Clop Ransomware: History, Timeline, And Adversary Simulation
https://ift.tt/TjSoxbQ
Submitted July 05, 2023 at 01:49PM by achilles4828
via reddit https://ift.tt/cHm1Wai
https://ift.tt/TjSoxbQ
Submitted July 05, 2023 at 01:49PM by achilles4828
via reddit https://ift.tt/cHm1Wai
FourCore
Clop Ransomware: History, Timeline, And Adversary Simulation - FourCore
The infamous Clop ransomware, mainly known as Cl0p, targets various industries and organizations, extorting data for a huge amount of ransom. It advances actively with new emerging campaigns. This blog walks through the Clop timeline, Mitre TTPs and their…
Extending Burp Suite for fun and profit - The Montoya way - Part 1
https://ift.tt/ScFONoQ
Submitted July 05, 2023 at 03:29PM by 0xdea
via reddit https://ift.tt/kT42Kbr
https://ift.tt/ScFONoQ
Submitted July 05, 2023 at 03:29PM by 0xdea
via reddit https://ift.tt/kT42Kbr
hn security
Extending Burp Suite for fun and profit - The Montoya way - Part 1 - hn security
-> Setting up the environment + […]
Actively Exploited ICS Hardware: SolarView Series
https://ift.tt/AuWQgsr
Submitted July 05, 2023 at 02:57PM by chicksdigthelongrun
via reddit https://ift.tt/IWa2T0F
https://ift.tt/AuWQgsr
Submitted July 05, 2023 at 02:57PM by chicksdigthelongrun
via reddit https://ift.tt/IWa2T0F
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Cloud Defense in Depth: Lessons from the Kinsing Malware – Sysdig
https://ift.tt/hqlEiCY
Submitted July 05, 2023 at 08:25PM by Hallow_Rose
via reddit https://ift.tt/D8Ete3g
https://ift.tt/hqlEiCY
Submitted July 05, 2023 at 08:25PM by Hallow_Rose
via reddit https://ift.tt/D8Ete3g
Sysdig
Cloud Defense in Depth: Lessons from the Kinsing Malware
Organizations should prioritize cloud defense in depth. With a strong security plan, you can lay a foundation for a secure cloud environment.
StackRot (CVE-2023-3269): Linux kernel privilege escalation vulnerability
https://ift.tt/rhSCQtN
Submitted July 05, 2023 at 08:05PM by poltess0
via reddit https://ift.tt/GoBjniH
https://ift.tt/rhSCQtN
Submitted July 05, 2023 at 08:05PM by poltess0
via reddit https://ift.tt/GoBjniH
Backdooring NPM Modules via Hijacking S3 Buckets
https://ift.tt/BqekAXI
Submitted July 06, 2023 at 09:53AM by clintgibler
via reddit https://ift.tt/F51XeU7
https://ift.tt/BqekAXI
Submitted July 06, 2023 at 09:53AM by clintgibler
via reddit https://ift.tt/F51XeU7
Checkmarx
Hijacking S3 Buckets: New Attack Technique
Without altering a single line of code, attackers poisoned the NPM package bignum by hijacking the S3 bucket serving binaries necessary for its function and replacing them with malicious ones
Two Stories for "What is CHERI?"
https://ift.tt/fcE7V4t
Submitted July 06, 2023 at 02:41PM by Xadartt
via reddit https://ift.tt/5I3k8rJ
https://ift.tt/fcE7V4t
Submitted July 06, 2023 at 02:41PM by Xadartt
via reddit https://ift.tt/5I3k8rJ
Mobile Application Hacking: Flutter Restrictions Bypass
https://ift.tt/fCb6lSz
Submitted July 06, 2023 at 03:04PM by CptWin_NZ
via reddit https://ift.tt/1GiKTzS
https://ift.tt/fCb6lSz
Submitted July 06, 2023 at 03:04PM by CptWin_NZ
via reddit https://ift.tt/1GiKTzS
CyberCX
Flutter Restrictions Bypass
This Technical Series blog investigates the Flutter framework (Google, n.d.) and the methods for bypassing its detections on iOS.
Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)
https://ift.tt/IktE3ao
Submitted July 06, 2023 at 07:46PM by AlmondOffSec
via reddit https://ift.tt/jLUiyuQ
https://ift.tt/IktE3ao
Submitted July 06, 2023 at 07:46PM by AlmondOffSec
via reddit https://ift.tt/jLUiyuQ
The five-day job: A BlackByte ransomware intrusion case study
https://ift.tt/smORhv3
Submitted July 06, 2023 at 10:42PM by SCI_Rusher
via reddit https://ift.tt/D8HXjQy
https://ift.tt/smORhv3
Submitted July 06, 2023 at 10:42PM by SCI_Rusher
via reddit https://ift.tt/D8HXjQy
Microsoft Security Blog
The five-day job: A BlackByte ransomware intrusion case study | Microsoft Security Blog
Microsoft IR investigation of a BlackByte 2.0 ransomware attack progressed thru full attack chain from initial access to impact in five days.
Check the safety of a URL without clicking it or copy&paste to the checker box
https://ift.tt/0rQCEnw
Submitted July 07, 2023 at 01:44PM by Active-Pianist-6389
via reddit https://ift.tt/gIXVo9f
https://ift.tt/0rQCEnw
Submitted July 07, 2023 at 01:44PM by Active-Pianist-6389
via reddit https://ift.tt/gIXVo9f
mmntm.me
URL Auto-scanner — Stay ahead of online threats with Auto URL Scanner.
No click or copy&paste required
Introducing Slinky Cat - Living off the AD Land
https://ift.tt/AXjR3ag
Submitted July 07, 2023 at 02:13PM by ZephrX112
via reddit https://ift.tt/i3lVBIf
https://ift.tt/AXjR3ag
Submitted July 07, 2023 at 02:13PM by ZephrX112
via reddit https://ift.tt/i3lVBIf
Lares Labs
Introducing Slinky Cat - Living off the AD Land
Slinky Cat has been developed to automate some of the methods introduced in living off the land and to supplement ScrapingKit. To help security and IT teams reduce their AD exposures and uncover quick wins and fixes designed for pen-testers and defenders…
Prompt Injection: How to Prevent It or Should We Prevent It?
https://ift.tt/hACy9jQ
Submitted July 06, 2023 at 07:13PM by utku1337
via reddit https://ift.tt/CU5n3Nk
https://ift.tt/hACy9jQ
Submitted July 06, 2023 at 07:13PM by utku1337
via reddit https://ift.tt/CU5n3Nk
Medium
Prompt Injection: How to Prevent It or Should We Prevent It?
As a traditional application security engineer, I’m trying to adapt myself to the AI mayhem. This post covers my thoughts about prompt…
A Journey Into Hacking Google Search Appliance | DEVCORE
https://ift.tt/lqunFmI
Submitted July 07, 2023 at 10:14PM by poltess0
via reddit https://ift.tt/Mf76t8Y
https://ift.tt/lqunFmI
Submitted July 07, 2023 at 10:14PM by poltess0
via reddit https://ift.tt/Mf76t8Y
DEVCORE 戴夫寇爾
[REL] A Journey Into Hacking Google Search Appliance | DEVCORE 戴夫寇爾
The Google Search Appliance (hereinafter referred to as GSA) is an enterprise search device launched by Google in 2002, used for indexing and retrieving internal or public network information
Pentest Mapper Burp Suite extension 1.7 is released.
https://ift.tt/xjlsmMC
Submitted July 08, 2023 at 08:09PM by Ano_F
via reddit https://ift.tt/KJhjEFp
https://ift.tt/xjlsmMC
Submitted July 08, 2023 at 08:09PM by Ano_F
via reddit https://ift.tt/KJhjEFp
GitHub
GitHub - Anof-cyber/Pentest-Mapper: A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows…
A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabilities - GitHub - Anof-cyber/Pentest-Mapper: A Burp Suite Exten...
EasyScan: A Lightweight Web Vulnerability Scanner to Secure Your Website
https://ift.tt/u9cnlx3
Submitted July 09, 2023 at 02:56AM by lazykid07
via reddit https://ift.tt/ZbMfgUj
https://ift.tt/u9cnlx3
Submitted July 09, 2023 at 02:56AM by lazykid07
via reddit https://ift.tt/ZbMfgUj
GitHub
GitHub - introvertmac/EasyScan: Light-weight web security scanner
Light-weight web security scanner. Contribute to introvertmac/EasyScan development by creating an account on GitHub.
Evilgophish Evilginx 3.0.0 Update
https://ift.tt/Mt6IAcl
Submitted July 09, 2023 at 09:24AM by edreatingmonkey
via reddit https://ift.tt/AoKCrNw
https://ift.tt/Mt6IAcl
Submitted July 09, 2023 at 09:24AM by edreatingmonkey
via reddit https://ift.tt/AoKCrNw
GitHub
evilginx3 update · fin3ss3g0d/evilgophish@9d5af2f
evilginx3 + gophish. Contribute to fin3ss3g0d/evilgophish development by creating an account on GitHub.
EdgeRouters's & AirCube's vulnerability allows LAN attackers to cause the service to overflow an internal heap and potentially execute arbitrary code
https://ift.tt/QeJkgZ4
Submitted July 09, 2023 at 01:50PM by SSDisclosure
via reddit https://ift.tt/rEBFXWH
https://ift.tt/QeJkgZ4
Submitted July 09, 2023 at 01:50PM by SSDisclosure
via reddit https://ift.tt/rEBFXWH
SSD Secure Disclosure
SSD Advisory - EdgeRouters and AirCube miniupnpd Heap Overflow - SSD Secure Disclosure
Summary A vulnerability in EdgeRouters’s and AirCube’s miniupnpd allows LAN attackers to cause the service to overflow an internal heap and potentially execute arbitrary code. Credit An independent security researcher working with SSD Secure Disclosure. CVE…
+Protecting Linux at Kernel Level Why and How
https://ift.tt/8zoVN4F
Submitted July 10, 2023 at 09:03AM by hardenedvault
via reddit https://ift.tt/FSavVDu
https://ift.tt/8zoVN4F
Submitted July 10, 2023 at 09:03AM by hardenedvault
via reddit https://ift.tt/FSavVDu
hardenedvault.net
+PROTECTING LINUX AT KERNEL LEVEL WHY AND HOW
Introduction We designed Vault Exploits Defense (VED) as a foundation security layer for various flavors of Linux operating system.
CloudPrivs - Brute force tool to determine AWS permissions from credentials
https://ift.tt/KjFHlLY
Submitted July 10, 2023 at 10:37AM by ROFLicious
via reddit https://ift.tt/v3Sa1BK
https://ift.tt/KjFHlLY
Submitted July 10, 2023 at 10:37AM by ROFLicious
via reddit https://ift.tt/v3Sa1BK
GitHub
GitHub - AbstractClass/CloudPrivs: Determine privileges from cloud credentials via brute-force testing.
Determine privileges from cloud credentials via brute-force testing. - AbstractClass/CloudPrivs
Delegate call bug in the ink! programming language
https://ift.tt/vioHd34
Submitted July 10, 2023 at 04:48PM by kruksym
via reddit https://ift.tt/GFigDQl
https://ift.tt/vioHd34
Submitted July 10, 2023 at 04:48PM by kruksym
via reddit https://ift.tt/GFigDQl
CoinFabrik
Delegate call bug in ink!
ink! is a programming language for smart contracts. It can be used in parachains built on Substrate. There was a bug in the CallBuilder::delegate() method and ink_env::invoke_contract_delegate() function which returns unexpected values.