Bypassing Veeam Authentication CVE-2024-29849
https://ift.tt/KwGF5XR
Submitted June 10, 2024 at 05:44PM by scopedsecurity
via reddit https://ift.tt/LuhoxRk
https://ift.tt/KwGF5XR
Submitted June 10, 2024 at 05:44PM by scopedsecurity
via reddit https://ift.tt/LuhoxRk
Summoning Team
Bypassing Veeam Authentication CVE-2024-29849
An interesting authentication bypass exploit in Veeam Backup Enterprise Manager
Finding the slab cache for each object in Linux kernel using static analysis
https://ift.tt/ncUrbNL
Submitted June 11, 2024 at 12:52AM by albocoder1
via reddit https://ift.tt/EsHV9gM
https://ift.tt/ncUrbNL
Submitted June 11, 2024 at 12:52AM by albocoder1
via reddit https://ift.tt/EsHV9gM
Erin Avllazagaj
Finding the slab cache for each object in Linux kernel using static analysis
Reimagining Contextualized SaaS Security with Generative AI
https://ift.tt/e02x4aE
Submitted June 11, 2024 at 01:49PM by vicanurim
via reddit https://ift.tt/s9mFA6W
https://ift.tt/e02x4aE
Submitted June 11, 2024 at 01:49PM by vicanurim
via reddit https://ift.tt/s9mFA6W
RSTCON: research, tradecraft, and exploitation of industrial sensors, systems, and architectures. Sept 13-15, 2024
https://ift.tt/6vhIUmP
Submitted June 11, 2024 at 08:08PM by h3rrmiller
via reddit https://ift.tt/yVernju
https://ift.tt/6vhIUmP
Submitted June 11, 2024 at 08:08PM by h3rrmiller
via reddit https://ift.tt/yVernju
rstcon.org
RSTCON 2024
September 13-15, 2024 in Savannah, GA
Disrupting Hell's Gate and GuLoader with DJB2 Hash Collisions
https://ift.tt/GKqXWYm
Submitted June 11, 2024 at 07:46PM by operat1ve
via reddit https://ift.tt/UARlaIn
https://ift.tt/GKqXWYm
Submitted June 11, 2024 at 07:46PM by operat1ve
via reddit https://ift.tt/UARlaIn
karma-x.io
Disrupting Hell's Gate, Caro Kann, and GuLoader with DJB2 Hash Collisions
AI Helps Catch CSRF Vulnerability Being Introduced in to 100,000+ Install WordPress Plugin Modula
https://ift.tt/UPpNE0R
Submitted June 11, 2024 at 11:10PM by PluginVulns
via reddit https://ift.tt/bz87Lxt
https://ift.tt/UPpNE0R
Submitted June 11, 2024 at 11:10PM by PluginVulns
via reddit https://ift.tt/bz87Lxt
Plugin Vulnerabilities
AI Helps Catch CSRF Vulnerability Being Introduced in to 100,000+ Install WordPress Plugin Modula
Decrypting Thecus NAS Firmware Images
https://ift.tt/L6eX78d
Submitted June 11, 2024 at 11:01PM by lightgrains
via reddit https://ift.tt/xakH3It
https://ift.tt/L6eX78d
Submitted June 11, 2024 at 11:01PM by lightgrains
via reddit https://ift.tt/xakH3It
CVE-2024-29824 Deep Dive: Ivanti EPM SQL Injection Remote Code Execution Vulnerability, IOCs, and POC
https://ift.tt/GZsdF28
Submitted June 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/5VTHm7M
https://ift.tt/GZsdF28
Submitted June 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/5VTHm7M
Horizon3.ai
CVE-2024-29824 Deep Dive: Ivanti EPM SQL Injection Remote Code Execution Vulnerability
CVE-2024-29824 Ivanti EPM SQL Injection Remote Code Execution Vulnerability. This blog details the internals of a SQLi RCE vulnerability.
BusKill Warrant Canary for 2024 H2 🕵️
https://ift.tt/mxfz7R4
Submitted June 12, 2024 at 10:02PM by maltfield
via reddit https://ift.tt/kxdwLbD
https://ift.tt/mxfz7R4
Submitted June 12, 2024 at 10:02PM by maltfield
via reddit https://ift.tt/kxdwLbD
BusKill
BusKill Canary #8 - BusKill
This post contains the cryptographically-signed BusKill warrant canary #008 for June 2024 to January 2025.
CVE-2024–4956 -Unauthenticated Path Traversal
https://ift.tt/phQEIFf
Submitted June 13, 2024 at 09:01PM by Justin_coco
via reddit https://ift.tt/CrwfR5L
https://ift.tt/phQEIFf
Submitted June 13, 2024 at 09:01PM by Justin_coco
via reddit https://ift.tt/CrwfR5L
Medium
POC — CVE-2024–4956 -Unauthenticated Path Traversal
POC — CVE-2024–4956 — Nexus Repository Manager 3 Unauthenticated Path Traversal
Introducing YetiHunter: An open-source tool to detect and hunt for Suspicious activity in Snowflake
https://ift.tt/r3NHFRn
Submitted June 13, 2024 at 10:27PM by permis0
via reddit https://ift.tt/qOD8N5S
https://ift.tt/r3NHFRn
Submitted June 13, 2024 at 10:27PM by permis0
via reddit https://ift.tt/qOD8N5S
permiso.io
Introducing YetiHunter: An open-source tool to detect and hunt for suspicious activity in Snowflake
YetiHunter is an open source tool that combines the indicators that Snowflake, Mandiant, DataDog and Permiso have into one easy to run noscript to detect and hunt for suspicious activity in Snowflake.
There are no Secrets || Exploiting Veeam CVE-2024-29855
https://ift.tt/omcq7na
Submitted June 13, 2024 at 09:57PM by juken
via reddit https://ift.tt/O3Pajul
https://ift.tt/omcq7na
Submitted June 13, 2024 at 09:57PM by juken
via reddit https://ift.tt/O3Pajul
Summoning Team
There are no Secrets || Exploiting Veeam CVE-2024-29855
This vulenrability is due to the fact that JWT secret used to generate authentication tokens was a hardcoded value which means an unauthenticated attacker can generate valid tokens for any user (not just the administrator) and login to the Veeam Recovery…
Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces: CVE-2023-51449 and CVE-2023-1561
https://ift.tt/miHq0Nu
Submitted June 14, 2024 at 06:59PM by scopedsecurity
via reddit https://ift.tt/Tf0kFwH
https://ift.tt/miHq0Nu
Submitted June 14, 2024 at 06:59PM by scopedsecurity
via reddit https://ift.tt/Tf0kFwH
Horizon3.ai
Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces
Exploiting file read vulnerabilities in Gradio to steal secrets from Hugging Face Spaces.
Type Juggling and Dangers of Loose Comparisons
https://ift.tt/PEIwNYW
Submitted June 14, 2024 at 10:46PM by HayMiz
via reddit https://ift.tt/BeELQlc
https://ift.tt/PEIwNYW
Submitted June 14, 2024 at 10:46PM by HayMiz
via reddit https://ift.tt/BeELQlc
haymiz@kali:~/blog$
Type Juggling and Dangers of Loose Comparisons
Exploring how type juggling leverages loose comparisons to breach web application security.
Encrypt/decrypt with SSH keys
https://ift.tt/PA8MDvF
Submitted June 15, 2024 at 05:32PM by yurichev
via reddit https://ift.tt/gxCR3MX
https://ift.tt/PA8MDvF
Submitted June 15, 2024 at 05:32PM by yurichev
via reddit https://ift.tt/gxCR3MX
In-Depth Cyberdefense Guide: Protecting Against Modern Threats
https://ift.tt/zTYRLMe
Submitted June 16, 2024 at 11:44PM by Dependent-Fishing630
via reddit https://ift.tt/mME6K9Q
https://ift.tt/zTYRLMe
Submitted June 16, 2024 at 11:44PM by Dependent-Fishing630
via reddit https://ift.tt/mME6K9Q
Iconv, set the charset to RCE (part 2): Remote code execution on Roundcube (CVE-2024-2961)
https://ift.tt/0JFrHsK
Submitted June 17, 2024 at 01:55PM by cfambionics
via reddit https://ift.tt/MBblDNK
https://ift.tt/0JFrHsK
Submitted June 17, 2024 at 01:55PM by cfambionics
via reddit https://ift.tt/MBblDNK
Ambionics
Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine (part 2)
In this blog post, we will explore a new way of exploiting the vulnerability on PHP, using direct calls to iconv(), and illustrate the vulnerability by targeting Roundcube, a popular PHP webmail.
Evaluating Security of banking apps against mobile theft: a Monzo case study
https://ift.tt/duU8J7f
Submitted June 17, 2024 at 03:23PM by adrian_rt
via reddit https://ift.tt/jiwVep3
https://ift.tt/duU8J7f
Submitted June 17, 2024 at 03:23PM by adrian_rt
via reddit https://ift.tt/jiwVep3
Cyber Security Services - London
The Best Security Features for Securing Phone and Banking Apps
Discover the risks of mobile phone theft and how to secure your device. Learn about the attack scenario targeting the Monzo banking app.
Abusing noscript reporting and tmux integration in iTerm2 for code execution (CVE-2024-38396)
https://ift.tt/TKV2uDP
Submitted June 17, 2024 at 03:02PM by nex25519
via reddit https://ift.tt/TQu0fzP
https://ift.tt/TKV2uDP
Submitted June 17, 2024 at 03:02PM by nex25519
via reddit https://ift.tt/TQu0fzP
Vin01’s Blog
Abusing noscript reporting and tmux integration in iTerm2 for code execution
Regression turned into RCE
ScriptBlock Smuggling: Spoofing PowerShell Security Logs and Bypassing AMSI Without Reflection or Patching
https://ift.tt/7QET4K0
Submitted June 17, 2024 at 06:31PM by Hubble_BC_Security
via reddit https://ift.tt/GF26Hzd
https://ift.tt/7QET4K0
Submitted June 17, 2024 at 06:31PM by Hubble_BC_Security
via reddit https://ift.tt/GF26Hzd
Bypassing Okta’s Passwordless MFA: Technical Analysis and Detection
https://ift.tt/FMvi3kI
Submitted June 17, 2024 at 05:52PM by Or1rez
via reddit https://ift.tt/dsIq6CX
https://ift.tt/FMvi3kI
Submitted June 17, 2024 at 05:52PM by Or1rez
via reddit https://ift.tt/dsIq6CX