g3n3r4l18
-
The CloudSec Engineer (engineer.cloudsecbooks.com)
Resources and articles for cloud security engineers. -
-
Entities allowed between function calls - Shazzer (shazzer.co.uk)
Analysis of security implications of entities allowed between function calls. -
-
Putting the C2 in C2loudflare | JUMPSEC LABS (labs.jumpsec.com)
An exploration of using Cloudflare for C2 infrastructure. -
-
Why I attack (nicholas.carlini.com)
Insights into the motivations behind security attacks. -
-
The security prioritization paradox (beaglesecurity.substack.com)
Discussing the challenges in prioritizing security tasks. -
-
Hacking Amazon's eero 6 (part 2) | Markuta (markuta.com)
Part two of the series on hacking Amazon's eero 6. -
-
17 vulnerabilities in Sharp Multi-Function Printers - IT Security Research by Pierre (pierrekim.github.io)
Detailed analysis of vulnerabilities in Sharp printers. -
-
Exploiting GCP Cloud Build for Privilege Escalation (blog.pwnedlabs.io)
Techniques for escalating privileges in GCP Cloud Build. -
-
Polyfill.io (threatmon.io)
Supply Chain Attack: How Over 100,000 Websites Were Compromised and What You Need to Know - ThreatMon Blog - Examination of a significant supply chain attack. -
-
Announcement of Reddit's bug bounty program. -
-
Holograph exploited for more than $1.2 million (web3isgoinggreat.com)
Details on the Holograph exploit incident. -
-
Techniques for cache breaking and RBAC bypass. -
-
Publicly Exposed AWS SSM Command Documents – High Signal Security – YAIB (Yet Another Infosec blog) (ramimac.me)
Discussion on exposed AWS SSM command documents. -
-
Project Zero: Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models (googleprojectzero.blogspot.com)
Evaluating LLMs for offensive security. -
-
Zip Slip meets Artifactory: A Bug Bounty Story | Karma(In)Security (karmainsecurity.com)
Bug bounty story involving Zip Slip and Artifactory. -
-
1-click Exploit in South Korea's biggest mobile chat app | stulle123's Blog (stulle123.github.io)
Account takeover exploit in KakaoTalk. -
-
Kubernetes Cluster Security - Nuclei Templates v9.9.0 🎉 (blog.projectdiscovery.io)
Latest templates for Kubernetes security. -
-
Under the Hood: Exploring the Architecture and Security Risks of Large Language Models (docs.google.com)
Presentation on the security risks of LLMs. -
g1thub4
-
A tool to prevent subdomain takeover. - Explore on GitHub
-
Trigii/MacHawkEye: Engine for analyzing binaries on macOS systems to identify potential vulnerabilities (github.com)
Tool for analyzing macOS binaries for vulnerabilities. - Explore on GitHub
-
WiFi Rubber Ducky with a web interface. - Explore on GitHub
-
Security best practices for implementing ChatGPT in web applications. - Explore on GitHub