StarHound - CLI tool for importing BloodHound's Active Directory and Azure data (for latest SharpHound/AzureHound data collectors)
https://ift.tt/IdnvG9K
Submitted February 05, 2023 at 05:26PM by malacupa
via reddit https://ift.tt/B8fAOUG
https://ift.tt/IdnvG9K
Submitted February 05, 2023 at 05:26PM by malacupa
via reddit https://ift.tt/B8fAOUG
malacupa.com
StarHound - CLI import tool for SharpHound/AzureHound data
StarHound - alternative tool to import SharpHound and AzureHound data into neo4j using CLI
Italy Takes Action Against Impending Global Cyberattack
https://ift.tt/x3Aj6P7
Submitted February 06, 2023 at 09:06PM by Damanjain
via reddit https://ift.tt/puV4US2
https://ift.tt/x3Aj6P7
Submitted February 06, 2023 at 09:06PM by Damanjain
via reddit https://ift.tt/puV4US2
The Buzz News
Italy Issues Global Cybersecurity Alert: Protect Your Systems Now!
Italy Cybersecurity Alert - Ransomware attacks have targeted thousands of computer servers worldwide. Hackers targeted VMware ESXi.
Hacking into Toyota's global supplier management network
https://ift.tt/P2c5thM
Submitted February 06, 2023 at 10:09PM by EatonZ
via reddit https://ift.tt/gkPBObt
https://ift.tt/P2c5thM
Submitted February 06, 2023 at 10:09PM by EatonZ
via reddit https://ift.tt/gkPBObt
Eaton-Works
Hacking into Toyota’s global supplier management network
Inside an exploit that allowed logging in to Toyota’s GSPIMS application as any user, including system admins.
SimpleX Chat – the 1st messenger without user IDs (not even random numbers) – v4.5 released with multiple user profiles and transport isolation!
https://ift.tt/resz3BS
Submitted February 07, 2023 at 01:26AM by epoberezkin
via reddit https://ift.tt/2PgvGSl
https://ift.tt/resz3BS
Submitted February 07, 2023 at 01:26AM by epoberezkin
via reddit https://ift.tt/2PgvGSl
simplex.chat
SimpleX Chat v4.5 released – with multiple chat profiles, message draft, transport isolation and Italian language!
I Built a Self-Destructing USB Drive Part 3
https://ift.tt/juzhJye
Submitted February 07, 2023 at 09:22AM by Machinehum
via reddit https://ift.tt/Kxmywaz
https://ift.tt/juzhJye
Submitted February 07, 2023 at 09:22AM by Machinehum
via reddit https://ift.tt/Kxmywaz
Interrupt Labs Blog
I Built a Self-Destructing USB Drive Part 3
I’m building an open-source USB drive with a hidden self-destruct feature. Say goodbye to your data if you don’t lick your fingers before plugging it
NETGEAR Nighthawk upnpd Pre-authentication Buffer Overflow
https://ift.tt/FilUNcg
Submitted February 07, 2023 at 03:25PM by luci_morningstart
via reddit https://ift.tt/d9otKpL
https://ift.tt/FilUNcg
Submitted February 07, 2023 at 03:25PM by luci_morningstart
via reddit https://ift.tt/d9otKpL
Tracing the Linux kernel using Exein Pulsar: a 5 Minute Tutorial
https://ift.tt/A4RtpC6
Submitted February 07, 2023 at 08:29PM by hdtrinh
via reddit https://ift.tt/B1WvhA6
https://ift.tt/A4RtpC6
Submitted February 07, 2023 at 08:29PM by hdtrinh
via reddit https://ift.tt/B1WvhA6
blog.exein.io
Tracing the Linux kernel using Exein Pulsar: a 5 Minute Tutorial | Exein Blog
Cover image
A Detailed Analysis of a New Stealer called Stealerium
https://ift.tt/IqfBdrJ
Submitted February 07, 2023 at 08:27PM by CyberMasterV
via reddit https://ift.tt/Mr7ViHQ
https://ift.tt/IqfBdrJ
Submitted February 07, 2023 at 08:27PM by CyberMasterV
via reddit https://ift.tt/Mr7ViHQ
Security Scorecard
[Whitepaper] A Detailed Analysis Of A New Stealer Called Stealerium
Discovering a weakness leading to a partial bypass of the login rate limiting in the AWS Console
https://ift.tt/SeULhGb
Submitted February 07, 2023 at 09:44PM by thorn42
via reddit https://ift.tt/EXlrA5o
https://ift.tt/SeULhGb
Submitted February 07, 2023 at 09:44PM by thorn42
via reddit https://ift.tt/EXlrA5o
Datadoghq
Discovering a weakness leading to a partial bypass of the login rate limiting in the AWS Console
In this post, we discuss a weakness we discovered in the AWS Console authentication flow that allowed an attacker to partially bypass the login rate limit.
GitHub - mazen160/secrets-patterns-db: Secrets Patterns DB: A comprehensive open-source regex database for secret detection.
https://ift.tt/6IWtvPk
Submitted February 07, 2023 at 09:54PM by mazen160
via reddit https://ift.tt/sIVtCpQ
https://ift.tt/6IWtvPk
Submitted February 07, 2023 at 09:54PM by mazen160
via reddit https://ift.tt/sIVtCpQ
GitHub
GitHub - mazen160/secrets-patterns-db: Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords…
Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more. - GitHub - mazen160/secrets-patterns-db: Secrets Patterns DB: The largest open-so...
Post-Exploitation: Abusing the KeePass Plugin Cache
https://ift.tt/KJV0v2H
Submitted February 07, 2023 at 11:57PM by guedou
via reddit https://ift.tt/M4eDGlU
https://ift.tt/KJV0v2H
Submitted February 07, 2023 at 11:57PM by guedou
via reddit https://ift.tt/M4eDGlU
Quarkslab
Post-Exploitation: Abusing the KeePass Plugin Cache
🔑 Introducing Matano Identity Data Lake for Open Source Cloud-Native SIEM!
https://ift.tt/0uIX5UH
Submitted February 08, 2023 at 01:11AM by shaeqahmed
via reddit https://ift.tt/EH61jAG
https://ift.tt/0uIX5UH
Submitted February 08, 2023 at 01:11AM by shaeqahmed
via reddit https://ift.tt/EH61jAG
www.matano.dev
Matano adds Identity Data Lake | Matano
We're adding support for pulling logs and enrichment data from identity and auth sources to your Matano data lake. This means you can query failed/successful sign-in attempts, view audit logs, and query user information from popular SaaS sources directly…
Recovery noscript for ESXiArgs ransomware
https://ift.tt/qAp2ojD
Submitted February 08, 2023 at 06:06AM by YogiBerra88888
via reddit https://ift.tt/aLZX2q3
https://ift.tt/qAp2ojD
Submitted February 08, 2023 at 06:06AM by YogiBerra88888
via reddit https://ift.tt/aLZX2q3
GitHub
GitHub - cisagov/ESXiArgs-Recover: A tool to recover from ESXiArgs ransomware
A tool to recover from ESXiArgs ransomware. Contribute to cisagov/ESXiArgs-Recover development by creating an account on GitHub.
Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game
https://ift.tt/fxTBtmb
Submitted February 08, 2023 at 03:30PM by stashing_the_smack
via reddit https://ift.tt/bnLPGZ1
https://ift.tt/fxTBtmb
Submitted February 08, 2023 at 03:30PM by stashing_the_smack
via reddit https://ift.tt/bnLPGZ1
Avast Threat Labs
Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game - Avast Threat Labs
Avast discovered an exploit for CVE-2021-38003 was used in the wild to attack Dota 2 players. This exploit achieved remote code execution on other players' machines by taking advantage of Dota's usage of an outdated V8 version. In response to Avast's findings…
Fearless CORS: a design philosophy for CORS middleware libraries (and a Go implementation) :: jub0bs.com
https://ift.tt/3j7QKxV
Submitted February 08, 2023 at 07:27PM by jub0bs
via reddit https://ift.tt/2ZdgYsB
https://ift.tt/3j7QKxV
Submitted February 08, 2023 at 07:27PM by jub0bs
via reddit https://ift.tt/2ZdgYsB
Jub0Bs
Fearless CORS: a design philosophy for CORS middleware libraries (and a Go implementation)
TL;DR ¶ In this post, I investigate why developers struggle with CORS and I derive Fearless CORS, a design philosophy for better CORS middleware libraries, which comprises the following twelve principles:
Optimise for readability Strive for a simple and…
Optimise for readability Strive for a simple and…
Rustproofing Linux (Part 1, Leaking Addresses)
https://ift.tt/dDYgN8M
Submitted February 08, 2023 at 08:34PM by Gallus
via reddit https://ift.tt/Jw8l73W
https://ift.tt/dDYgN8M
Submitted February 08, 2023 at 08:34PM by Gallus
via reddit https://ift.tt/Jw8l73W
NCC Group Research Blog
Rustproofing Linux (Part 1/4 Leaking Addresses)
Rust is a programming language guaranteeing memory and thread safety while still being able to access raw memory and hardware. This sounds impossible, and it is, that’s why Rust has an unsafe keywo…
Top 10 web hacking techniques of 2022
https://ift.tt/4hdipNu
Submitted February 08, 2023 at 07:55PM by Fugitif
via reddit https://ift.tt/aVfGgDj
https://ift.tt/4hdipNu
Submitted February 08, 2023 at 07:55PM by Fugitif
via reddit https://ift.tt/aVfGgDj
PortSwigger Research
Top 10 web hacking techniques of 2022
Welcome to the Top 10 Web Hacking Techniques of 2022, the 16th edition of our annual community-powered effort to identify the most important and innovative web security research published in the last
A Year in Review 2022: 100 vulnerabilities you should prioritize - PRIOn
https://ift.tt/luvBPMX
Submitted February 08, 2023 at 09:04PM by gfekkas
via reddit https://ift.tt/xw3qCQS
https://ift.tt/luvBPMX
Submitted February 08, 2023 at 09:04PM by gfekkas
via reddit https://ift.tt/xw3qCQS
PRIOn - Vulnerability Prioritization Technology
A Year in Review 2022: 100 vulnerabilities you should prioritize - PRIOn
In this article we present the analysis of one hundred (100) vulnerabilities that you should keep an eye on and prioritize them according to your environment.
OpenSSH Pre-Auth Double Free - CVE-2023-25136 - Writeup and Proof-of-Concept
https://ift.tt/qgEOI9j
Submitted February 08, 2023 at 11:03PM by n0llbyte
via reddit https://ift.tt/Ux4bwjR
https://ift.tt/qgEOI9j
Submitted February 08, 2023 at 11:03PM by n0llbyte
via reddit https://ift.tt/Ux4bwjR
JFrog
CVE-2023-25136 OpenSSH Pre-Auth Double Free Writeup & PoC
Understanding the OpenSSH CVE-2023-25136 high vulnerability. Read our analysis with Proof-of-Concept, learn what's vulnerable, and discover remediations.
Offphish - Phishing revisited in 2023
https://ift.tt/cdzPZ7s
Submitted February 09, 2023 at 03:40PM by 0xcsandker
via reddit https://ift.tt/fkaGbeU
https://ift.tt/cdzPZ7s
Submitted February 09, 2023 at 03:40PM by 0xcsandker
via reddit https://ift.tt/fkaGbeU
www.securesystems.de
Offphish - Phishing revisited in 2023
This blog post evaluates the state of the art with phishing, which techniques are still relevant and what know-how is worth revisiting. Additionally an overview of various techniques across the three stages of a phishing campaign, an overview of features…
Neo4jection: Secrets, Data, and Cloud Exploits - Attacking Neo4j
https://ift.tt/0vWoGyr
Submitted February 09, 2023 at 08:26PM by lowlandsmarch
via reddit https://ift.tt/WhrZC48
https://ift.tt/0vWoGyr
Submitted February 09, 2023 at 08:26PM by lowlandsmarch
via reddit https://ift.tt/WhrZC48
Varonis
Neo4jection: Secrets, Data, and Cloud Exploits
With the continuous rise of graph databases, especially Neo4j, we're seeing increased discussions among security researchers about issues found in those databases. However, given our experience with graph databases ― from designing complex and scalable solutions…