rowhammer like attack on SSD
http://ift.tt/2vX5pQw
Submitted August 15, 2017 at 08:02AM by bb111189
via reddit http://ift.tt/2w8GKYT
http://ift.tt/2vX5pQw
Submitted August 15, 2017 at 08:02AM by bb111189
via reddit http://ift.tt/2w8GKYT
CSP Is Dead, Long Live CSP! - On the Insecurity of Whitelists and the Future of Content Security Policy by Lukas Weichselbaum et. al.
http://ift.tt/2w9kii9
Submitted August 15, 2017 at 03:10PM by 0xKaishakunin
via reddit http://ift.tt/2vEJlrn
http://ift.tt/2w9kii9
Submitted August 15, 2017 at 03:10PM by 0xKaishakunin
via reddit http://ift.tt/2vEJlrn
UAC bypass and loading DLL from Webdav - Research on CMSTP.exe binary
http://ift.tt/2uK437U
Submitted August 15, 2017 at 03:08PM by oddvarmoe
via reddit http://ift.tt/2vEJlYp
http://ift.tt/2uK437U
Submitted August 15, 2017 at 03:08PM by oddvarmoe
via reddit http://ift.tt/2vEJlYp
MSitPros Blog
Research on CMSTP.exe
Whenever I have a chance I use my time diving into Windows internal binaries to uncover hidden functionality. This blogpost is dedicated to things I have discovered with the CMSTP.exe binary file. …
Launch – Hello Amazon Macie: Automatically Discover, Classify, and Secure Content at Scale | Amazon Web Services
http://ift.tt/2wXMUrQ
Submitted August 15, 2017 at 05:20PM by lighthouserecipes
via reddit http://ift.tt/2w6yJnU
http://ift.tt/2wXMUrQ
Submitted August 15, 2017 at 05:20PM by lighthouserecipes
via reddit http://ift.tt/2w6yJnU
Amazon Web Services
Launch – Hello Amazon Macie: Automatically Discover, Classify, and Secure Content at Scale | Amazon Web Services
When Jeff and I heard about this service, we both were curious on the meaning of the name Macie. Of course, Jeff being a great researcher looked up the name Macie and found that the name Macie has two meanings. It has both French and English (UK) based origin…
Build a local copy of Security Tracker. Notify via E-mail/Slack if there is an update.
http://ift.tt/2i27yED
Submitted August 15, 2017 at 06:26PM by knqyf263
via reddit http://ift.tt/2fIi2Zk
http://ift.tt/2i27yED
Submitted August 15, 2017 at 06:26PM by knqyf263
via reddit http://ift.tt/2fIi2Zk
GitHub
knqyf263/gost
gost - Build a local copy of Security Tracker. Notify via E-mail/Slack if there is an update.
Finding Cyber Threats with ATT&CK™-Based Analytics
http://ift.tt/2x0X374
Submitted August 15, 2017 at 08:41AM by whatsamanual
via reddit http://ift.tt/2wMhdTc
http://ift.tt/2x0X374
Submitted August 15, 2017 at 08:41AM by whatsamanual
via reddit http://ift.tt/2wMhdTc
Live Windows 95 Bug Hunting
https://www.youtube.com/watch?v=hLGQYi8W5sw
Submitted August 15, 2017 at 04:35AM by badbytesio
via reddit http://ift.tt/2vAdKss
https://www.youtube.com/watch?v=hLGQYi8W5sw
Submitted August 15, 2017 at 04:35AM by badbytesio
via reddit http://ift.tt/2vAdKss
YouTube
Stream Recording: Windows 95 Bug Finding #3 - Crash Analysis
In this episode, we get ollydbg up and running, and take a look at the crash we have. Spoiler alert: unfortunately, at the end of the stream I come to the co...
How someone lost 130K USD from Bittrex Crypto Exchange
http://ift.tt/2wabitd
Submitted August 15, 2017 at 09:06PM by airhack87
via reddit http://ift.tt/2waz7Bd
http://ift.tt/2wabitd
Submitted August 15, 2017 at 09:06PM by airhack87
via reddit http://ift.tt/2waz7Bd
Medium
2FA won’t save you from Phishing — Here’s how
My RSS feeder popped up the below reddit link from the crypto currency subreddit. The poster explains his friend clicked on a phishing…
Password Not Provided - Compromising Any Flurry User's Account [Yahoo Bug Bounty]
http://ift.tt/2vYyfzP
Submitted August 15, 2017 at 09:40PM by cablej
via reddit http://ift.tt/2vAhCJZ
http://ift.tt/2vYyfzP
Submitted August 15, 2017 at 09:40PM by cablej
via reddit http://ift.tt/2vAhCJZ
lightningsecurity.io
Password Not Provided - Compromising Any Flurry User's Account [Yahoo Bug Bounty]
GPD Pocket 7: Impressions, GNU/Linux Installation and Offensive Setup
http://ift.tt/2vAwCr1
Submitted August 16, 2017 at 12:26AM by PaulSec
via reddit http://ift.tt/2uGqkHx
http://ift.tt/2vAwCr1
Submitted August 16, 2017 at 12:26AM by PaulSec
via reddit http://ift.tt/2uGqkHx
evilsocket / Simone
GPD Pocket 7: Impressions, GNU/Linux Installation and Offensive Setup
It’s no secret I’ve been recently playing with the GPD Pocket 7, an ultra small laptop which can run GNU/Linux and has more than decent hardware. Tablets are cool and everything, but I’ve been a fan o
LNKUp: A .lnk file data exfiltration tool
http://ift.tt/2i0hCOt
Submitted August 16, 2017 at 01:50AM by Plazmaz1
via reddit http://ift.tt/2w80Wel
http://ift.tt/2i0hCOt
Submitted August 16, 2017 at 01:50AM by Plazmaz1
via reddit http://ift.tt/2w80Wel
GitHub
Plazmaz/LNKUp
LNKUp - Generates malicious LNK file payloads for data exfiltration
Malware Analysis - Bypassing Initial Infection Vector Anti-Sandbox Technique for URSNIF Banking Trojan
http://ift.tt/2vbY6na
Submitted August 16, 2017 at 02:06AM by majorllama
via reddit http://ift.tt/2uMw12S
http://ift.tt/2vbY6na
Submitted August 16, 2017 at 02:06AM by majorllama
via reddit http://ift.tt/2uMw12S
Ringzerolabs
The Multi Faceted Ursnif Trojan
Malware Analysis - Obfuscated javanoscript downloader for multi-faceted Ursnif Trojan.
MeatPistol - A Modular Malware Implant Framework
http://ift.tt/2uuaewO
Submitted August 16, 2017 at 03:33AM by C0de-Monkey
via reddit http://ift.tt/2w8bU3e
http://ift.tt/2uuaewO
Submitted August 16, 2017 at 03:33AM by C0de-Monkey
via reddit http://ift.tt/2w8bU3e
Exploitations of Uninitialized Uses on macOS Sierra
http://ift.tt/2uNfQCu
Submitted August 16, 2017 at 06:07AM by xorbits
via reddit http://ift.tt/2w8vOv6
http://ift.tt/2uNfQCu
Submitted August 16, 2017 at 06:07AM by xorbits
via reddit http://ift.tt/2w8vOv6
USENIX WOOT 2017 Workshop Program
http://ift.tt/2tD2HxZ
Submitted August 16, 2017 at 08:40AM by dguido
via reddit http://ift.tt/2uHUEBT
http://ift.tt/2tD2HxZ
Submitted August 16, 2017 at 08:40AM by dguido
via reddit http://ift.tt/2uHUEBT
USENIX
WOOT '17 Workshop Program
All sessions will be held in Grand Ballroom AB unless otherwise noted. The workshop papers are available for download below to registered attendees now and to everyone beginning Monday, August 14. Paper abstracts are available to everyone now. Copyright to…
$7 USB Rubber Ducky
http://ift.tt/2v0AKNC
Submitted August 16, 2017 at 10:28AM by EatonChips
via reddit http://ift.tt/2vClBW8
http://ift.tt/2v0AKNC
Submitted August 16, 2017 at 10:28AM by EatonChips
via reddit http://ift.tt/2vClBW8
Medium
Building a USB Rubber Ducky for $7
Lets start off with a stereotypical ‘This is for educational purposes only’, if you use this to pwn HBO and release the next season of GOT…
G-Scout: OSS tool to assess the security of Google Cloud Platform (GCP) environment configurations
http://ift.tt/2wcdFMe
Submitted August 16, 2017 at 10:27AM by digicat
via reddit http://ift.tt/2x2TehV
http://ift.tt/2wcdFMe
Submitted August 16, 2017 at 10:27AM by digicat
via reddit http://ift.tt/2x2TehV
Realmode Assembly - Writing Bootable Stuff - Part 3, Building and Running
http://ift.tt/2ufDJS4
Submitted August 16, 2017 at 03:26PM by Evil1337
via reddit http://ift.tt/2wa0goB
http://ift.tt/2ufDJS4
Submitted August 16, 2017 at 03:26PM by Evil1337
via reddit http://ift.tt/2wa0goB
New DDoS Assault Pattern Identified: Attackers Use DDoS Pulses to Pin Down Multiple Targets
http://ift.tt/2we5vCX
Submitted August 16, 2017 at 04:32PM by whitehattracker
via reddit http://ift.tt/2vIfHBp
http://ift.tt/2we5vCX
Submitted August 16, 2017 at 04:32PM by whitehattracker
via reddit http://ift.tt/2vIfHBp
What was the exploit and how did it benefit only them?
http://ift.tt/2uIxyuM
Submitted August 16, 2017 at 06:42PM by thomasbeck
via reddit http://ift.tt/2uP2xRM
http://ift.tt/2uIxyuM
Submitted August 16, 2017 at 06:42PM by thomasbeck
via reddit http://ift.tt/2uP2xRM
Washington Post
Police: Couple exploited website glitch for free merchandise
Authorities say a New Jersey couple exploited a computer glitch on a home improvement chain’s website to get thousands of dollars’ worth of items shipped to their home for free.
Libsodium Audit Results
http://ift.tt/2x3YkKV
Submitted August 16, 2017 at 07:59PM by privatevpn
via reddit http://ift.tt/2v1VKDv
http://ift.tt/2x3YkKV
Submitted August 16, 2017 at 07:59PM by privatevpn
via reddit http://ift.tt/2v1VKDv
Privacy Online News
Libsodium Audit Results | Privacy Online News
Private Internet Access today releases the results of its Libsodium audit. Libsodium is an open source, cryptographic library that is used far and wide in projects such as Zcash as well as internal applications at Private Internet Access. Private Internet…