I'm Lovin' It: Exploiting McDonald's APIs to hijack deliveries and order food for a penny
https://ift.tt/ncFhMLJ
Submitted December 19, 2024 at 06:42PM by EatonZ
via reddit https://ift.tt/BdJjEUC
https://ift.tt/ncFhMLJ
Submitted December 19, 2024 at 06:42PM by EatonZ
via reddit https://ift.tt/BdJjEUC
Eaton-Works
I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny
A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people’s delivery orders, view user information, and more.
New Windows Privilege Escalation Vulnerability!
https://ift.tt/Mv8Xho7
Submitted December 19, 2024 at 10:02PM by SSDisclosure
via reddit https://ift.tt/K0PA2W3
https://ift.tt/Mv8Xho7
Submitted December 19, 2024 at 10:02PM by SSDisclosure
via reddit https://ift.tt/K0PA2W3
SSD Secure Disclosure
SSD Advisory - cldflt Heap-based Overflow (PE) - SSD Secure Disclosure
Summary A vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system. The specific…
CISA Mandates Cloud Security for Federal Agencies by 2025 Under Binding Directive 25-01
https://ift.tt/z0HhKk1
Submitted December 20, 2024 at 03:19AM by Glad_Ad534
via reddit https://ift.tt/Vc0Y87n
https://ift.tt/z0HhKk1
Submitted December 20, 2024 at 03:19AM by Glad_Ad534
via reddit https://ift.tt/Vc0Y87n
techacademy.online
CISA Mandates Cloud Security for Federal Agencies by 2025 Under Binding Directive 25-01
CISA's new directive mandates federal agencies secure cloud environments by 2025, introducing SCuBA tools for monitoring and reducing cyberattack surf
Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits
https://ift.tt/kgKLXiC
Submitted December 20, 2024 at 02:58AM by Glad_Ad534
via reddit https://ift.tt/5YOurn7
https://ift.tt/kgKLXiC
Submitted December 20, 2024 at 02:58AM by Glad_Ad534
via reddit https://ift.tt/5YOurn7
techacademy.online
Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits
Fortinet patches critical flaws in FortiWLM and FortiManager. CVE-2023-34990 risks sensitive data, while CVE-2024-48889 enables command injection.
CVE-2024-44825 - Invesalius Arbitrary File Write and Directory Traversal
https://ift.tt/71fMsRc
Submitted December 20, 2024 at 03:17PM by AlbatrossMaximum4489
via reddit https://ift.tt/Qu7Hfxa
https://ift.tt/71fMsRc
Submitted December 20, 2024 at 03:17PM by AlbatrossMaximum4489
via reddit https://ift.tt/Qu7Hfxa
🌟 TOP 5 AI and Security Predictions for 2025
https://ift.tt/P2lb4Vt
Submitted December 20, 2024 at 10:33PM by mymalema
via reddit https://ift.tt/rsOwnQh
https://ift.tt/P2lb4Vt
Submitted December 20, 2024 at 10:33PM by mymalema
via reddit https://ift.tt/rsOwnQh
Medium
🚀 TOP 5 AI and Cybersecurity Predictions for 2025
Join the AI Security group at https://www.linkedin.com/groups/14545517 for more similar content.
Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
https://ift.tt/5IxoX7T
Submitted December 21, 2024 at 01:21PM by ffyns
via reddit https://ift.tt/qcd0Xv1
https://ift.tt/5IxoX7T
Submitted December 21, 2024 at 01:21PM by ffyns
via reddit https://ift.tt/qcd0Xv1
Pentesterlab
Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
Discover how a code review uncovered a JWT algorithm confusion vulnerability (CVE-2024-54150). Learn key insights to enhance your security skills and spot vulnerabilities effectively.
Security Implications of Catastrophic AI Risks
https://ift.tt/vpcouxw
Submitted December 22, 2024 at 03:34AM by mymalema
via reddit https://ift.tt/VTpwfxu
https://ift.tt/vpcouxw
Submitted December 22, 2024 at 03:34AM by mymalema
via reddit https://ift.tt/VTpwfxu
Medium
🔍 Cybersecurity Implications of Catastrophic AI Risks
The paper “An Overview of Catastrophic AI Risks” by the Center for AI Safety delves into how advanced AI systems introduce critical cybersecurity challenges. (Join the AI Security group at…
Incident Response for Generative AI Workloads: A Structured Approach by AWS
https://ift.tt/Ie6QVCk
Submitted December 22, 2024 at 08:35AM by mymalema
via reddit https://ift.tt/ST4Z6px
https://ift.tt/Ie6QVCk
Submitted December 22, 2024 at 08:35AM by mymalema
via reddit https://ift.tt/ST4Z6px
Medium
🔐 Incident Response for Generative AI Workloads: A Structured Approach by AWS
Amazon Web Services (AWS) outlines a structured approach for incident response in Generative AI workloads, emphasizing both response…
Modular Linux Backdoor IOCONTROL Hits OT, SCADA, IoT
https://ift.tt/DBxFq8y
Submitted December 23, 2024 at 07:52PM by derp6996
via reddit https://ift.tt/0VqvI8h
https://ift.tt/DBxFq8y
Submitted December 23, 2024 at 07:52PM by derp6996
via reddit https://ift.tt/0VqvI8h
Claroty
Inside a New OT/IoT Cyberweapon: IOCONTROL
Team82 has researched a malware sample called IOCONTROL linked to an Iran-based attack group used to target IoT and OT civilian infrastructure in the U.S. and Israel.
Agentic AI security podcast episode
https://ift.tt/EQ3H5jI
Submitted December 24, 2024 at 01:07PM by fcanogab
via reddit https://ift.tt/xSlV5Ek
https://ift.tt/EQ3H5jI
Submitted December 24, 2024 at 01:07PM by fcanogab
via reddit https://ift.tt/xSlV5Ek
Spotify for Creators
Agentic AI Security by Mind the Machine
In this episode of Mind the Machine, host Florencio Cano talks about the concept of agentic AI, exploring what makes AI systems capable of autonomously performing tasks and the unique security challenges they present.
While agentic AI can revolutionize industries…
While agentic AI can revolutionize industries…
Scraping By: My YouTube Data Adventure
https://ift.tt/eBYXhzv
Submitted December 25, 2024 at 12:53AM by nv1t
via reddit https://ift.tt/zBOfU89
https://ift.tt/eBYXhzv
Submitted December 25, 2024 at 12:53AM by nv1t
via reddit https://ift.tt/zBOfU89
Blog
Scraping By: My YouTube Data Adventure
A while ago, I reached out to Mats, the creator behind the YouTube channel Topfvollgold, offering my help with data scraping. I thought it might be useful for his projects and mentioned that I’d be happy to assist if the need ever arose.
Recently, Mats reached…
Recently, Mats reached…
Non-Intrusive Web Recon: Techniques from Chrome DevTools Recorder
https://ift.tt/RNvYwbD
Submitted December 25, 2024 at 09:42PM by toyojuni
via reddit https://ift.tt/YGuMf89
https://ift.tt/RNvYwbD
Submitted December 25, 2024 at 09:42PM by toyojuni
via reddit https://ift.tt/YGuMf89
GMO Flatt Security Research
Non-Intrusive Web Recon: Techniques from Chrome DevTools Recorder
Introduction: The Art of Non-Intrusive Web Recon
Hello, I’m pizzacat83 (@pizzacat83
), a software engineer at Flatt Security Inc.
When hunting for bugs, understanding the behavior of a target application is invaluable. The more knowledge you gain about the…
Hello, I’m pizzacat83 (@pizzacat83
), a software engineer at Flatt Security Inc.
When hunting for bugs, understanding the behavior of a target application is invaluable. The more knowledge you gain about the…
Looking For reputable Gateway which accepts Portuguese prepaid 5G SIM cards and can run open source
https://ift.tt/f41BSgd
Submitted December 27, 2024 at 03:34PM by JMLenterprise
via reddit https://ift.tt/8WvTgne
https://ift.tt/f41BSgd
Submitted December 27, 2024 at 03:34PM by JMLenterprise
via reddit https://ift.tt/8WvTgne
Teltonika-Networks
TRB500 5G Gateway
TRB500 is a compact, energy-efficient Teltonika Networks 5G gateway with speeds of up to 1 Gbps and backward compatibility. Click here to learn more.
Announcing the External Penetration Testing Program Pack
https://ift.tt/5ZhYzLs
Submitted December 28, 2024 at 05:44AM by SecTemplates
via reddit https://ift.tt/RMtyIqs
https://ift.tt/5ZhYzLs
Submitted December 28, 2024 at 05:44AM by SecTemplates
via reddit https://ift.tt/RMtyIqs
SecTemplates.com
Announcing the External Penetration Testing Program Pack v1.1
This release contains everything you need to scope your first pentest, work with a vendor, execute, and get the types of reports you need from an external tester. This will enable you to perform your first product or infrastructure level penetration test…
Performing AD LDAP Queries Like a Ninja | CravateRouge Ltd
https://ift.tt/UO0FHSt
Submitted December 28, 2024 at 11:01AM by CravateRouge
via reddit https://ift.tt/uyLvjcb
https://ift.tt/UO0FHSt
Submitted December 28, 2024 at 11:01AM by CravateRouge
via reddit https://ift.tt/uyLvjcb
CravateRouge Ltd
Performing AD LDAP Queries Like a Ninja | CravateRouge Ltd
Strategies to minimize logging generation, and methods to enhance logging efficiency
Volkswagen's bad streak: They know where your car is, Chaos Computer Club says – and they don't know how to secure it properly.
https://ift.tt/K31jQsm
Submitted December 29, 2024 at 07:12PM by ReynardSec
via reddit https://ift.tt/fHLh6BN
https://ift.tt/K31jQsm
Submitted December 29, 2024 at 07:12PM by ReynardSec
via reddit https://ift.tt/fHLh6BN
ReynardSec
Home
ReynardSec - Cybersecurity Advisor
NFS Security: Identifying and Exploiting Misconfigurations
https://ift.tt/XoK1Yim
Submitted December 30, 2024 at 01:39AM by edermi
via reddit https://ift.tt/gFUjyb7
https://ift.tt/XoK1Yim
Submitted December 30, 2024 at 01:39AM by edermi
via reddit https://ift.tt/gFUjyb7
HvS-Consulting
NFS Security: Identifying and Exploiting Misconfigurations | HvS-Consulting
Understand security features, misconfigurations and technical attacks on NFS shares.
Simple Prompts to get the System Prompts
https://ift.tt/ZRPIyfb
Submitted December 30, 2024 at 09:25AM by 0xcrypto
via reddit https://ift.tt/vLSldhs
https://ift.tt/ZRPIyfb
Submitted December 30, 2024 at 09:25AM by 0xcrypto
via reddit https://ift.tt/vLSldhs
eval.blog
Simple Prompts to get the System Prompts
This site contains research, technical papers, projects, and insights on systems programming, security, artificial intelligence, and game development by Vikrant aka 0xcrypto.
From Arbitrary File Write to RCE in Restricted Rails apps
https://ift.tt/RP52iU7
Submitted December 30, 2024 at 07:33PM by sercurity
via reddit https://ift.tt/iT0V9vo
https://ift.tt/RP52iU7
Submitted December 30, 2024 at 07:33PM by sercurity
via reddit https://ift.tt/iT0V9vo
Conviso AppSec
From Arbitrary File Write to RCE in Restricted Rails apps
We describe a technique that can be used to achieve remote code execution (RCE) from an arbitrary file write vulnerability by abusing the cache mechanism of Bootsnap.
Dumping Memory to Bypass BitLocker on Windows 11
https://ift.tt/0rvIpwo
Submitted December 30, 2024 at 11:17PM by NoInitialRamdisk
via reddit https://ift.tt/hwmMN9p
https://ift.tt/0rvIpwo
Submitted December 30, 2024 at 11:17PM by NoInitialRamdisk
via reddit https://ift.tt/hwmMN9p
Dumping Memory to Bypass BitLocker on Windows 11
Intro
A UEFI application for dumping the contents of RAM.