Research Case Study: Supply Chain Security at Scale – Insights into NPM Account Takeovers
https://ift.tt/BvMYaiL
Submitted November 19, 2024 at 12:22AM by Ancient_Title_1860
via reddit https://ift.tt/wml1RIH
https://ift.tt/BvMYaiL
Submitted November 19, 2024 at 12:22AM by Ancient_Title_1860
via reddit https://ift.tt/wml1RIH
Laburity - Cyber Security Services
Research Case Study: Supply Chain Security at Scale – Insights into NPM Account Takeovers - Laburity
Software supply chains are complex ecosystems where even a single vulnerability can lead to widely spread security issues. This blog focuses on supply chain account takeovers, particularly in NPM packages, and explains how attackers exploit expired email…
OpenBMC Remote OS Deployment: A Simplified Approach
https://ift.tt/QlP7wWp
Submitted November 19, 2024 at 10:43AM by hardenedvault
via reddit https://ift.tt/4rCmKOi
https://ift.tt/QlP7wWp
Submitted November 19, 2024 at 10:43AM by hardenedvault
via reddit https://ift.tt/4rCmKOi
hardenedvault.net
OpenBMC Remote OS Deployment: A Simplified Approach
OpenBMC Remote OS Deployment: A Simplified Approach Many BMC implementations can accept a disk image and present it as a read-only USB mass storage device inserted into the host machine, allowing the host machine to boot from this “disk” for remote installation…
Extending Burp Suite for fun and profit - The Montoya way - Part 7 (Using the Collaborator)
https://ift.tt/y1vo6HK
Submitted November 19, 2024 at 03:26PM by 0xdea
via reddit https://ift.tt/VX1HlBi
https://ift.tt/y1vo6HK
Submitted November 19, 2024 at 03:26PM by 0xdea
via reddit https://ift.tt/VX1HlBi
HN Security
Extending Burp Suite for fun and profit - The Montoya way - Part 7 - HN Security
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474 - watchTowr Labs
https://ift.tt/eZ4LJQA
Submitted November 19, 2024 at 03:07PM by dx7r__
via reddit https://ift.tt/9gNleQc
https://ift.tt/eZ4LJQA
Submitted November 19, 2024 at 03:07PM by dx7r__
via reddit https://ift.tt/9gNleQc
watchTowr Labs
Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474
It'll be no surprise that 2024, 2023, 2022, and every other year of humanities' existence has been tough for SSLVPN appliances.
Anyhow, there are new vulnerabilities (well, two of them) that are being exploited in the Palo Alto Networks firewall and SSLVPN…
Anyhow, there are new vulnerabilities (well, two of them) that are being exploited in the Palo Alto Networks firewall and SSLVPN…
Remediation for CVE-2024-20767 and CVE-2024-21216 Potential Exploitable Bugs
https://ift.tt/KIeV5xT
Submitted November 20, 2024 at 05:09AM by SL7reach
via reddit https://ift.tt/GpxBMKm
https://ift.tt/KIeV5xT
Submitted November 20, 2024 at 05:09AM by SL7reach
via reddit https://ift.tt/GpxBMKm
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
Remediation for CVE-2024-20767 and CVE-2024-21216: Protect Yourself Against Two Recent Critical Bugs Exploitable in the Wild
CVE-2024-20767- ColdFusion Path Traversal can lead to reading important data. CVE-2024-20767 is a vulnerability in ColdFusion versions 2023.6, 2021.12, and earlier. These versions are affected by...
Extracting Plaintext Credentials from Palo Alto Global Protect
https://ift.tt/S71F29N
Submitted November 19, 2024 at 09:55PM by AlmondOffSec
via reddit https://ift.tt/sWI1Hi6
https://ift.tt/S71F29N
Submitted November 19, 2024 at 09:55PM by AlmondOffSec
via reddit https://ift.tt/sWI1Hi6
Shells.Systems
Extracting Plaintext Credentials from Palo Alto Global Protect - Shells.Systems
Estimated Reading Time: 5 minutesOn a recent Red Team engagement, I was poking around having a look at different files and trying to see if I could extract any information that would allow me to move laterally through the network. I was hopeful, as always…
[PoC] Critical Authentication Vulnerability in SAP BusinessObjects Business Intelligence Platform
https://ift.tt/UmsaYOV
Submitted November 20, 2024 at 02:59PM by vah_13
via reddit https://ift.tt/1mvg8sp
https://ift.tt/UmsaYOV
Submitted November 20, 2024 at 02:59PM by vah_13
via reddit https://ift.tt/1mvg8sp
SAP Community
[PoC] Critical Authentication Vulnerability in SAP BusinessObjects Business Intelligence Platform
On August 13, 2024, SAP released a crucial security update to address a severe authentication vulnerability identified in the SAP BusinessObjects Business Intelligence Platform. This post provides an overview of the vulnerability, its potential impacts…
Security Researchers found 2k high risk vulnerabilities in exposed Fortune 1000 APIs
https://ift.tt/wLZmG8d
Submitted November 20, 2024 at 07:08PM by AlarmingApartment236
via reddit https://ift.tt/aLZ0hIk
https://ift.tt/wLZmG8d
Submitted November 20, 2024 at 07:08PM by AlarmingApartment236
via reddit https://ift.tt/aLZ0hIk
Escape DAST - Application Security Blog
Fortune 1000 at risk: How we discovered 100k vulnerabilities
Discover the alarming state of API security in Fortune 1000 and CAC 40. Escape's latest research reveals 2k high-risk vulnerabilities
Azure CloudQuarry: Searching for secrets in Public VM Images
https://ift.tt/NEgpJsG
Submitted November 20, 2024 at 07:41PM by phoenixzeu
via reddit https://ift.tt/TG5Whg0
https://ift.tt/NEgpJsG
Submitted November 20, 2024 at 07:41PM by phoenixzeu
via reddit https://ift.tt/TG5Whg0
Security Café
Azure CloudQuarry: Searching for secrets in Public VM Images
After the initial investigation ennoscriptd “AWS CloudQuarry: Digging for secrets in Public AMIs” was finalized, we continued with the same idea on Azure in order to search for hidden and …
Wormable XSS www.bing.com
https://ift.tt/ND9uMwg
Submitted November 20, 2024 at 06:59PM by Significant_Fix_1741
via reddit https://ift.tt/4qmJvQp
https://ift.tt/ND9uMwg
Submitted November 20, 2024 at 06:59PM by Significant_Fix_1741
via reddit https://ift.tt/4qmJvQp
Medium
Wormable XSS www.bing.com
XSS on www.bing.com context via Maps SDK
Spelunking in Comments and Documentation for Security Footguns - Include Security Research Blog
https://ift.tt/uVyjFn6
Submitted November 21, 2024 at 12:34AM by 907jessejones
via reddit https://ift.tt/9W1OQG8
https://ift.tt/uVyjFn6
Submitted November 21, 2024 at 12:34AM by 907jessejones
via reddit https://ift.tt/9W1OQG8
Include Security Research Blog
Spelunking in Comments and Documentation for Security Footguns - Include Security Research Blog
Join us as we explore seemingly safe but deceptively tricky ground in Elixir, Python, and the Golang standard library. We cover officially documented, or at least previously discussed, code functionality that could unexpectedly introduce vulnerabilities.…
Sync or Sink: Navigating the Choppy Waters of the Flipper Zero, and consumer friendly hacking…
https://ift.tt/Z8PjuIH
Submitted November 21, 2024 at 05:49PM by pentest4life
via reddit https://ift.tt/HrzwcqW
https://ift.tt/Z8PjuIH
Submitted November 21, 2024 at 05:49PM by pentest4life
via reddit https://ift.tt/HrzwcqW
Stop Using Predictable Bucket Names: A Failed Attempt at Hacking Satellites
https://ift.tt/GeLOK4t
Submitted November 21, 2024 at 11:31PM by crustysecurity
via reddit https://ift.tt/jkF3Yvl
https://ift.tt/GeLOK4t
Submitted November 21, 2024 at 11:31PM by crustysecurity
via reddit https://ift.tt/jkF3Yvl
www.securityrunners.io
Stop Using Predictable Bucket Names: A Failed Attempt at Hacking Satellites
This blog discusses the security risks of S3 bucket namesquatting in AWS, where attackers could potentially exploit predictable bucket naming patterns that include region names, and documents the author's research finding buckets pre-created for non-existent…
Azure Detection Engineering: Log idiosyncrasies you should know about
https://ift.tt/qz94SpW
Submitted November 21, 2024 at 10:52PM by tracebit
via reddit https://ift.tt/5GSozNR
https://ift.tt/qz94SpW
Submitted November 21, 2024 at 10:52PM by tracebit
via reddit https://ift.tt/5GSozNR
Tracebit
Azure Detection Engineering: Log idiosyncrasies you should know about | Tracebit
We share a few inconsistencies found in Azure logs which make detection engineering more challenging.
Automate Pentest Reporting with Faction
https://ift.tt/l7cqSux
Submitted November 22, 2024 at 02:30AM by ascetik
via reddit https://ift.tt/Eijqxmr
https://ift.tt/l7cqSux
Submitted November 22, 2024 at 02:30AM by ascetik
via reddit https://ift.tt/Eijqxmr
Medium
How to Automate Pentest Reporting Using Faction
Faction is an open-source security assessment collaboration framework designed to streamline and enhance your security workflows. With…
Leveraging An Order of Operations Bug to Achieve RCE in Sitecore 8.x - 10.x
https://ift.tt/4bWthGD
Submitted November 22, 2024 at 10:06AM by Mempodipper
via reddit https://ift.tt/Yih8tqr
https://ift.tt/4bWthGD
Submitted November 22, 2024 at 10:06AM by Mempodipper
via reddit https://ift.tt/Yih8tqr
www.assetnote.io
Leveraging An Order of Operations Bug to Achieve RCE in Sitecore 8.x - 10.x
Local file disclosure in Sitecore 8.x to 10.x that can lead to RCE (CVE-2024-46938) due to an order of operations bug within a handler responsible for reading local files.
Released My Longest Weekly Newsletter Yet - Feedback Appreciated!
https://ift.tt/FcSN9Qj
Submitted November 23, 2024 at 12:45AM by PacketsForward
via reddit https://ift.tt/A4sI5Pu
https://ift.tt/FcSN9Qj
Submitted November 23, 2024 at 12:45AM by PacketsForward
via reddit https://ift.tt/A4sI5Pu
Decrypt LOL
Newsletter 22 November 2024
Get the latest security insights, tech updates, and impactful tools reviewed in our November 22, 2024, newsletter.
Navigating the Leap: My Journey from Software Engineering to Offensive Security
https://ift.tt/aJZWMQY
Submitted November 23, 2024 at 02:29AM by andy-codes
via reddit https://ift.tt/rAbG8WV
https://ift.tt/aJZWMQY
Submitted November 23, 2024 at 02:29AM by andy-codes
via reddit https://ift.tt/rAbG8WV
OffSec
Navigating the Leap: My Journey from Software Engineering to Offensive Security | OffSec
A software engineer's journey into offensive security, sharing insights and tips for transitioning careers and thriving in the infosec field.
Prototype Pollution in NASAs Open MCT CVE-2023-45282
https://ift.tt/I2E0gyU
Submitted November 23, 2024 at 02:07AM by andy-codes
via reddit https://ift.tt/BtzdPYj
https://ift.tt/I2E0gyU
Submitted November 23, 2024 at 02:07AM by andy-codes
via reddit https://ift.tt/BtzdPYj
Visionspace
Prototype Pollution in NASAs Open MCT CVE-2023-45282
The Prototype Pollution vulnerability is specific to the JavaScript programming language. It enables an attacker to add or alter any properties of global object prototypes. Once the property is changed, the code that inherits it will use the injected property…
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
https://ift.tt/YhKv3dx
Submitted November 23, 2024 at 03:25AM by cryptogram
via reddit https://ift.tt/r06aHBA
https://ift.tt/YhKv3dx
Submitted November 23, 2024 at 03:25AM by cryptogram
via reddit https://ift.tt/r06aHBA
Volexity
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever worked. The investigation began when an alert from a custom…
Handling Cookies is a Minefield
https://ift.tt/I2gLVbl
Submitted November 24, 2024 at 06:07AM by smaury
via reddit https://ift.tt/Hq2yIpn
https://ift.tt/I2gLVbl
Submitted November 24, 2024 at 06:07AM by smaury
via reddit https://ift.tt/Hq2yIpn
grayduck.mn
April King — Handling Cookies is a Minefield
Discrepancies in how browsers and libraries handle HTTP cookies, and the problems caused by such things.