Tracking a stolen code-signing certificate with osquery
http://ift.tt/2fZRgsh
Submitted October 10, 2017 at 11:46PM by Fristle
via reddit http://ift.tt/2g06Qnr
http://ift.tt/2fZRgsh
Submitted October 10, 2017 at 11:46PM by Fristle
via reddit http://ift.tt/2g06Qnr
Trail of Bits Blog
Tracking a stolen code-signing certificate with osquery
Recently, 2.27 million computers running Windows were infected with malware signed with a stolen certificate from the creators of a popular app called CCleaner, and inserted into its software updat…
Intro To Measuring, Assessing And Mitigating Security Risk
http://ift.tt/2g7ZFNS
Submitted October 11, 2017 at 12:00AM by Uminekoshi
via reddit http://ift.tt/2yDWF3h
http://ift.tt/2g7ZFNS
Submitted October 11, 2017 at 12:00AM by Uminekoshi
via reddit http://ift.tt/2yDWF3h
Nehemiah Security
Intro to Measuring, Assessing and Mitigating Security Risk - Nehemiah Security
The holy grail for cyber is to measure and communicate risk in financial terms and come up with a mitigation plan that works for security professionals, all while speaking to the CEO, CFO and the board. The good news is that the basic formula for figuring…
Leveraging mobile for phishing key information is on the rise. Learn about attack vectors and mitigations.
http://ift.tt/2y9bUOD
Submitted October 10, 2017 at 11:26PM by Mi3Security
via reddit http://ift.tt/2yWdLWn
http://ift.tt/2y9bUOD
Submitted October 10, 2017 at 11:26PM by Mi3Security
via reddit http://ift.tt/2yWdLWn
Mi3 Security
Mobile Phishing attacks on the rise
The rising trend in phishing attacks across email and websites is spilling
over to mobile applications. Learn about the attack vectors and how to
mitigate.
over to mobile applications. Learn about the attack vectors and how to
mitigate.
StackRox database security on Docker
http://ift.tt/2gaGByJ
Submitted October 10, 2017 at 11:09PM by nslater
via reddit http://ift.tt/2yddmSi
http://ift.tt/2gaGByJ
Submitted October 10, 2017 at 11:09PM by nslater
via reddit http://ift.tt/2yddmSi
CrateDB
StackRox database security on Docker - CrateDB
How we deployed StackRox to harden database security on our public Docker container cluster running the CrateDB database.
A Bug Has No Name: Multiple Heap Buffer Overflows In the Windows DNS Client
http://ift.tt/2kCTram
Submitted October 11, 2017 at 12:28AM by ryanaraine
via reddit http://ift.tt/2xwUJ7Z
http://ift.tt/2kCTram
Submitted October 11, 2017 at 12:28AM by ryanaraine
via reddit http://ift.tt/2xwUJ7Z
Bishop Fox
A Bug Has No Name: Multiple Heap Buffer Overflows In the Windows DNS Client - Bishop Fox
Introduction CVE-2017-11779 fixed by Microsoft in October of 2017, covers multiple memory corruption vulnerabilities in the Windows DNS client. The issues affect computers running Windows 8/ Server 2012 or later, and can be triggered by a malicious DNS response.…
Used Outlook's S/MIME feature in the past 6 months? Your mails were probably not sent encrypted
http://ift.tt/2wLMQM6
Submitted October 11, 2017 at 12:39AM by kafbas
via reddit http://ift.tt/2yeLDAj
http://ift.tt/2wLMQM6
Submitted October 11, 2017 at 12:39AM by kafbas
via reddit http://ift.tt/2yeLDAj
A tale of love, betrayal, social engineering and Whatsapp | Robert Heaton
http://ift.tt/2yWV4li
Submitted October 11, 2017 at 01:17AM by funnybong
via reddit http://ift.tt/2yewUFj
http://ift.tt/2yWV4li
Submitted October 11, 2017 at 01:17AM by funnybong
via reddit http://ift.tt/2yewUFj
Robert Heaton
A tale of love, betrayal, social engineering and Whatsapp | Robert Heaton
You are fed up with with your dear friend and bitter rival, Steve Steveington. He claims to have no idea how all your D&D characters came to be renamed “Sir Doofus McGoofus <obscene drawing&...
Changes in Password Best Practices
http://ift.tt/2yW2aXx
Submitted October 11, 2017 at 01:23AM by speckz
via reddit http://ift.tt/2fZyDoa
http://ift.tt/2yW2aXx
Submitted October 11, 2017 at 01:23AM by speckz
via reddit http://ift.tt/2fZyDoa
reddit
Changes in Password Best Practices • r/security
1 points and 0 comments so far on reddit
Macro-less Code Exec in MSWord
http://ift.tt/2i1kdZ7
Submitted October 11, 2017 at 02:26AM by 0x4a616e
via reddit http://ift.tt/2gazczl
http://ift.tt/2i1kdZ7
Submitted October 11, 2017 at 02:26AM by 0x4a616e
via reddit http://ift.tt/2gazczl
Sensepost
SensePost | Macro-less code exec in msword
Leaders in Information Security
New Office 0day (CVE-2017-11826) Exploited in the Wild
http://ift.tt/2gtyM3Z
Submitted October 11, 2017 at 01:33AM by campuscodi
via reddit http://ift.tt/2i3TbQz
http://ift.tt/2gtyM3Z
Submitted October 11, 2017 at 01:33AM by campuscodi
via reddit http://ift.tt/2i3TbQz
360coresec.blogspot.co.uk
New Office 0day (CVE-2017-11826) Exploited in the Wild
On September 28, 2017, Qihoo 360 Core Security (@ 360CoreSec ) detected an in-the-wild attack that leveraged CVE-2017-11826, an office 0day ...
My First CloudFront Sub-Domain Hijack
http://ift.tt/2yEkecz
Submitted October 11, 2017 at 04:56AM by ZephrX112
via reddit http://ift.tt/2hA2N1G
http://ift.tt/2yEkecz
Submitted October 11, 2017 at 04:56AM by ZephrX112
via reddit http://ift.tt/2hA2N1G
Adventures In Information Security
My First CloudFront Sub-Domain Hijack
Subdomain takeover tutorial, explaining how to claim cloudfront domain. How to identify and claim hanging domains.
Need help with cybersecurity? Join our discord server for help!
http://ift.tt/2xxjnFt
Submitted October 11, 2017 at 05:34AM by Banqu
via reddit http://ift.tt/2yECbaL
http://ift.tt/2xxjnFt
Submitted October 11, 2017 at 05:34AM by Banqu
via reddit http://ift.tt/2yECbaL
Discord
Discord - Free voice and text chat for gamers
Step up your game with a modern voice & text chat app. Crystal clear voice, multiple server and channel support, mobile apps, and more. Get your free server now!
Dow Jones Technical Error: Google Bought Apple. WWHAT?!
http://ift.tt/2g05vgs
Submitted October 11, 2017 at 07:50AM by securitynewsIO
via reddit http://ift.tt/2y9tk00
http://ift.tt/2g05vgs
Submitted October 11, 2017 at 07:50AM by securitynewsIO
via reddit http://ift.tt/2y9tk00
Security News iO
Dow Jones Google bought Apple is a technical error | Security News iO
Dow Jones has a 'technical error' which caused the portal to report stories claiming that Google bought Apple for $9 billion.
Should infosec ppl need to be able to write code?
http://ift.tt/2zcQb8H
Submitted October 11, 2017 at 09:19AM by thegrugq
via reddit http://ift.tt/2yfG7xd
http://ift.tt/2zcQb8H
Submitted October 11, 2017 at 09:19AM by thegrugq
via reddit http://ift.tt/2yfG7xd
AlienVault
Do InfoSec Folks Need to be Able to Write Code?
I ran a poll on Twitter recently, trying to ask this question in an open way, to see what people thought. I was surprised that a lot of folks not only voted, but also shared some strong opinions. This was the final vote count:To be of value to #infosec community…
Awesome hacking resources
http://ift.tt/2yENgsy
Submitted October 11, 2017 at 12:35PM by vitalysim
via reddit http://ift.tt/2y9MNxz
http://ift.tt/2yENgsy
Submitted October 11, 2017 at 12:35PM by vitalysim
via reddit http://ift.tt/2y9MNxz
GitHub
vitalysim/Awesome-Hacking-Resources
A collection of hacking / penetration testing resources to make you better! - vitalysim/Awesome-Hacking-Resources
How Israel Caught Russian Hackers Scouring the World for U.S. Secrets
http://ift.tt/2yesGh0
Submitted October 11, 2017 at 11:36AM by thatshirtman
via reddit http://ift.tt/2i1TI5A
http://ift.tt/2yesGh0
Submitted October 11, 2017 at 11:36AM by thatshirtman
via reddit http://ift.tt/2i1TI5A
Nytimes
How Israel Caught Russian Hackers Scouring the World for U.S. Secrets
Exploiting the popular Kaspersky antivirus software, Russian hackers searched millions of computers for American intelligence keywords. Israeli intelligence tipped off American officials.
New google home mini spying 24/7
http://ift.tt/2g0d8Ud
Submitted October 11, 2017 at 03:01PM by Qstarnik
via reddit http://ift.tt/2y8nDiT
http://ift.tt/2g0d8Ud
Submitted October 11, 2017 at 03:01PM by Qstarnik
via reddit http://ift.tt/2y8nDiT
Android Police - Android News, Apps, Games, Phones, Tablets
Google is nerfing all Home Minis because mine spied on everything I said 24/7 [Update]
When the first home assistants were announced, I was excited. A device I could wake up with a simple hotword that would answer my questions, set reminders,... by Artem Russakovskii in Exclusives, Google, Google Home, Google Home Mini, News, Videos
Accenture – Embarrassing data leak business data in a public Amazon S3 bucket
http://ift.tt/2wMBoA7
Submitted October 11, 2017 at 02:47PM by MicheeLengronne
via reddit http://ift.tt/2hAChVW
http://ift.tt/2wMBoA7
Submitted October 11, 2017 at 02:47PM by MicheeLengronne
via reddit http://ift.tt/2hAChVW
Security Affairs
Accenture - Embarrassing data leak business data in a public Amazon S3 bucket
The leading global professional services company Accenture exposed its business data in a public Amazon S3 bucket. Disconcerting!
New spy phone software for mobile | Spyphone.it
http://ift.tt/2ydgNGI
Submitted October 11, 2017 at 04:25PM by walipoo789
via reddit http://ift.tt/2wOcgc2
http://ift.tt/2ydgNGI
Submitted October 11, 2017 at 04:25PM by walipoo789
via reddit http://ift.tt/2wOcgc2
www.spyphone.it
Best new spy phone software for mobile | Spyphone.it
Spy phone software for Android, iPhone, Blackberry mobile phones allowing you to spy all recorderd conversations, phone surroundings, SMS, GPS location etc.
Read on the Web: What’s Holding Back Enterprise Security Technology Transformation?
http://ift.tt/2yg46Nl
Submitted October 11, 2017 at 05:37PM by MicheeLengronne
via reddit http://ift.tt/2wNVBpi
http://ift.tt/2yg46Nl
Submitted October 11, 2017 at 05:37PM by MicheeLengronne
via reddit http://ift.tt/2wNVBpi
Limawi
Read on the Web: What’s Holding Back Enterprise Security Technology Transformation?
Read on the Web: Last week, I wrote about the rapid cycle of innovation happening with security technologies today — I’ve never experienced a time when every element of the security st...
Security In 5: Episode 87 - In Security You Need To Answer The Hardest Question, So What?
http://ift.tt/2yb9Ng1
Submitted October 11, 2017 at 06:32PM by BinaryBlog
via reddit http://ift.tt/2ybtilR
http://ift.tt/2yb9Ng1
Submitted October 11, 2017 at 06:32PM by BinaryBlog
via reddit http://ift.tt/2ybtilR
Libsyn
Security In Five Podcast: Episode 87 - In Security You Need To Answer The Hardest Question, So What?
So What? What does this mean to me? That's the question that you need to answer. Depending on who you talk to, the answer will be different. In Security you need to apply it to those questions, So What? It's the hardest question to answer, but if you don't…