Cradle.sh Open Source Threat Intelligence Hub
https://cradle.sh
Submitted March 13, 2025 at 07:50PM by small_talk101
via reddit https://ift.tt/fSdoX2Y
https://cradle.sh
Submitted March 13, 2025 at 07:50PM by small_talk101
via reddit https://ift.tt/fSdoX2Y
cradle.sh
CRADLE Intelligence Hub
Latest version: v2.10.0 CRADLE Intelligence Hub Batteries included collaborative knowledge management solution for threat intelligence researchers.
Brushing Up on Hardware Hacking Part 2 - SPI, UART, Pulseview, and Flashrom
https://ift.tt/a5hK3ID
Submitted March 13, 2025 at 09:10PM by wrongbaud
via reddit https://ift.tt/CGjuRYX
https://ift.tt/a5hK3ID
Submitted March 13, 2025 at 09:10PM by wrongbaud
via reddit https://ift.tt/CGjuRYX
Voidstar Security Research Blog
Brushing Up on Hardware Hacking Part 2 - SPI, UART, Pulseview, and Flashrom
Hacking a Low-Cost Electric Toothbrush
Memory Corruption in Delphi
https://ift.tt/lGxNHmq
Submitted March 14, 2025 at 02:59AM by 907jessejones
via reddit https://ift.tt/RNos3nU
https://ift.tt/lGxNHmq
Submitted March 14, 2025 at 02:59AM by 907jessejones
via reddit https://ift.tt/RNos3nU
Include Security Research Blog
Memory Corruption in Delphi - Include Security Research Blog
In our team's latest blog post, we build a few examples that showcase ways in which memory corruption vulnerabilities could manifest in Delphi code despite being included in a list of "memory safe" languages within a paper published by the NSA. We cover how…
Decrypting Encrypted files from Akira Ransomware (Linux/ESXI variant 2024) using a bunch of GPUs
https://ift.tt/LydpqoV
Submitted March 14, 2025 at 06:57AM by yohanes
via reddit https://ift.tt/efmcUwW
https://ift.tt/LydpqoV
Submitted March 14, 2025 at 06:57AM by yohanes
via reddit https://ift.tt/efmcUwW
Tinyhack.com
Decrypting Encrypted files from Akira Ransomware (Linux/ESXI variant 2024) using a bunch of GPUs
I recently helped a company recover their data from the Akira ransomware without paying the ransom. I'm sharing how I did it, along with the full source code.
The code is here: https://github.com/yohanes/akira-bruteforce
To clarify, multiple ransomware…
The code is here: https://github.com/yohanes/akira-bruteforce
To clarify, multiple ransomware…
Android Kernel Adventures: Insights into Compilation, Customization and Application Analysis
https://ift.tt/05Hw6CY
Submitted March 17, 2025 at 06:08AM by thewatcher_
via reddit https://ift.tt/qEArGx3
https://ift.tt/05Hw6CY
Submitted March 17, 2025 at 06:08AM by thewatcher_
via reddit https://ift.tt/qEArGx3
Medium
Android Kernel Adventures: Insights into Compilation, Customization and Application Analysis
This article marks the first in a series aimed at sharing my adventures, personal notes, and insights into the Android kernel. My focus…
History of NULL Pointer Dereferences on macOS
https://ift.tt/PxSYkG9
Submitted March 17, 2025 at 01:21PM by bajk
via reddit https://ift.tt/jVqiAS6
https://ift.tt/PxSYkG9
Submitted March 17, 2025 at 01:21PM by bajk
via reddit https://ift.tt/jVqiAS6
AFINE - digitally secure
History of NULL Pointer Dereferences on macOS - AFINE - digitally secure
Technical analysis of NULL Pointer Dereference bugs, mitigations, and exploit development challenges on Apple Silicon macOS.
Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
https://ift.tt/IaPXg0i
Submitted March 17, 2025 at 01:54PM by Malwarebeasts
via reddit https://ift.tt/FSKn5BR
https://ift.tt/IaPXg0i
Submitted March 17, 2025 at 01:54PM by Malwarebeasts
via reddit https://ift.tt/FSKn5BR
InfoStealers
Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
Stay informed with the latest insights in our Infostealers weekly report. Explore key findings, trends and data on info-stealing activities.
CVE-2025-24016: Unsafe Deserialization Vulnerability in Wazuh Leading to Remote Code Execution
https://ift.tt/0ezhAMy
Submitted March 17, 2025 at 04:13PM by amitschenedel
via reddit https://ift.tt/Jg2A0r9
https://ift.tt/0ezhAMy
Submitted March 17, 2025 at 04:13PM by amitschenedel
via reddit https://ift.tt/Jg2A0r9
Daily CVE Reports
CVE-2025-24016: Unsafe Deserialization Vulnerability in Wazuh Leading to Remote Code Execution
Deep dive into CVE-2025-24016 a critical remote code execution (RCE) vulnerability affecting Wazuh, a widely used open-source SIEM platform.
[Tool] TruffleShow: A Client-Side Web Viewer for TruffleHog Outputs
https://ift.tt/lM38u9z
Submitted March 17, 2025 at 06:47PM by pelesenk
via reddit https://ift.tt/MGxbYWh
https://ift.tt/lM38u9z
Submitted March 17, 2025 at 06:47PM by pelesenk
via reddit https://ift.tt/MGxbYWh
Bypassing Authentication Like It’s The ‘90s - Pre-Auth RCE Chain(s) in Kentico Xperience CMS - watchTowr Labs
https://ift.tt/Ec0sBNC
Submitted March 17, 2025 at 05:55PM by dx7r__
via reddit https://ift.tt/4ujiMQw
https://ift.tt/Ec0sBNC
Submitted March 17, 2025 at 05:55PM by dx7r__
via reddit https://ift.tt/4ujiMQw
watchTowr Labs
Bypassing Authentication Like It’s The ‘90s - Pre-Auth RCE Chain(s) in Kentico Xperience CMS
I recently joined watchTowr, and it is, therefore, time - time for my first watchTowr Labs blogpost, previously teased in a tweet of a pre-auth RCE chain affecting some ‘unknown software’.
Joining the team, I wanted to maintain the trail of destruction left…
Joining the team, I wanted to maintain the trail of destruction left…
SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries
https://ift.tt/9VWJjKi
Submitted March 17, 2025 at 07:03PM by Smooth-Loquat-4954
via reddit https://ift.tt/L3cKYNP
https://ift.tt/9VWJjKi
Submitted March 17, 2025 at 07:03PM by Smooth-Loquat-4954
via reddit https://ift.tt/L3cKYNP
Workos
SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries — WorkOS
Any service using xml-crypto or a Node.js SAML implementation using it, should update immediately to the latest version. WorkOS customers are safe and were not impacted.
Is AI actually helping with burnout in security, or just adding to the chaos
https://ift.tt/sZ7A4u0
Submitted March 18, 2025 at 02:33AM by Low_Fly_5338
via reddit https://ift.tt/oa3sVjd
https://ift.tt/sZ7A4u0
Submitted March 18, 2025 at 02:33AM by Low_Fly_5338
via reddit https://ift.tt/oa3sVjd
SecurityInfoWatch
Can strategic AI deployment reduce cybersecurity burnout?
Company-wide visibility and advocacy along with a pragmatic approach will set up security teams for success.
Arbitrary File Write CVE-2024-0402 in GitLab (Exploit)
https://ift.tt/hdGlDBt
Submitted March 18, 2025 at 06:38PM by nibblesec
via reddit https://ift.tt/vl8KdCh
https://ift.tt/hdGlDBt
Submitted March 18, 2025 at 06:38PM by nibblesec
via reddit https://ift.tt/vl8KdCh
Doyensec
!exploitable Episode Three - Devfile Adventures
I know, we have written it multiple times now, but in case you are just tuning in, Doyensec had found themselves on a cruise ship touring the Mediterranean for our company retreat. To kill time between parties, we had some hacking sessions analyzing real…
Learn how an out-of-bounds write vulnerability in the Linux kernel can be exploited to achieve an LPE (CVE-2025-0927)
https://ift.tt/0QmFjfI
Submitted March 18, 2025 at 06:05PM by SSDisclosure
via reddit https://ift.tt/yhdHRsW
https://ift.tt/0QmFjfI
Submitted March 18, 2025 at 06:05PM by SSDisclosure
via reddit https://ift.tt/yhdHRsW
SSD Secure Disclosure
SSD Advisory - Linux kernel hfsplus slab-out-of-bounds Write - SSD Secure Disclosure
Summary This advisory describes an out-of-bounds write vulnerability in the Linux kernel that achieves local privilege escalation on Ubuntu 22.04 for active user sessions. Credit An independent security researcher working with SSD Secure Disclosure. Vendor…
CEF Debugger Enabled in Google Web Designer | Google Bug Hunters
https://ift.tt/01FPpLG
Submitted March 18, 2025 at 06:52PM by smaury
via reddit https://ift.tt/iZqhjQA
https://ift.tt/01FPpLG
Submitted March 18, 2025 at 06:52PM by smaury
via reddit https://ift.tt/iZqhjQA
Google
CEF Debugger Enabled in Google Web Designer | Google Bug Hunters
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
Local Privilege Escalation via Unquoted Search Path in Plantronics Hub
https://ift.tt/XNHqAmZ
Submitted March 18, 2025 at 08:10PM by k8pf
via reddit https://ift.tt/Pjlg96W
https://ift.tt/XNHqAmZ
Submitted March 18, 2025 at 08:10PM by k8pf
via reddit https://ift.tt/Pjlg96W
SAML roulette: the hacker always wins
https://ift.tt/TkYQZ7N
Submitted March 18, 2025 at 09:31PM by albinowax
via reddit https://ift.tt/f2OjQVF
https://ift.tt/TkYQZ7N
Submitted March 18, 2025 at 09:31PM by albinowax
via reddit https://ift.tt/f2OjQVF
PortSwigger Research
SAML roulette: the hacker always wins
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
Compromised tj-actions/changed-files GitHub Action: A look at publicly leaked secrets
https://ift.tt/JN1p2Ai
Submitted March 19, 2025 at 12:02AM by mabote
via reddit https://ift.tt/jOvF2m1
https://ift.tt/JN1p2Ai
Submitted March 19, 2025 at 12:02AM by mabote
via reddit https://ift.tt/jOvF2m1
GitGuardian Blog - Take Control of Your Secrets Security
Compromised tj-actions/changed-files GitHub Action: A look at publicly leaked secrets
On March 14, 2025, the popular GitHub action tj-actions/changed-files was compromised, exposing secrets in CI logs. GitGuardian's analysis identified leaked secrets like GitHub tokens, AWS keys, and more.
Linux supply chain attack journey : critical vulnerabilities on multiple distribution build & packaging systems
https://ift.tt/kNxRJAi
Submitted March 19, 2025 at 03:19PM by SzLam__
via reddit https://ift.tt/RDHlAvI
https://ift.tt/kNxRJAi
Submitted March 19, 2025 at 03:19PM by SzLam__
via reddit https://ift.tt/RDHlAvI
Fenrisk
Supply Chain Attacks on Linux distributions - Overview
Security experts
Introducing WEBCAT: Web-based Code Assurance and Transparency
https://ift.tt/BOVAnEM
Submitted March 19, 2025 at 10:37PM by smaury
via reddit https://ift.tt/bgovkUu
https://ift.tt/BOVAnEM
Submitted March 19, 2025 at 10:37PM by smaury
via reddit https://ift.tt/bgovkUu
SecureDrop
Introducing WEBCAT: Web-based Code Assurance and Transparency
In this post, we introduce Web-based Code Assurance and Transparency, a project that supports verifiable in-browser code for single-page browser applications. Along with this post, we are publishing the WEBCAT project repository; follow-up posts will provide…
13 inch Macbook
https://ift.tt/YgSoE8W
Submitted March 20, 2025 at 04:55AM by Cheap_Thing1322
via reddit https://ift.tt/uj93VWE
https://ift.tt/YgSoE8W
Submitted March 20, 2025 at 04:55AM by Cheap_Thing1322
via reddit https://ift.tt/uj93VWE
Apple
MacBook Air 13-inch and MacBook Air 15-inch
MacBook Air laptop with the superfast M4 chip. Built for Apple Intelligence. Lightweight, with all-day battery life. Now in a new Sky Blue color.