Compromising Garmin's Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine - Anvil Secure
https://ift.tt/PaxDHEK
Submitted April 21, 2023 at 10:12PM by anvilventures
via reddit https://ift.tt/DIpnUzN
https://ift.tt/PaxDHEK
Submitted April 21, 2023 at 10:12PM by anvilventures
via reddit https://ift.tt/DIpnUzN
Anvil Secure
Compromising Garmin's Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine - Anvil Secure
I reversed the firmware of my Garmin Forerunner 245 Music back in 2022 and found a dozen or so vulnerabilities in their support for Connect IQ applications. They can be exploited…
Hiding in Plain Sight: Unlinking Malicious DLLs from the PEB
https://ift.tt/Z8Nw6tM
Submitted April 22, 2023 at 02:05AM by thorn42
via reddit https://ift.tt/Yc68U9P
https://ift.tt/Z8Nw6tM
Submitted April 22, 2023 at 02:05AM by thorn42
via reddit https://ift.tt/Yc68U9P
Christophe Tafani-Dereeper
Hiding in Plain Sight: Unlinking Malicious DLLs from the PEB - Christophe Tafani-Dereeper
In this post, we take a look at an anti-forensics technique that malware can leverage to hide injected DLLs. We dive into specific details of the Windows Process Environment Block (PEB) and how to abuse it to hide a malicious loaded DLL. Background: You may…
The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders
https://ift.tt/4tLMrdo
Submitted April 22, 2023 at 08:19AM by 1esproc
via reddit https://ift.tt/yRz9GvA
https://ift.tt/4tLMrdo
Submitted April 22, 2023 at 08:19AM by 1esproc
via reddit https://ift.tt/yRz9GvA
Vulkan Files
https://ift.tt/U79hORW
Submitted April 22, 2023 at 04:24PM by Snoo_27235
via reddit https://ift.tt/3tdeI7h
https://ift.tt/U79hORW
Submitted April 22, 2023 at 04:24PM by Snoo_27235
via reddit https://ift.tt/3tdeI7h
GitLab
prisma / Vulkan files · GitLab
Documents from the "Vulkan leak" both in russin (original) and english (translated).
ThePhish: an automated phishing email analysis tool - A new version will come when the Python API for TheHive 5 becomes stable, so stay tuned!
https://ift.tt/9z6CqMc
Submitted April 22, 2023 at 05:25PM by emalderson
via reddit https://ift.tt/1SAJrw5
https://ift.tt/9z6CqMc
Submitted April 22, 2023 at 05:25PM by emalderson
via reddit https://ift.tt/1SAJrw5
GitHub
GitHub - emalderson/ThePhish: ThePhish: an automated phishing email analysis tool
ThePhish: an automated phishing email analysis tool - GitHub - emalderson/ThePhish: ThePhish: an automated phishing email analysis tool
Machinegun is a better version of Metasploit's railgun, capable of reliably running arbitrary Windows API functions on a remote computer.
https://ift.tt/OqRtQTA
Submitted April 23, 2023 at 04:52PM by Idov31
via reddit https://ift.tt/Qdu69zn
https://ift.tt/OqRtQTA
Submitted April 23, 2023 at 04:52PM by Idov31
via reddit https://ift.tt/Qdu69zn
Google
http://google.com
Submitted April 23, 2023 at 04:50PM by Igbeen12
via reddit https://ift.tt/HfaDc98
http://google.com
Submitted April 23, 2023 at 04:50PM by Igbeen12
via reddit https://ift.tt/HfaDc98
Reddit
From the netsec community on Reddit: Google
Posted by Igbeen12 - No votes and 2 comments
Generative AI Design Best Practices for Web Applications
https://ift.tt/V4du78E
Submitted April 23, 2023 at 07:01PM by kerberosmansour
via reddit https://ift.tt/uae19E5
https://ift.tt/V4du78E
Submitted April 23, 2023 at 07:01PM by kerberosmansour
via reddit https://ift.tt/uae19E5
Medium
Generative AI Design Best Practices for Web Applications
In today’s digital landscape, generative AI has the potential to become an essential tool for web applications, offering personalized and…
GCP Cloud Function Abuse
https://ift.tt/K2pxQIg
Submitted April 24, 2023 at 06:44AM by debifrank
via reddit https://ift.tt/rWePzKq
https://ift.tt/K2pxQIg
Submitted April 24, 2023 at 06:44AM by debifrank
via reddit https://ift.tt/rWePzKq
Infosec Rabbit Holes
GCP Cloud Function Abuse
Article discussing GCP Cloud Function Abuse covering Local File Inclusion (LFI), Server-Side Request Forgery (SSRF), and Command Injection vulnerabilities. Explains how these vulnerabilities can be exploited to get access to authorization tokens and other…
PaperCut CVE-2023-27350 Deep Dive, Indicators of Compromise, and Exploit POC
https://ift.tt/T4eOWrU
Submitted April 24, 2023 at 04:53PM by scopedsecurity
via reddit https://ift.tt/ravhSyH
https://ift.tt/T4eOWrU
Submitted April 24, 2023 at 04:53PM by scopedsecurity
via reddit https://ift.tt/ravhSyH
Horizon3.ai
PaperCut CVE-2023-27350 Deep Dive and Indicators of Compromise
PaperCut CVE-2023-27350 Technical Deep-Dive, Indicators of Compromise, and Exploit Proof-of-Concept.
ChattyCaty - OSS tool that creates polymorphic programs using GPT models.
https://ift.tt/Md0Eprn
Submitted April 24, 2023 at 06:22PM by jat0369
via reddit https://ift.tt/Wv2lQcm
https://ift.tt/Md0Eprn
Submitted April 24, 2023 at 06:22PM by jat0369
via reddit https://ift.tt/Wv2lQcm
GitHub
GitHub - cyberark/ChattyCaty
Contribute to cyberark/ChattyCaty development by creating an account on GitHub.
Detecting and decrypting Sliver C2 – a threat hunter's guide
https://ift.tt/arDQBCW
Submitted April 24, 2023 at 08:30PM by kev-thehermit
via reddit https://ift.tt/13Wiga6
https://ift.tt/arDQBCW
Submitted April 24, 2023 at 08:30PM by kev-thehermit
via reddit https://ift.tt/13Wiga6
Immersive Labs
Detecting and decrypting Sliver C2 – a threat hunter's guide
Originating from the Bishop Fox team, Sliver is an open-source, cross-platform, and extensible C2 framework. It's written primarily in Go, making it fast, portable, and easy to customize. This versatility makes it a popular choice among red teams for adversary…
Eating 4 Day Old Sushi - Replicating the SushiSwap Blockchain Hack (Blog and Live Video)
https://ift.tt/c7KRDPh
Submitted April 24, 2023 at 08:19PM by mdulin2
via reddit https://ift.tt/7UsqW26
https://ift.tt/c7KRDPh
Submitted April 24, 2023 at 08:19PM by mdulin2
via reddit https://ift.tt/7UsqW26
Strikeout Security Blog
Eating 4 Day Old Sushi - Replicating the SushiSwap Hack
Hacking new SushiSwap router contract. Including full proof of concept and demo environment.
c0c0n XVI | The cy0ps c0n - Call For Papers & Call For Workshops
https://ift.tt/IshvNpm
Submitted April 24, 2023 at 09:18PM by pr4jwal
via reddit https://ift.tt/Cry7ntI
https://ift.tt/IshvNpm
Submitted April 24, 2023 at 09:18PM by pr4jwal
via reddit https://ift.tt/Cry7ntI
c0c0n.org
c0c0n XVI | The cy0ps c0n - Call For Papers & Call For Workshops
c0c0n is a 15 years old platform that is aimed at providing opportunities to showcase, educate, understand and spread awareness on Information Security, data protection, and privacy. It also aims to provide a hand-shaking platform for various Corporate, Government…
Fortune 500 at Risk: 250M Artifacts Exposed via Misconfigured Registries
https://ift.tt/BNtJlwc
Submitted April 24, 2023 at 10:46PM by gfdgfbal
via reddit https://ift.tt/lfaHTPG
https://ift.tt/BNtJlwc
Submitted April 24, 2023 at 10:46PM by gfdgfbal
via reddit https://ift.tt/lfaHTPG
Aquasec
Fortune 500 at Risk: 250M Artifacts Exposed via Misconfigured Registries
The Aqua Nautilus research team found detected thousands of exposed registries and artifact repositories in some of the world’s largest organizations
Book Review: Red Team Blues
https://ift.tt/dZoO5lJ
Submitted April 24, 2023 at 11:01PM by feross
via reddit https://ift.tt/wIDSc2x
https://ift.tt/dZoO5lJ
Submitted April 24, 2023 at 11:01PM by feross
via reddit https://ift.tt/wIDSc2x
A Few Thoughts on Cryptographic Engineering
Book Review: Red Team Blues
As a rule, book reviews are not a thing I usually do. So when I received an out-of-the-blue email from Cory Doctorow last week asking if I would review his latest book, Red Team Blues, it took a mi…
3D-Printable BusKill (USB Dead Man Switch) Prototype
https://ift.tt/3xzdWFX
Submitted April 24, 2023 at 10:52PM by maltfield
via reddit https://ift.tt/WanOiND
https://ift.tt/3xzdWFX
Submitted April 24, 2023 at 10:52PM by maltfield
via reddit https://ift.tt/WanOiND
BusKill
3D Printable BusKill Prototypes - BusKill
Update on our progress on the 3D-printable BusKill prototype, a DIY USB kill cord to protect your laptop's data from thieves.
New .NET Malware “WhiteSnake” Targets Python Developers, Uses Tor for C&C Communication
https://ift.tt/lh0GIBN
Submitted April 25, 2023 at 12:54AM by SRMish3
via reddit https://ift.tt/Hhc9wuL
https://ift.tt/lh0GIBN
Submitted April 25, 2023 at 12:54AM by SRMish3
via reddit https://ift.tt/Hhc9wuL
JFrog
New .NET Malware “WhiteSnake” Targets Python Developers, Uses Tor for C&C Communication | JFrog
In depth analysis of new python malware. Highlights: 22 malicious packages detected, C2 comms capable via TOR, manueaverable and stealth...
How AI helps keeping Gmail inboxes malware free
https://ift.tt/eWn51Rl
Submitted April 25, 2023 at 07:35AM by ebursztein
via reddit https://ift.tt/LzcmfRE
https://ift.tt/eWn51Rl
Submitted April 25, 2023 at 07:35AM by ebursztein
via reddit https://ift.tt/LzcmfRE
Elie Bursztein's site
How AI helps keeping Gmail inboxes malware free
This talk provides an overview of how Google uses AI to strengthen Gmail's document defenses and withstand attacks that evade traditional AVs
KeepassXC audit report
https://ift.tt/0Ubv7ly
Submitted April 25, 2023 at 11:43AM by Blocikinio
via reddit https://ift.tt/q3YcP1h
https://ift.tt/0Ubv7ly
Submitted April 25, 2023 at 11:43AM by Blocikinio
via reddit https://ift.tt/q3YcP1h
keepassxc.org
KeePassXC Audit Report – KeePassXC
KeePassXC Password Manager
Intel Trust Domain Extensions (TDX) Security Review by Google Project Zero
https://ift.tt/TkEnwNX
Submitted April 25, 2023 at 01:10PM by poltess0
via reddit https://ift.tt/vFedcDW
https://ift.tt/TkEnwNX
Submitted April 25, 2023 at 01:10PM by poltess0
via reddit https://ift.tt/vFedcDW