Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Course Club
[Cybrary] 12 Competencies of the Effective CISO [Career Path]

https://courseclub.me/wp-content/uploads/2021/04/785412541.jpg
https://courseclub.me/wp-content/uploads/2021/04/785412541.jpg
Learn the technical, management, and business competencies required to become an effective CISO in the 21st century

About this Career Path

Dr. Edward G. Amoroso, CEO of TAG Cyber and former CISO of AT&T develops insights into the twelve technical, management, and business competencies that are required to serve as an effective Chief Information Security Officer (CISO).

Courses

• CISO Competency – Innovation
• CISO Competency – Finance & Administration
• CISO Competency – Business
• CISO Competency – Security
• CISO Competency – Discretion
• CISO Competency – Public Speaking
• CISO Competency – Productivity
• CISO Competency – Technology
• CISO Competency – Threats
• CISO Competency – Compliance
• CISO Competency – Risk
• CISO Competency – Leadership

These competencies are also shown to provide an excellent career development and learning roadmap for anyone desiring advancement in the enterprise security management field. Lectures address the twelve insights with invited experts from the field offering their key insights and advice for participants.

Learning Objectives Participants will develop the valuable insights and insider knowledge necessary to support (1) optimizing career success and performance in their current enterprise security management or leadership role, and/or (2) increasing their chances of successful promotion to a senior leadership position, including the CISO role, within their present or future organization.

Target Participants The course is designed for working practitioners of enterprise security, at all possible stages of career growth, within business or government environments, who are either currently in management and leadership roles, or who aspire to improve their chances of promotion into executive roles, such as CISO.

The Competencies: Innovation Finance & Administration Business Operations Cybersecurity Expertise Discretion & Trust Public Speaking Personal Productivity Information Technology Threat Insights Balancing Compliance Risk Orientation Team Leadership and Vision

About Cybrary.It

Cybrary is a growing community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Size: 4.31 GB

Download Now

https://www.cybrary.it/catalog/career-path/12-competencies-of-the-effective-ciso/.

The post [Cybrary] 12 Competencies of the Effective CISO [Career Path] appeared first on Course Club.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Story of a Basic CSRF Vulnerability

https://cdn-images-1.medium.com/max/1200/1*QLJPykCtpFg2pf_61ITtKQ.jpeg
This article is about a simple CSRF vulnerability I found, I am going to discuss how I found it and share my POC. Cross-Site Request…

Continue reading on Medium »
Red Team Tactics:
1. As-Exploits 404Team
https://github.com/yzddmr6/As-Exploits
2. MS External Email Warning Bypass
https://whynotsecurity.com/blog/external-email-warning-bypass

Threat Research:
1. Zero-Day Exploits in SonicWall Email Security Lead to Enterprise Compromise
https://www.fireeye.com/blog/threat-research/2021/04/zero-day-exploits-in-sonicwall-email-security-lead-to-compromise.html
2. RCE in Homebrew by compromising the official Cask repository
https://blog.ryotak.me/post/homebrew-security-incident-en

CVE-2021-26415:
Windows Installer Elevation of Privilege Vulnerability (PoC)
https://www.cloaked.pl/2021/04/cve-2021-26415

exploit
CVE-2021-22893:
PoC script to exploit Pulse Secure VPNs
https://github.com/ZephrFish/CVE-2021-22893

Cloud Security:
Azure Application Proxy C2
https://www.trustedsec.com/blog/azure-application-proxy-c2
]-> AppProxyC2 PoC:
https://github.com/xpn/appproxyc2

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x
(x86/x86_64, ARM64)
https://github.com/m0nad/Diamorphine

___________________________

@hacking_Attack

@Hacking_Video
___________________________
#docker #privesc #enum

Docker Enumeration, Escalation of Privileges and Container Escapeshttps://github.com/stealthcopter/deepce

___________________________

@hacking_Attack

@Hacking_Video
___________________________
#pentest #api #cheatsheet

Bringing order to API hacking chaoshttps://dsopas.github.io/MindAPI/play/

___________________________

@hacking_Attack

@Hacking_Video
___________________________
hacking: security in practice
Can a FB restriction be removed by hacking?

Eng is not my native language so sorry for any typo

I know barely nothing 'bout hacking and honestly find the Facebook bot really annoying. I got several red flags from it because my posts "didn't follow the rules" but most of the times the post/comment was out of context (they erased a post about artistic nude drawing references, not even photos for being "sexual content", removed several of my cat videos because it was "spam" and also deleted funny comments referring to myself of my friends/my characters because it was "hate speech"). Im a freelance artist so the fact that I got banned for 30 days of commenting/posting is problematic because Facebook is the main media where I earn income from (commission posts + adoptables selling), and thats why I started to wonder if a hacker could somehow remove an account's ban.

Please lemme know if this is possible! ;m; any info would be useful~ thank you.

submitted by /u/applesjuic3
[link] [comments]

___________________________

@hacking_Attack

@Hacking_Video
___________________________
hacking: security in practice
URGENT: can someone hack me if they have my apple ID?

Can they go thru all my pictures and messages and all that?

Pls help

submitted by /u/MOONLITE24
[link] [comments]

___________________________

@hacking_Attack

@Hacking_Video
___________________________
Brave — Stealing your cookies remotely

Brave for Android had a vulnerability that allowed a malicious webpage to steal your cookies remotely.
Read more...

___________________________

@hacking_Attack

@Hacking_Video
___________________________
___________________________

@hacking_Attack

@Hacking_Video
___________________________
Hacking Articles Tips Tricks Videos Tutorials
___________________________ @hacking_Attack @Hacking_Video ___________________________
Hacking on Medium
Using pendrive as a password for your desktop / laptops.

Here by we are gonna do this with an amazing software name predator. This software turns your pendrive into a password for your laptop and…

Continue reading on Medium »

___________________________

@hacking_Attack

@Hacking_Video
___________________________
___________________________

@hacking_Attack

@Hacking_Video
___________________________
___________________________

@hacking_Attack

@Hacking_Video
___________________________
___________________________

@hacking_Attack

@Hacking_Video
___________________________
Hacking Articles Tips Tricks Videos Tutorials
___________________________ @hacking_Attack @Hacking_Video ___________________________
Black Hat Ethical Hacking
Mount Locker Ransomware Aggressively Changes Up Tactics

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Mount Locker Ransomware Aggressively Changes Up TacticsPost Views: 97
Reading Time: 2 Minutes
The Mount Locker ransomware has shaken things up in recent campaigns with more sophisticated scripting and anti-prevention features, according to researchers. And, the change in tactics appears to coincide with a rebranding for the malware into “AstroLocker.”
According to researchers, Mount Locker has been a swiftly moving threat. Having just hit the ransomware-as-a-service scene in the second half of 2020, the group released a major update in November that broadened its targeting capabilities (including searching for file extensions utilized by TurboTax tax-return software to encrypt). It also added improved detection evasion. Attacks have continued to escalate, and now, another major update signals “an aggressive shift in Mount Locker’s tactics,” according to an analysis released Thursday by GuidePoint Security. Mount Locker Adds Security-Evasion FeaturesLike many ransomware gangs, the operators not only lock up files, but also steal data and threaten to leak it if the ransom isn’t paid, in a double-extortion gambit. They’re also known for demanding multimillion-dollar ransoms and stealing especially large amounts of data (up to 400 GB).

In terms of technical approach, Mount Locker uses off-the-shelf, legitimate tools to move laterally, steal files and deploy encryption, GuidePoint noted. This includes the use of AdFind and Bloodhound for Active Directory and user reconnaissance; FTP for file exfiltration; and the pen-testing tool CobaltStrike for lateral movement and the delivery and execution of encryption, potentially through psExec.
See Also: Pulse Secure Critical Zero-Day Security Bug Under Active Exploit “After the environment is mapped, backup systems are identified and neutralized, and data is harvested, systems are encrypted with target-specific ransomware delivered via the established command-and-control channels (C2),” said Drew Schmitt, senior threat intelligence analyst for GuidePoint, in the analysis. “These payloads include executables, extensions and unique victim IDs for payment.”

More recent campaigns have jazzed things up with new batch scripts, researchers noted. These are designed to disable detection and prevention tools.

“[This] indicates that Mount Locker is increasing its capabilities and is becoming a more dangerous threat,” according to Schmitt. “These scripts were not just blanket steps to disable a large swath of tools, they were customized and targeted to the victim’s environment.”

Another change in tactics for the group involves using multiple CobaltStrike servers with unique domains. It’s an added step that helps with detection evasion, but Schmitt noted that it’s not often seen because it requires much more management to put into practice effectively.
See Also: Offensive Security Tool: Hunt Biotech Firms in Cyberattack Sightshttps://media.threatpost.com/wp-content/uploads/sites/103/2021/04/22150002/MountLocker-300x258.png

A Mount Locker ransom note. Click to enlarge. Source: GuidePoint Security.
The changes have been accompanied by an uptick in Mount Locker attacks, especially those taking aim at companies in the biological tech industry. Schmitt said there has been a surge in incidents in this segment, indicating that  there may be a larger campaign afoot that aggressively targets healthcare-adjacent industries.

“Biotech companies, in particular, are a prime target for ransomware because of their position in an industry flush not only with ca[...]

___________________________

@hacking_Attack

@Hacking_Video
___________________________