IP.Board 'nexus' Blind SQLi and AdminCP RCE
https://ift.tt/LRWtx1H
Submitted April 13, 2024 at 02:19PM by eg1x
via reddit https://ift.tt/mDtXvCF
https://ift.tt/LRWtx1H
Submitted April 13, 2024 at 02:19PM by eg1x
via reddit https://ift.tt/mDtXvCF
SSD Secure Disclosure
SSD Advisory - IP.Board 'nexus' RCE and Blind SQLi - SSD Secure Disclosure
Summary IP.Board e-commerce plugin ‘nexus’ contains two security vulnerabilities that when combined can be used to trigger a pre-auth RCE in AdminCP. Credit An independent security researcher, Egidio Romano from Karma(In)Security, working with SSD Secure…
Security headers audit tool
https://ift.tt/MvG4hpN
Submitted April 13, 2024 at 04:36PM by SmokeyShark_777
via reddit https://ift.tt/4w6ftGp
https://ift.tt/MvG4hpN
Submitted April 13, 2024 at 04:36PM by SmokeyShark_777
via reddit https://ift.tt/4w6ftGp
GitHub
GitHub - trap-bytes/hauditor: hauditor is a tool designed to analyze the security headers returned by a web page.
hauditor is a tool designed to analyze the security headers returned by a web page. - trap-bytes/hauditor
Cloudflare Turnstile Update - Apache2 retirement · fin3ss3g0d/evilgophish@6bf9f29
https://ift.tt/7c5n4fa
Submitted April 14, 2024 at 06:30AM by fin3ss3g0d
via reddit https://ift.tt/xzBSwQP
https://ift.tt/7c5n4fa
Submitted April 14, 2024 at 06:30AM by fin3ss3g0d
via reddit https://ift.tt/xzBSwQP
GitHub
Cloudflare Turnstile Update - Apache2 retirement · fin3ss3g0d/evilgophish@6bf9f29
evilginx3 + gophish. Contribute to fin3ss3g0d/evilgophish development by creating an account on GitHub.
Chromium developing device bound session tokens to combat session token theft techniques
https://ift.tt/U9yEnQD
Submitted April 14, 2024 at 06:55AM by Secret-Inspection180
via reddit https://ift.tt/1TiPK2x
https://ift.tt/U9yEnQD
Submitted April 14, 2024 at 06:55AM by Secret-Inspection180
via reddit https://ift.tt/1TiPK2x
Chromium Blog
Fighting cookie theft using device bound sessions
Cookies – small files created by sites you visit – are fundamental to the modern web. They make your online experience easier by saving bro...
Spectre v2 Exploit - Branch History Injection
https://ift.tt/FrdYp1G
Submitted April 14, 2024 at 10:30AM by sunshine-and-sorrow
via reddit https://ift.tt/2eb8nFN
https://ift.tt/FrdYp1G
Submitted April 14, 2024 at 10:30AM by sunshine-and-sorrow
via reddit https://ift.tt/2eb8nFN
vusec
Branch History Injection - vusec
BHI (or Spectre-BHB) is a revival of cross-privilege Spectre-v2 attacks on modern systems deploying in-hardware defenses. And we have a very neat end-to-end exploit leaking arbitrary kernel memory on modern Intel CPUs to prove it
Sentinel - An investigations assistance / digital forensics tool built in Python
https://ift.tt/j4Z3JXV
Submitted April 14, 2024 at 10:03AM by TheMaestro810
via reddit https://ift.tt/hHA84Wj
https://ift.tt/j4Z3JXV
Submitted April 14, 2024 at 10:03AM by TheMaestro810
via reddit https://ift.tt/hHA84Wj
GitHub
GitHub - 6abd/horus: An OSINT / digital forensics tool built in Python
An OSINT / digital forensics tool built in Python. Contribute to 6abd/horus development by creating an account on GitHub.
Ultimate guide to becoming a SOC analyst in 2024
https://ift.tt/ZYT4KnM
Submitted April 14, 2024 at 06:19PM by 7331senb
via reddit https://ift.tt/GUZdwPM
https://ift.tt/ZYT4KnM
Submitted April 14, 2024 at 06:19PM by 7331senb
via reddit https://ift.tt/GUZdwPM
TryHackMe
TryHackMe | Cyber Security Training
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
Why black-box testing should be discouraged
https://ift.tt/Uer8HW9
Submitted April 15, 2024 at 03:15PM by security_aaudit
via reddit https://ift.tt/S0M8qBb
https://ift.tt/Uer8HW9
Submitted April 15, 2024 at 03:15PM by security_aaudit
via reddit https://ift.tt/S0M8qBb
baldur.dk
BALDUR. - Security Consultancy
Cyber Security Consultancy based in Denmark that specializes in offensive security.
Customised CVE Notifier based on keywords
https://ift.tt/gIyFVlA
Submitted April 15, 2024 at 07:30PM by shantanu14g
via reddit https://ift.tt/X2kiMOn
https://ift.tt/gIyFVlA
Submitted April 15, 2024 at 07:30PM by shantanu14g
via reddit https://ift.tt/X2kiMOn
GitHub
GitHub - dark-warlord14/CVENotifier: Customized CVE FEED Notifier
Customized CVE FEED Notifier. Contribute to dark-warlord14/CVENotifier development by creating an account on GitHub.
Invision Community Vulnerabilities Risk E-Commerce Websites
https://ift.tt/FyTts5a
Submitted April 15, 2024 at 07:48PM by eg1x
via reddit https://ift.tt/NQ7ruEO
https://ift.tt/FyTts5a
Submitted April 15, 2024 at 07:48PM by eg1x
via reddit https://ift.tt/NQ7ruEO
LHN
Invision Community Vulnerabilities Risk E-Commerce Websites
A security researcher spotted numerous vulnerabilities in the Invision Community software that risked the corresponding e-commerce websites. While the vendors patched one of the two flaws, the other still remains a zero-day despite public disclosure. Multiple
Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover | Datadog Security Labs
https://ift.tt/bGU3uMO
Submitted April 15, 2024 at 09:09PM by RedTermSession
via reddit https://ift.tt/W4zmGNo
https://ift.tt/bGU3uMO
Submitted April 15, 2024 at 09:09PM by RedTermSession
via reddit https://ift.tt/W4zmGNo
Datadoghq
Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover
Public disclosure of a vulnerability in AWS Amplify which exposed IAM roles associated with Amplify projects to be assumed by anyone in the world.
Fixing Typos and Breaching Microsoft’s Perimeter
https://ift.tt/TLjCvz5
Submitted April 16, 2024 at 01:17AM by MegaManSec2
via reddit https://ift.tt/zjtvGO3
https://ift.tt/TLjCvz5
Submitted April 16, 2024 at 01:17AM by MegaManSec2
via reddit https://ift.tt/zjtvGO3
John Stawinski IV
Fixing Typos and Breaching Microsoft’s Perimeter
Progressing through certifications, developing as a red teamer, breaking into Bug Bounty — many steps along my security journey have been difficult. One of the easiest things I’ve done was breach M…
PuTTY vulnerability vuln-p521-bias
https://ift.tt/BqlOfDb
Submitted April 16, 2024 at 01:57AM by louis11
via reddit https://ift.tt/tYzIqvK
https://ift.tt/BqlOfDb
Submitted April 16, 2024 at 01:57AM by louis11
via reddit https://ift.tt/tYzIqvK
[Article] Sniping at web applications to discover input-handling vulnerabilities
https://ift.tt/IfBW5C9
Submitted April 16, 2024 at 01:54AM by daindragon2
via reddit https://ift.tt/YWe2Zvt
https://ift.tt/IfBW5C9
Submitted April 16, 2024 at 01:54AM by daindragon2
via reddit https://ift.tt/YWe2Zvt
SpringerLink
Sniping at web applications to discover input-handling vulnerabilities
Journal of Computer Virology and Hacking Techniques - Web applications play a crucial role in modern businesses, offering various services and often exposing sensitive data that can be enticing to...
Horus - A digital forensics / investigations assistance tool built with Python by me (repost with changes made from feedback)
https://ift.tt/SFKWaqE
Submitted April 16, 2024 at 06:14AM by TheMaestro810
via reddit https://ift.tt/Uvo3CKj
https://ift.tt/SFKWaqE
Submitted April 16, 2024 at 06:14AM by TheMaestro810
via reddit https://ift.tt/Uvo3CKj
GitHub
GitHub - 6abd/horus: An OSINT / digital forensics tool built in Python
An OSINT / digital forensics tool built in Python. Contribute to 6abd/horus development by creating an account on GitHub.
Open RAN: Attacks against mobile operators from the outside in practice
https://ift.tt/ZlhiTOx
Submitted April 16, 2024 at 02:09PM by sebazzen
via reddit https://ift.tt/G463MAP
https://ift.tt/ZlhiTOx
Submitted April 16, 2024 at 02:09PM by sebazzen
via reddit https://ift.tt/G463MAP
Penthertz
Open RAN: Attacks against mobile operators from the outside in practice | PentHertz Blog
Wireless and hardware security expertise, Penetration tests, Mobile security, Trainings, Software-Defined Radio Hacking, Vulnerability research
Telegram Arbitrary Code Execution via InstantView | TeleSec
https://ift.tt/Grm85l2
Submitted April 16, 2024 at 04:20PM by davtur19
via reddit https://ift.tt/AJ0hVNx
https://ift.tt/Grm85l2
Submitted April 16, 2024 at 04:20PM by davtur19
via reddit https://ift.tt/AJ0hVNx
How to Reduce the Risk of Using External AI Models in Your SDLC
https://ift.tt/B4R6hNT
Submitted April 16, 2024 at 04:00PM by roy_6472
via reddit https://ift.tt/IgnqBdZ
https://ift.tt/B4R6hNT
Submitted April 16, 2024 at 04:00PM by roy_6472
via reddit https://ift.tt/IgnqBdZ
Legitsecurity
How to Reduce the Risk of Using External AI Models in Your SDLC
Legit Security | How to Reduce the Risk of Using External AI Models in Your SDLC. Understand how AI models add risk and how to address it.
“All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass
https://ift.tt/GFb9PN7
Submitted April 16, 2024 at 07:42PM by pwnplusplus
via reddit https://ift.tt/7LT9hb8
https://ift.tt/GFb9PN7
Submitted April 16, 2024 at 07:42PM by pwnplusplus
via reddit https://ift.tt/7LT9hb8
Medium
“All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass
Delinea Secret Server is a privileged access management (PAM) solution that helps organizations secure, manage, and monitor privileged…
Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400) - watchTowr Labs
https://ift.tt/HQIyVLS
Submitted April 16, 2024 at 07:34PM by dx7r__
via reddit https://ift.tt/DM15zdu
https://ift.tt/HQIyVLS
Submitted April 16, 2024 at 07:34PM by dx7r__
via reddit https://ift.tt/DM15zdu
watchTowr Labs
Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400)
Welcome to April 2024, again. We’re back, again.
Over the weekend, we were all greeted by now-familiar news—a nation-state was exploiting a “sophisticated” vulnerability for full compromise in yet another enterprise-grade SSLVPN device.
We’ve seen all the…
Over the weekend, we were all greeted by now-familiar news—a nation-state was exploiting a “sophisticated” vulnerability for full compromise in yet another enterprise-grade SSLVPN device.
We’ve seen all the…
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
https://ift.tt/X4F1evD
Submitted April 16, 2024 at 10:43PM by hackers_and_builders
via reddit https://ift.tt/jufMYV4
https://ift.tt/X4F1evD
Submitted April 16, 2024 at 10:43PM by hackers_and_builders
via reddit https://ift.tt/jufMYV4
Rhino Security Labs
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
This blog covers 2 vulnerabilities discovered by Rhino Security Labs in Kemp LoadMaster load balancers: CVE-2024-2448 and CVE-2024-2449.