Prompt injection explained, with video, slides, and a transcript https://simonwillison.net/2023/May/2/prompt-injection-explained/
Simon Willison’s Weblog
Prompt injection explained, with video, slides, and a transcript
I participated in a webinar this morning about prompt injection, organized by LangChain and hosted by Harrison Chase, with Willem Pienaar, Kojin Oshiba (Robust Intelligence), and Jonathan Cohen and Christopher …
Linux ptrace introduction AKA injecting into sshd for fun https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/
XPN Infosec Blog
@_xpn_ - Linux ptrace introduction AKA injecting into sshd for fun
If there is one thing I've come to appreciate over this past few weeks, it's just how much support you are provided from the Win32 API. That being said, I wanted to tackle some Linux process injection, with the aim of loading a shared object into another…
Testing a new encrypted messaging app's extraordinary claims https://crnkovic.dev/testing-converso/
crnkovic.dev
Testing a new encrypted messaging app's extraordinary claims
How I breached a nonexistent database and found every private key in a 'state-of-the-art' encrypted messenger.
Fork off: Three ways to deal with forking processes https://www.skullsecurity.org/2023/fork-off-three-ways-to-deal-with-forking-processes
SkullSecurity Blog
Fork off: Three ways to deal with forking processes
Have you ever tested a Linux application that forks into multiple processes? Isn’t it a pain? Whether you’re debugging, trying to see a process crash, or trying to write an exploit, it can be super duper annoying! In a few days, I’m giving a talk at NorthSec…
Snooker Token Hack Analysis https://blog.solidityscan.com/snooker-token-hack-analysis-acd89cce6311
Medium
Snooker Token Hack Analysis
Overview:
New phishing-as-a-service tool “Greatness” already seen in the wild https://blog.talosintelligence.com/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild/
Cisco Talos
New phishing-as-a-service tool “Greatness” already seen in the wild
Greatness incorporates features seen in some of the most advanced PaaS offerings, such as multi-factor authentication (MFA) bypass, IP filtering and integration with Telegram bots.
47% of all internet traffic came from bots in 2022 https://www.securitymagazine.com/articles/99339-47-of-all-internet-traffic-came-from-bots-in-2022?v=preview
Securitymagazine
47% of all internet traffic came from bots in 2022
A new report reveals that in 2022, 47.4% of all internet traffic came from bots, a 5.1% increase over the previous year. The same report showed that human traffic, at 52.6%, decreased to its lowest level in eight years.
This week, Imperva released its 10th…
This week, Imperva released its 10th…
Kernel Object Names Lifetime https://scorpiosoftware.net/2023/05/15/kernel-object-names-lifetime/
Pavel Yosifovich
Kernel Object Names Lifetime
Much of the Windows kernel functionality is exposed via kernel objects. Processes, threads, events, desktops, semaphores, and many other object types exist. Some object types can have string-based …
CS:GO: From Zero to 0-day https://neodyme.io/blog/csgo_from_zero_to_0day/
neodyme.io
CS:GO: From Zero to 0-day
We identified three independent remote code execution (RCE) vulnerabilities in the popular Counter-Strike: Global Offensive game. Each vulnerability can be triggered when the game client connects to our malicious python CS:GO server. This post details our…
You’ve been kept in the dark (web): exposing Qilin’s RaaS program https://www.group-ib.com/blog/qilin-ransomware/?utm_source=twitter&utm_campaign=qilin-ransomware&utm_medium=social
Group-IB
The Qilin Ransomware: Analysis and Protection Strategies
Discover how Qilin ransomware threatens cybersecurity. Learn prevention tips and stay protected. ✓ Read more now and safeguard your data!
2023 ransomware insights https://assets.barracuda.com/assets/docs/dms/2023-Ransomware-insights-report.pdf
Linux IPv6 "Route of Death" 0day https://www.interruptlabs.co.uk/articles/linux-ipv6-route-of-death
Quasar Rat Analysis - Identification of 64 Quasar Servers Using Shodan and Censys https://embee-research.ghost.io/hunting-quasar-rat-shodan/
Embee Research
How To Track Quasar Rat C2 Infrastructure Using TLS Certificates
Extraction of Quasar C2 configuration via Dnspy, and using this information to pivot to additional servers utilising Shodan and Censys.
rax30 patch diff analysis & nday exploit for zdi-23-496 https://blog.coffinsec.com/nday/2023/05/12/rax30-patchdiff-nday-analysis.html
hyprblog
RAX30 Patch Diff Analysis & Nday Exploit for ZDI-23-496
patch diff analysis of the latest patches for the netgear rax30 and an nday exploit for one of them (ZDI-23-496)
The Race to Patch: Attackers Leverage Sample Exploit Code in WordPress Plug-in https://www.akamai.com/blog/security-research/attackers-leverage-sample-exploit-wordpress-plugin
Akamai
The Race to Patch: Attackers Leverage Sample Exploit Code in WordPress Plug-in | Akamai
The time for attackers to respond to known vulnerabilities is shrinking. See an example of an attacker using sample code.
CVE-2023-26818 - Bypass TCC with Telegram in macOS https://danrevah.github.io/2023/05/15/CVE-2023-26818-Bypass-TCC-with-Telegram/
Dan Revah’s Blog
CVE-2023-26818 - Bypassing TCC with Telegram in macOS
Preface
SID filter as security boundary between domains? (Part 1) - Kerberos authentication explained [7 parts, this is the first one] https://improsec.com/tech-blog/o83i79jgzk65bbwn1fwib1ela0rl2d
itm8.dk
Skal vi skabe nutidens og fremtidens IT sammen? itm8
Hvad er en itm8? Vi er præcis, hvad navnet siger: Din m8* (*mate), der er ekspert i IT. Vi er din partner til 360 graders IT.
Triple Threat: Breaking Teltonika Routers Three Ways https://claroty.com/team82/research/triple-threat-breaking-teltonika-routers-three-ways
Claroty
Triple Threat: Breaking Teltonika Routers Three Ways
Discover the vulnerabilities of Teltonika routers in this groundbreaking research by Team82. Explore three effective methods used to breach the security of these routers, providing valuable insights for network administrators and cybersecurity professionals.…
Hardware Hacking 101: Identifying and Dumping eMMC Flash https://www.riverloopsecurity.com/blog/2020/03/hw-101-emmc/
River Loop Security
Hardware Hacking 101: Identifying and Dumping eMMC Flash
Cybersecurity solutions for the whole lifecycle of IoT and embedded systems.
Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586) https://the-deniss.github.io/posts/avast-privileged-arbitrary-file-create-on-restore/
the-deniss.github.io
Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586)
And today I’m sharing the report describing the vulnerability (CVE-2023-1586) in Avast file restore functionality and exploitation of this vulnerability to execute arbitrary code in the “NT AUTHORITY\SYSTEM” context
Exploiting Windows’ vulnerabilities with Hyper-V: A Hacker’s swiss army knife https://reversing.info/posts/hyperdeceit/
Xyrem Engineering
Exploiting Windows' vulnerabilities with Hyper-V: A Hacker's swiss army knife
In this blog, we explore how to leverage the implementation of the Hyper-V virtualization technology to exploit and attack Windows systems and learn what measures should be taken to mitigate this vulnerability. Join us as we explore the world of Windows hacking…
👍1