Diving into PyPI package name squatting
https://ift.tt/ctB2W5z
Submitted November 09, 2023 at 05:55PM by 0rsinium
via reddit https://ift.tt/D0n2IxL
https://ift.tt/ctB2W5z
Submitted November 09, 2023 at 05:55PM by 0rsinium
via reddit https://ift.tt/D0n2IxL
blog.orsinium.dev
Diving into PyPI package name squatting
All sufficiently big public package registries are a mess full of malware, name squatting, and drama:
crates.io has a single user owning names like “any”, “bash”, and “class”. npmjs.com had a drama with left-pad when a single maintainer of a single one-liner…
crates.io has a single user owning names like “any”, “bash”, and “class”. npmjs.com had a drama with left-pad when a single maintainer of a single one-liner…
Send Bluetooth LE Spam impersonating 219 devices just using Android app instead of Flipper Zero
https://ift.tt/NQy6oOL
Submitted November 09, 2023 at 05:48PM by barakadua131
via reddit https://ift.tt/okgl2pA
https://ift.tt/NQy6oOL
Submitted November 09, 2023 at 05:48PM by barakadua131
via reddit https://ift.tt/okgl2pA
Mobile Hacker
Android Kitchen Sink: Send BLE spam to iOS, Android and Windows at once using Android app Mobile Hacker
The Kitchen Sink is a name of Bluetooth Low Energy (BLE) attack that sends random advertisement packets that targets iOS, Android, and Windows devices the same time in the vicinity. The attack is called “Kitchen Sink” because it tries to send every possible…
Article 45 Will Roll Back Web Security by 12 Years
https://ift.tt/lLu58sf
Submitted November 09, 2023 at 07:51PM by Xadartt
via reddit https://ift.tt/oAIqsxp
https://ift.tt/lLu58sf
Submitted November 09, 2023 at 07:51PM by Xadartt
via reddit https://ift.tt/oAIqsxp
Electronic Frontier Foundation
Article 45 Will Roll Back Web Security by 12 Years
The EU is poised to pass a sweeping new regulation, eIDAS 2.0. Buried deep in the text is Article 45, which returns us to the dark ages of 2011, when certificate authorities (CAs) could collaborate
AWS IoT Core: A Compromised Device Perspective
https://ift.tt/0dEemV8
Submitted November 09, 2023 at 09:27PM by SeanPesce
via reddit https://ift.tt/ocBUnth
https://ift.tt/0dEemV8
Submitted November 09, 2023 at 09:27PM by SeanPesce
via reddit https://ift.tt/ocBUnth
From Akamai to F5 to NTLM... with love
https://ift.tt/bhZFcx3
Submitted November 09, 2023 at 10:08PM by albinowax
via reddit https://ift.tt/wBxpJIj
https://ift.tt/bhZFcx3
Submitted November 09, 2023 at 10:08PM by albinowax
via reddit https://ift.tt/wBxpJIj
Malicious Group
From Akamai to F5 to NTLM... with love.
In this post, I am going to show the readers how I was able to abuse Akamai so I could abuse F5 to steal internal data including authorization and session tokens from their customers.
BugBountyGPT - Now GPT helps to find vulnerabilities!
https://ift.tt/DcTyhzq
Submitted November 10, 2023 at 03:08AM by lmpact_
via reddit https://ift.tt/J7ymXrc
https://ift.tt/DcTyhzq
Submitted November 10, 2023 at 03:08AM by lmpact_
via reddit https://ift.tt/J7ymXrc
ChatGPT
ChatGPT - BugBountyGPT
AppSec & Bug Bounty
Command and Control (C2) Redirectors
https://www.youtube.com/playlist?list=PLi7TjlX0Gi2hU0xN7IhIFrWpmBtQdmTyn
Submitted November 10, 2023 at 06:37AM by Numerous_General_808
via reddit https://ift.tt/C5NKIjB
https://www.youtube.com/playlist?list=PLi7TjlX0Gi2hU0xN7IhIFrWpmBtQdmTyn
Submitted November 10, 2023 at 06:37AM by Numerous_General_808
via reddit https://ift.tt/C5NKIjB
Reddit
From the netsec community on Reddit: Command and Control (C2) Redirectors
Posted by Numerous_General_808 - 18 votes and 1 comment
AOL's 92M records database leak in 2003 - A Retroactive Examination
https://ift.tt/JtqFCQj
Submitted November 10, 2023 at 08:06PM by nantucket
via reddit https://ift.tt/gNGqTsR
https://ift.tt/JtqFCQj
Submitted November 10, 2023 at 08:06PM by nantucket
via reddit https://ift.tt/gNGqTsR
Livejournal
When An AOL Coder Sold the Whole Database
Author : pad, x.com/123456 Introducing eGod – Internet Entrepreneur, Reformed Spam Cartel I recently chatted with my friend James a/k/a eGod and discussed the unprecedented 2003 AOL database leak. He has never been identified or associated with the leak until…
NoMoreCookies protector version 2.3 released
https://ift.tt/VIarw8D
Submitted November 10, 2023 at 08:27PM by AhmedMinegames
via reddit https://ift.tt/KLyiOM3
https://ift.tt/VIarw8D
Submitted November 10, 2023 at 08:27PM by AhmedMinegames
via reddit https://ift.tt/KLyiOM3
GitHub
GitHub - AdvDebug/NoMoreCookies: Browser Protector against various stealers, written in C# & C/C++.
Browser Protector against various stealers, written in C# & C/C++. - AdvDebug/NoMoreCookies
Basic Command and Control (C2) setup with Mythic C2
https://www.youtube.com/playlist?list=PLi7TjlX0Gi2ihoAJFa9mrG7vHhtUTur6R
Submitted November 11, 2023 at 08:33PM by Numerous_General_808
via reddit https://ift.tt/lFQ5Wku
https://www.youtube.com/playlist?list=PLi7TjlX0Gi2ihoAJFa9mrG7vHhtUTur6R
Submitted November 11, 2023 at 08:33PM by Numerous_General_808
via reddit https://ift.tt/lFQ5Wku
Reddit
From the netsec community on Reddit: Basic Command and Control (C2) setup with Mythic C2
Posted by Numerous_General_808 - No votes and no comments
BlueNoroff strikes again with new macOS malware
https://ift.tt/31fBn5P
Submitted November 11, 2023 at 10:50PM by avid_reader_72
via reddit https://ift.tt/5smNezA
https://ift.tt/31fBn5P
Submitted November 11, 2023 at 10:50PM by avid_reader_72
via reddit https://ift.tt/5smNezA
Jamf
Jamf Threat Labs Discovers Malware from BlueNoroff
Newly discovered later-stage malware from BlueNoroff APT group targets macOS with characteristics similar to their RustBucket campaign.
GPTs & Assistants API - Code Interpreter Data Exfiltration
https://ift.tt/7pKsHSi
Submitted November 12, 2023 at 03:47PM by Standard_Arm_4476
via reddit https://ift.tt/6N1jXmF
https://ift.tt/7pKsHSi
Submitted November 12, 2023 at 03:47PM by Standard_Arm_4476
via reddit https://ift.tt/6N1jXmF
One shot, Triple kill: Pwning all three Google kernelCTF instances with a single 1-day Linux vulnerability
https://ift.tt/f8owygW
Submitted November 13, 2023 at 08:07PM by poltess0
via reddit https://ift.tt/NCP7Tre
https://ift.tt/f8owygW
Submitted November 13, 2023 at 08:07PM by poltess0
via reddit https://ift.tt/NCP7Tre
CVE Watcher: Hunting Down CVEs Before the Patch Drops
https://ift.tt/wRcYmQt
Submitted November 14, 2023 at 01:44AM by Pale_Fly_2673
via reddit https://ift.tt/IDjaBLl
https://ift.tt/wRcYmQt
Submitted November 14, 2023 at 01:44AM by Pale_Fly_2673
via reddit https://ift.tt/IDjaBLl
GitHub
GitHub - Aqua-Nautilus/CVE-Half-Day-Watcher
Contribute to Aqua-Nautilus/CVE-Half-Day-Watcher development by creating an account on GitHub.
The Open Source Fortress: A workshop for finding vulnerabilities in codebases using open source tools
https://ossfortress.io
Submitted November 14, 2023 at 01:19PM by iosifache
via reddit https://ift.tt/4xJ1ysI
https://ossfortress.io
Submitted November 14, 2023 at 01:19PM by iosifache
via reddit https://ift.tt/4xJ1ysI
ossfortress.io
The Open Source Fortress | The Open Source Fortress
Nothing new, still broken, insecure by default since then: Python's e-mail libraries and certificate verification and how it affected open source projects
https://ift.tt/YIZ8Jb5
Submitted November 14, 2023 at 03:13PM by aunga
via reddit https://ift.tt/6x5wdlD
https://ift.tt/YIZ8Jb5
Submitted November 14, 2023 at 03:13PM by aunga
via reddit https://ift.tt/6x5wdlD
Pentagrid AG
Nothing new, still broken, insecure by default since then: Python's e-
Python’s e-mail libraries smtplib, imaplib, and poplib do not verify server certificates unless a proper SSL context is passed to the API. This leads to security problems.
Beginners guide to free SIEM: Automated setup of Graylog Open using Puppet
https://ift.tt/Cp0S8tc
Submitted November 14, 2023 at 05:22PM by ezzzzz
via reddit https://ift.tt/opLe6cD
https://ift.tt/Cp0S8tc
Submitted November 14, 2023 at 05:22PM by ezzzzz
via reddit https://ift.tt/opLe6cD
Research Blog | Project Black
Automated Graylog Open Setup using Puppet
The term SIEM often conjures images of complex configurations and $100k bills leading to inaction. It doesn't have to be that way. In cybersecurity (and often in life), starting somewhere and taking even a small step in the right direction is preferable to…
Passive SSH Key Compromise via Lattices
https://ift.tt/uhITYfO
Submitted November 14, 2023 at 06:52PM by elatllat
via reddit https://ift.tt/RbMi3OL
https://ift.tt/uhITYfO
Submitted November 14, 2023 at 06:52PM by elatllat
via reddit https://ift.tt/RbMi3OL
Vibrate'em All & Denial of Pleasure Attacks against BLE Adult Toys with a #FlipperZero 📡😎🔥♀️♂️⚧️
https://ift.tt/e4AEWUx
Submitted November 14, 2023 at 11:17PM by Fun-Book-8926
via reddit https://ift.tt/FLqGV32
https://ift.tt/e4AEWUx
Submitted November 14, 2023 at 11:17PM by Fun-Book-8926
via reddit https://ift.tt/FLqGV32
WHID - We Hack In Disguise
Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero
Become familiar with developing applications for Flipper Zero, which will be capable of activating adult toys all at once or completely inhibit their use for those within your range (i.e. Denial of Pleasure Attack).
Tapping into a telecommunications company's office cameras
https://ift.tt/9q4Hs57
Submitted November 15, 2023 at 12:40AM by EatonZ
via reddit https://ift.tt/E5JHDWh
https://ift.tt/9q4Hs57
Submitted November 15, 2023 at 12:40AM by EatonZ
via reddit https://ift.tt/E5JHDWh
Eaton-Works
Tapping into a telecommunications company’s office cameras
API flaw enabled livestreaming of a telecommunications company’s office cameras.
Critical bug bounty reports in Microsoft & GitHub, with publication of CVE-2023-36052: "All the Small Things: Azure CLI Leakage and Problematic Usage Patterns".
https://ift.tt/a56K3hM
Submitted November 15, 2023 at 02:04AM by Hefty_Knowledge_7449
via reddit https://ift.tt/2dGsX8R
https://ift.tt/a56K3hM
Submitted November 15, 2023 at 02:04AM by Hefty_Knowledge_7449
via reddit https://ift.tt/2dGsX8R
Palo Alto Networks Blog
All the Small Things: Azure CLI Leakage and Problematic Usage Patterns
Developer usage patterns with Azure CLI may leak sensitive data in CI/CD logs when used in public repositories, potentially exposing critical information.