OMGCICD - Attacking GitLab CI/CD via Shared Runners
https://ift.tt/Q7vg4sd
Submitted November 21, 2023 at 06:15AM by MysteriousHotel3017
via reddit https://ift.tt/y2AlRUQ
https://ift.tt/Q7vg4sd
Submitted November 21, 2023 at 06:15AM by MysteriousHotel3017
via reddit https://ift.tt/y2AlRUQ
Pulse Security
OMGCICD - Attacking GitLab CI/CD via Shared Runners
This article discusses compromising shared CI/CD runner infrastructure, and how an attacker can escalate their privileges from basic source-repository access to compromising the environments the wider system is deploying.
Can I get some help in relation to interpreting a log/data
https://ift.tt/4T7wQyi
Submitted November 21, 2023 at 05:47AM by Fai057
via reddit https://ift.tt/KikWD28
https://ift.tt/4T7wQyi
Submitted November 21, 2023 at 05:47AM by Fai057
via reddit https://ift.tt/KikWD28
[BlackHat MEA 23] SAP Penetration Testing
https://ift.tt/dJByLcG
Submitted November 21, 2023 at 04:55PM by vah_13
via reddit https://ift.tt/KHpci0g
https://ift.tt/dJByLcG
Submitted November 21, 2023 at 04:55PM by vah_13
via reddit https://ift.tt/KHpci0g
GitHub
SAP-Penetration-Testing/BHMEA23_SAP_Penetration_Testing.pdf at main · redrays-io/SAP-Penetration-Testing
SAP Penetration Testing: A Comprehensive Analysis of SAP Security Issues - redrays-io/SAP-Penetration-Testing
The Ticking Supply Chain Attack Bomb of Exposed Kubernetes Secrets
https://ift.tt/f9zCgSt
Submitted November 21, 2023 at 06:47PM by Pale_Fly_2673
via reddit https://ift.tt/s7Iquy5
https://ift.tt/f9zCgSt
Submitted November 21, 2023 at 06:47PM by Pale_Fly_2673
via reddit https://ift.tt/s7Iquy5
Aqua
The Ticking Supply Chain Attack Bomb of Exposed Kubernetes Secrets
Aqua Nautilus researchers found exposed Kubernetes secrets that pose a critical threat of supply chain attack to hundreds of organizations and OSS.
Private and Secure Windows
https://ift.tt/O4pSsAi
Submitted November 21, 2023 at 06:37PM by kygyty
via reddit https://ift.tt/Bgleroh
https://ift.tt/O4pSsAi
Submitted November 21, 2023 at 06:37PM by kygyty
via reddit https://ift.tt/Bgleroh
GitHub
GitHub - troennes/private-secure-windows: Privacy and security baseline for personal Windows 10 and Windows 11
Privacy and security baseline for personal Windows 10 and Windows 11 - troennes/private-secure-windows
InfoSec Black Friday Deals ~ "Friday Hack Fest" 2023 Edition
https://ift.tt/dVD8Kxz
Submitted November 21, 2023 at 05:50PM by B0b_Howard
via reddit https://ift.tt/SO9LeDV
https://ift.tt/dVD8Kxz
Submitted November 21, 2023 at 05:50PM by B0b_Howard
via reddit https://ift.tt/SO9LeDV
GitHub
GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
All the deals for InfoSec related software/tools this Black Friday - 0x90n/InfoSec-Black-Friday
Log4Shell - different avenues of exploitation
https://ift.tt/fWNVMQU
Submitted November 21, 2023 at 07:08PM by forgambo
via reddit https://ift.tt/WiKFNCP
https://ift.tt/fWNVMQU
Submitted November 21, 2023 at 07:08PM by forgambo
via reddit https://ift.tt/WiKFNCP
Olex’s Substack
Log4Shell - different avenues of exploitation
This is a story about different ways to achieve RCE through the Java Log4j2 vulnerability (Log4Shell, CVE-2021-44228). And while some methods may not work, others may.
How to Use OAuth Scopes for Authorization
https://ift.tt/dmkYp7X
Submitted November 21, 2023 at 11:39PM by Permit_io
via reddit https://ift.tt/otZaknB
https://ift.tt/dmkYp7X
Submitted November 21, 2023 at 11:39PM by Permit_io
via reddit https://ift.tt/otZaknB
www.permit.io
How to Use OAuth Scopes for Authorization | Permit
Learn how, when, and where to use OAuth scopes for authorization. Get a clear understanding of OAuth scopes definition and their proper usage.
Visual Studio Code Security: Finding New Vulnerabilities in the NPM Integration (3/3)
https://ift.tt/PHS1V92
Submitted November 21, 2023 at 11:02PM by monoimpact
via reddit https://ift.tt/jiFZH31
https://ift.tt/PHS1V92
Submitted November 21, 2023 at 11:02PM by monoimpact
via reddit https://ift.tt/jiFZH31
Sonarsource
Visual Studio Code Security: Finding New Vulnerabilities in the NPM Integration (3/3)
It's time to wrap up our series on the security of Visual Studio Code with new vulnerabilities in the NPM integration, bypassing the Workspace Trust security feature.
PyCript Burp Suite Extension v0.3 released
https://ift.tt/a5FO1EI
Submitted November 22, 2023 at 12:01AM by Ano_F
via reddit https://ift.tt/1V3UNA5
https://ift.tt/a5FO1EI
Submitted November 22, 2023 at 12:01AM by Ano_F
via reddit https://ift.tt/1V3UNA5
GitHub
Release 0.3 · Anof-cyber/PyCript
Fixed an error in Mac OS M1 and M2 that was caused by direct subprocess execution. Special thanks to Tavi for reporting the issue in the extension.
Added a logger to aid in debugging the encryption...
Added a logger to aid in debugging the encryption...
TJNulls list for prepping for OSCP/PWK
https://ift.tt/DsyM4Ka
Submitted November 22, 2023 at 01:42AM by McLabraid
via reddit https://ift.tt/bFnJQEI
https://ift.tt/DsyM4Ka
Submitted November 22, 2023 at 01:42AM by McLabraid
via reddit https://ift.tt/bFnJQEI
Google Docs
NetSecFocus Trophy Room
A Touch of Pwn: Attacking Windows Hello Fingerprint Authentication
https://ift.tt/cb7AZBf
Submitted November 22, 2023 at 05:39AM by Titokhan
via reddit https://ift.tt/axZ0hN8
https://ift.tt/cb7AZBf
Submitted November 22, 2023 at 05:39AM by Titokhan
via reddit https://ift.tt/axZ0hN8
Blackwinghq
A Touch of Pwn - Part I
Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations
XXE, You Can Depend On Me (OpenCMS CVE-2023-42344 and Friends) - watchTowr Labs
https://ift.tt/vwkAEJV
Submitted November 22, 2023 at 06:34AM by dx7r__
via reddit https://ift.tt/P6t4rEh
https://ift.tt/vwkAEJV
Submitted November 22, 2023 at 06:34AM by dx7r__
via reddit https://ift.tt/P6t4rEh
watchTowr Labs - Blog
XXE, You Can Depend On Me (OpenCMS CVE-2023-42344 and Friends)
In the idealistic world of security research, we’d be faced with the latest versions of off-the-shelf enterprise products, primed with fresh hardened code ready for analysis and code kung-fu.
In reality, however, enterprises and users often don’t update…
In reality, however, enterprises and users often don’t update…
Pentesting Azure Mindmap
https://ift.tt/DQfq42j
Submitted November 22, 2023 at 05:56PM by Computer-sec
via reddit https://ift.tt/yThmCXI
https://ift.tt/DQfq42j
Submitted November 22, 2023 at 05:56PM by Computer-sec
via reddit https://ift.tt/yThmCXI
GitHub
GitHub - synacktiv/Mindmaps: Azure mindmap for penetration tests
Azure mindmap for penetration tests. Contribute to synacktiv/Mindmaps development by creating an account on GitHub.
IPSec Analysis (X-Post from /r/malware)
https://ift.tt/QkXFoRj
Submitted November 22, 2023 at 08:39PM by tohitsugu
via reddit https://ift.tt/7HjFw9u
https://ift.tt/QkXFoRj
Submitted November 22, 2023 at 08:39PM by tohitsugu
via reddit https://ift.tt/7HjFw9u
Maldbg
A Look at IPStorm - Cross-Platform Malware Written in Go | MalDbg
File name: 6558073e997da5ca440b5a4b.exe
Diamond Sleet supply chain compromise distributes a modified CyberLink installer
https://ift.tt/TOQekPF
Submitted November 22, 2023 at 11:28PM by SCI_Rusher
via reddit https://ift.tt/K03JD1v
https://ift.tt/TOQekPF
Submitted November 22, 2023 at 11:28PM by SCI_Rusher
via reddit https://ift.tt/K03JD1v
Microsoft Security Blog
Diamond Sleet supply chain compromise distributes a modified CyberLink installer | Microsoft Security Blog
Microsoft has uncovered a supply chain attack by Diamond Sleet involving a malicious variant of an application developed by CyberLink Corp.
4 of the top 10 password strength tools are giving people bad password advice, and they don't care.
https://ift.tt/EwRu2mY
Submitted November 23, 2023 at 02:34AM by ezzzzz
via reddit https://ift.tt/YXx2UNm
https://ift.tt/EwRu2mY
Submitted November 23, 2023 at 02:34AM by ezzzzz
via reddit https://ift.tt/YXx2UNm
Research Blog | Project Black
Password Strength Checkers - Mostly Useless...
Think your password is strong? Ever trusted a password strength tool online (or maybe you don't trust anything)? You might be surprised to see how far off the mark some of the most popular password strength tools are.
CVE-2023-46604: Attacking & Defending ActiveMQ
https://ift.tt/Uq02brJ
Submitted November 23, 2023 at 01:46PM by gfekkas
via reddit https://ift.tt/owQnHXb
https://ift.tt/Uq02brJ
Submitted November 23, 2023 at 01:46PM by gfekkas
via reddit https://ift.tt/owQnHXb
PRIOn - AI Driven Vulnerablity Analysis & Prioritization
Blog - CVE-2023-46604-Attacking & Defending ActiveMQ - PRIOn
CVE-2023-46604 discloses a Remote Code Execution (RCE) flaw within Apache ActiveMQ. This vulnerability is trivial to exploit and its leveraged by threat actors.
Hide files inside images
https://ift.tt/irRVsuq
Submitted November 23, 2023 at 09:50PM by JizosKasa
via reddit https://ift.tt/pm5z1l6
https://ift.tt/irRVsuq
Submitted November 23, 2023 at 09:50PM by JizosKasa
via reddit https://ift.tt/pm5z1l6
GitHub
GitHub - JoshuaKasa/van-gonography: Hide 🕵️♂️ your files of any type inside a image of your choice using steganography
Hide 🕵️♂️ your files of any type inside a image of your choice using steganography - GitHub - JoshuaKasa/van-gonography: Hide 🕵️♂️ your files of any type inside a image of your choice using ste...
Comprehensive guide on writing your first metasploit remote code execution module
https://ift.tt/rafpHC6
Submitted November 24, 2023 at 02:17PM by security_aaudit
via reddit https://ift.tt/v7ynfzJ
https://ift.tt/rafpHC6
Submitted November 24, 2023 at 02:17PM by security_aaudit
via reddit https://ift.tt/v7ynfzJ
baldur.dk
Comprehensive guide on how to convert your RCE vulnerability into a fully functional metasploit module, that will spawn any payload. We use CVE-2023-32781 as our example.
Open Source Security Assessment Collaboration Platform
https://ift.tt/cdZTy3t
Submitted November 26, 2023 at 03:14PM by ascetik
via reddit https://ift.tt/ogwtkOL
https://ift.tt/cdZTy3t
Submitted November 26, 2023 at 03:14PM by ascetik
via reddit https://ift.tt/ogwtkOL
GitHub
GitHub - factionsecurity/faction: Pen Test Report Generation and Assessment Collaboration
Pen Test Report Generation and Assessment Collaboration - factionsecurity/faction