New ways to inject system CA certificates in Android 14
https://ift.tt/UgATxmY
Submitted September 21, 2023 at 06:05PM by pimterry
via reddit https://ift.tt/MB6wXRO
https://ift.tt/UgATxmY
Submitted September 21, 2023 at 06:05PM by pimterry
via reddit https://ift.tt/MB6wXRO
Httptoolkit
New ways to inject system CA certificates in Android 14
A couple of weeks ago I published a post about changes in Android 14 that fundamentally break existing approaches to installing system-level…
Finnish authorities have shut down PIILOPUOTI - a darknet drug market
https://ift.tt/6lC5ctJ
Submitted September 21, 2023 at 07:20PM by nareksays
via reddit https://ift.tt/c3yC7Wk
https://ift.tt/6lC5ctJ
Submitted September 21, 2023 at 07:20PM by nareksays
via reddit https://ift.tt/c3yC7Wk
Deform
Finnish Authorities Have Shut Down the Darknet Drug Market PIILOPUOTI - Deform
Finnish law enforcement authorities have announced the dismantling of PIILOPUOTI, a shady online marketplace that specialized in illegal drug trafficking
The WebP 0day
https://ift.tt/xJct8Ew
Submitted September 22, 2023 at 01:03AM by MegaManSec2
via reddit https://ift.tt/ZmdS3HE
https://ift.tt/xJct8Ew
Submitted September 22, 2023 at 01:03AM by MegaManSec2
via reddit https://ift.tt/ZmdS3HE
Isosceles Blog
The WebP 0day
Early last week, Google released a new stable update for Chrome. The update included a single security fix that was reported by Apple's Security Engineering and Architecture (SEAR) team. The issue, CVE-2023-4863, was a heap buffer overflow in the WebP image…
Critical DICOM Server Misconfigurations Lead to Exposure of 1.6M Medical Records
https://ift.tt/wDbVeS5
Submitted September 22, 2023 at 04:22PM by ziyahanalbeniz
via reddit https://ift.tt/184vwEk
https://ift.tt/wDbVeS5
Submitted September 22, 2023 at 04:22PM by ziyahanalbeniz
via reddit https://ift.tt/184vwEk
SOCRadar® Cyber Intelligence Inc.
Critical DICOM Server Misconfigurations Lead to Exposure of 1.6M Medical Records
In a regular threat and vulnerability hunting activity, SOCRadar has discovered during their research that thousands of DICOM servers were...
Cryptomining malware detected on a Russian thesaurus with 5 Million+ monthly visits
https://ift.tt/O3aT1dR
Submitted September 22, 2023 at 05:05PM by nareksays
via reddit https://ift.tt/XOVB0IS
https://ift.tt/O3aT1dR
Submitted September 22, 2023 at 05:05PM by nareksays
via reddit https://ift.tt/XOVB0IS
Group-IB
It’s a trap: Detecting a cryptominer on a popular website using Group-IB MXDR
Group-IB analysts discovered and analyzed a cryptojacking campaign on a popular educational resource using Group-IB Managed XDR.
Muppets group reportedly breached Sirena Travel: 3.5 Billion records compromised
https://ift.tt/W4uf7oy
Submitted September 23, 2023 at 12:07AM by nareksays
via reddit https://ift.tt/ecYTu2Z
https://ift.tt/W4uf7oy
Submitted September 23, 2023 at 12:07AM by nareksays
via reddit https://ift.tt/ecYTu2Z
Defeating Visual Studio Code embedded reverse shell
https://ift.tt/nWajPsv
Submitted September 23, 2023 at 01:13AM by ipfyx
via reddit https://ift.tt/hNJpTg3
https://ift.tt/nWajPsv
Submitted September 23, 2023 at 01:13AM by ipfyx
via reddit https://ift.tt/hNJpTg3
ipfyx.fr
Blocking Visual Studio Code embedded reverse shell before it's too late
Visual studio code tunnel Introduction Since July 2023, Microsoft is offering the perfect reverse shell, embedded inside Visual Studio Code, a widely used …
Past week in brief - Microsoft's 38TB Data Leak, Cisco's Splunk Acquisition, Apple's Triple Zero-Days, LastPass Security Update, and OpenAI's Red Teaming Initiative
https://ift.tt/TWNR4wL
Submitted September 24, 2023 at 02:22PM by mandos_io
via reddit https://ift.tt/5V9XQ1A
https://ift.tt/TWNR4wL
Submitted September 24, 2023 at 02:22PM by mandos_io
via reddit https://ift.tt/5V9XQ1A
Mandos Way
Brief #18: Microsoft's 38TB Data Leak, Cisco's Splunk Acquisition
Mandos Brief, Week 38 2023: Microsoft's 38TB data leak, Cisco's acquisition of Splunk, LastPass's new security measures, and OpenAI's Red Teaming Network.
A Prime on Client-side JavaScript Instrumentation
https://ift.tt/dWIvGpr
Submitted September 25, 2023 at 01:58PM by nibblesec
via reddit https://ift.tt/7ZxmFU2
https://ift.tt/dWIvGpr
Submitted September 25, 2023 at 01:58PM by nibblesec
via reddit https://ift.tt/7ZxmFU2
Doyensec
Client-side JavaScript Instrumentation · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Insecure URL handler (Electron) in iRacing leading to RCE in the client - bug discovery and exploit
https://ift.tt/hPT17Yn
Submitted September 25, 2023 at 03:58PM by ss2342-
via reddit https://ift.tt/iIVDceJ
https://ift.tt/hPT17Yn
Submitted September 25, 2023 at 03:58PM by ss2342-
via reddit https://ift.tt/iIVDceJ
Blog
iRacing Exploit allows attackers to take control of user’s computer
I’ve recently been looking into iRacing, which is an online racing simulation video game.
[P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955)
https://ift.tt/FbH5fJ8
Submitted September 25, 2023 at 05:20PM by scopedsecurity
via reddit https://ift.tt/SluYEte
https://ift.tt/FbH5fJ8
Submitted September 25, 2023 at 05:20PM by scopedsecurity
via reddit https://ift.tt/SluYEte
STAR Labs
[P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955)
Brief I may have achieved successful exploitation of a SharePoint target during Pwn2Own Vancouver 2023. While the live demonstration lasted only approximately 30 seconds, it is noteworthy that the process of discovering and crafting the exploit chain consumed…
Over 400K Buckets and 10.4B Files Are Public Due to Cloud Misconfigurations
https://ift.tt/NS0ojx7
Submitted September 25, 2023 at 06:17PM by ziyahanalbeniz
via reddit https://ift.tt/SsXqcb9
https://ift.tt/NS0ojx7
Submitted September 25, 2023 at 06:17PM by ziyahanalbeniz
via reddit https://ift.tt/SsXqcb9
SOCRadar® Cyber Intelligence Inc.
Over 400K Buckets and 10.4B Files Are Public Due to Cloud Misconfigurations
Using the open source programs/platform, anyone can scan millions of public buckets at once using certain keywords. Typically, buckets...
From ScreenConnect to Hive Ransomware in 61 hours
https://ift.tt/ktaKgpS
Submitted September 25, 2023 at 05:54PM by TheDFIRReport
via reddit https://ift.tt/kdoan3t
https://ift.tt/ktaKgpS
Submitted September 25, 2023 at 05:54PM by TheDFIRReport
via reddit https://ift.tt/kdoan3t
The DFIR Report
From ScreenConnect to Hive Ransomware in 61 hours - The DFIR Report
In 2022, The DFIR Report observed an increase in the adversarial usage of Remote Management and Monitoring (RMM) tools. When compared to post-exploitation channels that heavily rely on terminals, such … Read More
Analysis of CVE-2023-38831 Zero-Day vulnerability in WinRAR
https://ift.tt/lydIJ9M
Submitted September 26, 2023 at 01:33AM by SL7reach
via reddit https://ift.tt/EoRI2d9
https://ift.tt/lydIJ9M
Submitted September 26, 2023 at 01:33AM by SL7reach
via reddit https://ift.tt/EoRI2d9
Penetration Testing and CyberSecurity Solution - SecureLayer7
Analysis of CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE: CVE-2023-38831: A New WinRar Vulnerabilty A remote code execution when the user attempts to view a benign file within a ZIP archive. The issue occurs because a) ZIP archive may include a...
SocketSleuth: Improving security testing for WebSocket applications | The Snyk blog
https://ift.tt/kd2xZhi
Submitted September 26, 2023 at 02:12AM by lirantal
via reddit https://ift.tt/ekIErH8
https://ift.tt/kd2xZhi
Submitted September 26, 2023 at 02:12AM by lirantal
via reddit https://ift.tt/ekIErH8
Snyk
SocketSleuth: Improving security testing for WebSocket applications | Snyk
Today, we are proud to announce the beta version of SocketSleuth, our new Burp Suite extension for performing security testing against WebSocket-based applications. SocketSleuth was created out of our security research group to aid in our security research…
GDBleed: Binary instrumentation and hooking framework built on top of GDB for pentesters and IoT security researchers
https://ift.tt/pheHUBG
Submitted September 26, 2023 at 03:22AM by NoPaleontologist7419
via reddit https://ift.tt/8qfZS5s
https://ift.tt/pheHUBG
Submitted September 26, 2023 at 03:22AM by NoPaleontologist7419
via reddit https://ift.tt/8qfZS5s
GitHub
GitHub - tin-z/GDBleed: Dynamic-Static binary instrumentation framework on top of GDB
Dynamic-Static binary instrumentation framework on top of GDB - GitHub - tin-z/GDBleed: Dynamic-Static binary instrumentation framework on top of GDB
DNS Debugging: What you need to know
https://ift.tt/bkPAzvg
Submitted September 26, 2023 at 12:11PM by odd950
via reddit https://ift.tt/LqFBxUH
https://ift.tt/bkPAzvg
Submitted September 26, 2023 at 12:11PM by odd950
via reddit https://ift.tt/LqFBxUH
Checkly
DNS Debug Deep Dive | Step-by-Step Troubleshooting Guide
Join us on a DNS debugging deep dive, starting from bisecting the problem to reproducing the issue and finding a fix.
The bogus CVE problem
https://ift.tt/4b3kXLt
Submitted September 26, 2023 at 01:35PM by yqopmin
via reddit https://ift.tt/4o3lvpT
https://ift.tt/4b3kXLt
Submitted September 26, 2023 at 01:35PM by yqopmin
via reddit https://ift.tt/4o3lvpT
lwn.net
The bogus CVE problem
The "Common Vulnerabilities and
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Telegram Search Engine for CTI, Data Breach Discovery and Monitoring and More
http://Telemetryapp.io
Submitted September 26, 2023 at 12:40PM by ari_ben_am
via reddit https://ift.tt/l4woAb0
http://Telemetryapp.io
Submitted September 26, 2023 at 12:40PM by ari_ben_am
via reddit https://ift.tt/l4woAb0
Telemetry
Telemetry provides the most advanced search and analytics capabilities for telegram data
The De Vinci of DirtyPipe Local Privilege Escalation - CVE-2022-0847 - vsociety
https://ift.tt/cREMQws
Submitted September 26, 2023 at 02:32PM by vsociety_
via reddit https://ift.tt/IXGT2ho
https://ift.tt/cREMQws
Submitted September 26, 2023 at 02:32PM by vsociety_
via reddit https://ift.tt/IXGT2ho
www.vicarius.io
The De Vinci of DirtyPipe Local Privilege Escalation - CVE-2022-0847 - vsociety
CVE-2023-36664: Command injection with Ghostnoscript PoC + exploit - vsociety
https://ift.tt/NarJTuB
Submitted September 26, 2023 at 02:27PM by vsociety_
via reddit https://ift.tt/LrDySPg
https://ift.tt/NarJTuB
Submitted September 26, 2023 at 02:27PM by vsociety_
via reddit https://ift.tt/LrDySPg