Aggregator
揭秘云数仓ByteHouse四大「降本」硬招
nollium/CVE-2024-9264: Exploit for Grafana arbitrary file-read (CVE-2024-9264)
Over 6,000 WordPress hacked to install plugins pushing infostealers
cloudkicker: self-hosted Azure OSINT tool
cloudkicker self-hosted Azure OSINT tool It is very similar to what @DrAzureAD’s OSINT tool does (https://aadinternals.com/osint/). While this version lacks a few of the extra features, it is self-contained, requires no account, and can...
The post cloudkicker: self-hosted Azure OSINT tool appeared first on Penetration Testing Tools.
tuf: A Framework for Securing Software Update Systems
The Update Framework (TUF) The Update Framework (TUF) is written in Python and intended to conform to version 1.0 of the TUF specification. This implementation is in use in production systems but is also...
The post tuf: A Framework for Securing Software Update Systems appeared first on Penetration Testing Tools.
authelia: The Single Sign-On Multi-Factor portal for web apps
authelia Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications via a web portal. It acts as a companion of reverse proxies like nginx, Traefik or HAProxy to let them...
The post authelia: The Single Sign-On Multi-Factor portal for web apps appeared first on Penetration Testing Tools.
Kill
CVE-2016-1094 | Adobe Acrobat Reader up to 11.0.15/15.006 use after free (APSB16-14 / Nessus ID 91096)
Sophos Fortifies XDR Muscle With $859M Secureworks Purchase
Sophos is acquiring Secureworks in a deal valued at $859 million, aiming to integrate its managed security services with Secureworks' Taegis XDR platform. This merger is expected to deliver advanced detection and response capabilities, and enhance global cybersecurity for businesses of all sizes.
Dental Center Chain Settles Data Breach Lawsuit for $2.7M
A Michigan-based dental practice with 250 centers across nine states has agreed to pay $2.7 million under a preliminary settlement of a proposed consolidated class action lawsuit centered on a 2023 hacking incident reported as affecting more than 1.9 million patients and employees.
CISA Ramping Up Election Security Warnings as Voting Begins
The Cybersecurity and Infrastructure Security Agency is ramping up its warnings of potential election interference and influence campaigns in the lead up to the November vote. But voters can be assured their ballots are secure and will be counted as cast, the agency said.
Researchers Debut AI Tool That Helps Detect Zero-Days
Security researchers have developed an AI tool that can detect remote code flaws and arbitrary zero-day code in software. Protect AI applied the tool to nearly 10,000 GitHub projects and on CVSS data and uncovered local file inclusion, cross-site scripting and remote code flaws in APIs.
Using gRPC and HTTP/2 for Cryptominer Deployment: An Unconventional Approach
Russia-Linked Hackers Attack Japan's Govt, Ports
如何寻找隐藏的参数
Inside the Dark Web: How Threat Actors Are Selling Access to Corporate Networks
In recent weeks, underground forums on the dark web have continued to flourish as bustling marketplaces where cybercriminals sell unauthorized access to corporate networks. From VPN credentials to Remote Desktop Protocol (RDP) access, threat actors take advantage of compromised corporate environments, often leveraging data from recent breaches or stolen via infostealers. This analysis highlights the …
The post Inside the Dark Web: How Threat Actors Are Selling Access to Corporate Networks appeared first on Security Boulevard.