A Big Look at Security in OpenAPI
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
Liblab
OpenAPI Security: Five types & best practices
Explore OpenAPI security best practices. Learn the key methods and how they're implemented. See how liblab enhances SDK creation.
Tickling ksmbd: fuzzing SMB in the Linux kernel
https://ift.tt/QVwZ0XE
Submitted September 17, 2023 at 02:05PM by buherator
via reddit https://ift.tt/NM6mRUH
https://ift.tt/QVwZ0XE
Submitted September 17, 2023 at 02:05PM by buherator
via reddit https://ift.tt/NM6mRUH
Pwning Tech
Tickling ksmbd: fuzzing SMB in the Linux kernel
Following the adventure of manually discovering network-based vulnerabilities in the Linux kernel, I'm adding ksmbd-fuzzing functionality to the already extensive kernel-fuzzing tool that is Syzkaller.
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
pyn3rd.github.io
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
0x01 PrefaceHere is the explicit denoscription about Spring Kafka deserialization vulnerability in Vmware security bulletin. Reference https://spring.io/security/cve-2023-34040 According to the descrip
CVE-2022-32947: macOS GPU-launched kernel privilege escalation exploit (walkthrough slides + demo)
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
A Practical Approach to SBOM in CI/CD. Presenting concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
Medium
A Practical Approach to SBOM in CI/CD Part I — CycloneDX
The article covers the concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
New SocVel Quiz is out
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
Joshua.Hu
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
Introduction When fuzzing large-scale applications, using a single server (even with 4 64-core AMD Ryzen CPUs) may not be powerful enough by itself. That’s where parallelized/distributed fuzzing comes in (i.e. automatic sharing of results between fuzzing…
Risks in Liechtenstein's electronic health files and new vulns in the underlying Liferay portal software (article in German)
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
Pentagrid AG
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Lie
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Liechtenstein
When MFA isn't actually MFA
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
Retool
When MFA isn't actually MFA
Due to a recent Google change, MFA isn't truly MFA.
Fileless Remote Code Execution on Juniper Firewalls
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
VulnCheck
Fileless Remote Code Execution on Juniper Firewalls - Blog - VulnCheck
Learn about VulnCheck's development of an exploit for CVE-2023-36845, leading to stealthy code execution on Juniper firewalls, while also assessing the prevalence of unpatched systems in the wild.
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation – Sysdig
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
Sysdig
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation
AMBERSQUID is a cloud-native cryptojacking operation that leverages AWS services and can cost victims more than $10,000/day.
Zero-Knowledge Middleboxes
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
Tor Browser - browse web anonymously sends thru 3 relays layer encryption removed each relay sites see exit relay IP Address. Use with bridges (obsf4, meek-azure, snowflake) if in a country that censors Tor. Also access onion services only accessible via Tor aka "dark web."
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
www.torproject.org
The Tor Project | Privacy & Freedom Online
Defend yourself against tracking and surveillance. Circumvent censorship.
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
Pentagrid AG
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2
CVE-2023-38346 is a directory traversal vulnerability in Wind River's tarExtract function in VxWorks discovered by Pentagrid during a penetration test and source code review.
DEF CON 31 Main Stage Talks
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
Reddit
From the netsec community on Reddit: DEF CON 31 Main Stage Talks
Explore this post and more from the netsec community
#ShortAndMalicious — DarkGate
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
Medium
#ShortAndMalicious — DarkGate
Dissecting DarkGate’s new key log encryption and tools to decrypt key log files
MetaMask Airdrop
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
Crawlector Version 2.0 has been released. This is a milestone release.
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
GitHub
GitHub - MFMokbel/Crawlector: Crawlector is a threat hunting framework designed for scanning websites for malicious objects.
Crawlector is a threat hunting framework designed for scanning websites for malicious objects. - MFMokbel/Crawlector
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
The recent discontinuation of the JavaScript code virtualization tool “vm2” sounds the alarm for under-maintained open source packages. This post discusses the factors that led to its discontinuation and what can be done to save “isolated-vm”, the best alternative…
Howtorotate.com - Open Source Guides on Key Rotations from the Most Popular Providers
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL