The Mac Malware of 2022
https://ift.tt/sE621yq
Submitted January 06, 2023 at 07:04PM by KolideKenny
via reddit https://ift.tt/735XPku
https://ift.tt/sE621yq
Submitted January 06, 2023 at 07:04PM by KolideKenny
via reddit https://ift.tt/735XPku
objective-see.org
The Mac Malware of 2022 👾
A comprehensive analysis of the year's new malware
How the Lastpass Breach affects Lastpass SSO
https://ift.tt/3IDCOKf
Submitted January 06, 2023 at 09:46PM by csanders_
via reddit https://ift.tt/bsEaMnF
https://ift.tt/3IDCOKf
Submitted January 06, 2023 at 09:46PM by csanders_
via reddit https://ift.tt/bsEaMnF
Medium
How the Lastpass Breach affects Lastpass SSO
Every week, almost without fail, I come across one thing that confuses, entertains, or most commonly infuriates me. I’ve decided to keep a…
Fetch Diversion
https://ift.tt/8laehMU
Submitted January 06, 2023 at 09:34PM by albinowax
via reddit https://ift.tt/jcoQOyP
https://ift.tt/8laehMU
Submitted January 06, 2023 at 09:34PM by albinowax
via reddit https://ift.tt/jcoQOyP
acut3
Fetch Diversion
API calls and requests for resources can sometimes be diverted toward a different endpoint on the same host, potentially resulting in DOM XSS’s that would otherwise be impossible to trigger, or other types of client-side vulnerabilities.
Latest activity from Turla {Mandiant}
https://ift.tt/h1In7OR
Submitted January 06, 2023 at 10:41PM by EspoJ
via reddit https://ift.tt/YikbEHa
https://ift.tt/h1In7OR
Submitted January 06, 2023 at 10:41PM by EspoJ
via reddit https://ift.tt/YikbEHa
Mandiant
Turla: A Galaxy of Opportunity | Mandiant
TruffleHog Now Scans CircleCI log outputs for passwords/credentials
https://ift.tt/zyndq5R
Submitted January 07, 2023 at 12:32AM by wifihack
via reddit https://ift.tt/7aisS1t
https://ift.tt/zyndq5R
Submitted January 07, 2023 at 12:32AM by wifihack
via reddit https://ift.tt/7aisS1t
Truffle Security
TruffleHog Now Scans CircleCI Build Logs - Truffle Security
TruffleHog Open Source now scans CircleCI log outputs for passwords, API keys, and other forms of credentials
udon: A simple tool that helps to find assets/domains based on the Google Analytics ID.
https://ift.tt/tCQa4JM
Submitted January 07, 2023 at 12:26AM by BananaBounty
via reddit https://ift.tt/jBbEIYq
https://ift.tt/tCQa4JM
Submitted January 07, 2023 at 12:26AM by BananaBounty
via reddit https://ift.tt/jBbEIYq
GitHub
GitHub - dhn/udon: A simple tool that helps to find assets/domains based on the Google Analytics ID.
A simple tool that helps to find assets/domains based on the Google Analytics ID. - GitHub - dhn/udon: A simple tool that helps to find assets/domains based on the Google Analytics ID.
I scanned every package on PyPi and found 57 live AWS keys
https://ift.tt/ZkdpS7h
Submitted January 07, 2023 at 12:22AM by Most-Loss5834
via reddit https://ift.tt/SqG6eVt
https://ift.tt/ZkdpS7h
Submitted January 07, 2023 at 12:22AM by Most-Loss5834
via reddit https://ift.tt/SqG6eVt
tomforb.es
I scanned every package on PyPi and found 57 live AWS keys
After inadvertently finding that InfoSys leaked an AWS key on PyPi I wanted to know how many other live AWS keys may be present on Python package index. After scanning every release published to PyPi I found 57 valid access keys from organisations like:
Amazon…
Amazon…
I made an Open Source Browser extension to aid in Threat Investigations!
https://ift.tt/1EdYyuh
Submitted January 07, 2023 at 03:59AM by zack7601
via reddit https://ift.tt/ThD4Rde
https://ift.tt/1EdYyuh
Submitted January 07, 2023 at 03:59AM by zack7601
via reddit https://ift.tt/ThD4Rde
GitHub
GitHub - zdhenard42/SOC-Multitool: A powerful and user-friendly browser extension that streamlines investigations for security…
A powerful and user-friendly browser extension that streamlines investigations for security professionals. - GitHub - zdhenard42/SOC-Multitool: A powerful and user-friendly browser extension that s...
Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys
https://ift.tt/q5jRlP0
Submitted January 07, 2023 at 10:03AM by Gallus
via reddit https://ift.tt/7zo1Vy8
https://ift.tt/q5jRlP0
Submitted January 07, 2023 at 10:03AM by Gallus
via reddit https://ift.tt/7zo1Vy8
All Things Security
Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys
Intercepting and Manipulating client-side AES encrypted traffic in mobile applications having hardcoded Key and IV
Setting up your bug bounty noscripts with Python and Bash — The subdomain monitoring bot
https://ift.tt/pbD0Iwc
Submitted January 07, 2023 at 01:29PM by Plenty-Mix-2
via reddit https://ift.tt/tMJsHuy
https://ift.tt/pbD0Iwc
Submitted January 07, 2023 at 01:29PM by Plenty-Mix-2
via reddit https://ift.tt/tMJsHuy
Codelivly
Setting up your bug bounty noscripts with Python and Bash — The subdomain monitoring bot – Codelivly
Bug bounty programs have become increasingly popular in recent years, with companies offering rewards to hackers and security researchers who can find vulnerabilities in their systems. While there are many tools available to help with bug hunting, writing…
Reflections on Trusting VEX (or when humans can improve SBOMs)
https://ift.tt/gc8yisM
Submitted January 07, 2023 at 05:49PM by dlorenc
via reddit https://ift.tt/L3q4jpJ
https://ift.tt/gc8yisM
Submitted January 07, 2023 at 05:49PM by dlorenc
via reddit https://ift.tt/L3q4jpJ
www.chainguard.dev
Reflections on Trusting VEX (or when humans can improve SBOMs)
Everything you need to know about securing the software supply chain.
connmap now works with all DE/WM! Desktop widget that shows location of your current TCP peers on a world map in real-time.
https://ift.tt/oGFK4M3
Submitted January 07, 2023 at 07:52PM by jafarlihi
via reddit https://ift.tt/s8wlYM1
https://ift.tt/oGFK4M3
Submitted January 07, 2023 at 07:52PM by jafarlihi
via reddit https://ift.tt/s8wlYM1
GitHub
GitHub - jafarlihi/connmap: connmap is an X11 desktop widget that shows location of your current network peers on a world map
connmap is an X11 desktop widget that shows location of your current network peers on a world map - GitHub - jafarlihi/connmap: connmap is an X11 desktop widget that shows location of your current ...
Awesome Intelligence - A good collection of great OpenSource Intelligence (OSINT) Resources
https://ift.tt/xCEfGM6
Submitted January 07, 2023 at 09:26PM by glatisantbeast
via reddit https://ift.tt/I6bQu9h
https://ift.tt/xCEfGM6
Submitted January 07, 2023 at 09:26PM by glatisantbeast
via reddit https://ift.tt/I6bQu9h
GitHub
GitHub - ARPSyndicate/awesome-intelligence: A collaboratively curated list of awesome Open-Source Intelligence (OSINT) Resources
A collaboratively curated list of awesome Open-Source Intelligence (OSINT) Resources - GitHub - ARPSyndicate/awesome-intelligence: A collaboratively curated list of awesome Open-Source Intelligence...
VSCode Supply Chain Attacks: Protect Your IDE from Malicious Extensions
https://ift.tt/icP2UQx
Submitted January 08, 2023 at 01:02AM by gfdgfbal
via reddit https://ift.tt/9w2jEbq
https://ift.tt/icP2UQx
Submitted January 08, 2023 at 01:02AM by gfdgfbal
via reddit https://ift.tt/9w2jEbq
Aquasec
Can You Trust Your VSCode Extensions?
Aqua Nautilus breaks down how VSCode extensions can easily be impersonated by attackers who hide malicious code through tactics like typosquatting
GUARDARA 0.9.9 Available with Web Service Testing
https://ift.tt/srufEQq
Submitted January 08, 2023 at 03:16AM by JohnKeymanUK
via reddit https://ift.tt/bYcqw72
https://ift.tt/srufEQq
Submitted January 08, 2023 at 03:16AM by JohnKeymanUK
via reddit https://ift.tt/bYcqw72
guardara-community.gitlab.io
Releases | Build secure, rock-solid software
Version 0.9.9
Analyzing CVE-2022-46630 (DLL Hijacking in Squirrel.Windows)
https://ift.tt/I2uh5OP
Submitted January 08, 2023 at 09:08PM by DLLCoolJ
via reddit https://ift.tt/rmLJtM3
https://ift.tt/I2uh5OP
Submitted January 08, 2023 at 09:08PM by DLLCoolJ
via reddit https://ift.tt/rmLJtM3
Archcloudlabs
Analyzing CVE-2022-46630 (DLL Hijacking in Squirrel.Windows)
About The Project In December of 2022, a DLL Hijacking vulnerability with a CVSS score of 7.8 was reported in the Squirrel.Windows auto-install/update utility. This blog post will analyze the vulnerability, and analyze the root cause of said issue with procmon.…
Strategies for effective CSRF mitigation
https://ift.tt/IFKrYdB
Submitted January 08, 2023 at 08:56PM by DeliveryTypical
via reddit https://ift.tt/PZfvS8I
https://ift.tt/IFKrYdB
Submitted January 08, 2023 at 08:56PM by DeliveryTypical
via reddit https://ift.tt/PZfvS8I
Exact Realty Blog
Effectively mitigating CSRF
Cross-Site Request Forgery (CSRF) consists of making unauthorised requests on behalf of a user. Effective protection is essential for access control.
Bring your own vulnerable driver to the exploit party: Understanding BYOVD Attacks
https://ift.tt/or06572
Submitted January 08, 2023 at 10:15PM by achilles4828
via reddit https://ift.tt/NIH7SEw
https://ift.tt/or06572
Submitted January 08, 2023 at 10:15PM by achilles4828
via reddit https://ift.tt/NIH7SEw
FourCore
Exploit Party: Bring Your Own Vulnerable Driver Attacks - FourCore
BYOVD or Bring Your Own Vulnerable Driver is an attack where a threat actor brings a legitimately signed and vulnerable driver to perform malicious actions on the system. In a BYOVD attack, the attacker can use the vulnerabilities in the driver to execute…
Interactive Risk Explorer for Understanding Software Supply Chain Attacks
https://ift.tt/YL6ieFq
Submitted January 09, 2023 at 12:40AM by ewok94301
via reddit https://ift.tt/ATeOLWR
https://ift.tt/YL6ieFq
Submitted January 09, 2023 at 12:40AM by ewok94301
via reddit https://ift.tt/ATeOLWR
Endorlabs
Risk Explorer for Software Supply Chains
A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and other resources. The taxonomy as well as related safeguards can be explored using an interactive visualization tool.
How To Attack Admin Panels Successfully Part 2
https://ift.tt/0Ky2DkZ
Submitted January 09, 2023 at 06:44AM by banginpadr
via reddit https://ift.tt/qQi7bFl
https://ift.tt/0Ky2DkZ
Submitted January 09, 2023 at 06:44AM by banginpadr
via reddit https://ift.tt/qQi7bFl
Medium
How To Attack Admin Panels Successfully Part 2
Not Attacking Web Apps Admin Panels The Right Way?
Massive list of news sources in the Security space
https://ift.tt/D0wMtl8
Submitted January 09, 2023 at 07:26AM by infosec-jobs
via reddit https://ift.tt/MIpRBN1
https://ift.tt/D0wMtl8
Submitted January 09, 2023 at 07:26AM by infosec-jobs
via reddit https://ift.tt/MIpRBN1
GitHub
allinfosecnews_sources/README.md at main · foorilla/allinfosecnews_sources
A list of online news & info sources in the InfoSec/Cybersecurity space - allinfosecnews_sources/README.md at main · foorilla/allinfosecnews_sources