Week 36 in Information Security, 2017
http://ift.tt/2y13kQP
Submitted September 14, 2017 at 07:47PM by undercomm
via reddit http://ift.tt/2h3TeLX
http://ift.tt/2y13kQP
Submitted September 14, 2017 at 07:47PM by undercomm
via reddit http://ift.tt/2h3TeLX
Malgregator
Week 36, 2017
The security researcher Pierre Kim has discovered ten critical zero-day vulnerabilities in D-Link routers....
When passwords aren't totally strong - Credit agencies.
I went to freeze my credit at the big 3 today and Equifax was down (but only after you enter all your private stuff!) and the other two make you create an account. The passwords at Experian and Transunion failed when I used a - and a & character, so I had to dumb down my password scheme due to these weaknesses. Does anyone know what authentication systems they use that cant use ANY character, only a select few?
Submitted September 14, 2017 at 08:15PM by sexuallyactivepope
via reddit http://ift.tt/2x1NciT
I went to freeze my credit at the big 3 today and Equifax was down (but only after you enter all your private stuff!) and the other two make you create an account. The passwords at Experian and Transunion failed when I used a - and a & character, so I had to dumb down my password scheme due to these weaknesses. Does anyone know what authentication systems they use that cant use ANY character, only a select few?
Submitted September 14, 2017 at 08:15PM by sexuallyactivepope
via reddit http://ift.tt/2x1NciT
reddit
When passwords aren't totally strong - Credit agencies. • r/security
I went to freeze my credit at the big 3 today and Equifax was down (but only after you enter all your private stuff!) and the other two make you...
The EQUIFAX hackers are trying to crowd fund the release of all the data
http://ift.tt/2xmEU7a
Submitted September 14, 2017 at 09:13PM by westondeboer
via reddit http://ift.tt/2xnkI55
http://ift.tt/2xmEU7a
Submitted September 14, 2017 at 09:13PM by westondeboer
via reddit http://ift.tt/2xnkI55
Krypt3ia
EQUIHAX
Trawling the darknet as one does, I came across this little simple page this morning. It claims to be the real EQUIFAX hackers, unlike the last darknet site that was soon taken down by morons. I ha…
Don't Delay: Replace Symantec TLS/SSL Certs Now
http://ift.tt/2f3h75v
Submitted September 15, 2017 at 12:33AM by dc352
via reddit http://ift.tt/2x5aaXV
http://ift.tt/2f3h75v
Submitted September 15, 2017 at 12:33AM by dc352
via reddit http://ift.tt/2x5aaXV
Bankinfosecurity
Don't Delay: Replace Symantec TLS/SSL Certs Now
A major operation to cleanse websites of digital certificates created under questionable circumstances is underway. Google has issued the orders: Purge digital
A Rudimentary Threat Model Framework for Password vs. TouchID vs. FaceID
http://ift.tt/2x3FLI0
Submitted September 15, 2017 at 12:19AM by danielrm26
via reddit http://ift.tt/2h5gARs
http://ift.tt/2x3FLI0
Submitted September 15, 2017 at 12:19AM by danielrm26
via reddit http://ift.tt/2h5gARs
danielmiessler.com
A Rudimentary Threat Model Framework for Password vs. TouchID vs. FaceID
There's been a lot of discussion around Apple's replacement of TouchID with FaceID on the new iPhone X. There's conversation around the overall security of
(Podcast)Beers with Talos Ep12 now available
http://ift.tt/2vWGucx
Submitted September 15, 2017 at 01:41AM by WorksAtCisco
via reddit http://ift.tt/2wdgj5x
http://ift.tt/2vWGucx
Submitted September 15, 2017 at 01:41AM by WorksAtCisco
via reddit http://ift.tt/2wdgj5x
Talosintelligence
Beers with Talos EP12 - IrmaGerd! The Internet Ate Our Podcast!
Beers with Talos is a fast-paced, smart, and humorous podcast focused on security research topics. Staying abreast of security topics is difficult in this rapidly evolving threat landscape. Beers with Talos serves important security stories in a way that…
Bluetooth bug could expose billions of devices to attack, cyber experts warn
http://ift.tt/2xlTDPW
Submitted September 15, 2017 at 04:55AM by AnythingForSuccess
via reddit http://ift.tt/2fmjo8Y
http://ift.tt/2xlTDPW
Submitted September 15, 2017 at 04:55AM by AnythingForSuccess
via reddit http://ift.tt/2fmjo8Y
ABC News
BlueBorne: Bluetooth bug could expose billions of devices to attack, cyber experts warn
Internet security experts are urging people to update their software to protect against a serious vulnerability.
After Equifax: Why the US must finally outgrow SSNs as identifiers
https://mcafee.ly/2faf67P
Submitted September 15, 2017 at 05:42AM by jeffthechimp
via reddit http://ift.tt/2wt8h3Q
https://mcafee.ly/2faf67P
Submitted September 15, 2017 at 05:42AM by jeffthechimp
via reddit http://ift.tt/2wt8h3Q
McAfee Blogs
Equifax: Rethinking Social Security Numbers as Identifiers
Revelations about compromised social security numbers at Equifax remind us that the US needs to modernize the identification standard.
Malvertising Campaign Mines Cryptocurrency Right in Your Browser
http://ift.tt/2x4H0bk
Submitted September 15, 2017 at 06:34AM by majorllama
via reddit http://ift.tt/2y2F4hb
http://ift.tt/2x4H0bk
Submitted September 15, 2017 at 06:34AM by majorllama
via reddit http://ift.tt/2y2F4hb
BleepingComputer
Malvertising Campaign Mines Cryptocurrency Right in Your Browser
Malware authors are using JavaScript code delivered via malvertising campaigns to mine different cryptocurrencies inside people's browsers, without their knowledge.
Deep Dive in MarkLogic Exploitation Process via Argus PDF Converter
http://ift.tt/2x5yXv6
Submitted September 15, 2017 at 06:34AM by majorllama
via reddit http://ift.tt/2x3z2Oa
http://ift.tt/2x5yXv6
Submitted September 15, 2017 at 06:34AM by majorllama
via reddit http://ift.tt/2x3z2Oa
Talosintelligence
Deep Dive in MarkLogic Exploitation Process via Argus PDF Converter
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
Leti and Partners in PiezoMAT Project Develop New Fingerprint Technology
http://ift.tt/2gPpM8M's-On/Press%20release/leti-and-partners-in-piezomat-project-develop-new-fingerprint-technology-for-highly-reliable-security-and-id-applications.aspx
Submitted September 15, 2017 at 07:33AM by Chipdoc
via reddit http://ift.tt/2y9WEk9
http://ift.tt/2gPpM8M's-On/Press%20release/leti-and-partners-in-piezomat-project-develop-new-fingerprint-technology-for-highly-reliable-security-and-id-applications.aspx
Submitted September 15, 2017 at 07:33AM by Chipdoc
via reddit http://ift.tt/2y9WEk9
Ifttt
IFTTT helps you do more with the services you love. Connect Amazon Alexa, Facebook, Twitter, Instagram, Fitbit, Slack, Skype, and hundreds more.
Beat up an Android file transfer app with 10Million+ downloads. Check out the write up!
http://ift.tt/2x5E0vf
Submitted September 15, 2017 at 07:28AM by vincelasal
via reddit http://ift.tt/2yacMCv
http://ift.tt/2x5E0vf
Submitted September 15, 2017 at 07:28AM by vincelasal
via reddit http://ift.tt/2yacMCv
think_tank_sec
Latest Posts
mostly planetary things.
How-To Setup Fail2ban with Apache Guacamole to Stop Brute-Force Attacks
http://ift.tt/2h6ECYi
Submitted September 15, 2017 at 08:01AM by InfoSecJim
via reddit http://ift.tt/2h5AXdt
http://ift.tt/2h6ECYi
Submitted September 15, 2017 at 08:01AM by InfoSecJim
via reddit http://ift.tt/2h5AXdt
Jim Wilbur's Blog
How-To Setup Fail2ban with Guacamole to Stop Brute-Force Attacks
How to install and configure Fail2Ban with Guacamole 0.9.9 on CentOS 7. Fail2ban is an IPS framework that protects against brute-force attacks.
"WordPress....Most Popular Security Plugins..." ...
http://ift.tt/2jttoSi
Submitted September 15, 2017 at 10:34AM by Renee_Shuron
via reddit http://ift.tt/2faA9an
http://ift.tt/2jttoSi
Submitted September 15, 2017 at 10:34AM by Renee_Shuron
via reddit http://ift.tt/2faA9an
Equifax confirms Apache Struts security flaw it failed to patch is to blame for hack
http://ift.tt/2fmYsi9
Submitted September 15, 2017 at 10:05AM by radmind
via reddit http://ift.tt/2eZtH21
http://ift.tt/2fmYsi9
Submitted September 15, 2017 at 10:05AM by radmind
via reddit http://ift.tt/2eZtH21
Medium
Equifax Data Breach Due to Negligence
News of the Equifax data breach broke last week sending ripples across the global cybersecurity community.
CCTV Monitoring Security Services in Hyderabad
http://ift.tt/2xCUpJk
Submitted September 15, 2017 at 01:16PM by odmshyd
via reddit http://ift.tt/2wu8mUP
http://ift.tt/2xCUpJk
Submitted September 15, 2017 at 01:16PM by odmshyd
via reddit http://ift.tt/2wu8mUP
Ikansecurity
IKAN Security Services & Systems | CCTV Security Services
IKAN Security Services & Systems provide, install and maintains a wide range of CCTV monitoring devices to customers throughout the state with accuracy results.
Understanding the prevalence of web traffic interception
http://ift.tt/2jmwwzd
Submitted September 15, 2017 at 01:32PM by pgl
via reddit http://ift.tt/2fnv3nX
http://ift.tt/2jmwwzd
Submitted September 15, 2017 at 01:32PM by pgl
via reddit http://ift.tt/2fnv3nX
reddit
Understanding the prevalence of web traffic interception • r/netsec
1 points and 0 comments so far on reddit
Premium SMS malware EXPENSIVEWALL infected millions of Android handsets
http://ift.tt/2xoAXiF
Submitted September 15, 2017 at 02:00PM by MicheeLengronne
via reddit http://ift.tt/2vXASyJ
http://ift.tt/2xoAXiF
Submitted September 15, 2017 at 02:00PM by MicheeLengronne
via reddit http://ift.tt/2vXASyJ
Security Affairs
Premium SMS malware EXPENSIVEWALL infected millions of Android handsets
Google removed 50 malicious apps from the official Play Store after experts discovered a new malware, dubbed ExpensiveWall, eluded Google Bouncer checks.
4,000 ElasticSearch servers found hosting PoS malware
http://ift.tt/2x1SXgj
Submitted September 15, 2017 at 02:00PM by MicheeLengronne
via reddit http://ift.tt/2xDTg48
http://ift.tt/2x1SXgj
Submitted September 15, 2017 at 02:00PM by MicheeLengronne
via reddit http://ift.tt/2xDTg48
HackRead
4,000 ElasticSearch servers found hosting PoS malware
Kromtech’s security researchers have identified two point-of-sale (POS) malware strains namely AlinaPOS and JackPOS hosted on more than 4,000 ElasticSearch
From SQL Injection to Shell
http://ift.tt/1MVUlpg
Submitted September 15, 2017 at 02:03PM by Gallus
via reddit http://ift.tt/2wfgTQ9
http://ift.tt/1MVUlpg
Submitted September 15, 2017 at 02:03PM by Gallus
via reddit http://ift.tt/2wfgTQ9
Pentesterlab
[PentesterLab] From SQL Injection to Shell
Detektive für die Shop Diebstahl- und Kaufhausüberwachung
http://ift.tt/2juvsta
Submitted September 15, 2017 at 02:34PM by protexgroup
via reddit http://ift.tt/2fabz9G
http://ift.tt/2juvsta
Submitted September 15, 2017 at 02:34PM by protexgroup
via reddit http://ift.tt/2fabz9G
protex-group.de
Warenhausüberwachung durch Warenhausdetektive - Sicherheitsdienste der Protex Group
Sicherheitsdienste der Protex Group. Unser Schwerpunkt ist die Warenhausüberwachung, die Überwachungstechnik sowie der Veranstaltungsschutz in höchster Qualität. Wir beraten Industrieunternehmen, Handel, Banken, Dienstleister, Versicherungsgesellschaften…