Leopard Tank Announcement Prompt Retaliation
https://ift.tt/d0u8vQK
Submitted January 30, 2023 at 08:30PM by 0x636f6f6c
via reddit https://ift.tt/osz5EHF
https://ift.tt/d0u8vQK
Submitted January 30, 2023 at 08:30PM by 0x636f6f6c
via reddit https://ift.tt/osz5EHF
Cado Security | Cloud Investigation
Leopard Tank Announcement Prompts Cyber Retaliation - Cado Security | Cloud Investigation
The Cado Labs team discovered evidence of retaliation from high-profile Russian hacktivist groups in an effort to encourage collective cyber attacks against German infrastructure. This appears to be in response to yesterday’s expectations that Germany will…
DDoS attacks in Europe experienced a 73% increase in 2022 compared to the previous year
https://ift.tt/kyPAE4n
Submitted January 30, 2023 at 09:08PM by shapelez
via reddit https://ift.tt/hufNdsb
https://ift.tt/kyPAE4n
Submitted January 30, 2023 at 09:08PM by shapelez
via reddit https://ift.tt/hufNdsb
Habr
Q4 2022 DDoS Attacks and BGP Incidents
Now that 2022 has come to an end, we would like to share the DDoS attack mitigation and BGP incident statistics for the fourth quarter of the year, which overall saw unprecedented levels of DDoS...
Truffle Security is proud to host a new XSSHunter, that finds new vulnerabilities
https://ift.tt/zLlQYiD
Submitted January 30, 2023 at 09:56PM by wifihack
via reddit https://ift.tt/hIc75zi
https://ift.tt/zLlQYiD
Submitted January 30, 2023 at 09:56PM by wifihack
via reddit https://ift.tt/hIc75zi
Truffle Security
Truffle Security is proud to host a new XSSHunter - Truffle Security
Truffle Security is proud to be hosting a new XSSHunter, with new features, with the assistance of its original creator, Mandatory.
CloudGPT - Use ChatGPT to analyze AWS policies for vulnerabilities
https://ift.tt/lFWy9G5
Submitted January 31, 2023 at 08:01AM by ustayready
via reddit https://ift.tt/J8bgKLl
https://ift.tt/lFWy9G5
Submitted January 31, 2023 at 08:01AM by ustayready
via reddit https://ift.tt/J8bgKLl
Gist
CloudGPT - Use ChatGPT to analyze AWS policies for vulnerabilities
CloudGPT - Use ChatGPT to analyze AWS policies for vulnerabilities - gpt.py
Lockpicking The Lockout Policy For Information Correlation: Exploring the novel web app attack…
https://ift.tt/jS50Hfb
Submitted January 31, 2023 at 09:12AM by TheCrazyAcademic
via reddit https://ift.tt/zkeDalL
https://ift.tt/jS50Hfb
Submitted January 31, 2023 at 09:12AM by TheCrazyAcademic
via reddit https://ift.tt/zkeDalL
Medium
Lockpicking The Lockout Policy For Information Correlation: Exploring the novel web app attack…
If you don’t know what an oracle or testing oracle is in computer science in layman’s terms it’s where you ask a yes or no question in some…
How to identify and avoid malicious code in your software supply chain
https://ift.tt/v2GMN7D
Submitted January 31, 2023 at 04:33PM by n0llbyte
via reddit https://ift.tt/JwtQRZ5
https://ift.tt/v2GMN7D
Submitted January 31, 2023 at 04:33PM by n0llbyte
via reddit https://ift.tt/JwtQRZ5
JFrog
How to identify and avoid malicious code in your software supply chain
Dangerous payload scenarios are affecting cybersecurity now. Learn how attackers hide malicious code and methods to identify these packages to avoid infection.
The Good, Bad and Compromisable Aspects of Linux eBPF
https://ift.tt/XegUWO5
Submitted January 31, 2023 at 05:43PM by eberkut
via reddit https://ift.tt/TmG4loL
https://ift.tt/XegUWO5
Submitted January 31, 2023 at 05:43PM by eberkut
via reddit https://ift.tt/TmG4loL
Pentera
The Good, Bad and Compromisable Aspects of Linux eBPF - Pentera
2022 discoveries of new privilege escalation techniques Reading this blog will allow you to understand the eBPF mechanism and how a fairly small bug can
VMware vRealize Log Insight VMSA-2023-0001 Technical Deep Dive and Exploit POC
https://ift.tt/6HSIapt
Submitted January 31, 2023 at 05:41PM by scopedsecurity
via reddit https://ift.tt/rSz5wAJ
https://ift.tt/6HSIapt
Submitted January 31, 2023 at 05:41PM by scopedsecurity
via reddit https://ift.tt/rSz5wAJ
Horizon3.ai
VMware vRealize Log Insight VMSA-2023-0001 Technical Deep Dive
Technical deep-dive and exploit POC for VMware vRealize Log Insight RCE as reported in VMSA-2023-0001. This series of vulnerabilities leads to remote code execution and full system compromise. CVE-2022-31704, CVE-2022-31706, and CVE-2022-31711.
Exposing Secrets Via AppSec Tools: The SonarQube Case
https://ift.tt/lVpSnBO
Submitted January 31, 2023 at 04:59PM by roy_6472
via reddit https://ift.tt/CA0zVQd
https://ift.tt/lVpSnBO
Submitted January 31, 2023 at 04:59PM by roy_6472
via reddit https://ift.tt/CA0zVQd
Legitsecurity
Exposing Secrets Via SDLC Tools: The SonarQube Case
Legit Security | We investigate how sensitive information can get exposed via AppSec tools that you use in your dev pipeline, using the SonarQube Case.
Learning CodeQL - Going Beyond Grep
https://ift.tt/d9bsTOE
Submitted January 31, 2023 at 06:27PM by Gallus
via reddit https://ift.tt/6cUxEpe
https://ift.tt/d9bsTOE
Submitted January 31, 2023 at 06:27PM by Gallus
via reddit https://ift.tt/6cUxEpe
Goingbeyondgrep
Learning CodeQL
Unlike many SAST products, CodeQL is more than just a tool and learning it requires learning more than just a tool. It’s a programming language, a tool, and a supporting ecosystem that come together to create something extremely powerful, flexible, and unique.…
Github reports unauthorized access to some Github Desktop and Atom repositories
https://ift.tt/Mw5HBOY
Submitted January 31, 2023 at 06:12PM by qwerty0x41
via reddit https://ift.tt/eRC0MZu
https://ift.tt/Mw5HBOY
Submitted January 31, 2023 at 06:12PM by qwerty0x41
via reddit https://ift.tt/eRC0MZu
The GitHub Blog
Action needed for GitHub Desktop and Atom users | The GitHub Blog
Update to the latest version of Desktop and previous version of Atom before February 2.
Remote Command Execution in binwalk
https://ift.tt/Pu6X4mH
Submitted January 31, 2023 at 07:39PM by Gallus
via reddit https://ift.tt/lFqDaXz
https://ift.tt/Pu6X4mH
Submitted January 31, 2023 at 07:39PM by Gallus
via reddit https://ift.tt/lFqDaXz
ONEKEY
Security Advisory: Remote Command Execution in binwalk
Learn about the security vulnerability in binwalk v2.1.2b-2.3.3 !
We reversed engineered Splunk and created a pure python based S2S client
https://ift.tt/HlCnwi4
Submitted January 31, 2023 at 09:13PM by sh0n1z
via reddit https://ift.tt/qCyedFT
https://ift.tt/HlCnwi4
Submitted January 31, 2023 at 09:13PM by sh0n1z
via reddit https://ift.tt/qCyedFT
TimeException: A tool to find folders excluded from AV real-time scanning using a time oracle
https://ift.tt/0Oh7pRc
Submitted January 31, 2023 at 11:55PM by sanitybit
via reddit https://ift.tt/JQ425NC
https://ift.tt/0Oh7pRc
Submitted January 31, 2023 at 11:55PM by sanitybit
via reddit https://ift.tt/JQ425NC
GitHub
GitHub - bananabr/TimeException: A tool to find folders excluded from AV real-time scanning using a time oracle
A tool to find folders excluded from AV real-time scanning using a time oracle - GitHub - bananabr/TimeException: A tool to find folders excluded from AV real-time scanning using a time oracle
Setting you up for failure: Exploring 2FA bypasses in web application settings page functionality
https://ift.tt/bvRq1ls
Submitted February 01, 2023 at 03:45AM by TheCrazyAcademic
via reddit https://ift.tt/osApmUB
https://ift.tt/bvRq1ls
Submitted February 01, 2023 at 03:45AM by TheCrazyAcademic
via reddit https://ift.tt/osApmUB
Medium
Setting you up for failure: Exploring 2FA bypasses in web application settings page functionality
In January it was reported in the mainstream media a 2FA Bypass was discovered in Facebook involving their new account center APIs. This is…
RCE in Avaya Aura Device Services
https://ift.tt/SxwLBbm
Submitted February 01, 2023 at 06:33AM by Mempodipper
via reddit https://ift.tt/36Q0bOS
https://ift.tt/SxwLBbm
Submitted February 01, 2023 at 06:33AM by Mempodipper
via reddit https://ift.tt/36Q0bOS
Assetnote
RCE in Avaya Aura Device Services
Application security issues found by Assetnote
CVE-2021-34462: Exploiting the Windows AppXSvc Service Logic-Error Vulnerability
https://ift.tt/Qcsf2Hk
Submitted February 01, 2023 at 01:20PM by Gallus
via reddit https://ift.tt/XI6n1dO
https://ift.tt/Qcsf2Hk
Submitted February 01, 2023 at 01:20PM by Gallus
via reddit https://ift.tt/XI6n1dO
Precision Munitions for Denial of Service
https://ift.tt/BeL5pQV
Submitted February 01, 2023 at 08:10PM by DevSec23
via reddit https://ift.tt/0yzW79f
https://ift.tt/BeL5pQV
Submitted February 01, 2023 at 08:10PM by DevSec23
via reddit https://ift.tt/0yzW79f
beny23.github.io
Precision Munitions for Denial of Service
There’s a metaphor about the fight between attackers and defenders in the Denial of Service cybersecurity game. It’s an “arms race” between ever bigger attacks throwing huge amounts of traffic at ever more sophisticated defenses (e.g. AWS shield).
Incidentally…
Incidentally…
HeadCrab: A Novel State-of-the-Art Redis Malware in a Global Campaign
https://ift.tt/WyiG1pO
Submitted February 02, 2023 at 12:09AM by gfdgfbal
via reddit https://ift.tt/VYCtUux
https://ift.tt/WyiG1pO
Submitted February 02, 2023 at 12:09AM by gfdgfbal
via reddit https://ift.tt/VYCtUux
Aquasec
HeadCrab: A Novel State-of-the-Art Redis Malware in a Global Campaign
Aqua Nautilus uncovers threat actor HeadCrab has created an advanced malicious Redis framework that has compromised over 1200 servers and how to protect yourself
Ronin 2.0.0 has finally been released! Ronin is a free and Open Source Ruby toolkit for security research and development.
https://ift.tt/GBCWlsk
Submitted February 02, 2023 at 04:39AM by postmodern
via reddit https://ift.tt/lSXNk5P
https://ift.tt/GBCWlsk
Submitted February 02, 2023 at 04:39AM by postmodern
via reddit https://ift.tt/lSXNk5P
Unserializable, but unreachable: Remote Code Execution on vBulletin
https://ift.tt/WjcXJ0g
Submitted February 02, 2023 at 01:59PM by cfambionics
via reddit https://ift.tt/hOl1QbR
https://ift.tt/WjcXJ0g
Submitted February 02, 2023 at 01:59PM by cfambionics
via reddit https://ift.tt/hOl1QbR
Ambionics
Unserializable, but unreachable: Remote code execution on vBulletin
Ambionics Security team discovered a pre-authentication remote code execution in vBulletin 5.6.9.