K8s LAN Party - A Kubernetes Network Security CTF
https://k8slanparty.com
Submitted March 12, 2024 at 02:42AM by geekydeveloper
via reddit https://ift.tt/Wvey3mz
https://k8slanparty.com
Submitted March 12, 2024 at 02:42AM by geekydeveloper
via reddit https://ift.tt/Wvey3mz
K8Slanparty
K8s LAN Party
Kubernetes LAN Party - by Wiz
How we built an AI-Powered Multi Terrain Hacking Robot
https://ift.tt/svflazq
Submitted March 12, 2024 at 07:18AM by berylliumsec
via reddit https://ift.tt/tvdmJr4
https://ift.tt/svflazq
Submitted March 12, 2024 at 07:18AM by berylliumsec
via reddit https://ift.tt/tvdmJr4
Beryllium
How We Built an AI-powered Multi-terrain Hacking Robot — Beryllium
Meet Asteroid - an AI-powered, multi-terrain hacking robot designed to conduct cybersecurity missions in challenging environments where human involvement is either unfeasible or hazardous.
AI Powered Sensitive Information Detection
https://ift.tt/CK8p6NA
Submitted March 12, 2024 at 04:21PM by Civil_Alternative410
via reddit https://ift.tt/gsOym9K
https://ift.tt/CK8p6NA
Submitted March 12, 2024 at 04:21PM by Civil_Alternative410
via reddit https://ift.tt/gsOym9K
GitHub
GitHub - berylliumsec/eclipse: AI Powered Sensitive Information Detection
AI Powered Sensitive Information Detection. Contribute to berylliumsec/eclipse development by creating an account on GitHub.
Malware Pulse - Proactive command and control server discovery hub
https://malpulse.com/
Submitted March 12, 2024 at 06:17PM by mamudogurban
via reddit https://ift.tt/3lxHVrj
https://malpulse.com/
Submitted March 12, 2024 at 06:17PM by mamudogurban
via reddit https://ift.tt/3lxHVrj
Patch Tuesday Diffing: CVE-2024–20696 — Windows Libarchive RCE
https://ift.tt/YZWSClf
Submitted March 12, 2024 at 07:44PM by onlinereadme
via reddit https://ift.tt/NJb0URS
https://ift.tt/YZWSClf
Submitted March 12, 2024 at 07:44PM by onlinereadme
via reddit https://ift.tt/NJb0URS
Medium
Patch Tuesday Diffing: CVE-2024–20696 — Windows Libarchive RCE
TL;DR This post will teach you how to patch diff CVE-2024–20696 (and indirectly CVE-2024–20697) from the January 2024 Patch Tuesday.
Introducing WebTunnel | Tor Project
https://ift.tt/VjY8vLK
Submitted March 12, 2024 at 09:48PM by n3w57ake
via reddit https://ift.tt/Mc5WbSG
https://ift.tt/VjY8vLK
Submitted March 12, 2024 at 09:48PM by n3w57ake
via reddit https://ift.tt/Mc5WbSG
blog.torproject.org
Hiding in plain sight: Introducing WebTunnel | Tor Project
We're celebrating the World Day Against Cyber Censorship by officially announcing WebTunnel, a new type of Tor bridge designed to assist users in heavily censored regions to connect to the Tor network. Available now in the stable version of Tor Browser.
Decoding ScamClub’s Malicious VAST Attack
https://ift.tt/0Yy7lRu
Submitted March 12, 2024 at 08:59PM by moriya_pedael
via reddit https://ift.tt/0DPVz1f
https://ift.tt/0Yy7lRu
Submitted March 12, 2024 at 08:59PM by moriya_pedael
via reddit https://ift.tt/0DPVz1f
GeoEdge
Decoding ScamClub’s Malicious VAST Attack
ScamClub, a notorious threat actor, has shifted its focus towards video malvertising assaults, resulting in a surge in VAST forced redirect volumes since February 11, 2024. According to GeoEdge security research, upwards of a dozen SSPs and DSPs have fallen…
GhostRace - Exploiting and Mitigating Speculative Race Conditions (CVE-2024-2193)
https://ift.tt/I2abWHO
Submitted March 13, 2024 at 02:11AM by LordAlfredo
via reddit https://ift.tt/ZtrCpX3
https://ift.tt/I2abWHO
Submitted March 13, 2024 at 02:11AM by LordAlfredo
via reddit https://ift.tt/ZtrCpX3
vusec
GhostRace - vusec
Exploiting and Mitigating Speculative Race Conditions GhostRace: CVE-2024-2193 Race conditions arise when multiple threads attempt to access a shared resource without proper synchronization, often leading to vulnerabilities such as concurrent use-after-free.…
Unveiling the Ultimate Pentesting Distro: Perfectly Tailored for Ubuntu Aficionados!
https://ift.tt/MTF3vQL
Submitted March 13, 2024 at 02:07AM by snoopgodlinux
via reddit https://ift.tt/chAxo6F
https://ift.tt/MTF3vQL
Submitted March 13, 2024 at 02:07AM by snoopgodlinux
via reddit https://ift.tt/chAxo6F
Download
Discover SnoopGod, the open-source security-oriented OS based on Ubuntu. With 800+ pre-installed tools, it
Google's 'BeyondCorp and the long tail of Zero Trust' article
https://ift.tt/pSm2kxI
Submitted March 13, 2024 at 04:29PM by PhilipLGriffiths88
via reddit https://ift.tt/dr07GgJ
https://ift.tt/pSm2kxI
Submitted March 13, 2024 at 04:29PM by PhilipLGriffiths88
via reddit https://ift.tt/dr07GgJ
USENIX
BeyondCorp and the long tail of Zero Trust
Donex a new ransomware gang malware technical analysis
https://ift.tt/eEiIynK
Submitted March 13, 2024 at 05:25PM by ShadowStackRE
via reddit https://ift.tt/ulxgRe6
https://ift.tt/eEiIynK
Submitted March 13, 2024 at 05:25PM by ShadowStackRE
via reddit https://ift.tt/ulxgRe6
ShadowStackRE
Donex a new ransomware gang — ShadowStackRE
Donex, A new ransomware gang on the scene with a capable Windows based encryptor.
Building an AITM attack tool in Cloudflare Workers (174 LOC)
https://ift.tt/DBZTlgh
Submitted March 13, 2024 at 07:29PM by wez32
via reddit https://ift.tt/GKej4dQ
https://ift.tt/DBZTlgh
Submitted March 13, 2024 at 07:29PM by wez32
via reddit https://ift.tt/GKej4dQ
Zolder B.V.
Building an AITM attack tool in Cloudflare Workers (174 LOC)
In January we launched new functionality for Attic to detect AiTM attacks targeting the Microsoft 365 tenant of customers. Using the platform of didsomeoneclone.me and custom CSS in the Microsoft l…
A case of missing bytes: bruteforcing your way through Jenkins’ CVE-2024-23897
https://ift.tt/ZPhorIQ
Submitted March 13, 2024 at 10:32PM by gquere
via reddit https://ift.tt/4ZqT3jB
https://ift.tt/ZPhorIQ
Submitted March 13, 2024 at 10:32PM by gquere
via reddit https://ift.tt/4ZqT3jB
Threat Modeling on a Virtual Factory Floor
https://ift.tt/BUVcRh4
Submitted March 13, 2024 at 10:31PM by derp6996
via reddit https://ift.tt/VWP3I6F
https://ift.tt/BUVcRh4
Submitted March 13, 2024 at 10:31PM by derp6996
via reddit https://ift.tt/VWP3I6F
Claroty
Threat Modeling Industrial Environments Using A Virtual Factory (Part 1)
Claroty Team82 has built a virtual factory environment in order to help cybersecurity defenders visualize dependencies between components on a factory floor, and also threat model in an industrial setting.
Discovering Deserialization Gadget Chains in Rubyland - Include Security Research Blog
https://ift.tt/BEPldfT
Submitted March 14, 2024 at 12:45AM by 907jessejones
via reddit https://ift.tt/WJ1Cjly
https://ift.tt/BEPldfT
Submitted March 14, 2024 at 12:45AM by 907jessejones
via reddit https://ift.tt/WJ1Cjly
Include Security Research Blog
Discovering Deserialization Gadget Chains in Rubyland - Include Security Research Blog
If you have ever looked at the source code of a Ruby deserialization gadget chain, I bet you've thought "what sorcery is this"?
Researchers trying offensive capabilities of LLM agents
https://ift.tt/9sWFAQq
Submitted March 14, 2024 at 10:21AM by OtojonXudayarov
via reddit https://ift.tt/08jfLBE
https://ift.tt/9sWFAQq
Submitted March 14, 2024 at 10:21AM by OtojonXudayarov
via reddit https://ift.tt/08jfLBE
arXiv.org
LLM Agents can Autonomously Hack Websites
In recent years, large language models (LLMs) have become increasingly capable and can now interact with tools (i.e., call functions), read documents, and recursively call themselves. As a result,...
Microsoft Entra ID: The Complete Guide to Conditional Access Policies
https://ift.tt/dSG7MD5
Submitted March 14, 2024 at 02:30PM by Or1rez
via reddit https://ift.tt/Re4CuY8
https://ift.tt/dSG7MD5
Submitted March 14, 2024 at 02:30PM by Or1rez
via reddit https://ift.tt/Re4CuY8
Rezonate - Protect Identities, Everywhere
Microsoft Entra ID: The Complete Guide to Conditional Access Policies - Rezonate
Here it is - everything you need to know about using Entra ID's Conditional Access policies to boost your identity security posture.
Fortinet FortiWLM Multiple Vulnerabilities Deep-Dive and IOCs
https://ift.tt/MiEHZCp
Submitted March 14, 2024 at 07:00PM by scopedsecurity
via reddit https://ift.tt/F96Qtzw
https://ift.tt/MiEHZCp
Submitted March 14, 2024 at 07:00PM by scopedsecurity
via reddit https://ift.tt/F96Qtzw
Horizon3.ai
Fortinet FortiWLM Deep-Dive, IOCs, and the Almost Story of the “Forti Forty”
FortiWLM Deep Dive and Indicators of Compromise. This blog details the discovery of many critical security issues such as RCE, SQLi, and file reads leading to full device compromise. CVE-2023-34993, CVE-2023-34991, CVE-2023-42783, CVE-2023-34989.
IoT Penetration Testing Part 1: The Basics
https://ift.tt/mTchAok
Submitted March 14, 2024 at 06:49PM by needmorejava
via reddit https://ift.tt/cp6BfME
https://ift.tt/mTchAok
Submitted March 14, 2024 at 06:49PM by needmorejava
via reddit https://ift.tt/cp6BfME
The Anatomy of an ALPHA SPIDER Ransomware Attack
https://ift.tt/kNmLPoh
Submitted March 14, 2024 at 06:23PM by Due_Spare_6458
via reddit https://ift.tt/lH6i0EN
https://ift.tt/kNmLPoh
Submitted March 14, 2024 at 06:23PM by Due_Spare_6458
via reddit https://ift.tt/lH6i0EN
crowdstrike.com
The Anatomy of an ALPHA SPIDER Ransomware Attack
Read this blog on the anatomy of an ALPHA SPIDER ransomware attack to better understand how they operate and how to better protect your business.
Oauth implementation flaws allow access to private repos via ChatGPT plugins
https://ift.tt/U5rEtpX
Submitted March 15, 2024 at 02:18AM by ScottContini
via reddit https://ift.tt/pSQ0Nk2
https://ift.tt/U5rEtpX
Submitted March 15, 2024 at 02:18AM by ScottContini
via reddit https://ift.tt/pSQ0Nk2
salt.security
ChatGPT Vulnerability - Security Flaws within ChatGPT
Salt Labs researchers identified vulnerabilities in the ChatGPT ecosystem that could have granted access to accounts of users and sensitive data.