Kubernetes Scheduling And Secure Design
https://ift.tt/DQ120E7
Submitted January 24, 2024 at 02:22PM by nibblesec
via reddit https://ift.tt/SM7sjgy
https://ift.tt/DQ120E7
Submitted January 24, 2024 at 02:22PM by nibblesec
via reddit https://ift.tt/SM7sjgy
Methodology - Security Research: How we discovered over 18,000 API secret tokens & $20M in Stripe tokens
https://ift.tt/yqxwd3E
Submitted January 24, 2024 at 06:12PM by AlarmingApartment236
via reddit https://ift.tt/aVbYZ85
https://ift.tt/yqxwd3E
Submitted January 24, 2024 at 06:12PM by AlarmingApartment236
via reddit https://ift.tt/aVbYZ85
Escape - The API Security Blog
How we discovered over 18,000 API secret tokens
Our security team scanned 189.5M URLs and found more than 18,000 exposed API secrets. Explore the methodology.
Pwning a DLP solution: CVE-2024-22107 & CVE-2024-22108
https://ift.tt/VcS73Jn
Submitted January 25, 2024 at 01:46PM by gid0rah
via reddit https://ift.tt/6UkRruB
https://ift.tt/VcS73Jn
Submitted January 25, 2024 at 01:46PM by gid0rah
via reddit https://ift.tt/6UkRruB
A christmas tale: pwning GTB Central Console (CVE-2024-22107 & CVE-2024-22108) |
A christmas tale: pwning GTB Central Console (CVE-2024-22107 & CVE-2024-22108) | AdeptsOf0xCC
Yet another security platform being pwned by trivial vulnerabilities (CVE-2024-22107 & CVE-2024-22108)
*nix libX11: Uncovering and exploiting a 35-year-old vulnerability – Part 2 of 2
https://ift.tt/dx51IR0
Submitted January 25, 2024 at 02:57PM by SRMish3
via reddit https://ift.tt/9SC82VM
https://ift.tt/dx51IR0
Submitted January 25, 2024 at 02:57PM by SRMish3
via reddit https://ift.tt/9SC82VM
JFrog
CVE-2023-43786 & CVE-2023-43787 Vulns in libX11: All You Need To Know
Learn all about the 35-year-old vulnerabilities found by our Security Team in libX11, causing a denial-of-service and remote code execution.
Shipping your Private Key - CVE-2023-43870, Paxton do a Lenovo.
https://ift.tt/JyMZdmB
Submitted January 25, 2024 at 05:14PM by craigsblackie
via reddit https://ift.tt/PBveISc
https://ift.tt/JyMZdmB
Submitted January 25, 2024 at 05:14PM by craigsblackie
via reddit https://ift.tt/PBveISc
Cryptic Red Ltd
Shipping your Private Key - CVE-2023-43870, Paxton do a Lenovo
Paxton Access is a UK-based company specialising in access control solutions. Their products cater to a wide range of security needs in various sectors, including commercial, educational, and healthcare facilities.One of the key products from Paxton Access…
New Zyxel RCE Vulnerability allows remote attackes execute commands as root!
https://ift.tt/3CTYdEj
Submitted January 25, 2024 at 07:18PM by Straight-Zombie-646
via reddit https://ift.tt/KvMgwVf
https://ift.tt/3CTYdEj
Submitted January 25, 2024 at 07:18PM by Straight-Zombie-646
via reddit https://ift.tt/KvMgwVf
SSD Secure Disclosure
SSD Advisory - Zyxel VPN Series Pre-auth Remote Command Execution - SSD Secure Disclosure
Summary Chaining of three vulnerabilities allows unauthenticated attackers to execute arbitrary command with root privileges on Zyxel VPN firewall (VPN50, VPN100, VPN300, VPN500, VPN1000). Due to recent attack surface changes in Zyxel, the chain described…
We build X.509 chains so you don’t have to
https://ift.tt/yQi7eGz
Submitted January 25, 2024 at 09:30PM by yossarian_flew_away
via reddit https://ift.tt/4VHCymJ
https://ift.tt/yQi7eGz
Submitted January 25, 2024 at 09:30PM by yossarian_flew_away
via reddit https://ift.tt/4VHCymJ
The Trail of Bits Blog
We build X.509 chains so you don’t have to
For the past eight months, Trail of Bits has worked with the Python Cryptographic Authority to build cryptography-x509-verification, a brand-new, pure-Rust implementation of the X.509 path validation algorithm that TLS and other encryption and authentication…
AI-exploits: Triton Inference Server RCE exploit
https://ift.tt/kPLlpoJ
Submitted January 25, 2024 at 11:30PM by FlyingTriangle
via reddit https://ift.tt/PEqzop2
https://ift.tt/kPLlpoJ
Submitted January 25, 2024 at 11:30PM by FlyingTriangle
via reddit https://ift.tt/PEqzop2
Protectai
Triton Inference Server - Arbitrary File Overwrite
On September 20th, 2023 a member of the huntr community reported an issue in Triton where a file traversal vulnerability lead to the ability to overwrite any file on the server when Triton is run using a non-default configuration option.
CVE-2024-23897 Jenkins CLI PoC
https://ift.tt/Jm5ALeX
Submitted January 26, 2024 at 04:06PM by gquere
via reddit https://ift.tt/K5H3JQ1
https://ift.tt/Jm5ALeX
Submitted January 26, 2024 at 04:06PM by gquere
via reddit https://ift.tt/K5H3JQ1
GitHub
pwn_jenkins/README.md at master · gquere/pwn_jenkins
Notes about attacking Jenkins servers. Contribute to gquere/pwn_jenkins development by creating an account on GitHub.
AsyncRAT config decryption using CyberChef - Recipe 0x2 - Securityinbits
https://ift.tt/xEbuc0A
Submitted January 26, 2024 at 05:36PM by securityinbits
via reddit https://ift.tt/1JR6PTm
https://ift.tt/xEbuc0A
Submitted January 26, 2024 at 05:36PM by securityinbits
via reddit https://ift.tt/1JR6PTm
Securityinbits
AsyncRAT config decryption using CyberChef - Recipe 0x2 - Securityinbits
Decrypt AsyncRAT configurations effortlessly using CyberChef with our step-by-step guide. Dive into the recipe and enhance your malware analysis skills.
How I hacked chess.com
https://ift.tt/omSU1pV
Submitted January 26, 2024 at 09:47PM by J_ake20o4
via reddit https://ift.tt/K0BeNDi
https://ift.tt/omSU1pV
Submitted January 26, 2024 at 09:47PM by J_ake20o4
via reddit https://ift.tt/K0BeNDi
Skii.dev
Rook to XSS: How I hacked chess.com with a rookie exploit
Playing Chess is one of the many hobbies I like to do in my spare time, apart from tinkering around with technology. However, I'm not very good at it, and after losing many games, I decided to see if I could do something I'm much better at; hacking the system!
Building a password cracker in 2024 [Deep Dive]
https://ift.tt/gf8Hb0E
Submitted January 27, 2024 at 06:28AM by hpo1n7
via reddit https://ift.tt/mt7bFoC
https://ift.tt/gf8Hb0E
Submitted January 27, 2024 at 06:28AM by hpo1n7
via reddit https://ift.tt/mt7bFoC
SEVN-X | Cybersecurity
How to Build a Password Cracker
A step by step blog on how to build a password cracker for professional cracking.
CSIRT-CTI - Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks
https://ift.tt/AkaL2UH
Submitted January 27, 2024 at 09:47PM by 0x5h4un
via reddit https://ift.tt/BtPcKfZ
https://ift.tt/AkaL2UH
Submitted January 27, 2024 at 09:47PM by 0x5h4un
via reddit https://ift.tt/BtPcKfZ
NMAP-formatter: convert NMAP results to HTML, CSV, JSON, graphviz (dot), SQLite
https://ift.tt/53FSbdc
Submitted January 28, 2024 at 12:22AM by netsec_burn
via reddit https://ift.tt/tTSIKzW
https://ift.tt/53FSbdc
Submitted January 28, 2024 at 12:22AM by netsec_burn
via reddit https://ift.tt/tTSIKzW
GitHub
GitHub - vdjagilev/nmap-formatter: A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot)…
A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot) or sqlite. Simply put it's nmap converter. - GitHub - vdjagilev/nmap-formatter: A tool that allow...
ExecIT: Evasive DLL-Based Shellcode Loader
https://ift.tt/Glg63La
Submitted January 28, 2024 at 04:05PM by florilsk
via reddit https://ift.tt/q5BChJP
https://ift.tt/Glg63La
Submitted January 28, 2024 at 04:05PM by florilsk
via reddit https://ift.tt/q5BChJP
GitHub
GitHub - florylsk/ExecIT: Execute shellcode files with rundll32
Execute shellcode files with rundll32. Contribute to florylsk/ExecIT development by creating an account on GitHub.
TyphoonCon 2024 early bird ticket are now on sale!
https://ift.tt/dxBhPtT
Submitted January 28, 2024 at 09:50PM by Straight-Zombie-646
via reddit https://ift.tt/Vwcmti3
https://ift.tt/dxBhPtT
Submitted January 28, 2024 at 09:50PM by Straight-Zombie-646
via reddit https://ift.tt/Vwcmti3
Eventbrite
TyphoonCon 2024
TyphoonCon conference and training focus on highly technical offensive security topics.
The event is organized by SSD Secure Disclosure.
The event is organized by SSD Secure Disclosure.
“Scammers Paradise” —Exploring Telegram’s Dark Markets, Breeding Ground for Modern Phishing Operations
https://ift.tt/KT9tgIU
Submitted January 29, 2024 at 08:33PM by figgymmr
via reddit https://ift.tt/hBtPGKi
https://ift.tt/KT9tgIU
Submitted January 29, 2024 at 08:33PM by figgymmr
via reddit https://ift.tt/hBtPGKi
Medium
“Scammers Paradise” —Exploring Telegram’s Dark Markets, Breeding Ground for Modern Phishing Operations
By Oleg Zaytsev, Nati Tal (Guardio Labs)
Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours
https://ift.tt/exZjTpY
Submitted January 29, 2024 at 07:58PM by TheDFIRReport
via reddit https://ift.tt/JpKmkaw
https://ift.tt/exZjTpY
Submitted January 29, 2024 at 07:58PM by TheDFIRReport
via reddit https://ift.tt/JpKmkaw
The DFIR Report
Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours
Key Takeaways In late December 2022, we observed threat actors exploiting a publicly exposed Remote Desktop Protocol (RDP) host, leading to data exfiltration and the deployment of Trigona ransomwar…
Sys:All: How A Simple Loophole in Google Kubernetes Engine Puts Clusters at Risk of Compromise
https://ift.tt/4QOJZSp
Submitted January 29, 2024 at 09:16PM by shulginlegacy
via reddit https://ift.tt/tkajWfC
https://ift.tt/4QOJZSp
Submitted January 29, 2024 at 09:16PM by shulginlegacy
via reddit https://ift.tt/tkajWfC
Orca Security
Sys:All: How A Simple Loophole in Google Kubernetes Engine Puts Clusters at Risk of Compromise
The Orca Research Pod has discovered a risk in Google Kubernetes Engine (GKE) that would allow an attacker with any Google account to take over a Kubernetes cluster. Learn about this risk dubbed Sys:All and the recommended actions to take.
Your Firewalls and Proxies are about to be blind to real TLS destinations: Learn about Encrypted Client Hello
https://ift.tt/Jmo7HGn
Submitted January 30, 2024 at 12:14AM by Shu_asha
via reddit https://ift.tt/EcGIPw4
https://ift.tt/Jmo7HGn
Submitted January 30, 2024 at 12:14AM by Shu_asha
via reddit https://ift.tt/EcGIPw4
Most leaked keys aren't revoked, learn about API key rotation
https://ift.tt/aJ4EUTB
Submitted January 30, 2024 at 12:08AM by Phorcez
via reddit https://ift.tt/PAtB5vw
https://ift.tt/aJ4EUTB
Submitted January 30, 2024 at 12:08AM by Phorcez
via reddit https://ift.tt/PAtB5vw
Trufflesecurity
How to Remediate Leaked Secrets ◆ Truffle Security Co.
This webinar will focus on strategies for remediating leaked keys, managing key rotation, and handling platform-specific processes for the leading SaaS providers.