CCDC 2024
https://ift.tt/2KdlRrk
Submitted January 14, 2024 at 03:59AM by TopShelfHockeyMN
via reddit https://ift.tt/rCBcQxh
https://ift.tt/2KdlRrk
Submitted January 14, 2024 at 03:59AM by TopShelfHockeyMN
via reddit https://ift.tt/rCBcQxh
Exploit Security CTF
https://ift.tt/O6uHLCx
Submitted January 14, 2024 at 05:48PM by 9lyph
via reddit https://ift.tt/6FLJf7V
https://ift.tt/O6uHLCx
Submitted January 14, 2024 at 05:48PM by 9lyph
via reddit https://ift.tt/6FLJf7V
Supply Chain Attack on GHA Runner Images
https://ift.tt/EgtmJCy
Submitted January 12, 2024 at 09:53PM by cyberforce218
via reddit https://ift.tt/MlhZHfG
https://ift.tt/EgtmJCy
Submitted January 12, 2024 at 09:53PM by cyberforce218
via reddit https://ift.tt/MlhZHfG
Adnan Khan's Blog
One Supply Chain Attack to Rule Them All – Poisoning GitHub’s Runner Images
I successfully exploited a critical misconfiguration vulnerability in GitHub’s actions/runner images repository. I gained control over build agents used by the repository, accessed secrets, a…
Just started new opensource tool for optimisation the process of analyzing web logs. Suggest for me some features you would like to see? Repo name : OSTE WEB LOG ANALYZER (OSTE WLA)
https://ift.tt/n4mi8Iv
Submitted January 14, 2024 at 11:30PM by OSTEsayed
via reddit https://ift.tt/hLxq2sW
https://ift.tt/n4mi8Iv
Submitted January 14, 2024 at 11:30PM by OSTEsayed
via reddit https://ift.tt/hLxq2sW
GitHub
GitHub - OSTEsayed/OSTE-Web-Log-Analyzer: OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.
OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer. - OSTEsayed/OSTE-Web-Log-Analyzer
Access Controls: ABAC vs RBAC
https://ift.tt/vY0hU1d
Submitted January 15, 2024 at 11:31AM by zolakrystie
via reddit https://ift.tt/MbX3xup
https://ift.tt/vY0hU1d
Submitted January 15, 2024 at 11:31AM by zolakrystie
via reddit https://ift.tt/MbX3xup
NextLabs
ABAC
Attribute-Based Access Control (ABAC)
The Definitive Guide to Attribute-Based Access Control (ABAC)
Attribute-based access control (ABAC) has emerged as the next-gen technology for secure access to business-critical data. The complexities of today’s
The Definitive Guide to Attribute-Based Access Control (ABAC)
Attribute-based access control (ABAC) has emerged as the next-gen technology for secure access to business-critical data. The complexities of today’s
Lateral Movement - Visual Studio DTE
https://ift.tt/JdfZ5Nr
Submitted January 15, 2024 at 05:01PM by netbiosX
via reddit https://ift.tt/vUgm02R
https://ift.tt/JdfZ5Nr
Submitted January 15, 2024 at 05:01PM by netbiosX
via reddit https://ift.tt/vUgm02R
Penetration Testing Lab
Lateral Movement – Visual Studio DTE
A lot of organizations have some sort of application development program and it is highly likely that developers will utilize Visual Studio for their development needs. Outside of the risk of from …
Introducing Super Sharp Shares
https://ift.tt/DRqgTvZ
Submitted January 16, 2024 at 06:33PM by ZephrX112
via reddit https://ift.tt/Hut9o0Q
https://ift.tt/DRqgTvZ
Submitted January 16, 2024 at 06:33PM by ZephrX112
via reddit https://ift.tt/Hut9o0Q
Lares Labs
Introducing Super Sharp Shares
SuperSharpShares is a tool designed to automate enumerating domain shares, allowing for quick verification of accessible shares by your associated domain account.
Web LLM attacks - techniques & labs
https://ift.tt/VpyZnWx
Submitted January 16, 2024 at 09:06PM by albinowax
via reddit https://ift.tt/u4tMQPc
https://ift.tt/VpyZnWx
Submitted January 16, 2024 at 09:06PM by albinowax
via reddit https://ift.tt/u4tMQPc
portswigger.net
Web LLM attacks | Web Security Academy
Organizations are rushing to integrate Large Language Models (LLMs) in order to improve their online customer experience. This exposes them to web LLM ...
PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack
https://ift.tt/UfVheak
Submitted January 16, 2024 at 10:05PM by guedou
via reddit https://ift.tt/ZdeT0kH
https://ift.tt/UfVheak
Submitted January 16, 2024 at 10:05PM by guedou
via reddit https://ift.tt/ZdeT0kH
Quarkslab
PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack.
Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website
https://ift.tt/5hyfJ4w
Submitted January 17, 2024 at 10:28PM by EatonZ
via reddit https://ift.tt/N2HEThK
https://ift.tt/5hyfJ4w
Submitted January 17, 2024 at 10:28PM by EatonZ
via reddit https://ift.tt/N2HEThK
Eaton-Works
Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website
A vulnerable API on Toyota Tsusho Insurance Broker India’s premium calculator website exposed Microsoft corporate cloud credentials.
libX11: Uncovering and exploiting a 35-year-old vulnerability – Part 1 of 2
https://ift.tt/hHIPWk8
Submitted January 18, 2024 at 02:56AM by SRMish3
via reddit https://ift.tt/7C0hPLB
https://ift.tt/hHIPWk8
Submitted January 18, 2024 at 02:56AM by SRMish3
via reddit https://ift.tt/7C0hPLB
JFrog
CVE-2023-43786 & CVE-2023-43787 Vulns in libX11: All You Need To Know
Learn all about the 35-year-old vulnerabilities found by our Security Team in libX11, causing a denial-of-service and remote code execution.
The Second Wednesday Of The First Month Of Every Quarter: Juniper 0day Revisited - watchTowr Labs
https://ift.tt/k2lipPY
Submitted January 18, 2024 at 02:40PM by dx7r__
via reddit https://ift.tt/9zMjB80
https://ift.tt/k2lipPY
Submitted January 18, 2024 at 02:40PM by dx7r__
via reddit https://ift.tt/9zMjB80
watchTowr Labs - Blog
The Second Wednesday Of The First Month Of Every Quarter: Juniper 0day Revisited
Who likes vulnerabilities in appliances from security vendors? Everyone loves appliance vulnerabilities! If, by 'everyone', you mean various ransomware and APT groups of course (and us).
Regular watchTowr-watchers (meta-towr-watchers?) will remember our…
Regular watchTowr-watchers (meta-towr-watchers?) will remember our…
Deceptive Deprecation: The Truth About npm Deprecated Packages
https://ift.tt/NjC9dgV
Submitted January 18, 2024 at 07:19PM by ilay789
via reddit https://ift.tt/kzxfUWp
https://ift.tt/NjC9dgV
Submitted January 18, 2024 at 07:19PM by ilay789
via reddit https://ift.tt/kzxfUWp
Aqua
The Truth About npm Deprecated Packages
Researchers at Aqua Nautilus found that 8.2% percent of the most downloaded npm packages are officially deprecated, but the real number is much larger.
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
https://ift.tt/76TyFQL
Submitted January 18, 2024 at 09:29PM by lohacker0
via reddit https://ift.tt/zywOl7d
https://ift.tt/76TyFQL
Submitted January 18, 2024 at 09:29PM by lohacker0
via reddit https://ift.tt/zywOl7d
Varonis
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
Varonis Threat Labs discovered a new Outlook exploit and three new ways to access NTLM v2 hashed passwords.
How Praetorian Discovered a Critical TensorFlow Supply Chain Attack
https://ift.tt/7pgDXSi
Submitted January 19, 2024 at 03:35AM by cyberforce218
via reddit https://ift.tt/rcoWCmN
https://ift.tt/7pgDXSi
Submitted January 19, 2024 at 03:35AM by cyberforce218
via reddit https://ift.tt/rcoWCmN
Praetorian
TensorFlow Supply Chain Compromise via Self-Hosted Runner Attack
Introduction With the recent rise and adoption of artificial intelligence technologies, open-source frameworks such as TensorFlow are prime targets for attackers seeking to conduct software supply chain attacks. Over the last several years, Praetorian engineers…
npm Package Found Delivering RAT Through Signed Microsoft Executable
https://ift.tt/qw2TSLX
Submitted January 19, 2024 at 08:47AM by louis11
via reddit https://ift.tt/Dj9f2Y6
https://ift.tt/qw2TSLX
Submitted January 19, 2024 at 08:47AM by louis11
via reddit https://ift.tt/Dj9f2Y6
Phylum
npm Package Found Delivering Sophisticated RAT
⚠️This appears to be an ongoing campaign. Since publication, additional packages have been released tied to this threat actor. See the IOCs below.
On January 12, 2024 Phylum’s automated risk detection platform alerted us to a suspicious publication on npm.…
On January 12, 2024 Phylum’s automated risk detection platform alerted us to a suspicious publication on npm.…
Taking over WhatsApp accounts by reading voicemails
https://ift.tt/SE2RzCy
Submitted January 19, 2024 at 07:26PM by AffectionateOrchid10
via reddit https://ift.tt/kD7X2x4
https://ift.tt/SE2RzCy
Submitted January 19, 2024 at 07:26PM by AffectionateOrchid10
via reddit https://ift.tt/kD7X2x4
Medium
Taking over WhatsApp accounts by reading voicemails
When designing authentication systems, it’s common practice to implement backup mechanisms so users can easily regain access to their…
Technical Deepdive of the Okta HAR Breach Incident
https://ift.tt/nBSjsf6
Submitted January 19, 2024 at 10:59PM by Or1rez
via reddit https://ift.tt/MDTQS1b
https://ift.tt/nBSjsf6
Submitted January 19, 2024 at 10:59PM by Or1rez
via reddit https://ift.tt/MDTQS1b
Rezonate - Protect Identities, Everywhere
How Threat Actors Leveraged HAR Files to Attack Okta’s Customers - Rezonate
On October 19, 2023, Okta notified its customers of a security breach involving unauthorized access to their support system. This incident occurred when an external party obtained and misused Okta's support service account credentials. The investigation by…
LogBoost - A tool for parsing and enriching IP addresses in any type of log/file with GEO, DNS, OSINT IOCs and ASN context
https://ift.tt/nDXHSAh
Submitted January 20, 2024 at 08:30PM by panscanner
via reddit https://ift.tt/PYW9HO6
https://ift.tt/nDXHSAh
Submitted January 20, 2024 at 08:30PM by panscanner
via reddit https://ift.tt/PYW9HO6
GitHub
GitHub - joeavanzato/LogBoost: Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS…
Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indicator matches. - joeavanzato/LogBoost
Just released v10.1 of scanme a go package for scanning private and public IPs for open TCP ports 👁️ - it would be great to have some feedback from you pros, thanks in advance for any contribution!
https://ift.tt/lnGNPxS
Submitted January 21, 2024 at 08:32PM by Technical_Shelter621
via reddit https://ift.tt/68SEu9r
https://ift.tt/lnGNPxS
Submitted January 21, 2024 at 08:32PM by Technical_Shelter621
via reddit https://ift.tt/68SEu9r
GitHub
GitHub - CyberRoute/scanme: A Golang package for scanning private and public IPs for open TCP ports 👁️
A Golang package for scanning private and public IPs for open TCP ports 👁️ - CyberRoute/scanme
BusKill Warrant Canary #007 🕵️
https://ift.tt/naTNMp8
Submitted January 21, 2024 at 10:27PM by maltfield
via reddit https://ift.tt/HNKvnjg
https://ift.tt/naTNMp8
Submitted January 21, 2024 at 10:27PM by maltfield
via reddit https://ift.tt/HNKvnjg
BusKill
BusKill Canary #7 - BusKill
This post contains the cryptographically-signed BusKill warrant canary #007 for January 2023 to January 2024.