New Darkweb marketplace STYX, for any kind of financial fraud can replace Genesis market
07
Apr
2023

New Darkweb marketplace STYX, for any kind of financial fraud can replace Genesis market

It was only recently revealed that the well-known Dark Web marketplace Genesis’s Clearnet site was taken over by authorities. Now,…

Microsoft and Fortra to Take Down Malicious Cobalt Strike Infrastructure
07
Apr
2023

Microsoft and Fortra to Take Down Malicious Cobalt Strike Infrastructure

The U.S. District Court for the Eastern District of New York permits Microsoft to seize malicious Cobalt Strike infrastructure used…

Reflected XSS at Philips.com. A full write-up; reflected XSS was… | by Jonathan Bouman
07
Apr
2023

Reflected XSS at Philips.com. A full write-up; reflected XSS was… | by Jonathan Bouman

Proof of concept Are you aware of any (private) bug bounty programs? I would love to get an invite. Please…

CISA orders agencies to address Backup Exec bugs exploited in ransomware attack
07
Apr
2023

CISA orders agencies to patch Backup Exec bugs used by ransomware gang

On Friday, U.S. Cybersecurity and Infrastructure Security Agency (CISA) increased by five its list of security issues that threat actors…

BOUNTY THURSDAYS - LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions)
07
Apr
2023

BOUNTY THURSDAYS – LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions)

BOUNTY THURSDAYS – LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions) Source link

Facebook Gameroom
07
Apr
2023

Applying Offensive Reverse Engineering to Facebook Gameroom

Late last year, I was invited to Facebook’s Bountycon event, which is an invitation-only application security conference with a live-hacking…

Meet Anthalon, fighting for freedom of the press
07
Apr
2023

Meet Anthalon, fighting for freedom of the press

In today’s world, censorship and suppression of free speech are rampant in many parts of the globe. Governments and non-governmental…

Remotely Managing Hyper-V in a Workgroup Environment
07
Apr
2023

Remotely Managing Hyper-V in a Workgroup Environment

A few weekends ago, I decided (because apparently I’m a masochist) that I was tired of the free version of…

Massive Balada Injector campaign attacking WordPress sites since 2017
07
Apr
2023

Massive Balada Injector campaign attacking WordPress sites since 2017

An estimated one million WordPress websites have been compromised during a long-lasting campaign that exploits “all known and recently discovered…

How I could Steal Your Google Bug Hunter Account with Two Clicks in IE – Ron Chan
07
Apr
2023

How I could Steal Your Google Bug Hunter Account with Two Clicks in IE – Ron Chan

This post is another evidence to show how difficult to parse a URL correctly. IE has URL parsing problem, this…

Apple
07
Apr
2023

Apple fixes two zero-days exploited to hack iPhones and Macs

Apple has released emergency security updates to address two new zero-day vulnerabilities exploited in attacks to compromise iPhones, Macs, and…

No BS Guide - Better Subdomain Enumeration
07
Apr
2023

No BS Guide – Better Subdomain Enumeration

No BS Guide – Better Subdomain Enumeration Source link