SHA-1 gets SHAttered — A deep dive into why it was retired
https://ift.tt/OSYrCzw
Submitted March 23, 2023 at 11:20PM by Ecmoy
via reddit https://ift.tt/2c7qvTR
https://ift.tt/OSYrCzw
Submitted March 23, 2023 at 11:20PM by Ecmoy
via reddit https://ift.tt/2c7qvTR
Evervault
SHA-1 gets SHAttered — Blog — Evervault
Theoretical attacks on SHA-1 have become practical. SHA-1 should be deprecated everywhere.
iMessage and OpenGraph for Fun and Profit
https://ift.tt/zG50WDp
Submitted March 24, 2023 at 05:24AM by nobodyhome5nxc
via reddit https://ift.tt/l1kRfpy
https://ift.tt/zG50WDp
Submitted March 24, 2023 at 05:24AM by nobodyhome5nxc
via reddit https://ift.tt/l1kRfpy
NAPLISTENER: more bad dreams from developers of SIESTAGRAPH
https://ift.tt/wcuUKDa
Submitted March 24, 2023 at 09:45AM by montouesto
via reddit https://ift.tt/kgqrbVt
https://ift.tt/wcuUKDa
Submitted March 24, 2023 at 09:45AM by montouesto
via reddit https://ift.tt/kgqrbVt
Elastic Blog
NAPLISTENER: more bad dreams from developers of SIESTAGRAPH
Elastic Security Labs observes that the threat behind SIESTAGRAPH has shifted priorities from data theft to persistent access, deploying new malware like NAPLISTENER to evade detection.
ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers
https://ift.tt/AZf49Ky
Submitted March 24, 2023 at 09:12AM by montouesto
via reddit https://ift.tt/0FYhmUk
https://ift.tt/AZf49Ky
Submitted March 24, 2023 at 09:12AM by montouesto
via reddit https://ift.tt/0FYhmUk
ASEC BLOG
ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered the ChinaZ DDoS Bot malware being installed on inadequately managed Linux SSH servers. As one of the Chinese threat groups that were first discovered around 2014, the ChinaZ group installs…
GitHub.com’s RSA SSH private key was briefly exposed in a public GitHub repository
https://ift.tt/A1pPycg
Submitted March 24, 2023 at 12:23PM by eaglex
via reddit https://ift.tt/g9ZPu2n
https://ift.tt/A1pPycg
Submitted March 24, 2023 at 12:23PM by eaglex
via reddit https://ift.tt/g9ZPu2n
The GitHub Blog
We updated our RSA SSH host key | The GitHub Blog
At approximately 05:00 UTC on March 24, out of an abundance of caution, we replaced our RSA SSH host key used to secure Git operations for GitHub.com.
Remote unauthenticated system and cloud takeover found in major AI tool
https://ift.tt/fBVneks
Submitted March 24, 2023 at 05:24PM by FlyingTriangle
via reddit https://ift.tt/CEyvZq1
https://ift.tt/fBVneks
Submitted March 24, 2023 at 05:24PM by FlyingTriangle
via reddit https://ift.tt/CEyvZq1
Protectai
Hacking AI: System Takeover in MLflow Strikes Again (And Again)
2 patch bypasses found for severe MLflow LFI/RFI vulnerability
All patched in MLflow version 2.2.3
Protect AI’s vulnerability scanning and exploit tools updated with bypasses
All patched in MLflow version 2.2.3
Protect AI’s vulnerability scanning and exploit tools updated with bypasses
cariddi v1.3.1 is out🥳
https://ift.tt/wI3PKrm
Submitted March 24, 2023 at 07:36PM by edoardottt
via reddit https://ift.tt/E96eyCc
https://ift.tt/wI3PKrm
Submitted March 24, 2023 at 07:36PM by edoardottt
via reddit https://ift.tt/E96eyCc
GitHub
GitHub - edoardottt/cariddi: Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens…
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more - GitHub - edoardottt/cariddi: Take a list of domains, crawl urls and scan for endpoin...
Improper Privilege Management in Grails Spring Security Core <= 5.1.0 CVE-2022-41923 - Synacktiv [PDF]
https://ift.tt/40MbEsw
Submitted March 24, 2023 at 07:09PM by Gallus
via reddit https://ift.tt/x2cQVIw
https://ift.tt/40MbEsw
Submitted March 24, 2023 at 07:09PM by Gallus
via reddit https://ift.tt/x2cQVIw
Top 10 Mobile App Security Risks #1 — Improper Platform Usage on Android
https://ift.tt/rJNQhd2
Submitted March 24, 2023 at 08:36PM by RikoTheMachete
via reddit https://ift.tt/qlpCB4v
https://ift.tt/rJNQhd2
Submitted March 24, 2023 at 08:36PM by RikoTheMachete
via reddit https://ift.tt/qlpCB4v
Medium
Top 10 Mobile App Security Risks #1 — Improper Platform Usage on Android
The first article in a series dedicated to the OWASP Mobile Top 10 — a comprehensive list of the most common and significant security…
Have you ever heard of apk.sh? It makes reverse engineering Android apps easier.
https://ift.tt/GFdoUBS
Submitted March 24, 2023 at 11:13PM by FipoKa
via reddit https://ift.tt/60xsDgw
https://ift.tt/GFdoUBS
Submitted March 24, 2023 at 11:13PM by FipoKa
via reddit https://ift.tt/60xsDgw
GitHub
GitHub - ax/apk.sh: apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding…
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK. - GitHub - ax/apk.sh: apk.sh makes reverse engineering...
2023 Red Canary Threat Detection Report
https://ift.tt/P4ca0EB
Submitted March 25, 2023 at 01:49AM by RedCanaryCo
via reddit https://ift.tt/ZpHxWfq
https://ift.tt/P4ca0EB
Submitted March 25, 2023 at 01:49AM by RedCanaryCo
via reddit https://ift.tt/ZpHxWfq
Red Canary
2023 Red Canary Threat Detection Report
View our latest threat report to learn about the top cyber threats, MITRE ATT&CK® techniques, and detection trends from the year.
Twitter Removed My Two-Factor Authentication Without Notice
https://ift.tt/c7eA5n8
Submitted March 25, 2023 at 03:33AM by Slapbox
via reddit https://ift.tt/36SUalh
https://ift.tt/c7eA5n8
Submitted March 25, 2023 at 03:33AM by Slapbox
via reddit https://ift.tt/36SUalh
Hacked.com
Twitter Removed My Two-Factor Authentication Without Notice
I woke up to a shocking email today. Twitter had turned off my two-factor authentication without my knowledge or approval.
Open Source API Security Tool
https://ift.tt/NfL9hwy
Submitted March 25, 2023 at 04:32AM by LawfulnessFlat9560
via reddit https://ift.tt/giCXpsO
https://ift.tt/NfL9hwy
Submitted March 25, 2023 at 04:32AM by LawfulnessFlat9560
via reddit https://ift.tt/giCXpsO
GitHub
GitHub - metlo-labs/metlo: Metlo is an open-source API security platform.
Metlo is an open-source API security platform. Contribute to metlo-labs/metlo development by creating an account on GitHub.
Simple Shellcode Dissection
https://ift.tt/JEvTmqb
Submitted March 25, 2023 at 04:30AM by _vavkamil_
via reddit https://ift.tt/ZF5N3Sm
https://ift.tt/JEvTmqb
Submitted March 25, 2023 at 04:30AM by _vavkamil_
via reddit https://ift.tt/ZF5N3Sm
SANS Internet Storm Center
InfoSec Handlers Diary Blog - SANS Internet Storm Center
Internet Storm Center Diary 2023-04-13, Author: Johannes Ullrich
InjectGPT: remote code execution by asking nicely (literally)
https://ift.tt/3EpSfgH
Submitted March 25, 2023 at 03:05PM by TheMedianPrinter
via reddit https://ift.tt/DVJ3Kd6
https://ift.tt/3EpSfgH
Submitted March 25, 2023 at 03:05PM by TheMedianPrinter
via reddit https://ift.tt/DVJ3Kd6
Synthetic Memory Protections: An update on ROP mitigations [PDF]
https://ift.tt/Ij21tfZ
Submitted March 25, 2023 at 10:17PM by Gallus
via reddit https://ift.tt/6gwia9k
https://ift.tt/Ij21tfZ
Submitted March 25, 2023 at 10:17PM by Gallus
via reddit https://ift.tt/6gwia9k
Breaking Pedersen Hashes in Practice
https://ift.tt/2SbolU8
Submitted March 26, 2023 at 07:41AM by Gallus
via reddit https://ift.tt/2lHmMsB
https://ift.tt/2SbolU8
Submitted March 26, 2023 at 07:41AM by Gallus
via reddit https://ift.tt/2lHmMsB
NCC Group Research Blog
Breaking Pedersen Hashes in Practice
The Pedersen hash function has gained popularity due to its efficiency in the arithmetic circuits used in zero-knowledge proof systems. Hash functions are a crucial primitive in cryptography, and z…
The rising trend of malicious packages in open source ecosystems | Snyk
https://ift.tt/Q3Nx1mw
Submitted March 26, 2023 at 01:16PM by lirantal
via reddit https://ift.tt/0cCmusf
https://ift.tt/Q3Nx1mw
Submitted March 26, 2023 at 01:16PM by lirantal
via reddit https://ift.tt/0cCmusf
Snyk
The rising trend of malicious packages in open source ecosystems | Snyk
In this article, we want to share a broader picture of how the Snyk security team is monitoring and disclosing security incidents concerning malicious packages.
shortest input that will trick GPT to reveal the secret key
https://gpa.43z.one
Submitted March 26, 2023 at 04:41PM by aNieke4bToSega8cIomu
via reddit https://ift.tt/7DMcx1X
https://gpa.43z.one
Submitted March 26, 2023 at 04:41PM by aNieke4bToSega8cIomu
via reddit https://ift.tt/7DMcx1X
Reddit
r/netsec on Reddit: shortest input that will trick GPT to reveal the secret key
Posted by u/aNieke4bToSega8cIomu - 59 votes and 16 comments
New OST2 class: "Vulnerabilities 1002: C-Family Software Implementation Vulnerabilities"
https://ift.tt/fDpq635
Submitted March 27, 2023 at 05:50PM by OpenSecurityTraining
via reddit https://ift.tt/vowpPcN
https://ift.tt/fDpq635
Submitted March 27, 2023 at 05:50PM by OpenSecurityTraining
via reddit https://ift.tt/vowpPcN
p.ost2.fyi
Vulnerabilities 1002: C-Family Software Implementation Vulnerabilities
This class teaches developers about vulnerabilities so that they can avoid writing them, and it teaches vulnerability hunters how to find them so they can be reported. The vulnerabilities covered in this class are uninitialized data access (UDA), race conditions…
SSH Security: Protecting Linux Server from Threats
https://ift.tt/lCR3okQ
Submitted March 27, 2023 at 05:31PM by Unprotectedtxt
via reddit https://ift.tt/uwpezgo
https://ift.tt/lCR3okQ
Submitted March 27, 2023 at 05:31PM by Unprotectedtxt
via reddit https://ift.tt/uwpezgo
Linux Blog
SSH Security: Protecting Your Linux Server from Threats
As an essential tool for managing servers, SSH (Secure Shell) provides a secure way to remotely access a server's command line. However, for best SSH