POPULARITY
In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.MFASweep is a PowerShell script that attempts to log in to various Microsoft services using a provided set of credentials and will attempt to identify if MFA is enabled. CVE2CAPEC is a tool developed by Galeax that automates the process of mapping Common Vulnerabilities and Exposures (CVEs) to Common Weakness Enumerations (CWEs), Common Attack Pattern Enumeration and Classification (CAPEC), and MITRE ATT&CK Techniques.This tool helps security researchers identify vulnerabilities within macOS's sandbox restrictions, particularly targeting XPC services in the PID domain marked as "Application" services, which often lack adequate protection.Zscaler's recent blog discusses how North Korean IT professionals are increasingly finding remote work in Western companies, often under disguised identities.In a recent campaign, GootLoader malware has been targeting Bengal cat enthusiasts in Australia using SEO poisoning tactics.After a multi-month absence, the malware loader FakeBat—also known as Eugenloader or PaykLoader—has resurfaced, distributing malware through Google Ads, with a recent campaign exploiting ads for the popular app Notion.Over the past five years, Sophos has been engaged in a complex battle against Chinese state-sponsored cyber adversaries targeting its firewall products. This prolonged engagement, detailed in Sophos' "Pacific Rim" report, reveals a series of sophisticated attacks aimed at exploiting vulnerabilities in internet-facing devices, particularly those within critical infrastructure sectors across South and Southeast Asia.
Poradnik Doboru Ćwiczeń - https://kubacyka.pl/ Michał Tybora — trener wielokrotnych mistrzów, człowiek z ogromnym Doświadczeniem w Trójboju, a także obdarzony dotykiem Midasa i wyrafinowanym podejściem do treningowej mody (jest jej pionierem. To on wyznacza trendy). 80 to liczba niezbyt szczególna, ale okrągła i potrzebowała osoby, która nada jej szyku. Dlatego Osiemdziesiąty odcinek podcastu gości Michała Tybore (nie na odwrót), a ja Zapraszam do odsłuchu PrzePotężnie Dobrego Podcastu. i00:00-04:03 Wstęp 04:04-17:03 Ostatnie zawody (XPC) 17:04-23:13 Ile kalorii je Kajtek? (VS Bupciu) 23:14-32:00 Ładunek emocjonalny. 32:01-43:39 Początki z Trójbojem (KALISTENIKA!?) 43:40-49:00 Kajtek w roli trenera. 49:01-53:09 Zakończenie Instagram Michała: https://www.instagram.com/michalbenchpress/?hl=pl --- Send in a voice message: https://anchor.fm/kubacyka/message
Poradnik Doboru Ćwiczeń - https://kubacyka.pl/ Kajetan Nakonieczny. Trójboista, trener, były członek Barbell Brothers i obecny członek drużyny Potwory Tybory. Kajetan ma dopiero 22 lata, a to jeden z najlepszych zawodników trójboju siłowego w naszym kraju. Jak trenuje? Ile je? Co sprawia mu najwięcej trudności? I jak wpłynęła na niego zmiana Teamu? O tym w odcinku. Zapraszam! 00:00-04:03 Wstęp 04:04-17:03 Ostatnie zawody (XPC) 17:04-23:13 Ile kalorii je Kajtek? (VS Bupciu) 23:14-32:00 Ładunek emocjonalny. 32:01-43:39 Początki z Trójbojem (KALISTENIKA!?) 43:40-49:00 Kajtek w roli trenera. 49:01-53:09 Zakończenie Instagram Kajtora: https://www.instagram.com/kajtor_pt/?hl=pl --- Send in a voice message: https://anchor.fm/kubacyka/message
In this episode Coach Gaglione discussed his diet and training to prepare for the XPC finals at the Arnold classic Looking for additional resources to support your goals? Set up a consult with Coach Gaglione https://gaglionestrengthconsults.as.me Fresh ready to eat meal prep from Eat Clean Bro use Code GS5 at checkout to save ! https://eatcleanbro.com/nj/our-menu/view-all-meals-nj Use these Helpful Links below to kick start your gains and support our team! GS Approved Supplements GS Approved Electrolytes GS Approved Guided Programing Certified Piedmontese use code COACH at Check out for 25% off Locally Sourced LI Seafood from Fish Foodies use code GAGLIONEHEALTH at checkout for 15% off your first order
In this episode Coach Gaglione discussed his diet and training to prepare for the XPC finals at the Arnold classic Looking for additional resources to support your goals? Set up a consult with Coach Gaglione https://gaglionestrengthconsults.as.me Fresh ready to eat meal prep from Eat Clean Bro use Code GS5 at checkout to save ! https://eatcleanbro.com/nj/our-menu/view-all-meals-nj Use these Helpful Links below to kick start your gains and support our team! GS Approved Supplements GS Approved Electrolytes GS Approved Guided Programing Certified Piedmontese use code COACH at Check out for 25% off Locally Sourced LI Seafood from Fish Foodies use code GAGLIONEHEALTH at checkout for 15% off your first order
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/ios-0days-apache-dubbo-rces-and-npm-bugs.html Some of Apple's XPC services are leaking information, Finder has an RCE, and some CodeQL use to find many RCEs in Apache Dubbo. [00:00:38] macOS Finder RCE [00:06:11] AWS WorkSpaces Remote Code Execution [CVE-2021-38112] [00:10:09] Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program [00:26:51] 5 RCEs in npm for $15,000 [00:42:32] Apache Dubbo: All roads lead to RCE The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits. The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec You can also join our discord: https://discord.gg/daTxTK9 Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
Link to bioRxiv paper: http://biorxiv.org/cgi/content/short/2020.09.14.293290v1?rss=1 Authors: Feher, K. M., Kolbanovskiy, A., Durandin, A., Shim, Y., Min, J. H., Lee, Y. C., Shafirovich, V., Mu, H., Broyde, S., Geacintov, N. E. Abstract: The Nucleotide Excision Repair (NER) mechanism removes a wide spectrum of structurally different lesions that critically depend on the binding of the DNA damage sensing NER factor XPC-RAD23B (XPC) to the lesions. The bulky mutagenic benzo[a]pyrene diol epoxide metabolite-derived cis- and trans-B[a]P-dG lesions (G*) adopt base-displaced intercalative (cis) or minor groove (trans) conformations in fully paired DNA duplexes with the canonical C opposite G* (G*:C duplexes). While XPC has a high affinity for binding to these DNA lesions in fully complementary double-stranded DNA, we show here that deleting only the C in the complementary strand opposite the lesion G* embedded in 50-mer duplexes, fully abrogates XPC binding. Accurate values of XPC dissociation constants (KD) were determined by employing an excess of unmodified DNA as a competitor; this approach eliminated the binding and accumulation of multiple XPC molecules to the same DNA duplexes, a phenomenon that prevented the accurate estimation of XPC binding affinities in previous studies. Surprisingly, a detailed comparison of XPC dissociation constants KD of unmodified and lesion-containing G*:Del complexes, showed that the KD values were ~ 2.5 - 3.6 times greater in the case of G*:Del than in the unmodified G:Del and fully base-paired G:C duplexes. The origins of this unexpected XPC lesion avoidance effect is attributed to the intercalation of the bulky, planar B[a]P aromatic ring system between adjacent DNA bases that thermodynamically stabilize the G*:Del duplexes. The strong lesion-base stacking interactions associated with the absence of the partner base, prevent the DNA structural distortions needed for the binding of the BHD2 and BHD3 {beta}-hairpins of XPC to the deletion duplexes, thus accounting for the loss of XPC binding and the known NER-resistance of G*:Del duplexes. Copy rights belong to original authors. Visit the link for more info
Link to bioRxiv paper: http://biorxiv.org/cgi/content/short/2020.07.28.225433v1?rss=1 Authors: Scarfo, M., Sciandra, C., Santovito, A. Abstract: Aging and longevity are complex processes controlled at different levels, including genetic level. We evaluated the association of seven drug and DNA-repair gene polymorphisms with longevity in an Italian cohort. A sample of 756 subjects aged 18-98 was genotyped for CYP1A1 exon 7 A>G, GSTT1 null, GSTM1 null, GSTP A>G, XRCC1 exon 6 C>T, XRCC1 exon 9 A> G and XPC exon 15 A>C gene polymorphisms. The association between the analyzed gene polymorphisms and longevity was evaluated by dividing the sample into three age groups: 10-50, 51-85, and 86-98. We observed a significant decrease in the frequency of the GSTT1 null, GSTP G and XPC C alleles in the oldest group with respect to the youngest one and with respect to 51-85 age group. We obtained the same results also subdividing the sample into 1-85 and 86-98 age groups. The general linear model analyses confirmed a significant decreasing trend of the above mentioned alleles with age. We hypothesized that these minor alleles, being important in the sensitivity against the development of different types of cancer, may reflect a reduced life-expectancy in carrier subjects and may explain their significantly lower frequency observed among subjects belonging to oldest age group. Copy rights belong to original authors. Visit the link for more info
In this episode Coach Gaglione interviews Dan Dague after another successful XPC Finals at the Arnold Classic We discuss how the XPC started and how it became the premier equipped and raw with wraps meet in Columbus! We talk about the involvement of the WPO moving forward and what is to come in the future for the XPC Finals To learn how to qualify or get involved see the XPC pages and contact info below https://www.lexenxtreme.com https://www.xpcpowerlifting.com E-mail: lexenxtreme@aol.com Phone: (614) 554-8824 Looking for online programming and coaching? Click below http://www.gaglionestrength.com/gagli... Live on Long Island and want to join the team? Sign up for a trial workout here http://www.gaglionestrength.com/progr... Are you a coach or lifter looking for the science behind our programs and methods? Check out the Powerlifting Hand Book http://tinyurl.com/orq62ks
John and Rambo take a spontaneous deep-dive into XPC and the pros and cons of using it to modularize a Mac app. Also, what can be learned from looking at old code, comments on the latest Apple rumors, and designing a delicious dinner. Sponsored by OWC: Get the new OWC memory and Accelsior 4M2 SSD for the 2019 Mac Pro now. Enter the Mac Pro Rack giveaway here. Download MP3 Hosts: Gui on Twitter: @_inside John on Twitter: @johnsundell Links The episode with Casey Liss Verbal Pumpkin Indie Support Weeks Litur Formatter Coxinhas Swedish meatballs Tiramisu Subscribe: 🟣 Apple Podcasts 🟠 Overcast 🟢 Spotify
In this episode Coach Gaglione walks down memory lane with long time member of the coaching program Larry Wheels Williams We go over Larry's progression in powerlifting from his first meet with the team 6 years ago and his recent WR performance at the XPC finals After that we went LIVE and answered questions for fans and followers of the program Want to LIFT LIKE LARRY ? see below for all our coaching program http://larrywheels.com Get ready for your first meet click below https://www.amazon.com/Are-Ready-Compete-John-Gaglione/dp/1073036812/ref=sr_1_1?keywords=are+you+ready+to+compete&qid=1584732431&sr=8-1 Looking for online programming and coaching? Click below http://www.gaglionestrength.com/gaglione-power/ Sign up for a trial workout here http://www.gaglionestrength.com/programs/ Are you a coach or lifter looking for the science behind our programs and methods? Check out the Powerlifting Hand Book http://tinyurl.com/orq62ks
This episode we have SHW lifter and Elite FTS athlete, JP Caorroll. Find out about JP's recent performance at the XPC at the Arnold. We talk about some of the Good and Bad about the powerlifting world currently. And we reveal some bad news about Brandon's prep.
Hakuro Matsuda さんをゲストに迎えて、WWDC, iOS 12, macOS Mojave, AMD, Oculus Go などについて話しました。 Show Notes Apple Events - WWDC Keynote, June 2018 iOS 12 Preview Android Jetpack What is USDZ? FBX | Autodesk ARCore Overview Siri Shortcuts FAQ Apple has acquired Workflow Android For Employees iOS 12 introduces new features to reduce interruptions and manage Screen Time Apple’s Memoji lets you create an Animoji of yourself Designing Web Content for watchOS What's New in TVMLKit - WWDC 2018 OpenGL, OpenCL deprecated in favor of Metal 2 in macOS 10.14 Mojave KhronosGroup/MoltenVK: Bringing Vulkan to iOS and macOS eGPUでMacBook Proが変わる!4K動画編集も快適なGIGABYTEのRX580 Gaming Box Apple gives a sneak peek at multi-year project to bring UIKit iOS apps to the Mac Marzipan is wild. It's running the UIKit apps with XPC & remote rendering Platforms State of the Union - WWDC 2018 AMD unveils Threadripper 2: Up to 32 cores, 64 threads AMD Demos 7nm Vega GPU Android P Beta 2 and final APIs Accessories & Parts | Oculus Go ustwo Games The Very Real reason LG built Google the sharpest OLED display ever Apple acquired augmented reality headset startup Vrvana for $30M Hugo Barra joins Facebook to lead its VR efforts, including Oculus
Materials Available here:https://media.defcon.org/DEF%20CON%2023/DEF%20CON%2023%20presentations/DEFCON-23-Patrick-Wardle-Stick-that-in-your-(Root)Pipe-and-Smoke-it-UPDATED.pdf Stick That In Your (root)Pipe & Smoke It Patrick Wardle Director of R&D, Synack You may ask; "why would Apple add an XPC service that can create setuid files anywhere on the system - and then blindly allow any local user to leverage this service?" Honestly, I have no idea! The undocumented 'writeconfig' XPC service was recently uncovered by Emil Kvarnhammar, who determined its lax controls could be abused to escalate one's privileges to root. Dubbed ‘rootpipe,' this bug was patched in OS X 10.10.3. End of story, right? Nope, instead things then got quite interesting. First, Apple decided to leave older versions of OS X un-patched. Then, an astute researcher discovered that the OSX/XSLCmd malware which pre-dated the disclosure, exploited this same vulnerability as a 0day! Finally, yours truly, found a simple way to side-step Apple's patch to re-exploit the core vulnerability on a fully-patched system. So come attend (but maybe leave your MacBooks at home), as we dive into the technical details XPC and the rootpipe vulnerability, explore how malware exploited this flaw, and then fully detail the process of completely bypassing Apple's patch. The talk will conclude by examining Apple’s response, a second patch, that appears to squash ‘rootpipe’…for now. Patrick Wardle is the Director of Research at Synack, where he leads cyber R&D efforts. Having worked at NASA, the NSA, and Vulnerability Research Labs (VRL), he is intimately familiar with aliens, spies, and talking nerdy. Currently, Patrick’s focus is on automated vulnerability discovery, and the emerging threats of OS X and mobile malware. In his personal time, Patrick collects OS X malware and writes OS X security tools. Both can be found on his website Objective-See.com
Special guest Guy English. Topics center on WWDC 2014, particularly how XPC — interapplication communication — is playing a fundamental but largely behind-the-scenes role in many of the new features for iOS and OS X. The new much-improved WebKit API (which brings third-party apps the faster Nitro JavaScript engine), third-party keyboards, Sharing menu extensions, and Notification Center widgets — all these things are built on XPC. Other topics include Apple TV, Swift, and the apparent happiness not just of third-party developers, but Apple employees, too.
This episode of The Iron Subculture Podcast is packed full of industrial-strength, practical info guaranteed to enrich your training, health and life with all the subtlety of a punch-in-the-face! Top powerlifting trainer Josh Bryant shares some of his Metroflex Powerbuilding secrets. In a second feature interview, licensed counselor, pro athlete and diet expert Kori Propst discusses The Psychology of Dieting. Elitefts™ team member Jeremy Frey talks about his powerlifting journey. I call England to speak to WNBF drug-tested Mr. Universe Richard Gozdecki. Dan Dague talks to us about his plans for the XPC and how he hopes it will be a unifying force in powerlifting. Jeremiah Forster tells me how he transitioned from nationally-ranked bodybuilder to competitive eater (as well as some tips if you want to become a binge eating champion). We also hear briefly from Brian Carroll, Clint Darden and Mike Francois. Elitefts: Iron Subculture Podcast brought to you by Elitefts.com and hosted by The Guerrilla Journalist, Steve Colescott.