Google reportedly allows outside app developers to read people's Gmail
https://ift.tt/2KIXLkg
Submitted July 03, 2018 at 12:25AM by mynameis_neo
via reddit https://ift.tt/2Kr39Jo
https://ift.tt/2KIXLkg
Submitted July 03, 2018 at 12:25AM by mynameis_neo
via reddit https://ift.tt/2Kr39Jo
Business Insider
Google reportedly allows outside app developers to read people's Gmails
The Wall Street Journal reported Monday that hundreds of outside software developers are scanning the inboxes of millions of Gmail users. Google "does little to police those developers," the paper reported.
SaaS Revolution podcast featuring co-founder Bjoern on founding a CyberSec company in Silicon Valley
https://ift.tt/2z4e2vr
Submitted July 03, 2018 at 01:12AM by isityoupaul
via reddit https://ift.tt/2MF9wFG
https://ift.tt/2z4e2vr
Submitted July 03, 2018 at 01:12AM by isityoupaul
via reddit https://ift.tt/2MF9wFG
Templarbit Inc.
The SaaS Revolution Show with Bjoern
Recently, Alex Theuma, from the SaaS Revolution Show, sat...
Dangerous Methods - Burp Suite extension for finding dangerous JS methods
https://ift.tt/2Nj4lMD
Submitted July 03, 2018 at 03:13AM by IamJacksLackOf
via reddit https://ift.tt/2KJy8MZ
https://ift.tt/2Nj4lMD
Submitted July 03, 2018 at 03:13AM by IamJacksLackOf
via reddit https://ift.tt/2KJy8MZ
GitLab
TechnoTame / dangerous-methods
OSX.Dummy - new Mac malware targets the cryptocurrency community
https://ift.tt/2lNE7oX
Submitted July 03, 2018 at 03:01AM by EvanConover
via reddit https://ift.tt/2zaPUYa
https://ift.tt/2lNE7oX
Submitted July 03, 2018 at 03:01AM by EvanConover
via reddit https://ift.tt/2zaPUYa
Objective-See
OSX.Dummy
new mac malware targets the cryptocurrency community
Samsung's texting app is randomly sending messages and photos
https://ift.tt/2lQSvNi
Submitted July 03, 2018 at 04:39AM by k3170makan
via reddit https://ift.tt/2NeyGfn
https://ift.tt/2lQSvNi
Submitted July 03, 2018 at 04:39AM by k3170makan
via reddit https://ift.tt/2NeyGfn
Engadget
Samsung's texting app is randomly sending messages and photos
Samsung phone owners are reporting that the stock Messages app is randomly sending texts and photos to other people.
"Stylish" browser extension steals all your internet history
https://ift.tt/2KDf1Hv
Submitted July 03, 2018 at 10:45AM by highjeep
via reddit https://ift.tt/2IOTLcH
https://ift.tt/2KDf1Hv
Submitted July 03, 2018 at 10:45AM by highjeep
via reddit https://ift.tt/2IOTLcH
Robert Heaton
"Stylish" browser extension steals all your internet history | Robert Heaton
Before it became a covert surveillance tool disguised as an outstanding browser extension, Stylish really was an outstanding browser extension. It bestowed upon its users nothing less than the power to change the appearance of the internet. Its extensive…
Bypassing Web-Application Firewalls by abusing SSL/TLS
https://ift.tt/2KFkP3a
Submitted July 03, 2018 at 12:14PM by Sjoerder
via reddit https://ift.tt/2MHE3T2
https://ift.tt/2KFkP3a
Submitted July 03, 2018 at 12:14PM by Sjoerder
via reddit https://ift.tt/2MHE3T2
0x09AL Security blog
Bypassing Web-Application Firewalls by abusing SSL/TLS
Introduction
Exfiltrating credentials via PAM backdoors & DNS requests
https://ift.tt/2tIAyos
Submitted July 03, 2018 at 02:30PM by acidtrip1337
via reddit https://ift.tt/2tQtnKZ
https://ift.tt/2tIAyos
Submitted July 03, 2018 at 02:30PM by acidtrip1337
via reddit https://ift.tt/2tQtnKZ
x-c3ll.github.io
Exfiltrating credentials via PAM backdoors & DNS requests ::
DoomsDay Vault
DoomsDay Vault
Denoscription of how to backdoor PAM and exfiltrate credentials via DNS requests. Capture credentials FTW!
A Brief Look At North Korean Cryptography
https://ift.tt/2lNxUtg
Submitted July 03, 2018 at 05:52PM by not_2sec4u
via reddit https://ift.tt/2z2101k
https://ift.tt/2lNxUtg
Submitted July 03, 2018 at 05:52PM by not_2sec4u
via reddit https://ift.tt/2z2101k
Kryptoslogic
A Brief Look At North Korean Cryptography
With much attention lately over North Korea and its evolving cybersecurity capabilities, we thought to cover a somewhat related topic. A couple of years back...
Inside the Octagon - Analyzing System Guard Runtime Attestation [PDF] by @aionescu & @dwizzzleMSFT
https://ift.tt/2KF7wzL
Submitted July 03, 2018 at 08:19PM by 2xyo
via reddit https://ift.tt/2Nny6Mv
https://ift.tt/2KF7wzL
Submitted July 03, 2018 at 08:19PM by 2xyo
via reddit https://ift.tt/2Nny6Mv
XSS in Google Colaboratory + CSP bypass
https://ift.tt/2MGvHLx
Submitted July 03, 2018 at 11:07PM by overflowingInt
via reddit https://ift.tt/2KuK3SI
https://ift.tt/2MGvHLx
Submitted July 03, 2018 at 11:07PM by overflowingInt
via reddit https://ift.tt/2KuK3SI
blog.bentkowski.info
XSS in Google Colaboratory + CSP bypass
In this note, I describe an interesting XSS that I found in February 2018 in one of the Google applications. I won't only show directly wher...
Obfuscated Coinhive shortlink reveals larger mining operation
https://ift.tt/2u1rISd
Submitted July 04, 2018 at 12:05AM by EvanConover
via reddit https://ift.tt/2KO3sd6
https://ift.tt/2u1rISd
Submitted July 04, 2018 at 12:05AM by EvanConover
via reddit https://ift.tt/2KO3sd6
Malwarebytes Labs
Obfuscated Coinhive shortlink reveals larger mining operation - Malwarebytes Labs
A web miner injected into compromised sites is just the tip of the iceberg for an infrastructure hosting malicious Windows and Linux coin miners.
ZTE Replaces Board with Essentially the Same Board
https://ift.tt/2MAjYy1
Submitted July 03, 2018 at 11:54PM by PrimeMover17
via reddit https://ift.tt/2No3fze
https://ift.tt/2MAjYy1
Submitted July 03, 2018 at 11:54PM by PrimeMover17
via reddit https://ift.tt/2No3fze
WSJ
ZTE Replaces Board, but Power Structure Remains
Fourteen directors resigned from ZTE’s board as the Chinese telecom aims to get out from under U.S. penalties, but the changes may be less sweeping than they appear.
Two Zero-Day Exploits Found After Someone Uploaded 'Unarmed' PoC to VirusTotal
https://ift.tt/2KJq3HK
Submitted July 04, 2018 at 02:11AM by _vavkamil_
via reddit https://ift.tt/2tYaIfi
https://ift.tt/2KJq3HK
Submitted July 04, 2018 at 02:11AM by _vavkamil_
via reddit https://ift.tt/2tYaIfi
Microsoft
Taking apart a double zero-day sample discovered in joint hunt with ESET
In late March 2018, I analyzed an interesting PDF sample found by ESET senior malware researcher Anton Cherpanov. The sample was initially reported to Microsoft as a potential exploit for an unknown Windows kernel vulnerability. During my investigation in…
Local root jailbreak, authorization bypass & privilege escalation security vulnerabilities in all ADB broadband router / gateways / modems
https://ift.tt/2NoXvVL
Submitted July 04, 2018 at 02:53PM by 0x9000
via reddit https://ift.tt/2IRbPmH
https://ift.tt/2NoXvVL
Submitted July 04, 2018 at 02:53PM by 0x9000
via reddit https://ift.tt/2IRbPmH
Reading hotel key cards with a credit card magstripe reader
https://ift.tt/2z92MxT
Submitted July 04, 2018 at 03:28PM by polar
via reddit https://ift.tt/2KNyJx1
https://ift.tt/2z92MxT
Submitted July 04, 2018 at 03:28PM by polar
via reddit https://ift.tt/2KNyJx1
Portcullis Labs
Reading hotel key cards with a credit card magstripe reader - Portcullis Labs
Compiler-assisted Code Randomization – Kevin's Attic for Security Research
https://ift.tt/2u3cETX
Submitted July 04, 2018 at 04:15PM by mttd
via reddit https://ift.tt/2MO86bP
https://ift.tt/2u3cETX
Submitted July 04, 2018 at 04:15PM by mttd
via reddit https://ift.tt/2MO86bP
Kevin's Attic for Security Research
Compiler-assisted Code Randomization
I. MotivationII. Compiler-assisted Code Randomization (CCR) OverviewIII. Identifying Essential Information for RandomizationIV. Obtaining Metadata from the LLVM BackendV. Metadata Definition with G…
Top hackers' softwares you gotta get familiar with.
https://ift.tt/2lIFViV
Submitted July 04, 2018 at 07:27PM by HouseJustice
via reddit https://ift.tt/2ISuYEx
https://ift.tt/2lIFViV
Submitted July 04, 2018 at 07:27PM by HouseJustice
via reddit https://ift.tt/2ISuYEx
Spyhood
7 top Hacker tools and software
The top hacker tools and software gadgets for 2018...The keyllama hacking tool is the best undetectable softw..
All ways lead to Rome ! Remote Code Execution on MicroFocus Secure Messaging Gateway
https://ift.tt/2K9rKkW
Submitted July 04, 2018 at 10:26PM by wtfse
via reddit https://ift.tt/2IRhbOT
https://ift.tt/2K9rKkW
Submitted July 04, 2018 at 10:26PM by wtfse
via reddit https://ift.tt/2IRhbOT
Pentest Blog
Unexpected Journey #6 – All ways lead to Rome ! Remote Code Execution on MicroFocus Secure Messaging Gateway
It has been a quite while since I haven’t released a new part of unexpected journey article serie. Particularly this small 0-day research project has been certainly didactic to me. Thus, I’ve decided to write down the process of achieving remote code execution…
Profiling China based employees or organizations with a China presence
https://ift.tt/2Ky4a2e
Submitted July 05, 2018 at 04:41PM by vysec
via reddit https://ift.tt/2NmP6lX
https://ift.tt/2Ky4a2e
Submitted July 05, 2018 at 04:41PM by vysec
via reddit https://ift.tt/2NmP6lX
Vincent Yiu
MaiInt - Profiling China based Employees
Introduction MaiInt is a tool to perform OSINT, gather employee names and predict e-mail addresses for China based companies. The output is in HTML and CSV format. The Challenge The primary issue we’re trying to solve is that there are no good tools to enumerate…
How We Discovered a Virus Infecting Tens of Thousands of Fortnite Players
https://ift.tt/2ILYw6L
Submitted July 05, 2018 at 06:59PM by Bonfeu
via reddit https://ift.tt/2z9BqYw
https://ift.tt/2ILYw6L
Submitted July 05, 2018 at 06:59PM by Bonfeu
via reddit https://ift.tt/2z9BqYw
Rainway
How We Discovered a Virus Infecting Tens of Thousands of Fortnite Players | Rainway
Fortnite is the most popular game right now; it’s a genuine cultural phenomenon that is sweeping the world. Sadly, where there is a popular channel there will always be malicious actors. Today we want to diverge from our usual tech and vision blogs and share…