Dumb - a fast and flexible domain bruteforcer
http://ift.tt/2t6AG3i
Submitted February 27, 2018 at 03:20AM by giovanifss
via reddit http://ift.tt/2owcCSL
http://ift.tt/2t6AG3i
Submitted February 27, 2018 at 03:20AM by giovanifss
via reddit http://ift.tt/2owcCSL
GitHub
giovanifss/Dumb
Dumb - Dumain Bruteforcer - a fast and flexible domain bruteforcer
An Analysis of the Privacy and Security Risks of Android VPN Permission-enabled Apps [PDF Paper]
http://ift.tt/2ktJOK7
Submitted February 28, 2018 at 09:39AM by PeterG45
via reddit http://ift.tt/2EZV3kc
http://ift.tt/2ktJOK7
Submitted February 28, 2018 at 09:39AM by PeterG45
via reddit http://ift.tt/2EZV3kc
IoT hack: how to break a smart home…again
http://ift.tt/2GMQES0
Submitted February 28, 2018 at 06:09PM by ga-vu
via reddit http://ift.tt/2CP1k01
http://ift.tt/2GMQES0
Submitted February 28, 2018 at 06:09PM by ga-vu
via reddit http://ift.tt/2CP1k01
Securelist - Kaspersky Lab’s cyberthreat research and reports
IoT hack: how to break a smart home…again
This time, we’ve chosen a smart hub designed to control sensors and devices installed at home. It can be used for different purposes, such as energy and water management, monitoring and even security systems.
CVE-2018-4087 PoC: Escaping the iOS sandbox by misleading bluetoothd
http://ift.tt/2GR1GG1
Submitted February 28, 2018 at 06:37PM by IamNullByte
via reddit http://ift.tt/2t6oEHg
http://ift.tt/2GR1GG1
Submitted February 28, 2018 at 06:37PM by IamNullByte
via reddit http://ift.tt/2t6oEHg
Zimperium Mobile Security Blog
CVE-2018-4087 PoC: Escaping the sandbox by misleading bluetoothd - Zimperium Mobile Security Blog
Following my previous blog post noscriptd “New Crucial Vulnerabilities in Apple’s bluetoothd daemon”, I am releasing the vulnerability PoC. The PoC is released for educational purposes and evaluation by IT Administrators and Pentesters alike, and should not…
Security In 5: Episode 184 - Should We Create A National Cybersecurity Safety Board?
http://ift.tt/2CsvOta
Submitted February 28, 2018 at 07:37PM by BinaryBlog
via reddit http://ift.tt/2GQHios
http://ift.tt/2CsvOta
Submitted February 28, 2018 at 07:37PM by BinaryBlog
via reddit http://ift.tt/2GQHios
Libsyn
Security In Five Podcast: Episode 184 - Should We Create A National Cybersecurity Safety Board?
Is it time to create a National Cybersecurity Safety Board similar to the NTSB? This episode goes into the idea of this for post-breach investigations and recommendations after the fact. Be aware, be safe. ------------------------------------ Website …
Free Decrypter Available for GandCrab Ransomware Victims
http://ift.tt/2ow12qu
Submitted February 28, 2018 at 09:09PM by alessiodelv
via reddit http://ift.tt/2F13Bak
http://ift.tt/2ow12qu
Submitted February 28, 2018 at 09:09PM by alessiodelv
via reddit http://ift.tt/2F13Bak
BleepingComputer
Free Decrypter Available for GandCrab Ransomware Victims
Bitdefender has released a free decrypter that helps victims of GandCrab ransomware infections recover files without paying the ransom.
2,844 New Data Breaches in Have I Been Pwned
http://ift.tt/2taaFQL
Submitted February 28, 2018 at 08:51PM by alessiodelv
via reddit http://ift.tt/2FddwNp
http://ift.tt/2taaFQL
Submitted February 28, 2018 at 08:51PM by alessiodelv
via reddit http://ift.tt/2FddwNp
Pastebin
2,844 New Data Breaches in Have I Been Pwned - Pastebin.com
New RIG malvertising campaign uses cryptocurrency theme as decoy
http://ift.tt/2FDufHo
Submitted February 28, 2018 at 10:52PM by EvanConover
via reddit http://ift.tt/2EZ04gH
http://ift.tt/2FDufHo
Submitted February 28, 2018 at 10:52PM by EvanConover
via reddit http://ift.tt/2EZ04gH
Malwarebytes Labs
New RIG malvertising campaign uses cryptocurrency theme as decoy - Malwarebytes Labs
This malvertising campaign uses a popular cryptocurrency theme to redirect users to the RIG exploit kit.
Third party CSS is not safe
http://ift.tt/2EXG4as
Submitted February 28, 2018 at 11:18PM by speckz
via reddit http://ift.tt/2FbtZSh
http://ift.tt/2EXG4as
Submitted February 28, 2018 at 11:18PM by speckz
via reddit http://ift.tt/2FbtZSh
Jakearchibald
Third party CSS is not safe
A few days ago there was a lot of chatter about a 'keylogger' built in CSS, but the real problem is thinking that third party content is 'safe'.
http://ift.tt/2t4BaqA
http://ift.tt/2t4BaqA
Submitted February 28, 2018 at 10:54PM by home8ireland
via reddit http://ift.tt/2owdZ3x
http://ift.tt/2t4BaqA
Submitted February 28, 2018 at 10:54PM by home8ireland
via reddit http://ift.tt/2owdZ3x
Home8
Home Security Systems Ireland | Protection Systems - Video-Verified Security Alarms
Home8Security is the leading Irish Home Security and Safety System provider company, offer home protection by image authentication and Video alarm verification
SecOps Hub, an agnostic community for security professionals
http://ift.tt/2BVnYXR
Submitted February 28, 2018 at 11:16PM by SecOpsHub
via reddit http://ift.tt/2oFfqMj
http://ift.tt/2BVnYXR
Submitted February 28, 2018 at 11:16PM by SecOpsHub
via reddit http://ift.tt/2oFfqMj
SecOps Hub
SecOps Hub is a one-stop shop for security professionals to discuss strategies, incident response best practices, and ways to simplify it all through automation.
Trustico compromised 20,000 certificate private keys.
http://ift.tt/2Fe9GDQ
Submitted March 01, 2018 at 12:26AM by Kofeb
via reddit http://ift.tt/2F2uM4G
http://ift.tt/2Fe9GDQ
Submitted March 01, 2018 at 12:26AM by Kofeb
via reddit http://ift.tt/2F2uM4G
DigiCert
DigiCert Statement on Trustico Certificate Revocation - DigiCert
Today, DigiCert issued the following statement regarding Trustico certificate revocation: “Trustico requested revocation of their Symantec, GeoTrust, Thawte and RapidSSL certificates, claiming the certificates were compromised. When we asked for proof of…
KeePassXC 2.3.0 released
http://ift.tt/2GPIys3
Submitted February 28, 2018 at 11:58PM by pheedrus
via reddit http://ift.tt/2F01SSB
http://ift.tt/2GPIys3
Submitted February 28, 2018 at 11:58PM by pheedrus
via reddit http://ift.tt/2F01SSB
reddit
KeePassXC 2.3.0 released • r/netsec
1 points and 0 comments so far on reddit
How to implement "security.txt" to advocate responsible disclosures?
http://ift.tt/2owNnQe
Submitted March 01, 2018 at 12:21AM by xrna
via reddit http://ift.tt/2t4t3u4
http://ift.tt/2owNnQe
Submitted March 01, 2018 at 12:21AM by xrna
via reddit http://ift.tt/2t4t3u4
Cyber Sins
How to implement "security.txt" to advocate responsible disclosures?
After discussing CAA record in DNS to whitelist your certificate authorities in my previous article, do you know it's a matter of time that someone finds an issue with your web-presence, website or any front-facing application? If they do, what do you expect…
Duo Security has identified a security flaw in a third-party library used in the Duo Network Gateway which, under certain configurations, could allow for a bypass of the DNG's SAML first factor of authentication.
http://ift.tt/2F05EzH
Submitted March 01, 2018 at 12:48AM by EvanConover
via reddit http://ift.tt/2COF7iw
http://ift.tt/2F05EzH
Submitted March 01, 2018 at 12:48AM by EvanConover
via reddit http://ift.tt/2COF7iw
Duo Security
DUO-PSA-2017-003: Duo Product Security Advisory
How to Fight Mobile Number Port-out Scams
http://ift.tt/2FDviXX
Submitted March 01, 2018 at 02:28AM by volci
via reddit http://ift.tt/2oCkUIT
http://ift.tt/2FDviXX
Submitted March 01, 2018 at 02:28AM by volci
via reddit http://ift.tt/2oCkUIT
reddit
How to Fight Mobile Number Port-out Scams • r/security
3 points and 0 comments so far on reddit
Cheat engine priviliges
If every process has its own protected memory, how cheat engine read memory of other processes
Submitted March 01, 2018 at 02:58AM by Hadyelzayady
via reddit http://ift.tt/2t3SXOK
If every process has its own protected memory, how cheat engine read memory of other processes
Submitted March 01, 2018 at 02:58AM by Hadyelzayady
via reddit http://ift.tt/2t3SXOK
reddit
Cheat engine priviliges • r/security
If every process has its own protected memory, how cheat engine read memory of other processes
Industrial Control Systems Joint Working Group (ICSJWG) 2018 Spring Meeting: Albuquerque, NM | 10-12 April - Call for Abstracts
http://ift.tt/2lmRxHn
Submitted March 01, 2018 at 02:43AM by volci
via reddit http://ift.tt/2F0raA1
http://ift.tt/2lmRxHn
Submitted March 01, 2018 at 02:43AM by volci
via reddit http://ift.tt/2F0raA1
ics-cert.us-cert.gov
Industrial Control Systems Joint Working Group (ICSJWG) | ICS-CERT
The Department of Homeland Security (DHS) Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) established the Industrial Control Systems Joint Working Group (ICSJWG) to facilitate information sharing and reduce the risk to the nation’s industrial…
Risk Misconceptions in Social Engineering Testing
http://ift.tt/2CPdfLe
Submitted March 01, 2018 at 03:16AM by hackers_and_builders
via reddit http://ift.tt/2F1HJzQ
http://ift.tt/2CPdfLe
Submitted March 01, 2018 at 03:16AM by hackers_and_builders
via reddit http://ift.tt/2F1HJzQ
Rhino Security Labs
Risk Misconceptions in Social Engineering Testing - Rhino Security Labs
When considering social engineering, technical controls and understanding the potential impact of attacks are essential to a strong defense.
DigiCert Statement on Trustico Certificate Revocation
http://ift.tt/2Fe9GDQ
Submitted March 01, 2018 at 07:53AM by sifex
via reddit http://ift.tt/2oHFq9V
http://ift.tt/2Fe9GDQ
Submitted March 01, 2018 at 07:53AM by sifex
via reddit http://ift.tt/2oHFq9V
DigiCert
DigiCert Statement on Trustico Certificate Revocation - DigiCert
Today, DigiCert issued the following statement regarding Trustico certificate revocation: “Trustico requested revocation of their Symantec, GeoTrust, Thawte and RapidSSL certificates, claiming the certificates were compromised. When we asked for proof of…
antMan <= 0.9.0c Authentication Bypass
http://ift.tt/2ox6HfV
Submitted March 01, 2018 at 07:04AM by Bowserjklol
via reddit http://ift.tt/2GTaTxg
http://ift.tt/2ox6HfV
Submitted March 01, 2018 at 07:04AM by Bowserjklol
via reddit http://ift.tt/2GTaTxg
Codecatoctin
antMan Authentication Bypass
Issue Summary antMan versions <= 0.9.0c contain a critical authentication defect, allowing an unauthenticated attacker to obtain root...