Understanding RedLine Stealer: The Trojan Targeting Your Data
https://ift.tt/rqSbVjZ
Submitted October 31, 2024 at 12:52PM by rimdig219
via reddit https://ift.tt/WcyK2gl
https://ift.tt/rqSbVjZ
Submitted October 31, 2024 at 12:52PM by rimdig219
via reddit https://ift.tt/WcyK2gl
Malware Analysis, Phishing, and Email Scams
Understanding RedLine Stealer: The Trojan Targeting Your Data
In the ever-evolving landscape of cybersecurity threats, one name has increasingly become synonymous with stealth and precision: RedLine Stealer. This malicious software, often referred to as a Tro…
File Transfer Cheatsheet: Windows and Linux
https://ift.tt/Y9zTfEy
Submitted October 31, 2024 at 08:30PM by Justin_coco
via reddit https://ift.tt/fik7ZCY
https://ift.tt/Y9zTfEy
Submitted October 31, 2024 at 08:30PM by Justin_coco
via reddit https://ift.tt/fik7ZCY
Medium
File Transfer Cheatsheet: Windows and Linux
File transfer is a critical component in post-exploitation, penetration testing, and red teaming. Different environments require specific…
Attackers hiding hostnames on Ethereum Blockchain; Target Puppeteer Users In Typosquat Campaign
https://ift.tt/y8HWSoE
Submitted October 31, 2024 at 08:22PM by louis11
via reddit https://ift.tt/x5C8o9I
https://ift.tt/y8HWSoE
Submitted October 31, 2024 at 08:22PM by louis11
via reddit https://ift.tt/x5C8o9I
Phylum Research | Software Supply Chain Security
Fake Puppeteer Packages Contain Malware
Ongoing supply chain attack targets Puppeteer users with malicious npm packages.
Multiple Vulnerabilities found in Portainer using CodeQL
https://ift.tt/nibAoOe
Submitted November 01, 2024 at 01:37AM by jat0369
via reddit https://ift.tt/JO4nTxY
https://ift.tt/nibAoOe
Submitted November 01, 2024 at 01:37AM by jat0369
via reddit https://ift.tt/JO4nTxY
Methodology for Leveraging LLMs for 0-day discovery (18+ vulns including on Netflix, Hulu, and Salesforce)
https://ift.tt/2yVh3WX
Submitted November 01, 2024 at 03:54AM by anonjohn1212
via reddit https://ift.tt/xGczMe3
https://ift.tt/2yVh3WX
Submitted November 01, 2024 at 03:54AM by anonjohn1212
via reddit https://ift.tt/xGczMe3
Zeropath
Autonomous Discovery of Critical Zero-Days - ZeroPath Blog
Since July 2024, ZeroPath's tool has uncovered critical zero-day vulnerabilities—including RCE, authentication bypasses, and IDORs—in popular AI platforms and open-source projects. Our approach has identified security flaws in projects owned by Netflix, Salesforce…
An open source version of CyberScarecrow (Malware Scarecrow for your PC)
https://ift.tt/QT7gxJs
Submitted October 31, 2024 at 04:49AM by ThyGreatOof
via reddit https://ift.tt/tBSF4fE
https://ift.tt/QT7gxJs
Submitted October 31, 2024 at 04:49AM by ThyGreatOof
via reddit https://ift.tt/tBSF4fE
GitHub
GitHub - Babyhamsta/Malcrow: A Malware Scarecrow for Windows 10/11 with a user-friendly touch.
A Malware Scarecrow for Windows 10/11 with a user-friendly touch. - Babyhamsta/Malcrow
Running custom code on Alarmo, the Nintendo Sound Clock
https://ift.tt/uJyK5Oe
Submitted October 30, 2024 at 11:20PM by Titokhan
via reddit https://ift.tt/DnTiX9M
https://ift.tt/uJyK5Oe
Submitted October 30, 2024 at 11:20PM by Titokhan
via reddit https://ift.tt/DnTiX9M
Blogspot
Looking into the Nintendo Alarmo
While everyone was waiting on news for the successor of the Nintendo Switch, Nintendo released the Alarmo. A small plastic alarm clock that ...
From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code
https://ift.tt/y9rbczO
Submitted November 02, 2024 at 03:56AM by _vavkamil_
via reddit https://ift.tt/2x0IS8M
https://ift.tt/y9rbczO
Submitted November 02, 2024 at 03:56AM by _vavkamil_
via reddit https://ift.tt/2x0IS8M
Blogspot
From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code
Posted by the Big Sleep team Introduction In our previous post, Project Naptime: Evaluating Offensive Security Capabilities of Large L...
Can`t buy a jtagualator then build it - DIY build under 75USD - Hello! Welcome to IoT Security Research Group by @iotsrg1
https://ift.tt/3iFJcOw
Submitted November 02, 2024 at 05:43PM by v33ruiot
via reddit https://ift.tt/fn9HXN8
https://ift.tt/3iFJcOw
Submitted November 02, 2024 at 05:43PM by v33ruiot
via reddit https://ift.tt/fn9HXN8
www.iotsrg.org
Can`t buy a jtagualator then build it - DIY build under 75USD - Hello! Welcome to IoT Security Research Group
FAQ recently we faced jtagulator out of stock, do you alternative
🌪️Heads up speakers: TyphoonCon 2025 Call for Papers is now open!
https://ift.tt/9y5cuaZ
Submitted November 03, 2024 at 03:36PM by Straight-Zombie-646
via reddit https://ift.tt/eU7XIfp
https://ift.tt/9y5cuaZ
Submitted November 03, 2024 at 03:36PM by Straight-Zombie-646
via reddit https://ift.tt/eU7XIfp
Introducing lightyear: a new way to dump files in PHP
https://ift.tt/XaFoeMw
Submitted November 04, 2024 at 02:19PM by cfambionics
via reddit https://ift.tt/H8ciTIZ
https://ift.tt/XaFoeMw
Submitted November 04, 2024 at 02:19PM by cfambionics
via reddit https://ift.tt/H8ciTIZ
Ambionics
Introducing lightyear: a new way to dump files in PHP
In this blog post, we describe new techniques to dump files in PHP leveraging filters, and a tool that does it, lightyear.
32 vulnerabilities in IBM Security Verify Access
https://ift.tt/Jv1LT6k
Submitted November 04, 2024 at 02:18PM by albinowax
via reddit https://ift.tt/lxq8o14
https://ift.tt/Jv1LT6k
Submitted November 04, 2024 at 02:18PM by albinowax
via reddit https://ift.tt/lxq8o14
Keycloak V26 release performance test
https://ift.tt/DJMjGtH
Submitted November 04, 2024 at 04:29PM by Cloud-IAM
via reddit https://ift.tt/9KXyBdN
https://ift.tt/DJMjGtH
Submitted November 04, 2024 at 04:29PM by Cloud-IAM
via reddit https://ift.tt/9KXyBdN
Cloud-Iam
Keycloak V26 release
As launched in the v25 version as a feature preview, the sessions are stored in the database. This means that during a migration, from the 25 to 26 migration, you will not lose your sessions anymore.
HTTP Security Headers: A complete guide to HTTP headers
https://ift.tt/8MYShCu
Submitted November 04, 2024 at 05:13PM by Altrntiv-to-security
via reddit https://ift.tt/lhwImxr
https://ift.tt/8MYShCu
Submitted November 04, 2024 at 05:13PM by Altrntiv-to-security
via reddit https://ift.tt/lhwImxr
DarkRelay
HTTP Security Headers: A complete guide to HTTP headers
Why did the HTTP security headers go to therapy? They had major 'insecurity' issues!HTTP headers are an integral part of the Hypertext Transfer Protocol (HTTP), the foundation of data communication on the World Wide Web. HTTP headers are lines of additional…
The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela
https://ift.tt/IgCpWV4
Submitted November 04, 2024 at 07:15PM by EspoJ
via reddit https://ift.tt/jlWQx8A
https://ift.tt/IgCpWV4
Submitted November 04, 2024 at 07:15PM by EspoJ
via reddit https://ift.tt/jlWQx8A
Security Conversations
The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela - Security Conversations
Three Buddy Problem – Episode 19: We explore Ivan Kwiatkowski’s essay on the limits of threat intelligence, Sophos using kernel implants to surveil Chinese hackers, […]
ToxicPanda: a new banking trojan from Asia hit Europe and LATAM | Cleafy Labs
https://ift.tt/4UzetK6
Submitted November 04, 2024 at 09:23PM by f3d_0x0
via reddit https://ift.tt/zDQgm1F
https://ift.tt/4UzetK6
Submitted November 04, 2024 at 09:23PM by f3d_0x0
via reddit https://ift.tt/zDQgm1F
Cleafy
ToxicPanda: a new banking trojan from Asia hit Europe and LATAM | Cleafy Labs
Discover Cleafy's in-depth analysis of a new Android banking Trojan campaign, ToxicPanda, initially linked to TgToxic. Our findings reveal a sophisticated fraud operation targeting European and LATAM banks, using On-Device Fraud (ODF) tactics to execute account…
Alleged SYN-scans of known Honeypots from spoofed source IPs of Tor nodes
https://ift.tt/v5nULQi
Submitted November 04, 2024 at 09:33PM by da_peda
via reddit https://ift.tt/AEPuBrW
https://ift.tt/v5nULQi
Submitted November 04, 2024 at 09:33PM by da_peda
via reddit https://ift.tt/AEPuBrW
When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls
https://ift.tt/pnQkeE4
Submitted November 05, 2024 at 02:08PM by ffyns
via reddit https://ift.tt/vOswuhA
https://ift.tt/pnQkeE4
Submitted November 05, 2024 at 02:08PM by ffyns
via reddit https://ift.tt/vOswuhA
MDSec
When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls - MDSec
Web Application Firewalls (WAFs) help to protect web applications by monitoring, filtering, and blocking HTTP traffic to and from a web service. However, WAFs are too often relied upon as...
Escalating from Reader to Contributor in Azure API Management pt II
https://ift.tt/nqIARyu
Submitted November 05, 2024 at 03:02PM by piraterapper
via reddit https://ift.tt/ykPdt51
https://ift.tt/nqIARyu
Submitted November 05, 2024 at 03:02PM by piraterapper
via reddit https://ift.tt/ykPdt51
Binary Security AS
Escalating from Reader to Contributor in Azure API Management pt II
Binary Security has found several vulnerabilities in Azure API Management (APIM) over the years. These can, among other things, be exploited to escalate privileges from a Reader role to gaining full control of the APIM service. After receiving our reports…
Radare's binary reversing online conference, including Doyensec's Dennis Goodlett on bypassing malicious pickle detection.
https://ift.tt/6j8kmIX
Submitted November 05, 2024 at 10:33PM by ds_at
via reddit https://ift.tt/FVgx0uJ
https://ift.tt/6j8kmIX
Submitted November 05, 2024 at 10:33PM by ds_at
via reddit https://ift.tt/FVgx0uJ
Upcoming hardening in PHP
https://ift.tt/uRkvAhE
Submitted November 06, 2024 at 04:06PM by MegaManSec2
via reddit https://ift.tt/LFskAzM
https://ift.tt/uRkvAhE
Submitted November 06, 2024 at 04:06PM by MegaManSec2
via reddit https://ift.tt/LFskAzM
dustri.org
Upcoming hardening in PHP
Personal blog of Julien (jvoisin) Voisin