Protecting internal applications with a SAML-aware reverse-proxy (a tutorial)
https://ift.tt/2ATQydn
Submitted August 08, 2018 at 06:53PM by sullivanmatt
via reddit https://ift.tt/2Om8fUy
https://ift.tt/2ATQydn
Submitted August 08, 2018 at 06:53PM by sullivanmatt
via reddit https://ift.tt/2Om8fUy
The Standoff at Positive Hack Days 8 conference: attack debriefing
https://ift.tt/2vQd7to
Submitted August 08, 2018 at 04:57PM by alexlash
via reddit https://ift.tt/2nrVhJP
https://ift.tt/2vQd7to
Submitted August 08, 2018 at 04:57PM by alexlash
via reddit https://ift.tt/2nrVhJP
Phdays
The Standoff at Positive Hack Days 8: attack debriefing
Positive Hack Days is a unique global event. It is the only event which brings together the elite of the hackers' world, leaders of the information security industry and representatives of the Internet community to cooperate in addressing burning information…
FakesApp: A vulnerability in WhatsApp
https://ift.tt/2vKRnzi
Submitted August 08, 2018 at 08:35PM by CosLoMogolach
via reddit https://ift.tt/2AThdH9
https://ift.tt/2vKRnzi
Submitted August 08, 2018 at 08:35PM by CosLoMogolach
via reddit https://ift.tt/2AThdH9
Check Point Research
FakesApp: A Vulnerability in WhatsApp - Check Point Research
Research By: Dikla Barda, Roman Zaikin and Oded Vanunu As of early 2018, the Facebook-owned messaging application, WhatsApp, has over 1.5 billion users with over one billion groups and 65 billion messages sent every day. With so much chatter, the potential…
New attack on WPA/WPA2 using PMKID
https://ift.tt/2nalmwL
Submitted August 08, 2018 at 09:20PM by DataPhreak
via reddit https://ift.tt/2AT5pog
https://ift.tt/2nalmwL
Submitted August 08, 2018 at 09:20PM by DataPhreak
via reddit https://ift.tt/2AT5pog
Netflix Cloud Security: Detecting Credential Compromise in AWS
https://ift.tt/2KDNVf6
Submitted August 08, 2018 at 11:18PM by Chris911
via reddit https://ift.tt/2nmczHW
https://ift.tt/2KDNVf6
Submitted August 08, 2018 at 11:18PM by Chris911
via reddit https://ift.tt/2nmczHW
Medium
Netflix Cloud Security: Detecting Credential Compromise in AWS
Will Bengtson, Netflix Security Tools and Operations
Analysis of AdKoob: an information stealer which targets Facebook ad purchase info
https://ift.tt/2vMK9uF
Submitted August 08, 2018 at 11:08PM by _toti
via reddit https://ift.tt/2OmpTaJ
https://ift.tt/2vMK9uF
Submitted August 08, 2018 at 11:08PM by _toti
via reddit https://ift.tt/2OmpTaJ
AdKoob information thief targets Facebook ad purchase info
https://ift.tt/2vMK9uF
Submitted August 09, 2018 at 01:27AM by _toti
via reddit https://ift.tt/2vPmg5v
https://ift.tt/2vMK9uF
Submitted August 09, 2018 at 01:27AM by _toti
via reddit https://ift.tt/2vPmg5v
reddit
r/netsec - AdKoob information thief targets Facebook ad purchase info
2 votes and 0 comments so far on Reddit
AutoRepeater: Automated HTTP Request Repeating With Burp Suite
https://ift.tt/2M5j7th
Submitted August 09, 2018 at 05:41AM by jm00r3
via reddit https://ift.tt/2vvnR1g
https://ift.tt/2M5j7th
Submitted August 09, 2018 at 05:41AM by jm00r3
via reddit https://ift.tt/2vvnR1g
GitHub
nccgroup/AutoRepeater
AutoRepeater - Automated HTTP Request Repeating With Burp Suite
New attack on WPA/WPA2 using PMKID
https://ift.tt/2nalmwL
Submitted August 09, 2018 at 10:12AM by Fa1l3r
via reddit https://ift.tt/2AVOn94
https://ift.tt/2nalmwL
Submitted August 09, 2018 at 10:12AM by Fa1l3r
via reddit https://ift.tt/2AVOn94
reddit
r/netsec - New attack on WPA/WPA2 using PMKID
1 vote and 0 comments so far on Reddit
Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families
https://ift.tt/2AXyMWs
Submitted August 09, 2018 at 07:05PM by 0xbaadf00dsec
via reddit https://ift.tt/2vQ3knn
https://ift.tt/2AXyMWs
Submitted August 09, 2018 at 07:05PM by 0xbaadf00dsec
via reddit https://ift.tt/2vQ3knn
Intezer
Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families - Intezer
Attacks from the online groups Lazarus, Silent Chollima, Group 123, Hidden Cobra, DarkSeoul, Blockbuster, Operation Troy, and 10 Days of Rain are believed to have come from North Korea. But how can we know with certainty? And what connection does a DDoS and…
Mapping Social Media with Facial Recognition: A New (free!) Tool for Security Professionals
https://ift.tt/2M7G3aL
Submitted August 09, 2018 at 08:50PM by greenwolf247
via reddit https://ift.tt/2vT8wH9
https://ift.tt/2M7G3aL
Submitted August 09, 2018 at 08:50PM by greenwolf247
via reddit https://ift.tt/2vT8wH9
Trustwave
Mapping Social Media with Facial Recognition: A New Tool for Penetration Testers and Red Teamers
Social Mapper is a Social Media Enumeration & Correlation Tool
ELF Binary voodoo workshop, led by the ElfMaster October 27-28 2018
https://ift.tt/2KHuCBA
Submitted August 10, 2018 at 01:01AM by ryan_elfmaster
via reddit https://ift.tt/2vSzXkb
https://ift.tt/2KHuCBA
Submitted August 10, 2018 at 01:01AM by ryan_elfmaster
via reddit https://ift.tt/2vSzXkb
Eventbrite
ELF Voodoo binary analysis workshop, brought to you by the ElfMaster & Leviathan
A 2 day instructor led workshop by the ElfMaster, that navigates the participants through the most fascinating and arcane facets of the ELF binary format. This includes but is not limited to ELF internals, relocations, dynamic linking, virus infection, anti…
Osiris dropper found using process doppelgänging
https://ift.tt/2AZbvUc
Submitted August 10, 2018 at 01:53AM by EvanConover
via reddit https://ift.tt/2vx1Crx
https://ift.tt/2AZbvUc
Submitted August 10, 2018 at 01:53AM by EvanConover
via reddit https://ift.tt/2vx1Crx
A bug that affects million users - Kaspersky VPN
https://ift.tt/2vUjegq
Submitted August 10, 2018 at 04:51AM by jdrch
via reddit https://ift.tt/2MCYcKg
https://ift.tt/2vUjegq
Submitted August 10, 2018 at 04:51AM by jdrch
via reddit https://ift.tt/2MCYcKg
www.inputzero.io
A bug that affects million users - Kaspersky VPN
Kaspersky VPN | DNS Address leak | Privacy
Practical Web Cache Poisoning
https://ift.tt/2AW2Qlg
Submitted August 10, 2018 at 05:20PM by albinowax
via reddit https://ift.tt/2OXuNMA
https://ift.tt/2AW2Qlg
Submitted August 10, 2018 at 05:20PM by albinowax
via reddit https://ift.tt/2OXuNMA
Web Security Blog | PortSwigger
Practical Web Cache Poisoning
Abstract Web cache poisoning has long been an elusive vulnerability, a 'theoretical' threat used mostly to scare developers into obediently patching issues that nobody could actually exploit. In this
How to DoH-only with Firefox
https://ift.tt/2MxgpJn
Submitted August 10, 2018 at 04:34PM by pgl
via reddit https://ift.tt/2M4t62d
https://ift.tt/2MxgpJn
Submitted August 10, 2018 at 04:34PM by pgl
via reddit https://ift.tt/2M4t62d
reddit
r/netsec - How to DoH-only with Firefox
14 votes and 6 comments so far on Reddit
Hardware backdoors in x86 CPUs - Allows ring 3 code to read and write ring 0 data
https://ift.tt/2OqE5zQ
Submitted August 10, 2018 at 07:00PM by PeterG45
via reddit https://ift.tt/2AZmpJy
https://ift.tt/2OqE5zQ
Submitted August 10, 2018 at 07:00PM by PeterG45
via reddit https://ift.tt/2AZmpJy
GitHub
xoreaxeaxeax/rosenbridge
rosenbridge - Hardware backdoors in x86 CPUs
Nominees for the 2018 Pwnie Awards
https://ift.tt/2uyiC0I
Submitted August 11, 2018 at 01:23AM by pgl
via reddit https://ift.tt/2KHSGof
https://ift.tt/2uyiC0I
Submitted August 11, 2018 at 01:23AM by pgl
via reddit https://ift.tt/2KHSGof
How I Chained 4 Bugs(Features?) into RCE on Amazon Collaboration System
https://ift.tt/2MgJtYQ
Submitted August 11, 2018 at 06:35AM by 1lastBr3ath
via reddit https://ift.tt/2vxLrKS
https://ift.tt/2MgJtYQ
Submitted August 11, 2018 at 06:35AM by 1lastBr3ath
via reddit https://ift.tt/2vxLrKS
Orange
How I Chained 4 Bugs(Features?) into RCE on Amazon Collaboration System
This is 🍊 speaking
Genesis Scripting Engine (DC26)
https://ift.tt/2vyR8b4
Submitted August 11, 2018 at 11:14PM by gen0cide_
via reddit https://ift.tt/2MdN5e7
https://ift.tt/2vyR8b4
Submitted August 11, 2018 at 11:14PM by gen0cide_
via reddit https://ift.tt/2MdN5e7
Google Docs
DEFCON26 - Genesis Scripting Engine
1 I'LL SEE YOUR MISSLE AND RAISE YOU A MIRV: AN OVERVIEW OF THE GENESIS SCRIPTING ENGINE DEFCON 26 Alex Levinson (gen0cide) Dan Borges (ahhh)
New security flaw has been detected in Intel processors - passwords can potentially be stolen
https://ift.tt/2M9ebTw
Submitted August 12, 2018 at 01:04PM by suf0x
via reddit https://ift.tt/2KKXKbp
https://ift.tt/2M9ebTw
Submitted August 12, 2018 at 01:04PM by suf0x
via reddit https://ift.tt/2KKXKbp
Digitaljournal
New security flaw with Intel processors
A new security flaw has been detected by German researchers in relation to intel. This comes on the back of earlier concerns from January and March 2018. The flaw means that passwords can potentially be stolen.