J0hnny R1ng0

18 Followers
54 Following
36 Posts

"Behold the pale horse. The man who sat on him was death, and Hell followed with him."

cpu + human + phys sec | red team + offsec

Demonstrating CVE-2022-37958 RCE Vuln. Reachable via any Windows application protocol that authenticates. Yes, that means RDP, SMB and many more. Please patch this one, it's serious!

https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/

Critical Remote Code Execution Vulnerability in SPNEGO Extended Negotiation Security Mechanism

A vulnerability in SPNEGO NEGOEX has been reclassified as "Critical" after it was discovered that it could allow attackers to remotely execute code.

Security Intelligence

Under the lens of permanent sustainability, there is far less room for systems that require excessive centralized maintenance to continue existing. Automation is essential. The motivation is community.

Compare this to the world as it is now functioning under the delusional falsehood of permanent growth. Most things will fail, and very quickly, without constant attention. It's profit motivated; individualistic and unpersonal.

This is why the world burns and also how we fix it.

Musk encouraged everyone to vote Republican in the midterms, endorsed Ron DeSantis for president in 2024, and has repeatedly catered to far-right provocateurs on Twitter

It's pretty fucking simple

From @securityaffairs: Experts devised a technique to #bypass web application firewalls (#WAF) of several vendors.

"The researchers verifies that the bypass attack technique also worked against firewalls from other vendors, including #Cloudflare, #F5, Imperva, and #PaloAlto Networks."

#awswaf #infosec #WAFBypass

https://securityaffairs.co/wordpress/139445/hacking/web-application-firewalls-waf-bypass.html

Experts devised a technique to bypass web application firewalls (WAF) of several vendors

Claroty researchers devised a technique for bypassing the web application firewalls (WAF) of several vendors. Researchers at industrial and IoT cybersecurity firm Claroty devised an attack technique for bypassing the web application firewalls (WAF) of several industry-leading vendors. The technique was discovered while conducting unrelated research on Cambium Networks’ wireless device management platform. The researchers […]

Security Affairs

US Congress Drops Media Bargaining Bill

"Consumer advocacy groups and think tanks had also lined up against the measure, arguing in a letter Monday that it could force tech platforms to carry extreme or harmful content"

https://www.washingtonpost.com/technology/2022/12/06/ndaa-jcpa-newspapers-fail/

Congress drops media bargaining bill amid Facebook, industry blowback

The bill would have allowed publishers a temporary exemption from antitrust laws to negotiate jointly for the use of their content by the large tech companies.

The Washington Post

I think one of the things I like most about Mastodon (and most of the Small Web) is that links are links, not clicktracker shortlink redirect black holes. I can copy a URL and paste it into my interesting links list and it will probably be 100% usable. I can open a link in a different profile or a private browsing window and expect that I'm not being tracked.

It's a little thing, but it's a big thing.

The fact that Rev. Rafael Warnock won is cause to celebrate

The fact that the race was close – with someone as poor a human being as Herschel Walker – is cause for alarm

Please boost if you’re still masking indoors (in public places)
FLARE VM: A FLAREytale Open to the Public | Mandiant

Mandiant
This Extension Protects User from Cookie Pop-Ups https://ift.tt/73UfAmn
This Extension Protects User from Cookie Pop-Ups

Consent-O-Matic makes sure the website knows we are not OK with any form of tracking.

CySecurity News - Latest Information Security and Hacking Incidents