g3n3r4l18
-
A comprehensive guide to enhancing privacy and security across major operating systems.
-
Certificate Transparency (certificate.transparency.dev)
Delve into the world of certificate transparency and its pivotal role in internet security.
-
Quishing Simulator - Keepnet Labs (keepnetlabs.com)
An interactive simulator to understand and defend against quishing attacks.
-
A novel approach to exploiting XSS vulnerabilities using polyglot JPEGs and JavaScript.
-
Privilege Escalation in Cloudflare Pages (blog-ryotak-net.translate.goog)
Exploration of privilege escalation and page tampering issues in Cloudflare Pages.
-
An analysis of how adtech, including unverified vanity URLs, is catalyzing online fraud.
-
2023 CVE Data Review (jerrygamblin.com)
A comprehensive review of CVE data from the year 2023.
-
Control-M Web Security Advisory (errno.fr)
Important security update and advisory for Control-M Web users.
-
Unauthenticated RCE in Adobe Coldfusion (CVE-2023-26360) (blog.securelayer7.net)
A detailed analysis of a remote code execution vulnerability in Adobe Coldfusion.
-
GitLab Critical Security Release (Versions 16.7.2, 16.6.4, 16.5.6) (about.gitlab.com)
Details on GitLab's critical security update addressing significant vulnerabilities.
-
Defending Websites with ZIP Bombs (blog.haschek.at)
Strategies on using ZIP bombs to protect websites.
-
Analysis of HTTP2 Request Smuggling (paper.seebug.org)
In-depth exploration of utilizing HTTP2 request smuggling.
-
Best Security Movies (and some yet to be made) by Phil Venables (philvenables.com)
A curated list of the best security movies and some ideas for future films.
-
5 Katana Tricks for OSINT (osintteam.blog)
Advanced techniques for open-source intelligence gathering.
-
Sink Tracing in Modern Web Applications (ecsypno.com)
Techniques for tracing and securing web application sinks.
-
PaperCut WebDAV Vulnerability (CVE-2023-39143) (horizon3.ai)
: Comprehensive writeup on the PaperCut WebDAV vulnerability.
-
Opsec for Security Investigators by Cosive (cosive.com)
Essential operational security tips for professionals in the security field.
-
a new tool for detecting web shells.
g1thub13
-
In-depth analysis of a critical remote code execution vulnerability in MobSF.
-
Technical details of exploiting vulnerabilities in Chrome's V8 engine.
-
MSRC Security Report Analysis (gist.github.com)
A detailed examination of a security report from the Microsoft Security Response Center.
-
Paper-based Secret Sharing Technique - Sjlver/psst (github.com)
innovative approach to secret sharing using paper-based techniques. Explore on GitHub
-
SSH-Snake by MegaManSec (github.com)
A self-propagating, self-replicating, file-less script for automating SSH private key and host discovery. Explore on GitHub
-
Swarmsecurity/swarm (github.com)
The next generation of distributed cloud scanning and attack surface monitoring, evolved from Axiom. Explore on GitHub
-
Automate the importing of existing AWS resources into Terraform and outputs Terraform HCL code. Explore on GitHub
-
Secator by freelabz (github.com)
a unique tool in the realm of cybersecurity. Explore on GitHub
-
BypassFuzzer by intrudir (github.com)
A specialized tool for fuzzing 401/403/404 pages to discover bypass vulnerabilities. Explore on GitHub
-
Learn about low-level RASP techniques for protecting applications implemented in high-level programming languages. Explore on GitHub
-
PostMessage Logger - opnsec (github.com)
A simple Chrome extension for logging "postMessage" data, useful in security analysis. Explore on GitHub
-
Eval Villain: Discovering DOM XSS - swoops (github.com)
A Firefox Web Extension aimed at improving the discovery of DOM XSS vulnerabilities. Explore on GitHub
-
Damn Vulnerable LLM Agent - WithSecureLabs (github.com)
A repository dedicated to studying and understanding vulnerabilities in LLM agents. Explore on GitHub