GoBruteforcer: Golang-Based Botnet Actively Harvests Web Servers
https://ift.tt/OBXaSiT
Submitted April 10, 2023 at 07:14PM by montouesto
via reddit https://ift.tt/NJPzTkQ
https://ift.tt/OBXaSiT
Submitted April 10, 2023 at 07:14PM by montouesto
via reddit https://ift.tt/NJPzTkQ
Unit 42
GoBruteforcer: Golang-Based Botnet Actively Harvests Web Servers
New Golang-based malware we have dubbed GoBruteforcer targets web servers. Golang is becoming popular with malware programmers due to its versatility.
Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company
https://ift.tt/idWEFIV
Submitted April 10, 2023 at 09:46PM by EspoJ
via reddit https://ift.tt/Jxz7ICB
https://ift.tt/idWEFIV
Submitted April 10, 2023 at 09:46PM by EspoJ
via reddit https://ift.tt/Jxz7ICB
Zero Day
Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company
The document, part of a cache of leaks recently circulated on the internet, suggests the hackers had the ability to cause an explosion and sought instruction from the FSB.
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories
https://ift.tt/tFW0eBy
Submitted April 10, 2023 at 09:11PM by whisperingmime
via reddit https://ift.tt/Lz3up16
https://ift.tt/tFW0eBy
Submitted April 10, 2023 at 09:11PM by whisperingmime
via reddit https://ift.tt/Lz3up16
Blog by Joren Vrancken
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories
Last year, we published a blog post discussing an attack where a malicious actor hijacks Arch User Repository (AUR) vulnerable packages by registering expired domains.
Hacking play-to-earn blockchain games: The case of Manarium
https://ift.tt/0mlBbC2
Submitted April 10, 2023 at 09:58PM by juliocesarfort
via reddit https://ift.tt/6470qWB
https://ift.tt/0mlBbC2
Submitted April 10, 2023 at 09:58PM by juliocesarfort
via reddit https://ift.tt/6470qWB
Blaze Information Security
Hacking Play-to-Earn Blockchain Games: The Case Of Manarium
This post provides an overview of hacking play-to-earn blockchain games and common security pitfalls affecting P2E. It explains in detail how several vulnerabilities were discovered in a P2E game named Manarium.
Check out my new tool: SourceGPT a source code analyzer and prompt manager built on top of ChatGPT as the oracle. Then a set of prompt for security purposes can be found at the link provided below
https://ift.tt/nTCPSup
Submitted April 11, 2023 at 12:42AM by NoPaleontologist7419
via reddit https://ift.tt/J1As2zF
https://ift.tt/nTCPSup
Submitted April 11, 2023 at 12:42AM by NoPaleontologist7419
via reddit https://ift.tt/J1As2zF
GitHub
SourceGPT/use_cases at main · NightmareLab/SourceGPT
SourceGPT - prompt manager and source code analyzer built on top of ChatGPT as the oracle - SourceGPT/use_cases at main · NightmareLab/SourceGPT
Firewalls and Internet Security: Repelling the Wily Hacker -- now released under a Creative Commons license
https://wilyhacker.com/
Submitted April 11, 2023 at 06:24AM by self
via reddit https://ift.tt/Rb4zVQY
https://wilyhacker.com/
Submitted April 11, 2023 at 06:24AM by self
via reddit https://ift.tt/Rb4zVQY
Stowaway -- Multi-hop Proxy Tool for pentesters
https://ift.tt/YfFMuTP
Submitted April 10, 2023 at 05:54PM by CryptographerWeak578
via reddit https://ift.tt/5Dkmlvr
https://ift.tt/YfFMuTP
Submitted April 10, 2023 at 05:54PM by CryptographerWeak578
via reddit https://ift.tt/5Dkmlvr
GitHub
Stowaway/README_EN.md at master · ph4ntonn/Stowaway
👻Stowaway -- Multi-hop Proxy Tool for pentesters. Contribute to ph4ntonn/Stowaway development by creating an account on GitHub.
Awesome Hacker Search Engines
https://ift.tt/R6pm4Xl
Submitted April 11, 2023 at 08:51PM by edoardottt
via reddit https://ift.tt/CpZ3YvR
https://ift.tt/R6pm4Xl
Submitted April 11, 2023 at 08:51PM by edoardottt
via reddit https://ift.tt/CpZ3YvR
GitHub
GitHub - edoardottt/awesome-hacker-search-engines: A curated list of awesome search engines useful during Penetration testing,…
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more - GitHub - edoardottt/awesome-hacker-search-engi...
DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia
https://ift.tt/Ttfk7mO
Submitted April 11, 2023 at 10:47PM by SCI_Rusher
via reddit https://ift.tt/5RHy1lj
https://ift.tt/Ttfk7mO
Submitted April 11, 2023 at 10:47PM by SCI_Rusher
via reddit https://ift.tt/5RHy1lj
Microsoft Security Blog
DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast…
Microsoft analyzes a threat group tracked as DEV-0196, the actor’s iOS malware “KingsPawn”, and their link to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infrastructure…
Running An Adversary Emulation Exercise
https://ift.tt/0aDhmfp
Submitted April 12, 2023 at 06:09AM by Diesl
via reddit https://ift.tt/KdwlIDq
https://ift.tt/0aDhmfp
Submitted April 12, 2023 at 06:09AM by Diesl
via reddit https://ift.tt/KdwlIDq
Culbert Report
Adversary Emulation Exercises
Running An Adversary Emulation Exercise Adversary emulation can take many forms, but it will always have the same end goal. Helping companies come away knowing how to defend themselves better. You can bypass every defense and find every flaw but if they don’t…
[CVE-2023-21554] MSMQ (tcp/1801) Remote Code Execution (CVSS 9.8)
https://ift.tt/2eHnw8T
Submitted April 12, 2023 at 01:39PM by qwerty0x41
via reddit https://ift.tt/gW5JqZX
https://ift.tt/2eHnw8T
Submitted April 12, 2023 at 01:39PM by qwerty0x41
via reddit https://ift.tt/gW5JqZX
Rooting a Common-Criteria Certified Printer to Improve OPSEC
https://ift.tt/EYLDOmV
Submitted April 12, 2023 at 05:55PM by RedTeamPentesting
via reddit https://ift.tt/4QIdswz
https://ift.tt/EYLDOmV
Submitted April 12, 2023 at 05:55PM by RedTeamPentesting
via reddit https://ift.tt/4QIdswz
RedTeam Pentesting - Blog
Rooting a Common-Criteria Certified Printer to Improve OPSEC
Besides conducting penetration tests, we also attend to maintenance tasks of our internal infrastructure in order to have all systems being involved in our everyday work meet our specified requirements. One of these systems is the printer that we use …
Following the Lazarus group by tracking DeathNote campaign
https://ift.tt/PEIXqNb
Submitted April 12, 2023 at 07:57PM by EspoJ
via reddit https://ift.tt/Pn5WsQ2
https://ift.tt/PEIXqNb
Submitted April 12, 2023 at 07:57PM by EspoJ
via reddit https://ift.tt/Pn5WsQ2
Securelist
Following the Lazarus group by tracking DeathNote campaign
The Lazarus group is a high-profile Korean-speaking threat actor with multiple sub-campaigns. In this blog, we’ll focus on an active cluster that we dubbed DeathNote.
Shell in the Ghost: Ghostnoscript CVE-2023-28879 writeup
https://ift.tt/gpBNKfY
Submitted April 11, 2023 at 07:08PM by AlmondOffSec
via reddit https://ift.tt/ndhu8SF
https://ift.tt/gpBNKfY
Submitted April 11, 2023 at 07:08PM by AlmondOffSec
via reddit https://ift.tt/ndhu8SF
An emperical and practical guide to LLM hacking
https://ift.tt/aB7PHs3
Submitted April 12, 2023 at 10:09PM by alxjsn
via reddit https://ift.tt/FlGX4KN
https://ift.tt/aB7PHs3
Submitted April 12, 2023 at 10:09PM by alxjsn
via reddit https://ift.tt/FlGX4KN
Doublespeak.chat
A text-based AI escape game by Forces Unseen.
Hi! We're recruiting for a US Remote, Full-Time, Principal Security Researcher to join our client's Security Research team to work on O-day research. Requirements: Java web application exploitation experience at a senior level (7 plus years in security). More info and comp in link below.
https://ift.tt/XwYGCtU
Submitted April 13, 2023 at 04:25AM by dawnsaenz
via reddit https://ift.tt/mwHciWK
https://ift.tt/XwYGCtU
Submitted April 13, 2023 at 04:25AM by dawnsaenz
via reddit https://ift.tt/mwHciWK
Attackers can now plant "prompt injections" in a website the user is visiting, which silently turns Bing Chat into a Social Engineer who seeks out and exfiltrates personal information
https://ift.tt/5plHFvI
Submitted April 13, 2023 at 11:26AM by aknalid
via reddit https://ift.tt/1EUOud8
https://ift.tt/5plHFvI
Submitted April 13, 2023 at 11:26AM by aknalid
via reddit https://ift.tt/1EUOud8
Leaking Remote Memory Contents on SecurePoint’s UTM Firewall (CVE-2023-22897)
https://ift.tt/PAdY32t
Submitted April 13, 2023 at 12:30PM by albinowax
via reddit https://ift.tt/Em1INdK
https://ift.tt/PAdY32t
Submitted April 13, 2023 at 12:30PM by albinowax
via reddit https://ift.tt/Em1INdK
WhatsApp adds key transparency for all users to strengthen the security of end-to-end encrypted messaging
https://ift.tt/1EU5jfp
Submitted April 13, 2023 at 06:35PM by snowboardfreak63
via reddit https://ift.tt/Z5WVOLI
https://ift.tt/1EU5jfp
Submitted April 13, 2023 at 06:35PM by snowboardfreak63
via reddit https://ift.tt/Z5WVOLI
Engineering at Meta
Deploying key transparency at WhatsApp
With key transparency, WhatsApp provides a set of proofs that affirms the correctness of public encryption keys.
Malware Disguised as Document from Ukraine's Energoatom Delivers Havoc Demon Backdoor
https://ift.tt/z5HwXqn
Submitted April 13, 2023 at 05:25PM by montouesto
via reddit https://ift.tt/lGUyLTO
https://ift.tt/z5HwXqn
Submitted April 13, 2023 at 05:25PM by montouesto
via reddit https://ift.tt/lGUyLTO
Fortinet Blog
Malware Disguised as Document from Ukraine's Energoatom Delivers Havoc Demon Backdoor | FortiGuard Labs
FortiGuard Labs highlights the technical details of a multi-staged cyberattack used in the Russian-Ukrainian conflict, as well as some strange artifacts that could be work-in-progress or part of a …
Vare - New specific info stealer for Discord & iniltrating the fledgling crime group that created it.
https://ift.tt/IUAHGZo
Submitted April 13, 2023 at 08:15PM by CyberArkLabs
via reddit https://ift.tt/wZbtxWH
https://ift.tt/IUAHGZo
Submitted April 13, 2023 at 08:15PM by CyberArkLabs
via reddit https://ift.tt/wZbtxWH
Cyberark
The (Not so) Secret War on Discord
CyberArk Malware Research Team Abstract CyberArk Labs discovered a new malware called Vare that is distributed over the popular chatting service, Discord. Vare has been used to target new malware...