04/01

Bypassing DOMPurify with good old XML - Flatt Security Research

https://flatt.tech/research/posts/bypassing-dompurify-with-good-old-xml/
Bypassing DOMPurify with good old XML - Flatt Security Research

Malicious Apps Caught Secretly Turning Android Phones into Proxies for Cybercriminals

https://thehackernews.com/2024/04/malicious-apps-caught-secretly-turning.html
Malicious Apps Caught Secretly Turning Android Phones into Proxies for Cybercriminals

Chaining N-days to Compromise All: Part 2 — Windows Kernel LPE (a.k.a Chrome Sandbox Escape) | by Theori Vulnerability Research | Apr, 2024 | Theori BLOG

https://medium.com/theori-blog/chaining-n-days-to-compromise-all-part-2-windows-kernel-lpe-a-k-a-chrome-sandbox-escape-44cb49d7a4f8
Chaining N-days to Compromise All: Part 2 — Windows Kernel LPE (a.k.a Chrome Sandbox Escape) | by Theori Vulnerability Research | Apr, 2024 | Theori BLOG

Vultur Android Banking Trojan Returns with Upgraded Remote Control Capabilities

https://thehackernews.com/2024/04/vultur-android-banking-trojan-returns.html
Vultur Android Banking Trojan Returns with Upgraded Remote Control Capabilities

BSides Canberra 2024 :: pretalx

https://cfp.bsidescbr.com.au/bsides-canberra-2024/cfp
BSides Canberra 2024 :: pretalx

Sign in

https://hackerone.com/last-month
Sign in

100% MITRE Coverage

https://attack.mitre.org/full-coverage.html
100% MITRE Coverage

Ido Veltzman :: Security Research

https://idov31.github.io/posts/lord-of-the-ring0-p6
Ido Veltzman :: Security Research

Identity Providers for RedTeamers - XPN InfoSec Blog

https://blog.xpnsec.com/identity-providers-redteamers/
Identity Providers for RedTeamers - XPN InfoSec Blog

AI Hallucinated Packages Fool Unsuspecting Developers - SecurityWeek

https://www.securityweek.com/ai-hallucinated-packages-fool-unsuspecting-developers/
AI Hallucinated Packages Fool Unsuspecting Developers - SecurityWeek

Shopping platform PandaBuy data leak impacts 1.3 million users

https://www.bleepingcomputer.com/news/security/shopping-platform-pandabuy-data-leak-impacts-13-million-users/
Shopping platform PandaBuy data leak impacts 1.3 million users

GitHub - Sudistark/xss-writeups

https://github.com/Sudistark/xss-writeups
GitHub - Sudistark/xss-writeups

OWASP Data Breach Notification | OWASP Foundation

https://owasp.org/blog/2024/03/29/OWASP-data-breach-notification
OWASP Data Breach Notification | OWASP Foundation

DinodasRAT Linux variant targets users worldwide

https://securityaffairs.com/161255/malware/linux-variant-dinodasrat-backdoor.html
DinodasRAT Linux variant targets users worldwide

Indian Government Rescues 250 Citizens Forced into Cybercrime in Cambodia

https://thehackernews.com/2024/04/indian-government-rescues-250-citizens.html
Indian Government Rescues 250 Citizens Forced into Cybercrime in Cambodia

From OneNote to RansomNote: An Ice Cold Intrusion - The DFIR Report

https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion/
From OneNote to RansomNote: An Ice Cold Intrusion - The DFIR Report

Android Malware Vultur Expands Its Wingspan – Fox-IT International blog

https://blog.fox-it.com/2024/03/28/android-malware-vultur-expands-its-wingspan/
Android Malware Vultur Expands Its Wingspan – Fox-IT International blog

Supply Chain Attack: Major Linux Distributions Impacted by XZ Utils Backdoor - SecurityWeek

https://www.securityweek.com/supply-chain-attack-major-linux-distributions-impacted-by-xz-utils-backdoor/
Supply Chain Attack: Major Linux Distributions Impacted by XZ Utils Backdoor - SecurityWeek

Reverse Engineering Dark Souls 3 Networking (#1 - Connection) - Tim Leonard's Website

https://timleonard.uk/2022/05/29/reverse-engineering-dark-souls-3-networking
Reverse Engineering Dark Souls 3 Networking (#1 - Connection) - Tim Leonard's Website

Harvard Pilgrim data breach grows again, nearing 3M victims • The Register

https://go.theregister.com/feed/www.theregister.com/2024/04/01/in_brief_security/
Harvard Pilgrim data breach grows again, nearing 3M victims • The Register

Marco Ivaldi: "#Identity Providers for #RedTe…" - Infosec Exchange

https://infosec.exchange/@raptor/112194407775713800
Marco Ivaldi: "#Identity Providers for #RedTe…" - Infosec Exchange

Exploiting n-day in Home Security Camera

https://0xbigshaq.github.io/2024/01/05/tp-link-tapo-c100/
Exploiting n-day in Home Security Camera

FTC: Americans lost $1.1 billion to impersonation scams in 2023

https://www.bleepingcomputer.com/news/security/ftc-americans-lost-11-billion-to-impersonation-scams-in-2023/
FTC: Americans lost $1.1 billion to impersonation scams in 2023

https://redsiege.com/sshishing

https://redsiege.com/sshishing

Bloop Suite Shorts - YouTube

https://youtu.be/xZuCrSMPvZ8
Bloop Suite Shorts - YouTube