We Got Tired of Labs NOT preparing us for Real Targets… So We Built This (Seeking Beta Feedback!)
https://ift.tt/VxUAJ75
Submitted May 07, 2025 at 02:44PM by RogueSMG
via reddit https://ift.tt/RvzWVL9
https://ift.tt/VxUAJ75
Submitted May 07, 2025 at 02:44PM by RogueSMG
via reddit https://ift.tt/RvzWVL9
Known Exploited Vulnerabilities Intel
https://kevintel.com
Submitted May 07, 2025 at 04:10PM by ethicalhack3r
via reddit https://ift.tt/fSrupwZ
https://kevintel.com
Submitted May 07, 2025 at 04:10PM by ethicalhack3r
via reddit https://ift.tt/fSrupwZ
Reddit
From the netsec community on Reddit: Known Exploited Vulnerabilities Intel
Posted by ethicalhack3r - 12 votes and 0 comments
Drag and pwnd: Exploiting VS Code with ASCII
https://ift.tt/FtQCINX
Submitted May 07, 2025 at 03:55PM by albinowax
via reddit https://ift.tt/KtoMkVv
https://ift.tt/FtQCINX
Submitted May 07, 2025 at 03:55PM by albinowax
via reddit https://ift.tt/KtoMkVv
PortSwigger Research
Drag and Pwnd: Leverage ASCII characters to exploit VS Code
Control characters like SOH, STX, EOT and ETX were never meant to run your code - but in the world of modern terminal emulators, they sometimes do. In this post, I'll dive into the forgotten mechanics
Finding Vulnerable malloc Calls using Ghidra PCode Analysis
https://ift.tt/7ec4qZv
Submitted May 07, 2025 at 07:02PM by cy1337
via reddit https://ift.tt/UN6tHMl
https://ift.tt/7ec4qZv
Submitted May 07, 2025 at 07:02PM by cy1337
via reddit https://ift.tt/UN6tHMl
Medium
Tracing malloc calls with PCode
It’s that time of the year again, Black Hat USA is just a few months away and I’m honored to be back again for another year teaching about…
Summarisation of Cross Session Activation / Kerberos relaying attacks
https://ift.tt/qTJDjbI
Submitted May 07, 2025 at 07:33PM by S3cur3Th1sSh1t
via reddit https://ift.tt/FR2UNrH
https://ift.tt/qTJDjbI
Submitted May 07, 2025 at 07:33PM by S3cur3Th1sSh1t
via reddit https://ift.tt/FR2UNrH
www.r-tec.net
r-tec Blog | Windows is and always will be a Potatoland
This blog post will dive into the world of some of the recently published potato techniques that can lead to more serious risks than
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerability Reports
https://ift.tt/XbYVS1M
Submitted May 07, 2025 at 09:03PM by rcmaehl
via reddit https://ift.tt/yH1ojhS
https://ift.tt/XbYVS1M
Submitted May 07, 2025 at 09:03PM by rcmaehl
via reddit https://ift.tt/yH1ojhS
Socket
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerab...
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.
The Path to Memory Safety is Inevitable
https://ift.tt/fZzugXk
Submitted May 07, 2025 at 08:49PM by citypw
via reddit https://ift.tt/4t5QwbJ
https://ift.tt/fZzugXk
Submitted May 07, 2025 at 08:49PM by citypw
via reddit https://ift.tt/4t5QwbJ
hardenedlinux.org
The Path to Memory Safety is Inevitable
Santizer is the most effective way to enhance the memory safety. Fuzzer helps as well! Fil-C...
CVE-2024-11477- 7-Zip ZSTD Buffer Overflow Vulnerability - Crowdfense
https://ift.tt/vujZDGX
Submitted May 08, 2025 at 08:44PM by Void_Sec
via reddit https://ift.tt/OkF1a6U
https://ift.tt/vujZDGX
Submitted May 08, 2025 at 08:44PM by Void_Sec
via reddit https://ift.tt/OkF1a6U
Crowdfense
CVE-2024-11477- 7-Zip ZSTD Buffer Overflow Vulnerability - Crowdfense
CVE-2024-11477, a buffer overflow vulnerability in 7-Zip's ZSTD decompression algorithm; explore the technical details.
SCIM Hunting. Finding bugs in SCIM implementations
https://ift.tt/hUzQuDE
Submitted May 09, 2025 at 02:24AM by nibblesec
via reddit https://ift.tt/JUW1v0f
https://ift.tt/hUzQuDE
Submitted May 09, 2025 at 02:24AM by nibblesec
via reddit https://ift.tt/JUW1v0f
Doyensec
SCIM Hunting - Beyond SSO
Single Sign-On (SSO) related bugs have gotten an incredible amount of hype and a lot of amazing public disclosures in recent years. Just to cite a few examples:
Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources
https://ift.tt/M5VvtJj
Submitted May 10, 2025 at 04:34AM by Super_Weather3575
via reddit https://ift.tt/4Pg6QpV
https://ift.tt/M5VvtJj
Submitted May 10, 2025 at 04:34AM by Super_Weather3575
via reddit https://ift.tt/4Pg6QpV
Unit 42
Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources
Unit 42 details a new malware obfuscation technique where threat actors hide malware in bitmap resources within .NET applications. These deliver payloads like Agent Tesla or XLoader. Unit 42 details a new malware obfuscation technique where threat actors…
The Honeynet Workshop Conference 2025 is in June in Prague.
https://ift.tt/oQGb1kg
Submitted May 11, 2025 at 02:12AM by sebagarcia
via reddit https://ift.tt/oDiUERd
https://ift.tt/oQGb1kg
Submitted May 11, 2025 at 02:12AM by sebagarcia
via reddit https://ift.tt/oDiUERd
One-Click RCE in ASUS’s Preinstalled Driver Software
https://ift.tt/pmH13x8
Submitted May 11, 2025 at 02:13PM by AlmondOffSec
via reddit https://ift.tt/gkp91cG
https://ift.tt/pmH13x8
Submitted May 11, 2025 at 02:13PM by AlmondOffSec
via reddit https://ift.tt/gkp91cG
Mrbruh
MrBruh's Epic Blog
One-Click RCE in ASUS’s Preinstalled Driver Software Introduction This story begins with a conversation about new PC parts.
After ignoring the advice from my friend, I bought a new ASUS motherboard for my PC. I was a little concerned about having a BIOS that…
After ignoring the advice from my friend, I bought a new ASUS motherboard for my PC. I was a little concerned about having a BIOS that…
How I ruined my vacation by reverse engineering WSC
https://ift.tt/4l8OMEI
Submitted May 12, 2025 at 04:49PM by AlmondOffSec
via reddit https://ift.tt/nhTKLE7
https://ift.tt/4l8OMEI
Submitted May 12, 2025 at 04:49PM by AlmondOffSec
via reddit https://ift.tt/nhTKLE7
blog.es3n1n.eu
How I ruined my vacation by reverse engineering WSC
In this post I will briefly describe the journey I went through while implementing defendnot.
Even though this is most likely not what you expected to see here, but rather than going into full technical details on how everything works, I will describe what…
Even though this is most likely not what you expected to see here, but rather than going into full technical details on how everything works, I will describe what…
Statistical Analysis to Detect Uncommon Code
https://ift.tt/9IzWd3K
Submitted May 12, 2025 at 07:57PM by FoxInTheRedBox
via reddit https://ift.tt/GJwEInX
https://ift.tt/9IzWd3K
Submitted May 12, 2025 at 07:57PM by FoxInTheRedBox
via reddit https://ift.tt/GJwEInX
I built Mithra: a security scanner for LLM-integrated APIs (detects prompt injection, DAN..)
https://mithrasec.com
Submitted May 12, 2025 at 10:55PM by 1337kadir
via reddit https://ift.tt/Wpzfkjw
https://mithrasec.com
Submitted May 12, 2025 at 10:55PM by 1337kadir
via reddit https://ift.tt/Wpzfkjw
Mithrasec
Mithra LLM Scanner
Scan LLM-Integrated APIs in Minutes
Azure Managed Identities Abuse: Security Research - Defense strategies
https://ift.tt/GLJVNXq
Submitted May 13, 2025 at 06:21PM by HunterHex1123
via reddit https://ift.tt/tWgNV9y
https://ift.tt/GLJVNXq
Submitted May 13, 2025 at 06:21PM by HunterHex1123
via reddit https://ift.tt/tWgNV9y
www.hunters.security
Detecting Azure Managed Identity Abuse: Threat Hunting Techniques
Discover how to detect and hunt Azure Managed Identity abuse using real-world scenarios, log correlations, and high-fidelity detection queries.
[CVE-2025-47916] Invision Community <= 5.0.6 (customCss) Remote Code Execution
https://ift.tt/Dhlrg7f
Submitted May 14, 2025 at 06:05PM by eg1x
via reddit https://ift.tt/SEOhrPB
https://ift.tt/Dhlrg7f
Submitted May 14, 2025 at 06:05PM by eg1x
via reddit https://ift.tt/SEOhrPB
Karmainsecurity
Invision Community <= 5.0.6 (customCss) Remote Code Execution Vulnerability | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Integrate LDAP into Keycloak to modernize rather than delete it
https://ift.tt/E0tyOI8
Submitted May 14, 2025 at 07:41PM by Will-from-CloudIAM
via reddit https://ift.tt/eu9Antw
https://ift.tt/E0tyOI8
Submitted May 14, 2025 at 07:41PM by Will-from-CloudIAM
via reddit https://ift.tt/eu9Antw
Cloud-Iam
LDAP, Keycloak, and Modern IAM: Integrating LDAP into a scalable, secure IAM architecture with Keycloak
Modernize your user management while preserving your LDAP with Keycloak. Instead of replacing your LDAP, it's often wiser to reposition it as a source of truth, orchestrated by a modern IAM solution. Keycloak stands out because it can natively federate with…
Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428) - watchTowr Labs
https://ift.tt/QGLMVT4
Submitted May 15, 2025 at 08:25PM by dx7r__
via reddit https://ift.tt/eWMTrzZ
https://ift.tt/QGLMVT4
Submitted May 15, 2025 at 08:25PM by dx7r__
via reddit https://ift.tt/eWMTrzZ
watchTowr Labs
Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
Keeping your ears to the ground and eyes wide open for the latest vulnerability news at watchTowr is a given. Despite rummaging through enterprise code looking for 0days on a daily basis, our interest was piqued this week when news of fresh vulnerabilities…
Commit Stomping - Manipulating Git Histories to Obscure the Truth
https://ift.tt/RruLYyb
Submitted May 16, 2025 at 03:52AM by Fit-Cut9562
via reddit https://ift.tt/C8k0S5o
https://ift.tt/RruLYyb
Submitted May 16, 2025 at 03:52AM by Fit-Cut9562
via reddit https://ift.tt/C8k0S5o
ZephrSec - Adventures In Information Security
Commit Stomping
Manipulating Git Histories to Obscure the Truth
Announcing the Official Parity Release of Volatility 3!
https://ift.tt/s3XGYHg
Submitted May 16, 2025 at 09:04PM by transt
via reddit https://ift.tt/Sts8Cdf
https://ift.tt/s3XGYHg
Submitted May 16, 2025 at 09:04PM by transt
via reddit https://ift.tt/Sts8Cdf
The Volatility Foundation - Promoting Accessible Memory Analysis Tools Within the Memory Forensics Community
Announcing the Official Parity Release of Volatility 3!
Visit the post for more.