Need for speed: static analysis version
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
semgrep.dev
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.
SGX.Fail - Overview of SGX Attacks
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
Reddit
From the netsec community on Reddit: SGX.Fail - Overview of SGX Attacks
Posted by Gallus - 13 votes and 0 comments
Building Policy Gate for DevSecOps using Open Policy Agent
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
Medium
Building Policy Gate for DevSecOps using Open Policy Agent
In our last blog, we detailed our approach to building a continuous application security pipeline with the objective of providing…
Multiversity by @wefuzz_io, a collection of amazing resources for Hackers and Developers to learn, develop, showcase and contribute to the future of Web3 Security
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
multiversity.wefuzz.io
👾 WeFuzz Multiversity | Multiversity
New details on commercial spyware vendor Variston
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
Google
New details on commercial spyware vendor Variston
The Threat Analysis Group shares new information on the commercial spyware vendor Variston.
Black Hat USA 2022 Conference Recordings
https://www.youtube.com/playlist?list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq
Submitted December 01, 2022 at 05:46AM by sanitybit
via reddit https://ift.tt/mYk64vI
https://www.youtube.com/playlist?list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq
Submitted December 01, 2022 at 05:46AM by sanitybit
via reddit https://ift.tt/mYk64vI
YouTube
Black Hat USA 2022
Share your videos with friends, family, and the world
RFC 8628 lets you phish people even if they're using WebAuthn
https://ift.tt/cpNIYLj
Submitted December 01, 2022 at 05:44AM by sanitybit
via reddit https://ift.tt/T2z6uwx
https://ift.tt/cpNIYLj
Submitted December 01, 2022 at 05:44AM by sanitybit
via reddit https://ift.tt/T2z6uwx
Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328) - SUID-root program installed by default on Ubuntu
https://ift.tt/OvQHKgX
Submitted December 01, 2022 at 07:23AM by Gallus
via reddit https://ift.tt/07bJkwg
https://ift.tt/OvQHKgX
Submitted December 01, 2022 at 07:23AM by Gallus
via reddit https://ift.tt/07bJkwg
seclists.org
oss-sec: Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328)
Notice of Recent Security Incident - The LastPass Blog
https://ift.tt/7mWlxIg
Submitted December 01, 2022 at 07:55AM by svmseric
via reddit https://ift.tt/vukwsdx
https://ift.tt/7mWlxIg
Submitted December 01, 2022 at 07:55AM by svmseric
via reddit https://ift.tt/vukwsdx
The LastPass Blog
Notice of Recent Security Incident - The LastPass Blog
We are working diligently to understand the scope of the incident and identify what specific information has been accessed.
Remote code execution bug in FreeBSD's ping (CVE-2022-23093)
https://ift.tt/TrukG2P
Submitted December 01, 2022 at 09:40AM by Gallus
via reddit https://ift.tt/xfckVmZ
https://ift.tt/TrukG2P
Submitted December 01, 2022 at 09:40AM by Gallus
via reddit https://ift.tt/xfckVmZ
Bypassing Web Application Firewalls
https://ift.tt/ad0kRiL
Submitted December 01, 2022 at 04:51PM by ma-ni
via reddit https://ift.tt/fH8D37r
https://ift.tt/ad0kRiL
Submitted December 01, 2022 at 04:51PM by ma-ni
via reddit https://ift.tt/fH8D37r
How we found a supply-chain vulnerability in IBM Cloud Databases for PostgreSQL
https://ift.tt/ShHOswg
Submitted December 01, 2022 at 08:46PM by sagitz_
via reddit https://ift.tt/QIGE9e2
https://ift.tt/ShHOswg
Submitted December 01, 2022 at 08:46PM by sagitz_
via reddit https://ift.tt/QIGE9e2
wiz.io
Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access…
How IBM Cloud caught us exploring its infrastructure and how a hardcoded secret eventually led to build artifact access and manipulation
The CI/CD Goat just got wilder! - A new challenge to the deliberately vulnerable CI/CD environment
https://ift.tt/ju5vBda
Submitted December 01, 2022 at 08:11PM by TupleType
via reddit https://ift.tt/iAhkH4a
https://ift.tt/ju5vBda
Submitted December 01, 2022 at 08:11PM by TupleType
via reddit https://ift.tt/iAhkH4a
Cider Security Site
CI/CD Goat now supports GitLab in a brand new challenge - Cider Security Site
Exciting news – we’ve released a new version of our CI/CD Goat CTF platform, a deliberately vulnerable CI/CD environment. We decided to release a new version with a shiny new challenge, after our previous 10 challenges were enthusiastically received and widely…
Unauthenticated Command Injection in Asus M25 NAS
https://ift.tt/FMuoh1L
Submitted December 01, 2022 at 08:08PM by g_e_r_h_a_r_d
via reddit https://ift.tt/mA7ZaGS
https://ift.tt/FMuoh1L
Submitted December 01, 2022 at 08:08PM by g_e_r_h_a_r_d
via reddit https://ift.tt/mA7ZaGS
ONEKEY
Read Security Advisory here 👆
ONEKEY identifies a command injection bug in the M25 NAS from Asus. Read the latest Security Advisory here
Huawei Security Hypervisor Vulnerability
https://ift.tt/WNfjZI4
Submitted December 01, 2022 at 09:51PM by jeandrew
via reddit https://ift.tt/BU9keyK
https://ift.tt/WNfjZI4
Submitted December 01, 2022 at 09:51PM by jeandrew
via reddit https://ift.tt/BU9keyK
Impalabs
Huawei Security Hypervisor Vulnerability
This advisory contains information about the following vulnerabilities:
- OOB Accesses Using the Logging System
- OOB Accesses Using the Logging System
Windows Exploitation Challenge - Blue Frost Security 2022 - VoidSec
https://ift.tt/KOwMNlT
Submitted December 01, 2022 at 10:31PM by Void_Sec
via reddit https://ift.tt/uvcSElJ
https://ift.tt/KOwMNlT
Submitted December 01, 2022 at 10:31PM by Void_Sec
via reddit https://ift.tt/uvcSElJ
VoidSec
Windows Exploitation Challenge - Blue Frost Security 2022 (Ekoparty) - VoidSec
Last month, during Ekoparty, Blue Frost Security published a Windows challenge. Since having a Windows exploitation challenge, is one of a kind in CTFs, and since I’ve found the challenge interesting and very clever, I’ve decided to post about my reverse…
UART Essential for Pentester
https://ift.tt/3VYWkAd
Submitted December 02, 2022 at 03:41AM by Void_Sec
via reddit https://ift.tt/U7exFDV
https://ift.tt/3VYWkAd
Submitted December 02, 2022 at 03:41AM by Void_Sec
via reddit https://ift.tt/U7exFDV
Marco Negro's Blog
UART Essential for Pentester
Platform certificates used to sign Android malware
https://ift.tt/X1x5EnH
Submitted December 02, 2022 at 05:14AM by ScottContini
via reddit https://ift.tt/oObAUqW
https://ift.tt/X1x5EnH
Submitted December 02, 2022 at 05:14AM by ScottContini
via reddit https://ift.tt/oObAUqW
Visual Studio Code: Remote Code Execution
https://ift.tt/hIPTUbt
Submitted December 02, 2022 at 05:42AM by Zemnmez
via reddit https://ift.tt/FR0YmhM
https://ift.tt/hIPTUbt
Submitted December 02, 2022 at 05:42AM by Zemnmez
via reddit https://ift.tt/FR0YmhM
GitHub
Visual Studio Code: Remote Code Execution
### Summary
An attacker could, through a link or website, take over the computer of a Visual Studio Code user and any computers they were connected to via the [Visual Studio Code Remote Developmen...
An attacker could, through a link or website, take over the computer of a Visual Studio Code user and any computers they were connected to via the [Visual Studio Code Remote Developmen...
XSS on account.leagueoflegends.com via easyXDM [2016]
https://ift.tt/XMLlirf
Submitted December 02, 2022 at 11:15AM by bored-engineer
via reddit https://ift.tt/uN27yMt
https://ift.tt/XMLlirf
Submitted December 02, 2022 at 11:15AM by bored-engineer
via reddit https://ift.tt/uN27yMt
Medium
XSS on account.leagueoflegends.com via easyXDM [2016]
This post contains a chain of vulnerabilities I responsibly disclosed to Riot Games in November of 2016. I’m publicly disclosing it now as…
VLC : Integer overflow in vnc module - CVE-2022-41325
https://ift.tt/1uEjqSZ
Submitted December 02, 2022 at 02:59PM by jeandrew
via reddit https://ift.tt/iaUHogr
https://ift.tt/1uEjqSZ
Submitted December 02, 2022 at 02:59PM by jeandrew
via reddit https://ift.tt/iaUHogr