Prioritising Vulnerabilities Remedial Actions at Scale with EPSS
https://ift.tt/AsRoeF5
Submitted November 03, 2023 at 12:48AM by theowni
via reddit https://ift.tt/n25KZfo
https://ift.tt/AsRoeF5
Submitted November 03, 2023 at 12:48AM by theowni
via reddit https://ift.tt/n25KZfo
Medium
Prioritising Vulnerabilities Remedial Actions at Scale with EPSS
In this article, I’m presenting the Exploit Prediction Scoring System, its practical use cases, and how it can be used in tandem with CVSS.
Dozens of npm Packages Caught Attempting to Deploy Reverse Shell
https://ift.tt/7MC0VkE
Submitted November 02, 2023 at 11:57PM by louis11
via reddit https://ift.tt/9OVRfUM
https://ift.tt/7MC0VkE
Submitted November 02, 2023 at 11:57PM by louis11
via reddit https://ift.tt/9OVRfUM
Phylum
Dozens of npm Packages Caught Attempting to Deploy Reverse Shell
On October 27, Phylum’s automated risk detection platform began alerting us to a series of suspicious publications on npm. Over the course of the following few days, we discovered a campaign involving at least 48 different publications. These packages, deceptively…
Use Wasm to Bypass Latest Chrome v8sbx Again
https://ift.tt/wS5ML6z
Submitted November 03, 2023 at 03:18PM by poltess0
via reddit https://ift.tt/4hNxTXq
https://ift.tt/wS5ML6z
Submitted November 03, 2023 at 03:18PM by poltess0
via reddit https://ift.tt/4hNxTXq
Medium
Use Wasm to Bypass Latest Chrome v8sbx Again
01 - Introduction
Keylogger keyboard leaks passwords via Apple's "Find My" location network
https://ift.tt/DOvZBHb
Submitted November 03, 2023 at 07:01PM by ctmagazin
via reddit https://ift.tt/Lpx7AtV
https://ift.tt/DOvZBHb
Submitted November 03, 2023 at 07:01PM by ctmagazin
via reddit https://ift.tt/Lpx7AtV
Security
Keylogger keyboard leaks passwords via Apple's "Find My" location network
Originally, it is supposed to help track down lost things. However, our keylogger keyboard uses Apple's "Find My" location network to send sensitive data.
Looney Tunables Vulnerability Exploited by Kinsing
https://ift.tt/anibrgV
Submitted November 03, 2023 at 10:04PM by Easy-Bumblebee2503
via reddit https://ift.tt/ywlBYcT
https://ift.tt/anibrgV
Submitted November 03, 2023 at 10:04PM by Easy-Bumblebee2503
via reddit https://ift.tt/ywlBYcT
Aqua
Looney Tunables Vulnerability Exploited by Kinsing
We intercepted Kinsing's experimental incursions into cloud environments and have uncovered their efforts to manipulate the Looney Tunables vulnerability.
A stranger knows your lock code.
https://ift.tt/WNsYTk3
Submitted November 04, 2023 at 03:53PM by Thekeksociety-1313
via reddit https://ift.tt/mUK3hFP
https://ift.tt/WNsYTk3
Submitted November 04, 2023 at 03:53PM by Thekeksociety-1313
via reddit https://ift.tt/mUK3hFP
Smashing the TLB for fun and profit - ekoparty 2023
https://ift.tt/mrVCF3M
Submitted November 05, 2023 at 07:52AM by maurosoria
via reddit https://ift.tt/bvpNueM
https://ift.tt/mrVCF3M
Submitted November 05, 2023 at 07:52AM by maurosoria
via reddit https://ift.tt/bvpNueM
Looking for exploit dev/ vulnerability research blogs
https://ift.tt/1v5Hzt8
Submitted November 05, 2023 at 06:14PM by SnooSeagulls7023
via reddit https://ift.tt/wUKk05f
https://ift.tt/1v5Hzt8
Submitted November 05, 2023 at 06:14PM by SnooSeagulls7023
via reddit https://ift.tt/wUKk05f
Malwaretech
BlueKeep: A Journey from DoS to RCE (CVE-2019-0708) – MalwareTech
Due to the serious risk of a BlueKeep based worm, I’ve held back this write-up to avoid advancing the timeline. Now that a proof-of-concept for RCE (remote code execution) has been release as part of Metasploit, i feel it’s now safe for me to post this.
Persistence – Windows Telemetry
https://ift.tt/OHKmSpx
Submitted November 06, 2023 at 02:36PM by netbiosX
via reddit https://ift.tt/n6bgCQF
https://ift.tt/OHKmSpx
Submitted November 06, 2023 at 02:36PM by netbiosX
via reddit https://ift.tt/n6bgCQF
Penetration Testing Lab
Persistence – Windows Telemetry
Microsoft has introduced the compatibility telemetry in order to collect usage and performance data about Windows systems. The telemetry tasks are collected via the binary “CompatTelRunner.ex…
Blue2thprinting (blue-[tooth)-printing]: answering the question of 'WTF am I even looking at?!' (Slides from Hardwear.io last week)
https://ift.tt/GbUHTVR
Submitted November 06, 2023 at 05:45PM by BIOS4breakfast
via reddit https://ift.tt/F5csKw2
https://ift.tt/GbUHTVR
Submitted November 06, 2023 at 05:45PM by BIOS4breakfast
via reddit https://ift.tt/F5csKw2
Dark Mentor LLC
Blue2thprinting (blue-[tooth)-printing]: answering the question of 'WTF am I even looking at?!'
| Dark Mentor LLC
| Dark Mentor LLC
If one wants to know (for attack or defense) whether a Bluetooth (BT) device is vulnerable to unauthenticated remote over-the-air exploits, one needs to be able to query what firmware or OS the target is running. Unfortunately there is no universally-available…
Open Wounds: The last 5 years have left Bluetooth to bleed (Slides & Hack.lu video)
https://ift.tt/6UoylSz
Submitted November 06, 2023 at 05:45PM by BIOS4breakfast
via reddit https://ift.tt/275x4MK
https://ift.tt/6UoylSz
Submitted November 06, 2023 at 05:45PM by BIOS4breakfast
via reddit https://ift.tt/275x4MK
Dark Mentor LLC
Open Wounds: The last 5 years have left Bluetooth to bleed
| Dark Mentor LLC
| Dark Mentor LLC
Over the past 20 years there have been 3 waves of Bluetooth (BT) security research. The first wave peaked in 2004, and rather abruptly ended after 2005. Then for a long time there was very low interest and activity. That began to change around 2011 with the…
It Was Harder to Sniff Bluetooth Through My Mask During the Pandemic... (Slides & HITB HKT video)
https://ift.tt/yMvLsW9
Submitted November 06, 2023 at 05:44PM by BIOS4breakfast
via reddit https://ift.tt/CQxPwzN
https://ift.tt/yMvLsW9
Submitted November 06, 2023 at 05:44PM by BIOS4breakfast
via reddit https://ift.tt/CQxPwzN
Dark Mentor LLC
It Was Harder to Sniff Bluetooth Through My Mask During the Pandemic...
| Dark Mentor LLC
| Dark Mentor LLC
During the pandemic I took up Bluetooth (BT) sniffing as a way to get out of the house. I didn’t know what was out there for BT devices, but it felt important to know what the implications were of the new over-the-air, no-auth, cross-device, firmware-level…
Your printer is not your printer ! - Hacking Printers at Pwn2Own Part II | DEVCORE 戴夫寇爾
https://ift.tt/n4mwKUv
Submitted November 06, 2023 at 08:58PM by poltess0
via reddit https://ift.tt/yRYrvNh
https://ift.tt/n4mwKUv
Submitted November 06, 2023 at 08:58PM by poltess0
via reddit https://ift.tt/yRYrvNh
DEVCORE 戴夫寇爾
Your printer is not your printer ! - Hacking Printers at Pwn2Own Part II | DEVCORE 戴夫寇爾
We identified Pre-auth RCE vulnerabilities in Canon printers (CVE-2023-0853, CVE-2023-0854) and also discovered Pre-auth RCE flaws in HP printers, which led to our achievement of the Master of Pwn noscript at Pwn2Own Toronto 2022. This article will detail the…
Top 10 Best Open Source Tools for Malware Analysis (Updated)
https://ift.tt/QJWpUyI
Submitted November 06, 2023 at 09:44PM by keshav_xplore
via reddit https://ift.tt/yC1SXAG
https://ift.tt/QJWpUyI
Submitted November 06, 2023 at 09:44PM by keshav_xplore
via reddit https://ift.tt/yC1SXAG
Keshav Xplore
Top 10 Best Open Source Tools for Malware Analysis (Updated For 2024)
Unveil the best open source malware analysis tools to bolster your cybersecurity. Learn about their key features, functions, and how they work.
OPC UA Vulnerability Scanner - OpalOPC
https://opalopc.com/
Submitted November 06, 2023 at 11:45PM by Salmiakkilakritsi
via reddit https://ift.tt/hlOyfVM
https://opalopc.com/
Submitted November 06, 2023 at 11:45PM by Salmiakkilakritsi
via reddit https://ift.tt/hlOyfVM
Opalopc
OPC UA Vulnerability Scanner | OpalOPC
Reveal Security Issues in your Most Critical Systems.
OST2, Zephyr RTOS, and a bunch of CVEs
https://ift.tt/uRoC3YN
Submitted November 07, 2023 at 01:08PM by 0xdea
via reddit https://ift.tt/8dlmSnF
https://ift.tt/uRoC3YN
Submitted November 07, 2023 at 01:08PM by 0xdea
via reddit https://ift.tt/8dlmSnF
hn security
OST2, Zephyr RTOS, and a bunch of CVEs - hn security
“When hackers tell me it’s so […]
Post-exploiting a compromised etcd – Full control over the cluster and its nodes
https://ift.tt/456N1ix
Submitted November 07, 2023 at 02:09PM by D4r1
via reddit https://ift.tt/iZQ2r5O
https://ift.tt/456N1ix
Submitted November 07, 2023 at 02:09PM by D4r1
via reddit https://ift.tt/iZQ2r5O
NCC Group Research Blog
Post-exploiting a compromised etcd – Full control over the cluster and its nodes
Kubernetes is essentially a framework of various services that make up its typical architecture, which can be divided into two roles: the control-plane, which serves as a central control hub and ho…
Session Hijacking Visual Exploitation, New release with Office Documents Poisoning
https://ift.tt/KvUmDNH
Submitted November 07, 2023 at 04:17PM by nibblesec
via reddit https://ift.tt/eKd61MD
https://ift.tt/KvUmDNH
Submitted November 07, 2023 at 04:17PM by nibblesec
via reddit https://ift.tt/eKd61MD
Doyensec
Office Documents Poisoning in SHVE · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Data leak hits 665,000 MBS rewards programme members
https://ift.tt/3MkDqQU
Submitted November 07, 2023 at 06:35PM by gemyougym
via reddit https://ift.tt/w3dGLP1
https://ift.tt/3MkDqQU
Submitted November 07, 2023 at 06:35PM by gemyougym
via reddit https://ift.tt/w3dGLP1
The Straits Times
Data leak hits 665,000 MBS rewards programme members
MBS does not have evidence so far that the personal information has been misused. Read more at straitstimes.com.
Session-Hijacking-Visual-Exploitation: Session Hijacking Visual Exploitation
https://ift.tt/POzJxKw
Submitted November 07, 2023 at 06:31PM by gemyougym
via reddit https://ift.tt/S0zIHDZ
https://ift.tt/POzJxKw
Submitted November 07, 2023 at 06:31PM by gemyougym
via reddit https://ift.tt/S0zIHDZ
GitHub
GitHub - doyensec/Session-Hijacking-Visual-Exploitation: Session Hijacking Visual Exploitation
Session Hijacking Visual Exploitation. Contribute to doyensec/Session-Hijacking-Visual-Exploitation development by creating an account on GitHub.
When a vulnerability disclosure doesn't go how you expect.
https://ift.tt/aWHsQ1I
Submitted November 08, 2023 at 03:28AM by ezzzzz
via reddit https://ift.tt/nRo49d1
https://ift.tt/aWHsQ1I
Submitted November 08, 2023 at 03:28AM by ezzzzz
via reddit https://ift.tt/nRo49d1
Research Blog | Project Black
Why You Need a Vulnerability Disclosure Program (VDP)
You're out for a stroll and spot a house with its front door wide open. Out of concern, you try to inform the owner about the door. Unexpectedly, the owner snaps back, insisting the door is shut. This is a story about the worst vulnerability disclosure process…