The dark side of Gmail
https://ift.tt/uWyUZ3r
Submitted January 10, 2023 at 02:42AM by osint_matter
via reddit https://ift.tt/efkvxwc
https://ift.tt/uWyUZ3r
Submitted January 10, 2023 at 02:42AM by osint_matter
via reddit https://ift.tt/efkvxwc
osintmatter
The Dark Side of Gmail
Behind one of Gmail’s lesser-known features lies a potential threat to websites and platforms managers.
CircleCI Breach: Detect and Mitigate to Assure Readiness (Investigating AWS Access Keys)
https://ift.tt/3RJTLCs
Submitted January 10, 2023 at 01:35PM by Or1rez
via reddit https://ift.tt/z6M8EIQ
https://ift.tt/3RJTLCs
Submitted January 10, 2023 at 01:35PM by Or1rez
via reddit https://ift.tt/z6M8EIQ
Rezonate
CI/CD Breach: Detect & Mitigate to Assure Readiness | Rezonate
Detect and mitigate actions to assure readiness against a supply chain attack of your CICD Pipelines. Read more about it in Rezonate's blog here!
ImageMagick Security Policy Evaluator
https://ift.tt/QNghDT3
Submitted January 10, 2023 at 04:52PM by nibblesec
via reddit https://ift.tt/zgW85DB
https://ift.tt/QNghDT3
Submitted January 10, 2023 at 04:52PM by nibblesec
via reddit https://ift.tt/zgW85DB
Doyensec
ImageMagick Security Policy Evaluator
During our audits we occasionally stumble across ImageMagick security policy configuration files (policy.xml), useful for limiting the default behavior and the resources consumed by the library. In the wild, these files often contain a plethora of recommendations…
An electromagnetic-wave side-channel issue on ARMv8 AES instructions
https://ift.tt/IhmuJPT
Submitted January 10, 2023 at 05:21PM by Gallus
via reddit https://ift.tt/KTE31Sx
https://ift.tt/IhmuJPT
Submitted January 10, 2023 at 05:21PM by Gallus
via reddit https://ift.tt/KTE31Sx
How to Analyze JavaScript Malware – A Case Study of Vjw0rm
https://ift.tt/nfzYeVy
Submitted January 10, 2023 at 08:58PM by CyberMasterV
via reddit https://ift.tt/97CILiB
https://ift.tt/nfzYeVy
Submitted January 10, 2023 at 08:58PM by CyberMasterV
via reddit https://ift.tt/97CILiB
SecurityScorecard
Resources
Explore cybersecurity white papers, data sheets, webinars, videos, informative blogs, and more with SecurityScorecard.
Semgrep rules for Swift language (iOS mobile apps)
https://ift.tt/h62rjcS
Submitted January 10, 2023 at 11:12PM by brugmayq
via reddit https://ift.tt/rcOf6Ni
https://ift.tt/h62rjcS
Submitted January 10, 2023 at 11:12PM by brugmayq
via reddit https://ift.tt/rcOf6Ni
GitHub
GitHub - akabe1/akabe1-semgrep-rules: My collection of Semgrep rules for vulnerability detection on source code (swift, java)
My collection of Semgrep rules for vulnerability detection on source code (swift, java) - GitHub - akabe1/akabe1-semgrep-rules: My collection of Semgrep rules for vulnerability detection on source ...
Antivirus Evasion: Tearing AMSI down with 3 bytes only
https://ift.tt/kMY4CuL
Submitted January 11, 2023 at 02:51AM by juliocesarfort
via reddit https://ift.tt/LhRMPQj
https://ift.tt/kMY4CuL
Submitted January 11, 2023 at 02:51AM by juliocesarfort
via reddit https://ift.tt/LhRMPQj
Blaze Information Security
Antivirus Evasion: Tearing AMSI Down With 3 Bytes Only
This post aims on showcasing one of the many possible techniques for bypassing antivirus solutions through in-memory patching of AMSI instructions.
Taking over a Dead IoT Company
https://ift.tt/2GoPbpf
Submitted January 11, 2023 at 02:38AM by phree_radical
via reddit https://ift.tt/L6GMBgS
https://ift.tt/2GoPbpf
Submitted January 11, 2023 at 02:38AM by phree_radical
via reddit https://ift.tt/L6GMBgS
Kevin Chung
Taking over a Dead IoT Company
5 years after NYCTrainSign collapsed, I investigate why the company failed and end up writing an exploit to take over their fleet.
Cacti: Unauthenticated Remote Code Execution (CVE-2022-46169)
https://ift.tt/BUxzjQ9
Submitted January 11, 2023 at 05:28AM by monoimpact
via reddit https://ift.tt/hcIzBt2
https://ift.tt/BUxzjQ9
Submitted January 11, 2023 at 05:28AM by monoimpact
via reddit https://ift.tt/hcIzBt2
Sonarsource
Cacti: Unauthenticated Remote Code Execution
Learn how we discovered a critical vulnerability in Cacti with the help of SonarCloud.
How to find a Google account with a phone number
https://ift.tt/HURL6Mo
Submitted January 11, 2023 at 05:03AM by Gallus
via reddit https://ift.tt/ZmLdTp3
https://ift.tt/HURL6Mo
Submitted January 11, 2023 at 05:03AM by Gallus
via reddit https://ift.tt/ZmLdTp3
Aware Online Academy
How can I find a Google account with a phone number?
In this blog you can read how you can find a Google account (GAIA ID) of a user using a phone number (and/or email address)
SANS Christmas Challenge 2022 - Write-up
https://ift.tt/M3ynXSr
Submitted January 11, 2023 at 02:53PM by the-useless-one
via reddit https://ift.tt/7s3RPQh
https://ift.tt/M3ynXSr
Submitted January 11, 2023 at 02:53PM by the-useless-one
via reddit https://ift.tt/7s3RPQh
Legitify supports scanning GitLab for security misconfigurations and best practices
https://ift.tt/XZSkcTo
Submitted January 11, 2023 at 05:54PM by dotanoam
via reddit https://ift.tt/H3d6PZI
https://ift.tt/XZSkcTo
Submitted January 11, 2023 at 05:54PM by dotanoam
via reddit https://ift.tt/H3d6PZI
GitHub
Release v0.2.0 · Legit-Labs/legitify
Main Features:
Support for: GitHub Enterprise Server, GitLab Server, and GitLab Cloud
Added Legitify Custom GitHub Actions to ease Legitify CI/CD Automation
Changelog
bcf0773 feat: generalized S...
Support for: GitHub Enterprise Server, GitLab Server, and GitLab Cloud
Added Legitify Custom GitHub Actions to ease Legitify CI/CD Automation
Changelog
bcf0773 feat: generalized S...
T95 Allwinner T616 Malware Analysis - "Pre-owned" Android TV Device
https://ift.tt/Uq5FPc0
Submitted January 12, 2023 at 02:03AM by sanitybit
via reddit https://ift.tt/nv0G9Jg
https://ift.tt/Uq5FPc0
Submitted January 12, 2023 at 02:03AM by sanitybit
via reddit https://ift.tt/nv0G9Jg
GitHub
GitHub - DesktopECHO/T95-H616-Malware: "Pre-Owned" malware in ROM on T95 Android TV Box (AllWinner H616)
"Pre-Owned" malware in ROM on T95 Android TV Box (AllWinner H616) - GitHub - DesktopECHO/T95-H616-Malware: "Pre-Owned" malware in ROM on T95 Android TV Box (AllWinner H616)
Exfiltration Over a Blocked Port on a Next-Gen Firewall
https://ift.tt/fUmqaGz
Submitted January 12, 2023 at 02:37PM by cuptugout
via reddit https://ift.tt/OtUCM2b
https://ift.tt/fUmqaGz
Submitted January 12, 2023 at 02:37PM by cuptugout
via reddit https://ift.tt/OtUCM2b
Cymulate
Exfiltration Over a Blocked Port on a Next-Gen Firewall
How Does Cymulate Assess for Data Exfiltration? Learn more in this blog post by security advisor David Kellerman.
Avoiding API Key Exposures: The Importance of Strong Fundamentals and the Limitations of AI
https://tg12.github.io/
Submitted January 12, 2023 at 09:28PM by DevOpsMuffin39
via reddit https://ift.tt/epsV2tf
https://tg12.github.io/
Submitted January 12, 2023 at 09:28PM by DevOpsMuffin39
via reddit https://ift.tt/epsV2tf
reddit
Avoiding API Key Exposures: The Importance of Strong Fundamentals...
Posted in r/netsec by u/DevOpsMuffin39 • 1 point and 0 comments
Keeping the wolves out of wolfSSL (Protocol Fuzzing)
https://ift.tt/h7HCIGK
Submitted January 13, 2023 at 01:33AM by maxammann
via reddit https://ift.tt/O9USPh7
https://ift.tt/h7HCIGK
Submitted January 13, 2023 at 01:33AM by maxammann
via reddit https://ift.tt/O9USPh7
Trail of Bits Blog
Keeping the wolves out of wolfSSL
By Max Ammann Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152, CVE-2022-38153, CVE-2022-39173, and CVE-2022-42905. The four issues, which have CVSS sco…
List of git commits before and after a security audit
https://ift.tt/MG3AVgk
Submitted January 13, 2023 at 02:29AM by kruksym
via reddit https://ift.tt/d58VE4O
https://ift.tt/MG3AVgk
Submitted January 13, 2023 at 02:29AM by kruksym
via reddit https://ift.tt/d58VE4O
GraphQL exploitation – All you need to know – Cybervelia
https://ift.tt/lILWoxS
Submitted January 13, 2023 at 02:28AM by Necessary-Reality-80
via reddit https://ift.tt/SLsfWgA
https://ift.tt/lILWoxS
Submitted January 13, 2023 at 02:28AM by Necessary-Reality-80
via reddit https://ift.tt/SLsfWgA
Cybervelia
GraphQL exploitation – The ultimate guide
So you are a tester and you would like to know more about GraphQL Testing.
Bad things come in large packages: .pkg signature verification bypass on macOS
https://ift.tt/m7BK9nM
Submitted January 13, 2023 at 03:39PM by xnyhps
via reddit https://ift.tt/EsJ1GlY
https://ift.tt/m7BK9nM
Submitted January 13, 2023 at 03:39PM by xnyhps
via reddit https://ift.tt/EsJ1GlY
sector7.computest.nl
Bad things come in large packages: .pkg signature verification bypass on macOS
Code signing of applications is an essential element of macOS security. Besides signing applications, it is also possible to sign installer packages (.pkg files). During a short review of the xar source code, we found a vulnerability (CVE-2022-42841) that…
Crassus: Windows privilege escalation discovery tool
https://ift.tt/5BpuRQl
Submitted January 13, 2023 at 07:51PM by Fugitif
via reddit https://ift.tt/el0hwB4
https://ift.tt/5BpuRQl
Submitted January 13, 2023 at 07:51PM by Fugitif
via reddit https://ift.tt/el0hwB4
GitHub
GitHub - vu-ls/Crassus
Contribute to vu-ls/Crassus development by creating an account on GitHub.
Clear communication is crucial: why writing effective vulnerability reports matters
https://ift.tt/MQqmK3Y
Submitted January 13, 2023 at 07:44PM by glum-platimium
via reddit https://ift.tt/Bos83bv
https://ift.tt/MQqmK3Y
Submitted January 13, 2023 at 07:44PM by glum-platimium
via reddit https://ift.tt/Bos83bv