Exploiting CVE-2017-8759: SOAP WSDL Parser Code Injection by MDSec ActiveBreach
http://ift.tt/2x1RYyw
Submitted September 14, 2017 at 01:10AM by mdsec
via reddit http://ift.tt/2wpVejw
http://ift.tt/2x1RYyw
Submitted September 14, 2017 at 01:10AM by mdsec
via reddit http://ift.tt/2wpVejw
www.mdsec.co.uk
Exploiting CVE-2017-8759: SOAP WSDL Parser Code Injection – MDSec
A walk through on how to exploit CVE-2017-8759
1.65 Million Attacks: Kaspersky Reveals New Data on Crypto Mining Malware
http://ift.tt/2h1RtPe
Submitted September 14, 2017 at 01:03AM by lazec
via reddit http://ift.tt/2x1SIni
http://ift.tt/2h1RtPe
Submitted September 14, 2017 at 01:03AM by lazec
via reddit http://ift.tt/2x1SIni
CoinDesk
1.65 Million Attacks: Kaspersky Reveals New Data on Crypto Mining Malware - CoinDesk
Kaspersky Labs revealed it protected more than 1.65 million computers from cryptocurrency mining malware in a report on Tuesday.
FireEye Security Bug: Connection to physical host and adjacent network possible during analysis in Live-Mode
http://ift.tt/2f5Ab32
Submitted September 14, 2017 at 12:47AM by FireFart
via reddit http://ift.tt/2jq2NWp
http://ift.tt/2f5Ab32
Submitted September 14, 2017 at 12:47AM by FireFart
via reddit http://ift.tt/2jq2NWp
Insinuator.net
FireEye Security Bug: Connection to physical host and adjacent network possible during analysis in Live-Mode
We recently identified a security issue in FireEye AX 5400, that also affected other products. We responsibly disclosed the bug to FireEye and a fix that addresses the issue has been released with version 7.7.7. The fix was also merged into the common core…
Equifax pulls their vulnerable mobile application from app stores
http://ift.tt/2h3Kl1k
Submitted September 14, 2017 at 01:54AM by patcheudor
via reddit http://ift.tt/2wXHnVS
http://ift.tt/2h3Kl1k
Submitted September 14, 2017 at 01:54AM by patcheudor
via reddit http://ift.tt/2wXHnVS
The Man Behind Plugin Spam: Mason Soiza
http://ift.tt/2wpPfv0
Submitted September 14, 2017 at 01:51AM by speckz
via reddit http://ift.tt/2h4ATun
http://ift.tt/2wpPfv0
Submitted September 14, 2017 at 01:51AM by speckz
via reddit http://ift.tt/2h4ATun
Wordfence
The Man Behind Plugin Spam: Mason Soiza
This is a follow-up to our story noscriptd “Display Widgets Plugin Includes Malicious Code to Publish Spam on WP Sites“. In this post, we explore who is behind the purchase and corruption of the Display Widgets plugin and at least two other popular WordPress…
Zerodium Offering $1M for Tor Browser Zero Days | Threatpost
http://ift.tt/2fjcT70
Submitted September 14, 2017 at 01:59AM by majorllama
via reddit http://ift.tt/2x2buuI
http://ift.tt/2fjcT70
Submitted September 14, 2017 at 01:59AM by majorllama
via reddit http://ift.tt/2x2buuI
Threatpost | The first stop for security news
Zerodium Offering $1M for Tor Browser Zero Days
Exploit acquisition vendor Zerodium said Wednesday it will pay up to $1M for an unknown Tor Browser zero day.
They're Trying to Hack Your PayPal Account
http://ift.tt/2xxMj4t
Submitted September 14, 2017 at 02:30AM by sh_tomer
via reddit http://ift.tt/2f795Zm
http://ift.tt/2xxMj4t
Submitted September 14, 2017 at 02:30AM by sh_tomer
via reddit http://ift.tt/2f795Zm
dzone.com
They're Trying to Hack Your Account: Analyzing a Real Phishing Email - DZone Security
A DZone MVB breaks down a suspicious email he received to demonstrate how phishing attempts work, and certain key elements of phishing attempts to look out for.
Ayuda! (Help!) Equifax Has My Data!
http://ift.tt/2h1eKkx
Submitted September 14, 2017 at 02:42AM by dabshitty
via reddit http://ift.tt/2x2tfu0
http://ift.tt/2h1eKkx
Submitted September 14, 2017 at 02:42AM by dabshitty
via reddit http://ift.tt/2x2tfu0
reddit
Ayuda! (Help!) Equifax Has My Data! • r/security
1 points and 1 comments so far on reddit
Have you seen Halls-of-Valhalla.org? There are a ton of challenges including encryption, javanoscript, recon, SQLi, Steago and more– Here's the Beginners Challenge Levels 1-7 Walkthrough. Post your Halls of Valhalla Walkthrough below.
http://ift.tt/2wqKBgA
Submitted September 14, 2017 at 07:01AM by InfoSecJim
via reddit http://ift.tt/2wqMLN7
http://ift.tt/2wqKBgA
Submitted September 14, 2017 at 07:01AM by InfoSecJim
via reddit http://ift.tt/2wqMLN7
Jim Wilbur's Blog
Halls of Valhalla - Beginners Challenge 1-7 - Jim Wilbur's Blog
Here’s a walk-through for the Beginner Challenges on www.Halls-of-Valhalla.org Right click to view source and After a few minutes of perusing the source I found For this exercise we are using Burp Suite I flipped the Cookie: auth bit to true and…. After many…
US Gov orders all Kaspersky products removed in 90 days
http://ift.tt/2wqKth7
Submitted September 14, 2017 at 07:19AM by rhinoplzno
via reddit http://ift.tt/2eWg041
http://ift.tt/2wqKth7
Submitted September 14, 2017 at 07:19AM by rhinoplzno
via reddit http://ift.tt/2eWg041
Nytimes
Kaspersky Lab Antivirus Software Is Ordered Off U.S. Government Computers
The company’s origins in Russia have for years fueled suspicions about possible ties to Russian intelligence agencies. Kaspersky denies the allegations.
Red Hat JBoss EAP 3.0.7 - 4.0.0 vulnerable to server side cache poisoning
http://ift.tt/2fkuMlT
Submitted September 14, 2017 at 10:42AM by rhinoplzno
via reddit http://ift.tt/2jpQo4M
http://ift.tt/2fkuMlT
Submitted September 14, 2017 at 10:42AM by rhinoplzno
via reddit http://ift.tt/2jpQo4M
cve.mitre.org
CVE -
CVE-2017-7561
CVE-2017-7561
Common Vulnerabilities and Exposures (CVE®) is a dictionary of common names (i.e., CVE Identifiers) for publicly known cyber security vulnerabilities. Assigned by CVE Numbering Authorities from around the world, use of CVE Identifiers ensures confidence among…
Sharing is Caring: Why Cyber Security Needs to Be a United Sector
http://ift.tt/2y0bh90
Submitted September 14, 2017 at 02:18PM by InfoSecCrazy
via reddit http://ift.tt/2h2OqGt
http://ift.tt/2y0bh90
Submitted September 14, 2017 at 02:18PM by InfoSecCrazy
via reddit http://ift.tt/2h2OqGt
itsecuritycentral.teramind.co
Sharing is Caring: Why Cyber Security Needs to Be a United Sector | IT Security Central
As first responders and defenders of information infrastructure, cyber security professionals play an increasingly important role in maintaining the national
U.S. spies think the FBI is botching the Kaspersky investigation
http://ift.tt/2wV7sEC
Submitted September 14, 2017 at 02:07PM by johnmountain
via reddit http://ift.tt/2xzANpf
http://ift.tt/2wV7sEC
Submitted September 14, 2017 at 02:07PM by johnmountain
via reddit http://ift.tt/2xzANpf
Cyberscoop
U.S. spies think the FBI is botching the Kaspersky investigation
The FBI hasn't made public any evidence of a relationship between Kaspersky and the Kremlin.
New Variants of Agent.BTZ/ComRAT Found: The Threat That Hit The Pentagon In 2008 Still Evolving; Part 2/2
http://ift.tt/2xzR5hV
Submitted September 14, 2017 at 01:23PM by omri9741
via reddit http://ift.tt/2jpMZCT
http://ift.tt/2xzR5hV
Submitted September 14, 2017 at 01:23PM by omri9741
via reddit http://ift.tt/2jpMZCT
Intezer
New Variants of Agent.BTZ/ComRAT Found: The Threat That Hit The Pentagon In 2008 Still Evolving; Part 2/2 - Intezer
Our previous blog post was a short brief of new Agent.BTZ variants that we found. This second part in the series will demonstrate in greater detail exactly how we discovered these new variants. 1. Methodology To begin, we used our hunting methodology, which…
Kaspersky Lab solutions banned from US government agencies
http://ift.tt/2eXan5E
Submitted September 14, 2017 at 03:07PM by MicheeLengronne
via reddit http://ift.tt/2jpdUyJ
http://ift.tt/2eXan5E
Submitted September 14, 2017 at 03:07PM by MicheeLengronne
via reddit http://ift.tt/2jpdUyJ
Security Affairs
Kaspersky Lab solutions banned from US government agencies
The US Department of Homeland security banned government agencies for using software products developed by Kaspersky Lab
Users Freak Out After Dark Web Market Goes Down And Funds Go Missing
http://ift.tt/2fjBSqJ
Submitted September 14, 2017 at 03:08PM by MicheeLengronne
via reddit http://ift.tt/2wrsmY4
http://ift.tt/2fjBSqJ
Submitted September 14, 2017 at 03:08PM by MicheeLengronne
via reddit http://ift.tt/2wrsmY4
Motherboard
Users Freak Out After Dark Web Market Goes Down And Funds Go Missing
Never a dull moment in the world of dark web marketplaces.
How to Enlarge Your Botnet with Top D-Link Routers
http://ift.tt/2fi75ut
Submitted September 14, 2017 at 02:52PM by Embedi
via reddit http://ift.tt/2f75LO8
http://ift.tt/2fi75ut
Submitted September 14, 2017 at 02:52PM by Embedi
via reddit http://ift.tt/2f75LO8
Embedi
Enlarge your botnet with: top D-Link routers (DIR8xx D-Link routers cruisin' for a bruisin')
In this article, we are going to discuss vulnerabilities detected in the top D-Link routers: DIR890L DIR885L DIR895L and other DIR8xx D-Link routers cruising for a bruising. The devices use the same code, thus giving a magnificent and quite tempting opportunity…
Equifax confirms Apache Struts flaw it failed to patch was to blame for data breach
http://ift.tt/2y6MCQM
Submitted September 14, 2017 at 03:49PM by Hamm3rH3ad
via reddit http://ift.tt/2y8Nu7I
http://ift.tt/2y6MCQM
Submitted September 14, 2017 at 03:49PM by Hamm3rH3ad
via reddit http://ift.tt/2y8Nu7I
ZDNet
Equifax confirms Apache Struts security flaw it failed to patch is to blame for hack
The company said the March vulnerability was exploited by hackers.
Mathias Bynens Hacking with Unicode
http://ift.tt/2y7Pxcf
Submitted September 14, 2017 at 03:45PM by iamhabibone
via reddit http://ift.tt/2x1SkDm
http://ift.tt/2y7Pxcf
Submitted September 14, 2017 at 03:45PM by iamhabibone
via reddit http://ift.tt/2x1SkDm
IAMHABIB.NET
[Video] Mathias Bynens Hacking with Unicode - IAMHABIB.NET
IAMHABIB.NET is the videos tube site on Hacking, Security, Reverse Engineering and Social Engineeering
Using D-Link routers for a botnet
http://ift.tt/2fi75ut
Submitted September 14, 2017 at 05:25PM by Embedi
via reddit http://ift.tt/2f8O0xH
http://ift.tt/2fi75ut
Submitted September 14, 2017 at 05:25PM by Embedi
via reddit http://ift.tt/2f8O0xH
Embedi
Enlarge your botnet with: top D-Link routers (DIR8xx D-Link routers cruisin' for a bruisin')
In this article, we are going to discuss vulnerabilities detected in the top D-Link routers: DIR890L DIR885L DIR895L and other DIR8xx D-Link routers cruising for a bruising. The devices use the same code, thus giving a magnificent and quite tempting opportunity…
Anatomy of a hack SQLI to enterprise admin
http://ift.tt/2vVDH3g
Submitted September 14, 2017 at 06:32PM by pm_me_your_findings
via reddit http://ift.tt/2xmT8VQ
http://ift.tt/2vVDH3g
Submitted September 14, 2017 at 06:32PM by pm_me_your_findings
via reddit http://ift.tt/2xmT8VQ
NotSoSecure
Anatomy of a Hack: SQLi to Enterprise Admin
A story of corporate domain compromise featuring SQLi, OSINT, weak creds, password cracking, insecure configs, pivoting, AV & pure pwnage.