Ongoing Typosquatting Campaign Publishing Malware to PyPI
https://ift.tt/HbcD5kz
Submitted December 09, 2022 at 10:50PM by louis11
via reddit https://ift.tt/GmzIv7y
https://ift.tt/HbcD5kz
Submitted December 09, 2022 at 10:50PM by louis11
via reddit https://ift.tt/GmzIv7y
blog.phylum.io
Phylum Detects Ongoing Typosquatting Campaign in PyPI
Eleven malicious packages that download known malicious binaries published today, with more expected in the coming hours.
Polar: debugging on LLDB using OpenAI's davinci-003 language model - @ant4g0nist
https://ift.tt/Nh9Sd4k
Submitted December 10, 2022 at 06:31AM by ant4g0nist
via reddit https://ift.tt/DYqcBxP
https://ift.tt/Nh9Sd4k
Submitted December 10, 2022 at 06:31AM by ant4g0nist
via reddit https://ift.tt/DYqcBxP
GitHub
GitHub - ant4g0nist/polar: A LLDB plugin which queries OpenAI's davinci-003 language model to explain the disassembly
A LLDB plugin which queries OpenAI's davinci-003 language model to explain the disassembly - GitHub - ant4g0nist/polar: A LLDB plugin which queries OpenAI's davinci-003 language mod...
Nebuchadnezzar - Practically-exploitable Cryptographic Vulnerabilities in Matrix
https://ift.tt/vth2OaY
Submitted December 10, 2022 at 02:26PM by Gallus
via reddit https://ift.tt/a8oWiFL
https://ift.tt/vth2OaY
Submitted December 10, 2022 at 02:26PM by Gallus
via reddit https://ift.tt/a8oWiFL
Mobile Bug Bounty Hunting? Enter BLE – Cybervelia
https://ift.tt/9wS1d6p
Submitted December 10, 2022 at 02:14PM by Necessary-Reality-80
via reddit https://ift.tt/6PsL5pJ
https://ift.tt/9wS1d6p
Submitted December 10, 2022 at 02:14PM by Necessary-Reality-80
via reddit https://ift.tt/6PsL5pJ
Fuzzing ping(8)…and finding a 24 year old bug
https://ift.tt/z5ORFPV
Submitted December 11, 2022 at 09:57AM by Gallus
via reddit https://ift.tt/kyRpCqZ
https://ift.tt/z5ORFPV
Submitted December 11, 2022 at 09:57AM by Gallus
via reddit https://ift.tt/kyRpCqZ
Detecting heap memory pitfalls
https://ift.tt/yJ2phEr
Submitted December 11, 2022 at 10:00PM by CoolerVoid
via reddit https://ift.tt/maudUpx
https://ift.tt/yJ2phEr
Submitted December 11, 2022 at 10:00PM by CoolerVoid
via reddit https://ift.tt/maudUpx
antonio-cooler.gitbook.io
Detecting heap memory pitfalls | CoolerVoid tavern
Step by step and using custom taint analysis to detect heap security issues
IATelligence is a Python noscript that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix related
https://ift.tt/p7ZCXM3
Submitted December 12, 2022 at 10:07AM by boutnaru
via reddit https://ift.tt/vpJqA63
https://ift.tt/p7ZCXM3
Submitted December 12, 2022 at 10:07AM by boutnaru
via reddit https://ift.tt/vpJqA63
GitHub
GitHub - fr0gger/IATelligence: IATelligence is a Python noscript that will extract the IAT of a PE file and request GPT to get more…
IATelligence is a Python noscript that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix related - GitHub - fr0gger/IATelligence: I...
Finding JIT Optimizer Bugs using SMT Solvers and Fuzzing
https://ift.tt/lA02aFZ
Submitted December 12, 2022 at 06:17PM by surrealisticpillow12
via reddit https://ift.tt/qr86XEw
https://ift.tt/lA02aFZ
Submitted December 12, 2022 at 06:17PM by surrealisticpillow12
via reddit https://ift.tt/qr86XEw
PyPy
Finding JIT Optimizer Bugs using SMT Solvers and Fuzzing
In this blog post I want to describe a recent bug finding technique that I've
added to the PyPy JIT testing infrastructure. This technique uses the Z3
theorem prover to find bugs in the optimizer of P
added to the PyPy JIT testing infrastructure. This technique uses the Z3
theorem prover to find bugs in the optimizer of P
Precious Gemstones: The New Generation of Kerberos Attacks
https://ift.tt/g4OoTv8
Submitted December 13, 2022 at 11:47AM by 0xdea
via reddit https://ift.tt/fG62uxn
https://ift.tt/g4OoTv8
Submitted December 13, 2022 at 11:47AM by 0xdea
via reddit https://ift.tt/fG62uxn
Unit 42
Precious Gemstones: The New Generation of Kerberos Attacks
Unit 42 researchers show new methods to improve detection of a next-gen line of Kerberos attacks, which allow attackers to modify Kerberos tickets to maintain privileged access.
An Open Source tool for Fixing the Accidental Public GitHub Repo
https://ift.tt/PN97OuX
Submitted December 13, 2022 at 01:31PM by amirshk
via reddit https://ift.tt/W6Tzetm
https://ift.tt/PN97OuX
Submitted December 13, 2022 at 01:31PM by amirshk
via reddit https://ift.tt/W6Tzetm
Medium
Exposed Repository: Fixing the Accidental Public GitHub Repo
TL;DR The open-source GitHub App https://github.com/PerimeterX/gitapp_alert_on_public
Pass The eWPT Exam on Your First Attempt Using Free Resources!
https://ift.tt/fJ3dV0Z
Submitted December 13, 2022 at 02:11PM by grumpzsux
via reddit https://ift.tt/MOqA8Du
https://ift.tt/fJ3dV0Z
Submitted December 13, 2022 at 02:11PM by grumpzsux
via reddit https://ift.tt/MOqA8Du
Wannabe Bug Bounty Hunter.
Pass the eWPT Exam in 2023 Using Free Resources
Pass the eWPT Exam by eLearnSecurity in 2023 using only free resources, on your first attempt. Use the same resources I used to be successful.
Exploiting CVE-2022-42703 - Bringing back the stack attack
https://ift.tt/BaGFQVl
Submitted December 13, 2022 at 09:35AM by boutnaru
via reddit https://ift.tt/LMedT5D
https://ift.tt/BaGFQVl
Submitted December 13, 2022 at 09:35AM by boutnaru
via reddit https://ift.tt/LMedT5D
Blogspot
Exploiting CVE-2022-42703 - Bringing back the stack attack
Seth Jenkins, Project Zero This blog post details an exploit for CVE-2022-42703 (P0 issue 2351 - Fixed 5 September 2022), a bug Jann Horn ...
A Server Side Request Forgery protection library for Golang
https://ift.tt/x0sLc4p
Submitted December 13, 2022 at 07:22PM by nibblesec
via reddit https://ift.tt/FgWa0VE
https://ift.tt/x0sLc4p
Submitted December 13, 2022 at 07:22PM by nibblesec
via reddit https://ift.tt/FgWa0VE
Doyensec
safeurl for Go · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Critical Citrix ADC Bug Exploited in the Wild
https://ift.tt/XQN5jGS
Submitted December 13, 2022 at 07:07PM by YogiBerra88888
via reddit https://ift.tt/NITJpLE
https://ift.tt/XQN5jGS
Submitted December 13, 2022 at 07:07PM by YogiBerra88888
via reddit https://ift.tt/NITJpLE
Citrix Blogs
Released: Citrix ADC and Citrix Gateway (security bulletin CTX474995) security update | Citrix Blogs
Learn about security updates for versions 12.1 (including FIPS and NDcPP) and 13.0 before 13.0-58.32 of Citrix ADC and Citrix Gateway and get fixes for both (security bulletin CTX474995).
A Deep Dive into BianLian Ransomware [PDF]
https://ift.tt/2ePO0bz
Submitted December 13, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/JochqWx
https://ift.tt/2ePO0bz
Submitted December 13, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/JochqWx
SecurityScorecard
Resources
Explore cybersecurity white papers, data sheets, webinars, videos, informative blogs, and more with SecurityScorecard.
AWS ECR Public Vulnerability
https://ift.tt/9voLzjP
Submitted December 13, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/V937Wt4
https://ift.tt/9voLzjP
Submitted December 13, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/V937Wt4
blog.lightspin.io
AWS ECR Public Vulnerability
Let's go over a critical AWS Elastic Container Registry Public (ECR Public) vulnerability that allowed external actors to delete, update, and create ECR Public images, layers, and tags in registries and repositories that belong to other AWS Accounts, by abusing…
Sandworm.JS - dynamically analyses over 2M javanoscript packages to offer zero day, real time protection against malicious noscripts.
https://sandworm.dev
Submitted December 14, 2022 at 12:32AM by sculabobone
via reddit https://ift.tt/T0bQuHW
https://sandworm.dev
Submitted December 14, 2022 at 12:32AM by sculabobone
via reddit https://ift.tt/T0bQuHW
Reddit
r/netsec - Sandworm.JS - dynamically analyses over 2M javanoscript packages to offer zero day, real time protection against malicious…
73 votes and 4 comments so far on Reddit
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK.
https://ift.tt/1EvINpU
Submitted December 14, 2022 at 03:45AM by FipoKa
via reddit https://ift.tt/Zw5ltkj
https://ift.tt/1EvINpU
Submitted December 14, 2022 at 03:45AM by FipoKa
via reddit https://ift.tt/Zw5ltkj
GitHub
GitHub - ax/apk.sh: apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding…
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK. - GitHub - ax/apk.sh: apk.sh makes reverse engineering...
breaking chatgpt's "woke filter"
https://ift.tt/TB0OxVz
Submitted December 14, 2022 at 07:42AM by endless
via reddit https://ift.tt/HvmEqIc
https://ift.tt/TB0OxVz
Submitted December 14, 2022 at 07:42AM by endless
via reddit https://ift.tt/HvmEqIc
Livejournal
breaking chatgpt's woke filter
so i had to crack my way into public information, controversial topics and statistics on chatgpt. if you haven't noticed, there's a woke filter. while chatgpt claims to be programmatically incapable of political correctness, that is not the case at all. but…
Vulnerabilities found on Arcadyan Routers
https://ift.tt/GyPC4JS
Submitted December 14, 2022 at 08:37AM by asherdl02
via reddit https://ift.tt/OYLatGz
https://ift.tt/GyPC4JS
Submitted December 14, 2022 at 08:37AM by asherdl02
via reddit https://ift.tt/OYLatGz
Gist
Vulnerabilities found on Arcadyan Routers - Asher Davila L.
Vulnerabilities found on Arcadyan Routers - Asher Davila L. - Arcadyan Vulnerabilities.md
Coercer: A python noscript to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
https://ift.tt/bZzH1tg
Submitted December 14, 2022 at 01:29PM by boutnaru
via reddit https://ift.tt/kjEHq1p
https://ift.tt/bZzH1tg
Submitted December 14, 2022 at 01:29PM by boutnaru
via reddit https://ift.tt/kjEHq1p
GitHub
GitHub - p0dalirius/Coercer: A python noscript to automatically coerce a Windows server to authenticate on an arbitrary machine through…
A python noscript to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods. - GitHub - p0dalirius/Coercer: A python noscript to automatically coerce a Windows...