Free online service to audit iOS or Android apps for OWASP Mobile Top 10 and other vulnerabilities
http://ift.tt/2gjUpTF
Submitted October 23, 2017 at 09:11PM by alexmeisterq
via reddit http://ift.tt/2gD6UO5
http://ift.tt/2gjUpTF
Submitted October 23, 2017 at 09:11PM by alexmeisterq
via reddit http://ift.tt/2gD6UO5
Htbridge
Mobile X-Ray
Free online DAST, SAST and Behavioral assessment of your iOS or Android app.
Just found this podcast and it's great. It's called Darknet Diaries and it gives you the full details of how a specific breach occurred.
http://ift.tt/2xIxgAV
Submitted October 23, 2017 at 08:57PM by stonedonmars
via reddit http://ift.tt/2y0lyBP
http://ift.tt/2xIxgAV
Submitted October 23, 2017 at 08:57PM by stonedonmars
via reddit http://ift.tt/2y0lyBP
Darknetdiaries
Darknet Diaries – True stories from the dark side of the Internet.
A podcast featuring true stories from the dark side of the Internet.
Cybersecurity and Machine Learning/AI: What’s the Real Impact?
http://ift.tt/2gAg9yL
Submitted October 23, 2017 at 08:30PM by CrankyBear
via reddit http://ift.tt/2gxcDkS
http://ift.tt/2gAg9yL
Submitted October 23, 2017 at 08:30PM by CrankyBear
via reddit http://ift.tt/2gxcDkS
Security Boulevard
Cybersecurity and Machine Learning/AI: What’s the Real Impact? - Security Boulevard
Mastery and availability of new tools and weapons are a necessity in cybersecurity—chief among them are machine learning and AI.
US warns hackers are targeting energy, infrastructure and manufacturing sectors - SiliconANGLE
http://ift.tt/2yHQcTZ
Submitted October 23, 2017 at 10:16PM by SecurityTrust
via reddit http://ift.tt/2yHBURI
http://ift.tt/2yHQcTZ
Submitted October 23, 2017 at 10:16PM by SecurityTrust
via reddit http://ift.tt/2yHBURI
SiliconANGLE
US warns hackers are targeting energy, infrastructure and manufacturing sectors
The U.S. Department of Homeland Security and the Federal Bureau of Investigation have issued a rare joint statement warning that hackers are targeting firms in the energy, nuclear, water, aviation and
Update your IoTs before the hurricane arrives!
http://ift.tt/2itTzIA
Submitted October 23, 2017 at 10:28PM by securitynewsIO
via reddit http://ift.tt/2z2pJlu
http://ift.tt/2itTzIA
Submitted October 23, 2017 at 10:28PM by securitynewsIO
via reddit http://ift.tt/2z2pJlu
Security News iO
Gigantic IoT Botnet is Growing in the Shadows | Security News iO
A Gigantic IoT Botnet has been discovered by researchers at 360 lab. It has already infected millios of devices in preparation for a malware hurricane.
For Users of Redis, Running Locally Can Be a Major Security Risk
http://ift.tt/2l8g06Z
Submitted October 23, 2017 at 11:48PM by EdibleEnergy
via reddit http://ift.tt/2xiT7PM
http://ift.tt/2l8g06Z
Submitted October 23, 2017 at 11:48PM by EdibleEnergy
via reddit http://ift.tt/2xiT7PM
BugReplay Blog
For Users of Redis, Running Locally Can Be a Major Security Risk
If you are running Redis locally and, like most people as of this writing, you're using a version older than 3.2.7 (released January 31, 2017), I can most likely copy your entire database, drop an ssh key in your authorized_keys file, overwrite arbitrary…
docker-onion-nmap: Scan .onion hidden services using nmap and proxychains
http://ift.tt/2xiD2d7
Submitted October 23, 2017 at 11:30PM by chatmasta
via reddit http://ift.tt/2y0TmDG
http://ift.tt/2xiD2d7
Submitted October 23, 2017 at 11:30PM by chatmasta
via reddit http://ift.tt/2y0TmDG
GitHub
milesrichardson/docker-onion-nmap
docker-onion-nmap - Scan .onion hidden services with nmap using Tor, proxychains and dnsmasq in a minimal alpine Docker container.
Crafting Ethereum exploits by LASER fire
http://ift.tt/2yCD8Qp
Submitted October 24, 2017 at 01:42AM by berndtzl
via reddit http://ift.tt/2xi2PBV
http://ift.tt/2yCD8Qp
Submitted October 24, 2017 at 01:42AM by berndtzl
via reddit http://ift.tt/2xi2PBV
Hacker Noon
Crafting Ethereum exploits by LASER fire
Remember how the universe forks into multiple sub-universes every time a measurement is taken? Symbolic execution follows a similar…
Crippling crypto weakness opens millions of smartcards to cloning
http://ift.tt/2gBSnCg
Submitted October 24, 2017 at 04:47AM by nliausacmmv
via reddit http://ift.tt/2zz4Ieh
http://ift.tt/2gBSnCg
Submitted October 24, 2017 at 04:47AM by nliausacmmv
via reddit http://ift.tt/2zz4Ieh
Ars Technica
Crippling crypto weakness opens millions of smartcards to cloning
Gemalto IDPrime.NET almost certainly isn't the only smartcard vulnerable to ROCA.
Best practice AWS setup: multi-account / assume-tool + new cool tool release
http://ift.tt/2gt2dWS
Submitted October 24, 2017 at 03:48AM by fproulx
via reddit http://ift.tt/2gxSdIk
http://ift.tt/2gt2dWS
Submitted October 24, 2017 at 03:48AM by fproulx
via reddit http://ift.tt/2gxSdIk
The Coinbase Engineering Blog
You need more than one AWS account: AWS bastions and assume-role
You need more than one AWS account. This is to isolate production resources, manage limits (especially API rate limiting), handle costs…
MS Word Built-In Feature (DDE): Malware Execution and Attacks Demo
http://ift.tt/2iuLd38
Submitted October 24, 2017 at 09:36AM by hackerameer
via reddit http://ift.tt/2z2ZX0a
http://ift.tt/2iuLd38
Submitted October 24, 2017 at 09:36AM by hackerameer
via reddit http://ift.tt/2z2ZX0a
Ethical Hackers Club
MS Word Built-In Feature (DDE): Malware Execution and Attacks Demo
Here are some demos on using Microsoft Word built-in feature Dynamic Data Exchange (DDE) for malware execution and attacks.
Certainty: Automated CACert.pem Management for PHP Software (Open Source)
http://ift.tt/2y0grWZ
Submitted October 24, 2017 at 10:46AM by sarciszewski
via reddit http://ift.tt/2y0VBqz
http://ift.tt/2y0grWZ
Submitted October 24, 2017 at 10:46AM by sarciszewski
via reddit http://ift.tt/2y0VBqz
Paragonie
Certainty: Automated CACert.pem Management for PHP Software - Paragon Initiative Enterprises Blog
Our new open source library, which keeps your Certificate Authority certificate bundle up-to-date.
Security Issues in Sarahah uncovered By Scott Helme
http://ift.tt/2gZPCHW
Submitted October 24, 2017 at 10:43AM by srinathrajaram
via reddit http://ift.tt/2i1tH2D
http://ift.tt/2gZPCHW
Submitted October 24, 2017 at 10:43AM by srinathrajaram
via reddit http://ift.tt/2i1tH2D
reddit
Security Issues in Sarahah uncovered By Scott Helme • r/security
1 points and 0 comments so far on reddit
Let’s Enhance ! How we found @rogerkver’s $1000 wallet obfuscated private key.
http://ift.tt/2yEmjoe
Submitted October 24, 2017 at 12:15PM by shark0der
via reddit http://ift.tt/2gAqvut
http://ift.tt/2yEmjoe
Submitted October 24, 2017 at 12:15PM by shark0der
via reddit http://ift.tt/2gAqvut
Medium
Let’s Enhance ! How we found @rogerkver’s $1000 wallet obfuscated private key.
Broadcasted on French TV show “Complément d’enquête”.
Apple and Google assures to find remedies to fix Krack Wi-Fi flaw
Apple and Google assures to find remedies to fix Krack WiFi flaw to stop hackers to steal credit card numbers, passwords and private messages from internet users
Submitted October 24, 2017 at 12:41PM by CIOBulletin
via reddit http://ift.tt/2xjZ278
Apple and Google assures to find remedies to fix Krack WiFi flaw to stop hackers to steal credit card numbers, passwords and private messages from internet users
Submitted October 24, 2017 at 12:41PM by CIOBulletin
via reddit http://ift.tt/2xjZ278
reddit
Apple and Google assures to find remedies to fix... • r/security
Apple and Google assures to find remedies to fix Krack WiFi flaw to stop hackers to steal credit card numbers, passwords and private messages from...
Attack of the week: DUHK
http://ift.tt/2gwvCMc
Submitted October 24, 2017 at 02:15PM by campuscodi
via reddit http://ift.tt/2y2muW5
http://ift.tt/2gwvCMc
Submitted October 24, 2017 at 02:15PM by campuscodi
via reddit http://ift.tt/2y2muW5
A Few Thoughts on Cryptographic Engineering
Attack of the week: DUHK
Before we get started, fair warning: this is going to be a post about a fairly absurd (but non-trivial!) attack on cryptographic systems. But that’s ok, because it’s based on a fairly a…
The Cloud Native Computing Foundation adds two security projects to its open source stable
http://ift.tt/2yGpPyE
Submitted October 24, 2017 at 02:30PM by MicheeLengronne
via reddit http://ift.tt/2z2P8eD
http://ift.tt/2yGpPyE
Submitted October 24, 2017 at 02:30PM by MicheeLengronne
via reddit http://ift.tt/2z2P8eD
TechCrunch
The Cloud Native Computing Foundation adds two security projects to its open source stable
The Cloud Native Computing Foundation (CNCF) is probably best known for being the home of the Kubernetes container orchestration project, but there plenty of other projects that now fall under the…
Server Session SSL|TLS
http://ift.tt/2l9FjWa
Submitted October 24, 2017 at 02:55PM by MicheeLengronne
via reddit http://ift.tt/2yKpBFV
http://ift.tt/2l9FjWa
Submitted October 24, 2017 at 02:55PM by MicheeLengronne
via reddit http://ift.tt/2yKpBFV
Limawi
Server Session SSL|TLS
protocol about server session SSL/TLS.
SandBox-Dumper - Hacky Utility for providing iOS Application Sandbox location + Other information
http://ift.tt/2h48rd9
Submitted October 24, 2017 at 04:31PM by din3zh
via reddit http://ift.tt/2yKAVl7
http://ift.tt/2h48rd9
Submitted October 24, 2017 at 04:31PM by din3zh
via reddit http://ift.tt/2yKAVl7
GitHub
dineshshetty/iOS-SandBox-Dumper
iOS-SandBox-Dumper - SandBox-Dumper makes use of multiple private libraries to provide exact locations of the application sandbox, application bundle and some other interesting information
Solutions to the first 6 Fire-eye Flare-On challenges
http://vulnerable.space
Submitted October 24, 2017 at 02:57PM by _GradiusX_
via reddit http://ift.tt/2lcTYju
http://vulnerable.space
Submitted October 24, 2017 at 02:57PM by _GradiusX_
via reddit http://ift.tt/2lcTYju
reddit
Solutions to the first 6 Fire-eye Flare-On challenges • r/netsec
1 points and 0 comments so far on reddit
ADV170014 NTLM SSO: Exploitation Guide
http://ift.tt/2yMQZmS
Submitted October 24, 2017 at 05:15PM by galapag0
via reddit http://ift.tt/2ixMkPH
http://ift.tt/2yMQZmS
Submitted October 24, 2017 at 05:15PM by galapag0
via reddit http://ift.tt/2ixMkPH
Sysadmin Life...
ADV170014 NTLM SSO: Exploitation Guide
October 2017, Microsoft patch Tuesday included an optional security advisory, ADV170014, this advisory makes reference to a bug on the NTLM authentication scheme, that allows a malicious attacker t…