Detection Rules Development Framework
https://ift.tt/ExwslWR
Submitted February 21, 2024 at 03:06PM by netbiosX
via reddit https://ift.tt/YCPMhkc
https://ift.tt/ExwslWR
Submitted February 21, 2024 at 03:06PM by netbiosX
via reddit https://ift.tt/YCPMhkc
Purple Team
Detection Rules Development Framework
Organizations who invest in detection engineering have an edge towards identification of threats. However, there is no industry standard to define the framework around the development of detection …
A deep dive into the RansomHouse encryptor
https://ift.tt/qxvMESi
Submitted February 21, 2024 at 08:04PM by ShadowStackRE
via reddit https://ift.tt/ReaVWhK
https://ift.tt/qxvMESi
Submitted February 21, 2024 at 08:04PM by ShadowStackRE
via reddit https://ift.tt/ReaVWhK
ShadowStackRE
RansomHouse encryptor malware analysis — ShadowStackRE
RansomHouse technical malware analysis and yara rules
Ongoing Malware Laced Developer Job Interviews
https://ift.tt/ykaOmZK
Submitted February 21, 2024 at 09:13PM by louis11
via reddit https://ift.tt/PRuQhqt
https://ift.tt/ykaOmZK
Submitted February 21, 2024 at 09:13PM by louis11
via reddit https://ift.tt/PRuQhqt
Phylum
Fake Developer Jobs Laced With Malware
Phylum continues to discover malware polluting open-source ecosystems. In this blog post, we take a deep-dive into an npm package trying to masquerade as code profiler which actually installs several malicious noscripts including a cryptocurrency and credential…
re: Zyxel VPN Series Pre-auth Remote Command Execution
https://ift.tt/1zcqnPB
Submitted February 21, 2024 at 09:53PM by chicksdigthelongrun
via reddit https://ift.tt/xBWFCgl
https://ift.tt/1zcqnPB
Submitted February 21, 2024 at 09:53PM by chicksdigthelongrun
via reddit https://ift.tt/xBWFCgl
VulnCheck
re: Zyxel VPN Series Pre-auth Remote Command Execution - Blog - VulnCheck
VulnCheck uncovers the truth behind the recently published Zyxel pre-auth remote code execution: limited to specific configurations, limitations on repeated exploitation, and no evidence of active exploitation.
Statically detecting AWS Canary Tokens without setting them off
https://ift.tt/6e2UHBu
Submitted February 21, 2024 at 11:40PM by wifihack
via reddit https://ift.tt/W739LUc
https://ift.tt/6e2UHBu
Submitted February 21, 2024 at 11:40PM by wifihack
via reddit https://ift.tt/W739LUc
Trufflesecurity
TruffleHog Now Detects AWS Canaries without setting them off ◆ Truffle Security Co.
Today we’re unveiling a novel way to identify canarytokens.org canaries completely statically without setting them off. Thinkst offers self hosted, and paid alternatives that are protected from these techniques. We’re open sourcing this capability and including…
Optum / Change Healthcare Breach
https://ift.tt/5BWxpPu
Submitted February 22, 2024 at 04:00AM by ssgzeke
via reddit https://ift.tt/iRfNrVF
https://ift.tt/5BWxpPu
Submitted February 22, 2024 at 04:00AM by ssgzeke
via reddit https://ift.tt/iRfNrVF
Changehealthcare
Update: Some applications are experiencing connectivity issues. Hover or tap here for updates.
Optum Solutions's Status Page - Update: Some applications are experiencing connectivity issues. Hover or tap here for updates..
Auth Bypass in ConnectWise ScreenConnect
https://ift.tt/fcjHCU0
Submitted February 22, 2024 at 01:50PM by smokiesmk
via reddit https://ift.tt/YBD65SJ
https://ift.tt/fcjHCU0
Submitted February 22, 2024 at 01:50PM by smokiesmk
via reddit https://ift.tt/YBD65SJ
GitHub
GitHub - jhonnybonny/auth_bypass_connectwise_screenconnect: Exploit ConnectWise ScreenConnect (bypass authentication)
Exploit ConnectWise ScreenConnect (bypass authentication) - jhonnybonny/auth_bypass_connectwise_screenconnect
A stealthy threat uncovered: TeaBot on Google Play Store | Cleafy Labs
https://ift.tt/78Kf0Tj
Submitted February 22, 2024 at 02:39PM by f3d_0x0
via reddit https://ift.tt/aAovPSq
https://ift.tt/78Kf0Tj
Submitted February 22, 2024 at 02:39PM by f3d_0x0
via reddit https://ift.tt/aAovPSq
Cleafy
A stealthy threat uncovered: TeaBot on Google Play Store | Cleafy Labs
Recently, we have observed an increase in TeaBot banking trojan infections across several European countries, now even infiltrating the Google Play Store. Read the technical analysis to know all his functionalities and how to prevent it.
“To live is to fight, to fight is to live! - IBM ODM Remote Code Execution (watchTowr Labs)
https://ift.tt/vQgue6x
Submitted February 22, 2024 at 02:32PM by dx7r__
via reddit https://ift.tt/BLTuPDe
https://ift.tt/vQgue6x
Submitted February 22, 2024 at 02:32PM by dx7r__
via reddit https://ift.tt/BLTuPDe
watchTowr Labs - Blog
“To live is to fight, to fight is to live! - IBM ODM Remote Code Execution
In previous blogs, we’ve discussed some of the big players in the enterprise software space, but there is one that we have not mentioned before, that is - quite frankly - the heavy-weight champion of the world in terms of applications for large enterprises.…
SHA-256 Under the Hood
https://ift.tt/Nyzdsok
Submitted February 22, 2024 at 02:53PM by pickeydotai
via reddit https://ift.tt/kxTPgZw
https://ift.tt/Nyzdsok
Submitted February 22, 2024 at 02:53PM by pickeydotai
via reddit https://ift.tt/kxTPgZw
Medium
SHA-256 Under the Hood
Look inside the popular hash function and learn what makes it work so well.
New TP-Link authentication Bypass!
https://ift.tt/jivZgCR
Submitted February 22, 2024 at 08:20PM by Status_Resolve2971
via reddit https://ift.tt/Jp3c5z7
https://ift.tt/jivZgCR
Submitted February 22, 2024 at 08:20PM by Status_Resolve2971
via reddit https://ift.tt/Jp3c5z7
Go-EPSS: Golang library for interacting with EPSS (Exploit Prediction Scoring System)
https://ift.tt/5T7t8LW
Submitted February 23, 2024 at 04:38AM by KaanSK
via reddit https://ift.tt/ja0pP1E
https://ift.tt/5T7t8LW
Submitted February 23, 2024 at 04:38AM by KaanSK
via reddit https://ift.tt/ja0pP1E
GitHub
GitHub - KaanSK/go-epss: A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).
A Golang library for interacting with the EPSS (Exploit Prediction Scoring System). - KaanSK/go-epss
Python Risk Identification Tool for generative AI (PyRIT)
https://ift.tt/jxdMCXu
Submitted February 23, 2024 at 08:10AM by ___printf_chk
via reddit https://ift.tt/MoAeaSf
https://ift.tt/jxdMCXu
Submitted February 23, 2024 at 08:10AM by ___printf_chk
via reddit https://ift.tt/MoAeaSf
GitHub
GitHub - Azure/PyRIT: The Python Risk Identification Tool for generative AI (PyRIT) is an open access automation framework to empower…
The Python Risk Identification Tool for generative AI (PyRIT) is an open access automation framework to empower security professionals and machine learning engineers to proactively find risks in th...
Code injection or backdoor: A new look at Ivanti's CVE-2021-44529
https://ift.tt/d1nV3pc
Submitted February 23, 2024 at 05:23PM by albinowax
via reddit https://ift.tt/6FJgDeU
https://ift.tt/d1nV3pc
Submitted February 23, 2024 at 05:23PM by albinowax
via reddit https://ift.tt/6FJgDeU
GreyNoise Labs
GreyNoise Labs - Code injection or backdoor: A new look at Ivanti’s CVE-2021-44529
In 2021, Ivanti patched a vulnerability that they called “code injection”. Rumors say it was a backdoor in an open source project. Let’s find out what actually happened!
Continuously fuzzing Python C extensions
https://ift.tt/8tLxw6P
Submitted February 23, 2024 at 09:07PM by Schwag
via reddit https://ift.tt/EfMtIxO
https://ift.tt/8tLxw6P
Submitted February 23, 2024 at 09:07PM by Schwag
via reddit https://ift.tt/EfMtIxO
Trail of Bits Blog
Continuously fuzzing Python C extensions
By Matt Schwager Deserializing, decoding, and processing untrusted input are telltale signs that your project would benefit from fuzzing. Yes, even Python projects. Fuzzing helps reduce bugs in hig…
Wannabe Security Researcher!?!? Is the noscript of my very first blog post of my very first blog, I hope it to be informative for who is interested in Security and more specifically about an home assignment I received for a position of Sr. Security Researcher and how I approached it.
https://ift.tt/DnusIAl
Submitted February 24, 2024 at 03:59AM by Technical_Shelter621
via reddit https://ift.tt/iLIGU9a
https://ift.tt/DnusIAl
Submitted February 24, 2024 at 03:59AM by Technical_Shelter621
via reddit https://ift.tt/iLIGU9a
Blog
Wannabe Security Researcher!?!?
This is the very first article that I am publishing on this blog, I wanted to share this experience with folks that are passionate like myself about Security at 360 degrees and also share my thought …
Go Go XSS Gadgets: Chaining a DOM Clobbering Exploit in the Wild
https://ift.tt/70N1BCL
Submitted February 24, 2024 at 10:35PM by poltess0
via reddit https://ift.tt/F6IPT8o
https://ift.tt/70N1BCL
Submitted February 24, 2024 at 10:35PM by poltess0
via reddit https://ift.tt/F6IPT8o
VNC through ssh tunnel
http://localhost
Submitted February 25, 2024 at 08:45PM by Good_Till_970
via reddit https://ift.tt/q6TgsA1
http://localhost
Submitted February 25, 2024 at 08:45PM by Good_Till_970
via reddit https://ift.tt/q6TgsA1
Reddit
From the netsec community on Reddit: VNC through ssh tunnel
Posted by Good_Till_970 - 2 votes and 12 comments
SEO Poisoning to Domain Control: The Gootloader Saga Continues
https://ift.tt/FPHo0ig
Submitted February 26, 2024 at 06:46AM by TheDFIRReport
via reddit https://ift.tt/tiy0LDR
https://ift.tt/FPHo0ig
Submitted February 26, 2024 at 06:46AM by TheDFIRReport
via reddit https://ift.tt/tiy0LDR
The DFIR Report
SEO Poisoning to Domain Control: The Gootloader Saga Continues
Key Takeaways In February 2023, we detected an intrusion that was initiated by a user downloading and executing a file from a SEO-poisoned search result, leading to a Gootloader infection. Around n…
Exploiting inconsistent UTF-8 handling in mbstring to bypass an XSS filter in Joomla
https://ift.tt/RHNSWtL
Submitted February 26, 2024 at 02:15PM by albinowax
via reddit https://ift.tt/ZNgEleS
https://ift.tt/RHNSWtL
Submitted February 26, 2024 at 02:15PM by albinowax
via reddit https://ift.tt/ZNgEleS
Sonarsource
Joomla: PHP Bug Introduces Multiple XSS Vulnerabilities
Our Clean Code solution, SonarCloud, led us to a severe security issue in the popular Content Management System Joomla.
Join us in Seoul this May. Last chance to submit you talk for TyphoonCon 2024!
https://ift.tt/KzScmyb
Submitted February 26, 2024 at 01:56PM by LongjumpingLime4139
via reddit https://ift.tt/Dx64hM3
https://ift.tt/KzScmyb
Submitted February 26, 2024 at 01:56PM by LongjumpingLime4139
via reddit https://ift.tt/Dx64hM3