User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264)
https://ift.tt/8AvW6sH
Submitted April 27, 2023 at 06:00PM by Offensity
via reddit https://ift.tt/AFbKDcy
https://ift.tt/8AvW6sH
Submitted April 27, 2023 at 06:00PM by Offensity
via reddit https://ift.tt/AFbKDcy
Offensity
User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264) | Offensity
Security reports: efficient and straightforward. The simplest way to detect and fix vulnerabilities
Android greybox fuzzing with AFL++ Frida mode
https://ift.tt/3CaBfes
Submitted April 27, 2023 at 10:06PM by jeandrew
via reddit https://ift.tt/uoLHTFp
https://ift.tt/3CaBfes
Submitted April 27, 2023 at 10:06PM by jeandrew
via reddit https://ift.tt/uoLHTFp
Quarkslab
Android greybox fuzzing with AFL++ Frida mode
Dissecting Npm Malware: Five Packages And Their Evil Install Scripts
https://ift.tt/1Viv78N
Submitted April 28, 2023 at 01:18PM by sculabobone
via reddit https://ift.tt/PYd4Z9L
https://ift.tt/1Viv78N
Submitted April 28, 2023 at 01:18PM by sculabobone
via reddit https://ift.tt/PYd4Z9L
Sandworm
Dissecting Npm Malware: Five Packages And Their Evil Install Scripts
Packages published on npm can declare pre and post-install hooks, which are noscripts that run, well, pre or post-install. That is to say, when the npm CLI installs a package, it also runs those noscripts on your machine.
It runs them silently, in the ba...
It runs them silently, in the ba...
CVE-2022-37955: Vulnerability in Microsoft Windows Group Policy Updates Leads to Improper Link Resolution Before File Access (Privilege Escalation CWE-59)
https://ift.tt/e5hPBm4
Submitted April 28, 2023 at 02:43PM by usdAG
via reddit https://ift.tt/ea0LW4P
https://ift.tt/e5hPBm4
Submitted April 28, 2023 at 02:43PM by usdAG
via reddit https://ift.tt/ea0LW4P
usd HeroLab
Security Advisory usd-2022-0034 | usd HeroLab
Advisory ID: usd-2022-0034 | Product: Microsoft Windows | Vulnerability Type: Improper Link Resolution Before File Access (CWE-59)
Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707)
https://ift.tt/60BImhV
Submitted April 28, 2023 at 04:09PM by scopedsecurity
via reddit https://ift.tt/j3V6nkb
https://ift.tt/60BImhV
Submitted April 28, 2023 at 04:09PM by scopedsecurity
via reddit https://ift.tt/j3V6nkb
STAR Labs
Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707)
Introduction While analyzing CVE-2022-41082, also known as ProxyNotShell, we discovered this vulnerability which we have detailed in this blog. However, for a comprehensive understanding, we highly recommend reading the thorough analysis written by team ZDI.…
Chinese Alloy Taurus Updates PingPull Malware
https://ift.tt/Y4xeaPK
Submitted April 28, 2023 at 06:24PM by EspoJ
via reddit https://ift.tt/jGAnBLg
https://ift.tt/Y4xeaPK
Submitted April 28, 2023 at 06:24PM by EspoJ
via reddit https://ift.tt/jGAnBLg
Unit 42
Chinese Alloy Taurus Updates PingPull Malware
A PingPull malware variant for Linux has been found. We’re also tracking a new backdoor attributed to Alloy Taurus called Sword2033.
How Cloud Environments Are Exploited for Smishing Campaigns
https://ift.tt/oKFzAXw
Submitted April 28, 2023 at 11:25PM by permis0
via reddit https://ift.tt/LRoe01h
https://ift.tt/oKFzAXw
Submitted April 28, 2023 at 11:25PM by permis0
via reddit https://ift.tt/LRoe01h
permiso.io
Permiso | Blog | New Phone, Who Dis? How Cloud Environments Are Exploited for Smishing Campaigns
Commodity threat actors have recently begun to exploit cloud environments for smishing campaigns, employing techniques strikingly similar to those used in SES enumeration and abuse.
State of DNS Rebinding in 2023
https://ift.tt/XlMVn2b
Submitted April 29, 2023 at 06:20AM by Tough_Indication_710
via reddit https://ift.tt/d9MQ162
https://ift.tt/XlMVn2b
Submitted April 29, 2023 at 06:20AM by Tough_Indication_710
via reddit https://ift.tt/d9MQ162
NCC Group Research Blog
State of DNS Rebinding in 2023
Different forms of DNS rebinding attacks have been described as far back as 1996 for Java Applets and 2002 for JavaScript (Quick-Swap). It has been four years since our State of DNS Rebinding prese…
GitHub - dwisiswant0/siml: siml is a CLI tool for discovering similar, related to, competitive, or alternative options to a given site.
https://ift.tt/fu7GyCv
Submitted April 30, 2023 at 07:02AM by dwisiswant0
via reddit https://ift.tt/ZezX1SH
https://ift.tt/fu7GyCv
Submitted April 30, 2023 at 07:02AM by dwisiswant0
via reddit https://ift.tt/ZezX1SH
GitHub
GitHub - dwisiswant0/siml: siml is a CLI tool for discovering similar, related to, competitive, or alternative options to a given…
siml is a CLI tool for discovering similar, related to, competitive, or alternative options to a given site. - GitHub - dwisiswant0/siml: siml is a CLI tool for discovering similar, related to, com...
Automate Burp Certificate Installation on Android with ChatGPT's Python Tool
https://ift.tt/AUf7YmM
Submitted April 30, 2023 at 10:55AM by Ano_F
via reddit https://ift.tt/xh93Efr
https://ift.tt/AUf7YmM
Submitted April 30, 2023 at 10:55AM by Ano_F
via reddit https://ift.tt/xh93Efr
GitHub
GitHub - Anof-cyber/Androset: Automated noscript to convert and push Burp Suite certificate in Android, and modify Android's IP table…
Automated noscript to convert and push Burp Suite certificate in Android, and modify Android's IP table to redirect all traffic to Burp Suite. - Anof-cyber/Androset
Elastic Security Labs discovers the LOBSHOT malware
https://ift.tt/isDPqoM
Submitted April 30, 2023 at 05:40PM by montouesto
via reddit https://ift.tt/6jtWvn3
https://ift.tt/isDPqoM
Submitted April 30, 2023 at 05:40PM by montouesto
via reddit https://ift.tt/6jtWvn3
www.elastic.co
Elastic Security Labs discovers the LOBSHOT malware — Elastic Security Labs
Elastic Security Labs is naming a new malware family, LOBSHOT. LOBSHOT propagates and infiltrates targeted networks through Google Ads and hVNC sessions to deploy backdoors masquerading as legitimate application installers.
assetnote/ghostbuster: Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.
https://ift.tt/1PghFYi
Submitted April 30, 2023 at 05:38PM by Mempodipper
via reddit https://ift.tt/CJt1YFR
https://ift.tt/1PghFYi
Submitted April 30, 2023 at 05:38PM by Mempodipper
via reddit https://ift.tt/CJt1YFR
GitHub
GitHub - assetnote/ghostbuster: Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.
Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts. - GitHub - assetnote/ghostbuster: Eliminate dangling elastic IPs by performing analysis on your...
Sharing a tool I developed to help Blue Teamers discover Persistence on Windows - please check it out!
https://ift.tt/FDWp2Bl
Submitted April 30, 2023 at 07:22PM by panscanner
via reddit https://ift.tt/XJ61F3z
https://ift.tt/FDWp2Bl
Submitted April 30, 2023 at 07:22PM by panscanner
via reddit https://ift.tt/XJ61F3z
GitHub
GitHub - joeavanzato/Trawler: PowerShell noscript to help Incident Responders discover potential adversary persistence mechanisms.
PowerShell noscript to help Incident Responders discover potential adversary persistence mechanisms. - GitHub - joeavanzato/Trawler: PowerShell noscript to help Incident Responders discover potential a...
Azure DevOps CICD Pipelines - Command Injection with Parameters, Variables and a discussion on Runner hijacking
https://ift.tt/bvznAL4
Submitted May 01, 2023 at 02:12PM by MysteriousHotel3017
via reddit https://ift.tt/MJzI2pD
https://ift.tt/bvznAL4
Submitted May 01, 2023 at 02:12PM by MysteriousHotel3017
via reddit https://ift.tt/MJzI2pD
Pulse Security
Azure DevOps CICD Pipelines - Command Injection with Parameters, Variables and a discussion on Runner hijacking
This article discusses a vulnerability in Azure DevOps, and some of the impacts of a compromised pipeline and deployment runner. Variables and parameters used in Azure DevOps pipelines can be used to inject shell commands that run on the Azure DevOps runner.…
The Web Won't Survive AI
https://ift.tt/bxoU3K4
Submitted May 01, 2023 at 01:53PM by ConscienceRound
via reddit https://ift.tt/GYdq1QI
https://ift.tt/bxoU3K4
Submitted May 01, 2023 at 01:53PM by ConscienceRound
via reddit https://ift.tt/GYdq1QI
Thisunreality
The Web Won't Survive AI
The digital war of tomorrow pitches generative AI against digital ID
3CX data breach shows organizations can’t afford to overlook software supply chain attacks
https://ift.tt/m7vHygI
Submitted May 01, 2023 at 07:38PM by dlorenc
via reddit https://ift.tt/lhAxmw0
https://ift.tt/m7vHygI
Submitted May 01, 2023 at 07:38PM by dlorenc
via reddit https://ift.tt/lhAxmw0
VentureBeat
3CX data breach shows organizations can’t afford to overlook software supply chain attacks
The recent 3CX data breach highlights that organizations can't afford to overlook the risks presented by software supply chain attacks.
Practical Risks to Machine Learning Systems -- Pickle Serialization of Shared Models
https://ift.tt/zrKndZI
Submitted May 01, 2023 at 09:11PM by SUPACOMPUTA
via reddit https://ift.tt/lUChMxf
https://ift.tt/zrKndZI
Submitted May 01, 2023 at 09:11PM by SUPACOMPUTA
via reddit https://ift.tt/lUChMxf
Splunk-Blogs
Paws in the Pickle Jar: Risk & Vulnerability in the Model-sharing Ecosystem
As AI / Machine Learning (ML) systems now support millions of daily users, has our understanding of the relevant security risks kept pace with this wild rate of adoption?
[PAPERBUG] Nomadic Octopus’ Paperbug Campaign
https://ift.tt/peLRC9A
Submitted May 01, 2023 at 10:06PM by wtfse
via reddit https://ift.tt/oAP97ht
https://ift.tt/peLRC9A
Submitted May 01, 2023 at 10:06PM by wtfse
via reddit https://ift.tt/oAP97ht
Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera
https://ift.tt/a0JKNBD
Submitted May 02, 2023 at 09:49AM by Mempodipper
via reddit https://ift.tt/a0mXY5Z
https://ift.tt/a0JKNBD
Submitted May 02, 2023 at 09:49AM by Mempodipper
via reddit https://ift.tt/a0mXY5Z
Assetnote
Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera
Application security issues found by Assetnote
CoinMiner (KONO DIO DA) Distributed to Linux SSH Servers
https://ift.tt/AQkVzus
Submitted May 02, 2023 at 08:53AM by montouesto
via reddit https://ift.tt/njKgM1W
https://ift.tt/AQkVzus
Submitted May 02, 2023 at 08:53AM by montouesto
via reddit https://ift.tt/njKgM1W
ASEC BLOG
CoinMiner (KONO DIO DA) Distributed to Linux SSH Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered XMRig CoinMiner being installed on poorly managed Linux SSH servers. The attacks have been happening with a distinct pattern since 2022: they involve the usage of malware developed with…
Databricks platform root privilege escalation and bypassing cluster isolation
https://ift.tt/vbTjiVh
Submitted May 02, 2023 at 06:42PM by 0x9000
via reddit https://ift.tt/Hn28gaW
https://ift.tt/vbTjiVh
Submitted May 02, 2023 at 06:42PM by 0x9000
via reddit https://ift.tt/Hn28gaW
SEC Consult
Securing Databricks cluster init noscripts
This blog was co-authored by Elia Florio, Sr. Director of Detection & Response at Databricks and Florian Roth and Marius Bartholdy, security researchers with SEC Consult.