Cyber Security Round Up - June 15th, 23
XXE Attack, DVAPI, Cloud Security, Mobile Pentesting, Account Takeover, JWT, SSRF, Ethical Hacker Roadmap, Blind SQLi, Nuclei
We welcome you to Bi-Monthly newsletter by Hacklido to keep you updated with the latest Infosec trends around the globe.
📑 15 Blog Reads
A Comprehensive Guide to Protecting Your Applications from XXE Vulnerabilities | 2023
Begin your cloud security journey: Solving Flaws.cloud Part-1
Begin your cloud security journey: Solving Flaws.cloud Part-2
Linux for hackers - Part #3 | Logical Volume Management and Managing Basic Hardware devices
Linux for hackers - Part #4 | Network Scanning and Enumeration with Linux
Here is why CHAT-GPT is not going to take away your infosec-jobs
A Comparative Analysis of Vulnerability Assessment, Penetration Testing, and Red Team Engagement
Directory Bruteforcing on Web Server | Automation with Bash Scripting
📹️ 6 Videos
Understand Account Takeover with 146 bug reports by @BugBountyReportsExplained
Learn Bug Bounty Hunting with These Resources by @InsiderPHD
Watch Hacking With ChatGPT by @HackingSimplifiedAS
Watch the new video on How to Become an Ethical Hacker by @NahamSec
Learn Blind SQL Injection the easy way by @TCMSecurityAcademy
🧵 6 Twitter Threads
Understanding JSON Web Tokens By @Intigriti
Learn How to find 10x more domains with Subfinder By @AseemShrey
Master SSRF with these 15 resources By @Novasecio
Read about Some of the major vulnerabilities and related POCs By @AbhishekMeena
Increase Impact of No Rate Limiting By @Shubham_srt
Learn Automating JWT Attacks By @Intigriti
📚 6 Recommended Reads
🧰 2 Tools
Damn Vulnerable API - Practice API vulnerabilities according to the OWASP API Security Project 2023
Nbutools - A collection of tools for offensive security of NetBackup infrastructures
💻 3 Upcoming CTF Events
Mode: Online
Date: 15th June 2023
Duration: 48 Hours
Mode: Online
Date: 16 June 2023
Duration: 24 Hours
Mode: Online
Date: 23 June 2023
Duration: 48 Hours
📰 News
DDoS attack on Federal Administration: various Federal Administration websites and applications unavailable
New FortiOS RCE bug "may have been exploited" in attacks: CVE-2023-27997 | FortiOS SSL VPN vulnerability
Microsoft’s Azure portal down: Threat Actor claims of DDoS attack
💼 Jobs
Company - Applyboard
Role - Application Security Specialist
Location - Gurugram, Haryana, India (On-Site)
Company - TIAA
Role - Network Security Associate
Location - Mumbai, India (On-Site)
Without the sponsors and partners hacklido wouldn't be where it is now, So we would like to thank them.
Sponsors:
Community Partners:
If you wish to Sponsor / Partner with hacklido and get benefited? Reach out to us via Twitter or Discord and discuss with us!