Great to have @usdAG onboard as a Bronze Sponsor!
Security analyses, consulting & audits all driven by their mission: #moresecurity
Welcome and thank you! 🔥
Great to have @usdAG onboard as a Bronze Sponsor!
Security analyses, consulting & audits all driven by their mission: #moresecurity
Welcome and thank you! 🔥
The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.
Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.
All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.
🔎 You can find detailed information on the #SecurityAdvisories here: https://www.usd.de/en/security-advisories-entra-id-tenable-nessus-manager/
#SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity
Unauthenticated RCE in Agorum Core Open!
During their regular security analyses, our pentest professionals from #usdHeroLab examined the open source software #AgorumCoreOpen.
They discovered multiple #vulnerabilities that, when chained together, allow an unauthenticated attacker to achieve full remote code execution with root privileges. This critical flaw enables complete system compromise without prior authentication.
📰👉 Detailed information on the published #SecurityAdvisories can be found here: https://www.usd.de/en/security-advisories-on-agorum-core-open/
#Pentest #Pentesting #moresecurity #RCE #CyberSecurity #InfoSec
With the help of this utility we were able to identify all potentially interesting files and download those first to increase efficiency in our analysis. It's now also available on our company GitHub organization: https://github.com/usdAG/webtree.
🔔 Follow us for #moresecurity
🔁 Also, boost the first toot to spread the word!
As we highly support open source and the idea behind it, we'll investigate how to use this tool and ways to contribute to it in the future. Stay tuned for updates.
🔔 Follow us for #moresecurity
🔁 Also, boost the first toot to spread the word!
Proud of our colleagues Tobias ans Nicolas who spoke at the German #OWASP Day!
https://chaos.social/@c3voc_releases/113476273411466531
SAP from an Attacker's Perspective – Common Vulnerabilities and Pitfalls has been released on media.ccc.de #god2024 #OWASP #Saal1 https://media.ccc.de/v/god2024-56278-sap-from-an-attackers-pers
CSTC is a Burp Suite extension that allows request/response modification using a GUI analogous to CyberChef - GitHub - usdAG/cstc: CSTC is a Burp Suite extension that allows request/response modif...
Ladies and Gentlemen! Here it comes, the
AIR-GAPPED CLOUD INFRASTRUCTURE
#cloud #cyber #cybercyber #security #moresecurity #airgapped #hackerproof.
#Announcement: On Friday, our #usdHeroLab colleagues published a major release of our BurpSuite Plugin #FlowMate: https://github.com/usdAG/FlowMate/releases/tag/v1.1
During BlackHat USA 2023 and DEF CON 31, our colleagues received a lot of helpful feedback on their #tool: The new version 1.1 contains bug fixes and some new features. In our video, Florian Haag explains the advantages and possible use cases in the context of #WebApplication #Pentests: https://www.youtube.com/watch?v=BJhRhGmDATw
#CheckItOut #Security #Pentesting #Hacking #Tools #Community #moresecurity