Rosecurify

Seclog · Security Spotlight

Weekly curated security news, tweets, videos, and GitHub projects.

SECLOG #43

Spotlight: KeepnetLabs's Partnership with Pentesters, HTTP/2 ‘Rapid Reset’ DDoS attack, CURL (CVE-2023-38545), PyPI Malware Campaign, ZAP 2.14.0, etc.

SECLOG #42

Spotlight: IKEA Effect, Severity HIGH security problem of curl, Security is about data, DevSecOps with AI, GPU.zip ,CVE-2023-22515, etc.

SECLOG #41

Spotlight: Account Takeover of Internal Tesla Accounts, RCE in Chrome, I hacked macOS, security testing for WebSocket, SecDevOps or DevSecOps?, etc.

SECLOG #40

Spotlight: The bogus CVE problem, DevTunnels for C2, Finding things in JavaScript, web.Monitor, WS_RaceCondition_PoC, Linux Kernel a Process etc.

SECLOG #39

Spotlight: New Apple spyware, Zero-day Vulnerability Database, Docker for Pentest, Hacking GTA, URL parsers disagree, etc.

SECLOG #38

Spotlight: Hacking the Police, Bitlocker bypass on Lenovo, NCC's R1CS Implementation Review, Google Extensions etc.

SECLOG #37

OWASP Top 10 for Large Language Model Applications, Customer takeover in Shopify, Open Cybersecurity Schema Framework, Blocked by Cloudflare etc.

SECLOG #36

Spotlight: Websocket Pentesting with wsrepl, SVG Security Risks, New techniques Race conditions, XboxOneDirectoryTraversal, websocket_fuzzer etc.

SECLOG #35

Spotlight: Backdoor in TETRA Police Radios, How is Akamai blocking?, Find bugs with route-detect, LLM vulnerability scanner, saas-attacks etc.

SECLOG #34

Spotlight: How CodeQL works, Bundle Your Own Stealer, ShareFile RCE, RCE in Google Cloud Build, ORMs and Prepared Statements, etc.