Using AI to find software vulnerabilities in XNU
https://ift.tt/c3gi5FB
Submitted May 09, 2023 at 11:17PM by TimGMichaud
via reddit https://ift.tt/XnCs21S
https://ift.tt/c3gi5FB
Submitted May 09, 2023 at 11:17PM by TimGMichaud
via reddit https://ift.tt/XnCs21S
Inulledmyself
Using AI to find software vulnerabilities in XNU
Note : This work took place in May-Aug of 2022. It just took me this long to finally finish writing this (Too busy playing with my SRD 😅) L...
An analysis of partial/intermittent encryption, along with our newest OSS ransomware recovery tool...WHITE PHOENIX.
https://ift.tt/DxMJ4tA
Submitted May 10, 2023 at 03:18AM by jat0369
via reddit https://ift.tt/jQNT18v
https://ift.tt/DxMJ4tA
Submitted May 10, 2023 at 03:18AM by jat0369
via reddit https://ift.tt/jQNT18v
Cyberark
White Phoenix: Beating Intermittent Encryption
Recently, a new trend has emerged in the world of ransomware: intermittent encryption, the partial encryption of targeted files. Many ransomware groups, such as BlackCat and Play, have adopted...
An AWS IAM Wishlist
https://ift.tt/7xKoyME
Submitted May 10, 2023 at 03:08AM by VariousAd5147
via reddit https://ift.tt/TgxWYmH
https://ift.tt/7xKoyME
Submitted May 10, 2023 at 03:08AM by VariousAd5147
via reddit https://ift.tt/TgxWYmH
www.zeuscloud.io
An AWS IAM Wishlist
A wishlist of AWS IAM feature requests
Escaping Parallels Desktop with Plist Injection
https://ift.tt/juDxrnp
Submitted May 10, 2023 at 04:09AM by DOTheLOGA
via reddit https://ift.tt/YfROl6u
https://ift.tt/juDxrnp
Submitted May 10, 2023 at 04:09AM by DOTheLOGA
via reddit https://ift.tt/YfROl6u
pwn.win
Escaping Parallels Desktop with Plist Injection
This post details two bugs I found, a plist injection (CVE-2023-27328) and a race condition (CVE-2023-27327), which could be used to escape from a guest Parallels Desktop virtual machine. In this post I’ll break down the findings.
PwnAssistant - Controlling /home's via a Home Assistant RCE
https://ift.tt/60ezV9W
Submitted May 10, 2023 at 06:54AM by ffyns
via reddit https://ift.tt/l2Egx4A
https://ift.tt/60ezV9W
Submitted May 10, 2023 at 06:54AM by ffyns
via reddit https://ift.tt/l2Egx4A
Elttam
PwnAssistant - Controlling /home's via a Home Assistant RCE
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
Latest Developments in Unblob (Firmware Extraction Tool)
https://ift.tt/2a69FgD
Submitted May 10, 2023 at 12:24PM by g_e_r_h_a_r_d
via reddit https://ift.tt/zVZi4l6
https://ift.tt/2a69FgD
Submitted May 10, 2023 at 12:24PM by g_e_r_h_a_r_d
via reddit https://ift.tt/zVZi4l6
ONEKEY
Latest Developments in Unblob (2)
Revolutionize firmware extraction with UNBLOB! Discover the latest developments & advancements in this cutting-edge project. Don't miss latest blog post!
Stockfish, a very popular chess engine, has a buffer overflow vulnerability due to unsanatized input
https://ift.tt/BA9inDf
Submitted May 10, 2023 at 05:24PM by Diesl
via reddit https://ift.tt/A65kTaB
https://ift.tt/BA9inDf
Submitted May 10, 2023 at 05:24PM by Diesl
via reddit https://ift.tt/A65kTaB
GitHub
Increase MAX_MOVES to prevent buffer overflow and stack corruption by ZealanL · Pull Request #4558 · official-stockfish/Stockfish
SF's move buffer ExtMove moveList[MAX_MOVES] assumes a maximum move count of 256, but there are many "impossible" positions in which more than 256 moves are generated.
When running on...
When running on...
ChatGPT-Assisted Implant Development, Part 1.
https://ift.tt/azqV8YO
Submitted May 10, 2023 at 09:09PM by fullspectrumdev
via reddit https://ift.tt/1QnqVGO
https://ift.tt/azqV8YO
Submitted May 10, 2023 at 09:09PM by fullspectrumdev
via reddit https://ift.tt/1QnqVGO
Full Spectrum Things
ChatGPT-Assisted Implant Development, Part 1.
This is a rambling post series, as an introduction to some other, forthcoming posts on the same topic. It is mostly a braindump of sorts as I go through the design process and try get GPT to do some element of my job for me.
So recently I have been
So recently I have been
Security Audit of BlindAI Core, an open source ML deployment solution with Intel SGX enclave
https://ift.tt/wLxS40f
Submitted May 10, 2023 at 11:11PM by Wooden_Rip_2341
via reddit https://ift.tt/o1GBdXu
https://ift.tt/wLxS40f
Submitted May 10, 2023 at 11:11PM by Wooden_Rip_2341
via reddit https://ift.tt/o1GBdXu
Mithril Security Blog
BlindAI Passes an Independent Security Audit by Quarkslab
We take security and open-source data privacy seriously at Mithril Security. So we're very proud that our historical confidential computing solution, BlindAI, was successfully audited by Quarkslab!
Testing a new encrypted messaging app's extraordinary claims
https://ift.tt/XOkpgLU
Submitted May 11, 2023 at 04:50AM by crnkovic_
via reddit https://ift.tt/TPZY7ap
https://ift.tt/XOkpgLU
Submitted May 11, 2023 at 04:50AM by crnkovic_
via reddit https://ift.tt/TPZY7ap
crnković.dev
Testing a new encrypted messaging app's extraordinary claims
How I breached a nonexistent database and found every private key in a 'state-of-the-art' encrypted messenger.
Bypass IIS Authorisation with this One Weird Trick - Three RCEs and Two Auth Bypasses in Sitecore 9.3
https://ift.tt/WUkuGQn
Submitted May 11, 2023 at 02:26PM by Mempodipper
via reddit https://ift.tt/aE8NJvZ
https://ift.tt/WUkuGQn
Submitted May 11, 2023 at 02:26PM by Mempodipper
via reddit https://ift.tt/aE8NJvZ
Open Operational Technology Testing Guide (OOTTG)
https://ift.tt/L0KdWV5
Submitted May 11, 2023 at 02:18PM by pizzahax
via reddit https://ift.tt/fK4rNgT
https://ift.tt/L0KdWV5
Submitted May 11, 2023 at 02:18PM by pizzahax
via reddit https://ift.tt/fK4rNgT
aware7.gitbook.io
Einleitung
Cracked password analytics with Kraken
https://ift.tt/5UR3ZLk
Submitted May 11, 2023 at 03:30PM by 0xdea
via reddit https://ift.tt/a3dh5Ax
https://ift.tt/5UR3ZLk
Submitted May 11, 2023 at 03:30PM by 0xdea
via reddit https://ift.tt/a3dh5Ax
hn security
Cracked password analytics with Kraken - hn security
Hi! We are releasing Kraken, HN […]
RET2ASLR - return instructions from other processes can leak pointers through the Branch Target Buffer (BTB) in a reversed spectre-BTI like scenario
https://ift.tt/AmpSDwo
Submitted May 11, 2023 at 05:14PM by Gallus
via reddit https://ift.tt/MScxsYK
https://ift.tt/AmpSDwo
Submitted May 11, 2023 at 05:14PM by Gallus
via reddit https://ift.tt/MScxsYK
GitHub
security-research/pocs/cpus/ret2aslr at master · google/security-research
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code. - google/security-research
Chaining Five Vulnerabilities to Exploit Netgear Nighthawk RAX30 Routers at Pwn2Own Toronto 2022
https://ift.tt/VHO1jMX
Submitted May 11, 2023 at 07:38PM by sh0n1z
via reddit https://ift.tt/5ZLFObQ
https://ift.tt/VHO1jMX
Submitted May 11, 2023 at 07:38PM by sh0n1z
via reddit https://ift.tt/5ZLFObQ
Claroty
Pwn2Own Toronto 22: Exploit Netgear Nighthawk RAX30 Routers
Unveiling IoT Vulnerabilities: A Deep Dive into Netgear RAX30 Router Research from Pwn2Own Competition | Discover the insights gained from our investigation into the security weaknesses of IoT devices, as we analyze the Netgear RAX30 router in the renowned…
New EMBA firmware analyzer release - EMBA v1.2.3 - R.I.P. Binwalk
https://ift.tt/aXitwhI
Submitted May 11, 2023 at 07:33PM by _m-1-k-3_
via reddit https://ift.tt/kScFQue
https://ift.tt/aXitwhI
Submitted May 11, 2023 at 07:33PM by _m-1-k-3_
via reddit https://ift.tt/kScFQue
GitHub
Release EMBA v1.2.3 - R.I.P. Binwalk · e-m-b-a/emba
Binwalk, it was a long and great time with you. Now, you are a bit old and rusty and we had some issues in the past. Looks like we need to change our relationship a little bit ...
The binwalk extr...
The binwalk extr...
JAMBOREE: Powershell->Android Emulator,BloodHound,A1111 and AutoGPT in SECONDS
https://ift.tt/aGdHmOr
Submitted May 11, 2023 at 08:11PM by rmccurdyDOTcom
via reddit https://ift.tt/nqm2t0M
https://ift.tt/aGdHmOr
Submitted May 11, 2023 at 08:11PM by rmccurdyDOTcom
via reddit https://ift.tt/nqm2t0M
GitHub
GitHub - freeload101/Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy: Java Android Magisk Burp Objection Root Emulator Easy…
Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE) - freeload101/Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy
On Ashton Kutcher and Secure Multi-Party Computation
https://ift.tt/YOaJ17q
Submitted May 11, 2023 at 10:55PM by feross
via reddit https://ift.tt/gzaH2Kl
https://ift.tt/YOaJ17q
Submitted May 11, 2023 at 10:55PM by feross
via reddit https://ift.tt/gzaH2Kl
A Few Thoughts on Cryptographic Engineering
On Ashton Kutcher and Secure Multi-Party Computation
Back in March I was fortunate to spend several days visiting Brussels, where I had a chance to attend a panel on “chat control”: the new content scanning regime being considered by the …
Release Ghidra 10.3 · NationalSecurityAgency/ghidra
https://ift.tt/neJ7Hro
Submitted May 12, 2023 at 02:57AM by mumbel
via reddit https://ift.tt/qvptWMI
https://ift.tt/neJ7Hro
Submitted May 12, 2023 at 02:57AM by mumbel
via reddit https://ift.tt/qvptWMI
GitHub
Release Ghidra 10.3 · NationalSecurityAgency/ghidra
What's New
Change History
Installation Guide
SHA-256: 4e990af9b22be562769bb6ce5d4d609fbb45455a7a2f756167b8cdcdb75887fc
Change History
Installation Guide
SHA-256: 4e990af9b22be562769bb6ce5d4d609fbb45455a7a2f756167b8cdcdb75887fc
I built a tool that aggregates security advisories from multiple sources. You can get them by email!
https://cyberowl.org
Submitted May 12, 2023 at 04:52PM by karimhabush
via reddit https://ift.tt/d1oMTcW
https://cyberowl.org
Submitted May 12, 2023 at 04:52PM by karimhabush
via reddit https://ift.tt/d1oMTcW
cyberowl.org
Cyberowl | CyberOwl
Stay informed on the latest cyber threats - a one-stop destination for all the latest alerts and updates from multiple sources.
The printer goes brrrrr, again!
https://ift.tt/WrHTgp9
Submitted May 12, 2023 at 05:26PM by Gallus
via reddit https://ift.tt/7Mp4YEO
https://ift.tt/WrHTgp9
Submitted May 12, 2023 at 05:26PM by Gallus
via reddit https://ift.tt/7Mp4YEO
Synacktiv
The printer goes brrrrr, again!
For the second time at Pwn2Own competition, network printers have been featured in Toronto 2022.