20 Critical Characteristics of Non-Human Identities You Need to Know
https://ift.tt/4H1dNC6
Submitted January 25, 2025 at 12:57AM by MulberrySuch968
via reddit https://ift.tt/rnaNHP8
https://ift.tt/4H1dNC6
Submitted January 25, 2025 at 12:57AM by MulberrySuch968
via reddit https://ift.tt/rnaNHP8
TechDemocracy
20 Critical Characteristics of Non-Human Identities
Non-Human Identities (NHIs) are essential for automation but pose unique security challenges requiring tailored management and protection strategies. Know more!
Simplified Threat Intelligence gathering
https://ift.tt/cZsD4nC
Submitted January 25, 2025 at 03:01AM by stan_frbd
via reddit https://ift.tt/w2qxoCG
https://ift.tt/cZsD4nC
Submitted January 25, 2025 at 03:01AM by stan_frbd
via reddit https://ift.tt/w2qxoCG
Kali Linux Tutorials
Cyberbro : Revolutionizing Threat Intelligence With Simplified
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple services.
Clone2Leak: Your Git Credentials Belong To Us
https://ift.tt/qCODmz8
Submitted January 26, 2025 at 08:33PM by toyojuni
via reddit https://ift.tt/C2n0jqI
https://ift.tt/qCODmz8
Submitted January 26, 2025 at 08:33PM by toyojuni
via reddit https://ift.tt/C2n0jqI
GMO Flatt Security Research
Clone2Leak: Your Git Credentials Belong To Us
Introduction
Hello, I’m RyotaK ( @ryotkak
), a security engineer at GMO Flatt Security Inc.
In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise Server for a while, I felt bored and decided to try to…
Hello, I’m RyotaK ( @ryotkak
), a security engineer at GMO Flatt Security Inc.
In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise Server for a while, I felt bored and decided to try to…
WorstFit: Unveiling Hidden Transformers in Windows ANSI
https://ift.tt/EIstZ9h
Submitted January 27, 2025 at 03:20AM by Zezombye
via reddit https://ift.tt/uoH0QLJ
https://ift.tt/EIstZ9h
Submitted January 27, 2025 at 03:20AM by Zezombye
via reddit https://ift.tt/uoH0QLJ
DEVCORE 戴夫寇爾
WorstFit: Unveiling Hidden Transformers in Windows ANSI! | DEVCORE 戴夫寇爾
The research unveils a new attack surface in Windows by exploiting Best-Fit, an internal charset conversion feature. Through our work, we successfully transformed this feature into several practical attacks, including Path Traversal, Argument Injection, and…
New way to exploit BYOVD exploits with symbolic links.
https://ift.tt/DSsQ52A
Submitted January 27, 2025 at 02:07PM by Cold-Dinosaur
via reddit https://ift.tt/rchaZjg
https://ift.tt/DSsQ52A
Submitted January 27, 2025 at 02:07PM by Cold-Dinosaur
via reddit https://ift.tt/rchaZjg
Zerosalarium
BYOVD to the next level. Blind EDR with Windows Symbolic Link
A new way to use BYOVD technique. By combining the file-writing capabilities of a driver with Windows symbolic links
Don't let these open-source tools slip under your radar - Help Net Security
https://ift.tt/pwbJ0YI
Submitted January 27, 2025 at 06:09PM by stan_frbd
via reddit https://ift.tt/Tgnvw4C
https://ift.tt/pwbJ0YI
Submitted January 27, 2025 at 06:09PM by stan_frbd
via reddit https://ift.tt/Tgnvw4C
Help Net Security
Don’t let these open-source cybersecurity tools slip under your radar
This article lists open-source cybersecurity tools for Linux, Windows, and macOS to help enhance protection and stay ahead of threats.
Get FortiRekt, I am the Super_Admin Now - FortiOS Authentication Bypass CVE-2024-55591 - watchTowr Labs
https://ift.tt/iw2XBub
Submitted January 27, 2025 at 11:36PM by dx7r__
via reddit https://ift.tt/scAuzpe
https://ift.tt/iw2XBub
Submitted January 27, 2025 at 11:36PM by dx7r__
via reddit https://ift.tt/scAuzpe
watchTowr Labs
Get FortiRekt, I Am The Super_Admin Now - Fortinet FortiOS Authentication Bypass CVE-2024-55591
Welcome to Monday, and what an excitingly fresh start to the week we're all having.
Grab your coffee, grab your vodka - we're diving into a currently exploited-in-the-wild critical Authentication Bypass affecting foRtinet's (we are returning the misspelling…
Grab your coffee, grab your vodka - we're diving into a currently exploited-in-the-wild critical Authentication Bypass affecting foRtinet's (we are returning the misspelling…
A Missed Opportunity: Weak Password Hashing in VxWorks 6.9 and 7
https://ift.tt/1JaDTL8
Submitted January 28, 2025 at 02:18PM by Longjumping-Top2717
via reddit https://ift.tt/gKaDr3x
https://ift.tt/1JaDTL8
Submitted January 28, 2025 at 02:18PM by Longjumping-Top2717
via reddit https://ift.tt/gKaDr3x
SEC Consult
A Missed Opportunity: Addressing Weak Password Hashing in VxWorks
The security of embedded systems running Real-Time Operating Systems (RTOS) like Wind River VxWorks is vital in high stakes sectors such as OT, defense, and aviation.
Using AiTM to phish for access- and refreshtokens
https://ift.tt/kGzR6Bd
Submitted January 28, 2025 at 07:51PM by rikvduijn
via reddit https://ift.tt/ByxFkXZ
https://ift.tt/kGzR6Bd
Submitted January 28, 2025 at 07:51PM by rikvduijn
via reddit https://ift.tt/ByxFkXZ
Zolder - Applied Security Research
Phishing for Refresh Tokens | Zolder - Applied Security Research
leveraging AiTM and the OAuth 2.0 authorization code flow to steal access and refresh tokens. Modified AITMWorker for steal refreshtokens.
Single QR Code, Two Different URLs
https://ift.tt/8DJ3egH
Submitted January 29, 2025 at 12:06AM by ReynardSec
via reddit https://ift.tt/NTJBlVj
https://ift.tt/8DJ3egH
Submitted January 29, 2025 at 12:06AM by ReynardSec
via reddit https://ift.tt/NTJBlVj
Mastodon 🐘
Christian Walther (@isziaui@mstdn.social)
Attached: 1 image
@gvy_dvpont@mastodon.social Got me thinking… can it be done without the lens? This one seems to work!
@gvy_dvpont@mastodon.social Got me thinking… can it be done without the lens? This one seems to work!
CVE-2024-49138 Windows CLFS heap-based buffer overflow analysis
https://ift.tt/mbrLKvg
Submitted January 29, 2025 at 02:12PM by 0xdea
via reddit https://ift.tt/D01tpu8
https://ift.tt/mbrLKvg
Submitted January 29, 2025 at 02:12PM by 0xdea
via reddit https://ift.tt/D01tpu8
HN Security
CVE-2024-49138 Windows CLFS heap-based buffer overflow analysis - Part 1 - HN Security
CVE-2024-49138 is a Windows vulnerability detected by CrowdStrike as exploited in the wild. Microsoft patched the vulnerability on December 10th, […]
CVE-2024-46507: Yeti Platform Server-Side Template Injection (SSTI)
https://ift.tt/Dt7v5af
Submitted January 29, 2025 at 11:41PM by hackers_and_builders
via reddit https://ift.tt/HY5BcC0
https://ift.tt/Dt7v5af
Submitted January 29, 2025 at 11:41PM by hackers_and_builders
via reddit https://ift.tt/HY5BcC0
Rhino Security Labs
CVE-2024-46507: Yeti Platform Server-Side Template Injection (SSTI)
Yeti is a Forensic Intelligence platform and pipeline for DFIR teams. Rhino Security Labs will detail 2 security flaws that, combined, lead to unauthenticated RCE.
A short Introduction to BloodHound Custom Queries
https://ift.tt/RIEx74Y
Submitted January 30, 2025 at 05:43PM by k8pf
via reddit https://ift.tt/qlpFX76
https://ift.tt/RIEx74Y
Submitted January 30, 2025 at 05:43PM by k8pf
via reddit https://ift.tt/qlpFX76
Practising Heap Exploitation: Using House Of Force Technique with Practicals
https://ift.tt/LGO5g4c
Submitted January 30, 2025 at 06:20PM by Altrntiv-to-security
via reddit https://ift.tt/DIQHvCS
https://ift.tt/LGO5g4c
Submitted January 30, 2025 at 06:20PM by Altrntiv-to-security
via reddit https://ift.tt/DIQHvCS
DarkRelay
Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique
Heap exploitation techniques like House of Force demonstrate the complexities and risks associated with memory management systems.
WebAssembly and security: a review
https://ift.tt/7goO3s9
Submitted January 30, 2025 at 07:40PM by daindragon2
via reddit https://ift.tt/LUb4CAf
https://ift.tt/7goO3s9
Submitted January 30, 2025 at 07:40PM by daindragon2
via reddit https://ift.tt/LUb4CAf
CVE-2024-46506: Unauthenticated RCE in NetAlertx
https://ift.tt/nwI187Z
Submitted January 30, 2025 at 11:21PM by hackers_and_builders
via reddit https://ift.tt/PjS4yAc
https://ift.tt/nwI187Z
Submitted January 30, 2025 at 11:21PM by hackers_and_builders
via reddit https://ift.tt/PjS4yAc
Rhino Security Labs
CVE-2024-46506: Unauthenticated RCE in NetAlertx
NetAlertX is an open-source Wi-Fi / Local Area Network (LAN) intruder detector that scans for devices connected to your network and alerts you if new and unknown devices are found.
The Slow Death of OCSP
https://ift.tt/XMUB1wn
Submitted January 31, 2025 at 01:06AM by ScottContini
via reddit https://ift.tt/OdQawIY
https://ift.tt/XMUB1wn
Submitted January 31, 2025 at 01:06AM by ScottContini
via reddit https://ift.tt/OdQawIY
CRLF injection via TryAddWithoutValidation in .NET
https://ift.tt/cHNiEeQ
Submitted January 31, 2025 at 02:24PM by cbagdude
via reddit https://ift.tt/SjJNHTk
https://ift.tt/cHNiEeQ
Submitted January 31, 2025 at 02:24PM by cbagdude
via reddit https://ift.tt/SjJNHTk
Binary Security AS
CRLF injection via TryAddWithoutValidation in .NET
Binary Security was awarded two CVEs (CVE-2024-45302 and CVE-2024-51501) for header injection vulnerabilities in the RestSharp and Refit .NET libraries. This blog post outlines the research which lead to discovering these vulnerabilities.
RCE (LAN) in Marvel Rivals
https://ift.tt/4ZsbzcY
Submitted January 31, 2025 at 04:36PM by shalzuth
via reddit https://ift.tt/EqzIcuo
https://ift.tt/4ZsbzcY
Submitted January 31, 2025 at 04:36PM by shalzuth
via reddit https://ift.tt/EqzIcuo
Shalzuth
Reverse Engineering: I Found a Game Exploit That Lets Hackers Take Over Your PC
Reverse Engineering: I discovered a serious Remote Code Execution (RCE) vulnerability in a popular game that could let attackers run code on your PC. Watch how I found it, reported it, and what you can do to stay safe.
Cisco Webex Connect - Unauthenticated access to all chats
https://ift.tt/c6TPsEW
Submitted January 31, 2025 at 04:06PM by albinowax
via reddit https://ift.tt/JgWzEI9
https://ift.tt/c6TPsEW
Submitted January 31, 2025 at 04:06PM by albinowax
via reddit https://ift.tt/JgWzEI9
Ophionsecurity
Live Chat Blog #2: Cisco Webex Connect - Access to millions of chats histories - Ophion Security Publications
In July 2024, we identified a vulnerability that resulted in access to millions of live customer support messages for organizations using Cisco Webex Connect.
SlackPirate Set Sails Again! Or: How to Send the Entire “Bee Movie” Script to Your Friends in Slack
https://ift.tt/EkfBvto
Submitted January 31, 2025 at 10:44PM by Rooftoptile2
via reddit https://ift.tt/AzBeSOf
https://ift.tt/EkfBvto
Submitted January 31, 2025 at 10:44PM by Rooftoptile2
via reddit https://ift.tt/AzBeSOf
Medium
SlackPirate Set Sails Again! Or: How to Send the Entire “Bee Movie” Script to Your Friends in Slack
TLDR: SlackPirate has been defunct for a few years due to a breaking change in how the Slack client interacts with the Slack API. It has a…