Why a push for encryption backdoors is a global security risk
https://ift.tt/CKGbr9v
Submitted March 04, 2025 at 04:31PM by slypieok
via reddit https://ift.tt/HR7cJxM
https://ift.tt/CKGbr9v
Submitted March 04, 2025 at 04:31PM by slypieok
via reddit https://ift.tt/HR7cJxM
Help Net Security
Why a push for encryption backdoors is a global security risk
Governments in the UK, US, and Europe press tech firms to weaken encryption, risking privacy and exposing sensitive data to cyber threats.
We Deliberately Exposed AWS Keys on Developer Forums: Attackers Exploited One in 10 Hours
https://ift.tt/rVqv4DA
Submitted March 04, 2025 at 05:17PM by sadyetfly11
via reddit https://ift.tt/JkdiRoX
https://ift.tt/rVqv4DA
Submitted March 04, 2025 at 05:17PM by sadyetfly11
via reddit https://ift.tt/JkdiRoX
Clutch Security
Shattering the Rotation Illusion: Part 4 - Developer Forums
Explore Clutch Security’s research on leaked AWS Access Keys in developer forums like Stack Overflow and Quora, revealing critical security…
Hybrid Analysis Deep Dive Into Allegedly AI-Generated FunkSec Ransomware
https://ift.tt/s6c3SNt
Submitted March 04, 2025 at 07:37PM by CyberMasterV
via reddit https://ift.tt/i5wkhW0
https://ift.tt/s6c3SNt
Submitted March 04, 2025 at 07:37PM by CyberMasterV
via reddit https://ift.tt/i5wkhW0
Blogspot
Hybrid Analysis Deep Dive Into Allegedly AI-Generated FunkSec Ransomware
Author(s): Vlad Pasca New Rust-based ransomware FunkSec emerges with claimed AI capabilities , potentially indicating an advanced developmen...
Community powered, shift-left, security framework
https://ift.tt/lh5WFe2
Submitted March 04, 2025 at 10:28PM by Inevitable_Explorer6
via reddit https://ift.tt/wpRKJWB
https://ift.tt/lh5WFe2
Submitted March 04, 2025 at 10:28PM by Inevitable_Explorer6
via reddit https://ift.tt/wpRKJWB
Open Source Shift Left Framework
Get Users - Open Source Shift Left Framework
Techlore video review of BusKill (Open-Source Dead Man Switch) 🔒
https://ift.tt/3sStIij
Submitted March 04, 2025 at 11:24PM by maltfield
via reddit https://ift.tt/RY5dCqU
https://ift.tt/3sStIij
Submitted March 04, 2025 at 11:24PM by maltfield
via reddit https://ift.tt/RY5dCqU
BusKill
Techlore Review - BusKill
Techlore's Video review of the BusKill Laptop Kill Cord -- a Dead Man Switch to protect the privacy of your data from thieves
!exploitable Episode Two - Enter the Matrix. SSHD exploit used by Trinity in the movie The Matrix Reloaded
https://ift.tt/vHZV1CP
Submitted March 04, 2025 at 11:57PM by nibblesec
via reddit https://ift.tt/9iRfLhF
https://ift.tt/vHZV1CP
Submitted March 04, 2025 at 11:57PM by nibblesec
via reddit https://ift.tt/9iRfLhF
Doyensec
!exploitable Episode Two - Enter the Matrix
In case you are just tuning in, Doyensec has found themselves on a cruse ship touring the Mediterranean. Unwinding, hanging out with colleagues and having some fun. Part 1 covered our journey into IoT ARM exploitation, while our next blog post, coming in…
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails
https://ift.tt/cmYBPAo
Submitted March 05, 2025 at 07:01AM by _PentesterLab_
via reddit https://ift.tt/1PCAa7y
https://ift.tt/cmYBPAo
Submitted March 05, 2025 at 07:01AM by _PentesterLab_
via reddit https://ift.tt/1PCAa7y
Elttam
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails - elttam
elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.
Case Study: Traditional CVSS scoring missed this actively exploited vulnerability (CVE-2024-50302)
https://ift.tt/nxUOZBk
Submitted March 05, 2025 at 09:01AM by skimfl925
via reddit https://ift.tt/25XHNbd
https://ift.tt/nxUOZBk
Submitted March 05, 2025 at 09:01AM by skimfl925
via reddit https://ift.tt/25XHNbd
EvilLoader: Yesterday was published PoC for unpatched Vulnerability affecting Telegram for Android
https://ift.tt/50fsDaA
Submitted March 05, 2025 at 01:22PM by barakadua131
via reddit https://ift.tt/PNWTg9O
https://ift.tt/50fsDaA
Submitted March 05, 2025 at 01:22PM by barakadua131
via reddit https://ift.tt/PNWTg9O
Mobile Hacker
EvilLoader: Unpatched Telegram for Android Vulnerability Disclosed
A newly disclosed in Telegram for Android, dubbed EvilLoader, allows attackers to disguise malicious APKs as video files, potentially leading to unauthorized malware installations on users' devices.
Case study - Getting access to the internal network through a physical pentest
https://ift.tt/umI2ZPo
Submitted March 05, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/IarwY1L
https://ift.tt/umI2ZPo
Submitted March 05, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/IarwY1L
Hackmosphere
Pentest physique en magasin : retour d’expérience sur un cas réel - Hackmosphere
Un pentest physique mené dans un magasin d’ameublement a permis de mettre au jour plusieurs failles de sécurité importantes.
Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue
https://ift.tt/bJZPqy8
Submitted March 05, 2025 at 06:34PM by bajk
via reddit https://ift.tt/X35NyWk
https://ift.tt/bJZPqy8
Submitted March 05, 2025 at 06:34PM by bajk
via reddit https://ift.tt/X35NyWk
AFINE - digitally secure
Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue - AFINE - digitally secure
The discovery of a DoS in the macOS NS_01 driver within Apple’s IONVMeFamily, offering insights into integer overflow detection, and crash analysis.
Understanding and Mitigating TOCTOU Vulnerabilities in C# Applications
https://ift.tt/spPqRfV
Submitted March 05, 2025 at 06:33PM by bajk
via reddit https://ift.tt/WJZ6HjR
https://ift.tt/spPqRfV
Submitted March 05, 2025 at 06:33PM by bajk
via reddit https://ift.tt/WJZ6HjR
AFINE - digitally secure
Understanding and Mitigating TOCTOU Vulnerabilities in C# Applications - AFINE - digitally secure
In this article, we explore TOCTOU vulnerabilities, subtle yet dangerous race conditions that occur when security checks and resource usage are not tightly coupled. In C# development on Windows, where file operations and dynamic code loading are common, understanding…
Multiple backdoors injected using frontend JS
https://ift.tt/kAOsbaC
Submitted March 05, 2025 at 08:35PM by unknownhad
via reddit https://ift.tt/2X1tPpz
https://ift.tt/kAOsbaC
Submitted March 05, 2025 at 08:35PM by unknownhad
via reddit https://ift.tt/2X1tPpz
cside
Thousands of websites hit by four backdoors in 3rd party JavaScript attack
While analyzing threats targeting WordPress frameworks, we found an attack where a single 3rd party JavaScript file was used to inject four separate backdoors into 1,000 compromised websites using cdn.csyndication[.]com/.
Security ROI Explained: “Why Investing in Penetration Testing Saves Your Business” - Laburity
https://ift.tt/XfvLONa
Submitted March 06, 2025 at 12:58PM by Ancient_Title_1860
via reddit https://ift.tt/jYMIyFv
https://ift.tt/XfvLONa
Submitted March 06, 2025 at 12:58PM by Ancient_Title_1860
via reddit https://ift.tt/jYMIyFv
Laburity - Cyber Security Services
Cybersecurity ROI Explained: “Why Investing in Penetration Testing Saves Your Business” - Laburity
Introduction: Cybersecurity has to be a major concern for businesses in light of the growing cyber threats and increased regulatory pressure. A single breach can cost a business dearly, financially, and reputation-wise. Investing in the operation of security…
Zen and the Art of Microcode Hacking
https://ift.tt/FNcmtVu
Submitted March 06, 2025 at 02:04PM by AlmondOffSec
via reddit https://ift.tt/yplg4Th
https://ift.tt/FNcmtVu
Submitted March 06, 2025 at 02:04PM by AlmondOffSec
via reddit https://ift.tt/yplg4Th
Google
Blog: Zen and the Art of Microcode Hacking
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
Sleeping Beauty Vulnerability: Bypassing CrowdStrike Falcon With One Simple Trick
https://ift.tt/JBNk9z8
Submitted March 06, 2025 at 03:25PM by Longjumping-Top2717
via reddit https://ift.tt/UcAWJTo
https://ift.tt/JBNk9z8
Submitted March 06, 2025 at 03:25PM by Longjumping-Top2717
via reddit https://ift.tt/UcAWJTo
SEC Consult
Sleeping Beauty: Taming CrowdStrike Falcon With One Simple Trick
Sitecore: Unsafe Deserialisation Again! (CVE-2025-27218)
https://ift.tt/y69GPvo
Submitted March 06, 2025 at 02:40PM by Mempodipper
via reddit https://ift.tt/rFHi8jC
https://ift.tt/y69GPvo
Submitted March 06, 2025 at 02:40PM by Mempodipper
via reddit https://ift.tt/rFHi8jC
Searchlight Cyber
Sitecore: Unsafe Deserialisation Again! (CVE-2025-27218) › Searchlight Cyber
Assetnote, now a searchlight cyber company, has uncovered a zero day REMOTE COMMAND EXECUTION VULNERABILITY in SITECORE EXPERIENCE PLATFORM new Sitecore vulnerabilities discovered
The Burn Notice, Part 2/5 | How We Uncovered a Critical Vulnerability in a Leading AI Agent Framework
https://ift.tt/NgwRfeu
Submitted March 06, 2025 at 08:16PM by we-we-we
via reddit https://ift.tt/Ba2xNdO
https://ift.tt/NgwRfeu
Submitted March 06, 2025 at 08:16PM by we-we-we
via reddit https://ift.tt/Ba2xNdO
Medium
The Burn Notice, Part 2/5 | AI Agents: When Everything Becomes an Attack Surface
We Manipulated an HR Agent to Betray Its Own Organization and Discovered a Critical Vulnerability in The Process (CVE-2025–26319)
Command Injection - Compressive Guide & Payloads | VeryLazyTech
https://ift.tt/EoQt7BC
Submitted March 06, 2025 at 09:20PM by Justin_coco
via reddit https://ift.tt/HbGqpCA
https://ift.tt/EoQt7BC
Submitted March 06, 2025 at 09:20PM by Justin_coco
via reddit https://ift.tt/HbGqpCA
Verylazytech
Command Injection | VeryLazyTech
Crxplorer.com is a great free tool for blue team to check overly permissive browser extensions
http://Crxplorer.com
Submitted March 07, 2025 at 06:01PM by kinso1338
via reddit https://ift.tt/pRbVe7l
http://Crxplorer.com
Submitted March 07, 2025 at 06:01PM by kinso1338
via reddit https://ift.tt/pRbVe7l
CRXPlorer
CRXPlorer - Analyze Chrome Extensions for Security & Performance
Scan and analyze Chrome extensions for security vulnerabilities, performance issues, and compliance. Get detailed reports and insights.
Reversing Samsung's H-Arx Hypervisor Framework (Part 1)
https://ift.tt/uJZvFA5
Submitted March 08, 2025 at 06:10PM by PM_ME_YOUR_SHELLCODE
via reddit https://ift.tt/Oyv93X8
https://ift.tt/uJZvFA5
Submitted March 08, 2025 at 06:10PM by PM_ME_YOUR_SHELLCODE
via reddit https://ift.tt/Oyv93X8
dayzerosec
Reversing Samsung's H-Arx Hypervisor Framework - Part 1
In many ways, mobile devices lead the security industry when it comes to defense-in-depth and mitigation. Over the years, it has been proven time and again that the kernel cannot be trusted to be secure. As such, there has been effort put into moving secrets…