Subdomain Enumeration with DNSSEC
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
Systemsecurity
Subdomain Enumeration with DNSSEC
DNSSEC uses resource records like NSEC or NSEC3, which can be leveraged for subdomain enumeration. Different techniques for zone enumeration and countermeasures like White Lies and Black Lies are described in this blog post.
Xiongmai IoT Exploitation
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Looting Microsoft Configuration Manager
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
Withsecure
Looting Microsoft Configuration Manager
Configuration Manager often contain information that could be used by an attacker to find new attack paths or credentials that allow lateral movement.
Need for speed: static analysis version
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
semgrep.dev
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.
SGX.Fail - Overview of SGX Attacks
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
Reddit
From the netsec community on Reddit: SGX.Fail - Overview of SGX Attacks
Posted by Gallus - 13 votes and 0 comments
Building Policy Gate for DevSecOps using Open Policy Agent
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
Medium
Building Policy Gate for DevSecOps using Open Policy Agent
In our last blog, we detailed our approach to building a continuous application security pipeline with the objective of providing…
Multiversity by @wefuzz_io, a collection of amazing resources for Hackers and Developers to learn, develop, showcase and contribute to the future of Web3 Security
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
multiversity.wefuzz.io
👾 WeFuzz Multiversity | Multiversity
New details on commercial spyware vendor Variston
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
Google
New details on commercial spyware vendor Variston
The Threat Analysis Group shares new information on the commercial spyware vendor Variston.
Black Hat USA 2022 Conference Recordings
https://www.youtube.com/playlist?list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq
Submitted December 01, 2022 at 05:46AM by sanitybit
via reddit https://ift.tt/mYk64vI
https://www.youtube.com/playlist?list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq
Submitted December 01, 2022 at 05:46AM by sanitybit
via reddit https://ift.tt/mYk64vI
YouTube
Black Hat USA 2022
Share your videos with friends, family, and the world
RFC 8628 lets you phish people even if they're using WebAuthn
https://ift.tt/cpNIYLj
Submitted December 01, 2022 at 05:44AM by sanitybit
via reddit https://ift.tt/T2z6uwx
https://ift.tt/cpNIYLj
Submitted December 01, 2022 at 05:44AM by sanitybit
via reddit https://ift.tt/T2z6uwx
Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328) - SUID-root program installed by default on Ubuntu
https://ift.tt/OvQHKgX
Submitted December 01, 2022 at 07:23AM by Gallus
via reddit https://ift.tt/07bJkwg
https://ift.tt/OvQHKgX
Submitted December 01, 2022 at 07:23AM by Gallus
via reddit https://ift.tt/07bJkwg
seclists.org
oss-sec: Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328)
Notice of Recent Security Incident - The LastPass Blog
https://ift.tt/7mWlxIg
Submitted December 01, 2022 at 07:55AM by svmseric
via reddit https://ift.tt/vukwsdx
https://ift.tt/7mWlxIg
Submitted December 01, 2022 at 07:55AM by svmseric
via reddit https://ift.tt/vukwsdx
The LastPass Blog
Notice of Recent Security Incident - The LastPass Blog
We are working diligently to understand the scope of the incident and identify what specific information has been accessed.
Remote code execution bug in FreeBSD's ping (CVE-2022-23093)
https://ift.tt/TrukG2P
Submitted December 01, 2022 at 09:40AM by Gallus
via reddit https://ift.tt/xfckVmZ
https://ift.tt/TrukG2P
Submitted December 01, 2022 at 09:40AM by Gallus
via reddit https://ift.tt/xfckVmZ
Bypassing Web Application Firewalls
https://ift.tt/ad0kRiL
Submitted December 01, 2022 at 04:51PM by ma-ni
via reddit https://ift.tt/fH8D37r
https://ift.tt/ad0kRiL
Submitted December 01, 2022 at 04:51PM by ma-ni
via reddit https://ift.tt/fH8D37r
How we found a supply-chain vulnerability in IBM Cloud Databases for PostgreSQL
https://ift.tt/ShHOswg
Submitted December 01, 2022 at 08:46PM by sagitz_
via reddit https://ift.tt/QIGE9e2
https://ift.tt/ShHOswg
Submitted December 01, 2022 at 08:46PM by sagitz_
via reddit https://ift.tt/QIGE9e2
wiz.io
Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access…
How IBM Cloud caught us exploring its infrastructure and how a hardcoded secret eventually led to build artifact access and manipulation
The CI/CD Goat just got wilder! - A new challenge to the deliberately vulnerable CI/CD environment
https://ift.tt/ju5vBda
Submitted December 01, 2022 at 08:11PM by TupleType
via reddit https://ift.tt/iAhkH4a
https://ift.tt/ju5vBda
Submitted December 01, 2022 at 08:11PM by TupleType
via reddit https://ift.tt/iAhkH4a
Cider Security Site
CI/CD Goat now supports GitLab in a brand new challenge - Cider Security Site
Exciting news – we’ve released a new version of our CI/CD Goat CTF platform, a deliberately vulnerable CI/CD environment. We decided to release a new version with a shiny new challenge, after our previous 10 challenges were enthusiastically received and widely…
Unauthenticated Command Injection in Asus M25 NAS
https://ift.tt/FMuoh1L
Submitted December 01, 2022 at 08:08PM by g_e_r_h_a_r_d
via reddit https://ift.tt/mA7ZaGS
https://ift.tt/FMuoh1L
Submitted December 01, 2022 at 08:08PM by g_e_r_h_a_r_d
via reddit https://ift.tt/mA7ZaGS
ONEKEY
Read Security Advisory here 👆
ONEKEY identifies a command injection bug in the M25 NAS from Asus. Read the latest Security Advisory here
Huawei Security Hypervisor Vulnerability
https://ift.tt/WNfjZI4
Submitted December 01, 2022 at 09:51PM by jeandrew
via reddit https://ift.tt/BU9keyK
https://ift.tt/WNfjZI4
Submitted December 01, 2022 at 09:51PM by jeandrew
via reddit https://ift.tt/BU9keyK
Impalabs
Huawei Security Hypervisor Vulnerability
This advisory contains information about the following vulnerabilities:
- OOB Accesses Using the Logging System
- OOB Accesses Using the Logging System
Windows Exploitation Challenge - Blue Frost Security 2022 - VoidSec
https://ift.tt/KOwMNlT
Submitted December 01, 2022 at 10:31PM by Void_Sec
via reddit https://ift.tt/uvcSElJ
https://ift.tt/KOwMNlT
Submitted December 01, 2022 at 10:31PM by Void_Sec
via reddit https://ift.tt/uvcSElJ
VoidSec
Windows Exploitation Challenge - Blue Frost Security 2022 (Ekoparty) - VoidSec
Last month, during Ekoparty, Blue Frost Security published a Windows challenge. Since having a Windows exploitation challenge, is one of a kind in CTFs, and since I’ve found the challenge interesting and very clever, I’ve decided to post about my reverse…
UART Essential for Pentester
https://ift.tt/3VYWkAd
Submitted December 02, 2022 at 03:41AM by Void_Sec
via reddit https://ift.tt/U7exFDV
https://ift.tt/3VYWkAd
Submitted December 02, 2022 at 03:41AM by Void_Sec
via reddit https://ift.tt/U7exFDV
Marco Negro's Blog
UART Essential for Pentester
Platform certificates used to sign Android malware
https://ift.tt/X1x5EnH
Submitted December 02, 2022 at 05:14AM by ScottContini
via reddit https://ift.tt/oObAUqW
https://ift.tt/X1x5EnH
Submitted December 02, 2022 at 05:14AM by ScottContini
via reddit https://ift.tt/oObAUqW