Inside and Beyond Ticketmaster: The Many Breaches of Magecart
https://ift.tt/2m5DIhO
Submitted July 10, 2018 at 11:23PM by _0x3a_
via reddit https://ift.tt/2KYRVeG
https://ift.tt/2m5DIhO
Submitted July 10, 2018 at 11:23PM by _0x3a_
via reddit https://ift.tt/2KYRVeG
RiskIQ
Inside and Beyond Ticketmaster: The Many Breaches of Magecart
The hack of Ticketmaster was not a one-off event, but part of a massive digital credit card-skimming campaign by the threat group Magecart.
Sniff-Paste: Pastebin OSINT Harvester
https://ift.tt/2L2tIkh
Submitted July 11, 2018 at 12:46AM by amusciano
via reddit https://ift.tt/2maXmJ7
https://ift.tt/2L2tIkh
Submitted July 11, 2018 at 12:46AM by amusciano
via reddit https://ift.tt/2maXmJ7
GitHub
needmorecowbell/sniff-paste
sniff-paste - Pastebin OSINT Harvester
Speculative Buffer Overflows: Attacks and Defenses
https://ift.tt/2NDFq6N
Submitted July 11, 2018 at 03:53AM by _pdp_
via reddit https://ift.tt/2u8EoHE
https://ift.tt/2NDFq6N
Submitted July 11, 2018 at 03:53AM by _pdp_
via reddit https://ift.tt/2u8EoHE
Hey Reddit, we made a free-as-in-beer Splunk alternative in Go - announcing Gravwell Community Edition
https://ift.tt/2m5w7j8
Submitted July 11, 2018 at 03:38AM by remasis
via reddit https://ift.tt/2NHJaEc
https://ift.tt/2m5w7j8
Submitted July 11, 2018 at 03:38AM by remasis
via reddit https://ift.tt/2NHJaEc
www.gravwell.io
Gravwell Community Edition
Initial Gravwell testers did a lot of home monitoring with the software and wanted to get licenses for their friends and colleagues but Gravwell was built for larger enterprises and our pricing model isn't set up for home use. All of that changes with the…
Neatly bypassing Content Security Policy. Why 'unsafe-inline' is almost always a full-fledged XSS
https://ift.tt/2KLc3S1
Submitted July 10, 2018 at 10:16PM by i_bo0om
via reddit https://ift.tt/2L8WmQW
https://ift.tt/2KLc3S1
Submitted July 10, 2018 at 10:16PM by i_bo0om
via reddit https://ift.tt/2L8WmQW
Wallarm
Neatly bypassing CSP – Wallarm
How to trick CSP in letting you run whatever you want
Shutting down the BGP Hijack Factory
https://ift.tt/2JbhaoM
Submitted July 11, 2018 at 01:14PM by lormayna
via reddit https://ift.tt/2ulTeK5
https://ift.tt/2JbhaoM
Submitted July 11, 2018 at 01:14PM by lormayna
via reddit https://ift.tt/2ulTeK5
Dyn
Shutting down the BGP Hijack Factory | Dyn Blog
It started with a lengthy email to the NANOG mailing list on 25 June 2018: independent security researcher Ronald Guilmette detailed the ...
Double Free in openslp 2.0.0, PoC DoS exploit available, patch available
https://ift.tt/2IzuOSy
Submitted July 11, 2018 at 12:45PM by magnusstubman
via reddit https://ift.tt/2KQjoQx
https://ift.tt/2IzuOSy
Submitted July 11, 2018 at 12:45PM by magnusstubman
via reddit https://ift.tt/2KQjoQx
reddit
r/netsec - Double Free in openslp 2.0.0, PoC DoS exploit available, patch available
0 votes and 0 so far on reddit
Lawsuit: Data security firm Trustwave owes $30M for 2009 data breach at Heartland Payment Systems
https://ift.tt/2m5gBUI
Submitted July 11, 2018 at 06:07PM by thms0
via reddit https://ift.tt/2N6l3Od
https://ift.tt/2m5gBUI
Submitted July 11, 2018 at 06:07PM by thms0
via reddit https://ift.tt/2N6l3Od
Cookcountyrecord
Lawsuit: Data security firm Trustwave owes $30M for 2009 data breach at Heartland Payment Systems
Two insurance companies have joined together to ask a Cook County judge to order a data security firm to pay $30 million to reimburse the insurers for funds they had to pay out to settle claims resulting from a data breach at Heartland Payment Systems.
VPNs that share your data with Google
https://ift.tt/2u903zE
Submitted July 11, 2018 at 06:58PM by FarFinding
via reddit https://ift.tt/2NF0fyy
https://ift.tt/2u903zE
Submitted July 11, 2018 at 06:58PM by FarFinding
via reddit https://ift.tt/2NF0fyy
VPNpro
These VPNs might be leaking your email messages | VPNpro
By using the wrong VPN you might risk email message leaks since Gmail may share your private mails with third parties. Find out which VPNs use Gmail.
Most readers will probably be familiar with the story of bank robber Willie Sutton who, after being nailed by the cops, was asked why he robbed the bank. His answer (undoubtedly delivered in the most deadpan voice one can imagine): "Because that's where the money is.
https://ift.tt/2uliQXJ
Submitted July 11, 2018 at 08:28PM by longevitytech
via reddit https://ift.tt/2m9gpUr
https://ift.tt/2uliQXJ
Submitted July 11, 2018 at 08:28PM by longevitytech
via reddit https://ift.tt/2m9gpUr
Longevity Technology
New Deceptive Strains Of Payroll Phishing: "Because that's where the money is…" | Longevity Technology
Most readers will probably be familiar with the story of bank robber Willie Sutton who, after being nailed by the cops, was asked why he robbed the bank. His answer (undoubtedly delivered in the most deadpan voice one can imagine): "Because that's where the…
eBPF and Analysis of the get-rekt-linux-hardened.c Exploit for CVE-2017-16995
https://ift.tt/2zqFe7y
Submitted July 11, 2018 at 02:07AM by TotallyNotJoseAltuve
via reddit https://ift.tt/2L9MgiF
https://ift.tt/2zqFe7y
Submitted July 11, 2018 at 02:07AM by TotallyNotJoseAltuve
via reddit https://ift.tt/2L9MgiF
Blogspot
eBPF and Analysis of the get-rekt-linux-hardened.c Exploit for CVE-2017-16995
CVE-2017-16695 " One of the best/worst Linux kernel vulns of all time " - @bleidl " One of the worst vulnerabilities we have seen late...
COM and the PowerThIEf
https://ift.tt/2L3Fnm5
Submitted July 11, 2018 at 08:48PM by eth_
via reddit https://ift.tt/2N6EfeL
https://ift.tt/2L3Fnm5
Submitted July 11, 2018 at 08:48PM by eth_
via reddit https://ift.tt/2N6EfeL
Nettitude Labs
COM and the PowerThIEf
Recently, Component Object Model (COM) has come back in a big way, particularly with regards to it being used for persistence and lateral movement. In this blog we will run through how it can also …
Epic Overflow in Liberapay, 21 Servers Destroyed
https://ift.tt/2ud3NQr
Submitted July 11, 2018 at 09:50PM by badbytesio
via reddit https://ift.tt/2KYI4W2
https://ift.tt/2ud3NQr
Submitted July 11, 2018 at 09:50PM by badbytesio
via reddit https://ift.tt/2KYI4W2
HackerOne
Liberapay disclosed on HackerOne: Buffer overflow
A buffer overflow condition exists when a program attempts to put more data in a buffer than it can hold or when a program attempts to put data in a memory area past a buffer. In this case, a...
WANTED: Security Engineer for InnoGames, Germany-based gaming company!
https://ift.tt/2umCu5z
Submitted July 11, 2018 at 11:54PM by InnoGamesGmbH
via reddit https://ift.tt/2KT1Tiw
https://ift.tt/2umCu5z
Submitted July 11, 2018 at 11:54PM by InnoGamesGmbH
via reddit https://ift.tt/2KT1Tiw
InnoGames
InnoGames is hiring! Senior Security Engineer
Our Security Engineering is responsible for testing and auditing the security systems of our games and infrastructure. You maintain and improve the InnoGames security guidelines and processes and work closely with other departments to improve awareness and…
Popular Software Site Hacked to Redirect Users to Keylogger, Infostealer, More
https://ift.tt/2NDozAZ
Submitted July 12, 2018 at 02:08AM by longevitytech
via reddit https://ift.tt/2Je4mOP
https://ift.tt/2NDozAZ
Submitted July 12, 2018 at 02:08AM by longevitytech
via reddit https://ift.tt/2Je4mOP
Longevity Technology
Popular Software Site Hacked to Redirect Users to Keylogger, Infostealer, More | Longevity Technology
Hackers have breached the website of VSDC, a popular company that provides free audio and video conversion and editing software. Three different incidents have been recorded during which hackers changed the download links on the VSDC website with links that…
Engineer Faces Prison for Stashing Navy Drone Secrets on His Dropbox
https://ift.tt/2L64Vf9
Submitted July 12, 2018 at 02:37AM by mynameis_neo
via reddit https://ift.tt/2NLK02y
https://ift.tt/2L64Vf9
Submitted July 12, 2018 at 02:37AM by mynameis_neo
via reddit https://ift.tt/2NLK02y
www.justice.gov
Electrical Engineer Found Guilty for Intending to Convert Trade Secrets from Defense Contractor
A federal jury in Hartford, Connecticut yesterday returned guilty verdicts against a man for his conduct related to a scheme to convert trade secrets belonging to a defense contractor based in Groton, Connecticut, related to, among others, an innovative naval…
Military Reaper Drone Documents Leaked on the Dark Web
https://ift.tt/2NFDQkM
Submitted July 12, 2018 at 02:14AM by mynameis_neo
via reddit https://ift.tt/2L4wwjW
https://ift.tt/2NFDQkM
Submitted July 12, 2018 at 02:14AM by mynameis_neo
via reddit https://ift.tt/2L4wwjW
Recorded Future
Military Reaper Drone Documents Leaked on the Dark Web
See how direct threat actor interaction allowed Insikt Group to discover MQ-9 Reaper drone documents and other leaked military information on the dark web.
IBM Study for First Time Calculates the Full Cost of "Mega Breaches," as High as $350 Million
https://ift.tt/2L6VX1g
Submitted July 12, 2018 at 02:12AM by mynameis_neo
via reddit https://ift.tt/2Jg1G2T
https://ift.tt/2L6VX1g
Submitted July 12, 2018 at 02:12AM by mynameis_neo
via reddit https://ift.tt/2Jg1G2T
IBM News Room
IBM Study: Hidden Costs of Data Breaches Increase Expenses for Businesses
IBM (NYSE: IBM) Security today announced the results of a global study examining the full financial impact of a data breach on a company's bottom line. Overall, the study found that hidden costs...
Popular Software Site Hacked to Redirect Users to Keylogger, Infostealer, More
https://ift.tt/2NDozAZ
Submitted July 12, 2018 at 02:08AM by longevitytech
via reddit https://ift.tt/2Je4mOP
https://ift.tt/2NDozAZ
Submitted July 12, 2018 at 02:08AM by longevitytech
via reddit https://ift.tt/2Je4mOP
Longevity Technology
Popular Software Site Hacked to Redirect Users to Keylogger, Infostealer, More | Longevity Technology
Hackers have breached the website of VSDC, a popular company that provides free audio and video conversion and editing software. Three different incidents have been recorded during which hackers changed the download links on the VSDC website with links that…
Mind the hackers
https://ift.tt/2L11cCR
Submitted July 12, 2018 at 07:10PM by pixelpin
via reddit https://ift.tt/2JilouT
https://ift.tt/2L11cCR
Submitted July 12, 2018 at 07:10PM by pixelpin
via reddit https://ift.tt/2JilouT
Medium
Mind the hackers:
Financial losses are reaching billions of dollars, and about 30-40% of attacks are conducted by schoolkids of 14–16 years.
A dumb security flaw let a hacker download US drone secrets
https://ift.tt/2u9O1pp
Submitted July 12, 2018 at 07:37PM by pixelpin
via reddit https://ift.tt/2magvLg
https://ift.tt/2u9O1pp
Submitted July 12, 2018 at 07:37PM by pixelpin
via reddit https://ift.tt/2magvLg
WIRED UK
A dumb security flaw let a hacker download US drone secrets
Sensitive files about the MQ-9 Reaper drone and M1 Abrams tank could be accessed because of an unpatched router. It was totally avoidable