TechDailyCFP · @techdailycfp
25 followers · 428 posts · Server techhub.social

NULLCON (nullcon.net):

📡Time is running out for you to inspire the whole industry with your !

⚠️Call for Papers ends tonight 11:59 PM IST➡️ t.co/ZVLrlvZurC

t.co/GPDXIHLMIX

#securityresearch #nullcongoa2023 #cfp #infosec #conference

Last updated 1 year ago

TechDailyCFP · @techdailycfp
21 followers · 386 posts · Server techhub.social

NULLCON (nullcon.net):

💡Re-imagined Nullcon call for papers in the Anime World & with this, we are excited to receive your innovation in

⌚7 days left to submit | Call for Papers ➡️t.co/ZVLrlvZurC

t.co/d16xfYtjDo

#securityresearch #nullcongoa2023 #cfp #infosec #conference

Last updated 1 year ago

TechDailyCFP · @techdailycfp
19 followers · 356 posts · Server techhub.social

NULLCON (nullcon.net):

🤖Generative AI is growing in popularity in almost all products/industries; your scope is even wider now!

⌨️Present your latest with a vast range of topics you can choose ⌚Call for Papers ends on 10th July➡️t.co/ZVLrlvZurC

t.co/FVzU2ZN39c

#securityresearch #nullcongoa2023 #cfp

Last updated 1 year ago

· @kfekete
102 followers · 130 posts · Server hachyderm.io

Let's say you are a company with $2B+ revenue.
Let's say you have a security.txt with an email address.

Why don't you answer to emails from that email address?

Context: I started to hunt for bug bounties only 2 months ago, but I feel like I could already write multiple blog posts about my frustrations.

#security #securityresearch #BugBounty

Last updated 1 year ago

TechDailyCFP · @techdailycfp
19 followers · 311 posts · Server techhub.social

NULLCON (nullcon.net):

📢 Call for Papers closing soon! The platform where you can calm your senses, enjoy the 🌴serene destination & present your latest with a thrill

💻Submit your proposals by 10th July ➡️t.co/ZVLrlw02ha

@cfp_time t.co/cRyAHOkq3D

#securityresearch #nullcongoa2023 #cfp #conference

Last updated 1 year ago

GitHub · @github
27 followers · 86 posts · Server techhub.social
TechDailyCFP · @techdailycfp
11 followers · 175 posts · Server techhub.social

NULLCON (nullcon.net):

🌊 Experience the perfect blend of your cutting-edge research + relaxed vibes in one of the most beautiful destinations 🌅🌴

It's time to present your latest 👉 t.co/ZVLrlvZurC

t.co/mif0Hhgo3g

#securityresearch #cfp #nullcongoa2023 #callforpapers #infosec #conference

Last updated 1 year ago

TechDailyCFP · @techdailycfp
11 followers · 108 posts · Server techhub.social

NULLCON (nullcon.net):

🚀If you are the one pushing the boundaries with your then submit your research at Asia's finest destination & inspire the incredible community

🟢Call for Papers ends on 10th July ➡️ t.co/ZVLrlvZurC

t.co/Ob1l55qbnM

#securityresearch #infosec #nullcongoa2023 #cfp

Last updated 1 year ago

GitHub · @github
2 followers · 15 posts · Server techhub.social
Cory Doctorow's linkblog · @pluralistic
39937 followers · 37539 posts · Server mamot.fr

Mr Unpronounceable Adventures, spectacularly weird graphic novel in a Lovecraftian/Burroughsian vein memex.craphound.com/2013/03/30

Group whose entry was deleted for non-notability threatens lawsuit against Wikipedian who participated in the discussion mako.cc/copyrighteous/the-inst

Georgia criminalizes routine eff.org/deeplinks/2018/03/geor

6/

#10yrsago #wikipedia #5yrsago #securityresearch

Last updated 1 year ago

Neil Carpenter :unverified: · @neilcar
199 followers · 855 posts · Server infosec.exchange

Orca's cloud security research pod is hiring. Like I said on LinkedIn, they're a fantastic team doing important work. You'd probably be a good fit.

linkedin.com/feed/update/urn:l

#job #work #cloudresearch #securityresearch #cloudsecurity

Last updated 1 year ago

aegilops :github::microsoft: · @aegilops
118 followers · 432 posts · Server fosstodon.org

You can now run a single static analysis query across thousands of repos on GitHub using CodeQL's MRVA (Multi-repo Variant Analysis).

That's great both for security research and rapidly auditing exposure to a single vuln or weakness for security teams.

It works from the CodeQL extension for VSCode, with open source public repos & private repos where CodeQL Code Scanning is enabled.

github.blog/2023-03-09-multi-r

#github #securityresearch #vulnerabilityresearch #CodeQL #variantanalysis #mrva #sast

Last updated 1 year ago

James D · @jamesd
113 followers · 9 posts · Server infosec.exchange

Very grateful for my first CVE assigned by Apple today 🍎 -- Hopefully a blog post coming soon!

#grateful #securityresearch

Last updated 1 year ago

ronin-rb · @ronin_rb
62 followers · 24 posts · Server infosec.exchange
Opalsec :verified: · @Opalsec
160 followers · 74 posts · Server infosec.exchange

Security research company Horizon3 released a proof-of-concept (PoC) exploit for a vulnerability in the Fortinet FortiNAC appliance, just two business days after the vendor notified customers of its existence.

The PoC allows an attacker to write arbitrary files to disk, and was seized upon by malicious actors who - just one day later - were seen deploying web shells on vulnerable appliances in-the-wild.

While security research is an undeniably important component of Cyber Security, its participants are often on the bleeding edge of offensive tradecraft, and need to be cautious that their research isn't abused by bad actors.

Allowing organisations just two business days to patch a vulnerability before releasing a fully-functional exploit into the wild does not meet that standard.

This isn't a criticism of Horizon3 themselves, but a reminder that organisations take time to discover and patch vulnerabilities, and security researchers need to be mindful of this - especially when publishing offensive tooling.

opalsec.substack.com/p/poc-lea

#infosec #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #redteam #soc #threatintel #threatintelligence #poc #exploit #fortinet #fortinac #securityresearch

Last updated 1 year ago

Some New / for Some / / and Added to the list:

Full List here => github.com/DamonMohammadbagher

1. [offensive] @trickster012 , (Rust Weaponization for Red Team Engagements) => lnkd.in/eWsKKFY9

2. [offensive] @trickster012 , (roof of concept of bypassing(unhooking) the hook of potential EDRs) => lnkd.in/eQwQr4sY

3. [offensive] Deep Instinct , (A POC for the new injection technique, abusing windows fork API to evade EDRs) => lnkd.in/eGP2haTc

4. [offensive] @daem0nc0re , (investigation of Windows process execution techniques [C#]) => lnkd.in/eeyFi5Xz

5. [offensive] @D1rkMtr , (Bypass Userland EDR hooks by Loading Reflective Ntdll in memory) => lnkd.in/eVTy8WvP

6. [defensive] @ZeroMemoryEx , (malware analysts to extract Command and Control C2 traffic) => lnkd.in/eGWGKWgQ

7. [offensive] lem0nSec , (CreateRemoteThread: how to pass multiple parameters to the remote thread function without shellcode) => lnkd.in/eQ6ssfhK

8. [offensive] QAX A-Team , (A tool mainly to erase specified records from Windows event logs) => lnkd.in/eywTbFzr

9. [offensive] 3gstudent , (Remove individual lines from Windows XML Event Log (EVTX) files) => lnkd.in/ebn4AdaH

10. [offensive] @hlldz , (Windows Event Log Killer) => lnkd.in/es7V6xHt

11. [defensive] @foxit , (detect use of the DanderSpritz eventlogedit module [recover the removed event log entries]) => lnkd.in/evWYwRXQ

12. [offensive] @Ceramicskate0 , (C# Tool to interact with MS Exchange based on MS docs) => lnkd.in/ehiAcM6Z

13. [offensive] @reveng007 , (implant will exfiltrate data via smtp and will read commands from C2 [Gmail] via imap protocol) => lnkd.in/eBiXyEtR

14. [offensive] @cyberwarfarelab , (VectoredSyscall) => lnkd.in/eps_aJ6Z

15. [offensive] fosstodon.org/@mttaggart , (Notion as a platform for offensive operations) => lnkd.in/eXvKFTwP

16. [offensive] @t3l3machus , (A Windows reverse shell payload generator) => lnkd.in/e-Ce2zii

17. [offensive] @idov31 , (Sandman is a NTP based backdoor for red team engagements in hardened networks) => lnkd.in/eWzsBdXD

Full List here => github.com/DamonMohammadbagher

#codes #researches #pentesters #redtemaers #blueteamers #securityresearchers #cybersecurity #offensivesecurity #securityresearch #defensive #redteam #blueteam #pentest

Last updated 1 year ago

Wireghoul · @Wireghoul
253 followers · 107 posts · Server infosec.exchange
Zack Glick · @z1g1
101 followers · 29 posts · Server infosec.exchange

Fun walk thru from the port swigger crew on the Top 10 web hacking techniques of 2022 portswigger.net/research/top-1 Not as close to the vulnerability Reaserch space in this current job as the last but this is a great reminder about all TNT work going on in the and spaces. Keep those coordinated disclosures flowing

#securityresearch #bugbounty

Last updated 1 year ago

Doyensec · @doyensec
12 followers · 6 posts · Server infosec.exchange

Need help securing against the arbitrary file read described in CVE-2022-44268? The pictured policy change can mitigate it for you.

For more recommendations on hardening your security policies check out our free tool at:
imagemagick-secevaluator.doyen

#imagemagick #doyensec #appsec #secdevops #securityresearch

Last updated 2 years ago

ronin-rb · @ronin_rb
36 followers · 21 posts · Server infosec.exchange