CVE-2023-38408 how to.
https://ift.tt/IQd8sjO
Submitted February 22, 2025 at 06:58AM by xphilopes
via reddit https://ift.tt/31CFRx6
https://ift.tt/IQd8sjO
Submitted February 22, 2025 at 06:58AM by xphilopes
via reddit https://ift.tt/31CFRx6
www.vicarius.io
Exploring OpenSSH's Agent Forwarding RCE (CVE-2023-38408) - vsociety
Three questions about Apple, encryption, and the U.K.
https://ift.tt/Kbnsj9M
Submitted February 24, 2025 at 01:31AM by feross
via reddit https://ift.tt/0GyrEh9
https://ift.tt/Kbnsj9M
Submitted February 24, 2025 at 01:31AM by feross
via reddit https://ift.tt/0GyrEh9
A Few Thoughts on Cryptographic Engineering
Three questions about Apple, encryption, and the U.K.
Two weeks ago, the Washington Post reported that the U.K. government had issued a secret order to Apple demanding that the company include a “backdoor” into the company’s end-to-e…
What's new in LKRG? Interview about the project
https://ift.tt/UITJ1pd
Submitted February 24, 2025 at 03:02AM by dzidku
via reddit https://ift.tt/wPg1kJ9
https://ift.tt/UITJ1pd
Submitted February 24, 2025 at 03:02AM by dzidku
via reddit https://ift.tt/wPg1kJ9
Over 35,000 Websites Targeted in Full-Page Hijack Linking to a Chinese-Language Gambling Scam
https://ift.tt/ISJpDOv
Submitted February 24, 2025 at 07:14PM by unknownhad
via reddit https://ift.tt/eoNBn51
https://ift.tt/ISJpDOv
Submitted February 24, 2025 at 07:14PM by unknownhad
via reddit https://ift.tt/eoNBn51
c/side
Over 35,000 Websites Targeted in Full-Page Hijack Linking to a Chinese-Language Gambling Scam
A new malware campaign has compromised 35,000+ websites, injecting a malicious noscript from the websites listed below. Once the noscript loads, it fully hijacks the user’s browser window—often redirecting them to pages promoting a Chinese-language gambling (or…
Exposing Shadow AI Agents: How We Extracted Financial Data from Billion-Dollar Companies
https://ift.tt/dKaXPkp
Submitted February 24, 2025 at 08:16PM by we-we-we
via reddit https://ift.tt/7aHVQq4
https://ift.tt/dKaXPkp
Submitted February 24, 2025 at 08:16PM by we-we-we
via reddit https://ift.tt/7aHVQq4
Medium
The Burn Notice, Part 1/5 — Revealing Shadow Copilots
How We Extracted Financial Data from a Multi-Billion-Dollar Company
Miku Miku Beam: DDoS in Style
https://ift.tt/oUZ7uEb
Submitted February 24, 2025 at 10:28PM by asynchronous-x
via reddit https://ift.tt/4FPvSML
https://ift.tt/oUZ7uEb
Submitted February 24, 2025 at 10:28PM by asynchronous-x
via reddit https://ift.tt/4FPvSML
💯 - Miku Miku Beam: DDoS in Style
Because DDoS attacks are kawaii and even more so when Miku does them.
I have developed a Free Browser Extension Scanner and Code Fetch/Audit using AI https://crxplorer.com
https://crxplorer.com
Submitted February 24, 2025 at 11:58PM by kinso1338
via reddit https://ift.tt/brdPI4p
https://crxplorer.com
Submitted February 24, 2025 at 11:58PM by kinso1338
via reddit https://ift.tt/brdPI4p
Reddit
From the netsec community on Reddit: I have developed a Free Browser Extension Scanner and Code Fetch/Audit using AI https://crxplorer.com
Posted by kinso1338 - 0 votes and 6 comments
Methods of defeating potting compound on electronics
https://ift.tt/5Re62mC
Submitted February 25, 2025 at 12:27AM by gsuberland
via reddit https://ift.tt/5oJKPSR
https://ift.tt/5Re62mC
Submitted February 25, 2025 at 12:27AM by gsuberland
via reddit https://ift.tt/5oJKPSR
blog.poly.nomial.co.uk
Methods of defeating potting compound on electronics - Graham Sutherland's Blog
Cybercrooks Are Using Fake Job Listings to Steal Crypto | HackerNoon
https://ift.tt/gjZUv7n
Submitted February 24, 2025 at 02:41AM by Individual-Gas5276
via reddit https://ift.tt/mNoGdRp
https://ift.tt/gjZUv7n
Submitted February 24, 2025 at 02:41AM by Individual-Gas5276
via reddit https://ift.tt/mNoGdRp
Hackernoon
Cybercrooks Are Using Fake Job Listings to Steal Crypto
Moonlock Lab dives deep into a campaign tricking blockchain developers with fake job interviews to deploy malware that installs a backdoor and targets MetaMask.
Streamlining vulnerability research with IDA Pro and Rust
https://ift.tt/hVS3RBN
Submitted February 25, 2025 at 11:57AM by 0xdea
via reddit https://ift.tt/45xsCMR
https://ift.tt/hVS3RBN
Submitted February 25, 2025 at 11:57AM by 0xdea
via reddit https://ift.tt/45xsCMR
HN Security
Streamlining vulnerability research with IDA Pro and Rust - HN Security
“Rebels on the rise, we have sacrificed Been knocked down like a poltergeist Nocturnal by blood, in darkness we stand […]
Caller ID Spoofing: The Invisible Threat to Phone Security and How to Combat It
https://ift.tt/oQCU8Hl
Submitted February 25, 2025 at 01:13PM by s3yfullah
via reddit https://ift.tt/fdZ5Y8C
https://ift.tt/oQCU8Hl
Submitted February 25, 2025 at 01:13PM by s3yfullah
via reddit https://ift.tt/fdZ5Y8C
SwordSec
Caller ID Spoofing
Abusing VBS Enclaves to Create Evasive Malware
https://ift.tt/Zx9W2kQ
Submitted February 25, 2025 at 09:31PM by Narrow_Rooster_630
via reddit https://ift.tt/dPzIOBl
https://ift.tt/Zx9W2kQ
Submitted February 25, 2025 at 09:31PM by Narrow_Rooster_630
via reddit https://ift.tt/dPzIOBl
Akamai
Abusing VBS Enclaves to Create Evasive Malware | Akamai
Learn how attackers can abuse VBS enclaves, a Windows security feature, for malicious purposes.
Mixing up Public and Private Keys in OpenID Connect deployments
https://ift.tt/MtbQg9A
Submitted February 26, 2025 at 12:02AM by hannob
via reddit https://ift.tt/gHKcnBF
https://ift.tt/MtbQg9A
Submitted February 26, 2025 at 12:02AM by hannob
via reddit https://ift.tt/gHKcnBF
A Random and Simple Tip: Advanced Analysis of JNI Methods Using Frida
https://ift.tt/3twxUlu
Submitted February 25, 2025 at 10:20PM by thewatcher_
via reddit https://ift.tt/95RiE20
https://ift.tt/3twxUlu
Submitted February 25, 2025 at 10:20PM by thewatcher_
via reddit https://ift.tt/95RiE20
Medium
A Random and Simple Tip: Advanced Analysis of JNI Methods Using Frida
In this article, I will share a tip for those interested in performing a more detailed analysis of the behavior of native methods, with a…
The Best Security Is When We All Agree To Keep Everything Secret (Except The Secrets) - NAKIVO Backup & Replication (CVE-2024-48248) - watchTowr Labs
https://ift.tt/LXQgVs4
Submitted February 26, 2025 at 04:31PM by dx7r__
via reddit https://ift.tt/1icquOg
https://ift.tt/LXQgVs4
Submitted February 26, 2025 at 04:31PM by dx7r__
via reddit https://ift.tt/1icquOg
watchTowr Labs
The Best Security Is When We All Agree To Keep Everything Secret (Except The Secrets) - NAKIVO Backup & Replication (CVE-2024-48248)
As an industry, we believe that we’ve come to a common consensus after 25 years of circular debates - disclosure is terrible, information is actually dangerous, it’s best that it’s not shared, and the only way to really to ensure that no one ever uses information…
Kubernetes Golden Tickets
https://ift.tt/wB8ilbt
Submitted February 26, 2025 at 06:40PM by therealjoetesta
via reddit https://ift.tt/vSe73H6
https://ift.tt/wB8ilbt
Submitted February 26, 2025 at 06:40PM by therealjoetesta
via reddit https://ift.tt/vSe73H6
How Mercury defeats phishing with device verification
https://ift.tt/g0sFd5x
Submitted February 26, 2025 at 11:24PM by MaxGabriel
via reddit https://ift.tt/sdOkMjf
https://ift.tt/g0sFd5x
Submitted February 26, 2025 at 11:24PM by MaxGabriel
via reddit https://ift.tt/sdOkMjf
Mercury
How Mercury defeats phishing with device verification | Mercury
How Mercury defeated a phishing attack with device verification
An inside look at Equation/APT-C-40 TTPs from China’s lense
https://ift.tt/ENl3RFg
Submitted February 26, 2025 at 04:23PM by dukeofmola
via reddit https://ift.tt/2XOYj9e
https://ift.tt/ENl3RFg
Submitted February 26, 2025 at 04:23PM by dukeofmola
via reddit https://ift.tt/2XOYj9e
Inversecos
An inside look at NSA (Equation Group) TTPs from China’s lense
16 Malicious Chrome extensions infected over 3.2 mln users worldwide.
https://ift.tt/EvKZ8Do
Submitted February 27, 2025 at 03:54PM by Incogni_hi
via reddit https://ift.tt/7A2MCcL
https://ift.tt/EvKZ8Do
Submitted February 27, 2025 at 03:54PM by Incogni_hi
via reddit https://ift.tt/7A2MCcL
Research: Using Stylometry & Topic Modeling to Attribute State-Sponsored Hacktivist Groups
https://ift.tt/g8YXkfT
Submitted February 27, 2025 at 07:40PM by Megabeets
via reddit https://ift.tt/32FYXE0
https://ift.tt/g8YXkfT
Submitted February 27, 2025 at 07:40PM by Megabeets
via reddit https://ift.tt/32FYXE0
Check Point Research
Modern Approach to Attributing Hacktivist Groups - Check Point Research
Research by: Itay Cohen (@megabeets_) Over the past few decades, hacktivism has been, in a lot of cases, characterized by minor website defacements and distributed denial-of-service (DDoS) attacks, which, while making headlines, had minimal lasting impact.…
How to Find More IDORs - @verylazytech
https://ift.tt/gYdr4Je
Submitted February 27, 2025 at 10:07PM by Justin_coco
via reddit https://ift.tt/4tEa5Ii
https://ift.tt/gYdr4Je
Submitted February 27, 2025 at 10:07PM by Justin_coco
via reddit https://ift.tt/4tEa5Ii
Verylazytech
IDOR | VeryLazyTech
Learn to uncover more IDORs the lazy way with VeryLazyTech—tips, tricks, and hacks revealed!