Beers with Talos Ep28 - APT, BGP, RCEs, and an Old RAT
https://ift.tt/2rBHu7z
Submitted May 09, 2018 at 11:24PM by WorksAtCisco
via reddit https://ift.tt/2KahXrf
https://ift.tt/2rBHu7z
Submitted May 09, 2018 at 11:24PM by WorksAtCisco
via reddit https://ift.tt/2KahXrf
reddit
r/security - Beers with Talos Ep28 - APT, BGP, RCEs, and an Old RAT
1 votes and 0 so far on reddit
Microsoft Patch Tuesday for May Includes Updates for Actively-Exploited Vulnerabilities
https://ift.tt/2FYqjQ0
Submitted May 10, 2018 at 12:44AM by EvanConover
via reddit https://ift.tt/2I3FwFA
https://ift.tt/2FYqjQ0
Submitted May 10, 2018 at 12:44AM by EvanConover
via reddit https://ift.tt/2I3FwFA
Trendmicro
Microsoft Patch Tuesday for May Includes Updates for Actively-Exploited Vulnerabilities - TrendLabs Security Intelligence Blog
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
HTTPS: why the green padlock is not enough
https://ift.tt/2wt2n7V
Submitted May 10, 2018 at 02:28AM by EvanConover
via reddit https://ift.tt/2KOq9i3
https://ift.tt/2wt2n7V
Submitted May 10, 2018 at 02:28AM by EvanConover
via reddit https://ift.tt/2KOq9i3
Malwarebytes Labs
HTTPS: why the green padlock is not enough - Malwarebytes Labs
Cheap hosting deals offering free certificates have made the green padlock a less convincing sign of security. Here's what to look for to ensure a website is safe to visit.
Python exploit for Remote Code Execution on GPON home routers (CVE-2018-10562)
https://ift.tt/2rv6HOj
Submitted May 10, 2018 at 04:46AM by Prav123
via reddit https://ift.tt/2jMJOCK
https://ift.tt/2rv6HOj
Submitted May 10, 2018 at 04:46AM by Prav123
via reddit https://ift.tt/2jMJOCK
GitHub
f3d0x0/GPON
Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor (https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/), kudos for the...
Microsoft Exchange CVE-2018-8154 - Critical
https://ift.tt/2I4U3ko
Submitted May 10, 2018 at 09:39AM by mywarthog
via reddit https://ift.tt/2IcCOJF
https://ift.tt/2I4U3ko
Submitted May 10, 2018 at 09:39AM by mywarthog
via reddit https://ift.tt/2IcCOJF
reddit
Microsoft Exchange CVE-2018-8154 - Critical • r/security
1 points and 0 comments so far on reddit
Modal pop up in the ESPN app by Xfinity. I’ve never seen a modal ad in my life on this app. How did this happen? Xfinity is my ISP and I was on WiFi
https://ift.tt/2K8CFrl
Submitted May 10, 2018 at 07:57AM by PikawaNaNiboo
via reddit https://ift.tt/2IqeW8W
https://ift.tt/2K8CFrl
Submitted May 10, 2018 at 07:57AM by PikawaNaNiboo
via reddit https://ift.tt/2IqeW8W
No Win32_Process Needed – Expanding the WMI Lateral Movement Arsenal (With PoC Sources) - See Comment
https://ift.tt/2I7mmdJ
Submitted May 10, 2018 at 12:54PM by TechLord2
via reddit https://ift.tt/2jOB8M2
https://ift.tt/2I7mmdJ
Submitted May 10, 2018 at 12:54PM by TechLord2
via reddit https://ift.tt/2jOB8M2
Cybereason
No Win32_Process Needed – Expanding the WMI Lateral Movement Arsenal
Cybereason researchers discovered new lateral movement techniques discovered that abuse WMI (Windows Management Infrastructure) and provide a tool that’s a proof of concept for the techniques, showing what an attacker could potentially do with them.
Netflix and phishy
https://ift.tt/2G0TeCZ
Submitted May 10, 2018 at 02:23PM by Majortom80
via reddit https://ift.tt/2K8hntU
https://ift.tt/2G0TeCZ
Submitted May 10, 2018 at 02:23PM by Majortom80
via reddit https://ift.tt/2K8hntU
Security Boulevard
Netflix phish claims your membership is on hold - Security Boulevard
We take a look at a new Netflix phish in circulation, using the time-honored trick of claiming the recipient is about to lose access unless they hand over some personal information. Categories: Social engineering Threat analysis Tags: Appleemailemailsnetflixnetflix…
Valve has officially opened their bug bounty program
https://ift.tt/2IaMiFi
Submitted May 10, 2018 at 02:37PM by MSTRMN_
via reddit https://ift.tt/2I9kNMo
https://ift.tt/2IaMiFi
Submitted May 10, 2018 at 02:37PM by MSTRMN_
via reddit https://ift.tt/2I9kNMo
HackerOne
Vulnerability disclosure for Valve
Valve's bug bounty program and vulnerability disclosure program enlists the help of the hacker community to make Valve more secure.
Is it OK to ‘spy’ on my child with a tracking app?
https://ift.tt/2KQTx7o
Submitted May 10, 2018 at 04:02PM by Algoworks
via reddit https://ift.tt/2rwK6B2
https://ift.tt/2KQTx7o
Submitted May 10, 2018 at 04:02PM by Algoworks
via reddit https://ift.tt/2rwK6B2
The Telegraph
Is it OK to ‘spy’ on my child with a tracking app?
There’s never a ­moment when Debby Penton doesn’t know, exactly, where her 12-year-old son Ben is.
Maintain A-1 Security at Commercial Property with Automatic Gates
https://ift.tt/2wu1Q5U
Submitted May 10, 2018 at 05:22PM by accesscontrolus
via reddit https://ift.tt/2IwF1mE
https://ift.tt/2wu1Q5U
Submitted May 10, 2018 at 05:22PM by accesscontrolus
via reddit https://ift.tt/2IwF1mE
Access Control Systems in Miami, Florida
Maintain A-1 Security at Commercial Property with Automatic Gates - Access Control Systems in Miami, Florida
Having your commercial or industrial property safe and secure is one of the biggest matters of concern nowadays. In such a scenario, the increasing installment of automatic gates has become a boon for most of the businesses. A tough commercial gate not only…
Secrets of the Wiper: Inside the World's Most Destructive Malware | Threatpost
https://ift.tt/2ItTP5C
Submitted May 10, 2018 at 07:08PM by LindseyOD123
via reddit https://ift.tt/2KaP0ey
https://ift.tt/2ItTP5C
Submitted May 10, 2018 at 07:08PM by LindseyOD123
via reddit https://ift.tt/2KaP0ey
Threatpost | The first stop for security news
Secrets of the Wiper: Inside the World’s Most Destructive Malware
Shamoon, Black Energy, Destover, ExPetr/Not Petya and Olympic Destroyer: All of these wiper malwares, and others like them, have a singular purpose of destroying systems and/or data, usually causing
Details Emerging on new WPA3 protocol and how it will provide better confidentiality for wireless devices
https://ift.tt/2rznkcs
Submitted May 10, 2018 at 07:00PM by Derbel__McDillet
via reddit https://ift.tt/2K93wna
https://ift.tt/2rznkcs
Submitted May 10, 2018 at 07:00PM by Derbel__McDillet
via reddit https://ift.tt/2K93wna
SearchSecurity
How will the new WPA3 protocol strengthen password security?
The WPA3 protocol aims to better protect the next generation of Wi-Fi-enabled devices. Discover how this new Wi-Fi protocol works and how it's different from its predecessor, WPA2.
JavaScript Coinhive in Excel
https://ift.tt/2G00gYK
Submitted May 10, 2018 at 06:46PM by speckz
via reddit https://ift.tt/2rDZc8T
https://ift.tt/2G00gYK
Submitted May 10, 2018 at 06:46PM by speckz
via reddit https://ift.tt/2rDZc8T
reddit
JavaScript Coinhive in Excel • r/security
1 points and 0 comments so far on reddit
'Disappearing' Signal Messages Are Stored Indefinitely on Mac Hard Drives
https://ift.tt/2ruxPgz
Submitted May 10, 2018 at 07:28PM by GemmaJ123
via reddit https://ift.tt/2G3FU0X
https://ift.tt/2ruxPgz
Submitted May 10, 2018 at 07:28PM by GemmaJ123
via reddit https://ift.tt/2G3FU0X
Motherboard
'Disappearing' Signal Messages Are Stored Indefinitely on Mac Hard Drives
If you use the Signal desktop app, be careful with your notification settings.
CMSTP - Arbitrary DLL execution locally and remotely and SCT for AppLocker Bypass with PoC Source Code
https://ift.tt/2jMjJU3
Submitted May 10, 2018 at 09:44PM by Prav123
via reddit https://ift.tt/2G412nM
https://ift.tt/2jMjJU3
Submitted May 10, 2018 at 09:44PM by Prav123
via reddit https://ift.tt/2G412nM
Penetration Testing Lab
AppLocker Bypass – CMSTP
CMSTP is a binary which is associated with the Microsoft Connection Manager Profile Installer. It accepts INF files which can be weaponised with malicious commands in order to execute arbitrary cod…
SANS DFIR 2018 - Windows Forensics Cheatsheet - Finding Unknown Malware Step-by-Step
https://ift.tt/2KREWsn
Submitted May 10, 2018 at 09:28PM by TechLord2
via reddit https://ift.tt/2G3NKaL
https://ift.tt/2KREWsn
Submitted May 10, 2018 at 09:28PM by TechLord2
via reddit https://ift.tt/2G3NKaL
Microsoft Word Document Upload to Stored XSS: A Case Study
https://ift.tt/2I8yzPl
Submitted May 10, 2018 at 09:34PM by coalfirelabs
via reddit https://ift.tt/2jKXzS6
https://ift.tt/2I8yzPl
Submitted May 10, 2018 at 09:34PM by coalfirelabs
via reddit https://ift.tt/2jKXzS6
Coalfire.com
Coalfire - Coalfire Labs Blog
Coalfire Labs blog posts with opinions, findings and research from the technical testing of IT perspective.
Throwhammer: Rowhammer Attacks over the Network and Defenses (Rowhammering with 10G and RDMA)
https://ift.tt/2rzmqwA
Submitted May 10, 2018 at 10:25PM by Syonyk
via reddit https://ift.tt/2KRFoa2
https://ift.tt/2rzmqwA
Submitted May 10, 2018 at 10:25PM by Syonyk
via reddit https://ift.tt/2KRFoa2
NYPD tests new tool that detects credit card skimmers
https://ift.tt/2KbeVmr
Submitted May 10, 2018 at 10:26PM by EvanConover
via reddit https://ift.tt/2IxqGGL
https://ift.tt/2KbeVmr
Submitted May 10, 2018 at 10:26PM by EvanConover
via reddit https://ift.tt/2IxqGGL
AP News
NYPD tests new tool that detects credit card skimmers
GAINESVILLE, Fla. (AP) — Patrick Traynor, a cybersecurity expert, was in New York in February working with police to help identify a way to detect credit card skimmers on ATMs whe
An interesting feature in Windows 10 with encrypted ZIP files
https://ift.tt/2K7igmo
Submitted May 10, 2018 at 10:21PM by vah_13
via reddit https://ift.tt/2IulUKe
https://ift.tt/2K7igmo
Submitted May 10, 2018 at 10:21PM by vah_13
via reddit https://ift.tt/2IulUKe
GitHub
vah13/Win_ZIP_password
Python noscript to hook ZIP files passwords in Windows 10 - vah13/Win_ZIP_password