Security In 5: Episode 233 - Being A Security Professional Means Master A Balance With Flexibility
https://ift.tt/2rt8ALo
Submitted May 08, 2018 at 06:40PM by BinaryBlog
via reddit https://ift.tt/2KKAs6H
https://ift.tt/2rt8ALo
Submitted May 08, 2018 at 06:40PM by BinaryBlog
via reddit https://ift.tt/2KKAs6H
Libsyn
Security In Five Podcast: Episode 233 - Being A Security Professional Means Master A Balance With Flexibility
A security professional is more than the technical and regulatory resource in your company. A security professional needs to know how the business works in order to ensure the security controls are effective but also does not hinder business operations in…
Equifax reveals full horror of its data breach - "146.6 million names, 146.6 million dates of birth, 145.5 million social security numbers, 99 million address information and 209,000 payment cards (number and expiry date). There were also 38,000 US drivers' licenses and 3,200 passport details."
https://ift.tt/2I4hV3t
Submitted May 08, 2018 at 06:40PM by md5sumo
via reddit https://ift.tt/2rsLaWI
https://ift.tt/2I4hV3t
Submitted May 08, 2018 at 06:40PM by md5sumo
via reddit https://ift.tt/2rsLaWI
www.theregister.co.uk
Equifax reveals full horror of its data breach
146 million people, 99 million addresses, 209,000 payment cards, 38,000 drivers' licenses and 3,200 passports
How secure is your data when it’s stored in the cloud?
https://ift.tt/2rsV4aC
Submitted May 08, 2018 at 05:16PM by BrRafique1
via reddit https://ift.tt/2KKXBWK
https://ift.tt/2rsV4aC
Submitted May 08, 2018 at 05:16PM by BrRafique1
via reddit https://ift.tt/2KKXBWK
Medium
How secure is your data when it’s stored in the cloud?
As cloud storage becomes more common, data security is an increasing concern. Companies and schools have been increasing their use of…
Podcast: The Evolving Role of the CTO
https://ift.tt/2K3fTB9
Submitted May 08, 2018 at 05:10PM by Uminekoshi
via reddit https://ift.tt/2rtlqt3
https://ift.tt/2K3fTB9
Submitted May 08, 2018 at 05:10PM by Uminekoshi
via reddit https://ift.tt/2rtlqt3
SoundCloud
Episode 9 - The Evolving Role of the CTO with Jason Morris
In this CyberTangent episode, we are joined by Jason Morris, CTO at Next Rev Technologies. Our podcast host is Landon Johnson. Today's topic is "The Evolving Role of the CTO." Let's jump in! Learn mor
Are your IoT devices are mining cryptocurrencies in their spare time?
https://ift.tt/2FXM8zu
Submitted May 08, 2018 at 04:59PM by Iot_Security
via reddit https://ift.tt/2KLI6NZ
https://ift.tt/2FXM8zu
Submitted May 08, 2018 at 04:59PM by Iot_Security
via reddit https://ift.tt/2KLI6NZ
SecuriThings
Are your IoT devices are mining cryptocurrencies in their spare time?
When the masses start to use industry terminology, things have clearly gone mainstream. IoT is now mainstream, and there is no turning back. But, is security ready to move ahead at the speed of [...]
Running yara rules on malware app
I have bunch of yara rules (https://yara.readthedocs.io/en/v3.7.0/) which help me match certain patterns inside an APK. I have local installation of androguard with yara to help me with this regard. My question is, is there a service that I can use that can replace this task?I have seen https://koodous.com/. You can submit your own yara rules and they will attempt to run them whenever a new app is submitted to their system. I attempted to create my own rules but its not working. Moreover, I don't think koodous will run all rule set submitted by all users.Is there an alternative solution?Am also wondering how one might approach such problem?
Submitted May 08, 2018 at 07:44PM by sirackh
via reddit https://ift.tt/2rvfxvt
I have bunch of yara rules (https://yara.readthedocs.io/en/v3.7.0/) which help me match certain patterns inside an APK. I have local installation of androguard with yara to help me with this regard. My question is, is there a service that I can use that can replace this task?I have seen https://koodous.com/. You can submit your own yara rules and they will attempt to run them whenever a new app is submitted to their system. I attempted to create my own rules but its not working. Moreover, I don't think koodous will run all rule set submitted by all users.Is there an alternative solution?Am also wondering how one might approach such problem?
Submitted May 08, 2018 at 07:44PM by sirackh
via reddit https://ift.tt/2rvfxvt
Koodous — Collaborative Platform for Android Malware Analysts
Koodous is a collaborative platform for researching on Android malware that combines online analysis tools with social interactions between the analysts.
Making and Impact in InfoSec
Hello!I wanted to reach out and see if other people are feeling the way I do and/or get some advice.I have been working in the security community for half a decade now. Lately I have been dealing with this dreadful feeling that the work I am doing is useless. I still like my field. I study new things almost every night and am constantly learning. My company is pretty great to me, but I work for a single customer on a daily basis, and the work feels worthless (for various reasons that I am not going to get into). Like if I disappeared right now, there would be know negative impact to the projects we work on. My mgrs know I want something different, but it may be some time before I sneak out.I know not every job is like this and, when I do make the switch, this may not be a problem anymore. But I'm curious, do others feel this way? Or have felt this way? How do you stay motivated? Or do you not care? Is it worth risking giving up a job at a company that I fit in at and enjoy for someplace that might have more interesting work? Interested in hearing your thoughts.Thanks!
Submitted May 08, 2018 at 08:17PM by wheatless12
via reddit https://ift.tt/2I5NmKL
Hello!I wanted to reach out and see if other people are feeling the way I do and/or get some advice.I have been working in the security community for half a decade now. Lately I have been dealing with this dreadful feeling that the work I am doing is useless. I still like my field. I study new things almost every night and am constantly learning. My company is pretty great to me, but I work for a single customer on a daily basis, and the work feels worthless (for various reasons that I am not going to get into). Like if I disappeared right now, there would be know negative impact to the projects we work on. My mgrs know I want something different, but it may be some time before I sneak out.I know not every job is like this and, when I do make the switch, this may not be a problem anymore. But I'm curious, do others feel this way? Or have felt this way? How do you stay motivated? Or do you not care? Is it worth risking giving up a job at a company that I fit in at and enjoy for someplace that might have more interesting work? Interested in hearing your thoughts.Thanks!
Submitted May 08, 2018 at 08:17PM by wheatless12
via reddit https://ift.tt/2I5NmKL
reddit
r/security - Making and Impact in InfoSec
1 votes and 0 so far on reddit
Caroline Wong talks with Kevin E. Greene about how he got his handle Kevtorious, firewalls, Secure Coding by Nature, SWAMP, DevOps, and more on the newest episode of Humans of InfoSec.
https://ift.tt/2ruAYwz
Submitted May 08, 2018 at 09:06PM by ju1i3k
via reddit https://ift.tt/2K6DlOa
https://ift.tt/2ruAYwz
Submitted May 08, 2018 at 09:06PM by ju1i3k
via reddit https://ift.tt/2K6DlOa
SoundCloud
Ep 6 Kevin Greene: Where Cyber Meets Hip Hop
Kevin Greene started his security work at Ernst & Young and has throughout his career worked in a variety of leadership roles in both the public and private sectors. Recently, he led Software Assuranc
Don’t Share Email with Scripts and Macros
https://ift.tt/2HVJwrs
Submitted May 08, 2018 at 09:28PM by volci
via reddit https://ift.tt/2wnGVBl
https://ift.tt/2HVJwrs
Submitted May 08, 2018 at 09:28PM by volci
via reddit https://ift.tt/2wnGVBl
reddit
Don’t Share Email with Scripts and Macros • r/security
1 points and 0 comments so far on reddit
FBI: Cyber-Fraud Losses Rise to Reach $1.4B | Threatpost
https://ift.tt/2rt9uaN
Submitted May 08, 2018 at 09:24PM by LindseyOD123
via reddit https://ift.tt/2HZlmfF
https://ift.tt/2rt9uaN
Submitted May 08, 2018 at 09:24PM by LindseyOD123
via reddit https://ift.tt/2HZlmfF
Threatpost | The first stop for security news
FBI: Cyber-Fraud Losses Rise to Reach $1.4B
About 301,580 consumers reported cyber-fraud and malware attacks to the FBI's Internet Crime Complaint Center (IC3) last year – with reported losses exceeding a whopping $1.4 billion.The year's
Clickjacking Google YOLO
https://ift.tt/2JX9RC2
Submitted May 08, 2018 at 09:14PM by albinowax
via reddit https://ift.tt/2rumqNJ
https://ift.tt/2JX9RC2
Submitted May 08, 2018 at 09:14PM by albinowax
via reddit https://ift.tt/2rumqNJ
XSS Jigsaw
Google YOLO
Buttons are everywhere. Elevator buttons, machinery buttons, and even "Nuclear Button" that sits on the President's office desk. But are you always sure the button you push really performs what you want it to do? is a HTML element that lets a web page embed
GNU Wget (1.7 thru 1.19.4) Cookie Injection [CVE-2018-0494]
https://ift.tt/2KH1WtP
Submitted May 08, 2018 at 10:29PM by xBytez
via reddit https://ift.tt/2IqRpoe
https://ift.tt/2KH1WtP
Submitted May 08, 2018 at 10:29PM by xBytez
via reddit https://ift.tt/2IqRpoe
seclists.org
Full Disclosure: GNU Wget Cookie Injection [CVE-2018-0494]
"Equi-Facts": Equifax Clarifies the Numbers for Its Massive Breach | Threatpost
https://ift.tt/2HYFVsW
Submitted May 08, 2018 at 10:43PM by LindseyOD123
via reddit https://ift.tt/2rskTI3
https://ift.tt/2HYFVsW
Submitted May 08, 2018 at 10:43PM by LindseyOD123
via reddit https://ift.tt/2rskTI3
Threatpost | The first stop for security news
“Equi-Facts”: Equifax Clarifies the Numbers for Its Massive Breach
The number of affected U.S. consumers from the infamous 2017 Equifax data breach now totals about 147.9 million, and the breach has touched almost every adult in the U.S., with more than 45% of the po
Adobe Patches Critical Bugs In Flash Player, Creative Cloud | Threatpost
https://ift.tt/2HYA9r6
Submitted May 08, 2018 at 10:38PM by LindseyOD123
via reddit https://ift.tt/2HZ5F8n
https://ift.tt/2HYA9r6
Submitted May 08, 2018 at 10:38PM by LindseyOD123
via reddit https://ift.tt/2HZ5F8n
Threatpost | The first stop for security news
Adobe Patches Critical Bugs In Flash Player, Creative Cloud
Adobe has fixed several critical vulnerabilities – including a critical code execution bug in Adobe Flash Player – as part of its regularly scheduled May Security Bulletin, on Tuesday.In all,
SynAttack Ransomware Now Using Process Doppelgänging
https://ift.tt/2rskFRd
Submitted May 08, 2018 at 10:28PM by coldsystem
via reddit https://ift.tt/2HZ5FFp
https://ift.tt/2rskFRd
Submitted May 08, 2018 at 10:28PM by coldsystem
via reddit https://ift.tt/2HZ5FFp
OSRadar
SynAttack Ransomware Now Using Process Doppelgänging - OSRadar
Ransomware is one of the most heinous pieces of software floating in the cyber world. They attack a computer, encrypts its files and asks for ransom in the change of decryption of the file. SynAttack is one of such ransomware. Recently, an improved edition…
Asus Control Center – An Information Disclosure and a database connection Clear-Text password leakage Vulnerability
https://ift.tt/2FV8Ecc
Submitted May 08, 2018 at 10:27PM by SymbianSyMoh
via reddit https://ift.tt/2rtOyjP
https://ift.tt/2FV8Ecc
Submitted May 08, 2018 at 10:27PM by SymbianSyMoh
via reddit https://ift.tt/2rtOyjP
The US Is Unprepared for Election-Related Hacking in 2018
https://ift.tt/2jHXZJa
Submitted May 08, 2018 at 10:16PM by volci
via reddit https://ift.tt/2K54Rvj
https://ift.tt/2jHXZJa
Submitted May 08, 2018 at 10:16PM by volci
via reddit https://ift.tt/2K54Rvj
reddit
The US Is Unprepared for Election-Related Hacking in 2018 • r/security
1 points and 0 comments so far on reddit
NTLMv1 Multitool - Modifies NTLMv1/NTLMv1-ESS/MSCHAPv2 Hashes so they can be cracked with DES Mode 14000 in Hashcat
https://ift.tt/2FDRfUZ
Submitted May 08, 2018 at 10:58PM by TechLord2
via reddit https://ift.tt/2K0rSzt
https://ift.tt/2FDRfUZ
Submitted May 08, 2018 at 10:58PM by TechLord2
via reddit https://ift.tt/2K0rSzt
GitHub
evilmog/ntlmv1-multi
ntlmv1-multi - NTLMv1 Multitool
Any options like #VeraCrypt that don't require a GUI?
I love using VeraCrypt on various desktop systems I have.I'd like to be able to use it (or something like it) on headless devices - but it seems it requires a GUI to setup and run.What tools like it exist that are usable via the commandline?
Submitted May 08, 2018 at 11:02PM by volci
via reddit https://ift.tt/2FUWJv3
I love using VeraCrypt on various desktop systems I have.I'd like to be able to use it (or something like it) on headless devices - but it seems it requires a GUI to setup and run.What tools like it exist that are usable via the commandline?
Submitted May 08, 2018 at 11:02PM by volci
via reddit https://ift.tt/2FUWJv3
veracrypt.io
VeraCrypt - Free Open source disk encryption with strong security for the Paranoid
VeraCrypt is free open-source disk encryption software for Windows, Mac OS X and Linux. In case an attacker forces you to reveal the password, VeraCrypt provides plausible deniability. In contrast to file encryption, data encryption performed by VeraCrypt…
[Analysis + How-to] OffensiveSplunk vs Grep: Utilising Splunk on the Red Team!
https://ift.tt/2wkKLLz
Submitted May 08, 2018 at 11:59PM by vysec
via reddit https://ift.tt/2I1cjea
https://ift.tt/2wkKLLz
Submitted May 08, 2018 at 11:59PM by vysec
via reddit https://ift.tt/2I1cjea
Vincent Yiu
OffensiveSplunk vs. Grep
TLDR; Using Splunk for Offensive security data analysis has advantages over the traditional Grep when trifling through and analysing data. Why Splunk and not ELK? ELK is a fantastic open source project, and made even easier thanks to the HELK project by Cyb3rward0g.…
Hiding Metasploit Shellcode to Evade Windows Defender
https://ift.tt/2HMiKlv
Submitted May 09, 2018 at 12:27AM by PeterG45
via reddit https://ift.tt/2FW0f88
https://ift.tt/2HMiKlv
Submitted May 09, 2018 at 12:27AM by PeterG45
via reddit https://ift.tt/2FW0f88
Rapid7 Blog
Hiding Metasploit Shellcode to Evade Windows Defender
Being on the offensive side in the security field, I personally have a lot of respect for the researchers and engineers in the antivirus industry, and the companies dedicated to investing so much in them. If malware development is a cat-and-mouse game, then…