HTTP Security Headers: A complete guide to HTTP headers
https://ift.tt/8MYShCu
Submitted November 04, 2024 at 05:13PM by Altrntiv-to-security
via reddit https://ift.tt/lhwImxr
https://ift.tt/8MYShCu
Submitted November 04, 2024 at 05:13PM by Altrntiv-to-security
via reddit https://ift.tt/lhwImxr
DarkRelay
HTTP Security Headers: A complete guide to HTTP headers
Why did the HTTP security headers go to therapy? They had major 'insecurity' issues!HTTP headers are an integral part of the Hypertext Transfer Protocol (HTTP), the foundation of data communication on the World Wide Web. HTTP headers are lines of additional…
The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela
https://ift.tt/IgCpWV4
Submitted November 04, 2024 at 07:15PM by EspoJ
via reddit https://ift.tt/jlWQx8A
https://ift.tt/IgCpWV4
Submitted November 04, 2024 at 07:15PM by EspoJ
via reddit https://ift.tt/jlWQx8A
Security Conversations
The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela - Security Conversations
Three Buddy Problem – Episode 19: We explore Ivan Kwiatkowski’s essay on the limits of threat intelligence, Sophos using kernel implants to surveil Chinese hackers, […]
ToxicPanda: a new banking trojan from Asia hit Europe and LATAM | Cleafy Labs
https://ift.tt/4UzetK6
Submitted November 04, 2024 at 09:23PM by f3d_0x0
via reddit https://ift.tt/zDQgm1F
https://ift.tt/4UzetK6
Submitted November 04, 2024 at 09:23PM by f3d_0x0
via reddit https://ift.tt/zDQgm1F
Cleafy
ToxicPanda: a new banking trojan from Asia hit Europe and LATAM | Cleafy Labs
Discover Cleafy's in-depth analysis of a new Android banking Trojan campaign, ToxicPanda, initially linked to TgToxic. Our findings reveal a sophisticated fraud operation targeting European and LATAM banks, using On-Device Fraud (ODF) tactics to execute account…
Alleged SYN-scans of known Honeypots from spoofed source IPs of Tor nodes
https://ift.tt/v5nULQi
Submitted November 04, 2024 at 09:33PM by da_peda
via reddit https://ift.tt/AEPuBrW
https://ift.tt/v5nULQi
Submitted November 04, 2024 at 09:33PM by da_peda
via reddit https://ift.tt/AEPuBrW
When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls
https://ift.tt/pnQkeE4
Submitted November 05, 2024 at 02:08PM by ffyns
via reddit https://ift.tt/vOswuhA
https://ift.tt/pnQkeE4
Submitted November 05, 2024 at 02:08PM by ffyns
via reddit https://ift.tt/vOswuhA
MDSec
When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls - MDSec
Web Application Firewalls (WAFs) help to protect web applications by monitoring, filtering, and blocking HTTP traffic to and from a web service. However, WAFs are too often relied upon as...
Escalating from Reader to Contributor in Azure API Management pt II
https://ift.tt/nqIARyu
Submitted November 05, 2024 at 03:02PM by piraterapper
via reddit https://ift.tt/ykPdt51
https://ift.tt/nqIARyu
Submitted November 05, 2024 at 03:02PM by piraterapper
via reddit https://ift.tt/ykPdt51
Binary Security AS
Escalating from Reader to Contributor in Azure API Management pt II
Binary Security has found several vulnerabilities in Azure API Management (APIM) over the years. These can, among other things, be exploited to escalate privileges from a Reader role to gaining full control of the APIM service. After receiving our reports…
Radare's binary reversing online conference, including Doyensec's Dennis Goodlett on bypassing malicious pickle detection.
https://ift.tt/6j8kmIX
Submitted November 05, 2024 at 10:33PM by ds_at
via reddit https://ift.tt/FVgx0uJ
https://ift.tt/6j8kmIX
Submitted November 05, 2024 at 10:33PM by ds_at
via reddit https://ift.tt/FVgx0uJ
Upcoming hardening in PHP
https://ift.tt/uRkvAhE
Submitted November 06, 2024 at 04:06PM by MegaManSec2
via reddit https://ift.tt/LFskAzM
https://ift.tt/uRkvAhE
Submitted November 06, 2024 at 04:06PM by MegaManSec2
via reddit https://ift.tt/LFskAzM
dustri.org
Upcoming hardening in PHP
Personal blog of Julien (jvoisin) Voisin
Hacking 700 Million Electronic Arts Accounts
https://ift.tt/I3zlTgD
Submitted November 06, 2024 at 06:08PM by AlmondOffSec
via reddit https://ift.tt/Iizurmg
https://ift.tt/I3zlTgD
Submitted November 06, 2024 at 06:08PM by AlmondOffSec
via reddit https://ift.tt/Iizurmg
Sean Kahler
Hacking 700 Million Electronic Arts Accounts
(Ethically). Here's how I did it.
Breaking Down Multipart Parsers: File upload validation bypass
https://ift.tt/K8iB2VJ
Submitted November 06, 2024 at 10:12PM by theMiddleBlue
via reddit https://ift.tt/qQCDmx6
https://ift.tt/K8iB2VJ
Submitted November 06, 2024 at 10:12PM by theMiddleBlue
via reddit https://ift.tt/qQCDmx6
Sicuranext Blog
Breaking Down Multipart Parsers: File upload validation bypass
TL;DR: Basically, all multipart/form-data parsers fail to fully comply with the RFC, and when it comes to validating filenames or content uploaded by users, there are always numerous ways to bypass validation. We'll test various bypass techniques against…
Secure malware analysis
http://www.what.com
Submitted November 07, 2024 at 07:03PM by petrolsan
via reddit https://ift.tt/yM1UEm6
http://www.what.com
Submitted November 07, 2024 at 07:03PM by petrolsan
via reddit https://ift.tt/yM1UEm6
BestShop
BestShop | Best Price, Smart Shopping
Welcome to BestShop! Our AI-powered ecommerce platform offers the best prices on a wide variety of products, all while providing a smart shopping experience that's tailored to your needs. Shop with confidence and find the best deals today at BestShop.
Presentations from HEXACON 2024
https://www.youtube.com/playlist?list=PLiEHUFG7koLvk72LC2xGCn65M535-vIEC
Submitted November 08, 2024 at 04:46PM by albinowax
via reddit https://ift.tt/ENaUyhG
https://www.youtube.com/playlist?list=PLiEHUFG7koLvk72LC2xGCn65M535-vIEC
Submitted November 08, 2024 at 04:46PM by albinowax
via reddit https://ift.tt/ENaUyhG
A New Era of macOS Sandbox Escapes: Overlooked Attack Surface, 10+ New Vulns
https://ift.tt/PJhexuU
Submitted November 08, 2024 at 06:57PM by netsec_burn
via reddit https://ift.tt/rsCPXBW
https://ift.tt/PJhexuU
Submitted November 08, 2024 at 06:57PM by netsec_burn
via reddit https://ift.tt/rsCPXBW
jhftss.github.io
A New Era of macOS Sandbox Escapes: Diving into an Overlooked Attack Surface and Uncovering 10+ New Vulnerabilities
This is a blog post for my presentation at the conference POC2024. The slides are uploaded here.
Why Falco’s new response engine is a game changer for open source cloud native security
https://ift.tt/0u4QRIq
Submitted November 08, 2024 at 09:45PM by Hallow_Rose
via reddit https://ift.tt/r1wyh9U
https://ift.tt/0u4QRIq
Submitted November 08, 2024 at 09:45PM by Hallow_Rose
via reddit https://ift.tt/r1wyh9U
CNCF
Why Falco’s new response engine is a game changer for open source cloud native security
Project post by the Falco Team and Nigel Douglas Falco achieved CNCF Graduation status on February 29, 2024. Following the celebration of this significant milestone at KubeCon EU in Paris earlier this…
Microsoft Bookings – Facilitating Impersonation
https://ift.tt/BkDvE8S
Submitted November 08, 2024 at 10:33PM by nopslider
via reddit https://ift.tt/dk7VtEX
https://ift.tt/BkDvE8S
Submitted November 08, 2024 at 10:33PM by nopslider
via reddit https://ift.tt/dk7VtEX
Cyberis Limited
Microsoft Bookings – Facilitating Impersonation
Microsoft Bookings introduces a significant security risk by allowing end users to create fully functional Entra accounts without administrative oversight. These accounts, tied to shared Booking pages, can be exploited for impersonation, phishing, and email…
Beyond RCE: Autonomous Code Execution in Agentic AI
https://ift.tt/cdulMhq
Submitted November 09, 2024 at 03:30AM by crustysecurity
via reddit https://ift.tt/5ZTAWEG
https://ift.tt/cdulMhq
Submitted November 09, 2024 at 03:30AM by crustysecurity
via reddit https://ift.tt/5ZTAWEG
www.securityrunners.io
Beyond RCE: Autonomous Code Execution in Agentic AI
This blog post explores how agentic AI systems, specifically the "Computer Use" feature, can be manipulated through prompt injections and phishing techniques to execute arbitrary commands.
Reverse Engineering the Parrot Anafi Drone: Control Start/Land via PC
https://ift.tt/2YLKTQf
Submitted November 11, 2024 at 02:13AM by f3nter
via reddit https://ift.tt/s7PuYkB
https://ift.tt/2YLKTQf
Submitted November 11, 2024 at 02:13AM by f3nter
via reddit https://ift.tt/s7PuYkB
www.hardbreak.wiki
Parrot Anafi Drone Reverse Engineering | HardBreak
Red Team and Pentest anecdotes
https://ift.tt/YWTMBSZ
Submitted November 11, 2024 at 04:14PM by _kawhl
via reddit https://ift.tt/0Ne67Ay
https://ift.tt/YWTMBSZ
Submitted November 11, 2024 at 04:14PM by _kawhl
via reddit https://ift.tt/0Ne67Ay
therealunicornsecurity.github.io
Tales of the Crimson Foes
The Tales of the Crimson Foes
A compilation of red team and pentest stories
A compilation of red team and pentest stories
Bypass GuardDuty Pentest Findings for the AWS CLI
https://ift.tt/NAy1SFv
Submitted November 11, 2024 at 09:21PM by RedTermSession
via reddit https://ift.tt/iA6NBWr
https://ift.tt/NAy1SFv
Submitted November 11, 2024 at 09:21PM by RedTermSession
via reddit https://ift.tt/iA6NBWr
hackingthe.cloud
Bypass GuardDuty Pentest Findings for the AWS CLI - Hacking The Cloud
Prevent Kali Linux, ParrotOS, and Pentoo Linux from throwing GuardDuty alerts by modifying the User Agent string when using the AWS CLI.
Everyday Ghidra: Ghidra Data Types— When to Create Custom GDTs — Part 1
https://ift.tt/rZOb70t
Submitted November 12, 2024 at 08:13PM by onlinereadme
via reddit https://ift.tt/khyHoXe
https://ift.tt/rZOb70t
Submitted November 12, 2024 at 08:13PM by onlinereadme
via reddit https://ift.tt/khyHoXe
Medium
Everyday Ghidra: Ghidra Data Types— When to Create Custom GDTs — Part 1
In this 2-part “Everyday Ghidra” series post, we’ll walk through creating custom Ghidra data types by parsing C header files. In Everyday…
System Prompt Exposure: How AI Image Generators May Leak Sensitive Instructions
https://ift.tt/mOJWR29
Submitted November 12, 2024 at 09:32PM by Ok_Information1453
via reddit https://ift.tt/yFWYvP1
https://ift.tt/mOJWR29
Submitted November 12, 2024 at 09:32PM by Ok_Information1453
via reddit https://ift.tt/yFWYvP1
Invicti
System Prompt Exposure: How AI Image Generators May Leak Sensitive Instructions
Recraft's image generation service uses a unique architecture combining an LLM (Claude) with a diffusion model. Learn what led to the discovery that carefully crafted prompts could expose the system's internal instructions.