Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Free Spins and Coins for Coin Master: Your Daily Dose
https://undercodenews.com/free-spins-and-coins-for-coin-master-your-daily-dose/
@Undercode_News
https://undercodenews.com/free-spins-and-coins-for-coin-master-your-daily-dose/
@Undercode_News
UNDERCODE NEWS
Free Spins and Coins for Coin Master: Your Daily Dose - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
#Airbnb Host's Plea Sparks Debate: Is It Too Much to Ask for Respect?
https://undercodenews.com/airbnb-hosts-plea-sparks-debate-is-it-too-much-to-ask-for-respect/
@Undercode_News
https://undercodenews.com/airbnb-hosts-plea-sparks-debate-is-it-too-much-to-ask-for-respect/
@Undercode_News
UNDERCODE NEWS
Airbnb Host's Plea Sparks Debate: Is It Too Much to Ask for Respect? - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Israel's Tech Titans: A Year of Record-Breaking Funding Rounds
https://undercodenews.com/israels-tech-titans-a-year-of-record-breaking-funding-rounds/
@Undercode_News
https://undercodenews.com/israels-tech-titans-a-year-of-record-breaking-funding-rounds/
@Undercode_News
UNDERCODE NEWS
Israel's Tech Titans: A Year of Record-Breaking Funding Rounds - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
The OmniBook Ultra Flip 14: A Worthy Successor to the Spectre x360
https://undercodenews.com/the-omnibook-ultra-flip-14-a-worthy-successor-to-the-spectre-x360/
@Undercode_News
https://undercodenews.com/the-omnibook-ultra-flip-14-a-worthy-successor-to-the-spectre-x360/
@Undercode_News
UNDERCODE NEWS
The OmniBook Ultra Flip 14: A Worthy Successor to the Spectre x360 - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
#Netflix Fined โฌ475 Million for Privacy Violations
https://undercodenews.com/netflix-fined-eur475-million-for-privacy-violations/
@Undercode_News
https://undercodenews.com/netflix-fined-eur475-million-for-privacy-violations/
@Undercode_News
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐จ #Ransomware Threat Looms Large: Funksec Targets US Sectors
https://undercodenews.com/ransomware-threat-looms-large-funksec-targets-us-sectors/
@Undercode_News
https://undercodenews.com/ransomware-threat-looms-large-funksec-targets-us-sectors/
@Undercode_News
UNDERCODE NEWS
Ransomware Threat Looms Large: Funksec Targets US Sectors - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ Emerging #Ransomware Group Funksec Targets Chilean Website
https://undercodenews.com/emerging-ransomware-group-funksec-targets-chilean-website/
@Undercode_News
https://undercodenews.com/emerging-ransomware-group-funksec-targets-chilean-website/
@Undercode_News
UNDERCODE NEWS
Emerging Ransomware Group Funksec Targets Chilean Website - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
โก๏ธ New #Ransomware Attack: Funksec Targets Brazilian Engineering Institution
https://undercodenews.com/new-ransomware-attack-funksec-targets-brazilian-engineering-institution/
@Undercode_News
https://undercodenews.com/new-ransomware-attack-funksec-targets-brazilian-engineering-institution/
@Undercode_News
UNDERCODE NEWS
New Ransomware Attack: Funksec Targets Brazilian Engineering Institution - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ก๏ธ Securing the Cloud: CISA Mandates Stricter Federal Cybersecurity
https://undercodenews.com/securing-the-cloud-cisa-mandates-stricter-federal-cybersecurity/
@Undercode_News
https://undercodenews.com/securing-the-cloud-cisa-mandates-stricter-federal-cybersecurity/
@Undercode_News
UNDERCODE NEWS
Securing the Cloud: CISA Mandates Stricter Federal Cybersecurity - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ฑ #Apple Seeks Chinese #AI Partners: #Tencent and #Bytedance in the Spotlight
https://undercodenews.com/apple-seeks-chinese-ai-partners-tencent-and-bytedance-in-the-spotlight/
@Undercode_News
https://undercodenews.com/apple-seeks-chinese-ai-partners-tencent-and-bytedance-in-the-spotlight/
@Undercode_News
UNDERCODE NEWS
Apple Seeks Chinese AI Partners: Tencent and Bytedance in the Spotlight - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ค The Memo-First Meeting Revolution: A Deep Dive
https://undercodenews.com/the-memo-first-meeting-revolution-a-deep-dive/
@Undercode_News
https://undercodenews.com/the-memo-first-meeting-revolution-a-deep-dive/
@Undercode_News
UNDERCODE NEWS
The Memo-First Meeting Revolution: A Deep Dive - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ ๏ธ Urgent Patch Required! Fortinet Warns of Critical Vulnerabilities in FortiWLM and FortiManager
https://undercodenews.com/urgent-patch-required-fortinet-warns-of-critical-vulnerabilities-in-fortiwlm-and-fortimanager/
@Undercode_News
https://undercodenews.com/urgent-patch-required-fortinet-warns-of-critical-vulnerabilities-in-fortiwlm-and-fortimanager/
@Undercode_News
UNDERCODE NEWS
Urgent Patch Required! Fortinet Warns of Critical Vulnerabilities in FortiWLM and FortiManager - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆ๐๐ฅ๐๐ฏ๐๐ญ๐ ๐๐จ๐ฎ๐ซ ๐๐๐๐ก ๐๐จ๐ฎ๐ซ๐ง๐๐ฒ: ๐๐ฌ๐ฌ๐๐ง๐ญ๐ข๐๐ฅ ๐๐๐ฌ๐จ๐ฎ๐ซ๐๐๐ฌ ๐๐จ๐ซ ๐๐ซ๐จ๐ฐ๐ญ๐ก ๐๐ง๐ ๐๐๐ซ๐ญ๐ข๐๐ข๐๐๐ญ๐ข๐จ๐ง ๐๐ฎ๐๐๐๐ฌ๐ฌ
Whether youโre looking to break into tech, grow your expertise, or prepare for certifications, use these resources to help you level up:
๐ฏ Microsoft Learn: https://lnkd.in/ge973G3j
Explore interactive, self-paced modules on Azure, Microsoft 365, Power Platform, and more.
๐ฏ Microsoft Virtual Training Days: https://lnkd.in/g2B_2Yq3
Free, instructor-led events with opportunities to earn free certification exam vouchers!
๐ฏ GitHub Learning Lab: https://lab.github.com/
Dive into Git basics, open-source contributions, and DevOps workflows.
๐ฏ Microsoft Educator Center: https://lnkd.in/gFcX5xdm
Focused on education technology, this resource is excellent for educators learning Teams and Office 365 tools.
๐ฏ Azure DevOps Labs: https://lnkd.in/gi4uekjB
Get practical experience with CI/CD pipelines, infrastructure as code, and governanceโall for free!
๐ฏ AI for Good & Responsible AI Training: https://lnkd.in/gtXfexiY
Learn about cutting-edge AI applications and ethical AI practices.
Ref: Mohamad Hamadi
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Whether youโre looking to break into tech, grow your expertise, or prepare for certifications, use these resources to help you level up:
๐ฏ Microsoft Learn: https://lnkd.in/ge973G3j
Explore interactive, self-paced modules on Azure, Microsoft 365, Power Platform, and more.
๐ฏ Microsoft Virtual Training Days: https://lnkd.in/g2B_2Yq3
Free, instructor-led events with opportunities to earn free certification exam vouchers!
๐ฏ GitHub Learning Lab: https://lab.github.com/
Dive into Git basics, open-source contributions, and DevOps workflows.
๐ฏ Microsoft Educator Center: https://lnkd.in/gFcX5xdm
Focused on education technology, this resource is excellent for educators learning Teams and Office 365 tools.
๐ฏ Azure DevOps Labs: https://lnkd.in/gi4uekjB
Get practical experience with CI/CD pipelines, infrastructure as code, and governanceโall for free!
๐ฏ AI for Good & Responsible AI Training: https://lnkd.in/gtXfexiY
Learn about cutting-edge AI applications and ethical AI practices.
Ref: Mohamad Hamadi
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆ๐๐จ๐ฐ ๐๐ญ๐ญ๐๐๐ค๐๐ซ๐ฌ ๐๐๐๐ค ๐๐/๐๐ ๐๐ข๐ฉ๐๐ฅ๐ข๐ง๐๐ฌ ๐
I recently watched one of DEFCON's talk of this year "Your CI CD Pipeline Is Vulnerable, But It's Not Your Fault" by Elad Pticha, Oreen Livni and was really impressed by the attack vector (link in comments)
๐๐๐ญ'๐ฌ ๐ฌ๐๐ ๐ก๐จ๐ฐ ๐ข๐ญ ๐ฐ๐จ๐ซ๐ค๐ฌ
Github workflows are part of the CI/CD (Continous Integration/Continous Deployment) ecosystem that lets developers automate their workflow
For example: once a commit is made to the repo -> the code is scanned with a tool -> if the tests pass -> code is pushed to test/production
Now the interesting part is that (if the repo maintainer uses input that you control) inside the workflow, this can lead to command injection in the pipeline
๐๐ก๐ข๐๐ก ๐ฆ๐๐๐ง๐ฌ ๐ฒ๐จ๐ฎ ๐ฆ๐๐ฒ ๐๐ ๐๐๐ฅ๐ ๐ญ๐จ ๐ญ๐๐ค๐ ๐จ๐ฏ๐๐ซ ๐ญ๐ก๐ ๐ซ๐๐ฉ๐จ
In the example bellow, the pipeline uses the title of an issue as part of a bash echo command
That means anyone can create a issue named $(๐ฐ๐ก๐จ๐๐ฆ๐ข) and execute commands in the CI/CD
If you can do that -> you can abuse the command injection to steal the repo's Github token, read secrets or push malicious code
Ref: Andrei Agape
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
I recently watched one of DEFCON's talk of this year "Your CI CD Pipeline Is Vulnerable, But It's Not Your Fault" by Elad Pticha, Oreen Livni and was really impressed by the attack vector (link in comments)
๐๐๐ญ'๐ฌ ๐ฌ๐๐ ๐ก๐จ๐ฐ ๐ข๐ญ ๐ฐ๐จ๐ซ๐ค๐ฌ
Github workflows are part of the CI/CD (Continous Integration/Continous Deployment) ecosystem that lets developers automate their workflow
For example: once a commit is made to the repo -> the code is scanned with a tool -> if the tests pass -> code is pushed to test/production
Now the interesting part is that (if the repo maintainer uses input that you control) inside the workflow, this can lead to command injection in the pipeline
๐๐ก๐ข๐๐ก ๐ฆ๐๐๐ง๐ฌ ๐ฒ๐จ๐ฎ ๐ฆ๐๐ฒ ๐๐ ๐๐๐ฅ๐ ๐ญ๐จ ๐ญ๐๐ค๐ ๐จ๐ฏ๐๐ซ ๐ญ๐ก๐ ๐ซ๐๐ฉ๐จ
In the example bellow, the pipeline uses the title of an issue as part of a bash echo command
That means anyone can create a issue named $(๐ฐ๐ก๐จ๐๐ฆ๐ข) and execute commands in the CI/CD
If you can do that -> you can abuse the command injection to steal the repo's Github token, read secrets or push malicious code
Ref: Andrei Agape
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ป #AMD's RX 7900 GRE: A Short-Lived Graphics Card Champion
https://undercodenews.com/amds-rx-7900-gre-a-short-lived-graphics-card-champion/
@Undercode_News
https://undercodenews.com/amds-rx-7900-gre-a-short-lived-graphics-card-champion/
@Undercode_News
UNDERCODE NEWS
AMD's RX 7900 GRE: A Short-Lived Graphics Card Champion - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Pornhub to Exit Florida Due to Strict Age Verification Laws
https://undercodenews.com/pornhub-to-exit-florida-due-to-strict-age-verification-laws/
@Undercode_News
https://undercodenews.com/pornhub-to-exit-florida-due-to-strict-age-verification-laws/
@Undercode_News
UNDERCODE NEWS
Pornhub to Exit Florida Due to Strict Age Verification Laws - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Generalist Advantage: Why a Broad Perspective Trumps Specialization
https://undercodenews.com/generalist-advantage-why-a-broad-perspective-trumps-specialization/
@Undercode_News
https://undercodenews.com/generalist-advantage-why-a-broad-perspective-trumps-specialization/
@Undercode_News
UNDERCODE NEWS
Generalist Advantage: Why a Broad Perspective Trumps Specialization - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ฎ Alienware m16 RTX 4070 #Gaming #Laptop: A Black Friday Deal Worth Recapturing
https://undercodenews.com/alienware-m16-rtx-4070-gaming-laptop-a-black-friday-deal-worth-recapturing/
@Undercode_News
https://undercodenews.com/alienware-m16-rtx-4070-gaming-laptop-a-black-friday-deal-worth-recapturing/
@Undercode_News
UNDERCODE NEWS
Alienware m16 RTX 4070 Gaming Laptop: A Black Friday Deal Worth Recapturing - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from Exploiting Crew (Pr1vAt3)
1734579716223.pdf
491.1 KB