CVE-2024-29847 Deep Dive: Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data Remote Code Execution Vulnerability – Horizon3.ai
https://ift.tt/MGqi2U6
Submitted September 13, 2024 at 08:13PM by scopedsecurity
via reddit https://ift.tt/D4OhawG
https://ift.tt/MGqi2U6
Submitted September 13, 2024 at 08:13PM by scopedsecurity
via reddit https://ift.tt/D4OhawG
Horizon3.ai
CVE-2023-28324 Deep Dive: Ivanti Endpoint Manager AgentPortal Improper Input Validation
CVE-2023-28324 Ivanti Endpoint Manager AgentPortal Improper Input Validation Remote Code Execution Vulnerability.
Exploring Deserialization Attacks and Their Effects
https://ift.tt/Kh1oLWl
Submitted September 13, 2024 at 10:39PM by HayMiz
via reddit https://ift.tt/qW6uDtj
https://ift.tt/Kh1oLWl
Submitted September 13, 2024 at 10:39PM by HayMiz
via reddit https://ift.tt/qW6uDtj
haymiz@kali:~/blog$
Exploring Deserialization Attacks and Their Effects
Uncover how deserialization attacks work with real-world example and learn how to mitigate their risks.
Acquiring Malicious Browser Extension Samples on a Shoestring Budget
https://ift.tt/vnlcRJE
Submitted September 14, 2024 at 06:14PM by dashboard_monkey
via reddit https://ift.tt/9dO3bBG
https://ift.tt/vnlcRJE
Submitted September 14, 2024 at 06:14PM by dashboard_monkey
via reddit https://ift.tt/9dO3bBG
pepe berba
Acquiring Malicious Browser Extension Samples on a Shoestring Budget
Cracking the simple encryption scheme used by Genesis Market to hunt for malicious browser extensions
Attacking PowerShell CLIXML Deserialization
https://ift.tt/9dqRcJ4
Submitted September 15, 2024 at 10:16PM by 19829381
via reddit https://ift.tt/LwzXFgy
https://ift.tt/9dqRcJ4
Submitted September 15, 2024 at 10:16PM by 19829381
via reddit https://ift.tt/LwzXFgy
Truesec
Attacking PowerShell CLIXML Deserialization
In this article, we will learn that using PowerShell's CLIXML deserialization could lead to undesired effects, including remote code execution.
Escalating from Reader to Contributor in Azure API Management
https://ift.tt/xrOIoyt
Submitted September 15, 2024 at 09:43PM by piraterapper
via reddit https://ift.tt/QRa8ft6
https://ift.tt/xrOIoyt
Submitted September 15, 2024 at 09:43PM by piraterapper
via reddit https://ift.tt/QRa8ft6
Binary Security AS
Escalating from Reader to Contributor in Azure API Management
This blog post shows how a user with Reader-level access to an Azure API Management resource actually had the equivalent of Contributor-level access, allowing the user to read, modify and even delete configurations of the resource via the Direct Management…
Exploiting Microsoft Kernel Applocker Driver (CVE-2024-38041)
https://ift.tt/ikZKWP0
Submitted September 16, 2024 at 06:42PM by CyberSecurityIs
via reddit https://ift.tt/LWQudJV
https://ift.tt/ikZKWP0
Submitted September 16, 2024 at 06:42PM by CyberSecurityIs
via reddit https://ift.tt/LWQudJV
Csacyber
Exploiting Microsoft Kernel Applocker Driver (CVE-2024-38041)
In recent July Patch Tuesday Microsoft patched a vulnerability in the Microsoft Kernel driver appid.sys, which is the central driver behind AppLocker, the application whitelisting technology built into Windows.
Hacking the Planet - A DEFCON ICS CTF 2024 Retrospective
https://ift.tt/4hG5vC6
Submitted September 16, 2024 at 08:41PM by mdulin2
via reddit https://ift.tt/P7YeN18
https://ift.tt/4hG5vC6
Submitted September 16, 2024 at 08:41PM by mdulin2
via reddit https://ift.tt/P7YeN18
Strikeout Security Blog
Hacking the Planet - A DEFCON ICS CTF 2024 Retrospective
Red Alert ICS CTF Review. Winning a black badge and breaking smart cities.
CVE-2024-8190: Investigating CISA KEV Ivanti Cloud Service Appliance Command Injection Vulnerability
https://ift.tt/MDL5Xnd
Submitted September 16, 2024 at 09:18PM by scopedsecurity
via reddit https://ift.tt/T1ihELv
https://ift.tt/MDL5Xnd
Submitted September 16, 2024 at 09:18PM by scopedsecurity
via reddit https://ift.tt/T1ihELv
Horizon3.ai
CVE-2024-8190: Investigating CISA KEV Ivanti Cloud Service Appliance Command Injection Vulnerability
CVE-2024-8190: Investigating CISA KEV Ivanti Cloud Service Appliance Command Injection Vulnerability and Indicators of Compromise
SmuggleSheild - Basic protection against HTML smuggling attempts.
https://ift.tt/6HgpDM0
Submitted September 17, 2024 at 12:02AM by SkyFallRobin
via reddit https://ift.tt/zFnbX9c
https://ift.tt/6HgpDM0
Submitted September 17, 2024 at 12:02AM by SkyFallRobin
via reddit https://ift.tt/zFnbX9c
GitHub
GitHub - RootUp/SmuggleShield: Protection against HTML smuggling attempts.
Protection against HTML smuggling attempts. Contribute to RootUp/SmuggleShield development by creating an account on GitHub.
A vulnerability in LANCOM LCOS web interface (usually listening on port 443) allows a remote attacker to trigger a heap overflow in the service listening on this port
https://ift.tt/Ezbh8VN
Submitted September 17, 2024 at 03:13PM by SSDisclosure
via reddit https://ift.tt/1HuVEGD
https://ift.tt/Ezbh8VN
Submitted September 17, 2024 at 03:13PM by SSDisclosure
via reddit https://ift.tt/1HuVEGD
SSD Secure Disclosure
SSD Advisory - LANCOM LCOS Heap Overflow - SSD Secure Disclosure
Summary A vulnerability in LANCOM LCOS web interface (usually listening on port 443) allows a remote attacker to trigger a heap overflow in the service listening on this port. Credit An independent security researcher working with SSD Secure Disclosure Vendor…
Direct Memory Access Attacks - An easy way to hack into memory, bypass logon screens and ignore device encryption
https://ift.tt/WH750xU
Submitted September 17, 2024 at 08:24PM by CyberSecurityIs
via reddit https://ift.tt/IjBO639
https://ift.tt/WH750xU
Submitted September 17, 2024 at 08:24PM by CyberSecurityIs
via reddit https://ift.tt/IjBO639
SureCloud Cyber Services
Direct Memory Access Attacks - An easy way to hack into memory, bypass logon screens and ignore device encryption | Blog | SureCloud…
Have you ever come across a laptop, server or desktop computer that has Full Device Encryption (FDE) and protected by a password/logon screen that you would like to hack into easily? Well Direct Memory Access (DMA) attacks can easily bypass these security…
Taking over Train infrastructure / Traction power substation and lighting systems in Europe
https://ift.tt/0hoMfzm
Submitted September 17, 2024 at 08:08PM by bertinjoseb
via reddit https://ift.tt/WKefT5q
https://ift.tt/0hoMfzm
Submitted September 17, 2024 at 08:08PM by bertinjoseb
via reddit https://ift.tt/WKefT5q
Medium
Taking over Train infrastructure in Poland /Traction power substation and lighting systems
(6 Months later CZAT 7 Server is offline or changed to another ip address , this post was written 6 months ago, published today 9/2/2024)
Revisiting MiniFilter Abuse Techniques to Blind EDR
https://ift.tt/ScV1YpK
Submitted September 18, 2024 at 05:58AM by eitot8
via reddit https://ift.tt/W29FYGL
https://ift.tt/ScV1YpK
Submitted September 18, 2024 at 05:58AM by eitot8
via reddit https://ift.tt/W29FYGL
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Improved SLEAPING sleepmask using Timers and APCs in order to spoof Timer Callback addresses at sleeping time achieving a more resilient sleep mask that works against great in-memory scanner like HSB, Moneta, etc. Also call stack return address detection is addressed in the SWAPPALA implementation.
https://ift.tt/lhtusmo
Submitted September 18, 2024 at 11:15AM by oldboy21
via reddit https://ift.tt/pQWEcXR
https://ift.tt/lhtusmo
Submitted September 18, 2024 at 11:15AM by oldboy21
via reddit https://ift.tt/pQWEcXR
oldboy21.github.io
Timer Callbacks Spoofing to Improve your SLEAP and SWAPPALA Untold
Hello, Hello, Aloooooooo. After some time away from coding I am here again talking about sleeping masks. Thanks to the great cybersec community there is always something to work on 😄
Last time in my blog I have talked how to hide a memory mapping (where in…
Last time in my blog I have talked how to hide a memory mapping (where in…
Hertz leaks 60,000 insurance claim reports on their claims website
https://ift.tt/6Uaz8Pn
Submitted September 18, 2024 at 07:43PM by ok_bye_now_
via reddit https://ift.tt/n4A5YjK
https://ift.tt/6Uaz8Pn
Submitted September 18, 2024 at 07:43PM by ok_bye_now_
via reddit https://ift.tt/n4A5YjK
www.adversis.io
Rental Car Vendor's Security Flaw Exposed Damage Claims Reports
Legitimate emails with bad practices and an insecure website add insult to injury.
Solidity Static Analyzers: Reducing False Positives with CodeQL
https://ift.tt/VGpXY8I
Submitted September 19, 2024 at 01:37AM by arrowflakes
via reddit https://ift.tt/BAbglwQ
https://ift.tt/VGpXY8I
Submitted September 19, 2024 at 01:37AM by arrowflakes
via reddit https://ift.tt/BAbglwQ
CoinFabrik
Solidity Static Analyzers: Reducing False Positives with CodeQL
There's a need to address the common issues with Solidity static analyzers to reduce false positives and enhance security analysis.
Vulnerabilities in Open Source C2 Frameworks
https://ift.tt/gAhMPVJ
Submitted September 19, 2024 at 01:35AM by 907jessejones
via reddit https://ift.tt/Ui8GWSs
https://ift.tt/gAhMPVJ
Submitted September 19, 2024 at 01:35AM by 907jessejones
via reddit https://ift.tt/Ui8GWSs
Include Security Research Blog
Vulnerabilities in Open Source C2 Frameworks - Include Security Research Blog
Hacking Hackers - Even the software used by teams of offensive security professionals is prone to standard web application vulnerabilities.
SAP Hash Cracking Techniques
https://ift.tt/UlmhFdV
Submitted September 19, 2024 at 01:03PM by vah_13
via reddit https://ift.tt/iCagDxT
https://ift.tt/UlmhFdV
Submitted September 19, 2024 at 01:03PM by vah_13
via reddit https://ift.tt/iCagDxT
RedRays - Your SAP Security Solution
SAP Hash Cracking Techniques
Justice Department disrupts vast Chinese hacking operation that infected consumer devices
https://ift.tt/JoAgXCe
Submitted September 19, 2024 at 04:35PM by Fun__Panda
via reddit https://ift.tt/tg34czQ
https://ift.tt/JoAgXCe
Submitted September 19, 2024 at 04:35PM by Fun__Panda
via reddit https://ift.tt/tg34czQ
AP News
Justice Department disrupts vast Chinese hacking operation that infected consumer devices
FBI Director Chris Wray says the FBI has disrupted a group of hackers working at the direction of the Chinese government who targeted universities, government agencies and other organizations.
Exploiting Android Client WebViews with Help from HSTS
https://ift.tt/VyEDoZb
Submitted September 19, 2024 at 04:54PM by SeanPesce
via reddit https://ift.tt/FwdSzpj
https://ift.tt/VyEDoZb
Submitted September 19, 2024 at 04:54PM by SeanPesce
via reddit https://ift.tt/FwdSzpj
Blogspot
Exploiting Android Client WebViews with Help from HSTS
TL;DR I discovered a one-click account takeover vulnerability in a popular Indonesian Android app called Tokopedia . Th...
Applying security engineering to make phishing harder
https://ift.tt/1jlr3Iu
Submitted September 19, 2024 at 07:08PM by nibblesec
via reddit https://ift.tt/0OptxP1
https://ift.tt/1jlr3Iu
Submitted September 19, 2024 at 07:08PM by nibblesec
via reddit https://ift.tt/0OptxP1