Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server · Aura Research Division
https://ift.tt/Acj9kBI
Submitted April 04, 2023 at 11:11AM by Acceptable-Doubt-878
via reddit https://ift.tt/fAhMayQ
https://ift.tt/Acj9kBI
Submitted April 04, 2023 at 11:11AM by Acceptable-Doubt-878
via reddit https://ift.tt/fAhMayQ
Aura Research Division
Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server
Check that regex.
Proxyjacking - How attackers are monetizing internet bandwidth post exploitation
https://ift.tt/PjvWyXY
Submitted April 04, 2023 at 06:35PM by weseven
via reddit https://ift.tt/n03abJd
https://ift.tt/PjvWyXY
Submitted April 04, 2023 at 06:35PM by weseven
via reddit https://ift.tt/n03abJd
Sysdig
Proxyjacking has Entered the Chat – Sysdig
Did you know that you can effortlessly make a small passive income by simply letting an application run on your...
A fresh look at user enumeration in Microsoft Teams
https://ift.tt/ogP9z52
Submitted April 04, 2023 at 06:12PM by doitsukara
via reddit https://ift.tt/LcTktKV
https://ift.tt/ogP9z52
Submitted April 04, 2023 at 06:12PM by doitsukara
via reddit https://ift.tt/LcTktKV
www.securesystems.de
A fresh look at user enumeration in Microsoft Teams
User enumeration in Azure Active Directory environments is an important step in attack simulations. This blog post revisits how user enumeration can be performed for Microsoft Teams and introduces a new tool called TeamsEnum.
Suggestion needed to advance my career or learning something new
https://ift.tt/n59MiDU
Submitted April 04, 2023 at 08:35PM by Nithissh
via reddit https://ift.tt/uYNUEOF
https://ift.tt/n59MiDU
Submitted April 04, 2023 at 08:35PM by Nithissh
via reddit https://ift.tt/uYNUEOF
Practical DevSecOps
learning-path - Practical DevSecOps
Want to become an expert in DevSecOps? Our customised learning paths will help you learn DevSecOps and get certified. Learn more today!
Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack
https://ift.tt/dv2T5x3
Submitted April 04, 2023 at 11:26PM by roy_6472
via reddit https://ift.tt/gQFuBna
https://ift.tt/dv2T5x3
Submitted April 04, 2023 at 11:26PM by roy_6472
via reddit https://ift.tt/gQFuBna
Legitsecurity
Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack
Legit Security | Our team has found a vulnerability in Azure Pipelines (CVE-2023-21553) that allows an attacker to execute malicious code in a pipeline.
IDLE Abuse: A POC to Abuse: Shellcode execution using RegisterWaitForInputIdle.
https://ift.tt/HUheWZ6
Submitted April 05, 2023 at 02:37AM by navneetmuffin
via reddit https://ift.tt/jyIVfn6
https://ift.tt/HUheWZ6
Submitted April 05, 2023 at 02:37AM by navneetmuffin
via reddit https://ift.tt/jyIVfn6
Medium
Shellcode execution using RegisterWaitForInputIdle.
# Contents
Post Account Takeover? Account Takeover of Internal Tesla Accounts
https://ift.tt/VLYbOvp
Submitted April 05, 2023 at 02:11AM by techdash
via reddit https://ift.tt/JQUqKTL
https://ift.tt/VLYbOvp
Submitted April 05, 2023 at 02:11AM by techdash
via reddit https://ift.tt/JQUqKTL
Medium
Post Account Takeover? Account Takeover of Internal Tesla Accounts
In testing various Tesla web applications as part of the Tesla Bug Bounty Program, I’ve created many Tesla user accounts. At some point…
We put GPT-4 in Semgrep to point out false positives & fix code
https://ift.tt/ofKYTJr
Submitted April 05, 2023 at 03:47AM by pabloest
via reddit https://ift.tt/jGQZ7AB
https://ift.tt/ofKYTJr
Submitted April 05, 2023 at 03:47AM by pabloest
via reddit https://ift.tt/jGQZ7AB
We put GPT-4 in Semgrep to point out false positives & fix code
Semgrep is a code search tool many use for security scanning (SAST). We added GPT-4 to our cloud service to ask which Semgrep findings matter before we notify developers, and on our internal projects, it seemed to reason well about this task. We also tried…
The Current State of Security • Eleanor Saitta & Aino Vonge Corry [Podcast]
https://ift.tt/Ij2XsV0
Submitted April 05, 2023 at 12:46PM by goto-con
via reddit https://ift.tt/TWzrcxE
https://ift.tt/Ij2XsV0
Submitted April 05, 2023 at 12:46PM by goto-con
via reddit https://ift.tt/TWzrcxE
UI Best Practices for Password Manager Compatibility and Embracing Passwordless Security
https://ift.tt/xiRFTQm
Submitted April 05, 2023 at 02:40PM by agesdear
via reddit https://ift.tt/7yjxhmQ
https://ift.tt/xiRFTQm
Submitted April 05, 2023 at 02:40PM by agesdear
via reddit https://ift.tt/7yjxhmQ
Medium
UI Best Practices for Password Manager Compatibility and Embracing Passwordless Security
As user security continues to be a top priority in the digital age, it is essential for applications and companies to not only allow…
The Uninvited Guest: IDORs, Garage Doors, and Stolen Secrets
https://ift.tt/D2wpVcl
Submitted April 05, 2023 at 05:05PM by uniqualykerd
via reddit https://ift.tt/a1FYqjp
https://ift.tt/D2wpVcl
Submitted April 05, 2023 at 05:05PM by uniqualykerd
via reddit https://ift.tt/a1FYqjp
Medium
The Uninvited Guest: IDORs, Garage Doors, and Stolen Secrets
Uncovering Critical Security Flaws in Nexx’s Smart Devices: Garage Doors, Alarms, and Plugs at Risk
CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
https://ift.tt/qyptO0A
Submitted April 05, 2023 at 06:41PM by securitinerd
via reddit https://ift.tt/GzgqEPi
https://ift.tt/qyptO0A
Submitted April 05, 2023 at 06:41PM by securitinerd
via reddit https://ift.tt/GzgqEPi
DARKRELAY
CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
Introduction On the latest Patch Tuesday, Microsoft released 83 security fixes, one of which is the "CVE-2023-23397" vulnerability that affects all versions of the Outlook desktop app on Windows systems. However, this vulnerability does not impact the Outlook…
Operation Cookie Monster took down the cookie marketplace Genesis
https://ift.tt/UnmGFy2
Submitted April 05, 2023 at 08:20PM by tysonsw
via reddit https://ift.tt/UZ5hlBi
https://ift.tt/UnmGFy2
Submitted April 05, 2023 at 08:20PM by tysonsw
via reddit https://ift.tt/UZ5hlBi
Troy Hunt
Seized Genesis Market Data is Now Searchable in Have I Been Pwned, Courtesy of the FBI and "Operation Cookie Monster"
A quick summary first before the details: This week, the FBI in cooperation with international law enforcement partners took down a notorious marketplace trading in stolen identity data in an effort they've named "Operation Cookie Monster". They've provided…
Announcing Kurl
https://ift.tt/p1bTKjC
Submitted April 06, 2023 at 03:26AM by gabriel_schneider
via reddit https://ift.tt/trAVkv5
https://ift.tt/p1bTKjC
Submitted April 06, 2023 at 03:26AM by gabriel_schneider
via reddit https://ift.tt/trAVkv5
GitHub
GitHub - gbrls/kurl: HTTP Requests for security researchers
HTTP Requests for security researchers. Contribute to gbrls/kurl development by creating an account on GitHub.
My mate created a game that teaches you how to jailbreak LLM models like ChatGPT
https://ift.tt/DyXPf6Z
Submitted April 06, 2023 at 06:07AM by hakluke
via reddit https://ift.tt/tKxD1vJ
https://ift.tt/DyXPf6Z
Submitted April 06, 2023 at 06:07AM by hakluke
via reddit https://ift.tt/tKxD1vJ
Doublespeak.chat
A text-based AI escape game by Forces Unseen.
CyberGhostVPN Linux client vulnerable to MITM, RCE, LPE writeup
https://ift.tt/mzf3XCS
Submitted April 06, 2023 at 09:46AM by mmmds
via reddit https://ift.tt/Ds5aX3e
https://ift.tt/mzf3XCS
Submitted April 06, 2023 at 09:46AM by mmmds
via reddit https://ift.tt/Ds5aX3e
Technical analysis of the Genesis Market malware and tooling
https://ift.tt/vEYoK2r
Submitted April 06, 2023 at 02:30PM by xnyhps
via reddit https://ift.tt/GV8aT5l
https://ift.tt/vEYoK2r
Submitted April 06, 2023 at 02:30PM by xnyhps
via reddit https://ift.tt/GV8aT5l
sector7.computest.nl
Technical analysis of the Genesis Market
For the last couple of weeks we’ve assisted the Dutch police in investigating the Genesis Market. In case you are unfamiliar with this market, it was used to sell stolen login credentials, browser cookies and online fingerprints (in order to prevent ‘risky…
7 Questions and Answers about Firmware and Firmware Security
https://ift.tt/9ujEX6J
Submitted April 06, 2023 at 07:16PM by attilaszia
via reddit https://ift.tt/IALR6an
https://ift.tt/9ujEX6J
Submitted April 06, 2023 at 07:16PM by attilaszia
via reddit https://ift.tt/IALR6an
Bugprove
7 Questions and Answers about Firmware and Firmware Security
This all-inclusive article provides a complete overview of firmware, including how it works, common formats, and the importance plus mechanics of firmware security.
New Doyensec advisory! CSRF protection bypass discovered in Sveltekit. Ensure your apps are up-to-date.
https://ift.tt/z6Pypg5
Submitted April 06, 2023 at 09:28PM by ds_at
via reddit https://ift.tt/vYLSqwk
https://ift.tt/z6Pypg5
Submitted April 06, 2023 at 09:28PM by ds_at
via reddit https://ift.tt/vYLSqwk
Stopping cybercriminals from abusing security tools - Microsoft On the Issues
https://ift.tt/fzX0YTy
Submitted April 06, 2023 at 11:29PM by DH_Prelude
via reddit https://ift.tt/B7gMh8p
https://ift.tt/fzX0YTy
Submitted April 06, 2023 at 11:29PM by DH_Prelude
via reddit https://ift.tt/B7gMh8p
Microsoft On the Issues
Stopping cybercriminals from abusing security tools
Microsoft’s Digital Crimes Unit (DCU), cybersecurity software company Fortra™ and Health Information Sharing and Analysis Center (Health-ISAC) are taking technical and legal action to disrupt cracked, legacy copies of Cobalt Strike and abused Microsoft software…
Pwning Pixel 6 with a leftover patch
https://ift.tt/oHze5Kt
Submitted April 07, 2023 at 03:30AM by Titokhan
via reddit https://ift.tt/U6543iw
https://ift.tt/oHze5Kt
Submitted April 07, 2023 at 03:30AM by Titokhan
via reddit https://ift.tt/U6543iw
The GitHub Blog
Pwning Pixel 6 with a leftover patch | The GitHub Blog
In this post, I’ll look at a security-related change in version r40p0 of the Arm Mali driver that was AWOL in the January update of the Pixel bulletin, where other patches from r40p0 was applied, and how these two lines of changes can be exploited to gain…