A Guide to Delegated Administrator in AWS Organizations and Multi-Account Management and how to secure the Root Management Account
https://ift.tt/GZOvu3P
Submitted March 21, 2023 at 09:31PM by jsonpile
via reddit https://ift.tt/0kaZPil
https://ift.tt/GZOvu3P
Submitted March 21, 2023 at 09:31PM by jsonpile
via reddit https://ift.tt/0kaZPil
CloudQuery
A Guide to Delegated Administrator in AWS Organizations and Multi-Account Management | CloudQuery
A guide to managing multiple AWS Accounts using AWS Organizations and how to reduce blast radius by leveraging Delegated Administrator capabilities within AWS Organization to avoid usage of the management root account. This post covers security benefits…
Nexus: a new Android botnet? | Cleafy Labs
https://ift.tt/g7Vnq4H
Submitted March 21, 2023 at 09:26PM by f3d_0x0
via reddit https://ift.tt/TeugOva
https://ift.tt/g7Vnq4H
Submitted March 21, 2023 at 09:26PM by f3d_0x0
via reddit https://ift.tt/TeugOva
Cleafy
Nexus: a new Android botnet? | Cleafy Labs
A new Android banking trojan might be spreading under the name of Nexus. It is promoted via a MaaS subnoscription and it contains some relations with an already known SOVA banking trojan. Read the full article to know more about this new player in cybercrime.
Windows Installer EOP (CVE-2023-21800)
https://ift.tt/AyRj8bv
Submitted March 21, 2023 at 08:56PM by poltess0
via reddit https://ift.tt/fQMeukX
https://ift.tt/AyRj8bv
Submitted March 21, 2023 at 08:56PM by poltess0
via reddit https://ift.tt/fQMeukX
Doyensec
Windows Installer EOP (CVE-2023-21800) · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
PHP filter chains: file read from error-based oracle
https://ift.tt/d5zGMm7
Submitted March 21, 2023 at 08:52PM by poltess0
via reddit https://ift.tt/ogfMW1G
https://ift.tt/d5zGMm7
Submitted March 21, 2023 at 08:52PM by poltess0
via reddit https://ift.tt/ogfMW1G
Synacktiv
PHP filter chains: file read from error-based oracle
The possibilities allowed by filter chains will never stop amazing us.
PowerHub 2.0 released
https://ift.tt/E49nVgh
Submitted March 22, 2023 at 04:07AM by 0xfffffg
via reddit https://ift.tt/MiRHAb9
https://ift.tt/E49nVgh
Submitted March 22, 2023 at 04:07AM by 0xfffffg
via reddit https://ift.tt/MiRHAb9
Decoding DKP Project $80K Exploit | QuillAudits
https://ift.tt/FWZgywE
Submitted March 22, 2023 at 04:30PM by Devendra_Khati
via reddit https://ift.tt/sTphuDc
https://ift.tt/FWZgywE
Submitted March 22, 2023 at 04:30PM by Devendra_Khati
via reddit https://ift.tt/sTphuDc
Medium
Decoding DKP Token‘s $80K Exploit | QuillAudits
On February 8, 2023, the DKP token on the BNB chain was attacked. The attacker used the flash loan technique to exploit the contract.
Selefra: The Open-Source Policy-as-Code Tool for Terraform and Muti-Cloud
https://ift.tt/typ5K0M
Submitted March 22, 2023 at 06:12PM by Zealousideal_War153
via reddit https://ift.tt/1XZlK2u
https://ift.tt/typ5K0M
Submitted March 22, 2023 at 06:12PM by Zealousideal_War153
via reddit https://ift.tt/1XZlK2u
GitHub
GitHub - selefra/selefra: Selefra means "select * from infrastructure". It is an open-source policy-as-code software that provides…
Selefra means "select * from infrastructure". It is an open-source policy-as-code software that provides analysis for multi-cloud and SaaS environments, including over 30 services...
How to Create a Virtual Hacking Lab: The Ultimate Hacker Setup
https://ift.tt/VzZoj4J
Submitted March 22, 2023 at 08:11PM by flacao9
via reddit https://ift.tt/XjuKV7r
https://ift.tt/VzZoj4J
Submitted March 22, 2023 at 08:11PM by flacao9
via reddit https://ift.tt/XjuKV7r
StationX
How to Create a Virtual Hacking Lab: The Ultimate Hacker Setup
However many books you’ve read or courses you’ve taken, you know nothing beats hands-on practice. Obviously, attacking random systems is out of the question (ethical ha...
ChatGPT said that AI could hack the world! A DFIR analyst perspective.
https://ift.tt/oQealzT
Submitted March 22, 2023 at 10:35PM by chaign_c
via reddit https://ift.tt/RiVAbaw
https://ift.tt/oQealzT
Submitted March 22, 2023 at 10:35PM by chaign_c
via reddit https://ift.tt/RiVAbaw
ZeusCloud - An Open-source Cloud Security Platfrom
https://ift.tt/OP6qxVR
Submitted March 22, 2023 at 09:52PM by VariousAd5147
via reddit https://ift.tt/mhaLJOz
https://ift.tt/OP6qxVR
Submitted March 22, 2023 at 09:52PM by VariousAd5147
via reddit https://ift.tt/mhaLJOz
GitHub
GitHub - Zeus-Labs/ZeusCloud: Open Source Cloud Security
Open Source Cloud Security. Contribute to Zeus-Labs/ZeusCloud development by creating an account on GitHub.
Typhooncon's 2023 Call for Papers is open for submissions!
https://ift.tt/jYanc7Z
Submitted March 22, 2023 at 09:52PM by Marsy_star
via reddit https://ift.tt/wj5Pc8a
https://ift.tt/jYanc7Z
Submitted March 22, 2023 at 09:52PM by Marsy_star
via reddit https://ift.tt/wj5Pc8a
Malicious Actors Use Unicode Support in Python to Evade Detection
https://ift.tt/2nMSNGs
Submitted March 22, 2023 at 10:56PM by louis11
via reddit https://ift.tt/DOACip1
https://ift.tt/2nMSNGs
Submitted March 22, 2023 at 10:56PM by louis11
via reddit https://ift.tt/DOACip1
blog.phylum.io
Malicious Actors Use Unicode Support in Python to Evade Detection
Phylum uncovers a threat actor taking advantage of how the Python interpreter handles Unicode to obfuscate their malware.
Brute Ratel Analysis
https://ift.tt/5tC4rhb
Submitted March 23, 2023 at 01:51AM by Diesl
via reddit https://ift.tt/80ijDoh
https://ift.tt/5tC4rhb
Submitted March 23, 2023 at 01:51AM by Diesl
via reddit https://ift.tt/80ijDoh
YARA rule for rapid detection of PNG images affected by Acropalypse - CVE-2023-21036
https://ift.tt/cVHYxBf
Submitted March 23, 2023 at 12:53AM by fede_k
via reddit https://ift.tt/WTdzMrO
https://ift.tt/cVHYxBf
Submitted March 23, 2023 at 12:53AM by fede_k
via reddit https://ift.tt/WTdzMrO
GitHub
GitHub - infobyte/CVE-2023-21036: Detection and sanitization for Acropalypse Now - CVE-2023-21036
Detection and sanitization for Acropalypse Now - CVE-2023-21036 - infobyte/CVE-2023-21036
Detecting Unlinked Windows Services with Volatility 3
https://ift.tt/UMWhE09
Submitted March 23, 2023 at 02:02AM by transt
via reddit https://ift.tt/qU4Dh8Y
https://ift.tt/UMWhE09
Submitted March 23, 2023 at 02:02AM by transt
via reddit https://ift.tt/qU4Dh8Y
Blogspot
Memory Forensics R&D Illustrated: Detecting Hidden Windows Services
As mentioned in a recent blog post , our team is once again offering in-person training, and we have substantially updated our course for th...
Harvesting Logs for Fun and Profit
https://ift.tt/WkQANdC
Submitted March 23, 2023 at 06:29AM by DevSec23
via reddit https://ift.tt/vUozxe2
https://ift.tt/WkQANdC
Submitted March 23, 2023 at 06:29AM by DevSec23
via reddit https://ift.tt/vUozxe2
beny23.github.io
Harvesting Logs for Fun and Profit
From a security point of view, application logs are two-sided. On the one hand, it is really important to have good observability, to find out what is happening and what has happened. On the other hand, we don’t want to leak sensitive information. In this…
Veeam Backup and Replication CVE-2023-27532 Deep Dive and Linux POC Exploit
https://ift.tt/i6GEDrs
Submitted March 23, 2023 at 06:09PM by scopedsecurity
via reddit https://ift.tt/gi17pdr
https://ift.tt/i6GEDrs
Submitted March 23, 2023 at 06:09PM by scopedsecurity
via reddit https://ift.tt/gi17pdr
Horizon3.ai
Veeam Backup and Replication CVE-2023-27532 Deep Dive
Introduction Veeam has recently released an advisory for CVE-2023-27532 for Veeam Backup and Replication which allows an unauthenticated user with access to the Veeam backup service (TCP 9401 by default) to request cleartext credentials. Other’s have provides…
Remarks on “Chat Control”
https://ift.tt/PFiZyMX
Submitted March 23, 2023 at 08:21PM by feross
via reddit https://ift.tt/NIPs7KF
https://ift.tt/PFiZyMX
Submitted March 23, 2023 at 08:21PM by feross
via reddit https://ift.tt/NIPs7KF
A Few Thoughts on Cryptographic Engineering
Remarks on “Chat Control”
On March 23 I was invited to participate in a panel discussion at the European Internet Services Providers Association (EuroISPA). The focus of this discussion was on recent legislative proposals, …
Joomla! CVE-2023-23752 to Code Execution
https://ift.tt/9LX7RAB
Submitted March 23, 2023 at 07:58PM by chicksdigthelongrun
via reddit https://ift.tt/Y9VGAKc
https://ift.tt/9LX7RAB
Submitted March 23, 2023 at 07:58PM by chicksdigthelongrun
via reddit https://ift.tt/Y9VGAKc
Joomla! CVE-2023-23752 to Code Execution - Blog - VulnCheck
CVE-2023-23752 is an information leak affecting Joomla! 4.0 - 4.7. How can an attacker use this vulnerability to achieve code execution? How many internet-facing systems are at risk?
SHA-1 gets SHAttered — A deep dive into why it was retired
https://ift.tt/OSYrCzw
Submitted March 23, 2023 at 11:20PM by Ecmoy
via reddit https://ift.tt/2c7qvTR
https://ift.tt/OSYrCzw
Submitted March 23, 2023 at 11:20PM by Ecmoy
via reddit https://ift.tt/2c7qvTR
Evervault
SHA-1 gets SHAttered — Blog — Evervault
Theoretical attacks on SHA-1 have become practical. SHA-1 should be deprecated everywhere.
iMessage and OpenGraph for Fun and Profit
https://ift.tt/zG50WDp
Submitted March 24, 2023 at 05:24AM by nobodyhome5nxc
via reddit https://ift.tt/l1kRfpy
https://ift.tt/zG50WDp
Submitted March 24, 2023 at 05:24AM by nobodyhome5nxc
via reddit https://ift.tt/l1kRfpy