Adware company threatens to sue malware researcher for finding similarities to malware
http://ift.tt/2C6LX3U
Submitted December 13, 2017 at 07:48PM by Eliad-Cybereason
via reddit http://ift.tt/2ASjHC5
http://ift.tt/2C6LX3U
Submitted December 13, 2017 at 07:48PM by Eliad-Cybereason
via reddit http://ift.tt/2ASjHC5
Cybereason
OSX.Pirrit Mac Adware Part III: The DaVinci Code
Cybereason researcher Amit Serper discovers a new variant of TargetingEdge's Mac OSX Pirrit malware, now this adware includes remote access tool RAT capabilities.
The Curious Case of Caching CSRF Tokens
http://ift.tt/2ymFWwQ
Submitted December 13, 2017 at 07:47PM by civicode
via reddit http://ift.tt/2BYd7Jx
http://ift.tt/2ymFWwQ
Submitted December 13, 2017 at 07:47PM by civicode
via reddit http://ift.tt/2BYd7Jx
reddit
The Curious Case of Caching CSRF Tokens • r/netsec
0 points and 0 comments so far on reddit
TLS 'ROBOT' Vulnerability Allows Attackers to Obtain RSA Key Through Discrepancies in PKCS Padding
http://ift.tt/2BEEV9M
Submitted December 13, 2017 at 09:55PM by Derbel__McDillet
via reddit http://ift.tt/2j08Ygs
http://ift.tt/2BEEV9M
Submitted December 13, 2017 at 09:55PM by Derbel__McDillet
via reddit http://ift.tt/2j08Ygs
www.kb.cert.org
Vulnerability Note VU#144389 - TLS implementations may disclose side channel information via discrepencies between valid and invalid…
TLS implementations may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding, and may therefore be vulnerable to Bleichenbacher-style attacks.. This attack is known as a
5 ransomware as a service (RaaS) kits
http://ift.tt/2nY2X9A
Submitted December 13, 2017 at 09:39PM by volci
via reddit http://ift.tt/2ATWEGZ
http://ift.tt/2nY2X9A
Submitted December 13, 2017 at 09:39PM by volci
via reddit http://ift.tt/2ATWEGZ
Naked Security
5 ransomware as a service (RaaS) kits – SophosLabs investigates
A look at five RaaS kits and how each is marketed and priced
Palo Alto Networks firewalls pre-auth remote root code execution via web management (CVE-2017-15944)
http://ift.tt/2BiN8jk
Submitted December 13, 2017 at 09:46PM by 0xdea
via reddit http://ift.tt/2ASTeEk
http://ift.tt/2BiN8jk
Submitted December 13, 2017 at 09:46PM by 0xdea
via reddit http://ift.tt/2ASTeEk
seclists.org
Full Disclosure: CVE-2017-15944: Palo Alto Networks firewalls remote root code
execution
execution
Trend Micro researcher details a bug in DirecTV's Wireless Video Bridge that allows remote root.
http://ift.tt/2ABRvqh
Submitted December 13, 2017 at 10:30PM by RedmondSecGnome
via reddit http://ift.tt/2ynjzY6
http://ift.tt/2ABRvqh
Submitted December 13, 2017 at 10:30PM by RedmondSecGnome
via reddit http://ift.tt/2ynjzY6
Zero Day Initiative
Remote Root in DirecTV's Wireless Video Bridge: A Tale of Rage and Despair
In this guest blog, Trend Micro DVLabs researcher Ricky Lawshae discusses the recently disclosed CVE-2017-17411. He discovered and reported this bug through the ZDI program. Earlier this year, I learned that AT&T was starting to move customers away from its…
Remote Root in DirecTV's Wireless Video Bridge: A Tale of Rage and Despair
http://ift.tt/2ABRvqh
Submitted December 13, 2017 at 10:14PM by HeadlessZeke
via reddit http://ift.tt/2iZKq7l
http://ift.tt/2ABRvqh
Submitted December 13, 2017 at 10:14PM by HeadlessZeke
via reddit http://ift.tt/2iZKq7l
Zero Day Initiative
Remote Root in DirecTV's Wireless Video Bridge: A Tale of Rage and Despair
In this guest blog, Trend Micro DVLabs researcher Ricky Lawshae discusses the recently disclosed CVE-2017-17411. He discovered and reported this bug through the ZDI program. Earlier this year, I learned that AT&T was starting to move customers away from its…
Security Now 641 The iOS Security Trade-off | TWiT.TV
http://ift.tt/2z5ub1m
Submitted December 13, 2017 at 11:18PM by dmp1ce
via reddit http://ift.tt/2nZczAY
http://ift.tt/2z5ub1m
Submitted December 13, 2017 at 11:18PM by dmp1ce
via reddit http://ift.tt/2nZczAY
TWiT.tv
Security Now 641 The iOS Security Trade-off | TWiT.TV
This week we discuss the details behind the 'USB / JTAG takeover' of Intel's Management Engine, a rare Project Zero discovery, Microsoft's well-meaning but ill-tested IoT security …
Loveland Co to start tracking you via your cell phone's MAC address
http://ift.tt/2j0rBRq
Submitted December 13, 2017 at 11:23PM by Fearm0nger
via reddit http://ift.tt/2CeOjxQ
http://ift.tt/2j0rBRq
Submitted December 13, 2017 at 11:23PM by Fearm0nger
via reddit http://ift.tt/2CeOjxQ
Lovelandpolitics
Loveland tracking resident movements using unique identifier on mobile devices
Loveland's interim director of public works mislead Loveland's City Council on December 5, 2017 claiming receivers the city is placing around the community cannot link an individual to a phone.
How Email Open Tracking Quietly Took Over the Web
http://ift.tt/2B3jbmG
Submitted December 14, 2017 at 12:10AM by volci
via reddit http://ift.tt/2ATyso5
http://ift.tt/2B3jbmG
Submitted December 14, 2017 at 12:10AM by volci
via reddit http://ift.tt/2ATyso5
WIRED
How Email Open Tracking Quietly Took Over the Web
You give up more privacy than you might think each time you open an email.
Remote Root in DirectTV's Wireless Video Bridge
http://ift.tt/2ABRvqh
Submitted December 14, 2017 at 12:08AM by zalzane453
via reddit http://ift.tt/2C2dsuP
http://ift.tt/2ABRvqh
Submitted December 14, 2017 at 12:08AM by zalzane453
via reddit http://ift.tt/2C2dsuP
Zero Day Initiative
Remote Root in DirecTV's Wireless Video Bridge: A Tale of Rage and Despair
In this guest blog, Trend Micro DVLabs researcher Ricky Lawshae discusses the recently disclosed CVE-2017-17411. He discovered and reported this bug through the ZDI program. Earlier this year, I learned that AT&T was starting to move customers away from its…
Hermes: cryptographic access control for distributed systems
http://ift.tt/2BikWNs
Submitted December 13, 2017 at 11:59PM by paFarb
via reddit http://ift.tt/2iY8yav
http://ift.tt/2BikWNs
Submitted December 13, 2017 at 11:59PM by paFarb
via reddit http://ift.tt/2iY8yav
reddit
Hermes: cryptographic access control for distributed... • r/security
1 points and 0 comments so far on reddit
Don't Trust the Host Header for Sending Password Reset Emails
http://ift.tt/2CdrUko
Submitted December 14, 2017 at 12:34AM by cablej
via reddit http://ift.tt/2AiwjB7
http://ift.tt/2CdrUko
Submitted December 14, 2017 at 12:34AM by cablej
via reddit http://ift.tt/2AiwjB7
lightningsecurity.io
Don't Trust the Host Header for Sending Password Reset Emails
Mirai botnet creators plead guilty to charges over 2016 attack
http://ift.tt/2AUCHzP
Submitted December 14, 2017 at 01:47AM by DJRWolf
via reddit http://ift.tt/2C1yx8y
http://ift.tt/2AUCHzP
Submitted December 14, 2017 at 01:47AM by DJRWolf
via reddit http://ift.tt/2C1yx8y
Engadget
Mirai botnet creators plead guilty to charges over 2016 attack
They face fines and prison time for their roles in creating and using the botnet.
Hiding content from git diff
http://ift.tt/2ynh6Nq
Submitted December 14, 2017 at 01:26AM by reddit_read_today
via reddit http://ift.tt/2zaguOS
http://ift.tt/2ynh6Nq
Submitted December 14, 2017 at 01:26AM by reddit_read_today
via reddit http://ift.tt/2zaguOS
Twistlock
Hiding content from Git + more on escape sequences | TwistlockLabs Experiment | Twistlock
Hiding content from Git + more on escape sequences | TwistlockLabs Experiment from Twistlock. Dev-to-Production Docker and container security for enterprises.
Camp++ 0x7e2 call for papers
http://ift.tt/2CcAIXI
Submitted December 14, 2017 at 01:08AM by dn3t
via reddit http://ift.tt/2AjFBNb
http://ift.tt/2CcAIXI
Submitted December 14, 2017 at 01:08AM by dn3t
via reddit http://ift.tt/2AjFBNb
reddit
Camp++ 0x7e2 call for papers • r/netsec
1 points and 1 comments so far on reddit
attacking encrypted systems with qemu and volatility
http://ift.tt/2ACp8rY
Submitted December 14, 2017 at 03:54AM by virtual_pirate
via reddit http://ift.tt/2Bk8wEN
http://ift.tt/2ACp8rY
Submitted December 14, 2017 at 03:54AM by virtual_pirate
via reddit http://ift.tt/2Bk8wEN
DiabloHorn
attacking encrypted systems with qemu and volatility
Lately I’ve had to deal with setups which had transparent full disk encryption and were pretty hardened. If you are wondering what ‘transparent full disk encryption’ means, that&…
Guide to API Security Testing: The father of SQL injection offers his expert opinion on effective methodologies for security testing APIs.
http://ift.tt/2zafzOt
Submitted December 14, 2017 at 05:17AM by ju1i3k
via reddit http://ift.tt/2j1Z6TH
http://ift.tt/2zafzOt
Submitted December 14, 2017 at 05:17AM by ju1i3k
via reddit http://ift.tt/2j1Z6TH
resource.cobalt.io
Guide to API Security Testing
APIs have unique challenges when it comes to testing. Jeff Forristal offers his expert opinion on effective methodologies for security testing APIs.
AppLocker - How insecure is it really?
http://ift.tt/2CdabJS
Submitted December 13, 2017 at 08:09PM by oddvarmoe
via reddit http://ift.tt/2z9UCDa
http://ift.tt/2CdabJS
Submitted December 13, 2017 at 08:09PM by oddvarmoe
via reddit http://ift.tt/2z9UCDa
Oddvar Moe's Blog
AppLocker – Case study – How insecure is it really? – Part 1
I often hear that AppLocker is not very safe and it is easy to bypass. Since I really like AppLocker and I recommend it to customers, I decided to do this blogpost series and go over the different …
I'm Sorry You Feel This Way NatWest, but HTTPS on Your Landing Page Is Important
http://ift.tt/2BhZ0C1
Submitted December 14, 2017 at 05:59AM by volci
via reddit http://ift.tt/2nZqsyZ
http://ift.tt/2BhZ0C1
Submitted December 14, 2017 at 05:59AM by volci
via reddit http://ift.tt/2nZqsyZ
Troy Hunt
I'm Sorry You Feel This Way NatWest, but HTTPS on Your Landing Page Is Important
Occasionally, I feel like I'm just handing an organisation more shovels - "here, keep digging, I'm sure this'll work out just fine..." The latest such event was with NatWest (a bank in the UK), and it culminated with this tweet from them: I'm sorry you feel
[Discord Server] Information Security Chat
http://ift.tt/2j2NeAU
Submitted December 14, 2017 at 10:42AM by PoliFish
via reddit http://ift.tt/2kqJSrv
http://ift.tt/2j2NeAU
Submitted December 14, 2017 at 10:42AM by PoliFish
via reddit http://ift.tt/2kqJSrv
Discord
Discord - Free voice and text chat for gamers
Step up your game with a modern voice & text chat app. Crystal clear voice, multiple server and channel support, mobile apps, and more. Get your free server now!