Bitwarden PINs can be brute-forced, a how-to and reason for stronger master passwords.
https://ift.tt/10GmJ5A
Submitted March 19, 2023 at 09:55PM by AverageCowboyCentaur
via reddit https://ift.tt/x2nGzjs
https://ift.tt/10GmJ5A
Submitted March 19, 2023 at 09:55PM by AverageCowboyCentaur
via reddit https://ift.tt/x2nGzjs
Obfuscating WebAssembly using Emnoscripten with an LLVM-based obfuscator
https://ift.tt/GkWhQR2
Submitted March 20, 2023 at 01:23PM by Hawkis98
via reddit https://ift.tt/YApPODq
https://ift.tt/GkWhQR2
Submitted March 20, 2023 at 01:23PM by Hawkis98
via reddit https://ift.tt/YApPODq
GitHub
GitHub - HakonHarnes/emcc-obf: Modified Emnoscripten compiler with LLVM-level obfuscation
Modified Emnoscripten compiler with LLVM-level obfuscation - HakonHarnes/emcc-obf
Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research | Datadog Security Labs
https://ift.tt/WuEm5J4
Submitted March 20, 2023 at 07:39PM by RedTermSession
via reddit https://ift.tt/NTl051P
https://ift.tt/WuEm5J4
Submitted March 20, 2023 at 07:39PM by RedTermSession
via reddit https://ift.tt/NTl051P
Datadoghq
Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research
Public disclosure of CloudTrail bypass in AWS Service Catalog and other logging research.
Persistence – Service Control Manager
https://ift.tt/Bey0F8x
Submitted March 20, 2023 at 09:48PM by netbiosX
via reddit https://ift.tt/3NaECwg
https://ift.tt/Bey0F8x
Submitted March 20, 2023 at 09:48PM by netbiosX
via reddit https://ift.tt/3NaECwg
Penetration Testing Lab
Persistence – Service Control Manager
The service control manager (SCM) is responsible to start and stop services in windows environments including device drivers and start up applications. Microsoft introduced in Windows 2000 and late…
Attackers are starting to target .NET developers with malicious-code NuGet packages
https://ift.tt/ZBLEkfO
Submitted March 20, 2023 at 08:59PM by n0llbyte
via reddit https://ift.tt/LYCQ2Mg
https://ift.tt/ZBLEkfO
Submitted March 20, 2023 at 08:59PM by n0llbyte
via reddit https://ift.tt/LYCQ2Mg
JFrog
Attackers are starting to target .NET developers with malicious-code NuGet packages | JFrog
Update 2023-03-21 – We’ve talked with members of the NuGet team and they had already detected and removed the malicious packages in question. Malicious packages are often spread by the open source NPM and PyPI package repositories, with few other repositories…
New tool to detect use of known secrets in web frameworks - Badsecrets
https://ift.tt/a8bHJE3
Submitted March 20, 2023 at 11:42PM by L1QU1DF1R3
via reddit https://ift.tt/zgnoq0Y
https://ift.tt/a8bHJE3
Submitted March 20, 2023 at 11:42PM by L1QU1DF1R3
via reddit https://ift.tt/zgnoq0Y
Blacklanternsecurity
Introducing Badsecrets
A Library for Detecting Known or Weak Secrets Across Many Web Frameworks
KillNet and affiliate hacktivist groups targeting healthcare with DDoS attacks
https://ift.tt/9BNJrSX
Submitted March 20, 2023 at 11:05PM by SCI_Rusher
via reddit https://ift.tt/QsdrlzU
https://ift.tt/9BNJrSX
Submitted March 20, 2023 at 11:05PM by SCI_Rusher
via reddit https://ift.tt/QsdrlzU
Microsoft News
KillNet and affiliate hacktivist groups targeting healthcare with DDoS attacks
KillNet, a group that the US Department of Health and Human Services (DHHS) has called pro-Russia hacktivists, has been launching waves of attacks targeting governments and companies with focus on the healthcare sector. In this blog post, we provide an overview…
Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.
https://ift.tt/709Lrvy
Submitted March 21, 2023 at 12:20AM by XaFF-XaFF
via reddit https://ift.tt/Oz1itfh
https://ift.tt/709Lrvy
Submitted March 21, 2023 at 12:20AM by XaFF-XaFF
via reddit https://ift.tt/Oz1itfh
GitHub
GitHub - XaFF-XaFF/Black-Angel-Rootkit: Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled…
Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality. - GitHub - XaFF-XaFF/Black-Angel-Rootkit: Black Angel is a W...
Uncovering HinataBot: A Deep Dive into a Go-Based Threat
https://ift.tt/OaQ36sz
Submitted March 21, 2023 at 08:25AM by montouesto
via reddit https://ift.tt/9t0mbH4
https://ift.tt/OaQ36sz
Submitted March 21, 2023 at 08:25AM by montouesto
via reddit https://ift.tt/9t0mbH4
Akamai
Uncovering HinataBot: A Deep Dive into a Go-Based Threat | Akamai
Akamai researchers uncover and reverse engineer a new Go-based DDoS botnet.
Havoc Across the Cyberspace
https://ift.tt/EwmyQVq
Submitted March 21, 2023 at 08:24AM by montouesto
via reddit https://ift.tt/7UixQuR
https://ift.tt/EwmyQVq
Submitted March 21, 2023 at 08:24AM by montouesto
via reddit https://ift.tt/7UixQuR
Zscaler
Havoc Across the Cyberspace
ThreatLabz observed a new campaign targeting a Government organization in which the threat actors utilized a new Command & Control (C2) framework named Havoc
ShellBot Malware Being Distributed to Linux SSH Servers
https://ift.tt/i2cBMQp
Submitted March 21, 2023 at 08:23AM by montouesto
via reddit https://ift.tt/5sEXORx
https://ift.tt/i2cBMQp
Submitted March 21, 2023 at 08:23AM by montouesto
via reddit https://ift.tt/5sEXORx
ASEC BLOG
ShellBot Malware Being Distributed to Linux SSH Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered the ShellBot malware being installed on poorly managed Linux SSH servers. ShellBot, also known as PerlBot, is a DDoS Bot malware developed in Perl and characteristically uses IRC protocol…
Find Threats in Event Logs with Hayabusa
https://ift.tt/GlZVkan
Submitted March 21, 2023 at 08:10AM by skybound5
via reddit https://ift.tt/7SYINCd
https://ift.tt/GlZVkan
Submitted March 21, 2023 at 08:10AM by skybound5
via reddit https://ift.tt/7SYINCd
Eric’s Substack
Find Threats in Event Logs with Hayabusa
A powerful technique for finding threats in Windows event logs.
Parallels Desktop Toolgate Vulnerability
https://ift.tt/C93qtDe
Submitted March 21, 2023 at 03:08PM by poltess0
via reddit https://ift.tt/cuJ74DW
https://ift.tt/C93qtDe
Submitted March 21, 2023 at 03:08PM by poltess0
via reddit https://ift.tt/cuJ74DW
Impalabs
Parallels Desktop Toolgate Vulnerability
This advisory contains information about the following vulnerabilities:
- Directory Traversal Arbitrary File Write Vulnerability
- Directory Traversal Arbitrary File Write Vulnerability
Converting string to enum at the cost of 50 GB: let's analyze the CVE-2020-36620 vulnerability
https://ift.tt/M8kdQG0
Submitted March 21, 2023 at 04:46PM by Xadartt
via reddit https://ift.tt/oWBz6EP
https://ift.tt/M8kdQG0
Submitted March 21, 2023 at 04:46PM by Xadartt
via reddit https://ift.tt/oWBz6EP
PVS-Studio
Converting string to enum at the cost of 50 GB: let′s analyze th…
In this article, we′re going to discuss the CVE-2020-36620 vulnerability and see how a NuGet package for converting string to enum can make a C# application vulnerable to DoS attacks.
Deciphering Linux AuditD for Threat Detection Part 3
https://ift.tt/0GJ5zs1
Submitted March 21, 2023 at 04:25PM by InH4te
via reddit https://ift.tt/2U9yZQt
https://ift.tt/0GJ5zs1
Submitted March 21, 2023 at 04:25PM by InH4te
via reddit https://ift.tt/2U9yZQt
Medium
Linux auditd for Threat Detection [Final]
Mapping behaviors to auditd log events
elastic-security-labs-thawing-the-permafrost-of-icedid
https://ift.tt/itjxd5r
Submitted March 21, 2023 at 05:12PM by montouesto
via reddit https://ift.tt/62CgDcw
https://ift.tt/itjxd5r
Submitted March 21, 2023 at 05:12PM by montouesto
via reddit https://ift.tt/62CgDcw
Burp Project Settings for JumpCloud Console using a discovered JumpCloud API key
https://ift.tt/qj7XymO
Submitted March 21, 2023 at 06:39PM by AhBoon
via reddit https://ift.tt/DrXSULT
https://ift.tt/qj7XymO
Submitted March 21, 2023 at 06:39PM by AhBoon
via reddit https://ift.tt/DrXSULT
We Want Shells
JumpCloud-Proxy
JumpCloud is a Directory as a Service provider providing cloud native Directory service for cloud native companies. In a Red Team engagement or Pentest scenario, one may come across a API token which could have Administrative Privileges. Instead of going…
Guide: Terraform Security
https://ift.tt/FXQdZwA
Submitted March 21, 2023 at 08:21PM by MiguelHzBz
via reddit https://ift.tt/8Sxgw4K
https://ift.tt/FXQdZwA
Submitted March 21, 2023 at 08:21PM by MiguelHzBz
via reddit https://ift.tt/8Sxgw4K
Sysdig
Terraform Security Best Practices – Sysdig
Terraform is the common tool if you work with IaC, but its security best practices must be followed carefully. This article provides that guidance.
Mitigating SSRF in 2023
https://ift.tt/EhW6jnc
Submitted March 21, 2023 at 08:03PM by l_tennant
via reddit https://ift.tt/2W1fGbM
https://ift.tt/EhW6jnc
Submitted March 21, 2023 at 08:03PM by l_tennant
via reddit https://ift.tt/2W1fGbM
Include Security Research Blog
Mitigating SSRF in 2023 - Include Security Research Blog
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to trick a server-side application to make a request to an unintended location. SSRF, unlike most other specific vulnerabilities, has gained its own spot on the OWASP Top 10 2021.…
A Guide to Delegated Administrator in AWS Organizations and Multi-Account Management and how to secure the Root Management Account
https://ift.tt/GZOvu3P
Submitted March 21, 2023 at 09:31PM by jsonpile
via reddit https://ift.tt/0kaZPil
https://ift.tt/GZOvu3P
Submitted March 21, 2023 at 09:31PM by jsonpile
via reddit https://ift.tt/0kaZPil
CloudQuery
A Guide to Delegated Administrator in AWS Organizations and Multi-Account Management | CloudQuery
A guide to managing multiple AWS Accounts using AWS Organizations and how to reduce blast radius by leveraging Delegated Administrator capabilities within AWS Organization to avoid usage of the management root account. This post covers security benefits…
Nexus: a new Android botnet? | Cleafy Labs
https://ift.tt/g7Vnq4H
Submitted March 21, 2023 at 09:26PM by f3d_0x0
via reddit https://ift.tt/TeugOva
https://ift.tt/g7Vnq4H
Submitted March 21, 2023 at 09:26PM by f3d_0x0
via reddit https://ift.tt/TeugOva
Cleafy
Nexus: a new Android botnet? | Cleafy Labs
A new Android banking trojan might be spreading under the name of Nexus. It is promoted via a MaaS subnoscription and it contains some relations with an already known SOVA banking trojan. Read the full article to know more about this new player in cybercrime.