Tor Browser - browse web anonymously sends thru 3 relays layer encryption removed each relay sites see exit relay IP Address. Use with bridges (obsf4, meek-azure, snowflake) if in a country that censors Tor. Also access onion services only accessible via Tor aka "dark web."
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
www.torproject.org
The Tor Project | Privacy & Freedom Online
Defend yourself against tracking and surveillance. Circumvent censorship.
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
Pentagrid AG
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2
CVE-2023-38346 is a directory traversal vulnerability in Wind River's tarExtract function in VxWorks discovered by Pentagrid during a penetration test and source code review.
DEF CON 31 Main Stage Talks
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
Reddit
From the netsec community on Reddit: DEF CON 31 Main Stage Talks
Explore this post and more from the netsec community
#ShortAndMalicious — DarkGate
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
Medium
#ShortAndMalicious — DarkGate
Dissecting DarkGate’s new key log encryption and tools to decrypt key log files
MetaMask Airdrop
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
https://ift.tt/fAGm2ks
Submitted September 19, 2023 at 06:26PM by UniqueTurnover4563
via reddit https://ift.tt/sABS71F
Crawlector Version 2.0 has been released. This is a milestone release.
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
https://ift.tt/lsh25JN
Submitted September 19, 2023 at 07:13PM by MFMokbel
via reddit https://ift.tt/rdjZQmb
GitHub
GitHub - MFMokbel/Crawlector: Crawlector is a threat hunting framework designed for scanning websites for malicious objects.
Crawlector is a threat hunting framework designed for scanning websites for malicious objects. - MFMokbel/Crawlector
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
https://ift.tt/9Kp3mWQ
Submitted September 19, 2023 at 11:42PM by shorttermusernamemem
via reddit https://ift.tt/Q8shYGz
The indomitable maintainer spirit versus the indifferent cruelty of JavaScript
The recent discontinuation of the JavaScript code virtualization tool “vm2” sounds the alarm for under-maintained open source packages. This post discusses the factors that led to its discontinuation and what can be done to save “isolated-vm”, the best alternative…
Howtorotate.com - Open Source Guides on Key Rotations from the Most Popular Providers
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL
https://ift.tt/fQdUIK8
Submitted September 20, 2023 at 12:27AM by Phorcez
via reddit https://ift.tt/8W9QuZL
Atlassian Security Bulletin September 23
https://ift.tt/IqYJ9Qb
Submitted September 20, 2023 at 11:27AM by Alfrede81
via reddit https://ift.tt/UuwnOy0
https://ift.tt/IqYJ9Qb
Submitted September 20, 2023 at 11:27AM by Alfrede81
via reddit https://ift.tt/UuwnOy0
RCE in Tutanota Desktop: How a single email could compromise your machine
https://ift.tt/7NDJg09
Submitted September 20, 2023 at 09:24PM by SonarPaul
via reddit https://ift.tt/sPKqu7k
https://ift.tt/7NDJg09
Submitted September 20, 2023 at 09:24PM by SonarPaul
via reddit https://ift.tt/sPKqu7k
Sonarsource
Remote Code Execution in Tutanota Desktop due to Code Flaw
Our Research team discovered critical code vulnerabilities in Proton Mail, Skiff, and Tutanota. This post covers an XSS vulnerability in Tutanota Desktop and how it can be prevented.
LUCR-3: Scattered Spider Getting SaaS-y in the Cloud
https://ift.tt/04rgSo1
Submitted September 20, 2023 at 09:53PM by permis0
via reddit https://ift.tt/n20Ge3J
https://ift.tt/04rgSo1
Submitted September 20, 2023 at 09:53PM by permis0
via reddit https://ift.tt/n20Ge3J
permiso.io
LUCR-3: Scattered Spider Getting SaaS-y in the Cloud
LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment with the goal of stealing Intellectual Property…
Google Chrome is erroring chase.com for containing malware from static.chasecdn.com trying to load marketing-loader.js
https://chase.com
Submitted September 21, 2023 at 01:42AM by cybersecscrub
via reddit https://ift.tt/t3XaWrj
https://chase.com
Submitted September 21, 2023 at 01:42AM by cybersecscrub
via reddit https://ift.tt/t3XaWrj
Chase
Credit Card, Mortgage, Banking, Auto | Chase Online | Chase.com
Chase online; credit cards, mortgages, commercial banking, auto loans, investing & retirement planning, checking and business banking.
HDF5 - Multiple Memory Corruption Vulnerabilities
https://ift.tt/yYmBO3t
Submitted September 21, 2023 at 04:14AM by MysteriousHotel3017
via reddit https://ift.tt/Zu36rf1
https://ift.tt/yYmBO3t
Submitted September 21, 2023 at 04:14AM by MysteriousHotel3017
via reddit https://ift.tt/Zu36rf1
Pulse Security
HDF5 - Multiple Memory Corruption Vulnerabilities
Multiple memory corruption vulnerabilities were discovered in the LibHDF5 library including heap overflow, use-after-free and stack exhaustion.
New ways to inject system CA certificates in Android 14
https://ift.tt/UgATxmY
Submitted September 21, 2023 at 06:05PM by pimterry
via reddit https://ift.tt/MB6wXRO
https://ift.tt/UgATxmY
Submitted September 21, 2023 at 06:05PM by pimterry
via reddit https://ift.tt/MB6wXRO
Httptoolkit
New ways to inject system CA certificates in Android 14
A couple of weeks ago I published a post about changes in Android 14 that fundamentally break existing approaches to installing system-level…
Finnish authorities have shut down PIILOPUOTI - a darknet drug market
https://ift.tt/6lC5ctJ
Submitted September 21, 2023 at 07:20PM by nareksays
via reddit https://ift.tt/c3yC7Wk
https://ift.tt/6lC5ctJ
Submitted September 21, 2023 at 07:20PM by nareksays
via reddit https://ift.tt/c3yC7Wk
Deform
Finnish Authorities Have Shut Down the Darknet Drug Market PIILOPUOTI - Deform
Finnish law enforcement authorities have announced the dismantling of PIILOPUOTI, a shady online marketplace that specialized in illegal drug trafficking
The WebP 0day
https://ift.tt/xJct8Ew
Submitted September 22, 2023 at 01:03AM by MegaManSec2
via reddit https://ift.tt/ZmdS3HE
https://ift.tt/xJct8Ew
Submitted September 22, 2023 at 01:03AM by MegaManSec2
via reddit https://ift.tt/ZmdS3HE
Isosceles Blog
The WebP 0day
Early last week, Google released a new stable update for Chrome. The update included a single security fix that was reported by Apple's Security Engineering and Architecture (SEAR) team. The issue, CVE-2023-4863, was a heap buffer overflow in the WebP image…
Critical DICOM Server Misconfigurations Lead to Exposure of 1.6M Medical Records
https://ift.tt/wDbVeS5
Submitted September 22, 2023 at 04:22PM by ziyahanalbeniz
via reddit https://ift.tt/184vwEk
https://ift.tt/wDbVeS5
Submitted September 22, 2023 at 04:22PM by ziyahanalbeniz
via reddit https://ift.tt/184vwEk
SOCRadar® Cyber Intelligence Inc.
Critical DICOM Server Misconfigurations Lead to Exposure of 1.6M Medical Records
In a regular threat and vulnerability hunting activity, SOCRadar has discovered during their research that thousands of DICOM servers were...
Cryptomining malware detected on a Russian thesaurus with 5 Million+ monthly visits
https://ift.tt/O3aT1dR
Submitted September 22, 2023 at 05:05PM by nareksays
via reddit https://ift.tt/XOVB0IS
https://ift.tt/O3aT1dR
Submitted September 22, 2023 at 05:05PM by nareksays
via reddit https://ift.tt/XOVB0IS
Group-IB
It’s a trap: Detecting a cryptominer on a popular website using Group-IB MXDR
Group-IB analysts discovered and analyzed a cryptojacking campaign on a popular educational resource using Group-IB Managed XDR.
Muppets group reportedly breached Sirena Travel: 3.5 Billion records compromised
https://ift.tt/W4uf7oy
Submitted September 23, 2023 at 12:07AM by nareksays
via reddit https://ift.tt/ecYTu2Z
https://ift.tt/W4uf7oy
Submitted September 23, 2023 at 12:07AM by nareksays
via reddit https://ift.tt/ecYTu2Z
Defeating Visual Studio Code embedded reverse shell
https://ift.tt/nWajPsv
Submitted September 23, 2023 at 01:13AM by ipfyx
via reddit https://ift.tt/hNJpTg3
https://ift.tt/nWajPsv
Submitted September 23, 2023 at 01:13AM by ipfyx
via reddit https://ift.tt/hNJpTg3
ipfyx.fr
Blocking Visual Studio Code embedded reverse shell before it's too late
Visual studio code tunnel Introduction Since July 2023, Microsoft is offering the perfect reverse shell, embedded inside Visual Studio Code, a widely used …
Past week in brief - Microsoft's 38TB Data Leak, Cisco's Splunk Acquisition, Apple's Triple Zero-Days, LastPass Security Update, and OpenAI's Red Teaming Initiative
https://ift.tt/TWNR4wL
Submitted September 24, 2023 at 02:22PM by mandos_io
via reddit https://ift.tt/5V9XQ1A
https://ift.tt/TWNR4wL
Submitted September 24, 2023 at 02:22PM by mandos_io
via reddit https://ift.tt/5V9XQ1A
Mandos Way
Brief #18: Microsoft's 38TB Data Leak, Cisco's Splunk Acquisition
Mandos Brief, Week 38 2023: Microsoft's 38TB data leak, Cisco's acquisition of Splunk, LastPass's new security measures, and OpenAI's Red Teaming Network.