worth reading » ALPACA Attack: "application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates" https://alpaca-attack.com/
Abusing SIP for Cross-Site Scripting? Most definitely! https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/
W1 Feb| EN | Story of the week: Stealers on the Darkweb https://medium.com/s2wlab/w1-feb-en-story-of-the-week-stealers-on-the-darkweb-49945a31601d
Medium
W1 Feb| EN | Story of the week: Stealers on the Darkweb
The hand is quicker than the eye
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
Medium
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
Hiding your syscalls https://passthehashbrowns.github.io/hiding-your-syscalls
CVE-2021-31939 Outlook, Office • <= 16.0.13628.20274 • Use After Free https://cpr-zero.checkpoint.com/vulns/cprid-2164/
CPR-Zero
CPR-Zero: CVE-2021-31939
Check Point Research Vulnerability Repository
Data poisoning in action https://blog.f-secure.com/data-poisoning-in-action/
F-Secure Blog
Data poisoning in action - F-Secure Blog
While machine learning applications can be exposed to common security threats at the hardware, application, and network level, they are also exposed to domain specific threats that are currently overlooked. Data poisoning is amongst the most serious threats…
Nice contribution » D3fend MITRE: A knowledge graph of cybersecurity countermeasures https://d3fend.mitre.org/
old-but-gold type of bug :) » Quick Analysis for the SSID Format String Bug https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
codecolor.ist
CodeColorist
Personal notes
Solving CTF with Frida - Part 2 (intercepting TCP, UDP and HTTPS traffic) https://cmrodriguez.me/blog/hpandro-2/
cmrodriguez.me
Cesar Rodriguez | Personal blog
frida ctf challenge http intercept
Microsoft Paint 3D GLB File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-21-671/
Zerodayinitiative
ZDI-21-671
Microsoft Paint 3D GLB File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It https://thezerohack.com/apple-vulnerability-bug-bounty
The Zero Hack
How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It - The Zero Hack
This article is about how I found a vulnerability on Apple forgot password endpoint that allowed me to takeover an iCloud account. The vulnerability is completely patched by Apple security team and it no longer works. Apple Security Team rewarded me $18,000…
Ransomware Double Extortion and Beyond: REvil, Clop, and Conti https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/ransomware-double-extortion-and-beyond-revil-clop-and-conti
Trendmicro
Ransomware Double Extortion and Beyond: REvil, Clop, and Conti
Ransomware-stricken organizations grapple with multilevel extortion schemes that are advancing at an alarming rate. What exactly happens in these campaigns? We scrutinize three active ransomware families associated with these schemes to find out.
Part-1 Dive into Zoom Applications https://rakesh-thodupunoori.medium.com/part-1-dive-into-zoom-applications-d70f3de53ec5
Medium
Part-1 Dive into Zoom Applications
TL;DR
Introducing SLSA, an End-to-End Framework for Supply Chain Integrity https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html
Google Online Security Blog
Introducing SLSA, an End-to-End Framework for Supply Chain Integrity
Posted Kim Lewandowski, Google Open Source Security Team & Mark Lodato, Binary Authorization for Borg Team Supply chain integrity attacks—u...
Bypassing Image Load Kernel Callbacks https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/
MDSec
Bypassing Image Load Kernel Callbacks - MDSec
As security teams continue to advance, it has become essential for attacker’s to have complete control over every part of their operation, from the infrastructure down to individual actions that...
What you need to know about Process Ghosting, a new executable image tampering attack https://www.elastic.co/blog/process-ghosting-a-new-executable-image-tampering-attack
Elastic Blog
What you need to know about Process Ghosting, a new executable image tampering attack
Several common process tampering attacks exploit the gap between process creation and when security products are notified. Elastic Security detects a variety of such techniques, including Doppelgänging, Herpaderping, and a new technique: Ghosting
Critical Bug Identified in 88mph Awarded with $42,069 Bounty https://iosiro.com/blog/88mph-bug-bounty-post-mortem
Iosiro
Critical Bug Identified in 88mph Awarded with $42,069 Bounty | iosiro
iosiro identified a critical bug in the fixed-interest-rate lending protocol 88mph. The bug was reported to 88mph through Immunefi for a bounty of $42,069. This blog post details the bug and the disclosure process.