Visual Studio Code Security: Finding New Vulnerabilities in the NPM Integration (3/3)
https://ift.tt/PHS1V92
Submitted November 21, 2023 at 11:02PM by monoimpact
via reddit https://ift.tt/jiFZH31
https://ift.tt/PHS1V92
Submitted November 21, 2023 at 11:02PM by monoimpact
via reddit https://ift.tt/jiFZH31
Sonarsource
Visual Studio Code Security: Finding New Vulnerabilities in the NPM Integration (3/3)
It's time to wrap up our series on the security of Visual Studio Code with new vulnerabilities in the NPM integration, bypassing the Workspace Trust security feature.
PyCript Burp Suite Extension v0.3 released
https://ift.tt/a5FO1EI
Submitted November 22, 2023 at 12:01AM by Ano_F
via reddit https://ift.tt/1V3UNA5
https://ift.tt/a5FO1EI
Submitted November 22, 2023 at 12:01AM by Ano_F
via reddit https://ift.tt/1V3UNA5
GitHub
Release 0.3 · Anof-cyber/PyCript
Fixed an error in Mac OS M1 and M2 that was caused by direct subprocess execution. Special thanks to Tavi for reporting the issue in the extension.
Added a logger to aid in debugging the encryption...
Added a logger to aid in debugging the encryption...
TJNulls list for prepping for OSCP/PWK
https://ift.tt/DsyM4Ka
Submitted November 22, 2023 at 01:42AM by McLabraid
via reddit https://ift.tt/bFnJQEI
https://ift.tt/DsyM4Ka
Submitted November 22, 2023 at 01:42AM by McLabraid
via reddit https://ift.tt/bFnJQEI
Google Docs
NetSecFocus Trophy Room
A Touch of Pwn: Attacking Windows Hello Fingerprint Authentication
https://ift.tt/cb7AZBf
Submitted November 22, 2023 at 05:39AM by Titokhan
via reddit https://ift.tt/axZ0hN8
https://ift.tt/cb7AZBf
Submitted November 22, 2023 at 05:39AM by Titokhan
via reddit https://ift.tt/axZ0hN8
Blackwinghq
A Touch of Pwn - Part I
Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations
XXE, You Can Depend On Me (OpenCMS CVE-2023-42344 and Friends) - watchTowr Labs
https://ift.tt/vwkAEJV
Submitted November 22, 2023 at 06:34AM by dx7r__
via reddit https://ift.tt/P6t4rEh
https://ift.tt/vwkAEJV
Submitted November 22, 2023 at 06:34AM by dx7r__
via reddit https://ift.tt/P6t4rEh
watchTowr Labs - Blog
XXE, You Can Depend On Me (OpenCMS CVE-2023-42344 and Friends)
In the idealistic world of security research, we’d be faced with the latest versions of off-the-shelf enterprise products, primed with fresh hardened code ready for analysis and code kung-fu.
In reality, however, enterprises and users often don’t update…
In reality, however, enterprises and users often don’t update…
Pentesting Azure Mindmap
https://ift.tt/DQfq42j
Submitted November 22, 2023 at 05:56PM by Computer-sec
via reddit https://ift.tt/yThmCXI
https://ift.tt/DQfq42j
Submitted November 22, 2023 at 05:56PM by Computer-sec
via reddit https://ift.tt/yThmCXI
GitHub
GitHub - synacktiv/Mindmaps: Azure mindmap for penetration tests
Azure mindmap for penetration tests. Contribute to synacktiv/Mindmaps development by creating an account on GitHub.
IPSec Analysis (X-Post from /r/malware)
https://ift.tt/QkXFoRj
Submitted November 22, 2023 at 08:39PM by tohitsugu
via reddit https://ift.tt/7HjFw9u
https://ift.tt/QkXFoRj
Submitted November 22, 2023 at 08:39PM by tohitsugu
via reddit https://ift.tt/7HjFw9u
Maldbg
A Look at IPStorm - Cross-Platform Malware Written in Go | MalDbg
File name: 6558073e997da5ca440b5a4b.exe
Diamond Sleet supply chain compromise distributes a modified CyberLink installer
https://ift.tt/TOQekPF
Submitted November 22, 2023 at 11:28PM by SCI_Rusher
via reddit https://ift.tt/K03JD1v
https://ift.tt/TOQekPF
Submitted November 22, 2023 at 11:28PM by SCI_Rusher
via reddit https://ift.tt/K03JD1v
Microsoft Security Blog
Diamond Sleet supply chain compromise distributes a modified CyberLink installer | Microsoft Security Blog
Microsoft has uncovered a supply chain attack by Diamond Sleet involving a malicious variant of an application developed by CyberLink Corp.
4 of the top 10 password strength tools are giving people bad password advice, and they don't care.
https://ift.tt/EwRu2mY
Submitted November 23, 2023 at 02:34AM by ezzzzz
via reddit https://ift.tt/YXx2UNm
https://ift.tt/EwRu2mY
Submitted November 23, 2023 at 02:34AM by ezzzzz
via reddit https://ift.tt/YXx2UNm
Research Blog | Project Black
Password Strength Checkers - Mostly Useless...
Think your password is strong? Ever trusted a password strength tool online (or maybe you don't trust anything)? You might be surprised to see how far off the mark some of the most popular password strength tools are.
CVE-2023-46604: Attacking & Defending ActiveMQ
https://ift.tt/Uq02brJ
Submitted November 23, 2023 at 01:46PM by gfekkas
via reddit https://ift.tt/owQnHXb
https://ift.tt/Uq02brJ
Submitted November 23, 2023 at 01:46PM by gfekkas
via reddit https://ift.tt/owQnHXb
PRIOn - AI Driven Vulnerablity Analysis & Prioritization
Blog - CVE-2023-46604-Attacking & Defending ActiveMQ - PRIOn
CVE-2023-46604 discloses a Remote Code Execution (RCE) flaw within Apache ActiveMQ. This vulnerability is trivial to exploit and its leveraged by threat actors.
Hide files inside images
https://ift.tt/irRVsuq
Submitted November 23, 2023 at 09:50PM by JizosKasa
via reddit https://ift.tt/pm5z1l6
https://ift.tt/irRVsuq
Submitted November 23, 2023 at 09:50PM by JizosKasa
via reddit https://ift.tt/pm5z1l6
GitHub
GitHub - JoshuaKasa/van-gonography: Hide 🕵️♂️ your files of any type inside a image of your choice using steganography
Hide 🕵️♂️ your files of any type inside a image of your choice using steganography - GitHub - JoshuaKasa/van-gonography: Hide 🕵️♂️ your files of any type inside a image of your choice using ste...
Comprehensive guide on writing your first metasploit remote code execution module
https://ift.tt/rafpHC6
Submitted November 24, 2023 at 02:17PM by security_aaudit
via reddit https://ift.tt/v7ynfzJ
https://ift.tt/rafpHC6
Submitted November 24, 2023 at 02:17PM by security_aaudit
via reddit https://ift.tt/v7ynfzJ
baldur.dk
Comprehensive guide on how to convert your RCE vulnerability into a fully functional metasploit module, that will spawn any payload. We use CVE-2023-32781 as our example.
Open Source Security Assessment Collaboration Platform
https://ift.tt/cdZTy3t
Submitted November 26, 2023 at 03:14PM by ascetik
via reddit https://ift.tt/ogwtkOL
https://ift.tt/cdZTy3t
Submitted November 26, 2023 at 03:14PM by ascetik
via reddit https://ift.tt/ogwtkOL
GitHub
GitHub - factionsecurity/faction: Pen Test Report Generation and Assessment Collaboration
Pen Test Report Generation and Assessment Collaboration - factionsecurity/faction
Defending Azure Active Directory (Entra ID): Unveiling Threats Through Hunting Techniques
https://ift.tt/8s56LpH
Submitted November 27, 2023 at 03:27AM by Or1rez
via reddit https://ift.tt/Dgd2LPQ
https://ift.tt/8s56LpH
Submitted November 27, 2023 at 03:27AM by Or1rez
via reddit https://ift.tt/Dgd2LPQ
Rezonate - Protect Identities, Everywhere
Defending Azure Active Directory (Entra ID): Unveiling Threats through Hunting Techniques - Rezonate
Azure Active Directory (Entra ID) stands as one of the most popular and widely-used cloud-based identity and access management services provided by Microsoft. It serves as a comprehensive solution for managing user identities and controlling access to a diverse…
EvilSlackbot: A Slack Attack Framework
https://ift.tt/on6NC5c
Submitted November 27, 2023 at 07:37PM by Dr_Mantis_Tobbogon
via reddit https://ift.tt/vKVm19W
https://ift.tt/on6NC5c
Submitted November 27, 2023 at 07:37PM by Dr_Mantis_Tobbogon
via reddit https://ift.tt/vKVm19W
GitHub
GitHub - Drew-Sec/EvilSlackbot: A Slack bot phishing framework for Red Teaming exercises
A Slack bot phishing framework for Red Teaming exercises - GitHub - Drew-Sec/EvilSlackbot: A Slack bot phishing framework for Red Teaming exercises
LostTrust Ransomware - Trust nothing
https://ift.tt/i1Pw8az
Submitted November 27, 2023 at 10:29PM by ShadowStackRE
via reddit https://ift.tt/ZSIz5Bl
https://ift.tt/i1Pw8az
Submitted November 27, 2023 at 10:29PM by ShadowStackRE
via reddit https://ift.tt/ZSIz5Bl
ShadowStackRE
LostTrust Ransomware - Trust nothing — ShadowStackRE
LostTrust Ransomware malware technical analysis and research
Have I Been Squatted? — Check if your domain has been typosquatted
https://ift.tt/DxLu9bf
Submitted November 27, 2023 at 11:42PM by JDBHub
via reddit https://ift.tt/rovsCi6
https://ift.tt/DxLu9bf
Submitted November 27, 2023 at 11:42PM by JDBHub
via reddit https://ift.tt/rovsCi6
Haveibeensquatted
Have I Been Squatted? — Check if your domain has been typosquatted
A fast domain and typosquatting discovery tool
Big update to my Semgrep C/C++ ruleset
https://ift.tt/SaDicmp
Submitted November 28, 2023 at 12:16PM by 0xdea
via reddit https://ift.tt/9FCTtz2
https://ift.tt/SaDicmp
Submitted November 28, 2023 at 12:16PM by 0xdea
via reddit https://ift.tt/9FCTtz2
hn security
Big update to my Semgrep C/C++ ruleset - hn security
“The attack surface is the vulnerability. […]
Information Rights Management VS Traditional Digital Rights Management
https://ift.tt/sfmgjXA
Submitted November 28, 2023 at 02:46PM by zolakrystie
via reddit https://ift.tt/BKmeVcY
https://ift.tt/sfmgjXA
Submitted November 28, 2023 at 02:46PM by zolakrystie
via reddit https://ift.tt/BKmeVcY
NextLabs
What is Information Rights Management (IRM)? - NextLabs
Information Rights Management extends far beyond traditional data security measures. It is the solution that allows organizations to maintain the integrity of their data, protecting it from unauthorized access and potential breaches. It secures critical information…
Building Immune Authorization: AppSec in Healthcare Apps
https://ift.tt/suHd5hZ
Submitted November 28, 2023 at 04:30PM by Permit_io
via reddit https://ift.tt/seO9Wy3
https://ift.tt/suHd5hZ
Submitted November 28, 2023 at 04:30PM by Permit_io
via reddit https://ift.tt/seO9Wy3
www.permit.io
Building Immune Authorization: AppSec in Healthcare Apps
Protecting your user's personal medical information is vital in healthcare apps. Here's how to make sure you're doing everything to keep that data safe -
Fuzzer-V: New project for Fuzzing Hyper-V VSP's using Intel Processor Trace (IPT) for code coverage guided fuzzing, built upon WinAFL, winipt, HAFL1, and Microsoft’s IPT.sys.
https://ift.tt/LpkmiAV
Submitted November 28, 2023 at 07:36PM by jat0369
via reddit https://ift.tt/cThrJBy
https://ift.tt/LpkmiAV
Submitted November 28, 2023 at 07:36PM by jat0369
via reddit https://ift.tt/cThrJBy
Cyberark
Fuzzer-V
TL;DR An overview of a fuzzing project targeting the Hyper-V VSPs using Intel Processor Trace (IPT) for code coverage guided fuzzing, built upon WinAFL, winipt, HAFL1, and Microsoft’s IPT.sys....