Step: A New Open Source "Swiss Army Knife" for Zero Trust Security
https://ift.tt/2vLYLum
Submitted August 08, 2018 at 03:25AM by mjmalone
via reddit https://ift.tt/2AQWh3H
https://ift.tt/2vLYLum
Submitted August 08, 2018 at 03:25AM by mjmalone
via reddit https://ift.tt/2AQWh3H
Smallstep
Step: A New Zero Trust Swiss Army Knife from Smallstep
The way most software systems are secured today is fundamentally flawed. They rely on “perimeter” security: a firewall guarding access to a protected network. Inside the perimeter traffic is mostly trusted. This paradigm relies on assumptions that nobody…
92 percent of enterprises struggle to integrate security into DevOps
https://ift.tt/2MooJed
Submitted August 08, 2018 at 03:54AM by suf0x
via reddit https://ift.tt/2MrrLi6
https://ift.tt/2MooJed
Submitted August 08, 2018 at 03:54AM by suf0x
via reddit https://ift.tt/2MrrLi6
BetaNews
92 percent of enterprises struggle to integrate security into DevOps
A large majority of organizations are struggling to implement security into their DevOps processes, despite saying they want to do so, according to a new report. The study commissioned by applicati…
snapchat-source-code-to-github
https://ift.tt/2vNYYwP
Submitted August 08, 2018 at 08:09AM by bdazle21
via reddit https://ift.tt/2OVurWW
https://ift.tt/2vNYYwP
Submitted August 08, 2018 at 08:09AM by bdazle21
via reddit https://ift.tt/2OVurWW
tech.slashdot.org
Hacker Posts Snapchat Source Code To GitHub
tacarat shares a report from The Next Web with the caption, "Oops": A GitHub with the handle i5xx, believed to be from the village of Tando Bago in Pakistan's southeastern Sindh province, created a GitHub repository called Source-Snapchat. At the time of…
Protecting internal applications with a SAML-aware reverse-proxy (a tutorial)
https://ift.tt/2ATQydn
Submitted August 08, 2018 at 06:53PM by sullivanmatt
via reddit https://ift.tt/2Om8fUy
https://ift.tt/2ATQydn
Submitted August 08, 2018 at 06:53PM by sullivanmatt
via reddit https://ift.tt/2Om8fUy
The Standoff at Positive Hack Days 8 conference: attack debriefing
https://ift.tt/2vQd7to
Submitted August 08, 2018 at 04:57PM by alexlash
via reddit https://ift.tt/2nrVhJP
https://ift.tt/2vQd7to
Submitted August 08, 2018 at 04:57PM by alexlash
via reddit https://ift.tt/2nrVhJP
Phdays
The Standoff at Positive Hack Days 8: attack debriefing
Positive Hack Days is a unique global event. It is the only event which brings together the elite of the hackers' world, leaders of the information security industry and representatives of the Internet community to cooperate in addressing burning information…
FakesApp: A vulnerability in WhatsApp
https://ift.tt/2vKRnzi
Submitted August 08, 2018 at 08:35PM by CosLoMogolach
via reddit https://ift.tt/2AThdH9
https://ift.tt/2vKRnzi
Submitted August 08, 2018 at 08:35PM by CosLoMogolach
via reddit https://ift.tt/2AThdH9
Check Point Research
FakesApp: A Vulnerability in WhatsApp - Check Point Research
Research By: Dikla Barda, Roman Zaikin and Oded Vanunu As of early 2018, the Facebook-owned messaging application, WhatsApp, has over 1.5 billion users with over one billion groups and 65 billion messages sent every day. With so much chatter, the potential…
New attack on WPA/WPA2 using PMKID
https://ift.tt/2nalmwL
Submitted August 08, 2018 at 09:20PM by DataPhreak
via reddit https://ift.tt/2AT5pog
https://ift.tt/2nalmwL
Submitted August 08, 2018 at 09:20PM by DataPhreak
via reddit https://ift.tt/2AT5pog
Netflix Cloud Security: Detecting Credential Compromise in AWS
https://ift.tt/2KDNVf6
Submitted August 08, 2018 at 11:18PM by Chris911
via reddit https://ift.tt/2nmczHW
https://ift.tt/2KDNVf6
Submitted August 08, 2018 at 11:18PM by Chris911
via reddit https://ift.tt/2nmczHW
Medium
Netflix Cloud Security: Detecting Credential Compromise in AWS
Will Bengtson, Netflix Security Tools and Operations
Analysis of AdKoob: an information stealer which targets Facebook ad purchase info
https://ift.tt/2vMK9uF
Submitted August 08, 2018 at 11:08PM by _toti
via reddit https://ift.tt/2OmpTaJ
https://ift.tt/2vMK9uF
Submitted August 08, 2018 at 11:08PM by _toti
via reddit https://ift.tt/2OmpTaJ
AdKoob information thief targets Facebook ad purchase info
https://ift.tt/2vMK9uF
Submitted August 09, 2018 at 01:27AM by _toti
via reddit https://ift.tt/2vPmg5v
https://ift.tt/2vMK9uF
Submitted August 09, 2018 at 01:27AM by _toti
via reddit https://ift.tt/2vPmg5v
reddit
r/netsec - AdKoob information thief targets Facebook ad purchase info
2 votes and 0 comments so far on Reddit
AutoRepeater: Automated HTTP Request Repeating With Burp Suite
https://ift.tt/2M5j7th
Submitted August 09, 2018 at 05:41AM by jm00r3
via reddit https://ift.tt/2vvnR1g
https://ift.tt/2M5j7th
Submitted August 09, 2018 at 05:41AM by jm00r3
via reddit https://ift.tt/2vvnR1g
GitHub
nccgroup/AutoRepeater
AutoRepeater - Automated HTTP Request Repeating With Burp Suite
New attack on WPA/WPA2 using PMKID
https://ift.tt/2nalmwL
Submitted August 09, 2018 at 10:12AM by Fa1l3r
via reddit https://ift.tt/2AVOn94
https://ift.tt/2nalmwL
Submitted August 09, 2018 at 10:12AM by Fa1l3r
via reddit https://ift.tt/2AVOn94
reddit
r/netsec - New attack on WPA/WPA2 using PMKID
1 vote and 0 comments so far on Reddit
Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families
https://ift.tt/2AXyMWs
Submitted August 09, 2018 at 07:05PM by 0xbaadf00dsec
via reddit https://ift.tt/2vQ3knn
https://ift.tt/2AXyMWs
Submitted August 09, 2018 at 07:05PM by 0xbaadf00dsec
via reddit https://ift.tt/2vQ3knn
Intezer
Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families - Intezer
Attacks from the online groups Lazarus, Silent Chollima, Group 123, Hidden Cobra, DarkSeoul, Blockbuster, Operation Troy, and 10 Days of Rain are believed to have come from North Korea. But how can we know with certainty? And what connection does a DDoS and…
Mapping Social Media with Facial Recognition: A New (free!) Tool for Security Professionals
https://ift.tt/2M7G3aL
Submitted August 09, 2018 at 08:50PM by greenwolf247
via reddit https://ift.tt/2vT8wH9
https://ift.tt/2M7G3aL
Submitted August 09, 2018 at 08:50PM by greenwolf247
via reddit https://ift.tt/2vT8wH9
Trustwave
Mapping Social Media with Facial Recognition: A New Tool for Penetration Testers and Red Teamers
Social Mapper is a Social Media Enumeration & Correlation Tool
ELF Binary voodoo workshop, led by the ElfMaster October 27-28 2018
https://ift.tt/2KHuCBA
Submitted August 10, 2018 at 01:01AM by ryan_elfmaster
via reddit https://ift.tt/2vSzXkb
https://ift.tt/2KHuCBA
Submitted August 10, 2018 at 01:01AM by ryan_elfmaster
via reddit https://ift.tt/2vSzXkb
Eventbrite
ELF Voodoo binary analysis workshop, brought to you by the ElfMaster & Leviathan
A 2 day instructor led workshop by the ElfMaster, that navigates the participants through the most fascinating and arcane facets of the ELF binary format. This includes but is not limited to ELF internals, relocations, dynamic linking, virus infection, anti…
Osiris dropper found using process doppelgänging
https://ift.tt/2AZbvUc
Submitted August 10, 2018 at 01:53AM by EvanConover
via reddit https://ift.tt/2vx1Crx
https://ift.tt/2AZbvUc
Submitted August 10, 2018 at 01:53AM by EvanConover
via reddit https://ift.tt/2vx1Crx
A bug that affects million users - Kaspersky VPN
https://ift.tt/2vUjegq
Submitted August 10, 2018 at 04:51AM by jdrch
via reddit https://ift.tt/2MCYcKg
https://ift.tt/2vUjegq
Submitted August 10, 2018 at 04:51AM by jdrch
via reddit https://ift.tt/2MCYcKg
www.inputzero.io
A bug that affects million users - Kaspersky VPN
Kaspersky VPN | DNS Address leak | Privacy
Practical Web Cache Poisoning
https://ift.tt/2AW2Qlg
Submitted August 10, 2018 at 05:20PM by albinowax
via reddit https://ift.tt/2OXuNMA
https://ift.tt/2AW2Qlg
Submitted August 10, 2018 at 05:20PM by albinowax
via reddit https://ift.tt/2OXuNMA
Web Security Blog | PortSwigger
Practical Web Cache Poisoning
Abstract Web cache poisoning has long been an elusive vulnerability, a 'theoretical' threat used mostly to scare developers into obediently patching issues that nobody could actually exploit. In this
How to DoH-only with Firefox
https://ift.tt/2MxgpJn
Submitted August 10, 2018 at 04:34PM by pgl
via reddit https://ift.tt/2M4t62d
https://ift.tt/2MxgpJn
Submitted August 10, 2018 at 04:34PM by pgl
via reddit https://ift.tt/2M4t62d
reddit
r/netsec - How to DoH-only with Firefox
14 votes and 6 comments so far on Reddit
Hardware backdoors in x86 CPUs - Allows ring 3 code to read and write ring 0 data
https://ift.tt/2OqE5zQ
Submitted August 10, 2018 at 07:00PM by PeterG45
via reddit https://ift.tt/2AZmpJy
https://ift.tt/2OqE5zQ
Submitted August 10, 2018 at 07:00PM by PeterG45
via reddit https://ift.tt/2AZmpJy
GitHub
xoreaxeaxeax/rosenbridge
rosenbridge - Hardware backdoors in x86 CPUs
Nominees for the 2018 Pwnie Awards
https://ift.tt/2uyiC0I
Submitted August 11, 2018 at 01:23AM by pgl
via reddit https://ift.tt/2KHSGof
https://ift.tt/2uyiC0I
Submitted August 11, 2018 at 01:23AM by pgl
via reddit https://ift.tt/2KHSGof