Plus récents

SAML is insecure by design : SAML uses signatures based on computed values. The practice is inherently insecure and thus SAML as a design is insecure

joonas.fi/2021/08/saml-is-inse

In this research, our goal is to read « LSASS.exe » memory from userland. We experimented against Total Security (KTS), one of the top security products currently.

blog.vincss.net/2021/08/ex007-

pyWhisker is a tool allows users to manipulate the msDS-KeyCredentialLink attribute of a target user/computer to obtain full control over that object.

github.com/ShutdownRepo/pywhis

Limelighter is a tool for generating fake code signing certificates or signing real ones

github.com/Tylous/Limelighter

ADSI is a set of interfaces allowing administrators to query information on an *Active Directory environment

grimmie.net/tools-techniques-a

(CVE-2020-29015) An OS command injection vulnerability in FortiWeb's management interface (version 6.3.11 and prior) can allow a remote, authenticated attacker to execute arbitrary commands on the system, via the SAML server configuration page

rapid7.com/blog/post/2021/08/1

(CVE-2021-28372) Critical Vulnerability That Affects Millions of internet-of-things () that use the ThroughTek « Kalay » network - one that exposes live video and audio streams to eavesdropping threat actors and which could enable attackers to take over control of devices, including security webcams and connected baby monitors

fireeye.com/blog/threat-resear

(CVE-2021-21832) Memory corruption vulnerability in Daemon Tools Pro can cause memory corruption in the application if the user opens an adversary-created ISO file that causes an integer overflow. This vulnerability exists in the way the application parses ISOs.

blog.talosintelligence.com/202

Multiple Issues in Realtek SDK Affects Hundreds of Thousands of Devices Down the Chain : At least 65 vendors affected by severe vulnerabilities that enable unauthenticated attackers to fully compromise the target device and execute arbitrary code with the highest level of privilege. chipsets are found in many embedded in the IoT space. RTL8xxx SoCs – which provide capabilities – are very common.

  • CVE-2021-35392 ( Simple Config’ stack buffer overflow via UPnP)
  • CVE-2021-35393 (WiFi Simple Config’ heap buffer overflow via SSDP)
  • CVE-2021-35394 (MP Daemon diagnostic tool command injection)
  • CVE-2021-35395 (management web interface multiple vulnerabilities

iot-inspector.com/blog/advisor

Ce dimanche 15 août 2021, le centre de de Saint-Céré () a été victime d'un acte de vandalisme. Les faits ont été constatés lundi 16 août 2021 au matin par les responsables de cet espace dédiés aux injections contre la -19. Outre les dégradations, le matériel permettant la gestion de cet acte médical et la délivrance du pass sanitaire a été dérobé

ladepeche.fr/2021/08/17/lot-il

Volodymyr Diachenko, security researcher at Comparitech (comparitech.com) has revealed the discovery of a federal terrorist watchlist that includes 1.9 million records. The watchlist came from the Terrorist Screening Center (TSC), a multi-agency group administered by the FBI. The TSC maintains the country's no-fly list, which is a subset of the larger watchlist. The exposed server was indexed by search engines Censys (censys.io) and ZoomEye (zoomeye.org)

threatpost.com/terrorist-watch

's Tokio Marine (tokiomarinehd.com), which has a U.S. division and offers a product, is the latest insurer to be victimized by

cyberscoop.com/tokio-marine-ry

Suite au piratage du médecin responsable du centre de d'Arcachon () , des malfaiteurs ont pu se connecter avec ses identifiants sur le site de l'Agence Numérique de la Santé (esante.gouv.fr) et imprimer 55 certificats de vaccination

france3-regions.francetvinfo.f

Pine64 PineNote (e-ink device) Specifications:
60 FPS e-ink panel
191.1 x 232.5 x 7.4mm
Total Weight: 438g
OS: Manjaro
10.3″ 1404 x 1872 Resolution (Pixels)
227 DPI
16 levels of Grayscale
Touchscreen
EMR Stylus Pen with Wacom technology
Front light (FL)
36 level cold and warm light
CPU = RK3566 1.8GHz 64-bit Quad-Core A55

pine64.org/2021/08/15/introduc

Plus anciens