Author: Cybernoz

[tl;dr sec] #167 - SBOM, Scaling Security Alert Management, Mitigating RBAC-Based PrivEsc in Kubernetes
08
Apr
2023

[tl;dr sec] #167 – SBOM, Scaling Security Alert Management, Mitigating RBAC-Based PrivEsc in Kubernetes

Hey there, I hope you’ve been doing well! Come say “How ya?” at OWASP Dublin If you’re going to be…

Unveiling the Wild World of Bug Bounties
08
Apr
2023

Unveiling the Wild World of Bug Bounties

Unveiling the Wild World of Bug Bounties Source link

CSRF protection on OIDC login is broken
08
Apr
2023

CSRF protection on OIDC login is broken

Nextcloud disclosed a bug submitted by mikaelgundersen: https://hackerone.com/reports/1878381 Source link

Top 3 Most Dangerous Lines of Code
07
Apr
2023

Top 3 Most Dangerous Lines of Code

Top 3 Most Dangerous Lines of Code Source link

Firefox privacy and security hardening guide (2022 revised edition)
07
Apr
2023

Firefox privacy and security hardening guide (2022 revised edition)

Firefox privacy and security hardening guide (2022 revised edition) Source link

Targetoo's Precision Targeting Vows to Transform Mobile Advertising
07
Apr
2023

Targetoo’s Precision Targeting Vows to Transform Mobile Advertising

In today’s fast-paced digital world, mobile advertising has become an essential tool for businesses looking to engage with their target…

Easily leaking passenger information on an Airline | by Sean (zseano)
07
Apr
2023

Easily leaking passenger information on an Airline | by Sean (zseano)

This post is going to outline how I simply applied my methodology and managed to find multiple vulnerabilities leaking airline…

New Darkweb marketplace STYX, for any kind of financial fraud can replace Genesis market
07
Apr
2023

New Darkweb marketplace STYX, for any kind of financial fraud can replace Genesis market

It was only recently revealed that the well-known Dark Web marketplace Genesis’s Clearnet site was taken over by authorities. Now,…

Microsoft and Fortra to Take Down Malicious Cobalt Strike Infrastructure
07
Apr
2023

Microsoft and Fortra to Take Down Malicious Cobalt Strike Infrastructure

The U.S. District Court for the Eastern District of New York permits Microsoft to seize malicious Cobalt Strike infrastructure used…

Reflected XSS at Philips.com. A full write-up; reflected XSS was… | by Jonathan Bouman
07
Apr
2023

Reflected XSS at Philips.com. A full write-up; reflected XSS was… | by Jonathan Bouman

Proof of concept Are you aware of any (private) bug bounty programs? I would love to get an invite. Please…

CISA orders agencies to address Backup Exec bugs exploited in ransomware attack
07
Apr
2023

CISA orders agencies to patch Backup Exec bugs used by ransomware gang

On Friday, U.S. Cybersecurity and Infrastructure Security Agency (CISA) increased by five its list of security issues that threat actors…

BOUNTY THURSDAYS - LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions)
07
Apr
2023

BOUNTY THURSDAYS – LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions)

BOUNTY THURSDAYS – LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions) Source link