Customised CVE Notifier based on keywords
https://ift.tt/gIyFVlA
Submitted April 15, 2024 at 07:30PM by shantanu14g
via reddit https://ift.tt/X2kiMOn
https://ift.tt/gIyFVlA
Submitted April 15, 2024 at 07:30PM by shantanu14g
via reddit https://ift.tt/X2kiMOn
GitHub
GitHub - dark-warlord14/CVENotifier: Customized CVE FEED Notifier
Customized CVE FEED Notifier. Contribute to dark-warlord14/CVENotifier development by creating an account on GitHub.
Invision Community Vulnerabilities Risk E-Commerce Websites
https://ift.tt/FyTts5a
Submitted April 15, 2024 at 07:48PM by eg1x
via reddit https://ift.tt/NQ7ruEO
https://ift.tt/FyTts5a
Submitted April 15, 2024 at 07:48PM by eg1x
via reddit https://ift.tt/NQ7ruEO
LHN
Invision Community Vulnerabilities Risk E-Commerce Websites
A security researcher spotted numerous vulnerabilities in the Invision Community software that risked the corresponding e-commerce websites. While the vendors patched one of the two flaws, the other still remains a zero-day despite public disclosure. Multiple
Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover | Datadog Security Labs
https://ift.tt/bGU3uMO
Submitted April 15, 2024 at 09:09PM by RedTermSession
via reddit https://ift.tt/W4zmGNo
https://ift.tt/bGU3uMO
Submitted April 15, 2024 at 09:09PM by RedTermSession
via reddit https://ift.tt/W4zmGNo
Datadoghq
Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover
Public disclosure of a vulnerability in AWS Amplify which exposed IAM roles associated with Amplify projects to be assumed by anyone in the world.
Fixing Typos and Breaching Microsoft’s Perimeter
https://ift.tt/TLjCvz5
Submitted April 16, 2024 at 01:17AM by MegaManSec2
via reddit https://ift.tt/zjtvGO3
https://ift.tt/TLjCvz5
Submitted April 16, 2024 at 01:17AM by MegaManSec2
via reddit https://ift.tt/zjtvGO3
John Stawinski IV
Fixing Typos and Breaching Microsoft’s Perimeter
Progressing through certifications, developing as a red teamer, breaking into Bug Bounty — many steps along my security journey have been difficult. One of the easiest things I’ve done was breach M…
PuTTY vulnerability vuln-p521-bias
https://ift.tt/BqlOfDb
Submitted April 16, 2024 at 01:57AM by louis11
via reddit https://ift.tt/tYzIqvK
https://ift.tt/BqlOfDb
Submitted April 16, 2024 at 01:57AM by louis11
via reddit https://ift.tt/tYzIqvK
[Article] Sniping at web applications to discover input-handling vulnerabilities
https://ift.tt/IfBW5C9
Submitted April 16, 2024 at 01:54AM by daindragon2
via reddit https://ift.tt/YWe2Zvt
https://ift.tt/IfBW5C9
Submitted April 16, 2024 at 01:54AM by daindragon2
via reddit https://ift.tt/YWe2Zvt
SpringerLink
Sniping at web applications to discover input-handling vulnerabilities
Journal of Computer Virology and Hacking Techniques - Web applications play a crucial role in modern businesses, offering various services and often exposing sensitive data that can be enticing to...
Horus - A digital forensics / investigations assistance tool built with Python by me (repost with changes made from feedback)
https://ift.tt/SFKWaqE
Submitted April 16, 2024 at 06:14AM by TheMaestro810
via reddit https://ift.tt/Uvo3CKj
https://ift.tt/SFKWaqE
Submitted April 16, 2024 at 06:14AM by TheMaestro810
via reddit https://ift.tt/Uvo3CKj
GitHub
GitHub - 6abd/horus: An OSINT / digital forensics tool built in Python
An OSINT / digital forensics tool built in Python. Contribute to 6abd/horus development by creating an account on GitHub.
Open RAN: Attacks against mobile operators from the outside in practice
https://ift.tt/ZlhiTOx
Submitted April 16, 2024 at 02:09PM by sebazzen
via reddit https://ift.tt/G463MAP
https://ift.tt/ZlhiTOx
Submitted April 16, 2024 at 02:09PM by sebazzen
via reddit https://ift.tt/G463MAP
Penthertz
Open RAN: Attacks against mobile operators from the outside in practice | PentHertz Blog
Wireless and hardware security expertise, Penetration tests, Mobile security, Trainings, Software-Defined Radio Hacking, Vulnerability research
Telegram Arbitrary Code Execution via InstantView | TeleSec
https://ift.tt/Grm85l2
Submitted April 16, 2024 at 04:20PM by davtur19
via reddit https://ift.tt/AJ0hVNx
https://ift.tt/Grm85l2
Submitted April 16, 2024 at 04:20PM by davtur19
via reddit https://ift.tt/AJ0hVNx
How to Reduce the Risk of Using External AI Models in Your SDLC
https://ift.tt/B4R6hNT
Submitted April 16, 2024 at 04:00PM by roy_6472
via reddit https://ift.tt/IgnqBdZ
https://ift.tt/B4R6hNT
Submitted April 16, 2024 at 04:00PM by roy_6472
via reddit https://ift.tt/IgnqBdZ
Legitsecurity
How to Reduce the Risk of Using External AI Models in Your SDLC
Legit Security | How to Reduce the Risk of Using External AI Models in Your SDLC. Understand how AI models add risk and how to address it.
“All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass
https://ift.tt/GFb9PN7
Submitted April 16, 2024 at 07:42PM by pwnplusplus
via reddit https://ift.tt/7LT9hb8
https://ift.tt/GFb9PN7
Submitted April 16, 2024 at 07:42PM by pwnplusplus
via reddit https://ift.tt/7LT9hb8
Medium
“All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass
Delinea Secret Server is a privileged access management (PAM) solution that helps organizations secure, manage, and monitor privileged…
Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400) - watchTowr Labs
https://ift.tt/HQIyVLS
Submitted April 16, 2024 at 07:34PM by dx7r__
via reddit https://ift.tt/DM15zdu
https://ift.tt/HQIyVLS
Submitted April 16, 2024 at 07:34PM by dx7r__
via reddit https://ift.tt/DM15zdu
watchTowr Labs
Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400)
Welcome to April 2024, again. We’re back, again.
Over the weekend, we were all greeted by now-familiar news—a nation-state was exploiting a “sophisticated” vulnerability for full compromise in yet another enterprise-grade SSLVPN device.
We’ve seen all the…
Over the weekend, we were all greeted by now-familiar news—a nation-state was exploiting a “sophisticated” vulnerability for full compromise in yet another enterprise-grade SSLVPN device.
We’ve seen all the…
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
https://ift.tt/X4F1evD
Submitted April 16, 2024 at 10:43PM by hackers_and_builders
via reddit https://ift.tt/jufMYV4
https://ift.tt/X4F1evD
Submitted April 16, 2024 at 10:43PM by hackers_and_builders
via reddit https://ift.tt/jufMYV4
Rhino Security Labs
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
This blog covers 2 vulnerabilities discovered by Rhino Security Labs in Kemp LoadMaster load balancers: CVE-2024-2448 and CVE-2024-2449.
A quick post on Chen’s algorithm
https://ift.tt/VF4s8cU
Submitted April 17, 2024 at 01:45AM by feross
via reddit https://ift.tt/7WcR6UF
https://ift.tt/VF4s8cU
Submitted April 17, 2024 at 01:45AM by feross
via reddit https://ift.tt/7WcR6UF
A Few Thoughts on Cryptographic Engineering
A quick post on Chen’s algorithm
Update (April 19): Yilei Chen announced the discovery of a bug in the algorithm, which he does not know how to fix. This was independently discovered by Hongxun Wu and Thomas Vidick. At present, th…
A quick post on Chen’s algorithm
https://ift.tt/Uz8kPSA
Submitted April 17, 2024 at 05:01AM by feross
via reddit https://ift.tt/DysHBLz
https://ift.tt/Uz8kPSA
Submitted April 17, 2024 at 05:01AM by feross
via reddit https://ift.tt/DysHBLz
A Few Thoughts on Cryptographic Engineering
A quick post on Chen’s algorithm
Update (April 19): Yilei Chen announced the discovery of a bug in the algorithm, which he does not know how to fix. This was independently discovered by Hongxun Wu and Thomas Vidick. At present, th…
[AI/ML Security] Scan and fix your LLM jailbreaks
https://ift.tt/floCsKQ
Submitted April 17, 2024 at 03:24PM by rukhrunnin
via reddit https://ift.tt/4UxLEGH
https://ift.tt/floCsKQ
Submitted April 17, 2024 at 03:24PM by rukhrunnin
via reddit https://ift.tt/4UxLEGH
mindgard.ai
Find and Mitigate an LLM Jailbreak - Mindgard
Learn how to identify, mitigate, and protect your AI/LLM from jailbreak attacks. This guide helps secure your AI applications from vulnerabilities and reputational damage.
An Obscure Actions Workflow Vulnerability in Google’s Flank
https://ift.tt/HBJXIUN
Submitted April 18, 2024 at 12:30AM by louis11
via reddit https://ift.tt/JT8IpOb
https://ift.tt/HBJXIUN
Submitted April 18, 2024 at 12:30AM by louis11
via reddit https://ift.tt/JT8IpOb
Adnan Khan's Blog
An Obscure Actions Workflow Vulnerability in Google's Flank
Introduction
Recently, I reported a “Pwn Request” vulnerability in Google’s Flank repository. Flank is described as a “Massively parallel Android and iOS test runner for Firebase Test Lab” and is an official Google open source project.
The vulnerability…
Recently, I reported a “Pwn Request” vulnerability in Google’s Flank repository. Flank is described as a “Massively parallel Android and iOS test runner for Firebase Test Lab” and is an official Google open source project.
The vulnerability…
Element Android CVE-2024-26131, CVE-2024-26132 - Never Take Intents From Strangers - Shielder
https://ift.tt/x2ZbNhU
Submitted April 18, 2024 at 02:56PM by smaury
via reddit https://ift.tt/x2ymBu5
https://ift.tt/x2ZbNhU
Submitted April 18, 2024 at 02:56PM by smaury
via reddit https://ift.tt/x2ymBu5
Shielder
Shielder - Element Android CVE-2024-26131, CVE-2024-26132 - Never Take Intents From Strangers
A writeup about two intent-based Android vulnerabilities CVE-2024-26131 and CVE-2024-26132 in Element (Matrix).
Breaking Custom Encryption Using Frida (Mobile Application Pentesting)
https://ift.tt/HWPUxoZ
Submitted April 18, 2024 at 04:22PM by Waste-Kick-6814
via reddit https://ift.tt/vy3Rueb
https://ift.tt/HWPUxoZ
Submitted April 18, 2024 at 04:22PM by Waste-Kick-6814
via reddit https://ift.tt/vy3Rueb
Cognisys Group Labs
Breaking Custom Encryption Using Frida (Mobile Application Pentesting)
Overview
Introducing Cloud Console Cartographer: An Open-Source Tool To Help Security Teams Easily Understand Log Events Generated by AWS Console Activity
https://ift.tt/HRKVnsO
Submitted April 18, 2024 at 07:32PM by permis0
via reddit https://ift.tt/8LipODK
https://ift.tt/HRKVnsO
Submitted April 18, 2024 at 07:32PM by permis0
via reddit https://ift.tt/8LipODK
permiso.io
Introducing Cloud Console Cartographer: An Open-Source Tool To Help Security Teams Easily Understand Log Events Generated by AWS…
Cloud Console Cartographer is an open-source tool that is built to help security teams distill the noise of events generated in cloud logs by activity in AWS console. Could Console Cartographer maps the myriad of events generated in cloud logs to a consolidated…
On Windows Registry by researcher who got 50+ CVEs there
https://ift.tt/o84AUJR
Submitted April 18, 2024 at 10:37PM by gynvael
via reddit https://ift.tt/SOIs5Qv
https://ift.tt/o84AUJR
Submitted April 18, 2024 at 10:37PM by gynvael
via reddit https://ift.tt/SOIs5Qv
Blogspot
The Windows Registry Adventure #1: Introduction and research results
Posted by Mateusz Jurczyk, Google Project Zero In the 20-month period between May 2022 and December 2023, I thoroughly audited the Win...