Indirect Prompt Injection on Bing Chat
https://ift.tt/bKLdCMZ
Submitted March 01, 2023 at 03:49PM by Gallus
via reddit https://ift.tt/6i7DGO4
https://ift.tt/bKLdCMZ
Submitted March 01, 2023 at 03:49PM by Gallus
via reddit https://ift.tt/6i7DGO4
Using JFrog Artifactory? Make sure it doesn't mistakenly expose your secrets, apparently it's not uncommon
https://ift.tt/zGSnOjB
Submitted March 01, 2023 at 03:17PM by roy_6472
via reddit https://ift.tt/028KLis
https://ift.tt/zGSnOjB
Submitted March 01, 2023 at 03:17PM by roy_6472
via reddit https://ift.tt/028KLis
Legitsecurity
Exposing Secrets Via SDLC Tools: The Artifactory Case
Legit Security | Our team investigated how sensitive information can get exposed via SDLC tools that may be used as part of your development pipeline.
Finding 10x+ Performance Improvements in C++ with CodeQL – Part 2/2 on Combining Dynamic and Static Analysis for Performance Optimisation
https://ift.tt/ZqadTwY
Submitted March 01, 2023 at 08:20PM by poltess0
via reddit https://ift.tt/95jxiTz
https://ift.tt/ZqadTwY
Submitted March 01, 2023 at 08:20PM by poltess0
via reddit https://ift.tt/95jxiTz
Sean Heelan's Blog
Finding 10x+ Performance Improvements in C++ with CodeQL – Part 2/2 on Combining Dynamic and Static Analysis for Performance Optimisation
In the previous post I advocated for building systems that combine static and dynamic analysis for performance optimisation. By doing so, we can build tools that are much more useful than those foc…
CI/CD secrets extraction, tips and tricks
https://ift.tt/dmuYoR8
Submitted March 01, 2023 at 09:01PM by Gallus
via reddit https://ift.tt/1YGHJ4p
https://ift.tt/dmuYoR8
Submitted March 01, 2023 at 09:01PM by Gallus
via reddit https://ift.tt/1YGHJ4p
Synacktiv
CI/CD secrets extraction, tips and tricks
Introduction CI/CD (Continuous Integration / Continuous Delivery) systems are becoming more and more popular today.
Making New Connections – Leveraging Cisco AnyConnect Client to Drop and Run Payloads
https://ift.tt/NoqAHRK
Submitted March 01, 2023 at 10:00PM by 0xdea
via reddit https://ift.tt/qe3VJ2d
https://ift.tt/NoqAHRK
Submitted March 01, 2023 at 10:00PM by 0xdea
via reddit https://ift.tt/qe3VJ2d
NCC Group Research
Making New Connections – Leveraging Cisco AnyConnect Client to Drop and Run Payloads
The Cisco AnyConnect client has received a fair amount of scrutiny from the security community over the years, with a particular focus on leveraging the vpnagent.exe service for privilege escalatio…
Socket for Python — Protect your Python app from a software supply chain attack
https://ift.tt/cVyXWIx
Submitted March 02, 2023 at 03:21AM by feross
via reddit https://ift.tt/kAsjvU8
https://ift.tt/cVyXWIx
Submitted March 02, 2023 at 03:21AM by feross
via reddit https://ift.tt/kAsjvU8
Socket
Introducing Python Support - Socket
We're excited to announce that Socket now supports the Python programming language.
Incident Response in Google Cloud: Forensic Artifacts
https://ift.tt/DsUWCnl
Submitted March 02, 2023 at 04:02AM by MiguelHzBz
via reddit https://ift.tt/T0jMOG2
https://ift.tt/DsUWCnl
Submitted March 02, 2023 at 04:02AM by MiguelHzBz
via reddit https://ift.tt/T0jMOG2
blog.sygnia.co
Incident Response in Google Cloud: Forensic Artifacts
Discover effective incident response in Google Cloud. Learn how to analyze forensic artifacts for swift resolution. Expert insights on Sygnia blog.
Gitpod remote code execution 0-day vulnerability via WebSockets
https://ift.tt/rMyZPcf
Submitted March 02, 2023 at 04:55AM by lirantal
via reddit https://ift.tt/AIUshpq
https://ift.tt/rMyZPcf
Submitted March 02, 2023 at 04:55AM by lirantal
via reddit https://ift.tt/AIUshpq
Snyk
Gitpod remote code execution 0-day vulnerability via WebSockets | Snyk
In this post, we present the first findings from our current research into Cloud Development Environments (CDEs) — which allowed a full account takeover through visiting a link, exploiting a commonly misunderstood vulnerability (WebSocket Hijacking), and…
SSH PKI on top of Web PKI
https://ift.tt/ryNEKvV
Submitted March 02, 2023 at 01:40PM by ptman
via reddit https://ift.tt/VnscUdN
https://ift.tt/ryNEKvV
Submitted March 02, 2023 at 01:40PM by ptman
via reddit https://ift.tt/VnscUdN
paul.totterman.name
SSH PKI on top of Web PKI | Paul's page
Reading Future Internet PKI schemes need to be bootstrapped through web
PKI I was
reminded by all the problems I’ve had with SSH (Secure SHell) PKI (Public Key
Infrastructure). SSH host verification is trust-on-first-use (TOFU). So SSH is
protected from man…
PKI I was
reminded by all the problems I’ve had with SSH (Secure SHell) PKI (Public Key
Infrastructure). SSH host verification is trust-on-first-use (TOFU). So SSH is
protected from man…
BlackLotus UEFI bootkit: Myth confirmed
https://ift.tt/OE9aBT2
Submitted March 02, 2023 at 02:11PM by hardenedvault
via reddit https://ift.tt/ecPm2fy
https://ift.tt/OE9aBT2
Submitted March 02, 2023 at 02:11PM by hardenedvault
via reddit https://ift.tt/ecPm2fy
WeLiveSecurity
BlackLotus UEFI bootkit: Myth confirmed
ESET researchers are the first to publish an analysis of BlackLotus, the first in-the-wild UEFI bootkit capable of bypassing UEFI Secure Boot.
Taking over booking.com accounts by abusing OAuth 2.0
https://ift.tt/Z8Q51hX
Submitted March 02, 2023 at 06:50PM by ynvb
via reddit https://ift.tt/hI5MWDH
https://ift.tt/Z8Q51hX
Submitted March 02, 2023 at 06:50PM by ynvb
via reddit https://ift.tt/hI5MWDH
salt.security
Salt Labs | Traveling with OAuth - Account Takeover on Booking.com
Given the widespread usage of OAuth, any vulnerabilities found in its components or their implementations may lead to considerable security impact in the applications and services using them.
Lesser Known Persistence Techniques of WinXP are still effective on Win 10 and 11.
https://ift.tt/ZPR4evG
Submitted March 03, 2023 at 01:07AM by jat0369
via reddit https://ift.tt/ZeGSuAz
https://ift.tt/ZPR4evG
Submitted March 03, 2023 at 01:07AM by jat0369
via reddit https://ift.tt/ZeGSuAz
Cyberark
Persistence Techniques That Persist
Abstract Once threat actors gain a foothold on a system, they must implement techniques to maintain that access, even in the event of restarts, updates in credentials or any other type of change...
Backups of ALL customer vault data, including encrypted passwords and decrypted authenticator seeds, exfiltrated in 2022 LastPass breach, You will need to regenerate OTP KEYS for all services and if you have a weak master password or low iteration count, you will need to change all of your passwords
https://ift.tt/QnMXIyo
Submitted March 03, 2023 at 03:57AM by alexanderpas
via reddit https://ift.tt/5BEwpi3
https://ift.tt/QnMXIyo
Submitted March 03, 2023 at 03:57AM by alexanderpas
via reddit https://ift.tt/5BEwpi3
The LastPass Blog
Security Incident March 2023 Update & Actions - LastPass
Our March 2023 update regarding the LastPass security breach incident including our additional security measures and recommended actions for our LastPass users.
Nosey Parker, a fast secrets detector, now enumerates GitHub repos, writes SARIF output, and has 90 default rules
https://ift.tt/ZF6e7yW
Submitted March 03, 2023 at 05:31AM by exploding_nun
via reddit https://ift.tt/4IKJaQ8
https://ift.tt/ZF6e7yW
Submitted March 03, 2023 at 05:31AM by exploding_nun
via reddit https://ift.tt/4IKJaQ8
GitHub
Release Nosey Parker v0.12.0 · praetorian-inc/noseyparker
A prebuilt Docker image for this release is available for x86_64 architectures:
docker pull ghcr.io/praetorian-inc/noseyparker:v0.12.0
Additions
The scan command can now be given Git https URLs,...
docker pull ghcr.io/praetorian-inc/noseyparker:v0.12.0
Additions
The scan command can now be given Git https URLs,...
Reverse SSH - A Fast, Stable Reverse Shell Handler
https://ift.tt/KIBNmsE
Submitted March 03, 2023 at 06:10AM by Acceptable-Doubt-878
via reddit https://ift.tt/9qP3CTJ
https://ift.tt/KIBNmsE
Submitted March 03, 2023 at 06:10AM by Acceptable-Doubt-878
via reddit https://ift.tt/9qP3CTJ
research.aurainfosec.io
Reverse SSH: A Fast, Stable Reverse Shell Handler
Want to use SSH for reverse shells? Now you can.
Hacking the Nintendo DSi Browser
https://ift.tt/fubXSMw
Submitted March 04, 2023 at 12:47PM by Gallus
via reddit https://ift.tt/EOUqnQB
https://ift.tt/fubXSMw
Submitted March 04, 2023 at 12:47PM by Gallus
via reddit https://ift.tt/EOUqnQB
farlow.dev
Hacking the Nintendo DSi Browser
I managed to exploit the Nintendo DSi browser 15 years after it was released in Japan. This post will go over the journey and the technical details.
“StreamJacking” - Hijacking Hundreds of YouTube Channels Per Day Propagating Elon Musk Branded Crypto Giveaway Scams
https://ift.tt/NTepfE4
Submitted March 05, 2023 at 03:00PM by lowlet3443
via reddit https://ift.tt/txAFh76
https://ift.tt/NTepfE4
Submitted March 05, 2023 at 03:00PM by lowlet3443
via reddit https://ift.tt/txAFh76
Medium
“StreamJacking” - Hijacking Hundreds of YouTube Channels Per Day Propagating Elon Musk Branded Crypto Giveaway Scams
By Nati Tal (Guardio Labs)
Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign
https://ift.tt/1cdKnQe
Submitted March 05, 2023 at 05:50PM by -nbsp-
via reddit https://ift.tt/0fOMLWw
https://ift.tt/1cdKnQe
Submitted March 05, 2023 at 05:50PM by -nbsp-
via reddit https://ift.tt/0fOMLWw
kmsec.uk
kmsec | Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign
This post explores an often overlooked type of subdomain takeover attack I am dubbing "passive takeover."
Obfuscating Rubeus using Codecepticon
https://ift.tt/sYOKgQe
Submitted March 05, 2023 at 05:40PM by h0wlett
via reddit https://ift.tt/uJCbRad
https://ift.tt/sYOKgQe
Submitted March 05, 2023 at 05:40PM by h0wlett
via reddit https://ift.tt/uJCbRad
Pavel Tsakalidis - Personal Blog
Obfuscating Rubeus using Codecepticon
How to use Codecepticon for obfuscating offensive security tooling, such as Rubeus
Lord Of The Ring0 - Part 4 is out!
https://ift.tt/ut3bOXR
Submitted March 05, 2023 at 05:35PM by Idov31
via reddit https://ift.tt/cnwEFdM
https://ift.tt/ut3bOXR
Submitted March 05, 2023 at 05:35PM by Idov31
via reddit https://ift.tt/cnwEFdM
idov31.github.io
Lord Of The Ring0 - Part 4 | The call back home - Ido Veltzman - Security Blog
PrologueIn the last blog post, we learned some debugging concepts, understood what is IOCTL how to handle it and started to learn how to validate the data th...
Polynonce A Novel Attack against ECDSA. Paper, Code, and associated Story
https://ift.tt/JuRxLfw
Submitted March 06, 2023 at 07:43PM by nhamiel
via reddit https://ift.tt/hCZnrQt
https://ift.tt/JuRxLfw
Submitted March 06, 2023 at 07:43PM by nhamiel
via reddit https://ift.tt/hCZnrQt
Kudelski Security Research
Polynonce: A Tale of a Novel ECDSA Attack and Bitcoin Tears
Introduction In this blog post, we tell a tale of how we discovered a novel attack against ECDSA and how we applied it to datasets we found in the wild, including the Bitcoin and Ethereum net…