g3n3r4l22
-
LOTP - Living Off the Pipeline (boostsecurityio.github.io)
strategies for software development without a traditional CI/CD pipeline.
-
pico.sh (pico.sh)
minimalistic, server-side scripting environment for streamlined web development.
-
AI's Best Friend eBook by Robert Hansen (amazon.com)
Dive into the evolving relationship between AI and humans in this insightful eBook.
-
De-google-ify Internet (degooglisons-internet.org)
Learn about initiatives to reduce reliance on Google's ecosystem for a more diversified internet.
-
Learn and Test DMARC (dmarctester.com)
Enhance email security and prevent phishing with DMARC testing tools.
-
We Hacked Google A.I. for $50,000 - Lupin & Holmes (landh.tech)
An account of how Lupin & Holmes successfully hacked Google's AI, claiming a $50,000 reward.
-
Kali Linux 2024.1 Release (Micro Mirror) (kali.org)
Announcement and details about the latest release of Kali Linux, version 2024.1.
-
Official playbooks from CISA for responding to cybersecurity incidents and vulnerabilities.
-
Exploiting CSP Wildcards for Google Domains (attackshipsonfi.re)
A technical exploration of exploiting CSP (Content Security Policy) wildcards in Google domains.
-
Security: Arbitrary JavaScript Code Execution in "devtools://devtools" - Chromium (issues.chromium.org)
A security report detailing how attackers can execute arbitrary JavaScript code in a privileged Chromium origin.
-
Unauthenticated Email Enumeration via API Fuzzing - Jineesh AK (jineeshak.github.io)
An exploration of how API fuzzing can be used to enumerate email addresses without authentication.
-
A case study on monitoring a Russian bank using open-source internet routing tools.
-
Preventing AWS Subdomain Takeover - Sena Yakut (senayakut.com)
Strategies and case studies for enhancing security and preventing AWS subdomain takeover.
-
Session Timeout Vulnerabilities & Extension - Burp Suite (whiteoaksecurity.com)
Discussion of vulnerabilities related to session timeouts and how to extend sessions using Burp Suite.
-
V8 Sandbox - External Pointer Sandboxing - Google Docs (docs.google.com)
A document detailing the sandboxing of external pointers in the V8 JavaScript engine.
-
An analysis of Attribute-Based Access Control (ABAC) on AWS as of 2024.
-
Joomla: Multiple XSS Vulnerabilities - Sonar (sonarsource.com)
A report on multiple XSS vulnerabilities introduced by a PHP bug in Joomla.
-
Server-Side Prototype Pollution Gadgets Scanner - Doyensec's Blog (blog.doyensec.com)
Introduction of a scanner for detecting server-side prototype pollution gadgets.
-
Monitor Certificate Expiry via RSS - Raphting (raphting.dev)
A guide on monitoring SSL/TLS certificate expiry using RSS feeds.
-
Type Confusion in V8 WebAssembly Leading to RCE - Chromium (issues.chromium.org)
A security issue in V8 WebAssembly that could lead to remote code execution.
-
Advanced Fuzzing Techniques Applied to cURL - Trail of Bits Blog (blog.trailofbits.com)
An overview of how advanced fuzzing techniques were applied to the cURL tool.
-
MeshCentral Cross-Site Websocket Hijacking Vulnerability (praetorian.com)
Examine the cross-site WebSocket hijacking vulnerability in MeshCentral.
X1
-
X: Discussing "LockBit releases a long read of what happened."
y0utube2
-
The 5 Week Program: IDOR Q&A + Labs (youtube.com)
A comprehensive guide and Q&A on IDOR vulnerabilities, accompanied by practical labs. Watch Here
-
Exploring the integration of cybersecurity and insurance through the journey of Cysurance. Watch Here
g1thub4
-
beigeworm/BadUSB-Files-For-FlipperZero (github.com)
A collection of over 60 scripts tailored for the BadUSB function on FlipperZero. Explore on GitHub
-
moom825/xeno-rat (github.com)
Xeno-RAT, a comprehensive open-source remote access tool developed in C, featuring HVNC, live microphone, reverse proxy, and more. Explore on GitHub
-
sea-erkin/log-snare (github.com)
LogSnare, a versatile tool for testing, preventing, and logging IDOR vulnerabilities. Explore on GitHub
-
latiotech/LAST (github.com)
Utilize AI to scan your code for security issues and code smells from the command line. Explore on GitHub