Our security team at @YSecurity has identified multiple vulnerabilities in TIM BPM Suite/TIM FLOW, allowing authorization bypass, privilege escalation, and SQL/HQL injection.
Advisory + Mitigation: https://t.co/8hQFq0wn2s
Our security team at @YSecurity has identified a vulnerability in AXESS Auto Configuration Server (CVE-2024-56316) which allows unauthenticated remote attackers to trigger a permanent DoS.
Advisory + Mitigation: https://t.co/6P23JaVskn
#YSecurity#CVE202456316#TR069#ACS
Between July 2023 and June 2024, Microsoft observed nation-state threat actors conduct operations for financial gain, enlist cybercriminals to collect intelligence, and make use of the same tools and frameworks favored by cybercriminals: https://t.co/sB1inbeUtm
The time has come, and with it your reading material for the week.
Phrack #71 is officially released ONLINE! Let us know what you think!
https://t.co/BRnK9lnGjI
We have publicly released our internal tool StealthGuardian at Black Hat USA 2024.
It can be combined with adversary simulation tools to verify the resistance, detection level and behaviour detection of defence mechanisms.
https://t.co/QzlnzvmAAS
#bhusa#blackhat#redteam
Are you taking steps towards a career as an Attack Simulation Specialist?
Maybe you already have experience as a Penetration Tester or with platforms like Hack The Box or certifications like OSCP?
If so, we would love to talk to you!
#job#redteam#pentest#germany
Our tool StealthGuardian has been accepted for Black Hat ARSENAL USA 2024. The Y-Security team will be in Las Vegas to present on protecting Red Team payloads from Blue Teams.
https://t.co/2yV075y5Pj
#BlackHat#BHUSA#RedTeam#VegasBaby
New blog: Lateral movement and on-prem NT hash dumping with Microsoft Entra Temporary Access Passes.
Some tips and tricks on abusing TAPs for Windows Hello persistence and NT hash recovery over Cloud Kerberos Trust. https://t.co/h3XHjBhwtz
Our team recently took the challenge of mastering the Red Team Ops I and Red Team Ops II exam offered by @zeropointsecltd . After completion, we received both the Red Team Operator and Red Team Lead certifications.
Read our recent post: https://t.co/fAeTOhkHgv
#RedTeam#RTO
Recently we checked the security of a LoRaWAN implementation. In our latest post we share insights about the security of LoRaWAN, common LoRaWAN attacks and how we built a custom methodology and testing environment.
https://t.co/z5vyADDsyf
#pentest#lorawan#ysecurity
Template engines are very popular in web applications. A severe threat posing a risk for the application, its data, and its users: Template Injection Vulnerabilities
Detect them – manually and automatically:
Blog 🌐https://t.co/5YDHcJdPWD
Tool 🛠️ https://t.co/JzxS6O9oLq
@ajxchapman@github You will not like it ... graphql can provide you with the attachment link:
query{project(fullPath:"your/project"){issues{nodes{title notes{edges{node{id body}}}}}}}
We started to play with censorship circumventions. Of course, we exploit our TLS skills to bypass big firewalls. In our first work, @JonSnowWhite2 shows that TLS record fragmentation is a useful technique to bypass the Great Firewall of China (GFW). https://t.co/RfiQFPvbKf