It Was Harder to Sniff Bluetooth Through My Mask During the Pandemic... (Slides & HITB HKT video)
https://ift.tt/yMvLsW9
Submitted November 06, 2023 at 05:44PM by BIOS4breakfast
via reddit https://ift.tt/CQxPwzN
https://ift.tt/yMvLsW9
Submitted November 06, 2023 at 05:44PM by BIOS4breakfast
via reddit https://ift.tt/CQxPwzN
Dark Mentor LLC
It Was Harder to Sniff Bluetooth Through My Mask During the Pandemic...
| Dark Mentor LLC
| Dark Mentor LLC
During the pandemic I took up Bluetooth (BT) sniffing as a way to get out of the house. I didn’t know what was out there for BT devices, but it felt important to know what the implications were of the new over-the-air, no-auth, cross-device, firmware-level…
Your printer is not your printer ! - Hacking Printers at Pwn2Own Part II | DEVCORE 戴夫寇爾
https://ift.tt/n4mwKUv
Submitted November 06, 2023 at 08:58PM by poltess0
via reddit https://ift.tt/yRYrvNh
https://ift.tt/n4mwKUv
Submitted November 06, 2023 at 08:58PM by poltess0
via reddit https://ift.tt/yRYrvNh
DEVCORE 戴夫寇爾
Your printer is not your printer ! - Hacking Printers at Pwn2Own Part II | DEVCORE 戴夫寇爾
We identified Pre-auth RCE vulnerabilities in Canon printers (CVE-2023-0853, CVE-2023-0854) and also discovered Pre-auth RCE flaws in HP printers, which led to our achievement of the Master of Pwn noscript at Pwn2Own Toronto 2022. This article will detail the…
Top 10 Best Open Source Tools for Malware Analysis (Updated)
https://ift.tt/QJWpUyI
Submitted November 06, 2023 at 09:44PM by keshav_xplore
via reddit https://ift.tt/yC1SXAG
https://ift.tt/QJWpUyI
Submitted November 06, 2023 at 09:44PM by keshav_xplore
via reddit https://ift.tt/yC1SXAG
Keshav Xplore
Top 10 Best Open Source Tools for Malware Analysis (Updated For 2024)
Unveil the best open source malware analysis tools to bolster your cybersecurity. Learn about their key features, functions, and how they work.
OPC UA Vulnerability Scanner - OpalOPC
https://opalopc.com/
Submitted November 06, 2023 at 11:45PM by Salmiakkilakritsi
via reddit https://ift.tt/hlOyfVM
https://opalopc.com/
Submitted November 06, 2023 at 11:45PM by Salmiakkilakritsi
via reddit https://ift.tt/hlOyfVM
Opalopc
OPC UA Vulnerability Scanner | OpalOPC
Reveal Security Issues in your Most Critical Systems.
OST2, Zephyr RTOS, and a bunch of CVEs
https://ift.tt/uRoC3YN
Submitted November 07, 2023 at 01:08PM by 0xdea
via reddit https://ift.tt/8dlmSnF
https://ift.tt/uRoC3YN
Submitted November 07, 2023 at 01:08PM by 0xdea
via reddit https://ift.tt/8dlmSnF
hn security
OST2, Zephyr RTOS, and a bunch of CVEs - hn security
“When hackers tell me it’s so […]
Post-exploiting a compromised etcd – Full control over the cluster and its nodes
https://ift.tt/456N1ix
Submitted November 07, 2023 at 02:09PM by D4r1
via reddit https://ift.tt/iZQ2r5O
https://ift.tt/456N1ix
Submitted November 07, 2023 at 02:09PM by D4r1
via reddit https://ift.tt/iZQ2r5O
NCC Group Research Blog
Post-exploiting a compromised etcd – Full control over the cluster and its nodes
Kubernetes is essentially a framework of various services that make up its typical architecture, which can be divided into two roles: the control-plane, which serves as a central control hub and ho…
Session Hijacking Visual Exploitation, New release with Office Documents Poisoning
https://ift.tt/KvUmDNH
Submitted November 07, 2023 at 04:17PM by nibblesec
via reddit https://ift.tt/eKd61MD
https://ift.tt/KvUmDNH
Submitted November 07, 2023 at 04:17PM by nibblesec
via reddit https://ift.tt/eKd61MD
Doyensec
Office Documents Poisoning in SHVE · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Data leak hits 665,000 MBS rewards programme members
https://ift.tt/3MkDqQU
Submitted November 07, 2023 at 06:35PM by gemyougym
via reddit https://ift.tt/w3dGLP1
https://ift.tt/3MkDqQU
Submitted November 07, 2023 at 06:35PM by gemyougym
via reddit https://ift.tt/w3dGLP1
The Straits Times
Data leak hits 665,000 MBS rewards programme members
MBS does not have evidence so far that the personal information has been misused. Read more at straitstimes.com.
Session-Hijacking-Visual-Exploitation: Session Hijacking Visual Exploitation
https://ift.tt/POzJxKw
Submitted November 07, 2023 at 06:31PM by gemyougym
via reddit https://ift.tt/S0zIHDZ
https://ift.tt/POzJxKw
Submitted November 07, 2023 at 06:31PM by gemyougym
via reddit https://ift.tt/S0zIHDZ
GitHub
GitHub - doyensec/Session-Hijacking-Visual-Exploitation: Session Hijacking Visual Exploitation
Session Hijacking Visual Exploitation. Contribute to doyensec/Session-Hijacking-Visual-Exploitation development by creating an account on GitHub.
When a vulnerability disclosure doesn't go how you expect.
https://ift.tt/aWHsQ1I
Submitted November 08, 2023 at 03:28AM by ezzzzz
via reddit https://ift.tt/nRo49d1
https://ift.tt/aWHsQ1I
Submitted November 08, 2023 at 03:28AM by ezzzzz
via reddit https://ift.tt/nRo49d1
Research Blog | Project Black
Why You Need a Vulnerability Disclosure Program (VDP)
You're out for a stroll and spot a house with its front door wide open. Out of concern, you try to inform the owner about the door. Unexpectedly, the owner snaps back, insisting the door is shut. This is a story about the worst vulnerability disclosure process…
The Escalating Digital Front in the Israel-Hamas Conflict
https://ift.tt/n08HzqV
Submitted November 08, 2023 at 01:53PM by woja111
via reddit https://ift.tt/VXUH6sr
https://ift.tt/n08HzqV
Submitted November 08, 2023 at 01:53PM by woja111
via reddit https://ift.tt/VXUH6sr
OP Innovate - Premium Application Penetration testing and Incident Response
The Escalating Cyber Front in the Israel-ISISHamas Conflict
The Israel-ISISHamas conflict has recently seen an alarming shift from traditional battlegrounds to sophisticated cyber warfare.
Former Meta staffer’s allegations renew calls for kids online safety bill
https://ift.tt/oyWxs0m
Submitted November 08, 2023 at 01:43PM by anujtomar_17
via reddit https://ift.tt/hqrbLgB
https://ift.tt/oyWxs0m
Submitted November 08, 2023 at 01:43PM by anujtomar_17
via reddit https://ift.tt/hqrbLgB
Visual Studio Code Security: Deep Dive into Your Favorite Editor (1/3)
https://ift.tt/zOJs5mb
Submitted November 08, 2023 at 03:57PM by monoimpact
via reddit https://ift.tt/AN8wKj6
https://ift.tt/zOJs5mb
Submitted November 08, 2023 at 03:57PM by monoimpact
via reddit https://ift.tt/AN8wKj6
Sonarsource
Visual Studio Code Security: Deep Dive into Your Favorite Editor (1/3)
We took a look at the security of the most popular code editor, Visual Studio Code! This blog post covers common risks and attack surfaces so you know what to expect when using it.
How to get RCE on PTRG with CVE-2023-32782
https://ift.tt/rpNsTSw
Submitted November 08, 2023 at 02:37PM by security_aaudit
via reddit https://ift.tt/5xrlOCZ
https://ift.tt/rpNsTSw
Submitted November 08, 2023 at 02:37PM by security_aaudit
via reddit https://ift.tt/5xrlOCZ
baldur.dk
This post details the process of exploiting CVE-2023-32782 in PRTG to gain remote code execution.
Our Pwn2Own journey against time and randomness (part 2) | Quarkslab
https://ift.tt/Abawkcm
Submitted November 08, 2023 at 07:18PM by poltess0
via reddit https://ift.tt/Xu43BPW
https://ift.tt/Abawkcm
Submitted November 08, 2023 at 07:18PM by poltess0
via reddit https://ift.tt/Xu43BPW
Quarkslab
Our Pwn2Own journey against time and randomness (part 2)
50 Shades of Vulnerabilities: Uncovering Flaws in Open-Source Vulnerability Disclosures
https://ift.tt/TKadjP5
Submitted November 08, 2023 at 06:40PM by ilay789
via reddit https://ift.tt/Zjr8ViD
https://ift.tt/TKadjP5
Submitted November 08, 2023 at 06:40PM by ilay789
via reddit https://ift.tt/Zjr8ViD
Aqua
Uncovering Flaws in Open-Source Vulnerability Disclosures
Nautilus researchers evaluated the disclosure process of open-source projects and found flaws that allowed harvesting the vulnerabilities before patched
avoidr - masscan with exclusive exclusions
https://ift.tt/8Y6UkeQ
Submitted November 09, 2023 at 02:25AM by acidvegas
via reddit https://ift.tt/mgQtwIY
https://ift.tt/8Y6UkeQ
Submitted November 09, 2023 at 02:25AM by acidvegas
via reddit https://ift.tt/mgQtwIY
GitHub
GitHub - acidvegas/avoidr: masscan with exclusive excludes
masscan with exclusive excludes. Contribute to acidvegas/avoidr development by creating an account on GitHub.
Using Github as C2
https://ift.tt/5IpAM7z
Submitted November 09, 2023 at 12:28PM by cybermepls
via reddit https://ift.tt/RYUhVJA
https://ift.tt/5IpAM7z
Submitted November 09, 2023 at 12:28PM by cybermepls
via reddit https://ift.tt/RYUhVJA
Medium
Windows Malware in C# — Using Github as C2
In the realm of cybersecurity, Advanced Persistent Threat (APT) groups continue to evolve and adapt, often employing innovative techniques…
Diving into PyPI package name squatting
https://ift.tt/ctB2W5z
Submitted November 09, 2023 at 05:55PM by 0rsinium
via reddit https://ift.tt/D0n2IxL
https://ift.tt/ctB2W5z
Submitted November 09, 2023 at 05:55PM by 0rsinium
via reddit https://ift.tt/D0n2IxL
blog.orsinium.dev
Diving into PyPI package name squatting
All sufficiently big public package registries are a mess full of malware, name squatting, and drama:
crates.io has a single user owning names like “any”, “bash”, and “class”. npmjs.com had a drama with left-pad when a single maintainer of a single one-liner…
crates.io has a single user owning names like “any”, “bash”, and “class”. npmjs.com had a drama with left-pad when a single maintainer of a single one-liner…
Send Bluetooth LE Spam impersonating 219 devices just using Android app instead of Flipper Zero
https://ift.tt/NQy6oOL
Submitted November 09, 2023 at 05:48PM by barakadua131
via reddit https://ift.tt/okgl2pA
https://ift.tt/NQy6oOL
Submitted November 09, 2023 at 05:48PM by barakadua131
via reddit https://ift.tt/okgl2pA
Mobile Hacker
Android Kitchen Sink: Send BLE spam to iOS, Android and Windows at once using Android app Mobile Hacker
The Kitchen Sink is a name of Bluetooth Low Energy (BLE) attack that sends random advertisement packets that targets iOS, Android, and Windows devices the same time in the vicinity. The attack is called “Kitchen Sink” because it tries to send every possible…
Article 45 Will Roll Back Web Security by 12 Years
https://ift.tt/lLu58sf
Submitted November 09, 2023 at 07:51PM by Xadartt
via reddit https://ift.tt/oAIqsxp
https://ift.tt/lLu58sf
Submitted November 09, 2023 at 07:51PM by Xadartt
via reddit https://ift.tt/oAIqsxp
Electronic Frontier Foundation
Article 45 Will Roll Back Web Security by 12 Years
The EU is poised to pass a sweeping new regulation, eIDAS 2.0. Buried deep in the text is Article 45, which returns us to the dark ages of 2011, when certificate authorities (CAs) could collaborate