Diving Deeper into AI Package Hallucinations
https://ift.tt/Nt2iJpW
Submitted April 05, 2024 at 01:40PM by mowaptpop
via reddit https://ift.tt/vFmDutw
https://ift.tt/Nt2iJpW
Submitted April 05, 2024 at 01:40PM by mowaptpop
via reddit https://ift.tt/vFmDutw
www.lasso.security
Diving Deeper into AI Package Hallucinations
Lass Security's recent research on AI Package Hallucinations extends the attack technique to GPT-3.5-Turbo, GPT-4, Gemini Pro (Bard), and Coral (Cohere).
Security Advisory: Systems with a SONIX Technology Webcam vulnerable to DLL hijacking attack allowing attackers to execute malicious DLL and escalate privileges
https://ift.tt/Rmy9TiU
Submitted April 05, 2024 at 02:03PM by usdAG
via reddit https://ift.tt/lpbGkj5
https://ift.tt/Rmy9TiU
Submitted April 05, 2024 at 02:03PM by usdAG
via reddit https://ift.tt/lpbGkj5
usd HeroLab
usd-2023-0029 - usd HeroLab
Advisory ID: usd-2023-0029 | Product: SONIX Technology Webcam | Vulnerability Type: CWE 732 - Incorrect Permission Assignment for Critical Resource
Wifi credential dumping
https://ift.tt/vH6kI3h
Submitted April 05, 2024 at 02:43PM by S3cur3Th1sSh1t
via reddit https://ift.tt/HkvBb2V
https://ift.tt/vH6kI3h
Submitted April 05, 2024 at 02:43PM by S3cur3Th1sSh1t
via reddit https://ift.tt/HkvBb2V
www.r-tec.net
WIFI Credential Dumping: Techniques to retrieve the PSK from a workstation post-compromise
This blog won't dive into any of the mentioned WIFI attacks, but will highlight techniques to retrieve the PSK from a workstation post-compromise instead.
Galactical Bug Hunting: How we discovered new issues in CD Projekt Red’s Gaming Platform
https://ift.tt/nuxOGNM
Submitted April 05, 2024 at 08:59PM by proccessunknown
via reddit https://ift.tt/T1ADsJi
https://ift.tt/nuxOGNM
Submitted April 05, 2024 at 08:59PM by proccessunknown
via reddit https://ift.tt/T1ADsJi
Anvil Secure
Galactical Bug Hunting: How we discovered new issues in CD Projekt Red's Gaming Platform - Anvil Secure
As a researcher I often run into situations in which I need to make a compiled binary do things that it wouldn’t normally do or change the way it works in some way. Of course, if one…
Don't trust the cache :Exposing Web cache vulnerabilities
https://ift.tt/CXN16Bi
Submitted April 05, 2024 at 10:43PM by anasbetis94
via reddit https://ift.tt/e1zZO9K
https://ift.tt/CXN16Bi
Submitted April 05, 2024 at 10:43PM by anasbetis94
via reddit https://ift.tt/e1zZO9K
Medium
Don’t Trust the Cache: Exposing Web Cache Poisoning and Deception vulnerabilities
Good Day!
League of legends stalkerware
https://ift.tt/cMY8Dd2
Submitted April 06, 2024 at 08:40PM by Cyfiefie
via reddit https://ift.tt/on98Wb7
https://ift.tt/cMY8Dd2
Submitted April 06, 2024 at 08:40PM by Cyfiefie
via reddit https://ift.tt/on98Wb7
Leagueoflegends
League of Legends
League of Legends is a team-based game with over 140 champions to make epic plays with. Play now for free.
Streamline Threat Hunting: Shortemall Automates Short URL Analysis with a Click
https://ift.tt/XDKsVJN
Submitted April 08, 2024 at 11:43PM by osint_matter
via reddit https://ift.tt/Pkiu0ZF
https://ift.tt/XDKsVJN
Submitted April 08, 2024 at 11:43PM by osint_matter
via reddit https://ift.tt/Pkiu0ZF
GitHub
GitHub - osintmatter/shortemall: Shortemall is a Python-based tool that automates the process of scanning hidden content of Short…
Shortemall is a Python-based tool that automates the process of scanning hidden content of Short URLs. - GitHub - osintmatter/shortemall: Shortemall is a Python-based tool that automates the proce...
Telegram Users Warned of Potential Security Risk
https://ift.tt/lS5sLEk
Submitted April 09, 2024 at 07:01PM by Educational_Swim8665
via reddit https://ift.tt/KnDJzia
https://ift.tt/lS5sLEk
Submitted April 09, 2024 at 07:01PM by Educational_Swim8665
via reddit https://ift.tt/KnDJzia
BitDegree
Telegram Users Warned of Potential Security Risk
CertiK has reported a high-risk vulnerability in the Telegram Desktop application that could allow for remote code execution attacks.
RUBYCARP: A Detailed Analysis of a Sophisticated Decade-Old Botnet Group
https://ift.tt/yn5vNqx
Submitted April 09, 2024 at 09:48PM by MiguelHzBz
via reddit https://ift.tt/TBI1F5b
https://ift.tt/yn5vNqx
Submitted April 09, 2024 at 09:48PM by MiguelHzBz
via reddit https://ift.tt/TBI1F5b
Sysdig
RUBYCARP: A Detailed Analysis of a Sophisticated Decade-Old Botnet Group | Sysdig
The Sysdig Threat Research Team discovered a long-running botnet operated by a Romanian threat actor group, which we are calling RUBYCARP.
The Distribution Problem: what's wrong with internal CAs (and what to do about it)
https://ift.tt/0gfsJZp
Submitted April 09, 2024 at 09:56PM by ben_burkert
via reddit https://ift.tt/nci3oh8
https://ift.tt/0gfsJZp
Submitted April 09, 2024 at 09:56PM by ben_burkert
via reddit https://ift.tt/nci3oh8
anchor.dev
The Distribution Problem
At Anchor, we see certificate provisioning as table-stakes for any certificate management product, and we’re obsessive about solving these distribution problems. We want to change how developers think about internal CAs.
Simple python wrapper around Terraform and Ansible to help manage and mature domains for pentesting engagements
https://ift.tt/OCnE95T
Submitted April 09, 2024 at 11:41PM by Fudgedotdotdot
via reddit https://ift.tt/ZBMcnoJ
https://ift.tt/OCnE95T
Submitted April 09, 2024 at 11:41PM by Fudgedotdotdot
via reddit https://ift.tt/ZBMcnoJ
GitHub
GitHub - Fudgedotdotdot/oceanbreeze
Contribute to Fudgedotdotdot/oceanbreeze development by creating an account on GitHub.
New OpenSecurityTraining2 class: "Architecture 1005: RISC-V Assembly" by Xeno Kovah (~28 hours)
https://ift.tt/rTcjmgL
Submitted April 10, 2024 at 12:13AM by OpenSecurityTraining
via reddit https://ift.tt/3NZP95H
https://ift.tt/rTcjmgL
Submitted April 10, 2024 at 12:13AM by OpenSecurityTraining
via reddit https://ift.tt/3NZP95H
p.ost2.fyi
Architecture 1005: RISC-V Assembly
This class teaches RISC-V assembly language. It requires you know C programming.
BatBadBut: You can't securely execute commands on Windows
https://ift.tt/TDKqEbt
Submitted April 10, 2024 at 05:53AM by toyojuni
via reddit https://ift.tt/fABDdvH
https://ift.tt/TDKqEbt
Submitted April 10, 2024 at 05:53AM by toyojuni
via reddit https://ift.tt/fABDdvH
GMO Flatt Security Research
BatBadBut: You can't securely execute commands on Windows
Introduction
Hello, I’m RyotaK ( @ryotkak
), a security engineer at Flatt Security Inc.
Recently, I reported multiple vulnerabilities to several programming languages that allowed an attacker to perform command injection on Windows when the specific conditions…
Hello, I’m RyotaK ( @ryotkak
), a security engineer at Flatt Security Inc.
Recently, I reported multiple vulnerabilities to several programming languages that allowed an attacker to perform command injection on Windows when the specific conditions…
Havoc C2 Framework – A Defensive Operator’s Guide
https://ift.tt/AkRunGU
Submitted April 10, 2024 at 02:34PM by kev-thehermit
via reddit https://ift.tt/EqwxvcC
https://ift.tt/AkRunGU
Submitted April 10, 2024 at 02:34PM by kev-thehermit
via reddit https://ift.tt/EqwxvcC
Immersivelabs
Havoc C2 Framework – A Defensive Operator’s Guide
This blog empowers defenders to detect the presence of Havoc C2, analyze its proprietary agents and enhance organizational resilience.
The DDoS Report: The complete guide to Distributed Denial of Service (DDoS) attacks for developers and operators
https://ddos.report/
Submitted April 11, 2024 at 03:33PM by relaygus
via reddit https://ift.tt/fNca84v
https://ddos.report/
Submitted April 11, 2024 at 03:33PM by relaygus
via reddit https://ift.tt/fNca84v
Reddit
From the netsec community on Reddit: The DDoS Report: The complete guide to Distributed Denial of Service (DDoS) attacks for developers…
Posted by relaygus - 0 votes and 0 comments
PlasmaPup: Improve Active Directory your security posture. Perfect for admins in large environments wanting quick permission audits, and for large decentalized organizations where you'd like all your unit admins to be empowered to quickly audit their own OUs.
https://ift.tt/wR8nPqX
Submitted April 11, 2024 at 04:31PM by RossGeerlings
via reddit https://ift.tt/3eaUBDh
https://ift.tt/wR8nPqX
Submitted April 11, 2024 at 04:31PM by RossGeerlings
via reddit https://ift.tt/3eaUBDh
GitHub
GitHub - RossGeerlings/PlasmaPup: PlasmaPup is designed to help central and departmental IT personnel understand their exposures…
PlasmaPup is designed to help central and departmental IT personnel understand their exposures in Active Directory by showing which accounts have permissions to make changes within their OU(s) or m...
Vulnerability Management Goes Much Deeper Than Patching
https://ift.tt/Ps56moU
Submitted April 11, 2024 at 07:23PM by KolideKenny
via reddit https://ift.tt/T4bULAk
https://ift.tt/Ps56moU
Submitted April 11, 2024 at 07:23PM by KolideKenny
via reddit https://ift.tt/T4bULAk
1Password
Vulnerability management goes much deeper than patching | 1Password
Compliance guidelines are driving companies toward vulnerability management, but how can teams broaden their scope beyond the patchable problems?
How a 9.8 critical security vulnerability in ZeroMQ was found (with mostly pure luck)
https://ift.tt/3HYekDG
Submitted April 12, 2024 at 01:06AM by louis11
via reddit https://ift.tt/kXV2MGb
https://ift.tt/3HYekDG
Submitted April 12, 2024 at 01:06AM by louis11
via reddit https://ift.tt/kXV2MGb
Fang-Pen's coding note
How I discovered a 9.8 critical security vulnerability in ZeroMQ with mostly pure luck and my two cents about xz backdoor
Fang-Pen Lin's blog about programming
Several vulnerabilities in LG WebOS. Chained, lead to RCE.
https://ift.tt/7fLsXu1
Submitted April 12, 2024 at 12:26PM by jaymzu
via reddit https://ift.tt/8mzjZQJ
https://ift.tt/7fLsXu1
Submitted April 12, 2024 at 12:26PM by jaymzu
via reddit https://ift.tt/8mzjZQJ
Bitdefender Labs
Vulnerabilities Identified in LG WebOS
As the creator of the world’s first smart home cybersecurity hub, Bitdefender regularly audits popular IoT hardware for vulnerabilities.
CVE 10.0 vulnerability in PAN-OS
https://ift.tt/Ya8ICZ0
Submitted April 12, 2024 at 02:59PM by kerubi
via reddit https://ift.tt/2mKqJI7
https://ift.tt/Ya8ICZ0
Submitted April 12, 2024 at 02:59PM by kerubi
via reddit https://ift.tt/2mKqJI7
Palo Alto Networks Product Security Assurance
CVE-2024-3400 PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurat...
CVE-2024-20670 Report - "New Outlook" NTLM Leak and File Execution
https://ift.tt/1dBI0ko
Submitted April 12, 2024 at 06:47PM by sottaly
via reddit https://ift.tt/0hPy3MU
https://ift.tt/1dBI0ko
Submitted April 12, 2024 at 06:47PM by sottaly
via reddit https://ift.tt/0hPy3MU
mpizzicaroli.github.io
Missfile://CVE-2024-20670
Before I start, I want to give a shout to the Charles Schwab Threat Intelligence team and our leadership for giving me the opportunity, time, and opinions to give this some legs. As the new Unstructured Hunt lead, this was a thrilling find.