My FirsReportt Instagram Bug Bounty
https://ift.tt/3lgDBzX
Submitted August 19, 2021 at 04:06PM by banginpadr
via reddit https://ift.tt/3AUgbER
https://ift.tt/3lgDBzX
Submitted August 19, 2021 at 04:06PM by banginpadr
via reddit https://ift.tt/3AUgbER
Medium
My First Instagram Bug Bounty Report
Something is better than nothing, even if it is less than one wanted.
AnchorWatch: A Rogue Device Detection Script with Email Alerts Functionality [Windows Subsystem/PowerShell]
https://ift.tt/2SV9vA8
Submitted August 19, 2021 at 06:47PM by rootsh3ll
via reddit https://ift.tt/3y0FJhQ
https://ift.tt/2SV9vA8
Submitted August 19, 2021 at 06:47PM by rootsh3ll
via reddit https://ift.tt/3y0FJhQ
GitHub
GitHub - iamrootsh3ll/AnchorWatch: A Rogue Device Detection Script with Email Alerts Functionality for Windows Subsystem
A Rogue Device Detection Script with Email Alerts Functionality for Windows Subsystem - GitHub - iamrootsh3ll/AnchorWatch: A Rogue Device Detection Script with Email Alerts Functionality for Window...
Figuring out user behavior on Windows
https://ift.tt/3ATp0i9
Submitted August 19, 2021 at 07:19PM by oddvarmoe
via reddit https://ift.tt/3CYHWOp
https://ift.tt/3ATp0i9
Submitted August 19, 2021 at 07:19PM by oddvarmoe
via reddit https://ift.tt/3CYHWOp
TrustedSec
Oh, Behave! Figuring Out User Behavior
I decided to embark on a journey to understand user behavior without knowing exactly how I would gather details about user activity as a research topic. A…
ShadowPad | A Masterpiece of Privately Sold Malware in Chinese Espionage
https://ift.tt/3y5Emym
Submitted August 19, 2021 at 08:18PM by Cyberthere
via reddit https://ift.tt/3mhWYco
https://ift.tt/3y5Emym
Submitted August 19, 2021 at 08:18PM by Cyberthere
via reddit https://ift.tt/3mhWYco
SentinelOne
ShadowPad | A Masterpiece of Privately Sold Malware in Chinese Espionage - SentinelLabs
Supplying a custom backdoor to a cluster of APT groups, the personas behind ShadowPad have maintained a cloak of secrecy, until now.
T-Mobile allegedly hacked, claims no sensitive data stolen
https://ift.tt/3iYT4CU
Submitted August 19, 2021 at 11:51PM by Pm_dat_bootyhole
via reddit https://ift.tt/2XKLOmh
https://ift.tt/3iYT4CU
Submitted August 19, 2021 at 11:51PM by Pm_dat_bootyhole
via reddit https://ift.tt/2XKLOmh
T-Mobile
Our Response to the Data Breach (Aug 2021) | T-Mobile
Learn more about our response to the recent cybersecurity incident and the steps we're taking to ensure our customers' data is safe.
Independent Peer Review (from Cititzen Lab) of Amnesty International’s Forensic Methods for Identifying Pegasus Spyware
https://ift.tt/3eylaCB
Submitted August 20, 2021 at 02:40AM by Turbulent_Froyo9385
via reddit https://ift.tt/3swUJTn
https://ift.tt/3eylaCB
Submitted August 20, 2021 at 02:40AM by Turbulent_Froyo9385
via reddit https://ift.tt/3swUJTn
The Citizen Lab
Independent Peer Review of Amnesty International's Forensic Methods for Identifying Pegasus Spyware - The Citizen Lab
Citizen Lab's peer review of Amnesty International's forensic techniques to identify Pegasus spyware concludes they are sound.
CIA: Confidentiality, Integrity and Availability
https://ift.tt/3xWH0GN
Submitted August 20, 2021 at 03:29AM by WeHackPurpleAcademy
via reddit https://ift.tt/3sz1ww8
https://ift.tt/3xWH0GN
Submitted August 20, 2021 at 03:29AM by WeHackPurpleAcademy
via reddit https://ift.tt/3sz1ww8
reddit
CIA: Confidentiality, Integrity and Availability
Posted in r/netsec by u/WeHackPurpleAcademy • 0 points and 1 comment
How to contact Google SRE: Dropping a shell in cloud SQL
https://ift.tt/2CLqeDY
Submitted August 20, 2021 at 06:46AM by NearbyIssue629
via reddit https://ift.tt/3syYTKD
https://ift.tt/2CLqeDY
Submitted August 20, 2021 at 06:46AM by NearbyIssue629
via reddit https://ift.tt/3syYTKD
Offensi
How to contact Google SRE: Dropping a shell in cloud SQL
Note: The vulnerabilities that are discussed in this post were patched quickly and properly by Google. We support responsible disclosure. The research that resulted in this post was done by me and …
DTLS Interception Tool (DIT) | A mitmproxy-like tool for DTLS connections
https://ift.tt/2WceUK9
Submitted August 20, 2021 at 02:43PM by WasZurHecke
via reddit https://ift.tt/3sBJucC
https://ift.tt/2WceUK9
Submitted August 20, 2021 at 02:43PM by WasZurHecke
via reddit https://ift.tt/3sBJucC
GitHub
GitHub - CountablyInfinite/dit: DIT is a DTLS MitM proxy implemented in Python 3. It can intercept, manipulate and suppress datagrams…
DIT is a DTLS MitM proxy implemented in Python 3. It can intercept, manipulate and suppress datagrams between two DTLS endpoints and supports psk-based and certificate-based authentication schemes ...
Dissecting the last version of Conti Ransomware using a step-by-step approach
https://ift.tt/3hOPbP4
Submitted August 20, 2021 at 06:02PM by transt
via reddit https://ift.tt/3y3vzgq
https://ift.tt/3hOPbP4
Submitted August 20, 2021 at 06:02PM by transt
via reddit https://ift.tt/3y3vzgq
reddit
Dissecting the last version of Conti Ransomware using a...
Posted in r/netsec by u/transt • 76 points and 0 comments
[CFP] Call for Papers for Hardwear.io Security Conference Netherlands 2021 is OPEN
https://ift.tt/3rD3Ql4
Submitted August 20, 2021 at 07:41PM by hardweario
via reddit https://ift.tt/384oVf6
https://ift.tt/3rD3Ql4
Submitted August 20, 2021 at 07:41PM by hardweario
via reddit https://ift.tt/384oVf6
www.hardwear.io
Call for Papers | hardwear.io | Netherlands 2021
hardwear.io Netherlands 2021 - Hardware Security Conference & Training is seeking innovative research on attacks or mitigation on any hardware. Submit your research paper.
Lobste.rs Password Reset Vulnerability (via Timing Side-Channel)
https://ift.tt/2W47V6I
Submitted August 20, 2021 at 08:45PM by Soatok
via reddit https://ift.tt/37XNYAL
https://ift.tt/2W47V6I
Submitted August 20, 2021 at 08:45PM by Soatok
via reddit https://ift.tt/37XNYAL
Dhole Moments
Timing Attack on SQL Queries Through Lobste.rs Password Reset
Just to assuage any panic, let me state this up front. If you’re reading this blog post wondering if your Lobste.rs account is at risk, good news: I didn’t publish it until after the vu…
Cloudflare says it mitigated a record-breaking 17.2M rps DDoS attack
https://ift.tt/3iYGCDm
Submitted August 20, 2021 at 10:08PM by Snardley
via reddit https://ift.tt/3B00Kek
https://ift.tt/3iYGCDm
Submitted August 20, 2021 at 10:08PM by Snardley
via reddit https://ift.tt/3B00Kek
The Record by Recorded Future
Cloudflare says it mitigated a record-breaking 17.2M rps DDoS attack
Internet infrastructure company Cloudflare disclosed today that it mitigated the largest volumetric distributed denial of service (DDoS) attack that was recorded to date.
Facebook tool protects Afghan people who fear becoming Taliban targets
https://ift.tt/3k5PBBY
Submitted August 20, 2021 at 10:41PM by No_Fisherman_661
via reddit https://ift.tt/3z4gHQ8
https://ift.tt/3k5PBBY
Submitted August 20, 2021 at 10:41PM by No_Fisherman_661
via reddit https://ift.tt/3z4gHQ8
TechnoidHost
Facebook tool protects Afghan people who fear becoming Taliban targets | TechnoidHost
The Latest Facebook tool protects Afghan people who fear becoming Taliban targets. The Facebook toll launched by Facebook will help the people in fear of
Office 365 audit logging and its bypasses
https://ift.tt/3z4ZmXf
Submitted August 21, 2021 at 12:41AM by rikvduijn
via reddit https://ift.tt/3DeVVQu
https://ift.tt/3z4ZmXf
Submitted August 21, 2021 at 12:41AM by rikvduijn
via reddit https://ift.tt/3DeVVQu
Zolder - Applied Security Research
Office 365 audit logging | Zolder - Applied Security Research
It’s important to enable audit logging for o365 even if you are not monitoring them actively. Atleast if you get...
Understanding Network Access in Windows AppContainers
https://ift.tt/3sElmpK
Submitted August 21, 2021 at 11:41AM by 0xdea
via reddit https://ift.tt/3sAekSM
https://ift.tt/3sElmpK
Submitted August 21, 2021 at 11:41AM by 0xdea
via reddit https://ift.tt/3sAekSM
Blogspot
Understanding Network Access in Windows AppContainers
Posted by James Forshaw, Project Zero Recently I've been delving into the inner workings of the Windows Firewall. This is interesting to ...
Breaking electron-store's encryption
https://ift.tt/2WiTJ9G
Submitted August 22, 2021 at 07:52AM by veggiedefender
via reddit https://ift.tt/2WcArmi
https://ift.tt/2WiTJ9G
Submitted August 22, 2021 at 07:52AM by veggiedefender
via reddit https://ift.tt/2WcArmi
blog.jse.li
Breaking electron-store's encryption | Jesse Li
Well-known vulnerabilities in `aes-256-cbc` allow attackers to modify encrypted config files without knowing the secret key.
CVE-2021-32682 / CVE-2021-23394 - Write-up of several pre-auth RCEs in elFinder < 2.1.59
https://ift.tt/3iVdfSk
Submitted August 22, 2021 at 11:03PM by monoimpact
via reddit https://ift.tt/3y5wHjz
https://ift.tt/3iVdfSk
Submitted August 22, 2021 at 11:03PM by monoimpact
via reddit https://ift.tt/3y5wHjz
Sonarsource
elFinder - A Case Study of Web File Manager Vulnerabilities
Our case study of elFinder 2.1.57 describes several critical code vulnerabilities commonly found in web file managers and how to patch them.
macOS 11's hidden security improvements
https://ift.tt/3iUbcOr
Submitted August 23, 2021 at 01:52AM by 0xdea
via reddit https://ift.tt/386tnKo
https://ift.tt/3iUbcOr
Submitted August 23, 2021 at 01:52AM by 0xdea
via reddit https://ift.tt/386tnKo
Malwarebytes
macOS 11’s hidden security improvements
A deep dive into macOS 11's internals reveals some security surprises that deserve to be more widely known.
https://ift.tt/2Wk2YXf
https://ift.tt/2Wk2YXf
Submitted August 23, 2021 at 03:14AM by russell1492
via reddit https://ift.tt/3mpfwHq
https://ift.tt/2Wk2YXf
Submitted August 23, 2021 at 03:14AM by russell1492
via reddit https://ift.tt/3mpfwHq
Google
Real-time meetings by Google. Using your browser, share your video, desktop, and presentations with teammates and customers.
Anti-Debug JS/WASM Polyglots by Hand
https://ift.tt/3y8WhEg
Submitted August 23, 2021 at 03:54AM by netsecfriends
via reddit https://ift.tt/3B3DiNn
https://ift.tt/3y8WhEg
Submitted August 23, 2021 at 03:54AM by netsecfriends
via reddit https://ift.tt/3B3DiNn
remyhax.xyz
Anti-Debug JS/WASM by Hand
Last week a friend of mine asked me to debug/RE some phishing emails that had been sent to them. These phishing emails were visually very clever and looked identical to the real site! But as I looked at the javanoscript I frankly became embarassed for the developer.