05/06

Cookie Bugs - Smuggling & Injection

https://blog.ankursundara.com/cookie-bugs/
Cookie Bugs - Smuggling & Injection

CVE-2023-25136 OpenSSH Pre-Auth Double Free Writeup & PoC

https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/
CVE-2023-25136 OpenSSH Pre-Auth Double Free Writeup & PoC

Metasploit Weekly Wrap-Up: May 5, 2023 | Rapid7 Blog

https://www.rapid7.com/blog/post/2023/05/05/metasploit-weekly-wrap-up-9/
Metasploit Weekly Wrap-Up: May 5, 2023 | Rapid7 Blog

Intel OEM Private Key Leak: A Blow to UEFI Secure Boot Security

https://securityonline.info/intel-oem-private-key-leak-a-blow-to-uefi-secure-boot-security/
Intel OEM Private Key Leak: A Blow to UEFI Secure Boot Security

Twitter says 'security incident' exposed private Circle tweets

https://www.bleepingcomputer.com/news/security/twitter-says-security-incident-exposed-private-circle-tweets/
Twitter says 'security incident' exposed private Circle tweets

Dragon Breath APT Group Using Double-Clean-App Technique to Target Gambling Industry

https://thehackernews.com/2023/05/dragon-breath-apt-group-using-double.html
Dragon Breath APT Group Using Double-Clean-App Technique to Target Gambling Industry

Lack of Visibility: The Challenge of Protecting Websites from Third-Party Scripts

https://thehackernews.com/2023/05/lack-of-visibility-challenge-of.html
Lack of Visibility: The Challenge of Protecting Websites from Third-Party Scripts

CVE-2021-38001: A Brief Introduction to V8 Inline Cache and Exploitating Type Confusion – !

http://y4y.space/2023/05/06/cve-2021-38001-a-brief-introduction-to-v8-inline-cache-and-exploitating-type-confusion/
CVE-2021-38001: A Brief Introduction to V8 Inline Cache and Exploitating Type Confusion – !

New Android FluHorse malware steals your passwords, 2FA codes

https://www.bleepingcomputer.com/news/security/new-android-fluhorse-malware-steals-your-passwords-2fa-codes/
New Android FluHorse malware steals your passwords, 2FA codes

Coming to DEF CON 31: Hacking AI models | CyberScoop

https://cyberscoop.com/def-con-red-teaming-ai/
Coming to DEF CON 31: Hacking AI models | CyberScoop

New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to Cyberattacks

https://thehackernews.com/2023/05/new-vulnerability-in-popular-wordpress.html
New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to Cyberattacks

Lab - Certificate Authority Setup

https://blog.nathanmcnulty.com/lab-certificate-authority-setup/
Lab - Certificate Authority Setup

WordPress Advanced Custom Fields plugin XSS exposes +2M sites to attacksSecurity Affairs

https://securityaffairs.com/145847/hacking/wordpress-advanced-custom-fields-xss.html
WordPress Advanced Custom Fields plugin XSS exposes +2M sites to attacksSecurity Affairs

misc/CVE-2023-28231_poc.py at master · omair2084/misc · GitHub

https://github.com/omair2084/misc/blob/master/CVE-2023-28231_poc.py
misc/CVE-2023-28231_poc.py at master · omair2084/misc · GitHub

Capita’s “standard industry practice” 633gb open cloud storage | by Kevin Beaumont | May, 2023 | DoublePulsar

https://doublepulsar.com/capitas-standard-industry-practice-633gb-open-cloud-storage-5d87e7e96a70
Capita’s “standard industry practice” 633gb open cloud storage | by Kevin Beaumont | May, 2023 | DoublePulsar

Evilginx Mastery

https://academy.breakdev.org/evilginx-mastery
Evilginx Mastery

APT_REPORT/Anonymous-Sudan-Report.pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/Anonymous/Anonymous-Sudan-Report.pdf
APT_REPORT/Anonymous-Sudan-Report.pdf at master · blackorbird/APT_REPORT · GitHub

c3rb3ru5d3d53c - Twitch

https://twitch.tv/c3rb3ru5d3d53c
c3rb3ru5d3d53c - Twitch

Visualizing Katana crawl results using SpiderSuite. | by Enock N Michael | May, 2023 | Medium

https://medium.com/@enock.n.michael/visualizing-katana-crawl-results-using-spidersuite-a49c853f24ee
Visualizing Katana crawl results using SpiderSuite. | by Enock N Michael | May, 2023 | Medium