Threat Hunting Introduction: Cobalt Strike
https://ift.tt/vUo4dT8
Submitted June 23, 2025 at 10:13PM by rushter_
via reddit https://ift.tt/qQlNhge
https://ift.tt/vUo4dT8
Submitted June 23, 2025 at 10:13PM by rushter_
via reddit https://ift.tt/qQlNhge
Artem Golubin
Threat Hunting Introduction: Cobalt Strike | Artem Golubin
An introduction to Threat Hunting and Cobalt Strike
Iran's Internet: A Censys Perspective
https://ift.tt/nJPXtwY
Submitted June 24, 2025 at 02:30AM by _Invalid_User_Token_
via reddit https://ift.tt/7GYdi3j
https://ift.tt/nJPXtwY
Submitted June 24, 2025 at 02:30AM by _Invalid_User_Token_
via reddit https://ift.tt/7GYdi3j
Censys
Iran's Internet: A Censys Perspective
Inside Iran’s online landscape, what Censys sees in access, control, and exposure across the country’s internet.
Remote Code Execution on 40,000 WiFi alarm clocks
https://ift.tt/n4sqj57
Submitted June 24, 2025 at 02:09AM by Sw2Bechu
via reddit https://ift.tt/caAbCJs
https://ift.tt/n4sqj57
Submitted June 24, 2025 at 02:09AM by Sw2Bechu
via reddit https://ift.tt/caAbCJs
iank.org
Remote Code Execution on 40,000 WiFi alarm clocks
While looking for an API to use with Home Assistant, I found a remote code execution vulnerability in a popular WiFi-connected alarm clock.
FileFix – New Alternative to ClickFix Attack
https://ift.tt/P8RIGEZ
Submitted June 24, 2025 at 08:13PM by barakadua131
via reddit https://ift.tt/vr0j8Cs
https://ift.tt/P8RIGEZ
Submitted June 24, 2025 at 08:13PM by barakadua131
via reddit https://ift.tt/vr0j8Cs
Mobile Hacker
Introducing FileFix – A New Alternative to ClickFix Attacks
A new browser attack vectors just dropped, and it’s called FileFix — an alternative to the well-known ClickFix attack. This method, discovered and shared by mrd0x, shows how attackers can to execute commands right from browser, without requesting target to…
Remote code execution in CentOS Web Panel - CVE-2025-48703
https://ift.tt/sjryc7b
Submitted June 24, 2025 at 07:34PM by AlmondOffSec
via reddit https://ift.tt/BoAKgL8
https://ift.tt/sjryc7b
Submitted June 24, 2025 at 07:34PM by AlmondOffSec
via reddit https://ift.tt/BoAKgL8
Fenrisk
Remote code execution in CentOS Web Panel - CVE-2025-48703
Security experts
New Kerio Control Advisory!
https://ift.tt/7YEAZGg
Submitted June 24, 2025 at 11:33PM by Straight-Zombie-646
via reddit https://ift.tt/hfxqdQl
https://ift.tt/7YEAZGg
Submitted June 24, 2025 at 11:33PM by Straight-Zombie-646
via reddit https://ift.tt/hfxqdQl
SSD Secure Disclosure
SSD Advisory - Kerio Control Authentication Bypass and RCE - SSD Secure Disclosure
Summary An analysis primarily of Kerio Control revealed a design flaw in the implementation of the communication with GFI AppManager, leading to an authentication bypass vulnerability in the product under audit. Once the authentication bypass is achieved…
TrashTalk.me - A new secure way to chat
https://trashtalk.me
Submitted June 24, 2025 at 11:14PM by merklerkmanitee
via reddit https://ift.tt/i5Xlo8z
https://trashtalk.me
Submitted June 24, 2025 at 11:14PM by merklerkmanitee
via reddit https://ift.tt/i5Xlo8z
Reddit
From the netsec community on Reddit: TrashTalk.me - A new secure way to chat
Posted by merklerkmanitee - 0 votes and 2 comments
Cryptominers’ Anatomy: Shutting Down Mining Botnets
https://ift.tt/LEZo1sJ
Submitted June 24, 2025 at 11:10PM by Narrow_Rooster_630
via reddit https://ift.tt/XOdWbrL
https://ift.tt/LEZo1sJ
Submitted June 24, 2025 at 11:10PM by Narrow_Rooster_630
via reddit https://ift.tt/XOdWbrL
Akamai
Cryptominers’ Anatomy: Shutting Down Mining Botnets | Akamai
In the final installment of Cryptominers’ Anatomy, Akamai researchers analyze cryptominers and reveal a novel technique to shut down mining botnet campaigns.
Security Benchmarking Authorization Policy Engines
https://ift.tt/fXxNqzl
Submitted June 25, 2025 at 02:42PM by nibblesec
via reddit https://ift.tt/gM60OZN
https://ift.tt/fXxNqzl
Submitted June 25, 2025 at 02:42PM by nibblesec
via reddit https://ift.tt/gM60OZN
Goteleport
Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA & Teleport ACD
Explore how the Security Policy Evaluation Framework (SPEF) enables automated, dynamic security benchmarking of leading authorization engines—Rego, Cedar, OpenFGA, and Teleport ACD. Developed by Doyensec with support from Teleport, SPEF tests for vulnerabilities…
Deleting a file in Wire doesn’t remove it from servers — and other findings
https://ift.tt/CcOrZKg
Submitted June 25, 2025 at 03:24PM by AlmondOffSec
via reddit https://ift.tt/4WO3U8e
https://ift.tt/CcOrZKg
Submitted June 25, 2025 at 03:24PM by AlmondOffSec
via reddit https://ift.tt/4WO3U8e
How to Set Up Your Own WireGuard VPN on a VPS (Beginner-Friendly Tutorial)
https://ift.tt/KJXx0uB
Submitted June 25, 2025 at 08:14PM by kongwenbin
via reddit https://ift.tt/zxtuN1Q
https://ift.tt/KJXx0uB
Submitted June 25, 2025 at 08:14PM by kongwenbin
via reddit https://ift.tt/zxtuN1Q
My Learning Journey
How to Set Up Your Own WireGuard VPN on a VPS (Beginner-Friendly Tutorial)
Beginner-friendly Step-by-step guide to setting up a WireGuard VPN on a VPS. Ideal for bug bounty hunters and privacy-focused users.
We built a smart, searchable infosec library indexing 20+ years of resources
https://talkback.sh
Submitted June 26, 2025 at 10:16AM by elttam
via reddit https://ift.tt/enixObw
https://talkback.sh
Submitted June 26, 2025 at 10:16AM by elttam
via reddit https://ift.tt/enixObw
Talkback
Talkback is a smart infosec resource aggregator, designed to help security enthusiasts, practitioners and researchers be more productive.
Read “Windows Registry Manipulation“ by ONESithuation
https://ift.tt/aMdWmFY
Submitted June 26, 2025 at 10:07AM by Johny166xz
via reddit https://ift.tt/hN6L4zV
https://ift.tt/aMdWmFY
Submitted June 26, 2025 at 10:07AM by Johny166xz
via reddit https://ift.tt/hN6L4zV
Medium
Windows Registry Manipulation
Episode 01
Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork - Putting Millions at Risk
https://ift.tt/Tdj6bVm
Submitted June 26, 2025 at 04:43PM by Most-Anywhere-6651
via reddit https://ift.tt/ZYFaiSp
https://ift.tt/Tdj6bVm
Submitted June 26, 2025 at 04:43PM by Most-Anywhere-6651
via reddit https://ift.tt/ZYFaiSp
Medium
Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork; Putting Millions at Risk
TL;DR: We discovered a critical vulnerability in open-vsx.org — the open-source VS Code extension marketplace used by over 8,000,000…
Scanning Beyond the Patch: A Public-Interest Hunt for Hidden Shells
https://ift.tt/YMgyR2h
Submitted June 26, 2025 at 07:21PM by 0x5h4un
via reddit https://ift.tt/ukmlabS
https://ift.tt/YMgyR2h
Submitted June 26, 2025 at 07:21PM by 0x5h4un
via reddit https://ift.tt/ukmlabS
disclosing.observer
Scanning Beyond the Patch: A Public-Interest Hunt for Hidden Shells - Disclosing.Observer
Even after patching, many edge devices remain compromised. This post explores how to ethically scan for backdoors left behind.
When Your Login Page Becomes the Frontline: Lessons from a Real-World DDoS Attack
https://ift.tt/JNWniZm
Submitted June 26, 2025 at 10:08PM by Will-from-CloudIAM
via reddit https://ift.tt/qc6aH2t
https://ift.tt/JNWniZm
Submitted June 26, 2025 at 10:08PM by Will-from-CloudIAM
via reddit https://ift.tt/qc6aH2t
Cloud-Iam
Our resilience against cyber attacks
As an IAM SaaS company, our work often remains in the shadows—until something goes wrong. Today, I want to shed light on how we handle security at the very first layer all IAM systems have: the login page. Specifically, I’ll walk you through an incident we…
Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails
https://ift.tt/JW1rmL7
Submitted June 27, 2025 at 10:16AM by No-Reputation7691
via reddit https://ift.tt/1lLWtij
https://ift.tt/JW1rmL7
Submitted June 27, 2025 at 10:16AM by No-Reputation7691
via reddit https://ift.tt/1lLWtij
Varonis
Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails
Varonis Threat Labs uncovered a phishing campaign with M365's Direct Send feature that spoofs internal users without ever needing to compromise an account.
Pertama Digital Partners Netsec To Strengthen Digital Security For Govt And Private Sector
https://ift.tt/jwqfYrs
Submitted June 27, 2025 at 03:04PM by hectormoodya
via reddit https://ift.tt/cJNVwG0
https://ift.tt/jwqfYrs
Submitted June 27, 2025 at 03:04PM by hectormoodya
via reddit https://ift.tt/cJNVwG0
BusinessToday
Pertama Digital Partners Netsec To Strengthen Digital Security For Govt And Private Sector - BusinessToday
Pertama Digital Bhd (PDB) is collaborating with Netsec Sdn Bhd to enhance the security, resilience and performance of digital platforms for both the government and private sectors. In a statement, PDB said this partnership addresses the rising complexity…
Demystifying MCP (Model Context Protocol): 3 Common Misconceptions
https://ift.tt/3AuLs5D
Submitted June 27, 2025 at 06:52PM by hectormoodya
via reddit https://ift.tt/ieL57m9
https://ift.tt/3AuLs5D
Submitted June 27, 2025 at 06:52PM by hectormoodya
via reddit https://ift.tt/ieL57m9
www.pynt.io
Demystifying MCP (Model Context Protocol): 3 Common Mis
in this article, we delve deeper into three commonly misunderstood aspects of MCP, providing clarity to help developers, integrators, and security professionals safely leverage MCP-based technologies.
End-to-End Encryption: Architecturally Necessary
https://ift.tt/Npv1XwY
Submitted June 27, 2025 at 08:15PM by MagicianPutrid5245
via reddit https://ift.tt/vHuGbqd
https://ift.tt/Npv1XwY
Submitted June 27, 2025 at 08:15PM by MagicianPutrid5245
via reddit https://ift.tt/vHuGbqd
RIPE Labs
End-to-End Encryption: Architecturally Necessary
Good intentions don’t always result in good outcomes. This is especially the case with recent suggestions regarding end-to-end-encryption adaptability requirements for number independent communication services. Not only is security an issue, the suggestions…
When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365"
https://ift.tt/WPkXcea
Submitted June 28, 2025 at 01:05AM by parzel
via reddit https://ift.tt/klgSMBw
https://ift.tt/WPkXcea
Submitted June 28, 2025 at 01:05AM by parzel
via reddit https://ift.tt/klgSMBw
Modzero
When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365" / modzero