Pre-Authenticated RCE in VMware vRealize Network Insight
https://ift.tt/qXeR9V2
Submitted June 14, 2023 at 07:52PM by scopedsecurity
via reddit https://ift.tt/lagRd5J
https://ift.tt/qXeR9V2
Submitted June 14, 2023 at 07:52PM by scopedsecurity
via reddit https://ift.tt/lagRd5J
Summoning Team
Pre-authenticated RCE in VMware vRealize Network Insight
An interesting case of Pre-authenticated RCE in VMware vRealize Network Insight (CVE-2023-20887)
Google Ads: An effective phishing delivery mechanism for over a decade.
https://ift.tt/6USGtl0
Submitted June 14, 2023 at 09:39PM by Seaerkin2
via reddit https://ift.tt/wJQKYmC
https://ift.tt/6USGtl0
Submitted June 14, 2023 at 09:39PM by Seaerkin2
via reddit https://ift.tt/wJQKYmC
Guardyourdomain
DomainGuard | Threat Visibility Platform
We guard your domain, so you have peace of mind. Threat Visibility Platform.
Cadet Blizzard emerges as a novel and distinct Russian threat actor | Threat Intelligence
https://ift.tt/Bmi0k2r
Submitted June 14, 2023 at 10:14PM by SCI_Rusher
via reddit https://ift.tt/eV0x4nB
https://ift.tt/Bmi0k2r
Submitted June 14, 2023 at 10:14PM by SCI_Rusher
via reddit https://ift.tt/eV0x4nB
Microsoft News
Cadet Blizzard emerges as a novel and distinct Russian threat actor
Microsoft shares new details about techniques of a distinct Russian state-sponsored threat actor, now elevated to the name Cadet Blizzard.
Hardware Hacking to Bypass BIOS Passwords
https://ift.tt/aQTtzSX
Submitted June 15, 2023 at 01:38PM by CptWin_NZ
via reddit https://ift.tt/uqfazAP
https://ift.tt/aQTtzSX
Submitted June 15, 2023 at 01:38PM by CptWin_NZ
via reddit https://ift.tt/uqfazAP
CyberCX
Hardware Hacking to Bypass BIOS Passwords
A beginners hardware hacking journey of performing a BIOS password bypass on Lenovo laptops. In this article we identify what the problem is, how to identify a vulnerable chip, how to bypass a vulnerable chip, and finally identify why this attack works and…
Reverse Engineering Terminator aka Zemana AntiMalware Driver to achieve LPE - VoidSec
https://ift.tt/dReNHGk
Submitted June 15, 2023 at 09:08PM by Void_Sec
via reddit https://ift.tt/XQ74C1S
https://ift.tt/dReNHGk
Submitted June 15, 2023 at 09:08PM by Void_Sec
via reddit https://ift.tt/XQ74C1S
VoidSec
Reverse Engineering Terminator aka Zemana AntiMalware/AntiLogger Driver - VoidSec
Reverse engineering Spybot's Terminator tool (Zemana Antimalware driver) to achieve LPE as SYSTEM and unrestricted raw SCSI disk read/write.
Freaky Leaky SMS: Extracting User Locations by Analyzing SMS Timings
https://ift.tt/Fl2Nk1j
Submitted June 15, 2023 at 11:18PM by nangaparbat
via reddit https://ift.tt/uHi2Dtv
https://ift.tt/Fl2Nk1j
Submitted June 15, 2023 at 11:18PM by nangaparbat
via reddit https://ift.tt/uHi2Dtv
Serious vulnerabilities found in Georgia's Dominion ImageCast X ballot marking devices
https://ift.tt/2Ees8bO
Submitted June 16, 2023 at 03:33AM by magenta_placenta
via reddit https://ift.tt/qwLjAfN
https://ift.tt/2Ees8bO
Submitted June 16, 2023 at 03:33AM by magenta_placenta
via reddit https://ift.tt/qwLjAfN
June 1st CA/Browser Forum Code Signing Requirements Require the use of an HSM
https://ift.tt/diQIeXE
Submitted June 16, 2023 at 09:38AM by marklarledu
via reddit https://ift.tt/YAb87pm
https://ift.tt/diQIeXE
Submitted June 16, 2023 at 09:38AM by marklarledu
via reddit https://ift.tt/YAb87pm
Garantir
View the New CA/Browser Forum Code Signing Requirements Now
New in 2023, in order to satisfy the CA, you must use a hardware security module (HSM) to protect your code signing private keys.
End game: Why InfoSec Must Stop Playing Cat & Mouse
https://ift.tt/MUk8y36
Submitted June 16, 2023 at 10:46AM by One-Fan7214
via reddit https://ift.tt/WJv3GDA
https://ift.tt/MUk8y36
Submitted June 16, 2023 at 10:46AM by One-Fan7214
via reddit https://ift.tt/WJv3GDA
Memcyco
End game:Why InfoSec Must Stop Playing Cat & Mouse | Memcyco
As cyber attacks become more diverse in exploiting technical and psychological weaknesses, playing cat and mouse is no longer viable.
vault1317 FAQ: cryptographic deniability for decentralized approach via federation (XMPP) and relay (Nostr)
https://ift.tt/ogTjr6h
Submitted June 16, 2023 at 01:34PM by hardenedvault
via reddit https://ift.tt/yRO9mp5
https://ift.tt/ogTjr6h
Submitted June 16, 2023 at 01:34PM by hardenedvault
via reddit https://ift.tt/yRO9mp5
GitHub
vault1317/README.md at master · hardenedvault/vault1317
Off-chain secure communication protocol with Zero-knowledge proof (Ring Signature) and metadata protection. - hardenedvault/vault1317
MobSecco: Clone Cordova Android application for bypassing security restrictions.
https://ift.tt/ADen6SF
Submitted June 16, 2023 at 04:41PM by Ano_F
via reddit https://ift.tt/gcejOWl
https://ift.tt/ADen6SF
Submitted June 16, 2023 at 04:41PM by Ano_F
via reddit https://ift.tt/gcejOWl
GitHub
GitHub - Anof-cyber/MobSecco: Cloning apk for bypassing code tampering detection, Google Safety Net and scanning vulnerable plugins
Cloning apk for bypassing code tampering detection, Google Safety Net and scanning vulnerable plugins - GitHub - Anof-cyber/MobSecco: Cloning apk for bypassing code tampering detection, Google Saf...
Step by Step Security Tools and Setups for Small and Medium Sized Companies
https://ift.tt/OsAherk
Submitted June 16, 2023 at 04:32PM by windfisher
via reddit https://ift.tt/L0uvx3n
https://ift.tt/OsAherk
Submitted June 16, 2023 at 04:32PM by windfisher
via reddit https://ift.tt/L0uvx3n
Recently, I have undertaken thorough research on Cordova mobile apps, focusing on the replication of such apps by utilizing APK source code. This process allows for bypassing security checks such as Code Tampering detection or Google Safenynet.
https://ift.tt/wZB7YAy
Submitted June 16, 2023 at 05:28PM by Ano_F
via reddit https://ift.tt/t3xw7XG
https://ift.tt/wZB7YAy
Submitted June 16, 2023 at 05:28PM by Ano_F
via reddit https://ift.tt/t3xw7XG
Medium
Recreating Cordova Mobile Apps to Bypass Security Implementations
Cloning Cordova Mobile Apps to Bypass Security Implementations
Decompiler for LLDB, a RetDec plugin by @ant4g0nist
https://ift.tt/rMYmoQt
Submitted June 16, 2023 at 06:09PM by ant4g0nist
via reddit https://ift.tt/VzZdE6l
https://ift.tt/rMYmoQt
Submitted June 16, 2023 at 06:09PM by ant4g0nist
via reddit https://ift.tt/VzZdE6l
GitHub
GitHub - ant4g0nist/decompiler: RetDec plugin for LLDB. RetDec is a retargetable machine-code decompiler based on LLVM.
RetDec plugin for LLDB. RetDec is a retargetable machine-code decompiler based on LLVM. - ant4g0nist/decompiler
Mimecast Partners with StellarCyber to Combat Phishing Attack Security
https://ift.tt/AMJEnIH
Submitted June 16, 2023 at 07:13PM by Ok_Lavishness_9618
via reddit https://ift.tt/SdA8rY6
https://ift.tt/AMJEnIH
Submitted June 16, 2023 at 07:13PM by Ok_Lavishness_9618
via reddit https://ift.tt/SdA8rY6
MSSP Alert
Stellar Cyber, Mimecast Partnership Delivers Phishing Attack Security -
Stellar Cyber and Mimecast have announced an integration designed to help organizations protect against email-based attacks.
I want to create an exact replica of my laptop
https://google.com
Submitted June 16, 2023 at 10:34PM by _discEx_
via reddit https://ift.tt/13bSnUs
https://google.com
Submitted June 16, 2023 at 10:34PM by _discEx_
via reddit https://ift.tt/13bSnUs
Reddit
From the netsec community on Reddit: I want to create an exact replica of my laptop
Posted by _discEx_ - 0 votes and 3 comments
harbian-audit v0.7 releases: security audit and hardening for Debian 12
https://ift.tt/C1VLPqh
Submitted June 17, 2023 at 04:35PM by hardenedvault
via reddit https://ift.tt/tE3qnHj
https://ift.tt/C1VLPqh
Submitted June 17, 2023 at 04:35PM by hardenedvault
via reddit https://ift.tt/tE3qnHj
GitHub
Release harbian-audit-V0.7.0 · hardenedlinux/harbian-audit
HardenedLinux community: harbian-audit v0.7.0 complianced for Debian GNU/Linux 12.
Reverse Engineering: iOS App Extraction & Analysis
https://ift.tt/VjUI10L
Submitted June 17, 2023 at 08:31PM by theappanalyst
via reddit https://ift.tt/w9gAiLC
https://ift.tt/VjUI10L
Submitted June 17, 2023 at 08:31PM by theappanalyst
via reddit https://ift.tt/w9gAiLC
/data/local/tmp
Ios App Extraction & Analysis
There are many reasons you may want to extract iOS applications; one in particular is reviewing security and privacy aspects with an analysis tool such as Ghidra. Unfortunately, unlike .apk files for Android, .ipa files cannot be side-loaded very easily;…
CISA SBOM standards efforts stymied by confusion, inertia | TechTarget
https://ift.tt/NXeODvU
Submitted June 18, 2023 at 12:41AM by dlorenc
via reddit https://ift.tt/kxySObo
https://ift.tt/NXeODvU
Submitted June 18, 2023 at 12:41AM by dlorenc
via reddit https://ift.tt/kxySObo
IT Operations
CISA SBOM standards efforts stymied by confusion, inertia
The threat of software supply chain attacks is accelerating, but CISA SBOM guidance efforts aren't matching its pace, according to industry experts.
MOVEit SQLi vulnerability used in recent Louisiana DMV attack.
https://ift.tt/7J932w4
Submitted June 18, 2023 at 12:26AM by Beard_o_Bees
via reddit https://ift.tt/ba6GeC9
https://ift.tt/7J932w4
Submitted June 18, 2023 at 12:26AM by Beard_o_Bees
via reddit https://ift.tt/ba6GeC9
Progress
MOVEit Transfer Critical Vulnerability – CVE-2023-35036 (June 9, 2023) - Progress Community
SQL Injection (CVE-2023-35036)
In Progress MOVEit Transfer versions released before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), 2023.0.2 (15.0.2), multiple SQL injection vulnerabilities have been identified in the MOVEit…
In Progress MOVEit Transfer versions released before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), 2023.0.2 (15.0.2), multiple SQL injection vulnerabilities have been identified in the MOVEit…
Explainer: Dominion vulnerabilities reported by Halderman
https://ift.tt/ya7bdCB
Submitted June 18, 2023 at 06:00AM by SameCookiePseudonym
via reddit https://ift.tt/CGdogS7
https://ift.tt/ya7bdCB
Submitted June 18, 2023 at 06:00AM by SameCookiePseudonym
via reddit https://ift.tt/CGdogS7
Cybersect
Explainer: Dominion vulns reported by Halderman
Dominion Voting Systems is the famous voting machine vendor that’s been at the center of Trump’s 2020 election denial, used in such swing states as Georgia and Arizona. Fox News paid $700 million to settle a defamation lawsuit, over claims that Dominion machines…