"I'm the cybersecurity director at NSA and you could absolutely craft a phishing message that would get me to click a link. You’ve got to design your architecture to assume the humans are humans and bad things will happen." @RGB_Lights
AMEN
Needle (CVE-2023-0179) exploit
This repository contains the exploit for my recently discovered vulnerability in the nftables subsystem that was assigned CVE-2023-0179
https://t.co/LL9quUUN69
🚨This unauthorized RCE bug (CVE-2023-21554) in the "forgotten" MSMQ service may have big impact. If you’re a Windows admin, you need to check your environments ASAP (you may have unawarely enabled the service).
https://t.co/oNelXKq2ZO
OpenAI (LLM) Integration is coming to @pdnuclei using DSL that can be used in the template input/output context.
Here is a basic example of analyzing the response header, but it could be anything! unknown patterns/secrets; it's a matter of how creative you can be with your query to explore the power of LLM.
Used prompt with DSL extractor in the shared template -
llm_prompt("what tech this server is using? return idk if you dont know" + header)
Let me know what you think or have any other interesting use cases or ideas to utilize LLM / prompts for security?
#hackwithautomation #openai #LLM
If you've ever had to deal with angry family members because you accidentally got blocked by a WAF then listen up! 🚨
⚠️ Detect if a url is behind a WAF before testing it with the WAF-detect template!
Find it here 👉 https://t.co/XP6TRiJ95U
El grupo Ransom House responde y confirma el ataque #DDoS realizado por los Mossos.
Amenaza con publicar mas datos en breve sobre pacientes con enfermedades infecciosas.
Via @_bettercyber_
The final results of the Blockchain Hacking Techniques of 2022 are in! After a year of increased participation, as well as novel attack vectors leading to over $3.7B in losses, this initiative aims to provide critical insights into the ongoing challenges facing blockchain security. Ultimately, the collective efforts of the community can help to ensure the safety and stability of Web3 projects in the future.
Read the final results below 👇
https://t.co/hGp0K3OjJx
Sometimes when developers configure CORS origin whitelists, they accidentally allow connections from unwanted origins and potentially facilitate data transfer to malicious origins!
Let's look at the most common mistakes developers make when setting up CORS policies 👇
Nueva Vulnerabilidad en Azure Active Directory 😱: Ataque BingBang 💥 Compromete Bing y Datos Personales de Usuarios 👥
Wiz Research 🔍 @wiz_io han descubierto un nuevo vector de ataque en Azure Active Directory 😰 que deja expuestas aplicaciones mal configuradas a accesos no autorizados 🚫. Esta vulnerabilidad afecta aproximadamente al 25% de las aplicaciones multi-tenant 📊.
Entre las aplicaciones vulnerables de Microsoft, se encuentra un sistema de gestión de contenidos (CMS) que controla https://t.co/KPSklKl2W6 🌐, lo que permite modificar resultados de búsqueda 🔍 y lanzar ataques XSS 💣 de alto impacto en los usuarios de Bing, poniendo en riesgo datos personales como correos electrónicos de Outlook 📧 y documentos de SharePoint 🧵👇
👋 I just released "JSpector" : a simple Burp Suite extension to passively crawl JS files and display the results (URLs & endpoints) in the "Issues" tab of each target.
I needed something simple to do this, and now that it's done, I'm sharing i!🤗
➡ You can download it here: https://t.co/K8Bn6Btb2e
#BugBounty