AppView 1.0.0 is released! Instrument, Observe, Secure your deployments with no code modification.
https://appview.org/
Submitted April 21, 2024 at 10:57PM by algo9
via reddit https://ift.tt/QRNxk1p
https://appview.org/
Submitted April 21, 2024 at 10:57PM by algo9
via reddit https://ift.tt/QRNxk1p
appview.org
AppView is an open source instrumentation utility for any application, regardless of its runtime, with no code modification required. Collect only the data you need for full observability of your applications, systems and infrastructure.
How easy I made $$$$
https://ift.tt/upV9WoT
Submitted April 23, 2024 at 03:05PM by anasbetis94
via reddit https://ift.tt/DUw1Hca
https://ift.tt/upV9WoT
Submitted April 23, 2024 at 03:05PM by anasbetis94
via reddit https://ift.tt/DUw1Hca
Medium
How easy I made $$$$
Good morning!
An Analysis of the DHEat DoS Against SSH in Cloud Environments
https://ift.tt/RI2U05S
Submitted April 23, 2024 at 03:53PM by therealjoetesta
via reddit https://ift.tt/IJBnqDO
https://ift.tt/RI2U05S
Submitted April 23, 2024 at 03:53PM by therealjoetesta
via reddit https://ift.tt/IJBnqDO
Dauthi - MDM Authentication Framework
https://ift.tt/3TwNu09
Submitted April 23, 2024 at 06:37PM by emptynebuli
via reddit https://ift.tt/gD19Mkl
https://ift.tt/3TwNu09
Submitted April 23, 2024 at 06:37PM by emptynebuli
via reddit https://ift.tt/gD19Mkl
GitHub
GitHub - emptynebuli/dauthi: dauthi is a tool that takes advantage of API functionality across a variety of MDM solutions to perform…
dauthi is a tool that takes advantage of API functionality across a variety of MDM solutions to perform user enumeration and single-factor authentication attacks. Additionally, the framework offers...
BlackBerry MDM Has Some Authentication Flaws
https://ift.tt/0fyQFcl
Submitted April 23, 2024 at 06:36PM by emptynebuli
via reddit https://ift.tt/Vq1v4iM
https://ift.tt/0fyQFcl
Submitted April 23, 2024 at 06:36PM by emptynebuli
via reddit https://ift.tt/Vq1v4iM
Into the Abyss
BlackBerry MDM Has Some Authentication Flaws
After detailing authentication issues with VMWare’s Airwatch and Ivanti’s MobileIron, I began to search other popular Mobile Device Management (MDM) tools for similar logic flaws. One of my primary targets for this effort was the BlackBerry MDM. Black who…
CVE-2024-2389: Command Injection Vulnerability In Progress Flowmon
https://ift.tt/jd0cmQ9
Submitted April 23, 2024 at 09:15PM by hackers_and_builders
via reddit https://ift.tt/tuT8r9m
https://ift.tt/jd0cmQ9
Submitted April 23, 2024 at 09:15PM by hackers_and_builders
via reddit https://ift.tt/tuT8r9m
Rhino Security Labs
CVE-2024-2389: Command Injection Vulnerability In Progress Flowmon
CVE-2024-2389 unauthenticated command injection vulnerability found in Progress Flowmon server.
Nation-State Threat Actors Renew Publications to npm
https://ift.tt/bIdKWvh
Submitted April 24, 2024 at 07:21AM by louis11
via reddit https://ift.tt/BPHcKZI
https://ift.tt/bIdKWvh
Submitted April 24, 2024 at 07:21AM by louis11
via reddit https://ift.tt/BPHcKZI
Phylum Research | Software Supply Chain Security
Nation-State Threat Actors Renew Publications to npm | Phylum
North Korean threat actors return to npm with a new attack. Phylum detects malicious packages targeting macOS and Windows. Protect your software supply chain.
SAP Threat Modeling Tool - Open Source Software
https://ift.tt/9Ea30zP
Submitted April 24, 2024 at 11:17AM by vah_13
via reddit https://ift.tt/H5cuMUn
https://ift.tt/9Ea30zP
Submitted April 24, 2024 at 11:17AM by vah_13
via reddit https://ift.tt/H5cuMUn
GitHub
GitHub - redrays-io/SAP-Threat-Modeling: The SAP Threat Modeling Tool is an on-premises open-source web application designed to…
The SAP Threat Modeling Tool is an on-premises open-source web application designed to analyze and visualize connections between SAP systems, helping users identify security risks and vulnerabiliti...
ASPJinjaObfuscator: Heavily obfuscated ASP web shell generation tool.
https://ift.tt/gTDyrl7
Submitted April 24, 2024 at 06:04PM by fin3ss3g0d
via reddit https://ift.tt/eQCd3iT
https://ift.tt/gTDyrl7
Submitted April 24, 2024 at 06:04PM by fin3ss3g0d
via reddit https://ift.tt/eQCd3iT
GitHub
GitHub - fin3ss3g0d/ASPJinjaObfuscator: Heavily obfuscated ASP web shell generation tool.
Heavily obfuscated ASP web shell generation tool. Contribute to fin3ss3g0d/ASPJinjaObfuscator development by creating an account on GitHub.
18 vulnerabilities in Brocade SANnav
https://ift.tt/aeTQxjV
Submitted April 24, 2024 at 08:07PM by PierreKimSec
via reddit https://ift.tt/Vydlz3x
https://ift.tt/aeTQxjV
Submitted April 24, 2024 at 08:07PM by PierreKimSec
via reddit https://ift.tt/Vydlz3x
XZ Utils Rundown: What We Learned and What To Do Next
https://ift.tt/kNRj02O
Submitted April 24, 2024 at 11:15PM by Offsec_Community
via reddit https://ift.tt/0lfT4oU
https://ift.tt/kNRj02O
Submitted April 24, 2024 at 11:15PM by Offsec_Community
via reddit https://ift.tt/0lfT4oU
Offsec
XZ Utils Rundown: What We Learned and What To Do Next
Join OffSec's own Jeremiah Roe, Advisory CISO and Jeremy (Harbinger) Miller, Senior Content Strategy & Development Manager, as we provide a status update on what we know about this incident so far, some lessons we've already learned, and what you and your…
Cisco ASA exploit in the wild.
https://ift.tt/6znQw7m
Submitted April 25, 2024 at 12:13AM by MrSanford
via reddit https://ift.tt/y8D5qu1
https://ift.tt/6znQw7m
Submitted April 25, 2024 at 12:13AM by MrSanford
via reddit https://ift.tt/y8D5qu1
Cisco Talos Blog
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVEs related to the event. We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
I got a 10% discount ticket for 1 Typhooncon training
https://ift.tt/Ln32v6d
Submitted April 25, 2024 at 04:04AM by Status_Resolve2971
via reddit https://ift.tt/acFu7zY
https://ift.tt/Ln32v6d
Submitted April 25, 2024 at 04:04AM by Status_Resolve2971
via reddit https://ift.tt/acFu7zY
Eventbrite
TyphoonCon 2024
TyphoonCon conference and training focus on highly technical offensive security topics.
The event is organized by SSD Secure Disclosure.
The event is organized by SSD Secure Disclosure.
Literal Security Measures
https://ift.tt/s8SkPMH
Submitted April 25, 2024 at 12:31PM by samsbp97
via reddit https://ift.tt/Z2aJYQS
https://ift.tt/s8SkPMH
Submitted April 25, 2024 at 12:31PM by samsbp97
via reddit https://ift.tt/Z2aJYQS
Random Access Memory
Literal Security Measures
security measures, policies that we do for literal namesakes
Exploring Vulnerabilities in Embedded Devices: A Case Study of an IP Phone
https://ift.tt/Fm8V491
Submitted April 25, 2024 at 04:10PM by security_aaudit
via reddit https://ift.tt/SAE0i7G
https://ift.tt/Fm8V491
Submitted April 25, 2024 at 04:10PM by security_aaudit
via reddit https://ift.tt/SAE0i7G
baldur.dk
BALDUR. - Security Consultancy
How to achieve a working remote code execution exploit in an embedded phone without any previous access.
Multiple Vulnerabilities in Open Devin (Autonomous AI Software Engineer)
https://ift.tt/8qDylEF
Submitted April 25, 2024 at 07:54PM by Standard_Arm_4476
via reddit https://ift.tt/X7GIwxd
https://ift.tt/8qDylEF
Submitted April 25, 2024 at 07:54PM by Standard_Arm_4476
via reddit https://ift.tt/X7GIwxd
Moriarty v1.2 has been released!
https://ift.tt/sELxvpo
Submitted April 25, 2024 at 08:42PM by Hubble_BC_Security
via reddit https://ift.tt/GFtqsSi
https://ift.tt/sELxvpo
Submitted April 25, 2024 at 08:42PM by Hubble_BC_Security
via reddit https://ift.tt/GFtqsSi
GitHub
GitHub - BC-SECURITY/Moriarty: Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential…
Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in Windows environments. - GitHub - BC-SECURITY/Moriarty: Mor...
How MFA Is Falling Short
https://ift.tt/gPR3mTU
Submitted April 25, 2024 at 09:29PM by KolideKenny
via reddit https://ift.tt/ok54POr
https://ift.tt/gPR3mTU
Submitted April 25, 2024 at 09:29PM by KolideKenny
via reddit https://ift.tt/ok54POr
1Password
How MFA is falling short | 1Password
MFA was supposed to solve our security problems, so why do attackers keep getting around it?
Coverage Guided Fuzzing - Extending Instrumentation to Hunt Down Bugs Faster! - Include Security Research Blog
https://ift.tt/ugdZ27a
Submitted April 26, 2024 at 12:42AM by 907jessejones
via reddit https://ift.tt/UXeo503
https://ift.tt/ugdZ27a
Submitted April 26, 2024 at 12:42AM by 907jessejones
via reddit https://ift.tt/UXeo503
Include Security Research Blog
Coverage Guided Fuzzing - Extending Instrumentation to Hunt Down Bugs Faster! - Include Security Research Blog
In our latest blog post, we introduce coverage-guided fuzzing with a brief denoscription of fundamentals and a demonstration of how modifying program instrumentation can be used to more easily track down the source of vulnerabilities and identify interesting…
CVE-2024-29417: a security software vulnerability allows for privilege escalation or auth bypass, even when Windows is locked.
https://ift.tt/8JehnIb
Submitted April 26, 2024 at 12:49AM by Zealousideal_Tip2086
via reddit https://ift.tt/ive0lDA
https://ift.tt/8JehnIb
Submitted April 26, 2024 at 12:49AM by Zealousideal_Tip2086
via reddit https://ift.tt/ive0lDA
PRIDE Security Blog
Horacius (IAM) - Local privilege escalation, even without a Windows account.
Unauthenticated privilege escalation in Horacius (Identity and Access Management) - CVE-2024-29417: a security software vulnerability allows for local privilege escalation, even when Windows is locked.
Disclaimer
This Security Advisory is provided on an…
Disclaimer
This Security Advisory is provided on an…
Postman users are exposing Thousands of live Passwords/API keys
https://ift.tt/MWEoVLK
Submitted April 26, 2024 at 02:36AM by wifihack
via reddit https://ift.tt/E6xzOuA
https://ift.tt/MWEoVLK
Submitted April 26, 2024 at 02:36AM by wifihack
via reddit https://ift.tt/E6xzOuA
Trufflesecurity
(The) Postman Carries Lots of Secrets ◆ Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a…