This week's articles
Leveraging VSCode Extensions for Initial Access
#attack
The article discusses how to use VSCode extensions for initial access during security assessments. It provides examples of extensions that can be leveraged for reconnaissance, exploitation, and post-exploitation activities, highlighting their capabilities and potential risks.
7 Ways to Escape a Container
#attack, #containers
Post delving into seven common container escape techniques, shedding light on the essential configurations and minimal Linux capabilities required for each method.
New Attack Vector In The Cloud: Attackers caught exploiting Object Storage Services
#attack
Security Joes Incident Response team recently became aware of a set of relatively new CVEs that were released at the end of March 2023. Surprisingly, these vulnerabilities have received little to no media coverage regarding their ease of exploitation and the potential security implications they pose to any cluster running a non-native object storage.
|