Bypassing Okta’s Passwordless MFA: Technical Analysis and Detection
https://ift.tt/FMvi3kI
Submitted June 17, 2024 at 05:52PM by Or1rez
via reddit https://ift.tt/dsIq6CX
https://ift.tt/FMvi3kI
Submitted June 17, 2024 at 05:52PM by Or1rez
via reddit https://ift.tt/dsIq6CX
DERO cryptojacking takes a new shape
https://ift.tt/46Aitsp
Submitted June 16, 2024 at 03:19AM by apalasec
via reddit https://ift.tt/SuO6JjN
https://ift.tt/46Aitsp
Submitted June 16, 2024 at 03:19AM by apalasec
via reddit https://ift.tt/SuO6JjN
wiz.io
DERO cryptojacking adopts new techniques to evade detection | Wiz Blog
Wiz research shares how threat actors behind the 2023 DERO cryptojacking campaign have adapted their techniques, and how to mitigate your risk.
Microsoft Windows Endpoint Forensics Readiness Booster
https://ift.tt/7cbNLGH
Submitted June 17, 2024 at 06:55PM by GelosSnake
via reddit https://ift.tt/Nry1AUw
https://ift.tt/7cbNLGH
Submitted June 17, 2024 at 06:55PM by GelosSnake
via reddit https://ift.tt/Nry1AUw
profero.io
Microsoft Windows Endpoint Forensics Readiness Booster
Enhance Windows forensics with our guide. Configure built-in logs for better incident response and breach detection using built-in tools, no extra software need
Exfiltrate WhatsApp chat, or internal data of any Android app, running on Android 12 or 13 by exploiting CVE-2024-0044 vulnerability
https://ift.tt/azyc1OH
Submitted June 17, 2024 at 10:02PM by barakadua131
via reddit https://ift.tt/CtyZSbg
https://ift.tt/azyc1OH
Submitted June 17, 2024 at 10:02PM by barakadua131
via reddit https://ift.tt/CtyZSbg
Mobile Hacker
Exfiltrate sensitive user data from apps on Android 12 and 13 using CVE-2024-0044 vulnerability Mobile Hacker
With physical access to Android device with enabled ADB debugging running Android 12 or 13 before receiving March 2024 security patch, it is possible to access internal data of any user installed app by misusing CVE-2024-0044 vulnerability. Internal data…
School question.
https://ift.tt/Fnicmae
Submitted June 18, 2024 at 05:19AM by Horror_Command8068
via reddit https://ift.tt/SHXsmpf
https://ift.tt/Fnicmae
Submitted June 18, 2024 at 05:19AM by Horror_Command8068
via reddit https://ift.tt/SHXsmpf
Mobile OAuth Attacks - iOS URL Scheme Hijacking Revamped
https://ift.tt/GjCWwRA
Submitted June 19, 2024 at 12:38AM by techdash
via reddit https://ift.tt/UXbVxLv
https://ift.tt/GjCWwRA
Submitted June 19, 2024 at 12:38AM by techdash
via reddit https://ift.tt/UXbVxLv
Evan Connelly
Mobile OAuth Attacks - iOS URL Scheme Hijacking Revamped
Summary
We (Julien Ahrens @MrTuxracer and myself @Evan_Connelly) identified nearly 30 popular apps, as well as a feature within iOS itself, vulnerable to an attack in which any installed iOS app from the Apple App Store could perform an account takeover of…
We (Julien Ahrens @MrTuxracer and myself @Evan_Connelly) identified nearly 30 popular apps, as well as a feature within iOS itself, vulnerable to an attack in which any installed iOS app from the Apple App Store could perform an account takeover of…
Physical security management help
https://ift.tt/mGFh91L
Submitted June 19, 2024 at 12:31AM by discreetdawg8991
via reddit https://ift.tt/utNTro4
https://ift.tt/mGFh91L
Submitted June 19, 2024 at 12:31AM by discreetdawg8991
via reddit https://ift.tt/utNTro4
Everbridge
What is PSIM? Guide to what PSIM means and its benefits
PSIM software integrates security apps, automates workflows, and unifies device control for a seamless user experience.
Active Directory Methodology in Pentesting: A Comprehensive Guide
https://ift.tt/dtSiaFX
Submitted June 19, 2024 at 01:41PM by Justin_coco
via reddit https://ift.tt/F0Hd7hf
https://ift.tt/dtSiaFX
Submitted June 19, 2024 at 01:41PM by Justin_coco
via reddit https://ift.tt/F0Hd7hf
Medium
Active Directory Methodology in Pentesting: A Comprehensive Guide
In today’s digital landscape, Active Directory (AD) serves as the backbone for managing network resources in most enterprise environments…
Extending Burp Suite for fun and profit - The Montoya way - Part 5
https://ift.tt/r7w68p9
Submitted June 19, 2024 at 05:28PM by 0xdea
via reddit https://ift.tt/5EuY3i0
https://ift.tt/r7w68p9
Submitted June 19, 2024 at 05:28PM by 0xdea
via reddit https://ift.tt/5EuY3i0
HN Security
Extending Burp Suite for fun and profit - The Montoya way - Part 5 - HN Security
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
A Case Study About Exploiting the Flexibility of Email Addresses For OS Command Injection
https://ift.tt/P8bMXsi
Submitted June 20, 2024 at 01:33PM by parzel
via reddit https://ift.tt/2WYOhxF
https://ift.tt/P8bMXsi
Submitted June 20, 2024 at 01:33PM by parzel
via reddit https://ift.tt/2WYOhxF
Threat modeling an IdP compromise, and hardening (Teleport specific). Full tech paper.
https://ift.tt/mu3c8hk
Submitted June 21, 2024 at 01:58PM by nibblesec
via reddit https://ift.tt/jmn530D
https://ift.tt/mu3c8hk
Submitted June 21, 2024 at 01:58PM by nibblesec
via reddit https://ift.tt/jmn530D
Analysis of CVE-2024-25065: Apache OFBiz Security bypass
https://ift.tt/k1eKZHn
Submitted June 21, 2024 at 05:14PM by SL7reach
via reddit https://ift.tt/xwaWDpL
https://ift.tt/k1eKZHn
Submitted June 21, 2024 at 05:14PM by SL7reach
via reddit https://ift.tt/xwaWDpL
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
Analysis of CVE-2024-25065: Apache OFBiz Security bypass
Introduction CVE-2024-25065 is a vulnerability that exists in Apache OFBiz before version 18.12.12. It is a path traversal vulnerability that allows authentication bypass through the contextPath...
Reverse Engineering and Exploiting Augentix System on Chip Unicorn Binary
https://ift.tt/PEKnOCs
Submitted June 22, 2024 at 03:56AM by somersetrecon
via reddit https://ift.tt/vdXrQ3A
https://ift.tt/PEKnOCs
Submitted June 22, 2024 at 03:56AM by somersetrecon
via reddit https://ift.tt/vdXrQ3A
Somerset Recon
Reverse Engineering The Unicorn — Somerset Recon
While reversing a device, we stumbled across an interesting binary named unicorn . The binary appeared to be a developer utility potentially related to the Augentix SoC SDK. The unicorn binary is only executed when the device is set to developer mode. Fortunately…
Zip Slip meets Artifactory: A Bug Bounty Story
https://ift.tt/hZoDydb
Submitted June 23, 2024 at 04:16PM by eg1x
via reddit https://ift.tt/VxWF5BN
https://ift.tt/hZoDydb
Submitted June 23, 2024 at 04:16PM by eg1x
via reddit https://ift.tt/VxWF5BN
Karmainsecurity
Zip Slip meets Artifactory: A Bug Bounty Story | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Understanding Protected Management Frames
https://ift.tt/HVhe7py
Submitted June 23, 2024 at 03:48PM by thexerocouk
via reddit https://ift.tt/ILytpcn
https://ift.tt/HVhe7py
Submitted June 23, 2024 at 03:48PM by thexerocouk
via reddit https://ift.tt/ILytpcn
Monitor file system changes using fsmon on Android, Linux, iOS, OS X
https://ift.tt/7HsR65l
Submitted June 24, 2024 at 06:11PM by barakadua131
via reddit https://ift.tt/X0MmBqr
https://ift.tt/7HsR65l
Submitted June 24, 2024 at 06:11PM by barakadua131
via reddit https://ift.tt/X0MmBqr
Mobile Hacker
Monitoring Android file system with fsmon
FileSystem Monitor (fsmon) allows you to monitor file system events at runtime on Linux, OSX, iOS and Android systems. Useful for bug bounty hunters, malware analyst
Crack Faster, Hack Smarter: Custom Hashcat Module for Apache Shiro 1 SHA-512
https://ift.tt/Ht4JkSQ
Submitted June 25, 2024 at 12:30AM by meterpretersession1
via reddit https://ift.tt/C7qG6Kr
https://ift.tt/Ht4JkSQ
Submitted June 25, 2024 at 12:30AM by meterpretersession1
via reddit https://ift.tt/C7qG6Kr
Medium
Crack Faster, Hack Smarter: Custom Hashcat Module for Apache Shiro 1 SHA-512
Custom Hashcat Module for Apache Shiro 1 SHA-512
Two bluetooth vulnerabilities in Windows (write-up: CVE-2023-24871 + CVE-2023-23388)
https://ift.tt/MKNhWbJ
Submitted June 25, 2024 at 12:14AM by goodbyeselene
via reddit https://ift.tt/KbiTlks
https://ift.tt/MKNhWbJ
Submitted June 25, 2024 at 12:14AM by goodbyeselene
via reddit https://ift.tt/KbiTlks
###
Two bluetooth vulnerabilities in Windows
Announcing the Ronin 2.1.0 Open Beta. Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development.
https://ift.tt/4VTENOy
Submitted June 25, 2024 at 09:38AM by postmodern
via reddit https://ift.tt/4ygI1zB
https://ift.tt/4VTENOy
Submitted June 25, 2024 at 09:38AM by postmodern
via reddit https://ift.tt/4ygI1zB
Medusa Reborn: A New Compact Variant Discovered / Cleafy Labs
https://ift.tt/jHJ7oML
Submitted June 25, 2024 at 05:36PM by f3d_0x0
via reddit https://ift.tt/wpQ5ChU
https://ift.tt/jHJ7oML
Submitted June 25, 2024 at 05:36PM by f3d_0x0
via reddit https://ift.tt/wpQ5ChU
Cleafy
Medusa Reborn: A New Compact Variant Discovered | Cleafy Labs
Discover the latest insights from the Cleafy Threat Intelligence team on new fraud campaigns involving the Medusa (TangleBot) banking trojan. Learn about Medusa's sophisticated capabilities, recent updates, and shifts in distribution strategies targeting…
ORM Leak vulnerabilities
https://ift.tt/7EBDf1I
Submitted June 25, 2024 at 06:11PM by albinowax
via reddit https://ift.tt/b3OzsYn
https://ift.tt/7EBDf1I
Submitted June 25, 2024 at 06:11PM by albinowax
via reddit https://ift.tt/b3OzsYn
Elttam
plORMbing your Django ORM - elttam
elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.