The Black Box of GitHub Leaks: Analyzing Companies' GitHub Repos
https://ift.tt/LFmICtv
Submitted July 26, 2023 at 12:57AM by bartukilic
via reddit https://ift.tt/CvFdK6h
https://ift.tt/LFmICtv
Submitted July 26, 2023 at 12:57AM by bartukilic
via reddit https://ift.tt/CvFdK6h
SOCRadar® Cyber Intelligence Inc.
The Black Box of GitHub Leaks: Analyzing Companies' GitHub Repos - SOCRadar® Cyber Intelligence Inc.
This research aimed to investigate the files that companies might have accidentally uploaded to GitHub and identify any sensitive information that could be
This minuscule 4 KB file can allow an attacker to take over your Windows system
https://ift.tt/uMs8t1H
Submitted July 26, 2023 at 01:22PM by ElectricalResource29
via reddit https://ift.tt/kG5uXKe
https://ift.tt/uMs8t1H
Submitted July 26, 2023 at 01:22PM by ElectricalResource29
via reddit https://ift.tt/kG5uXKe
TechKranti
This minuscule 4 KB file can allow an attacker to take over your Windows system
The noscript sounds dramatic, right? Is this clickbait? No, it isn’t. Bear with me while I make my case to justify the noscript. So, what’s this dangerous minuscule file the noscript talks about?
Huawei Theme Manager Arbitrary Code Execution Vulnerability
https://ift.tt/CbHjmR2
Submitted July 26, 2023 at 04:03PM by nibblesec
via reddit https://ift.tt/AKROLEt
https://ift.tt/CbHjmR2
Submitted July 26, 2023 at 04:03PM by nibblesec
via reddit https://ift.tt/AKROLEt
Doyensec
Huawei Theme Manager Arbitrary Code Execution · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Linux kernel rootkit Reptile supports Linux 5.8 for Vault Range
https://ift.tt/ZkrQMiY
Submitted July 26, 2023 at 05:08PM by hardenedvault
via reddit https://ift.tt/Ws2JQGr
https://ift.tt/ZkrQMiY
Submitted July 26, 2023 at 05:08PM by hardenedvault
via reddit https://ift.tt/Ws2JQGr
GitHub
GitHub - hardenedvault/Reptile: LKM Linux rootkit
LKM Linux rootkit. Contribute to hardenedvault/Reptile development by creating an account on GitHub.
AWS WAF Bypass: invalid JSON object and Unicode escape sequences
https://ift.tt/FJlmHTz
Submitted July 26, 2023 at 07:22PM by theMiddleBlue
via reddit https://ift.tt/REGvpfu
https://ift.tt/FJlmHTz
Submitted July 26, 2023 at 07:22PM by theMiddleBlue
via reddit https://ift.tt/REGvpfu
Sicuranext Blog
AWS WAF Bypass: invalid JSON object and unicode escape sequences
In recent times, the security community has been witnessing an increasing number of reports from researchers highlighting various bypass techniques targeting AWS Web Application Firewall¹. These bypasses have brought to light not only the absence of certain…
TETRA:BURST
https://ift.tt/Zl3Bxd6
Submitted July 26, 2023 at 10:03PM by WhooisWhoo
via reddit https://ift.tt/zn2sSBj
https://ift.tt/Zl3Bxd6
Submitted July 26, 2023 at 10:03PM by WhooisWhoo
via reddit https://ift.tt/zn2sSBj
www.midnightblue.nl
TETRA:BURST | Midnight Blue
TETRA:BURST is a collection of five vulnerabilities, two of which are deemed critical, affecting the Terrestrial Trunked Radio (TETRA) standard used globally by law enforcement, military, critical infrastructure, and industrial asset owners in the power,…
SVG Security Risks - not just a scalable graphic
https://ift.tt/5sPJOM1
Submitted July 27, 2023 at 01:00PM by co1nc1dence
via reddit https://ift.tt/Vw2ActC
https://ift.tt/5sPJOM1
Submitted July 27, 2023 at 01:00PM by co1nc1dence
via reddit https://ift.tt/Vw2ActC
www.securesystems.de
SVG Security Risks - not just a scalable graphic
Embedding Scalable Vector Graphics (SVG) can expose websites to code injection. This article explores how SVGs work, the risks they pose, and how to mitigate them.
Total BYOVD Kernel-level protection for Windows using Windows Defender Application Control
https://ift.tt/VC69vXS
Submitted July 27, 2023 at 02:31PM by HotCakeXXXXXXXXXXXXX
via reddit https://ift.tt/9EwqKkG
https://ift.tt/VC69vXS
Submitted July 27, 2023 at 02:31PM by HotCakeXXXXXXXXXXXXX
via reddit https://ift.tt/9EwqKkG
GitHub
WDAC policy for BYOVD Kernel mode only protection
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers...
Tales Of Security Issues In Cryptocurrency Software Wallets
https://ift.tt/kyhmUqP
Submitted July 27, 2023 at 09:06PM by juliocesarfort
via reddit https://ift.tt/id9EeNw
https://ift.tt/kyhmUqP
Submitted July 27, 2023 at 09:06PM by juliocesarfort
via reddit https://ift.tt/id9EeNw
Blaze Information Security
Tales Of Security Issues In Cryptocurrency Software Wallets
This post discusses security concerns and two vulnerabilities in Harmony and oByte, two browser extensions that serves as a cryptocurrency software wallet.
How come Unicode characters leads to the bypass of the security measures? 🔐
https://ift.tt/lNpFWbi
Submitted July 27, 2023 at 11:56PM by Sim4n6
via reddit https://ift.tt/7h15PBT
https://ift.tt/lNpFWbi
Submitted July 27, 2023 at 11:56PM by Sim4n6
via reddit https://ift.tt/7h15PBT
Query Chronicles
Unicode characters to Bypass Security Checks
🌐 "WebPalm: Unleash Websites" 🌐
https://ift.tt/OoIZqpi
Submitted July 28, 2023 at 03:45AM by Adventurous_Dance527
via reddit https://ift.tt/0aN2m9I
https://ift.tt/OoIZqpi
Submitted July 28, 2023 at 03:45AM by Adventurous_Dance527
via reddit https://ift.tt/0aN2m9I
GitHub
GitHub - Malwarize/webpalm: WebPalm is a powerful command-line tool for website mapping and web scraping. With its recursive approach…
WebPalm is a powerful command-line tool for website mapping and web scraping. With its recursive approach, it can generate a complete tree of all webpages and their links on a website. It can also ...
Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646)
https://ift.tt/CcHRqpf
Submitted July 28, 2023 at 07:02AM by Mempodipper
via reddit https://ift.tt/YNP36Di
https://ift.tt/CcHRqpf
Submitted July 28, 2023 at 07:02AM by Mempodipper
via reddit https://ift.tt/YNP36Di
Assetnote
Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646)
Application security issues found by Assetnote
Trail of Bits Testing Handbook with the first chapter on Semgrep
https://ift.tt/dOV7UmL
Submitted July 28, 2023 at 11:22AM by Zealousideal-Half863
via reddit https://ift.tt/hE3ZPyz
https://ift.tt/dOV7UmL
Submitted July 28, 2023 at 11:22AM by Zealousideal-Half863
via reddit https://ift.tt/hE3ZPyz
Trail of Bits Blog
Announcing the Trail of Bits Testing Handbook
By Maciej Domanski Trail of Bits is thrilled to announce the Testing Handbook, the shortest path for developers and security professionals to derive maximum value from the static and dynamic analys…
GitHub-to-AWS OIDC implementation flaws (and compromising an IAM role of the UK government)
https://ift.tt/zA6VikT
Submitted July 28, 2023 at 03:33AM by thorn42
via reddit https://ift.tt/GJjHzhF
https://ift.tt/zA6VikT
Submitted July 28, 2023 at 03:33AM by thorn42
via reddit https://ift.tt/GJjHzhF
Datadoghq
No keys attached: Exploring GitHub-to-AWS keyless authentication flaws
While popular, GitHub-to-AWS keyless authentication mechanisms can be insecurely configured.
Introducing Chronometry by @yokai_network. A free tamper-proof tool designed for hackers to record and preserve Proof-of-Hacks (PoH)
https://ift.tt/xE9IjJu
Submitted July 28, 2023 at 02:06PM by ant4g0nist
via reddit https://ift.tt/eHbJAOw
https://ift.tt/xE9IjJu
Submitted July 28, 2023 at 02:06PM by ant4g0nist
via reddit https://ift.tt/eHbJAOw
Medium
Introducing Chronometry by Yōkai
A free tamper-proof tool designed for hackers to record and preserve Proof-of-Hacks (PoH)
Virtual CISO Happy Hour | Tuesday, August 1st at 12PM EST
https://ift.tt/0Qg1WoA
Submitted July 28, 2023 at 06:41PM by aptconsulting
via reddit https://ift.tt/S4sJyHT
https://ift.tt/0Qg1WoA
Submitted July 28, 2023 at 06:41PM by aptconsulting
via reddit https://ift.tt/S4sJyHT
Zoom
Video Conferencing, Web Conferencing, Webinars, Screen Sharing
Zoom is the leader in modern enterprise video communications, with an easy, reliable cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems. Zoom Rooms is the original software-based conference room solution…
Xep-WhoIs - A TypeScript WHOIS library which supports almost all the text-based WHOIS servers (minimal code)
https://ift.tt/qyxAPT4
Submitted July 29, 2023 at 07:12PM by Oshan96
via reddit https://ift.tt/yqC0SnM
https://ift.tt/qyxAPT4
Submitted July 29, 2023 at 07:12PM by Oshan96
via reddit https://ift.tt/yqC0SnM
GitHub
GitHub - xeptagondev/xep-whois: Lightweight WhoIs client
Lightweight WhoIs client. Contribute to xeptagondev/xep-whois development by creating an account on GitHub.
razy_importer: Rust implementation of lazy_importer
https://ift.tt/b61gAPN
Submitted July 30, 2023 at 01:02AM by oil_sardine
via reddit https://ift.tt/Vmbfwx7
https://ift.tt/b61gAPN
Submitted July 30, 2023 at 01:02AM by oil_sardine
via reddit https://ift.tt/Vmbfwx7
GitHub
GitHub - kkent030315/razy_importer: Rust implementation of lazy_importer
Rust implementation of lazy_importer. Contribute to kkent030315/razy_importer development by creating an account on GitHub.
AMD 'Zenbleed' Bug Leaks Data From Zen 2 Ryzen, EPYC CPUs: Most Patches Coming Q4
https://ift.tt/fYXbCyr
Submitted July 30, 2023 at 12:37PM by PsyOmega
via reddit https://ift.tt/BJZNPYb
https://ift.tt/fYXbCyr
Submitted July 30, 2023 at 12:37PM by PsyOmega
via reddit https://ift.tt/BJZNPYb
Tom's Hardware
AMD 'Zenbleed' Bug Leaks Data From Zen 2 Ryzen, EPYC CPUs: Most Patches Coming Q4 (Updated)
A huge Zen 2 leak requires a patch.
CVE-2023-27997: Critical Fortinet Fortigate RCE Vulnerability
https://ift.tt/NUzfm0k
Submitted July 30, 2023 at 09:18PM by jpanixix
via reddit https://ift.tt/h3IJzqg
https://ift.tt/NUzfm0k
Submitted July 30, 2023 at 09:18PM by jpanixix
via reddit https://ift.tt/h3IJzqg
Rapid7
CVE-2023-27997: Critical Fortinet Fortigate RCE Vulnerability | Rapid7 Blog
Rapid7 is tracking CVE-2023-27997, a purportedly critical remote code execution (RCE) vulnerability in Fortigate SSL VPN firewalls.
SpyNote continues to attack financial institutions | Cleafy Labs
https://ift.tt/Vtqc9W7
Submitted July 31, 2023 at 03:30PM by f3d_0x0
via reddit https://ift.tt/TfMOs1w
https://ift.tt/Vtqc9W7
Submitted July 31, 2023 at 03:30PM by f3d_0x0
via reddit https://ift.tt/TfMOs1w
Cleafy
SpyNote continues to attack financial institutions | Cleafy Labs
Discovered at the end of 2022, SpyNote is now executing an extensive campaign against multiple European customers of different banks. Read the technical analysis to know all his functionalities and how to prevent it.