Technical Deepdive of the Okta HAR Breach Incident
https://ift.tt/nBSjsf6
Submitted January 19, 2024 at 10:59PM by Or1rez
via reddit https://ift.tt/MDTQS1b
https://ift.tt/nBSjsf6
Submitted January 19, 2024 at 10:59PM by Or1rez
via reddit https://ift.tt/MDTQS1b
Rezonate - Protect Identities, Everywhere
How Threat Actors Leveraged HAR Files to Attack Okta’s Customers - Rezonate
On October 19, 2023, Okta notified its customers of a security breach involving unauthorized access to their support system. This incident occurred when an external party obtained and misused Okta's support service account credentials. The investigation by…
LogBoost - A tool for parsing and enriching IP addresses in any type of log/file with GEO, DNS, OSINT IOCs and ASN context
https://ift.tt/nDXHSAh
Submitted January 20, 2024 at 08:30PM by panscanner
via reddit https://ift.tt/PYW9HO6
https://ift.tt/nDXHSAh
Submitted January 20, 2024 at 08:30PM by panscanner
via reddit https://ift.tt/PYW9HO6
GitHub
GitHub - joeavanzato/LogBoost: Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS…
Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indicator matches. - joeavanzato/LogBoost
Just released v10.1 of scanme a go package for scanning private and public IPs for open TCP ports 👁️ - it would be great to have some feedback from you pros, thanks in advance for any contribution!
https://ift.tt/lnGNPxS
Submitted January 21, 2024 at 08:32PM by Technical_Shelter621
via reddit https://ift.tt/68SEu9r
https://ift.tt/lnGNPxS
Submitted January 21, 2024 at 08:32PM by Technical_Shelter621
via reddit https://ift.tt/68SEu9r
GitHub
GitHub - CyberRoute/scanme: A Golang package for scanning private and public IPs for open TCP ports 👁️
A Golang package for scanning private and public IPs for open TCP ports 👁️ - CyberRoute/scanme
BusKill Warrant Canary #007 🕵️
https://ift.tt/naTNMp8
Submitted January 21, 2024 at 10:27PM by maltfield
via reddit https://ift.tt/HNKvnjg
https://ift.tt/naTNMp8
Submitted January 21, 2024 at 10:27PM by maltfield
via reddit https://ift.tt/HNKvnjg
BusKill
BusKill Canary #7 - BusKill
This post contains the cryptographically-signed BusKill warrant canary #007 for January 2023 to January 2024.
AsyncRAT: Config Decryption Techniques and Salt Analysis - Securityinbits
https://ift.tt/BcXSCwW
Submitted January 22, 2024 at 10:29AM by securityinbits
via reddit https://ift.tt/57CKUSH
https://ift.tt/BcXSCwW
Submitted January 22, 2024 at 10:29AM by securityinbits
via reddit https://ift.tt/57CKUSH
Securityinbits
AsyncRAT: Config Decryption Techniques and Salt Analysis - Securityinbits
Explore AsyncRAT inner workings. Learn unique decryption techniques to enhance your cybersecurity skills today!
Domain Escalation – Backup Operator
https://ift.tt/Mil2FZN
Submitted January 22, 2024 at 04:37PM by netbiosX
via reddit https://ift.tt/Gtv79cN
https://ift.tt/Mil2FZN
Submitted January 22, 2024 at 04:37PM by netbiosX
via reddit https://ift.tt/Gtv79cN
Penetration Testing Lab
Domain Escalation – Backup Operator
The Backup Operators is a Windows built-in group. Users which are part of this group have permissions to perform backup and restore operations. More specifically, these users have the SeBackupPrivi…
Vulnerability in Gambio pertains to an insecure deserialization flaw, which ultimately allows an attacker to execute remote code on affected systems.
https://ift.tt/sIBkJ9b
Submitted January 22, 2024 at 06:23PM by usdAG
via reddit https://ift.tt/yvXFKb5
https://ift.tt/sIBkJ9b
Submitted January 22, 2024 at 06:23PM by usdAG
via reddit https://ift.tt/yvXFKb5
usd HeroLab
usd-2023-0046 | usd HeroLab
Advisory ID: usd-2023-0046 | Product: Gambio | Vulnerability Type: Deserialization of Untrusted Data (CWE-502)
How a vulnerability in WifiKey's AC Gateway allows remote attackers to trigger a pre-auth RCE
https://ift.tt/g1HvRdw
Submitted January 22, 2024 at 10:24PM by SSDisclosure
via reddit https://ift.tt/zpn1P9E
https://ift.tt/g1HvRdw
Submitted January 22, 2024 at 10:24PM by SSDisclosure
via reddit https://ift.tt/zpn1P9E
SSD Secure Disclosure
SSD Advisory - WifiKey AC Gateway Pre-auth RCE - SSD Secure Disclosure
Summary A vulnerability exists in WifiKey’s AC Gateway allowing remote attackers to trigger a pre-auth RCE vulnerability in the product allowing complete compromise of the device. Credit An independent security researcher working with SSD Secure Disclosure.…
EC2 Privilege Escalation Through User Data
https://ift.tt/A6ohNxk
Submitted January 22, 2024 at 11:02PM by RedTermSession
via reddit https://ift.tt/akEXMWn
https://ift.tt/A6ohNxk
Submitted January 22, 2024 at 11:02PM by RedTermSession
via reddit https://ift.tt/akEXMWn
hackingthe.cloud
EC2 Privilege Escalation Through User Data - Hacking The Cloud
How to escalate privileges on an EC2 instance by abusing user data.
Many CVE Records Are Listing the Wrong Versions of Software as Being Affected
https://ift.tt/xXjyTpJ
Submitted January 23, 2024 at 12:26AM by PluginVulns
via reddit https://ift.tt/0iQJa4I
https://ift.tt/xXjyTpJ
Submitted January 23, 2024 at 12:26AM by PluginVulns
via reddit https://ift.tt/0iQJa4I
Plugin Vulnerabilities
Many CVE Records Are Listing the Wrong Versions of Software as Being Affected
[VNCERT/CC] CVE-2023-22527 realworld poc The original PoC: payload is length limited Solution: 1. Write the noscript file in parts 2. Run the noscript
https://ift.tt/rKI1UYN
Submitted January 23, 2024 at 01:01PM by arleth94
via reddit https://ift.tt/W2ULexi
https://ift.tt/rKI1UYN
Submitted January 23, 2024 at 01:01PM by arleth94
via reddit https://ift.tt/W2ULexi
GitHub
GitHub - VNCERT-CC/CVE-2023-22527-confluence: [Confluence] CVE-2023-22527 realworld poc
[Confluence] CVE-2023-22527 realworld poc. Contribute to VNCERT-CC/CVE-2023-22527-confluence development by creating an account on GitHub.
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing (CVE-2023-45866)
https://ift.tt/G2c5R1n
Submitted January 23, 2024 at 03:14PM by barakadua131
via reddit https://ift.tt/8mjWXuO
https://ift.tt/G2c5R1n
Submitted January 23, 2024 at 03:14PM by barakadua131
via reddit https://ift.tt/8mjWXuO
Mobile Hacker
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing - Mobile Hacker
[update 2024-02-19] This vulnerability can be even used to remotely wipe data of targeted Android smartphone. Using this vulnerability it is possible to guess user lock screen PIN. After five incorrect PINs device is locked out for 30 seconds. This operation…
Typhooncon 2024 has less than 2 weeks left for CFT submissions. Don't miss out!
https://ift.tt/0vFf7n5
Submitted January 23, 2024 at 04:04PM by Straight-Zombie-646
via reddit https://ift.tt/CoXhp6N
https://ift.tt/0vFf7n5
Submitted January 23, 2024 at 04:04PM by Straight-Zombie-646
via reddit https://ift.tt/CoXhp6N
Export Controls: Explained
https://ift.tt/9AXZWwf
Submitted January 23, 2024 at 05:05PM by zolakrystie
via reddit https://ift.tt/Py1bJWH
https://ift.tt/9AXZWwf
Submitted January 23, 2024 at 05:05PM by zolakrystie
via reddit https://ift.tt/Py1bJWH
NextLabs
What are Export Controls?
Export Controls are laws and regulations that govern the transfer or disclosure of goods, technology and funds originating in one country to persons or entities based or having citizenship in another country. This applies even if the regulated items are not…
A recent analysis of the Cactus Ransomware
https://ift.tt/Menxqzd
Submitted January 23, 2024 at 07:58PM by ShadowStackRE
via reddit https://ift.tt/YO5Ehpj
https://ift.tt/Menxqzd
Submitted January 23, 2024 at 07:58PM by ShadowStackRE
via reddit https://ift.tt/YO5Ehpj
ShadowStackRE
Cactus Ransomware malware analysis — ShadowStackRE
A technical analysis of the Cactus Ransomware malware
Windows - Data Protection API - A journey into various DPAPI potential abuses from an offensive security perspective
https://ift.tt/DWBMa1F
Submitted January 24, 2024 at 12:48AM by clod81
via reddit https://ift.tt/I9q81Kr
https://ift.tt/DWBMa1F
Submitted January 24, 2024 at 12:48AM by clod81
via reddit https://ift.tt/I9q81Kr
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
CVE-2024-0204: Fortra GoAnywhere MFT Authentication Bypass Deep-Dive, IOCs, and Exploit
https://ift.tt/aO0xWdR
Submitted January 24, 2024 at 02:22AM by scopedsecurity
via reddit https://ift.tt/PeRKiBf
https://ift.tt/aO0xWdR
Submitted January 24, 2024 at 02:22AM by scopedsecurity
via reddit https://ift.tt/PeRKiBf
Horizon3.ai
CVE-2024-0204: Fortra GoAnywhere MFT Authentication Bypass Deep-Dive – Horizon3.ai
CVE-2024-0204 Fortra GoAnywhere MFT Deep-Dive and Indicators of Compromise. This blog details the authentication bypass which allows an unauthenticated attacker to add an administrative user to the application.
Improving LLM Security Against Prompt Injection: AppSec Guidance For Pentesters and Developers
https://ift.tt/pZ36WGC
Submitted January 24, 2024 at 02:50AM by 907jessejones
via reddit https://ift.tt/4jVBqlv
https://ift.tt/pZ36WGC
Submitted January 24, 2024 at 02:50AM by 907jessejones
via reddit https://ift.tt/4jVBqlv
Include Security Research Blog
Improving LLM Security Against Prompt Injection: AppSec Guidance For Pentesters and Developers - Include Security Research Blog
Developers should be using OpenAI roles to mitigate LLM prompt injection, while pentesters are missing vulnerabilities in LLM design.
15 MCQ questions for practice related to security
https://ift.tt/HaZmbXs
Submitted January 24, 2024 at 11:59AM by eren_rndm
via reddit https://ift.tt/7EsJPMm
https://ift.tt/HaZmbXs
Submitted January 24, 2024 at 11:59AM by eren_rndm
via reddit https://ift.tt/7EsJPMm
practicepedia
15 MCQ questions for practice related to cybersecurity on practicepedia
15 cybersecurity MCQ questions to practice and improve your knowledge in cybersecurity with practicepedia. improve your knowledge
Kubernetes Scheduling And Secure Design
https://ift.tt/DQ120E7
Submitted January 24, 2024 at 02:22PM by nibblesec
via reddit https://ift.tt/SM7sjgy
https://ift.tt/DQ120E7
Submitted January 24, 2024 at 02:22PM by nibblesec
via reddit https://ift.tt/SM7sjgy
Methodology - Security Research: How we discovered over 18,000 API secret tokens & $20M in Stripe tokens
https://ift.tt/yqxwd3E
Submitted January 24, 2024 at 06:12PM by AlarmingApartment236
via reddit https://ift.tt/aVbYZ85
https://ift.tt/yqxwd3E
Submitted January 24, 2024 at 06:12PM by AlarmingApartment236
via reddit https://ift.tt/aVbYZ85
Escape - The API Security Blog
How we discovered over 18,000 API secret tokens
Our security team scanned 189.5M URLs and found more than 18,000 exposed API secrets. Explore the methodology.