Russian cyberops fact sheet (UK gov)
https://ift.tt/a0D1Rs7
Submitted December 08, 2023 at 04:06PM by vjeuss
via reddit https://ift.tt/n7gheRV
https://ift.tt/a0D1Rs7
Submitted December 08, 2023 at 04:06PM by vjeuss
via reddit https://ift.tt/n7gheRV
GOV.UK
Russia's FSB malign activity: factsheet
Russia is one of the world’s most prolific cyber actors and dedicate significant resource into conducting cyber operations around the globe. The UK government has publicly attributed malign cyber activity to parts of three Russian Intelligence services: the…
AIJacking - A Vulnerability in the Popular Hugging Face AI Platform
https://ift.tt/cp3fuj5
Submitted December 08, 2023 at 09:10PM by roy_6472
via reddit https://ift.tt/RflNQHd
https://ift.tt/cp3fuj5
Submitted December 08, 2023 at 09:10PM by roy_6472
via reddit https://ift.tt/RflNQHd
Legitsecurity
Legit Discovers "AI Jacking" Vulnerability in Popular Hugging Face AI Platform
Legit Security | Uncovering 'AIJacking': How Attackers Exploit Hugging Face for AI Supply Chain Attacks - A Deep Dive into Vulnerabilities and Risks.
CVE-2023-45866: Unauthenticated Bluetooth keystroke-injection in Android, Linux, macOS and iOS
https://ift.tt/GdAaZB1
Submitted December 09, 2023 at 12:57AM by bagaudin
via reddit https://ift.tt/vWofjVZ
https://ift.tt/GdAaZB1
Submitted December 09, 2023 at 12:57AM by bagaudin
via reddit https://ift.tt/vWofjVZ
GitHub
reblog/cve-2023-45866 at main · skysafe/reblog
SkySafe Miscellaneous Reverse Engineering Blog. Contribute to skysafe/reblog development by creating an account on GitHub.
New Apache Struts file upload/execution vulnerability - CVE-2023-50164
https://ift.tt/Cz5mjYK
Submitted December 09, 2023 at 03:43AM by ExplodingFist
via reddit https://ift.tt/zmgjuAp
https://ift.tt/Cz5mjYK
Submitted December 09, 2023 at 03:43AM by ExplodingFist
via reddit https://ift.tt/zmgjuAp
CTO at NCSC Summary: week ending December 10th
https://ift.tt/ePrVl2a
Submitted December 10, 2023 at 11:37AM by digicat
via reddit https://ift.tt/CLNimOt
https://ift.tt/ePrVl2a
Submitted December 10, 2023 at 11:37AM by digicat
via reddit https://ift.tt/CLNimOt
CTO at NCSC - Cyber Defence Analysis
CTO at NCSC Summary: week ending December 10th
Industrial Control System spillover is a thing...
New payload to exploit Error-based SQL injection - Oracle database
https://ift.tt/yoVPj6c
Submitted December 10, 2023 at 01:37PM by 1046ica
via reddit https://ift.tt/Df71wLx
https://ift.tt/yoVPj6c
Submitted December 10, 2023 at 01:37PM by 1046ica
via reddit https://ift.tt/Df71wLx
www.mannulinux.org
New payload to exploit Error-based SQL injection - Oracle database
Learn Basic Concepts of Linux. Best site to learn Linux from beginner to Advanced.
AWS Organizations Defaults & Pivoting - Hacking The Cloud
https://ift.tt/JVnxGfq
Submitted December 10, 2023 at 10:45PM by RedTermSession
via reddit https://ift.tt/hVlDuJK
https://ift.tt/JVnxGfq
Submitted December 10, 2023 at 10:45PM by RedTermSession
via reddit https://ift.tt/hVlDuJK
hackingthe.cloud
AWS Organizations Defaults & Pivoting - Hacking The Cloud
How to abuse AWS Organizations' default behavior and lateral movement capabilities.
GitHub - boringtools/git-alerts: Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files
https://ift.tt/eAP85OU
Submitted December 11, 2023 at 11:23AM by predev0x00
via reddit https://ift.tt/Kt1aQWb
https://ift.tt/eAP85OU
Submitted December 11, 2023 at 11:23AM by predev0x00
via reddit https://ift.tt/Kt1aQWb
GitHub
GitHub - boringtools/git-alerts: Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files
Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files - boringtools/git-alerts
wrapwrap: using PHP filters to wrap a file with a prefix and suffix (SSRF, file read)
https://ift.tt/rRBpgw3
Submitted December 11, 2023 at 01:48PM by cfambionics
via reddit https://ift.tt/qQBLXCe
https://ift.tt/rRBpgw3
Submitted December 11, 2023 at 01:48PM by cfambionics
via reddit https://ift.tt/qQBLXCe
Ambionics
Introducing wrapwrap: using PHP filters to wrap a file with a prefix and suffix
We introduce a tool that uses PHP filters to wrap PHP resources in an arbitrary prefix and suffix.
Rhysida Ransomware: History, TTPs and Adversary Emulation Plans
https://ift.tt/QUXAOns
Submitted December 12, 2023 at 12:03AM by achilles4828
via reddit https://ift.tt/vLgFbjU
https://ift.tt/QUXAOns
Submitted December 12, 2023 at 12:03AM by achilles4828
via reddit https://ift.tt/vLgFbjU
FourCore
Rhysida Ransomware: History, TTPs and Adversary Emulation Plans
Rhysida is a new player in the Ransomware space, first appearing in May 2023, and has been targeting industries all across the globe. In recent months, Rhysida has run campaigns compromising and extorting organizations from the government, education, healthcare…
JMP slide: A NOP-sled alternative
https://ift.tt/awEh9rp
Submitted December 12, 2023 at 07:17AM by NoPaleontologist7419
via reddit https://ift.tt/UnPXLOA
https://ift.tt/awEh9rp
Submitted December 12, 2023 at 07:17AM by NoPaleontologist7419
via reddit https://ift.tt/UnPXLOA
Lambda driver blog
JMP slide: A NOP-sled alternative
In the following blog post, I will introduce you to two techniques similar to NOP-sled or NOP slide, but with the advantage that they are faster. Those techniques are: JMP slide and JCC slide.
SyzGPT: When the fuzzer meets the LLM
https://ift.tt/R8cBafF
Submitted December 12, 2023 at 12:03PM by albocoder1
via reddit https://ift.tt/dg97any
https://ift.tt/R8cBafF
Submitted December 12, 2023 at 12:03PM by albocoder1
via reddit https://ift.tt/dg97any
Practice on certifications tool is now on offsec.tools check it out!
https://ift.tt/IvM1VBC
Submitted December 12, 2023 at 04:17PM by cybersecq
via reddit https://ift.tt/rA3F6Ba
https://ift.tt/IvM1VBC
Submitted December 12, 2023 at 04:17PM by cybersecq
via reddit https://ift.tt/rA3F6Ba
offsec.tools
CyberSec Quizzes on offsec.tools
Test your knowledge on cyber security and practice for industry recognised certifications.
EMBA and EMBArk version alert - EMBA version 1.3.2 is out AND the first EMBArk version is here
https://ift.tt/Xz3k42A
Submitted December 12, 2023 at 06:47PM by _m-1-k-3_
via reddit https://ift.tt/PfG1WpT
https://ift.tt/Xz3k42A
Submitted December 12, 2023 at 06:47PM by _m-1-k-3_
via reddit https://ift.tt/PfG1WpT
GitHub
Release Version 0.1 - Hello World! · e-m-b-a/embark
The first official EMBArk release is out now!
Everything started as an idea in the beginning of 2021. The idea was to build an enterprise ready open source firmware analysis environment on top ...
Everything started as an idea in the beginning of 2021. The idea was to build an enterprise ready open source firmware analysis environment on top ...
Silverpeas App: Multiple CVEs leading to File Read on Server
https://ift.tt/dD7jFLP
Submitted December 12, 2023 at 09:28PM by hackers_and_builders
via reddit https://ift.tt/wS46CKU
https://ift.tt/dD7jFLP
Submitted December 12, 2023 at 09:28PM by hackers_and_builders
via reddit https://ift.tt/wS46CKU
Rhino Security Labs
Silverpeas App: Multiple CVEs leading to File Read on Server - Rhino Security Labs
Rhino Security Labs identified 8 new CVEs in the Silverpeas Core application.
Analysis of CVE-2023-22518 Authentication Bypass in Confluence
https://ift.tt/FbpP6B9
Submitted December 13, 2023 at 12:18AM by SL7reach
via reddit https://ift.tt/6o3KedY
https://ift.tt/FbpP6B9
Submitted December 13, 2023 at 12:18AM by SL7reach
via reddit https://ift.tt/6o3KedY
Penetration Testing and CyberSecurity Solution - SecureLayer7
Analysis of CVE-2023-22518 Authentication Bypass in Confluence
CVE-2023-22518 is a zero-day vulnerability found in Confluence Data Center, a self-managed solution known for providing organizations with best practices for collaboration. This vulnerability was...
Social Security payments increase in December for millions of Americans - California18
https://ift.tt/nsz2Hqh
Submitted December 13, 2023 at 02:45AM by Tarunkumar039
via reddit https://ift.tt/Br8A2mX
https://ift.tt/nsz2Hqh
Submitted December 13, 2023 at 02:45AM by Tarunkumar039
via reddit https://ift.tt/Br8A2mX
california18
- california18
iPhone: millions of users are threatened by a huge flaw January 17, 2022 by CA18 iPhones are not completely immune to malware and security vulnerabilities. The only advantage iPhone users have over competing Android smartphones is that Apple knows its devices…
Apache Struts Critical RCE
https://ift.tt/eSDFkjx
Submitted December 13, 2023 at 05:28AM by Cubensis-n-sanpedro
via reddit https://ift.tt/V7ZW3gz
https://ift.tt/eSDFkjx
Submitted December 13, 2023 at 05:28AM by Cubensis-n-sanpedro
via reddit https://ift.tt/V7ZW3gz
Credential Harvesting with PowerShell and SpecterInsight
https://ift.tt/jTm8Gob
Submitted December 13, 2023 at 06:37AM by pracsec
via reddit https://ift.tt/KHEo19C
https://ift.tt/jTm8Gob
Submitted December 13, 2023 at 06:37AM by pracsec
via reddit https://ift.tt/KHEo19C
Practical Security Analytics LLC
Credential Harvesting with PowerShell and SpecterInsight
Overview Credential harvesting, also known as credential theft or credential stealing, refers to the collection sensitive authentication information from individuals or systems. The goal of credent…
Rhysida Ransomware analysis - A painful sting to Insomniac Games
https://ift.tt/NdVIv1G
Submitted December 13, 2023 at 11:18AM by ShadowStackRE
via reddit https://ift.tt/OcHy3nX
https://ift.tt/NdVIv1G
Submitted December 13, 2023 at 11:18AM by ShadowStackRE
via reddit https://ift.tt/OcHy3nX
ShadowStackRE
Rhysida Ransomware analysis - A painful sting to Insomniac Games — ShadowStackRE
Rhysida Ransomware analysis - A painful sting to Insomniac Games Hack
Sensing Vulnerabilities in your pfSense Firewall: From XSS to RCE
https://ift.tt/GvHO4Ep
Submitted December 12, 2023 at 09:17PM by SonarPaul
via reddit https://ift.tt/GL16wEr
https://ift.tt/GvHO4Ep
Submitted December 12, 2023 at 09:17PM by SonarPaul
via reddit https://ift.tt/GL16wEr
Sonarsource
pfSense Security: Sensing Code Vulnerabilities with SonarCloud
Our Clean Code solution SonarCloud discovered multiple vulnerabilities leading to remote code execution on pfSense CE 2.7.0. Let's see how SonarCloud found them and how it can keep your code clean.