Attacking Cortex XDR from an unprivileged user perspective
https://ift.tt/Tz8LeMf
Submitted December 12, 2024 at 06:54PM by AlmondOffSec
via reddit https://ift.tt/BElhqsy
https://ift.tt/Tz8LeMf
Submitted December 12, 2024 at 06:54PM by AlmondOffSec
via reddit https://ift.tt/BElhqsy
300K+ Prometheus Servers and Exporters Exposed to DoS Attack
https://ift.tt/F4AkUiJ
Submitted December 12, 2024 at 09:56PM by Pale_Fly_2673
via reddit https://ift.tt/9Mgtj4b
https://ift.tt/F4AkUiJ
Submitted December 12, 2024 at 09:56PM by Pale_Fly_2673
via reddit https://ift.tt/9Mgtj4b
Aqua
300,000+ Prometheus Servers and Exporters Exposed to DoS Attacks
Our findings highlight that at least 336,000 servers expose their Prometheus servers and exporters to the internet
Astalavista.com - Security Community - Relaunch 2024
https://ift.tt/k3hR1mA
Submitted December 13, 2024 at 12:48AM by ddanchev123
via reddit https://ift.tt/9zTrE1Y
https://ift.tt/k3hR1mA
Submitted December 13, 2024 at 12:48AM by ddanchev123
via reddit https://ift.tt/9zTrE1Y
Android's CVE-2022-20201 (InstalldNativeService)
https://ift.tt/oF3W0gM
Submitted December 13, 2024 at 01:33AM by pwntheplanet
via reddit https://ift.tt/ioSlGKL
https://ift.tt/oF3W0gM
Submitted December 13, 2024 at 01:33AM by pwntheplanet
via reddit https://ift.tt/ioSlGKL
( ͡◕ _ ͡◕)👌
Android's CVE-2022-20201 (InstalldNativeService)
Intro This is another attempt as part of my @vr_progress to hack my old, unpatched OnePlus phone which didn’t get any updates for years. This time I chose CVE-2022-20201, a crafty little bug hiding in one of the subsystems used by Android’s package manager.
Using a 😡 emoji to DoS Facebook Messenger
https://ift.tt/ceTECVA
Submitted December 13, 2024 at 03:57AM by theappanalyst
via reddit https://ift.tt/sBrPCw3
https://ift.tt/ceTECVA
Submitted December 13, 2024 at 03:57AM by theappanalyst
via reddit https://ift.tt/sBrPCw3
Signal 11
Messenger Group Call DoS for iOS
Messenger is used by hundreds of millions of people globally, and as of December 2023, it has adopted end-to-end encryption (E2EE) by default for chats and calls. However, when a group chat is created, it initially does not use E2EE. Interestingly, non-E2EE…
CVE-2024-55557 - Weasis 4.5.1
https://ift.tt/pvPrkzH
Submitted December 13, 2024 at 01:36PM by AlbatrossMaximum4489
via reddit https://ift.tt/05t9ulO
https://ift.tt/pvPrkzH
Submitted December 13, 2024 at 01:36PM by AlbatrossMaximum4489
via reddit https://ift.tt/05t9ulO
Microsoft enforces defenses preventing NTLM relay attacks - Help Net Security
https://ift.tt/QHEwTZU
Submitted December 15, 2024 at 04:36PM by busevepet
via reddit https://ift.tt/45Gs1dv
https://ift.tt/QHEwTZU
Submitted December 15, 2024 at 04:36PM by busevepet
via reddit https://ift.tt/45Gs1dv
Help Net Security
Microsoft enforces defenses preventing NTLM relay attacks
Until NTLM gets disabled by default, Microsoft is working on shoring up defenses against NTLM relay attacks.
Post: Mutation XSS: Explained, CVE and Challenge | Jorian Woltjer
https://ift.tt/YBr0EFe
Submitted December 15, 2024 at 08:24PM by warbitlip
via reddit https://ift.tt/0A7ZPRO
https://ift.tt/YBr0EFe
Submitted December 15, 2024 at 08:24PM by warbitlip
via reddit https://ift.tt/0A7ZPRO
jorianwoltjer.com
Mutation XSS: Explained, CVE and Challenge | Jorian Woltjer
Learn how to bypass HTML sanitizers by abusing the intricate parsing rules and mutations. Including my CVE-2024-52595 (lxml_html_clean bypass) and the solution to a hard challenge I shared online
CVE-2024-42845
https://ift.tt/bksP1z3
Submitted December 16, 2024 at 03:09AM by AlbatrossMaximum4489
via reddit https://ift.tt/edIzkra
https://ift.tt/bksP1z3
Submitted December 16, 2024 at 03:09AM by AlbatrossMaximum4489
via reddit https://ift.tt/edIzkra
[Network tarpit] Scanners Beware: Welcome to the Network from Hell
https://ift.tt/kt2x3nR
Submitted December 16, 2024 at 07:01PM by oherrala
via reddit https://ift.tt/zyHDe8d
https://ift.tt/kt2x3nR
Submitted December 16, 2024 at 07:01PM by oherrala
via reddit https://ift.tt/zyHDe8d
Medium
Scanners Beware: Welcome to the Network from Hell
We’ve crafted a bold defense strategy that not only slows scans but actively disrupts and deceives attackers.
Mozilla Firefox removes "Do Not Track" Feature support
https://ift.tt/UpcgtNl
Submitted December 16, 2024 at 08:02PM by towtoo893
via reddit https://ift.tt/ljTxNRu
https://ift.tt/UpcgtNl
Submitted December 16, 2024 at 08:02PM by towtoo893
via reddit https://ift.tt/ljTxNRu
Windows Report
Mozilla Firefox removes "Do Not Track" Feature support: Here's what it means for your Privacy
Firefox is removing the Do Not Track setting from version 135 onwards. Mozilla recommends using Global Privacy Control setting as alternative,
Finding Bugs in Chrome with CodeQL
https://ift.tt/wb6O7qs
Submitted December 16, 2024 at 07:51PM by rawion363
via reddit https://ift.tt/TLRhOb5
https://ift.tt/wb6O7qs
Submitted December 16, 2024 at 07:51PM by rawion363
via reddit https://ift.tt/TLRhOb5
Google
Blog: Finding Bugs in Chrome with CodeQL
Want to learn about using a static analysis tool called CodeQL to search for vulnerabilities in Google Chrome? Then this blog post is for you!
Platform.sh team finds auth bypass in Go SSH package
https://ift.tt/GC56EFW
Submitted December 16, 2024 at 07:38PM by rawion363
via reddit https://ift.tt/3gBC7JV
https://ift.tt/GC56EFW
Submitted December 16, 2024 at 07:38PM by rawion363
via reddit https://ift.tt/3gBC7JV
Upsun
Security vulnerability uncovered and patched in the golang.org/x/crypto /ssh package
Misimplementation of PublicKeyCallback leads to authorization bypass in Go's x/crypto/sshPlatform.
“DeceptionAds” — Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising
https://ift.tt/bTlWFwZ
Submitted December 16, 2024 at 08:27PM by towtoo893
via reddit https://ift.tt/L9hsCNl
https://ift.tt/bTlWFwZ
Submitted December 16, 2024 at 08:27PM by towtoo893
via reddit https://ift.tt/L9hsCNl
Medium
“DeceptionAds” — Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising
By Nati Tal (Head of Guardio Labs)
Hacking Kerio Control via CVE-2024-52875: from CRLF Injection to 1-click RCE
https://ift.tt/bQ7aKcV
Submitted December 16, 2024 at 09:34PM by eg1x
via reddit https://ift.tt/zX2ipG3
https://ift.tt/bQ7aKcV
Submitted December 16, 2024 at 09:34PM by eg1x
via reddit https://ift.tt/zX2ipG3
Karmainsecurity
Hacking Kerio Control via CVE-2024-52875: from CRLF Injection to 1-click RCE | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Unsafe Archive Unpacking: Labs and Semgrep Rules
https://ift.tt/rdYgBk2
Submitted December 17, 2024 at 01:52AM by nibblesec
via reddit https://ift.tt/RPvx01S
https://ift.tt/rdYgBk2
Submitted December 17, 2024 at 01:52AM by nibblesec
via reddit https://ift.tt/RPvx01S
The Full Story of CVE-2024-6386: Remote Code Execution in WPML
https://ift.tt/OVe1Nnj
Submitted December 17, 2024 at 01:21PM by jonas02
via reddit https://ift.tt/FAbZ1l4
https://ift.tt/OVe1Nnj
Submitted December 17, 2024 at 01:21PM by jonas02
via reddit https://ift.tt/FAbZ1l4
WPSec
The Full Story of CVE-2024-6386: Remote Code Execution in WPML - WPSec
The WordPress Multilingual Plugin (WPML), with over 1,000,000 active installations, was vulnerable to Remote Code Execution (RCE) via a Server-Side Template Injection (SSTI) vulnerability in the Twig template engine. WPML is a premium plugin that provides…
LLM for ABAP Code Scanner
https://ift.tt/ncHrpmE
Submitted December 17, 2024 at 01:47PM by vah_13
via reddit https://ift.tt/ApCta92
https://ift.tt/ncHrpmE
Submitted December 17, 2024 at 01:47PM by vah_13
via reddit https://ift.tt/ApCta92
owasp.org
RedRays ABAP Code Scanner | OWASP Foundation
A Python tool for scanning offline SAP ABAP source code to detect security vulnerabilities
Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware
https://ift.tt/MZ8R0f1
Submitted December 18, 2024 at 04:13AM by Glad_Ad534
via reddit https://ift.tt/jDsKR9b
https://ift.tt/MZ8R0f1
Submitted December 18, 2024 at 04:13AM by Glad_Ad534
via reddit https://ift.tt/jDsKR9b
Authentication Bypass Vulnerability in Philips IntelliSpace Cardiovascular
https://ift.tt/OUtD0QH
Submitted December 18, 2024 at 08:37AM by panicnot42
via reddit https://ift.tt/rCPZtlD
https://ift.tt/OUtD0QH
Submitted December 18, 2024 at 08:37AM by panicnot42
via reddit https://ift.tt/rCPZtlD
Understanding Logits And Their Possible Impacts On Large Language Model Output Safety
https://ift.tt/qs59VTv
Submitted December 19, 2024 at 01:24AM by 0xRaindrop
via reddit https://ift.tt/t9GvjlI
https://ift.tt/qs59VTv
Submitted December 19, 2024 at 01:24AM by 0xRaindrop
via reddit https://ift.tt/t9GvjlI