220 - Windows Kernel Bugs, Safari Integer Underflow, and CONSTIFY
https://dayzerosec.com/podcast/220.html
https://dayzerosec.com/podcast/220.html
dayzerosec
Windows Kernel Bugs, Safari Integer Underflow, and CONSTIFY
Diving right into some binary exploitation issues this week. Starting wtih a look at a rare sort of curl vulnerability where a malicious server could compromise a curl user. Then we take a look at a pretty straight-forward type confusion in Windows kernel…
Joint Industry statement of support for Consumer IoT Security Principles
http://security.googleblog.com/2023/10/joint-industry-statement-of-support-for.html
http://security.googleblog.com/2023/10/joint-industry-statement-of-support-for.html
Google Online Security Blog
Joint Industry statement of support for Consumer IoT Security Principles
David Kleidermacher, VP Engineering, Android Security & Privacy and DSPA Security & Privacy, and Eugene Liderman, Director, Android Security...
Elevate CVE Remediation with EPSS, Now Integrated in HackerOne Hacktivity
https://www.hackerone.com/vulnerability-management/hacktivity-epss-integration
https://www.hackerone.com/vulnerability-management/hacktivity-epss-integration
HackerOne
Elevate CVE Remediation with EPSS, Now Integrated in HackerOne Hacktivity
HackerOne has integrated EPSS scoring into Hacktivity for more comprehensive CVE remediation.
Smart Pension launches a Vulnerability Disclosure Program on Intigriti
https://blog.intigriti.com/2023/10/26/smart-pension-vdp-launch/
https://blog.intigriti.com/2023/10/26/smart-pension-vdp-launch/
GitHub - foozzi/discoshell: a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and others
https://github.com/foozzi/discoshell
https://github.com/foozzi/discoshell
GitHub
GitHub - foozzi/discoshell: a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and…
a simple discovery noscript that uses popular tools like subfinder, amass, puredns, alterx, massdns and others - foozzi/discoshell
Joint Industry statement of support for Consumer IoT Security Principles
http://security.googleblog.com/2023/10/joint-industry-statement-of-support-for.html
http://security.googleblog.com/2023/10/joint-industry-statement-of-support-for.html
Google Online Security Blog
Joint Industry statement of support for Consumer IoT Security Principles
David Kleidermacher, VP Engineering, Android Security & Privacy and DSPA Security & Privacy, and Eugene Liderman, Director, Android Security...
Bypass Android Applications Debug and Root Detection via debugger.
https://medium.com/@shubhamsonani/hacking-with-precision-bypass-techniques-via-debugger-in-android-apps-27fd562b2cc0
https://medium.com/@shubhamsonani/hacking-with-precision-bypass-techniques-via-debugger-in-android-apps-27fd562b2cc0
Medium
Bypass Android Applications Debug and Root Detection via debugger.
Hi Everyone,
GitHub - sAjibuu/Upload_Bypass: File upload restrictions bypass, by using different bug bounty techniques covered in Hacktricks.
https://github.com/sAjibuu/Upload_Bypass
https://github.com/sAjibuu/Upload_Bypass
GitHub
GitHub - sAjibuu/Upload_Bypass: A simple tool for bypassing file upload restrictions.
A simple tool for bypassing file upload restrictions. - sAjibuu/Upload_Bypass
Google’s reward criteria for reporting bugs in AI products
http://security.googleblog.com/2023/10/googles-reward-criteria-for-reporting.html
http://security.googleblog.com/2023/10/googles-reward-criteria-for-reporting.html
Google Online Security Blog
Google’s reward criteria for reporting bugs in AI products
Eduardo Vela, Jan Keller and Ryan Rinaldi, Google Engineering In September, we shared how we are implementing the voluntary AI commitments...
GitHub - xnl-h4ck3r/XnlReveal: A Chrome browser extension to show alerts for relfected query params, show hidden elements and enable disabled elements.
https://github.com/xnl-h4ck3r/XnlReveal
https://github.com/xnl-h4ck3r/XnlReveal
GitHub
GitHub - xnl-h4ck3r/XnlReveal: A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive…
A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled elements. - xnl-h4ck3r/XnlReveal
Increasing transparency in AI security
http://security.googleblog.com/2023/10/increasing-transparency-in-ai-security.html
http://security.googleblog.com/2023/10/increasing-transparency-in-ai-security.html
Google Online Security Blog
Increasing transparency in AI security
Mihai Maruseac, Sarah Meiklejohn, Mark Lodato, Google Open Source Security Team (GOSST) New AI innovations and applications are reaching con...
NetSupport Intrusion Results in Domain Compromise - The DFIR Report
https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
The DFIR Report
NetSupport Intrusion Results in Domain Compromise
NetSupport Manager is one of the oldest third-party remote access tools still currently on the market with over 33 years of history. This is the first time we will report on a NetSupport RAT intrus…