"Dissecting redis CVE-2023-28425 with chatGPT as assistant" blog post
https://ift.tt/eTt7AKF
Submitted April 03, 2023 at 01:29AM by NoPaleontologist7419
via reddit https://ift.tt/ZDvH3WQ
https://ift.tt/eTt7AKF
Submitted April 03, 2023 at 01:29AM by NoPaleontologist7419
via reddit https://ift.tt/ZDvH3WQ
Lambda driver blog
Dissecting redis CVE-2023-28425 with chatGPT as assistant
Intro
Malicious ISO File Leads to Domain Wide Ransomware
https://ift.tt/Pq5biFo
Submitted April 03, 2023 at 07:04AM by TheDFIRReport
via reddit https://ift.tt/B7UF0db
https://ift.tt/Pq5biFo
Submitted April 03, 2023 at 07:04AM by TheDFIRReport
via reddit https://ift.tt/B7UF0db
The DFIR Report
Malicious ISO File Leads to Domain Wide Ransomware - The DFIR Report
IcedID continues to deliver malspam emails to facilitate a compromise. This case covers the activity from a campaign in late September of 2022. Post exploitation activities detail some familiar and … Read More
Need help installing hackazon
https://ift.tt/KOEbzWP
Submitted April 03, 2023 at 09:05AM by wolfweaver98
via reddit https://ift.tt/ENMStXQ
https://ift.tt/KOEbzWP
Submitted April 03, 2023 at 09:05AM by wolfweaver98
via reddit https://ift.tt/ENMStXQ
Multiple vulnerabilities in Aten PE8108 power distribution unit - There is no security firmware update, yet.
https://ift.tt/h5yRk1l
Submitted April 03, 2023 at 04:05PM by fr0r
via reddit https://ift.tt/hmlXHby
https://ift.tt/h5yRk1l
Submitted April 03, 2023 at 04:05PM by fr0r
via reddit https://ift.tt/hmlXHby
Pentagrid AG
Multiple vulnerabilities in Aten PE8108 power distribution unit
A Pentagrid security advisory about multiple vulnerabilities in the Aten PE8108 PDU remote power outlet control.
Argument Injection Cheatsheet
https://ift.tt/bAJsBWU
Submitted April 03, 2023 at 06:33PM by monoimpact
via reddit https://ift.tt/SlpoXcA
https://ift.tt/bAJsBWU
Submitted April 03, 2023 at 06:33PM by monoimpact
via reddit https://ift.tt/SlpoXcA
GTFOArgs: A Curated List Of Binaries For Argument Injection.
https://ift.tt/XSJbted
Submitted April 03, 2023 at 07:45PM by MegaManSec2
via reddit https://ift.tt/QpbaD9c
https://ift.tt/XSJbted
Submitted April 03, 2023 at 07:45PM by MegaManSec2
via reddit https://ift.tt/QpbaD9c
Bypassing Amazon Kids+ Parental Controls
https://ift.tt/akpuQMS
Submitted April 03, 2023 at 07:51PM by n00py
via reddit https://ift.tt/H1SvYLM
https://ift.tt/akpuQMS
Submitted April 03, 2023 at 07:51PM by n00py
via reddit https://ift.tt/H1SvYLM
www.n00py.io
Bypassing Amazon Kids+ Parental Controls
Recently for Christmas my 4 year old daughter got an Amazon Kids tablet. So far the tablet has been great and Kids+ seems like a pretty decent value for what you get. I'm very wary of the types of content available on the internet, and as a parent it's my…
The Bug Bounty Radar - The latest Bug Bounty programs from various platforms
https://bbradar.io
Submitted April 03, 2023 at 11:33PM by SyntifyTech
via reddit https://ift.tt/vSgL6sc
https://bbradar.io
Submitted April 03, 2023 at 11:33PM by SyntifyTech
via reddit https://ift.tt/vSgL6sc
bbradar.io
The Bug Bounty Radar - The Latest Public Bug Bounty Programs | The Bug Bounty Radar
The Bug Bounty Radar - Discover and explore the latest public bug bounty programs from top platforms. Find security research opportunities, compare rewards, and access the most comprehensive bug bounty database. 6 new programs added recently.
Why API Security Matters More Than You Think
https://ift.tt/bp3Cm8O
Submitted April 04, 2023 at 04:25AM by shrisukhani
via reddit https://ift.tt/LjhTvMr
https://ift.tt/bp3Cm8O
Submitted April 04, 2023 at 04:25AM by shrisukhani
via reddit https://ift.tt/LjhTvMr
Metlo
Why API Security Matters More Than You Think
What are APIs?
APIs are the glue that holds the modern world together. They allow different applications and services to communicate with each other, and they power everything from e-commerce to social media. However, with this ease of connectivity comes…
APIs are the glue that holds the modern world together. They allow different applications and services to communicate with each other, and they power everything from e-commerce to social media. However, with this ease of connectivity comes…
Smishing Protection - Robokiller
https://robokiller.com
Submitted April 04, 2023 at 08:39AM by evilmanbot
via reddit https://ift.tt/7nqP3VO
https://robokiller.com
Submitted April 04, 2023 at 08:39AM by evilmanbot
via reddit https://ift.tt/7nqP3VO
Robokiller
The Text & Spam Call Blocker App That Actually Works | Robokiller
Block 99% of spam calls and texts with the leading spam call blocker app. Create a world without spam calls and get some sweet revenge along the way!
Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server · Aura Research Division
https://ift.tt/Acj9kBI
Submitted April 04, 2023 at 11:11AM by Acceptable-Doubt-878
via reddit https://ift.tt/fAhMayQ
https://ift.tt/Acj9kBI
Submitted April 04, 2023 at 11:11AM by Acceptable-Doubt-878
via reddit https://ift.tt/fAhMayQ
Aura Research Division
Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server
Check that regex.
Proxyjacking - How attackers are monetizing internet bandwidth post exploitation
https://ift.tt/PjvWyXY
Submitted April 04, 2023 at 06:35PM by weseven
via reddit https://ift.tt/n03abJd
https://ift.tt/PjvWyXY
Submitted April 04, 2023 at 06:35PM by weseven
via reddit https://ift.tt/n03abJd
Sysdig
Proxyjacking has Entered the Chat – Sysdig
Did you know that you can effortlessly make a small passive income by simply letting an application run on your...
A fresh look at user enumeration in Microsoft Teams
https://ift.tt/ogP9z52
Submitted April 04, 2023 at 06:12PM by doitsukara
via reddit https://ift.tt/LcTktKV
https://ift.tt/ogP9z52
Submitted April 04, 2023 at 06:12PM by doitsukara
via reddit https://ift.tt/LcTktKV
www.securesystems.de
A fresh look at user enumeration in Microsoft Teams
User enumeration in Azure Active Directory environments is an important step in attack simulations. This blog post revisits how user enumeration can be performed for Microsoft Teams and introduces a new tool called TeamsEnum.
Suggestion needed to advance my career or learning something new
https://ift.tt/n59MiDU
Submitted April 04, 2023 at 08:35PM by Nithissh
via reddit https://ift.tt/uYNUEOF
https://ift.tt/n59MiDU
Submitted April 04, 2023 at 08:35PM by Nithissh
via reddit https://ift.tt/uYNUEOF
Practical DevSecOps
learning-path - Practical DevSecOps
Want to become an expert in DevSecOps? Our customised learning paths will help you learn DevSecOps and get certified. Learn more today!
Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack
https://ift.tt/dv2T5x3
Submitted April 04, 2023 at 11:26PM by roy_6472
via reddit https://ift.tt/gQFuBna
https://ift.tt/dv2T5x3
Submitted April 04, 2023 at 11:26PM by roy_6472
via reddit https://ift.tt/gQFuBna
Legitsecurity
Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack
Legit Security | Our team has found a vulnerability in Azure Pipelines (CVE-2023-21553) that allows an attacker to execute malicious code in a pipeline.
IDLE Abuse: A POC to Abuse: Shellcode execution using RegisterWaitForInputIdle.
https://ift.tt/HUheWZ6
Submitted April 05, 2023 at 02:37AM by navneetmuffin
via reddit https://ift.tt/jyIVfn6
https://ift.tt/HUheWZ6
Submitted April 05, 2023 at 02:37AM by navneetmuffin
via reddit https://ift.tt/jyIVfn6
Medium
Shellcode execution using RegisterWaitForInputIdle.
# Contents
Post Account Takeover? Account Takeover of Internal Tesla Accounts
https://ift.tt/VLYbOvp
Submitted April 05, 2023 at 02:11AM by techdash
via reddit https://ift.tt/JQUqKTL
https://ift.tt/VLYbOvp
Submitted April 05, 2023 at 02:11AM by techdash
via reddit https://ift.tt/JQUqKTL
Medium
Post Account Takeover? Account Takeover of Internal Tesla Accounts
In testing various Tesla web applications as part of the Tesla Bug Bounty Program, I’ve created many Tesla user accounts. At some point…
We put GPT-4 in Semgrep to point out false positives & fix code
https://ift.tt/ofKYTJr
Submitted April 05, 2023 at 03:47AM by pabloest
via reddit https://ift.tt/jGQZ7AB
https://ift.tt/ofKYTJr
Submitted April 05, 2023 at 03:47AM by pabloest
via reddit https://ift.tt/jGQZ7AB
We put GPT-4 in Semgrep to point out false positives & fix code
Semgrep is a code search tool many use for security scanning (SAST). We added GPT-4 to our cloud service to ask which Semgrep findings matter before we notify developers, and on our internal projects, it seemed to reason well about this task. We also tried…
The Current State of Security • Eleanor Saitta & Aino Vonge Corry [Podcast]
https://ift.tt/Ij2XsV0
Submitted April 05, 2023 at 12:46PM by goto-con
via reddit https://ift.tt/TWzrcxE
https://ift.tt/Ij2XsV0
Submitted April 05, 2023 at 12:46PM by goto-con
via reddit https://ift.tt/TWzrcxE
UI Best Practices for Password Manager Compatibility and Embracing Passwordless Security
https://ift.tt/xiRFTQm
Submitted April 05, 2023 at 02:40PM by agesdear
via reddit https://ift.tt/7yjxhmQ
https://ift.tt/xiRFTQm
Submitted April 05, 2023 at 02:40PM by agesdear
via reddit https://ift.tt/7yjxhmQ
Medium
UI Best Practices for Password Manager Compatibility and Embracing Passwordless Security
As user security continues to be a top priority in the digital age, it is essential for applications and companies to not only allow…
The Uninvited Guest: IDORs, Garage Doors, and Stolen Secrets
https://ift.tt/D2wpVcl
Submitted April 05, 2023 at 05:05PM by uniqualykerd
via reddit https://ift.tt/a1FYqjp
https://ift.tt/D2wpVcl
Submitted April 05, 2023 at 05:05PM by uniqualykerd
via reddit https://ift.tt/a1FYqjp
Medium
The Uninvited Guest: IDORs, Garage Doors, and Stolen Secrets
Uncovering Critical Security Flaws in Nexx’s Smart Devices: Garage Doors, Alarms, and Plugs at Risk