Found SaltStack on a network and don't know how to attack the thing? Check out how a few configuration issues and a new spin on Jinja template injections can undo a network managed by Salt
#SaltStack#cybersecurity#redteam#Pentesting
https://t.co/pPprqEjgsV
Researchers disclose details on several critical vulnerabilities affecting Nagios IT monitoring #software that could let attackers hijack corporate networks.
Read: https://t.co/aic8rxv3iJ
#infosec#cybersecurity#hacking
@sam0x21r from @SkylightCyber at #bsidescbr had a good look at Nagios and found, at last count, 13 vulnerabilities! A classic line in the <src> code: “as long as user input is never passed here directly this is safe”.
Samir Ghanem taking us through his inspirational journey from career amnesia, to how a monitoring tool helped him find a new passion in life. #7 definitely shocked me. @BSidesCbr#bsidescbr
Introducing VNSee, a post-exploitation tool for turning enterprise RealVNC installations to a credential harvesting machine as well as a backdoor. Choose better authentication protocols.
https://t.co/kaKgQra5n5
https://t.co/E6GrwCKeIh
It's not every day that you get to find a super simple vulnerability that enables you to gain root privileges on one server. Hang on... make it *all* the servers in a given cloud. Sorry, I meant gazillion servers in thousands of cloud companies! Post here: https://t.co/ZPnhalQ22b
"Rocket League" is the game we've used to deceive Cylance's AI.
We've just updated our write-up of our Cylance universal passive bypass to include information yet to be published. Seems like Cylance SmartAV is still exploitable :-(
https://t.co/Azrc2EaoyC
@ram_ssk@martijn_grooten@KimZetter@dlowd With spam, you know that strings are the *the* features. No real need to analyze the feature extraction process and how the model is applied to the feature vector. Also, you have a good chance hypothesising about what strings would be good or bad. We had neither in this case.
@ram_ssk@martijn_grooten@KimZetter@dlowd Hi, actually we did not attack the centroids mechanism, it just provided us with the necessary inspiration to abuse the main model (which is based on neural network approximated using matrix multiplication). You can read the technical details here: https://t.co/Azrc2EaoyC
AI vendors said they solved end point security. We checked, they didn't.
Check out our rather amusing bypass for @cylanceinc as reported by @KimZetter on @VICE : https://t.co/Azrc2EaoyC
We demonstrate how Right-To-Left-Override tricks can be applied to deceive users and auditors of smart contracts, and discuss mitigation techniques
#ethereum#SmartContracts#vulnerabilities#solidity
https://t.co/i34aN1MHYK
Thanks to a suggestion by
@VessOnSecurity we've uploaded an extended list of targeted MAC addresses to indicate when a single MAC address means you have been targeted and when two MAC addresses are required. #shadowhammer Download at https://t.co/G8QUVpi34M
Thanks to https://t.co/Oa34QN6AEK @FSecure we were able to reverse some more hashes out of #shadowhammer target list. The updated list can be found in https://t.co/G8QUVpi34M
@VessOnSecurity@TheHackersNews Technically, you are correct. We wanted to get the list published so that large organizations can quickly verify that they have not been targeted. Most will get negative response, others will have to dig deeper