How cybercriminals are outpacing macOS security in 2024
https://ift.tt/oRe6nf3
Submitted December 06, 2024 at 04:20AM by Individual-Gas5276
via reddit https://ift.tt/bx03mTk
https://ift.tt/oRe6nf3
Submitted December 06, 2024 at 04:20AM by Individual-Gas5276
via reddit https://ift.tt/bx03mTk
Moonlock
Moonlock's 2024 macOS threat report
A deep dive into macOS malware this year.
U.S. Officials Tell Americans to Use Encrypted Apps as Scope of Cyberattack Grows
https://ift.tt/2LKhOfx
Submitted December 06, 2024 at 08:16AM by yazik
via reddit https://ift.tt/Y9OXlLt
https://ift.tt/2LKhOfx
Submitted December 06, 2024 at 08:16AM by yazik
via reddit https://ift.tt/Y9OXlLt
Vulnerable U
U.S. Officials Tell Americans to Use Encrypted Apps as Scope of Cyberattack Grows
At least eight U.S. telecom firms and dozens of nations have been tied up in the unprecedented Salt Typhoon attack, according to new details from U.S. officials.
Trying to Exploit My Old Android Device, take 2 (CVE-2020-0401, PackageManagerService)
https://ift.tt/dcKABw3
Submitted December 06, 2024 at 03:15PM by pwntheplanet
via reddit https://ift.tt/0kn7612
https://ift.tt/dcKABw3
Submitted December 06, 2024 at 03:15PM by pwntheplanet
via reddit https://ift.tt/0kn7612
( ͡◕ _ ͡◕)👌
Android's CVE-2020-0401 (PackageManagerService)
Note This is another attempt in my Android Side Quest (the previous one was Android’s CVE-2020-0238). Intro While digging around through my old gadgets, I found my ancient OnePlus phone that had been gathering dust in a drawer.
Azure CLI Token Leak
https://ift.tt/PnGkRUh
Submitted December 06, 2024 at 05:09PM by cbagdude
via reddit https://ift.tt/qliwZ3e
https://ift.tt/PnGkRUh
Submitted December 06, 2024 at 05:09PM by cbagdude
via reddit https://ift.tt/qliwZ3e
Binary Security AS
Azure CLI Token Leak
Azure CLI was vulnerable to a registry server confusion attack in it’s Azure Container Registry (ACR) module. If an attacker controls the value of the registry name, they can leak the token of the principal, scoped to the ARM API at https://management.azure.com/…
New dog, old tricks: DaMAgeCard attack targets memory directly thru SD card reader
https://ift.tt/eg7Uwfn
Submitted December 06, 2024 at 07:48PM by AlmondOffSec
via reddit https://ift.tt/G9Cg2Q4
https://ift.tt/eg7Uwfn
Submitted December 06, 2024 at 07:48PM by AlmondOffSec
via reddit https://ift.tt/G9Cg2Q4
PT SWARM
New dog, old tricks: DaMAgeCard attack targets memory directly thru SD card reader
Did I ever tell you what the definition of insanity is? Insanity is doing the exact… same ******* thing… over and over again expecting… **** to change… That. Is. Crazy.Far Cry 3 Intro The peripheral device industry has once again sacrificed security in the…
zizmor would have caught the Ultralytics workflow vulnerability
https://ift.tt/YSz4PZR
Submitted December 07, 2024 at 12:01AM by yossarian_flew_away
via reddit https://ift.tt/mJYMrA2
https://ift.tt/YSz4PZR
Submitted December 07, 2024 at 12:01AM by yossarian_flew_away
via reddit https://ift.tt/mJYMrA2
blog.yossarian.net
zizmor would have caught the Ultralytics workflow vulnerability
🚀 Share Your Research! Submit by Jan 17 for Après Summit (March 6–7, 2025) in Scenic Park City, UT!
https://ift.tt/tC8UFOG
Submitted December 07, 2024 at 03:38AM by PilotSmooth9439
via reddit https://ift.tt/ywk81Rr
https://ift.tt/tC8UFOG
Submitted December 07, 2024 at 03:38AM by PilotSmooth9439
via reddit https://ift.tt/ywk81Rr
Apres-Cyber
Apres-Cyber Slopes Summit
Apres-Cyber Slopes Summit is a Cybersecurity conference event with trainings and briefings at a ski-in/ski-out resort located within the Canyons Village at Park City Utah, the largest ski resort in the USA. Focused on cybersecurity leaders (e.g. CISOs) and…
🎤 Call for Speakers: Submit Your Talk for BSidesSLC 2025 by Jan. 10th!
https://ift.tt/6c0onI2
Submitted December 07, 2024 at 03:32AM by PilotSmooth9439
via reddit https://ift.tt/ngiRA0c
https://ift.tt/6c0onI2
Submitted December 07, 2024 at 03:32AM by PilotSmooth9439
via reddit https://ift.tt/ngiRA0c
BSidesSLC
HOME | BSidesSLC Cybersecurity Community Utah Network
BSidesSLC Utah's local Cybersecurity Community. Learn, Train, Compete, and Network. For the people, by the people!
From XSS Vulnerability to Full Admin Access
https://ift.tt/Va6gZMl
Submitted December 09, 2024 at 11:41AM by HayMiz
via reddit https://ift.tt/xTecMhg
https://ift.tt/Va6gZMl
Submitted December 09, 2024 at 11:41AM by HayMiz
via reddit https://ift.tt/xTecMhg
haymiz@kali:~/blog$
From XSS Vulnerability to Full Admin Access
A Real-World Case Study, How I Took Over an Entire Application Using a Classic XSS Vulnerability.
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
https://ift.tt/fRBuXCJ
Submitted December 09, 2024 at 03:14PM by AlmondOffSec
via reddit https://ift.tt/6gBvmL3
https://ift.tt/fRBuXCJ
Submitted December 09, 2024 at 03:14PM by AlmondOffSec
via reddit https://ift.tt/6gBvmL3
GMO Flatt Security Research
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction
Hello, I’m RyotaK (@ryotkak
), a security engineer at Flatt Security Inc.
A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt
on my router.1 After accessing the LuCI, which is the web interface of OpenWrt…
Hello, I’m RyotaK (@ryotkak
), a security engineer at Flatt Security Inc.
A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt
on my router.1 After accessing the LuCI, which is the web interface of OpenWrt…
The Ruby on Rails _json Juggling Attack
https://ift.tt/xc0Gz5w
Submitted December 10, 2024 at 02:59PM by albinowax
via reddit https://ift.tt/hdNyP5M
https://ift.tt/xc0Gz5w
Submitted December 10, 2024 at 02:59PM by albinowax
via reddit https://ift.tt/hdNyP5M
Write, debug and execute BOFs with bof-launcher library (part 1)
https://ift.tt/bp5anTL
Submitted December 10, 2024 at 05:13PM by michal-z-
via reddit https://ift.tt/Bk4NI32
https://ift.tt/bp5anTL
Submitted December 10, 2024 at 05:13PM by michal-z-
via reddit https://ift.tt/Bk4NI32
Performing Android Static Analysis 101-A Complete Guide for Beginners - Laburity
https://ift.tt/FuNzvB0
Submitted December 10, 2024 at 07:18PM by Ancient_Title_1860
via reddit https://ift.tt/hHgwP84
https://ift.tt/FuNzvB0
Submitted December 10, 2024 at 07:18PM by Ancient_Title_1860
via reddit https://ift.tt/hHgwP84
Laburity - Cyber Security Services
Performing Android Static Analysis 101-A Complete Guide for Beginners - Laburity
Android Static Analysis is a foundational approach to identifying vulnerabilities in applications without executing them. This blog provides insight into the tools and techniques required for effective analysis. What is Android Static Analysis: Android static…
$750K stolen: The Telegram Groups’ Huge Scam (Investigation)
https://ift.tt/sVgLiZE
Submitted December 10, 2024 at 06:46PM by hisfuntie
via reddit https://ift.tt/NuBjvJ3
https://ift.tt/sVgLiZE
Submitted December 10, 2024 at 06:46PM by hisfuntie
via reddit https://ift.tt/NuBjvJ3
BlockFence
$750K stolen: The Telegram Groups' Huge Scam (Investigation)
TL;DR Blockfence recently discovered a rug pull scam carried out through the Telegram group “NoLiquids”, where the scammers promoted fake tokens that
Elevate Your Game with CASA Tier 2 Compliance!
https://cyberixlab.com/
Submitted December 11, 2024 at 01:15AM by Brave_State_4859
via reddit https://ift.tt/hYVwCjS
https://cyberixlab.com/
Submitted December 11, 2024 at 01:15AM by Brave_State_4859
via reddit https://ift.tt/hYVwCjS
Reddit
From the netsec community on Reddit: Elevate Your Game with CASA Tier 2 Compliance!
Posted by Brave_State_4859 - 0 votes and 0 comments
A complete OWASP API Top 10 Manual Testing Guide with vAPI
https://ift.tt/xUSVsuC
Submitted December 11, 2024 at 12:43PM by Altrntiv-to-security
via reddit https://ift.tt/opR14Is
https://ift.tt/xUSVsuC
Submitted December 11, 2024 at 12:43PM by Altrntiv-to-security
via reddit https://ift.tt/opR14Is
DarkRelay
OWASP API Testing Guide: A Visual Guide to OWASP API Testing with vAPI
Mastering OWASP API Testing: A Visual Guide to Testing OWASP Top 10 API Security with vAPI & real world examples. Learn expert techniques.
Mastering Bug Bounty Recon: Essential Techniques for Ethical Hackers
https://ift.tt/1xku4Ie
Submitted December 11, 2024 at 02:03PM by Justin_coco
via reddit https://ift.tt/Js3hALZ
https://ift.tt/1xku4Ie
Submitted December 11, 2024 at 02:03PM by Justin_coco
via reddit https://ift.tt/Js3hALZ
Medium
Mastering Bug Bounty Recon: Essential Techniques for Ethical Hackers
The first step to attacking any target is conducting reconnaissance, or simply put, gathering information about the target. Reconnaissance…
The Ultralytics Supply Chain Attack: Connecting the Dots with GitGuardian’s Public Monitoring Data
https://ift.tt/WFsTgib
Submitted December 11, 2024 at 06:54PM by guedou
via reddit https://ift.tt/STdAwRz
https://ift.tt/WFsTgib
Submitted December 11, 2024 at 06:54PM by guedou
via reddit https://ift.tt/STdAwRz
GitGuardian Blog - Take Control of Your Secrets Security
The Ultralytics Supply Chain Attack: Connecting the Dots with GitGuardian’s Public Monitoring Data
On December 4, 2024, the Ultralytics Python module was backdoored to deploy a cryptominer. Using GitGuardian’s data, we reconstructed deleted commits, connecting the dots with the initial analysis. This investigation highlights the value of GitGuardian’s…
Hacking AI Applications: From 3D Printing to Remote Code Execution
https://ift.tt/TKPx3iE
Submitted December 11, 2024 at 08:02PM by crustysecurity
via reddit https://ift.tt/tOzIywF
https://ift.tt/TKPx3iE
Submitted December 11, 2024 at 08:02PM by crustysecurity
via reddit https://ift.tt/tOzIywF
www.securityrunners.io
Hacking AI Applications: From 3D Printing to Remote Code Execution
The blog post examines methods for hacking AI-native applications by detailing vulnerabilities discovered while building KachraCraft, a 3D design generation tool, including techniques for revealing system prompts, executing server-side request forgery (SSRF)…
Why Can’t You Fix This Bug Faster?
https://ift.tt/E5cprh4
Submitted December 11, 2024 at 10:02PM by mdulin2
via reddit https://ift.tt/PTVjafe
https://ift.tt/E5cprh4
Submitted December 11, 2024 at 10:02PM by mdulin2
via reddit https://ift.tt/PTVjafe
Strikeout Security Blog
Why Can't You Fix This Bug Faster?
Fixing security vulnerabilities in a timely manner is more complicated than you realize.
Far From Random: Three Mistakes From Dart/Flutter's Weak PRNG
https://ift.tt/2Rpw9Gm
Submitted December 12, 2024 at 04:12AM by bored_cs_student
via reddit https://ift.tt/5EpFwTV
https://ift.tt/2Rpw9Gm
Submitted December 12, 2024 at 04:12AM by bored_cs_student
via reddit https://ift.tt/5EpFwTV
www.zellic.io
Far From Random: Three Mistakes From Dart/Flutter's Weak PRNG | Zellic — Research
A look into how an unexpectedly weak PRNG in Dart led to Zellic's discovery of multiple vulnerabilities