|
You are here |
landave.io | ||
| | | | |
blog.isosceles.com
|
|
| | | | | Early last week, Google released a new stable update for Chrome. The update included a single security fix that was reported by Apple's Security Engineering and Architecture (SEAR) team. The issue, CVE-2023-4863, was a heap buffer overflow in the WebP image library, and it had a familiar warning attached: "Google | |
| | | | |
blog.inhq.net
|
|
| | | | | I have recently discovered the serious CVE-2021-31616 vulnerability in the KeepKey hardware wallet. This is part I of a small article series that describes some of the technical journey of how I got code execution on the device. | |
| | | | |
rtx.meta.security
|
|
| | | | | Technical writeups by Meta's Security folks, including Red Team. | |
| | | | |
www.cybereason.com
|
|
| | | Cybereason GSOC observed distribution of the Bumblebee Loader and post-exploitation activities including privilege escalation, reconnaissance and credential theft. Bumblebee operators use the Cobalt Strike framework throughout the attack and abuse credentials for privilege escalation to access Active Directory, as well as abusing a domain administrator account to move laterally, create local user accounts and exfiltrate data... | ||