Uncovering a Critical Vulnerability in Authentik's PKCE Implementation (CVE-2023-48228) | Offensity
https://ift.tt/irVHTCw
Submitted June 10, 2024 at 02:51PM by Offensity
via reddit https://ift.tt/rwagQvh
https://ift.tt/irVHTCw
Submitted June 10, 2024 at 02:51PM by Offensity
via reddit https://ift.tt/rwagQvh
Offensity
Uncovering a Critical Vulnerability in Authentik's PKCE Implementation (CVE-2023-48228) | Offensity
Security reports: efficient and straightforward. The simplest way to detect and fix vulnerabilities
How to prevent domain verification bypasses of your server certificate
https://ift.tt/uJtq9VA
Submitted June 10, 2024 at 03:47PM by fr0r
via reddit https://ift.tt/o53JhWp
https://ift.tt/uJtq9VA
Submitted June 10, 2024 at 03:47PM by fr0r
via reddit https://ift.tt/o53JhWp
Pentagrid AG
How to prevent domain verification bypasses of your server certificate
Denoscription of the CAA accounturi binding to mitigate or prevent domain verification bypasses and monitoring approaches like certificate transparency log analysis.
Create your own VPN Service with Cableguard VPN and NEAR Protocol
https://ift.tt/KRoNQIU
Submitted June 10, 2024 at 04:55PM by alanesmizi
via reddit https://ift.tt/ROv3ZCI
https://ift.tt/KRoNQIU
Submitted June 10, 2024 at 04:55PM by alanesmizi
via reddit https://ift.tt/ROv3ZCI
Medium
Create your own VPN Service with Cableguard VPN and NEAR Protocol
It is easy!
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment
https://ift.tt/dpzvPLh
Submitted June 10, 2024 at 05:58PM by TheDFIRReport
via reddit https://ift.tt/QMAsjKZ
https://ift.tt/dpzvPLh
Submitted June 10, 2024 at 05:58PM by TheDFIRReport
via reddit https://ift.tt/QMAsjKZ
The DFIR Report
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment
Key Takeaways In October 2023, we observed an intrusion that began with a spam campaign, distributing a forked IcedID loader. The threat actor used Impacket’s wmiexec and RDP to install Scree…
Bypassing Veeam Authentication CVE-2024-29849
https://ift.tt/KwGF5XR
Submitted June 10, 2024 at 05:44PM by scopedsecurity
via reddit https://ift.tt/LuhoxRk
https://ift.tt/KwGF5XR
Submitted June 10, 2024 at 05:44PM by scopedsecurity
via reddit https://ift.tt/LuhoxRk
Summoning Team
Bypassing Veeam Authentication CVE-2024-29849
An interesting authentication bypass exploit in Veeam Backup Enterprise Manager
Finding the slab cache for each object in Linux kernel using static analysis
https://ift.tt/ncUrbNL
Submitted June 11, 2024 at 12:52AM by albocoder1
via reddit https://ift.tt/EsHV9gM
https://ift.tt/ncUrbNL
Submitted June 11, 2024 at 12:52AM by albocoder1
via reddit https://ift.tt/EsHV9gM
Erin Avllazagaj
Finding the slab cache for each object in Linux kernel using static analysis
Reimagining Contextualized SaaS Security with Generative AI
https://ift.tt/e02x4aE
Submitted June 11, 2024 at 01:49PM by vicanurim
via reddit https://ift.tt/s9mFA6W
https://ift.tt/e02x4aE
Submitted June 11, 2024 at 01:49PM by vicanurim
via reddit https://ift.tt/s9mFA6W
RSTCON: research, tradecraft, and exploitation of industrial sensors, systems, and architectures. Sept 13-15, 2024
https://ift.tt/6vhIUmP
Submitted June 11, 2024 at 08:08PM by h3rrmiller
via reddit https://ift.tt/yVernju
https://ift.tt/6vhIUmP
Submitted June 11, 2024 at 08:08PM by h3rrmiller
via reddit https://ift.tt/yVernju
rstcon.org
RSTCON 2024
September 13-15, 2024 in Savannah, GA
Disrupting Hell's Gate and GuLoader with DJB2 Hash Collisions
https://ift.tt/GKqXWYm
Submitted June 11, 2024 at 07:46PM by operat1ve
via reddit https://ift.tt/UARlaIn
https://ift.tt/GKqXWYm
Submitted June 11, 2024 at 07:46PM by operat1ve
via reddit https://ift.tt/UARlaIn
karma-x.io
Disrupting Hell's Gate, Caro Kann, and GuLoader with DJB2 Hash Collisions
AI Helps Catch CSRF Vulnerability Being Introduced in to 100,000+ Install WordPress Plugin Modula
https://ift.tt/UPpNE0R
Submitted June 11, 2024 at 11:10PM by PluginVulns
via reddit https://ift.tt/bz87Lxt
https://ift.tt/UPpNE0R
Submitted June 11, 2024 at 11:10PM by PluginVulns
via reddit https://ift.tt/bz87Lxt
Plugin Vulnerabilities
AI Helps Catch CSRF Vulnerability Being Introduced in to 100,000+ Install WordPress Plugin Modula
Decrypting Thecus NAS Firmware Images
https://ift.tt/L6eX78d
Submitted June 11, 2024 at 11:01PM by lightgrains
via reddit https://ift.tt/xakH3It
https://ift.tt/L6eX78d
Submitted June 11, 2024 at 11:01PM by lightgrains
via reddit https://ift.tt/xakH3It
CVE-2024-29824 Deep Dive: Ivanti EPM SQL Injection Remote Code Execution Vulnerability, IOCs, and POC
https://ift.tt/GZsdF28
Submitted June 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/5VTHm7M
https://ift.tt/GZsdF28
Submitted June 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/5VTHm7M
Horizon3.ai
CVE-2024-29824 Deep Dive: Ivanti EPM SQL Injection Remote Code Execution Vulnerability
CVE-2024-29824 Ivanti EPM SQL Injection Remote Code Execution Vulnerability. This blog details the internals of a SQLi RCE vulnerability.
BusKill Warrant Canary for 2024 H2 🕵️
https://ift.tt/mxfz7R4
Submitted June 12, 2024 at 10:02PM by maltfield
via reddit https://ift.tt/kxdwLbD
https://ift.tt/mxfz7R4
Submitted June 12, 2024 at 10:02PM by maltfield
via reddit https://ift.tt/kxdwLbD
BusKill
BusKill Canary #8 - BusKill
This post contains the cryptographically-signed BusKill warrant canary #008 for June 2024 to January 2025.
CVE-2024–4956 -Unauthenticated Path Traversal
https://ift.tt/phQEIFf
Submitted June 13, 2024 at 09:01PM by Justin_coco
via reddit https://ift.tt/CrwfR5L
https://ift.tt/phQEIFf
Submitted June 13, 2024 at 09:01PM by Justin_coco
via reddit https://ift.tt/CrwfR5L
Medium
POC — CVE-2024–4956 -Unauthenticated Path Traversal
POC — CVE-2024–4956 — Nexus Repository Manager 3 Unauthenticated Path Traversal
Introducing YetiHunter: An open-source tool to detect and hunt for Suspicious activity in Snowflake
https://ift.tt/r3NHFRn
Submitted June 13, 2024 at 10:27PM by permis0
via reddit https://ift.tt/qOD8N5S
https://ift.tt/r3NHFRn
Submitted June 13, 2024 at 10:27PM by permis0
via reddit https://ift.tt/qOD8N5S
permiso.io
Introducing YetiHunter: An open-source tool to detect and hunt for suspicious activity in Snowflake
YetiHunter is an open source tool that combines the indicators that Snowflake, Mandiant, DataDog and Permiso have into one easy to run noscript to detect and hunt for suspicious activity in Snowflake.
There are no Secrets || Exploiting Veeam CVE-2024-29855
https://ift.tt/omcq7na
Submitted June 13, 2024 at 09:57PM by juken
via reddit https://ift.tt/O3Pajul
https://ift.tt/omcq7na
Submitted June 13, 2024 at 09:57PM by juken
via reddit https://ift.tt/O3Pajul
Summoning Team
There are no Secrets || Exploiting Veeam CVE-2024-29855
This vulenrability is due to the fact that JWT secret used to generate authentication tokens was a hardcoded value which means an unauthenticated attacker can generate valid tokens for any user (not just the administrator) and login to the Veeam Recovery…
Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces: CVE-2023-51449 and CVE-2023-1561
https://ift.tt/miHq0Nu
Submitted June 14, 2024 at 06:59PM by scopedsecurity
via reddit https://ift.tt/Tf0kFwH
https://ift.tt/miHq0Nu
Submitted June 14, 2024 at 06:59PM by scopedsecurity
via reddit https://ift.tt/Tf0kFwH
Horizon3.ai
Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces
Exploiting file read vulnerabilities in Gradio to steal secrets from Hugging Face Spaces.
Type Juggling and Dangers of Loose Comparisons
https://ift.tt/PEIwNYW
Submitted June 14, 2024 at 10:46PM by HayMiz
via reddit https://ift.tt/BeELQlc
https://ift.tt/PEIwNYW
Submitted June 14, 2024 at 10:46PM by HayMiz
via reddit https://ift.tt/BeELQlc
haymiz@kali:~/blog$
Type Juggling and Dangers of Loose Comparisons
Exploring how type juggling leverages loose comparisons to breach web application security.
Encrypt/decrypt with SSH keys
https://ift.tt/PA8MDvF
Submitted June 15, 2024 at 05:32PM by yurichev
via reddit https://ift.tt/gxCR3MX
https://ift.tt/PA8MDvF
Submitted June 15, 2024 at 05:32PM by yurichev
via reddit https://ift.tt/gxCR3MX
In-Depth Cyberdefense Guide: Protecting Against Modern Threats
https://ift.tt/zTYRLMe
Submitted June 16, 2024 at 11:44PM by Dependent-Fishing630
via reddit https://ift.tt/mME6K9Q
https://ift.tt/zTYRLMe
Submitted June 16, 2024 at 11:44PM by Dependent-Fishing630
via reddit https://ift.tt/mME6K9Q
Iconv, set the charset to RCE (part 2): Remote code execution on Roundcube (CVE-2024-2961)
https://ift.tt/0JFrHsK
Submitted June 17, 2024 at 01:55PM by cfambionics
via reddit https://ift.tt/MBblDNK
https://ift.tt/0JFrHsK
Submitted June 17, 2024 at 01:55PM by cfambionics
via reddit https://ift.tt/MBblDNK
Ambionics
Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine (part 2)
In this blog post, we will explore a new way of exploiting the vulnerability on PHP, using direct calls to iconv(), and illustrate the vulnerability by targeting Roundcube, a popular PHP webmail.