Writeup of a [RCE] in Factorio by supplying a modified save file.
https://ift.tt/v9T6EDa
Submitted January 11, 2024 at 03:40PM by moviuro
via reddit https://ift.tt/JVuYXRb
https://ift.tt/v9T6EDa
Submitted January 11, 2024 at 03:40PM by moviuro
via reddit https://ift.tt/JVuYXRb
GitHub
GitHub - Valentin-Metz/writeup_factorio: Writeup of a remote code execution in Factorio by supplying a modified save file.
Writeup of a remote code execution in Factorio by supplying a modified save file. - Valentin-Metz/writeup_factorio
Vulnerabilities on Bosch Rexroth Nutrunners May Be Abused to Stop Production Lines, Tamper with Safety-Critical Tightenings
https://ift.tt/ECSKa5Q
Submitted January 11, 2024 at 07:08PM by _vavkamil_
via reddit https://ift.tt/T7kYhgR
https://ift.tt/ECSKa5Q
Submitted January 11, 2024 at 07:08PM by _vavkamil_
via reddit https://ift.tt/T7kYhgR
Nozominetworks
Vulnerabilities on Bosch Rexroth Nutrunners May Be Abused to Stop Production Lines, Tamper with Safety-Critical Tightenings
New vulnerabilities discovered in the Bosch Rexroth NXA015S-36V-B, a popular smart nutrunner used in automotive production lines, may halt production or compromise safety.
Weaponizing Apache OFBiz CVE-2023-51467
https://ift.tt/A7b6IUM
Submitted January 11, 2024 at 08:37PM by chicksdigthelongrun
via reddit https://ift.tt/GTyhQbH
https://ift.tt/A7b6IUM
Submitted January 11, 2024 at 08:37PM by chicksdigthelongrun
via reddit https://ift.tt/GTyhQbH
VulnCheck
Weaponizing Apache OFBiz CVE-2023-51467 - Blog - VulnCheck
VulnCheck bypasses the Apache OFBiz Groovy sandbox to land a memory resident reverse shell.
Dependency Confusions in Docker and remote pwning of your infra
https://ift.tt/q4fLlRM
Submitted January 11, 2024 at 10:23PM by gquere
via reddit https://ift.tt/0vRIOh4
https://ift.tt/q4fLlRM
Submitted January 11, 2024 at 10:23PM by gquere
via reddit https://ift.tt/0vRIOh4
Critical PyTorch Supply Chain Vulnerability
https://ift.tt/vB4nCLW
Submitted January 11, 2024 at 11:19PM by IrohsLotusTile
via reddit https://ift.tt/F31wq9x
https://ift.tt/vB4nCLW
Submitted January 11, 2024 at 11:19PM by IrohsLotusTile
via reddit https://ift.tt/F31wq9x
John Stawinski IV
Playing with Fire – How We Executed a Critical Supply Chain Attack on PyTorch
Security tends to lag behind adoption, and AI/ML is no exception. Four months ago, Adnan Khan and I exploited a critical CI/CD vulnerability in PyTorch, one of the world’s leading ML platform…
Attack of the week: Airdrop tracing
https://ift.tt/NE8gx0v
Submitted January 11, 2024 at 10:31PM by feross
via reddit https://ift.tt/VmxGjhs
https://ift.tt/NE8gx0v
Submitted January 11, 2024 at 10:31PM by feross
via reddit https://ift.tt/VmxGjhs
A Few Thoughts on Cryptographic Engineering
Attack of the week: Airdrop tracing
It’s been a while since I wrote an “attack of the week” post, and the fault for this is entirely mine. I’ve been much too busy writing boring posts about Schnorr signatures!…
Introducing Exploit Observer — More than Shodan Exploits, Less than Vulners
https://ift.tt/fhpH4ty
Submitted January 12, 2024 at 08:37AM by glatisantbeast
via reddit https://ift.tt/qRYef42
https://ift.tt/fhpH4ty
Submitted January 12, 2024 at 08:37AM by glatisantbeast
via reddit https://ift.tt/qRYef42
Medium
Introducing Exploit Observer — More than Shodan Exploits, Less than Vulners
I’m going to tell you how Exploit Observer has revolutionized the ways of automated exploit discovery & analysis at A.R.P. Syndicate.
Talkback Intro: A smart infosec resource aggregator
https://ift.tt/7IbAdDs
Submitted January 12, 2024 at 11:38AM by thinkV
via reddit https://ift.tt/de1imsI
https://ift.tt/7IbAdDs
Submitted January 12, 2024 at 11:38AM by thinkV
via reddit https://ift.tt/de1imsI
Elttam
Keeping up with the Pwnses
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
unblob project update - Filesystem sandboxing, nice UI, and pattern auto-identification.
https://ift.tt/mXUVbTk
Submitted January 12, 2024 at 01:35PM by g_e_r_h_a_r_d
via reddit https://ift.tt/STXjYEN
https://ift.tt/mXUVbTk
Submitted January 12, 2024 at 01:35PM by g_e_r_h_a_r_d
via reddit https://ift.tt/STXjYEN
ONEKEY
Explore our blog 👉️ for the latest UNBLOB insights.
Including new features, bug fixes, and more that have landed in UNBLOB in the second half of 2023.
Utilizing Unit testing Frameworks as a Vulnerability Scanner
https://ift.tt/7ChWrfm
Submitted January 12, 2024 at 12:53PM by 0xcrypto
via reddit https://ift.tt/mMFDBcC
https://ift.tt/7ChWrfm
Submitted January 12, 2024 at 12:53PM by 0xcrypto
via reddit https://ift.tt/mMFDBcC
Keeping up with the Pwnses
https://ift.tt/7IbAdDs
Submitted January 12, 2024 at 05:22PM by thinkV
via reddit https://ift.tt/7pJVhz3
https://ift.tt/7IbAdDs
Submitted January 12, 2024 at 05:22PM by thinkV
via reddit https://ift.tt/7pJVhz3
Elttam
Keeping up with the Pwnses
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
How to Leverage Internal Proxies for Lateral Movement, Firewall Evasion, and Trust Exploitation
https://ift.tt/ZHyYCwk
Submitted January 12, 2024 at 07:36PM by pracsec
via reddit https://ift.tt/yMVApkH
https://ift.tt/ZHyYCwk
Submitted January 12, 2024 at 07:36PM by pracsec
via reddit https://ift.tt/yMVApkH
Practical Security Analytics LLC
How to Leverage Internal Proxies for Lateral Movement, Firewall Evasion, and Trust Exploitation
Overview The primary tactic we will be exploring in this post is the use of proxies inside of a target network. There are a lot of different types of proxies for both offense and defense. This post…
CVE-2023-43208: NextGen Mirth Connect Pre-Auth RCE Deep-Dive
https://ift.tt/SuAGIan
Submitted January 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/xarFA15
https://ift.tt/SuAGIan
Submitted January 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/xarFA15
Horizon3.ai
Writeup for CVE-2023-43208: NextGen Mirth Connect Pre-Auth RCE – Horizon3.ai
Mirth Connect, by NextGen HealthCare, versions prior to 4.4.1 are vulnerable to an unauthenticated RCE vulnerability, CVE-2023-43208.
CVE-2023-39143: PaperCut WebDAV RCE Deep-Dive
https://ift.tt/95hTGC1
Submitted January 12, 2024 at 08:07PM by scopedsecurity
via reddit https://ift.tt/tO4YZDA
https://ift.tt/95hTGC1
Submitted January 12, 2024 at 08:07PM by scopedsecurity
via reddit https://ift.tt/tO4YZDA
Horizon3.ai
Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability – Horizon3.ai
Introduction Back in Aug. 2023 we released an advisory for CVE-2023-39143, a critical vulnerability that affects Windows installs of the PaperCut NG/MF print management software. Attackers can exploit this vulnerability […]
A BadUSB that can exfiltrate stored WiFi passwords
https://ift.tt/wi2uMFa
Submitted January 12, 2024 at 08:40PM by 42-is-the-number
via reddit https://ift.tt/Z3tL0SN
https://ift.tt/wi2uMFa
Submitted January 12, 2024 at 08:40PM by 42-is-the-number
via reddit https://ift.tt/Z3tL0SN
GitHub
GitHub - AleksaMCode/WiFi-password-stealer: Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data…
Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password). - AleksaMCode/WiFi-password-stealer
VBA: having fun with macros, overwritten pointers & R/W/X memory
https://ift.tt/1c6dgGY
Submitted January 13, 2024 at 04:21PM by gid0rah
via reddit https://ift.tt/SC8JXyT
https://ift.tt/1c6dgGY
Submitted January 13, 2024 at 04:21PM by gid0rah
via reddit https://ift.tt/SC8JXyT
VBA: having fun with macros, overwritten pointers & R/W/X memory |
VBA: having fun with macros, overwritten pointers & R/W/X memory | AdeptsOf0xCC
Article describing an alternative method to trigger shellcode execution
Privilege escalation using the XAML diagnostics API (CVE-2023-36003)
https://ift.tt/h4QO0gs
Submitted January 13, 2024 at 03:41PM by m417z
via reddit https://ift.tt/DoR8F14
https://ift.tt/h4QO0gs
Submitted January 13, 2024 at 03:41PM by m417z
via reddit https://ift.tt/DoR8F14
M417Z
Privilege escalation using the XAML diagnostics API (CVE-2023-36003)
This is a write-up of a vulnerability that I discovered in Windows. The vulnerability was patched in December’s Patch Tuesday, and the CVE assigned to it is CVE-2023-36003. The vulnerability allows a non-elevated process to inject a DLL into an elevated or…
Welcome To 2024, The SSLVPN Chaos Continues - Ivanti CVE-2023-46805 & CVE-2024-21887 (watchTowr Labs)
https://ift.tt/I4TBSO5
Submitted January 13, 2024 at 05:58PM by dx7r__
via reddit https://ift.tt/Tizlu7c
https://ift.tt/I4TBSO5
Submitted January 13, 2024 at 05:58PM by dx7r__
via reddit https://ift.tt/Tizlu7c
watchTowr Labs - Blog
Welcome To 2024, The SSLVPN Chaos Continues - Ivanti CVE-2023-46805 & CVE-2024-21887
Did you have a good break? Have you had a chance to breathe? Wake up.
It’s 2024, and the chaos continues - thanks to Volexity (Volexity’s writeup), the industry has been alerted to in-the-wild exploitation of 2 incredibly serious 0days (CVE-2023-46805 and…
It’s 2024, and the chaos continues - thanks to Volexity (Volexity’s writeup), the industry has been alerted to in-the-wild exploitation of 2 incredibly serious 0days (CVE-2023-46805 and…
Hedera and Algorand team up to create the DeRec Alliance, wow this is huge! This is a pretty big deal for security on the decentralized web. I generated this article while researching it, you may find it interesting. Note: Contains some affiliate links at the end for cryptography books.
https://ift.tt/aKWY8no
Submitted January 14, 2024 at 12:45AM by dima11235813
via reddit https://ift.tt/wve6G4n
https://ift.tt/aKWY8no
Submitted January 14, 2024 at 12:45AM by dima11235813
via reddit https://ift.tt/wve6G4n
Learn Internet Grow
🚀 Breaking News: Decentralized Key Management
Revolutionizing Digital Asset Security with the DeRec Alliance 🌐 🔐 #DeRecAlliance #DigitalAssetSecurity #Hedera & #Algorand
Scame
https://ift.tt/UM3uoXb
Submitted January 14, 2024 at 02:13AM by Technical_Shelter621
via reddit https://ift.tt/CaTsxk2
https://ift.tt/UM3uoXb
Submitted January 14, 2024 at 02:13AM by Technical_Shelter621
via reddit https://ift.tt/CaTsxk2
GitHub
GitHub - CyberRoute/scanme: A Golang package for scanning private and public IPs for open TCP ports 👁️
A Golang package for scanning private and public IPs for open TCP ports 👁️ - CyberRoute/scanme
v0.14.0 Release of Backhand - SquashFS library and binaries
https://ift.tt/tF4aYq6
Submitted January 14, 2024 at 03:33AM by arch_rust
via reddit https://ift.tt/6vVXkWq
https://ift.tt/tF4aYq6
Submitted January 14, 2024 at 03:33AM by arch_rust
via reddit https://ift.tt/6vVXkWq
GitHub
Release v0.14.0 · wcampbell0x2a/backhand
Major changes were made to the organization of this repo, with the library backhand now being separated from
the backhand-cli package, which is used to install unsquashfs, replace, and add.
backhan...
the backhand-cli package, which is used to install unsquashfs, replace, and add.
backhan...