11 year old security bug in util-linux (Leak user passwords on Ubuntu)
https://ift.tt/z08aWOb
Submitted March 27, 2024 at 11:11PM by sky0023
via reddit https://ift.tt/sWbR631
https://ift.tt/z08aWOb
Submitted March 27, 2024 at 11:11PM by sky0023
via reddit https://ift.tt/sWbR631
Crumbled Security: Unmasking the Cookie-Stealing Malware Threat
https://ift.tt/yLza15t
Submitted March 28, 2024 at 12:30AM by jat0369
via reddit https://ift.tt/9axYzkB
https://ift.tt/yLza15t
Submitted March 28, 2024 at 12:30AM by jat0369
via reddit https://ift.tt/9axYzkB
Cyberark
Crumbled Security: Unmasking the Cookie-Stealing Malware Threat
Over the past few years, we’ve seen a huge increase in the adoption of identity security solutions. Since these types of solutions help protect against a whole range of password-guessing and...
Malicious Implant to remotely control Electronic Locks via WiFi
https://ift.tt/EVtahcU
Submitted March 28, 2024 at 02:15AM by Zealousideal_Tip2086
via reddit https://ift.tt/tPqSXuQ
https://ift.tt/EVtahcU
Submitted March 28, 2024 at 02:15AM by Zealousideal_Tip2086
via reddit https://ift.tt/tPqSXuQ
PRIDE Security Blog
Turnstiles from a hacker perspective - Part 2
Physical implants in turnstiles, replay attacks, and a brief introduction to the Wiegand protocol
Disclaimer
This Security Advisory is provided on an "as is" basis and do not imply any kind of guarantee or warranty. Your use of the information in this…
Disclaimer
This Security Advisory is provided on an "as is" basis and do not imply any kind of guarantee or warranty. Your use of the information in this…
Introducing SharpConflux
https://ift.tt/cTNQnJL
Submitted March 28, 2024 at 04:28PM by campuscodi
via reddit https://ift.tt/mKHblZI
https://ift.tt/cTNQnJL
Submitted March 28, 2024 at 04:28PM by campuscodi
via reddit https://ift.tt/mKHblZI
LRQA Nettitude Labs
Introducing SharpConflux
Today, we are releasing a new tool called SharpConflux, a .NET application built to facilitate Confluence exploration. It allows Red Team operators to easily investigate Confluence instances with the goal of finding credential material and documentation relating…
After almost 7 years, new version of drozer was released
https://ift.tt/V4DrXop
Submitted March 28, 2024 at 07:08PM by agathocles11
via reddit https://ift.tt/2S97jsX
https://ift.tt/V4DrXop
Submitted March 28, 2024 at 07:08PM by agathocles11
via reddit https://ift.tt/2S97jsX
GitHub
GitHub - ReversecLabs/drozer: The Leading Security Assessment Framework for Android.
The Leading Security Assessment Framework for Android. - ReversecLabs/drozer
PyPI Suspends New User Registration In Wake of Large Typosquatting Campaign
https://ift.tt/pLWqZMz
Submitted March 28, 2024 at 11:05PM by louis11
via reddit https://ift.tt/dBmynGM
https://ift.tt/pLWqZMz
Submitted March 28, 2024 at 11:05PM by louis11
via reddit https://ift.tt/dBmynGM
Phylum
Typosquatting Campaign Targets Python Developers
On 26 March 2024, Phylum’s automated risk detection platform picked up yet another typosquat campaign targeting some attackers’ favorite targets in PyPI. As of writing, this attack still appears to be active and has come in two big waves after about a 20…
Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu - Exodus Intelligence
https://ift.tt/8v3SMU0
Submitted March 29, 2024 at 01:22AM by Soggy_Sally
via reddit https://ift.tt/KgrxbX8
https://ift.tt/8v3SMU0
Submitted March 29, 2024 at 01:22AM by Soggy_Sally
via reddit https://ift.tt/KgrxbX8
Exodus Intelligence
Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu - Exodus Intelligence
By Oriol Castejón Overview This post discusses a use-after-free vulnerability, CVE-2024-0582, in io_uring in the Linux kernel. Despite the vulnerability being patched in the stable kernel in December 2023, it wasn’t ported to Ubuntu kernels for over two months…
Bref Security Audit - Shielder
https://ift.tt/zyRN0ML
Submitted March 29, 2024 at 05:42PM by smaury
via reddit https://ift.tt/zrdiRQE
https://ift.tt/zyRN0ML
Submitted March 29, 2024 at 05:42PM by smaury
via reddit https://ift.tt/zrdiRQE
Shielder
Shielder - Bref Security Audit
Bref Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
oss-security - Backdoor in upstream xz/liblzma leading to ssh server compromise
https://ift.tt/Vga5SMu
Submitted March 29, 2024 at 10:57PM by netsec_burn
via reddit https://ift.tt/mP0GuWj
https://ift.tt/Vga5SMu
Submitted March 29, 2024 at 10:57PM by netsec_burn
via reddit https://ift.tt/mP0GuWj
Hijacking Chatbots: Dangerous Methods Manipulating GPTs
https://ift.tt/ZXwk8hm
Submitted March 30, 2024 at 05:10AM by derjanni
via reddit https://ift.tt/KWADa8t
https://ift.tt/ZXwk8hm
Submitted March 30, 2024 at 05:10AM by derjanni
via reddit https://ift.tt/KWADa8t
Medium
Hijacking Chatbots: Dangerous Methods Manipulating GPTs
Security research on GPTs and LLMs has only just begun. It’s already become a meme to force customer service chatbots to start programming…
Vulnerability Management Lifecycle in DevSecOps
https://ift.tt/Xo9gmMa
Submitted April 01, 2024 at 02:27AM by doctormay6
via reddit https://ift.tt/bVQWTU7
https://ift.tt/Xo9gmMa
Submitted April 01, 2024 at 02:27AM by doctormay6
via reddit https://ift.tt/bVQWTU7
GitGuardian Blog - Take Control of Your Secrets Security
Vulnerability Management Lifecycle in DevSecOps
In this new series, CJ May shares his expertise in implementing secure-by-design software processes that empower engineering teams.
The first stage of his DevSecOps program: vulnerability management.
The first stage of his DevSecOps program: vulnerability management.
ROP Emporium - ret2win Buffer Overflow Challenge
https://ift.tt/NtyTMaJ
Submitted April 01, 2024 at 09:29AM by Accomplished-Mud1210
via reddit https://ift.tt/sNnzfpu
https://ift.tt/NtyTMaJ
Submitted April 01, 2024 at 09:29AM by Accomplished-Mud1210
via reddit https://ift.tt/sNnzfpu
RingBuffer's Blog
ROP Challenge – Exploiting ret2win Binary – RingBuffer's Blog
A detail guide on how to capture the flag using return oriented programming buffer overflow challenge on ROP Emporium.
What is Deception Technology? - Fidelis Security
https://ift.tt/wrWvsx8
Submitted April 01, 2024 at 12:11PM by cybergeekus
via reddit https://ift.tt/4SGkec3
https://ift.tt/wrWvsx8
Submitted April 01, 2024 at 12:11PM by cybergeekus
via reddit https://ift.tt/4SGkec3
Fidelis Security
What is Cyber Deception and Why Does an Organization Need It?| Fidelis Security
Discover what cyber deception is, how it works, and why organizations need it to detect, mislead, and stop attackers effectively.
Fine-tuning Semgrep for Ruby Security: Pundit and SQL injection
https://ift.tt/MmJn6Th
Submitted April 01, 2024 at 12:39PM by s0rcy
via reddit https://ift.tt/QonF83g
https://ift.tt/MmJn6Th
Submitted April 01, 2024 at 12:39PM by s0rcy
via reddit https://ift.tt/QonF83g
sorted unsorted thoughts
Fine-tuning Semgrep for Ruby Security: Pundit and SQL injection
In this blog post, we’ll go over the construction and tuning of a few Semgrep rules I created while looking at a Ruby on Rails application. Semgrep is a powerful code analysis tool, and while there are a fair number of community rules, the default rules don’t…
From OneNote to RansomNote: An Ice Cold Intrusion
https://ift.tt/qgrNwiz
Submitted April 01, 2024 at 05:21PM by TheDFIRReport
via reddit https://ift.tt/eYnZ8ly
https://ift.tt/qgrNwiz
Submitted April 01, 2024 at 05:21PM by TheDFIRReport
via reddit https://ift.tt/eYnZ8ly
The DFIR Report
From OneNote to RansomNote: An Ice Cold Intrusion
Key Takeaways In late February 2023, threat actors rode a wave of initial access using Microsoft OneNote files. In this case, we observed a threat actor deliver IcedID using this method. After load…
Last part of Lord Of The Ring0
https://ift.tt/z3NJK9o
Submitted April 01, 2024 at 07:06PM by Idov31
via reddit https://ift.tt/8cnNaED
https://ift.tt/z3NJK9o
Submitted April 01, 2024 at 07:06PM by Idov31
via reddit https://ift.tt/8cnNaED
Bypassing DOMPurify with good old XML
https://ift.tt/AOl4h2d
Submitted April 01, 2024 at 08:33PM by toyojuni
via reddit https://ift.tt/ZmU0cBh
https://ift.tt/AOl4h2d
Submitted April 01, 2024 at 08:33PM by toyojuni
via reddit https://ift.tt/ZmU0cBh
flatt.tech
Bypassing DOMPurify with good old XML
How I could bypass DOMPurify with XML
BGGP4: PleaseMom, QUANTUM, Rat?
https://remyhax.xyz/posts/bggp4-quantum-rat/
Submitted April 01, 2024 at 07:48PM by netsecfriends
via reddit https://ift.tt/xtelr7A
https://remyhax.xyz/posts/bggp4-quantum-rat/
Submitted April 01, 2024 at 07:48PM by netsecfriends
via reddit https://ift.tt/xtelr7A
remyhax.xyz
BGGP4: PleaseMom, QUANTUM, Rat?
For this last years Binary Golf Grand Prix the goal was to:
Create the smallest self-replicating file.
Requirements:
Create the smallest self-replicating file.
Requirements:
xz/liblzma Backdoor: Open Source Nuke? Maybe Not That Bad!
https://ift.tt/SbeW2Vw
Submitted April 01, 2024 at 11:03AM by hardenedvault
via reddit https://ift.tt/VILkAoa
https://ift.tt/SbeW2Vw
Submitted April 01, 2024 at 11:03AM by hardenedvault
via reddit https://ift.tt/VILkAoa
hardenedvault.net
xz/liblzma Backdoor: Open Source Nuke? Maybe Not That Bad!
xz/liblzma Backdoor: Open Source Nuke? Maybe Not That Bad! Story Background On March 29, 2024, a report exposing a backdoor in the upstream source code of the controversial open-source project, the xz software package, was made public on the oss-security…
How Complex Systems Fail
https://ift.tt/EeCyXij
Submitted April 01, 2024 at 07:39PM by Alexander_Selkirk
via reddit https://ift.tt/t8MJm9C
https://ift.tt/EeCyXij
Submitted April 01, 2024 at 07:39PM by Alexander_Selkirk
via reddit https://ift.tt/t8MJm9C
Xzbot: exploit demo for the xz backdoor (CVE-2024-3094)
https://ift.tt/wAJp7qK
Submitted April 01, 2024 at 10:21PM by netsec_burn
via reddit https://ift.tt/bQHZmpl
https://ift.tt/wAJp7qK
Submitted April 01, 2024 at 10:21PM by netsec_burn
via reddit https://ift.tt/bQHZmpl
GitHub
GitHub - amlweems/xzbot: notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094) - amlweems/xzbot