Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
$20K Buys Insider Access to Telegram Servers, Dark Web Ad Claims

In the ad, cybercriminals are offering to sell employee-level access to Telegram, researchers warn.
Dark Reading: Attacks/Breaches
Software Supply Chain Security Needs a Bigger Picture

SBOMs aren't enough. OpenSSF's Alpha-Omega brings in new blood to help secure the open source projects most impactful to the software supply chain.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New Survey Sheds Light on Why Enterprises Struggle to Thwart API Attacks

Corsha’s Annual State of API Secrets Management Report finds over 50% of respondents suffered a data breach due to compromised API secrets.
Dark Reading: Attacks/Breaches
SailPoint Acquires SecZetta to Provide Comprehensive Identity Security for Non-Employee Identities

This move accelerates the company’s vision of becoming the de facto identity security platform of choice for the modern enterprise.
Dark Reading: Attacks/Breaches
Critical Cisco SMB Router Flaw Allows Authentication Bypass, PoC Available

Unpatched Cisco bugs, tracked as CVE-2023-20025 and CVE-2023-20026, allow lateral movement, data theft, and malware infestations.
Pods Bug Bounty V2

Let’s hunt some bugs 🔍Continue reading on Pods »
Read more...
Yet another litany of "dumb" & "googlable" questions from a wanna-be red team member
https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/

<!-- SC_OFF -->Background: I'm just a typical developer who aspires to be red team one day. I'm studying for the cissp and would like to eventually become a red team member for the government. I have some credentials that allow me to work in this space but I want to Branch out from development and be more active in cyber security. I am AWS certified and after the cissp I will get the security certification from AWS. Has anyone tried a Portapack H2 Mayhem (RFOne knock off I think)? Just curious if anyone has tried this device. I saw it on eBay for 240 bucks and I've got some money burning a hole in my wallet so I thought I might take a look at it, see what I can see with it. Reportedly it goes up to 40 MHz to 6 GHz. I don't think I'd ever be required to use it for any reason but it might be fun to play with and at least learn something that you guys know by heart. A. Should I just bite the bullet and get an RFOne off Hak5? In your professional opinion, what certifications might teach & test for the most useful skills? 2.A. Ones that are respected the most within the industry? Where might be sandboxes that I can use to hone my skills without getting sued or breaking the law? 3.A. in your opinion, what might be the best training ground to use to learn these skills? Is bug crowd one might use to practice and actively work on offensive security techniques? I signed up and it seems like they just released the client requirements then let you get at it hacking the client based on their specifications. You find anything you write the report and submit it and then wait and see if it's accepted. My previous question to this Reddit was concerning physical security, having learned that that is not a high demand skill, that leaves me internet and networking exploits to learn. In your opinion how would you go about learning everything you can about the tools and techniques for that facet of information security? RTFM, I know but I need a safe place to do so without breaking the law for any reason or inadvertently causing damage. I would not do anything to any system that has not given me express permission to do so. That's pretty obvious. I genuinely want to learn and become a white hat red team member and I'm willing to do what it takes, this is why I'm asking for your opinion as to where to get started. Thanks I'm sorry to annoy some here but a little guidance from professionals in the field would at least clue me in on where I need to start besides Google. Any advice you can provide is greatly appreciated. <!-- SC_ON --> submitted by /u/mikealicious- (https://www.reddit.com/user/mikealicious-)
[link] (https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/) [comments] (https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
what should my security be on tor browser ?

out of the three options wich one should i use and what could happen if i use the first one ?

submitted by /u/ageneric_pybro
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Ducky script/snippet to send a sequence of modifier keys?

Hey!, not sure if this is the right place to post this question but some googling around pointed me to this forum so hopefully someone can point me in the right direction.

I have a KVM that is controlled by a sequence of keys and I want to try to automate its use (by integrating it with Home Assistant). Following this project here I managed to get a Ducky-like device that can receive commands from a network. When I connect it to my computer it works perfectly. All good so far.

What I can't figure out however is how to send sequence of modifier keys. The one I'm trying to mimic is hitting left control -> Releasing -> Left control again -> Release -> A number from 1 to 4.

All the examples I can find are about holding modifier keys while pressing something else or how to send just the Windows key without anything else but can't figure out how to script the sequence I need.

Any ideas?.

submitted by /u/Laucien
[link] [comments]