Password Compliance (PCI, HIPAA, FDA, SOC2, NIST)
http://ift.tt/2xy7IY4
Submitted August 30, 2017 at 10:41PM by kstra
via reddit http://ift.tt/2vFF4mw
http://ift.tt/2xy7IY4
Submitted August 30, 2017 at 10:41PM by kstra
via reddit http://ift.tt/2vFF4mw
Inversoft
Password Security Compliance Checklist | Inversoft
Use this Password Security Compliance Checklist as a tool to strengthen your existing password policy and ensure compliance.
Learn ROP through a short series of practical challenges
http://ift.tt/2x5KdYI
Submitted August 31, 2017 at 12:42AM by CptGibbon
via reddit http://ift.tt/2xNeVD4
http://ift.tt/2x5KdYI
Submitted August 31, 2017 at 12:42AM by CptGibbon
via reddit http://ift.tt/2xNeVD4
Ropemporium
ROP Emporium
Learn ROP
New IoT Device Vulnerability "ConnManDo"
http://ift.tt/2vCTowj
Submitted August 31, 2017 at 03:39AM by cybersecurityGS
via reddit http://ift.tt/2wTEcPz
http://ift.tt/2vCTowj
Submitted August 31, 2017 at 03:39AM by cybersecurityGS
via reddit http://ift.tt/2wTEcPz
Nri-Secure
New IoT Device Vulnerability "ConnManDo"
We found a stack buffer overflow vulnerability which can cause crash in the DNS-proxy feature of ConnMan. In some cases, this vulnerability can cause arbitrary code execution as exec user privilege of ConnMan. We have confirmed the reproducibility of this…
Critical Pacemaker Vulnerability Revealed - Millions of Lives at Risk
http://ift.tt/2vLcM9A
Submitted August 31, 2017 at 05:50AM by greenterminal
via reddit http://ift.tt/2xzkWUE
http://ift.tt/2vLcM9A
Submitted August 31, 2017 at 05:50AM by greenterminal
via reddit http://ift.tt/2xzkWUE
Hackers Grid
Critical Pacemaker Vulnerability Revealed - Millions of Lives at Risk - Hackers Grid
Critical pacemaker vulnerability allows hackers to hack into Abbott's pacemakers using RF waves and fully take control over the running device.
Hacking things by touching them: A guide to physical security
http://ift.tt/2vtGHDF
Submitted August 31, 2017 at 06:16AM by knoy
via reddit http://ift.tt/2wprbdC
http://ift.tt/2vtGHDF
Submitted August 31, 2017 at 06:16AM by knoy
via reddit http://ift.tt/2wprbdC
EXCLUSIVE: The FCC.gov Website Lets You Upload Malware Using Its Own API Key
http://ift.tt/2gqJOK2
Submitted August 31, 2017 at 08:01AM by Smokebits
via reddit http://ift.tt/2x74gWT
http://ift.tt/2gqJOK2
Submitted August 31, 2017 at 08:01AM by Smokebits
via reddit http://ift.tt/2x74gWT
Medium
The FCC.gov Website Lets You Upload Malware Using Its Own Public API Key
Somewhat incredibly I am the first tech writer on the planet to break this story, but even more incredibly the FCC lets you upload any file…
SharknAT&To - vulnerabilities in Arris routers
http://ift.tt/2wpIfQl
Submitted August 31, 2017 at 01:07PM by campuscodi
via reddit http://ift.tt/2vHv38l
http://ift.tt/2wpIfQl
Submitted August 31, 2017 at 01:07PM by campuscodi
via reddit http://ift.tt/2vHv38l
Nomotion Blog
SharknAT&To - Nomotion Blog
Introduction When evidence of the problems described in this report were first noticed, it almost seemed hard to believe. However, for those familiar with the technical history of Arris and their careless lingering of hardcoded accounts on their products…
Exploiting CVE-2016-10277 for untethered root on Moto devices (USENIX WOOT '17)
http://ift.tt/2x7GgTx
Submitted August 31, 2017 at 01:53PM by dv80
via reddit http://ift.tt/2wUX7t8
http://ift.tt/2x7GgTx
Submitted August 31, 2017 at 01:53PM by dv80
via reddit http://ift.tt/2wUX7t8
alephsecurity.github.io
Untethered initroot (USENIX WOOT '17)
Exploiting CVE-2016-10277 for untethered jailbreak on Moto devices (and more!)
Spambot : 711 million targeted by Ursnif, a really vicious malware mails
http://ift.tt/2wpTbhe
Submitted August 31, 2017 at 03:02PM by vibedzer
via reddit http://ift.tt/2vusGty
http://ift.tt/2wpTbhe
Submitted August 31, 2017 at 03:02PM by vibedzer
via reddit http://ift.tt/2vusGty
Xtreme TechTips
Spambot : 711 million targeted by Ursnif, a really vicious malware mails
A major threat on the web, since it would have already hacked nearly 711 million of email addresses and probably infected at least a hund...
Instagram Suffered Data Breach Of High Profiles Verified Users Contact Information
http://ift.tt/2glj6yT
Submitted August 31, 2017 at 03:40PM by abhihpes
via reddit http://ift.tt/2xOWnlK
http://ift.tt/2glj6yT
Submitted August 31, 2017 at 03:40PM by abhihpes
via reddit http://ift.tt/2xOWnlK
www.techposts.net
Instagram Suffered Data Breach, Hacker Gained High-Profiles Contact Information |
Instagram has revealed that it has suffered from serious data breach and the hacker has gained access to the contact information of the verified users
[crypto] Visual demonstration of why two-time pads are bad
http://ift.tt/2gldi8i
Submitted August 31, 2017 at 03:26PM by k3170makan
via reddit http://ift.tt/2x8BTr1
http://ift.tt/2gldi8i
Submitted August 31, 2017 at 03:26PM by k3170makan
via reddit http://ift.tt/2x8BTr1
Gist
Simple visual demonstration of the affect of key entropy and key re-use on a simple one time bad
Reverse Engineering the OBi200 Google Voice Appliance: Part 1
http://ift.tt/2eHjnfi
Submitted August 31, 2017 at 06:35PM by rwestergren
via reddit http://ift.tt/2gskzHi
http://ift.tt/2eHjnfi
Submitted August 31, 2017 at 06:35PM by rwestergren
via reddit http://ift.tt/2gskzHi
Randy Westergren
Reverse Engineering the OBi200 Google Voice Appliance: Part 1 - Randy Westergren
The OBi200 by Obihai is a VoIP gateway for home/SOHO that integrates with Google Voice. It supports most standard VoIP features out of the box and can integrate with virtually any “bring your own device” SIP service. I purchased one earlier this year to act…
CertReq Exfiltration – Getting Data via Native Tools & CSRs!
http://ift.tt/2eseb27
Submitted August 31, 2017 at 07:04PM by doylersec
via reddit http://ift.tt/2vMoikY
http://ift.tt/2eseb27
Submitted August 31, 2017 at 07:04PM by doylersec
via reddit http://ift.tt/2vMoikY
doyler.net
CertReq Exfiltration - Getting Data via Native Tools & CSRs! | doyler.net
Now, finally sharing something new again, I present CertReq exfiltration! The Spark It all started one Thursday that I was on the bench with an innocuous looking tweet from subTee. He mentioned that it seemed like certreq.exe could arbitrarily POST … Continue…
A look at the shortfalls of SIEM and how EDR can pick up the slack.
http://ift.tt/2vLXz81
Submitted August 31, 2017 at 06:49PM by Leeor18
via reddit http://ift.tt/2x9gDSd
http://ift.tt/2vLXz81
Submitted August 31, 2017 at 06:49PM by Leeor18
via reddit http://ift.tt/2x9gDSd
Secdo
Is EDR picking up SIEM’s slack?
As headlines about breaches increase, it becomes clear that the current IR capabilities of SIEM providers are not meeting the needs of today’s security teams
WINspect - Powershell-based Windows Security Auditing Toolbox
http://ift.tt/2vIuzPf
Submitted August 31, 2017 at 07:59PM by hack4net
via reddit http://ift.tt/2glt4jU
http://ift.tt/2vIuzPf
Submitted August 31, 2017 at 07:59PM by hack4net
via reddit http://ift.tt/2glt4jU
Hack4Net ☠
WINspect - Powershell-based Windows Security Auditing Toolbox
WINspect is part of a larger project for auditing different areas of Windows environments. It focuses on enumerating different parts of a...
Anyone was able to host arbitrary files to the FCC.gov domain
http://ift.tt/2gliLfz
Submitted August 31, 2017 at 07:39PM by xorflame
via reddit http://ift.tt/2vuyrro
http://ift.tt/2gliLfz
Submitted August 31, 2017 at 07:39PM by xorflame
via reddit http://ift.tt/2vuyrro
Hacker Noon
The FCC.gov Website Lets You Upload Malware Using Its Own Public API Key
Somewhat incredibly I am the first tech writer on the planet to break this story, but even more incredibly the FCC lets you upload any file…
Analysis of a recent Poison Ivy sample
http://ift.tt/2vHORsj
Submitted August 31, 2017 at 09:01PM by rexrage
via reddit http://ift.tt/2glv23s
http://ift.tt/2vHORsj
Submitted August 31, 2017 at 09:01PM by rexrage
via reddit http://ift.tt/2glv23s
Writeup of RHME3 exploitation challenge (use-after-free vulnerability)
http://ift.tt/2wkV5Be
Submitted August 31, 2017 at 08:13PM by _gipi_
via reddit http://ift.tt/2xB7WxU
http://ift.tt/2wkV5Be
Submitted August 31, 2017 at 08:13PM by _gipi_
via reddit http://ift.tt/2xB7WxU
AngelFire - CIA Implant For Windows Machines
http://ift.tt/2elV0U1
Submitted August 31, 2017 at 10:04PM by greenterminal
via reddit http://ift.tt/2wldxtu
http://ift.tt/2elV0U1
Submitted August 31, 2017 at 10:04PM by greenterminal
via reddit http://ift.tt/2wldxtu
Hackers Grid
AngelFire – CIA Implant For Windows Machines
Vault 7 is a series of documents and tools released by WikiLeaks, that gives information about detailed activities and capabilities of the US CIA to perform spying and cyber warfare. Today, 31 August 2017, Wikileaks
ROPEMAKER: Stop Trying to Make it Happen; ROPEMAKER is Not Going to Happen
http://ift.tt/2wVKRZC
Submitted September 01, 2017 at 03:06AM by xor_al_al
via reddit http://ift.tt/2vNfoDU
http://ift.tt/2wVKRZC
Submitted September 01, 2017 at 03:06AM by xor_al_al
via reddit http://ift.tt/2vNfoDU
Fuzzing x86 instruction set
https://youtu.be/KrksBdWcZgQ
Submitted September 01, 2017 at 07:22AM by fproulx
via reddit http://ift.tt/2wmM36B
https://youtu.be/KrksBdWcZgQ
Submitted September 01, 2017 at 07:22AM by fproulx
via reddit http://ift.tt/2wmM36B
YouTube
Breaking the x86 Instruction Set
A processor is not a trusted black box for running code; on the contrary, modern x86 chips are packed full of secret instructions and hardware bugs. In this talk, we'll demonstrate how page fault analysis and some creative processor fuzzing can be used to…