Deceptive Deprecation: The Truth About npm Deprecated Packages
https://ift.tt/NjC9dgV
Submitted January 18, 2024 at 07:19PM by ilay789
via reddit https://ift.tt/kzxfUWp
https://ift.tt/NjC9dgV
Submitted January 18, 2024 at 07:19PM by ilay789
via reddit https://ift.tt/kzxfUWp
Aqua
The Truth About npm Deprecated Packages
Researchers at Aqua Nautilus found that 8.2% percent of the most downloaded npm packages are officially deprecated, but the real number is much larger.
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
https://ift.tt/76TyFQL
Submitted January 18, 2024 at 09:29PM by lohacker0
via reddit https://ift.tt/zywOl7d
https://ift.tt/76TyFQL
Submitted January 18, 2024 at 09:29PM by lohacker0
via reddit https://ift.tt/zywOl7d
Varonis
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
Varonis Threat Labs discovered a new Outlook exploit and three new ways to access NTLM v2 hashed passwords.
How Praetorian Discovered a Critical TensorFlow Supply Chain Attack
https://ift.tt/7pgDXSi
Submitted January 19, 2024 at 03:35AM by cyberforce218
via reddit https://ift.tt/rcoWCmN
https://ift.tt/7pgDXSi
Submitted January 19, 2024 at 03:35AM by cyberforce218
via reddit https://ift.tt/rcoWCmN
Praetorian
TensorFlow Supply Chain Compromise via Self-Hosted Runner Attack
Introduction With the recent rise and adoption of artificial intelligence technologies, open-source frameworks such as TensorFlow are prime targets for attackers seeking to conduct software supply chain attacks. Over the last several years, Praetorian engineers…
npm Package Found Delivering RAT Through Signed Microsoft Executable
https://ift.tt/qw2TSLX
Submitted January 19, 2024 at 08:47AM by louis11
via reddit https://ift.tt/Dj9f2Y6
https://ift.tt/qw2TSLX
Submitted January 19, 2024 at 08:47AM by louis11
via reddit https://ift.tt/Dj9f2Y6
Phylum
npm Package Found Delivering Sophisticated RAT
⚠️This appears to be an ongoing campaign. Since publication, additional packages have been released tied to this threat actor. See the IOCs below.
On January 12, 2024 Phylum’s automated risk detection platform alerted us to a suspicious publication on npm.…
On January 12, 2024 Phylum’s automated risk detection platform alerted us to a suspicious publication on npm.…
Taking over WhatsApp accounts by reading voicemails
https://ift.tt/SE2RzCy
Submitted January 19, 2024 at 07:26PM by AffectionateOrchid10
via reddit https://ift.tt/kD7X2x4
https://ift.tt/SE2RzCy
Submitted January 19, 2024 at 07:26PM by AffectionateOrchid10
via reddit https://ift.tt/kD7X2x4
Medium
Taking over WhatsApp accounts by reading voicemails
When designing authentication systems, it’s common practice to implement backup mechanisms so users can easily regain access to their…
Technical Deepdive of the Okta HAR Breach Incident
https://ift.tt/nBSjsf6
Submitted January 19, 2024 at 10:59PM by Or1rez
via reddit https://ift.tt/MDTQS1b
https://ift.tt/nBSjsf6
Submitted January 19, 2024 at 10:59PM by Or1rez
via reddit https://ift.tt/MDTQS1b
Rezonate - Protect Identities, Everywhere
How Threat Actors Leveraged HAR Files to Attack Okta’s Customers - Rezonate
On October 19, 2023, Okta notified its customers of a security breach involving unauthorized access to their support system. This incident occurred when an external party obtained and misused Okta's support service account credentials. The investigation by…
LogBoost - A tool for parsing and enriching IP addresses in any type of log/file with GEO, DNS, OSINT IOCs and ASN context
https://ift.tt/nDXHSAh
Submitted January 20, 2024 at 08:30PM by panscanner
via reddit https://ift.tt/PYW9HO6
https://ift.tt/nDXHSAh
Submitted January 20, 2024 at 08:30PM by panscanner
via reddit https://ift.tt/PYW9HO6
GitHub
GitHub - joeavanzato/LogBoost: Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS…
Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indicator matches. - joeavanzato/LogBoost
Just released v10.1 of scanme a go package for scanning private and public IPs for open TCP ports 👁️ - it would be great to have some feedback from you pros, thanks in advance for any contribution!
https://ift.tt/lnGNPxS
Submitted January 21, 2024 at 08:32PM by Technical_Shelter621
via reddit https://ift.tt/68SEu9r
https://ift.tt/lnGNPxS
Submitted January 21, 2024 at 08:32PM by Technical_Shelter621
via reddit https://ift.tt/68SEu9r
GitHub
GitHub - CyberRoute/scanme: A Golang package for scanning private and public IPs for open TCP ports 👁️
A Golang package for scanning private and public IPs for open TCP ports 👁️ - CyberRoute/scanme
BusKill Warrant Canary #007 🕵️
https://ift.tt/naTNMp8
Submitted January 21, 2024 at 10:27PM by maltfield
via reddit https://ift.tt/HNKvnjg
https://ift.tt/naTNMp8
Submitted January 21, 2024 at 10:27PM by maltfield
via reddit https://ift.tt/HNKvnjg
BusKill
BusKill Canary #7 - BusKill
This post contains the cryptographically-signed BusKill warrant canary #007 for January 2023 to January 2024.
AsyncRAT: Config Decryption Techniques and Salt Analysis - Securityinbits
https://ift.tt/BcXSCwW
Submitted January 22, 2024 at 10:29AM by securityinbits
via reddit https://ift.tt/57CKUSH
https://ift.tt/BcXSCwW
Submitted January 22, 2024 at 10:29AM by securityinbits
via reddit https://ift.tt/57CKUSH
Securityinbits
AsyncRAT: Config Decryption Techniques and Salt Analysis - Securityinbits
Explore AsyncRAT inner workings. Learn unique decryption techniques to enhance your cybersecurity skills today!
Domain Escalation – Backup Operator
https://ift.tt/Mil2FZN
Submitted January 22, 2024 at 04:37PM by netbiosX
via reddit https://ift.tt/Gtv79cN
https://ift.tt/Mil2FZN
Submitted January 22, 2024 at 04:37PM by netbiosX
via reddit https://ift.tt/Gtv79cN
Penetration Testing Lab
Domain Escalation – Backup Operator
The Backup Operators is a Windows built-in group. Users which are part of this group have permissions to perform backup and restore operations. More specifically, these users have the SeBackupPrivi…
Vulnerability in Gambio pertains to an insecure deserialization flaw, which ultimately allows an attacker to execute remote code on affected systems.
https://ift.tt/sIBkJ9b
Submitted January 22, 2024 at 06:23PM by usdAG
via reddit https://ift.tt/yvXFKb5
https://ift.tt/sIBkJ9b
Submitted January 22, 2024 at 06:23PM by usdAG
via reddit https://ift.tt/yvXFKb5
usd HeroLab
usd-2023-0046 | usd HeroLab
Advisory ID: usd-2023-0046 | Product: Gambio | Vulnerability Type: Deserialization of Untrusted Data (CWE-502)
How a vulnerability in WifiKey's AC Gateway allows remote attackers to trigger a pre-auth RCE
https://ift.tt/g1HvRdw
Submitted January 22, 2024 at 10:24PM by SSDisclosure
via reddit https://ift.tt/zpn1P9E
https://ift.tt/g1HvRdw
Submitted January 22, 2024 at 10:24PM by SSDisclosure
via reddit https://ift.tt/zpn1P9E
SSD Secure Disclosure
SSD Advisory - WifiKey AC Gateway Pre-auth RCE - SSD Secure Disclosure
Summary A vulnerability exists in WifiKey’s AC Gateway allowing remote attackers to trigger a pre-auth RCE vulnerability in the product allowing complete compromise of the device. Credit An independent security researcher working with SSD Secure Disclosure.…
EC2 Privilege Escalation Through User Data
https://ift.tt/A6ohNxk
Submitted January 22, 2024 at 11:02PM by RedTermSession
via reddit https://ift.tt/akEXMWn
https://ift.tt/A6ohNxk
Submitted January 22, 2024 at 11:02PM by RedTermSession
via reddit https://ift.tt/akEXMWn
hackingthe.cloud
EC2 Privilege Escalation Through User Data - Hacking The Cloud
How to escalate privileges on an EC2 instance by abusing user data.
Many CVE Records Are Listing the Wrong Versions of Software as Being Affected
https://ift.tt/xXjyTpJ
Submitted January 23, 2024 at 12:26AM by PluginVulns
via reddit https://ift.tt/0iQJa4I
https://ift.tt/xXjyTpJ
Submitted January 23, 2024 at 12:26AM by PluginVulns
via reddit https://ift.tt/0iQJa4I
Plugin Vulnerabilities
Many CVE Records Are Listing the Wrong Versions of Software as Being Affected
[VNCERT/CC] CVE-2023-22527 realworld poc The original PoC: payload is length limited Solution: 1. Write the noscript file in parts 2. Run the noscript
https://ift.tt/rKI1UYN
Submitted January 23, 2024 at 01:01PM by arleth94
via reddit https://ift.tt/W2ULexi
https://ift.tt/rKI1UYN
Submitted January 23, 2024 at 01:01PM by arleth94
via reddit https://ift.tt/W2ULexi
GitHub
GitHub - VNCERT-CC/CVE-2023-22527-confluence: [Confluence] CVE-2023-22527 realworld poc
[Confluence] CVE-2023-22527 realworld poc. Contribute to VNCERT-CC/CVE-2023-22527-confluence development by creating an account on GitHub.
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing (CVE-2023-45866)
https://ift.tt/G2c5R1n
Submitted January 23, 2024 at 03:14PM by barakadua131
via reddit https://ift.tt/8mjWXuO
https://ift.tt/G2c5R1n
Submitted January 23, 2024 at 03:14PM by barakadua131
via reddit https://ift.tt/8mjWXuO
Mobile Hacker
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing - Mobile Hacker
[update 2024-02-19] This vulnerability can be even used to remotely wipe data of targeted Android smartphone. Using this vulnerability it is possible to guess user lock screen PIN. After five incorrect PINs device is locked out for 30 seconds. This operation…
Typhooncon 2024 has less than 2 weeks left for CFT submissions. Don't miss out!
https://ift.tt/0vFf7n5
Submitted January 23, 2024 at 04:04PM by Straight-Zombie-646
via reddit https://ift.tt/CoXhp6N
https://ift.tt/0vFf7n5
Submitted January 23, 2024 at 04:04PM by Straight-Zombie-646
via reddit https://ift.tt/CoXhp6N
Export Controls: Explained
https://ift.tt/9AXZWwf
Submitted January 23, 2024 at 05:05PM by zolakrystie
via reddit https://ift.tt/Py1bJWH
https://ift.tt/9AXZWwf
Submitted January 23, 2024 at 05:05PM by zolakrystie
via reddit https://ift.tt/Py1bJWH
NextLabs
What are Export Controls?
Export Controls are laws and regulations that govern the transfer or disclosure of goods, technology and funds originating in one country to persons or entities based or having citizenship in another country. This applies even if the regulated items are not…
A recent analysis of the Cactus Ransomware
https://ift.tt/Menxqzd
Submitted January 23, 2024 at 07:58PM by ShadowStackRE
via reddit https://ift.tt/YO5Ehpj
https://ift.tt/Menxqzd
Submitted January 23, 2024 at 07:58PM by ShadowStackRE
via reddit https://ift.tt/YO5Ehpj
ShadowStackRE
Cactus Ransomware malware analysis — ShadowStackRE
A technical analysis of the Cactus Ransomware malware
Windows - Data Protection API - A journey into various DPAPI potential abuses from an offensive security perspective
https://ift.tt/DWBMa1F
Submitted January 24, 2024 at 12:48AM by clod81
via reddit https://ift.tt/I9q81Kr
https://ift.tt/DWBMa1F
Submitted January 24, 2024 at 12:48AM by clod81
via reddit https://ift.tt/I9q81Kr
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team