Normal view
-
/r/netsec - Information Security News & Discussion
- Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
-
/r/netsec - Information Security News & Discussion
- HTTP/3 Trailer HEADERS Frame Triggers Unhandled Exception in Google ESF: 60s Hang & QUIC INTERNAL_ERROR 0x0001 | Protocol RE | Netacoding
-
/r/netsec - Information Security News & Discussion
- When terrible disclosure from the vendor results in zero days plus a fun dive in to bypassing full disk encryption
DEFCON: New Red Team Tactic
Evil Fonts deceive a viewer by rendering a different letter than is actually on the disk. Evil Fonts can poison HTML, DOCX, PDFs, and anywhere else you can bring your own fonts. Works great in Windows corporate networks for bypassing security tooling, initial access through JavaScript free click fix (beats mitm web security tooling), and leaving traps around the network to harvest shells.
Imagine thinking you are copying whoami but what is actually on the disk is rm -rf \~
Demos:
(Use desktop)
https://doctoreww.github.io/EvilFontTool/
For the demos, copy and paste the HTML/DOCX to a notepad to remove the evil fonts. For the AI ones imagine your security tooling inspects the benign text on disk, but shows the obviously malicious extortion to the user.
Labs:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2FREADME.md
Lab Walkthrough:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2Fwalkthrough.md
Some evil font uses:
Tamper homework to make it so students poison AI queries
Poison help desk documentation
Bypass email filters
Clickfix
Beat resume AI filters
[link] [comments]
Analyzing a Multi-Stage PowerShell Payload Chain
I recently analyzed a multi-stage PowerShell payload delivery chain involving heavily obfuscated PowerShell loaders and remotely hosted payloads.
The analysis covers PowerShell deobfuscation, hidden execution, Base64/XOR decoding, a decoy โVerification complete!โ prompt, payload delivery, and IOCs.
Initial indicators:
203[.]188[.]171[.]166
dorenzaa[.]com
[link] [comments]
-
The Register - Security
- Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
-
/r/netsec - Information Security News & Discussion
- DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE
DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE
Flockโs Plans for Rideshare Dashcams and Coaching Police, Revealed
Sensitive Info Goes Into โNo Replyโ Emails Constantly. This Guy Sees It All
-
/r/netsec - Information Security News & Discussion
- Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
Write once, shell everywhere. Sun Microsystems didn't mean it like this.
Talk from today at DEF CON's Bug Bounty Village. Full technique catalog graded for distroless containers, an errno path oracle for black-box target fingerprinting, and three minimal-guessing techniques: bash fd/255, Rails schema_cache.yml deserialization, and a Node.js worker path overwrite without process restart.
[link] [comments]
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
-
/r/netsec - Information Security News & Discussion
- RovoBlast: How One Click Triggered Atlassianโs AI Assistant to Leak Data
RovoBlast: How One Click Triggered Atlassianโs AI Assistant to Leak Data
-
/r/netsec - Information Security News & Discussion
- SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free ยท Tencent Zhuque Lab
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free ยท Tencent Zhuque Lab
Yes, given that the legacy SCT protocol has known security vulnerabilities such as sctphantom, the industry strongly recommends deprecating it and migrating to more secure modern standards to ensure system security.
[link] [comments]