Security News

MaLDAPtive: Open-source framework for LDAP SearchFilter parsing, obfuscation, and more!
2024-10-04 04:00

MaLDAPtive is an open-source framework for LDAP SearchFilter parsing, obfuscation, deobfuscation, and detection. At its core, the project features a custom-built C# LDAP parser designed for...

Compliance frameworks and GenAI: The Wild West of security standards
2024-09-16 04:00

In this Help Net Security interview, Kristian Kamber, CEO at SplxAI, discusses how security challenges for GenAI differ from traditional software. Unlike predictable software, GenAI introduces...

NIST Cybersecurity Framework (CSF) and CTEM – Better Together
2024-09-05 09:19

It’s been a decade since the National Institute of Standards and Technology (NIST) introduced its Cybersecurity Framework (CSF) 1.0. Created following a 2013 Executive Order, NIST was tasked with...

Automated Security Validation: One (Very Important) Part of a Complete CTEM Framework
2024-08-08 11:00

One of these categories is Automated Security Validation, which provides the attacker's perspective of exposures and equips security teams to continuously validate exposures, security measures, and remediation at scale. Traditional security methods can miss hidden assets or fail to account for vulnerabilities hiding in user accounts or security policies.

Realm: Open-source adversary emulation framework
2024-07-15 04:16

Realm is an open-source adversary emulation framework emphasizing scalability, reliability, and automation. It's designed to handle engagements of any size.

How to design a third-party risk management framework
2024-07-12 04:30

An effective third-party risk management framework ensures that an organization is not derailed by vendor risks and vulnerabilities. Right after you categorize your third-party vendors based on their importance to your organization, next you must define the scope of your third-party risk management services and framework by identification of the type of third parties involved and the risk factors posed by them.

Israeli Entities Targeted by Cyberattack Using Donut and Sliver Frameworks
2024-07-03 03:56

Cybersecurity researchers have discovered an attack campaign that targets various Israeli entities with publicly-available frameworks like Donut and Sliver. The campaign, believed to be highly...

Ghidra: Open-source software reverse engineering framework
2024-06-17 04:00

Ghidra, a cutting-edge open-source software reverse engineering framework, is a product of the National Security Agency Research Directorate. The framework features high-end software analysis tools, enabling users to analyze compiled code across various platforms, including Windows, macOS, and Linux.

Radare: Open-source reverse engineering framework
2024-06-10 04:30

Radare is an open-source UNIX-like reverse engineering framework and command-line toolset. "I started the project in 2006 when I was working as a forensic analyst, and I wrote a simple command-line hexadecimal editor to scan a hard drive looking for keywords and dump the results to disk to recover some files. Over time, the project evolved to meet my diverse requirements, serving as a debugger, a disassembler, and a platform for exploring various architectures. It proved invaluable during CTF competitions, at work, and for personal reverse engineering projects," Sergi Àlvarez, the creator of Radare, told Help Net Security.

Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code
2024-05-14 11:17

The maintainers of the Cacti open-source network monitoring and fault management framework have addressed a dozen security flaws, including two critical issues that could lead to the execution of...