Kobold letters – Why HTML emails are a risk to your organization
https://ift.tt/SreE8O9
Submitted April 03, 2024 at 09:06PM by lutrasecurity
via reddit https://ift.tt/cP9BuMY
https://ift.tt/SreE8O9
Submitted April 03, 2024 at 09:06PM by lutrasecurity
via reddit https://ift.tt/cP9BuMY
Lutrasecurity
Kobold letters – Lutra Security
Anyone who has had to deal with HTML emails on a technical level has probably reached the point where they wanted to quit their job or just set fire to all the mail clients due to their inconsistent implementations. But HTML emails are not just a source of…
Showcasing Incinerator a Powerful Android Malware Reversing Tool
https://ift.tt/Nzu5tQK
Submitted April 03, 2024 at 09:44PM by WiseTuna
via reddit https://ift.tt/KkbGBeE
https://ift.tt/Nzu5tQK
Submitted April 03, 2024 at 09:44PM by WiseTuna
via reddit https://ift.tt/KkbGBeE
Boschko Security Blog
Incinerator: The Ultimate Android Malware Reversing Tool
Master Android malware reversal with ease using Incinerator, your trusted ally in the fight against threat actors for experts and novices alike.
Gram - Self-hosted Threat Modeling Webapp
https://ift.tt/ZUmxRXq
Submitted April 04, 2024 at 01:22AM by Tethik
via reddit https://ift.tt/U4dKHuX
https://ift.tt/ZUmxRXq
Submitted April 04, 2024 at 01:22AM by Tethik
via reddit https://ift.tt/U4dKHuX
GitHub
GitHub - klarna-incubator/gram: Gram is Klarna's own threat model diagramming tool
Gram is Klarna's own threat model diagramming tool - klarna-incubator/gram
unch 😗: Hides message with invisible Unicode characters
https://ift.tt/tFfMJYD
Submitted April 04, 2024 at 03:55AM by dwisiswant0
via reddit https://ift.tt/Z1SoICJ
https://ift.tt/tFfMJYD
Submitted April 04, 2024 at 03:55AM by dwisiswant0
via reddit https://ift.tt/Z1SoICJ
GitHub
GitHub - dwisiswant0/unch: Hides message with invisible Unicode characters
Hides message with invisible Unicode characters. Contribute to dwisiswant0/unch development by creating an account on GitHub.
Diving Deeper into AI Package Hallucinations
https://ift.tt/Nt2iJpW
Submitted April 05, 2024 at 01:40PM by mowaptpop
via reddit https://ift.tt/vFmDutw
https://ift.tt/Nt2iJpW
Submitted April 05, 2024 at 01:40PM by mowaptpop
via reddit https://ift.tt/vFmDutw
www.lasso.security
Diving Deeper into AI Package Hallucinations
Lass Security's recent research on AI Package Hallucinations extends the attack technique to GPT-3.5-Turbo, GPT-4, Gemini Pro (Bard), and Coral (Cohere).
Security Advisory: Systems with a SONIX Technology Webcam vulnerable to DLL hijacking attack allowing attackers to execute malicious DLL and escalate privileges
https://ift.tt/Rmy9TiU
Submitted April 05, 2024 at 02:03PM by usdAG
via reddit https://ift.tt/lpbGkj5
https://ift.tt/Rmy9TiU
Submitted April 05, 2024 at 02:03PM by usdAG
via reddit https://ift.tt/lpbGkj5
usd HeroLab
usd-2023-0029 - usd HeroLab
Advisory ID: usd-2023-0029 | Product: SONIX Technology Webcam | Vulnerability Type: CWE 732 - Incorrect Permission Assignment for Critical Resource
Wifi credential dumping
https://ift.tt/vH6kI3h
Submitted April 05, 2024 at 02:43PM by S3cur3Th1sSh1t
via reddit https://ift.tt/HkvBb2V
https://ift.tt/vH6kI3h
Submitted April 05, 2024 at 02:43PM by S3cur3Th1sSh1t
via reddit https://ift.tt/HkvBb2V
www.r-tec.net
WIFI Credential Dumping: Techniques to retrieve the PSK from a workstation post-compromise
This blog won't dive into any of the mentioned WIFI attacks, but will highlight techniques to retrieve the PSK from a workstation post-compromise instead.
Galactical Bug Hunting: How we discovered new issues in CD Projekt Red’s Gaming Platform
https://ift.tt/nuxOGNM
Submitted April 05, 2024 at 08:59PM by proccessunknown
via reddit https://ift.tt/T1ADsJi
https://ift.tt/nuxOGNM
Submitted April 05, 2024 at 08:59PM by proccessunknown
via reddit https://ift.tt/T1ADsJi
Anvil Secure
Galactical Bug Hunting: How we discovered new issues in CD Projekt Red's Gaming Platform - Anvil Secure
As a researcher I often run into situations in which I need to make a compiled binary do things that it wouldn’t normally do or change the way it works in some way. Of course, if one…
Don't trust the cache :Exposing Web cache vulnerabilities
https://ift.tt/CXN16Bi
Submitted April 05, 2024 at 10:43PM by anasbetis94
via reddit https://ift.tt/e1zZO9K
https://ift.tt/CXN16Bi
Submitted April 05, 2024 at 10:43PM by anasbetis94
via reddit https://ift.tt/e1zZO9K
Medium
Don’t Trust the Cache: Exposing Web Cache Poisoning and Deception vulnerabilities
Good Day!
League of legends stalkerware
https://ift.tt/cMY8Dd2
Submitted April 06, 2024 at 08:40PM by Cyfiefie
via reddit https://ift.tt/on98Wb7
https://ift.tt/cMY8Dd2
Submitted April 06, 2024 at 08:40PM by Cyfiefie
via reddit https://ift.tt/on98Wb7
Leagueoflegends
League of Legends
League of Legends is a team-based game with over 140 champions to make epic plays with. Play now for free.
Streamline Threat Hunting: Shortemall Automates Short URL Analysis with a Click
https://ift.tt/XDKsVJN
Submitted April 08, 2024 at 11:43PM by osint_matter
via reddit https://ift.tt/Pkiu0ZF
https://ift.tt/XDKsVJN
Submitted April 08, 2024 at 11:43PM by osint_matter
via reddit https://ift.tt/Pkiu0ZF
GitHub
GitHub - osintmatter/shortemall: Shortemall is a Python-based tool that automates the process of scanning hidden content of Short…
Shortemall is a Python-based tool that automates the process of scanning hidden content of Short URLs. - GitHub - osintmatter/shortemall: Shortemall is a Python-based tool that automates the proce...
Telegram Users Warned of Potential Security Risk
https://ift.tt/lS5sLEk
Submitted April 09, 2024 at 07:01PM by Educational_Swim8665
via reddit https://ift.tt/KnDJzia
https://ift.tt/lS5sLEk
Submitted April 09, 2024 at 07:01PM by Educational_Swim8665
via reddit https://ift.tt/KnDJzia
BitDegree
Telegram Users Warned of Potential Security Risk
CertiK has reported a high-risk vulnerability in the Telegram Desktop application that could allow for remote code execution attacks.
RUBYCARP: A Detailed Analysis of a Sophisticated Decade-Old Botnet Group
https://ift.tt/yn5vNqx
Submitted April 09, 2024 at 09:48PM by MiguelHzBz
via reddit https://ift.tt/TBI1F5b
https://ift.tt/yn5vNqx
Submitted April 09, 2024 at 09:48PM by MiguelHzBz
via reddit https://ift.tt/TBI1F5b
Sysdig
RUBYCARP: A Detailed Analysis of a Sophisticated Decade-Old Botnet Group | Sysdig
The Sysdig Threat Research Team discovered a long-running botnet operated by a Romanian threat actor group, which we are calling RUBYCARP.
The Distribution Problem: what's wrong with internal CAs (and what to do about it)
https://ift.tt/0gfsJZp
Submitted April 09, 2024 at 09:56PM by ben_burkert
via reddit https://ift.tt/nci3oh8
https://ift.tt/0gfsJZp
Submitted April 09, 2024 at 09:56PM by ben_burkert
via reddit https://ift.tt/nci3oh8
anchor.dev
The Distribution Problem
At Anchor, we see certificate provisioning as table-stakes for any certificate management product, and we’re obsessive about solving these distribution problems. We want to change how developers think about internal CAs.
Simple python wrapper around Terraform and Ansible to help manage and mature domains for pentesting engagements
https://ift.tt/OCnE95T
Submitted April 09, 2024 at 11:41PM by Fudgedotdotdot
via reddit https://ift.tt/ZBMcnoJ
https://ift.tt/OCnE95T
Submitted April 09, 2024 at 11:41PM by Fudgedotdotdot
via reddit https://ift.tt/ZBMcnoJ
GitHub
GitHub - Fudgedotdotdot/oceanbreeze
Contribute to Fudgedotdotdot/oceanbreeze development by creating an account on GitHub.
New OpenSecurityTraining2 class: "Architecture 1005: RISC-V Assembly" by Xeno Kovah (~28 hours)
https://ift.tt/rTcjmgL
Submitted April 10, 2024 at 12:13AM by OpenSecurityTraining
via reddit https://ift.tt/3NZP95H
https://ift.tt/rTcjmgL
Submitted April 10, 2024 at 12:13AM by OpenSecurityTraining
via reddit https://ift.tt/3NZP95H
p.ost2.fyi
Architecture 1005: RISC-V Assembly
This class teaches RISC-V assembly language. It requires you know C programming.
BatBadBut: You can't securely execute commands on Windows
https://ift.tt/TDKqEbt
Submitted April 10, 2024 at 05:53AM by toyojuni
via reddit https://ift.tt/fABDdvH
https://ift.tt/TDKqEbt
Submitted April 10, 2024 at 05:53AM by toyojuni
via reddit https://ift.tt/fABDdvH
GMO Flatt Security Research
BatBadBut: You can't securely execute commands on Windows
Introduction
Hello, I’m RyotaK ( @ryotkak
), a security engineer at Flatt Security Inc.
Recently, I reported multiple vulnerabilities to several programming languages that allowed an attacker to perform command injection on Windows when the specific conditions…
Hello, I’m RyotaK ( @ryotkak
), a security engineer at Flatt Security Inc.
Recently, I reported multiple vulnerabilities to several programming languages that allowed an attacker to perform command injection on Windows when the specific conditions…
Havoc C2 Framework – A Defensive Operator’s Guide
https://ift.tt/AkRunGU
Submitted April 10, 2024 at 02:34PM by kev-thehermit
via reddit https://ift.tt/EqwxvcC
https://ift.tt/AkRunGU
Submitted April 10, 2024 at 02:34PM by kev-thehermit
via reddit https://ift.tt/EqwxvcC
Immersivelabs
Havoc C2 Framework – A Defensive Operator’s Guide
This blog empowers defenders to detect the presence of Havoc C2, analyze its proprietary agents and enhance organizational resilience.
The DDoS Report: The complete guide to Distributed Denial of Service (DDoS) attacks for developers and operators
https://ddos.report/
Submitted April 11, 2024 at 03:33PM by relaygus
via reddit https://ift.tt/fNca84v
https://ddos.report/
Submitted April 11, 2024 at 03:33PM by relaygus
via reddit https://ift.tt/fNca84v
Reddit
From the netsec community on Reddit: The DDoS Report: The complete guide to Distributed Denial of Service (DDoS) attacks for developers…
Posted by relaygus - 0 votes and 0 comments
PlasmaPup: Improve Active Directory your security posture. Perfect for admins in large environments wanting quick permission audits, and for large decentalized organizations where you'd like all your unit admins to be empowered to quickly audit their own OUs.
https://ift.tt/wR8nPqX
Submitted April 11, 2024 at 04:31PM by RossGeerlings
via reddit https://ift.tt/3eaUBDh
https://ift.tt/wR8nPqX
Submitted April 11, 2024 at 04:31PM by RossGeerlings
via reddit https://ift.tt/3eaUBDh
GitHub
GitHub - RossGeerlings/PlasmaPup: PlasmaPup is designed to help central and departmental IT personnel understand their exposures…
PlasmaPup is designed to help central and departmental IT personnel understand their exposures in Active Directory by showing which accounts have permissions to make changes within their OU(s) or m...
Vulnerability Management Goes Much Deeper Than Patching
https://ift.tt/Ps56moU
Submitted April 11, 2024 at 07:23PM by KolideKenny
via reddit https://ift.tt/T4bULAk
https://ift.tt/Ps56moU
Submitted April 11, 2024 at 07:23PM by KolideKenny
via reddit https://ift.tt/T4bULAk
1Password
Vulnerability management goes much deeper than patching | 1Password
Compliance guidelines are driving companies toward vulnerability management, but how can teams broaden their scope beyond the patchable problems?