Intel left a fascinating security flaw in its chips for 16 years – here's how to exploit it • The Register
http://ift.tt/2qhD3yD
Submitted January 03, 2018 at 04:23PM by Seiryth
via reddit http://ift.tt/2lKf8Dc
http://ift.tt/2qhD3yD
Submitted January 03, 2018 at 04:23PM by Seiryth
via reddit http://ift.tt/2lKf8Dc
www.theregister.co.uk
Intel left a fascinating security flaw in its chips for 16 years – here's how to exploit it
Howler opens door for SMM rootkits
Bancor's HackMe Security Bounty ends in 1 week! Participate now to win ETH & BNT!
http://ift.tt/2ttpeL2
Submitted January 03, 2018 at 05:17PM by BancorAmbassador
via reddit http://ift.tt/2lL9kcM
http://ift.tt/2ttpeL2
Submitted January 03, 2018 at 05:17PM by BancorAmbassador
via reddit http://ift.tt/2lL9kcM
app.demo.bancor.network
Bancor Protocol
Bancor Protocol is a standard for a new generation of cryptocurrencies called Smart Tokens
Web Application Penetration Testing With WFuzz
http://ift.tt/2ELVQ8x
Submitted January 03, 2018 at 06:37PM by berkdusunurx
via reddit http://ift.tt/2Czg48a
http://ift.tt/2ELVQ8x
Submitted January 03, 2018 at 06:37PM by berkdusunurx
via reddit http://ift.tt/2Czg48a
www.berkdusunur.net
Web Application Penetration Testing With WFuzz (Wfuzz İle Web Uygulama Güvenliği Testleri)
What İs WFuzz? WFuzz is a powerful tool for general web security testing where we can perform security tests on web applications, p...
exploit vulnerable windows using metasploit [kali linux] advanced ethical hacking and pen testing
https://youtu.be/A_xhZPnNWpY
Submitted January 03, 2018 at 07:15PM by jasminsmith1
via reddit http://ift.tt/2lNZnKU
https://youtu.be/A_xhZPnNWpY
Submitted January 03, 2018 at 07:15PM by jasminsmith1
via reddit http://ift.tt/2lNZnKU
YouTube
exploit vulnerable windows using metasploit [kali linux] advanced ethical hacking and pen testing
exploit vulnerable windows using metasploit [kali linux] advanced ethical hacking and pen testing This YouTube Video is all about vulnerability and exploit t...
Security In 5: Episode 144 - Top 10 Tips To Secure Your Network - 9 - Define Strong Rules For Admin Accounts
http://ift.tt/2Cy7oyE
Submitted January 03, 2018 at 07:36PM by BinaryBlog
via reddit http://ift.tt/2COKXlN
http://ift.tt/2Cy7oyE
Submitted January 03, 2018 at 07:36PM by BinaryBlog
via reddit http://ift.tt/2COKXlN
Libsyn
Security In Five Podcast: Episode 144 - Top 10 Tips To Secure Your Network - 9 - Define Strong Rules For Admin Accounts
Continuing with mini-series Top 10 Tips to Secure Your Network we are at number nine. Define strong rules for your administrator accounts. These accounts are the keys to the kingdom, full access for your employees to the their jobs easily but also allows…
Office 365 ATP Safe links giving you a hard time? Check out this bypass technique and how to protect
http://ift.tt/2CA4OHQ
Submitted January 03, 2018 at 07:45PM by oddvarmoe
via reddit http://ift.tt/2E1Tb9o
http://ift.tt/2CA4OHQ
Submitted January 03, 2018 at 07:45PM by oddvarmoe
via reddit http://ift.tt/2E1Tb9o
Oddvar Moe's Blog
Office 365 Safe links bypass
Time for a break from the AppLocker case study to blog about this issue, since I found it very interesting. This issue was actually discovered by me and a customer of mine by coincidence. The issue…
9% of Popular Websites Use Anti-Adblock Scripts
http://ift.tt/2A61rmK
Submitted January 03, 2018 at 09:30PM by DJRWolf
via reddit http://ift.tt/2lRPFHB
http://ift.tt/2A61rmK
Submitted January 03, 2018 at 09:30PM by DJRWolf
via reddit http://ift.tt/2lRPFHB
BleepingComputer
9% of Popular Websites Use Anti-Adblock Scripts
Around 9% of today's most popular websites deployed or are deploying anti-adblock noscripts in an effort to maintain advertising revenues and fight off the rise in the adoption of ad-blocking extensions.
2018: Mobile App Security Outlook
http://ift.tt/2EQh7hs
Submitted January 03, 2018 at 10:09PM by Mi3Security
via reddit http://ift.tt/2CC98Hu
http://ift.tt/2EQh7hs
Submitted January 03, 2018 at 10:09PM by Mi3Security
via reddit http://ift.tt/2CC98Hu
Mi3 Security
2018: Mobile App Security Outlook
2017 was an interesting year for mobile app security, including extensive activity around ransomware, cryptocurrencies and mining apps, rootkits and bootkits, and trojans. Beyond mobile we saw numerous breaches including the likes of Gmail, Docusign, Verizon…
www.itwissen.info infects your computer with a JavaScript cryptocurrency miner
I tested it with Google Chrome, Firefox and Internet Explorer. Everytime I opened the website, my Symantec Endpoint Protection encountered a JavaScript cryptocurrency miner in my cache (Image).http://ift.tt/2CkANbq Do not hesitate to test it yourself in a secure environment.This is illegal and definitely not in the interest of the customer/visitor.Your opinions?
Submitted January 03, 2018 at 09:55PM by BlackyGhosty
via reddit http://ift.tt/2AhVRO7
I tested it with Google Chrome, Firefox and Internet Explorer. Everytime I opened the website, my Symantec Endpoint Protection encountered a JavaScript cryptocurrency miner in my cache (Image).http://ift.tt/2CkANbq Do not hesitate to test it yourself in a secure environment.This is illegal and definitely not in the interest of the customer/visitor.Your opinions?
Submitted January 03, 2018 at 09:55PM by BlackyGhosty
via reddit http://ift.tt/2AhVRO7
Imgur
ITwissen.info is infecting!
Imgur: The magic of the Internet
Automating the detection of Mimikatz with ELK
http://ift.tt/2CM6WK2
Submitted January 04, 2018 at 12:04AM by ok_bye_now_
via reddit http://ift.tt/2qjAYlJ
http://ift.tt/2CM6WK2
Submitted January 04, 2018 at 12:04AM by ok_bye_now_
via reddit http://ift.tt/2qjAYlJ
JP
Automating the detection of Mimikatz with ELK
I’ve been going through CyberWarDog’s Threat Hunting posts as of late and stumbled upon his ‘Hunting for In-Memory Mimikatz’ Series. The methods used to build signatures are very straight forward a…
Kernel-memory-leaking Intel processor design flaw forces Linux, Windows redesign
http://ift.tt/2lEEKle
Submitted January 04, 2018 at 12:03AM by RandomCollection
via reddit http://ift.tt/2lP24wp
http://ift.tt/2lEEKle
Submitted January 04, 2018 at 12:03AM by RandomCollection
via reddit http://ift.tt/2lP24wp
www.theregister.co.uk
'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign
Other OSes will need an update, performance hits loom
Intel's CEO Just Sold a Lot of Stock
http://ift.tt/2AiZS4R
Submitted January 04, 2018 at 12:28AM by Jeditobe
via reddit http://ift.tt/2CAdVc7
http://ift.tt/2AiZS4R
Submitted January 04, 2018 at 12:28AM by Jeditobe
via reddit http://ift.tt/2CAdVc7
Evidence suggests Reddit employees use their Reddit database access privileges to engage in tribal attacks and hack users
http://ift.tt/2EItT1s
Submitted January 04, 2018 at 01:19AM by geekmonk
via reddit http://ift.tt/2E1QKnD
http://ift.tt/2EItT1s
Submitted January 04, 2018 at 01:19AM by geekmonk
via reddit http://ift.tt/2E1QKnD
Hacker Noon
Reddit internal security threat: Evidence suggests Reddit employees may use their Reddit database access privileges to engage in…
Several Reddit users active in the r/btc subreddit were hacked in December 2017. Among the victims are a moderator of r/btc (victim 1) and…
Intel Responds to Security Research Findings
http://ift.tt/2CzZjJP
Submitted January 04, 2018 at 01:51AM by jurais
via reddit http://ift.tt/2E0UiGz
http://ift.tt/2CzZjJP
Submitted January 04, 2018 at 01:51AM by jurais
via reddit http://ift.tt/2E0UiGz
Intel Newsroom
Intel Responds to Security Research Findings
Intel Corporation and other technology companies have been made aware of new security research describing software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from computing devices that…
Intel's KPMI vulnerability and virtual machines
From what is known about this vulnerability, does this only apply to hardware-based systems (like hypervisors and bare metal) or is it likely to be emulated through to the guests and require those be patched as well??Edit: I meant KPTI, obviously, but I can't edit the noscript :(
Submitted January 04, 2018 at 01:47AM by clownburner
via reddit http://ift.tt/2Cw3e9V
From what is known about this vulnerability, does this only apply to hardware-based systems (like hypervisors and bare metal) or is it likely to be emulated through to the guests and require those be patched as well??Edit: I meant KPTI, obviously, but I can't edit the noscript :(
Submitted January 04, 2018 at 01:47AM by clownburner
via reddit http://ift.tt/2Cw3e9V
reddit
Intel's KPMI vulnerability and virtual machines • r/security
From what is known about this vulnerability, does this *only* apply to hardware-based systems (like hypervisors and bare metal) or is it likely to...
Intel Responds to security reseach findings
http://ift.tt/2CzZjJP
Submitted January 04, 2018 at 02:49AM by Zratch
via reddit http://ift.tt/2CAsRqF
http://ift.tt/2CzZjJP
Submitted January 04, 2018 at 02:49AM by Zratch
via reddit http://ift.tt/2CAsRqF
Intel Newsroom
Intel Responds to Security Research Findings
Intel Corporation and other technology companies have been made aware of new security research describing software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from computing devices that…
Google Security Blog post on the Intel CPU vulnerability
http://ift.tt/2lOp7aO
Submitted January 04, 2018 at 04:02AM by killall9firefox
via reddit http://ift.tt/2CAffvP
http://ift.tt/2lOp7aO
Submitted January 04, 2018 at 04:02AM by killall9firefox
via reddit http://ift.tt/2CAffvP
Google Online Security Blog
Today's CPU vulnerability: what you need to know
Posted by Matt Linton, Senior Security Engineer and Pat Parseghian, Technical Program Manager Last year, Google’s Project Zero team dis...
Shaf Patel, the blind hacker, forgets to switch accounts while posting fake hate tweet to himself. In the absence of hate crimes, "victims" will manufacture their own to increase their "victim index"(tm).
http://ift.tt/2CzrJUt
Submitted January 04, 2018 at 04:44AM by sfbayVAR
via reddit http://ift.tt/2CPjpgd
http://ift.tt/2CzrJUt
Submitted January 04, 2018 at 04:44AM by sfbayVAR
via reddit http://ift.tt/2CPjpgd
archive.fo
Tweets with replies by Shaf Patel (@ShafPatel) | Twitter
archived 3 Jan 2018 04:12:15 UTC
/r/netsec's Q1 2018 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere.Include the geographic location of the position along with the availability of relocation assistance.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted January 04, 2018 at 04:36AM by ranok
via reddit http://ift.tt/2CkUZu3
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere.Include the geographic location of the position along with the availability of relocation assistance.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted January 04, 2018 at 04:36AM by ranok
via reddit http://ift.tt/2CkUZu3
Reddit
netsec: search results - Information Security Hiring Thread
reddit: the front page of the internet
XSA-254: "Systems running all versions of Xen are affected" by Meltdown/Spectre
http://ift.tt/2CjKgA2
Submitted January 04, 2018 at 04:29AM by lachryma
via reddit http://ift.tt/2CAjYgR
http://ift.tt/2CjKgA2
Submitted January 04, 2018 at 04:29AM by lachryma
via reddit http://ift.tt/2CAjYgR
reddit
XSA-254: "Systems running all versions of Xen are... • r/netsec
7 points and 4 comments so far on reddit
Meltdown and Spectre (CPU bugs)
http://ift.tt/2EOJNax
Submitted January 04, 2018 at 03:55AM by ranok
via reddit http://ift.tt/2E3Uvc5
http://ift.tt/2EOJNax
Submitted January 04, 2018 at 03:55AM by ranok
via reddit http://ift.tt/2E3Uvc5
reddit
Meltdown and Spectre (CPU bugs) • r/netsec
39 points and 13 comments so far on reddit