Fortinet FortiNAC CVE-2022-39952 Deep-Dive, IOCs, and POC
https://ift.tt/wH6o0Fv
Submitted February 21, 2023 at 06:22PM by scopedsecurity
via reddit https://ift.tt/mPojJW4
https://ift.tt/wH6o0Fv
Submitted February 21, 2023 at 06:22PM by scopedsecurity
via reddit https://ift.tt/mPojJW4
Horizon3.ai
Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs
Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs. This vulnerability allows remote code execution as the root user.
ClamAV Critical Patch Review
https://ift.tt/aU2jHKu
Submitted February 21, 2023 at 08:32PM by g_e_r_h_a_r_d
via reddit https://ift.tt/g7FhPZS
https://ift.tt/aU2jHKu
Submitted February 21, 2023 at 08:32PM by g_e_r_h_a_r_d
via reddit https://ift.tt/g7FhPZS
ONEKEY
ClamAV Critical Patch Review
Explore issues resolved by ClamAV's recent critical patch in technical deep dive.
A Deep Dive Into a PoshC2 Implant
https://ift.tt/ZXC31Eo
Submitted February 21, 2023 at 08:32PM by CyberMasterV
via reddit https://ift.tt/UYRiqj5
https://ift.tt/ZXC31Eo
Submitted February 21, 2023 at 08:32PM by CyberMasterV
via reddit https://ift.tt/UYRiqj5
SecurityScorecard
Resources
Explore cybersecurity white papers, data sheets, webinars, videos, informative blogs, and more with SecurityScorecard.
OWASP Kubernetes Top 10 - Tools & Techniques
https://ift.tt/nw3fX7C
Submitted February 21, 2023 at 09:15PM by MiguelHzBz
via reddit https://ift.tt/YBCr0lQ
https://ift.tt/nw3fX7C
Submitted February 21, 2023 at 09:15PM by MiguelHzBz
via reddit https://ift.tt/YBCr0lQ
Sysdig
OWASP Kubernetes Top 10 – Sysdig
OWASP has created the OWASP Kubernetes Top 10, which helps identify the most likely risks.
Introducing Sublime: A new, open approach to email security
https://ift.tt/M4AnyGu
Submitted February 22, 2023 at 03:23AM by Glomar-Response
via reddit https://ift.tt/UrQBP2M
https://ift.tt/M4AnyGu
Submitted February 22, 2023 at 03:23AM by Glomar-Response
via reddit https://ift.tt/UrQBP2M
sublime.security
Introducing Sublime: A new, open approach to email security
The detection and response platform for securing email.
Let's build a Chrome extension that steals everything
https://ift.tt/fUlTB7M
Submitted February 22, 2023 at 07:23AM by ScottContini
via reddit https://ift.tt/UqfE8Ah
https://ift.tt/fUlTB7M
Submitted February 22, 2023 at 07:23AM by ScottContini
via reddit https://ift.tt/UqfE8Ah
Building Browser Extensions
Let's build a Chrome extension that steals everything
Today's adventure: DIY whole hog data exfiltration
Multiple vulnerabilities in Nokia BTS Airscale ASIKA [PDF]
https://ift.tt/RH0uF3Q
Submitted February 22, 2023 at 03:45PM by Gallus
via reddit https://ift.tt/vK1IAwm
https://ift.tt/RH0uF3Q
Submitted February 22, 2023 at 03:45PM by Gallus
via reddit https://ift.tt/vK1IAwm
A New Privilege Escalation Bug Class on macOS and iOS
https://ift.tt/5a38fiM
Submitted February 22, 2023 at 05:08PM by poltess0
via reddit https://ift.tt/MJcKbEy
https://ift.tt/5a38fiM
Submitted February 22, 2023 at 05:08PM by poltess0
via reddit https://ift.tt/MJcKbEy
Trellix
Trellix Advanced Research Center Discovers a New Privilege Escalation Bug Class on macOS and iOS
The Trellix Advanced Research Center vulnerability team has discovered a large new class of bugs that allow bypassing code signing to execute arbitrary code in the context of several platform applications, leading to escalation of privileges and sandbox escape…
Disabling ClamAV as an Unprivileged User
https://ift.tt/YlPaKhC
Submitted February 22, 2023 at 06:28PM by DLLCoolJ
via reddit https://ift.tt/QcGrYsB
https://ift.tt/YlPaKhC
Submitted February 22, 2023 at 06:28PM by DLLCoolJ
via reddit https://ift.tt/QcGrYsB
Archcloudlabs
Disabling ClamAV as an Unprivileged User
About The Project ClamAV is an Open Source antivirus engine that is widely used on mail servers to scan incoming messages. On February 15, 2023 ClamAV published a security advisory detailing a potential remote code execution vulnerability in its HFS+ file…
What the Hack: A Personal Story about Ethical Hacking
https://www.youtube.com/watch?v=pdH8bd-niyQ&list=PLEx5khR4g7PIEgcDlsEP5veliuyKgnpbt
Submitted February 22, 2023 at 07:03PM by Ambitious_Material67
via reddit https://ift.tt/JYuNhpc
https://www.youtube.com/watch?v=pdH8bd-niyQ&list=PLEx5khR4g7PIEgcDlsEP5veliuyKgnpbt
Submitted February 22, 2023 at 07:03PM by Ambitious_Material67
via reddit https://ift.tt/JYuNhpc
YouTube
What the Hack: A Personal Story about Ethical Hacking • Ben Sadeghipour • GOTO 2022
This presentation was recorded at GOTO Copenhagen 2022. #GOTOcon #GOTOcph
http://gotocph.com
Ben Sadeghipour - VP of Research at Hadrian Security @NahamSec
ORIGINAL TALK TITLE
What the Hack?
ABSTRACT
Join Ben Sadeghipour in this session. He is Head of…
http://gotocph.com
Ben Sadeghipour - VP of Research at Hadrian Security @NahamSec
ORIGINAL TALK TITLE
What the Hack?
ABSTRACT
Join Ben Sadeghipour in this session. He is Head of…
Vulnerability write-up - "Dangerous assumptions" (6 CVEs in Node.js packages)
https://ift.tt/jO0uhAm
Submitted February 22, 2023 at 10:10PM by ThomasRinsma
via reddit https://ift.tt/nf5xuNs
https://ift.tt/jO0uhAm
Submitted February 22, 2023 at 10:10PM by ThomasRinsma
via reddit https://ift.tt/nf5xuNs
Codean
Vulnerability write-up - "Dangerous assumptions"
d08e8132-1c34-4223-b83d-9b7622e0f9c4
Exploit Airlines to get Free WiFi - Airline Vulnerability
https://ift.tt/CRyj1H0
Submitted February 23, 2023 at 09:46AM by brekfasbaksetz
via reddit https://ift.tt/lBr6OmZ
https://ift.tt/CRyj1H0
Submitted February 23, 2023 at 09:46AM by brekfasbaksetz
via reddit https://ift.tt/lBr6OmZ
AD Offsec Testing Tools Pre-Compiled, up to date, and ready to use
https://ift.tt/lrj2Yk9
Submitted February 23, 2023 at 12:16PM by Pleasant-Drawer729
via reddit https://ift.tt/2DK3ouZ
https://ift.tt/lrj2Yk9
Submitted February 23, 2023 at 12:16PM by Pleasant-Drawer729
via reddit https://ift.tt/2DK3ouZ
GitHub
GitHub - Syslifters/offsec-tools: Compiled tools for internal assessments
Compiled tools for internal assessments. Contribute to Syslifters/offsec-tools development by creating an account on GitHub.
Detecting Server-Side Prototype Pollution
https://ift.tt/YqM9En8
Submitted February 23, 2023 at 04:29PM by dcthatch
via reddit https://ift.tt/fcBkS5N
https://ift.tt/YqM9En8
Submitted February 23, 2023 at 04:29PM by dcthatch
via reddit https://ift.tt/fcBkS5N
www.intruder.io
Detecting Server-Side Prototype Pollution
Prototype pollution bugs have been a feature in many CTFs in recent years, and real-world examples in open-source applications have led to impactful exploits such as remote code execution and denial-of-service. The discovery of these bugs has long relied…
41 imposter HTTP libraries discovered on PyPI
https://ift.tt/4yq59vL
Submitted February 23, 2023 at 06:45PM by ledgit
via reddit https://ift.tt/8vzaGIc
https://ift.tt/4yq59vL
Submitted February 23, 2023 at 06:45PM by ledgit
via reddit https://ift.tt/8vzaGIc
ReversingLabs
Developers beware: Imposter HTTP libraries lurk on PyPI
ReversingLabs researchers discovered more than three dozen malicious packages on the PyPI repository that mimic popular HTTP libraries.
Ronin 2.0–Open Source Ruby toolkit for security research and development
https://ift.tt/LCFkpP6
Submitted February 23, 2023 at 10:00PM by pmz
via reddit https://ift.tt/eCwdgrf
https://ift.tt/LCFkpP6
Submitted February 23, 2023 at 10:00PM by pmz
via reddit https://ift.tt/eCwdgrf
www.i-programmer.info
Ronin 2.0–Open Source Ruby toolkit for security research and development
Programming book reviews, programming tutorials,programming news, C#, Ruby, Python,C, C++, PHP, Visual Basic, Computer book reviews, computer history, programming history, joomla, theory, spreadsheets and more.
520 Malware Packages Published to PyPI in Ongoing Attack
https://ift.tt/3wEXDBo
Submitted February 24, 2023 at 07:01AM by louis11
via reddit https://ift.tt/sa23dtj
https://ift.tt/3wEXDBo
Submitted February 24, 2023 at 07:01AM by louis11
via reddit https://ift.tt/sa23dtj
Phylum
Phylum Discovers Aggressive Attack on PyPI Attempting to Deliver Rust Executable
Phylum discovers ~6,000 malicious packages published to PyPI shipping Rust stage 1 executables in ongoing malware campaign.
OpenEMR - Remote Code Execution in your Healthcare System
https://ift.tt/Bm0HuFK
Submitted February 24, 2023 at 02:50PM by _noraj_
via reddit https://ift.tt/DeCbOGI
https://ift.tt/Bm0HuFK
Submitted February 24, 2023 at 02:50PM by _noraj_
via reddit https://ift.tt/DeCbOGI
Sonarsource
OpenEMR - Remote Code Execution in your Healthcare System
We recently discovered three vulnerabilities that allow arbitrary code execution on OpenEMR. Let’s see what we can learn from them and discuss their patches!
The code that wasn't there: Reading memory on an Android device by accident
https://ift.tt/CAlZn4v
Submitted February 24, 2023 at 02:00PM by albinowax
via reddit https://ift.tt/ZRXAs3u
https://ift.tt/CAlZn4v
Submitted February 24, 2023 at 02:00PM by albinowax
via reddit https://ift.tt/ZRXAs3u
The GitHub Blog
The code that wasn't there: Reading memory on an Android device by accident
CVE-2022-25664, a vulnerability in the Qualcomm Adreno GPU, can be used to leak large amounts of information to a malicious Android application. Learn more about how the vulnerability can be used to leak information in both the user space and kernel space…
SSO Gadgets: Escalate (Self-)XSS to ATO
https://ift.tt/8C6lOfB
Submitted February 24, 2023 at 03:43PM by albinowax
via reddit https://ift.tt/JlDMeTX
https://ift.tt/8C6lOfB
Submitted February 24, 2023 at 03:43PM by albinowax
via reddit https://ift.tt/JlDMeTX
security.lauritz-holtmann.de
SSO Gadgets: Escalate (Self-)XSS to ATO
With the rise of Single-Sign-On (SSO) and especially OAuth 2.0 and OpenID Connect (OIDC), the attack surface of web applications has increased significantly. In this post, I will show how to escalate a Cross-Site Scripting (XSS) vulnerability to an Account…
A Review of Attacks Against Language-Based Package Managers
https://ift.tt/z7sWK5J
Submitted February 24, 2023 at 05:51PM by panoptischall
via reddit https://ift.tt/XzqE8o0
https://ift.tt/z7sWK5J
Submitted February 24, 2023 at 05:51PM by panoptischall
via reddit https://ift.tt/XzqE8o0