Release of EMBA firmware analyzer in version 1.2.0 - aka London Calling
https://ift.tt/RgaUdDv
Submitted December 05, 2022 at 06:57PM by _m-1-k-3_
via reddit https://ift.tt/VwDRepW
https://ift.tt/RgaUdDv
Submitted December 05, 2022 at 06:57PM by _m-1-k-3_
via reddit https://ift.tt/VwDRepW
GitHub
Release EMBA v1.2.0 - London Calling · e-m-b-a/emba
Beside bug fixes this release introduces many new features. You are invited to celebrate the new EMBA version with us.
Spread the word and secure the Internet of Things with EMBA!
Since versio...
Spread the word and secure the Internet of Things with EMBA!
Since versio...
A Detailed Analysis of The Last Version of REvil Ransomware [PDF]
https://ift.tt/aBqiN7P
Submitted December 05, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/YgfD59K
https://ift.tt/aBqiN7P
Submitted December 05, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/YgfD59K
Security Scorecard
A Detailed Analysis Of The Last Version Of R Evil Ransomware
Default NETGEAR Router Configuration Allows Attacks from WAN
https://ift.tt/O4eptul
Submitted December 05, 2022 at 10:52PM by dinobyt3s
via reddit https://ift.tt/RQkB5ws
https://ift.tt/O4eptul
Submitted December 05, 2022 at 10:52PM by dinobyt3s
via reddit https://ift.tt/RQkB5ws
Medium
NETGEAR Router Network Misconfiguration
Last Minute Patch Thwarts Pwn2Own Entries
Hijacking GitHub Repositories by Deleting and Restoring Them
https://ift.tt/UwgFvjO
Submitted December 05, 2022 at 10:30PM by whisperingmime
via reddit https://ift.tt/5QHWuoO
https://ift.tt/UwgFvjO
Submitted December 05, 2022 at 10:30PM by whisperingmime
via reddit https://ift.tt/5QHWuoO
Blog by Joren Vrancken
Hijacking GitHub Repositories by Deleting and Restoring Them
Recently, we encountered an obscure security measure while researching GitHub repositories: the popular repository namespace retirement. This security measure was implemented by GitHub to protect (popular) repositories against repo jacking (i.e. hijacking…
[Help] I'm looking for a downloadable list of all CVEs including vulnerability
https://ift.tt/3E4PVUC
Submitted December 06, 2022 at 04:00AM by much_thanks
via reddit https://ift.tt/F8mfKxQ
https://ift.tt/3E4PVUC
Submitted December 06, 2022 at 04:00AM by much_thanks
via reddit https://ift.tt/F8mfKxQ
cve.mitre.org
CVE -
Download CVE List
Download CVE List
The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.
Moobot Uses a Fake Vulnerability
https://ift.tt/3DKiMT2
Submitted December 06, 2022 at 07:52PM by chicksdigthelongrun
via reddit https://ift.tt/uaT9YZi
https://ift.tt/3DKiMT2
Submitted December 06, 2022 at 07:52PM by chicksdigthelongrun
via reddit https://ift.tt/uaT9YZi
VulnCheck
Moobot Uses a Fake Vulnerability - Blog - VulnCheck
An investigation into CVE-2022-28958 finds the vulnerability doesn't actually exist.
The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022
https://ift.tt/vzwsCtW
Submitted December 06, 2022 at 08:21PM by Gallus
via reddit https://ift.tt/Dqv9NcF
https://ift.tt/vzwsCtW
Submitted December 06, 2022 at 08:21PM by Gallus
via reddit https://ift.tt/Dqv9NcF
STAR Labs
The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022
Background Some time ago, we were playing with some Netgear routers and we learned so much from this target.
However, Netgear recently patched several vulnerabilities in their RAX30 router firmware, including the two vulnerabilities in the DHCP interface…
However, Netgear recently patched several vulnerabilities in their RAX30 router firmware, including the two vulnerabilities in the DHCP interface…
An open source SMS gateway for pentest projects
https://ift.tt/vNmDwKb
Submitted December 07, 2022 at 02:55AM by aunga
via reddit https://ift.tt/gDWXiYF
https://ift.tt/vNmDwKb
Submitted December 07, 2022 at 02:55AM by aunga
via reddit https://ift.tt/gDWXiYF
Pentagrid AG
An open source SMS gateway for pentest projects
We publish an open source Python-based server for sending and especially receiving SMS using multiple GSM modems and SIM cards, which helps us in pentesting projects, but also for alerting system moni
RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass
https://ift.tt/iJLpbhS
Submitted December 07, 2022 at 08:01AM by Gallus
via reddit https://ift.tt/FHgo8bO
https://ift.tt/iJLpbhS
Submitted December 07, 2022 at 08:01AM by Gallus
via reddit https://ift.tt/FHgo8bO
h1pmnh.github.io
Bug Writeup: RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass
Writeup of a collaborated bug on Bugcrowd where I was able to bypass Akamai WAF to exploit RCE on Spring Boot error page using SpEL
PyPI-distributed malicious package campagin tying into GitHub accounts and embedded into repos to disguise its intention - FULL ANALYSIS
https://ift.tt/vZe3R0u
Submitted December 07, 2022 at 09:05PM by dalmoz
via reddit https://ift.tt/7tMuU3J
https://ift.tt/vZe3R0u
Submitted December 07, 2022 at 09:05PM by dalmoz
via reddit https://ift.tt/7tMuU3J
Apiiro | Secure your development and delivery to the cloud
Apiiro’s AI engine detected a software supply chain attack in PyPI
The Apiiro AI engine discovered a malicious Python package that is currently presented on the python PyPI package management portal.
Firewalls under the hood - UFW
https://ift.tt/iFPdK6S
Submitted December 08, 2022 at 04:02AM by doitsukara
via reddit https://ift.tt/5DTfyxH
https://ift.tt/iFPdK6S
Submitted December 08, 2022 at 04:02AM by doitsukara
via reddit https://ift.tt/5DTfyxH
blog.kanbach.org
Firewalls under the hood - UFW
IT-Security and stuff - Firewalls under the hood - UFW
GitHub - klezVirus/SilentMoonwalk: PoC Implementation of a TRUE call stack spoofer
https://ift.tt/l3mOZoa
Submitted December 08, 2022 at 03:24PM by R3dCr0wn
via reddit https://ift.tt/gvCJrlj
https://ift.tt/l3mOZoa
Submitted December 08, 2022 at 03:24PM by R3dCr0wn
via reddit https://ift.tt/gvCJrlj
GitHub
GitHub - klezVirus/SilentMoonwalk: PoC Implementation of a fully dynamic call stack spoofer
PoC Implementation of a fully dynamic call stack spoofer - GitHub - klezVirus/SilentMoonwalk: PoC Implementation of a fully dynamic call stack spoofer
Shoggoth
https://ift.tt/iM4gyEA
Submitted December 08, 2022 at 06:30PM by DarkGrejuva
via reddit https://ift.tt/SXavVkh
https://ift.tt/iM4gyEA
Submitted December 08, 2022 at 06:30PM by DarkGrejuva
via reddit https://ift.tt/SXavVkh
GitHub
GitHub - frkngksl/Shoggoth: Shoggoth: Asmjit Based Polymorphic Encryptor
Shoggoth: Asmjit Based Polymorphic Encryptor. Contribute to frkngksl/Shoggoth development by creating an account on GitHub.
cli google search client written by chatgpt ai - bypasses captcha and rate limiting
https://ift.tt/IyY3E5e
Submitted December 08, 2022 at 07:59PM by endless
via reddit https://ift.tt/pgSm7qt
https://ift.tt/IyY3E5e
Submitted December 08, 2022 at 07:59PM by endless
via reddit https://ift.tt/pgSm7qt
GitHub
GitHub - visualbasic6/search: a cli google client written by ai (chatgpt) that bypasses captcha and rate limiting by using the…
a cli google client written by ai (chatgpt) that bypasses captcha and rate limiting by using the google alert's "preview" feature - GitHub - visualbasic6/search: a cli goo...
How to secure your Open Source Project – A quick guide for developers
https://ift.tt/JuLsBlx
Submitted December 08, 2022 at 09:18PM by TupleType1
via reddit https://ift.tt/XJgksaR
https://ift.tt/JuLsBlx
Submitted December 08, 2022 at 09:18PM by TupleType1
via reddit https://ift.tt/XJgksaR
Cider Security Site
“How to secure your Open Source Project - A quick guide for developers”.
Check out our latest blog post: “How to secure your Open Source Project - A quick guide for developers”. This post provides valuable guidance on how to ensure the security of your open source project. We will be sharing some practical tips and best practices…
Using JSON in a New Generic Web Application Firewall Bypass
https://ift.tt/kPq3jwl
Submitted December 08, 2022 at 09:04PM by derp6996
via reddit https://ift.tt/SFXomdE
https://ift.tt/kPq3jwl
Submitted December 08, 2022 at 09:04PM by derp6996
via reddit https://ift.tt/SFXomdE
Claroty
{JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF
Team82 developed a generic web application firewall bypass that exploits a lack of JSON syntax support in leading vendors' SQL injection inspection process.
Fuzzing Golang msgpack for fun and panic
https://ift.tt/1d65yBS
Submitted December 09, 2022 at 12:44AM by Schwag
via reddit https://ift.tt/wzn51fx
https://ift.tt/1d65yBS
Submitted December 09, 2022 at 12:44AM by Schwag
via reddit https://ift.tt/wzn51fx
Red Canary
Fuzzing Golang msgpack for fun and panic - Red Canary
How the Red Canary Product Security Team found a vulnerability in a Go programming language MessagePack implementation.
Hacking the Furbo Dog Camera: Part III
https://ift.tt/Lt4OqH7
Submitted December 09, 2022 at 02:29AM by somersetrecon
via reddit https://ift.tt/1RVGUd7
https://ift.tt/Lt4OqH7
Submitted December 09, 2022 at 02:29AM by somersetrecon
via reddit https://ift.tt/1RVGUd7
Somerset Recon
Hacking the Furbo Dog Camera: Part III Fun with Firmware — Somerset Recon
We’re back with another entry in our Furbo hacking escapade! In our last post we mentioned we were taking a look at the then recently released Furbo Mini device and we are finally getting around to writing about what we found. Background Some time in the…
Nosey Parker: a new scanner to find misplaced secrets in textual data and Git history
https://ift.tt/slWOh4w
Submitted December 09, 2022 at 04:07AM by exploding_nun
via reddit https://ift.tt/rHx2E04
https://ift.tt/slWOh4w
Submitted December 09, 2022 at 04:07AM by exploding_nun
via reddit https://ift.tt/rHx2E04
GitHub
GitHub - praetorian-inc/noseyparker: Nosey Parker is a command-line program that finds secrets and sensitive information in textual…
Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history. - GitHub - praetorian-inc/noseyparker: Nosey Parker is a command-line program th...
Hooking System Calls in Windows 11 22H2 like Avast Antivirus. Research, analysis and bypass
https://ift.tt/DxvurjH
Submitted December 09, 2022 at 07:28AM by Gallus
via reddit https://ift.tt/a4kHtQI
https://ift.tt/DxvurjH
Submitted December 09, 2022 at 07:28AM by Gallus
via reddit https://ift.tt/a4kHtQI
the-deniss.github.io
Hooking System Calls in Windows 11 22H2 like Avast Antivirus. Research, analysis and bypass
0x00: Introduction
Using ChatGPT to Generate Phishing Campaigns
https://ift.tt/jg86Dzk
Submitted December 09, 2022 at 08:32AM by rickyrockslide
via reddit https://ift.tt/cNmWALR
https://ift.tt/jg86Dzk
Submitted December 09, 2022 at 08:32AM by rickyrockslide
via reddit https://ift.tt/cNmWALR
Richardosgood
Using OpenAI Chat to Generate Phishing Campaigns
Generating phishing campaigns with OpenAI Chat and GPT-3