In another example of misconfigured cloud services impacting security, over a billion records belonging to CVS Health have been exposed …
TChopper – Conduct Lateral Movement Attack By Leveraging Unfiltered Services Display Name To Smuggle Binaries As Chunks Into The Target Machine
New technique I have discovered recently and give it a nickname (Chop chop) to perform lateral movement using windows services …
Critical remote code execution flaw in thousands of VMWare vCenter servers remains unpatched
Researchers have warned that thousands of internet-facing VMWare vCenter servers still harbor critical vulnerabilities weeks after patches were released. The …
defenselessV1 – Just Another Vulnerable Web Application
Defenseless is a vulnerable web application written in PHP/MySQL. This is the first version of this application. The purpose of …
Volkswagen, Audi disclose data breach impacting over 3.3 million customers, interested buyers
Volkswagen has revealed a data breach impacting over 3.3 million customers. The majority of impacted individuals are either current or …
Honeywell Introduces Operational Technology Cybersecurity Service to Facilitate Monitoring and Response, and Boost Safety
Honeywell is a massive organization in the American industrial market, and an industrial cybersecurity world leader. The organization has introduced …
EmailFinder – Search Emails From A Domain Through Search Engines
_______ _______ _ ______ _______ ( ____ \( ____ \( ( /|( __ \ ( ____ )| ( \/| ( …
PuzzleMaker attacks exploit Windows zero-day, Chrome vulnerabilities
Researchers say zero-day vulnerabilities fixed in Microsoft’s recent Patch Tuesday round have been used in targeted attacks against the enterprise. …
Nebula – Cloud C2 Framework, Which At The Moment Offers Reconnaissance, Enumeration, Exploitation, Post Exploitation On AWS
Nebula is a Cloud and (hopefully) DevOps Penetration Testing framework. It is build with modules for each provider and each …
Feds strike Slilpp, a marketplace for flogging initial access credentials
Law enforcement has seized one of the largest marketplaces for selling stolen account credentials. The website’s infrastructure has been taken …