https://ift.tt/seRg69H
Submitted November 29, 2022 at 07:14AM by sanitybit
via reddit https://ift.tt/jypN8wV
TrustedSec
The Art of Bypassing Kerberoast Detections with Orpheus
Subdomain Enumeration with DNSSEC
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
Systemsecurity
Subdomain Enumeration with DNSSEC
DNSSEC uses resource records like NSEC or NSEC3, which can be leveraged for subdomain enumeration. Different techniques for zone enumeration and countermeasures like White Lies and Black Lies are described in this blog post.
Xiongmai IoT Exploitation
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Looting Microsoft Configuration Manager
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
Withsecure
Looting Microsoft Configuration Manager
Configuration Manager often contain information that could be used by an attacker to find new attack paths or credentials that allow lateral movement.
Need for speed: static analysis version
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
semgrep.dev
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.