New vulnerabilities disclosed in Ivanti EPM
https://ift.tt/uwhjE9V
Submitted September 07, 2023 at 10:24PM by jrozner
via reddit https://ift.tt/Ji0U5AH
https://ift.tt/uwhjE9V
Submitted September 07, 2023 at 10:24PM by jrozner
via reddit https://ift.tt/Ji0U5AH
Yahooinc
Paranoids Vulnerability Research: Ivanti Issues Security Alert | Paranoids | Yahoo Inc.
Nagios Plugins: Hacking Monitored Servers with check_by_ssh and Argument Injection: CVE-2023-37154
https://ift.tt/Qd0BJeM
Submitted September 08, 2023 at 04:01AM by MegaManSec2
via reddit https://ift.tt/DQY0yn1
https://ift.tt/Qd0BJeM
Submitted September 08, 2023 at 04:01AM by MegaManSec2
via reddit https://ift.tt/DQY0yn1
Joshua.Hu
Nagios Plugins: Hacking Monitored Servers with check_by_ssh and Argument Injection: CVE-2023-37154
Nagios-compatible systems are some of the most widely used infrastructure monitoring solutions. They use “plugins” to monitor server performance, with “Nagios Core” interpreting results. However, there’s a potentially significant security issue with Nagios…
BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
https://ift.tt/T4CJMBt
Submitted September 08, 2023 at 05:42AM by Frostlike2816
via reddit https://ift.tt/8ypEvmq
https://ift.tt/T4CJMBt
Submitted September 08, 2023 at 05:42AM by Frostlike2816
via reddit https://ift.tt/8ypEvmq
The Citizen Lab
BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild - The Citizen Lab
Citizen Lab found an actively exploited zero-click vulnerability being used to deliver NSO Group’s Pegasus mercenary spyware while checking the device of an individual employed by a Washington DC-based civil society organization with international offices. We…
Orbeon Forms: The Final Form? On A Journey To RCE 0day
https://ift.tt/qXsWxyQ
Submitted September 08, 2023 at 09:47AM by dx7r__
via reddit https://ift.tt/1Iz5uQn
https://ift.tt/qXsWxyQ
Submitted September 08, 2023 at 09:47AM by dx7r__
via reddit https://ift.tt/1Iz5uQn
watchTowr Labs - Blog
Orbeon Forms: The Final Form? On A Journey To RCE
When software is introduced as the solution used by “Enterprises and Governments”, it is almost rude of us not to engage further and see how terrifying everything becomes.
One of our key missions at watchTowr is to review large amounts of data and extract…
One of our key missions at watchTowr is to review large amounts of data and extract…
How to DoS iOS devices with Bluetooth pairing messages using Android
https://ift.tt/DARrsxE
Submitted September 08, 2023 at 12:18PM by barakadua131
via reddit https://ift.tt/pqFB1cM
https://ift.tt/DARrsxE
Submitted September 08, 2023 at 12:18PM by barakadua131
via reddit https://ift.tt/pqFB1cM
Mobile Hacker
Spoof iOS devices with Bluetooth pairing messages using Android - Mobile Hacker
[update 09.10.2023] In this update, I will share how to extend the signal of Android nRF Connect app that can send pairing messages, demonstrate AppleJuice on the latest iOS 17, show which specific advertisement packet can trigger pop-ups from up to 50 meters…
⚠️CVE-2023-3959, CVE-2023-4249 - Multiple critical vulnerabilities in Zavio IP cameras (34 RCEs total, including 7 pre-auth BoFs)
https://ift.tt/zBwlETv
Submitted September 08, 2023 at 01:21PM by attilaszia
via reddit https://ift.tt/olXcAJh
https://ift.tt/zBwlETv
Submitted September 08, 2023 at 01:21PM by attilaszia
via reddit https://ift.tt/olXcAJh
Bugprove
CVE-2023-3959, CVE-2023-4249 - Multiple critical vulnerabilities in Zavio IP cameras
BugProve uncovers seven pre-authentication remote code execution flaws and 26 post-authentication code execution vectors in Zavio IP cameras. Despite repeated warnings, Zavio remained unresponsive, necessitating intervention from CISA.
Bcrypt at 25: A retrospective on password security
https://ift.tt/rKXGeCN
Submitted September 08, 2023 at 04:56PM by ScottContini
via reddit https://ift.tt/Q0IjGib
https://ift.tt/rKXGeCN
Submitted September 08, 2023 at 04:56PM by ScottContini
via reddit https://ift.tt/Q0IjGib
APNIC Blog
bcrypt at 25: A retrospective on password security | APNIC Blog
Guest Post: Examining the history of password security and how it's shaping the future.
New Website that teaches Ethical Hacking & Security - Feedback? **LOOKING FOR WEB DEVS WITH SECURITY KNOWLEDGE & DIGITAL MARKETERS TO GROW WEBSITE**
http://hackblue.org
Submitted September 09, 2023 at 04:34AM by william150_
via reddit https://ift.tt/H6Fx15A
http://hackblue.org
Submitted September 09, 2023 at 04:34AM by william150_
via reddit https://ift.tt/H6Fx15A
Cybercriminals target Windows Advanced Installer to run crypto-mining malware
https://ift.tt/TYU7Mpi
Submitted September 08, 2023 at 11:46PM by nareksays
via reddit https://ift.tt/vqGBzUk
https://ift.tt/TYU7Mpi
Submitted September 08, 2023 at 11:46PM by nareksays
via reddit https://ift.tt/vqGBzUk
Cisco Talos Blog
Cybercriminals target graphic designers with GPU miners
Cybercriminals are abusing Advanced Installer, a legitimate Windows tool used for creating software packages, to drop cryptocurrency-mining malware including PhoenixMiner and lolMiner on infected machines.
Azure Incident Response Cheat Sheet (PDF)
https://ift.tt/jwZr19K
Submitted September 09, 2023 at 06:16PM by 0x636f6f6c
via reddit https://ift.tt/ohnVdHB
https://ift.tt/jwZr19K
Submitted September 09, 2023 at 06:16PM by 0x636f6f6c
via reddit https://ift.tt/ohnVdHB
Rustproofing Linux (Part 1/4 Leaking Addresses)
https://ift.tt/GQv4w3X
Submitted September 10, 2023 at 04:32AM by meowerguy
via reddit https://ift.tt/cHPTW34
https://ift.tt/GQv4w3X
Submitted September 10, 2023 at 04:32AM by meowerguy
via reddit https://ift.tt/cHPTW34
NCC Group Research Blog
Rustproofing Linux (Part 1/4 Leaking Addresses)
Rust is a programming language guaranteeing memory and thread safety while still being able to access raw memory and hardware. This sounds impossible, and it is, that’s why Rust has an unsafe keywo…
“MrTonyScam” — Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts
https://ift.tt/QIJBNCE
Submitted September 10, 2023 at 04:35PM by lowlet3443
via reddit https://ift.tt/1CvA5mb
https://ift.tt/QIJBNCE
Submitted September 10, 2023 at 04:35PM by lowlet3443
via reddit https://ift.tt/1CvA5mb
Medium
“MrTonyScam” — Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts
By Oleg Zaytsev (Guardio Labs)
How to Import and Stack Data Using Python Pandas and Jupyter Notebooks
https://ift.tt/BgqG6sm
Submitted September 10, 2023 at 05:17PM by m_edmondson
via reddit https://ift.tt/3GsZIW7
https://ift.tt/BgqG6sm
Submitted September 10, 2023 at 05:17PM by m_edmondson
via reddit https://ift.tt/3GsZIW7
The Threat Hunter's Dilemma
How to Import and Stack Data Using Python Pandas and Jupyter Notebooks
An important tool in a threat hunter's tool belt.
GitHub - boringtools/git-alerts: A Public Git repository & misconfiguration detection tool
https://ift.tt/nt7RxBi
Submitted September 11, 2023 at 04:43PM by predev0x00
via reddit https://ift.tt/Tgq5mxG
https://ift.tt/nt7RxBi
Submitted September 11, 2023 at 04:43PM by predev0x00
via reddit https://ift.tt/Tgq5mxG
GitHub
GitHub - boringtools/git-alerts: Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files
Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files - GitHub - boringtools/git-alerts: Tool to detect and monitor GitHub org users' publ...
HijackLoader: a new malware downloader with modular architecture
https://ift.tt/wfWpqXP
Submitted September 11, 2023 at 06:46PM by nareksays
via reddit https://ift.tt/MeOUmaK
https://ift.tt/wfWpqXP
Submitted September 11, 2023 at 06:46PM by nareksays
via reddit https://ift.tt/MeOUmaK
Zscaler
Technical Analysis of HijackLoader | Zscaler
HijackLoader | Learn its tactics, evasion techniques, and modular architecture in our in-depth analysis.
Unmanaged Devices Run Rampant in 47% of Companies
https://ift.tt/HiK07uf
Submitted September 12, 2023 at 12:44AM by KolideKenny
via reddit https://ift.tt/mUS6gpO
https://ift.tt/HiK07uf
Submitted September 12, 2023 at 12:44AM by KolideKenny
via reddit https://ift.tt/mUS6gpO
Kolide
Unmanaged Devices Run Rampant in 47% of Companies
New research shows that employees access sensitive data on personal devices–
often to get around security.
often to get around security.
Activation Context Hell - DosDevices Remapping Attack under Impersonation
https://ift.tt/KaksQcu
Submitted September 12, 2023 at 12:33AM by hacksysteam
via reddit https://ift.tt/IhwSLAR
https://ift.tt/KaksQcu
Submitted September 12, 2023 at 12:33AM by hacksysteam
via reddit https://ift.tt/IhwSLAR
The Growing Threat of Insider Attacks
https://ift.tt/adiTOAS
Submitted September 12, 2023 at 09:49AM by OkPossible7152
via reddit https://ift.tt/hn45woZ
https://ift.tt/adiTOAS
Submitted September 12, 2023 at 09:49AM by OkPossible7152
via reddit https://ift.tt/hn45woZ
Virtual Cybersecurit
Unseen Predators: The Growing Threat of Insider Attacks in Cybersecurity
Explore the growing threat of insider attacks in the realm of cybersecurity. From defining what constitutes an insider threat, its various types, to strategies for mitigating such risks, this comprehensive guide covers all aspects of this pressing issue.…
Exploring Cloud Security: Safeguarding Your Digital Assets in Cloud
https://ift.tt/TJVl9I6
Submitted September 12, 2023 at 11:19AM by Icy-Avocado-1634
via reddit https://ift.tt/gjwuvhA
https://ift.tt/TJVl9I6
Submitted September 12, 2023 at 11:19AM by Icy-Avocado-1634
via reddit https://ift.tt/gjwuvhA
Medium
Exploring Cloud Security — Safeguarding Your Digital Assets in the Cloud
Cloud Security Explained for Businesses- How it Plays a Pivotal Role in Ensuring the Confidentiality, of Your Company Data
Analyzing Security Vulnerabilities in XWiki: In-Depth Examination
https://ift.tt/6ZAIBpr
Submitted September 12, 2023 at 06:19PM by appsec1337
via reddit https://ift.tt/ucmS0pq
https://ift.tt/6ZAIBpr
Submitted September 12, 2023 at 06:19PM by appsec1337
via reddit https://ift.tt/ucmS0pq
Penetration Testing and CyberSecurity Solution - SecureLayer7
Analyzing Security Vulnerabilities in XWiki: In-Depth Examination
XWiki is an open-source knowledge repository which is primarily meant for enterprise use, i.e. intra-company knowledge storage and sharing. As per its website, XWiki is a "second generation" wiki,...
Blog Patrowl: OmniSpace, from automated 0day XSS to RCE by @Pepito_oh
https://ift.tt/dtF8sh9
Submitted September 12, 2023 at 06:36PM by MaKyOtOx
via reddit https://ift.tt/wGUt7gP
https://ift.tt/dtF8sh9
Submitted September 12, 2023 at 06:36PM by MaKyOtOx
via reddit https://ift.tt/wGUt7gP
External Exposure Management as a Service
External Exposure Management as a Service | Patrowl
Identify and harden your External Security Posture with the leader. Let us manage time-consuming tasks and focus on remediation