This $39 Device Can Defeat iOS USB Restricted Mode
https://ift.tt/2Jaf5cP
Submitted July 10, 2018 at 10:28AM by numberbuzy
via reddit https://ift.tt/2zs2iD6
https://ift.tt/2Jaf5cP
Submitted July 10, 2018 at 10:28AM by numberbuzy
via reddit https://ift.tt/2zs2iD6
Patching & Unsupported Software Websites by Vendor
https://ift.tt/2J8OcGr
Submitted July 10, 2018 at 04:20PM by bonniek4t
via reddit https://ift.tt/2JeuOaO
https://ift.tt/2J8OcGr
Submitted July 10, 2018 at 04:20PM by bonniek4t
via reddit https://ift.tt/2JeuOaO
Security Exploits & News
Patching & Unsupported Software - Security Exploits & News
Looking to keep your systems up-to-date by patching and replacing unsupported software? Use this list of master links to multiple vendor sites as a guide.
Synner—A TCP SYN Client written in Rust
https://ift.tt/2ukYU7g
Submitted July 10, 2018 at 05:59PM by JDBHub
via reddit https://ift.tt/2usDMfx
https://ift.tt/2ukYU7g
Submitted July 10, 2018 at 05:59PM by JDBHub
via reddit https://ift.tt/2usDMfx
Digital Horror
Synner—A TCP SYN Client written in Rust
Synner—a TCP SYN client written in Rust.
AT&T acquires threat intelligence company AlienVault
https://ift.tt/2ugo1b6
Submitted July 10, 2018 at 07:24PM by rickyboone
via reddit https://ift.tt/2m5lD3p
https://ift.tt/2ugo1b6
Submitted July 10, 2018 at 07:24PM by rickyboone
via reddit https://ift.tt/2m5lD3p
VentureBeat
AT&T acquires threat intelligence company AlienVault
AT&T has announced plans to acquire cybersecurity company AlienVault. Terms of the deal were not disclosed. Founded in 2007, AlienVault offers a number of tools for detecting and responding to …
Beyond LLMNR/NBNS Spoofing
https://ift.tt/2J9wq5V
Submitted July 10, 2018 at 08:51PM by _pdp_
via reddit https://ift.tt/2L4itLg
https://ift.tt/2J9wq5V
Submitted July 10, 2018 at 08:51PM by _pdp_
via reddit https://ift.tt/2L4itLg
NetSPI Blog
Beyond LLMNR/NBNS Spoofing – Exploiting Active Directory-Integrated DNS
Exploiting weaknesses in name resolution protocols is a common technique for performing man-in-the-middle (MITM) attacks. Two particularly vulnerable name resolution protocols are Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBNS).…
PLEAD Downloader Used by BlackTech
https://ift.tt/2M7W7qe
Submitted July 10, 2018 at 09:21PM by EvanConover
via reddit https://ift.tt/2umLwj3
https://ift.tt/2M7W7qe
Submitted July 10, 2018 at 09:21PM by EvanConover
via reddit https://ift.tt/2umLwj3
JPCERT/CC Blog
PLEAD Downloader Used by BlackTech
In a past article, we introduced TSCookie, malware which seems to be used by BlackTech[1]. It has been revealed that this actor also uses another type of malware “PLEAD”. (“PLEAD” is referred to both as a name of malware including...
Inside and Beyond Ticketmaster: The Many Breaches of Magecart
https://ift.tt/2m5DIhO
Submitted July 10, 2018 at 11:23PM by _0x3a_
via reddit https://ift.tt/2KYRVeG
https://ift.tt/2m5DIhO
Submitted July 10, 2018 at 11:23PM by _0x3a_
via reddit https://ift.tt/2KYRVeG
RiskIQ
Inside and Beyond Ticketmaster: The Many Breaches of Magecart
The hack of Ticketmaster was not a one-off event, but part of a massive digital credit card-skimming campaign by the threat group Magecart.
Sniff-Paste: Pastebin OSINT Harvester
https://ift.tt/2L2tIkh
Submitted July 11, 2018 at 12:46AM by amusciano
via reddit https://ift.tt/2maXmJ7
https://ift.tt/2L2tIkh
Submitted July 11, 2018 at 12:46AM by amusciano
via reddit https://ift.tt/2maXmJ7
GitHub
needmorecowbell/sniff-paste
sniff-paste - Pastebin OSINT Harvester
Speculative Buffer Overflows: Attacks and Defenses
https://ift.tt/2NDFq6N
Submitted July 11, 2018 at 03:53AM by _pdp_
via reddit https://ift.tt/2u8EoHE
https://ift.tt/2NDFq6N
Submitted July 11, 2018 at 03:53AM by _pdp_
via reddit https://ift.tt/2u8EoHE
Hey Reddit, we made a free-as-in-beer Splunk alternative in Go - announcing Gravwell Community Edition
https://ift.tt/2m5w7j8
Submitted July 11, 2018 at 03:38AM by remasis
via reddit https://ift.tt/2NHJaEc
https://ift.tt/2m5w7j8
Submitted July 11, 2018 at 03:38AM by remasis
via reddit https://ift.tt/2NHJaEc
www.gravwell.io
Gravwell Community Edition
Initial Gravwell testers did a lot of home monitoring with the software and wanted to get licenses for their friends and colleagues but Gravwell was built for larger enterprises and our pricing model isn't set up for home use. All of that changes with the…
Neatly bypassing Content Security Policy. Why 'unsafe-inline' is almost always a full-fledged XSS
https://ift.tt/2KLc3S1
Submitted July 10, 2018 at 10:16PM by i_bo0om
via reddit https://ift.tt/2L8WmQW
https://ift.tt/2KLc3S1
Submitted July 10, 2018 at 10:16PM by i_bo0om
via reddit https://ift.tt/2L8WmQW
Wallarm
Neatly bypassing CSP – Wallarm
How to trick CSP in letting you run whatever you want
Shutting down the BGP Hijack Factory
https://ift.tt/2JbhaoM
Submitted July 11, 2018 at 01:14PM by lormayna
via reddit https://ift.tt/2ulTeK5
https://ift.tt/2JbhaoM
Submitted July 11, 2018 at 01:14PM by lormayna
via reddit https://ift.tt/2ulTeK5
Dyn
Shutting down the BGP Hijack Factory | Dyn Blog
It started with a lengthy email to the NANOG mailing list on 25 June 2018: independent security researcher Ronald Guilmette detailed the ...
Double Free in openslp 2.0.0, PoC DoS exploit available, patch available
https://ift.tt/2IzuOSy
Submitted July 11, 2018 at 12:45PM by magnusstubman
via reddit https://ift.tt/2KQjoQx
https://ift.tt/2IzuOSy
Submitted July 11, 2018 at 12:45PM by magnusstubman
via reddit https://ift.tt/2KQjoQx
reddit
r/netsec - Double Free in openslp 2.0.0, PoC DoS exploit available, patch available
0 votes and 0 so far on reddit
Lawsuit: Data security firm Trustwave owes $30M for 2009 data breach at Heartland Payment Systems
https://ift.tt/2m5gBUI
Submitted July 11, 2018 at 06:07PM by thms0
via reddit https://ift.tt/2N6l3Od
https://ift.tt/2m5gBUI
Submitted July 11, 2018 at 06:07PM by thms0
via reddit https://ift.tt/2N6l3Od
Cookcountyrecord
Lawsuit: Data security firm Trustwave owes $30M for 2009 data breach at Heartland Payment Systems
Two insurance companies have joined together to ask a Cook County judge to order a data security firm to pay $30 million to reimburse the insurers for funds they had to pay out to settle claims resulting from a data breach at Heartland Payment Systems.
VPNs that share your data with Google
https://ift.tt/2u903zE
Submitted July 11, 2018 at 06:58PM by FarFinding
via reddit https://ift.tt/2NF0fyy
https://ift.tt/2u903zE
Submitted July 11, 2018 at 06:58PM by FarFinding
via reddit https://ift.tt/2NF0fyy
VPNpro
These VPNs might be leaking your email messages | VPNpro
By using the wrong VPN you might risk email message leaks since Gmail may share your private mails with third parties. Find out which VPNs use Gmail.
Most readers will probably be familiar with the story of bank robber Willie Sutton who, after being nailed by the cops, was asked why he robbed the bank. His answer (undoubtedly delivered in the most deadpan voice one can imagine): "Because that's where the money is.
https://ift.tt/2uliQXJ
Submitted July 11, 2018 at 08:28PM by longevitytech
via reddit https://ift.tt/2m9gpUr
https://ift.tt/2uliQXJ
Submitted July 11, 2018 at 08:28PM by longevitytech
via reddit https://ift.tt/2m9gpUr
Longevity Technology
New Deceptive Strains Of Payroll Phishing: "Because that's where the money is…" | Longevity Technology
Most readers will probably be familiar with the story of bank robber Willie Sutton who, after being nailed by the cops, was asked why he robbed the bank. His answer (undoubtedly delivered in the most deadpan voice one can imagine): "Because that's where the…
eBPF and Analysis of the get-rekt-linux-hardened.c Exploit for CVE-2017-16995
https://ift.tt/2zqFe7y
Submitted July 11, 2018 at 02:07AM by TotallyNotJoseAltuve
via reddit https://ift.tt/2L9MgiF
https://ift.tt/2zqFe7y
Submitted July 11, 2018 at 02:07AM by TotallyNotJoseAltuve
via reddit https://ift.tt/2L9MgiF
Blogspot
eBPF and Analysis of the get-rekt-linux-hardened.c Exploit for CVE-2017-16995
CVE-2017-16695 " One of the best/worst Linux kernel vulns of all time " - @bleidl " One of the worst vulnerabilities we have seen late...
COM and the PowerThIEf
https://ift.tt/2L3Fnm5
Submitted July 11, 2018 at 08:48PM by eth_
via reddit https://ift.tt/2N6EfeL
https://ift.tt/2L3Fnm5
Submitted July 11, 2018 at 08:48PM by eth_
via reddit https://ift.tt/2N6EfeL
Nettitude Labs
COM and the PowerThIEf
Recently, Component Object Model (COM) has come back in a big way, particularly with regards to it being used for persistence and lateral movement. In this blog we will run through how it can also …
Epic Overflow in Liberapay, 21 Servers Destroyed
https://ift.tt/2ud3NQr
Submitted July 11, 2018 at 09:50PM by badbytesio
via reddit https://ift.tt/2KYI4W2
https://ift.tt/2ud3NQr
Submitted July 11, 2018 at 09:50PM by badbytesio
via reddit https://ift.tt/2KYI4W2
HackerOne
Liberapay disclosed on HackerOne: Buffer overflow
A buffer overflow condition exists when a program attempts to put more data in a buffer than it can hold or when a program attempts to put data in a memory area past a buffer. In this case, a...
WANTED: Security Engineer for InnoGames, Germany-based gaming company!
https://ift.tt/2umCu5z
Submitted July 11, 2018 at 11:54PM by InnoGamesGmbH
via reddit https://ift.tt/2KT1Tiw
https://ift.tt/2umCu5z
Submitted July 11, 2018 at 11:54PM by InnoGamesGmbH
via reddit https://ift.tt/2KT1Tiw
InnoGames
InnoGames is hiring! Senior Security Engineer
Our Security Engineering is responsible for testing and auditing the security systems of our games and infrastructure. You maintain and improve the InnoGames security guidelines and processes and work closely with other departments to improve awareness and…
Popular Software Site Hacked to Redirect Users to Keylogger, Infostealer, More
https://ift.tt/2NDozAZ
Submitted July 12, 2018 at 02:08AM by longevitytech
via reddit https://ift.tt/2Je4mOP
https://ift.tt/2NDozAZ
Submitted July 12, 2018 at 02:08AM by longevitytech
via reddit https://ift.tt/2Je4mOP
Longevity Technology
Popular Software Site Hacked to Redirect Users to Keylogger, Infostealer, More | Longevity Technology
Hackers have breached the website of VSDC, a popular company that provides free audio and video conversion and editing software. Three different incidents have been recorded during which hackers changed the download links on the VSDC website with links that…