Using XSS without user interaction?

The most common use cases for XSS seem to be related to hijacking a users session, but are there any ways an XSS vulnerability can be used without relying on user interaction? I get that the main point of XSS is to run JS in someone else’s browser sess…

I made a tool to make brute force attacks easier

https://github.com/Kitchen-Kreations/listparse ​ listparse is a tool the goes through word/password lists, and creates a smaller list to fit password policies to make brute force attacks quicker. submitted by /u/PapaCooki [link] …

Microsoft details techniques of Mac ransomware

Microsoft warns of different ransomware families (KeRanger, FileCoder, MacRansom, and EvilQuest) targeting Apple macOS systems. Microsoft Security Threat Intelligence team warns of four different ransomware families (KeRanger, FileCoder, MacRansom, and EvilQuest) that impact Apple macOS systems. The initial vector in attacks involving Mac ransomware typically relies on user-assisted methods, such as downloading and running fake […]

The post Microsoft details techniques of Mac ransomware appeared first on Security Affairs.

Twitter suffers data breach as information of 235 million users exposed

Social media platform Twitter could have suffered from a data breach. An online hacker forum has exposed the details of around 235 million users. The data breach could be one of the largest data leaks that could have ever been reported to date. Twitter…

Triangulation and location tracking

I was told by an alleged hacker that he can get anyones live location. By first triangulating their phone to locate them, and then remotely downloading a tracking app on their phone with which they can then be tracked all the time. I’m a newb with hack…

Remote Vulnerabilities in Automobiles

This group has found a ton of remote vulnerabilities in all sorts of automobiles.
It’s enough to make you want to buy a car that is not Internet-connected. Unfortunately, that seems to be impossible.

Secure Contact

We have formed a new team, but we do not know where to contact. (Telegram/discord is not secure, if they sue they will give IP.) I need secure communication. Any ideas or help? submitted by /u/emir_durden [link] [comments]

Rackspace: Play Ransomware gang used a previously unknown exploit to access its Hosted Exchange email environment

Cloud services provider Rackspace confirmed that the recent data breach was the result of the Play Ransomware gang’s attack. Cloud services provider Rackspace announced this week that the recent data breach was the result of an attack conducted by the Play ransomware group. The ransomware attack took place on December 2, 2022, threat actors exploited a […]

The post Rackspace: Play Ransomware gang used a previously unknown exploit to access its Hosted Exchange email environment appeared first on Security Affairs.

National Safety Council

I am taking defensive driving through National Safety Council to lower my insurance cost. I have taken this every three years for the last bunch of decades. What I am trying to say is that this is not court ordered or anything like that. And I have seen the information multiple times.

I use to be able to inspect elements, change the page number in URL but all of those seem to not work anymore. And video speed controller doesn’t seem to work. I have a mouse clicker that helps but there are so many stops and position changes that I need to come back anyways.

Anyone have a work around for this?

submitted by /u/supergokogt
[link] [comments]