Trail of Bits Testing Handbook with the first chapter on Semgrep
https://ift.tt/dOV7UmL
Submitted July 28, 2023 at 11:22AM by Zealousideal-Half863
via reddit https://ift.tt/hE3ZPyz
https://ift.tt/dOV7UmL
Submitted July 28, 2023 at 11:22AM by Zealousideal-Half863
via reddit https://ift.tt/hE3ZPyz
Trail of Bits Blog
Announcing the Trail of Bits Testing Handbook
By Maciej Domanski Trail of Bits is thrilled to announce the Testing Handbook, the shortest path for developers and security professionals to derive maximum value from the static and dynamic analys…
GitHub-to-AWS OIDC implementation flaws (and compromising an IAM role of the UK government)
https://ift.tt/zA6VikT
Submitted July 28, 2023 at 03:33AM by thorn42
via reddit https://ift.tt/GJjHzhF
https://ift.tt/zA6VikT
Submitted July 28, 2023 at 03:33AM by thorn42
via reddit https://ift.tt/GJjHzhF
Datadoghq
No keys attached: Exploring GitHub-to-AWS keyless authentication flaws
While popular, GitHub-to-AWS keyless authentication mechanisms can be insecurely configured.
Introducing Chronometry by @yokai_network. A free tamper-proof tool designed for hackers to record and preserve Proof-of-Hacks (PoH)
https://ift.tt/xE9IjJu
Submitted July 28, 2023 at 02:06PM by ant4g0nist
via reddit https://ift.tt/eHbJAOw
https://ift.tt/xE9IjJu
Submitted July 28, 2023 at 02:06PM by ant4g0nist
via reddit https://ift.tt/eHbJAOw
Medium
Introducing Chronometry by Yōkai
A free tamper-proof tool designed for hackers to record and preserve Proof-of-Hacks (PoH)
Virtual CISO Happy Hour | Tuesday, August 1st at 12PM EST
https://ift.tt/0Qg1WoA
Submitted July 28, 2023 at 06:41PM by aptconsulting
via reddit https://ift.tt/S4sJyHT
https://ift.tt/0Qg1WoA
Submitted July 28, 2023 at 06:41PM by aptconsulting
via reddit https://ift.tt/S4sJyHT
Zoom
Video Conferencing, Web Conferencing, Webinars, Screen Sharing
Zoom is the leader in modern enterprise video communications, with an easy, reliable cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems. Zoom Rooms is the original software-based conference room solution…
Xep-WhoIs - A TypeScript WHOIS library which supports almost all the text-based WHOIS servers (minimal code)
https://ift.tt/qyxAPT4
Submitted July 29, 2023 at 07:12PM by Oshan96
via reddit https://ift.tt/yqC0SnM
https://ift.tt/qyxAPT4
Submitted July 29, 2023 at 07:12PM by Oshan96
via reddit https://ift.tt/yqC0SnM
GitHub
GitHub - xeptagondev/xep-whois: Lightweight WhoIs client
Lightweight WhoIs client. Contribute to xeptagondev/xep-whois development by creating an account on GitHub.
razy_importer: Rust implementation of lazy_importer
https://ift.tt/b61gAPN
Submitted July 30, 2023 at 01:02AM by oil_sardine
via reddit https://ift.tt/Vmbfwx7
https://ift.tt/b61gAPN
Submitted July 30, 2023 at 01:02AM by oil_sardine
via reddit https://ift.tt/Vmbfwx7
GitHub
GitHub - kkent030315/razy_importer: Rust implementation of lazy_importer
Rust implementation of lazy_importer. Contribute to kkent030315/razy_importer development by creating an account on GitHub.
AMD 'Zenbleed' Bug Leaks Data From Zen 2 Ryzen, EPYC CPUs: Most Patches Coming Q4
https://ift.tt/fYXbCyr
Submitted July 30, 2023 at 12:37PM by PsyOmega
via reddit https://ift.tt/BJZNPYb
https://ift.tt/fYXbCyr
Submitted July 30, 2023 at 12:37PM by PsyOmega
via reddit https://ift.tt/BJZNPYb
Tom's Hardware
AMD 'Zenbleed' Bug Leaks Data From Zen 2 Ryzen, EPYC CPUs: Most Patches Coming Q4 (Updated)
A huge Zen 2 leak requires a patch.
CVE-2023-27997: Critical Fortinet Fortigate RCE Vulnerability
https://ift.tt/NUzfm0k
Submitted July 30, 2023 at 09:18PM by jpanixix
via reddit https://ift.tt/h3IJzqg
https://ift.tt/NUzfm0k
Submitted July 30, 2023 at 09:18PM by jpanixix
via reddit https://ift.tt/h3IJzqg
Rapid7
CVE-2023-27997: Critical Fortinet Fortigate RCE Vulnerability | Rapid7 Blog
Rapid7 is tracking CVE-2023-27997, a purportedly critical remote code execution (RCE) vulnerability in Fortigate SSL VPN firewalls.
SpyNote continues to attack financial institutions | Cleafy Labs
https://ift.tt/Vtqc9W7
Submitted July 31, 2023 at 03:30PM by f3d_0x0
via reddit https://ift.tt/TfMOs1w
https://ift.tt/Vtqc9W7
Submitted July 31, 2023 at 03:30PM by f3d_0x0
via reddit https://ift.tt/TfMOs1w
Cleafy
SpyNote continues to attack financial institutions | Cleafy Labs
Discovered at the end of 2022, SpyNote is now executing an extensive campaign against multiple European customers of different banks. Read the technical analysis to know all his functionalities and how to prevent it.
Get Flipper Zero for free - a portable multi-tool for geeks
https://ift.tt/Eav8dB5
Submitted July 31, 2023 at 09:42PM by Normal-Struggle5874
via reddit https://ift.tt/gRbqrsA
https://ift.tt/Eav8dB5
Submitted July 31, 2023 at 09:42PM by Normal-Struggle5874
via reddit https://ift.tt/gRbqrsA
Multi-threaded secretsdump.py
https://ift.tt/0SR79w3
Submitted August 01, 2023 at 01:45AM by edreatingmonkey
via reddit https://ift.tt/f8Hr752
https://ift.tt/0SR79w3
Submitted August 01, 2023 at 01:45AM by edreatingmonkey
via reddit https://ift.tt/f8Hr752
GitHub
GitHub - fin3ss3g0d/secretsdump.py: Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input…
Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets extraction. - GitHub - fin3ss3g0d/secretsdump.p...
Legitify 1.0 is officially out! Armed with new enterprise-level policies to make sure your GitHub Enterprise / GitLab Server doesn't contain risky misconfigurations. Plus improved performance and stability 🚀
https://ift.tt/b5QPhmF
Submitted August 01, 2023 at 05:55PM by roy_6472
via reddit https://ift.tt/5EXuUkT
https://ift.tt/b5QPhmF
Submitted August 01, 2023 at 05:55PM by roy_6472
via reddit https://ift.tt/5EXuUkT
GitHub
GitHub - Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets - Legit-Labs/legitify
AWS IAM Persistence Methods - Hacking The Cloud
https://ift.tt/7W0ABsV
Submitted August 01, 2023 at 07:10PM by RedTermSession
via reddit https://ift.tt/24NsEmw
https://ift.tt/7W0ABsV
Submitted August 01, 2023 at 07:10PM by RedTermSession
via reddit https://ift.tt/24NsEmw
hackingthe.cloud
AWS IAM Persistence Methods - Hacking The Cloud
A catalog of methods to maintain access to the AWS control plane.
CSRFing VS Code's Debug Adapter Protocol
https://ift.tt/43i9AML
Submitted August 01, 2023 at 08:10PM by 80x25
via reddit https://ift.tt/hGxgTVW
https://ift.tt/43i9AML
Submitted August 01, 2023 at 08:10PM by 80x25
via reddit https://ift.tt/hGxgTVW
www.mcnulty.blog
CSRFing VS Code's Debug Adapter Protocol
A technical write-up for a cross-site request forgery vulnerability present in some Debug Adapter Protocol implementations. The Debug Adapter Protocol is used by VS Code and other development tools to debug programs. The write-up details the vulnerability…
Installing P4wnP1 on an LTE modem
https://ift.tt/62LDdJl
Submitted August 02, 2023 at 12:32AM by RoganDawes
via reddit https://ift.tt/2vjFsVd
https://ift.tt/62LDdJl
Submitted August 02, 2023 at 12:32AM by RoganDawes
via reddit https://ift.tt/2vjFsVd
Sensepost
SensePost | P4wnp1-lte
Leaders in Information Security
Escaping the Google kCTF Container with a Data-Only Exploit
https://ift.tt/wnTSKq4
Submitted August 02, 2023 at 03:40PM by poltess0
via reddit https://ift.tt/XOFbRCE
https://ift.tt/wnTSKq4
Submitted August 02, 2023 at 03:40PM by poltess0
via reddit https://ift.tt/XOFbRCE
The Human Machine Interface
Escaping the Google kCTF Container with a Data-Only Exploit
Introduction I’ve been doing some Linux kernel exploit development/study and vulnerability research off and on since last Fall and a few months ago I had some downtime on vacation to sit and challenge myself to write my first data-only exploit for a real…
Manager of third-party sources of Semgrep rules
https://ift.tt/DxOS7TL
Submitted August 02, 2023 at 05:14PM by iosifache
via reddit https://ift.tt/W1KD2wt
https://ift.tt/DxOS7TL
Submitted August 02, 2023 at 05:14PM by iosifache
via reddit https://ift.tt/W1KD2wt
GitHub
GitHub - iosifache/semgrep-rules-manager: Manager of third-party sources of Semgrep rules 🗂
Manager of third-party sources of Semgrep rules 🗂 - GitHub - iosifache/semgrep-rules-manager: Manager of third-party sources of Semgrep rules 🗂
CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You
https://ift.tt/q2h9byJ
Submitted August 02, 2023 at 05:11PM by preazmiko
via reddit https://ift.tt/mWnOvgh
https://ift.tt/q2h9byJ
Submitted August 02, 2023 at 05:11PM by preazmiko
via reddit https://ift.tt/mWnOvgh
emily.id.au
CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You
TL;DR Recommendations
Critical Zero-Day Vulnerability in Citrix NetScaler ADC and NetScaler Gateway
https://ift.tt/cmqrKLF
Submitted August 02, 2023 at 05:53PM by tapmylap
via reddit https://ift.tt/AJjuZS1
https://ift.tt/cmqrKLF
Submitted August 02, 2023 at 05:53PM by tapmylap
via reddit https://ift.tt/AJjuZS1
Rapid7
Critical Zero-Day Vulnerability in Citrix NetScaler ADC and NetScaler Gateway | Rapid7 Blog
Citrix has published a security bulletin warning users of three new vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
Ports and Protocols: An In-Depth Exploration for Ethical Hacking in Networking
https://ift.tt/zTwNvUC
Submitted August 02, 2023 at 07:17PM by securnerd_02
via reddit https://ift.tt/52eXAL3
https://ift.tt/zTwNvUC
Submitted August 02, 2023 at 07:17PM by securnerd_02
via reddit https://ift.tt/52eXAL3
Codelivly
Ports and Protocols: An In-Depth Exploration for Ethical Hacking in Networking
By the end , you’ll have a solid understanding of what ports and protocols are, how they work, and why they’re so vital in the field hacking.
Vulnerability Uncovered in Salesforce’s Email Services Exploited for Phishing Facebook Accounts In-The-Wil
https://ift.tt/nLMhuJc
Submitted August 02, 2023 at 06:47PM by pinpepnet
via reddit https://ift.tt/Sye7Rqx
https://ift.tt/nLMhuJc
Submitted August 02, 2023 at 06:47PM by pinpepnet
via reddit https://ift.tt/Sye7Rqx
Medium
“PhishForce” — Vulnerability Uncovered in Salesforce’s Email Services Exploited for Phishing Facebook Accounts In-The-Wild
By Oleg Zaytsev, Nati Tal (Guardio Labs)