■■■■□ HttpDoom - A Tool For Response-Based Inspection Of Websites Across A Large Amount Of Hosts For Quickly Gaining An Overview Of HTTP-based Attack Surface.
https://github.com/filipi86/httpdoom
https://github.com/filipi86/httpdoom
GitHub
GitHub - filipi86/httpdoom: HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly…
HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly gaining an overview of HTTP-based attack surface. - filipi86/httpdoom
■■■■■ (POC) Remove any Facebook’s live video ($14,000 bounty) | by Ahmad Talahmeh | Apr, 2021.
https://infosecwriteups.com/poc-remove-any-facebooks-live-video-14-000-bounty-70c8135b7b4c
https://infosecwriteups.com/poc-remove-any-facebooks-live-video-14-000-bounty-70c8135b7b4c
Medium
(POC) Remove any Facebook’s live video ($14,000 bounty)
Description / Impact
■□□□□ Pakistan 🇵🇰 shut down several social networks within its borders last Friday but lifted the ban after around four hours.
https://mobile.twitter.com/PTAofficialpk/status/1382963881979482112
https://www.theregister.com/2021/04/19/pakistan_brief_social_media_ban/
https://mobile.twitter.com/PTAofficialpk/status/1382963881979482112
https://www.theregister.com/2021/04/19/pakistan_brief_social_media_ban/
Twitter
PTA
Press Release: In order to maintain public order and safety, access to certain social media applications has been restricted temporarily.
■■□□□ Interesting thread: https://mobile.twitter.com/sec_r0/status/1381645790263697411
Twitter
Rohit
🚨🥳😍#SecurityZine - Day 1/30 SQLi leads to Auth Bypass, info disclosure, tamper existing data and much more. Learn SQli through the Zine landing on 14th, and guess what it will be free and under pay as u wish. #SqlInjection #infosec #security #appsec #webdev…
■■□□□ Command to extract all endpoints from a JS File.
cat files.txt | grep -aoP "(?<=(\"|\'|`))\/[a-zA-Z0-9?&=\/-#.](?=(\"|\'|`))" | sort -u | tee output.txt
■□□□□ Almost all XSS Payloads / brute-force list for quick results.
https://github.com/irfan-knr/KNR-XSS-Payloads
https://github.com/irfan-knr/KNR-XSS-Payloads
■□□□□ Interesting Thread: https://mobile.twitter.com/Aamer_Sha/status/1384077678941073408
Twitter
Aamer Shah 🐦
Google Chrome Zeroday. Type: Escalation of Privilege Severity: Medium / Low Google chose not to fix. The bug exists in all chromium based browsers (including v92 Chrome) except 'Samsung Internet' that choose to patch it after my report in 2018 (SVE-2018-11602).
■□□□□ Malware Spreads Via Xcode Projects Now Targeting Apple's M1-based Macs.
https://thehackernews.com/2021/04/malware-spreads-via-xcode-projects-now.html
https://thehackernews.com/2021/04/malware-spreads-via-xcode-projects-now.html
■■■□□ Grype – Vulnerability Scanner For Container Images & Filesystems.
https://github.com/anchore/grype
https://github.com/anchore/grype
GitHub
GitHub - anchore/grype: A vulnerability scanner for container images and filesystems
A vulnerability scanner for container images and filesystems - anchore/grype
■□□□□ Google Trumpets New Mobile App Security Standard.
https://www.infosecurity-magazine.com:443/news/google-trumpets-new-mobile-app/
https://www.infosecurity-magazine.com:443/news/google-trumpets-new-mobile-app/
Infosecurity Magazine
Google Trumpets New Mobile App Security Standard
Google Trumpets New Mobile App Security Standard. Tech giant encourages developers to get on board
■■□□□ Vulnerability Spotlight: Remote code execution vulnerabilities in Cosori smart air fryer.
https://blog.talosintelligence.com/2021/04/vuln-spotlight-co.html
https://blog.talosintelligence.com/2021/04/vuln-spotlight-co.html
Cisco Talos
Vulnerability Spotlight: Remote code execution vulnerabilities in Cosori smart air fryer
Dave McDaniel of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw. Update (April 27, 2021): Cosori has released an update for this product that fixes these two vulnerabilities. Cisco Talos recently discovered two code execution vulnerabilities…
■■■□□ Cypheroth - Automated, Extensible Toolset That Runs Cypher Queries Against Bloodhound's Neo4j Backend And Saves Output To Spreadsheets.
https://github.com/seajaysec/cypheroth
https://github.com/seajaysec/cypheroth
GitHub
GitHub - seajaysec/cypheroth: Automated, extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves…
Automated, extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves output to spreadsheets. - seajaysec/cypheroth
■□□□□ Data-Leak: Geico data breach exposed customers' driver's license numbers.
https://www.bleepingcomputer.com/news/security/geico-data-breach-exposed-customers-drivers-license-numbers/
https://www.bleepingcomputer.com/news/security/geico-data-breach-exposed-customers-drivers-license-numbers/
BleepingComputer
Geico data breach exposed customers' driver's license numbers
Car insurance provider Geico has suffered a data breach where threat actors stole the driver's licenses for policyholders for over a month.
■□□□□ United States: The US 🇺🇸 government's response groups for dealing with recent SolarWinds and Microsoft Exchange vulnerabilities have reached the end of the road.
https://www.theregister.com/2021/04/19/federal_solarwinds_investigation/
https://www.theregister.com/2021/04/19/federal_solarwinds_investigation/
The Register
Who knew Uncle Sam had strike teams for SolarWinds, Exchange flaws? Well, anyway, they are disbanded
Lessons learned and mission accomplished, apparently
■■■■■ North Korea 🇰🇵: Lazarus APT Hackers are now using BMP images to hide RAT malware.
https://thehackernews.com/2021/04/lazarus-apt-hackers-are-now-using-bmp.html
https://thehackernews.com/2021/04/lazarus-apt-hackers-are-now-using-bmp.html
■□□□□ KubiScan - A Tool To Scan Kubernetes Cluster For Risky Permissions.
https://github.com/cyberark/KubiScan
https://github.com/cyberark/KubiScan
GitHub
GitHub - cyberark/KubiScan: A tool to scan Kubernetes cluster for risky permissions
A tool to scan Kubernetes cluster for risky permissions - cyberark/KubiScan
■□□□□ Mobile malware analysis.
https://blog.nviso.eu/2021/04/19/how-to-analyze-mobile-malware-a-cabassous-flubot-case-study
https://blog.nviso.eu/2021/04/19/how-to-analyze-mobile-malware-a-cabassous-flubot-case-study
NVISO Labs
How to analyze mobile malware: a Cabassous/FluBot Case study
This blogpost explains all the steps I took while analyzing the Cabassous/FluBot malware. I wrote this while analyzing the sample and I’ve written down both successful and failed attempts at …
■□□□□ Internal Facebook email reveals intent to frame data scraping as ‘normalized, broad industry issue’.
https://www.zdnet.com/article/facebook-internal-email-reveals-intent-to-frame-data-scraping-as-broad-industry-issue-and-normalized
https://www.zdnet.com/article/facebook-internal-email-reveals-intent-to-frame-data-scraping-as-broad-industry-issue-and-normalized
ZDNET
Internal Facebook email reveals intent to frame data scraping as ‘normalized, broad industry issue’
Updated: More scraping incidents are "expected" in the future.