A growing database of InfoSec salaries for 2024 (Open Data)
https://ift.tt/KW2bjRL
Submitted February 27, 2024 at 07:24PM by infosec-jobs
via reddit https://ift.tt/kyZbiGz
https://ift.tt/KW2bjRL
Submitted February 27, 2024 at 07:24PM by infosec-jobs
via reddit https://ift.tt/kyZbiGz
isecjobs.com
The Global InfoSec / Cybersecurity Salary Index for 2024
An open database of salaries in the InfoSec / Cybersecurity space.
Podcast: Lockbit the largest ransomware gang hacked
https://ift.tt/fio8tHr
Submitted February 27, 2024 at 08:05PM by ShadowStackRE
via reddit https://ift.tt/kWYZ3ts
https://ift.tt/fio8tHr
Submitted February 27, 2024 at 08:05PM by ShadowStackRE
via reddit https://ift.tt/kWYZ3ts
New Server Side Prototype Pollution Gadgets Scanner from Doyensec
https://ift.tt/pvWuh0l
Submitted February 27, 2024 at 09:23PM by ds_at
via reddit https://ift.tt/vEVOKZz
https://ift.tt/pvWuh0l
Submitted February 27, 2024 at 09:23PM by ds_at
via reddit https://ift.tt/vEVOKZz
Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor
https://ift.tt/rRGfoCm
Submitted February 27, 2024 at 09:32PM by SRMish3
via reddit https://ift.tt/XSjfTq2
https://ift.tt/rRGfoCm
Submitted February 27, 2024 at 09:32PM by SRMish3
via reddit https://ift.tt/XSjfTq2
JFrog
Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor
Is Hugging Face the target of model-based attacks? See a detailed explanation of the attack mechanism and what is required to identify real threats >
APT29 adopts new TTPs, according to a bunch of agencies
https://ift.tt/fiwomqN
Submitted February 28, 2024 at 04:10AM by Betterworldguys
via reddit https://ift.tt/YNgjTmV
https://ift.tt/fiwomqN
Submitted February 28, 2024 at 04:10AM by Betterworldguys
via reddit https://ift.tt/YNgjTmV
CyberTalk
NCSC warns of new TTPs employed by APT 29 - CyberTalk
A recent advisory from the U.K. National Cyber Security Centre (NCSC) and international partners details the recently developed tactics...
LOTP - Living Off the Pipeline
https://ift.tt/zo5f0MO
Submitted February 28, 2024 at 03:42AM by fproulx
via reddit https://ift.tt/B9l7aPd
https://ift.tt/zo5f0MO
Submitted February 28, 2024 at 03:42AM by fproulx
via reddit https://ift.tt/B9l7aPd
Hacking Terraform state to gain code execution and privilege escalation
https://ift.tt/NGiLAkV
Submitted February 28, 2024 at 10:04AM by dagrz-cloudsec
via reddit https://ift.tt/9YwfSa5
https://ift.tt/NGiLAkV
Submitted February 28, 2024 at 10:04AM by dagrz-cloudsec
via reddit https://ift.tt/9YwfSa5
Plerion
Hacking Terraform State for Privilege Escalation - Plerion
What can an attacker do if they can edit Terraform state? The answer should be 'nothing' but is actually 'take over your CI/CD pipeline'.
Revitalizing MouseJacking: Another Pen Test Story
https://ift.tt/7Lg2eOi
Submitted February 28, 2024 at 04:43PM by needmorejava
via reddit https://ift.tt/usHReWz
https://ift.tt/7Lg2eOi
Submitted February 28, 2024 at 04:43PM by needmorejava
via reddit https://ift.tt/usHReWz
Brackish Security
MouseJacking (With Flipper Zero): Tales from Pen Testing Trenches - Brackish Security
As a continuation in our series of penetration testing stories (who doesn’t love those) we bring you MouseJacking (With Flipper Zero). Check out the first blog post in the series here here. In this engagement, we were successfully able to compromise a network…
ThreatCheck alternative that can work with any antivirus, given a config file.
https://ift.tt/euX0MSL
Submitted February 28, 2024 at 05:00PM by Immediate-Fruit3833
via reddit https://ift.tt/ZFx4CAd
https://ift.tt/euX0MSL
Submitted February 28, 2024 at 05:00PM by Immediate-Fruit3833
via reddit https://ift.tt/ZFx4CAd
GitHub
GitHub - MultSec/MultCheck: Identifies bad bytes from static analysis with any Anti-Virus scanner.
Identifies bad bytes from static analysis with any Anti-Virus scanner. - MultSec/MultCheck
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day
https://ift.tt/EjQLse4
Submitted February 28, 2024 at 06:58PM by stashing_the_smack
via reddit https://ift.tt/qBKuYcw
https://ift.tt/EjQLse4
Submitted February 28, 2024 at 06:58PM by stashing_the_smack
via reddit https://ift.tt/qBKuYcw
Avast Threat Labs
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day - Avast Threat Labs
The Lazarus Group is back with an upgraded variant of their FudModule rootkit, this time enabled by a zero-day admin-to-kernel vulnerability for CVE-2024-21338. Read this blog for a detailed analysis of this rootkit variant and learn more about several new…
Comparison of Enterprise SAST/DAST Products
https://ift.tt/djeAqRJ
Submitted February 29, 2024 at 02:26AM by bcdefense
via reddit https://ift.tt/soULgMh
https://ift.tt/djeAqRJ
Submitted February 29, 2024 at 02:26AM by bcdefense
via reddit https://ift.tt/soULgMh
GitHub
GitHub - bcdannyboy/EnterpriseSASTDASTProductLandscape: Analysis of the Enterprise SAST/DAST product landscape
Analysis of the Enterprise SAST/DAST product landscape - bcdannyboy/EnterpriseSASTDASTProductLandscape
An EBPF based open source stateful linux firewall that integrates with OpenZiti Zero Trust Framework
https://ift.tt/oQ56bKn
Submitted February 29, 2024 at 04:50AM by e_secure5592
via reddit https://ift.tt/790BtLd
https://ift.tt/oQ56bKn
Submitted February 29, 2024 at 04:50AM by e_secure5592
via reddit https://ift.tt/790BtLd
GitHub
GitHub - netfoundry/zfw: An EBPF based IP4/IPv6 firewall with integrations for OpenZiti edge-routers and tunnellers
An EBPF based IP4/IPv6 firewall with integrations for OpenZiti edge-routers and tunnellers - netfoundry/zfw
Unauthenticated Email Enumeration via API Fuzzing
https://ift.tt/VMHFWK1
Submitted February 29, 2024 at 09:41AM by Zestyclose-Welder-33
via reddit https://ift.tt/TXuexDm
https://ift.tt/VMHFWK1
Submitted February 29, 2024 at 09:41AM by Zestyclose-Welder-33
via reddit https://ift.tt/TXuexDm
Jineesh AK
Unauthenticated Email Enumeration via API Fuzzing
Introduction
Exploiting CSP Wildcards for Google Domains
https://ift.tt/GjlfI6o
Submitted February 29, 2024 at 05:07PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/4UyHrKJ
https://ift.tt/GjlfI6o
Submitted February 29, 2024 at 05:07PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/4UyHrKJ
attackshipsonfi.re
Exploiting CSP Wildcards for Google Domains
TL;DR The Google developer documentation includes CSP examples which use domain wildcards (which have been widely cut & pasted), and additionally there are numerous endpoints within the Google eTLDs which are vulnerable to Javanoscript XSS.
Glitching in 3D: Low Cost EMFI Attacks
https://ift.tt/Bjt3pYo
Submitted February 29, 2024 at 08:16PM by wrongbaud
via reddit https://ift.tt/LK6b0Fq
https://ift.tt/Bjt3pYo
Submitted February 29, 2024 at 08:16PM by wrongbaud
via reddit https://ift.tt/LK6b0Fq
SubdoMailing Checker: Type in a domain to see if it’s been compromised by “SubdoMailers”
https://ift.tt/HQinR3b
Submitted March 01, 2024 at 12:18AM by pinpepnet
via reddit https://ift.tt/8YS257p
https://ift.tt/HQinR3b
Submitted March 01, 2024 at 12:18AM by pinpepnet
via reddit https://ift.tt/8YS257p
Guardio
SubdoMailing Checker Tool | Guardio
Use Guardio's checker tool to find out if your domain has been compromised by SubdoMailers
Celebrating Falco's Journey to CNCF Graduation
https://ift.tt/ZuPFTzp
Submitted March 01, 2024 at 03:38AM by Hallow_Rose
via reddit https://ift.tt/CrnGzMO
https://ift.tt/ZuPFTzp
Submitted March 01, 2024 at 03:38AM by Hallow_Rose
via reddit https://ift.tt/CrnGzMO
Sysdig
Falco's Journey to CNCF graduation
In February 2024, Falco graduated within the Cloud Native Computing Foundation (CNCF). Graduation marks an important milestone for a journey...
Exploiting Stack Based Buffer Overflow
https://ift.tt/IJ0Rsb2
Submitted March 01, 2024 at 12:26PM by Accomplished-Mud1210
via reddit https://ift.tt/lZ1O2H7
https://ift.tt/IJ0Rsb2
Submitted March 01, 2024 at 12:26PM by Accomplished-Mud1210
via reddit https://ift.tt/lZ1O2H7
RingBuffer's Blog
Buffer Overflow : Exploiting Easy RM to MP3 Converter
Buffer Overflow Demonstration on Exploiting Easy RM to MP3 Converter
LogSnare: A web application playground for testing, preventing, and logging IDOR vulnerabilities.
https://ift.tt/g23Tvpr
Submitted March 01, 2024 at 06:50PM by Seaerkin2
via reddit https://ift.tt/95duxiZ
https://ift.tt/g23Tvpr
Submitted March 01, 2024 at 06:50PM by Seaerkin2
via reddit https://ift.tt/95duxiZ
GitHub
GitHub - sea-erkin/log-snare: LogSnare: A playground for testing, preventing, and logging IDOR vulnerabilities.
LogSnare: A playground for testing, preventing, and logging IDOR vulnerabilities. - sea-erkin/log-snare
Google VRP: CSP bypass to email exfiltration via Bard
https://ift.tt/VL61KeD
Submitted March 01, 2024 at 08:25PM by poltess0
via reddit https://ift.tt/wfP19FY
https://ift.tt/VL61KeD
Submitted March 01, 2024 at 08:25PM by poltess0
via reddit https://ift.tt/wfP19FY
www.landh.tech
We Hacked Google A.I. for $50,000 - Lupin & Holmes
Phrack #71: Call For Paper
http://www.phrack.org
Submitted March 02, 2024 at 03:05PM by loselasso
via reddit https://ift.tt/qdLKfQp
http://www.phrack.org
Submitted March 02, 2024 at 03:05PM by loselasso
via reddit https://ift.tt/qdLKfQp
Phrack
Introduction
Click to read the article on phrack