Category: Mix

Information Security News Resources
17
Mar
2023

Information Security News Resources

A centralized way to consume your information security news, with a focus on web application security. Save time and effort,…

Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI – Assetnote
17
Mar
2023

Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI – Assetnote

At Assetnote, we often audit enterprise software source code to discover pre-authentication vulnerabilities. Yellowfin BI had significance to us because…

Your Java builds might break starting January 13th (no more repo access via HTTP)
17
Mar
2023

Your Java builds might break starting January 13th (if you haven’t yet switched repo access to HTTPS) – Alphabot Security

Summary This blog post is a reminder that you should make sure that all your builds in the Java ecosystem…

an Out-of-Band DNS Monitor – allysonomalley.com
17
Mar
2023

an Out-of-Band DNS Monitor – allysonomalley.com

I’ve been working on a few small projects while learning Go, and this one turned out to be useful enough…

Container security: Privilege escalation bug patched in Docker Engine
17
Mar
2023

Container security: Privilege escalation bug patched in Docker Engine

Adam Bannister 09 February 2021 at 12:47 UTC Updated: 09 February 2021 at 12:59 UTC ‘An odd one, impact wise’…

17
Mar
2023

AMF parsing and XXE | Agarri : Sécurité informatique offensive

AMF parsing and XXE I recently played with two libraries parsing the AMF (aka Action Message Format) binary format: BlazeDS…

2022 Year-End API ThreatStats™ Report
16
Mar
2023

2022 Year-End API ThreatStats™ Report

In 2022, the Wallarm Threat Research team went through almost 350,000 reports to find 650 API-specific vulnerabilities, and tracked 115…

Career and Community building with Bug Bounties | NahamCon Panel
16
Mar
2023

Career and Community building with Bug Bounties | NahamCon Panel

Career and Community building with Bug Bounties | NahamCon Panel Source link

Networking Fundamentals
16
Mar
2023

Networking Fundamentals

Networking Fundamentals Source link

[tl;dr sec] #173 - What Software Will Be Post GPT-4, the Cybersecurity Landscape, Reducing Attack Surface in AWS
16
Mar
2023

[tl;dr sec] #173 – What Software Will Be Post GPT-4, the Cybersecurity Landscape, Reducing Attack Surface in AWS

Hey there, I hope you’ve been doing well! Pi Day In case you weren’t familiar, March 14th (3.14) was National…

Webinar: Bug Bounty Q&A
16
Mar
2023

Webinar: Bug Bounty Q&A

Webinar: Bug Bounty Q&A Source link

[CVE-2022-44268] Arbitrary Remote Leak via ImageMagick
16
Mar
2023

[CVE-2022-44268] Arbitrary Remote Leak via ImageMagick

HackerOne disclosed a bug submitted by mikkocarreon: https://hackerone.com/reports/1858574 – Bounty: $25000 Source link