Compromised tj-actions/changed-files GitHub Action: A look at publicly leaked secrets
https://ift.tt/JN1p2Ai
Submitted March 19, 2025 at 12:02AM by mabote
via reddit https://ift.tt/jOvF2m1
https://ift.tt/JN1p2Ai
Submitted March 19, 2025 at 12:02AM by mabote
via reddit https://ift.tt/jOvF2m1
GitGuardian Blog - Take Control of Your Secrets Security
Compromised tj-actions/changed-files GitHub Action: A look at publicly leaked secrets
On March 14, 2025, the popular GitHub action tj-actions/changed-files was compromised, exposing secrets in CI logs. GitGuardian's analysis identified leaked secrets like GitHub tokens, AWS keys, and more.
Linux supply chain attack journey : critical vulnerabilities on multiple distribution build & packaging systems
https://ift.tt/kNxRJAi
Submitted March 19, 2025 at 03:19PM by SzLam__
via reddit https://ift.tt/RDHlAvI
https://ift.tt/kNxRJAi
Submitted March 19, 2025 at 03:19PM by SzLam__
via reddit https://ift.tt/RDHlAvI
Fenrisk
Supply Chain Attacks on Linux distributions - Overview
Security experts
Introducing WEBCAT: Web-based Code Assurance and Transparency
https://ift.tt/BOVAnEM
Submitted March 19, 2025 at 10:37PM by smaury
via reddit https://ift.tt/bgovkUu
https://ift.tt/BOVAnEM
Submitted March 19, 2025 at 10:37PM by smaury
via reddit https://ift.tt/bgovkUu
SecureDrop
Introducing WEBCAT: Web-based Code Assurance and Transparency
In this post, we introduce Web-based Code Assurance and Transparency, a project that supports verifiable in-browser code for single-page browser applications. Along with this post, we are publishing the WEBCAT project repository; follow-up posts will provide…
13 inch Macbook
https://ift.tt/YgSoE8W
Submitted March 20, 2025 at 04:55AM by Cheap_Thing1322
via reddit https://ift.tt/uj93VWE
https://ift.tt/YgSoE8W
Submitted March 20, 2025 at 04:55AM by Cheap_Thing1322
via reddit https://ift.tt/uj93VWE
Apple
MacBook Air 13-inch and MacBook Air 15-inch
MacBook Air laptop with the superfast M4 chip. Built for Apple Intelligence. Lightweight, with all-day battery life. Now in a new Sky Blue color.
By Executive Order, We Are Banning Blacklists - Domain-Level RCE in Veeam Backup & Replication (CVE-2025-23120) - watchTowr Labs
https://ift.tt/WGgYNPA
Submitted March 20, 2025 at 08:24AM by dx7r__
via reddit https://ift.tt/ORnSzg1
https://ift.tt/WGgYNPA
Submitted March 20, 2025 at 08:24AM by dx7r__
via reddit https://ift.tt/ORnSzg1
watchTowr Labs
By Executive Order, We Are Banning Blacklists - Domain-Level RCE in Veeam Backup & Replication (CVE-2025-23120)
It’s us again!
Once again, we hear the collective groans - but we're back and with yet another merciless pwnage of an inspired and clearly comprehensive RCE solution - no, wait, it's another vuln in yet another backup and replication solution..
While we…
Once again, we hear the collective groans - but we're back and with yet another merciless pwnage of an inspired and clearly comprehensive RCE solution - no, wait, it's another vuln in yet another backup and replication solution..
While we…
Orphaned DNS Records & Dangling IPs Still a problem in 2025
https://ift.tt/F8qaPIi
Submitted March 20, 2025 at 06:57PM by Seaerkin2
via reddit https://ift.tt/e3ohMFJ
https://ift.tt/F8qaPIi
Submitted March 20, 2025 at 06:57PM by Seaerkin2
via reddit https://ift.tt/e3ohMFJ
Guardyourdomain
DomainGuard | Threat Visibility Platform
We guard your domain, so you have peace of mind. Threat Visibility Platform.
Shield Your Devices, Secure Your Business: Master Windows Endpoint Security
https://ift.tt/6vzgGLJ
Submitted March 20, 2025 at 06:55PM by Signal_Car_5756
via reddit https://ift.tt/VCjQ6H4
https://ift.tt/6vzgGLJ
Submitted March 20, 2025 at 06:55PM by Signal_Car_5756
via reddit https://ift.tt/VCjQ6H4
Scalefusion
Windows Endpoint Security
Strengthen Windows endpoint security with the all-in-one powerful Scalefusion UEM. Unlock unmatched security with zero trust architecture.
The National Security Case for Email Plus Addressing
https://ift.tt/hQFI8Mg
Submitted March 20, 2025 at 08:22PM by kedmi
via reddit https://ift.tt/Sm7z2tC
https://ift.tt/hQFI8Mg
Submitted March 20, 2025 at 08:22PM by kedmi
via reddit https://ift.tt/Sm7z2tC
Sagi Kedmi
The National Security Case for Email Plus Addressing
How OSINT Exploits Password Recovery Flows to Expose Your Digital Identity
What not to do with on prem virtualization
https://ift.tt/9KEsZm8
Submitted March 21, 2025 at 06:10PM by _kawhl
via reddit https://ift.tt/hmAnjFk
https://ift.tt/9KEsZm8
Submitted March 21, 2025 at 06:10PM by _kawhl
via reddit https://ift.tt/hmAnjFk
therealunicornsecurity.github.io
What not to do with on prem virtualization
Common misconfigurations in on prem VM environments
There's a big problem with browser bookmark security.
https://ift.tt/i9Ytjyb
Submitted March 21, 2025 at 08:17PM by TheThingCreator
via reddit https://ift.tt/K7MQeUs
https://ift.tt/i9Ytjyb
Submitted March 21, 2025 at 08:17PM by TheThingCreator
via reddit https://ift.tt/K7MQeUs
WebCull
The Problem With Browser Bookmark Security - WebCull Blog
Web browsers store bookmarks in plain text, making them vulnerable to malware, unauthorized access, profiling, and potential regulatory risks.
Palo Alto Cortex XDR bypass (CVE-2024-8690)
https://ift.tt/Peay4gi
Submitted March 22, 2025 at 02:24AM by CptWin_NZ
via reddit https://ift.tt/1wtvY0f
https://ift.tt/Peay4gi
Submitted March 22, 2025 at 02:24AM by CptWin_NZ
via reddit https://ift.tt/1wtvY0f
CyberCX
Palo Alto Cortex XDR bypass
Technical details outlining how this Palo Alto vulnerability could be exploited by an Administrator-level user account to disable Cortex XDR.
TraceFind - Email OSINT Tool - Information Gathering | DM for free credits - no AD, I want your opinion on it.
https://tracefind.info
Submitted March 22, 2025 at 10:44PM by ProtDos
via reddit https://ift.tt/elW6Ffn
https://tracefind.info
Submitted March 22, 2025 at 10:44PM by ProtDos
via reddit https://ift.tt/elW6Ffn
tracefind.info
TraceFind | Advanced OSINT Tool for Email and Username
TraceFind is a powerful OSINT tool that helps you gather intelligence on emails, usernames, and phone numbers. Enhance your investigations with precise and comprehensive data collection.
Secrets.tools - security tool for scanning login pages for secrets, emails, ips and urls
https://secrets.tools
Submitted March 23, 2025 at 01:34AM by bubblehack3r
via reddit https://ift.tt/tAl5qZY
https://secrets.tools
Submitted March 23, 2025 at 01:34AM by bubblehack3r
via reddit https://ift.tt/tAl5qZY
secrets.tools
Secrets.tools - Login Page Security Scanner
Scan login pages for exposed secrets, API keys, and embedded URLs. Professional security tool for developers and security teams.
Profile Image Intel - OSINT Tool for checking when profile pictures were last changed
https://ift.tt/7YmItKz
Submitted March 23, 2025 at 01:33AM by bubblehack3r
via reddit https://ift.tt/MYJbGzA
https://ift.tt/7YmItKz
Submitted March 23, 2025 at 01:33AM by bubblehack3r
via reddit https://ift.tt/MYJbGzA
Profileimageintel
Profile Image Intel - OSINT Tool for Social Media Pictures
Discover when profile pictures were uploaded across Instagram, Facebook, and WhatsApp. Professional OSINT tool for social media investigation.
After a decade of open source security educational tools (SecGen), we've launched a hosted platform, Hacktivity
https://ift.tt/QrcIajk
Submitted March 23, 2025 at 03:24PM by zcliffe
via reddit https://ift.tt/lZbX5Ti
https://ift.tt/QrcIajk
Submitted March 23, 2025 at 03:24PM by zcliffe
via reddit https://ift.tt/lZbX5Ti
Hacktivity Cyber Security Labs
Introducing Hacktivity Subnoscriptions for Individuals - Hacktivity Cyber Security Labs
## Launch Announcement of Subnoscriptions for Individuals
After a decade of proven success in university settings, we're excited to announce the public laun...
After a decade of proven success in university settings, we're excited to announce the public laun...
Privateers Reborn: Digital Letters of Marque
https://ift.tt/zK1vIVZ
Submitted March 24, 2025 at 03:48AM by a_real_society
via reddit https://ift.tt/T2zWkDe
https://ift.tt/zK1vIVZ
Submitted March 24, 2025 at 03:48AM by a_real_society
via reddit https://ift.tt/T2zWkDe
Substack
Privateers Reborn: Cyber Letters of Marque
Congressional failure to act and how America can leverage its citizenry on the global cyber battlefield
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://ift.tt/uTlfdnb
Submitted March 24, 2025 at 02:22PM by Mempodipper
via reddit https://ift.tt/mFuBcYR
https://ift.tt/uTlfdnb
Submitted March 24, 2025 at 02:22PM by Mempodipper
via reddit https://ift.tt/mFuBcYR
Searchlight Cyber
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927) › Searchlight Cyber
This critical vulnerability allowed attackers to bypass authentication implemented in the middleware layer. With the popularity of this framework on the internet and within our customers' attack surfaces, our Security Research team took a deeper look at the…
Bypassing Detections with Command-Line Obfuscation
https://ift.tt/mx9KwMj
Submitted March 24, 2025 at 02:58PM by Wietze-
via reddit https://ift.tt/aKLw1cd
https://ift.tt/mx9KwMj
Submitted March 24, 2025 at 02:58PM by Wietze-
via reddit https://ift.tt/aKLw1cd
www.wietzebeukema.nl
Bypassing Detections with Command-Line Obfuscation
Defensive tools like AVs and EDRs rely on command-line arguments for detecting malicious activity. This post demonstrates how command-line obfuscation, a shell-independent technique that exploits executables’ parsing “flaws”, can bypass such detections. It…
Takumi, the AI Security Engineer | GMO Flatt Security Inc.
https://ift.tt/ANsLjCu
Submitted March 24, 2025 at 08:11PM by toyojuni
via reddit https://ift.tt/OfHjUvM
https://ift.tt/ANsLjCu
Submitted March 24, 2025 at 08:11PM by toyojuni
via reddit https://ift.tt/OfHjUvM
GMO Flatt Security
Takumi, the AI Security Engineer | GMO Flatt Security Inc.
Tuned by world-class offensive security experts, our AI agent, Takumi, uncovers critical vulnerabilities within your codebase that other tools miss, such as business logic bugs and broken authorizations. This allows you to receive actionable alerts with minimal…
Former U.S. Homeland Security Secretary Tom Ridge serves as a strategic advisor to CyberCatch, having inspired CEO Sai Huda to launch the company.
https://ift.tt/uwe7Z6B
Submitted March 24, 2025 at 10:56PM by Appropriate-Hunt-897
via reddit https://ift.tt/m3vV7IK
https://ift.tt/uwe7Z6B
Submitted March 24, 2025 at 10:56PM by Appropriate-Hunt-897
via reddit https://ift.tt/m3vV7IK
CyberCatch - AI-Enabled Cybersecurity Solution that enables compliance and cyber risk mitigation in 2 weeks or less.
A Special Message from The Honorable Tom Ridge
We are honored to have first U.S. Secretary of Homeland Security Tom Ridge on our team as Board Advisor. He inspired our CEO, Sai Huda, to found CyberCatch.
"How CyberCatch is using their AI-enabled platform for continuous compliance and risk mitigation" BNN Bloomberg LIVE Interview with CyberCatch CEO, Sai HudaSecurity
https://ift.tt/9uBFgo5
Submitted March 25, 2025 at 12:48AM by Appropriate-Hunt-897
via reddit https://ift.tt/b3hBaqD
https://ift.tt/9uBFgo5
Submitted March 25, 2025 at 12:48AM by Appropriate-Hunt-897
via reddit https://ift.tt/b3hBaqD