tripu · @tripu
205 followers · 1862 posts · Server qoto.org

This is what your should never ever under any circumstances do:

  1. Overflow a buffer
  2. Allow XSS
  3. Allow SQL injection
  4. Allocate, then free memory, without erasing its content
  5. Allow command injection

cwe.mitre.org/top25/archive/20

#cybersecurity #software #security #vulns

Last updated 1 year ago

฿@🅂εD͓̽:parrot: · @1337
13 followers · 125 posts · Server h4x0r.army

Only 1337 m@st0r setup in cafe like this to and wit

#apt #cybersecurity #h4x0r #hack #pwn #zeroday #vulns

Last updated 2 years ago

Dan Conn @ Open UK 7-8th Feb · @danjconn
718 followers · 320 posts · Server defcon.social

A cool video from one of our security researchers Carlos Fernandez at Sonatype

Mutating remote access Trojans, or RAT mutants, are being found within our Nexus IQ and Lifecycle products, and Carlos pulls them apart.

helpnetsecurity.com/2023/01/24

#pypi #malware #vulns #python #rat

Last updated 2 years ago

· @postmodern
824 followers · 468 posts · Server infosec.exchange

What are some good recent CVEs that I could try writing exploits for in order to stress test the API of ronin-exploits?
github.com/ronin-rb/ronin-expl

#exdev #infosec #vulns

Last updated 2 years ago

Dan Conn · @danjconn
669 followers · 123 posts · Server defcon.social

Loving this collaboration with my colleagues Hernán Ortiz and Lex Vorona.

Think my favourite is the low bass on the audio rendering of Text4Shell!

Nice to see Log4Shell giving something positive over the holidays this year! Enjoy!

blog.sonatype.com/caroling-thr

#vulns #music #cybersecurity #vulnerabilities

Last updated 2 years ago

iCyberFighter · @iCyberFighter
150 followers · 53 posts · Server infosec.exchange

via: @campuscodi

QiAnXin published a report on the recent attacks of () that targeted Chinese organizations throughout 2021.

The group allegedly used 3 zero-day :

+1 in an unnamed antivirus product
+2 in an unnamed workstation management system. More here (in Chinese): mp.weixin.qq.com/s/pd6fUs5TLdB |

#OceanLotus #APT32 #vulns #infosec #espionage #malware

Last updated 2 years ago

Yeah, I see this, and the world is gonna have an issue. How many devices are going to be missed?
Also since it seems to affect version 3.0 and higher, how many people are going to start spouting anti-patch and anti-update sentiment?

#zerotrust #infosec #vulns #vulnspotlight

Last updated 2 years ago

Lars Lehtonen · @alrs
696 followers · 2731 posts · Server lsngl.us

I've lost track, am I still supposed to be disabling if I care about and the ? I don't want to find myself on the wrong end of the .

#hyperthreading #infosec #vulns #lulz

Last updated 4 years ago

Les capsules du prof Lutz · @lutzray
197 followers · 2972 posts · Server mamot.fr

"The root cause of the Spectre and Meltdown vulnerabilities was that processor architects were trying to build not just fast processors, but fast processors that expose the same abstract machine as a PDP-11. This is essential because it allows C programmers to continue in the belief that their language is close to the underlying hardware." queue.acm.org/detail.cfm?id=32

#compsci #vulns #malware #security

Last updated 6 years ago