CVE-2023-26818 - Bypass TCC with Telegram in macOS https://danrevah.github.io/2023/05/15/CVE-2023-26818-Bypass-TCC-with-Telegram/
Dan Revah’s Blog
CVE-2023-26818 - Bypassing TCC with Telegram in macOS
Preface
SID filter as security boundary between domains? (Part 1) - Kerberos authentication explained [7 parts, this is the first one] https://improsec.com/tech-blog/o83i79jgzk65bbwn1fwib1ela0rl2d
itm8.dk
Skal vi skabe nutidens og fremtidens IT sammen? itm8
Hvad er en itm8? Vi er præcis, hvad navnet siger: Din m8* (*mate), der er ekspert i IT. Vi er din partner til 360 graders IT.
Triple Threat: Breaking Teltonika Routers Three Ways https://claroty.com/team82/research/triple-threat-breaking-teltonika-routers-three-ways
Claroty
Triple Threat: Breaking Teltonika Routers Three Ways
Discover the vulnerabilities of Teltonika routers in this groundbreaking research by Team82. Explore three effective methods used to breach the security of these routers, providing valuable insights for network administrators and cybersecurity professionals.…
Hardware Hacking 101: Identifying and Dumping eMMC Flash https://www.riverloopsecurity.com/blog/2020/03/hw-101-emmc/
River Loop Security
Hardware Hacking 101: Identifying and Dumping eMMC Flash
Cybersecurity solutions for the whole lifecycle of IoT and embedded systems.
Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586) https://the-deniss.github.io/posts/avast-privileged-arbitrary-file-create-on-restore/
the-deniss.github.io
Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586)
And today I’m sharing the report describing the vulnerability (CVE-2023-1586) in Avast file restore functionality and exploitation of this vulnerability to execute arbitrary code in the “NT AUTHORITY\SYSTEM” context
Exploiting Windows’ vulnerabilities with Hyper-V: A Hacker’s swiss army knife https://reversing.info/posts/hyperdeceit/
Xyrem Engineering
Exploiting Windows' vulnerabilities with Hyper-V: A Hacker's swiss army knife
In this blog, we explore how to leverage the implementation of the Hyper-V virtualization technology to exploit and attack Windows systems and learn what measures should be taken to mitigate this vulnerability. Join us as we explore the world of Windows hacking…
👍1
Testing a new encrypted messaging app's extraordinary claims https://crnkovic.dev/testing-converso/
crnkovic.dev
Testing a new encrypted messaging app's extraordinary claims
How I breached a nonexistent database and found every private key in a 'state-of-the-art' encrypted messenger.
Sticky notes for pentesting. https://exploit-notes.hdks.org/
‘FriendlyName’ Buffer Overflow Vulnerability in Wemo Smart Plug V2 https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/
Sternum IoT
‘FriendlyName’ Buffer Overflow Vulnerability in Wemo Smart Plug V2 | Sternum IoT
Manufacturer chooses not to patch the Sternum-identified buffer overflow vulnerability (CVE-2023-27217) in the Wemo Mini Smart Plug V2.
👍3
Finding the Footprints of Hidden Shellcode https://i.blackhat.com/Asia-23/AS-23-Uhlmann-You-Can-Run-But-You-Cant-Hide.pdf
👍1
New Strain of Sotdas Malware Discovered https://blog.qualys.com/vulnerabilities-threat-research/2023/05/17/new-strain-of-sotdas-malware-discovered
Qualys
New Strain of Sotdas Malware Discovered | Qualys
There are numerous malicious codes that are currently active on smart devices, such as Ddosf, Dofloo, Gafgyt, MrBlack, Persirai, Sotdas, Tsunami, Triddy, Mirai, Moose, and Satori, among others.
Black Basta: Anatomy of the Attack https://blogs.infoblox.com/cyber-threat-intelligence/black-basta-anatomy-of-the-attack/
Infoblox Blog
Black Basta: Anatomy of the Attack
Black Basta, is an active cybercriminal group targeting Europe and English-speaking countries. Uncover their tactics, including double extortion, and delve into their recent attack on ABB in this article.
Google Chrome V8 ArrayShift Race Condition Remote Code Execution https://blog.exodusintel.com/2023/05/16/google-chrome-v8-arrayshift-race-condition-remote-code-execution/
Exodus Intelligence
Google Chrome V8 ArrayShift Race Condition Remote Code Execution - Exodus Intelligence
By Javier Jimenez Overview This post describes a method of exploiting a race condition in the V8 JavaScript engine, version 9.1.269.33. The vulnerability affects the following versions of Chrome and Edge: Google Chrome versions between 90.0.4430.0 and 91.0.4472.100.…
👍1
Abusing Time-Of-Check Time-Of-Use (TOCTOU) Race Condition Vulnerabilities in Games, Harry Potter Style https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/abusing-time-of-check-time-of-use-toctou-race-condition-vulnerabilities-in-games-harry-potter-style/
Trustwave
Abusing Time-Of-Check Time-Of-Use (TOCTOU) Race Condition Vulnerabilities in Games, Harry Potter Style | Trustwave
I feel I need to clarify, for legal reasons, that this is nothing to do with any Harry Potter game. The reference is made because we are dealing with spells and magic, and I mean magic in the literal sense, not a reference to application security – although…
KeePass 2.X Master Password Dumper (CVE-2023-32784) https://github.com/vdohney/keepass-password-dumper
GitHub
GitHub - vdohney/keepass-password-dumper: Original PoC for CVE-2023-32784
Original PoC for CVE-2023-32784. Contribute to vdohney/keepass-password-dumper development by creating an account on GitHub.
CVE-2023-31070 Broadcom BCM47xx SDK EMF slab-out-of-bounds write - the uncomfortable reality of the IoT Linux kernel space https://bugprove.com/knowledge-hub/cve-2023-31070-broadcom-bcm-47xx-sdk-emf-slab-out-of-bounds-write/
Bugprove
CVE-2023-31070 Broadcom BCM47xx SDK EMF slab-out-of-bounds write
Exploring the Impact of CVE-2023-31070: A Deep Dive into Broadcom BCM47xx SDK, found by Attila Szasz with BugProve's engine.
Rendezvous with a Chatbot: Chaining Contextual Risk Vulnerabilities https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/rendezvous-with-a-chatbot-chaining-contextual-risk-vulnerabilities/
Trustwave
Rendezvous with a Chatbot: Chaining Contextual Risk Vulnerabilities | Trustwave
Ignoring the little stuff is never a good idea. Anyone who has pretended that the small noise their car engine is making is unimportant, only to later find themselves stuck on the side of the road with a dead motor will understand this statement.
Block C2 communication with Defender for Endpoint https://jeffreyappel.nl/block-c2-communication-with-defender-for-endpoint/
Jeffrey Appel - Microsoft Security blog
Block C2 communication with Defender for Endpoint
Human-operated ransomware (HumOR) is growing and needs different layers of protection. Microsoft released some new features to protect against C2 communication. Attackers rely heavily on C2 communications for multiple stages, and blocking these direct connections…
sniffnet: Application to comfortably monitor your Internet traffic 🕵️♂️ https://github.com/GyulyVGC/sniffnet
GitHub
GitHub - GyulyVGC/sniffnet: Comfortably monitor your Internet traffic 🕵️♂️
Comfortably monitor your Internet traffic 🕵️♂️. Contribute to GyulyVGC/sniffnet development by creating an account on GitHub.