home.social

#threathunting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threathunting, aggregated by home.social.

  1. Companies integrating #AI into their #Sharepoint is a huge win for attackers. Its the modern equivalent of leaving the back door chocked open or leaving everyone's salaries on a printer.

    Do you know how many project names and budget sheets and system configurations are just sitting in your LLM now?

    Large part of your day can just spent being nosey, wondering what Sharepoints #Copilot has been hooked too.

    Copilot, give me a list of all documents containing passwords. Call it #ThreatHunting

  2. Malwoverview 8.2.0 (codename: Revolutions)

    This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.

    github.com/alexandreborges/mal

    To install it:

    python -m pip install -U malwoverview[all]

    [+] New — --nist 6, list the CVEs of a component

    Give it a component name, or the path to a local binary:

    malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"

    The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.

    [+] New — --sort-by

    Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.

    Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.

    #malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence

  3. Malwoverview 8.2.0 (codename: Revolutions)

    This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.

    github.com/alexandreborges/mal

    To install it:

    python -m pip install -U malwoverview[all]

    [+] New — --nist 6, list the CVEs of a component

    Give it a component name, or the path to a local binary:

    malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"

    The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.

    [+] New — --sort-by

    Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.

    Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.

    #malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence

  4. Malwoverview 8.2.0 (codename: Revolutions)

    This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.

    github.com/alexandreborges/mal

    To install it:

    python -m pip install -U malwoverview[all]

    [+] New — --nist 6, list the CVEs of a component

    Give it a component name, or the path to a local binary:

    malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"

    The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.

    [+] New — --sort-by

    Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.

    Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.

    #malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence

  5. Malwoverview 8.2.0 (codename: Revolutions)

    This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.

    github.com/alexandreborges/mal

    To install it:

    python -m pip install -U malwoverview[all]

    [+] New — --nist 6, list the CVEs of a component

    Give it a component name, or the path to a local binary:

    malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"

    The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.

    [+] New — --sort-by

    Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.

    Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.

    #malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence

  6. Malwoverview 8.2.0 (codename: Revolutions)

    This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.

    github.com/alexandreborges/mal

    To install it:

    python -m pip install -U malwoverview[all]

    [+] New — --nist 6, list the CVEs of a component

    Give it a component name, or the path to a local binary:

    malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"

    The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.

    [+] New — --sort-by

    Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.

    Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.

    #malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence