Black Hat USA: Lessons Learned After CrowdStrike Incident
https://ift.tt/tBMeWXQ
Submitted August 09, 2024 at 10:46AM by Background_Value_610
via reddit https://ift.tt/VflOzb0
https://ift.tt/tBMeWXQ
Submitted August 09, 2024 at 10:46AM by Background_Value_610
via reddit https://ift.tt/VflOzb0
ChannelE2E
Black Hat USA: Lessons Learned After CrowdStrike Incident
Black Hat USA is a great outlet for sharing lessons learned after the CrowdStrike incident.
Exploiting pfsense Remote Code Execution – CVE-2022-31814
https://ift.tt/3dDX8At
Submitted August 09, 2024 at 10:43AM by Ancient_Title_1860
via reddit https://ift.tt/W9yrl7i
https://ift.tt/3dDX8At
Submitted August 09, 2024 at 10:43AM by Ancient_Title_1860
via reddit https://ift.tt/W9yrl7i
Laburity - Cyber Security Services
Exploiting pfsense Remote Code Execution – CVE-2022-31814 - Laburity
Greetings everyone, In this write-up, we will be exploring the interesting exploitation that has been done against the pfsense CVE-2022-31814. What is pfsense? pfSense software is a FreeBSD-based operating system designed to install and configure a firewall…
Apache OFBiz RCE Scanner (CVE-2024-38856)
https://ift.tt/Qlh3TMU
Submitted August 08, 2024 at 08:37AM by FreshConversation639
via reddit https://ift.tt/NYAbmSy
https://ift.tt/Qlh3TMU
Submitted August 08, 2024 at 08:37AM by FreshConversation639
via reddit https://ift.tt/NYAbmSy
GitHub
GitHub - securelayer7/CVE-2024-38856_Scanner: Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856) - securelayer7/CVE-2024-38856_Scanner
BBoT 2.0 Released!
https://ift.tt/npm12Vl
Submitted August 09, 2024 at 07:44PM by aconite33
via reddit https://ift.tt/ZTW8o3J
https://ift.tt/npm12Vl
Submitted August 09, 2024 at 07:44PM by aconite33
via reddit https://ift.tt/ZTW8o3J
Blacklanternsecurity
BBOT 2.0 - Release Announcement
The recursive internet scanner gets an upgrade
We discovered critical vulnerabilities in 6 AWS services
https://ift.tt/NReHrvU
Submitted August 10, 2024 at 04:31AM by Pale_Fly_2673
via reddit https://ift.tt/8gtjnrf
https://ift.tt/NReHrvU
Submitted August 10, 2024 at 04:31AM by Pale_Fly_2673
via reddit https://ift.tt/8gtjnrf
Aqua
Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources
We discovered critical vulnerabilities in six AWS services that range between RCE, full account takeover, manipulation and more.
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server
https://ift.tt/CKJkj8a
Submitted August 10, 2024 at 08:16AM by hashkitten
via reddit https://ift.tt/hqfOm1p
https://ift.tt/CKJkj8a
Submitted August 10, 2024 at 08:16AM by hashkitten
via reddit https://ift.tt/hqfOm1p
Orange Tsai
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
[ 繁體中文版本 | English Version ] Hey there! This is my research on Apache HTTP Server presented at Black Hat USA 2024. Additionally, this research will also be presented at HITCON and OrangeCon. If you
What’s the worst place to leave your secrets? – Research into what happens to AWS credentials that are left in public places
https://ift.tt/7w8HpaT
Submitted August 11, 2024 at 12:56PM by cydan99
via reddit https://ift.tt/TKQsjMW
https://ift.tt/7w8HpaT
Submitted August 11, 2024 at 12:56PM by cydan99
via reddit https://ift.tt/TKQsjMW
Cybenari
What’s the worst place to leave your secrets? – Research into what happens to AWS credentials that are left in public places -…
Microprobing with ICEBite - A Definitive guide fo soldeless testing probes - Hello! Welcome to IoTSecurity101 by @iotsecurity101
https://ift.tt/4nDY17B
Submitted August 12, 2024 at 10:29AM by v33ruiot
via reddit https://ift.tt/noMj2hB
https://ift.tt/4nDY17B
Submitted August 12, 2024 at 10:29AM by v33ruiot
via reddit https://ift.tt/noMj2hB
www.iotsecurity101.org
Microprobing with ICEBite - A Definitive guide fo soldeless testing probes - Hello! Welcome to IoTSecurity101
This innovative tool ensures precision and convenience without the need for soldering, circuit inspe
SQL Injection Isn't Dead - Smuggling Queries at the Protocol Level
https://ift.tt/Dxg4AjH
Submitted August 13, 2024 at 12:24AM by lormayna
via reddit https://ift.tt/qzJXGlg
https://ift.tt/Dxg4AjH
Submitted August 13, 2024 at 12:24AM by lormayna
via reddit https://ift.tt/qzJXGlg
All Security News | With allinfosecnews going down, I decided to keep the dream going. It was my favorite site to visit daily so I couldn't go without it.
https://allsecnews.com/
Submitted August 13, 2024 at 12:05AM by CognitoCyber
via reddit https://ift.tt/yci68NW
https://allsecnews.com/
Submitted August 13, 2024 at 12:05AM by CognitoCyber
via reddit https://ift.tt/yci68NW
Allsecnews
All Security News - Home
Stay updated with the latest in Cyber Security, InfoSec, Cryptography, Online Privacy, Hacking, Vulnerability and Threat Research. Discover top news, podcasts, and expert insights, all aggregated in one place
Announcing the Bug Bounty program pack 1.0
https://ift.tt/fVWCyrB
Submitted August 13, 2024 at 02:30AM by SecTemplates
via reddit https://ift.tt/enThtu7
https://ift.tt/fVWCyrB
Submitted August 13, 2024 at 02:30AM by SecTemplates
via reddit https://ift.tt/enThtu7
SecTemplates.com
Announcing the Bug Bounty program pack 1.0
Introduction I have participated in, and built bug bounty programs at companies such as PayPal and Box and supported similar programs at several other companies. Below is part of a whiteboard session from 2012, conducted before launching PayPal's bug bounty…
How to find XML External Entity (XXE) vulnerabilities in Code (C++)
https://ift.tt/5RsZorj
Submitted August 13, 2024 at 10:26AM by Electronic_Village_8
via reddit https://ift.tt/2cNQqw4
https://ift.tt/5RsZorj
Submitted August 13, 2024 at 10:26AM by Electronic_Village_8
via reddit https://ift.tt/2cNQqw4
mqst
Security Code Review: Finding XML vulnerabilities in Code [1/2]
In this blog post series, we embark on a Journey of Secure Code Mastery! I'm delighted to unveil the first chapter of our in-depth blog series on Security Code Reviews.
Protecting Mission Critical Assets within the Energy & Utilities Industry
https://ift.tt/5zh8DTa
Submitted August 13, 2024 at 11:47AM by zolakrystie
via reddit https://ift.tt/hRgLbkr
https://ift.tt/5zh8DTa
Submitted August 13, 2024 at 11:47AM by zolakrystie
via reddit https://ift.tt/hRgLbkr
NextLabs
Energy & Utilities
Protecting Mission Critical Assets
Companies in the energy industry today are confronted with unprecedented cyber security challenges. They need to safeguard their mission-critical information assets against criminal hackers and internal employees who…
Companies in the energy industry today are confronted with unprecedented cyber security challenges. They need to safeguard their mission-critical information assets against criminal hackers and internal employees who…
ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts
https://ift.tt/XzE2qSk
Submitted August 13, 2024 at 05:26PM by Due_Lengthiness_9329
via reddit https://ift.tt/wQAlgr5
https://ift.tt/XzE2qSk
Submitted August 13, 2024 at 05:26PM by Due_Lengthiness_9329
via reddit https://ift.tt/wQAlgr5
Unit 42
ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts
New research uncovers a potential attack vector on GitHub repositories, with leaked tokens leading to potential compromise of services.
Too Many Secrets: Proprietary Encryption Protocol Analysis in VStarcam CB73 Security Camera
https://ift.tt/XOim0Ba
Submitted August 13, 2024 at 05:24PM by mattbrwn0
via reddit https://ift.tt/3ZlVcTH
https://ift.tt/XOim0Ba
Submitted August 13, 2024 at 05:24PM by mattbrwn0
via reddit https://ift.tt/3ZlVcTH
Compromising Microsoft's AI Healthcare Chatbot Service (Critical Issue with Cross-Tenant Access)
https://ift.tt/EZHti7c
Submitted August 13, 2024 at 06:32PM by dinobyt3s
via reddit https://ift.tt/cqHFtdC
https://ift.tt/EZHti7c
Submitted August 13, 2024 at 06:32PM by dinobyt3s
via reddit https://ift.tt/cqHFtdC
Tenable®
Compromising Microsoft's AI Healthcare Chatbot Service
Tenable Research discovered multiple privilege-escalation issues in the Azure Health Bot Service via a server-side request forgery (SSRF), which allowed researchers access to cross-tenant resources.
Real World Cloud TTPs vs. Canary Infrastructure
https://ift.tt/QaJ0LwM
Submitted August 13, 2024 at 07:39PM by tracebit
via reddit https://ift.tt/P5WF1qb
https://ift.tt/QaJ0LwM
Submitted August 13, 2024 at 07:39PM by tracebit
via reddit https://ift.tt/P5WF1qb
Tracebit
Canary Infrastructure vs. Real World TTPs | Tracebit
We investigate three recent AWS security incidents and discuss how canaries could help you detect these early, and throughout the attack lifecycle.
Snaffler Parser (HTML, TXT, CSV and more output / Pure PowerShell no dependencies)
https://ift.tt/jFHtcs4
Submitted August 14, 2024 at 12:02AM by GonzoZH
via reddit https://ift.tt/7mhAzLu
https://ift.tt/jFHtcs4
Submitted August 14, 2024 at 12:02AM by GonzoZH
via reddit https://ift.tt/7mhAzLu
GitHub
GitHub - zh54321/SnafflerParser: Parses Snaffler output file and generate beautified outputs.
Parses Snaffler output file and generate beautified outputs. - zh54321/SnafflerParser
Wormable Substack XSS
https://ift.tt/i2VbHw7
Submitted August 12, 2024 at 11:46PM by Mission-Egg7495
via reddit https://ift.tt/HADKCrm
https://ift.tt/i2VbHw7
Submitted August 12, 2024 at 11:46PM by Mission-Egg7495
via reddit https://ift.tt/HADKCrm
blog.calif.io
Wormable Substack XSS
We found a stored Cross-Site Scripting (XSS) vulnerability in Substack.
RCE in Windows IPv6 Stack (CVE-2024-38063)
https://ift.tt/crePQoK
Submitted August 14, 2024 at 09:16PM by nicholashairs
via reddit https://ift.tt/mNEfU6v
https://ift.tt/crePQoK
Submitted August 14, 2024 at 09:16PM by nicholashairs
via reddit https://ift.tt/mNEfU6v
Lil Pwny Rides Again: Streamline Your Active Directory Password Audits with the New 3.2.0 Update
https://ift.tt/L4vXYT9
Submitted August 15, 2024 at 02:24AM by TheAlphaBravo
via reddit https://ift.tt/vZAO4Lm
https://ift.tt/L4vXYT9
Submitted August 15, 2024 at 02:24AM by TheAlphaBravo
via reddit https://ift.tt/vZAO4Lm
PaperMtn
Lil Pwny Rides Again: Streamline Your Active Directory Password Audits with the New 3.2.0 Update
I’m excited to announce the release of Lil Pwny 3.2.0, featuring powerful new enhancements to the Active Directory password auditing tool. This update brings significant improvements and new …