Vulnerable version of WordPress that is provided monthly.
https://ift.tt/rmLVnFQ
Submitted April 08, 2023 at 06:37PM by seyyid_
via reddit https://ift.tt/sihYLr7
https://ift.tt/rmLVnFQ
Submitted April 08, 2023 at 06:37PM by seyyid_
via reddit https://ift.tt/sihYLr7
GitHub
GitHub - onhexgroup/Vulnerable-WordPress: Vulnerable version of WordPress that is provided monthly.
Vulnerable version of WordPress that is provided monthly. - GitHub - onhexgroup/Vulnerable-WordPress: Vulnerable version of WordPress that is provided monthly.
Using Python to Operate in EDR blind spots
https://ift.tt/5XNmAOY
Submitted April 08, 2023 at 07:12PM by naksyn_
via reddit https://ift.tt/5J2KLjI
https://ift.tt/5XNmAOY
Submitted April 08, 2023 at 07:12PM by naksyn_
via reddit https://ift.tt/5J2KLjI
GitHub
GitHub - naksyn/Pyramid: a tool to help operate in EDRs' blind spots
a tool to help operate in EDRs' blind spots. Contribute to naksyn/Pyramid development by creating an account on GitHub.
🚀 Cilium Tetragon - eBPF-based Security Observability and Runtime Enforcement in Kubernetes Goat 🐐
https://ift.tt/CTzNAgS
Submitted April 09, 2023 at 12:09AM by madhuakula
via reddit https://ift.tt/wT9yt7q
https://ift.tt/CTzNAgS
Submitted April 09, 2023 at 12:09AM by madhuakula
via reddit https://ift.tt/wT9yt7q
Madhuakula
⎈ Cilium Tetragon - eBPF-based Security Observability and Runtime Enforcement | Kubernetes Goat
Learn to monitor, detect and enforce the runtime security using eBPF-based Cilium Tetragon in the Kubernetes Clusters - Kubernetes Goat Scenario 🚀
Bridging the gap between infosec and the IT Teams
https://ift.tt/hnyX3AR
Submitted April 09, 2023 at 06:22PM by pageup83
via reddit https://ift.tt/dOBvk2h
https://ift.tt/hnyX3AR
Submitted April 09, 2023 at 06:22PM by pageup83
via reddit https://ift.tt/dOBvk2h
Securing Kubernetes Clusters using Kyverno Policy Engine - New Kubernetes Goat Scenario 🚀
https://ift.tt/bfwrK80
Submitted April 09, 2023 at 10:28PM by madhuakula
via reddit https://ift.tt/xQHC6T0
https://ift.tt/bfwrK80
Submitted April 09, 2023 at 10:28PM by madhuakula
via reddit https://ift.tt/xQHC6T0
Madhuakula
⎈ Securing Kubernetes Clusters using Kyverno Policy Engine | Kubernetes Goat
Use Kyverno policy engine to validate, mutate, generate the Kubernetes cluster resources. We create policies to prevent insecure patterns and build secure guardrails - Kubernetes Goat Scenario 🚀
Catching Threat Actors using honeypots
https://ift.tt/CaVtexU
Submitted April 10, 2023 at 06:49AM by TachiPy
via reddit https://ift.tt/EBRD2OU
https://ift.tt/CaVtexU
Submitted April 10, 2023 at 06:49AM by TachiPy
via reddit https://ift.tt/EBRD2OU
Burningmalware Security Research
Catching Threat Actors using honeypots! (Part1)
In this post we will discuss how to set up honeypots to catch some nasty Threat Actors!
Tool to Decrypt Chrome, Firefox and Edge login information
https://ift.tt/q6hOXFy
Submitted April 10, 2023 at 06:46AM by Affectionate-Bed4878
via reddit https://ift.tt/mDg2N6X
https://ift.tt/q6hOXFy
Submitted April 10, 2023 at 06:46AM by Affectionate-Bed4878
via reddit https://ift.tt/mDg2N6X
MediaFire
CollectAndDecrypt
Programs that can collect the user credentials for Google Chrome, Mozilla Firefox and Microsoft Edge and decrypt them then save the decrypted output to .txt files - Lukey J
Building a Budget Red Team Implant for Fun
https://ift.tt/JnyUMp5
Submitted April 10, 2023 at 03:01PM by Fedorable_One
via reddit https://ift.tt/eAWvjIL
https://ift.tt/JnyUMp5
Submitted April 10, 2023 at 03:01PM by Fedorable_One
via reddit https://ift.tt/eAWvjIL
Medium
Building a Budget Red Team Implant
Why Do I Need an Implant?
Rilide: A New Malicious Browser Extension for Stealing Cryptocurrencies
https://ift.tt/1Io9bep
Submitted April 10, 2023 at 07:18PM by montouesto
via reddit https://ift.tt/3NbaTWd
https://ift.tt/1Io9bep
Submitted April 10, 2023 at 07:18PM by montouesto
via reddit https://ift.tt/3NbaTWd
Trustwave
Rilide: A New Malicious Browser Extension for Stealing Cryptocurrencies
Trustwave SpiderLabs uncovered a new strain of malware that it dubbed Rilide, which targets Chromium-based browsers such as Google Chrome, Microsoft Edge, Brave, and Opera.
GoBruteforcer: Golang-Based Botnet Actively Harvests Web Servers
https://ift.tt/OBXaSiT
Submitted April 10, 2023 at 07:14PM by montouesto
via reddit https://ift.tt/NJPzTkQ
https://ift.tt/OBXaSiT
Submitted April 10, 2023 at 07:14PM by montouesto
via reddit https://ift.tt/NJPzTkQ
Unit 42
GoBruteforcer: Golang-Based Botnet Actively Harvests Web Servers
New Golang-based malware we have dubbed GoBruteforcer targets web servers. Golang is becoming popular with malware programmers due to its versatility.
Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company
https://ift.tt/idWEFIV
Submitted April 10, 2023 at 09:46PM by EspoJ
via reddit https://ift.tt/Jxz7ICB
https://ift.tt/idWEFIV
Submitted April 10, 2023 at 09:46PM by EspoJ
via reddit https://ift.tt/Jxz7ICB
Zero Day
Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company
The document, part of a cache of leaks recently circulated on the internet, suggests the hackers had the ability to cause an explosion and sought instruction from the FSB.
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories
https://ift.tt/tFW0eBy
Submitted April 10, 2023 at 09:11PM by whisperingmime
via reddit https://ift.tt/Lz3up16
https://ift.tt/tFW0eBy
Submitted April 10, 2023 at 09:11PM by whisperingmime
via reddit https://ift.tt/Lz3up16
Blog by Joren Vrancken
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories
Last year, we published a blog post discussing an attack where a malicious actor hijacks Arch User Repository (AUR) vulnerable packages by registering expired domains.
Hacking play-to-earn blockchain games: The case of Manarium
https://ift.tt/0mlBbC2
Submitted April 10, 2023 at 09:58PM by juliocesarfort
via reddit https://ift.tt/6470qWB
https://ift.tt/0mlBbC2
Submitted April 10, 2023 at 09:58PM by juliocesarfort
via reddit https://ift.tt/6470qWB
Blaze Information Security
Hacking Play-to-Earn Blockchain Games: The Case Of Manarium
This post provides an overview of hacking play-to-earn blockchain games and common security pitfalls affecting P2E. It explains in detail how several vulnerabilities were discovered in a P2E game named Manarium.
Check out my new tool: SourceGPT a source code analyzer and prompt manager built on top of ChatGPT as the oracle. Then a set of prompt for security purposes can be found at the link provided below
https://ift.tt/nTCPSup
Submitted April 11, 2023 at 12:42AM by NoPaleontologist7419
via reddit https://ift.tt/J1As2zF
https://ift.tt/nTCPSup
Submitted April 11, 2023 at 12:42AM by NoPaleontologist7419
via reddit https://ift.tt/J1As2zF
GitHub
SourceGPT/use_cases at main · NightmareLab/SourceGPT
SourceGPT - prompt manager and source code analyzer built on top of ChatGPT as the oracle - SourceGPT/use_cases at main · NightmareLab/SourceGPT
Firewalls and Internet Security: Repelling the Wily Hacker -- now released under a Creative Commons license
https://wilyhacker.com/
Submitted April 11, 2023 at 06:24AM by self
via reddit https://ift.tt/Rb4zVQY
https://wilyhacker.com/
Submitted April 11, 2023 at 06:24AM by self
via reddit https://ift.tt/Rb4zVQY
Stowaway -- Multi-hop Proxy Tool for pentesters
https://ift.tt/YfFMuTP
Submitted April 10, 2023 at 05:54PM by CryptographerWeak578
via reddit https://ift.tt/5Dkmlvr
https://ift.tt/YfFMuTP
Submitted April 10, 2023 at 05:54PM by CryptographerWeak578
via reddit https://ift.tt/5Dkmlvr
GitHub
Stowaway/README_EN.md at master · ph4ntonn/Stowaway
👻Stowaway -- Multi-hop Proxy Tool for pentesters. Contribute to ph4ntonn/Stowaway development by creating an account on GitHub.
Awesome Hacker Search Engines
https://ift.tt/R6pm4Xl
Submitted April 11, 2023 at 08:51PM by edoardottt
via reddit https://ift.tt/CpZ3YvR
https://ift.tt/R6pm4Xl
Submitted April 11, 2023 at 08:51PM by edoardottt
via reddit https://ift.tt/CpZ3YvR
GitHub
GitHub - edoardottt/awesome-hacker-search-engines: A curated list of awesome search engines useful during Penetration testing,…
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more - GitHub - edoardottt/awesome-hacker-search-engi...
DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia
https://ift.tt/Ttfk7mO
Submitted April 11, 2023 at 10:47PM by SCI_Rusher
via reddit https://ift.tt/5RHy1lj
https://ift.tt/Ttfk7mO
Submitted April 11, 2023 at 10:47PM by SCI_Rusher
via reddit https://ift.tt/5RHy1lj
Microsoft Security Blog
DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast…
Microsoft analyzes a threat group tracked as DEV-0196, the actor’s iOS malware “KingsPawn”, and their link to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infrastructure…
Running An Adversary Emulation Exercise
https://ift.tt/0aDhmfp
Submitted April 12, 2023 at 06:09AM by Diesl
via reddit https://ift.tt/KdwlIDq
https://ift.tt/0aDhmfp
Submitted April 12, 2023 at 06:09AM by Diesl
via reddit https://ift.tt/KdwlIDq
Culbert Report
Adversary Emulation Exercises
Running An Adversary Emulation Exercise Adversary emulation can take many forms, but it will always have the same end goal. Helping companies come away knowing how to defend themselves better. You can bypass every defense and find every flaw but if they don’t…
[CVE-2023-21554] MSMQ (tcp/1801) Remote Code Execution (CVSS 9.8)
https://ift.tt/2eHnw8T
Submitted April 12, 2023 at 01:39PM by qwerty0x41
via reddit https://ift.tt/gW5JqZX
https://ift.tt/2eHnw8T
Submitted April 12, 2023 at 01:39PM by qwerty0x41
via reddit https://ift.tt/gW5JqZX
Rooting a Common-Criteria Certified Printer to Improve OPSEC
https://ift.tt/EYLDOmV
Submitted April 12, 2023 at 05:55PM by RedTeamPentesting
via reddit https://ift.tt/4QIdswz
https://ift.tt/EYLDOmV
Submitted April 12, 2023 at 05:55PM by RedTeamPentesting
via reddit https://ift.tt/4QIdswz
RedTeam Pentesting - Blog
Rooting a Common-Criteria Certified Printer to Improve OPSEC
Besides conducting penetration tests, we also attend to maintenance tasks of our internal infrastructure in order to have all systems being involved in our everyday work meet our specified requirements. One of these systems is the printer that we use …