New EMOTET Hijacks a Windows API, Evades Sandbox and Analysis
http://ift.tt/2iZ0JB1
Submitted November 15, 2017 at 08:39PM by EvanConover
via reddit http://ift.tt/2APBb1u
http://ift.tt/2iZ0JB1
Submitted November 15, 2017 at 08:39PM by EvanConover
via reddit http://ift.tt/2APBb1u
Trendmicro
New EMOTET Hijacks a Windows API, Evades Sandbox and Analysis - TrendLabs Security Intelligence Blog
We discussed the re-emergence of banking malware EMOTET in September and how it has adopted a wider scope since it wasn’t picky about the industries it attacks. We recently discovered that EMOTET has a new iteration (detected as TSPY_EMOTET.SMD10) with a…
Sith Spam Bots Take a Page from a Star Wars Novel(s)
http://ift.tt/2zMaQkQ
Submitted November 15, 2017 at 09:20PM by whitehattracker
via reddit http://ift.tt/2A0vKzo
http://ift.tt/2zMaQkQ
Submitted November 15, 2017 at 09:20PM by whitehattracker
via reddit http://ift.tt/2A0vKzo
reddit
Sith Spam Bots Take a Page from a Star Wars Novel(s) • r/security
1 points and 0 comments so far on reddit
Bsides Lisbon 2017 Videos
https://www.youtube.com/playlist?list=PLbuNP88_wbNx3RfhlCMhjlIEKg4t8YopL
Submitted November 15, 2017 at 04:54PM by clviper
via reddit http://ift.tt/2zF7zGs
https://www.youtube.com/playlist?list=PLbuNP88_wbNx3RfhlCMhjlIEKg4t8YopL
Submitted November 15, 2017 at 04:54PM by clviper
via reddit http://ift.tt/2zF7zGs
YouTube
BSidesLisbon 2017 - YouTube
BSidesLisbon is the premier technical information security conference in Portugal. It is a community organized, not for profit, conference started in 2013 an...
What happens when you try to guess the type of a void pointer (CVE-2017-16379)
http://ift.tt/2APS8c4
Submitted November 15, 2017 at 09:43PM by Cybellum
via reddit http://ift.tt/2zGSqnA
http://ift.tt/2APS8c4
Submitted November 15, 2017 at 09:43PM by Cybellum
via reddit http://ift.tt/2zGSqnA
Cybellum
CY-2017-011: Type Confusion in Adobe Acrobat | Cybellum
Protect JS/VBS/PS Payloads with Environmental and HTTP Keying
http://ift.tt/2z49e8S
Submitted November 15, 2017 at 10:04PM by ad4pt_
via reddit http://ift.tt/2z4wNhT
http://ift.tt/2z49e8S
Submitted November 15, 2017 at 10:04PM by ad4pt_
via reddit http://ift.tt/2z4wNhT
Adapt and Attack
Keying Payloads for Scripting Languages
Keying payloads is an effective method to evade sandbox detection, prevent antivirus detection, and slow down incident response. This post covers environmental keying and HTTP keying.
ZeroNights ICO Hacking Contest Writeup
http://ift.tt/2ihQTdY
Submitted November 15, 2017 at 11:22PM by alexlash
via reddit http://ift.tt/2juAFBO
http://ift.tt/2ihQTdY
Submitted November 15, 2017 at 11:22PM by alexlash
via reddit http://ift.tt/2juAFBO
ICO Security
ZeroNights ICO Hacking Contest Writeup
Prior to ZeroNights security conference, an ICO hacking contest had been announced. The first three contestants to solve the tasks could…
Blind Operator Mode - An open source "defensive" rootkit created for a VPN provider that wants to keep their customer's connections private
http://ift.tt/2iXBRcN
Submitted November 15, 2017 at 11:09PM by IncludeSec
via reddit http://ift.tt/2hBLyRx
http://ift.tt/2iXBRcN
Submitted November 15, 2017 at 11:09PM by IncludeSec
via reddit http://ift.tt/2hBLyRx
PoshC2 v3 with SOCKS Proxy (SharpSocks)
http://ift.tt/2zJZEqZ
Submitted November 15, 2017 at 11:59PM by eth_
via reddit http://ift.tt/2hudgMB
http://ift.tt/2zJZEqZ
Submitted November 15, 2017 at 11:59PM by eth_
via reddit http://ift.tt/2hudgMB
Nettitude Labs
PoshC2 v3 with SOCKS Proxy (SharpSocks)
OVERVIEW We’ve been working on quite a few changes since the release of PoshC2 v2, our public Command & Control framework, back in December 2016. In this blog we’ll talk about the top changes a…
[News] MacPass 0.7 released (native macOS port of KeePass)
GitHub Link http://ift.tt/1j7w6AhChangelog:MacPass 0.7 introduces a lot of changes and a vast amount of bug fixes.Features:KDBX4 support (ChaCha Cipher, Argon2 Key Derivation)Database merge on file change as well as manual mergeTwofish Cipher for KDB and KDBX databasesFull support of the entry historyPartial support for multi-selection of entries and groupsSupport for custom iconsCreate custom icons from favorite icons for URLsEnhanced display in database settingsAuto-completion for tagsBackground color of entries is used to colorize default iconsAdded settings to enabled and change history support on databasesAdded additional enforce password change once optionAdded setting to lock database if user changes (e.g fast user switching)Moved custom fields to the general tab and removed additional tab.Removed a lot of annoyances when working with KDB filesEnhanced Auto-type candidate selection dialogBugfixes:fixed broken clearing of clipboard when copy is directly invoked via Cmd+C or menu item on text inputsfixed issues resulting in placeholders not being evaluated on Auto-typefixed multiple issues resulting in lost data after edits (notes in particular)removed many incompatibilities in KDBX output with other Keepass clientsKnown Issues:it's currently not possible to show protected custom attributes independently from their protected settingFor a complete list of changes see 0.6.2-alpha…0.7 and the corresponding submodule commitsVersion 0.7 requires macOS 10.10. Support for 10.8 and 10.9 has been dropped.
Submitted November 16, 2017 at 12:49AM by WalrusSwarm
via reddit http://ift.tt/2hu2ztm
GitHub Link http://ift.tt/1j7w6AhChangelog:MacPass 0.7 introduces a lot of changes and a vast amount of bug fixes.Features:KDBX4 support (ChaCha Cipher, Argon2 Key Derivation)Database merge on file change as well as manual mergeTwofish Cipher for KDB and KDBX databasesFull support of the entry historyPartial support for multi-selection of entries and groupsSupport for custom iconsCreate custom icons from favorite icons for URLsEnhanced display in database settingsAuto-completion for tagsBackground color of entries is used to colorize default iconsAdded settings to enabled and change history support on databasesAdded additional enforce password change once optionAdded setting to lock database if user changes (e.g fast user switching)Moved custom fields to the general tab and removed additional tab.Removed a lot of annoyances when working with KDB filesEnhanced Auto-type candidate selection dialogBugfixes:fixed broken clearing of clipboard when copy is directly invoked via Cmd+C or menu item on text inputsfixed issues resulting in placeholders not being evaluated on Auto-typefixed multiple issues resulting in lost data after edits (notes in particular)removed many incompatibilities in KDBX output with other Keepass clientsKnown Issues:it's currently not possible to show protected custom attributes independently from their protected settingFor a complete list of changes see 0.6.2-alpha…0.7 and the corresponding submodule commitsVersion 0.7 requires macOS 10.10. Support for 10.8 and 10.9 has been dropped.
Submitted November 16, 2017 at 12:49AM by WalrusSwarm
via reddit http://ift.tt/2hu2ztm
GitHub
mstarke/MacPass
MacPass - A native OS X KeePass client
White House Blog: Improving and Making the Vulnerability Equities Process Transparent is the Right Thing to Do
http://ift.tt/2zDe8cq
Submitted November 16, 2017 at 12:33AM by jamesgalb
via reddit http://ift.tt/2zJ7XTW
http://ift.tt/2zDe8cq
Submitted November 16, 2017 at 12:33AM by jamesgalb
via reddit http://ift.tt/2zJ7XTW
whitehouse.gov
Improving and Making the Vulnerability Equities Process Transparent is the Right Thing to Do
There can be no doubt that America faces significant risk to our national security and public safety from cyber threats. During the past 25 years, we have moved much of what we value to a digital format and stored it in Internet-connected devices that are…
CVE-2017-12337: Cisco Voice Operating System-Based Products Unauthorized Access Vulnerability
http://ift.tt/2hu2xlh
Submitted November 15, 2017 at 11:54PM by bagaudin
via reddit http://ift.tt/2ijgFP6
http://ift.tt/2hu2xlh
Submitted November 15, 2017 at 11:54PM by bagaudin
via reddit http://ift.tt/2ijgFP6
Cisco
Cisco Security Threat and Vulnerability Intelligence
The Cisco Security portal provides actionable intelligence for security threats and vulnerabilities in Cisco products and services and third-party products.
Spammers using "send to a friend" form filler bots and Star Wars to trick spam filters
http://ift.tt/2zMaQkQ
Submitted November 16, 2017 at 01:02AM by buildops
via reddit http://ift.tt/2msFegZ
http://ift.tt/2zMaQkQ
Submitted November 16, 2017 at 01:02AM by buildops
via reddit http://ift.tt/2msFegZ
reddit
Spammers using "send to a friend" form filler bots and... • r/netsec
2 points and 0 comments so far on reddit
afl-unicorn: Part 2 — Fuzzing the ‘Unfuzzable’
http://ift.tt/2mtmdeu
Submitted November 16, 2017 at 12:46AM by njv299
via reddit http://ift.tt/2AOJL0x
http://ift.tt/2mtmdeu
Submitted November 16, 2017 at 12:46AM by njv299
via reddit http://ift.tt/2AOJL0x
Hacker Noon
afl-unicorn: Part 2 — Fuzzing the ‘Unfuzzable’
Demonstrating how to use afl-unicorn against real-world userland applications
CVS says outages at pharmacies due to network problems
http://ift.tt/2zZgRNX
Submitted November 16, 2017 at 02:31AM by SecurityWiseGuy
via reddit http://ift.tt/2ALAoh7
http://ift.tt/2zZgRNX
Submitted November 16, 2017 at 02:31AM by SecurityWiseGuy
via reddit http://ift.tt/2ALAoh7
CNBC
Some CVS pharmacies are blocking prenoscription refills, exec blames 'internal network' issues
The cause is not known yet, CVS Health's David Dorman tells CNBC.
How to perform simple malware behavior analysis?
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've already tried to submit to hybrid-analysis.com, but it gives me an error.What tool could I use that is not too difficulty to learn (as disassembly, etc.)?Thanks
Submitted November 16, 2017 at 02:42AM by joaopaocha
via reddit http://ift.tt/2jvwQfr
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've already tried to submit to hybrid-analysis.com, but it gives me an error.What tool could I use that is not too difficulty to learn (as disassembly, etc.)?Thanks
Submitted November 16, 2017 at 02:42AM by joaopaocha
via reddit http://ift.tt/2jvwQfr
reddit
How to perform simple malware behavior analysis? • r/security
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've...
No boundaries: Exfiltration of personal data by session-replay noscripts
http://ift.tt/2A0gjr3
Submitted November 16, 2017 at 03:10AM by danwin
via reddit http://ift.tt/2ARQ978
http://ift.tt/2A0gjr3
Submitted November 16, 2017 at 03:10AM by danwin
via reddit http://ift.tt/2ARQ978
reddit
No boundaries: Exfiltration of personal data by... • r/netsec
1 points and 0 comments so far on reddit
Parsing Untrusted File Formats Safely
http://ift.tt/2AIKQWH
Submitted November 16, 2017 at 05:14AM by defunct_io
via reddit http://ift.tt/2zI2DQA
http://ift.tt/2AIKQWH
Submitted November 16, 2017 at 05:14AM by defunct_io
via reddit http://ift.tt/2zI2DQA
GitHub
google/puffs
puffs - Parsing Untrusted File Formats Safely
Forbes '30 Under 30' Conference Website Exposed Attendees' Personal Information
http://ift.tt/2zEf9Rm
Submitted November 16, 2017 at 10:15AM by antdude
via reddit http://ift.tt/2iZxnCP
http://ift.tt/2zEf9Rm
Submitted November 16, 2017 at 10:15AM by antdude
via reddit http://ift.tt/2iZxnCP
Motherboard
Forbes '30 Under 30' Conference Website Exposed Attendees' Personal Information
A former honoree discovered a security flaw in Forbes’ system that revealed phone numbers, emails, and date of birth.
Plus Accounts for Students! (ProtonMail)
http://ift.tt/2mvgZii
Submitted November 16, 2017 at 10:56AM by sixw
via reddit http://ift.tt/2infEFV
http://ift.tt/2mvgZii
Submitted November 16, 2017 at 10:56AM by sixw
via reddit http://ift.tt/2infEFV
Customer Feedback for ProtonMail
Plus Account with EDU Email
-> Free plus account for uni/post-secondary students
- Can be featured in github's student pack (https://education.github.com/pack)
- Account upgrade could simply expire at the end of educational term
- Custom domain options allow students to use their…
- Can be featured in github's student pack (https://education.github.com/pack)
- Account upgrade could simply expire at the end of educational term
- Custom domain options allow students to use their…
What is the best password manager according to you?
No text found
Submitted November 16, 2017 at 12:39PM by HugoTRB
via reddit http://ift.tt/2hDeade
No text found
Submitted November 16, 2017 at 12:39PM by HugoTRB
via reddit http://ift.tt/2hDeade
reddit
What is the best password manager according to you? • r/security
2 points and 2 comments so far on reddit
Week 45 in Information Security, 2017
http://ift.tt/2ALNGdD
Submitted November 16, 2017 at 04:57PM by undercomm
via reddit http://ift.tt/2in9Yvn
http://ift.tt/2ALNGdD
Submitted November 16, 2017 at 04:57PM by undercomm
via reddit http://ift.tt/2in9Yvn
Malgregator
InfoSec Week 45, 2017
Researchers exploited antivirus software quarantine mechanism to gain privileges by manipulating the restore process from the virus...