Freshly patched RCE in PHP-FPM:
https://bugs.php.net/bug.php?id=78599
Exploit:
https://github.com/neex/phuip-fpizdam
Many nginx+PHP configurations vulnerable, watch out!
https://bugs.php.net/bug.php?id=78599
Exploit:
https://github.com/neex/phuip-fpizdam
Many nginx+PHP configurations vulnerable, watch out!
GitHub
GitHub - neex/phuip-fpizdam: Exploit for CVE-2019-11043
Exploit for CVE-2019-11043. Contribute to neex/phuip-fpizdam development by creating an account on GitHub.
A flaw in PMx Driver can give hackers full access to a device
https://ift.tt/2pc7w1k
https://ift.tt/2pc7w1k
Security Affairs
A flaw in PMx Driver can give hackers full access to a device
Eclypsium experts found a vulnerability affecting a popular Intel driver that can give malicious actors deep access to a device.
Exploiting Intel’s Management Engine – Part 1: Understanding PT’s TXE PoC (INTEL-SA-00086)
https://ift.tt/2CJlWsY
https://ift.tt/2CJlWsY
New Hacking Group Using Metasploit To Install Backdoor Malware On Windows By Exploiting MS Office
https://gbhackers.com/new-hacking-group/
https://gbhackers.com/new-hacking-group/
GBHackers On Security
New Hacking Group Install Backdoor On Windows By Exploiting MS Office
Researchers detect a wave of malware campaigns from a new hacking group named TA2101 that targeting various organizations in German and Italy.
Introducing Merlin — A cross-platform post-exploitation HTTP/2 Command & Control Tool
https://ift.tt/2oLAhRp
https://ift.tt/2oLAhRp
Medium
Introducing Merlin — A cross-platform post-exploitation HTTP/2 Command & Control Tool
tl;dr Evade network detection during a penetration test/red team exercise by using a protocol that existing tools aren’t equipped to…
HackerOne is looking for Mobile Security Engineer
//I would never thought I would post job offere in here, but this might help someone to move further in Mobile infosec field
https://jobs.lever.co/hackerone/316d0fbd-cf24-41be-a3e2-5180f62f3658
//I would never thought I would post job offere in here, but this might help someone to move further in Mobile infosec field
https://jobs.lever.co/hackerone/316d0fbd-cf24-41be-a3e2-5180f62f3658
Android StrandHogg vulnerability
Vulnerability allows malicious app to masquerade as any other app on the device.
So, if you launch Facebook, malware is executed.
https://promon.co/security-news/strandhogg/
Video demo: https://twitter.com/LukasStefanko/status/1201597521560244225
Vulnerability allows malicious app to masquerade as any other app on the device.
So, if you launch Facebook, malware is executed.
https://promon.co/security-news/strandhogg/
Video demo: https://twitter.com/LukasStefanko/status/1201597521560244225
Burp Suite Secret Finder - Burp Suite Extension To Discover Apikeys/Tokens From HTTP Response
https://ift.tt/34LHNwt
https://ift.tt/34LHNwt
KitPloit - PenTest & Hacking Tools
Burp Suite Secret Finder - Burp Suite Extension To Discover Apikeys/Tokens From HTTP Response
StrongSalt Eases Pain of Searching Encrypted Data in the Cloud
http://feedproxy.google.com/~r/Securityweek/~3/2hBd0XFlT5g/strongsalt-eases-pain-searching-encrypted-data-cloud
StrongSalt Helps Customers Gain Compliance Through Searchable Encryption for Cloud Services and Enterprise Applications
read more
(https://www.securityweek.com/strongsalt-eases-pain-searching-encrypted-data-cloud)
http://feedproxy.google.com/~r/Securityweek/~3/2hBd0XFlT5g/strongsalt-eases-pain-searching-encrypted-data-cloud
StrongSalt Helps Customers Gain Compliance Through Searchable Encryption for Cloud Services and Enterprise Applications
read more
(https://www.securityweek.com/strongsalt-eases-pain-searching-encrypted-data-cloud)
Securityweek
StrongSalt Eases Pain of Searching Encrypted Data in the Cloud | SecurityWeek.Com
StrongSalt has developed a Privacy API platform to make it easy to implement searchable encryption to any app using any storage for any company.
#Adobe #ZeroDay patch
https://www.zdnet.com/google-amp/article/adobe-patches-17-critical-code-execution-bugs-in-photoshop-reader-brackets/
https://www.zdnet.com/google-amp/article/adobe-patches-17-critical-code-execution-bugs-in-photoshop-reader-brackets/
ZDNET
Adobe patches 17 critical code execution bugs in Photoshop, Reader, Brackets
Other vulnerabilities resolved include privilege escalation and information leaks.