Over 400K Buckets and 10.4B Files Are Public Due to Cloud Misconfigurations
https://ift.tt/NS0ojx7
Submitted September 25, 2023 at 06:17PM by ziyahanalbeniz
via reddit https://ift.tt/SsXqcb9
https://ift.tt/NS0ojx7
Submitted September 25, 2023 at 06:17PM by ziyahanalbeniz
via reddit https://ift.tt/SsXqcb9
SOCRadar® Cyber Intelligence Inc.
Over 400K Buckets and 10.4B Files Are Public Due to Cloud Misconfigurations
Using the open source programs/platform, anyone can scan millions of public buckets at once using certain keywords. Typically, buckets...
From ScreenConnect to Hive Ransomware in 61 hours
https://ift.tt/ktaKgpS
Submitted September 25, 2023 at 05:54PM by TheDFIRReport
via reddit https://ift.tt/kdoan3t
https://ift.tt/ktaKgpS
Submitted September 25, 2023 at 05:54PM by TheDFIRReport
via reddit https://ift.tt/kdoan3t
The DFIR Report
From ScreenConnect to Hive Ransomware in 61 hours - The DFIR Report
In 2022, The DFIR Report observed an increase in the adversarial usage of Remote Management and Monitoring (RMM) tools. When compared to post-exploitation channels that heavily rely on terminals, such … Read More
Analysis of CVE-2023-38831 Zero-Day vulnerability in WinRAR
https://ift.tt/lydIJ9M
Submitted September 26, 2023 at 01:33AM by SL7reach
via reddit https://ift.tt/EoRI2d9
https://ift.tt/lydIJ9M
Submitted September 26, 2023 at 01:33AM by SL7reach
via reddit https://ift.tt/EoRI2d9
Penetration Testing and CyberSecurity Solution - SecureLayer7
Analysis of CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE: CVE-2023-38831: A New WinRar Vulnerabilty A remote code execution when the user attempts to view a benign file within a ZIP archive. The issue occurs because a) ZIP archive may include a...
SocketSleuth: Improving security testing for WebSocket applications | The Snyk blog
https://ift.tt/kd2xZhi
Submitted September 26, 2023 at 02:12AM by lirantal
via reddit https://ift.tt/ekIErH8
https://ift.tt/kd2xZhi
Submitted September 26, 2023 at 02:12AM by lirantal
via reddit https://ift.tt/ekIErH8
Snyk
SocketSleuth: Improving security testing for WebSocket applications | Snyk
Today, we are proud to announce the beta version of SocketSleuth, our new Burp Suite extension for performing security testing against WebSocket-based applications. SocketSleuth was created out of our security research group to aid in our security research…
GDBleed: Binary instrumentation and hooking framework built on top of GDB for pentesters and IoT security researchers
https://ift.tt/pheHUBG
Submitted September 26, 2023 at 03:22AM by NoPaleontologist7419
via reddit https://ift.tt/8qfZS5s
https://ift.tt/pheHUBG
Submitted September 26, 2023 at 03:22AM by NoPaleontologist7419
via reddit https://ift.tt/8qfZS5s
GitHub
GitHub - tin-z/GDBleed: Dynamic-Static binary instrumentation framework on top of GDB
Dynamic-Static binary instrumentation framework on top of GDB - GitHub - tin-z/GDBleed: Dynamic-Static binary instrumentation framework on top of GDB
DNS Debugging: What you need to know
https://ift.tt/bkPAzvg
Submitted September 26, 2023 at 12:11PM by odd950
via reddit https://ift.tt/LqFBxUH
https://ift.tt/bkPAzvg
Submitted September 26, 2023 at 12:11PM by odd950
via reddit https://ift.tt/LqFBxUH
Checkly
DNS Debug Deep Dive | Step-by-Step Troubleshooting Guide
Join us on a DNS debugging deep dive, starting from bisecting the problem to reproducing the issue and finding a fix.
The bogus CVE problem
https://ift.tt/4b3kXLt
Submitted September 26, 2023 at 01:35PM by yqopmin
via reddit https://ift.tt/4o3lvpT
https://ift.tt/4b3kXLt
Submitted September 26, 2023 at 01:35PM by yqopmin
via reddit https://ift.tt/4o3lvpT
lwn.net
The bogus CVE problem
The "Common Vulnerabilities and
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Telegram Search Engine for CTI, Data Breach Discovery and Monitoring and More
http://Telemetryapp.io
Submitted September 26, 2023 at 12:40PM by ari_ben_am
via reddit https://ift.tt/l4woAb0
http://Telemetryapp.io
Submitted September 26, 2023 at 12:40PM by ari_ben_am
via reddit https://ift.tt/l4woAb0
Telemetry
Telemetry provides the most advanced search and analytics capabilities for telegram data
The De Vinci of DirtyPipe Local Privilege Escalation - CVE-2022-0847 - vsociety
https://ift.tt/cREMQws
Submitted September 26, 2023 at 02:32PM by vsociety_
via reddit https://ift.tt/IXGT2ho
https://ift.tt/cREMQws
Submitted September 26, 2023 at 02:32PM by vsociety_
via reddit https://ift.tt/IXGT2ho
www.vicarius.io
The De Vinci of DirtyPipe Local Privilege Escalation - CVE-2022-0847 - vsociety
CVE-2023-36664: Command injection with Ghostnoscript PoC + exploit - vsociety
https://ift.tt/NarJTuB
Submitted September 26, 2023 at 02:27PM by vsociety_
via reddit https://ift.tt/LrDySPg
https://ift.tt/NarJTuB
Submitted September 26, 2023 at 02:27PM by vsociety_
via reddit https://ift.tt/LrDySPg
A tale about a Red Team exercise and the Forcepoint Endpoint One DLP client - vsociety
https://ift.tt/bCQywXz
Submitted September 26, 2023 at 02:13PM by vsociety_
via reddit https://ift.tt/mKv7kVT
https://ift.tt/bCQywXz
Submitted September 26, 2023 at 02:13PM by vsociety_
via reddit https://ift.tt/mKv7kVT
www.vicarius.io
A tale about a Red Team exercise and the Forcepoint Endpoint One DLP client - vsociety
Compile it ⚙️ , Debug it 🔬 , Hack it 😎 it's the Linux kernel 🐧 - vsociety
https://ift.tt/fPlHNjE
Submitted September 26, 2023 at 02:13PM by vsociety_
via reddit https://ift.tt/Fu4fU9n
https://ift.tt/fPlHNjE
Submitted September 26, 2023 at 02:13PM by vsociety_
via reddit https://ift.tt/Fu4fU9n
www.vicarius.io
Compile it ⚙️ , Debug it 🔬 , Hack it 😎 it's the Linux kernel 🐧 - vsociety
Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)
https://ift.tt/41y3pbw
Submitted September 26, 2023 at 05:12PM by scopedsecurity
via reddit https://ift.tt/tM0vc8N
https://ift.tt/41y3pbw
Submitted September 26, 2023 at 05:12PM by scopedsecurity
via reddit https://ift.tt/tM0vc8N
Code-White
CODE WHITE | Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)
The `TemplateParser` is fundamental in ASP.NET Web Forms. It is used for parsing different ASP.NET source files such as `*.aspx` and for parsing other input from various sources, including user provided data.
In this two part series we will take a deep look…
In this two part series we will take a deep look…
Malicious npm Packages Strike Again: Exfiltrating Kubernetes Configurations and SSH Keys
https://ift.tt/i1OzGn2
Submitted September 26, 2023 at 09:06PM by Professional-Ad6429
via reddit https://ift.tt/9hqIxas
https://ift.tt/i1OzGn2
Submitted September 26, 2023 at 09:06PM by Professional-Ad6429
via reddit https://ift.tt/9hqIxas
Cyber-Oracle
Malicious npm Packages Strike Again: Exfiltrating Kubernetes Configurations and SSH Keys
Plus, Signal Fortifies Its Encryption: PQXDH Protocol Upgrade Bolsters Quantum Resistance
Guide to hacking htmx applications
https://ift.tt/SUBuTZf
Submitted September 26, 2023 at 10:19PM by 4lreadytekken
via reddit https://ift.tt/OpS45Q6
https://ift.tt/SUBuTZf
Submitted September 26, 2023 at 10:19PM by 4lreadytekken
via reddit https://ift.tt/OpS45Q6
Medium
Hacking htmx applications
With the normal flow of frontend frameworks moving from hipster to mainstream in the coming few months, during a test, you bump into this…
Survive Access Key Deletion with sts:GetFederationToken - Hacking The Cloud
https://ift.tt/jLiB9KT
Submitted September 26, 2023 at 10:46PM by RedTermSession
via reddit https://ift.tt/xS4eKwU
https://ift.tt/jLiB9KT
Submitted September 26, 2023 at 10:46PM by RedTermSession
via reddit https://ift.tt/xS4eKwU
hackingthe.cloud
Survive Access Key Deletion with sts:GetFederationToken - Hacking The Cloud
Use sts:GetFederationToken to maintain access, even if the original IAM credentials are revoked.
Getting RCE in Chrome with incorrect side effect in the JIT compiler
https://ift.tt/VPzMbDS
Submitted September 27, 2023 at 02:37PM by poltess0
via reddit https://ift.tt/EUJIHou
https://ift.tt/VPzMbDS
Submitted September 27, 2023 at 02:37PM by poltess0
via reddit https://ift.tt/EUJIHou
The GitHub Blog
Getting RCE in Chrome with incorrect side effect in the JIT compiler
In this post, I'll exploit CVE-2023-3420, a type confusion in Chrome that allows remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site.
NoSQL injection techniques & labs
https://ift.tt/Q7RbVvj
Submitted September 27, 2023 at 05:44PM by albinowax
via reddit https://ift.tt/ZqruSVF
https://ift.tt/Q7RbVvj
Submitted September 27, 2023 at 05:44PM by albinowax
via reddit https://ift.tt/ZqruSVF
portswigger.net
NoSQL injection | Web Security Academy
NoSQL injection is a vulnerability where an attacker is able to interfere with the queries that an application makes to a NoSQL database. NoSQL injection ...
A Deep Dive into Brute Ratel C4 payloads – Part 2
https://ift.tt/udSJRKY
Submitted September 27, 2023 at 06:40PM by CyberMasterV
via reddit https://ift.tt/cfTO7uo
https://ift.tt/udSJRKY
Submitted September 27, 2023 at 06:40PM by CyberMasterV
via reddit https://ift.tt/cfTO7uo
How to get persistent reverse shell from Android app without visible permissions to DoS device
https://ift.tt/l1ycgCz
Submitted September 27, 2023 at 07:57PM by barakadua131
via reddit https://ift.tt/enC5KIZ
https://ift.tt/l1ycgCz
Submitted September 27, 2023 at 07:57PM by barakadua131
via reddit https://ift.tt/enC5KIZ
Mobile Hacker
Get persistent reverse shell from Android app without visible permissions to make device unusable Mobile Hacker
This blog will introduce you how it is possible to write a persistent reverse shell app on Android without any user requested and visible permissions. Since such application has no permissions, it shouldn’t be able to perform any task. Well, that isn’t true.…
Chalk - Total visibility of your software engineering lifecycle
https://ift.tt/wCM6rj8
Submitted September 27, 2023 at 10:06PM by sanitybit
via reddit https://ift.tt/bNmEhaj
https://ift.tt/wCM6rj8
Submitted September 27, 2023 at 10:06PM by sanitybit
via reddit https://ift.tt/bNmEhaj
Crash Override
Chalk™ is now officially open-source