Automating API Vulnerabilities Using Postman Workflows
https://ift.tt/iyOEDwH
Submitted April 27, 2024 at 11:39PM by HayMiz
via reddit https://ift.tt/Ij4RpZm
https://ift.tt/iyOEDwH
Submitted April 27, 2024 at 11:39PM by HayMiz
via reddit https://ift.tt/Ij4RpZm
haymiz@kali:~/blog$
Automating API Vulnerability Testing Using Postman Workflows
Explore the art of automating and visually demonstrating API vulnerabilities you've identified using Postman Workflows.
Just-in-Time admin and production access using Azure PIM
https://ift.tt/l7G0pO5
Submitted April 28, 2024 at 06:44PM by nindustries
via reddit https://ift.tt/jkrY5Df
https://ift.tt/l7G0pO5
Submitted April 28, 2024 at 06:44PM by nindustries
via reddit https://ift.tt/jkrY5Df
ironpeak.be
The way of the Cookie - ironPeak Blog
How to provide secure temporary production access to Azure objects, production networks and cloud infrastructure using Azure Privileged Identity Management.
LSASS rings KsecDD ext. 0 - Overview of the recent KexecDD exploit
https://ift.tt/pqaiPsQ
Submitted April 29, 2024 at 11:23AM by clod81
via reddit https://ift.tt/H37XBxl
https://ift.tt/pqaiPsQ
Submitted April 29, 2024 at 11:23AM by clod81
via reddit https://ift.tt/H37XBxl
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Judge0 Sandbox Escape - CVE-2024-29021, CVE-2024-28185 and CVE-2024-28189
https://ift.tt/bhpkZIf
Submitted April 29, 2024 at 12:20PM by _pimps
via reddit https://ift.tt/Upt7XMx
https://ift.tt/bhpkZIf
Submitted April 29, 2024 at 12:20PM by _pimps
via reddit https://ift.tt/Upt7XMx
Tanto Security
Judge0 Sandbox Escape
A sandbox escape for Judge0
How A Blackbox Target Turned To Whitebox With Recon
https://ift.tt/xVE5uNR
Submitted April 29, 2024 at 04:01PM by Specific_Energy_3895
via reddit https://ift.tt/dJBhKlg
https://ift.tt/xVE5uNR
Submitted April 29, 2024 at 04:01PM by Specific_Energy_3895
via reddit https://ift.tt/dJBhKlg
Medium
How A Blackbox Target Turned To Whitebox With Recon
I was invited to a private bug bounty program of a tech company, one of the biggest tech companies in its country. The scope was pretty…
From IcedID to Dagon Locker Ransomware in 29 Days
https://ift.tt/Ggh2Jk5
Submitted April 29, 2024 at 05:37PM by TheDFIRReport
via reddit https://ift.tt/jmYkARd
https://ift.tt/Ggh2Jk5
Submitted April 29, 2024 at 05:37PM by TheDFIRReport
via reddit https://ift.tt/jmYkARd
The DFIR Report
From IcedID to Dagon Locker Ransomware in 29 Days
Key Takeaways In August 2023, we observed an intrusion that started with a phishing campaign using PrometheusTDS to distribute IcedID. IcedID dropped and executed a Cobalt Strike beacon, which was …
How an empty S3 bucket can make your AWS bill explode
https://ift.tt/nMxWz6L
Submitted April 30, 2024 at 10:28AM by xiongchiamiov
via reddit https://ift.tt/2R9OtoV
https://ift.tt/nMxWz6L
Submitted April 30, 2024 at 10:28AM by xiongchiamiov
via reddit https://ift.tt/2R9OtoV
Medium
How an empty S3 bucket can make your AWS bill explode
Imagine you create an empty, private AWS S3 bucket in a region of your preference. What will your AWS bill be the next morning?
How Not To Protect Your Android Applications
https://ift.tt/CHvfzQX
Submitted April 30, 2024 at 01:46PM by Lightricks_Tech
via reddit https://ift.tt/sfwWEM1
https://ift.tt/CHvfzQX
Submitted April 30, 2024 at 01:46PM by Lightricks_Tech
via reddit https://ift.tt/sfwWEM1
Medium
How Not To Protect Your Android Applications
This article takes an uncommon approach to security articles. Insteading of suggesting ways to enhance your application’s security, this…
Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP with Syzkaller
https://ift.tt/czskNKi
Submitted April 30, 2024 at 03:03PM by alon_za
via reddit https://ift.tt/LizgDwh
https://ift.tt/czskNKi
Submitted April 30, 2024 at 03:03PM by alon_za
via reddit https://ift.tt/LizgDwh
Cyberark
Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP Driver for Linux with Syzkaller
Following research conducted by a colleague of mine [1] at CyberArk Labs, I better understood NVMe-oF/TCP. This kernel subsystem exposes INET socket(s), which can be a fruitful attack surface for...
Nearly 20% of Docker Hub Repositories were used to spread malware & phishing scams
https://ift.tt/CbG8Wz9
Submitted April 30, 2024 at 07:48PM by SRMish3
via reddit https://ift.tt/r0gqAOh
https://ift.tt/CbG8Wz9
Submitted April 30, 2024 at 07:48PM by SRMish3
via reddit https://ift.tt/r0gqAOh
JFrog
JFrog Security research discovers coordinated attacks on Docker Hub that planted millions of malicious repositories
Attackers are using Docker Hub for malicious campaigns of various types, including spreading malware, phishing and scams. Read the analysis of 3 malware campaigns.
Exploit Education :: Andrew Griffiths' Exploit Education
https://ift.tt/1gzPWS2
Submitted April 30, 2024 at 09:18PM by louis11
via reddit https://ift.tt/ZDyp8Fs
https://ift.tt/1gzPWS2
Submitted April 30, 2024 at 09:18PM by louis11
via reddit https://ift.tt/ZDyp8Fs
A Basic Guide to AFL QEMU
https://ift.tt/PQOIm6y
Submitted May 01, 2024 at 05:09AM by cy1337
via reddit https://ift.tt/6b5Mjsu
https://ift.tt/PQOIm6y
Submitted May 01, 2024 at 05:09AM by cy1337
via reddit https://ift.tt/6b5Mjsu
Medium
A Basic Guide to AFL QEMU
Over the years that I’ve been teaching Ghidra at Black Hat and other events, there is one question which inevitably comes up.
Front Porch Digital Forensics - Trap beats, open loops and Dirty Daves spell trouble for our forensicators.
https://ift.tt/D7j8RaG
Submitted May 01, 2024 at 07:39PM by jms_dot_py
via reddit https://ift.tt/zdr86uy
https://ift.tt/D7j8RaG
Submitted May 01, 2024 at 07:39PM by jms_dot_py
via reddit https://ift.tt/zdr86uy
Bullshithunting
Front Porch Digital Forensics
Trap beats, open loops and Dirty Daves spell trouble for our forensicators.
5 Methods I Use To Discover APIs
https://ift.tt/Kzpb8Za
Submitted May 01, 2024 at 09:40PM by Specific_Energy_3895
via reddit https://ift.tt/CmZlv31
https://ift.tt/Kzpb8Za
Submitted May 01, 2024 at 09:40PM by Specific_Energy_3895
via reddit https://ift.tt/CmZlv31
Medium
5 Methods I Use To Discover APIs
While working on a target, some of the most interesting parts to test is its API. APIs are dynamics, they get updated more often then…
It’s Morphin’ Time: Self-Modifying Code Sections with WriteProcessMemory for EDR Evasion
https://ift.tt/tQfBan9
Submitted May 02, 2024 at 11:25AM by thewatcher_
via reddit https://ift.tt/rqnjUGX
https://ift.tt/tQfBan9
Submitted May 02, 2024 at 11:25AM by thewatcher_
via reddit https://ift.tt/rqnjUGX
Medium
It’s Morphin’ Time: Self-Modifying Code Sections with WriteProcessMemory for EDR Evasion
The Mockingjay process injection technique was designed to prevent the allocation of a buffer with RWX permission, typically used for…
North Korea's Lazarus Group Tied to Laundering $200M+ in Crypto Since 2020
https://ift.tt/PNHwUxy
Submitted May 02, 2024 at 01:28PM by webbs3
via reddit https://ift.tt/mcFwp8I
https://ift.tt/PNHwUxy
Submitted May 02, 2024 at 01:28PM by webbs3
via reddit https://ift.tt/mcFwp8I
BitDegree
Lazarus Group Tied to Laundering $200M+ in Crypto Since 2020
The Lazarus Group, a hacking organization backed by North Korea, has laundered over $200M in crypto through 25+ hacks from 2020 to 2023
Microsoft Developer Blogs Search Tool
https://ift.tt/Fci6Dmh
Submitted May 03, 2024 at 09:09AM by elliotkillick
via reddit https://ift.tt/BdyYamQ
https://ift.tt/Fci6Dmh
Submitted May 03, 2024 at 09:09AM by elliotkillick
via reddit https://ift.tt/BdyYamQ
GitHub
GitHub - ElliotKillick/ms-devblogs-search: Microsoft Developer Blogs Search Tool
Microsoft Developer Blogs Search Tool. Contribute to ElliotKillick/ms-devblogs-search development by creating an account on GitHub.
Ever wondered where your inserted data went? Our Burp Suite Extension FlowMate helps you find out.
https://ift.tt/2KahRV5
Submitted May 03, 2024 at 07:00PM by usdAG
via reddit https://ift.tt/Ltg6U7z
https://ift.tt/2KahRV5
Submitted May 03, 2024 at 07:00PM by usdAG
via reddit https://ift.tt/Ltg6U7z
GitHub
GitHub - usdAG/FlowMate: FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters…
FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application and matches their occurrences in the responses. - usdAG/FlowMate
Demystifying RCE Vulnerabilities in LLM-Integrated Apps
https://ift.tt/Gnk8ly0
Submitted May 03, 2024 at 09:03PM by louis11
via reddit https://ift.tt/JK5NAvz
https://ift.tt/Gnk8ly0
Submitted May 03, 2024 at 09:03PM by louis11
via reddit https://ift.tt/JK5NAvz
Flutter Windows Thick Client SSL Pinning Bypass
https://ift.tt/Jgdfv1P
Submitted May 03, 2024 at 10:54PM by Ano_F
via reddit https://ift.tt/NDAG76Y
https://ift.tt/Jgdfv1P
Submitted May 03, 2024 at 10:54PM by Ano_F
via reddit https://ift.tt/NDAG76Y
Medium
Flutter Windows Thick Client SSL Pinning Bypass
I recently worked on a Flutter-based application and learned that it is different from other hybrid frameworks like React Native or…
pcap-did-what: Analyze pcaps with Zeek and a Grafana Dashboard
https://ift.tt/4q19l6S
Submitted May 05, 2024 at 04:41AM by thewanderer1999
via reddit https://ift.tt/IdJPYK9
https://ift.tt/4q19l6S
Submitted May 05, 2024 at 04:41AM by thewanderer1999
via reddit https://ift.tt/IdJPYK9
GitHub
GitHub - hackertarget/pcap-did-what: Analyze pcaps with Zeek and a Grafana Dashboard
Analyze pcaps with Zeek and a Grafana Dashboard. Contribute to hackertarget/pcap-did-what development by creating an account on GitHub.