Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
--outpath C:\Clients\2021\FooBar\TFOutput --config myCustomConfig.json --enum --validate-msol --usernames C:\Clients\2021\FooBar\OSINT\Usernames.txt
--outpath C:\Clients\2021\FooBar\TFOutput --config myCustomConfig.json --backdoor
--outpath C:\Clients\2021\FooBar\TFOutput --config myCustomConfig.json --database
Credits GitHub - KoenZomers/OneDriveAPI: API in .NET to communicate with OneDrive Personal and OneDrive for Business (https://github.com/KoenZomers/OneDriveAPI) Research into Undocumented Behavior of Azure AD Refresh Tokens (https://github.com/secureworks/family-of-client-ids-research) WS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation (https://github.com/ustayready/fireprox) Credits to [Ryan] (https://twitter.com/detectdotdev) for validating and discussing my observations / questions! The entire TrustedSec (https://trustedsec.com/) team for helping me polish this tool!

Download TeamFiltration (https://github.com/Flangvik/TeamFiltration)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Why CVE Management as a Primary Strategy Doesn't Work

With only about 15% of vulnerabilities actually exploitable, patching every vulnerability is not an effective use of time.
Dark Reading: Attacks/Breaches
Okta Launches New Workforce Identity Cloud

Okta Worforce Identity Cloud has all three identity functions – identity access management, identity governance, and privilege access management – under the hood.
Dark Reading: Attacks/Breaches
RomCom Malware Woos Victims With 'Wrapped' SolarWinds, KeePass Software

An analysis of the RomCom APT shows the group is expanding its efforts beyond the Ukrainian military into the UK and other English-speaking countries.
Dark Reading: Attacks/Breaches
Detecting Malicious User Behavior Within and Across Applications

The solution lies in analyzing sequences of activities as user journeys, instead of analyzing each activity on its own.
Dark Reading: Attacks/Breaches
W4SP Stealer Stings Python Developers in Supply Chain Attack

Threat actors continue to push malicious Python packages to the popular PyPI service, striking with typosquatting, authentic sounding file names, and hidden imports to fool developers and steal their information.
Dark Reading: Attacks/Breaches
Build Security Around Users: A Human-First Approach to Cyber Resilience

Security is more like a seat belt than a technical challenge. It's time for developers to shift away from a product-first mentality and craft defenses that are built around user behaviors.
Dark Reading: Attacks/Breaches
Oreo Giant Mondelez Settles NotPetya 'Act of War' Insurance Suit

The settlement muddies the waters even further for the viability of war exclusion clauses when it comes to cyber insurance.
Dark Reading: Attacks/Breaches
NCSC Implements Vulnerability Scanning Program Across UK

The cybersecurity agency announced it intends to scan all Internet-connected devices hosted in the UK for known vulnerabilities.
Dark Reading: Attacks/Breaches
FIN7 Cybercrime Group Likely Behind Black Basta Ransomware Campaign

Several artifacts from recent attacks strongly suggest a connection between the two operations, researchers say.