New tool to detect use of known secrets in web frameworks - Badsecrets
https://ift.tt/a8bHJE3
Submitted March 20, 2023 at 11:42PM by L1QU1DF1R3
via reddit https://ift.tt/zgnoq0Y
https://ift.tt/a8bHJE3
Submitted March 20, 2023 at 11:42PM by L1QU1DF1R3
via reddit https://ift.tt/zgnoq0Y
Blacklanternsecurity
Introducing Badsecrets
A Library for Detecting Known or Weak Secrets Across Many Web Frameworks
KillNet and affiliate hacktivist groups targeting healthcare with DDoS attacks
https://ift.tt/9BNJrSX
Submitted March 20, 2023 at 11:05PM by SCI_Rusher
via reddit https://ift.tt/QsdrlzU
https://ift.tt/9BNJrSX
Submitted March 20, 2023 at 11:05PM by SCI_Rusher
via reddit https://ift.tt/QsdrlzU
Microsoft News
KillNet and affiliate hacktivist groups targeting healthcare with DDoS attacks
KillNet, a group that the US Department of Health and Human Services (DHHS) has called pro-Russia hacktivists, has been launching waves of attacks targeting governments and companies with focus on the healthcare sector. In this blog post, we provide an overview…
Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.
https://ift.tt/709Lrvy
Submitted March 21, 2023 at 12:20AM by XaFF-XaFF
via reddit https://ift.tt/Oz1itfh
https://ift.tt/709Lrvy
Submitted March 21, 2023 at 12:20AM by XaFF-XaFF
via reddit https://ift.tt/Oz1itfh
GitHub
GitHub - XaFF-XaFF/Black-Angel-Rootkit: Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled…
Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality. - GitHub - XaFF-XaFF/Black-Angel-Rootkit: Black Angel is a W...
Uncovering HinataBot: A Deep Dive into a Go-Based Threat
https://ift.tt/OaQ36sz
Submitted March 21, 2023 at 08:25AM by montouesto
via reddit https://ift.tt/9t0mbH4
https://ift.tt/OaQ36sz
Submitted March 21, 2023 at 08:25AM by montouesto
via reddit https://ift.tt/9t0mbH4
Akamai
Uncovering HinataBot: A Deep Dive into a Go-Based Threat | Akamai
Akamai researchers uncover and reverse engineer a new Go-based DDoS botnet.
Havoc Across the Cyberspace
https://ift.tt/EwmyQVq
Submitted March 21, 2023 at 08:24AM by montouesto
via reddit https://ift.tt/7UixQuR
https://ift.tt/EwmyQVq
Submitted March 21, 2023 at 08:24AM by montouesto
via reddit https://ift.tt/7UixQuR
Zscaler
Havoc Across the Cyberspace
ThreatLabz observed a new campaign targeting a Government organization in which the threat actors utilized a new Command & Control (C2) framework named Havoc
ShellBot Malware Being Distributed to Linux SSH Servers
https://ift.tt/i2cBMQp
Submitted March 21, 2023 at 08:23AM by montouesto
via reddit https://ift.tt/5sEXORx
https://ift.tt/i2cBMQp
Submitted March 21, 2023 at 08:23AM by montouesto
via reddit https://ift.tt/5sEXORx
ASEC BLOG
ShellBot Malware Being Distributed to Linux SSH Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered the ShellBot malware being installed on poorly managed Linux SSH servers. ShellBot, also known as PerlBot, is a DDoS Bot malware developed in Perl and characteristically uses IRC protocol…
Find Threats in Event Logs with Hayabusa
https://ift.tt/GlZVkan
Submitted March 21, 2023 at 08:10AM by skybound5
via reddit https://ift.tt/7SYINCd
https://ift.tt/GlZVkan
Submitted March 21, 2023 at 08:10AM by skybound5
via reddit https://ift.tt/7SYINCd
Eric’s Substack
Find Threats in Event Logs with Hayabusa
A powerful technique for finding threats in Windows event logs.
Parallels Desktop Toolgate Vulnerability
https://ift.tt/C93qtDe
Submitted March 21, 2023 at 03:08PM by poltess0
via reddit https://ift.tt/cuJ74DW
https://ift.tt/C93qtDe
Submitted March 21, 2023 at 03:08PM by poltess0
via reddit https://ift.tt/cuJ74DW
Impalabs
Parallels Desktop Toolgate Vulnerability
This advisory contains information about the following vulnerabilities:
- Directory Traversal Arbitrary File Write Vulnerability
- Directory Traversal Arbitrary File Write Vulnerability
Converting string to enum at the cost of 50 GB: let's analyze the CVE-2020-36620 vulnerability
https://ift.tt/M8kdQG0
Submitted March 21, 2023 at 04:46PM by Xadartt
via reddit https://ift.tt/oWBz6EP
https://ift.tt/M8kdQG0
Submitted March 21, 2023 at 04:46PM by Xadartt
via reddit https://ift.tt/oWBz6EP
PVS-Studio
Converting string to enum at the cost of 50 GB: let′s analyze th…
In this article, we′re going to discuss the CVE-2020-36620 vulnerability and see how a NuGet package for converting string to enum can make a C# application vulnerable to DoS attacks.
Deciphering Linux AuditD for Threat Detection Part 3
https://ift.tt/0GJ5zs1
Submitted March 21, 2023 at 04:25PM by InH4te
via reddit https://ift.tt/2U9yZQt
https://ift.tt/0GJ5zs1
Submitted March 21, 2023 at 04:25PM by InH4te
via reddit https://ift.tt/2U9yZQt
Medium
Linux auditd for Threat Detection [Final]
Mapping behaviors to auditd log events
elastic-security-labs-thawing-the-permafrost-of-icedid
https://ift.tt/itjxd5r
Submitted March 21, 2023 at 05:12PM by montouesto
via reddit https://ift.tt/62CgDcw
https://ift.tt/itjxd5r
Submitted March 21, 2023 at 05:12PM by montouesto
via reddit https://ift.tt/62CgDcw
Burp Project Settings for JumpCloud Console using a discovered JumpCloud API key
https://ift.tt/qj7XymO
Submitted March 21, 2023 at 06:39PM by AhBoon
via reddit https://ift.tt/DrXSULT
https://ift.tt/qj7XymO
Submitted March 21, 2023 at 06:39PM by AhBoon
via reddit https://ift.tt/DrXSULT
We Want Shells
JumpCloud-Proxy
JumpCloud is a Directory as a Service provider providing cloud native Directory service for cloud native companies. In a Red Team engagement or Pentest scenario, one may come across a API token which could have Administrative Privileges. Instead of going…
Guide: Terraform Security
https://ift.tt/FXQdZwA
Submitted March 21, 2023 at 08:21PM by MiguelHzBz
via reddit https://ift.tt/8Sxgw4K
https://ift.tt/FXQdZwA
Submitted March 21, 2023 at 08:21PM by MiguelHzBz
via reddit https://ift.tt/8Sxgw4K
Sysdig
Terraform Security Best Practices – Sysdig
Terraform is the common tool if you work with IaC, but its security best practices must be followed carefully. This article provides that guidance.
Mitigating SSRF in 2023
https://ift.tt/EhW6jnc
Submitted March 21, 2023 at 08:03PM by l_tennant
via reddit https://ift.tt/2W1fGbM
https://ift.tt/EhW6jnc
Submitted March 21, 2023 at 08:03PM by l_tennant
via reddit https://ift.tt/2W1fGbM
Include Security Research Blog
Mitigating SSRF in 2023 - Include Security Research Blog
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to trick a server-side application to make a request to an unintended location. SSRF, unlike most other specific vulnerabilities, has gained its own spot on the OWASP Top 10 2021.…
A Guide to Delegated Administrator in AWS Organizations and Multi-Account Management and how to secure the Root Management Account
https://ift.tt/GZOvu3P
Submitted March 21, 2023 at 09:31PM by jsonpile
via reddit https://ift.tt/0kaZPil
https://ift.tt/GZOvu3P
Submitted March 21, 2023 at 09:31PM by jsonpile
via reddit https://ift.tt/0kaZPil
CloudQuery
A Guide to Delegated Administrator in AWS Organizations and Multi-Account Management | CloudQuery
A guide to managing multiple AWS Accounts using AWS Organizations and how to reduce blast radius by leveraging Delegated Administrator capabilities within AWS Organization to avoid usage of the management root account. This post covers security benefits…
Nexus: a new Android botnet? | Cleafy Labs
https://ift.tt/g7Vnq4H
Submitted March 21, 2023 at 09:26PM by f3d_0x0
via reddit https://ift.tt/TeugOva
https://ift.tt/g7Vnq4H
Submitted March 21, 2023 at 09:26PM by f3d_0x0
via reddit https://ift.tt/TeugOva
Cleafy
Nexus: a new Android botnet? | Cleafy Labs
A new Android banking trojan might be spreading under the name of Nexus. It is promoted via a MaaS subnoscription and it contains some relations with an already known SOVA banking trojan. Read the full article to know more about this new player in cybercrime.
Windows Installer EOP (CVE-2023-21800)
https://ift.tt/AyRj8bv
Submitted March 21, 2023 at 08:56PM by poltess0
via reddit https://ift.tt/fQMeukX
https://ift.tt/AyRj8bv
Submitted March 21, 2023 at 08:56PM by poltess0
via reddit https://ift.tt/fQMeukX
Doyensec
Windows Installer EOP (CVE-2023-21800) · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
PHP filter chains: file read from error-based oracle
https://ift.tt/d5zGMm7
Submitted March 21, 2023 at 08:52PM by poltess0
via reddit https://ift.tt/ogfMW1G
https://ift.tt/d5zGMm7
Submitted March 21, 2023 at 08:52PM by poltess0
via reddit https://ift.tt/ogfMW1G
Synacktiv
PHP filter chains: file read from error-based oracle
The possibilities allowed by filter chains will never stop amazing us.
PowerHub 2.0 released
https://ift.tt/E49nVgh
Submitted March 22, 2023 at 04:07AM by 0xfffffg
via reddit https://ift.tt/MiRHAb9
https://ift.tt/E49nVgh
Submitted March 22, 2023 at 04:07AM by 0xfffffg
via reddit https://ift.tt/MiRHAb9
Decoding DKP Project $80K Exploit | QuillAudits
https://ift.tt/FWZgywE
Submitted March 22, 2023 at 04:30PM by Devendra_Khati
via reddit https://ift.tt/sTphuDc
https://ift.tt/FWZgywE
Submitted March 22, 2023 at 04:30PM by Devendra_Khati
via reddit https://ift.tt/sTphuDc
Medium
Decoding DKP Token‘s $80K Exploit | QuillAudits
On February 8, 2023, the DKP token on the BNB chain was attacked. The attacker used the flash loan technique to exploit the contract.
Selefra: The Open-Source Policy-as-Code Tool for Terraform and Muti-Cloud
https://ift.tt/typ5K0M
Submitted March 22, 2023 at 06:12PM by Zealousideal_War153
via reddit https://ift.tt/1XZlK2u
https://ift.tt/typ5K0M
Submitted March 22, 2023 at 06:12PM by Zealousideal_War153
via reddit https://ift.tt/1XZlK2u
GitHub
GitHub - selefra/selefra: Selefra means "select * from infrastructure". It is an open-source policy-as-code software that provides…
Selefra means "select * from infrastructure". It is an open-source policy-as-code software that provides analysis for multi-cloud and SaaS environments, including over 30 services...