News
- ICE Is Buying Access to Credit Card Records - Through data brokers, ICE is buying the information you provided to open a credit card. Schneier on Security
- Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover Shai Laron (Semperis)
Techniques and Write-ups
- Borrowing Windows Hello keys for authentication and persistence - A compromised, non-privileged Windows user session can use the TPM-bound Windows Hello key without requiring the user to re-enter their PIN or provide biometric authentication. dirkjanm.io
- ChainDrop: Inside a Self-Propagating npm Worm - ChainDop Analysis (npm supply chain worm) Unit 42
- CSS:the bomb inside your inbox - Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this 0day Fans
- CRLF-Powered Desync Attacks: Beheading HTTP Streams - Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power 0day Fans
- Can AI do novel security research? Meet the HTTP Terminator - Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi 0day Fans
- ESC1 is alive again - Interesting read Oxmaz
Tools and Exploits
- Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th) - Centralized bash history in homelab (if your homelab isn't complex enough already) SANS ISC
- Weaponizing Windows Updates with NotWSUSpicious - TL;DR: NotWSUSpicious is a tool repo to aid in creating custom updates after gaining access to a WSUS database server. The Turning Enterprise Update Servers Into Backdoor Factories (0_o) series covers how the database takeover works. This blog strictly covers … SpecterOps
Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.