A Year in Review 2022: 100 vulnerabilities you should prioritize - PRIOn
https://ift.tt/luvBPMX
Submitted February 08, 2023 at 09:04PM by gfekkas
via reddit https://ift.tt/xw3qCQS
https://ift.tt/luvBPMX
Submitted February 08, 2023 at 09:04PM by gfekkas
via reddit https://ift.tt/xw3qCQS
PRIOn - Vulnerability Prioritization Technology
A Year in Review 2022: 100 vulnerabilities you should prioritize - PRIOn
In this article we present the analysis of one hundred (100) vulnerabilities that you should keep an eye on and prioritize them according to your environment.
OpenSSH Pre-Auth Double Free - CVE-2023-25136 - Writeup and Proof-of-Concept
https://ift.tt/qgEOI9j
Submitted February 08, 2023 at 11:03PM by n0llbyte
via reddit https://ift.tt/Ux4bwjR
https://ift.tt/qgEOI9j
Submitted February 08, 2023 at 11:03PM by n0llbyte
via reddit https://ift.tt/Ux4bwjR
JFrog
CVE-2023-25136 OpenSSH Pre-Auth Double Free Writeup & PoC
Understanding the OpenSSH CVE-2023-25136 high vulnerability. Read our analysis with Proof-of-Concept, learn what's vulnerable, and discover remediations.
Offphish - Phishing revisited in 2023
https://ift.tt/cdzPZ7s
Submitted February 09, 2023 at 03:40PM by 0xcsandker
via reddit https://ift.tt/fkaGbeU
https://ift.tt/cdzPZ7s
Submitted February 09, 2023 at 03:40PM by 0xcsandker
via reddit https://ift.tt/fkaGbeU
www.securesystems.de
Offphish - Phishing revisited in 2023
This blog post evaluates the state of the art with phishing, which techniques are still relevant and what know-how is worth revisiting. Additionally an overview of various techniques across the three stages of a phishing campaign, an overview of features…
Neo4jection: Secrets, Data, and Cloud Exploits - Attacking Neo4j
https://ift.tt/0vWoGyr
Submitted February 09, 2023 at 08:26PM by lowlandsmarch
via reddit https://ift.tt/WhrZC48
https://ift.tt/0vWoGyr
Submitted February 09, 2023 at 08:26PM by lowlandsmarch
via reddit https://ift.tt/WhrZC48
Varonis
Neo4jection: Secrets, Data, and Cloud Exploits
With the continuous rise of graph databases, especially Neo4j, we're seeing increased discussions among security researchers about issues found in those databases. However, given our experience with graph databases ― from designing complex and scalable solutions…
Exploit Vector Analysis of Emerging 'ESXiArgs' Ransomware
https://ift.tt/8ekw2IE
Submitted February 10, 2023 at 01:18AM by DrinkMoreCodeMore
via reddit https://ift.tt/Ndsr6me
https://ift.tt/8ekw2IE
Submitted February 10, 2023 at 01:18AM by DrinkMoreCodeMore
via reddit https://ift.tt/Ndsr6me
www.greynoise.io
GreyNoise | Exploit Vector Analysis of Emerging ‘ESXiArgs’ Ransomware (a.k.a. Wow do I hate ESXi Threat Intel [right now])
GreyNoise researchers provide context around the mass confusion that is the state of ransomware campaigns against exposed VMWare ESXi hosts and bad attribution takes.
We had a security incident. Here’s what we know.
/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
Submitted February 10, 2023 at 01:59AM by sanitybit
via reddit https://ift.tt/86qcYfm
/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
Submitted February 10, 2023 at 01:59AM by sanitybit
via reddit https://ift.tt/86qcYfm
Reddit
r/netsec on Reddit
We had a security incident. Here’s what we know. - No votes and no comments
Avalanche Blockchain Vulnerable to 0day DoS
https://ift.tt/sbtlPzg
Submitted February 10, 2023 at 07:47AM by endless
via reddit https://ift.tt/FgTJj6x
https://ift.tt/sbtlPzg
Submitted February 10, 2023 at 07:47AM by endless
via reddit https://ift.tt/FgTJj6x
Livejournal
0Day Avalanche Blockchain API DoS
Author : https://twitter.com/123456 Avalanche just fucked me out of a sizable bug bounty — so I immediately found another bug to disclose to the public. This is a remote API DoS/crash that should OOM chain P and render a vulnerable node mostly or entirely…
Found SaltStack on a network and don't know how to attack the thing? Check out how a few configuration issues and a new spin on Jinja template injections can undo a network managed by Salt
https://ift.tt/ART3g6U
Submitted February 10, 2023 at 09:50AM by SkylightCyber
via reddit https://ift.tt/wAma1bd
https://ift.tt/ART3g6U
Submitted February 10, 2023 at 09:50AM by SkylightCyber
via reddit https://ift.tt/wAma1bd
Skylightcyber
Skylight Cyber | A-Salt: attacking SaltStack
Found SaltStack on a network and don't know how to attack the thing? Check out how a few configuration issues and a new spin on Jinja template injections can undo a network managed by Salt.
secpat2gf: convert secret patterns to gf compatible.
https://ift.tt/LGwKF2W
Submitted February 10, 2023 at 09:22AM by dwisiswant0
via reddit https://ift.tt/6iYSmnM
https://ift.tt/LGwKF2W
Submitted February 10, 2023 at 09:22AM by dwisiswant0
via reddit https://ift.tt/6iYSmnM
GitHub
GitHub - dwisiswant0/secpat2gf: convert secret patterns to gf compatible.
convert secret patterns to gf compatible. Contribute to dwisiswant0/secpat2gf development by creating an account on GitHub.
Find Writable Shares with Python.
https://ift.tt/iyYDhSm
Submitted February 10, 2023 at 06:47PM by oldboy21
via reddit https://ift.tt/eulwT2W
https://ift.tt/iyYDhSm
Submitted February 10, 2023 at 06:47PM by oldboy21
via reddit https://ift.tt/eulwT2W
GitHub
GitHub - oldboy21/RSMBI: Find Writable Shares
Find Writable Shares. Contribute to oldboy21/RSMBI development by creating an account on GitHub.
Cracking the Odd Case of Randomness in Java
https://ift.tt/FIPWvbU
Submitted February 10, 2023 at 06:20PM by Gallus
via reddit https://ift.tt/aUwY0Iy
https://ift.tt/FIPWvbU
Submitted February 10, 2023 at 06:20PM by Gallus
via reddit https://ift.tt/aUwY0Iy
Elttam
Cracking the Odd Case of Randomness in Java
This blog post details a technique for breaking Apache Commons Lang's RandomStringUtils and Java's random.nextInt(bound) when the bound is odd. A tool is released which demonstrates the practicality of the attack.
#ShortAndMalicious — PikaBot and the Matanbuchus connection
https://ift.tt/gnZYky6
Submitted February 10, 2023 at 07:04PM by OwnPreparation3424
via reddit https://ift.tt/bG8RgYH
https://ift.tt/gnZYky6
Submitted February 10, 2023 at 07:04PM by OwnPreparation3424
via reddit https://ift.tt/bG8RgYH
Medium
#ShortAndMalicious — PikaBot and the Matanbuchus connection
A brief analysis of the new loader malware distributed by Qakbot
Unlocking the Secrets of Ethical Hacking: The Best Certifications to Boost Your Career in 2023
https://ift.tt/GpW1ste
Submitted February 10, 2023 at 08:19PM by glum-platimium
via reddit https://ift.tt/OHnj1RX
https://ift.tt/GpW1ste
Submitted February 10, 2023 at 08:19PM by glum-platimium
via reddit https://ift.tt/OHnj1RX
Codelivly
Unlocking the Secrets of Ethical Hacking: The Best Certifications to Boost Your Career in 2023
These days, it seems that hardly a week goes by without at least one report of a data breach. A store may have had their credit card data stolen. A health insurance company may have lost the record…
New vuln in in NTFS3 leads to DoS
https://ift.tt/3CoF6KZ
Submitted February 10, 2023 at 10:32PM by jat0369
via reddit https://ift.tt/2wzTZbk
https://ift.tt/3CoF6KZ
Submitted February 10, 2023 at 10:32PM by jat0369
via reddit https://ift.tt/2wzTZbk
Cyberark
The Linux Kernel and the Cursed Driver
Introduction NTFS is a filesystem developed by Microsoft that was introduced in 1993. Since then, it has become the primary filesystem for Windows. In recent years, the need for an NTFS...
Information disclosure to GDPR breach? A Google tale…
https://ift.tt/JopCXje
Submitted February 10, 2023 at 10:26PM by lukeberner
via reddit https://ift.tt/pqGmZzD
https://ift.tt/JopCXje
Submitted February 10, 2023 at 10:26PM by lukeberner
via reddit https://ift.tt/pqGmZzD
Medium
Information disclosure or GDPR breach? A Google tale…
This is a vulnerability I reported back in April, 2022
LocalPotato - When Swapping The Context Leads You To SYSTEM
https://ift.tt/g2xsO5a
Submitted February 10, 2023 at 10:21PM by splinter_code
via reddit https://ift.tt/3YmEZnF
https://ift.tt/g2xsO5a
Submitted February 10, 2023 at 10:21PM by splinter_code
via reddit https://ift.tt/3YmEZnF
Localpotato
LocalPotato - When Swapping The Context Leads You To SYSTEM
Here we are again with our new *potato flavor, the LocalPotato! This was a cool finding so we decided to create this dedicated website ;)
FireFly : an advanced black-box fuzzer and not just a standard asset discovery tool
https://ift.tt/qQ3rGK6
Submitted February 11, 2023 at 02:29AM by hisxo
via reddit https://ift.tt/Pt6BxRH
https://ift.tt/qQ3rGK6
Submitted February 11, 2023 at 02:29AM by hisxo
via reddit https://ift.tt/Pt6BxRH
GitHub
GitHub - Brum3ns/firefly: Black box fuzzer for web applications
Black box fuzzer for web applications. Contribute to Brum3ns/firefly development by creating an account on GitHub.
Active Malware Campaign Targeting Popular Python Packages Underway
https://ift.tt/s6Qlbck
Submitted February 11, 2023 at 06:02AM by louis11
via reddit https://ift.tt/JTYhDbs
https://ift.tt/s6Qlbck
Submitted February 11, 2023 at 06:02AM by louis11
via reddit https://ift.tt/JTYhDbs
Phylum
Phylum Discovers Revived Crypto Wallet Address Replacement Attack
Phylum discovers over 451 unique malicious packages targeting popular PyPI packages like Selenium.
Understanding auditd logs for threat hunting
https://ift.tt/AWke2yr
Submitted February 11, 2023 at 01:07PM by InH4te
via reddit https://ift.tt/KkcTJfV
https://ift.tt/AWke2yr
Submitted February 11, 2023 at 01:07PM by InH4te
via reddit https://ift.tt/KkcTJfV
Medium
Linux auditd for Threat Detection [Part 2]
Part 1: Linux auditd for Threat Detection [Part 1]
GitHub - dwisiswant0/gfx: A wrapper around grep, to help you grep for things! - Improved version of gf by @tomnomnom.
https://ift.tt/WXjFeU7
Submitted February 11, 2023 at 06:31PM by dwisiswant0
via reddit https://ift.tt/zfcUInx
https://ift.tt/WXjFeU7
Submitted February 11, 2023 at 06:31PM by dwisiswant0
via reddit https://ift.tt/zfcUInx
GitHub
GitHub - dwisiswant0/gfx: A wrapper around grep, to help you grep for things! - Improved version of gf by @tomnomnom.
A wrapper around grep, to help you grep for things! - Improved version of gf by @tomnomnom. - GitHub - dwisiswant0/gfx: A wrapper around grep, to help you grep for things! - Improved version of gf ...
CHERIoT: Rethinking security for low-cost embedded systems - Microsoft Research
https://ift.tt/v4tiz75
Submitted February 12, 2023 at 03:00PM by Gallus
via reddit https://ift.tt/zXCce0S
https://ift.tt/v4tiz75
Submitted February 12, 2023 at 03:00PM by Gallus
via reddit https://ift.tt/zXCce0S
Microsoft Research
CHERIoT: Rethinking security for low-cost embedded systems - Microsoft Research
Small embedded cores have little area to spare for security features and yet must often run code written in unsafe languages and, increasingly, are exposed to the hostile Internet. CHERIoT (Capability Hardware Extension to RISC-V for Internet of Things)…