Peeking under the bonnet of the Litter Robot 3
https://ift.tt/tsJm5TN
Submitted September 06, 2023 at 07:17AM by thinkV
via reddit https://ift.tt/M3Y8DSI
https://ift.tt/tsJm5TN
Submitted September 06, 2023 at 07:17AM by thinkV
via reddit https://ift.tt/M3Y8DSI
Elttam
RE of LR3
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
Lord Of The Ring0 part 5 is out (kernel development series)
https://ift.tt/1laR4Td
Submitted September 06, 2023 at 11:04AM by Idov31
via reddit https://ift.tt/pDIOmzo
https://ift.tt/1laR4Td
Submitted September 06, 2023 at 11:04AM by Idov31
via reddit https://ift.tt/pDIOmzo
idov31.github.io
Lord Of The Ring0 - Part 5 | Saruman's Manipulation - Ido Veltzman - Security Blog
PrologueIn the last blog post, we learned about the different types of kernel callbacks and created our registry protector driver.In this blog post, I’ll exp...
Looking for someone learn from
https://ift.tt/tAS6TLr
Submitted September 06, 2023 at 01:35PM by Puzzleheaded_Cut_273
via reddit https://ift.tt/Kwe0xGX
https://ift.tt/tAS6TLr
Submitted September 06, 2023 at 01:35PM by Puzzleheaded_Cut_273
via reddit https://ift.tt/Kwe0xGX
How to Write a Secure JWT Library If You Absolutely Must
https://ift.tt/ngrAWoe
Submitted September 06, 2023 at 01:58PM by sarciszewski
via reddit https://ift.tt/C1ZYepT
https://ift.tt/ngrAWoe
Submitted September 06, 2023 at 01:58PM by sarciszewski
via reddit https://ift.tt/C1ZYepT
Semantically Secure
How to Write a Secure JWT Library If You Absolutely Must
I am famously not a fan of JSON Web Tokens (JWT). Like most cryptography and security experts familiar with JWT, I would much rather you use something else if you can. I even proposed a secure alte…
XSS vulnerability in Proton Mail allowed to leak unencrypted emails
https://ift.tt/ua3rwkV
Submitted September 06, 2023 at 03:14PM by SonarPaul
via reddit https://ift.tt/z2NF4kP
https://ift.tt/ua3rwkV
Submitted September 06, 2023 at 03:14PM by SonarPaul
via reddit https://ift.tt/z2NF4kP
Sonarsource
Code Vulnerabilities Put Proton Mails at Risk
The Sonar Research team discovered critical code vulnerabilities in Proton Mail, Skiff and Tutanota. This post covers the technical details of the XSS vulnerability in Proton Mail.
eBPF Offensive Capabilities
https://ift.tt/gGxkl7K
Submitted September 06, 2023 at 07:08PM by weseven
via reddit https://ift.tt/6fnUBgs
https://ift.tt/gGxkl7K
Submitted September 06, 2023 at 07:08PM by weseven
via reddit https://ift.tt/6fnUBgs
Sysdig
eBPF Offensive Capabilities - Get Ready for Next-gen Malware
In this article, we will explore some of the offensive capabilities that eBPF can provide to an attacker and how to defend against them.
Apache Superset Part II: RCE, Credential Harvesting and More
https://ift.tt/OnTc5rA
Submitted September 06, 2023 at 08:13PM by scopedsecurity
via reddit https://ift.tt/41Hxndk
https://ift.tt/OnTc5rA
Submitted September 06, 2023 at 08:13PM by scopedsecurity
via reddit https://ift.tt/41Hxndk
Horizon3.ai
Apache Superset Part II: RCE, Credential Harvesting and More – Horizon3.ai
Apache Superset is a popular open source data exploration and visualization tool. In a previous post, we disclosed a vulnerability, CVE-2023-27524, affecting thousands of Superset servers on the Internet, that […]
Main Analytical Frameworks for CTI
https://ift.tt/ftZR1dn
Submitted September 06, 2023 at 08:04PM by ziyahanalbeniz
via reddit https://ift.tt/5G3hxMz
https://ift.tt/ftZR1dn
Submitted September 06, 2023 at 08:04PM by ziyahanalbeniz
via reddit https://ift.tt/5G3hxMz
SOCRadar® Cyber Intelligence Inc.
Main Analytical Frameworks for Cyber Threat Intelligence
Threat intelligence is a cyber-security discipline focusing on detailed knowledge about the cyber threats targeting an organization. Threat...
Dissect : hi all looking for command dissect framework : how can i export image file or just it. how can check hash for hidden file or restore file, i try it by going true the documation but i could'nt found the correct way thanks :)
https://ift.tt/K87R5mT
Submitted September 06, 2023 at 10:30PM by SULeI_man
via reddit https://ift.tt/liVtaJo
https://ift.tt/K87R5mT
Submitted September 06, 2023 at 10:30PM by SULeI_man
via reddit https://ift.tt/liVtaJo
DogeRAT malware targets Indian users (tracks Locations, makes illegal payments, and more)
https://ift.tt/kavyE7F
Submitted September 06, 2023 at 10:08PM by nareksays
via reddit https://ift.tt/zvJtSf4
https://ift.tt/kavyE7F
Submitted September 06, 2023 at 10:08PM by nareksays
via reddit https://ift.tt/zvJtSf4
Deform
DogeRAT Malware Strikes India: Tracks Locations, Makes Unauthorized Payments - Deform
Indian Android users are under threat from DogeRAT, a malicious software that illicitly accesses critical data, including banking information, contacts, and
Results of Major Technical Investigations for Storm-0558 Key Acquisition (How a threat actor acquired and used a Microsoft signing key to access customer emails)
https://ift.tt/zjtQLv8
Submitted September 07, 2023 at 12:25AM by The_Electric_Feel
via reddit https://ift.tt/8Z4OKak
https://ift.tt/zjtQLv8
Submitted September 07, 2023 at 12:25AM by The_Electric_Feel
via reddit https://ift.tt/8Z4OKak
Microsoft
Results of Major Technical Investigations for Storm-0558 Key Acquisition | MSRC Blog
| Microsoft Security Response Center
| Microsoft Security Response Center
A tale about a Red Team exercise and the Forcepoint Endpoint One DLP client - vsociety
https://ift.tt/u1UzGXS
Submitted September 07, 2023 at 03:46AM by k4m1ll0
via reddit https://ift.tt/w5tnp7u
https://ift.tt/u1UzGXS
Submitted September 07, 2023 at 03:46AM by k4m1ll0
via reddit https://ift.tt/w5tnp7u
www.vicarius.io
A tale about a Red Team exercise and the Forcepoint Endpoint One DLP client - vsociety
Mastering Third Party Risk Assessments: A Detailed Guide
https://ift.tt/1O4PaFo
Submitted September 07, 2023 at 07:54AM by OkPossible7152
via reddit https://ift.tt/Hg67pLN
https://ift.tt/1O4PaFo
Submitted September 07, 2023 at 07:54AM by OkPossible7152
via reddit https://ift.tt/Hg67pLN
Virtual Cybersecurit
Mastering Third Party Risk Assessments: A Detailed Guide
Steps for Conducting a Third-Party Risk Assessment: Define Assessment Criteria (NIST Framework Integration): Tailoring NIST's Cybersecurity Framework to your organization's specific needs is crucial when defining assessment criteria. These criteria encompass…
Next-Generation Context Aware Password Cracking
https://ift.tt/HcVGReC
Submitted September 07, 2023 at 08:33AM by Exact-Practice-8658
via reddit https://ift.tt/xwdtXBI
https://ift.tt/HcVGReC
Submitted September 07, 2023 at 08:33AM by Exact-Practice-8658
via reddit https://ift.tt/xwdtXBI
Medium
Next-Generation Context Aware Password Cracking
With Chat GPT, passwords are going to get worse
Annoying Apple Fans: The Flipper Zero Bluetooth Prank Revealed
https://ift.tt/zwl0EtK
Submitted September 07, 2023 at 10:35AM by Fabse333
via reddit https://ift.tt/xUmy3sw
https://ift.tt/zwl0EtK
Submitted September 07, 2023 at 10:35AM by Fabse333
via reddit https://ift.tt/xUmy3sw
⚠️⚠️⚠️ CVE-2023-3959, CVE-2023-4249 - Multiple critical vulnerabilities in Zavio IP cameras (34 RCEs total, including 7 pre-auth BoFs)
https://ift.tt/zBwlETv
Submitted September 07, 2023 at 05:05PM by attilaszia
via reddit https://ift.tt/a4M0G8p
https://ift.tt/zBwlETv
Submitted September 07, 2023 at 05:05PM by attilaszia
via reddit https://ift.tt/a4M0G8p
Bugprove
CVE-2023-3959, CVE-2023-4249 - Multiple critical vulnerabilities in Zavio IP cameras
BugProve uncovers seven pre-authentication remote code execution flaws and 26 post-authentication code execution vectors in Zavio IP cameras. Despite repeated warnings, Zavio remained unresponsive, necessitating intervention from CISA.
Event Likelihood Scoring Model
https://ift.tt/p9UVGhC
Submitted September 07, 2023 at 07:32PM by OkPossible7152
via reddit https://ift.tt/FyDEHvi
https://ift.tt/p9UVGhC
Submitted September 07, 2023 at 07:32PM by OkPossible7152
via reddit https://ift.tt/FyDEHvi
Boot Unguarded: x86 Trust Anchor Downfalls to The Leaked OEM Internal Tools and Signing Keys
https://ift.tt/zv0WKAi
Submitted September 07, 2023 at 08:55PM by hardenedvault
via reddit https://ift.tt/bMYVoFA
https://ift.tt/zv0WKAi
Submitted September 07, 2023 at 08:55PM by hardenedvault
via reddit https://ift.tt/bMYVoFA
hardenedlinux.org
Boot Unguarded: x86 Trust Anchor Downfalls to The Leaked OEM Internal Tools and Signing Keys
By Hardcore Matrix
One “Leak” can rule them all! In March 2023, Micro-Star International (MSI) suffered a significant attack orchestrated by the Money Message ransomware group. Unfortunately, this is not just another random leak. The aftermath revealed a…
One “Leak” can rule them all! In March 2023, Micro-Star International (MSI) suffered a significant attack orchestrated by the Money Message ransomware group. Unfortunately, this is not just another random leak. The aftermath revealed a…
New vulnerabilities disclosed in Ivanti EPM
https://ift.tt/uwhjE9V
Submitted September 07, 2023 at 10:24PM by jrozner
via reddit https://ift.tt/Ji0U5AH
https://ift.tt/uwhjE9V
Submitted September 07, 2023 at 10:24PM by jrozner
via reddit https://ift.tt/Ji0U5AH
Yahooinc
Paranoids Vulnerability Research: Ivanti Issues Security Alert | Paranoids | Yahoo Inc.
Nagios Plugins: Hacking Monitored Servers with check_by_ssh and Argument Injection: CVE-2023-37154
https://ift.tt/Qd0BJeM
Submitted September 08, 2023 at 04:01AM by MegaManSec2
via reddit https://ift.tt/DQY0yn1
https://ift.tt/Qd0BJeM
Submitted September 08, 2023 at 04:01AM by MegaManSec2
via reddit https://ift.tt/DQY0yn1
Joshua.Hu
Nagios Plugins: Hacking Monitored Servers with check_by_ssh and Argument Injection: CVE-2023-37154
Nagios-compatible systems are some of the most widely used infrastructure monitoring solutions. They use “plugins” to monitor server performance, with “Nagios Core” interpreting results. However, there’s a potentially significant security issue with Nagios…
BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
https://ift.tt/T4CJMBt
Submitted September 08, 2023 at 05:42AM by Frostlike2816
via reddit https://ift.tt/8ypEvmq
https://ift.tt/T4CJMBt
Submitted September 08, 2023 at 05:42AM by Frostlike2816
via reddit https://ift.tt/8ypEvmq
The Citizen Lab
BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild - The Citizen Lab
Citizen Lab found an actively exploited zero-click vulnerability being used to deliver NSO Group’s Pegasus mercenary spyware while checking the device of an individual employed by a Washington DC-based civil society organization with international offices. We…