With KEYPLUG, China’s RedGolf Spies On, Steals From Wide Field of Targets
https://ift.tt/ZI6b2q8
Submitted March 30, 2023 at 06:01PM by montouesto
via reddit https://ift.tt/KZ1nNgR
https://ift.tt/ZI6b2q8
Submitted March 30, 2023 at 06:01PM by montouesto
via reddit https://ift.tt/KZ1nNgR
It’s a (SNMP) Trap: Gaining Code Execution on LibreNMS
https://ift.tt/LfqMCl7
Submitted March 30, 2023 at 07:50PM by monoimpact
via reddit https://ift.tt/FioRx2p
https://ift.tt/LfqMCl7
Submitted March 30, 2023 at 07:50PM by monoimpact
via reddit https://ift.tt/FioRx2p
CVE-2022-27666: My file your memory
https://ift.tt/N5HdZqV
Submitted March 30, 2023 at 07:38PM by albocoder1
via reddit https://ift.tt/bDyeZrs
https://ift.tt/N5HdZqV
Submitted March 30, 2023 at 07:38PM by albocoder1
via reddit https://ift.tt/bDyeZrs
Revisiting Heaven's Gate with Lumma Stealer
https://ift.tt/wby63az
Submitted March 30, 2023 at 07:29PM by CyberMasterV
via reddit https://ift.tt/8gJFfNS
https://ift.tt/wby63az
Submitted March 30, 2023 at 07:29PM by CyberMasterV
via reddit https://ift.tt/8gJFfNS
Security Scorecard
[Whitepaper] Revisiting Heaven’s Gate With Lumma Stealer
Booby Trapping IBM i
https://ift.tt/12CI7lx
Submitted March 30, 2023 at 08:44PM by buherator
via reddit https://ift.tt/5LzfJV1
https://ift.tt/12CI7lx
Submitted March 30, 2023 at 08:44PM by buherator
via reddit https://ift.tt/5LzfJV1
Silent Signal Techblog
Booby Trapping IBM i
Because we can!
Spam-tastic! npm Registry Swamped by Bizarre John Wick Frenzy
https://ift.tt/pleVGZi
Submitted March 30, 2023 at 09:05PM by feross
via reddit https://ift.tt/1Tn849p
https://ift.tt/pleVGZi
Submitted March 30, 2023 at 09:05PM by feross
via reddit https://ift.tt/1Tn849p
Socket
Spam-tastic! npm Registry Swamped by Bizarre John Wick Frenzy - Socket
The npm public registry is drowning in a tsunami of spam and phishing, and it's all thanks to everyone's favorite gun-toting antihero, John Wick.
Protection against enumeration and timing attacks with opaque IDs
https://ift.tt/egr7xTw
Submitted March 31, 2023 at 02:13AM by DeliveryTypical
via reddit https://ift.tt/uBwkfvg
https://ift.tt/egr7xTw
Submitted March 31, 2023 at 02:13AM by DeliveryTypical
via reddit https://ift.tt/uBwkfvg
Exact Realty Blog
Opaque IDs: the ultimate protection against enumeration attacks
IDs in APIs can be exploited to gain unauthorized access to data, for example though enumeration and timing attacks. These can be mitigated using authenticated encryption and opaque IDs.
We scanned every NPM and PyPI package for malware with ChatGPT
https://ift.tt/lUQbvjP
Submitted March 31, 2023 at 05:48AM by feross
via reddit https://ift.tt/NTAyJ63
https://ift.tt/lUQbvjP
Submitted March 31, 2023 at 05:48AM by feross
via reddit https://ift.tt/NTAyJ63
Socket
Introducing Socket AI – ChatGPT-Powered Threat Analysis - Socket
Socket is using ChatGPT to examine every npm and PyPI package for security issues.
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife
https://ift.tt/BHhQp9A
Submitted March 30, 2023 at 07:43PM by EspoJ
via reddit https://ift.tt/JrWbM8j
https://ift.tt/BHhQp9A
Submitted March 30, 2023 at 07:43PM by EspoJ
via reddit https://ift.tt/JrWbM8j
SentinelOne
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife
A sophisticated new toolset is being used to harvest credentials from multiple cloud service providers, including AWS SES and Microsoft Office 365.
A Comparison of Exploit-DB and 0day.today
https://ift.tt/ar2IE3F
Submitted March 31, 2023 at 09:11PM by chicksdigthelongrun
via reddit https://ift.tt/doa3clt
https://ift.tt/ar2IE3F
Submitted March 31, 2023 at 09:11PM by chicksdigthelongrun
via reddit https://ift.tt/doa3clt
A Comparison of Exploit-DB and 0day.today - Blog - VulnCheck
Exploit-DB and 0day.today are two of the largest public exploit databases. In this blog, we compare the databases to determine which one is the most relevant today.
SafeDep Vet - Open Source Software Supply Chain Dependency Risks 🚀
https://ift.tt/NsBXrw2
Submitted March 31, 2023 at 11:42PM by madhuakula
via reddit https://ift.tt/NsqaJQr
https://ift.tt/NsBXrw2
Submitted March 31, 2023 at 11:42PM by madhuakula
via reddit https://ift.tt/NsqaJQr
safedep.io
Introducing SafeDep vet 🚀 | SafeDep
Today we are super excited to release the SafeDep vet 🚀 to identify risks in Open Source dependencies and establish trust in open source software supply chain security.
Understand your open source software supply chain dependency risks
https://ift.tt/ndtxRlp
Submitted April 01, 2023 at 12:31AM by nicksthehacker_
via reddit https://ift.tt/ZRV0oP8
https://ift.tt/ndtxRlp
Submitted April 01, 2023 at 12:31AM by nicksthehacker_
via reddit https://ift.tt/ZRV0oP8
boringtools/git-alerts: A Public Git repository & misconfiguration detection tool
https://ift.tt/CVvOLhg
Submitted April 01, 2023 at 02:36AM by nicksthehacker_
via reddit https://ift.tt/p2Ehm0z
https://ift.tt/CVvOLhg
Submitted April 01, 2023 at 02:36AM by nicksthehacker_
via reddit https://ift.tt/p2Ehm0z
GitHub
GitHub - boringtools/git-alerts: A Public Git repository & misconfiguration detection tool
A Public Git repository & misconfiguration detection tool - GitHub - boringtools/git-alerts: A Public Git repository & misconfiguration detection tool
How to avoid the aCropalypse
https://ift.tt/mLH71Dl
Submitted April 01, 2023 at 10:19AM by Gallus
via reddit https://ift.tt/SljWyXK
https://ift.tt/mLH71Dl
Submitted April 01, 2023 at 10:19AM by Gallus
via reddit https://ift.tt/SljWyXK
Trail of Bits Blog
How to avoid the aCropalypse
By Henrik Brodin, Lead Security Engineer, Research The aCropalypse is upon us! Last week, news about CVE-2023-21036, nicknamed the “aCropalypse,” spread across Twitter and other media, and I quickl…
Leveraging LLMs for solving bounty hunting pain points
https://ift.tt/GPrzuOV
Submitted April 01, 2023 at 12:57PM by DebugDucky
via reddit https://ift.tt/wDNInRX
https://ift.tt/GPrzuOV
Submitted April 01, 2023 at 12:57PM by DebugDucky
via reddit https://ift.tt/wDNInRX
Charlie's blog
Leveraging LLMs for solving bounty hunting pain points
In 2022, I embarked on a journey with jswzl, believing that a single developer could deliver immense value without a team by focusing on high-value outputs and minimizing low-leverage work. As a so…
Exploiting Hibernate Injection in "Order by" Clause (Oracle database)
https://ift.tt/fwKDRTM
Submitted April 01, 2023 at 03:24PM by 1046ica
via reddit https://ift.tt/FQKidLU
https://ift.tt/fwKDRTM
Submitted April 01, 2023 at 03:24PM by 1046ica
via reddit https://ift.tt/FQKidLU
www.mannulinux.org
Exploiting Hibernate Injection in "Order by" Clause (Oracle database)
Learn Basic Concepts of Linux. Best site to learn Linux from beginner to Advanced.
The Defender's Guide to the 3CX Supply Chain Attack - How it happened, why it matters, and what's being done about it
https://ift.tt/rhLZSKT
Submitted April 01, 2023 at 04:03PM by SuaveHobo
via reddit https://ift.tt/1ydlLZ9
https://ift.tt/rhLZSKT
Submitted April 01, 2023 at 04:03PM by SuaveHobo
via reddit https://ift.tt/1ydlLZ9
Opalsec
The Defender's Guide to the 3CX Supply Chain Attack
How it happened, why it matters, and what's being done about it.
Developing a Robust Vulnerability Detection Tool for ink!
https://ift.tt/dxavLSi
Submitted April 01, 2023 at 07:12PM by kruksym
via reddit https://ift.tt/r7UnO21
https://ift.tt/dxavLSi
Submitted April 01, 2023 at 07:12PM by kruksym
via reddit https://ift.tt/r7UnO21
Medium
Developing a Robust Vulnerability Detection Tool for ink! Smart Contracts on Substrate-Based Blockchains
CoinFabrik received a grant from the Web3 Foundation to develop a proof-of-concept tool for detecting security vulnerabilities in Parity’s…
"Alexa, what is my wifi password?" by Daniel, a 14 year old developer
https://ift.tt/l2DhbMK
Submitted April 01, 2023 at 07:00PM by Gallus
via reddit https://ift.tt/2zrUbOZ
https://ift.tt/l2DhbMK
Submitted April 01, 2023 at 07:00PM by Gallus
via reddit https://ift.tt/2zrUbOZ
dragon863.github.io
Dragon863 - "Alexa, What is my Wifi Password?"
Taking a look at the (in)security of the amazon echo dot.
"Dissecting redis CVE-2023-28425 with chatGPT as assistant" blog post
https://ift.tt/eTt7AKF
Submitted April 03, 2023 at 01:29AM by NoPaleontologist7419
via reddit https://ift.tt/ZDvH3WQ
https://ift.tt/eTt7AKF
Submitted April 03, 2023 at 01:29AM by NoPaleontologist7419
via reddit https://ift.tt/ZDvH3WQ
Lambda driver blog
Dissecting redis CVE-2023-28425 with chatGPT as assistant
Intro
Malicious ISO File Leads to Domain Wide Ransomware
https://ift.tt/Pq5biFo
Submitted April 03, 2023 at 07:04AM by TheDFIRReport
via reddit https://ift.tt/B7UF0db
https://ift.tt/Pq5biFo
Submitted April 03, 2023 at 07:04AM by TheDFIRReport
via reddit https://ift.tt/B7UF0db
The DFIR Report
Malicious ISO File Leads to Domain Wide Ransomware - The DFIR Report
IcedID continues to deliver malspam emails to facilitate a compromise. This case covers the activity from a campaign in late September of 2022. Post exploitation activities detail some familiar and … Read More