|
You are here |
www.thezdi.com | ||
| | | | |
srcincite.io
|
|
| | | | | In mid-November 2020 I discovered a logical remote code execution vulnerability in Microsoft Exchange Server that had a bizarre twist - it required a morpheu... | |
| | | | |
y4y.space
|
|
| | | | | TCC? Preface A few days ago, Orange dropped another two Microsoft Exchange attack chains on his BlackHat presentation. The two new attacks are ProxyOrcale, which focuses on the Padding Orcale Attack, and ProxyShell, which exploits a Path Confusion vulnerability to achieve arbitrary file write and eventually code execution. This blog assumes readers have read Orange's... | |
| | | | |
blog.blindspotsecurity.com
|
|
| | | | | [AI summary] A security researcher details how protocol stream injection vulnerabilities in Java and Python FTP libraries can be exploited to bypass firewalls and open arbitrary high-numbered TCP ports on victim systems. | |
| | | | |
blog.darkwolfsolutions.com
|
|
| | | September 16, 2024 Episode 13 The Evolving Threat Landscape: A Catalyst for Innovation Author: Brian "BP" Panarello Throughout this series, we've embarked on a journey into the evolving realm of cloud security, navigating the complexities of Zero Trust architectures, the critical role of Cloud | ||