Bypassing Server-Side Request Forgery filters by abusing a bug in Ruby's native resolver
12
Apr
2023

Bypassing Server-Side Request Forgery filters by abusing a bug in Ruby’s native resolver

Summary This is a security advisory for a bug that I discovered in Resolv::getaddresses that enabled me to bypass multiple…

12
Apr
2023

Threat hunting programs can save organizations from costly security breaches

Cybersecurity threats to organizations are only increasing, not only in number but in scope, according to Team Cymru. The true…

See technologies on the attack surface plus updates to Attack Surface Custom Policies and API keys
12
Apr
2023

See technologies on the attack surface plus updates to Attack Surface Custom Policies and API keys

Tl;dr We’ve made some major improvements to data shown on the Surface Management page. We’ve also made a few updates…

danielmiessler_an_artificial_intelligence_filtering_newsletters_c3b22c72-ca87-4f38-a72b-6f5e48784025
12
Apr
2023

AI’s Threat to Newsletters – Daniel Miessler

We’re about to see a blast of AI-generated newsletters, and most human creators won’t survive Created/Updated: April 10, 2023 AI-driven…

Discovering Cloud Assets Externally, with CloudEnum
12
Apr
2023

Discovering Cloud Assets Externally, with CloudEnum

Discovering Cloud Assets Externally, with CloudEnum Source link

A week in security (April 3
12
Apr
2023

A week in security (April 3

The most interesting security related news from the week of April 3 – 9. Last week on Malwarebytes Labs: Stay…

Hunting IDOR with Z-winK (Part 2)
12
Apr
2023

Hunting IDOR with Z-winK (Part 2)

Hunting IDOR with Z-winK (Part 2) Source link

Apple releases emergency updates for two known-to-be-exploited vulnerabilities
12
Apr
2023

Apple releases emergency updates for two known-to-be-exploited vulnerabilities

Apple has released iOS 16.4.1, iPadOS 16.4.1, and macOS 13.3.1 for the iPhone, iPad, and Mac, respectively, and our advice…

How to get greater bounties for MEDIUM and LOW risk reports? Account takeover - Stripe
12
Apr
2023

How to get greater bounties for MEDIUM and LOW risk reports? Account takeover – Stripe

How to get greater bounties for MEDIUM and LOW risk reports? Account takeover – Stripe Source link

Microsoft (& Apple) Patch Tuesday, April 2023 Edition – Krebs on Security
12
Apr
2023

Microsoft (& Apple) Patch Tuesday, April 2023 Edition – Krebs on Security

Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a…

11
Apr
2023

What is TCP/IP? Layers and protocols explained

Alternatively titled, “Why the Internet Protocol Suite is an imaginary rainbow layer cake” A significant part of the process of…

Nahamsec interviews Alyssa Herrera
11
Apr
2023

Nahamsec interviews Alyssa Herrera

Note that during these interviews I also moderate thus quality may vary. Profile 🐝 Got into hacking in middleschool Cicumventing…