mXSS in Skiff: How browser mutations and Cloudflare helped to steal decrypted emails
https://ift.tt/ScKWRFd
Submitted September 13, 2023 at 02:09PM by SonarPaul
via reddit https://ift.tt/9xeHmjs
https://ift.tt/ScKWRFd
Submitted September 13, 2023 at 02:09PM by SonarPaul
via reddit https://ift.tt/9xeHmjs
Sonarsource
Code Vulnerabilities Put Skiff Emails at Risk
Our Research team discovered critical code vulnerabilities in Proton Mail, Skiff, and Tutanota. This post covers the technical details of the XSS vulnerability in Skiff.
Compile it ⚙️ , Debug it 🔬 , Hack it 😎 it's the Linux kernel 🐧 - vsociety
https://ift.tt/z5VLPct
Submitted September 13, 2023 at 06:34PM by vsociety_
via reddit https://ift.tt/6YQyfV3
https://ift.tt/z5VLPct
Submitted September 13, 2023 at 06:34PM by vsociety_
via reddit https://ift.tt/6YQyfV3
www.vicarius.io
Compile it ⚙️ , Debug it 🔬 , Hack it 😎 it's the Linux kernel 🐧 - vsociety
CVE-2023-38146: Arbitrary Code Execution via Windows Themes
https://ift.tt/oz9qmk1
Submitted September 13, 2023 at 10:25PM by gabe_k
via reddit https://ift.tt/rYpgdCR
https://ift.tt/oz9qmk1
Submitted September 13, 2023 at 10:25PM by gabe_k
via reddit https://ift.tt/rYpgdCR
3AM: New Ransomware Family Used As Fallback in Failed LockBit Attack
https://ift.tt/scAldWq
Submitted September 13, 2023 at 09:36PM by nareksays
via reddit https://ift.tt/YSAdtpI
https://ift.tt/scAldWq
Submitted September 13, 2023 at 09:36PM by nareksays
via reddit https://ift.tt/YSAdtpI
Security
3AM: New Ransomware Family Used As Fallback in Failed LockBit Attack
Attackers resorted to new ransomware after deployment of LockBit was blocked on targeted network.
Split BloodHound input files to prevent import failures
https://ift.tt/1gjlG3v
Submitted September 14, 2023 at 01:34PM by Pleasant-Drawer729
via reddit https://ift.tt/n1l9uj3
https://ift.tt/1gjlG3v
Submitted September 14, 2023 at 01:34PM by Pleasant-Drawer729
via reddit https://ift.tt/n1l9uj3
GitHub
GitHub - Syslifters/split-bloodhound
Contribute to Syslifters/split-bloodhound development by creating an account on GitHub.
Top 10 Facts About MOVEit Breach
https://ift.tt/gyPBZJw
Submitted September 14, 2023 at 12:42PM by ziyahanalbeniz
via reddit https://ift.tt/KYXMIeB
https://ift.tt/gyPBZJw
Submitted September 14, 2023 at 12:42PM by ziyahanalbeniz
via reddit https://ift.tt/KYXMIeB
SOCRadar® Cyber Intelligence Inc.
Top 10 Facts About MOVEit Breach
In this article, we delve into the top 10 facts about the MOVEit breach, shedding light on its magnitude, the perpetrators behind it, and...
Column-Level Encryption 101: What is It, implementation & Benefits
https://ift.tt/yNbKCXz
Submitted September 14, 2023 at 01:54PM by donofsue
via reddit https://ift.tt/FsH5kop
https://ift.tt/yNbKCXz
Submitted September 14, 2023 at 01:54PM by donofsue
via reddit https://ift.tt/FsH5kop
Piiano
Column-Level Encryption: Implementation & Benefits
Explore the advantages of column-level encryption and understand database encryption methods and related security implications.
BabelInkCrypt a python program that combines multiple methods to offer an infinite storage by storing it on YouTube and safe with an encryption method
https://ift.tt/pNKuQ3R
Submitted September 14, 2023 at 02:49PM by omnidotus
via reddit https://ift.tt/VxSyEtG
https://ift.tt/pNKuQ3R
Submitted September 14, 2023 at 02:49PM by omnidotus
via reddit https://ift.tt/VxSyEtG
GitHub
GitHub - youneshlal7/BabelInkCrypt: BabelInkCrypt is an open-source project that combines encryption, library of babel, and video…
BabelInkCrypt is an open-source project that combines encryption, library of babel, and video making to create a secure infinite storage system. - GitHub - youneshlal7/BabelInkCrypt: BabelInkCrypt ...
Simple PoC for demonstrating Race Conditions on Websockets
https://ift.tt/wpn174P
Submitted September 14, 2023 at 02:43PM by vah_13
via reddit https://ift.tt/5uCPsiW
https://ift.tt/wpn174P
Submitted September 14, 2023 at 02:43PM by vah_13
via reddit https://ift.tt/5uCPsiW
GitHub
GitHub - redrays-io/WS_RaceCondition_PoC: Simple PoC for demonstrating Race Conditions on Websockets
Simple PoC for demonstrating Race Conditions on Websockets - GitHub - redrays-io/WS_RaceCondition_PoC: Simple PoC for demonstrating Race Conditions on Websockets
The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree
https://ift.tt/DFn0COq
Submitted September 14, 2023 at 07:19PM by TupleType1
via reddit https://ift.tt/UR7GCxa
https://ift.tt/DFn0COq
Submitted September 14, 2023 at 07:19PM by TupleType1
via reddit https://ift.tt/UR7GCxa
Palo Alto Networks Blog
The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree
GitHub Actions worm compromises GitHub repositories via action dependencies in a novel attack vector allowing attackers to distribute malware across repositories, research shows.
Uncursing the ncurses: Memory corruption vulnerabilities found in library
https://ift.tt/ZTNDBQE
Submitted September 14, 2023 at 06:49PM by YogiBerra88888
via reddit https://ift.tt/oXsqbr4
https://ift.tt/ZTNDBQE
Submitted September 14, 2023 at 06:49PM by YogiBerra88888
via reddit https://ift.tt/oXsqbr4
Microsoft Security Blog
Uncursing the ncurses: Memory corruption vulnerabilities found in library | Microsoft Security Blog
A set of memory corruption vulnerabilities in the ncurses library could have allowed attackers to chain the vulnerabilities to elevate privileges and run code in the targeted program's context or perform other malicious actions.
Bypass SSL Pinning on Windows Application
https://ift.tt/WwR4LY6
Submitted September 15, 2023 at 02:29AM by HermaeusMora0
via reddit https://ift.tt/3xiwgKD
https://ift.tt/WwR4LY6
Submitted September 15, 2023 at 02:29AM by HermaeusMora0
via reddit https://ift.tt/3xiwgKD
Charlesproxy
Charles Web Debugging Proxy • HTTP Monitor / HTTP Proxy / HTTPS & SSL Proxy / Reverse Proxy
Charles Web Debugging Proxy - Official Site
Bypassing UAC with SSPI Datagram Contexts
https://ift.tt/94Nsb27
Submitted September 15, 2023 at 04:31AM by splinter_code
via reddit https://ift.tt/TbevwxR
https://ift.tt/94Nsb27
Submitted September 15, 2023 at 04:31AM by splinter_code
via reddit https://ift.tt/TbevwxR
Meta Quest 2: Defense through offense
https://ift.tt/svMuXrz
Submitted September 15, 2023 at 04:08PM by poltess0
via reddit https://ift.tt/X169ZkQ
https://ift.tt/svMuXrz
Submitted September 15, 2023 at 04:08PM by poltess0
via reddit https://ift.tt/X169ZkQ
Engineering at Meta
Meta Quest 2: Defense through offense
Meta’s Native Assurance team regularly performs manual code reviews as part of our ongoing commitment to improve the security posture of Meta’s products. In 2021, we discovered a vulnerability in …
A detailed analysis of the Money Message Ransomware
https://ift.tt/ZuKSR6y
Submitted September 15, 2023 at 06:33PM by CyberMasterV
via reddit https://ift.tt/GODaQkf
https://ift.tt/ZuKSR6y
Submitted September 15, 2023 at 06:33PM by CyberMasterV
via reddit https://ift.tt/GODaQkf
SecurityScorecard
Resources
Explore cybersecurity white papers, data sheets, webinars, videos, informative blogs, and more with SecurityScorecard.
Konni has entered the game: A new, possibly North Korean group exploits WinRAR vulnerability for cyberattacks.
https://ift.tt/xVYspz0
Submitted September 15, 2023 at 09:30PM by nareksays
via reddit https://ift.tt/jF1tPGB
https://ift.tt/xVYspz0
Submitted September 15, 2023 at 09:30PM by nareksays
via reddit https://ift.tt/jF1tPGB
Correction: the previous CA injection method doesn't work on Android 14, but there is still a way.
https://ift.tt/sIGXlc1
Submitted September 16, 2023 at 05:29AM by pi3ch
via reddit https://ift.tt/FpVcnNY
https://ift.tt/sIGXlc1
Submitted September 16, 2023 at 05:29AM by pi3ch
via reddit https://ift.tt/FpVcnNY
g1a55er::blog
Android 14 Still Allows Modification of System Certificates
Tim Perry recently claimed in an article that “Android 14 blocks all modification of system certificates, even as root”. This sparked significant discussion on Hacker News. Thankfully my tests show that it is still possible to adjust the system certificate…
New analysis tool: donut-decryptor: Retrieve inner payloads from Donut samples
https://ift.tt/legBFKD
Submitted September 16, 2023 at 08:49PM by transt
via reddit https://ift.tt/VGnKl9F
https://ift.tt/legBFKD
Submitted September 16, 2023 at 08:49PM by transt
via reddit https://ift.tt/VGnKl9F
GitHub
GitHub - volexity/donut-decryptor: Retrieve inner payloads from Donut samples
Retrieve inner payloads from Donut samples. Contribute to volexity/donut-decryptor development by creating an account on GitHub.
The bogus CVE problem
https://ift.tt/bBntavL
Submitted September 16, 2023 at 09:35PM by keissiaresa
via reddit https://ift.tt/B4tciEp
https://ift.tt/bBntavL
Submitted September 16, 2023 at 09:35PM by keissiaresa
via reddit https://ift.tt/B4tciEp
lwn.net
The bogus CVE problem
The "Common Vulnerabilities and
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Similar issues detected in different cryptocurrency exchange backends
https://ift.tt/9Goy5hK
Submitted September 16, 2023 at 10:40PM by arrowflakes
via reddit https://ift.tt/KdsJ08l
https://ift.tt/9Goy5hK
Submitted September 16, 2023 at 10:40PM by arrowflakes
via reddit https://ift.tt/KdsJ08l
CoinFabrik
Quality Assurance QA/QC backend in Cryptocurrency Exchanges
Explore the vital role of quality assurance (QA/QC) backend processes in cryptocurrency exchanges ensuring quality and reliability.
A Big Look at Security in OpenAPI
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
Liblab
OpenAPI Security: Five types & best practices
Explore OpenAPI security best practices. Learn the key methods and how they're implemented. See how liblab enhances SDK creation.