Deep dive on the most severe Kubernetes vulnerabilities to date - CVE-2017-1002101 and CVE-2017-1002102
http://ift.tt/2IJnqoZ
Submitted March 23, 2018 at 02:27PM by Caleb666
via reddit http://ift.tt/2pyFmKW
http://ift.tt/2IJnqoZ
Submitted March 23, 2018 at 02:27PM by Caleb666
via reddit http://ift.tt/2pyFmKW
Twistlock
Deep dive on the most severe Kubernetes vulnerabilities to date - CVE-2017-1002101 and CVE-2017-1002102 | Twistlock
Deep dive on the most severe Kubernetes vulnerabilities to date - CVE-2017-1002101 and CVE-2017-1002102 from Twistlock. Dev-to-Production Docker and container security for enterprises.
Tracking ransomware end-to-end
http://ift.tt/2G1Deli
Submitted March 23, 2018 at 02:13PM by al-maisan
via reddit http://ift.tt/2pA0AXV
http://ift.tt/2G1Deli
Submitted March 23, 2018 at 02:13PM by al-maisan
via reddit http://ift.tt/2pA0AXV
the morning paper
Tracking ransomware end-to-end
Tracking ransomware end-to-end Huang et al., IEEE Security & Privacy 2018 With thanks to Elie Bursztein for bringing this paper to my attention. You get two for the price of one with today’s pa…
We need to talk about IDS signatures
http://ift.tt/2pmpWcu
Submitted March 23, 2018 at 05:09PM by alexlash
via reddit http://ift.tt/2G3zRdq
http://ift.tt/2pmpWcu
Submitted March 23, 2018 at 05:09PM by alexlash
via reddit http://ift.tt/2G3zRdq
Ptsecurity
We need to talk about IDS signatures
The names Snort and Suricata are known to all who work in the field of network security. WAF and IDS are two classes of security systems...
Trustico Statement In Regard to DigiCert Revocation
http://ift.tt/2udXNt7
Submitted March 23, 2018 at 05:39PM by stugster
via reddit http://ift.tt/2pzcHpe
http://ift.tt/2udXNt7
Submitted March 23, 2018 at 05:39PM by stugster
via reddit http://ift.tt/2pzcHpe
Security In 5: Episode 201 - Tools, Tips and Tricks - MXToolbox.com
http://ift.tt/2HXMOWS
Submitted March 23, 2018 at 06:34PM by BinaryBlog
via reddit http://ift.tt/2pypnfP
http://ift.tt/2HXMOWS
Submitted March 23, 2018 at 06:34PM by BinaryBlog
via reddit http://ift.tt/2pypnfP
Libsyn
Security In Five Podcast: Episode 201 - Tools, Tips and Tricks - MXToolbox.com
This week's Tools, Tips and Tricks talks about MXToolbox.com. A collection of network, email and web testing/monitoring tools. If you run a website or manage an infrastructure there are tools in the MXToolbox that you will find useful. MXToolbox.com Be…
Top Five Ways the Red Team breached the External Perimeter
http://ift.tt/2pBRVoT
Submitted March 23, 2018 at 08:15PM by wootock
via reddit http://ift.tt/2pz9Bl4
http://ift.tt/2pBRVoT
Submitted March 23, 2018 at 08:15PM by wootock
via reddit http://ift.tt/2pz9Bl4
Medium
Top Five Ways the Red Team breached the External Perimeter
I have been performing “red team” breach assessments for many years. Often the goal is penetrating an external network, and gaining access…
Why do banking websites insist on continuing these insecure password requirements? Screenshot taken from Merrill Lynch
https://ift.tt/2G5T6TH
Submitted March 23, 2018 at 10:32PM by peepeeopi
via reddit https://ift.tt/2DPU6JL
https://ift.tt/2G5T6TH
Submitted March 23, 2018 at 10:32PM by peepeeopi
via reddit https://ift.tt/2DPU6JL
What all web application security testing cases can be completed just by using browsers
https://ift.tt/2ILab7i
Submitted March 23, 2018 at 10:37PM by assliekthat
via reddit https://ift.tt/2G6mbyz
https://ift.tt/2ILab7i
Submitted March 23, 2018 at 10:37PM by assliekthat
via reddit https://ift.tt/2G6mbyz
Getmantra
Web app security testing with browsers
A guide on using browser dev-tools for performing web app pentesting
KSMA: Breaking Android kernel isolation and Rooting with ARM MMU features [Blackhat Asia 2018]
https://ift.tt/2GlDoqQ
Submitted March 23, 2018 at 11:41PM by TechLord2
via reddit https://ift.tt/2pDPDVg
https://ift.tt/2GlDoqQ
Submitted March 23, 2018 at 11:41PM by TechLord2
via reddit https://ift.tt/2pDPDVg
return-to-csu: A New Method to Bypass 64-bit Linux ASLR [Paper - Blackhat Asia 2018]
https://ift.tt/2Gm0YE6
Submitted March 23, 2018 at 11:34PM by TechLord2
via reddit https://ift.tt/2G4eKI4
https://ift.tt/2Gm0YE6
Submitted March 23, 2018 at 11:34PM by TechLord2
via reddit https://ift.tt/2G4eKI4
SSRF - Exploiting URL Parser in Trending Programming Languages [Blackhat Asia 2018 Presentation]
https://ift.tt/2GfEkgu
Submitted March 23, 2018 at 11:30PM by TechLord2
via reddit https://ift.tt/2pzoZgs
https://ift.tt/2GfEkgu
Submitted March 23, 2018 at 11:30PM by TechLord2
via reddit https://ift.tt/2pzoZgs
Syntia: Breaking State-of-the-Art Binary Code Obfuscation via Program Synthesis
https://ift.tt/2pAS3UR
Submitted March 23, 2018 at 11:26PM by TechLord2
via reddit https://ift.tt/2IMwsBD
https://ift.tt/2pAS3UR
Submitted March 23, 2018 at 11:26PM by TechLord2
via reddit https://ift.tt/2IMwsBD
Breach Detection at Scale with AWS Honey Tokens [Blackhat Asia 2018]
https://ift.tt/2FYuY9C
Submitted March 23, 2018 at 11:22PM by TechLord2
via reddit https://ift.tt/2Gi98gv
https://ift.tt/2FYuY9C
Submitted March 23, 2018 at 11:22PM by TechLord2
via reddit https://ift.tt/2Gi98gv
AES Wireless Keyboard - Template Attack for Eavesdropping [Blackhat Asia 2018]
https://ift.tt/2pA9nKp
Submitted March 23, 2018 at 11:20PM by TechLord2
via reddit https://ift.tt/2ueLrRx
https://ift.tt/2pA9nKp
Submitted March 23, 2018 at 11:20PM by TechLord2
via reddit https://ift.tt/2ueLrRx
DoJ indicts Iranian hackers for stealing data from 144 US universities
https://ift.tt/2GhzYFz
Submitted March 23, 2018 at 11:55PM by Temptunes48
via reddit https://ift.tt/2pCnBtn
https://ift.tt/2GhzYFz
Submitted March 23, 2018 at 11:55PM by Temptunes48
via reddit https://ift.tt/2pCnBtn
ZDNet
DoJ indicts Iranian hackers for stealing data from 144 US universities | ZDNet
In all, 320 universities around the world were attacked and the 31.5 terabytes of stolen data was sold for profit in Iran.
Shadow-Box v2: The Practical and Omnipotent Sandbox for ARM [BlackHat Asia 2018 - with Github Sources]
https://ift.tt/2pyV4pg
Submitted March 23, 2018 at 11:48PM by TechLord2
via reddit https://ift.tt/2HZWVum
https://ift.tt/2pyV4pg
Submitted March 23, 2018 at 11:48PM by TechLord2
via reddit https://ift.tt/2HZWVum
DNC “lone hacker” Guccifer 2.0 pegged as Russian spy after opsec fail – Ars Technica
http://ift.tt/2pzRI5z
Submitted March 24, 2018 at 12:05AM by nmgreddit
via reddit https://ift.tt/2G6aUOx
http://ift.tt/2pzRI5z
Submitted March 24, 2018 at 12:05AM by nmgreddit
via reddit https://ift.tt/2G6aUOx
Ars Technica
DNC “lone hacker” Guccifer 2.0 pegged as Russian spy after opsec fail
"Hacktivist" logged into a social media account from an IP address at GRU HQ in Moscow.
Use our suite of Ethereum security tools
http://ift.tt/2pAq4Vl
Submitted March 24, 2018 at 12:19AM by AwesomeJosh
via reddit https://ift.tt/2pzRXNV
http://ift.tt/2pAq4Vl
Submitted March 24, 2018 at 12:19AM by AwesomeJosh
via reddit https://ift.tt/2pzRXNV
Trail of Bits Blog
Use our suite of Ethereum security tools
Two years ago, when we began taking on blockchain security engagements, there were no tools engineered for the work. No static analyzers, fuzzers, or reverse engineering tools for Ethereum. So, we …
Public-Private Cybersecurity Center Opens for Business in Sydney
http://ift.tt/2DMA0Af
Submitted March 24, 2018 at 12:47AM by techie_programmer
via reddit https://ift.tt/2pzWzUf
http://ift.tt/2DMA0Af
Submitted March 24, 2018 at 12:47AM by techie_programmer
via reddit https://ift.tt/2pzWzUf
Latest Hacking News
Public-Private Cybersecurity Center Opens for Business in Sydney
The 4th Joint Cyber-Security Center is now officially opened in Sydney, almost a year after the 1st was launched in Brisbane. The government of Australia has now officially opened the Sydney Joint Cyber Security Centre (JCSC). Angus Taylor, the Minister for…
Ransomware Attack Cripples Several Atlanta City Systems
http://ift.tt/2G4PYYp
Submitted March 24, 2018 at 01:20AM by volci
via reddit https://ift.tt/2G75OSf
http://ift.tt/2G4PYYp
Submitted March 24, 2018 at 01:20AM by volci
via reddit https://ift.tt/2G75OSf
Threatpost | The first stop for security news
Ransomware Attack Cripples Several Atlanta City Systems
The city of Atlanta is being extorted for $51,000 in a ransomware attack that occurred early Thursday that impacted several local government departments.
The bug that made free money
http://ift.tt/2udiYLQ
Submitted March 24, 2018 at 01:19AM by volci
via reddit https://ift.tt/2GlZCcg
http://ift.tt/2udiYLQ
Submitted March 24, 2018 at 01:19AM by volci
via reddit https://ift.tt/2GlZCcg
Naked Security
The bug that made free money
What would you do if you found a bug that could create money out of thin air?