August 7, 2023 at 03:24AM

■■■■□ No keys attached: Exploring GitHub-to-AWS keyless authentication flaws. https://securitylabs.datadoghq.com/articles/exploring-github-to-aws-keyless-authentication-flaws/ https://t.me/cKure/12718

August 6, 2023 at 10:37PM

■■■□□ Air-Gap: New acoustic attack steals data from keystrokes with 95% accuracy. https://www.bleepingcomputer.com/news/security/new-acoustic-attack-steals-data-from-keystrokes-with-95-percent-accuracy/ https://t.me/cKure/12716

August 4, 2023 at 07:16PM

■■□□□ Meet Window Snyder, the trailblazer who changed Microsoft and Apple, and helped secure billions of Macs and iPhones by default. “Her legacy is about changing big companies and moving big ships.” https://techcrunch.com/2023/08/04/window-snyder-cybersecurity-trailblazer/ https://t.me/cKure/12710

August 4, 2023 at 07:11PM

■■■■□ Amazon’s AWS SSM agent can be used as post-exploitation RAT malware. https://www.bleepingcomputer.com/news/security/amazons-aws-ssm-agent-can-be-used-as-post-exploitation-rat-malware/ https://t.me/cKure/12709

August 4, 2023 at 02:22PM

■■■□□ pdlist is a passive subdomain finder written in python3. This tool can be used effectively to collect information about a domain without ever sending a single packet to any of its hosts. Given a domain like “example.com” it will find all the hosts which have a hostname .example.com or URLs strictly related to example.com.…

August 4, 2023 at 03:22AM

Exploiting A Flaw In Bitmap Handling In Windows User-mode Printer Drivers. https://www.zerodayinitiative.com/blog/2023/8/1/exploiting-a-flaw-in-bitmap-handling-in-windows-user-mode-printer-drivers https://t.me/cKure/12706