Announcing the public beta of Caido, a BurpSuite alternative
https://ift.tt/MPOwTQn
Submitted January 17, 2023 at 09:39PM by TheSytten
via reddit https://ift.tt/Ox6jGJ3
https://ift.tt/MPOwTQn
Submitted January 17, 2023 at 09:39PM by TheSytten
via reddit https://ift.tt/Ox6jGJ3
Medium
Caido is now in public beta
We’re excited to announce the public beta of Caido!
AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass | Datadog Security Labs
https://ift.tt/1iazyZX
Submitted January 17, 2023 at 09:33PM by RedTermSession
via reddit https://ift.tt/d6RvmP8
https://ift.tt/1iazyZX
Submitted January 17, 2023 at 09:33PM by RedTermSession
via reddit https://ift.tt/d6RvmP8
Datadoghq
AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass
Public disclosure of a method to bypass CloudTrail for specific IAM actions.
Security audit of Git
https://ift.tt/WkXG2P0
Submitted January 18, 2023 at 01:20AM by joernchen
via reddit https://ift.tt/7okJZMa
https://ift.tt/WkXG2P0
Submitted January 18, 2023 at 01:20AM by joernchen
via reddit https://ift.tt/7okJZMa
X41 D-SEC
X41 Audited Git
X41 releases the audit report of Git
Hacking ICS Historians: The Pivot Point From IT to OT
https://ift.tt/kRobpVO
Submitted January 18, 2023 at 02:10AM by derp6996
via reddit https://ift.tt/CKcVSls
https://ift.tt/kRobpVO
Submitted January 18, 2023 at 02:10AM by derp6996
via reddit https://ift.tt/CKcVSls
Claroty
Hacking ICS Historians: The Pivot Point from IT to OT
Tailscale bug allowed a person to share nodes from other tailnets without auth
https://ift.tt/hzBJwC8
Submitted January 18, 2023 at 07:10AM by Security_Chief_Odo
via reddit https://ift.tt/4rYbU3K
https://ift.tt/hzBJwC8
Submitted January 18, 2023 at 07:10AM by Security_Chief_Odo
via reddit https://ift.tt/4rYbU3K
Tailscale
Security notifications affecting the Tailscale client and service If you’re directly affected by a security issue in Tailscale, and we have your contact information, we will contact you.
Nothing new under the Sun - Discovering and exploiting a CDE bug chain
https://ift.tt/ZmE6agQ
Submitted January 18, 2023 at 02:30PM by 0xdea
via reddit https://ift.tt/dEN4kQM
https://ift.tt/ZmE6agQ
Submitted January 18, 2023 at 02:30PM by 0xdea
via reddit https://ift.tt/dEN4kQM
hn security
Nothing new under the Sun - Discovering and exploiting a CDE bug chain - hn security
“What has been will be again, […]
Top 10 security predictions for 2023
https://ift.tt/QPENDWK
Submitted January 18, 2023 at 07:51PM by KeyDutch
via reddit https://ift.tt/USrDcZx
https://ift.tt/QPENDWK
Submitted January 18, 2023 at 07:51PM by KeyDutch
via reddit https://ift.tt/USrDcZx
Immuniweb
Top 10 Cybersecurity Predictions for 2023
Although 2022 has been a quite tumultuous year for cyber security industry, 2023 is expected to be even more challenging for security teams, experts warn.
Gold Digger: a simple tool to quickly discover credentials/sensitive information in files recursively
https://ift.tt/3akKSEL
Submitted January 18, 2023 at 10:32PM by ustayready
via reddit https://ift.tt/nTHJje1
https://ift.tt/3akKSEL
Submitted January 18, 2023 at 10:32PM by ustayready
via reddit https://ift.tt/nTHJje1
GitHub
GitHub - ustayready/golddigger
Contribute to ustayready/golddigger development by creating an account on GitHub.
Java XML security issues and how to address them
https://ift.tt/LmlgAVB
Submitted January 18, 2023 at 10:02PM by got_nations
via reddit https://ift.tt/p8xg7DF
https://ift.tt/LmlgAVB
Submitted January 18, 2023 at 10:02PM by got_nations
via reddit https://ift.tt/p8xg7DF
XML Security in Java
In this blog post, you can read just how much of a mess Java XML security is
Sudoedit can edit arbitrary files (CVE-2023-22809)
https://ift.tt/I4U8OtJ
Submitted January 19, 2023 at 01:59AM by 0xdea
via reddit https://ift.tt/TIP3QJX
https://ift.tt/I4U8OtJ
Submitted January 19, 2023 at 01:59AM by 0xdea
via reddit https://ift.tt/TIP3QJX
Sudo
Sudoedit can edit arbitrary files
A flaw in exists in sudo’s -e option (aka sudoedit) that allows a malicious user with sudoedit privileges to edit arbitrary files.
Sudo versions affected: Sudo versions 1.8.0 through 1.9.12p1 inclusive are affected. Versions of sudo prior to 1.8.0 construct…
Sudo versions affected: Sudo versions 1.8.0 through 1.9.12p1 inclusive are affected. Versions of sudo prior to 1.8.0 construct…
Centreon Map plugin allows pre-auth remote process memory dump (CVSS 8.3) - PoC
https://ift.tt/3U9xKJI
Submitted January 19, 2023 at 12:33PM by qwerty0x41
via reddit https://ift.tt/xvS2PIr
https://ift.tt/3U9xKJI
Submitted January 19, 2023 at 12:33PM by qwerty0x41
via reddit https://ift.tt/xvS2PIr
SeeProxy: Golang reverse proxy with CobaltStrike malleable profile validation.
https://ift.tt/Uw6bV5g
Submitted January 19, 2023 at 05:42PM by bambo_gambo
via reddit https://ift.tt/e6cbHoK
https://ift.tt/Uw6bV5g
Submitted January 19, 2023 at 05:42PM by bambo_gambo
via reddit https://ift.tt/e6cbHoK
GitHub
GitHub - nopbrick/SeeProxy: Golang reverse proxy with CobaltStrike malleable profile validation.
Golang reverse proxy with CobaltStrike malleable profile validation. - GitHub - nopbrick/SeeProxy: Golang reverse proxy with CobaltStrike malleable profile validation.
Exploiting CVE-2021-3490 for Container Escapes
https://ift.tt/r2cXUpe
Submitted January 19, 2023 at 05:01PM by Gallus
via reddit https://ift.tt/v3dSMqc
https://ift.tt/r2cXUpe
Submitted January 19, 2023 at 05:01PM by Gallus
via reddit https://ift.tt/v3dSMqc
CrowdStrike.com
Exploiting CVE-2021-3490 for Container Escapes | CrowdStrike
Learn how to modify and exploit a Linux Kernel vulnerability to escape container environments, and how CrowdStrike can help to prevent and hunt for similar threats.
POC Exploit for CVE-2022-47966 affecting multiple ManageEngine products
https://ift.tt/4cZl7zt
Submitted January 19, 2023 at 06:52PM by scopedsecurity
via reddit https://ift.tt/we3bRx4
https://ift.tt/4cZl7zt
Submitted January 19, 2023 at 06:52PM by scopedsecurity
via reddit https://ift.tt/we3bRx4
GitHub
GitHub - horizon3ai/CVE-2022-47966: POC for CVE-2022-47966 affecting multiple ManageEngine products
POC for CVE-2022-47966 affecting multiple ManageEngine products - horizon3ai/CVE-2022-47966
Simple, open-source, lightweight stress testing tool
https://ift.tt/CJDx5pf
Submitted January 19, 2023 at 09:38PM by chrisy_e
via reddit https://ift.tt/NblMW8E
https://ift.tt/CJDx5pf
Submitted January 19, 2023 at 09:38PM by chrisy_e
via reddit https://ift.tt/NblMW8E
GitHub
GitHub - getanteon/anteon: Anteon (formerly Ddosify) - Effortless Kubernetes Monitoring and Performance Testing. Available on CLI…
Anteon (formerly Ddosify) - Effortless Kubernetes Monitoring and Performance Testing. Available on CLI, Self-Hosted, and Cloud - getanteon/anteon
New Remcos RATversion uses direct syscalls to evade detection.
https://ift.tt/nPdt9Wk
Submitted January 19, 2023 at 10:49PM by woja111
via reddit https://ift.tt/1IFTKng
https://ift.tt/nPdt9Wk
Submitted January 19, 2023 at 10:49PM by woja111
via reddit https://ift.tt/1IFTKng
Rapid7
Rapid7: Endpoint to Cloud, Command Your Attack Surface
Aerleon a vendor agnostic firewall management system
https://ift.tt/5L72C9O
Submitted January 20, 2023 at 12:19AM by ankenyr
via reddit https://ift.tt/TFMavi7
https://ift.tt/5L72C9O
Submitted January 20, 2023 at 12:19AM by ankenyr
via reddit https://ift.tt/TFMavi7
GitHub
GitHub - aerleon/aerleon: Multi-platform ACL generation system
Multi-platform ACL generation system. Contribute to aerleon/aerleon development by creating an account on GitHub.
How to completely own an airline in 3 easy steps
https://ift.tt/DsZiIY6
Submitted January 20, 2023 at 07:48AM by _vavkamil_
via reddit https://ift.tt/CoDSNga
https://ift.tt/DsZiIY6
Submitted January 20, 2023 at 07:48AM by _vavkamil_
via reddit https://ift.tt/CoDSNga
maia :3
how to completely own an airline in 3 easy steps
and grab the TSA nofly list along the way
Building a io_uring based network scanner in Rust
https://ift.tt/wxBmGOU
Submitted January 20, 2023 at 05:08PM by Gallus
via reddit https://ift.tt/zNESQx7
https://ift.tt/wxBmGOU
Submitted January 20, 2023 at 05:08PM by Gallus
via reddit https://ift.tt/zNESQx7
Synacktiv
Building a io_uring based network scanner in Rust
Abusing Adopted Authority on IBM i
https://ift.tt/Cw3IhmT
Submitted January 20, 2023 at 07:03PM by buherator
via reddit https://ift.tt/Bb1S3hP
https://ift.tt/Cw3IhmT
Submitted January 20, 2023 at 07:03PM by buherator
via reddit https://ift.tt/Bb1S3hP
Silent Signal Techblog
Abusing Adopted Authority on IBM i
Because we can!
Vijilan - Managed service Providers (msp)
https://ift.tt/UekdrDm
Submitted January 21, 2023 at 01:49AM by High_Sleep3694
via reddit https://ift.tt/LhX04gI
https://ift.tt/UekdrDm
Submitted January 21, 2023 at 01:49AM by High_Sleep3694
via reddit https://ift.tt/LhX04gI