Reverse Engineering The Apple Lightning Connector https://hackaday.com/2023/02/22/reverse-engineering-the-apple-lightning-connector/
Hackaday
Reverse Engineering The Apple Lightning Connector
A frequent contributor to the hacker community, [stacksmashing] has prepared an excellent instructional video on reverse engineering Apple’s Lighting connector proprietary protocol. The video…
A Primer On Slowable Encoders https://research.nccgroup.com/2023/02/20/a-primer-on-slowable-encoders/
Hardening Firmware Across the Android Ecosystem https://security.googleblog.com/2023/02/hardening-firmware-across-android.html
Google Online Security Blog
Hardening Firmware Across the Android Ecosystem
Posted by Roger Piqueras Jover, Ivan Lozano, Sudhi Herle, and Stephan Somogyi, Android Team A modern Android powered smartphone is a comp...
OWASP Kubernetes Top 10 https://sysdig.com/blog/top-owasp-kubernetes/
Verify first-party Microsoft applications in sign-in reports https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in
Docs
Verify first-party Microsoft applications in sign-in reports
Describes how to verify first-party Microsoft applications in sign-in reports.
CVE-2023-24998: Apache Commons FileUpload and Tomcat DoS Flaw https://securityonline.info/cve-2023-24998-apache-commons-fileupload-and-tomcat-dos-flaw/
Cybersecurity News
CVE-2023-24998: Apache Commons FileUpload and Tomcat DoS Flaw
Apache Tomcat was vulnerable to Apache Commons FileUpload flaw CVE-2023-24998 as there was no limit to the number of request parts processed
👍1
Security Code Review With ChatGPT https://research.nccgroup.com/2023/02/09/security-code-review-with-chatgpt/
Vulnerability write-up - "Dangerous assumptions" https://www.codean.io/blog/vulnerability-write-up---%22dangerous-assumptions%22
Introduction to SSRF Exploitation: A Practical Tutorial for Ethical Hackers — StackZero https://infosecwriteups.com/introduction-to-ssrf-exploitation-a-practical-tutorial-for-ethical-hackers-stackzero-385c02bd28f2
Medium
Introduction to SSRF Exploitation: A Practical Tutorial for Ethical Hackers — StackZero
Introduction to SSRF covering its mechanics, techniques, and effective countermeasures to defend against such attacks.
The Stack Series: The X64 Stack https://offensivecraft.wordpress.com/2023/02/11/the-stack-series-the-x64-stack/
offensivecraft
The Stack Series: The X64 Stack
Overview of x64 stack static RSP On x64 CPU, RSP register serves as both frame pointer and stack pointer, all the stack references are performed based on RSP as a result both local variables and pa…
NtQueueApcThreadEx NTDLL Gadget Injection https://github.com/LloydLabs/ntqueueapcthreadex-ntdll-gadget-injection
GitHub
GitHub - LloydLabs/ntqueueapcthreadex-ntdll-gadget-injection: This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine…
This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can be used for stealthy code injection. - LloydLabs...
👍1
Cybercriminals stung as HIVE infrastructure shut down https://www.europol.europa.eu/media-press/newsroom/news/cybercriminals-stung-hive-infrastructure-shut-down
Europol
Cybercriminals stung as HIVE infrastructure shut down – Europol supported German, Dutch and US authorities to shut down the servers…
In the last year, HIVE ransomware has been identified as a major threat as it has been used to compromise and encrypt the data and computer systems of large IT and oil multinationals in the EU and the USA. Since June 2021, over 1 500 companies from over 80…
Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices https://binarly.io/posts/Multiple_Vulnerabilities_in_Qualcomm_and_Lenovo_ARM_based_Devices/index.html
Binarly
Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices | Binarly
Uncover the latest ARM device vulnerabilities affecting Qualcomm and Lenovo. BINARLY's detailed exploration of CVE-2022-3430 and CVE-2022-3431 issues.
Linux Kernel Exploitation Technique: Overwriting modprobe_path https://lkmidas.github.io/posts/20210223-linux-kernel-pwn-modprobe/
My cool site
Linux Kernel Exploitation Technique: Overwriting modprobe_path
A popular and powerful technique to exploit the Linux kernel through modprobe_path
Exploit Airlines that use T-Mobile for Free WiFi https://cylect.io/blog/cybr-2/exploit-airlines-to-get-free-wifi-airline-vulnerability-8
Havoc Across the Cyberspace https://www.zscaler.com/blogs/security-research/havoc-across-cyberspace
Zscaler
Havoc Across the Cyberspace | Blog | Zscaler
ThreatLabz observed a new campaign targeting a Government organization in which the threat actors utilized a new Command & Control (C2) framework named Havoc
The code that wasn’t there: Reading memory on an Android device by accident https://github.blog/2023-02-23-the-code-that-wasnt-there-reading-memory-on-an-android-device-by-accident/
The GitHub Blog
The code that wasn't there: Reading memory on an Android device by accident
CVE-2022-25664, a vulnerability in the Qualcomm Adreno GPU, can be used to leak large amounts of information to a malicious Android application. Learn more about how the vulnerability can be used to leak information in both the user space and kernel space…
OpenEMR - Remote Code Execution in your Healthcare System https://www.sonarsource.com/blog/openemr-remote-code-execution-in-your-healthcare-system/
Hackers Using Trojanized macOS Apps to Deploy Evasive Cryptocurrency Mining Malware https://thehackernews.com/2023/02/hackers-using-trojanized-macos-apps-to.html