Session Hijacking Visual Exploitation (SHVE). New tool for XSS Exploitation
https://ift.tt/IxT5CmD
Submitted September 02, 2023 at 05:01AM by nibblesec
via reddit https://ift.tt/eNzLRkm
https://ift.tt/IxT5CmD
Submitted September 02, 2023 at 05:01AM by nibblesec
via reddit https://ift.tt/eNzLRkm
Doyensec
Introducing Session Hijacking Visual Exploitation (SHVE): An Innovative Open-Source Tool for XSS Exploitation · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Annoying Apple Fans: The Flipper Zero Bluetooth Prank Revealed
https://ift.tt/oDZG2O1
Submitted September 02, 2023 at 06:23AM by Techryptic
via reddit https://ift.tt/H7gMLwB
https://ift.tt/oDZG2O1
Submitted September 02, 2023 at 06:23AM by Techryptic
via reddit https://ift.tt/H7gMLwB
Secure FastAPI with eBPF
https://ift.tt/Vum1IOr
Submitted September 03, 2023 at 04:32PM by cov_id19
via reddit https://ift.tt/FMtvCQ2
https://ift.tt/Vum1IOr
Submitted September 03, 2023 at 04:32PM by cov_id19
via reddit https://ift.tt/FMtvCQ2
Medium
Secure FastAPI with eBPF
Leverage eBPF to secure internet-facing APIs: FastAPI, BlackSheep, Flask, Django, aiohttp, tornado, and more.
New advisory: File History Service (fhsvc.dll) Elevation of Privilege - SSD Secure Disclosure
https://ift.tt/Ya7jgX3
Submitted September 03, 2023 at 07:49PM by SSDisclosure
via reddit https://ift.tt/0a6rOZp
https://ift.tt/Ya7jgX3
Submitted September 03, 2023 at 07:49PM by SSDisclosure
via reddit https://ift.tt/0a6rOZp
SSD Secure Disclosure
SSD Advisory - File History Service (fhsvc.dll) Elevation of Privilege - SSD Secure Disclosure
Summary A vulnerability in Windows’s File History Service allows local users to gain elevated privileges on the Windows operating system. Credit An independent security researcher working with SSD Secure Disclosure, the vulnerability was one of the winners…
China-linked cybercriminals bypass Barracuda’s security patch
https://ift.tt/VMThCIB
Submitted September 04, 2023 at 01:44AM by nareksays
via reddit https://ift.tt/mAiPV8r
https://ift.tt/VMThCIB
Submitted September 04, 2023 at 01:44AM by nareksays
via reddit https://ift.tt/mAiPV8r
Deform
China-linked Cybercriminals Bypass Barracuda's Security Patch - Deform
Barracuda email security gateway devices became the target of a cyber espionage attack from a group with ties to China, known as UNC4841. This group managed
WordPress website fingerprint techniques
https://ift.tt/ngGvuB7
Submitted September 04, 2023 at 01:37PM by theMiddleBlue
via reddit https://ift.tt/FqhoTvQ
https://ift.tt/ngGvuB7
Submitted September 04, 2023 at 01:37PM by theMiddleBlue
via reddit https://ift.tt/FqhoTvQ
Sicuranext Blog
How attackers fingerprint your WordPress website
Attackers have quite a few sneaky ways to gather information from your WordPress website. They can get their hands on details like the WordPress version you're using, the active plugins and their versions, and even info about your active users. In this article…
Microsoft Edge Forensics: Screenshot History
https://ift.tt/olZncUd
Submitted September 04, 2023 at 01:08PM by OwnPreparation3424
via reddit https://ift.tt/pF50ly9
https://ift.tt/olZncUd
Submitted September 04, 2023 at 01:08PM by OwnPreparation3424
via reddit https://ift.tt/pF50ly9
Medium
Microsoft Edge Forensics: Screenshot History
According to a recent article on Neowin, Microsoft Edge has a new feature that allows it to take screenshots of every web page a user…
Arbitrary Configuration Injection 💉 (intro)
https://ift.tt/7jcTYfy
Submitted September 04, 2023 at 02:25PM by Sim4n6
via reddit https://ift.tt/i23FnlB
https://ift.tt/7jcTYfy
Submitted September 04, 2023 at 02:25PM by Sim4n6
via reddit https://ift.tt/i23FnlB
Query Chronicles
Arbitrary Configuration Injection
A full report of penetration test of OPNsense (an open source, FreeBSD based firewall and routing platform).
https://ift.tt/ti5G4JI
Submitted September 04, 2023 at 06:29PM by logicaltrust-net
via reddit https://ift.tt/wtjhHnO
https://ift.tt/ti5G4JI
Submitted September 04, 2023 at 06:29PM by logicaltrust-net
via reddit https://ift.tt/wtjhHnO
Pwn2Own contest offers $1M in cash and prizes for hacking cars
https://ift.tt/MVlJxgO
Submitted September 04, 2023 at 08:28PM by nhavag
via reddit https://ift.tt/tYA6L4f
https://ift.tt/MVlJxgO
Submitted September 04, 2023 at 08:28PM by nhavag
via reddit https://ift.tt/tYA6L4f
Useful resources for SOC Analyst and SOC Analyst candidates.
https://ift.tt/cEwxLKC
Submitted September 04, 2023 at 08:43PM by ogunal00
via reddit https://ift.tt/vqlzSti
https://ift.tt/cEwxLKC
Submitted September 04, 2023 at 08:43PM by ogunal00
via reddit https://ift.tt/vqlzSti
GitHub
GitHub - LetsDefend/awesome-soc-analyst: Useful resources for SOC Analyst and SOC Analyst candidates.
Useful resources for SOC Analyst and SOC Analyst candidates. - GitHub - LetsDefend/awesome-soc-analyst: Useful resources for SOC Analyst and SOC Analyst candidates.
Using Open Source Software Composition Analysis Tool From Google. Presenting the usage of the osv-scanner tool in real-life Python and Java projects. A tool review with pros and cons.
https://ift.tt/Xx5uWhH
Submitted September 04, 2023 at 11:05PM by theowni
via reddit https://ift.tt/woiDvS2
https://ift.tt/Xx5uWhH
Submitted September 04, 2023 at 11:05PM by theowni
via reddit https://ift.tt/woiDvS2
Medium
Using Open-Source Software Composition Analysis Tool From Google
Presenting the usage of the osv-scanner tool from Google in real-life Python and Java projects. A tool review with its pros and cons.
Nascent Malware Campaign Targets npm, PyPI, and RubyGems Developers
https://ift.tt/R7uW1hi
Submitted September 05, 2023 at 12:27AM by louis11
via reddit https://ift.tt/Jf32kxe
https://ift.tt/R7uW1hi
Submitted September 05, 2023 at 12:27AM by louis11
via reddit https://ift.tt/Jf32kxe
Phylum
Malware targets Python, Ruby and Javanoscript Developers
Phylum has identified a malware campaign spanning PyPI, npm and RubyGems. Delivering early stage malware to users.
Uncovering Web Cache Deception: A Missed Vulnerability in the Most Unexpected Places
https://ift.tt/AEjCxYS
Submitted September 05, 2023 at 03:30AM by vikzsharma
via reddit https://ift.tt/Uxf96Ts
https://ift.tt/AEjCxYS
Submitted September 05, 2023 at 03:30AM by vikzsharma
via reddit https://ift.tt/Uxf96Ts
Agilehunt
Uncovering Web Cache Deception: A Missed Vulnerability in the Most Unexpected Places
VULNERABILITY DESCRIPTION
This vulnerability involves a Web Cache Deception attack targeting the https://redacted.com/anynonexisting URL endpoint. By manipulating the caching mechanisms, unauthorized users can gain access to sensitive Personally Identifiable…
This vulnerability involves a Web Cache Deception attack targeting the https://redacted.com/anynonexisting URL endpoint. By manipulating the caching mechanisms, unauthorized users can gain access to sensitive Personally Identifiable…
Chepy 6.0.0 released with lots of new changes, capabilities etc. Cyberchef in pure python
https://ift.tt/uPQRjaT
Submitted September 05, 2023 at 05:57AM by securisec
via reddit https://ift.tt/QU1DfGM
https://ift.tt/uPQRjaT
Submitted September 05, 2023 at 05:57AM by securisec
via reddit https://ift.tt/QU1DfGM
GitHub
GitHub - securisec/chepy: Chepy is a python lib/cli equivalent of the awesome CyberChef tool.
Chepy is a python lib/cli equivalent of the awesome CyberChef tool. - GitHub - securisec/chepy: Chepy is a python lib/cli equivalent of the awesome CyberChef tool.
VulnHub Kioptrix Level 1.1 CTF Walkthrough - Step-by-step with Explanations
https://ift.tt/Bp8RmAD
Submitted September 05, 2023 at 10:42AM by kongwenbin
via reddit https://ift.tt/NFpoqT6
https://ift.tt/Bp8RmAD
Submitted September 05, 2023 at 10:42AM by kongwenbin
via reddit https://ift.tt/NFpoqT6
My Learning Journey
VulnHub Kioptrix Level 1.1 CTF Walkthrough - Step-by-step with Explanations - My Learning Journey
Setup Kioptrix 1.1 & start hacking, commenting & showing every step from recon, port scan, exploitation, privilege escalation & becoming root
When URL parsers disagree (CVE-2023-38633)
https://ift.tt/AeQsXgu
Submitted September 05, 2023 at 01:27PM by ScottContini
via reddit https://ift.tt/iUNWTyM
https://ift.tt/AeQsXgu
Submitted September 05, 2023 at 01:27PM by ScottContini
via reddit https://ift.tt/iUNWTyM
canva.dev
When URL parsers disagree (CVE-2023-38633) - Canva Engineering Blog
Discovery and walkthrough of CVE-2023-38633 in librnoscript, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path traversal.
LFI/RCE Vulnerability in WordPress Media Library Assistant Plugin - CVE-2023-4634 - Patrowl
https://ift.tt/IgOBvMy
Submitted September 05, 2023 at 01:52PM by Pepito_oh
via reddit https://ift.tt/fqhSzOJ
https://ift.tt/IgOBvMy
Submitted September 05, 2023 at 01:52PM by Pepito_oh
via reddit https://ift.tt/fqhSzOJ
Patrowl
External Exposure Management as a Service | Patrowl - Patrowl
Identify and harden your External Security Posture with the leader. Let us manage time-consuming tasks and focus on remediation
Improving nmap's service scanning accuracy and speed with nmap-service-probes data
https://ift.tt/IuydGWU
Submitted September 05, 2023 at 03:54PM by MegaManSec2
via reddit https://ift.tt/S6AJwr9
https://ift.tt/IuydGWU
Submitted September 05, 2023 at 03:54PM by MegaManSec2
via reddit https://ift.tt/S6AJwr9
Joshua.Hu
Improve nmap’s service scanning with this 1 weird trick!
In my past two blog posts, I’ve explored how to combine multiple port scanning tools to create a fast service scanning tool for large networks, and how I sped up nmap’s service scanning by changing its “wait for content” time. In this post, I’m going to be…
Analysis of a new Facebook profile stealer written in Node.js
https://ift.tt/viba2rX
Submitted September 05, 2023 at 05:07PM by nareksays
via reddit https://ift.tt/QUO51to
https://ift.tt/viba2rX
Submitted September 05, 2023 at 05:07PM by nareksays
via reddit https://ift.tt/QUO51to
Trend Micro
Analyzing a Facebook Profile Stealer Written in Node js
We analyze an information stealer written in Node.js, packaged into an executable, exfiltrated stolen data via both Telegram bot API and a C&C server, and employed GraphQL as a channel for C&C communication.
Live API Keys and Source Code Leaked in 4,500 of the Top Alexa Sites
https://ift.tt/wMmcTZX
Submitted September 05, 2023 at 09:58PM by Phorcez
via reddit https://ift.tt/2w0ZWho
https://ift.tt/wMmcTZX
Submitted September 05, 2023 at 09:58PM by Phorcez
via reddit https://ift.tt/2w0ZWho
Truffle Security
4,500 of the Top 1 Million Websites Leaked Source Code, Secrets - Truffle Security
TruffleHog scanned the top 1 Million visited websites and discovered 4,500 exposed git directories and hundreds of leaked API keys + secrets.