g3n3r4l21
-
PoisonTap (samy.pl)
Exploiting locked computers through USB peripherals, demonstrating techniques to bypass security measures on locked machines.
-
Securing 4 C's of a Software Product (rohitsalecha.com)
Comprehensive guide focusing on implementing AWS security measures across different product components.
-
GitHub Enterprise SAML Bypass (projectdiscovery.io)
Analysis of critical authentication bypass vulnerabilities affecting GitHub Enterprise Server.
-
Sharing Secrets (netmeister.org)
Comprehensive guide exploring various methodologies and best practices for secure secret sharing in organizations.
-
IBM Security Verify Access (pierrekim.github.io)
Detailed analysis of 32 security vulnerabilities discovered in IBM's security platform.
-
Fortune 500 Supply Chain (landh.tech)
Investigation into hidden supply chain vulnerabilities affecting Fortune 500 companies.
-
Ubuntu Privilege Escalation (snyk.io)
Technical analysis of root privilege escalation techniques in Ubuntu 24.04.
-
Application Security Assessment (sekurno.com)
Methodological approach to effectively evaluate application security posture.
-
Citrix Remote Access (labs.watchtowr.com)
Research on critical vulnerabilities in Citrix Virtual Apps and Desktops.
-
Arc Browser Security (medium.com)
Discovery of UXSS, local file read, and RCE vulnerabilities in Arc Browser.
-
Firefox Animation Bug (dimitrifourny.github.io)
Technical analysis of CVE-2024-9680 affecting Firefox's animation system.
-
SoftBank Mesh Analysis (neroteam.com)
In-depth vulnerability research on SoftBank Mesh RP562B devices.
-
CVE-2024-47575 (attackerkb.com)
Detailed analysis and impact assessment of critical vulnerability.
-
Incident Response Evolution (jamie.ideasasylum.com)
Case study on the development of incident response processes at Podia.
-
VPN Trust Analysis (blog.orhun.dev)
Critical examination of trust issues in modern VPN services.
-
GuardDuty Bypass (hackingthe.cloud)
Techniques for bypassing AWS GuardDuty pentest detection mechanisms.
-
AI Red Team Services (crowdstrike.com)
Introduction to CrowdStrike's new AI security testing capabilities.
-
AWS Ransomware (chrisfarris.com)
Comprehensive guide on effective AWS ransomware techniques and prevention.
-
Technical Team Leadership (securing.dev)
Insights into effectively leading technical security teams.
-
JWT Attack Methods (trustedsec.com)
Analysis of attack vectors using self-signed JWT claims.
-
Apple Security Feature (chaos.social)
Discussion on newly implemented security features in Apple systems. Watch Here
X4
-
Ethernet History (@todayininfosec)
Historical perspective on the creation and implementation of Ethernet. Watch Here
-
Malware Museum (@mikko)
Announcement of the upcoming Museum of Malware Art in Helsinki. Watch Here
-
Password Comic (@todayininfosec)
Historical Foxtrot comic highlighting password management challenges. Watch Here
-
Gnark Vulnerability (@FuzzingLabs)
Technical thread on memory vulnerability discovery in Gnark. Watch Here
y0utube3
-
BlueHat 2024 (youtube.com)
Complete collection of presentations from BlueHat 2024 security conference. Watch Here
-
CURL Analysis (youtube.com)
Deep dive into CURL HTTPS verbose output analysis. Watch Here
-
Cities Skylines Malware (youtube.com)
Comprehensive reverse engineering analysis of Cities Skylines II malware. Watch Here
g1thub3
-
CVE-2024-50340-eos-exploit (github.com)
Exploit implementation for Symfony vulnerability. Explore on GitHub
-
C2TeamServer (github.com)
Framework for Command and Control server implementation. Explore on GitHub
-
web-chains (github.com)
Java payload generation and exploitation toolkit. Explore on GitHub