CVE-2021-27198 - Arbitrary Write to RCE
https://ift.tt/quaR2Mn
Submitted October 25, 2023 at 06:16PM by securifera
via reddit https://ift.tt/pwGBIRt
https://ift.tt/quaR2Mn
Submitted October 25, 2023 at 06:16PM by securifera
via reddit https://ift.tt/pwGBIRt
Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction
https://ift.tt/7xRzBaS
Submitted October 25, 2023 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/kYTRdC3
https://ift.tt/7xRzBaS
Submitted October 25, 2023 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/kYTRdC3
Microsoft Security Blog
Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction | Microsoft Security Blog
Financially motivated threat actor Octo Tempest's evolving campaigns represent growing concern for organizations across multiple industries.
Cisco IOS XE CVE-2023-20198 and CVE-2023-20273: WebUI Internals, Patch Diffs, and Theory Crafting
https://ift.tt/WgqkvQt
Submitted October 26, 2023 at 12:19AM by scopedsecurity
via reddit https://ift.tt/QMmTVvn
https://ift.tt/WgqkvQt
Submitted October 26, 2023 at 12:19AM by scopedsecurity
via reddit https://ift.tt/QMmTVvn
Horizon3.ai
Cisco IOS XE CVE-2023-20198 and CVE-2023-20273: WebUI Internals, Patch Diffs, and Theory Crafting – Horizon3.ai
Cisco IOS XE CVE-2023-20198 technical deep-dive, WebUI internals, patch diffing, and exploit theory crafting.
Perfect DLL Hijacking
https://ift.tt/m3LZ8HE
Submitted October 26, 2023 at 09:43AM by elliotkillick
via reddit https://ift.tt/uTo3GkI
https://ift.tt/m3LZ8HE
Submitted October 26, 2023 at 09:43AM by elliotkillick
via reddit https://ift.tt/uTo3GkI
Elliot on Security
Elliot on Security - Perfect DLL Hijacking
Disengaging Loader Lock to do anything directly from DLLMain...
CVE-2023-4357: Libxslt arbitrary file reading using document() method and external entities
https://ift.tt/ZH84MQz
Submitted October 26, 2023 at 02:23PM by poltess0
via reddit https://ift.tt/oI4KbZs
https://ift.tt/ZH84MQz
Submitted October 26, 2023 at 02:23PM by poltess0
via reddit https://ift.tt/oI4KbZs
CVE-2023-46747: Pre-Auth Remote Code Execution in F5-BIGIP via AJP Request Smuggling
https://ift.tt/65GQvTf
Submitted October 26, 2023 at 11:16PM by bouncyhat
via reddit https://ift.tt/oJ6FjgI
https://ift.tt/65GQvTf
Submitted October 26, 2023 at 11:16PM by bouncyhat
via reddit https://ift.tt/oJ6FjgI
Praetorian
Refresh: Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747 | Praetorian
Overview In an effort to safeguard our customers, we perform proactive vulnerability research with the goal of identifying zero-day vulnerabilities that are likely to impact the security of leading organizations. We decided to focus on the F5 BIG-IP suite…
Threat Hunting: Detecting Browser Credential Stealing [T1555.003]
https://ift.tt/DFQsgl0
Submitted October 26, 2023 at 10:36PM by achilles4828
via reddit https://ift.tt/nM9LQrK
https://ift.tt/DFQsgl0
Submitted October 26, 2023 at 10:36PM by achilles4828
via reddit https://ift.tt/nM9LQrK
FourCore
Threat Hunting: Detecting Browser Credential Stealing [T1555.003]
Adversaries can steal credentials, cookies and other private data from browsers using various techniques. We cover how you can simulate Credential Stealing From Browser s and detect it with your security tools. Sigma Rules Inside.
Cure53 | Pentest-Report Tor Browser & OONI 02.-03.2023
https://ift.tt/uhSOp7i
Submitted October 27, 2023 at 05:38PM by shulginlegacy
via reddit https://ift.tt/gNMmlsh
https://ift.tt/uhSOp7i
Submitted October 27, 2023 at 05:38PM by shulginlegacy
via reddit https://ift.tt/gNMmlsh
Discoshell - a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and others
https://ift.tt/1b6pqvr
Submitted October 28, 2023 at 12:06AM by fz0x1
via reddit https://ift.tt/myVfxK5
https://ift.tt/1b6pqvr
Submitted October 28, 2023 at 12:06AM by fz0x1
via reddit https://ift.tt/myVfxK5
GitHub
GitHub - foozzi/discoshell: a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and…
a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and others - foozzi/discoshell
A new ransomware uses virtual machine to dodge security
https://ift.tt/F31rPEb
Submitted October 28, 2023 at 03:37AM by Bionic-Ion
via reddit https://ift.tt/m9f1FiR
https://ift.tt/F31rPEb
Submitted October 28, 2023 at 03:37AM by Bionic-Ion
via reddit https://ift.tt/m9f1FiR
HT Tech
A new ransomware uses virtual machine to dodge security
Ragnar Locker remains out of reach of the security software.
De4py: Toolkit for python reverse engineering
https://ift.tt/0lH3awx
Submitted October 28, 2023 at 03:08AM by AhmedMinegames
via reddit https://ift.tt/XfsHTln
https://ift.tt/0lH3awx
Submitted October 28, 2023 at 03:08AM by AhmedMinegames
via reddit https://ift.tt/XfsHTln
GitHub
GitHub - Fadi002/de4py: toolkit for python reverse engineering
toolkit for python reverse engineering. Contribute to Fadi002/de4py development by creating an account on GitHub.
Three new NGINX ingress controller vulnerabilities were just reported and how they affect Kubernetes
https://ift.tt/yeS4swu
Submitted October 28, 2023 at 05:01PM by Jonkaftzan
via reddit https://ift.tt/xHivzS0
https://ift.tt/yeS4swu
Submitted October 28, 2023 at 05:01PM by Jonkaftzan
via reddit https://ift.tt/xHivzS0
ARMO
3 new NGINX ingress controller Kubernetes related vulnerabilities
CVE-2023-5043, CVE-2023-5044 and CVE-2022-4886 can be exploited by attacker to steal secret credentials from the cluster. Read all about it!
Turning a boring file move into a privilege escalation on Mac
https://ift.tt/KY34w5i
Submitted October 28, 2023 at 04:41PM by DOTheLOGA
via reddit https://ift.tt/KG5qR6d
https://ift.tt/KY34w5i
Submitted October 28, 2023 at 04:41PM by DOTheLOGA
via reddit https://ift.tt/KG5qR6d
pwn.win
Turning a boring file move into a privilege escalation on Mac
While poking around Parallels Desktop I found a noscript which is invoked by a setuid-root binary, which has the following snippet: local prl_dir="${usr_home}/Library/Parallels" if [ -e "$prl_dir" -a ! -d "$prl_dir" ]; then log warning "'${prl_dir}' is not…
How I Hack WiFi Passwords in 10 minutes using Hashcat
https://ift.tt/oz09gXu
Submitted October 28, 2023 at 07:03PM by keshav_xplore
via reddit https://ift.tt/ilxpdDR
https://ift.tt/oz09gXu
Submitted October 28, 2023 at 07:03PM by keshav_xplore
via reddit https://ift.tt/ilxpdDR
Keshav Xplore
How to Hack WiFi Passwords in 10 minutes using Hashcat
Uncover the steps to hack WiFi passwords using Hashcat. This guide provides a comprehensive walkthrough, from dictionary attacks to brute-force attack
Finally a Offsec ML Framework
https://ift.tt/34ElY8h
Submitted October 28, 2023 at 07:52PM by layzhi
via reddit https://ift.tt/joxqWwh
https://ift.tt/34ElY8h
Submitted October 28, 2023 at 07:52PM by layzhi
via reddit https://ift.tt/joxqWwh
OffSecML Playbook
Welcome to the Offensive ML Playbook - OffSecML Playbook
Latest: 4/02/24 version: 0.9.9 First published 10/26/23. Shiny new things Inverting DNN models with a framework A threat intelligence update to the ML Pipeline Attacks on Ray Updates to repeated tok…
The Importance of Self-Custody Password Managers: A Deep Dive
https://ift.tt/c7rxzmS
Submitted October 30, 2023 at 02:19AM by zoggy90
via reddit https://ift.tt/wkAmGFd
https://ift.tt/c7rxzmS
Submitted October 30, 2023 at 02:19AM by zoggy90
via reddit https://ift.tt/wkAmGFd
Help Everyone Do Better Security
https://ift.tt/KRUzuAC
Submitted October 30, 2023 at 01:26PM by haroldmilesandray47
via reddit https://ift.tt/BnTiCeb
https://ift.tt/KRUzuAC
Submitted October 30, 2023 at 01:26PM by haroldmilesandray47
via reddit https://ift.tt/BnTiCeb
matduggan.com
Help Everyone Do Better Security
One interesting thing about the contrast between infrastructure and security is the expectation of open-source software. When a common problem arises we all experience, a company will launch a product to solve this problem. In infrastructure, typically the…
Detecting and annoying Burp users
https://ift.tt/nLMj6aQ
Submitted October 30, 2023 at 04:32PM by meowerguy
via reddit https://ift.tt/n1rLIqj
https://ift.tt/nLMj6aQ
Submitted October 30, 2023 at 04:32PM by meowerguy
via reddit https://ift.tt/n1rLIqj
web.archive.org
Detecting and annoying Burp users
Personal blog of Julien (jvoisin) Voisin
How HackerOne Is Building Responsible Generative AI
https://ift.tt/LDkb4yU
Submitted October 30, 2023 at 04:29PM by meowerguy
via reddit https://ift.tt/MgmyfEF
https://ift.tt/LDkb4yU
Submitted October 30, 2023 at 04:29PM by meowerguy
via reddit https://ift.tt/MgmyfEF
HackerOne
Responsible AI at HackerOne
At HackerOne, we are combining human intelligence with artificial intelligence at scale to improve the efficiency of people and unlock entirely new capabilities.
NetSupport Intrusion Results in Domain Compromise
https://ift.tt/MI2xkCd
Submitted October 30, 2023 at 06:47PM by TheDFIRReport
via reddit https://ift.tt/df5C6Rm
https://ift.tt/MI2xkCd
Submitted October 30, 2023 at 06:47PM by TheDFIRReport
via reddit https://ift.tt/df5C6Rm
The DFIR Report
NetSupport Intrusion Results in Domain Compromise
NetSupport Manager is one of the oldest third-party remote access tools still currently on the market with over 33 years of history. This is the first time we will report on a NetSupport RAT intrus…
Scapy in your browser
https://ift.tt/eEAqFbf
Submitted October 30, 2023 at 10:07PM by guedou
via reddit https://ift.tt/3CK19oj
https://ift.tt/eEAqFbf
Submitted October 30, 2023 at 10:07PM by guedou
via reddit https://ift.tt/3CK19oj