ӉѦСҠіИԌ ҬЄѦӍ СѦИѦL ѺҒіСіѦL DіҒԱՏіóИ
Closed channel
1 781
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
#Offensive_security
Near-Ultrasound Inaudible Trojan (NUIT Attack against voice assistants (Siri, Google Assistant, Alexa, Cortana)): Exploit Your Speaker to Attack Your Microphone
https://sites.google.com/view/nuitattack/home
#Red_Team_Tactics
A story about tampering EDRs
https://redops.at/en/blog/a-story-about-tampering-edrs
#Malware_analysis
1. MacStealer Malware
https://www.uptycs.com/blog/macstealer-command-and-control-c2-malware
2. Deep dive into JS/Vjw0rm
https://infosecwriteups.com/deep-dive-into-js-vjw0rm-9983482c20ca
3. NullMixer Malware
https://securityaffairs.com/144092/malware/maas-threats-delivered-through-nullmixer-malware.html
#tools
#Hardware_Security
USBvalve - Expose USB activity on the fly
https://github.com/cecio/USBvalve
#Red_Team_Tactics
1. Red Team Guides 1.0
https://redteamguides.com
2. NUIT - new inaudible attack against voice assistants (Siri, Google Assistant, Alexa, Cortana) that can be waged remotely through internet
https://sites.google.com/view/nuitattack/home
3. A CLI to exploit parameters vulnerable to PHP filter chain error based oracle
https://github.com/synacktiv/php_filter_chains_oracle_exploit
#exploit
1. CVE-2023-1177:
Hacking AI: System and Cloud Takeover via MLflow Exploit
https://protectai.com/blog/hacking-ai-system-takeover-exploit-in-mlflow
2. Google Chrome 109.0.5414.74 - Unsafe Library Load
https://packetstormsecurity.com/files/171495/Google-Chrome-109.0.5414.74-Unsafe-Library-Load.htm
#Offensive_security
ChatGPT Prompts for Bug Bounty & Pentesting
https://github.com/TakSec/chatgpt-prompts-bug-bounty
Metlo is an open-source API security platform.
https://github.com/metlo-labs/metlo
AIx
A cli tool to interact with Large Language Models (LLM) APIs.
Features:
• AMA with AI over CLI
• Query LLM APIs (OpenAI)
• Supports GPT-3.5 and GPT-4.0 models
• Configurable with OpenAI API key
• Flexible output options
https://github.com/projectdiscovery/aix
#cybersecurity #infosec
The curl quirk that exposed Burp Suite & Google Chrome
https://portswigger.net/research/the-curl-quirk-that-exposed-burp-suite-amp-google-chrome
ChatGPT: Build me a Recon Tool
https://vickieli.medium.com/chatgpt-build-me-a-recon-tool-123c23a6a23f
A collection of small scripts and tools for deobfuscation and malware analysis
https://github.com/dr4k0nia/tooling-playground
JSpector: is a Burp Suite extension that passively crawls JavaScript files and automatically creates issues with URLs and endpoints found on the JS files
https://github.com/hisxo/JSpector
Poastal: is an email OSINT tool that provides valuable information on any email address
https://github.com/jakecreps/poastal
