cyber
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/
Welcome back to another watchTowr Labs blog. Brace yourselves, this is one of our most astounding discoveries.
Summary
What started out as a bit of fun between colleagues while avoiding the Vegas heat and $20 bottles of water in our Black Hat hotel rooms - has now seemingly become a
Added 1 month ago
https://www.helpnetsecurity.com/2024/09/10/open-source-cybersec-tools/
https://www.helpnetsecurity.com/2024/09/10/open-source-cybersec-tools/
Here, you'll find a list of free, open-source cybersec tools that are ready to be added to your organization's arsenal.
Added 1 month ago
pushsecurity/saas-attacks
https://github.com/pushsecurity/saas-attacks?tab=readme-ov-file
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown - pushsecurity/saas-attacks
Added 1 month ago
Bypassing airport security via SQL injection
https://ian.sh/tsa
We discovered a serious vulnerability in the Known Crewmember (KCM) and Cockpit Access Security System (CASS) programs used by the Transportation Security Administration.
Added 1 month ago
Nuclei: Open-source vulnerability scanner - Help Net Security
https://www.helpnetsecurity.com/2024/08/26/nuclei-open-source-vulnerability-scanner/
Nuclei is a fast and customizable open-source vulnerability scanner powered by YAML-based templates. With its flexible templating system, Nuclei can be
Added 1 month ago
Local Networks Go Global When Domain Names Collide – Krebs on Security
https://krebsonsecurity.com/2024/08/local-networks-go-global-when-domain-names-collide/
The proliferation of new top-level domains (TLDs) has exacerbated a well-known security weakness: Many organizations set up their internal Microsoft authentication systems years ago using domain names in TLDs that didn't exist at the time. Meaning, they are continuously sending…
Added 1 month ago
OpenCTI: Open-source cyber threat intelligence platform - Help Net Security
https://www.helpnetsecurity.com/2024/08/21/opencti-open-source-cyber-threat-intelligence-platform/
OpenCTI is an open-source platform designed to help organizations manage their cyber threat intelligence (CTI) data and observables.
Added 1 month ago