#Assetnote

☮ ♥ ♬ 🧑‍💻peterrenshaw@ioc.exchange
2025-01-30

“Two #Brisbane #entrepreneurs whose start-up helps major companies find weaknesses in their #cybersecurity have sold out to a British private equity-backed firm for more than $100 million.

Michael #Gianarakis and Shubham #Shah, who describe themselves as #EthicalHackers, founded #Assetnote in 2018. They have since signed Atlassian, Qantas and Canva as clients, and have been profitable since they started.”

#Australia / #Hackers <afr.com/technology/brisbane-et>

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-10-26

"🚨 #CitrixBleed Exploit Unleashed! Hackers Hijack NetScaler Accounts 🚨"

A new proof-of-concept (PoC) exploit for the 'Citrix Bleed' vulnerability (CVE-2023-4966) has emerged, enabling attackers to snatch authentication session cookies from susceptible Citrix NetScaler ADC and NetScaler Gateway appliances. This critical-severity flaw, which Citrix addressed on October 10, was exploited as a zero-day in limited attacks since late August 2023. Assetnote researchers have now shared an in-depth analysis of the exploitation method and even released a PoC exploit on GitHub. The vulnerability stems from an unauthenticated buffer-related issue, which, when exploited, can lead to buffer over-reads. By leveraging this flaw, attackers can retrieve session cookies, granting them unrestricted access to vulnerable devices. Given the public availability of this exploit, there's an anticipated surge in attacks targeting Citrix Netscaler devices. System admins are strongly urged to apply patches immediately.

Source: BleepingComputer

Tags: #Cybersecurity #Citrix #NetScaler #CVE2023 #Exploit #PoC #Assetnote #Vulnerability #InfoSec

Author: Bill Toulas

2023-08-23

Tourists Give Themselves Away by Looking Up. So Do Most Network Intruders. - In large metropolitan areas, tourists are often easy to spot because they’re far m... krebsonsecurity.com/2023/08/to #thecomingstorm #securitytools #canarytokens #hazelburton #shubhamshah #ransomware #ciscotalos #haroonmeer #assetnote #thinkst

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst