Several vulnerabilities in LG WebOS. Chained, lead to RCE.
https://ift.tt/7fLsXu1
Submitted April 12, 2024 at 12:26PM by jaymzu
via reddit https://ift.tt/8mzjZQJ
https://ift.tt/7fLsXu1
Submitted April 12, 2024 at 12:26PM by jaymzu
via reddit https://ift.tt/8mzjZQJ
Bitdefender Labs
Vulnerabilities Identified in LG WebOS
As the creator of the world’s first smart home cybersecurity hub, Bitdefender regularly audits popular IoT hardware for vulnerabilities.
CVE 10.0 vulnerability in PAN-OS
https://ift.tt/Ya8ICZ0
Submitted April 12, 2024 at 02:59PM by kerubi
via reddit https://ift.tt/2mKqJI7
https://ift.tt/Ya8ICZ0
Submitted April 12, 2024 at 02:59PM by kerubi
via reddit https://ift.tt/2mKqJI7
Palo Alto Networks Product Security Assurance
CVE-2024-3400 PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurat...
CVE-2024-20670 Report - "New Outlook" NTLM Leak and File Execution
https://ift.tt/1dBI0ko
Submitted April 12, 2024 at 06:47PM by sottaly
via reddit https://ift.tt/0hPy3MU
https://ift.tt/1dBI0ko
Submitted April 12, 2024 at 06:47PM by sottaly
via reddit https://ift.tt/0hPy3MU
mpizzicaroli.github.io
Missfile://CVE-2024-20670
Before I start, I want to give a shout to the Charles Schwab Threat Intelligence team and our leadership for giving me the opportunity, time, and opinions to give this some legs. As the new Unstructured Hunt lead, this was a thrilling find.
The Hidden Economy of Open Source Software
https://ift.tt/FTnG8Uu
Submitted April 12, 2024 at 08:05PM by Hallow_Rose
via reddit https://ift.tt/P4KsH8t
https://ift.tt/FTnG8Uu
Submitted April 12, 2024 at 08:05PM by Hallow_Rose
via reddit https://ift.tt/P4KsH8t
Sysdig
The Hidden Economy of Open Source Software | Sysdig
The recent discovery of a backdoor in XZ Utils (CVE-2024-3094) underscores the importance of open-source software security.
Unpacking the Fuxnet Malware
https://ift.tt/JRsdAUL
Submitted April 12, 2024 at 11:54PM by derp6996
via reddit https://ift.tt/49Lgw87
https://ift.tt/JRsdAUL
Submitted April 12, 2024 at 11:54PM by derp6996
via reddit https://ift.tt/49Lgw87
Claroty
Unpacking the Blackjack Group's Fuxnet Malware
Claroty Team82 has analyzed the Fuxnet malware developed by the Blackjack hacking group and used in an cyberattack against Moscow-based Moscollector, a sewage and communication infrastructure company.
A Roadmap to Becoming an Ethical Hacker
https://ift.tt/68BQKSH
Submitted April 13, 2024 at 02:19AM by danishlogon1
via reddit https://ift.tt/LUDVaOH
https://ift.tt/68BQKSH
Submitted April 13, 2024 at 02:19AM by danishlogon1
via reddit https://ift.tt/LUDVaOH
HackProofHacks
Ethical Hacking and Cybersecurity - HackproofHacks
Join us for in-depth ethical hacking and cybersecurity tutorials. Get hands-on with step-by-step demonstrations and level up your hacking skills.
DES/3DES algorithm illustrated
https://ift.tt/1eZJF5s
Submitted April 13, 2024 at 05:49AM by tootac
via reddit https://ift.tt/hRpD486
https://ift.tt/1eZJF5s
Submitted April 13, 2024 at 05:49AM by tootac
via reddit https://ift.tt/hRpD486
IBM QRadar - When The Attacker Controls Your Security Stack (CVE-2022-26377) - watchTowr Labs
https://ift.tt/85nG1Nf
Submitted April 13, 2024 at 09:49AM by dx7r__
via reddit https://ift.tt/zNIHlXM
https://ift.tt/85nG1Nf
Submitted April 13, 2024 at 09:49AM by dx7r__
via reddit https://ift.tt/zNIHlXM
watchTowr Labs
IBM QRadar - When The Attacker Controls Your Security Stack (CVE-2022-26377)
Welcome to April 2024.
A depressing year so far - we've seen critical vulnerabilities across a wide range of enterprise software stacks.
In addition, we've seen surreptitious and patient threat actors light our industry on fire with slowly introduced backdoors…
A depressing year so far - we've seen critical vulnerabilities across a wide range of enterprise software stacks.
In addition, we've seen surreptitious and patient threat actors light our industry on fire with slowly introduced backdoors…
Seccomp Internals - pt.1
https://ift.tt/NoK8Ya7
Submitted April 13, 2024 at 12:36PM by amitschenedel
via reddit https://ift.tt/giT40mx
https://ift.tt/NoK8Ya7
Submitted April 13, 2024 at 12:36PM by amitschenedel
via reddit https://ift.tt/giT40mx
ARMO
Seccomp: Enhance Security for Linux Applications
In this blog, we will explore the internals of seccomp, including its architecture, key concepts, and practical applications
IP.Board 'nexus' Blind SQLi and AdminCP RCE
https://ift.tt/LRWtx1H
Submitted April 13, 2024 at 02:19PM by eg1x
via reddit https://ift.tt/mDtXvCF
https://ift.tt/LRWtx1H
Submitted April 13, 2024 at 02:19PM by eg1x
via reddit https://ift.tt/mDtXvCF
SSD Secure Disclosure
SSD Advisory - IP.Board 'nexus' RCE and Blind SQLi - SSD Secure Disclosure
Summary IP.Board e-commerce plugin ‘nexus’ contains two security vulnerabilities that when combined can be used to trigger a pre-auth RCE in AdminCP. Credit An independent security researcher, Egidio Romano from Karma(In)Security, working with SSD Secure…
Security headers audit tool
https://ift.tt/MvG4hpN
Submitted April 13, 2024 at 04:36PM by SmokeyShark_777
via reddit https://ift.tt/4w6ftGp
https://ift.tt/MvG4hpN
Submitted April 13, 2024 at 04:36PM by SmokeyShark_777
via reddit https://ift.tt/4w6ftGp
GitHub
GitHub - trap-bytes/hauditor: hauditor is a tool designed to analyze the security headers returned by a web page.
hauditor is a tool designed to analyze the security headers returned by a web page. - trap-bytes/hauditor
Cloudflare Turnstile Update - Apache2 retirement · fin3ss3g0d/evilgophish@6bf9f29
https://ift.tt/7c5n4fa
Submitted April 14, 2024 at 06:30AM by fin3ss3g0d
via reddit https://ift.tt/xzBSwQP
https://ift.tt/7c5n4fa
Submitted April 14, 2024 at 06:30AM by fin3ss3g0d
via reddit https://ift.tt/xzBSwQP
GitHub
Cloudflare Turnstile Update - Apache2 retirement · fin3ss3g0d/evilgophish@6bf9f29
evilginx3 + gophish. Contribute to fin3ss3g0d/evilgophish development by creating an account on GitHub.
Chromium developing device bound session tokens to combat session token theft techniques
https://ift.tt/U9yEnQD
Submitted April 14, 2024 at 06:55AM by Secret-Inspection180
via reddit https://ift.tt/1TiPK2x
https://ift.tt/U9yEnQD
Submitted April 14, 2024 at 06:55AM by Secret-Inspection180
via reddit https://ift.tt/1TiPK2x
Chromium Blog
Fighting cookie theft using device bound sessions
Cookies – small files created by sites you visit – are fundamental to the modern web. They make your online experience easier by saving bro...
Spectre v2 Exploit - Branch History Injection
https://ift.tt/FrdYp1G
Submitted April 14, 2024 at 10:30AM by sunshine-and-sorrow
via reddit https://ift.tt/2eb8nFN
https://ift.tt/FrdYp1G
Submitted April 14, 2024 at 10:30AM by sunshine-and-sorrow
via reddit https://ift.tt/2eb8nFN
vusec
Branch History Injection - vusec
BHI (or Spectre-BHB) is a revival of cross-privilege Spectre-v2 attacks on modern systems deploying in-hardware defenses. And we have a very neat end-to-end exploit leaking arbitrary kernel memory on modern Intel CPUs to prove it
Sentinel - An investigations assistance / digital forensics tool built in Python
https://ift.tt/j4Z3JXV
Submitted April 14, 2024 at 10:03AM by TheMaestro810
via reddit https://ift.tt/hHA84Wj
https://ift.tt/j4Z3JXV
Submitted April 14, 2024 at 10:03AM by TheMaestro810
via reddit https://ift.tt/hHA84Wj
GitHub
GitHub - 6abd/horus: An OSINT / digital forensics tool built in Python
An OSINT / digital forensics tool built in Python. Contribute to 6abd/horus development by creating an account on GitHub.
Ultimate guide to becoming a SOC analyst in 2024
https://ift.tt/ZYT4KnM
Submitted April 14, 2024 at 06:19PM by 7331senb
via reddit https://ift.tt/GUZdwPM
https://ift.tt/ZYT4KnM
Submitted April 14, 2024 at 06:19PM by 7331senb
via reddit https://ift.tt/GUZdwPM
TryHackMe
TryHackMe | Cyber Security Training
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
Why black-box testing should be discouraged
https://ift.tt/Uer8HW9
Submitted April 15, 2024 at 03:15PM by security_aaudit
via reddit https://ift.tt/S0M8qBb
https://ift.tt/Uer8HW9
Submitted April 15, 2024 at 03:15PM by security_aaudit
via reddit https://ift.tt/S0M8qBb
baldur.dk
BALDUR. - Security Consultancy
Cyber Security Consultancy based in Denmark that specializes in offensive security.
Customised CVE Notifier based on keywords
https://ift.tt/gIyFVlA
Submitted April 15, 2024 at 07:30PM by shantanu14g
via reddit https://ift.tt/X2kiMOn
https://ift.tt/gIyFVlA
Submitted April 15, 2024 at 07:30PM by shantanu14g
via reddit https://ift.tt/X2kiMOn
GitHub
GitHub - dark-warlord14/CVENotifier: Customized CVE FEED Notifier
Customized CVE FEED Notifier. Contribute to dark-warlord14/CVENotifier development by creating an account on GitHub.
Invision Community Vulnerabilities Risk E-Commerce Websites
https://ift.tt/FyTts5a
Submitted April 15, 2024 at 07:48PM by eg1x
via reddit https://ift.tt/NQ7ruEO
https://ift.tt/FyTts5a
Submitted April 15, 2024 at 07:48PM by eg1x
via reddit https://ift.tt/NQ7ruEO
LHN
Invision Community Vulnerabilities Risk E-Commerce Websites
A security researcher spotted numerous vulnerabilities in the Invision Community software that risked the corresponding e-commerce websites. While the vendors patched one of the two flaws, the other still remains a zero-day despite public disclosure. Multiple
Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover | Datadog Security Labs
https://ift.tt/bGU3uMO
Submitted April 15, 2024 at 09:09PM by RedTermSession
via reddit https://ift.tt/W4zmGNo
https://ift.tt/bGU3uMO
Submitted April 15, 2024 at 09:09PM by RedTermSession
via reddit https://ift.tt/W4zmGNo
Datadoghq
Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover
Public disclosure of a vulnerability in AWS Amplify which exposed IAM roles associated with Amplify projects to be assumed by anyone in the world.
Fixing Typos and Breaching Microsoft’s Perimeter
https://ift.tt/TLjCvz5
Submitted April 16, 2024 at 01:17AM by MegaManSec2
via reddit https://ift.tt/zjtvGO3
https://ift.tt/TLjCvz5
Submitted April 16, 2024 at 01:17AM by MegaManSec2
via reddit https://ift.tt/zjtvGO3
John Stawinski IV
Fixing Typos and Breaching Microsoft’s Perimeter
Progressing through certifications, developing as a red teamer, breaking into Bug Bounty — many steps along my security journey have been difficult. One of the easiest things I’ve done was breach M…