g3n3r4l16
-
Read More (brokencloudstorage.info)
End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem - An analysis of the current state of encrypted cloud storage solutions.
-
Read More (blog.doyensec.com)
Class Pollution in Ruby: A Deep Dive into Exploiting Recursive Merges - Exploring security vulnerabilities in Ruby's recursive merge operations.
-
Read More (outpost24.com)
Exploiting trust: Weaponizing permissive CORS configurations - Examining the security risks associated with overly permissive CORS settings.
-
Read More (cloud.google.com)
Google Cloud launches new Vulnerability Rewards Program - Details on Google Cloud's initiative to enhance security through bug bounties.
-
Read More (blog.quarkslab.com)
Exploiting Microsoft Teams on macOS during a Purple Team engagement - A case study on uncovering vulnerabilities in Microsoft Teams for macOS.
-
Read More (citizenlab.ca)
Should We Chat, Too? Security Analysis of WeChat's MMTLS Encryption Protocol - An in-depth look at the security measures in WeChat's encryption protocol.
-
Read More (issues.chromium.org)
Sandbox escape from extensions due to insufficient checks in Chrome - Details on a security vulnerability in Chrome's extension system.
-
Read More (ostif.org)
Node.js fuzzing audit - Comprehensive security audit report for Node.js.
-
Read More (invictus-ir.com)
Cloud native incident response in AWS - Part II - Strategies for handling security incidents in AWS environments.
-
Read More (github.blog)
3 ways to get Remote Code Execution in Kafka UI - Exploring vulnerabilities in Kafka UI that could lead to RCE.
-
Read More (fortinet.com)
Burning Zero Days: Suspected Nation-State Adversary Targets Ivanti CSA - Analysis of a sophisticated attack on Ivanti Connect Secure Appliance.
-
Read More (rhinosecuritylabs.com)
CloudGoat: New Scenario and Walkthrough (sns\secrets) - A new AWS security scenario for training purposes.
-
Read More (securityrunners.io)
Turning AWS Documentation into Gold: AI-Assisted Security Research - Leveraging AI for more effective AWS security research.
-
Read More (blackwinghq.com)
Finding Vulnerability Variants at Scale - Techniques for identifying similar vulnerabilities across large codebases.
-
Read More (redops.at)
Cobalt Strike - CDN / Reverse Proxy Setup - Guide on setting up Cobalt Strike with CDN and reverse proxy.
-
Tahribat.com (tahribat.com)
Interview with Aytek -HolyOne- Üstündağ, Founder of - An in-depth conversation with the creator of a prominent Turkish hacking and security forum. Watch Here
X3
-
Read More (@fs0c131y)
Baptiste Robert on the arrest of "USDoD" - OSINT breakdown of how a famous hacker's identity was uncovered.
-
Read More (@mixedenn)
Denis Shilov on GPT-4 jailbreak - Sharing a simple method to bypass GPT-4 content restrictions.
-
Read More (@webtonull)
Erlend Oftedal on WiFi Pineapple XSS - Recounting an XSS vulnerability discovery in WiFi Pineapple's admin GUI.
y0utube1
-
DEF CO (youtube.com)
N 32 - Winning the Game of Active Directory - Brandon Colley's presentation on Active Directory security strategies. Watch Here
g1thub4
-
Explore on GitHub (github.com)
adanalvarez/TrailDiscover - A repository of CloudTrail events with detailed security insights.
-
Explore on GitHub (github.com)
anchore/syft - CLI tool for generating Software Bill of Materials from container images and filesystems.
-
Explore on GitHub (github.com)
mllamazares/vulncov - Tool to correlate Semgrep scans with Python test coverage for prioritizing SAST findings.
-
Explore on GitHub (github.com)
protectai/vulnhuntr - Zero-shot vulnerability discovery using LLMs.