Fraud Friday: Investigation into a fake university scam
https://ift.tt/WgJDAVe
Submitted April 14, 2023 at 06:19PM by Seaerkin2
via reddit https://ift.tt/JhkGVem
https://ift.tt/WgJDAVe
Submitted April 14, 2023 at 06:19PM by Seaerkin2
via reddit https://ift.tt/JhkGVem
Guardyourdomain
DomainGuard | Threat Visibility Platform
We guard your domain, so you have peace of mind. Threat Visibility Platform.
Manage (and soon deploy) Android machines with pre-defined behaviors for CyberRange environments.
https://ift.tt/umKbqOx
Submitted April 14, 2023 at 07:53PM by deleee
via reddit https://ift.tt/GY6Dgyx
https://ift.tt/umKbqOx
Submitted April 14, 2023 at 07:53PM by deleee
via reddit https://ift.tt/GY6Dgyx
GitHub
GitHub - cybersecsi/robodroid: Manage (and soon deploy) Android machines with pre-defined behaviors for Cyber Range environments.
Manage (and soon deploy) Android machines with pre-defined behaviors for Cyber Range environments. - GitHub - cybersecsi/robodroid: Manage (and soon deploy) Android machines with pre-defined behavi...
uni-due-syssec/efcf-framework: Extremely Fast smart Contract Fuzzing
https://ift.tt/C23GDrn
Submitted April 15, 2023 at 12:15AM by Gallus
via reddit https://ift.tt/o3YA1DJ
https://ift.tt/C23GDrn
Submitted April 15, 2023 at 12:15AM by Gallus
via reddit https://ift.tt/o3YA1DJ
GitHub
GitHub - uni-due-syssec/efcf-framework: EF/CF - Extremely Fast smart Contract Fuzzing
EF/CF - Extremely Fast smart Contract Fuzzing . Contribute to uni-due-syssec/efcf-framework development by creating an account on GitHub.
Lost in ChatGPT's memories: escaping ChatGPT-3.5 memory issues to write CVE PoCs
https://ift.tt/ZSnyWti
Submitted April 15, 2023 at 03:14AM by NoPaleontologist7419
via reddit https://ift.tt/wH0BI45
https://ift.tt/ZSnyWti
Submitted April 15, 2023 at 03:14AM by NoPaleontologist7419
via reddit https://ift.tt/wH0BI45
Lambda driver blog
Lost in ChatGPT’s memories: escaping ChatGPT-3.5 memory issues to write CVE PoCs
In the last blog (link), we described how ChatGPT can be used to better understand a codebase and assist us during the making of a PoC for a CVE. ChatGPT didn’t find the vulnerability nor wrote the PoC, but as an assistant gave us hints about the project’s…
Remote Code Execution Vulnerability in Google They Are Not Willing To Fix
https://ift.tt/E48Blzw
Submitted April 15, 2023 at 12:29PM by Hydroksiid
via reddit https://ift.tt/SofsUiW
https://ift.tt/E48Blzw
Submitted April 15, 2023 at 12:29PM by Hydroksiid
via reddit https://ift.tt/SofsUiW
10 Methods to Bypass Windows Defender for Unrestricted Code Execution
https://ift.tt/WNGABxC
Submitted April 15, 2023 at 09:17PM by florilsk
via reddit https://ift.tt/lj4NG52
https://ift.tt/WNGABxC
Submitted April 15, 2023 at 09:17PM by florilsk
via reddit https://ift.tt/lj4NG52
Vulnerability scanner for AWS customer-managed policies using ChatGPT w/ built-in account redaction.
https://ift.tt/XOlGmeN
Submitted April 16, 2023 at 08:33AM by ustayready
via reddit https://ift.tt/Hpq7evY
https://ift.tt/XOlGmeN
Submitted April 16, 2023 at 08:33AM by ustayready
via reddit https://ift.tt/Hpq7evY
GitHub
GitHub - ustayready/cloudgpt: Vulnerability scanner for AWS customer managed policies using ChatGPT
Vulnerability scanner for AWS customer managed policies using ChatGPT - GitHub - ustayready/cloudgpt: Vulnerability scanner for AWS customer managed policies using ChatGPT
WorLLMs
https://ift.tt/ATXaSCD
Submitted April 16, 2023 at 02:29PM by rain5
via reddit https://ift.tt/n3lu6Oo
https://ift.tt/ATXaSCD
Submitted April 16, 2023 at 02:29PM by rain5
via reddit https://ift.tt/n3lu6Oo
Gist
WorLLMs
WorLLMs. GitHub Gist: instantly share code, notes, and snippets.
Trigona Ransomware Attacking MS-SQL Servers
https://ift.tt/Xfd0jYz
Submitted April 17, 2023 at 01:28PM by montouesto
via reddit https://ift.tt/aPMwWoG
https://ift.tt/Xfd0jYz
Submitted April 17, 2023 at 01:28PM by montouesto
via reddit https://ift.tt/aPMwWoG
ASEC BLOG
Trigona Ransomware Attacking MS-SQL Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered the Trigona ransomware being installed on poorly managed MS-SQL servers. Trigona is a relatively recent ransomware that was first discovered in October 2022, and Unit 42 has recently…
GitHub - quarkslab/pastis: PASTIS: Collaborative Fuzzing Framework
https://ift.tt/t3eZ9Yv
Submitted April 17, 2023 at 02:47PM by jeandrew
via reddit https://ift.tt/JtKd2Wb
https://ift.tt/t3eZ9Yv
Submitted April 17, 2023 at 02:47PM by jeandrew
via reddit https://ift.tt/JtKd2Wb
GitHub
GitHub - quarkslab/pastis: PASTIS: Collaborative Fuzzing Framework
PASTIS: Collaborative Fuzzing Framework. Contribute to quarkslab/pastis development by creating an account on GitHub.
Weaponizing Discord DLL Hijacking via Excel Macros (POC)
https://ift.tt/xTWbk0Z
Submitted April 17, 2023 at 09:11PM by thehunter699
via reddit https://ift.tt/cFvmHYr
https://ift.tt/xTWbk0Z
Submitted April 17, 2023 at 09:11PM by thehunter699
via reddit https://ift.tt/cFvmHYr
GitHub
GitHub - MitchHS/Discord-DLL-Hijacking: This is a simple example of DLL hijacking enabling proxy execution.
This is a simple example of DLL hijacking enabling proxy execution. - GitHub - MitchHS/Discord-DLL-Hijacking: This is a simple example of DLL hijacking enabling proxy execution.
TruffleHog is now 2x faster, thanks to Aho Corasick
https://ift.tt/0H1P6QZ
Submitted April 17, 2023 at 11:51PM by wifihack
via reddit https://ift.tt/xvyLZSh
https://ift.tt/0H1P6QZ
Submitted April 17, 2023 at 11:51PM by wifihack
via reddit https://ift.tt/xvyLZSh
Truffle Security
TruffleHog 2x faster!
TruffleHog v3.28.6 introduces the Aho-Corasick algorithm for keyword optimization, leading to a 2x average speedup in scanning. This allows for faster keyword preflight searches in linear time, improving performance as more detectors are added.
Hey, I wrote a GCP pentesting guide, check it out if you are interested in cloud security and please lmk your thoughts. Appreciate it.
https://ift.tt/hN92DbO
Submitted April 17, 2023 at 11:41PM by Sloky
via reddit https://ift.tt/pdHC4PY
https://ift.tt/hN92DbO
Submitted April 17, 2023 at 11:41PM by Sloky
via reddit https://ift.tt/pdHC4PY
A Practical, AI-Generated Phishing PoC with ChatGPT
https://ift.tt/1AuPeKZ
Submitted April 18, 2023 at 12:04AM by IndySecMan
via reddit https://ift.tt/YR5heFX
https://ift.tt/1AuPeKZ
Submitted April 18, 2023 at 12:04AM by IndySecMan
via reddit https://ift.tt/YR5heFX
Medium
A Practical, AI-Generated Phishing PoC With ChatGPT
While Sidestepping Ethical Controls
Ransomware in the Cloud - A step by step breakdown
https://ift.tt/AOh24ga
Submitted April 18, 2023 at 11:24AM by VariousAd5147
via reddit https://ift.tt/TwU3pxb
https://ift.tt/AOh24ga
Submitted April 18, 2023 at 11:24AM by VariousAd5147
via reddit https://ift.tt/TwU3pxb
Medium
Ransomware in the cloud
Insights from practical experience
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1
https://ift.tt/QmO7UgY
Submitted April 18, 2023 at 01:29PM by albinowax
via reddit https://ift.tt/xX34D68
https://ift.tt/QmO7UgY
Submitted April 18, 2023 at 01:29PM by albinowax
via reddit https://ift.tt/xX34D68
GhostCcamm's Cyber Misadventures
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1
Strapi had multiple critical vulnerabilities that could be chained together to gain Unauthenticated Remote Code Execution. This is my public disclosure of the vulnerabilities I found in Strapi, how they were patched and some nonsensical ramblings.
Kerio Mailbox Takeover - SSD Secure Disclosure vulnerability publication
https://ift.tt/tn0wDO8
Submitted April 18, 2023 at 02:31PM by SSDisclosure
via reddit https://ift.tt/WXr5G3L
https://ift.tt/tn0wDO8
Submitted April 18, 2023 at 02:31PM by SSDisclosure
via reddit https://ift.tt/WXr5G3L
SSD Secure Disclosure
SSD Advisory - Kerio Mailbox Takeover - SSD Secure Disclosure
Summary By exploiting file upload functionality users are able to upload .html type of files, containing arbitrary JavaScript code, the file is then saved within server. An attacker would then compose and send an email containing URL to said malicious to…
I hack, U-Boot
https://ift.tt/0CK3mQ8
Submitted April 18, 2023 at 03:38PM by Gallus
via reddit https://ift.tt/zR7v1LT
https://ift.tt/0CK3mQ8
Submitted April 18, 2023 at 03:38PM by Gallus
via reddit https://ift.tt/zR7v1LT
Synacktiv
I hack, U-Boot
During hardware assessments, it is common to come across devices implementing U-Boot.
Vulnerability scanner for open source packages
https://dependuck.dev/
Submitted April 18, 2023 at 03:26PM by mastermindbravery
via reddit https://ift.tt/GtfKDFT
https://dependuck.dev/
Submitted April 18, 2023 at 03:26PM by mastermindbravery
via reddit https://ift.tt/GtfKDFT
dependuck.dev
Dependency Scanning with Dependuck | Find and Fix Vulnerabilities
Dependuck provides dependency scanning to help you identify and fix known vulnerabilities in your dependencies. Find dependency vulnerabilities and more.
Memory corruption in JCRE: An unpatchable HSM may swallow your private key
https://ift.tt/PpB9ReF
Submitted April 18, 2023 at 07:12PM by hardenedvault
via reddit https://ift.tt/YtwqXoQ
https://ift.tt/PpB9ReF
Submitted April 18, 2023 at 07:12PM by hardenedvault
via reddit https://ift.tt/YtwqXoQ
hardenedvault.net
Memory corruption in JCRE: An unpatchable HSM may swallow your private key
Background The key has always been a core target of security protection.
AWS Account ID: An Attacker's Perspective
https://ift.tt/Kn3a5zp
Submitted April 18, 2023 at 08:49PM by VariousAd5147
via reddit https://ift.tt/8QFe9Yh
https://ift.tt/Kn3a5zp
Submitted April 18, 2023 at 08:49PM by VariousAd5147
via reddit https://ift.tt/8QFe9Yh
www.zeuscloud.io
AWS Account ID: An Attacker's Perspective
How attackers can find and use AWS Account IDs