CVE-2024–23897 – Arbitrary file read in Jenkins
https://ift.tt/euIJ8Tj
Submitted March 11, 2024 at 04:35PM by SL7reach
via reddit https://ift.tt/VlaQT5z
https://ift.tt/euIJ8Tj
Submitted March 11, 2024 at 04:35PM by SL7reach
via reddit https://ift.tt/VlaQT5z
Penetration Testing and CyberSecurity Solution - SecureLayer7
CVE-2024–23897 – Arbitrary file read in Jenkins
Overview CVE-2024–23897 is a critical vulnerability discovered in Jenkins, with a high CVSS score of 9.8. This vulnerability allows the attacker to read files in the system through the integrated...
CVE-2023-49785 SSRF in NextChat: An AI Chatbot That Lets You Talk to Anyone You Want To
https://ift.tt/fne2riv
Submitted March 11, 2024 at 07:23PM by scopedsecurity
via reddit https://ift.tt/z5hI3gD
https://ift.tt/fne2riv
Submitted March 11, 2024 at 07:23PM by scopedsecurity
via reddit https://ift.tt/z5hI3gD
Horizon3.ai
NextChat: An AI Chatbot That Lets You Talk to Anyone You Want To – Horizon3.ai
NextChat a.k.a ChatGPT-Next-Web, a popular Gen AI ChatBot, is vulnerable to a critical server-side request forgery (SSRF) vulnerability.
Introduction to LLM Security
https://ift.tt/OVyD0hz
Submitted March 11, 2024 at 08:05PM by nilla615615
via reddit https://ift.tt/0mQ8o6M
https://ift.tt/OVyD0hz
Submitted March 11, 2024 at 08:05PM by nilla615615
via reddit https://ift.tt/0mQ8o6M
Cloudsecuritypartners
Introduction to LLM Security
Read about Introduction to LLM Security
CVE-2024-28084 iwd double-free in beacon parsing
https://ift.tt/0H384GQ
Submitted March 11, 2024 at 09:16PM by supernetworks
via reddit https://ift.tt/XhVS5OB
https://ift.tt/0H384GQ
Submitted March 11, 2024 at 09:16PM by supernetworks
via reddit https://ift.tt/XhVS5OB
www.supernetworks.org
Beacon Double Free in IWD | SPR
CVE-2024-28084 Patched in Inet Wireless Daemon 2.16
ShellFeck: A BrainF*ck Inspired Shell Obfuscation Proof-of-Concept
https://ift.tt/Ic8FuAX
Submitted March 11, 2024 at 08:48PM by Aaron_Dj0nt
via reddit https://ift.tt/DKWTSyn
https://ift.tt/Ic8FuAX
Submitted March 11, 2024 at 08:48PM by Aaron_Dj0nt
via reddit https://ift.tt/DKWTSyn
GitHub
GitHub - CyberSecurityN00b/shellfeck: A BrainF*ck Inspired Shell Obfuscation Proof-of-Concept
A BrainF*ck Inspired Shell Obfuscation Proof-of-Concept - CyberSecurityN00b/shellfeck
Practical and Theoretical Attacks in the Industrial Landscape (Part 2)
https://ift.tt/N7ERgVO
Submitted March 12, 2024 at 01:29AM by sh0n1z
via reddit https://ift.tt/dt3Mv7l
https://ift.tt/N7ERgVO
Submitted March 12, 2024 at 01:29AM by sh0n1z
via reddit https://ift.tt/dt3Mv7l
Claroty
Practical and Theoretical Attacks in the Industrial Landscape (Part 2)
In part two of this Team82 series, we examine practical and theoretical attacks against operational technology (OT) through the use of a virtual factory environment. The attacks range in sophistication and present defenders with an opportunity to threat model…
Presenting Scanme: Deep Dive into Network Scanning with Golang: Building a Port Scanner
https://ift.tt/hMj24IS
Submitted March 12, 2024 at 01:19AM by Technical_Shelter621
via reddit https://ift.tt/x2btmqp
https://ift.tt/hMj24IS
Submitted March 12, 2024 at 01:19AM by Technical_Shelter621
via reddit https://ift.tt/x2btmqp
Blog
Presenting Scanme: Deep Dive into Network Scanning with Golang: …
Introduction: In today’s interconnected world, understanding network security is essential. One essential tool in a security professional’s arsenal is a port scanner. You probably thinking …
K8s LAN Party - A Kubernetes Network Security CTF
https://k8slanparty.com
Submitted March 12, 2024 at 02:42AM by geekydeveloper
via reddit https://ift.tt/Wvey3mz
https://k8slanparty.com
Submitted March 12, 2024 at 02:42AM by geekydeveloper
via reddit https://ift.tt/Wvey3mz
K8Slanparty
K8s LAN Party
Kubernetes LAN Party - by Wiz
How we built an AI-Powered Multi Terrain Hacking Robot
https://ift.tt/svflazq
Submitted March 12, 2024 at 07:18AM by berylliumsec
via reddit https://ift.tt/tvdmJr4
https://ift.tt/svflazq
Submitted March 12, 2024 at 07:18AM by berylliumsec
via reddit https://ift.tt/tvdmJr4
Beryllium
How We Built an AI-powered Multi-terrain Hacking Robot — Beryllium
Meet Asteroid - an AI-powered, multi-terrain hacking robot designed to conduct cybersecurity missions in challenging environments where human involvement is either unfeasible or hazardous.
AI Powered Sensitive Information Detection
https://ift.tt/CK8p6NA
Submitted March 12, 2024 at 04:21PM by Civil_Alternative410
via reddit https://ift.tt/gsOym9K
https://ift.tt/CK8p6NA
Submitted March 12, 2024 at 04:21PM by Civil_Alternative410
via reddit https://ift.tt/gsOym9K
GitHub
GitHub - berylliumsec/eclipse: AI Powered Sensitive Information Detection
AI Powered Sensitive Information Detection. Contribute to berylliumsec/eclipse development by creating an account on GitHub.
Malware Pulse - Proactive command and control server discovery hub
https://malpulse.com/
Submitted March 12, 2024 at 06:17PM by mamudogurban
via reddit https://ift.tt/3lxHVrj
https://malpulse.com/
Submitted March 12, 2024 at 06:17PM by mamudogurban
via reddit https://ift.tt/3lxHVrj
Patch Tuesday Diffing: CVE-2024–20696 — Windows Libarchive RCE
https://ift.tt/YZWSClf
Submitted March 12, 2024 at 07:44PM by onlinereadme
via reddit https://ift.tt/NJb0URS
https://ift.tt/YZWSClf
Submitted March 12, 2024 at 07:44PM by onlinereadme
via reddit https://ift.tt/NJb0URS
Medium
Patch Tuesday Diffing: CVE-2024–20696 — Windows Libarchive RCE
TL;DR This post will teach you how to patch diff CVE-2024–20696 (and indirectly CVE-2024–20697) from the January 2024 Patch Tuesday.
Introducing WebTunnel | Tor Project
https://ift.tt/VjY8vLK
Submitted March 12, 2024 at 09:48PM by n3w57ake
via reddit https://ift.tt/Mc5WbSG
https://ift.tt/VjY8vLK
Submitted March 12, 2024 at 09:48PM by n3w57ake
via reddit https://ift.tt/Mc5WbSG
blog.torproject.org
Hiding in plain sight: Introducing WebTunnel | Tor Project
We're celebrating the World Day Against Cyber Censorship by officially announcing WebTunnel, a new type of Tor bridge designed to assist users in heavily censored regions to connect to the Tor network. Available now in the stable version of Tor Browser.
Decoding ScamClub’s Malicious VAST Attack
https://ift.tt/0Yy7lRu
Submitted March 12, 2024 at 08:59PM by moriya_pedael
via reddit https://ift.tt/0DPVz1f
https://ift.tt/0Yy7lRu
Submitted March 12, 2024 at 08:59PM by moriya_pedael
via reddit https://ift.tt/0DPVz1f
GeoEdge
Decoding ScamClub’s Malicious VAST Attack
ScamClub, a notorious threat actor, has shifted its focus towards video malvertising assaults, resulting in a surge in VAST forced redirect volumes since February 11, 2024. According to GeoEdge security research, upwards of a dozen SSPs and DSPs have fallen…
GhostRace - Exploiting and Mitigating Speculative Race Conditions (CVE-2024-2193)
https://ift.tt/I2abWHO
Submitted March 13, 2024 at 02:11AM by LordAlfredo
via reddit https://ift.tt/ZtrCpX3
https://ift.tt/I2abWHO
Submitted March 13, 2024 at 02:11AM by LordAlfredo
via reddit https://ift.tt/ZtrCpX3
vusec
GhostRace - vusec
Exploiting and Mitigating Speculative Race Conditions GhostRace: CVE-2024-2193 Race conditions arise when multiple threads attempt to access a shared resource without proper synchronization, often leading to vulnerabilities such as concurrent use-after-free.…
Unveiling the Ultimate Pentesting Distro: Perfectly Tailored for Ubuntu Aficionados!
https://ift.tt/MTF3vQL
Submitted March 13, 2024 at 02:07AM by snoopgodlinux
via reddit https://ift.tt/chAxo6F
https://ift.tt/MTF3vQL
Submitted March 13, 2024 at 02:07AM by snoopgodlinux
via reddit https://ift.tt/chAxo6F
Download
Discover SnoopGod, the open-source security-oriented OS based on Ubuntu. With 800+ pre-installed tools, it
Google's 'BeyondCorp and the long tail of Zero Trust' article
https://ift.tt/pSm2kxI
Submitted March 13, 2024 at 04:29PM by PhilipLGriffiths88
via reddit https://ift.tt/dr07GgJ
https://ift.tt/pSm2kxI
Submitted March 13, 2024 at 04:29PM by PhilipLGriffiths88
via reddit https://ift.tt/dr07GgJ
USENIX
BeyondCorp and the long tail of Zero Trust
Donex a new ransomware gang malware technical analysis
https://ift.tt/eEiIynK
Submitted March 13, 2024 at 05:25PM by ShadowStackRE
via reddit https://ift.tt/ulxgRe6
https://ift.tt/eEiIynK
Submitted March 13, 2024 at 05:25PM by ShadowStackRE
via reddit https://ift.tt/ulxgRe6
ShadowStackRE
Donex a new ransomware gang — ShadowStackRE
Donex, A new ransomware gang on the scene with a capable Windows based encryptor.
Building an AITM attack tool in Cloudflare Workers (174 LOC)
https://ift.tt/DBZTlgh
Submitted March 13, 2024 at 07:29PM by wez32
via reddit https://ift.tt/GKej4dQ
https://ift.tt/DBZTlgh
Submitted March 13, 2024 at 07:29PM by wez32
via reddit https://ift.tt/GKej4dQ
Zolder B.V.
Building an AITM attack tool in Cloudflare Workers (174 LOC)
In January we launched new functionality for Attic to detect AiTM attacks targeting the Microsoft 365 tenant of customers. Using the platform of didsomeoneclone.me and custom CSS in the Microsoft l…
A case of missing bytes: bruteforcing your way through Jenkins’ CVE-2024-23897
https://ift.tt/ZPhorIQ
Submitted March 13, 2024 at 10:32PM by gquere
via reddit https://ift.tt/4ZqT3jB
https://ift.tt/ZPhorIQ
Submitted March 13, 2024 at 10:32PM by gquere
via reddit https://ift.tt/4ZqT3jB
Threat Modeling on a Virtual Factory Floor
https://ift.tt/BUVcRh4
Submitted March 13, 2024 at 10:31PM by derp6996
via reddit https://ift.tt/VWP3I6F
https://ift.tt/BUVcRh4
Submitted March 13, 2024 at 10:31PM by derp6996
via reddit https://ift.tt/VWP3I6F
Claroty
Threat Modeling Industrial Environments Using A Virtual Factory (Part 1)
Claroty Team82 has built a virtual factory environment in order to help cybersecurity defenders visualize dependencies between components on a factory floor, and also threat model in an industrial setting.