CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
pyn3rd.github.io
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
0x01 PrefaceHere is the explicit denoscription about Spring Kafka deserialization vulnerability in Vmware security bulletin. Reference https://spring.io/security/cve-2023-34040 According to the descrip
CVE-2022-32947: macOS GPU-launched kernel privilege escalation exploit (walkthrough slides + demo)
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
A Practical Approach to SBOM in CI/CD. Presenting concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
Medium
A Practical Approach to SBOM in CI/CD Part I — CycloneDX
The article covers the concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
New SocVel Quiz is out
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
Joshua.Hu
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
Introduction When fuzzing large-scale applications, using a single server (even with 4 64-core AMD Ryzen CPUs) may not be powerful enough by itself. That’s where parallelized/distributed fuzzing comes in (i.e. automatic sharing of results between fuzzing…
Risks in Liechtenstein's electronic health files and new vulns in the underlying Liferay portal software (article in German)
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
Pentagrid AG
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Lie
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Liechtenstein
When MFA isn't actually MFA
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
Retool
When MFA isn't actually MFA
Due to a recent Google change, MFA isn't truly MFA.
Fileless Remote Code Execution on Juniper Firewalls
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
VulnCheck
Fileless Remote Code Execution on Juniper Firewalls - Blog - VulnCheck
Learn about VulnCheck's development of an exploit for CVE-2023-36845, leading to stealthy code execution on Juniper firewalls, while also assessing the prevalence of unpatched systems in the wild.
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation – Sysdig
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
Sysdig
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation
AMBERSQUID is a cloud-native cryptojacking operation that leverages AWS services and can cost victims more than $10,000/day.
Zero-Knowledge Middleboxes
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
Tor Browser - browse web anonymously sends thru 3 relays layer encryption removed each relay sites see exit relay IP Address. Use with bridges (obsf4, meek-azure, snowflake) if in a country that censors Tor. Also access onion services only accessible via Tor aka "dark web."
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
www.torproject.org
The Tor Project | Privacy & Freedom Online
Defend yourself against tracking and surveillance. Circumvent censorship.
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
Pentagrid AG
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2
CVE-2023-38346 is a directory traversal vulnerability in Wind River's tarExtract function in VxWorks discovered by Pentagrid during a penetration test and source code review.
DEF CON 31 Main Stage Talks
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
Reddit
From the netsec community on Reddit: DEF CON 31 Main Stage Talks
Explore this post and more from the netsec community
#ShortAndMalicious — DarkGate
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
Medium
#ShortAndMalicious — DarkGate
Dissecting DarkGate’s new key log encryption and tools to decrypt key log files
MetaMask Airdrop
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
Crawlector Version 2.0 has been released. This is a milestone release.
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
GitHub
GitHub - MFMokbel/Crawlector: Crawlector is a threat hunting framework designed for scanning websites for malicious objects.
Crawlector is a threat hunting framework designed for scanning websites for malicious objects. - MFMokbel/Crawlector
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
The recent discontinuation of the JavaScript code virtualization tool “vm2” sounds the alarm for under-maintained open source packages. This post discusses the factors that led to its discontinuation and what can be done to save “isolated-vm”, the best alternative…
Howtorotate.com - Open Source Guides on Key Rotations from the Most Popular Providers
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL
Atlassian Security Bulletin September 23
https://ift.tt/IqYJ9Qb
Submitted September 20, 2023 at 11:27AM by Alfrede81
via reddit https://ift.tt/UuwnOy0
https://ift.tt/IqYJ9Qb
Submitted September 20, 2023 at 11:27AM by Alfrede81
via reddit https://ift.tt/UuwnOy0
RCE in Tutanota Desktop: How a single email could compromise your machine
https://ift.tt/7NDJg09
Submitted September 20, 2023 at 09:24PM by SonarPaul
via reddit https://ift.tt/sPKqu7k
https://ift.tt/7NDJg09
Submitted September 20, 2023 at 09:24PM by SonarPaul
via reddit https://ift.tt/sPKqu7k
Sonarsource
Remote Code Execution in Tutanota Desktop due to Code Flaw
Our Research team discovered critical code vulnerabilities in Proton Mail, Skiff, and Tutanota. This post covers an XSS vulnerability in Tutanota Desktop and how it can be prevented.