Plus récents

The OSINT Curious Project is a source of quality, actionable, Open Source Intelligence news, original blogs, instructional videos, and live streams. We try to keep people curious about exploring web applications for bits of information or trying out new techniques to access important OSINT data.

osintcurio.us

Pivot SQL Injection Into RCE - SQL injections are considered the most severe security vulnerability by OWASP. In this article, we discuss how a CVE in PTMS was pivoted into Remote Code Execution (RCE).

securecoding.com/blog/pivot-sq

Nous ( Cerba ) tenons à vous informer que notre Laboratoire a été victime d'un vol de données à la suite d'une défaillance de l'un de nos prestataires, en charge de l'hébergement de l'une de nos bases de données. Cette base de données contenant des informations de a en effet été momentanément exposée sur . Malgré l'absence d'exploitation de ces données à ce jour, nous vous recommandons néanmoins de faire preuve de vigilance face à tout démarchage inhabituel qui pourrait s'apparenter à une tentative d'escroquerie.

lab-cerba.com/home/vous-inform

XML eXternal Entity (XXE) attacks - From XML to Remote Code Execution (RCE)

programmersought.com/article/7

Kaseya left customer portal vulnerable to 2015 flaw in its own - CVE-2015-2862 was issued in July 2015. Six years later, Kaseya's customer portal was still exposed to the data-leaking weakness

krebsonsecurity.com/2021/07/ka

Understanding Russia's Strategy - The Russian Federation's willingness to engage in offensive cyber operations has caused enormous harm, including massive losses, interruptions to the operation of critical infrastructure, and disruptions of crucial software chains.

fpri.org/article/2021/07/under

With FileSec stay up-to-date with the latest file extensions being used by attackers

filesec.io

This was the recently patched SYSTEM Remote Code Execution (RCE) in Defender ! No big surprise, memory corruption in a complex unpacker on some old version of ASProtect from the 90s. « Security products » are plagued by problems like this 😣 ( Tavis Ormandy )

bugs.chromium.org/p/project-ze

A recent report suggests that China trails the United States in cyberspace. But Chinese leaders are eying a long-term strategy, so Western governments would be wise not to underestimate Beijing. Comparisons of different states' capabilities are fraught with difficulty. is deploying its capabilities in pursuit of long-term strategic objectives in ways that make the effects hard to measure for comparative purposes.

carnegieendowment.org/2021/07/

For years YouTube's video-recommending algorithm has stood accused of fuelling a grab-bag of societal ills by feeding users an AI-amplified diet of hate speech, political extremism and/or conspiracy junk/disinformation for the profiteering motive of trying to keep billions of eyeballs stuck to its ad inventory. New research published today by Mozilla backs that notion up, suggesting 's ( (Alphabet Inc.) ) artificial intelligence ( AI ) continues to puff up piles of bottom-feeding/low grade/divisive/disinforming content - stuff that tries to grab eyeballs by triggering people's sense of outrage, sewing division/polarization or spreading baseless/harmful disinformation - which in turn implies that YouTube's problem with recommending terrible stuff is indeed systemic ; a side-effect of the platform's rapacious appetite to harvest views to serve his advertising. In today's world, « Artificial Intelligence controls what the world is watching. » ( algotransparency.org )

techcrunch.com/2021/07/07/yout

A sales consultant, Hisham Chaudhary, has been found guilty of using to fund the Islamic State (IS) group. Anti-terrorism police arrested Chaudhary in a dawn raid in November 2019. During the arrest, police found devices in his bedroom containing what were described as IS propaganda videos. The 28-year-old, of Chestnut Drive, Oadby, Leicestershire, was found guilty of 7 offences under the Act by a jury at Birmingham Crown Court on Tuesday.

bbc.com/news/uk-england-leices

4 vulnerabilities afflict the popular Sage X3 Enterprise Resource Planning (ERP) platform including 1 critical bug that rates 10 out of 10 on the CVSS vulnerability-severity scale. 2 of the bugs could be chained together to allow complete system takeovers, with potential supply-chain ramifications

medium.com/tenable-techblog/do

On a previous story regarding WildPressure was dedicated to their campaign against industrial-related targets in the Middle East. By keeping track of their malware in spring 2021, we were able to find a newer version. We have very limited visibility for the samples described in this report. Based on our telemetry, we suspect that the targets in the same Middle East region were related to the oil and gas industry.

securelist.com/wildpressure-ta

Plus anciens