g3n3r4l18
-
Advisory: Reflected Cross-Site Scripting in cPanel (CVE-2023-29489) (blog.assetnote.io)
-
Git Arbitrary Configuration Injection (CVE-2023-29007) (blog.ethiack.com)
-
A Beginner’s Guide To BSidesSF (lastweekasavciso.com)
-
AWS Codebuild - Token Leakage (cloud.hacktricks.xyz)
-
Integrating DAST into DevSecOps (beaglesecurity.substack.com)
-
CVE-2022-0540 - Authentication bypass in Seraph (blog.viettelcybersecurity.com)
-
WebSockets are a Pain (blog.zsec.uk)
-
Privilege escalation in AWS Elastic Kubernetes Service (EKS) (blog.calif.io)
-
CVE Reference Rot (jerrygamblin.com)
-
Supply Chain Security Jumps the Shark (postmodernsecurity.com)
-
LLMs and Phishing - Schneier on Security (schneier.com)
-
1710564 Possible to spoof Origin in "Connected Sites" (hackerone.com)
-
Argument Injection Vectors (sonarsource.github.io)
-
API: critical dependency data for secure supply chains (security.googleblog.com)
-
Security best practices for Amazon S3 - Amazon Simple Storage Service (docs.aws.amazon.com)
-
Mysk🇨🇦🇩🇪: "Google has just updated its 2F…" - DEF CON Social (defcon.social)
y0utube2
-
Penetrating the Cloud: Uncovering Unknown Vulns (youtube.com)
-
Coding with ChatGPT is so easy, a caveman could do it (youtube.com)
g1thub13
-
advanced-security/enterprise-security-team (github.com)
-
AdguardTeam/cname-trackers (github.com)
-
pufferffish/wireproxy (github.com)
-
sametsazak/mergen (github.com)
-
quarkslab/pastis (github.com)
-
akto-api-security/30-API-security-tests (github.com)
-
WesleyWong420/RedTeamOps-Havoc-101 (github.com)
-
GreyDGL/PentestGPT (github.com)
-
stealthsploit/OneRuleToRuleThemStill (github.com)
-
codingo/dorky (github.com)
-
ethiack/CVE-2023-29007 (github.com)
-
hmgle/graftcp (github.com)
-
RhinoSecurityLabs/ccat (github.com)