Customizing Sliver - Part 1 - hn security
https://ift.tt/Ia9D2OV
Submitted October 24, 2023 at 03:53PM by 0xdea
via reddit https://ift.tt/tYVCD89
https://ift.tt/Ia9D2OV
Submitted October 24, 2023 at 03:53PM by 0xdea
via reddit https://ift.tt/tYVCD89
hn security
Customizing Sliver - Part 1 - hn security
Lately I’ve been conducting research into […]
Citrix Bleed: Leaking Session Tokens with CVE-2023-4966
https://ift.tt/AL5CTuO
Submitted October 24, 2023 at 05:35PM by Mempodipper
via reddit https://ift.tt/lK6xjsS
https://ift.tt/AL5CTuO
Submitted October 24, 2023 at 05:35PM by Mempodipper
via reddit https://ift.tt/lK6xjsS
www.assetnote.io
Citrix Bleed: Leaking Session Tokens with CVE-2023-4966
It's time for another round Citrix Patch Diffing! Earlier this month Citrix released a security bulletin which mentioned "unauthenticated buffer-related vulnerabilities" and two CVEs. These issues affected Citrix NetScaler ADC and NetScaler Gateway.
Best Practices for Writing Quality Vulnerability Reports - How to write great vulnerability reports? If you’re a security consultant, penetration tester or a bug bounty hunter, these tips are for you!
https://ift.tt/i7FL6ZD
Submitted October 24, 2023 at 08:23PM by theowni
via reddit https://ift.tt/MHUvXzQ
https://ift.tt/i7FL6ZD
Submitted October 24, 2023 at 08:23PM by theowni
via reddit https://ift.tt/MHUvXzQ
Medium
Best Practices for Writing Quality Vulnerability Reports
How to write great vulnerability reports? If you’re a security consultant, penetration tester or a bug bounty hunter these tips are for…
[Crypto] Why authenticated encryption and MAC is so important
https://ift.tt/3ceIUDK
Submitted October 24, 2023 at 09:23PM by yurichev
via reddit https://ift.tt/0BHy1DY
https://ift.tt/3ceIUDK
Submitted October 24, 2023 at 09:23PM by yurichev
via reddit https://ift.tt/0BHy1DY
Certificate Ripper v2.2.0 released - tool to extract server certificates
https://ift.tt/gRFaLQn
Submitted October 25, 2023 at 12:59AM by Hakky54
via reddit https://ift.tt/xb7HYkp
https://ift.tt/gRFaLQn
Submitted October 25, 2023 at 12:59AM by Hakky54
via reddit https://ift.tt/xb7HYkp
GitHub
GitHub - Hakky54/certificate-ripper: 🔐 A CLI tool to extract server certificates
🔐 A CLI tool to extract server certificates. Contribute to Hakky54/certificate-ripper development by creating an account on GitHub.
Yet another vulnerability AI scoring. Now in scale.
https://ift.tt/FMzKunJ
Submitted October 25, 2023 at 10:01AM by videns
via reddit https://ift.tt/p2O7YiT
https://ift.tt/FMzKunJ
Submitted October 25, 2023 at 10:01AM by videns
via reddit https://ift.tt/p2O7YiT
Vulners
We analyzed 3 million cybersecurity records and here is what we came up with: Vulners AI Score v2 | Vulners
Discover vulnerability assessment using artificial intelligence: start using the new AI score as a second opinion, don't rely on the CVSS score alone.
Tenable + Ermetic
https://ift.tt/4N6h7MP
Submitted October 25, 2023 at 10:56AM by JustifiedSimplicity
via reddit https://ift.tt/nDMIet2
https://ift.tt/4N6h7MP
Submitted October 25, 2023 at 10:56AM by JustifiedSimplicity
via reddit https://ift.tt/nDMIet2
Tenable®
Tenable Completes Acquisition of Ermetic
Tenable® Holdings, Inc., the Exposure Management company, today announced it has closed its acquisition of Ermetic, Ltd. (“Ermetic”), an innovative cloud-native application protection platform (CNAPP) company, and a leading provider of cloud infrastructure…
CVE-2021-27198 - Arbitrary Write to RCE
https://ift.tt/quaR2Mn
Submitted October 25, 2023 at 06:16PM by securifera
via reddit https://ift.tt/pwGBIRt
https://ift.tt/quaR2Mn
Submitted October 25, 2023 at 06:16PM by securifera
via reddit https://ift.tt/pwGBIRt
Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction
https://ift.tt/7xRzBaS
Submitted October 25, 2023 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/kYTRdC3
https://ift.tt/7xRzBaS
Submitted October 25, 2023 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/kYTRdC3
Microsoft Security Blog
Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction | Microsoft Security Blog
Financially motivated threat actor Octo Tempest's evolving campaigns represent growing concern for organizations across multiple industries.
Cisco IOS XE CVE-2023-20198 and CVE-2023-20273: WebUI Internals, Patch Diffs, and Theory Crafting
https://ift.tt/WgqkvQt
Submitted October 26, 2023 at 12:19AM by scopedsecurity
via reddit https://ift.tt/QMmTVvn
https://ift.tt/WgqkvQt
Submitted October 26, 2023 at 12:19AM by scopedsecurity
via reddit https://ift.tt/QMmTVvn
Horizon3.ai
Cisco IOS XE CVE-2023-20198 and CVE-2023-20273: WebUI Internals, Patch Diffs, and Theory Crafting – Horizon3.ai
Cisco IOS XE CVE-2023-20198 technical deep-dive, WebUI internals, patch diffing, and exploit theory crafting.
Perfect DLL Hijacking
https://ift.tt/m3LZ8HE
Submitted October 26, 2023 at 09:43AM by elliotkillick
via reddit https://ift.tt/uTo3GkI
https://ift.tt/m3LZ8HE
Submitted October 26, 2023 at 09:43AM by elliotkillick
via reddit https://ift.tt/uTo3GkI
Elliot on Security
Elliot on Security - Perfect DLL Hijacking
Disengaging Loader Lock to do anything directly from DLLMain...
CVE-2023-4357: Libxslt arbitrary file reading using document() method and external entities
https://ift.tt/ZH84MQz
Submitted October 26, 2023 at 02:23PM by poltess0
via reddit https://ift.tt/oI4KbZs
https://ift.tt/ZH84MQz
Submitted October 26, 2023 at 02:23PM by poltess0
via reddit https://ift.tt/oI4KbZs
CVE-2023-46747: Pre-Auth Remote Code Execution in F5-BIGIP via AJP Request Smuggling
https://ift.tt/65GQvTf
Submitted October 26, 2023 at 11:16PM by bouncyhat
via reddit https://ift.tt/oJ6FjgI
https://ift.tt/65GQvTf
Submitted October 26, 2023 at 11:16PM by bouncyhat
via reddit https://ift.tt/oJ6FjgI
Praetorian
Refresh: Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747 | Praetorian
Overview In an effort to safeguard our customers, we perform proactive vulnerability research with the goal of identifying zero-day vulnerabilities that are likely to impact the security of leading organizations. We decided to focus on the F5 BIG-IP suite…
Threat Hunting: Detecting Browser Credential Stealing [T1555.003]
https://ift.tt/DFQsgl0
Submitted October 26, 2023 at 10:36PM by achilles4828
via reddit https://ift.tt/nM9LQrK
https://ift.tt/DFQsgl0
Submitted October 26, 2023 at 10:36PM by achilles4828
via reddit https://ift.tt/nM9LQrK
FourCore
Threat Hunting: Detecting Browser Credential Stealing [T1555.003]
Adversaries can steal credentials, cookies and other private data from browsers using various techniques. We cover how you can simulate Credential Stealing From Browser s and detect it with your security tools. Sigma Rules Inside.
Cure53 | Pentest-Report Tor Browser & OONI 02.-03.2023
https://ift.tt/uhSOp7i
Submitted October 27, 2023 at 05:38PM by shulginlegacy
via reddit https://ift.tt/gNMmlsh
https://ift.tt/uhSOp7i
Submitted October 27, 2023 at 05:38PM by shulginlegacy
via reddit https://ift.tt/gNMmlsh
Discoshell - a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and others
https://ift.tt/1b6pqvr
Submitted October 28, 2023 at 12:06AM by fz0x1
via reddit https://ift.tt/myVfxK5
https://ift.tt/1b6pqvr
Submitted October 28, 2023 at 12:06AM by fz0x1
via reddit https://ift.tt/myVfxK5
GitHub
GitHub - foozzi/discoshell: a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and…
a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and others - foozzi/discoshell
A new ransomware uses virtual machine to dodge security
https://ift.tt/F31rPEb
Submitted October 28, 2023 at 03:37AM by Bionic-Ion
via reddit https://ift.tt/m9f1FiR
https://ift.tt/F31rPEb
Submitted October 28, 2023 at 03:37AM by Bionic-Ion
via reddit https://ift.tt/m9f1FiR
HT Tech
A new ransomware uses virtual machine to dodge security
Ragnar Locker remains out of reach of the security software.
De4py: Toolkit for python reverse engineering
https://ift.tt/0lH3awx
Submitted October 28, 2023 at 03:08AM by AhmedMinegames
via reddit https://ift.tt/XfsHTln
https://ift.tt/0lH3awx
Submitted October 28, 2023 at 03:08AM by AhmedMinegames
via reddit https://ift.tt/XfsHTln
GitHub
GitHub - Fadi002/de4py: toolkit for python reverse engineering
toolkit for python reverse engineering. Contribute to Fadi002/de4py development by creating an account on GitHub.
Three new NGINX ingress controller vulnerabilities were just reported and how they affect Kubernetes
https://ift.tt/yeS4swu
Submitted October 28, 2023 at 05:01PM by Jonkaftzan
via reddit https://ift.tt/xHivzS0
https://ift.tt/yeS4swu
Submitted October 28, 2023 at 05:01PM by Jonkaftzan
via reddit https://ift.tt/xHivzS0
ARMO
3 new NGINX ingress controller Kubernetes related vulnerabilities
CVE-2023-5043, CVE-2023-5044 and CVE-2022-4886 can be exploited by attacker to steal secret credentials from the cluster. Read all about it!
Turning a boring file move into a privilege escalation on Mac
https://ift.tt/KY34w5i
Submitted October 28, 2023 at 04:41PM by DOTheLOGA
via reddit https://ift.tt/KG5qR6d
https://ift.tt/KY34w5i
Submitted October 28, 2023 at 04:41PM by DOTheLOGA
via reddit https://ift.tt/KG5qR6d
pwn.win
Turning a boring file move into a privilege escalation on Mac
While poking around Parallels Desktop I found a noscript which is invoked by a setuid-root binary, which has the following snippet: local prl_dir="${usr_home}/Library/Parallels" if [ -e "$prl_dir" -a ! -d "$prl_dir" ]; then log warning "'${prl_dir}' is not…
How I Hack WiFi Passwords in 10 minutes using Hashcat
https://ift.tt/oz09gXu
Submitted October 28, 2023 at 07:03PM by keshav_xplore
via reddit https://ift.tt/ilxpdDR
https://ift.tt/oz09gXu
Submitted October 28, 2023 at 07:03PM by keshav_xplore
via reddit https://ift.tt/ilxpdDR
Keshav Xplore
How to Hack WiFi Passwords in 10 minutes using Hashcat
Uncover the steps to hack WiFi passwords using Hashcat. This guide provides a comprehensive walkthrough, from dictionary attacks to brute-force attack