Cisco ASA exploit in the wild.
https://ift.tt/6znQw7m
Submitted April 25, 2024 at 12:13AM by MrSanford
via reddit https://ift.tt/y8D5qu1
https://ift.tt/6znQw7m
Submitted April 25, 2024 at 12:13AM by MrSanford
via reddit https://ift.tt/y8D5qu1
Cisco Talos Blog
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVEs related to the event. We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
I got a 10% discount ticket for 1 Typhooncon training
https://ift.tt/Ln32v6d
Submitted April 25, 2024 at 04:04AM by Status_Resolve2971
via reddit https://ift.tt/acFu7zY
https://ift.tt/Ln32v6d
Submitted April 25, 2024 at 04:04AM by Status_Resolve2971
via reddit https://ift.tt/acFu7zY
Eventbrite
TyphoonCon 2024
TyphoonCon conference and training focus on highly technical offensive security topics.
The event is organized by SSD Secure Disclosure.
The event is organized by SSD Secure Disclosure.
Literal Security Measures
https://ift.tt/s8SkPMH
Submitted April 25, 2024 at 12:31PM by samsbp97
via reddit https://ift.tt/Z2aJYQS
https://ift.tt/s8SkPMH
Submitted April 25, 2024 at 12:31PM by samsbp97
via reddit https://ift.tt/Z2aJYQS
Random Access Memory
Literal Security Measures
security measures, policies that we do for literal namesakes
Exploring Vulnerabilities in Embedded Devices: A Case Study of an IP Phone
https://ift.tt/Fm8V491
Submitted April 25, 2024 at 04:10PM by security_aaudit
via reddit https://ift.tt/SAE0i7G
https://ift.tt/Fm8V491
Submitted April 25, 2024 at 04:10PM by security_aaudit
via reddit https://ift.tt/SAE0i7G
baldur.dk
BALDUR. - Security Consultancy
How to achieve a working remote code execution exploit in an embedded phone without any previous access.
Multiple Vulnerabilities in Open Devin (Autonomous AI Software Engineer)
https://ift.tt/8qDylEF
Submitted April 25, 2024 at 07:54PM by Standard_Arm_4476
via reddit https://ift.tt/X7GIwxd
https://ift.tt/8qDylEF
Submitted April 25, 2024 at 07:54PM by Standard_Arm_4476
via reddit https://ift.tt/X7GIwxd
Moriarty v1.2 has been released!
https://ift.tt/sELxvpo
Submitted April 25, 2024 at 08:42PM by Hubble_BC_Security
via reddit https://ift.tt/GFtqsSi
https://ift.tt/sELxvpo
Submitted April 25, 2024 at 08:42PM by Hubble_BC_Security
via reddit https://ift.tt/GFtqsSi
GitHub
GitHub - BC-SECURITY/Moriarty: Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential…
Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in Windows environments. - GitHub - BC-SECURITY/Moriarty: Mor...
How MFA Is Falling Short
https://ift.tt/gPR3mTU
Submitted April 25, 2024 at 09:29PM by KolideKenny
via reddit https://ift.tt/ok54POr
https://ift.tt/gPR3mTU
Submitted April 25, 2024 at 09:29PM by KolideKenny
via reddit https://ift.tt/ok54POr
1Password
How MFA is falling short | 1Password
MFA was supposed to solve our security problems, so why do attackers keep getting around it?
Coverage Guided Fuzzing - Extending Instrumentation to Hunt Down Bugs Faster! - Include Security Research Blog
https://ift.tt/ugdZ27a
Submitted April 26, 2024 at 12:42AM by 907jessejones
via reddit https://ift.tt/UXeo503
https://ift.tt/ugdZ27a
Submitted April 26, 2024 at 12:42AM by 907jessejones
via reddit https://ift.tt/UXeo503
Include Security Research Blog
Coverage Guided Fuzzing - Extending Instrumentation to Hunt Down Bugs Faster! - Include Security Research Blog
In our latest blog post, we introduce coverage-guided fuzzing with a brief denoscription of fundamentals and a demonstration of how modifying program instrumentation can be used to more easily track down the source of vulnerabilities and identify interesting…
CVE-2024-29417: a security software vulnerability allows for privilege escalation or auth bypass, even when Windows is locked.
https://ift.tt/8JehnIb
Submitted April 26, 2024 at 12:49AM by Zealousideal_Tip2086
via reddit https://ift.tt/ive0lDA
https://ift.tt/8JehnIb
Submitted April 26, 2024 at 12:49AM by Zealousideal_Tip2086
via reddit https://ift.tt/ive0lDA
PRIDE Security Blog
Horacius (IAM) - Local privilege escalation, even without a Windows account.
Unauthenticated privilege escalation in Horacius (Identity and Access Management) - CVE-2024-29417: a security software vulnerability allows for local privilege escalation, even when Windows is locked.
Disclaimer
This Security Advisory is provided on an…
Disclaimer
This Security Advisory is provided on an…
Postman users are exposing Thousands of live Passwords/API keys
https://ift.tt/MWEoVLK
Submitted April 26, 2024 at 02:36AM by wifihack
via reddit https://ift.tt/E6xzOuA
https://ift.tt/MWEoVLK
Submitted April 26, 2024 at 02:36AM by wifihack
via reddit https://ift.tt/E6xzOuA
Trufflesecurity
(The) Postman Carries Lots of Secrets ◆ Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a…
Dependency Confusion Vulnerability Found in an Archived Apache Project
https://ift.tt/IBbxV5T
Submitted April 26, 2024 at 03:09AM by roy_6472
via reddit https://ift.tt/4QPteAZ
https://ift.tt/IBbxV5T
Submitted April 26, 2024 at 03:09AM by roy_6472
via reddit https://ift.tt/4QPteAZ
Legitsecurity
Dependency Confusion Vulnerability Found in an Archived Apache Project
Legit Security | Dependency Confusion Vulnerability Found in an Archived Apache Project. Get details on the Legit research team's discovery of a dependency confusion vulnerability in an archived Apache project.
Seeking research study participants! SOC analysts and managers that experienced SolarWinds, Log4Shell or both.
https://ift.tt/d1Yhza5
Submitted April 26, 2024 at 07:29PM by welp_that_happened
via reddit https://ift.tt/BflEHNL
https://ift.tt/d1Yhza5
Submitted April 26, 2024 at 07:29PM by welp_that_happened
via reddit https://ift.tt/BflEHNL
Office
Please fill out this form
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining - Avast Threat Labs
https://ift.tt/Z5n6bxY
Submitted April 27, 2024 at 01:33AM by MegaManSec2
via reddit https://ift.tt/vh495nW
https://ift.tt/Z5n6bxY
Submitted April 27, 2024 at 01:33AM by MegaManSec2
via reddit https://ift.tt/vh495nW
Gendigital
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
Malware Campaign Exploiting Antivirus Updates
Automating API Vulnerabilities Using Postman Workflows
https://ift.tt/iyOEDwH
Submitted April 27, 2024 at 11:39PM by HayMiz
via reddit https://ift.tt/Ij4RpZm
https://ift.tt/iyOEDwH
Submitted April 27, 2024 at 11:39PM by HayMiz
via reddit https://ift.tt/Ij4RpZm
haymiz@kali:~/blog$
Automating API Vulnerability Testing Using Postman Workflows
Explore the art of automating and visually demonstrating API vulnerabilities you've identified using Postman Workflows.
Just-in-Time admin and production access using Azure PIM
https://ift.tt/l7G0pO5
Submitted April 28, 2024 at 06:44PM by nindustries
via reddit https://ift.tt/jkrY5Df
https://ift.tt/l7G0pO5
Submitted April 28, 2024 at 06:44PM by nindustries
via reddit https://ift.tt/jkrY5Df
ironpeak.be
The way of the Cookie - ironPeak Blog
How to provide secure temporary production access to Azure objects, production networks and cloud infrastructure using Azure Privileged Identity Management.
LSASS rings KsecDD ext. 0 - Overview of the recent KexecDD exploit
https://ift.tt/pqaiPsQ
Submitted April 29, 2024 at 11:23AM by clod81
via reddit https://ift.tt/H37XBxl
https://ift.tt/pqaiPsQ
Submitted April 29, 2024 at 11:23AM by clod81
via reddit https://ift.tt/H37XBxl
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Judge0 Sandbox Escape - CVE-2024-29021, CVE-2024-28185 and CVE-2024-28189
https://ift.tt/bhpkZIf
Submitted April 29, 2024 at 12:20PM by _pimps
via reddit https://ift.tt/Upt7XMx
https://ift.tt/bhpkZIf
Submitted April 29, 2024 at 12:20PM by _pimps
via reddit https://ift.tt/Upt7XMx
Tanto Security
Judge0 Sandbox Escape
A sandbox escape for Judge0
How A Blackbox Target Turned To Whitebox With Recon
https://ift.tt/xVE5uNR
Submitted April 29, 2024 at 04:01PM by Specific_Energy_3895
via reddit https://ift.tt/dJBhKlg
https://ift.tt/xVE5uNR
Submitted April 29, 2024 at 04:01PM by Specific_Energy_3895
via reddit https://ift.tt/dJBhKlg
Medium
How A Blackbox Target Turned To Whitebox With Recon
I was invited to a private bug bounty program of a tech company, one of the biggest tech companies in its country. The scope was pretty…
From IcedID to Dagon Locker Ransomware in 29 Days
https://ift.tt/Ggh2Jk5
Submitted April 29, 2024 at 05:37PM by TheDFIRReport
via reddit https://ift.tt/jmYkARd
https://ift.tt/Ggh2Jk5
Submitted April 29, 2024 at 05:37PM by TheDFIRReport
via reddit https://ift.tt/jmYkARd
The DFIR Report
From IcedID to Dagon Locker Ransomware in 29 Days
Key Takeaways In August 2023, we observed an intrusion that started with a phishing campaign using PrometheusTDS to distribute IcedID. IcedID dropped and executed a Cobalt Strike beacon, which was …
How an empty S3 bucket can make your AWS bill explode
https://ift.tt/nMxWz6L
Submitted April 30, 2024 at 10:28AM by xiongchiamiov
via reddit https://ift.tt/2R9OtoV
https://ift.tt/nMxWz6L
Submitted April 30, 2024 at 10:28AM by xiongchiamiov
via reddit https://ift.tt/2R9OtoV
Medium
How an empty S3 bucket can make your AWS bill explode
Imagine you create an empty, private AWS S3 bucket in a region of your preference. What will your AWS bill be the next morning?
How Not To Protect Your Android Applications
https://ift.tt/CHvfzQX
Submitted April 30, 2024 at 01:46PM by Lightricks_Tech
via reddit https://ift.tt/sfwWEM1
https://ift.tt/CHvfzQX
Submitted April 30, 2024 at 01:46PM by Lightricks_Tech
via reddit https://ift.tt/sfwWEM1
Medium
How Not To Protect Your Android Applications
This article takes an uncommon approach to security articles. Insteading of suggesting ways to enhance your application’s security, this…