Blind CSS Exfiltration: exfiltrate unknown web pages
https://ift.tt/YI7yFZB
Submitted December 06, 2023 at 03:48PM by albinowax
via reddit https://ift.tt/1efF2p5
https://ift.tt/YI7yFZB
Submitted December 06, 2023 at 03:48PM by albinowax
via reddit https://ift.tt/1efF2p5
PortSwigger Research
Blind CSS Exfiltration: exfiltrate unknown web pages
This is a gif of the exfiltration process (We've increased the speed so you're not waiting around for 1 minute). Read on to discover how this works... CSS Cafe presentation I presented this technique
+1500 HuggingFace API Tokens were exposed, leaving millions of Meta-Llama, Bloom, and Pythia users vulnerable to supply chain attacks
https://ift.tt/g2LTbWp
Submitted December 06, 2023 at 05:38PM by Lany_B
via reddit https://ift.tt/SXyvZml
https://ift.tt/g2LTbWp
Submitted December 06, 2023 at 05:38PM by Lany_B
via reddit https://ift.tt/SXyvZml
Vulnerability disclosure for Zyxel's personal cloud storage device (NAS326) - Part1
https://ift.tt/DVWasYM
Submitted December 06, 2023 at 07:22PM by BugProve
via reddit https://ift.tt/sOujdC5
https://ift.tt/DVWasYM
Submitted December 06, 2023 at 07:22PM by BugProve
via reddit https://ift.tt/sOujdC5
Bugprove
CVE-2023-4473 & CVE-2023-4474 - Authentication bypass and multiple blind OS command injection vulnerabilities in Zyxel’s NAS326…
BugProve discovers additional zero-day vulnerabilities in Zyxel's personal cloud storage device. Detailed writeup of the firmware analysis process.
Split-Second DNS Rebinding in Chrome, Edge and Safari
https://ift.tt/iWUDO75
Submitted December 06, 2023 at 06:59PM by dcthatch
via reddit https://ift.tt/2EW4jX5
https://ift.tt/iWUDO75
Submitted December 06, 2023 at 06:59PM by dcthatch
via reddit https://ift.tt/2EW4jX5
www.intruder.io
Tricks for Reliable Split-Second DNS Rebinding in Chrome and Safari
This is the second post in a two-part series on DNS rebinding. In this post, I introduce new techniques for achieving reliable, split-second DNS rebinding in Chrome, Edge, and Safari when IPv6 is available, as well as a technique for bypassing the local network…
Unicode XSS via Combining Characters
https://ift.tt/Stf6rZl
Submitted December 05, 2023 at 07:42PM by ablativeyoyo
via reddit https://ift.tt/jrbFD6x
https://ift.tt/Stf6rZl
Submitted December 05, 2023 at 07:42PM by ablativeyoyo
via reddit https://ift.tt/jrbFD6x
Gist
index.md
GitHub Gist: instantly share code, notes, and snippets.
New RCE popchain in Laravel
https://ift.tt/I4yZm2a
Submitted December 06, 2023 at 09:23PM by monoimpact
via reddit https://ift.tt/hVt4yNF
https://ift.tt/I4yZm2a
Submitted December 06, 2023 at 09:23PM by monoimpact
via reddit https://ift.tt/hVt4yNF
Fenrisk
Gadgets chain in Laravel
Security experts
Red team or adversary? Hunting Supply Chain Threat Actors Targeting A Major Financial Institution.
https://ift.tt/0WiHBPk
Submitted December 07, 2023 at 03:29AM by louis11
via reddit https://ift.tt/hJZ7H0z
https://ift.tt/0WiHBPk
Submitted December 07, 2023 at 03:29AM by louis11
via reddit https://ift.tt/hJZ7H0z
Phylum
Encrypted npm Packages Found Targeting Major Financial Institution
Determining the intent behind a package publication is notoriously difficult. Is it a legitimate threat actor or a security researcher? We can rarely make this determination, so Phylum generally errs on the side of caution and annotates packages that exhibit…
Cybresec & Opensource firmware online party! - today at 5 PM UTC
https://ift.tt/Er6lWTz
Submitted December 07, 2023 at 02:12PM by Mike-Banon1
via reddit https://ift.tt/DiMuRav
https://ift.tt/Er6lWTz
Submitted December 07, 2023 at 02:12PM by Mike-Banon1
via reddit https://ift.tt/DiMuRav
Attendize.com
Dasharo User Group #4
Dasharo User Group (DUG) #4 and Dasharo Developers vPub 0x9 When? 07th December 2023 5PM UTC to last hacker standing...
What is Loader Lock?
https://ift.tt/uHYk46n
Submitted December 07, 2023 at 12:48AM by elliotkillick
via reddit https://ift.tt/YC8FbWO
https://ift.tt/uHYk46n
Submitted December 07, 2023 at 12:48AM by elliotkillick
via reddit https://ift.tt/YC8FbWO
Elliot on Security
Elliot on Security - What is Loader Lock?
A modern investigation of the Windows loader architecure and loader lock
Cueing up a calculator: an introduction to exploit development on Linux
https://ift.tt/vLqlTpt
Submitted December 07, 2023 at 02:03PM by poltess0
via reddit https://ift.tt/UyxmGTP
https://ift.tt/vLqlTpt
Submitted December 07, 2023 at 02:03PM by poltess0
via reddit https://ift.tt/UyxmGTP
The GitHub Blog
Cueing up a calculator: an introduction to exploit development on Linux
Using CVE-2023-43641 as an example, I’ll explain how to develop an exploit for a memory corruption vulnerability on Linux. The exploit has to bypass several mitigations to achieve code execution.
Web API testing techniques & labs
https://ift.tt/qsIM1eL
Submitted December 07, 2023 at 07:23PM by albinowax
via reddit https://ift.tt/4eLlJtH
https://ift.tt/qsIM1eL
Submitted December 07, 2023 at 07:23PM by albinowax
via reddit https://ift.tt/4eLlJtH
portswigger.net
API testing | Web Security Academy
APIs (Application Programming Interfaces) enable software systems and applications to communicate and share data. API testing is important as ...
Introducing Fuzzomatic: Using AI to Automatically Fuzz Rust Projects from Scratch
https://ift.tt/iulgUTy
Submitted December 07, 2023 at 09:02PM by tmlxs
via reddit https://ift.tt/9UzbLWA
https://ift.tt/iulgUTy
Submitted December 07, 2023 at 09:02PM by tmlxs
via reddit https://ift.tt/9UzbLWA
Kudelski Security Research
Introducing Fuzzomatic: Using AI to Automatically Fuzz Rust Projects from Scratch
Introduction In August 2023, Google published research they did on AI-powered fuzzing. They showed they could automatically improve fuzzing code coverage of C/C++ projects already enrolled in OSS-F…
Qilin Ransomware malware analysis
https://ift.tt/alSX6i9
Submitted December 07, 2023 at 08:52PM by ShadowStackRE
via reddit https://ift.tt/s5H82nN
https://ift.tt/alSX6i9
Submitted December 07, 2023 at 08:52PM by ShadowStackRE
via reddit https://ift.tt/s5H82nN
ShadowStackRE
Qilin Ransomware malware analysis — ShadowStackRE
CVE-2023-46818: PHP Code Injection Vulnerability in ISPConfig <= 3.2.11
https://ift.tt/PGEhI5S
Submitted December 07, 2023 at 10:26PM by eg1x
via reddit https://ift.tt/gU58MWf
https://ift.tt/PGEhI5S
Submitted December 07, 2023 at 10:26PM by eg1x
via reddit https://ift.tt/gU58MWf
Karmainsecurity
ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
CISA ICS Advisory: ControlbyWeb Relay
https://ift.tt/ahliWp5
Submitted December 08, 2023 at 01:10AM by deepwatch_sec
via reddit https://ift.tt/rixsoPX
https://ift.tt/ahliWp5
Submitted December 08, 2023 at 01:10AM by deepwatch_sec
via reddit https://ift.tt/rixsoPX
Spoofing DNS records by abusing Microsoft DHCP server
https://ift.tt/o0GdFeV
Submitted December 08, 2023 at 02:50AM by oridavid1231
via reddit https://ift.tt/6p5sHzJ
https://ift.tt/o0GdFeV
Submitted December 08, 2023 at 02:50AM by oridavid1231
via reddit https://ift.tt/6p5sHzJ
Akamai
Spoofing DNS Records by Abusing DHCP DNS Dynamic Updates | Akamai
Akamai researchers discovered a new set of attacks against Active Directory (AD) using Microsoft DHCP servers that can lead to full AD takeover.
BSidesSF 2024 CFP is now open!
https://ift.tt/Zx73toq
Submitted December 08, 2023 at 07:48AM by sarah-bsidessf
via reddit https://ift.tt/V5S8Dua
https://ift.tt/Zx73toq
Submitted December 08, 2023 at 07:48AM by sarah-bsidessf
via reddit https://ift.tt/V5S8Dua
BSidesSF
BSidesSF 2025 Call For Participation
BSidesSF is soliciting submissions for the annual BSidesSF conference on April 26-27, 2025. Call for Participation is currently open for all tracks.Note: We DO NOT provide speaker or travel ...
RCE and LPE in a wide range of Unify OpenStage and OpenScape phones in default config (plus PoC)
https://ift.tt/DzJ1Amj
Submitted December 08, 2023 at 11:41AM by aunga
via reddit https://ift.tt/jYt09LW
https://ift.tt/DzJ1Amj
Submitted December 08, 2023 at 11:41AM by aunga
via reddit https://ift.tt/jYt09LW
Pentagrid AG
Remote code execution and elevation of local privileges in Mitel Unify
Multiple vulnerabilities in Mitel Unify OpenStage and OpenScape phones allow a remote compromise in the unhardened default configuration and an elevation of privileges to become the root user.
Russian cyberops fact sheet (UK gov)
https://ift.tt/a0D1Rs7
Submitted December 08, 2023 at 04:06PM by vjeuss
via reddit https://ift.tt/n7gheRV
https://ift.tt/a0D1Rs7
Submitted December 08, 2023 at 04:06PM by vjeuss
via reddit https://ift.tt/n7gheRV
GOV.UK
Russia's FSB malign activity: factsheet
Russia is one of the world’s most prolific cyber actors and dedicate significant resource into conducting cyber operations around the globe. The UK government has publicly attributed malign cyber activity to parts of three Russian Intelligence services: the…
AIJacking - A Vulnerability in the Popular Hugging Face AI Platform
https://ift.tt/cp3fuj5
Submitted December 08, 2023 at 09:10PM by roy_6472
via reddit https://ift.tt/RflNQHd
https://ift.tt/cp3fuj5
Submitted December 08, 2023 at 09:10PM by roy_6472
via reddit https://ift.tt/RflNQHd
Legitsecurity
Legit Discovers "AI Jacking" Vulnerability in Popular Hugging Face AI Platform
Legit Security | Uncovering 'AIJacking': How Attackers Exploit Hugging Face for AI Supply Chain Attacks - A Deep Dive into Vulnerabilities and Risks.
CVE-2023-45866: Unauthenticated Bluetooth keystroke-injection in Android, Linux, macOS and iOS
https://ift.tt/GdAaZB1
Submitted December 09, 2023 at 12:57AM by bagaudin
via reddit https://ift.tt/vWofjVZ
https://ift.tt/GdAaZB1
Submitted December 09, 2023 at 12:57AM by bagaudin
via reddit https://ift.tt/vWofjVZ
GitHub
reblog/cve-2023-45866 at main · skysafe/reblog
SkySafe Miscellaneous Reverse Engineering Blog. Contribute to skysafe/reblog development by creating an account on GitHub.