The Web Won't Survive AI
https://ift.tt/bxoU3K4
Submitted May 01, 2023 at 01:53PM by ConscienceRound
via reddit https://ift.tt/GYdq1QI
https://ift.tt/bxoU3K4
Submitted May 01, 2023 at 01:53PM by ConscienceRound
via reddit https://ift.tt/GYdq1QI
Thisunreality
The Web Won't Survive AI
The digital war of tomorrow pitches generative AI against digital ID
3CX data breach shows organizations can’t afford to overlook software supply chain attacks
https://ift.tt/m7vHygI
Submitted May 01, 2023 at 07:38PM by dlorenc
via reddit https://ift.tt/lhAxmw0
https://ift.tt/m7vHygI
Submitted May 01, 2023 at 07:38PM by dlorenc
via reddit https://ift.tt/lhAxmw0
VentureBeat
3CX data breach shows organizations can’t afford to overlook software supply chain attacks
The recent 3CX data breach highlights that organizations can't afford to overlook the risks presented by software supply chain attacks.
Practical Risks to Machine Learning Systems -- Pickle Serialization of Shared Models
https://ift.tt/zrKndZI
Submitted May 01, 2023 at 09:11PM by SUPACOMPUTA
via reddit https://ift.tt/lUChMxf
https://ift.tt/zrKndZI
Submitted May 01, 2023 at 09:11PM by SUPACOMPUTA
via reddit https://ift.tt/lUChMxf
Splunk-Blogs
Paws in the Pickle Jar: Risk & Vulnerability in the Model-sharing Ecosystem
As AI / Machine Learning (ML) systems now support millions of daily users, has our understanding of the relevant security risks kept pace with this wild rate of adoption?
[PAPERBUG] Nomadic Octopus’ Paperbug Campaign
https://ift.tt/peLRC9A
Submitted May 01, 2023 at 10:06PM by wtfse
via reddit https://ift.tt/oAP97ht
https://ift.tt/peLRC9A
Submitted May 01, 2023 at 10:06PM by wtfse
via reddit https://ift.tt/oAP97ht
Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera
https://ift.tt/a0JKNBD
Submitted May 02, 2023 at 09:49AM by Mempodipper
via reddit https://ift.tt/a0mXY5Z
https://ift.tt/a0JKNBD
Submitted May 02, 2023 at 09:49AM by Mempodipper
via reddit https://ift.tt/a0mXY5Z
Assetnote
Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera
Application security issues found by Assetnote
CoinMiner (KONO DIO DA) Distributed to Linux SSH Servers
https://ift.tt/AQkVzus
Submitted May 02, 2023 at 08:53AM by montouesto
via reddit https://ift.tt/njKgM1W
https://ift.tt/AQkVzus
Submitted May 02, 2023 at 08:53AM by montouesto
via reddit https://ift.tt/njKgM1W
ASEC BLOG
CoinMiner (KONO DIO DA) Distributed to Linux SSH Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered XMRig CoinMiner being installed on poorly managed Linux SSH servers. The attacks have been happening with a distinct pattern since 2022: they involve the usage of malware developed with…
Databricks platform root privilege escalation and bypassing cluster isolation
https://ift.tt/vbTjiVh
Submitted May 02, 2023 at 06:42PM by 0x9000
via reddit https://ift.tt/Hn28gaW
https://ift.tt/vbTjiVh
Submitted May 02, 2023 at 06:42PM by 0x9000
via reddit https://ift.tt/Hn28gaW
SEC Consult
Securing Databricks cluster init noscripts
This blog was co-authored by Elia Florio, Sr. Director of Detection & Response at Databricks and Florian Roth and Marius Bartholdy, security researchers with SEC Consult.
Easy Pentest Reporting Tool SysReptor released (Community Edition)
https://ift.tt/lO4E5X3
Submitted May 02, 2023 at 07:22PM by Pleasant-Drawer729
via reddit https://ift.tt/zrTwBbn
https://ift.tt/lO4E5X3
Submitted May 02, 2023 at 07:22PM by Pleasant-Drawer729
via reddit https://ift.tt/zrTwBbn
GitHub
GitHub - Syslifters/sysreptor: Fully customisable, offensive security reporting solution designed for pentesters, red teamers and…
Fully customisable, offensive security reporting solution designed for pentesters, red teamers and other security-related people alike. - GitHub - Syslifters/sysreptor: Fully customisable, offensiv...
A Guide to Privilege Escalation with AWS Identity Center (formerly known as AWS SSO)
https://ift.tt/Z9FfVmQ
Submitted May 02, 2023 at 10:38PM by jsonpile
via reddit https://ift.tt/8PJq9C5
https://ift.tt/Z9FfVmQ
Submitted May 02, 2023 at 10:38PM by jsonpile
via reddit https://ift.tt/8PJq9C5
CloudQuery
AWS Identity Center (formerly known as AWS SSO): A Guide to Privilege Escalation and Identity and Access Management | CloudQuery
AWS Identity Center is one way of managing access to AWS Accounts. With AWS Identity Center (previously SSO), there exists multiple pathways to privilege escalation. In this blog post, we cover Identity Center, research into the inner workings of cloud…
Exploring Algorithm Confusion Attacks on JWT: Exploiting ECDSA
https://ift.tt/mXKQpBa
Submitted May 03, 2023 at 04:21AM by Gallus
via reddit https://ift.tt/05WQvj4
https://ift.tt/mXKQpBa
Submitted May 03, 2023 at 04:21AM by Gallus
via reddit https://ift.tt/05WQvj4
Medium
Exploring Algorithm Confusion Attacks on JWT: Exploiting ECDSA
JSON Web Tokens (JWT) are widely used for authentication in modern applications. As their use increases, so does the importance of…
Rapture, a Ransomware Family With Similarities to Paradise
https://ift.tt/IiQpx7W
Submitted May 03, 2023 at 11:11AM by montouesto
via reddit https://ift.tt/zN0QSal
https://ift.tt/IiQpx7W
Submitted May 03, 2023 at 11:11AM by montouesto
via reddit https://ift.tt/zN0QSal
Trend Micro
Rapture, a Ransomware Family With Similarities to Paradise
In March and April 2023, we observed a type of ransomware targeting its victims via a minimalistic approach with tools that leave only a minimal footprint behind. Our findings revealed many of the preparations made by the perpetrators and how quickly they…
RecordBreaker Stealer Distributed via Hacked YouTube Accounts
https://ift.tt/Kei4BcF
Submitted May 03, 2023 at 08:40PM by montouesto
via reddit https://ift.tt/dfHaV1j
https://ift.tt/Kei4BcF
Submitted May 03, 2023 at 08:40PM by montouesto
via reddit https://ift.tt/dfHaV1j
ASEC BLOG
RecordBreaker Stealer Distributed via Hacked YouTube Accounts - ASEC BLOG
RecordBreaker is a new Infostealer that appeared in 2022 and is known as the new version of Raccoon Stealer. Similar to other Infostealers, such as CryptBot, RedLine, and Vidar, it is a major malware type that usually disguises itself as a software crack…
Reverse engineering tricks: identifying opaque network protocols
https://ift.tt/Ymk8JN5
Submitted May 03, 2023 at 08:02PM by iagox86
via reddit https://ift.tt/1Wz54qe
https://ift.tt/Ymk8JN5
Submitted May 03, 2023 at 08:02PM by iagox86
via reddit https://ift.tt/1Wz54qe
SkullSecurity Blog
Reverse engineering tricks: identifying opaque network protocols
Lately, I’ve been reverse engineering a reasonably complex network protocol, and I ran into a mystery - while the protocol is generally an unencrypted binary protocol, one of the messages was large and random. In an otherwise unencrypted protocol, why is…
Vulnerability Spotlight: Vulnerabilities in IBM AIX could lead to command injection with elevated privileges
https://ift.tt/MS9cRCE
Submitted May 03, 2023 at 09:11PM by timb_machine
via reddit https://ift.tt/gB0ytrG
https://ift.tt/MS9cRCE
Submitted May 03, 2023 at 09:11PM by timb_machine
via reddit https://ift.tt/gB0ytrG
Cisco Talos Blog
Vulnerability Spotlight: Vulnerabilities in IBM AIX could lead to command injection with elevated privileges
The issue could then allow the malicious actor to generate arbitrary logs which can trigger malicious commands to be run with elevated privileges.
Dracon – Open Source ASOC got major upgrades
https://ift.tt/CNYwKzg
Submitted May 03, 2023 at 08:56PM by ___foo_bar___
via reddit https://ift.tt/kOF9wYc
https://ift.tt/CNYwKzg
Submitted May 03, 2023 at 08:56PM by ___foo_bar___
via reddit https://ift.tt/kOF9wYc
GitHub
GitHub - ocurity/dracon: Security scanning orchestration and results enrichment framework -- forked and rewritten from @thought…
Security scanning orchestration and results enrichment framework -- forked and rewritten from @thought-machine/dracon - GitHub - ocurity/dracon: Security scanning orchestration and results enrichme...
OpenPubkey adds public keys to OpenID (OIDC) without breaking compatibility with IDPs
https://ift.tt/fKED14M
Submitted May 03, 2023 at 11:35PM by xor_rotate
via reddit https://ift.tt/YbNKxfH
https://ift.tt/fKED14M
Submitted May 03, 2023 at 11:35PM by xor_rotate
via reddit https://ift.tt/YbNKxfH
Bastionzero
A New Era for Cryptographic Signatures | BastionZero
Learn how the new OpenPubkey protocol advances cryptographic signature technology while bolstering OpenID Connect MFA.
So long passwords, thanks for all the phish
https://ift.tt/OCqeRVG
Submitted May 04, 2023 at 04:38AM by ScottContini
via reddit https://ift.tt/kPKoHzX
https://ift.tt/OCqeRVG
Submitted May 04, 2023 at 04:38AM by ScottContini
via reddit https://ift.tt/kPKoHzX
Google Online Security Blog
So long passwords, thanks for all the phish
By: Arnar Birgisson and Diana K Smetters, Identity Ecosystems and Google Account Security and Safety teams Starting today , you can create a...
How to Analyze Java Malware – A Case Study of STRRAT
https://ift.tt/rW105eQ
Submitted May 04, 2023 at 11:46AM by CyberMasterV
via reddit https://ift.tt/r5ahYl2
https://ift.tt/rW105eQ
Submitted May 04, 2023 at 11:46AM by CyberMasterV
via reddit https://ift.tt/r5ahYl2
Security Scorecard
How To Analyze Java Malware – A Case Study Of STRRAT
Apache Solr 8.3.1 RCE from exposed administration interface
https://ift.tt/xDpIf2k
Submitted May 04, 2023 at 12:34PM by IIIWeedWizard420III
via reddit https://ift.tt/Pce7vfO
https://ift.tt/xDpIf2k
Submitted May 04, 2023 at 12:34PM by IIIWeedWizard420III
via reddit https://ift.tt/Pce7vfO
From Chaos to Clarity: How to Secure Your Supply Chain with Attestations
https://ift.tt/CzpUxd8
Submitted May 04, 2023 at 02:43PM by BarakScribe
via reddit https://ift.tt/jCZN4QB
https://ift.tt/CzpUxd8
Submitted May 04, 2023 at 02:43PM by BarakScribe
via reddit https://ift.tt/jCZN4QB
Scribe Security
From Chaos to Clarity: How to Secure Your Supply Chain with Attestations
How to use a new model to build trust in your software supply chain elements through a comprehensive compliance platform turning building blocks into verifiable evidence.
Uncovering drIBAN fraud operations - Chapter 1 | Cleafy Labs
https://ift.tt/93hLdJk
Submitted May 04, 2023 at 03:43PM by f3d_0x0
via reddit https://ift.tt/BNt2Iyh
https://ift.tt/93hLdJk
Submitted May 04, 2023 at 03:43PM by f3d_0x0
via reddit https://ift.tt/BNt2Iyh
Cleafy
Uncovering drIBAN fraud operations 1 | Cleafy Labs
The threat intelligence team of Cleafy analyzed undercovering drIBAN fraud operations. Read here the first episode of the series of technical analysis.