File-write on Gitlab via YAML parser differential
https://ift.tt/zFXCTxO
Submitted May 07, 2024 at 02:23PM by albinowax
via reddit https://ift.tt/QfXL4v0
https://ift.tt/zFXCTxO
Submitted May 07, 2024 at 02:23PM by albinowax
via reddit https://ift.tt/QfXL4v0
Multiple vulnerabilities in RIOT OS
https://ift.tt/fnpv1As
Submitted May 07, 2024 at 02:18PM by 0xdea
via reddit https://ift.tt/9AGrltp
https://ift.tt/fnpv1As
Submitted May 07, 2024 at 02:18PM by 0xdea
via reddit https://ift.tt/9AGrltp
HN Security
Multiple vulnerabilities in RIOT OS - HN Security
Coordinated disclosure writeup about multiple vulnerabilities in RIOT OS (CVE-2024-31225, CVE-2024-32017, CVE-2024-32018, and more).
CVE-2024-3661: TunnelVision - DHCP option 121 allows attacker controlled DHCP to subvert VPN routing rules
https://ift.tt/WVu5hR9
Submitted May 07, 2024 at 02:09PM by Secret-Inspection180
via reddit https://ift.tt/BnpvkwL
https://ift.tt/WVu5hR9
Submitted May 07, 2024 at 02:09PM by Secret-Inspection180
via reddit https://ift.tt/BnpvkwL
Leviathan Security Group - Penetration Testing, Security Assessment, Risk Advisory
CVE-2024-3661: TunnelVision - How Attackers Can Decloak Routing-Based VPNs For a Total VPN Leak — Leviathan Security Group - Penetration…
We discovered a fundamental design problem in VPNs and we're calling it TunnelVision. This problem lets someone see what you're doing online, even if you think you're safely using a VPN.
Introducing SecureDrop Protocol
https://ift.tt/zKXleZ1
Submitted May 07, 2024 at 04:04PM by smaury
via reddit https://ift.tt/xOVRPUS
https://ift.tt/zKXleZ1
Submitted May 07, 2024 at 04:04PM by smaury
via reddit https://ift.tt/xOVRPUS
SecureDrop
Introducing SecureDrop Protocol
This blog post is a part of a series about our research toward the next generation of the SecureDrop whistleblowing …
Neat idea - A 'scarecrow' for your computer.
https://ift.tt/Yn049XV
Submitted May 07, 2024 at 06:27PM by Hoban_Riverpath
via reddit https://ift.tt/LAhOKYG
https://ift.tt/Yn049XV
Submitted May 07, 2024 at 06:27PM by Hoban_Riverpath
via reddit https://ift.tt/LAhOKYG
Cyberscarecrow
Cyber Scarecrow
An app for scaring away malware
3D-Printed USB Dead Man Switch (Prototype Demo)
https://ift.tt/gyKQrqp
Submitted May 07, 2024 at 10:52PM by maltfield
via reddit https://ift.tt/N7FsQzd
https://ift.tt/gyKQrqp
Submitted May 07, 2024 at 10:52PM by maltfield
via reddit https://ift.tt/N7FsQzd
BusKill
3D-Printable BusKill Prototype Demo - BusKill
Demo of our DIY USB Dead Man Switch (prototype) with a 3D-Printable Case triggering a lockscreen when the kill-cord's connection is severed.
Over the past couple of months, I've built more than a dozen Python and D3 tools that might interest you. Such as this GitHub repo; an application that catalogs and visualizes all internal facing links from a given number of pages on a specific domain. Other similar links in the comments.
https://ift.tt/8CIO6z1
Submitted May 08, 2024 at 03:01PM by -bretbernhoft__
via reddit https://ift.tt/8WLXFnR
https://ift.tt/8CIO6z1
Submitted May 08, 2024 at 03:01PM by -bretbernhoft__
via reddit https://ift.tt/8WLXFnR
GitHub
GitHub - devbret/website-internal-links: Explore a website's internal links, then visualize those connections as a network graph…
Explore a website's internal links, then visualize those connections as a network graph with scorecards and analysis using Claude AI. - devbret/website-internal-links
Interesting take on current state of phishing sim & sat
https://ift.tt/MwXNdSP
Submitted May 08, 2024 at 05:57PM by markqlogan
via reddit https://ift.tt/RweGl2v
https://ift.tt/MwXNdSP
Submitted May 08, 2024 at 05:57PM by markqlogan
via reddit https://ift.tt/RweGl2v
Online DFIR Conference
https://ift.tt/MBHRcfj
Submitted May 08, 2024 at 06:56PM by dardaryy
via reddit https://ift.tt/ZMP96av
https://ift.tt/MBHRcfj
Submitted May 08, 2024 at 06:56PM by dardaryy
via reddit https://ift.tt/ZMP96av
Belkasoft
BelkaDay 2024: Digital Forensics and Cyber Incident Response Conference
Discover key insights and trends from experts at the 2024 BelkaDay Asia conference
Redefining Roles in Application Security
https://ift.tt/MjAUasV
Submitted May 08, 2024 at 06:53PM by NXT1_Cloud
via reddit https://ift.tt/SJ5TaIe
https://ift.tt/MjAUasV
Submitted May 08, 2024 at 06:53PM by NXT1_Cloud
via reddit https://ift.tt/SJ5TaIe
Everyday Ghidra: Symbols — Prenoscription Lenses for Reverse Engineers — Part 1
https://ift.tt/LfqQkje
Submitted May 08, 2024 at 06:36PM by onlinereadme
via reddit https://ift.tt/GnfuTx3
https://ift.tt/LfqQkje
Submitted May 08, 2024 at 06:36PM by onlinereadme
via reddit https://ift.tt/GnfuTx3
Medium
Everyday Ghidra: Symbols — Prenoscription Lenses for Reverse Engineers — Part 1
In reverse engineering a closed-source binary using Ghidra or other software reverse engineering frameworks, a key objective is to…
Systematic VPN Detection
https://ift.tt/mSV1Ekl
Submitted May 08, 2024 at 08:25PM by incolumitas
via reddit https://ift.tt/fm6WTyn
https://ift.tt/mSV1Ekl
Submitted May 08, 2024 at 08:25PM by incolumitas
via reddit https://ift.tt/fm6WTyn
ipapi.is
ipapi.is - Detecting VPN Services
ipapi.is offers precise IP data via a user-friendly API, encompassing geolocation, ASN data, hosting detection, VPN detection, and proxy detection.
AI-Exploits: 4 new exploits released for major AI tools - Gradio, BentoML, FastAPI, AnythingLLM
https://ift.tt/cLDaoOH
Submitted May 08, 2024 at 09:51PM by FlyingTriangle
via reddit https://ift.tt/msEWiqd
https://ift.tt/cLDaoOH
Submitted May 08, 2024 at 09:51PM by FlyingTriangle
via reddit https://ift.tt/msEWiqd
Palo Alto Networks Blog
Network Security - Palo Alto Networks Blog
Secure your enterprise against tomorrow's threats, today. Protect users, applications and data anywhere with intelligent network security from Palo Alto Networks.
mlcsec/SharpGraphView: Microsoft Graph API post-exploitation toolkit
https://ift.tt/Ycz5g6X
Submitted May 09, 2024 at 12:32AM by Frequent_Passenger82
via reddit https://ift.tt/aVW7jIZ
https://ift.tt/Ycz5g6X
Submitted May 09, 2024 at 12:32AM by Frequent_Passenger82
via reddit https://ift.tt/aVW7jIZ
GitHub
GitHub - mlcsec/SharpGraphView: Microsoft Graph API post-exploitation toolkit
Microsoft Graph API post-exploitation toolkit. Contribute to mlcsec/SharpGraphView development by creating an account on GitHub.
E2E Security Testing via exploratory Testing
https://ift.tt/G5hmEte
Submitted May 09, 2024 at 11:32AM by samsbp97
via reddit https://ift.tt/LdzUQAF
https://ift.tt/G5hmEte
Submitted May 09, 2024 at 11:32AM by samsbp97
via reddit https://ift.tt/LdzUQAF
Random Access Memory
E2E Security Testing via exploratory Testing
How exploratory testing helps in driving the success factor of security testing
AWS CloudQuarry: Digging for Secrets in Public AMIs
https://ift.tt/Y6U9qBO
Submitted May 09, 2024 at 05:14PM by _TheTime_
via reddit https://ift.tt/I34UzLG
https://ift.tt/Y6U9qBO
Submitted May 09, 2024 at 05:14PM by _TheTime_
via reddit https://ift.tt/I34UzLG
Security Café
AWS CloudQuarry: Digging for Secrets in Public AMIs
Money, secrets and mass exploitation: This research unveils a quarry of sensitive data stored in public AMIs. Digging through each AMI we managed to collect 500 GB of credentials, private repositor…
Minecraft Source Pack Becomes Gateway for zEus Stealer Distribution
https://ift.tt/kO8qCie
Submitted May 09, 2024 at 10:40PM by goki7
via reddit https://ift.tt/OQerp3g
https://ift.tt/kO8qCie
Submitted May 09, 2024 at 10:40PM by goki7
via reddit https://ift.tt/OQerp3g
CyberInsider
Minecraft Source Pack Becomes Gateway for zEus Stealer Distribution
Fortinet's FortiGuard Labs researchers have uncovered a zEus stealer malware dissemination method involving a crafted Minecraft source pack.
apk.sh v1.0.9 is out! Making reverse engineering Android apps easier!
https://ift.tt/Am6aweJ
Submitted May 10, 2024 at 03:01AM by recovo_recovo
via reddit https://ift.tt/rnXvP6M
https://ift.tt/Am6aweJ
Submitted May 10, 2024 at 03:01AM by recovo_recovo
via reddit https://ift.tt/rnXvP6M
GitHub
GitHub - ax/apk.sh: Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding…
Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding and patching an APK. - ax/apk.sh
Digging for SSRF in NextJS apps
https://ift.tt/MHoKWwF
Submitted May 10, 2024 at 04:09AM by Mempodipper
via reddit https://ift.tt/lFJYMfK
https://ift.tt/MHoKWwF
Submitted May 10, 2024 at 04:09AM by Mempodipper
via reddit https://ift.tt/lFJYMfK
www.assetnote.io
Digging for SSRF in NextJS apps
At Assetnote, we encounter sites running NextJS extremely often; in this blog post we will detail some common misconfigurations we find in NextJS websites, along with a vulnerability we found in the framework.
SSL/TLS, part 3: Toy TLS 1.2 client in ~1600 SLOC of Python.
https://ift.tt/Cm17OlU
Submitted May 10, 2024 at 04:54PM by yurichev
via reddit https://ift.tt/YDrxQzh
https://ift.tt/Cm17OlU
Submitted May 10, 2024 at 04:54PM by yurichev
via reddit https://ift.tt/YDrxQzh
Kinsing Demystified - A Comprehensive Technical Guide
https://ift.tt/A5dWMkH
Submitted May 10, 2024 at 06:14PM by Pale_Fly_2673
via reddit https://ift.tt/TIX84c3
https://ift.tt/A5dWMkH
Submitted May 10, 2024 at 06:14PM by Pale_Fly_2673
via reddit https://ift.tt/TIX84c3