“All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass
https://ift.tt/GFb9PN7
Submitted April 16, 2024 at 07:42PM by pwnplusplus
via reddit https://ift.tt/7LT9hb8
https://ift.tt/GFb9PN7
Submitted April 16, 2024 at 07:42PM by pwnplusplus
via reddit https://ift.tt/7LT9hb8
Medium
“All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass
Delinea Secret Server is a privileged access management (PAM) solution that helps organizations secure, manage, and monitor privileged…
Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400) - watchTowr Labs
https://ift.tt/HQIyVLS
Submitted April 16, 2024 at 07:34PM by dx7r__
via reddit https://ift.tt/DM15zdu
https://ift.tt/HQIyVLS
Submitted April 16, 2024 at 07:34PM by dx7r__
via reddit https://ift.tt/DM15zdu
watchTowr Labs
Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400)
Welcome to April 2024, again. We’re back, again.
Over the weekend, we were all greeted by now-familiar news—a nation-state was exploiting a “sophisticated” vulnerability for full compromise in yet another enterprise-grade SSLVPN device.
We’ve seen all the…
Over the weekend, we were all greeted by now-familiar news—a nation-state was exploiting a “sophisticated” vulnerability for full compromise in yet another enterprise-grade SSLVPN device.
We’ve seen all the…
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
https://ift.tt/X4F1evD
Submitted April 16, 2024 at 10:43PM by hackers_and_builders
via reddit https://ift.tt/jufMYV4
https://ift.tt/X4F1evD
Submitted April 16, 2024 at 10:43PM by hackers_and_builders
via reddit https://ift.tt/jufMYV4
Rhino Security Labs
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
This blog covers 2 vulnerabilities discovered by Rhino Security Labs in Kemp LoadMaster load balancers: CVE-2024-2448 and CVE-2024-2449.
A quick post on Chen’s algorithm
https://ift.tt/VF4s8cU
Submitted April 17, 2024 at 01:45AM by feross
via reddit https://ift.tt/7WcR6UF
https://ift.tt/VF4s8cU
Submitted April 17, 2024 at 01:45AM by feross
via reddit https://ift.tt/7WcR6UF
A Few Thoughts on Cryptographic Engineering
A quick post on Chen’s algorithm
Update (April 19): Yilei Chen announced the discovery of a bug in the algorithm, which he does not know how to fix. This was independently discovered by Hongxun Wu and Thomas Vidick. At present, th…
A quick post on Chen’s algorithm
https://ift.tt/Uz8kPSA
Submitted April 17, 2024 at 05:01AM by feross
via reddit https://ift.tt/DysHBLz
https://ift.tt/Uz8kPSA
Submitted April 17, 2024 at 05:01AM by feross
via reddit https://ift.tt/DysHBLz
A Few Thoughts on Cryptographic Engineering
A quick post on Chen’s algorithm
Update (April 19): Yilei Chen announced the discovery of a bug in the algorithm, which he does not know how to fix. This was independently discovered by Hongxun Wu and Thomas Vidick. At present, th…
[AI/ML Security] Scan and fix your LLM jailbreaks
https://ift.tt/floCsKQ
Submitted April 17, 2024 at 03:24PM by rukhrunnin
via reddit https://ift.tt/4UxLEGH
https://ift.tt/floCsKQ
Submitted April 17, 2024 at 03:24PM by rukhrunnin
via reddit https://ift.tt/4UxLEGH
mindgard.ai
Find and Mitigate an LLM Jailbreak - Mindgard
Learn how to identify, mitigate, and protect your AI/LLM from jailbreak attacks. This guide helps secure your AI applications from vulnerabilities and reputational damage.
An Obscure Actions Workflow Vulnerability in Google’s Flank
https://ift.tt/HBJXIUN
Submitted April 18, 2024 at 12:30AM by louis11
via reddit https://ift.tt/JT8IpOb
https://ift.tt/HBJXIUN
Submitted April 18, 2024 at 12:30AM by louis11
via reddit https://ift.tt/JT8IpOb
Adnan Khan's Blog
An Obscure Actions Workflow Vulnerability in Google's Flank
Introduction
Recently, I reported a “Pwn Request” vulnerability in Google’s Flank repository. Flank is described as a “Massively parallel Android and iOS test runner for Firebase Test Lab” and is an official Google open source project.
The vulnerability…
Recently, I reported a “Pwn Request” vulnerability in Google’s Flank repository. Flank is described as a “Massively parallel Android and iOS test runner for Firebase Test Lab” and is an official Google open source project.
The vulnerability…
Element Android CVE-2024-26131, CVE-2024-26132 - Never Take Intents From Strangers - Shielder
https://ift.tt/x2ZbNhU
Submitted April 18, 2024 at 02:56PM by smaury
via reddit https://ift.tt/x2ymBu5
https://ift.tt/x2ZbNhU
Submitted April 18, 2024 at 02:56PM by smaury
via reddit https://ift.tt/x2ymBu5
Shielder
Shielder - Element Android CVE-2024-26131, CVE-2024-26132 - Never Take Intents From Strangers
A writeup about two intent-based Android vulnerabilities CVE-2024-26131 and CVE-2024-26132 in Element (Matrix).
Breaking Custom Encryption Using Frida (Mobile Application Pentesting)
https://ift.tt/HWPUxoZ
Submitted April 18, 2024 at 04:22PM by Waste-Kick-6814
via reddit https://ift.tt/vy3Rueb
https://ift.tt/HWPUxoZ
Submitted April 18, 2024 at 04:22PM by Waste-Kick-6814
via reddit https://ift.tt/vy3Rueb
Cognisys Group Labs
Breaking Custom Encryption Using Frida (Mobile Application Pentesting)
Overview
Introducing Cloud Console Cartographer: An Open-Source Tool To Help Security Teams Easily Understand Log Events Generated by AWS Console Activity
https://ift.tt/HRKVnsO
Submitted April 18, 2024 at 07:32PM by permis0
via reddit https://ift.tt/8LipODK
https://ift.tt/HRKVnsO
Submitted April 18, 2024 at 07:32PM by permis0
via reddit https://ift.tt/8LipODK
permiso.io
Introducing Cloud Console Cartographer: An Open-Source Tool To Help Security Teams Easily Understand Log Events Generated by AWS…
Cloud Console Cartographer is an open-source tool that is built to help security teams distill the noise of events generated in cloud logs by activity in AWS console. Could Console Cartographer maps the myriad of events generated in cloud logs to a consolidated…
On Windows Registry by researcher who got 50+ CVEs there
https://ift.tt/o84AUJR
Submitted April 18, 2024 at 10:37PM by gynvael
via reddit https://ift.tt/SOIs5Qv
https://ift.tt/o84AUJR
Submitted April 18, 2024 at 10:37PM by gynvael
via reddit https://ift.tt/SOIs5Qv
Blogspot
The Windows Registry Adventure #1: Introduction and research results
Posted by Mateusz Jurczyk, Google Project Zero In the 20-month period between May 2022 and December 2023, I thoroughly audited the Win...
How Hackers Sniff Passwords
https://ift.tt/2szeT8l
Submitted April 19, 2024 at 04:12PM by danishlogon1
via reddit https://ift.tt/aQK2whT
https://ift.tt/2szeT8l
Submitted April 19, 2024 at 04:12PM by danishlogon1
via reddit https://ift.tt/aQK2whT
HackProofHacks
How Hackers Use Wireshark for Password Sniffing: What does Wireshark do? - HackProofHacks
Hey there, let's dive deep into the world of password sniffing and understand how hackers operate to steal sensitive information like login credentials.
EvilLsassTwin - PPL Bypass, Fast 12MB In-Memory Dumps
https://ift.tt/LgmEn0X
Submitted April 19, 2024 at 08:55PM by EphReborn
via reddit https://ift.tt/mdaKxTC
https://ift.tt/LgmEn0X
Submitted April 19, 2024 at 08:55PM by EphReborn
via reddit https://ift.tt/mdaKxTC
GitHub
Nimperiments/EvilLsassTwin at main · RePRGM/Nimperiments
Various one-off pentesting projects written in Nim. Updates happen on a whim. - RePRGM/Nimperiments
Backdooring Dotnet Applications
https://ift.tt/P9dauBO
Submitted April 19, 2024 at 11:57PM by lightgrains
via reddit https://ift.tt/RQTrLig
https://ift.tt/P9dauBO
Submitted April 19, 2024 at 11:57PM by lightgrains
via reddit https://ift.tt/RQTrLig
Chronicles of a F/OSS tool (Arachni)
https://ift.tt/yMnsJPe
Submitted April 20, 2024 at 02:33PM by tasos_laskos
via reddit https://ift.tt/jSgnsw6
https://ift.tt/yMnsJPe
Submitted April 20, 2024 at 02:33PM by tasos_laskos
via reddit https://ift.tt/jSgnsw6
Ecsypno
The Arachni Chronicles
A story of curiosity, experimentation, development, million euro deal, fraudsters, abandonment and revitalization.
From the inception of the F/OSS Arachni WebAppSec scanner to the opening of Ecsypno’s doors with its flagship product Codename SCNR.
From the inception of the F/OSS Arachni WebAppSec scanner to the opening of Ecsypno’s doors with its flagship product Codename SCNR.
Commercial successor to the Arachni WebAppSec scanner
https://ift.tt/N9uY1KS
Submitted April 20, 2024 at 05:59PM by tasos_laskos
via reddit https://ift.tt/UOK3GaN
https://ift.tt/N9uY1KS
Submitted April 20, 2024 at 05:59PM by tasos_laskos
via reddit https://ift.tt/UOK3GaN
Ecsypno
Codename SCNR
A modern, versatile, high-performace, modular, scalable and easy to integrate WebAppSec DAST scanner.
Codename RKN: The first WebApp attack surface mapper
https://ift.tt/4RLfoe0
Submitted April 20, 2024 at 09:25PM by tasos_laskos
via reddit https://ift.tt/Jt79oRy
https://ift.tt/4RLfoe0
Submitted April 20, 2024 at 09:25PM by tasos_laskos
via reddit https://ift.tt/Jt79oRy
Ecsypno
Codename RKN
Explore the Codename SCNR DAST/IAST web application security scanner and our F/OSS projects.
Introducing MalStatWare: Revolutionizing Malware Analysis with Automation! 💻🔒
https://ift.tt/tl3hyJa
Submitted April 21, 2024 at 06:51AM by OSTEsayed
via reddit https://ift.tt/zV4xqwj
https://ift.tt/tl3hyJa
Submitted April 21, 2024 at 06:51AM by OSTEsayed
via reddit https://ift.tt/zV4xqwj
GitHub
GitHub - OSTEsayed/OSTE-MalStatWare: MalStatWare automates malware analysis with Python. Extract key details like file size, type…
MalStatWare automates malware analysis with Python. Extract key details like file size, type, hash, path, and digital signature. It analyzes headers, APIs, and strings, giving quick insights for th...
AppView 1.0.0 is released! Instrument, Observe, Secure your deployments with no code modification.
https://appview.org/
Submitted April 21, 2024 at 10:57PM by algo9
via reddit https://ift.tt/QRNxk1p
https://appview.org/
Submitted April 21, 2024 at 10:57PM by algo9
via reddit https://ift.tt/QRNxk1p
appview.org
AppView is an open source instrumentation utility for any application, regardless of its runtime, with no code modification required. Collect only the data you need for full observability of your applications, systems and infrastructure.
How easy I made $$$$
https://ift.tt/upV9WoT
Submitted April 23, 2024 at 03:05PM by anasbetis94
via reddit https://ift.tt/DUw1Hca
https://ift.tt/upV9WoT
Submitted April 23, 2024 at 03:05PM by anasbetis94
via reddit https://ift.tt/DUw1Hca
Medium
How easy I made $$$$
Good morning!
An Analysis of the DHEat DoS Against SSH in Cloud Environments
https://ift.tt/RI2U05S
Submitted April 23, 2024 at 03:53PM by therealjoetesta
via reddit https://ift.tt/IJBnqDO
https://ift.tt/RI2U05S
Submitted April 23, 2024 at 03:53PM by therealjoetesta
via reddit https://ift.tt/IJBnqDO