OSV-Scanner: A vulnerability scanner written in Go which uses the data provided by OSV.dev
https://ift.tt/ly82KCe
Submitted December 20, 2022 at 02:21PM by Titokhan
via reddit https://ift.tt/l8HBtYU
https://ift.tt/ly82KCe
Submitted December 20, 2022 at 02:21PM by Titokhan
via reddit https://ift.tt/l8HBtYU
GitHub
GitHub - google/osv-scanner: Vulnerability scanner written in Go which uses the data provided by https://osv.dev
Vulnerability scanner written in Go which uses the data provided by https://osv.dev - GitHub - google/osv-scanner: Vulnerability scanner written in Go which uses the data provided by https://osv.dev
Bypass iOS backup's TCC protection
https://ift.tt/Fn31eqd
Submitted December 20, 2022 at 11:28PM by surrealisticpillow12
via reddit https://ift.tt/bP5iuhU
https://ift.tt/Fn31eqd
Submitted December 20, 2022 at 11:28PM by surrealisticpillow12
via reddit https://ift.tt/bP5iuhU
theevilbit.github.io
CVE-2022-32929 - Bypass iOS backup's TCC protection
Intro Normally, when a users backup their iOS device, the backup is saved into ~/Library/Application Support/MobileSync/Backup directory. The MobileSync directory is properly protected by TCC, as the backup can contain photos, contact information, everything…
Using Leaking Sentinel Value to Bypass the Latest Chrome v8 HardenProtect
https://ift.tt/c7vTymG
Submitted December 20, 2022 at 11:24PM by surrealisticpillow12
via reddit https://ift.tt/JsM0GKv
https://ift.tt/c7vTymG
Submitted December 20, 2022 at 11:24PM by surrealisticpillow12
via reddit https://ift.tt/JsM0GKv
Medium
Using Leaking Sentinel Value to Bypass the Latest Chrome v8 HardenProtect
A technical analysis where we use sentinel value to bypass the Latest Chrome v8 HardenProtect
Validating Okta Access Tokens in Python with PyJWT
https://ift.tt/o3egBH5
Submitted December 21, 2022 at 02:03AM by csanders_
via reddit https://ift.tt/cmrVxK6
https://ift.tt/o3egBH5
Submitted December 21, 2022 at 02:03AM by csanders_
via reddit https://ift.tt/cmrVxK6
Medium
Validating Okta Access Tokens in Python with PyJWT
Every week, almost without fail, I come across one thing that confuses, entertains, or most commonly infuriates me. I’ve decided to keep a…
New Chaes campaign uses Windows Management Instrumentation Command-Line Utility
https://ift.tt/R3FXlf9
Submitted December 21, 2022 at 05:07AM by PENGUINPLOW
via reddit https://ift.tt/x1RFSEw
https://ift.tt/R3FXlf9
Submitted December 21, 2022 at 05:07AM by PENGUINPLOW
via reddit https://ift.tt/x1RFSEw
sidechannel.blog
New Chaes campaign uses Windows Management Instrumentation Command-Line Utility | SideChannel – Tempest
Exploring the depths of Istio: A researcher's guide to analyzing a caching vulnerability
https://ift.tt/smxYTeD
Submitted December 21, 2022 at 11:28AM by jat0369
via reddit https://ift.tt/g9u4G2J
https://ift.tt/smxYTeD
Submitted December 21, 2022 at 11:28AM by jat0369
via reddit https://ift.tt/g9u4G2J
Cyberark
What I Learned from Analyzing a Caching Vulnerability in Istio
TL;DR Istio is an open-source service mash that can layer over applications. Studying CVE-2021-34824 in Istio will allow us to dive into some concepts of Istio and service meshes in general. We...
Cisco BroadWorks CommPilot Application Software Authenticated Remote Code Execution (CVE-2022-20958)
https://ift.tt/CQtm93e
Submitted December 21, 2022 at 04:41PM by smaury
via reddit https://ift.tt/lT2CBH5
https://ift.tt/CQtm93e
Submitted December 21, 2022 at 04:41PM by smaury
via reddit https://ift.tt/lT2CBH5
Shielder
Shielder - Cisco BroadWorks CommPilot Application Software Authenticated Remote Code Execution (CVE-2022-20958)
CVE-2022-20958: Cisco BroadWorks CommPilot Application allows authenticated users to upload configuration files on the platform. The lack of file validation and a broken access control on the vulnerable upload serverlet allows any authenticated user to upload…
Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951)
https://ift.tt/OAzwT6u
Submitted December 21, 2022 at 04:40PM by smaury
via reddit https://ift.tt/L59OyzW
https://ift.tt/OAzwT6u
Submitted December 21, 2022 at 04:40PM by smaury
via reddit https://ift.tt/L59OyzW
Shielder
Shielder - Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951)
CVE-2022-20951: Cisco BroadWorks CommPilot Application exposes a servlet that allows the application to be used as an HTTP proxy server. The lack of validation of the the target URL and the lack of authentication protection allows an unauthenticated attacker…
DirtyCred Remastered: UAF to LPE (CVE-2022-2602)
https://ift.tt/YbP6cLo
Submitted December 21, 2022 at 07:45PM by Void_Sec
via reddit https://ift.tt/dtVc6i1
https://ift.tt/YbP6cLo
Submitted December 21, 2022 at 07:45PM by Void_Sec
via reddit https://ift.tt/dtVc6i1
LukeGix
DirtyCred Remastered
DirtyCred Remastered: how to turn an UAF into Privilege Escalation
A journey into IoT - Unknown Chinese alarm - Part 4 - Internal communications
https://ift.tt/ot28baN
Submitted December 21, 2022 at 08:32PM by 0xdea
via reddit https://ift.tt/mGDvXC2
https://ift.tt/ot28baN
Submitted December 21, 2022 at 08:32PM by 0xdea
via reddit https://ift.tt/mGDvXC2
hn security
A journey into IoT - Unknown Chinese alarm - Part 4 - Internal communications - hn security
Disclaimer: as many other security researchers […]
Deconstructing and Exploiting CVE-2020-6418
https://ift.tt/zvYZpHL
Submitted December 21, 2022 at 07:56PM by surrealisticpillow12
via reddit https://ift.tt/I0Ri9OG
https://ift.tt/zvYZpHL
Submitted December 21, 2022 at 07:56PM by surrealisticpillow12
via reddit https://ift.tt/I0Ri9OG
STAR Labs
Deconstructing and Exploiting CVE-2020-6418
As part of my internship at STAR Labs, I conducted n-day analysis of CVE-2020-6418. This vulnerability lies in the V8 engine of Google Chrome, namely its optimizing compiler Turbofan. Specifically, the vulnerable version is in Google Chrome’s V8 prior to…
Puckungfu: A NETGEAR WAN Command Injection
https://ift.tt/8pYDvB4
Submitted December 22, 2022 at 05:02PM by ArbitraryWrite
via reddit https://ift.tt/paMGtRe
https://ift.tt/8pYDvB4
Submitted December 22, 2022 at 05:02PM by ArbitraryWrite
via reddit https://ift.tt/paMGtRe
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
GLPI Exploitation Timeline
https://ift.tt/gNnY2aJ
Submitted December 22, 2022 at 07:15PM by chicksdigthelongrun
via reddit https://ift.tt/L7S3jqX
https://ift.tt/gNnY2aJ
Submitted December 22, 2022 at 07:15PM by chicksdigthelongrun
via reddit https://ift.tt/L7S3jqX
GLPI Exploitation Timeline - Blog - VulnCheck
Taking a look at the timeline leading up to exploitation of CVE-2022-35914 and the current state of attacks in the wild.
Cross-tenant network bypass in Azure Cognitive Search
https://ift.tt/IYmxw2V
Submitted December 22, 2022 at 08:20PM by FrankTr3nd
via reddit https://ift.tt/GLKhmgf
https://ift.tt/IYmxw2V
Submitted December 22, 2022 at 08:20PM by FrankTr3nd
via reddit https://ift.tt/GLKhmgf
Mnemonic
ACSESSED: Cross-tenant network bypass in Azure Cognitive Search
How enabling a single vulnerable feature removed the entire network and identity perimeter around internet-isolated Azure Cognitive Search instances.
[x-post from blueteamsec] I started a newsletter that aggregates Detection Engineering news and techniques. Here’s the latest Issue. Let me know what you think!
https://ift.tt/73JQdeI
Submitted December 22, 2022 at 10:44PM by dudeimawizard
via reddit https://ift.tt/n7mVWIz
https://ift.tt/73JQdeI
Submitted December 22, 2022 at 10:44PM by dudeimawizard
via reddit https://ift.tt/n7mVWIz
Detection Engineering
Detection Engineering Weekly - Issue 4
Last week's news and how-tos in the art and science of Detection Engineering
Attack of the clones - Stealthy Kubernetes persistence with eathar, tòcan and teisteanas
https://ift.tt/fHaLeou
Submitted December 23, 2022 at 01:12AM by raesene2
via reddit https://ift.tt/bBV4RvO
https://ift.tt/fHaLeou
Submitted December 23, 2022 at 01:12AM by raesene2
via reddit https://ift.tt/bBV4RvO
raesene.github.io
Attack of the clones - Stealthy Kubernetes persistence with eathar, tòcan and teisteanas
Lastpass Security Incident - December 22 update
https://ift.tt/4U5Ku1y
Submitted December 23, 2022 at 02:04AM by tkokilroy
via reddit https://ift.tt/gvWwfaU
https://ift.tt/4U5Ku1y
Submitted December 23, 2022 at 02:04AM by tkokilroy
via reddit https://ift.tt/gvWwfaU
The LastPass Blog
Notice of Recent Security Incident - The LastPass Blog
We are working diligently to understand the scope of the incident and identify what specific information has been accessed.
[Hiring] InfoSec Assurance Roles in USA and Europe
https://ift.tt/6Oxy8zY
Submitted December 23, 2022 at 04:01AM by RecruitingAdmin
via reddit https://ift.tt/402rYbd
https://ift.tt/6Oxy8zY
Submitted December 23, 2022 at 04:01AM by RecruitingAdmin
via reddit https://ift.tt/402rYbd
boards.greenhouse.io
Laika
Laika helps companies manage compliance, obtain security certifications, and build trust with enterprise customers.
Introducing the Columbus Project
https://ift.tt/X0lBYgv
Submitted December 23, 2022 at 01:08PM by g0rbe
via reddit https://ift.tt/oDn712q
https://ift.tt/X0lBYgv
Submitted December 23, 2022 at 01:08PM by g0rbe
via reddit https://ift.tt/oDn712q
Elmasy Blog
Introducing the Columbus Project
An open source append only database of known subdomains to discover, store and serve subdomains as fast as possible.
PyRDP 1.2.0 released – Can perform Net-NTLM hash capture before the certificate error on RDP
https://ift.tt/T2P9WAn
Submitted December 23, 2022 at 11:36PM by obilodeau
via reddit https://ift.tt/UimejZM
https://ift.tt/T2P9WAn
Submitted December 23, 2022 at 11:36PM by obilodeau
via reddit https://ift.tt/UimejZM
GoSecure
A New PyRDP Release: The Rudolph Desktop Protocol! - GoSecure
Isn’t there a better moment than the Holiday season to release a major update of our RDP Attack and Eavesdropping tool PyRDP? That’s right, pour yourself a little glass of eggnog, sit in a comfortable chair, put on some Christmas music and read about the…
Linux kernel module generator for Hidden firewall that follows the rules in the external YAML file.
https://ift.tt/DU1J6XY
Submitted December 24, 2022 at 11:46AM by CoolerVoid
via reddit https://ift.tt/Lhk1BFO
https://ift.tt/DU1J6XY
Submitted December 24, 2022 at 11:46AM by CoolerVoid
via reddit https://ift.tt/Lhk1BFO