Crowdstrike Outage brings down the Internet
https://ift.tt/BOiycsI
Submitted July 19, 2024 at 10:25PM by Altrntiv-to-security
via reddit https://ift.tt/yA7DiE4
https://ift.tt/BOiycsI
Submitted July 19, 2024 at 10:25PM by Altrntiv-to-security
via reddit https://ift.tt/yA7DiE4
DarkRelay
Crowdstrike Outage: Critical Services Impacted
Windows users have encountered a significant outage, part of a global outage. On July 19, 2024, Crowdstrike users experienced outage
Electron JS ASAR Integrity Bypass
https://ift.tt/litjFBf
Submitted July 20, 2024 at 12:42AM by Ano_F
via reddit https://ift.tt/aTXUPrl
https://ift.tt/litjFBf
Submitted July 20, 2024 at 12:42AM by Ano_F
via reddit https://ift.tt/aTXUPrl
Medium
Electron JS ASAR Integrity Bypass
I recently created an Electron JS-based Windows and MacOS application. The newer version of Electron has Integrity detection which…
RDP security consequences of TLS vs. NLA from a threat exposure perspective - GoSecure
https://ift.tt/ot9WiCE
Submitted July 20, 2024 at 04:24AM by Willsec
via reddit https://ift.tt/MxLsfgS
https://ift.tt/ot9WiCE
Submitted July 20, 2024 at 04:24AM by Willsec
via reddit https://ift.tt/MxLsfgS
GoSecure
Navigating the RDP security consequences of TLS vs. NLA from a threat exposure perspective
This blogpost explores the choice of security protocols and their consequences RDP Security by navigating Transport Layer Security (TLS) and Network Level Authentication (NLA) of Remote Desktop Protocol (RDP). Attack Trends and Geographic Dynamics are explored…
🚀 Excited to share my blog on Trusted Platform Computing!This blog aims to explain the complexities of #TPM, making them accessible and relevant to our daily tech interactions and possibly creating solutions around it.
https://ift.tt/qLAXaW7
Submitted July 21, 2024 at 07:17PM by L0u51f3r007
via reddit https://ift.tt/OlVstLh
https://ift.tt/qLAXaW7
Submitted July 21, 2024 at 07:17PM by L0u51f3r007
via reddit https://ift.tt/OlVstLh
S3curity Ninja
Trusted Platform Module (TPM)
Discover Trusted Platform Modules (TPMs) for boosted security in computing. Understand their history, functions, architecture and use-cases.
Comprehensive Guide to Purchasing the Best NetFlow Analyzer 2024
https://ift.tt/UR2B9qd
Submitted July 22, 2024 at 12:03PM by Suitable_Grab8859
via reddit https://ift.tt/0PrGHQC
https://ift.tt/UR2B9qd
Submitted July 22, 2024 at 12:03PM by Suitable_Grab8859
via reddit https://ift.tt/0PrGHQC
Trisul Network Analytics
Purchasing NetFlow Analyzer In 2024: A Comprehensive Guide - Trisul
Investing in a NetFlow Analyzer boosts operational excellence and ROI. This guide will help you find the right fit.
A public database "The API Threat Landscape", summarizing information about publicly disclosed API security data breaches from 2022
https://ift.tt/IGANSyK
Submitted July 22, 2024 at 01:55PM by AlarmingApartment236
via reddit https://ift.tt/JwpWrRU
https://ift.tt/IGANSyK
Submitted July 22, 2024 at 01:55PM by AlarmingApartment236
via reddit https://ift.tt/JwpWrRU
Hacking a High End Fan Away From Its Cloud Overlords
https://ift.tt/UBD8JqN
Submitted July 22, 2024 at 03:39PM by ouaibe
via reddit https://ift.tt/LdcKwBH
https://ift.tt/UBD8JqN
Submitted July 22, 2024 at 03:39PM by ouaibe
via reddit https://ift.tt/LdcKwBH
GitHub
GitHub - ouaibe/dreo-cloudcutter: A repository describing how we can cut some Dreo fans from the cloud, allowing them to run completely…
A repository describing how we can cut some Dreo fans from the cloud, allowing them to run completely locally via HA. - ouaibe/dreo-cloudcutter
WebAssembly and Security: a review
https://ift.tt/o7xmqEV
Submitted July 22, 2024 at 07:30PM by daindragon2
via reddit https://ift.tt/ktfhC72
https://ift.tt/o7xmqEV
Submitted July 22, 2024 at 07:30PM by daindragon2
via reddit https://ift.tt/ktfhC72
arXiv.org
WebAssembly and Security: a review
WebAssembly is revolutionizing the approach to developing modern applications. Although this technology was born to create portable and performant modules in web browsers, currently, its...
3 ways to get Remote Code Execution in Kafka UI
https://ift.tt/GeymU6O
Submitted July 22, 2024 at 08:54PM by artsploit
via reddit https://ift.tt/oaEjX1I
https://ift.tt/GeymU6O
Submitted July 22, 2024 at 08:54PM by artsploit
via reddit https://ift.tt/oaEjX1I
The GitHub Blog
3 ways to get Remote Code Execution in Kafka UI
In this blog post, we'll explain how we discovered three critical vulnerabilities in Kafka UI and how they can be exploited.
Inside Doppelganger – How Russia uses EU companies for its propaganda
https://ift.tt/nvt9yj8
Submitted July 22, 2024 at 10:37PM by Substantial-Bag202
via reddit https://ift.tt/jcG0syW
https://ift.tt/nvt9yj8
Submitted July 22, 2024 at 10:37PM by Substantial-Bag202
via reddit https://ift.tt/jcG0syW
CORRECTIV
Inside Doppelganger – How Russia uses EU companies for its propaganda
How Doppelganger, one of the biggest Russian disinformation campaigns, is using EU companies to keep spreading its propaganda – despite sanctions.
Web Browser Notification Threat More Alarming than Expected - GoSecure
https://ift.tt/oGjmTPZ
Submitted July 23, 2024 at 12:00AM by Willsec
via reddit https://ift.tt/2LeaSdB
https://ift.tt/oGjmTPZ
Submitted July 23, 2024 at 12:00AM by Willsec
via reddit https://ift.tt/2LeaSdB
GoSecure
Web Browser Notification Threat More Alarming than Expected
Explore our recent investigation that reveals how web browser notification service workers are being exploited by malicious actors to deliver ads and harmful code without detection. This blog discusses the techniques used, including undetectable user interaction…
Ronin 2.1.0 has finally been released! This release includes new database tables, new payloads, a new recon engine, a local Web UI, and more. Ronin is a Ruby toolkit for security research and development.
https://ift.tt/ENKo7pi
Submitted July 23, 2024 at 05:07AM by postmodern
via reddit https://ift.tt/ATHJPVu
https://ift.tt/ENKo7pi
Submitted July 23, 2024 at 05:07AM by postmodern
via reddit https://ift.tt/ATHJPVu
Announcing the incident response program pack 1.0
https://ift.tt/4YlUKyC
Submitted July 23, 2024 at 06:42AM by SecTemplates
via reddit https://ift.tt/2Li4hmC
https://ift.tt/4YlUKyC
Submitted July 23, 2024 at 06:42AM by SecTemplates
via reddit https://ift.tt/2Li4hmC
SecTemplates.com
Announcing the incident response program pack 1.0
I'm pleased to announce our first release, the Incident Response Program Pack. The goal of this release is to provide you with everything you need to establish a functioning security incident response program at your company. In this pack, we cover Definitions:…
Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android
https://ift.tt/0BD8jCR
Submitted July 23, 2024 at 03:26PM by _vavkamil_
via reddit https://ift.tt/xAif71S
https://ift.tt/0BD8jCR
Submitted July 23, 2024 at 03:26PM by _vavkamil_
via reddit https://ift.tt/xAif71S
Welivesecurity
Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android
ESET researchers discovered a zero-day Telegram for Android exploit that allows sending malicious files disguised as videos.
Blocking EDR Telemetry via PitM Network Filtering
https://ift.tt/oJgf6kT
Submitted July 23, 2024 at 02:02PM by eitot8
via reddit https://ift.tt/TcXg1Yp
https://ift.tt/oJgf6kT
Submitted July 23, 2024 at 02:02PM by eitot8
via reddit https://ift.tt/TcXg1Yp
GitHub
GitHub - TierZeroSecurity/edr_blocker: Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is…
Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination IP addresses are parsed based on the server name in TLS Cli...
CVE-2019-8805: Apple EndpointSecurity framework Privilege Escalation
https://ift.tt/d26Bs73
Submitted July 23, 2024 at 08:02PM by appsec1337
via reddit https://ift.tt/u41FabS
https://ift.tt/d26Bs73
Submitted July 23, 2024 at 08:02PM by appsec1337
via reddit https://ift.tt/u41FabS
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
CVE-2019-8805: Apple EndpointSecurity framework Privilege Escalation
CVE-2019-8805 is a privilege escalation vulnerability found in macOS Catalina 10.15 by Scott Knight. This vulnerability occurs through the Endpoint Security framework introduced in Catalina 10.15....
NO_WILDCARD: How we discovered the AWS Organization ID for any AWS Account
https://ift.tt/arcMH2Z
Submitted July 23, 2024 at 10:03PM by tracebit
via reddit https://ift.tt/iGucarQ
https://ift.tt/arcMH2Z
Submitted July 23, 2024 at 10:03PM by tracebit
via reddit https://ift.tt/iGucarQ
Tracebit
NO_WILDCARD: How I discovered the Organization ID of any AWS Account
Our latest research into VPC Endpoint Policy causes AWS to introduce significant changes!
Announcing the Bug Bounty program pack 1.0
https://ift.tt/5EWu1AB
Submitted July 24, 2024 at 05:04AM by SecTemplates
via reddit https://ift.tt/FNPSYTf
https://ift.tt/5EWu1AB
Submitted July 24, 2024 at 05:04AM by SecTemplates
via reddit https://ift.tt/FNPSYTf
SecTemplates.com
Announcing the Bug Bounty program pack 1.0
Introduction I have participated in, and built bug bounty programs at companies such as PayPal and Box and supported similar programs at several other companies. Below is part of a whiteboard session from 2012, conducted before launching PayPal's bug bounty…
Let’s Encrypt Intent to End OCSP Service
https://ift.tt/pVdE1kb
Submitted July 24, 2024 at 01:02AM by c0r0n3r
via reddit https://ift.tt/aq2oS9x
https://ift.tt/pVdE1kb
Submitted July 24, 2024 at 01:02AM by c0r0n3r
via reddit https://ift.tt/aq2oS9x
letsencrypt.org
Intent to End OCSP Service
Today we are announcing our intent to end Online Certificate Status Protocol (OCSP) support in favor of Certificate Revocation Lists (CRLs) as soon as possible. OCSP and CRLs are both mechanisms by which CAs can communicate certificate revocation information…
Gouge: Burp Suite extension to extract URLs from a webpage & all its JS files too.
https://ift.tt/761BKfN
Submitted July 23, 2024 at 12:01PM by Electronic_Village_8
via reddit https://ift.tt/1DKj7OU
https://ift.tt/761BKfN
Submitted July 23, 2024 at 12:01PM by Electronic_Village_8
via reddit https://ift.tt/1DKj7OU
GitHub
GitHub - mqst/gouge: Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different…
Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp Suite - mqst/gouge
Studying 0days: How we hacked Anki, the world's most popular flashcard app
https://ift.tt/09rZN8I
Submitted July 24, 2024 at 08:58PM by J_ake20o4
via reddit https://ift.tt/SKOtUru
https://ift.tt/09rZN8I
Submitted July 24, 2024 at 08:58PM by J_ake20o4
via reddit https://ift.tt/SKOtUru
Skii.dev
Studying 0days: How we hacked Anki, the world's most popular flashcard app
It took us 10 days to go from “We think this might be vulnerable” to full-blown remote code execution, including the 7 days we were both on holiday.