CEO cybersecurity 101: Improve your security hygiene
http://ift.tt/2ib04wb
Submitted October 27, 2017 at 11:06PM by CrankyBear
via reddit http://ift.tt/2gJuIwi
http://ift.tt/2ib04wb
Submitted October 27, 2017 at 11:06PM by CrankyBear
via reddit http://ift.tt/2gJuIwi
HPE
CEO cybersecurity 101: Improve your security hygiene | HPE
Executives must be exemplary users of corporate security. It's time to ditch easy-to-guess passwords and incorporate multifactor authentication methods.
Is there a list of USB device vendors, which implement code-signing protections on their devices?
The context of the question is "BadUSB" - USB devices firmware can be infected with malware.Let's assume I would use USB device (USB dongle for wireless mouse and keyboard, USB flash drive) on infected computer.Where to buy USB device, which is resistant to reinstalling the firmware?
Submitted October 27, 2017 at 10:43PM by vstoykov
via reddit http://ift.tt/2ib1giP
The context of the question is "BadUSB" - USB devices firmware can be infected with malware.Let's assume I would use USB device (USB dongle for wireless mouse and keyboard, USB flash drive) on infected computer.Where to buy USB device, which is resistant to reinstalling the firmware?
Submitted October 27, 2017 at 10:43PM by vstoykov
via reddit http://ift.tt/2ib1giP
reddit
Is there a list of USB device vendors, which... • r/security
The context of the question is "BadUSB" - USB devices firmware can be infected with malware. Let's assume I would use USB device (USB dongle for...
What security sites / feeds do you follow daily?
No text found
Submitted October 27, 2017 at 10:41PM by the_caller
via reddit http://ift.tt/2xvuXl5
No text found
Submitted October 27, 2017 at 10:41PM by the_caller
via reddit http://ift.tt/2xvuXl5
reddit
What security sites / feeds do you follow daily? • r/security
2 points and 0 comments so far on reddit
Google's Advanced Protection and your threat model
Google released its Advanced Protection program for public sign-up a few weeks ago. Some questions:Do you plan to make use of it?Do you have a threat model that necessitates it, or do you think it's just generally something most security professionals should take advantage of?I'm considering it myself, so I'm wondering what others are doing, or if they're even paying attention to it.
Submitted October 27, 2017 at 11:47PM by astrobase_go
via reddit http://ift.tt/2iEmDgt
Google released its Advanced Protection program for public sign-up a few weeks ago. Some questions:Do you plan to make use of it?Do you have a threat model that necessitates it, or do you think it's just generally something most security professionals should take advantage of?I'm considering it myself, so I'm wondering what others are doing, or if they're even paying attention to it.
Submitted October 27, 2017 at 11:47PM by astrobase_go
via reddit http://ift.tt/2iEmDgt
Google
Google Advanced Protection Program
The strongest account security made to protect the personal data and information of people most at risk of phishing, hacking and targeted digital attacks.
Public Key Pinning Being Removed from Chrome
http://ift.tt/2gPjppO
Submitted October 28, 2017 at 03:36AM by wchill
via reddit http://ift.tt/2ia3aAo
http://ift.tt/2gPjppO
Submitted October 28, 2017 at 03:36AM by wchill
via reddit http://ift.tt/2ia3aAo
Google
Google Groups
Google Groups allows you to create and participate in online forums and email-based groups with a rich experience for community conversations.
Password Keeper and the Human Factor
http://ift.tt/2hgPjZf
Submitted October 28, 2017 at 04:34AM by tin_hack
via reddit http://ift.tt/2zLBAkd
http://ift.tt/2hgPjZf
Submitted October 28, 2017 at 04:34AM by tin_hack
via reddit http://ift.tt/2zLBAkd
Microfocus
Password Keeper and the Human Factor | Micro Focus Blog
How do you keep track of your passwords? In your head because you only use a handful for everything? In a document on your PC, Mac, or Linux desktop, on sticky
Replace Your Exploit-Ridden Firmware with Linux
https://youtu.be/iffTJ1vPCSo
Submitted October 28, 2017 at 04:27AM by bleahbloh
via reddit http://ift.tt/2hgPl3j
https://youtu.be/iffTJ1vPCSo
Submitted October 28, 2017 at 04:27AM by bleahbloh
via reddit http://ift.tt/2hgPl3j
YouTube
Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google
Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google
With the WikiLeaks release of the vault7 material, the security of the UEFI (Unified Extensible Firmware Interface) firmware used in most PCs and laptops is once again a concern. UEFI…
With the WikiLeaks release of the vault7 material, the security of the UEFI (Unified Extensible Firmware Interface) firmware used in most PCs and laptops is once again a concern. UEFI…
Someone has Scraped my Entire Site & Have the Similar Domain Name as Mine, Pls Help!
Hello All, Need Help I have one website ficode.co.uk someone copied my all content on ficode.net , How can anyone copied my whole content. Please tell me now what should i do.
Submitted October 28, 2017 at 09:27AM by Ameliapro
via reddit http://ift.tt/2hhF6M8
Hello All, Need Help I have one website ficode.co.uk someone copied my all content on ficode.net , How can anyone copied my whole content. Please tell me now what should i do.
Submitted October 28, 2017 at 09:27AM by Ameliapro
via reddit http://ift.tt/2hhF6M8
reddit
Someone has Scraped my Entire Site & Have the Similar... • r/security
Hello All, Need Help I have one website ficode.co.uk someone copied my all content on ficode.net , How can anyone copied my whole content. Please...
[News] IoT_reaper/IoTroop likely a simple DDoS-for-hire botnet, seems to only actually have 10,000-20,000 nodes at any time. Phew!
http://ift.tt/2yLGLnt
Submitted October 28, 2017 at 03:04PM by dscottboggs
via reddit http://ift.tt/2yRF3kb
http://ift.tt/2yLGLnt
Submitted October 28, 2017 at 03:04PM by dscottboggs
via reddit http://ift.tt/2yRF3kb
Arbor Networks Threat Intelligence
Reaper Madness
On October 19th, a team of security researchers warned of a new IoT Botnet that had already infected “an estimated million organizations” and that was pois
10 Ways Hackers use to Hack your Facebook
http://ift.tt/2zUBsj4
Submitted October 28, 2017 at 02:21PM by deepupak
via reddit http://ift.tt/2xuOfHs
http://ift.tt/2zUBsj4
Submitted October 28, 2017 at 02:21PM by deepupak
via reddit http://ift.tt/2xuOfHs
Cybernog
10 Ways Hackers use to Hack your Facebook
Facebook had 2 billion monthly active users. which makes Facebook to be a preferred target of hackers. In this post i will list you the Top 10 ways hackers can hack your Facebook account.
APNIC resets passwords after whois credentials spill
http://ift.tt/2xk0Vkb
Submitted October 28, 2017 at 06:25PM by ollie-pidgy
via reddit http://ift.tt/2yaeOGh
http://ift.tt/2xk0Vkb
Submitted October 28, 2017 at 06:25PM by ollie-pidgy
via reddit http://ift.tt/2yaeOGh
reddit
APNIC resets passwords after whois credentials spill • r/security
1 points and 0 comments so far on reddit
Hungary Orders Spies to Target Soros ‘Empire’
http://ift.tt/2lhXRDP
Submitted October 28, 2017 at 11:26PM by Bastet1
via reddit http://ift.tt/2iI1i5V
http://ift.tt/2lhXRDP
Submitted October 28, 2017 at 11:26PM by Bastet1
via reddit http://ift.tt/2iI1i5V
Bloomberg.com
Hungary Orders Spies to Target Soros ‘Empire’
Hungarian Prime Minister Viktor Orban renewed his assault on George Soros, instructing his intelligence services to map what he described as the networks run by the billionaire financier’s “empire” targeting his country.
U.S. to Sanction Russian Companies After Missing Oct. 1 Deadline
http://ift.tt/2zKrYpC
Submitted October 28, 2017 at 11:13PM by Bastet1
via reddit http://ift.tt/2yZds05
http://ift.tt/2zKrYpC
Submitted October 28, 2017 at 11:13PM by Bastet1
via reddit http://ift.tt/2yZds05
Bloomberg.com
U.S. to Sanction Russian Companies After Missing Oct. 1 Deadline
The U.S. State Department said it would sanction dozens of Russian companies in the country’s defense and intelligence industry, after coming under criticism from lawmakers for missing an Oct. 1 deadline Congress set to punish Russia for its 2016 election…
Remote Code Execution in wget
http://ift.tt/2lq5asX
Submitted October 29, 2017 at 04:59AM by _Ki_
via reddit http://ift.tt/2ydGsSH
http://ift.tt/2lq5asX
Submitted October 29, 2017 at 04:59AM by _Ki_
via reddit http://ift.tt/2ydGsSH
Packetstormsecurity
Red Hat Security Advisory 2017-3075-01 ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
Chief Cybersecurity Technologist at DLT, on the evolution of the RMF and how organizations can leverage it to improve their security posture
https://www.youtube.com/watch?v=siPQmgoWmzo
Submitted October 29, 2017 at 05:25AM by hacking_love
via reddit http://ift.tt/2zMB19O
https://www.youtube.com/watch?v=siPQmgoWmzo
Submitted October 29, 2017 at 05:25AM by hacking_love
via reddit http://ift.tt/2zMB19O
YouTube
ICIT Fellow Insights: NIST Risk Management Framework: Challenges and Solutions w/Don Maclean (DLT)
In this edition of ICIT Fellow Insights, we will speak with Don Maclean, an ICIT Fellow, and Chief Cybersecurity Technologist at DLT, on the evolution of the...
Unencrypted USB drive found in street containing confidential info about Heathrow Airport
http://ift.tt/2zNHyAY
Submitted October 29, 2017 at 09:51AM by nzwasp
via reddit http://ift.tt/2ySE9UN
http://ift.tt/2zNHyAY
Submitted October 29, 2017 at 09:51AM by nzwasp
via reddit http://ift.tt/2ySE9UN
Security Breach Online
Cyber Security Leak of data about Heathrow Airport - Security Breach Online
A USB stick containing confidential information has been found on a street in London, the data is said to contain plans of when the Queen flies.
Amazon account under constant attack
Hey guys. I wasn't sure where to go with this, but I hope some of you can offer help. Basically this started with me getting 2FA codes spammed to my phone. I panicked and cleared all trusted machines for the account, changed the password to something fairly complex, and hoped it was over. It wasn't. The next day, same thing. 15 texts all at once, then silence for 15 minutes (amazon's 2FA lockout timer, I'm guessing.) Only thing that gets it to stop is changing my password. But then it picks up AGAIN the next day. And then AGAIN today. Each time, pretty complex passwords. My last one was something like $!$A8162a#19nSD1! for example.I ran MBAM, Adwcleaner, Roguekiller, Win defender and found nothing at all. It seems you can only request a 2FA code by getting the password CORRECT. And this seems to be backed up by the fact that the spam stops for a day or so each time I change it.I'm at a loss. I'm panicking. Only with Amazon is this happening, but I feel like nothing is secure at all if these passwords are getting cracked that easily. I'm terrified and I don't know what to do. Is it POSSIBLE that somehow they're able to spam the 2FA requests without guessing my password? Is it possible there's a data breach? Is there anything I can do to make this stop?
Submitted October 29, 2017 at 11:38AM by Doctor_Turkleton
via reddit http://ift.tt/2ycn34H
Hey guys. I wasn't sure where to go with this, but I hope some of you can offer help. Basically this started with me getting 2FA codes spammed to my phone. I panicked and cleared all trusted machines for the account, changed the password to something fairly complex, and hoped it was over. It wasn't. The next day, same thing. 15 texts all at once, then silence for 15 minutes (amazon's 2FA lockout timer, I'm guessing.) Only thing that gets it to stop is changing my password. But then it picks up AGAIN the next day. And then AGAIN today. Each time, pretty complex passwords. My last one was something like $!$A8162a#19nSD1! for example.I ran MBAM, Adwcleaner, Roguekiller, Win defender and found nothing at all. It seems you can only request a 2FA code by getting the password CORRECT. And this seems to be backed up by the fact that the spam stops for a day or so each time I change it.I'm at a loss. I'm panicking. Only with Amazon is this happening, but I feel like nothing is secure at all if these passwords are getting cracked that easily. I'm terrified and I don't know what to do. Is it POSSIBLE that somehow they're able to spam the 2FA requests without guessing my password? Is it possible there's a data breach? Is there anything I can do to make this stop?
Submitted October 29, 2017 at 11:38AM by Doctor_Turkleton
via reddit http://ift.tt/2ycn34H
reddit
Amazon account under constant attack • r/security
Hey guys. I wasn't sure where to go with this, but I hope some of you can offer help. Basically this started with me getting 2FA codes spammed to...
10 Methods to Bypass Cross Site Request Forgery (CSRF) Protection
http://ift.tt/2gLV1Sy
Submitted October 29, 2017 at 03:21PM by InformationSecurity
via reddit http://ift.tt/2gMdJsW
http://ift.tt/2gLV1Sy
Submitted October 29, 2017 at 03:21PM by InformationSecurity
via reddit http://ift.tt/2gMdJsW
Haider Mahmood Infosec Blog
10 Methods to Bypass Cross Site Request Forgery (CSRF) Protection
Anti CSRF token bypass, Cross Site Request Forgery Bypass, Cross Site Request Forgery examples, Methods to Bypass CSRF, CSRF protection, CSRF Prevention
Always the pens... Heathrow Queen’s Security Details Found in USB Drive
http://ift.tt/2yT2FVP
Submitted October 29, 2017 at 04:12PM by sterlingarcher79
via reddit http://ift.tt/2yZVY3M
http://ift.tt/2yT2FVP
Submitted October 29, 2017 at 04:12PM by sterlingarcher79
via reddit http://ift.tt/2yZVY3M
The Telegraph
Heathrow investigates after Queen's security details 'found on USB drive discovered lying in street'
A memory stick containing sensitive Heathrow security data, including the Queen’s route to the airport, was reportedly found lying in the street.
Randomly generated username
For sites where your username is not forced to be your email address, or is not used as your display name, is there value in having a randomly generated username?
Submitted October 29, 2017 at 06:33PM by plazman30
via reddit http://ift.tt/2xxNgGF
For sites where your username is not forced to be your email address, or is not used as your display name, is there value in having a randomly generated username?
Submitted October 29, 2017 at 06:33PM by plazman30
via reddit http://ift.tt/2xxNgGF
reddit
Randomly generated username • r/security
For sites where your username is not forced to be your email address, or is not used as your display name, is there value in having a randomly...
Techniques to Bypass Cross Site Request Forgery (CSRF) Protections
http://ift.tt/2gLV1Sy
Submitted October 29, 2017 at 05:53PM by InformationSecurity
via reddit http://ift.tt/2xw9icw
http://ift.tt/2gLV1Sy
Submitted October 29, 2017 at 05:53PM by InformationSecurity
via reddit http://ift.tt/2xw9icw
Haider Mahmood Infosec Blog
10 Methods to Bypass Cross Site Request Forgery (CSRF) Protection
Anti CSRF token bypass, Cross Site Request Forgery Bypass, Cross Site Request Forgery examples, Methods to Bypass CSRF, CSRF protection, CSRF Prevention