SAP Threat Modeling Tool - Open Source Software
https://ift.tt/9Ea30zP
Submitted April 24, 2024 at 11:17AM by vah_13
via reddit https://ift.tt/H5cuMUn
https://ift.tt/9Ea30zP
Submitted April 24, 2024 at 11:17AM by vah_13
via reddit https://ift.tt/H5cuMUn
GitHub
GitHub - redrays-io/SAP-Threat-Modeling: The SAP Threat Modeling Tool is an on-premises open-source web application designed to…
The SAP Threat Modeling Tool is an on-premises open-source web application designed to analyze and visualize connections between SAP systems, helping users identify security risks and vulnerabiliti...
ASPJinjaObfuscator: Heavily obfuscated ASP web shell generation tool.
https://ift.tt/gTDyrl7
Submitted April 24, 2024 at 06:04PM by fin3ss3g0d
via reddit https://ift.tt/eQCd3iT
https://ift.tt/gTDyrl7
Submitted April 24, 2024 at 06:04PM by fin3ss3g0d
via reddit https://ift.tt/eQCd3iT
GitHub
GitHub - fin3ss3g0d/ASPJinjaObfuscator: Heavily obfuscated ASP web shell generation tool.
Heavily obfuscated ASP web shell generation tool. Contribute to fin3ss3g0d/ASPJinjaObfuscator development by creating an account on GitHub.
18 vulnerabilities in Brocade SANnav
https://ift.tt/aeTQxjV
Submitted April 24, 2024 at 08:07PM by PierreKimSec
via reddit https://ift.tt/Vydlz3x
https://ift.tt/aeTQxjV
Submitted April 24, 2024 at 08:07PM by PierreKimSec
via reddit https://ift.tt/Vydlz3x
XZ Utils Rundown: What We Learned and What To Do Next
https://ift.tt/kNRj02O
Submitted April 24, 2024 at 11:15PM by Offsec_Community
via reddit https://ift.tt/0lfT4oU
https://ift.tt/kNRj02O
Submitted April 24, 2024 at 11:15PM by Offsec_Community
via reddit https://ift.tt/0lfT4oU
Offsec
XZ Utils Rundown: What We Learned and What To Do Next
Join OffSec's own Jeremiah Roe, Advisory CISO and Jeremy (Harbinger) Miller, Senior Content Strategy & Development Manager, as we provide a status update on what we know about this incident so far, some lessons we've already learned, and what you and your…
Cisco ASA exploit in the wild.
https://ift.tt/6znQw7m
Submitted April 25, 2024 at 12:13AM by MrSanford
via reddit https://ift.tt/y8D5qu1
https://ift.tt/6znQw7m
Submitted April 25, 2024 at 12:13AM by MrSanford
via reddit https://ift.tt/y8D5qu1
Cisco Talos Blog
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVEs related to the event. We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
I got a 10% discount ticket for 1 Typhooncon training
https://ift.tt/Ln32v6d
Submitted April 25, 2024 at 04:04AM by Status_Resolve2971
via reddit https://ift.tt/acFu7zY
https://ift.tt/Ln32v6d
Submitted April 25, 2024 at 04:04AM by Status_Resolve2971
via reddit https://ift.tt/acFu7zY
Eventbrite
TyphoonCon 2024
TyphoonCon conference and training focus on highly technical offensive security topics.
The event is organized by SSD Secure Disclosure.
The event is organized by SSD Secure Disclosure.
Literal Security Measures
https://ift.tt/s8SkPMH
Submitted April 25, 2024 at 12:31PM by samsbp97
via reddit https://ift.tt/Z2aJYQS
https://ift.tt/s8SkPMH
Submitted April 25, 2024 at 12:31PM by samsbp97
via reddit https://ift.tt/Z2aJYQS
Random Access Memory
Literal Security Measures
security measures, policies that we do for literal namesakes
Exploring Vulnerabilities in Embedded Devices: A Case Study of an IP Phone
https://ift.tt/Fm8V491
Submitted April 25, 2024 at 04:10PM by security_aaudit
via reddit https://ift.tt/SAE0i7G
https://ift.tt/Fm8V491
Submitted April 25, 2024 at 04:10PM by security_aaudit
via reddit https://ift.tt/SAE0i7G
baldur.dk
BALDUR. - Security Consultancy
How to achieve a working remote code execution exploit in an embedded phone without any previous access.
Multiple Vulnerabilities in Open Devin (Autonomous AI Software Engineer)
https://ift.tt/8qDylEF
Submitted April 25, 2024 at 07:54PM by Standard_Arm_4476
via reddit https://ift.tt/X7GIwxd
https://ift.tt/8qDylEF
Submitted April 25, 2024 at 07:54PM by Standard_Arm_4476
via reddit https://ift.tt/X7GIwxd
Moriarty v1.2 has been released!
https://ift.tt/sELxvpo
Submitted April 25, 2024 at 08:42PM by Hubble_BC_Security
via reddit https://ift.tt/GFtqsSi
https://ift.tt/sELxvpo
Submitted April 25, 2024 at 08:42PM by Hubble_BC_Security
via reddit https://ift.tt/GFtqsSi
GitHub
GitHub - BC-SECURITY/Moriarty: Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential…
Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in Windows environments. - GitHub - BC-SECURITY/Moriarty: Mor...
How MFA Is Falling Short
https://ift.tt/gPR3mTU
Submitted April 25, 2024 at 09:29PM by KolideKenny
via reddit https://ift.tt/ok54POr
https://ift.tt/gPR3mTU
Submitted April 25, 2024 at 09:29PM by KolideKenny
via reddit https://ift.tt/ok54POr
1Password
How MFA is falling short | 1Password
MFA was supposed to solve our security problems, so why do attackers keep getting around it?
Coverage Guided Fuzzing - Extending Instrumentation to Hunt Down Bugs Faster! - Include Security Research Blog
https://ift.tt/ugdZ27a
Submitted April 26, 2024 at 12:42AM by 907jessejones
via reddit https://ift.tt/UXeo503
https://ift.tt/ugdZ27a
Submitted April 26, 2024 at 12:42AM by 907jessejones
via reddit https://ift.tt/UXeo503
Include Security Research Blog
Coverage Guided Fuzzing - Extending Instrumentation to Hunt Down Bugs Faster! - Include Security Research Blog
In our latest blog post, we introduce coverage-guided fuzzing with a brief denoscription of fundamentals and a demonstration of how modifying program instrumentation can be used to more easily track down the source of vulnerabilities and identify interesting…
CVE-2024-29417: a security software vulnerability allows for privilege escalation or auth bypass, even when Windows is locked.
https://ift.tt/8JehnIb
Submitted April 26, 2024 at 12:49AM by Zealousideal_Tip2086
via reddit https://ift.tt/ive0lDA
https://ift.tt/8JehnIb
Submitted April 26, 2024 at 12:49AM by Zealousideal_Tip2086
via reddit https://ift.tt/ive0lDA
PRIDE Security Blog
Horacius (IAM) - Local privilege escalation, even without a Windows account.
Unauthenticated privilege escalation in Horacius (Identity and Access Management) - CVE-2024-29417: a security software vulnerability allows for local privilege escalation, even when Windows is locked.
Disclaimer
This Security Advisory is provided on an…
Disclaimer
This Security Advisory is provided on an…
Postman users are exposing Thousands of live Passwords/API keys
https://ift.tt/MWEoVLK
Submitted April 26, 2024 at 02:36AM by wifihack
via reddit https://ift.tt/E6xzOuA
https://ift.tt/MWEoVLK
Submitted April 26, 2024 at 02:36AM by wifihack
via reddit https://ift.tt/E6xzOuA
Trufflesecurity
(The) Postman Carries Lots of Secrets ◆ Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a…
Dependency Confusion Vulnerability Found in an Archived Apache Project
https://ift.tt/IBbxV5T
Submitted April 26, 2024 at 03:09AM by roy_6472
via reddit https://ift.tt/4QPteAZ
https://ift.tt/IBbxV5T
Submitted April 26, 2024 at 03:09AM by roy_6472
via reddit https://ift.tt/4QPteAZ
Legitsecurity
Dependency Confusion Vulnerability Found in an Archived Apache Project
Legit Security | Dependency Confusion Vulnerability Found in an Archived Apache Project. Get details on the Legit research team's discovery of a dependency confusion vulnerability in an archived Apache project.
Seeking research study participants! SOC analysts and managers that experienced SolarWinds, Log4Shell or both.
https://ift.tt/d1Yhza5
Submitted April 26, 2024 at 07:29PM by welp_that_happened
via reddit https://ift.tt/BflEHNL
https://ift.tt/d1Yhza5
Submitted April 26, 2024 at 07:29PM by welp_that_happened
via reddit https://ift.tt/BflEHNL
Office
Please fill out this form
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining - Avast Threat Labs
https://ift.tt/Z5n6bxY
Submitted April 27, 2024 at 01:33AM by MegaManSec2
via reddit https://ift.tt/vh495nW
https://ift.tt/Z5n6bxY
Submitted April 27, 2024 at 01:33AM by MegaManSec2
via reddit https://ift.tt/vh495nW
Gendigital
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
Malware Campaign Exploiting Antivirus Updates
Automating API Vulnerabilities Using Postman Workflows
https://ift.tt/iyOEDwH
Submitted April 27, 2024 at 11:39PM by HayMiz
via reddit https://ift.tt/Ij4RpZm
https://ift.tt/iyOEDwH
Submitted April 27, 2024 at 11:39PM by HayMiz
via reddit https://ift.tt/Ij4RpZm
haymiz@kali:~/blog$
Automating API Vulnerability Testing Using Postman Workflows
Explore the art of automating and visually demonstrating API vulnerabilities you've identified using Postman Workflows.
Just-in-Time admin and production access using Azure PIM
https://ift.tt/l7G0pO5
Submitted April 28, 2024 at 06:44PM by nindustries
via reddit https://ift.tt/jkrY5Df
https://ift.tt/l7G0pO5
Submitted April 28, 2024 at 06:44PM by nindustries
via reddit https://ift.tt/jkrY5Df
ironpeak.be
The way of the Cookie - ironPeak Blog
How to provide secure temporary production access to Azure objects, production networks and cloud infrastructure using Azure Privileged Identity Management.
LSASS rings KsecDD ext. 0 - Overview of the recent KexecDD exploit
https://ift.tt/pqaiPsQ
Submitted April 29, 2024 at 11:23AM by clod81
via reddit https://ift.tt/H37XBxl
https://ift.tt/pqaiPsQ
Submitted April 29, 2024 at 11:23AM by clod81
via reddit https://ift.tt/H37XBxl
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Judge0 Sandbox Escape - CVE-2024-29021, CVE-2024-28185 and CVE-2024-28189
https://ift.tt/bhpkZIf
Submitted April 29, 2024 at 12:20PM by _pimps
via reddit https://ift.tt/Upt7XMx
https://ift.tt/bhpkZIf
Submitted April 29, 2024 at 12:20PM by _pimps
via reddit https://ift.tt/Upt7XMx
Tanto Security
Judge0 Sandbox Escape
A sandbox escape for Judge0