Fault Injection – Looking for a Unicorn
https://ift.tt/vuTBinH
Submitted February 11, 2025 at 01:48PM by 0xdea
via reddit https://ift.tt/oUrIhE4
https://ift.tt/vuTBinH
Submitted February 11, 2025 at 01:48PM by 0xdea
via reddit https://ift.tt/oUrIhE4
hn security
Fault Injection – Looking for a Unicorn - hn security
Intro In our previous article Fault […]
Exploring a VPN Appliance: A Researcher’s Journey
https://ift.tt/4OTbNjt
Submitted February 11, 2025 at 09:29PM by Narrow_Rooster_630
via reddit https://ift.tt/kgKH3mY
https://ift.tt/4OTbNjt
Submitted February 11, 2025 at 09:29PM by Narrow_Rooster_630
via reddit https://ift.tt/kgKH3mY
Akamai
Exploring a VPN Appliance: A Researcher’s Journey | Akamai
Akamai researchers explore Fortinet FortiOS and discover multiple vulnerabilities that can lead to denial-of-service and remote code execution attacks.
PsExec’ing the right way and why zero trust is mandatory
https://ift.tt/Qwgln4I
Submitted February 11, 2025 at 09:19PM by AlmondOffSec
via reddit https://ift.tt/ph5TBIG
https://ift.tt/Qwgln4I
Submitted February 11, 2025 at 09:19PM by AlmondOffSec
via reddit https://ift.tt/ph5TBIG
Sensepost
SensePost | Psexec’ing the right way and why zero trust is mandatory
Leaders in Information Security
Tenda AC15 CVE-2020-13393 Exploit (!exploitable episode one)
https://ift.tt/opOYCBN
Submitted February 11, 2025 at 08:58PM by nibblesec
via reddit https://ift.tt/fx5eAJw
https://ift.tt/opOYCBN
Submitted February 11, 2025 at 08:58PM by nibblesec
via reddit https://ift.tt/fx5eAJw
CVE-2025-0693: AWS IAM User Enumeration
https://ift.tt/eWytRGd
Submitted February 11, 2025 at 11:40PM by hackers_and_builders
via reddit https://ift.tt/G2hTpr8
https://ift.tt/eWytRGd
Submitted February 11, 2025 at 11:40PM by hackers_and_builders
via reddit https://ift.tt/G2hTpr8
Rhino Security Labs
CVE-2025-0693: AWS IAM User Enumeration
Rhino Security Labs discovered two username enumeration vulnerabilities in the AWS Web Console.
How auto-generated passwords in Sitevision leads to signing key leakage - CVE-2022-35202
https://ift.tt/2IHDB9v
Submitted February 12, 2025 at 02:16AM by ivxrehc
via reddit https://ift.tt/g2Ei7kP
https://ift.tt/2IHDB9v
Submitted February 12, 2025 at 02:16AM by ivxrehc
via reddit https://ift.tt/g2Ei7kP
Shelltrail - Swedish offensive security experts
How auto-generated passwords in Sitevision leads to signing key leakage - CVE-2022-35202 | Shelltrail - Swedish offensive security…
A security issue in Sitevision version 10.3.1 and older allows remote attacker, in certain scenarios, to gain access signing keys used for Authn SAML requests.
How We Hacked a Software Supply Chain for $50K
https://ift.tt/UVjtxHl
Submitted February 12, 2025 at 02:03PM by albinowax
via reddit https://ift.tt/DMfpmuw
https://ift.tt/UVjtxHl
Submitted February 12, 2025 at 02:03PM by albinowax
via reddit https://ift.tt/DMfpmuw
www.landh.tech
How We Hacked a Software Supply Chain for $50K - Lupin & Holmes
Leaking the email of any YouTube user for $10,000
https://ift.tt/7yDAWK2
Submitted February 12, 2025 at 05:59PM by AlmondOffSec
via reddit https://ift.tt/sMWrZxD
https://ift.tt/7yDAWK2
Submitted February 12, 2025 at 05:59PM by AlmondOffSec
via reddit https://ift.tt/sMWrZxD
brutecat.com
Leaking the email of any YouTube user for $10,000
What could've been the largest data breach in the world - an attack chain on Google services to leak the email address of any YouTube channel
From Convenience to Contagion: The Half-Day Threat and Libarchive Vulnerabilities Lurking in Windows 11
https://ift.tt/g8R0nEv
Submitted February 12, 2025 at 08:49PM by AlmondOffSec
via reddit https://ift.tt/CnRIkrz
https://ift.tt/g8R0nEv
Submitted February 12, 2025 at 08:49PM by AlmondOffSec
via reddit https://ift.tt/CnRIkrz
DEVCORE 戴夫寇爾
From Convenience to Contagion: The Half-Day Threat and Libarchive Vulnerabilities Lurking in Windows 11 | DEVCORE 戴夫寇爾
Windows 11's KB5031455 update adds RAR and 7z support via libarchive, but DEVCORE discovered multiple vulnerabilities, including Heap Buffer Overflow and arbitrary file operations. Delayed patching also enables “Half-day” attacks, putting projects like ClickHouse…
whoAMI: A cloud image name confusion attack | Datadog Security Labs
https://ift.tt/9Isvc8R
Submitted February 13, 2025 at 12:43AM by sethsec
via reddit https://ift.tt/AItvBYl
https://ift.tt/9Isvc8R
Submitted February 13, 2025 at 12:43AM by sethsec
via reddit https://ift.tt/AItvBYl
Datadoghq
whoAMI: A cloud image name confusion attack
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
Nginx/Apache Path Confusion to Auth Bypass in PAN-OS (CVE-2025-0108)
https://ift.tt/JbAQ2Ns
Submitted February 13, 2025 at 04:15AM by Mempodipper
via reddit https://ift.tt/LaFhmXN
https://ift.tt/JbAQ2Ns
Submitted February 13, 2025 at 04:15AM by Mempodipper
via reddit https://ift.tt/LaFhmXN
Searchlight Cyber
Nginx/Apache Path Confusion to Auth Bypass in PAN-OS (CVE-2025-0108) › Searchlight Cyber
Assetnote, now a searchlight cyber company, has uncovered a zero day auth bypass in the pan-os management interface new palo alto vulnerabilities discovered A few months ago, the news broke that CVE-2024-0012 and CVE-2024-9474 were under active exploitation…
55 Security Flaws Detected by Microsoft: 2 were Exploited by Hackers
https://ift.tt/EfQmjNH
Submitted February 13, 2025 at 10:21AM by Fabulous_Bluebird931
via reddit https://ift.tt/fMtaZTy
https://ift.tt/EfQmjNH
Submitted February 13, 2025 at 10:21AM by Fabulous_Bluebird931
via reddit https://ift.tt/fMtaZTy
Verdaily
55 Security Flaws Detected by Microsoft: 2 were Exploited by Hackers
Microsoft has patched 55 Windows security flaws in its latest security update, including four zero-day vulnerabilities—two of which were actively exploited by hackers in cyberattacks.
Curious case of AD CS ESC15 vulnerable instance and its manual exploitation
https://ift.tt/adFyxDP
Submitted February 13, 2025 at 07:53PM by 1046ica
via reddit https://ift.tt/pyH6O0g
https://ift.tt/adFyxDP
Submitted February 13, 2025 at 07:53PM by 1046ica
via reddit https://ift.tt/pyH6O0g
www.mannulinux.org
Curious case of AD CS ESC15 vulnerable instance and its manual exploitation
Learn Basic Concepts of Linux. Best site to learn Linux from beginner to Advanced.
Consider joining the OSTIF meetup about Nym's recent audit ennoscriptd "Unmasking Cryptographic Risks: A Deep Dive into the Nym Audit” w/ Nadim Kobeissi
https://lu.ma/o2dasp0m
Submitted February 14, 2025 at 04:26PM by carrotcypher
via reddit https://ift.tt/vIZGyDa
https://lu.ma/o2dasp0m
Submitted February 14, 2025 at 04:26PM by carrotcypher
via reddit https://ift.tt/vIZGyDa
lu.ma
Unmasking Cryptographic Risks: A Deep Dive into the Nym Audit w/ Nadim Kobeissi · Zoom · Luma
Join us for a presentation and meetup with Nadim Kobeissi, Senior Applied Cryptography Auditor of Cure53.
Denoscription
Privacy networks and cryptographic…
Denoscription
Privacy networks and cryptographic…
Writing a Ghidra Processor module for iRISC
https://ift.tt/6IptJ1f
Submitted February 14, 2025 at 11:15PM by jonasrudloff
via reddit https://ift.tt/7EmcIFG
https://ift.tt/6IptJ1f
Submitted February 14, 2025 at 11:15PM by jonasrudloff
via reddit https://ift.tt/7EmcIFG
Applied for an OSINT Job—Turns Out It Never Existed
https://ift.tt/rcWEzoR
Submitted February 15, 2025 at 02:12AM by CLKnDGGR
via reddit https://ift.tt/2eFT71O
https://ift.tt/rcWEzoR
Submitted February 15, 2025 at 02:12AM by CLKnDGGR
via reddit https://ift.tt/2eFT71O
Hetheringtongroup
The Hetherington Group - Expert OSINT Investigations
Expert OSINT investigations and training to keep people, businesses, and assets safe from online threats.
PyCript WebSocket - Burp Suite extension for bypassing client-side encryption in Web Socket Messages
https://ift.tt/OUJ9n4i
Submitted February 15, 2025 at 03:38AM by Ano_F
via reddit https://ift.tt/uVF9Oxq
https://ift.tt/OUJ9n4i
Submitted February 15, 2025 at 03:38AM by Ano_F
via reddit https://ift.tt/uVF9Oxq
GitHub
GitHub - Anof-cyber/PyCript-WebSocket: Burp Suite extension for bypassing client-side encryption for pentesting and bug bounty…
Burp Suite extension for bypassing client-side encryption for pentesting and bug bounty in WebSocket - Anof-cyber/PyCript-WebSocket
CTF Online on 20th Feb
https://ift.tt/1A9w8CL
Submitted February 16, 2025 at 06:55PM by ProfessorFyodor
via reddit https://ift.tt/q4SYif7
https://ift.tt/1A9w8CL
Submitted February 16, 2025 at 06:55PM by ProfessorFyodor
via reddit https://ift.tt/q4SYif7
How to approach network protocol fuzzing
https://ift.tt/moB6I0E
Submitted February 16, 2025 at 11:38PM by Standard_Ad8210
via reddit https://ift.tt/BHS4o2s
https://ift.tt/moB6I0E
Submitted February 16, 2025 at 11:38PM by Standard_Ad8210
via reddit https://ift.tt/BHS4o2s
Announcing the Incident response program pack 1.5
https://ift.tt/D1rGQnh
Submitted February 17, 2025 at 08:15AM by SecTemplates
via reddit https://ift.tt/du7JCc9
https://ift.tt/D1rGQnh
Submitted February 17, 2025 at 08:15AM by SecTemplates
via reddit https://ift.tt/du7JCc9
SecTemplates.com
Announcing the Incident Response Program Pack v1.5
This release is to provide you with everything you need to establish a functioning security incident response program at your company. In this pack, we cover Definitions: This document introduces sample terminology and roles during an incident, the various…
Interactive demo of an SSH honeypot using AI (open-source)
https://ift.tt/mfw72aL
Submitted February 17, 2025 at 10:02PM by MoCyberB3
via reddit https://ift.tt/BA5enHC
https://ift.tt/mfw72aL
Submitted February 17, 2025 at 10:02PM by MoCyberB3
via reddit https://ift.tt/BA5enHC
Trapster
Démo interactive d'un honeypot utilisant l'IA - Trapster
Découvrez notre démo interactive avec intelligence artificielle appliquée à un honeypot SSH.