Hackstack Security | Cyber Security Resources | OSCP CISSP OSWE CEH CISA Web3 Hacking
157 subscribers
8 photos
2 files
37 links
Hackstack Security is a leading authority in the realm of cybersecurity, offering a comprehensive Security Services designed to safeguard your digital assets.

Here on Telegram we aim to provide Free Resources which will help you to get better in Infosec
Download Telegram
By living deeply in the present moment we can understand the past better and we can prepare for a better future
Top 10 Vulnerabilities of 2023:

1. CVE-2023-34362: MOVEit Vulnerability

2. CVE-2023-23397: MS Outlook PE

3. CVE-2023-43641: 1-Click RCE on GNOME

4. CVE-2023-28252: Windows CLFS PE

5. CVE-2023-2868: Barracuda ESG CI

6. CVE-2023-26360: Adobe ColdFusion

7. CVE-2023-4966: Citrix Bleed

8. CVE-2023-22952: SugarCRM RCE

9. CVE-2023-24880: Win Smart Screen Bypass
https://www.vicarius.io/vsociety/posts/windows-smartscreen-security-feature-bypass-cve-2023-24880

10. CVE-2022-42475:
FortiOS heap-based buffer overflow in sslvpnd
https://bishopfox.com/blog/exploit-cve-2022-42475
https://github.com/scrt/cve-2022-42475


—— Hackstack Security ——

@hackstacksecurity

Follow Us On Twitter: https://twitter.com/hackstacksec
Follow Our Page On LinkedIn: https://www.linkedin.com/company/hackstack-security/
Follow Us On Instagram: https://www.instagram.com/hackstacksecurity/
Contact Us: https://hackstacksecure.com/contact
Are you looking for FREE cybersecurity certifications?

1. Vulnerability Management: https://lnkd.in/g64maMet

2. Global IT Asset Inventory: https://lnkd.in/gXR5bD5N

3. Scanning Strategies: https://lnkd.in/g6cQjQuh

4. Reporting Strategies: https://lnkd.in/gs6Vn-DA

5. Patch Management: https://lnkd.in/gnWVDCNp

6. Policy Compliance: https://lnkd.in/g5SXKncJ

7. PCI Compliance: https://lnkd.in/gZns6Xdf

8. Endpoint Detection & Response: https://lnkd.in/gw22Y__E

9. Vulnerability Management: https://lnkd.in/gYAFfAuT

10. Cloud Security Assessment & Response: https://lnkd.in/grrHivcW

11. API Fundamentals: https://lnkd.in/gngVxhbu

12. Cloud Agent: https://lnkd.in/gngVxhbu

13. Container Security: https://lnkd.in/gYNCGY8A

14. File Integrity Monitoring: https://lnkd.in/gYNCGY8A

15. Web Application Scanning: https://lnkd.in/ggpJ-vG6

Here are 15 FREE courses provided by the Qualys.

https://www.linkedin.com/posts/hackstack-security_cybersecurity-freecourses-infosec-activity-7154837232141402112-4kjb

—— Hackstack Security ——

@hackstacksecurity

Contact Us: https://hackstacksecure.com/contact/
👍3
Top 10 Tools for Bug Bounty Hunting


Core Tools

1. Burp Suite:
The most essential tool for web application security testing. It offers a comprehensive suite of features for intercepting, modifying, and analyzing web traffic.

2. Nmap: A versatile network scanning tool used for discovering hosts, services, and vulnerabilities on a network.

3. FFUF: A fast web fuzzer that helps in discovering hidden directories, files, and parameters.

Intelligence Gathering

4. Amass: An open-source tool for conducting subdomain enumeration and asset discovery.
5. ReconFTW: Open-source reconnaissance tool for gathering information.

Vulnerability Scanning and Exploitation

6. Nuclei: A fast and lightweight vulnerability scanner for finding vulnerabilities using YAML-based templates.

7. SQLmap: A powerful penetration testing framework for SQL injection and database takeover.

8. WPScan: Specifically designed for WordPress vulnerability scanning.

Additional Tools:

9. Kali Linux: A Debian-based Linux distribution with a pre-installed set of penetration testing tools.

10. Wireshark: A packet analyzer for capturing and analyzing network traffic.

I know these are just few of them! Add more in the comments.
The 5 Most Used Security Frameworks

1. ISO 27001:
- Leading in recognition, it offers a comprehensive approach to information security.

2. NIST Cybersecurity Framework:
- More common in the USA to manage cybersecurity risks.

3. CIS Controls:
- Simple and effective best practices for cybersecurity.

4. COBIT:
- Focuses on governance and management of enterprise IT.

5. PCI DSS:
- Essential for all organizations that process credit card transactions.

And Why Does ISO 27001 Certification Stand at the Top?

- Universal Recognition: ISO 27001 is globally recognized and respected.
- Flexibility: Suitable for companies of every size and industry.
- Risk Management: Provides a solid framework for managing security risks.
- Building Trust: Signals to customers and partners that their data is secure.
- Competitive Advantage: Can open the door to new business opportunities.

More: https://www.getronics.com/the-top-five-cyber-security-frameworks/

More: https://complianceforge.com/solutions/nist-csf