Detect Suspicious/Malicious ICMP Echo Traffic - Using Behavioral and Protocol Semantic Analysis
https://ift.tt/I6iBjVU
Submitted September 08, 2025 at 07:00PM by MFMokbel
via reddit https://ift.tt/PqnsmiJ
https://ift.tt/I6iBjVU
Submitted September 08, 2025 at 07:00PM by MFMokbel
via reddit https://ift.tt/PqnsmiJ
PacketSmith
Detect Suspicious/Malicious ICMP Echo Traffic - PacketSmith
Detect Suspicious/Malicious ICMP Echo Traffic Using Behavioral and Protocol Semantic Analysis Introduction With release version 2.0, we have added a new advanced detection module to PacketSmith, with the sole objective of scanning for suspicious/malicious…
NPM Debug and Chalk Packages Compromised
https://ift.tt/ecBq0Zl
Submitted September 08, 2025 at 11:02PM by sheepfiend
via reddit https://ift.tt/1YDRVe7
https://ift.tt/ecBq0Zl
Submitted September 08, 2025 at 11:02PM by sheepfiend
via reddit https://ift.tt/1YDRVe7
www.aikido.dev
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
Department of War Doesn’t Defend its Web Streams From Hackers
https://ift.tt/VLXhHRm
Submitted September 09, 2025 at 12:22AM by eatfruitallday
via reddit https://ift.tt/zUWbrf1
https://ift.tt/VLXhHRm
Submitted September 09, 2025 at 12:22AM by eatfruitallday
via reddit https://ift.tt/zUWbrf1
The Intercept
Department of War Doesn’t Defend its Web Streams From Hackers
The Pentagon publicly posts the stream keys to its Facebook, YouTube, and X channels, exposing livestreams to account takeovers.
A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes
https://ift.tt/IUnD05c
Submitted September 10, 2025 at 01:10AM by 0xggus
via reddit https://ift.tt/CPgw8sc
https://ift.tt/IUnD05c
Submitted September 10, 2025 at 01:10AM by 0xggus
via reddit https://ift.tt/CPgw8sc
[Apple] Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
https://ift.tt/LTIHpGw
Submitted September 10, 2025 at 03:19AM by Pandalicious
via reddit https://ift.tt/pktP5Gc
https://ift.tt/LTIHpGw
Submitted September 10, 2025 at 03:19AM by Pandalicious
via reddit https://ift.tt/pktP5Gc
Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our advanced operating system security to provide industry-first…
Pwn My Ride: Apple CarPlay RCE - iAP2 protocol and CVE-2025-24132 Explained
https://ift.tt/FgpyYm2
Submitted September 10, 2025 at 02:13PM by cov_id19
via reddit https://ift.tt/7tejJMp
https://ift.tt/FgpyYm2
Submitted September 10, 2025 at 02:13PM by cov_id19
via reddit https://ift.tt/7tejJMp
www.oligo.security
Apple CarPlay Hacking Risks: CVE-2025-24132 Explained | Oligo Security
At DefCon, Oligo Security revealed critical Apple CarPlay vulnerabilities, including CVE-2025-24132 in the AirPlay SDK. Learn how attackers exploit iAP2 and AirPlay to compromise connected cars, and why patching delays leave vehicles exposed.
Kerberoasting
https://ift.tt/cW6iGV8
Submitted September 10, 2025 at 05:30PM by feross
via reddit https://ift.tt/dzViFEG
https://ift.tt/cW6iGV8
Submitted September 10, 2025 at 05:30PM by feross
via reddit https://ift.tt/dzViFEG
A Few Thoughts on Cryptographic Engineering
Kerberoasting
I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy (“oh, why didn’t I think of that”) or else they impress me w…
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
https://thedfirreport.com/2025/09/08/blurring-the-lines-intrusion-shows-connection-with-three-major-ransomware-gangs/
Submitted September 10, 2025 at 07:27PM by gdraperi
via reddit https://ift.tt/wsF83WL
https://thedfirreport.com/2025/09/08/blurring-the-lines-intrusion-shows-connection-with-three-major-ransomware-gangs/
Submitted September 10, 2025 at 07:27PM by gdraperi
via reddit https://ift.tt/wsF83WL
The DFIR Report
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Key Takeaways The intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped SectopRAT malware. The threat actor d…
You Already Have Our Personal Data, Take Our Phone Calls Too (FreePBX CVE-2025-57819) - watchTowr Labs
https://ift.tt/AUIKJ20
Submitted September 10, 2025 at 08:19PM by dx7r__
via reddit https://ift.tt/sp93hnH
https://ift.tt/AUIKJ20
Submitted September 10, 2025 at 08:19PM by dx7r__
via reddit https://ift.tt/sp93hnH
watchTowr Labs
You Already Have Our Personal Data, Take Our Phone Calls Too (FreePBX CVE-2025-57819)
We’re back - it’s a day, in a month, in a year - and once again, something has happened.
In this week’s episode of “the Internet is made of string and there is literally no evidence to suggest otherwise”, we present even further evidence that as a
In this week’s episode of “the Internet is made of string and there is literally no evidence to suggest otherwise”, we present even further evidence that as a
Stealing the keys from the octopus: Exfiltrate Git Credentials in Argocd
https://futuresight.club/posts/0x00_exfiltrate_git_credentials_argocd.html
Submitted September 11, 2025 at 03:02AM by Hakyza
via reddit https://ift.tt/YxsKMW6
https://futuresight.club/posts/0x00_exfiltrate_git_credentials_argocd.html
Submitted September 11, 2025 at 03:02AM by Hakyza
via reddit https://ift.tt/YxsKMW6
Reddit
From the netsec community on Reddit: Stealing the keys from the octopus: Exfiltrate Git Credentials in Argocd
Posted by Hakyza - 11 votes and 1 comment
Practice spotting typo squatted domains (Browser game: Typosquat Detective)
https://ift.tt/XICcsiL
Submitted September 11, 2025 at 03:09PM by unknownhad
via reddit https://ift.tt/BMh9U5l
https://ift.tt/XICcsiL
Submitted September 11, 2025 at 03:09PM by unknownhad
via reddit https://ift.tt/BMh9U5l
Inboxfuscation - a free, open-source obfuscation and detection framework to help security teams detect and stop Unicode-obfuscated Microsoft Exchange inbox rules
https://ift.tt/V0nepzh
Submitted September 11, 2025 at 08:12PM by permis0
via reddit https://ift.tt/ip82yhW
https://ift.tt/V0nepzh
Submitted September 11, 2025 at 08:12PM by permis0
via reddit https://ift.tt/ip82yhW
permiso.io
Inboxfuscation: Because Rules Are Meant to Be Broken
Permiso launches Inboxfuscation, an open-source tool enabling organizations to detect Unicode-obfuscated Microsoft Exchange inbox rules and secure Microsoft 365.
Windows KASLR Bypass - CVE-2025-53136
https://ift.tt/5wq6WjM
Submitted September 11, 2025 at 09:39PM by Void_Sec
via reddit https://ift.tt/4XVEZRL
https://ift.tt/5wq6WjM
Submitted September 11, 2025 at 09:39PM by Void_Sec
via reddit https://ift.tt/4XVEZRL
Crowdfense
NT OS Kernel Information Disclosure Vulnerability - CVE-2025-53136 - Crowdfense
Bidding farewell to one of the last kernel address leaks, CVE-2025-53136. Even patches can open new doors for exploitation.
IDOR: How I Could Delete Any Product Image on an E-Commerce Platform
https://ift.tt/Ta4soCI
Submitted September 12, 2025 at 08:07AM by General_Speaker9653
via reddit https://ift.tt/qhkd8nm
https://ift.tt/Ta4soCI
Submitted September 12, 2025 at 08:07AM by General_Speaker9653
via reddit https://ift.tt/qhkd8nm
Medium
IDOR: How I Could Delete Any Product Image on an E-Commerce Platform
Hello folks,
Fine-grained HTTP filtering for Claude Code
https://ift.tt/VdkZawq
Submitted September 13, 2025 at 02:46AM by ammarbandukwala
via reddit https://ift.tt/vdrKF5O
https://ift.tt/VdkZawq
Submitted September 13, 2025 at 02:46AM by ammarbandukwala
via reddit https://ift.tt/vdrKF5O
ammar.io
Fine-grained HTTP filtering for Claude Code
Default‑deny HTTP(S) for dev tools and AI agents. Script rules in JS or shell, log every request, and keep egress within your policy.
🛡️ I’ve started a Pentesting Weekly Digest — would love your feedback & thoughts!
https://ift.tt/RBQLJzc
Submitted September 13, 2025 at 11:22AM by Western-Fox-5184
via reddit https://ift.tt/pNSuhtq
https://ift.tt/RBQLJzc
Submitted September 13, 2025 at 11:22AM by Western-Fox-5184
via reddit https://ift.tt/pNSuhtq
Substack
Pentesting Weekly Digest — September 8–12, 2025
Welcome to the first issue of Pentesting Weekly Digest — your curated roundup of the most important news, tools, and vulnerabilities from the world of penetration testing and cybersecurity.
WSASS - Old But Gold, Dumping LSASS With Windows Error Reporting On Modern Windows 11
https://ift.tt/3gLhplH
Submitted September 13, 2025 at 01:08PM by Cold-Dinosaur
via reddit https://ift.tt/Z3aHAb6
https://ift.tt/3gLhplH
Submitted September 13, 2025 at 01:08PM by Cold-Dinosaur
via reddit https://ift.tt/Z3aHAb6
Zerosalarium
Old But Gold, Dumping LSASS With Windows Error Reporting On Modern Windows 11
Use the offensive tool WSASS to dump the LSASS memory area by exploiting the vulnerability in WerFaultSecure.exe
2025 Supabase Security Best Practices Guide - Common Misconfigs from Recent Pentests.
https://ift.tt/PvNqBem
Submitted September 15, 2025 at 12:37AM by thatsabingo98
via reddit https://ift.tt/URy4xW1
https://ift.tt/PvNqBem
Submitted September 15, 2025 at 12:37AM by thatsabingo98
via reddit https://ift.tt/URy4xW1
Pentestly.io
Harden Your Supabase: Lessons from Real-World Pentests | Pentestly.io Blog
Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.
New OpenSecurityTraining2 class: "TPM 2.0 Programming using Python and the tpm2-pytss libraries" (~13 hours)
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 04:05AM by OpenSecurityTraining
via reddit https://ift.tt/Qy3jIVb
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 04:05AM by OpenSecurityTraining
via reddit https://ift.tt/Qy3jIVb
p.ost2.fyi
TPM 2.0 Programming using Python and the tpm2-pytss libraries
This course provides a comprehensive introduction to Trusted Platform Module (TPM) 2.0 programming using the Python-based tpm2-pytss library.
New OpenSecurityTraining2 class: "TPM 2.0 Programming using Python and the tpm2-pytss libraries" (~13 hours)
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 05:00AM by OpenSecurityTraining
via reddit https://ift.tt/dY6Ihvt
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 05:00AM by OpenSecurityTraining
via reddit https://ift.tt/dY6Ihvt
p.ost2.fyi
TPM 2.0 Programming using Python and the tpm2-pytss libraries
This course provides a comprehensive introduction to Trusted Platform Module (TPM) 2.0 programming using the Python-based tpm2-pytss library.
Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic…
https://ift.tt/15mUQJf
Submitted September 15, 2025 at 06:18AM by thewatcher_
via reddit https://ift.tt/QmDYpAa
https://ift.tt/15mUQJf
Submitted September 15, 2025 at 06:18AM by thewatcher_
via reddit https://ift.tt/QmDYpAa
Medium
Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic…
In my work analyzing native code in Android applications, I often try different techniques. Some work, others not so much. I’ve realized I…