Research: Using Stylometry & Topic Modeling to Attribute State-Sponsored Hacktivist Groups
https://ift.tt/g8YXkfT
Submitted February 27, 2025 at 07:40PM by Megabeets
via reddit https://ift.tt/32FYXE0
https://ift.tt/g8YXkfT
Submitted February 27, 2025 at 07:40PM by Megabeets
via reddit https://ift.tt/32FYXE0
Check Point Research
Modern Approach to Attributing Hacktivist Groups - Check Point Research
Research by: Itay Cohen (@megabeets_) Over the past few decades, hacktivism has been, in a lot of cases, characterized by minor website defacements and distributed denial-of-service (DDoS) attacks, which, while making headlines, had minimal lasting impact.…
How to Find More IDORs - @verylazytech
https://ift.tt/gYdr4Je
Submitted February 27, 2025 at 10:07PM by Justin_coco
via reddit https://ift.tt/4tEa5Ii
https://ift.tt/gYdr4Je
Submitted February 27, 2025 at 10:07PM by Justin_coco
via reddit https://ift.tt/4tEa5Ii
Verylazytech
IDOR | VeryLazyTech
Learn to uncover more IDORs the lazy way with VeryLazyTech—tips, tricks, and hacks revealed!
Join us in 2 weeks on March 12th at 13:00 GMT-5 for a meetup teamup: Liz Steininger from Least Authority and Pacu from Zcash Community Grants! The two will be presenting "Enhancing Zcash Security: a long-term engagement with Least Authority, the Zcash Ecosystem Security Lead".
https://lu.ma/uxmc2wgl
Submitted February 27, 2025 at 09:54PM by carrotcypher
via reddit https://ift.tt/1Lr3zaC
https://lu.ma/uxmc2wgl
Submitted February 27, 2025 at 09:54PM by carrotcypher
via reddit https://ift.tt/1Lr3zaC
lu.ma
Enhancing Zcash Security w/ Least Authority and Zcash · Zoom · Luma
Denoscription
Join us for a deep dive into the ongoing security audits of Zcash, completed by the Zcash Ecosystem Security Lead Least Authority, and funded by…
Join us for a deep dive into the ongoing security audits of Zcash, completed by the Zcash Ecosystem Security Lead Least Authority, and funded by…
Github scam investigation: Thousands of "mods" and "cracks" stealing your data
https://ift.tt/FoAbOp9
Submitted February 28, 2025 at 03:39AM by WesternBest
via reddit https://ift.tt/ihceDHw
https://ift.tt/FoAbOp9
Submitted February 28, 2025 at 03:39AM by WesternBest
via reddit https://ift.tt/ihceDHw
tim.sh
Github scam investigation: Thousands of "mods" and "cracks" stealing your data
How I found 1000+ malicious repositories spread on Github
Bypass AMSI in 2025
https://ift.tt/dMx63nV
Submitted February 28, 2025 at 07:15PM by S3cur3Th1sSh1t
via reddit https://ift.tt/4tL5FWS
https://ift.tt/dMx63nV
Submitted February 28, 2025 at 07:15PM by S3cur3Th1sSh1t
via reddit https://ift.tt/4tL5FWS
www.r-tec.net
r-tec Blog | Bypass AMSI in 2025
This blog post will shed some light on what's behind AMSI (roughly, but hopefully easy to understand) and how you can still effectively bypass it - more than four years later.
Bybit $1.5b hack was a Safe Wallet web app JS payload injection
https://ift.tt/Bklboh7
Submitted March 01, 2025 at 05:48PM by pzduniak
via reddit https://ift.tt/MESOdH1
https://ift.tt/Bklboh7
Submitted March 01, 2025 at 05:48PM by pzduniak
via reddit https://ift.tt/MESOdH1
DocSend
Bybit Hack Report
Former Disney employee files wrongful termination complaint after compromise
https://ift.tt/BgKAIYs
Submitted March 01, 2025 at 06:31PM by damontoo
via reddit https://ift.tt/13kxpQL
https://ift.tt/BgKAIYs
Submitted March 01, 2025 at 06:31PM by damontoo
via reddit https://ift.tt/13kxpQL
CBS News
Former Disney employee files wrongful termination complaint after cyber attack
Matthew Van Andel filed a wrongful termination complaint against Disney after he unknowingly downloaded malware that compromised the company's cybersecurity.
Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China
https://ift.tt/TroV8cJ
Submitted March 02, 2025 at 06:35AM by campuscodi
via reddit https://ift.tt/gXLOQlS
https://ift.tt/TroV8cJ
Submitted March 02, 2025 at 06:35AM by campuscodi
via reddit https://ift.tt/gXLOQlS
GFW Report
Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China
We present Wallbleed, a buffer over-read vulnerability that existed in the DNS injection subsystem of the Great Firewall of China. Wallbleed caused certain nation-wide censorship middleboxes to reveal up to 125 bytes of their memory when censoring a crafted…
Substack Domain Takeover
https://ift.tt/2lLepmF
Submitted March 02, 2025 at 04:30PM by whisperingmime
via reddit https://ift.tt/MFjugit
https://ift.tt/2lLepmF
Submitted March 02, 2025 at 04:30PM by whisperingmime
via reddit https://ift.tt/MFjugit
Blog by Joren Vrancken
Substack Domain Takeover
Substack is a popular blogging platform. It allows writers to easily create their own personal blog, with payments, comments, analytics and other advanced features. Substack empowers writers to customize their blogs by adding a custom domain.
MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
https://ift.tt/jnaNwKQ
Submitted March 02, 2025 at 11:23PM by winhumone
via reddit https://ift.tt/t5gohX0
https://ift.tt/jnaNwKQ
Submitted March 02, 2025 at 11:23PM by winhumone
via reddit https://ift.tt/t5gohX0
seclists.org
Full Disclosure: Re: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
HUB Security Secures Continued Nasdaq Listing, Marking an Important Milestone
https://ift.tt/k9WP7Cq
Submitted March 03, 2025 at 01:33AM by winhumone
via reddit https://ift.tt/9wFYdZ4
https://ift.tt/k9WP7Cq
Submitted March 03, 2025 at 01:33AM by winhumone
via reddit https://ift.tt/9wFYdZ4
Understanding the AI Act and its compliance challenges
https://ift.tt/zThMKyv
Submitted March 03, 2025 at 03:54PM by sadyetfly11
via reddit https://ift.tt/bmiJGhD
https://ift.tt/zThMKyv
Submitted March 03, 2025 at 03:54PM by sadyetfly11
via reddit https://ift.tt/bmiJGhD
Help Net Security
Understanding the AI Act and its compliance challenges
David Dumont explains how organizations can leverage GDPR compliance to meet AI Act obligations on transparency and risk mitigation.
The Full Costs of a DIY Security Canary Program
https://ift.tt/Pz9425k
Submitted March 03, 2025 at 06:17PM by tracebit
via reddit https://ift.tt/1CTiJDW
https://ift.tt/Pz9425k
Submitted March 03, 2025 at 06:17PM by tracebit
via reddit https://ift.tt/1CTiJDW
Tracebit
The full costs of building your own Canary Program | Tracebit
We explore why there can be a bias to build canaries and what's actually involved for a successful security canary program.
I have an assignment to find two real websites that are vulnerable to local file inclusion. So far I couldn't find any. I used a lot of google dorks similiar to this `site:"*/file.php?file=index.php"`. Please help.
https://ift.tt/Ry6rtMW
Submitted March 03, 2025 at 09:14PM by WillJMoriartyPatriot
via reddit https://ift.tt/jgFpswf
https://ift.tt/Ry6rtMW
Submitted March 03, 2025 at 09:14PM by WillJMoriartyPatriot
via reddit https://ift.tt/jgFpswf
Massive security gaps discovered in building access systems
https://ift.tt/yX215x9
Submitted March 03, 2025 at 09:50PM by rimdig219
via reddit https://ift.tt/wsHyOP1
https://ift.tt/yX215x9
Submitted March 03, 2025 at 09:50PM by rimdig219
via reddit https://ift.tt/wsHyOP1
heise online
Massive security gaps discovered in building access systems
Cyber criminals can easily access building access systems worldwide. A study reveals the extent and causes.
Burp Variables: a Burp extension that lets you store and reuse variables in outgoing requests, similar to functionality in Postman/Insomnia/other API testing clients
https://ift.tt/kbrRG47
Submitted March 04, 2025 at 12:06AM by 0xceba
via reddit https://ift.tt/O81nXCf
https://ift.tt/kbrRG47
Submitted March 04, 2025 at 12:06AM by 0xceba
via reddit https://ift.tt/O81nXCf
portswigger.net
Burp Variables
Store and reuse variables in requests.
Hacking the Xbox 360 Hypervisor Part 2: The Bad Update Exploit
https://ift.tt/NL509y1
Submitted March 04, 2025 at 07:39AM by litheon
via reddit https://ift.tt/lERIuYO
https://ift.tt/NL509y1
Submitted March 04, 2025 at 07:39AM by litheon
via reddit https://ift.tt/lERIuYO
I Code 4 Coffee
Hacking the Xbox 360 Hypervisor Part 2: The Bad Update Exploit
Finding and exploiting bugs in the Xbox 360 hypervisor to create the "Bad Update" exploit.
Evading Detection with Payload Pipelines
https://ift.tt/whC9jSy
Submitted March 04, 2025 at 07:21AM by pracsec
via reddit https://ift.tt/ER6YQig
https://ift.tt/whC9jSy
Submitted March 04, 2025 at 07:21AM by pracsec
via reddit https://ift.tt/ER6YQig
Practical Security Analytics LLC
Bypassing AMSI and Evading AV Detection with SpecterInsight
Introduction A few weeks ago, there was a post on reddit asking for advice on how to get their AMSI bypass through Windows Defender without being detected. Recently, it has become much more difficu…
Client-Side Path Traversal - Penetesting guide | @VeryLazyTech
https://ift.tt/tQGUJkZ
Submitted March 04, 2025 at 01:21PM by Justin_coco
via reddit https://ift.tt/g2eriWn
https://ift.tt/tQGUJkZ
Submitted March 04, 2025 at 01:21PM by Justin_coco
via reddit https://ift.tt/g2eriWn
Verylazytech
Client-Side Path Traversal | VeryLazyTech
Docusnap Inventory Files Encrypted With Static Key
https://ift.tt/IC4atYk
Submitted March 04, 2025 at 02:15PM by RedTeamPentesting
via reddit https://ift.tt/F8q7Xty
https://ift.tt/IC4atYk
Submitted March 04, 2025 at 02:15PM by RedTeamPentesting
via reddit https://ift.tt/F8q7Xty
www.redteam-pentesting.de
RedTeam Pentesting - Docusnap Inventory Files Encrypted with Static Key
Inventory files created by Docusnap, containing information like installed programs, firewall rules and local administrators, are encrypted with a static key. The decryption key can be obtained easily from the .NET application, downloadable from the vendor’s…
Obfuscating API Patches to Bypass New Windows Defender Behavior Signatures
https://ift.tt/tQ7dhlV
Submitted March 04, 2025 at 04:43PM by sadyetfly11
via reddit https://ift.tt/SKfZ3zR
https://ift.tt/tQ7dhlV
Submitted March 04, 2025 at 04:43PM by sadyetfly11
via reddit https://ift.tt/SKfZ3zR
Practical Security Analytics LLC
Obfuscating API Patches to Bypass New Windows Defender Behavior Signatures
Introduction I’ve got a short post today based on some recent changes by Windows Defender. Over the weekend, I noticed that some of my unit tests began failing on code that had not been recen…