Intel's Meltdown And Spectre Security Updates Will Hit 90% Of Its Processors By Next Week
http://ift.tt/2lZLWHI
Submitted January 05, 2018 at 07:33PM by DJRWolf
via reddit http://ift.tt/2CVWJL6
http://ift.tt/2lZLWHI
Submitted January 05, 2018 at 07:33PM by DJRWolf
via reddit http://ift.tt/2CVWJL6
HotHardware
Intel's Meltdown And Spectre Security Updates Will Hit 90% Of Its Processors By Next Week | HotHardware
The tech industry is still trying to recover from the fallout surrounding the Meltdown and Spectre vulnerabilities that were disclosed this week. Intel, AMD, Apple, Microsoft, ARM, and other key players in the hardware and software arena have been working…
Spectre-on-Kubernetes, a proof of concept
http://ift.tt/2CL8KX9
Submitted January 05, 2018 at 09:22PM by speckz
via reddit http://ift.tt/2m0ektB
http://ift.tt/2CL8KX9
Submitted January 05, 2018 at 09:22PM by speckz
via reddit http://ift.tt/2m0ektB
Hacker Noon
Spectre-on-Kubernetes, a proof of concept
TL;DR: a PoC demonstrating Spectre, the nasty CPU bug, running on Kubernetes.
Documenting system/app settings
At work I was tasked with documenting the decision made for settings for "widget" software. That way in 2-5 years when some asks "Why did we use this setting vs others?" we have something to support the decision.Ive tried hitting google and Im having difficulty finding resources that are helpful.What do you call this practice? what are phrases I could search? What resources do you have?
Submitted January 05, 2018 at 09:21PM by gnomeparadox
via reddit http://ift.tt/2CL8PcF
At work I was tasked with documenting the decision made for settings for "widget" software. That way in 2-5 years when some asks "Why did we use this setting vs others?" we have something to support the decision.Ive tried hitting google and Im having difficulty finding resources that are helpful.What do you call this practice? what are phrases I could search? What resources do you have?
Submitted January 05, 2018 at 09:21PM by gnomeparadox
via reddit http://ift.tt/2CL8PcF
reddit
Documenting system/app settings • r/security
At work I was tasked with documenting the decision made for settings for "widget" software. That way in 2-5 years when some asks "Why did we use...
“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
http://archive.is/XO6Fz
Submitted January 05, 2018 at 07:18PM by w122
via reddit http://ift.tt/2Eamt69
http://archive.is/XO6Fz
Submitted January 05, 2018 at 07:18PM by w122
via reddit http://ift.tt/2Eamt69
archive.is
'Intel Core 2' - MARC
archived 4 Jan 2018 15:10:45 UTC
How Kaspersky’s Software Fell Under Suspicion of Spying on America
http://ift.tt/2m0mMK3
Submitted January 05, 2018 at 11:13PM by SuccessfulOperation
via reddit http://ift.tt/2CXmHOs
http://ift.tt/2m0mMK3
Submitted January 05, 2018 at 11:13PM by SuccessfulOperation
via reddit http://ift.tt/2CXmHOs
WSJ
How Kaspersky’s Software Fell Under Suspicion of Spying on America
U.S. officials haven’t offered conclusive evidence that antivirus products made by Kaspersky Lab were behind national-security breaches, but a series of incidents drove them to raise alarms about the Russian security-software company.
[eBook] Cybersecurity for Dummies
http://ift.tt/2F48boO
Submitted January 05, 2018 at 10:43PM by DiceIT
via reddit http://ift.tt/2CuD1Fw
http://ift.tt/2F48boO
Submitted January 05, 2018 at 10:43PM by DiceIT
via reddit http://ift.tt/2CuD1Fw
YourDailyTech
[eBook] Cybersecurity for Dummies | YourDailyTech
Cybersecurity For Dummies, Thycotic Special Edition, helps you understand and recognize the most common cybersecurity threats people face daily in their personal and work lives. With that understanding, you can then begin to adopt good cyber hygiene that…
A new malicious miner that works over Secure Shell (SSH)
http://ift.tt/2CWV7AM
Submitted January 05, 2018 at 11:43PM by momfat
via reddit http://ift.tt/2CwrSnw
http://ift.tt/2CWV7AM
Submitted January 05, 2018 at 11:43PM by momfat
via reddit http://ift.tt/2CwrSnw
Segurança Informática | seguranca-informatica.pt
Crypto-jacking again identified in Monero cryptocurrency - Segurança Informática | seguranca-informatica.pt
Again crypto-jacking on Monero. PyCryptoMiner is a botnet cryptocurrency-oriented, designed in Python, that uses Pastebin as the source-pool when the C&C server is unavailable. It attacks Linux machines and exploits SSH service via brute-force.
very vulnerable ARM application
http://ift.tt/2lIFo13
Submitted January 06, 2018 at 12:46AM by fireh7nter
via reddit http://ift.tt/2CUvaBT
http://ift.tt/2lIFo13
Submitted January 06, 2018 at 12:46AM by fireh7nter
via reddit http://ift.tt/2CUvaBT
GitHub
bkerler/exploit_me
exploit_me - Very vulnerable ARM application (CTF style exploitation tutorial)
Why Raspberry Pi isn't vulnerable to Spectre or Meltdown
http://ift.tt/2Cv5ACE
Submitted January 06, 2018 at 12:36AM by Chris911
via reddit http://ift.tt/2qvs3Oh
http://ift.tt/2Cv5ACE
Submitted January 06, 2018 at 12:36AM by Chris911
via reddit http://ift.tt/2qvs3Oh
Raspberry Pi
Why Raspberry Pi isn't vulnerable to Spectre or Meltdown - Raspberry Pi
Eben gives you a crash course in how modern processors work to explain why Raspberry Pi is unaffected by the Spectre and Meltdown security vulnerabilities.
Microsoft could soon be “password free”
http://ift.tt/2CsE7RV
Submitted January 06, 2018 at 01:18AM by volci
via reddit http://ift.tt/2Ctt4YH
http://ift.tt/2CsE7RV
Submitted January 06, 2018 at 01:18AM by volci
via reddit http://ift.tt/2Ctt4YH
Naked Security
Microsoft could soon be “password free”
Is it the beginning of the end for passwords?
gitMask - Develop Anonymously
http://ift.tt/2E6jtr4
Submitted January 06, 2018 at 02:16AM by pheedrus
via reddit http://ift.tt/2qvLOVX
http://ift.tt/2E6jtr4
Submitted January 06, 2018 at 02:16AM by pheedrus
via reddit http://ift.tt/2qvLOVX
reddit
gitMask - Develop Anonymously • r/netsec
1 points and 0 comments so far on reddit
Set of tricks to solving vulnerable machines
http://ift.tt/2CH1lXU
Submitted January 06, 2018 at 02:42AM by 0xc0ffeed00d
via reddit http://ift.tt/2CXyPik
http://ift.tt/2CH1lXU
Submitted January 06, 2018 at 02:42AM by 0xc0ffeed00d
via reddit http://ift.tt/2CXyPik
Explaining IDOR in (almost) real life scenario in Bug Bounty program.
http://ift.tt/2CNR2lO
Submitted January 06, 2018 at 02:40AM by Mysterii8
via reddit http://ift.tt/2CXyRqs
http://ift.tt/2CNR2lO
Submitted January 06, 2018 at 02:40AM by Mysterii8
via reddit http://ift.tt/2CXyRqs
Medium
Explaining IDOR in (almost) real life scenario in Bug Bounty program.
Important
Meltdown and Spectre and DragonFly
http://ift.tt/2qy8epL
Submitted January 06, 2018 at 01:51AM by rhabarba
via reddit http://ift.tt/2lXR3Iu
http://ift.tt/2qy8epL
Submitted January 06, 2018 at 01:51AM by rhabarba
via reddit http://ift.tt/2lXR3Iu
reddit
Meltdown and Spectre and DragonFly • r/security
1 points and 0 comments so far on reddit
Explaining IDOR in (almost) real life scenario in Bug Bounty program.
http://ift.tt/2CNR2lO
Submitted January 06, 2018 at 02:41AM by Mysterii8
via reddit http://ift.tt/2CL5pqk
http://ift.tt/2CNR2lO
Submitted January 06, 2018 at 02:41AM by Mysterii8
via reddit http://ift.tt/2CL5pqk
Medium
Explaining IDOR in (almost) real life scenario in Bug Bounty program.
Important
AMD-PSP: fTPM Remote Code Execution via crafted EK certificate
http://ift.tt/2F3BRCe
Submitted January 06, 2018 at 02:52AM by igor_sk
via reddit http://ift.tt/2CL8mqy
http://ift.tt/2F3BRCe
Submitted January 06, 2018 at 02:52AM by igor_sk
via reddit http://ift.tt/2CL8mqy
seclists.org
Full Disclosure: AMD-PSP: fTPM Remote Code Execution via crafted EK certificate
Zero-day vulnerabilities hijack full Dell EMC Data Protection Suite
http://ift.tt/2CJaCiZ
Submitted January 06, 2018 at 03:14AM by imr2017
via reddit http://ift.tt/2COe7EP
http://ift.tt/2CJaCiZ
Submitted January 06, 2018 at 03:14AM by imr2017
via reddit http://ift.tt/2COe7EP
ZDNet
Zero-day vulnerabilities hijack full Dell EMC Data Protection Suite
Researchers have discovered severe vulnerabilities in the suite which can lead to full system takeover.
RSA and ECDSA hybrid Nginx setup with LetsEncrypt certificates generated through Docker image using acme.sh and certbot clients
http://ift.tt/2CYDT6l
Submitted January 06, 2018 at 03:44AM by alsam88
via reddit http://ift.tt/2CKDp6S
http://ift.tt/2CYDT6l
Submitted January 06, 2018 at 03:44AM by alsam88
via reddit http://ift.tt/2CKDp6S
Medium
RSA and ECDSA hybrid Nginx setup with LetsEncrypt certificates generated via acme.sh and certbot clients wrapped in Docker image
RSA vs ECC comparison. Issuing LetsEncrypt certificates using certbot and acme.sh clients wrapped in Docker image. Nginx setup
Generate, renew, revoke RSA and/or ECDSA SSL certificates from LetsEncrypt CA using certbot and acme.sh clients through docker image
http://ift.tt/2AywOX7
Submitted January 06, 2018 at 03:38AM by alsam88
via reddit http://ift.tt/2AyvqUj
http://ift.tt/2AywOX7
Submitted January 06, 2018 at 03:38AM by alsam88
via reddit http://ift.tt/2AyvqUj
GitHub
samoshkin/docker-letsencrypt-certgen
docker-letsencrypt-certgen - Docker image to generate, renew, revoke RSA and/or ECDSA SSL certificates from LetsEncrypt CA using certbot and acme.sh clients in automated fashion
"Meltdown" hardware exploit : technical details.
http://ift.tt/2lS6LFO
Submitted January 06, 2018 at 06:16AM by vwibrasivat
via reddit http://ift.tt/2F4CQCk
http://ift.tt/2lS6LFO
Submitted January 06, 2018 at 06:16AM by vwibrasivat
via reddit http://ift.tt/2F4CQCk
blog.cyberus-technology.de
Cyberus Technology Blog - Meltdown
Cyberus Technology GmbH Tech-Blog
Mailgun security incident: An update on the state of password resets
http://ift.tt/2m0EL1U
Submitted January 06, 2018 at 06:54AM by philipwhiuk
via reddit http://ift.tt/2qzE3ys
http://ift.tt/2m0EL1U
Submitted January 06, 2018 at 06:54AM by philipwhiuk
via reddit http://ift.tt/2qzE3ys
reddit
Mailgun security incident: An update on the state of... • r/bugs
On 12/31, Reddit received several reports regarding password reset emails that were initiated and completed without the account owners’...