Persistence via Shell Extensions
https://ift.tt/leBWEwq
Submitted July 25, 2023 at 12:02AM by NecessaryDark3283
via reddit https://ift.tt/tHzp25s
https://ift.tt/leBWEwq
Submitted July 25, 2023 at 12:02AM by NecessaryDark3283
via reddit https://ift.tt/tHzp25s
GitHub
GitHub - aahmad097/Test004: Persistence via Shell Extensions
Persistence via Shell Extensions. Contribute to aahmad097/Test004 development by creating an account on GitHub.
EchoCLI: A tethered root solution for the Amazon Echo Dot 2nd generation
https://ift.tt/FVaJq4u
Submitted July 25, 2023 at 01:59AM by Titokhan
via reddit https://ift.tt/OhQIpln
https://ift.tt/FVaJq4u
Submitted July 25, 2023 at 01:59AM by Titokhan
via reddit https://ift.tt/OhQIpln
dragon863.github.io
Dragon863 - Rooting the Amazon Echo Dot
Gaining a temporary root on the Amazon echo dot 2nd generation.
CVE-2023-35086 POC - ASUS routers format string vulnerability
https://ift.tt/9PSzfsX
Submitted July 25, 2023 at 07:13AM by NoPaleontologist7419
via reddit https://ift.tt/Z4BXzOL
https://ift.tt/9PSzfsX
Submitted July 25, 2023 at 07:13AM by NoPaleontologist7419
via reddit https://ift.tt/Z4BXzOL
GitHub
GitHub - tin-z/CVE-2023-35086-POC: POC of CVE-2023-35086 only DoS
POC of CVE-2023-35086 only DoS. Contribute to tin-z/CVE-2023-35086-POC development by creating an account on GitHub.
Introduction to Cross-Site Leaks (XS-Leaks) – Attacks and Mitigations
https://ift.tt/3P9Hu2w
Submitted July 25, 2023 at 02:13PM by CptWin_NZ
via reddit https://ift.tt/E2DvU16
https://ift.tt/3P9Hu2w
Submitted July 25, 2023 at 02:13PM by CptWin_NZ
via reddit https://ift.tt/E2DvU16
New release of EMBA version 1.3.0 is now available. AI-Assisted firmware analysis is now integrated into the fully automated Open-Source firmware security analyzer EMBA.
https://ift.tt/cZpAPB6
Submitted July 25, 2023 at 04:36PM by _m-1-k-3_
via reddit https://ift.tt/Mmdw92v
https://ift.tt/cZpAPB6
Submitted July 25, 2023 at 04:36PM by _m-1-k-3_
via reddit https://ift.tt/Mmdw92v
GitHub
Release EMBA v1.3.0 - AI-Assisted Firmware Analysis · e-m-b-a/emba
Q: Can we use AI for firmware analysis?
A: Sure, let's do it! EMBA now supports AI-assisted firmware analysis.
Again, we rise the bar in the field of Open-Source firmware security analysis. ...
A: Sure, let's do it! EMBA now supports AI-assisted firmware analysis.
Again, we rise the bar in the field of Open-Source firmware security analysis. ...
Exploiting MikroTik RouterOS Hardware
https://ift.tt/QxGqFAg
Submitted July 25, 2023 at 04:41PM by chicksdigthelongrun
via reddit https://ift.tt/fJA0PxL
https://ift.tt/QxGqFAg
Submitted July 25, 2023 at 04:41PM by chicksdigthelongrun
via reddit https://ift.tt/fJA0PxL
VulnCheck
Exploiting MikroTik RouterOS Hardware with CVE-2023-30799 - Blog - VulnCheck
VulnCheck develops an exploit that gets a root shell on MikroTik RouterOS.
Zenbleed Vulnerability Affects AMD Zen2 Processors, Sensitive Data at Risk
https://ift.tt/tTa70NU
Submitted July 25, 2023 at 10:36PM by KindooGaming
via reddit https://ift.tt/jh3gHTw
https://ift.tt/tTa70NU
Submitted July 25, 2023 at 10:36PM by KindooGaming
via reddit https://ift.tt/jh3gHTw
RFC 9420: The Messaging Layer Security (MLS) Protocol
https://ift.tt/bFJDM5k
Submitted July 26, 2023 at 12:19AM by moofali
via reddit https://ift.tt/zvKI5XY
https://ift.tt/bFJDM5k
Submitted July 26, 2023 at 12:19AM by moofali
via reddit https://ift.tt/zvKI5XY
IETF Datatracker
RFC 9420: The Messaging Layer Security (MLS) Protocol
Messaging applications are increasingly making use of end-to-end security mechanisms to ensure that messages are only accessible to the communicating endpoints, and not to any servers involved in delivering messages. Establishing keys to provide such protections…
Critical Vulnerabilities Discovered in Global TETRA Communication Standard Used by Law Enforcement and Critical Infrastructure
https://ift.tt/wNCGAZd
Submitted July 25, 2023 at 11:44PM by Errol_dont_care
via reddit https://ift.tt/RhVEvGN
https://ift.tt/wNCGAZd
Submitted July 25, 2023 at 11:44PM by Errol_dont_care
via reddit https://ift.tt/RhVEvGN
The Black Box of GitHub Leaks: Analyzing Companies' GitHub Repos
https://ift.tt/LFmICtv
Submitted July 26, 2023 at 12:57AM by bartukilic
via reddit https://ift.tt/CvFdK6h
https://ift.tt/LFmICtv
Submitted July 26, 2023 at 12:57AM by bartukilic
via reddit https://ift.tt/CvFdK6h
SOCRadar® Cyber Intelligence Inc.
The Black Box of GitHub Leaks: Analyzing Companies' GitHub Repos - SOCRadar® Cyber Intelligence Inc.
This research aimed to investigate the files that companies might have accidentally uploaded to GitHub and identify any sensitive information that could be
This minuscule 4 KB file can allow an attacker to take over your Windows system
https://ift.tt/uMs8t1H
Submitted July 26, 2023 at 01:22PM by ElectricalResource29
via reddit https://ift.tt/kG5uXKe
https://ift.tt/uMs8t1H
Submitted July 26, 2023 at 01:22PM by ElectricalResource29
via reddit https://ift.tt/kG5uXKe
TechKranti
This minuscule 4 KB file can allow an attacker to take over your Windows system
The noscript sounds dramatic, right? Is this clickbait? No, it isn’t. Bear with me while I make my case to justify the noscript. So, what’s this dangerous minuscule file the noscript talks about?
Huawei Theme Manager Arbitrary Code Execution Vulnerability
https://ift.tt/CbHjmR2
Submitted July 26, 2023 at 04:03PM by nibblesec
via reddit https://ift.tt/AKROLEt
https://ift.tt/CbHjmR2
Submitted July 26, 2023 at 04:03PM by nibblesec
via reddit https://ift.tt/AKROLEt
Doyensec
Huawei Theme Manager Arbitrary Code Execution · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Linux kernel rootkit Reptile supports Linux 5.8 for Vault Range
https://ift.tt/ZkrQMiY
Submitted July 26, 2023 at 05:08PM by hardenedvault
via reddit https://ift.tt/Ws2JQGr
https://ift.tt/ZkrQMiY
Submitted July 26, 2023 at 05:08PM by hardenedvault
via reddit https://ift.tt/Ws2JQGr
GitHub
GitHub - hardenedvault/Reptile: LKM Linux rootkit
LKM Linux rootkit. Contribute to hardenedvault/Reptile development by creating an account on GitHub.
AWS WAF Bypass: invalid JSON object and Unicode escape sequences
https://ift.tt/FJlmHTz
Submitted July 26, 2023 at 07:22PM by theMiddleBlue
via reddit https://ift.tt/REGvpfu
https://ift.tt/FJlmHTz
Submitted July 26, 2023 at 07:22PM by theMiddleBlue
via reddit https://ift.tt/REGvpfu
Sicuranext Blog
AWS WAF Bypass: invalid JSON object and unicode escape sequences
In recent times, the security community has been witnessing an increasing number of reports from researchers highlighting various bypass techniques targeting AWS Web Application Firewall¹. These bypasses have brought to light not only the absence of certain…
TETRA:BURST
https://ift.tt/Zl3Bxd6
Submitted July 26, 2023 at 10:03PM by WhooisWhoo
via reddit https://ift.tt/zn2sSBj
https://ift.tt/Zl3Bxd6
Submitted July 26, 2023 at 10:03PM by WhooisWhoo
via reddit https://ift.tt/zn2sSBj
www.midnightblue.nl
TETRA:BURST | Midnight Blue
TETRA:BURST is a collection of five vulnerabilities, two of which are deemed critical, affecting the Terrestrial Trunked Radio (TETRA) standard used globally by law enforcement, military, critical infrastructure, and industrial asset owners in the power,…
SVG Security Risks - not just a scalable graphic
https://ift.tt/5sPJOM1
Submitted July 27, 2023 at 01:00PM by co1nc1dence
via reddit https://ift.tt/Vw2ActC
https://ift.tt/5sPJOM1
Submitted July 27, 2023 at 01:00PM by co1nc1dence
via reddit https://ift.tt/Vw2ActC
www.securesystems.de
SVG Security Risks - not just a scalable graphic
Embedding Scalable Vector Graphics (SVG) can expose websites to code injection. This article explores how SVGs work, the risks they pose, and how to mitigate them.
Total BYOVD Kernel-level protection for Windows using Windows Defender Application Control
https://ift.tt/VC69vXS
Submitted July 27, 2023 at 02:31PM by HotCakeXXXXXXXXXXXXX
via reddit https://ift.tt/9EwqKkG
https://ift.tt/VC69vXS
Submitted July 27, 2023 at 02:31PM by HotCakeXXXXXXXXXXXXX
via reddit https://ift.tt/9EwqKkG
GitHub
WDAC policy for BYOVD Kernel mode only protection
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers...
Tales Of Security Issues In Cryptocurrency Software Wallets
https://ift.tt/kyhmUqP
Submitted July 27, 2023 at 09:06PM by juliocesarfort
via reddit https://ift.tt/id9EeNw
https://ift.tt/kyhmUqP
Submitted July 27, 2023 at 09:06PM by juliocesarfort
via reddit https://ift.tt/id9EeNw
Blaze Information Security
Tales Of Security Issues In Cryptocurrency Software Wallets
This post discusses security concerns and two vulnerabilities in Harmony and oByte, two browser extensions that serves as a cryptocurrency software wallet.
How come Unicode characters leads to the bypass of the security measures? 🔐
https://ift.tt/lNpFWbi
Submitted July 27, 2023 at 11:56PM by Sim4n6
via reddit https://ift.tt/7h15PBT
https://ift.tt/lNpFWbi
Submitted July 27, 2023 at 11:56PM by Sim4n6
via reddit https://ift.tt/7h15PBT
Query Chronicles
Unicode characters to Bypass Security Checks
🌐 "WebPalm: Unleash Websites" 🌐
https://ift.tt/OoIZqpi
Submitted July 28, 2023 at 03:45AM by Adventurous_Dance527
via reddit https://ift.tt/0aN2m9I
https://ift.tt/OoIZqpi
Submitted July 28, 2023 at 03:45AM by Adventurous_Dance527
via reddit https://ift.tt/0aN2m9I
GitHub
GitHub - Malwarize/webpalm: WebPalm is a powerful command-line tool for website mapping and web scraping. With its recursive approach…
WebPalm is a powerful command-line tool for website mapping and web scraping. With its recursive approach, it can generate a complete tree of all webpages and their links on a website. It can also ...
Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646)
https://ift.tt/CcHRqpf
Submitted July 28, 2023 at 07:02AM by Mempodipper
via reddit https://ift.tt/YNP36Di
https://ift.tt/CcHRqpf
Submitted July 28, 2023 at 07:02AM by Mempodipper
via reddit https://ift.tt/YNP36Di
Assetnote
Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646)
Application security issues found by Assetnote