■■■□□ Recruitment Trap for Blockchain Practitioners: Analysis of Suspected Lazarus (APT-Q-1) Secret Stealing Operation. https://mp.weixin.qq.com/s/84lUaNSGo4lhQlpnCVUHfQ https://t.me/cKure/14006
All posts tagged cyber
May 10, 2024 at 06:25AM
■■■■■ Active Directory LDAPS certificate selection deep dive. https://awakecoding.com/posts/active-directory-ldaps-certificate-selection-deep-dive/ https://t.me/cKure/14005
May 10, 2024 at 06:21AM
■■■■□ Analysing a NSO iOS Spyware Sample(#blastpass) CVE-2023-41064 + CVE-2023-41061 + WebP Vulnerability CVE-2023-4863. https://github.com/blackorbird/APT_REPORT/blob/master/NSOGroup/Asia-24-Frielingsdorf-YouShallNotPassAnalysing.pdf https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/ https://t.me/cKure/14004
May 9, 2024 at 10:33PM
■■■□□ Talos discloses multiple zero-day vulnerabilities, two of which could lead to code execution. https://blog.talosintelligence.com/vulnerability-roundup-zero-days-may-8-2024/ https://t.me/cKure/14003
May 9, 2024 at 03:39PM
■■■■■ Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246). https://medium.com/@elpepinillo/heap-heap-hooray-unveiling-glibc-heap-overflow-vulnerability-cve-2023-6246-0c6412423269 https://t.me/cKure/14002
May 9, 2024 at 01:21AM
■■■■□ Awesome Burp extensions (plugins) list. https://github.com/snoopysecurity/awesome-burp-extensions https://t.me/cKure/14001
May 8, 2024 at 12:40AM
■■■■■ Code Interoperability: The Perils of Technological Diversity. https://www.sonarsource.com/blog/avocado-nightmare-1/ https://t.me/cKure/13999
May 8, 2024 at 12:14AM
■■■■□ AI enabled warfare. Technical details by VOX News of extermination of Muslims and Christians in Gaza, Palestine amid ongoing genocide using Gospel AI and modified version of it called Lavender AI. The same was covered by us in this post: https://t.me/ckuRED/432 https://t.me/cKure/13997
May 7, 2024 at 10:02PM
■□□□□ A tool to demonstrate how passwordless solutions such as Okta Verify’s FastPass or other FIDO2/WebAuthn type solutions can be abused once an authenticator endpoint has been compromised. https://github.com/CCob/okta-terrify https://t.me/cKure/13996
May 7, 2024 at 05:52PM
■■■■□ PoC of fuzzing closed-source userspace binaries with KVM. https://github.com/klecko/kvm-fuzz https://t.me/cKure/13994
