Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
Joshua.Hu
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
Introduction When fuzzing large-scale applications, using a single server (even with 4 64-core AMD Ryzen CPUs) may not be powerful enough by itself. That’s where parallelized/distributed fuzzing comes in (i.e. automatic sharing of results between fuzzing…
Risks in Liechtenstein's electronic health files and new vulns in the underlying Liferay portal software (article in German)
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
Pentagrid AG
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Lie
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Liechtenstein
When MFA isn't actually MFA
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
Retool
When MFA isn't actually MFA
Due to a recent Google change, MFA isn't truly MFA.
Fileless Remote Code Execution on Juniper Firewalls
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
VulnCheck
Fileless Remote Code Execution on Juniper Firewalls - Blog - VulnCheck
Learn about VulnCheck's development of an exploit for CVE-2023-36845, leading to stealthy code execution on Juniper firewalls, while also assessing the prevalence of unpatched systems in the wild.
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation – Sysdig
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
Sysdig
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation
AMBERSQUID is a cloud-native cryptojacking operation that leverages AWS services and can cost victims more than $10,000/day.
Zero-Knowledge Middleboxes
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
Tor Browser - browse web anonymously sends thru 3 relays layer encryption removed each relay sites see exit relay IP Address. Use with bridges (obsf4, meek-azure, snowflake) if in a country that censors Tor. Also access onion services only accessible via Tor aka "dark web."
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
www.torproject.org
The Tor Project | Privacy & Freedom Online
Defend yourself against tracking and surveillance. Circumvent censorship.
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
Pentagrid AG
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2
CVE-2023-38346 is a directory traversal vulnerability in Wind River's tarExtract function in VxWorks discovered by Pentagrid during a penetration test and source code review.
DEF CON 31 Main Stage Talks
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
Reddit
From the netsec community on Reddit: DEF CON 31 Main Stage Talks
Explore this post and more from the netsec community
#ShortAndMalicious — DarkGate
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
Medium
#ShortAndMalicious — DarkGate
Dissecting DarkGate’s new key log encryption and tools to decrypt key log files
MetaMask Airdrop
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
Crawlector Version 2.0 has been released. This is a milestone release.
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
GitHub
GitHub - MFMokbel/Crawlector: Crawlector is a threat hunting framework designed for scanning websites for malicious objects.
Crawlector is a threat hunting framework designed for scanning websites for malicious objects. - MFMokbel/Crawlector
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
The recent discontinuation of the JavaScript code virtualization tool “vm2” sounds the alarm for under-maintained open source packages. This post discusses the factors that led to its discontinuation and what can be done to save “isolated-vm”, the best alternative…
Howtorotate.com - Open Source Guides on Key Rotations from the Most Popular Providers
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL
Atlassian Security Bulletin September 23
https://ift.tt/IqYJ9Qb
Submitted September 20, 2023 at 11:27AM by Alfrede81
via reddit https://ift.tt/UuwnOy0
https://ift.tt/IqYJ9Qb
Submitted September 20, 2023 at 11:27AM by Alfrede81
via reddit https://ift.tt/UuwnOy0
RCE in Tutanota Desktop: How a single email could compromise your machine
https://ift.tt/7NDJg09
Submitted September 20, 2023 at 09:24PM by SonarPaul
via reddit https://ift.tt/sPKqu7k
https://ift.tt/7NDJg09
Submitted September 20, 2023 at 09:24PM by SonarPaul
via reddit https://ift.tt/sPKqu7k
Sonarsource
Remote Code Execution in Tutanota Desktop due to Code Flaw
Our Research team discovered critical code vulnerabilities in Proton Mail, Skiff, and Tutanota. This post covers an XSS vulnerability in Tutanota Desktop and how it can be prevented.
LUCR-3: Scattered Spider Getting SaaS-y in the Cloud
https://ift.tt/04rgSo1
Submitted September 20, 2023 at 09:53PM by permis0
via reddit https://ift.tt/n20Ge3J
https://ift.tt/04rgSo1
Submitted September 20, 2023 at 09:53PM by permis0
via reddit https://ift.tt/n20Ge3J
permiso.io
LUCR-3: Scattered Spider Getting SaaS-y in the Cloud
LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment with the goal of stealing Intellectual Property…
Google Chrome is erroring chase.com for containing malware from static.chasecdn.com trying to load marketing-loader.js
https://chase.com
Submitted September 21, 2023 at 01:42AM by cybersecscrub
via reddit https://ift.tt/t3XaWrj
https://chase.com
Submitted September 21, 2023 at 01:42AM by cybersecscrub
via reddit https://ift.tt/t3XaWrj
Chase
Credit Card, Mortgage, Banking, Auto | Chase Online | Chase.com
Chase online; credit cards, mortgages, commercial banking, auto loans, investing & retirement planning, checking and business banking.
HDF5 - Multiple Memory Corruption Vulnerabilities
https://ift.tt/yYmBO3t
Submitted September 21, 2023 at 04:14AM by MysteriousHotel3017
via reddit https://ift.tt/Zu36rf1
https://ift.tt/yYmBO3t
Submitted September 21, 2023 at 04:14AM by MysteriousHotel3017
via reddit https://ift.tt/Zu36rf1
Pulse Security
HDF5 - Multiple Memory Corruption Vulnerabilities
Multiple memory corruption vulnerabilities were discovered in the LibHDF5 library including heap overflow, use-after-free and stack exhaustion.
New ways to inject system CA certificates in Android 14
https://ift.tt/UgATxmY
Submitted September 21, 2023 at 06:05PM by pimterry
via reddit https://ift.tt/MB6wXRO
https://ift.tt/UgATxmY
Submitted September 21, 2023 at 06:05PM by pimterry
via reddit https://ift.tt/MB6wXRO
Httptoolkit
New ways to inject system CA certificates in Android 14
A couple of weeks ago I published a post about changes in Android 14 that fundamentally break existing approaches to installing system-level…
Finnish authorities have shut down PIILOPUOTI - a darknet drug market
https://ift.tt/6lC5ctJ
Submitted September 21, 2023 at 07:20PM by nareksays
via reddit https://ift.tt/c3yC7Wk
https://ift.tt/6lC5ctJ
Submitted September 21, 2023 at 07:20PM by nareksays
via reddit https://ift.tt/c3yC7Wk
Deform
Finnish Authorities Have Shut Down the Darknet Drug Market PIILOPUOTI - Deform
Finnish law enforcement authorities have announced the dismantling of PIILOPUOTI, a shady online marketplace that specialized in illegal drug trafficking