Kali Linux 2023.1 introduces 'Purple' distro for defensive security
https://ift.tt/dowJu6H
Submitted March 14, 2023 at 04:25PM by MrNobody136
via reddit https://ift.tt/9BIgRf0
https://ift.tt/dowJu6H
Submitted March 14, 2023 at 04:25PM by MrNobody136
via reddit https://ift.tt/9BIgRf0
GitLab
Home · Wiki · Kali Linux / kali-purple / Documentation · GitLab
The ultimate SOC-in-a-box community project
Bootkit Showcase: Real-World Examples of Infrastructure Security Threats
https://ift.tt/H80brGl
Submitted March 14, 2023 at 04:56PM by hardenedvault
via reddit https://ift.tt/BlUXEg2
https://ift.tt/H80brGl
Submitted March 14, 2023 at 04:56PM by hardenedvault
via reddit https://ift.tt/BlUXEg2
GitHub
bootkit-samples/README.md at master · hardenedvault/bootkit-samples
Bootkit sample for firmware attack. Contribute to hardenedvault/bootkit-samples development by creating an account on GitHub.
I have compiled a list of common methods people use to attempt to access accounts based on my research. It would be greatly appreciated if you could provide your feedback on the list. Thank you!
https://ift.tt/aBbAqyj
Submitted March 14, 2023 at 06:40PM by Kinsleynkt
via reddit https://ift.tt/RSCX9sw
https://ift.tt/aBbAqyj
Submitted March 14, 2023 at 06:40PM by Kinsleynkt
via reddit https://ift.tt/RSCX9sw
9 Types of Password Attacks and How to Stop Them | MojoAuth Blog
Passwords are a common form of authentication and are used to grant access to online accounts, devices, and other resources. However, passwords are also a common target for attackers, who may use a variety of techniques to try to guess or capture them. This…
Vulnerabilities in the TPM 2.0 reference implementation code
https://ift.tt/a2nMhp1
Submitted March 14, 2023 at 06:19PM by guedou
via reddit https://ift.tt/pfbLF83
https://ift.tt/a2nMhp1
Submitted March 14, 2023 at 06:19PM by guedou
via reddit https://ift.tt/pfbLF83
Quarkslab
Vulnerabilities in the TPM 2.0 reference implementation code
Examining OpenSSH Sandboxing and Privilege Separation – Attack Surface Analysis
https://ift.tt/8EvFmKh
Submitted March 14, 2023 at 10:43PM by n0llbyte
via reddit https://ift.tt/1VuXlYj
https://ift.tt/8EvFmKh
Submitted March 14, 2023 at 10:43PM by n0llbyte
via reddit https://ift.tt/1VuXlYj
JFrog
OpenSSH Privilege Separation and Sandbox - Attack Surface Analysis
An in-depth analysis of OpenSSH's attack surface and security measures. Read our research findings and analysis >
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
https://ift.tt/Tv7AxmX
Submitted March 15, 2023 at 06:55AM by Gallus
via reddit https://ift.tt/gcBMiFl
https://ift.tt/Tv7AxmX
Submitted March 15, 2023 at 06:55AM by Gallus
via reddit https://ift.tt/gcBMiFl
MDSec
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability - MDSec
Date: 14th March 2023 Today saw Microsoft patch an interesting vulnerability in Microsoft Outlook. The vulnerability is described as follows: Microsoft Office Outlook contains a privilege escalation vulnerability that allows...
Producing a POC for CVE-2022-42475 (Fortinet RCE)
https://ift.tt/oiNMkK6
Submitted March 15, 2023 at 01:21PM by BlackCatNeo
via reddit https://ift.tt/iRM7SLq
https://ift.tt/oiNMkK6
Submitted March 15, 2023 at 01:21PM by BlackCatNeo
via reddit https://ift.tt/iRM7SLq
We need a new way to measure AI security
https://ift.tt/D0EQd5v
Submitted March 15, 2023 at 09:18PM by yossarian_flew_away
via reddit https://ift.tt/T9egVSn
https://ift.tt/D0EQd5v
Submitted March 15, 2023 at 09:18PM by yossarian_flew_away
via reddit https://ift.tt/T9egVSn
Trail of Bits Blog
We need a new way to measure AI security
Tl;dr: Trail of Bits has launched a practice focused on machine learning and artificial intelligence, bringing together safety and security methodologies to create a new risk assessment and assuran…
How TikTok became a national security risk in the United States
https://ift.tt/GxbosJc
Submitted March 15, 2023 at 11:46PM by HeroldMcHerold
via reddit https://ift.tt/tHLOs72
https://ift.tt/GxbosJc
Submitted March 15, 2023 at 11:46PM by HeroldMcHerold
via reddit https://ift.tt/tHLOs72
Utah Business
How TikTok became a national security risk in the United States
Federal and local government officials, including Utah Gov. Spencer Cox, cite national security risk concerns.
CVE-2023-23415 - ICMP Remote Code Execution
https://ift.tt/CExKqzk
Submitted March 16, 2023 at 01:50AM by Thrimbor
via reddit https://ift.tt/2iJdZUN
https://ift.tt/CExKqzk
Submitted March 16, 2023 at 01:50AM by Thrimbor
via reddit https://ift.tt/2iJdZUN
I hacked Blackhat! 😎🤘- Responsible vulnerability disclosure
https://ift.tt/Knl7eid
Submitted March 16, 2023 at 08:33AM by zer0byt3
via reddit https://ift.tt/Q18nqvM
https://ift.tt/Knl7eid
Submitted March 16, 2023 at 08:33AM by zer0byt3
via reddit https://ift.tt/Q18nqvM
From Vulnerability to Victory: Defending Your CI/CD Pipeline
https://ift.tt/2lJ3pIR
Submitted March 16, 2023 at 12:23PM by BarakScribe
via reddit https://ift.tt/nGAkHfO
https://ift.tt/2lJ3pIR
Submitted March 16, 2023 at 12:23PM by BarakScribe
via reddit https://ift.tt/nGAkHfO
Scribe Security
From Vulnerability to Victory: Defending Your CI/CD Pipeline
This article uses some of the most infamous breaches in prominent CI/CD tools to illustrate the pipeline’s vulnerability as an attack vector and how to defend it
Nonsense, mayhem, browser security, CSRF, and CORS - Part 1
https://ift.tt/krGoP7Y
Submitted March 16, 2023 at 11:57AM by arnc_cryptid
via reddit https://ift.tt/zYfHCy8
https://ift.tt/krGoP7Y
Submitted March 16, 2023 at 11:57AM by arnc_cryptid
via reddit https://ift.tt/zYfHCy8
kernelpanic.cryptid.fr
Nonsense, mayhem, browser security, CSRF, and CORS - Part 1 | kernel panic
Keep calm and grab a shell
NPM request Library SSRF Cross Protocol Redirect Bypass
https://ift.tt/7su5zxk
Submitted March 16, 2023 at 06:45PM by nibblesec
via reddit https://ift.tt/s8IAwC1
https://ift.tt/7su5zxk
Submitted March 16, 2023 at 06:45PM by nibblesec
via reddit https://ift.tt/s8IAwC1
Doyensec
SSRF Cross Protocol Redirect Bypass · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Rapid7 Vulnerability Intelligence Report Webcast - today at 11am PDT / 2pm EDT
https://ift.tt/1VtSuGY
Submitted March 16, 2023 at 08:17PM by iagox86
via reddit https://ift.tt/qzdFGMO
https://ift.tt/1VtSuGY
Submitted March 16, 2023 at 08:17PM by iagox86
via reddit https://ift.tt/qzdFGMO
Rapid7
2022 Vulnerability Intelligence Report Webcast
Rapid7’s Vulnerability Intelligence Report is an annual research report that highlights CVE exploitation trends, explores attacker use cases, and offers a practical framework for risk-based vulnerability prioritization. With the release of a new edition of…
Smart Contracts Security: Exploring Common Bugs
https://ift.tt/Qs9nvyM
Submitted March 16, 2023 at 08:00PM by kobsoN
via reddit https://ift.tt/b3MFJfU
https://ift.tt/Qs9nvyM
Submitted March 16, 2023 at 08:00PM by kobsoN
via reddit https://ift.tt/b3MFJfU
Introducing "safe npm" – magical NPM wrapper to protect developers from malware
https://ift.tt/nm5cTu6
Submitted March 17, 2023 at 12:46AM by feross
via reddit https://ift.tt/lfhotGB
https://ift.tt/nm5cTu6
Submitted March 17, 2023 at 12:46AM by feross
via reddit https://ift.tt/lfhotGB
Socket
Introducing "safe npm", a Socket npm Wrapper - Socket
Socket is proud to introduce an exciting new tool—“safe npm”—that protects developers whenever they use npm install.
Debugging D-Link: Emulating firmware and hacking hardware
https://ift.tt/xQEfbpM
Submitted March 17, 2023 at 01:08AM by netsecfriends
via reddit https://ift.tt/6ZOlehK
https://ift.tt/xQEfbpM
Submitted March 17, 2023 at 01:08AM by netsecfriends
via reddit https://ift.tt/6ZOlehK
www.greynoise.io
Debugging D-Link: Emulating firmware and hacking hardware
GreyNoise researchers explain the process of how attackers gain footholds in organizations via exploiting weaknesses in device firmware, with a practical, working example of exploiting several vulnerabilities in D-Link routers.
Surveying Software Supply Chain Security
https://ift.tt/vyq2No8
Submitted March 17, 2023 at 03:27AM by pmz
via reddit https://ift.tt/ySwRkIJ
https://ift.tt/vyq2No8
Submitted March 17, 2023 at 03:27AM by pmz
via reddit https://ift.tt/ySwRkIJ
www.i-programmer.info
Surveying Software Supply Chain Security
Programming book reviews, programming tutorials,programming news, C#, Ruby, Python,C, C++, PHP, Visual Basic, Computer book reviews, computer history, programming history, joomla, theory, spreadsheets and more.
Adversary Simulation with Voice Cloning in Real Time, Part 1
https://ift.tt/lWHoG8f
Submitted March 17, 2023 at 09:06AM by kerberoast
via reddit https://ift.tt/uWfypFb
https://ift.tt/lWHoG8f
Submitted March 17, 2023 at 09:06AM by kerberoast
via reddit https://ift.tt/uWfypFb
Threat Blog
Adversary Simulation with Voice Cloning in Real Time, Part 1
Every day, blog posts and news articles warn us about the danger of artificial intelligence (AI) and how the technology behind it can be used by criminals to perform sophisticated attacks.
Our clients often ask, “Should we be worried?” Emerging technology…
Our clients often ask, “Should we be worried?” Emerging technology…
How to Google Dork a Specific Website for Hacking
https://ift.tt/dgeRDjK
Submitted March 17, 2023 at 05:43PM by josh252
via reddit https://ift.tt/TeiF1HA
https://ift.tt/dgeRDjK
Submitted March 17, 2023 at 05:43PM by josh252
via reddit https://ift.tt/TeiF1HA
StationX
How to Google Dork a Specific Website for Hacking
Not sure how to Google dork a specific website? Read this article to learn what Google dorking is, how to Google dork, and issues to pay attention to.