China-linked cybercriminals bypass Barracuda’s security patch
https://ift.tt/VMThCIB
Submitted September 04, 2023 at 01:44AM by nareksays
via reddit https://ift.tt/mAiPV8r
https://ift.tt/VMThCIB
Submitted September 04, 2023 at 01:44AM by nareksays
via reddit https://ift.tt/mAiPV8r
Deform
China-linked Cybercriminals Bypass Barracuda's Security Patch - Deform
Barracuda email security gateway devices became the target of a cyber espionage attack from a group with ties to China, known as UNC4841. This group managed
WordPress website fingerprint techniques
https://ift.tt/ngGvuB7
Submitted September 04, 2023 at 01:37PM by theMiddleBlue
via reddit https://ift.tt/FqhoTvQ
https://ift.tt/ngGvuB7
Submitted September 04, 2023 at 01:37PM by theMiddleBlue
via reddit https://ift.tt/FqhoTvQ
Sicuranext Blog
How attackers fingerprint your WordPress website
Attackers have quite a few sneaky ways to gather information from your WordPress website. They can get their hands on details like the WordPress version you're using, the active plugins and their versions, and even info about your active users. In this article…
Microsoft Edge Forensics: Screenshot History
https://ift.tt/olZncUd
Submitted September 04, 2023 at 01:08PM by OwnPreparation3424
via reddit https://ift.tt/pF50ly9
https://ift.tt/olZncUd
Submitted September 04, 2023 at 01:08PM by OwnPreparation3424
via reddit https://ift.tt/pF50ly9
Medium
Microsoft Edge Forensics: Screenshot History
According to a recent article on Neowin, Microsoft Edge has a new feature that allows it to take screenshots of every web page a user…
Arbitrary Configuration Injection 💉 (intro)
https://ift.tt/7jcTYfy
Submitted September 04, 2023 at 02:25PM by Sim4n6
via reddit https://ift.tt/i23FnlB
https://ift.tt/7jcTYfy
Submitted September 04, 2023 at 02:25PM by Sim4n6
via reddit https://ift.tt/i23FnlB
Query Chronicles
Arbitrary Configuration Injection
A full report of penetration test of OPNsense (an open source, FreeBSD based firewall and routing platform).
https://ift.tt/ti5G4JI
Submitted September 04, 2023 at 06:29PM by logicaltrust-net
via reddit https://ift.tt/wtjhHnO
https://ift.tt/ti5G4JI
Submitted September 04, 2023 at 06:29PM by logicaltrust-net
via reddit https://ift.tt/wtjhHnO
Pwn2Own contest offers $1M in cash and prizes for hacking cars
https://ift.tt/MVlJxgO
Submitted September 04, 2023 at 08:28PM by nhavag
via reddit https://ift.tt/tYA6L4f
https://ift.tt/MVlJxgO
Submitted September 04, 2023 at 08:28PM by nhavag
via reddit https://ift.tt/tYA6L4f
Useful resources for SOC Analyst and SOC Analyst candidates.
https://ift.tt/cEwxLKC
Submitted September 04, 2023 at 08:43PM by ogunal00
via reddit https://ift.tt/vqlzSti
https://ift.tt/cEwxLKC
Submitted September 04, 2023 at 08:43PM by ogunal00
via reddit https://ift.tt/vqlzSti
GitHub
GitHub - LetsDefend/awesome-soc-analyst: Useful resources for SOC Analyst and SOC Analyst candidates.
Useful resources for SOC Analyst and SOC Analyst candidates. - GitHub - LetsDefend/awesome-soc-analyst: Useful resources for SOC Analyst and SOC Analyst candidates.
Using Open Source Software Composition Analysis Tool From Google. Presenting the usage of the osv-scanner tool in real-life Python and Java projects. A tool review with pros and cons.
https://ift.tt/Xx5uWhH
Submitted September 04, 2023 at 11:05PM by theowni
via reddit https://ift.tt/woiDvS2
https://ift.tt/Xx5uWhH
Submitted September 04, 2023 at 11:05PM by theowni
via reddit https://ift.tt/woiDvS2
Medium
Using Open-Source Software Composition Analysis Tool From Google
Presenting the usage of the osv-scanner tool from Google in real-life Python and Java projects. A tool review with its pros and cons.
Nascent Malware Campaign Targets npm, PyPI, and RubyGems Developers
https://ift.tt/R7uW1hi
Submitted September 05, 2023 at 12:27AM by louis11
via reddit https://ift.tt/Jf32kxe
https://ift.tt/R7uW1hi
Submitted September 05, 2023 at 12:27AM by louis11
via reddit https://ift.tt/Jf32kxe
Phylum
Malware targets Python, Ruby and Javanoscript Developers
Phylum has identified a malware campaign spanning PyPI, npm and RubyGems. Delivering early stage malware to users.
Uncovering Web Cache Deception: A Missed Vulnerability in the Most Unexpected Places
https://ift.tt/AEjCxYS
Submitted September 05, 2023 at 03:30AM by vikzsharma
via reddit https://ift.tt/Uxf96Ts
https://ift.tt/AEjCxYS
Submitted September 05, 2023 at 03:30AM by vikzsharma
via reddit https://ift.tt/Uxf96Ts
Agilehunt
Uncovering Web Cache Deception: A Missed Vulnerability in the Most Unexpected Places
VULNERABILITY DESCRIPTION
This vulnerability involves a Web Cache Deception attack targeting the https://redacted.com/anynonexisting URL endpoint. By manipulating the caching mechanisms, unauthorized users can gain access to sensitive Personally Identifiable…
This vulnerability involves a Web Cache Deception attack targeting the https://redacted.com/anynonexisting URL endpoint. By manipulating the caching mechanisms, unauthorized users can gain access to sensitive Personally Identifiable…
Chepy 6.0.0 released with lots of new changes, capabilities etc. Cyberchef in pure python
https://ift.tt/uPQRjaT
Submitted September 05, 2023 at 05:57AM by securisec
via reddit https://ift.tt/QU1DfGM
https://ift.tt/uPQRjaT
Submitted September 05, 2023 at 05:57AM by securisec
via reddit https://ift.tt/QU1DfGM
GitHub
GitHub - securisec/chepy: Chepy is a python lib/cli equivalent of the awesome CyberChef tool.
Chepy is a python lib/cli equivalent of the awesome CyberChef tool. - GitHub - securisec/chepy: Chepy is a python lib/cli equivalent of the awesome CyberChef tool.
VulnHub Kioptrix Level 1.1 CTF Walkthrough - Step-by-step with Explanations
https://ift.tt/Bp8RmAD
Submitted September 05, 2023 at 10:42AM by kongwenbin
via reddit https://ift.tt/NFpoqT6
https://ift.tt/Bp8RmAD
Submitted September 05, 2023 at 10:42AM by kongwenbin
via reddit https://ift.tt/NFpoqT6
My Learning Journey
VulnHub Kioptrix Level 1.1 CTF Walkthrough - Step-by-step with Explanations - My Learning Journey
Setup Kioptrix 1.1 & start hacking, commenting & showing every step from recon, port scan, exploitation, privilege escalation & becoming root
When URL parsers disagree (CVE-2023-38633)
https://ift.tt/AeQsXgu
Submitted September 05, 2023 at 01:27PM by ScottContini
via reddit https://ift.tt/iUNWTyM
https://ift.tt/AeQsXgu
Submitted September 05, 2023 at 01:27PM by ScottContini
via reddit https://ift.tt/iUNWTyM
canva.dev
When URL parsers disagree (CVE-2023-38633) - Canva Engineering Blog
Discovery and walkthrough of CVE-2023-38633 in librnoscript, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path traversal.
LFI/RCE Vulnerability in WordPress Media Library Assistant Plugin - CVE-2023-4634 - Patrowl
https://ift.tt/IgOBvMy
Submitted September 05, 2023 at 01:52PM by Pepito_oh
via reddit https://ift.tt/fqhSzOJ
https://ift.tt/IgOBvMy
Submitted September 05, 2023 at 01:52PM by Pepito_oh
via reddit https://ift.tt/fqhSzOJ
Patrowl
External Exposure Management as a Service | Patrowl - Patrowl
Identify and harden your External Security Posture with the leader. Let us manage time-consuming tasks and focus on remediation
Improving nmap's service scanning accuracy and speed with nmap-service-probes data
https://ift.tt/IuydGWU
Submitted September 05, 2023 at 03:54PM by MegaManSec2
via reddit https://ift.tt/S6AJwr9
https://ift.tt/IuydGWU
Submitted September 05, 2023 at 03:54PM by MegaManSec2
via reddit https://ift.tt/S6AJwr9
Joshua.Hu
Improve nmap’s service scanning with this 1 weird trick!
In my past two blog posts, I’ve explored how to combine multiple port scanning tools to create a fast service scanning tool for large networks, and how I sped up nmap’s service scanning by changing its “wait for content” time. In this post, I’m going to be…
Analysis of a new Facebook profile stealer written in Node.js
https://ift.tt/viba2rX
Submitted September 05, 2023 at 05:07PM by nareksays
via reddit https://ift.tt/QUO51to
https://ift.tt/viba2rX
Submitted September 05, 2023 at 05:07PM by nareksays
via reddit https://ift.tt/QUO51to
Trend Micro
Analyzing a Facebook Profile Stealer Written in Node js
We analyze an information stealer written in Node.js, packaged into an executable, exfiltrated stolen data via both Telegram bot API and a C&C server, and employed GraphQL as a channel for C&C communication.
Live API Keys and Source Code Leaked in 4,500 of the Top Alexa Sites
https://ift.tt/wMmcTZX
Submitted September 05, 2023 at 09:58PM by Phorcez
via reddit https://ift.tt/2w0ZWho
https://ift.tt/wMmcTZX
Submitted September 05, 2023 at 09:58PM by Phorcez
via reddit https://ift.tt/2w0ZWho
Truffle Security
4,500 of the Top 1 Million Websites Leaked Source Code, Secrets - Truffle Security
TruffleHog scanned the top 1 Million visited websites and discovered 4,500 exposed git directories and hundreds of leaked API keys + secrets.
Flaws in IBM Security Verify allows hackers to steal sensitive information
https://ift.tt/AacoeGd
Submitted September 05, 2023 at 09:47PM by nareksays
via reddit https://ift.tt/F24vOuS
https://ift.tt/AacoeGd
Submitted September 05, 2023 at 09:47PM by nareksays
via reddit https://ift.tt/F24vOuS
V9BET
V9BET - Trang cá cược thể thao uy tín, an toàn bậc nhất
V9BET là địa chỉ chơi game online chất lượng hàng đầu tại Việt Nam hiện nay. Mọi thể loại cá cược đều có tại sân chơi. Hãy nhấp link này để khám phá thêm.
Android 14 blocks all modification of system certificates, even as root
https://ift.tt/gUTfzbD
Submitted September 06, 2023 at 03:24AM by pi3ch
via reddit https://ift.tt/B3h0j2U
https://ift.tt/gUTfzbD
Submitted September 06, 2023 at 03:24AM by pi3ch
via reddit https://ift.tt/B3h0j2U
Httptoolkit
Android 14 blocks modification of system certificates, even as root
Update: This post sparked a lot of excellent discussion and debate on workarounds, and there are now multple working solutions to allow certificate injection...
Peeking under the bonnet of the Litter Robot 3
https://ift.tt/tsJm5TN
Submitted September 06, 2023 at 07:17AM by thinkV
via reddit https://ift.tt/M3Y8DSI
https://ift.tt/tsJm5TN
Submitted September 06, 2023 at 07:17AM by thinkV
via reddit https://ift.tt/M3Y8DSI
Elttam
RE of LR3
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
Lord Of The Ring0 part 5 is out (kernel development series)
https://ift.tt/1laR4Td
Submitted September 06, 2023 at 11:04AM by Idov31
via reddit https://ift.tt/pDIOmzo
https://ift.tt/1laR4Td
Submitted September 06, 2023 at 11:04AM by Idov31
via reddit https://ift.tt/pDIOmzo
idov31.github.io
Lord Of The Ring0 - Part 5 | Saruman's Manipulation - Ido Veltzman - Security Blog
PrologueIn the last blog post, we learned about the different types of kernel callbacks and created our registry protector driver.In this blog post, I’ll exp...