Bypassing UAC with SSPI Datagram Contexts
https://ift.tt/94Nsb27
Submitted September 15, 2023 at 04:31AM by splinter_code
via reddit https://ift.tt/TbevwxR
https://ift.tt/94Nsb27
Submitted September 15, 2023 at 04:31AM by splinter_code
via reddit https://ift.tt/TbevwxR
Meta Quest 2: Defense through offense
https://ift.tt/svMuXrz
Submitted September 15, 2023 at 04:08PM by poltess0
via reddit https://ift.tt/X169ZkQ
https://ift.tt/svMuXrz
Submitted September 15, 2023 at 04:08PM by poltess0
via reddit https://ift.tt/X169ZkQ
Engineering at Meta
Meta Quest 2: Defense through offense
Meta’s Native Assurance team regularly performs manual code reviews as part of our ongoing commitment to improve the security posture of Meta’s products. In 2021, we discovered a vulnerability in …
A detailed analysis of the Money Message Ransomware
https://ift.tt/ZuKSR6y
Submitted September 15, 2023 at 06:33PM by CyberMasterV
via reddit https://ift.tt/GODaQkf
https://ift.tt/ZuKSR6y
Submitted September 15, 2023 at 06:33PM by CyberMasterV
via reddit https://ift.tt/GODaQkf
SecurityScorecard
Resources
Explore cybersecurity white papers, data sheets, webinars, videos, informative blogs, and more with SecurityScorecard.
Konni has entered the game: A new, possibly North Korean group exploits WinRAR vulnerability for cyberattacks.
https://ift.tt/xVYspz0
Submitted September 15, 2023 at 09:30PM by nareksays
via reddit https://ift.tt/jF1tPGB
https://ift.tt/xVYspz0
Submitted September 15, 2023 at 09:30PM by nareksays
via reddit https://ift.tt/jF1tPGB
Correction: the previous CA injection method doesn't work on Android 14, but there is still a way.
https://ift.tt/sIGXlc1
Submitted September 16, 2023 at 05:29AM by pi3ch
via reddit https://ift.tt/FpVcnNY
https://ift.tt/sIGXlc1
Submitted September 16, 2023 at 05:29AM by pi3ch
via reddit https://ift.tt/FpVcnNY
g1a55er::blog
Android 14 Still Allows Modification of System Certificates
Tim Perry recently claimed in an article that “Android 14 blocks all modification of system certificates, even as root”. This sparked significant discussion on Hacker News. Thankfully my tests show that it is still possible to adjust the system certificate…
New analysis tool: donut-decryptor: Retrieve inner payloads from Donut samples
https://ift.tt/legBFKD
Submitted September 16, 2023 at 08:49PM by transt
via reddit https://ift.tt/VGnKl9F
https://ift.tt/legBFKD
Submitted September 16, 2023 at 08:49PM by transt
via reddit https://ift.tt/VGnKl9F
GitHub
GitHub - volexity/donut-decryptor: Retrieve inner payloads from Donut samples
Retrieve inner payloads from Donut samples. Contribute to volexity/donut-decryptor development by creating an account on GitHub.
The bogus CVE problem
https://ift.tt/bBntavL
Submitted September 16, 2023 at 09:35PM by keissiaresa
via reddit https://ift.tt/B4tciEp
https://ift.tt/bBntavL
Submitted September 16, 2023 at 09:35PM by keissiaresa
via reddit https://ift.tt/B4tciEp
lwn.net
The bogus CVE problem
The "Common Vulnerabilities and
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Similar issues detected in different cryptocurrency exchange backends
https://ift.tt/9Goy5hK
Submitted September 16, 2023 at 10:40PM by arrowflakes
via reddit https://ift.tt/KdsJ08l
https://ift.tt/9Goy5hK
Submitted September 16, 2023 at 10:40PM by arrowflakes
via reddit https://ift.tt/KdsJ08l
CoinFabrik
Quality Assurance QA/QC backend in Cryptocurrency Exchanges
Explore the vital role of quality assurance (QA/QC) backend processes in cryptocurrency exchanges ensuring quality and reliability.
A Big Look at Security in OpenAPI
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
Liblab
OpenAPI Security: Five types & best practices
Explore OpenAPI security best practices. Learn the key methods and how they're implemented. See how liblab enhances SDK creation.
Tickling ksmbd: fuzzing SMB in the Linux kernel
https://ift.tt/QVwZ0XE
Submitted September 17, 2023 at 02:05PM by buherator
via reddit https://ift.tt/NM6mRUH
https://ift.tt/QVwZ0XE
Submitted September 17, 2023 at 02:05PM by buherator
via reddit https://ift.tt/NM6mRUH
Pwning Tech
Tickling ksmbd: fuzzing SMB in the Linux kernel
Following the adventure of manually discovering network-based vulnerabilities in the Linux kernel, I'm adding ksmbd-fuzzing functionality to the already extensive kernel-fuzzing tool that is Syzkaller.
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
pyn3rd.github.io
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
0x01 PrefaceHere is the explicit denoscription about Spring Kafka deserialization vulnerability in Vmware security bulletin. Reference https://spring.io/security/cve-2023-34040 According to the descrip
CVE-2022-32947: macOS GPU-launched kernel privilege escalation exploit (walkthrough slides + demo)
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
A Practical Approach to SBOM in CI/CD. Presenting concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
Medium
A Practical Approach to SBOM in CI/CD Part I — CycloneDX
The article covers the concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
New SocVel Quiz is out
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
Joshua.Hu
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
Introduction When fuzzing large-scale applications, using a single server (even with 4 64-core AMD Ryzen CPUs) may not be powerful enough by itself. That’s where parallelized/distributed fuzzing comes in (i.e. automatic sharing of results between fuzzing…
Risks in Liechtenstein's electronic health files and new vulns in the underlying Liferay portal software (article in German)
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
Pentagrid AG
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Lie
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Liechtenstein
When MFA isn't actually MFA
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
Retool
When MFA isn't actually MFA
Due to a recent Google change, MFA isn't truly MFA.
Fileless Remote Code Execution on Juniper Firewalls
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
VulnCheck
Fileless Remote Code Execution on Juniper Firewalls - Blog - VulnCheck
Learn about VulnCheck's development of an exploit for CVE-2023-36845, leading to stealthy code execution on Juniper firewalls, while also assessing the prevalence of unpatched systems in the wild.
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation – Sysdig
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
Sysdig
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation
AMBERSQUID is a cloud-native cryptojacking operation that leverages AWS services and can cost victims more than $10,000/day.
Zero-Knowledge Middleboxes
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR