Dark Reading: Attacks/Breaches
Real Estate Phish Swallows 1,000s of Microsoft 365 Credentials
The attacks showcase broader security concerns as phishing grows in volume and sophistication, especially given that Windows Defender's Safe Links feature for identifying malicious links in emails completely failed in the campaign.
Real Estate Phish Swallows 1,000s of Microsoft 365 Credentials
The attacks showcase broader security concerns as phishing grows in volume and sophistication, especially given that Windows Defender's Safe Links feature for identifying malicious links in emails completely failed in the campaign.
CVE-2022–37700 Directory Transversal in ZenTao Easy soft ALM v16.5
https://medium.com/@sc0p3hacker/cve-2022-37700-directory-transversal-in-zentao-easy-soft-alm-2573c1f0fc21?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sc0p3hacker/cve-2022-37700-directory-transversal-in-zentao-easy-soft-alm-2573c1f0fc21?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–37700 Directory Transversal in ZenTao Easy soft ALM v16.5
I am Shubham Sudhir Sawant a Security Researcher, super thrilled to write my very first blog. Medium is one of my favorite platform where I…
I am Shubham Sudhir Sawant a Security Researcher, super thrilled to write my very first blog.Continue reading on Medium » (https://medium.com/@sc0p3hacker/cve-2022-37700-directory-transversal-in-zentao-easy-soft-alm-2573c1f0fc21?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–37700 Directory Transversal in ZenTao Easy soft ALM v16.5
I am Shubham Sudhir Sawant a Security Researcher, super thrilled to write my very first blog. Medium is one of my favorite platform where I…
hacking: security in practice
Did I disclose a vulnerability improperly?
I work in IT and they have us working on Macs. I spotted a few things that an employee could abuse. So I sent 3 emails regarding each vulnerability, and each email was sent as i found them. Keep in mind, this process was along-side my training and nesting. So I was supposed to be doing my work, however, I was probing and enumerating my Mac for vulns on the side as well.
After the 3rd email, the security team asked to have a meeting with me. The meeting went well, except there was a moment when the head of security accused me of sneaking around due to not talking to security first.
Thoughts on this?
EDIT: clarification:
When i found the first privesc vulnerability, i notified my direct supervisors and they supported my decision to let someone know. They helped get those emails sent up the chain.
submitted by /u/EnthusiasmWorried496
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Did I disclose a vulnerability improperly?
I work in IT and they have us working on Macs. I spotted a few things that an employee could abuse. So I sent 3 emails regarding each vulnerability, and each email was sent as i found them. Keep in mind, this process was along-side my training and nesting. So I was supposed to be doing my work, however, I was probing and enumerating my Mac for vulns on the side as well.
After the 3rd email, the security team asked to have a meeting with me. The meeting went well, except there was a moment when the head of security accused me of sneaking around due to not talking to security first.
Thoughts on this?
EDIT: clarification:
When i found the first privesc vulnerability, i notified my direct supervisors and they supported my decision to let someone know. They helped get those emails sent up the chain.
submitted by /u/EnthusiasmWorried496
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Did I disclose a vulnerability improperly?
I work in IT and they have us working on Macs. I spotted a few things that an employee could abuse. So I sent 3 emails regarding each...
Getting Paid With Just Picking Color — Bug Bounty
Suppppp guysss, this is my first write-up about bug bounty, let me introduce myself, my name is Redza you can call me za, ja, dza, red, or…Continue reading on Medium »
Read more...
Suppppp guysss, this is my first write-up about bug bounty, let me introduce myself, my name is Redza you can call me za, ja, dza, red, or…Continue reading on Medium »
Read more...
Getting Paid With Just Picking Color — Bug Bounty
https://medium.com/@rdzsp/getting-paid-with-just-picking-color-bug-bounty-d3dbbac277fa?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@rdzsp/getting-paid-with-just-picking-color-bug-bounty-d3dbbac277fa?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Getting Paid With Just Picking Color — Bug Bounty
Suppppp guysss, this is my first write-up about bug bounty, let me introduce myself, my name is Redza you can call me za, ja, dza, red, or…
Suppppp guysss, this is my first write-up about bug bounty, let me introduce myself, my name is Redza you can call me za, ja, dza, red, or…Continue reading on Medium » (https://medium.com/@rdzsp/getting-paid-with-just-picking-color-bug-bounty-d3dbbac277fa?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Getting Paid With Just Picking Color — Bug Bounty
Suppppp guysss, this is my first write-up about bug bounty, let me introduce myself, my name is Redza you can call me za, ja, dza, red, or…
Does anyone know if Daryl Gibson has a book for Pentest+ or any study material on pentesting in general. Any study material would be greatly appreciated! #cyber #security #Pentest+ #Pentesting
https://www.reddit.com/r/Pentesting/comments/xg44g6/does_anyone_know_if_daryl_gibson_has_a_book_for/
submitted by /u/RoyD389 (https://www.reddit.com/user/RoyD389)
[link] (https://www.reddit.com/r/Pentesting/comments/xg44g6/does_anyone_know_if_daryl_gibson_has_a_book_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/xg44g6/does_anyone_know_if_daryl_gibson_has_a_book_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/xg44g6/does_anyone_know_if_daryl_gibson_has_a_book_for/
submitted by /u/RoyD389 (https://www.reddit.com/user/RoyD389)
[link] (https://www.reddit.com/r/Pentesting/comments/xg44g6/does_anyone_know_if_daryl_gibson_has_a_book_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/xg44g6/does_anyone_know_if_daryl_gibson_has_a_book_for/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does anyone know if Daryl Gibson has a book for Pentest+ or any...
Posted in r/Pentesting by u/RoyD389 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Analyze obfuscated Microsoft Office files
https://cdn-images-1.medium.com/max/1686/1*23tBpzwTpGsT-RgjK0S2ZA.png
When you are under incident investigation, the time does the different to provide the right solution to your stakeholders. Sometimes to go…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Analyze obfuscated Microsoft Office files
https://cdn-images-1.medium.com/max/1686/1*23tBpzwTpGsT-RgjK0S2ZA.png
When you are under incident investigation, the time does the different to provide the right solution to your stakeholders. Sometimes to go…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Analyze obfuscated Microsoft Office files
When you are under incident investigation, the time does the different to provide the right solution to your stakeholders. Sometimes to go…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Why Uber’s ‘No Evidence’ Claim of Stolen User Data Is PR Bullshit
https://cdn-images-1.medium.com/max/2600/1*l5zUwJhULZIVGz3Z-64TFA.jpeg
Uber has released an official security update at 10:30 PST on September 16th, 2022 regarding the breach that allowed a hacker to gain…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Why Uber’s ‘No Evidence’ Claim of Stolen User Data Is PR Bullshit
https://cdn-images-1.medium.com/max/2600/1*l5zUwJhULZIVGz3Z-64TFA.jpeg
Uber has released an official security update at 10:30 PST on September 16th, 2022 regarding the breach that allowed a hacker to gain…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why Uber’s ‘No Evidence’ Claim of Stolen User Data Is PR Bullshit
Uber has released an official security update at 10:30 PST on September 16th, 2022 regarding the breach that allowed a hacker to gain…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
All-in-One post. How Uber was hacked in 2022
https://external-preview.redd.it/w2lfSJsr9fSSi6mSShofydy7gWNKzLoFoG8-HmI19Io.jpg?width=640&crop=smart&auto=webp&s=8983b6538b5c87dbe545791507539618365b86e0 submitted by /u/Ivan_Wallarm
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
All-in-One post. How Uber was hacked in 2022
https://external-preview.redd.it/w2lfSJsr9fSSi6mSShofydy7gWNKzLoFoG8-HmI19Io.jpg?width=640&crop=smart&auto=webp&s=8983b6538b5c87dbe545791507539618365b86e0 submitted by /u/Ivan_Wallarm
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
All-in-One post. How Uber was hacked in 2022
Posted in r/hacking by u/Ivan_Wallarm • 187 points and 9 comments
hacking: security in practice
Interview
Hello. I have a podcast and am looking for some interesting guests. If you know a lot about hacking and have some interesting stories I’d love to have you on. Thanks.
submitted by /u/More_Kaleidoscope888
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Interview
Hello. I have a podcast and am looking for some interesting guests. If you know a lot about hacking and have some interesting stories I’d love to have you on. Thanks.
submitted by /u/More_Kaleidoscope888
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Interview
Hello. I have a podcast and am looking for some interesting guests. If you know a lot about hacking and have some interesting stories I’d love to...
hacking: security in practice
Silent Crypto Miner Tutorial (First YT Video :D)
submitted by /u/Adventurous-Tap-1540
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Silent Crypto Miner Tutorial (First YT Video :D)
submitted by /u/Adventurous-Tap-1540
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Silent Crypto Miner Tutorial (First YT Video :D)
Posted in r/hacking by u/Adventurous-Tap-1540 • 1 point and 0 comments