Russian Hackers Reach U.S. Utility Control Rooms, Homeland Security Officials Say
https://ift.tt/2LIwc7Q
Submitted July 24, 2018 at 09:45AM by mycall
via reddit https://ift.tt/2NFyLrJ
https://ift.tt/2LIwc7Q
Submitted July 24, 2018 at 09:45AM by mycall
via reddit https://ift.tt/2NFyLrJ
WSJ
Russian Hackers Reach U.S. Utility Control Rooms, Homeland Security Officials Say
Hackers working for Russia claimed “hundreds of victims” last year in a long-running campaign that put them inside the control rooms of U.S. electric utilities where they could have caused blackouts, federal officials said.
Red Alert 2.0: Android Trojan targets security-seekers
https://ift.tt/2A5el9I
Submitted July 24, 2018 at 12:35PM by Goovscoov
via reddit https://ift.tt/2NFcp9H
https://ift.tt/2A5el9I
Submitted July 24, 2018 at 12:35PM by Goovscoov
via reddit https://ift.tt/2NFcp9H
elfbac - runtime intent-level ABI-granular memory protection for Linux
http://elfbac.org/
Submitted July 24, 2018 at 12:57PM by wademealing
via reddit https://ift.tt/2A3ary1
http://elfbac.org/
Submitted July 24, 2018 at 12:57PM by wademealing
via reddit https://ift.tt/2A3ary1
TR | Web Application Penetration Tests With Netsparker
https://ift.tt/2mHFgim
Submitted July 24, 2018 at 04:14PM by berkdusunurx
via reddit https://ift.tt/2A6TPp6
https://ift.tt/2mHFgim
Submitted July 24, 2018 at 04:14PM by berkdusunurx
via reddit https://ift.tt/2A6TPp6
www.berkdusunur.net
TR | Netsparker ile Web Uygulama Sızma Testleri
Herkese Selamlar, Bu post Netsparker ile yapılan bir web uygulama testini simüle edip false positive oranları, optimizasyon ve diğer uy...
Compromised JavaScript Package Caught Stealing npm Credentials
https://ift.tt/2L9TdA5
Submitted July 24, 2018 at 06:13PM by vietthang0705
via reddit https://ift.tt/2uIRoEk
https://ift.tt/2L9TdA5
Submitted July 24, 2018 at 06:13PM by vietthang0705
via reddit https://ift.tt/2uIRoEk
BleepingComputer
Compromised JavaScript Package Caught Stealing npm Credentials
A hacker has gained access to a developer's npm account and injected malicious code into a popular JavaScript library, code that was designed to steal the npm credentials of users who utilize the poisoned package inside their projects.
Generate OpenConnect CSD files to bypass Cisco AnyConnect hostscan
https://ift.tt/2Ocp9pC
Submitted July 24, 2018 at 06:17PM by krieger_0x00
via reddit https://ift.tt/2v0eMwk
https://ift.tt/2Ocp9pC
Submitted July 24, 2018 at 06:17PM by krieger_0x00
via reddit https://ift.tt/2v0eMwk
reddit
r/netsec - Generate OpenConnect CSD files to bypass Cisco AnyConnect hostscan
1 vote and 0 comments so far on Reddit
Going Proactive on Security: Driving Encryption Adoption Intelligently
https://ift.tt/2JPDTaB
Submitted July 24, 2018 at 11:52PM by civicode
via reddit https://ift.tt/2ObwtBX
https://ift.tt/2JPDTaB
Submitted July 24, 2018 at 11:52PM by civicode
via reddit https://ift.tt/2ObwtBX
Cloudflare Blog
Going Proactive on Security: Driving Encryption Adoption Intelligently
It's no secret that Cloudflare operates at a huge scale. Cloudflare provides security and performance to over 9 million websites all around the world, from small businesses and WordPress blogs to Fortune 500 companies. That means one in every 10 web requests…
The IT security researchers at Israel Institute of Technology have discovered a critical security vulnerability in some implementations of the Bluetooth standard in which not all the parameters involved are appropriately validated by the cryptographic algorithm.
https://ift.tt/2uMNdaz
Submitted July 25, 2018 at 07:37AM by longevitytech
via reddit https://ift.tt/2A7AODf
https://ift.tt/2uMNdaz
Submitted July 25, 2018 at 07:37AM by longevitytech
via reddit https://ift.tt/2A7AODf
Longevity Technology
Update your devices: New Bluetooth flaw lets attackers monitor traffic
The Bluetooth flaw also opens door to a man-in-the-middle attack.
The IT security researchers at Israel Institute of Technology have discovered a critical s
The IT security researchers at Israel Institute of Technology have discovered a critical s
GhostPack: a collection of new offensive security C# tools
https://ift.tt/2mEXi4M
Submitted July 25, 2018 at 11:29AM by 0xdea
via reddit https://ift.tt/2v4KW9Z
https://ift.tt/2mEXi4M
Submitted July 25, 2018 at 11:29AM by 0xdea
via reddit https://ift.tt/2v4KW9Z
harmj0y
GhostPack
Anyone who has followed myself or my teammates at SpecterOps for a while knows that we’re fairly big fans of PowerShell. I’ve been involved in offensive PowerShell for about 4 years, @m…
Dirhunt: directory listing without bruteforce
https://ift.tt/2L9PhzC
Submitted July 25, 2018 at 11:14AM by toxicosmico
via reddit https://ift.tt/2Oeu6hG
https://ift.tt/2L9PhzC
Submitted July 25, 2018 at 11:14AM by toxicosmico
via reddit https://ift.tt/2Oeu6hG
GitHub
Nekmo/dirhunt
dirhunt - Find web directories without bruteforce
Attacking Private Networks from the Internet with DNS Rebinding
https://ift.tt/2I3OzRT
Submitted July 25, 2018 at 01:48PM by vasiliborodin
via reddit https://ift.tt/2LjCvCx
https://ift.tt/2I3OzRT
Submitted July 25, 2018 at 01:48PM by vasiliborodin
via reddit https://ift.tt/2LjCvCx
Medium
Attacking Private Networks from the Internet with DNS Rebinding
TL;DR Following the wrong link could allow remote attackers to control your WiFi router, Google Home, Roku, Sonos speakers, home…
UNDER THE HOODIE: Lessons from a Season of Penetration Testing (2018)
https://ift.tt/2LAOjzu
Submitted July 25, 2018 at 02:21PM by shleimeleh
via reddit https://ift.tt/2LzZ9WJ
https://ift.tt/2LAOjzu
Submitted July 25, 2018 at 02:21PM by shleimeleh
via reddit https://ift.tt/2LzZ9WJ
CVE-2018-14533: From writing to /tmp to a root shell on Inteno IOPSYS
https://ift.tt/2OdYAAt
Submitted July 25, 2018 at 09:32PM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2A9jg9P
https://ift.tt/2OdYAAt
Submitted July 25, 2018 at 09:32PM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2A9jg9P
neonsea.uk
From writing to /tmp to a root shell on Inteno IOPSYS
In this blog post, I describe how multiple safe features and configurations can be used to gain full filesystem read-write access - and a root shell - on dev...
Oracle Privilege Escalation via XML Deserialization
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
Syfrtext
Oracle Privilege Escalation via Deserialization
TLDR: Oracle Database is vulnerable to user privilege escalation via a java deserialization vector that bypasses built in Oracle JVM secur...
Cracking the Walls of the Safari Sandbox: Fuzzing the macOS WindowServer for Exploitable Vulnerabilities
https://ift.tt/2JVawna
Submitted July 25, 2018 at 10:25PM by gaasedelen
via reddit https://ift.tt/2mGMXoV
https://ift.tt/2JVawna
Submitted July 25, 2018 at 10:25PM by gaasedelen
via reddit https://ift.tt/2mGMXoV
Ret2 Systems Blog
Cracking the Walls of the Safari Sandbox
When exploiting real world software or devices, achieving arbitrary code execution on a system may only be the first step towards total compromise. For high ...
Oracle Privilege Escalation via XML Deserialization
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
Syfrtext
Oracle Privilege Escalation via Deserialization
TLDR: Oracle Database is vulnerable to user privilege escalation via a java deserialization vector that bypasses built in Oracle JVM secur...
Solving the Atredis BlackHat 2018 CTF Challenge
https://ift.tt/2JRLaXg
Submitted July 25, 2018 at 10:01PM by rolfr
via reddit https://ift.tt/2mNSlH7
https://ift.tt/2JRLaXg
Submitted July 25, 2018 at 10:01PM by rolfr
via reddit https://ift.tt/2mNSlH7
Möbius Strip Reverse Engineering
The Atredis BlackHat 2018 CTF Challenge
This post covers my solution to the Atredis BlackHat 2018 challenge , for which I won second place and a ticket to BlackHat. I'd like to express my gratitude to the author, the increasingly-reclusive Dionysus Blazakis, as well as Atredis for running the…
Top HTTP Security Headers and How to Deploy Them
https://ift.tt/2LP0MN2
Submitted July 25, 2018 at 11:43PM by isityoupaul
via reddit https://ift.tt/2OeiQ4Z
https://ift.tt/2LP0MN2
Submitted July 25, 2018 at 11:43PM by isityoupaul
via reddit https://ift.tt/2OeiQ4Z
Templarbit Inc.
Top HTTP Security Headers and How to Deploy Them
HTTP response headers can be used to increase the security...
Introducing BYOB (Build Your Own Botnet)
https://ift.tt/2OfqsnE
Submitted July 26, 2018 at 06:40AM by PoonSafari
via reddit https://ift.tt/2A7QNBe
https://ift.tt/2OfqsnE
Submitted July 26, 2018 at 06:40AM by PoonSafari
via reddit https://ift.tt/2A7QNBe
GitHub
malwaredllc/byob
BYOB (Build Your Own Botnet). Contribute to malwaredllc/byob development by creating an account on GitHub.
Why No HTTPS? The World's Largest Websites Not Redirecting Insecure Requests to HTTPS
https://whynohttps.com
Submitted July 26, 2018 at 02:37PM by anonyymi
via reddit https://ift.tt/2vedj5N
https://whynohttps.com
Submitted July 26, 2018 at 02:37PM by anonyymi
via reddit https://ift.tt/2vedj5N
Whynohttps
Why No HTTPS? The World's Largest Websites Not Redirecting Insecure Requests to HTTPS
With the web rapidly becoming secure by default, "Why No HTTPS?" is a who's who of the world's biggest websites globally and by country still not defaulting to HTTPS.
Evilginx 2 - Next Generation of Phishing 2FA Tokens (Tool)
https://ift.tt/2JTHIeF
Submitted July 26, 2018 at 03:31PM by kgretzky
via reddit https://ift.tt/2LrIAgf
https://ift.tt/2JTHIeF
Submitted July 26, 2018 at 03:31PM by kgretzky
via reddit https://ift.tt/2LrIAgf
reddit
r/netsec - Evilginx 2 - Next Generation of Phishing 2FA Tokens (Tool)
3 votes and 0 comments so far on Reddit