❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayVerSprite

Chrome Exploitation: How to easily launch a Chrome RCE+SBX exploit chain with one command

By: bigdrop
30 December 2022 at 10:11

To teach Chrome exploitation to my team, I’ve selected a previous 0day RCE that I found last year for my company VerSprite: CVE-2021-21224Β https://crbug.com/1195777, and I’ve paired it with a SBX...

The post Chrome Exploitation: How to easily launch a Chrome RCE+SBX exploit chain with one command appeared first on Versprite.

VerSprite CyberWatch. We Dive Into the Latest CyberSecurity News

By: bigdrop
17 January 2023 at 11:26

January 17, 2023Author:Β Β Daniel Stiegman Severe Security Flaw Alert: JWT Secret Poisoning (CVE-2022-23529) CVE-2022-23529, is a vulnerability rated as high severity (CVSS 7.6). This vulnerability has insecure input validation inΒ jwt.verifyΒ function, that...

The post VerSprite CyberWatch. We Dive Into the Latest CyberSecurity News appeared first on Versprite.

Why Bad Guys do Bad Things: How Maslow’s Hierarchy of Needs can help identify cyber threats.

By: bigdrop
23 January 2023 at 11:48

Daniel Stiegman Principal Intelligence Analyst – Threat Intelligence GroupΒ at VerSprite Why does crime happen? Cyber security professionals can be so invested in answering theΒ β€œHow?” or theΒ β€œWhat?” that occurred in a cyber incident, that...

The post Why Bad Guys do Bad Things: How Maslow’s Hierarchy of Needs can help identify cyber threats. appeared first on VerSprite.

Welcome to The World of Geopolitics and Cybersecurity!

By: bigdrop
27 January 2023 at 12:01

In today’s interconnected global landscape,Β understanding the intersection of the two critical fields, cybersecurity and geopoliticsΒ is more important than ever. Our new eBook, created by the VerSpriteΒ Threat IntelligenceΒ &Β GeopoliticsΒ Group, delves into the...

The post Welcome to The World of Geopolitics and Cybersecurity! appeared first on VerSprite.

AI and Cybersecurity: Threats and Opportunities

By: bigdrop
2 February 2023 at 12:43

AI and Machine Learning Tools Are Changing Cybersecurity. Joaquin Paredes Director of Offensive Security Practice Artificial Intelligence (AI) has a definitive place in cybersecurity.Β The experts at McKinsey define AIΒ as a...

The post AI and Cybersecurity: Threats and Opportunities appeared first on VerSprite.

DATA *MIS*MANAGEMENT: ONE OF THE LEADING CAUSES OF SECURITY BREACHES

By: bigdrop
15 February 2023 at 12:23

Steps to take now to ensure data management oversight doesn’t make your organization an easy target for cybercriminals Β by Marian Reed, Vice President, GRC Cybersecurity efforts, such as improving security...

The post DATA *MIS*MANAGEMENT: ONE OF THE LEADING CAUSES OF SECURITY BREACHES appeared first on VerSprite.

Envisions Geopolitical Threat Report:

By: bigdrop
7 March 2023 at 12:07

Geopolitical Trends Influencing Cybercrime In VerSprite Envisions 2023 threat intelligence report, you’ll discover the latest insights on cyber threat trends expected to impact businesses, organizations, and governments. Explore how cyberwarfare...

The post Envisions Geopolitical Threat Report: appeared first on VerSprite.

VerSprite and AppSecEngineer Partner to Operationalize Security Training

By: bigdrop
23 March 2023 at 11:57

Full-stack, comprehensive, and affordable security training Today, leading cybersecurity service providerΒ VerSpriteΒ and security training leaderΒ AppSecEngineerΒ announce a partnership toΒ operationalize security training.Β The joint effort will result in a comprehensive full-stack security training program...

The post VerSprite and AppSecEngineer Partner to Operationalize Security Training appeared first on VerSprite.

Grey Box Application Testing: What It Is and Why You Need It

By: bigdrop
27 March 2023 at 10:51

Grey box pen testing is the best approach to ensure optimized app pen testing Rodrigo Contarino Offensive Security Managing Consultant Mobile, web, and cloud-based solutions for online communications and other...

The post Grey Box Application Testing: What It Is and Why You Need It appeared first on VerSprite.

Security Vulnerability Classes in Popular Programming Languages

By: bigdrop
15 December 2021 at 21:17

VerSprite's security researchers explain common security vulnerabilities found in programming languages including: Python, JavaScript, PhP, Java, C, C++, and Swift. Plus, get advice for choosing which programing language is best for your application.

The post Security Vulnerability Classes in Popular Programming Languages appeared first on VerSprite.

Printer Spooler Bug Research

By: bigdrop
22 December 2022 at 15:07

In this blog, we dive into and show how attackers could combine the 0day CVE-2020-0986 with the 0day in IE browser to achieve privilege escalation and then execute code remotely. Now, Maddie Stone, a security researcher on Google's Project Zero team, found that an attacker can still trigger CVE-2020-0986 and elevate kernel privileges by sending an offset instead of a pointer.

The post Printer Spooler Bug Research appeared first on VerSprite.

AFD.sys – Primitives in The Pocket | Integer Shenanigans

By: bigdrop
24 July 2023 at 20:32

Intro VerSprite VS-Labs Research team discovered an interesting integer arithmetic bug within the Windows Kernel Ancillary Function Driver (AFD.sys) while performing N-day analysis after Microsoft Patch Tuesday. Within this blog...

The post AFD.sys – Primitives in The Pocket | Integer Shenanigans appeared first on VerSprite.

Exploit with VS- Labs. CVE-2023-3439: Analyzing UAF Vulnerability in Linux MCTPΒ 

By: bigdrop
21 September 2023 at 13:58

Β  In this blog post, we will analyze the UAF vulnerability in the Linux mctp component and possible exploitation scenarios in detail. We will show the necessary steps to prepare...

The post Exploit with VS- Labs. CVE-2023-3439: Analyzing UAF Vulnerability in Linux MCTPΒ  appeared first on VerSprite.

Unpatched Security Vulnerability in OPTO 22 PAC Basic Software

By: bigdrop
23 April 2021 at 14:07

This ungated Vulnerability Analysis Report outlines the vulnerabilities found by VerSprite's security research team within Razer's Synapse 3 software suite, including risk level, disclosure timeline, and remediation information. The vulnerabilities covered are CVE-2021-30493 and CVE-2021-30494.

The post Unpatched Security Vulnerability in OPTO 22 PAC Basic Software appeared first on VerSprite.

❌
❌