JSC GREC Makeyev and other Russian entities under attack
A cyberespionage campaign hit multiple Russian organizations, including JSC GREC Makeyev, a major defense contractor, exploiting a recently disclosed zero-day....
A cyberespionage campaign hit multiple Russian organizations, including JSC GREC Makeyev, a major defense contractor, exploiting a recently disclosed zero-day....
A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free...
Researchers from Google’s TAG team reported that financially motivated actors are using new code signing tricks to evade detection. Researchers...
The customer care and call center provider GSS has suffered a ransomware attack that crippled its systems and impacted its...
QueenSono tool only relies on the fact that ICMP protocol isn't monitored. It is quite common. It could also been...
Project dedicated to provide DDoS protection with proof-of-workDescriptionPoW Shield provides DDoS protection on OSI application layer by acting as a...
Immediately after the public release of the exploit code for the VMware vCenter CVE-2021-22005 flaw threat actors started using it....
Google released a Chrome emergency update for Windows, Mac, and Linux that addresses a high-severity zero-day flaw exploited in the wild....
European Union representatives formally accused Russia of attempting to target the elections and political systems of several EU states. European...
SonicWall fixed a critical security flaw, tracked as CVE-2021-20034, that impacts some Secure Mobile Access (SMA) 100 series products that...
Turns any junk text into a usable wordlist for brute-forcing.Installationgo install github.com/hakluke/haklistgen@latest Usage ExamplesScrape all words out of an HTTP...
Reconky is a script written in bash to automate the task of recon and information gathering.This Bash Script allows you...
Researcher release PoC exploit code for three iOS zero-day flaws after Apple delayed addressing them and did not credit him....
Cisco fixed three critical flaws impacting IOS XE operating system powering some of its devices, such as routers and wireless...
A user on a popular hacker forum is selling a database that purportedly contains 3.8 billion Clubhouse and Facebook user...
Researchers spotted a new cyberespionage group, dubbed FamousSparrow, that used ProxyLogon exploits to target hotels worldwide. Researchers from ESET discovered a...
Apple has addressed three zero-day vulnerabilities exploited by threat actors in attacks in the wild to take over iPhones and...
A flaw in the Microsoft Exchange Autodiscover feature can be exploited to harvest Windows domain and app credentials. Security researchers...
Source code analysis - Screenshot Supporting Materials : https://twitter.com/har1sec/status/1314469278322655233 https://github.com/BlackFan/client-side-prototype-pollution https://github.com/ThePacketBender/notes/blob/01c0b834f6e3ee4d934b087b2d92c9e484dc2a50/web/prototype_pollution.txt https://habr.com/ru/company/huawei/blog/547178/ https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2 https://github.com/securitum/research/tree/master/r2020_prototype-pollution Learn Prototype Pollution in Series -...
wordlistgen is a tool to pass a list of URLs and get back a list of relevant words for your...
Microsoft uncovered a large-scale phishing-as-a-service operation, dubbed BulletProofLink, that enabled threat actors to easily carry out malicious campaigns. Microsoft researchers...
Minnesota-based farming supply cooperative Crystal Valley was hit by a ransomware attack, it is the second attack against the agriculture...
CVE-2021-40847 flaw in Netgear SOHO routers could be exploited by a remote attacker to execute arbitrary code as root. Security...
CISA, FBI, and the NSA warned today of an escalation of the attacks of the Conti ransomware gang targeting US...