Use Case of ASM for Vulnerability Detection
https://ift.tt/eQP24iN
Submitted July 04, 2023 at 11:23AM by talentSA112200
via reddit https://ift.tt/a2NxTJY
https://ift.tt/eQP24iN
Submitted July 04, 2023 at 11:23AM by talentSA112200
via reddit https://ift.tt/a2NxTJY
CIP Blog
Vulnerability Detection Using Attack Surface Management: Criminal IP ASM Use Case (1) | CIP Blog
Attack Surface Management (ASM) is the proactive practice of identifying and managing the potential attack surface of an organization's IT assets to prevent and mitigate potential attacks by hackers. It is essential to minimize the exposure of valuable assets…
A reminder to test the CVSS 4.0 while it matters!
https://ift.tt/dkemG2H
Submitted July 04, 2023 at 12:41PM by forgetful_12345
via reddit https://ift.tt/Kmj7VqN
https://ift.tt/dkemG2H
Submitted July 04, 2023 at 12:41PM by forgetful_12345
via reddit https://ift.tt/Kmj7VqN
FIRST — Forum of Incident Response and Security Teams
Common Vulnerability Scoring System Version 4.0 Calculator
A reminder to test the CVSS 4.0 calculator while it matters.
https://ift.tt/dkemG2H
Submitted July 04, 2023 at 12:59PM by forgetful_12345
via reddit https://ift.tt/a9ptJ38
https://ift.tt/dkemG2H
Submitted July 04, 2023 at 12:59PM by forgetful_12345
via reddit https://ift.tt/a9ptJ38
FIRST — Forum of Incident Response and Security Teams
Common Vulnerability Scoring System Version 4.0 Calculator
[CVE-2022-43684] - Insecure Access Control to Full Administrator Takeover in ServiceNow Instances
https://ift.tt/m3I8PEK
Submitted July 04, 2023 at 12:01PM by Rezk0n_
via reddit https://ift.tt/hwBejrZ
https://ift.tt/m3I8PEK
Submitted July 04, 2023 at 12:01PM by Rezk0n_
via reddit https://ift.tt/hwBejrZ
R3zk0n
ServiceNow Insecure Access Control To Full Admin Takeover
ServiceNow Insecure Access Control leading to Administrator Account Takeover - CVE-2022-43684
Extracting Bitwarden master passwords after a vault is locked
https://ift.tt/S6flcNq
Submitted July 04, 2023 at 02:36PM by markuta
via reddit https://ift.tt/wEnHriq
https://ift.tt/S6flcNq
Submitted July 04, 2023 at 02:36PM by markuta
via reddit https://ift.tt/wEnHriq
Hexiosec
Hunting for Bitwarden master passwords stored in memory | Hexiosec Blogs
We discovered a vulnerability in the Bitwarden desktop app that exposed master passwords in the memory after a vault had been locked.
Hacking Back Infrastructure Used in Facebook Phishing Attack Chain
https://ift.tt/zKODegc
Submitted July 04, 2023 at 02:45PM by zdl007
via reddit https://ift.tt/ceO0hTN
https://ift.tt/zKODegc
Submitted July 04, 2023 at 02:45PM by zdl007
via reddit https://ift.tt/ceO0hTN
Zeroday.PRO
Hacking Back Infrastructure Used in Facebook Phishing Attack Chain
Our team of security experts will provide an exclusive glimpse into the phishing emails used in Facebook Phishing Campaign.
Hunting for Nginx Alias Traversals in the wild
https://ift.tt/G69k5hX
Submitted July 04, 2023 at 03:59PM by albinowax
via reddit https://ift.tt/sbOvloz
https://ift.tt/G69k5hX
Submitted July 04, 2023 at 03:59PM by albinowax
via reddit https://ift.tt/sbOvloz
Hakai
Vulnerability Research
Clop Ransomware and MoveIT CVE: Ransomware: History, Timeline, And Adversary Simulation - FourCore
https://ift.tt/RPZ5OAU
Submitted July 05, 2023 at 01:48AM by achilles4828
via reddit https://ift.tt/zCj0M4x
https://ift.tt/RPZ5OAU
Submitted July 05, 2023 at 01:48AM by achilles4828
via reddit https://ift.tt/zCj0M4x
Clop Ransomware: History, Timeline, And Adversary Simulation
https://ift.tt/TjSoxbQ
Submitted July 05, 2023 at 01:49PM by achilles4828
via reddit https://ift.tt/cHm1Wai
https://ift.tt/TjSoxbQ
Submitted July 05, 2023 at 01:49PM by achilles4828
via reddit https://ift.tt/cHm1Wai
FourCore
Clop Ransomware: History, Timeline, And Adversary Simulation - FourCore
The infamous Clop ransomware, mainly known as Cl0p, targets various industries and organizations, extorting data for a huge amount of ransom. It advances actively with new emerging campaigns. This blog walks through the Clop timeline, Mitre TTPs and their…
Extending Burp Suite for fun and profit - The Montoya way - Part 1
https://ift.tt/ScFONoQ
Submitted July 05, 2023 at 03:29PM by 0xdea
via reddit https://ift.tt/kT42Kbr
https://ift.tt/ScFONoQ
Submitted July 05, 2023 at 03:29PM by 0xdea
via reddit https://ift.tt/kT42Kbr
hn security
Extending Burp Suite for fun and profit - The Montoya way - Part 1 - hn security
-> Setting up the environment + […]
Actively Exploited ICS Hardware: SolarView Series
https://ift.tt/AuWQgsr
Submitted July 05, 2023 at 02:57PM by chicksdigthelongrun
via reddit https://ift.tt/IWa2T0F
https://ift.tt/AuWQgsr
Submitted July 05, 2023 at 02:57PM by chicksdigthelongrun
via reddit https://ift.tt/IWa2T0F
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Cloud Defense in Depth: Lessons from the Kinsing Malware – Sysdig
https://ift.tt/hqlEiCY
Submitted July 05, 2023 at 08:25PM by Hallow_Rose
via reddit https://ift.tt/D8Ete3g
https://ift.tt/hqlEiCY
Submitted July 05, 2023 at 08:25PM by Hallow_Rose
via reddit https://ift.tt/D8Ete3g
Sysdig
Cloud Defense in Depth: Lessons from the Kinsing Malware
Organizations should prioritize cloud defense in depth. With a strong security plan, you can lay a foundation for a secure cloud environment.
StackRot (CVE-2023-3269): Linux kernel privilege escalation vulnerability
https://ift.tt/rhSCQtN
Submitted July 05, 2023 at 08:05PM by poltess0
via reddit https://ift.tt/GoBjniH
https://ift.tt/rhSCQtN
Submitted July 05, 2023 at 08:05PM by poltess0
via reddit https://ift.tt/GoBjniH
Backdooring NPM Modules via Hijacking S3 Buckets
https://ift.tt/BqekAXI
Submitted July 06, 2023 at 09:53AM by clintgibler
via reddit https://ift.tt/F51XeU7
https://ift.tt/BqekAXI
Submitted July 06, 2023 at 09:53AM by clintgibler
via reddit https://ift.tt/F51XeU7
Checkmarx
Hijacking S3 Buckets: New Attack Technique
Without altering a single line of code, attackers poisoned the NPM package bignum by hijacking the S3 bucket serving binaries necessary for its function and replacing them with malicious ones
Two Stories for "What is CHERI?"
https://ift.tt/fcE7V4t
Submitted July 06, 2023 at 02:41PM by Xadartt
via reddit https://ift.tt/5I3k8rJ
https://ift.tt/fcE7V4t
Submitted July 06, 2023 at 02:41PM by Xadartt
via reddit https://ift.tt/5I3k8rJ
Mobile Application Hacking: Flutter Restrictions Bypass
https://ift.tt/fCb6lSz
Submitted July 06, 2023 at 03:04PM by CptWin_NZ
via reddit https://ift.tt/1GiKTzS
https://ift.tt/fCb6lSz
Submitted July 06, 2023 at 03:04PM by CptWin_NZ
via reddit https://ift.tt/1GiKTzS
CyberCX
Flutter Restrictions Bypass
This Technical Series blog investigates the Flutter framework (Google, n.d.) and the methods for bypassing its detections on iOS.
Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)
https://ift.tt/IktE3ao
Submitted July 06, 2023 at 07:46PM by AlmondOffSec
via reddit https://ift.tt/jLUiyuQ
https://ift.tt/IktE3ao
Submitted July 06, 2023 at 07:46PM by AlmondOffSec
via reddit https://ift.tt/jLUiyuQ
The five-day job: A BlackByte ransomware intrusion case study
https://ift.tt/smORhv3
Submitted July 06, 2023 at 10:42PM by SCI_Rusher
via reddit https://ift.tt/D8HXjQy
https://ift.tt/smORhv3
Submitted July 06, 2023 at 10:42PM by SCI_Rusher
via reddit https://ift.tt/D8HXjQy
Microsoft Security Blog
The five-day job: A BlackByte ransomware intrusion case study | Microsoft Security Blog
Microsoft IR investigation of a BlackByte 2.0 ransomware attack progressed thru full attack chain from initial access to impact in five days.
Check the safety of a URL without clicking it or copy&paste to the checker box
https://ift.tt/0rQCEnw
Submitted July 07, 2023 at 01:44PM by Active-Pianist-6389
via reddit https://ift.tt/gIXVo9f
https://ift.tt/0rQCEnw
Submitted July 07, 2023 at 01:44PM by Active-Pianist-6389
via reddit https://ift.tt/gIXVo9f
mmntm.me
URL Auto-scanner — Stay ahead of online threats with Auto URL Scanner.
No click or copy&paste required
Introducing Slinky Cat - Living off the AD Land
https://ift.tt/AXjR3ag
Submitted July 07, 2023 at 02:13PM by ZephrX112
via reddit https://ift.tt/i3lVBIf
https://ift.tt/AXjR3ag
Submitted July 07, 2023 at 02:13PM by ZephrX112
via reddit https://ift.tt/i3lVBIf
Lares Labs
Introducing Slinky Cat - Living off the AD Land
Slinky Cat has been developed to automate some of the methods introduced in living off the land and to supplement ScrapingKit. To help security and IT teams reduce their AD exposures and uncover quick wins and fixes designed for pen-testers and defenders…
Prompt Injection: How to Prevent It or Should We Prevent It?
https://ift.tt/hACy9jQ
Submitted July 06, 2023 at 07:13PM by utku1337
via reddit https://ift.tt/CU5n3Nk
https://ift.tt/hACy9jQ
Submitted July 06, 2023 at 07:13PM by utku1337
via reddit https://ift.tt/CU5n3Nk
Medium
Prompt Injection: How to Prevent It or Should We Prevent It?
As a traditional application security engineer, I’m trying to adapt myself to the AI mayhem. This post covers my thoughts about prompt…