#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation
https://ift.tt/v1z4qBR
Submitted August 20, 2023 at 12:49PM by ron_by
via reddit https://ift.tt/aVnNZ2D
https://ift.tt/v1z4qBR
Submitted August 20, 2023 at 12:49PM by ron_by
via reddit https://ift.tt/aVnNZ2D
GitHub
GitHub - deepinstinct/NoFilter
Contribute to deepinstinct/NoFilter development by creating an account on GitHub.
Can machines dream of secure code? From AI hallucinations to software vulnerabilities | Snyk
https://ift.tt/6gRnXcB
Submitted August 20, 2023 at 11:27PM by lirantal
via reddit https://ift.tt/N2kLDBP
https://ift.tt/6gRnXcB
Submitted August 20, 2023 at 11:27PM by lirantal
via reddit https://ift.tt/N2kLDBP
Snyk
AI Hallucinations: How Do They Happen And Why Is It An Issue For Development? | Snyk
AI hallucinations are a common issue in Generative AI, and can cause vulnerabilities to be introduced into your software if AI is used without security guardrails.
RateMyAI - Prompt Composer - A Generative AI Testing Tool
https://ift.tt/H4Qd719
Submitted August 21, 2023 at 02:34AM by MyAccessAccount
via reddit https://ift.tt/Zy7Nv5i
https://ift.tt/H4Qd719
Submitted August 21, 2023 at 02:34AM by MyAccessAccount
via reddit https://ift.tt/Zy7Nv5i
GitHub
GitHub - milosilo/RateMyAI: Prompt Engineering Tool for AI Models with cli prompt or api usage
Prompt Engineering Tool for AI Models with cli prompt or api usage - milosilo/RateMyAI
Threat Hunting Newsletter
https://ift.tt/jPwSb7D
Submitted August 21, 2023 at 02:52AM by m_edmondson
via reddit https://ift.tt/92aLxiq
https://ift.tt/jPwSb7D
Submitted August 21, 2023 at 02:52AM by m_edmondson
via reddit https://ift.tt/92aLxiq
Substack
The Threat Hunter's Dilemma | Marcus Edmondson | Substack
I share threat hunting advice and tips for small and medium sized businesses on a budget. Click to read The Threat Hunter's Dilemma, by Marcus Edmondson, a Substack publication with hundreds of subscribers.
Finally added a raspberry pie to my lab!!
https://ibb.co/p45nZSt
Submitted August 21, 2023 at 05:16AM by seymoorefrog
via reddit https://ift.tt/EpUmu19
https://ibb.co/p45nZSt
Submitted August 21, 2023 at 05:16AM by seymoorefrog
via reddit https://ift.tt/EpUmu19
ImgBB
IMG-4285 hosted at ImgBB
Image IMG-4285 hosted in ImgBB
iTWire - auDA now admits attack, says ransomware group provided proof
https://ift.tt/39bthqF
Submitted August 21, 2023 at 10:55AM by ZestycloseStorage4
via reddit https://ift.tt/Nq6CVbw
https://ift.tt/39bthqF
Submitted August 21, 2023 at 10:55AM by ZestycloseStorage4
via reddit https://ift.tt/Nq6CVbw
Itwire
iTWire - auDA now admits attack, says ransomware group provided proof
The au Domain Administration, the organisation that administers the Australian domain namespace, now says attackers who claimed they had breached its network have provided evidence of the breach. auDA...
mTLS: When certificate authentication is done wrong
https://ift.tt/ThGZ8jA
Submitted August 21, 2023 at 03:33PM by artsploit
via reddit https://ift.tt/9OK5BE7
https://ift.tt/ThGZ8jA
Submitted August 21, 2023 at 03:33PM by artsploit
via reddit https://ift.tt/9OK5BE7
The GitHub Blog
mTLS: When certificate authentication is done wrong
In this post, we'll deep dive into some interesting attacks on mTLS authentication. We'll have a look at implementation vulnerabilities and how developers can make their mTLS systems vulnerable to user impersonation, privilege escalation, and information…
A step by step guide to Fuzzing C++ entities using LibFuzzer.
https://ift.tt/noFfQjl
Submitted August 21, 2023 at 02:44PM by Altrntiv-to-security
via reddit https://ift.tt/xfTsyoJ
https://ift.tt/noFfQjl
Submitted August 21, 2023 at 02:44PM by Altrntiv-to-security
via reddit https://ift.tt/xfTsyoJ
DARKRELAY
Fuzzing with libFuzzer
Fuzzing with libfuzzer cybersecurity blog will show how to apply fuzz testing using libFuzzer to the C++ project.
The Risks of Downloading Files from Telegram Channels
https://ift.tt/d16DoG5
Submitted August 21, 2023 at 07:06PM by Nightwind011
via reddit https://ift.tt/KhVpU2g
https://ift.tt/d16DoG5
Submitted August 21, 2023 at 07:06PM by Nightwind011
via reddit https://ift.tt/KhVpU2g
SOCRadar® Cyber Intelligence Inc.
Telegram Channels Unveiled: The Hidden Dangers Lurking in Shared Files - SOCRadar® Cyber Intelligence Inc.
In today’s interconnected world, cyberspace has become a breeding ground for legitimate and malicious activities; Telegram, a popular messaging platform known
ScienceLogic Dumpster Fire
https://ift.tt/vpQXCdk
Submitted August 21, 2023 at 07:57PM by securifera
via reddit https://ift.tt/GY53Xlj
https://ift.tt/vpQXCdk
Submitted August 21, 2023 at 07:57PM by securifera
via reddit https://ift.tt/GY53Xlj
Automating parts of Active Directory pentests with BloodHound CE
https://ift.tt/hZ17bO2
Submitted August 21, 2023 at 08:40PM by k8pf
via reddit https://ift.tt/DReHrlu
https://ift.tt/hZ17bO2
Submitted August 21, 2023 at 08:40PM by k8pf
via reddit https://ift.tt/DReHrlu
www.8com.de
BloodHound Active Directory Automation Pentest
This blog post explores functionality of BloodHound CE and automates important tasks
Hunchly Team Releases 6 Years of Tor Crawls
https://ift.tt/dBI5Wnc
Submitted August 21, 2023 at 09:55PM by jms_dot_py
via reddit https://ift.tt/uPaGjQb
https://ift.tt/dBI5Wnc
Submitted August 21, 2023 at 09:55PM by jms_dot_py
via reddit https://ift.tt/uPaGjQb
Some rough impressions of Worldcoin
https://ift.tt/Foz9eVH
Submitted August 22, 2023 at 04:01AM by feross
via reddit https://ift.tt/AJlHMIy
https://ift.tt/Foz9eVH
Submitted August 22, 2023 at 04:01AM by feross
via reddit https://ift.tt/AJlHMIy
A Few Thoughts on Cryptographic Engineering
Some rough impressions of Worldcoin
Recently a reader wrote in and asked if I would look at Sam Altman’s Worldcoin, presumably to give thoughts on it from a privacy perspective. This was honestly the last thing I wanted to do, …
Technical Details of CVE-2023-30988 - IBM Facsimile Support Privilege Escalation
https://ift.tt/akpyZWY
Submitted August 22, 2023 at 03:06PM by buherator
via reddit https://ift.tt/L6lW7Yt
https://ift.tt/akpyZWY
Submitted August 22, 2023 at 03:06PM by buherator
via reddit https://ift.tt/L6lW7Yt
Silent Signal Techblog
Technical Details of CVE-2023-30988 - IBM Facsimile Support Privilege Escalation
Because we can!
Exploitation of Openfire CVE-2023-32315
https://ift.tt/bFUL8Vt
Submitted August 22, 2023 at 06:30PM by chicksdigthelongrun
via reddit https://ift.tt/5YDPflr
https://ift.tt/bFUL8Vt
Submitted August 22, 2023 at 06:30PM by chicksdigthelongrun
via reddit https://ift.tt/5YDPflr
VulnCheck
Exploitation of Openfire CVE-2023-32315 - Blog - VulnCheck
CVE-2023-32315 was first exploited in the wild in June 2023. However, VulnCheck has discovered an new approach to exploiting this vulnerability, streamlining the attack process and adeptly bypassing the generation of log entries. In addition, VulnCheck analyzes…
Lateral movement: A conceptual overview
https://ift.tt/gXxM8NC
Submitted August 23, 2023 at 02:43AM by DiabloHorn
via reddit https://ift.tt/Q3JkjLz
https://ift.tt/gXxM8NC
Submitted August 23, 2023 at 02:43AM by DiabloHorn
via reddit https://ift.tt/Q3JkjLz
DiabloHorn
Lateral movement: A conceptual overview
I’ve often been in the situation of explaining lateral movement to people who do not work in the offensive security field on a daily basis or have a different level of technical understanding…
A Secure Design Pattern to Verify Content Size Without Relying on Untrusted File or Protocol Headers
https://ift.tt/g63Sdz2
Submitted August 23, 2023 at 04:42AM by pi3ch
via reddit https://ift.tt/oavVTRj
https://ift.tt/g63Sdz2
Submitted August 23, 2023 at 04:42AM by pi3ch
via reddit https://ift.tt/oavVTRj
Discuss
Stream Buffer Read: A Defensive Design Pattern for Content Size Validation
Tl;dr: Apps rely on untrusted parameter to perform size check. This can result into DoS attack. Stream Buffer Read is a defensive design pattern that prevents this. (This is another post in my series of articles on defensive design patterns: Avoid validation…
The Importance of Key Rotation for Data Security
https://ift.tt/hqb06ul
Submitted August 23, 2023 at 01:04PM by padout395
via reddit https://ift.tt/UcmswoV
https://ift.tt/hqb06ul
Submitted August 23, 2023 at 01:04PM by padout395
via reddit https://ift.tt/UcmswoV
Piiano
Key Rotation Strategies for Securing Sensitive Data
Learn why cryptographic key rotation is important for data security, explore key rotation strategies, and learn how to implement them. Read more!
Understanding Hackers' Work: An Empirical Study of Offensive Security Practitioners
https://ift.tt/XEHBQLY
Submitted August 23, 2023 at 05:13PM by andreashappe
via reddit https://ift.tt/nfv1QFN
https://ift.tt/XEHBQLY
Submitted August 23, 2023 at 05:13PM by andreashappe
via reddit https://ift.tt/nfv1QFN
Traders' Dollars in Danger: CVE-2023-38831 zero-Day vulnerability in WinRAR exploited by cybercriminals to target traders
https://ift.tt/gsUr1bJ
Submitted August 23, 2023 at 10:27PM by sunher444
via reddit https://ift.tt/COYgLbT
https://ift.tt/gsUr1bJ
Submitted August 23, 2023 at 10:27PM by sunher444
via reddit https://ift.tt/COYgLbT
Group-IB
Traders' dollars in danger: CVE-2023-38831 zero-day vulnerability in WinRAR exploited by cybercriminals to target traders
Spoof extensions help cybercriminals target users on trading forums as 130 devices still infected at time of writing.
Deep dive into the recent bugs in the NVMe protocol and the impact on cloud providers and on-premises servers.
https://ift.tt/MIfRxkV
Submitted August 24, 2023 at 01:16AM by jat0369
via reddit https://ift.tt/vUXdR1S
https://ift.tt/MIfRxkV
Submitted August 24, 2023 at 01:16AM by jat0369
via reddit https://ift.tt/vUXdR1S
Cyberark
NVMe: New Vulnerabilities Made Easy
As vulnerability researchers, our primary mission is to find as many vulnerabilities as possible with the highest severity as possible. Finding vulnerabilities is usually challenging. But could...