g3n3r4l12
-
Owning a Bitcoin ATM (labs.ioactive.com)
Security analysis of Bitcoin ATMs, discussing vulnerabilities and implications.
-
Rook to XSS: How I hacked (skii.dev)
chess.com with a rookie exploit - A detailed case study of exploiting a cross-site scripting vulnerability on a popular website.
-
Attack of the week: Airdrop tracing (blog.cryptographyengineering.com)
Exploration of security flaws in airdrop technology and their potential impacts.
-
Gambio 4.9.2.0 - Insecure Deserialization (herolab.usd.de)
\- Technical breakdown of a specific security vulnerability.
-
An overview of the current threats in cloud computing.
-
Top 10 web hacking techniques of 2023 - PortSwigger (portswigger.net)
Review of the most influential web hacking methods of the past year.
-
Analysis of a critical vulnerability found in Opera's browser.
-
Ivanti vulnerabilities - recap - Koen Van Impe (vanimpe.eu)
A recap of recent vulnerabilities discovered in Ivanti products.
-
Yin Yang Metaphor of DNS Privacy (ekremcelikel.medium.com)
Discussion on the balance between DNS functionality and privacy.
-
CVE-2023-5480: Chrome new XSS Vector - Slonser Notes (blog.slonser.info)
Examination of a new XSS vector found in Chrome.
-
Bypassing browser tracking protection for CORS misconfiguration abuse (swarm.ptsecurity.com)
Insights into how CORS misconfigurations can be exploited.
-
GitLab Critical Security Release: 16.8.1, 16.7.4, 16.6.6, 16.5.8 (about.gitlab.com)
Information on critical security updates for GitLab.
X1
-
Massimo on X (@Rainmaker1973)
Tweet about a tool for replicating keys without the original. View Tweet
y0utube1
-
Securing CI/CD Runners Through eBPF Agent (youtube.com)
A video discussing the security of CI/CD runners using eBPF Agent. Watch Here
g1thub6
-
kondukto-io/kntrl (github.com)
An eBPF based CI/CD security tool. Explore on GitHub
-
horizon3ai/CVE-2024-0204 (github.com)
Authentication Bypass in GoAnywhere MFT. Explore on GitHub
-
RedTeamPentesting/pretender (github.com)
A tool for relaying attacks featuring multiple spoofing techniques. Explore on GitHub
-
kunai-project/kunai (github.com)
A threat-hunting tool for Linux. Explore on GitHub
-
ACK-J/postMessage-tracker-firefox (github.com)
A Firefox Extension for tracking postMessage usage. Explore on GitHub
-
nicocha30/ligolo-ng (github.com)
An advanced tunneling/pivoting tool using a TUN interface. Explore on GitHub