Which Vulnerabilities Are Being Exploited by Attackers
https://ift.tt/2LIbm7C
Submitted September 05, 2018 at 12:41PM by CyberBullets
via reddit https://ift.tt/2wJTh3F
https://ift.tt/2LIbm7C
Submitted September 05, 2018 at 12:41PM by CyberBullets
via reddit https://ift.tt/2wJTh3F
Rapid7 Blog
Common Vulnerabilities Exploited in Attacks and Penetration Tests
Software vulnerabilities are at the core of pen testing—and our "Under the Hoodie" report provides insights and advice one can only get in the trenches.
Company claim "New" way to access home routers and home networks
https://ift.tt/2NiGmzR
Submitted September 05, 2018 at 01:39PM by le-quack
via reddit https://ift.tt/2oEWDBc
https://ift.tt/2NiGmzR
Submitted September 05, 2018 at 01:39PM by le-quack
via reddit https://ift.tt/2oEWDBc
SureCloud
Wi-Jacking: Accessing your neighbour’s WiFi without cracking
During a recent engagement we found an interesting interaction of browser behaviour and an accepted weakness in almost every home router that could be Abusing ‘by design’ behaviour to gain the ability to hijack millions of WiFi networks through saved credentials…
Passwordless Authentication Wallet (PAW)
https://ift.tt/2M5zDVC
Submitted September 05, 2018 at 09:36PM by jrjr17
via reddit https://ift.tt/2NiUw4g
https://ift.tt/2M5zDVC
Submitted September 05, 2018 at 09:36PM by jrjr17
via reddit https://ift.tt/2NiUw4g
GitHub
jrjr/paw.js
Passwordless Authentication Wallet (PAW) is key-based authentication for the web. The library helps manage identities, their associated public/private keypairs, and signing operations in the browse...
MEGA Chrome Extension Hacked - Detailed Timeline of Events - SerHack security engineer
https://ift.tt/2NkWlgV
Submitted September 05, 2018 at 10:40PM by serhack
via reddit https://ift.tt/2wKfHlg
https://ift.tt/2NkWlgV
Submitted September 05, 2018 at 10:40PM by serhack
via reddit https://ift.tt/2wKfHlg
serhack.me
MEGA Chrome Extension Hacked - Detailed Timeline of Events - SerHack security engineer
On 4 September at 14:30 UTC, an unknown attacker managed to hack into MEGA's Google Chrome web store account and upload a malicious version 3.39.4 of an extension to the web store, according to a blog post published by the company.
Hack the Struts 2 RCE Vulnerability (CVE-2018-11776) in a live sandbox
https://ift.tt/2LLN2Sj
Submitted September 06, 2018 at 12:57AM by jrkjared3
via reddit https://ift.tt/2Q58dSJ
https://ift.tt/2LLN2Sj
Submitted September 06, 2018 at 12:57AM by jrkjared3
via reddit https://ift.tt/2Q58dSJ
HackEDU
Interactive Cybersecurity Training | HackEDU
Interactive Cybersecurity Training. HackEDU offers comprehensive online Secure Development Training for your developers, engineers, and IT personnel to assist your organization in laying a foundation of security and application vulnerability prevention, assessment…
Cisco has addressed vulnerabilities in its products
https://ift.tt/2LXgUeJ
Submitted September 06, 2018 at 02:37PM by sirpedrotavares
via reddit https://ift.tt/2NjdI1E
https://ift.tt/2LXgUeJ
Submitted September 06, 2018 at 02:37PM by sirpedrotavares
via reddit https://ift.tt/2NjdI1E
Segurança Informática
Cisco has addressed vulnerabilities in its products
Cisco addressed a dozen and high severity vulnerabilities affecting the company's RV series, SD-WAN, Umbrella, and other products.
Fallout Exploit Kit Used in Malvertising Campaign to Deliver GandCrab Ransomware
https://ift.tt/2NUoAzY
Submitted September 07, 2018 at 01:26AM by EvanConover
via reddit https://ift.tt/2CmPcZc
https://ift.tt/2NUoAzY
Submitted September 07, 2018 at 01:26AM by EvanConover
via reddit https://ift.tt/2CmPcZc
FireEye
Fallout Exploit Kit Used in Malvertising Campaign to Deliver GandCrab Ransomware « Fallout Exploit Kit Used in Malvertising Campaign…
FireEye identified a new exploit kit that was being served up as part of a malvertising campaign affecting users in Japan, Korea, the Middle East, Southern Europe, and other countries in the Asia Pacific region.
XSS using quirky implementations of ACME http-01
https://ift.tt/2M3WUXU
Submitted September 05, 2018 at 01:40PM by zulln
via reddit https://ift.tt/2NlIl6O
https://ift.tt/2M3WUXU
Submitted September 05, 2018 at 01:40PM by zulln
via reddit https://ift.tt/2NlIl6O
Detectify Labs
XSS using quirky implementations of ACME http-01
Some hosting providers implemented http-01 having one part of the challenge key reflected in the response. This resulted in a huge amount of websites being vulnerable to XSS just because of their quirky implementation of the http-01 ACME-challenge.
Public IP Addresses of Tor Sites Exposed via SSL Certificates
https://ift.tt/2PFnUiL
Submitted September 07, 2018 at 01:24PM by CyberBullets
via reddit https://ift.tt/2oMuGHZ
https://ift.tt/2PFnUiL
Submitted September 07, 2018 at 01:24PM by CyberBullets
via reddit https://ift.tt/2oMuGHZ
BleepingComputer
Public IP Addresses of Tor Sites Exposed via SSL Certificates
A security researcher has found a method that can be used to easily identify the public IP addresses of misconfigured dark web servers. While some feel that this researcher is attacking Tor or other similar networks, in reality he is exposing the pitfalls…
New persistence technique using Appx debugger - Not discovered by Autoruns
https://ift.tt/2wSIhSr
Submitted September 07, 2018 at 02:14PM by oddvarmoe
via reddit https://ift.tt/2Cqv0Wg
https://ift.tt/2wSIhSr
Submitted September 07, 2018 at 02:14PM by oddvarmoe
via reddit https://ift.tt/2Cqv0Wg
Oddvar Moe's Blog
Persistence using Universal Windows Platform apps (APPX)
TL;DR Persistence can be achieved with Appx/UWP apps using the debugger options. This technique will not be visible by Autoruns. Two different approaches exists (registry keys). Listed below are th…
Bypassing Hotstar Premium with DOM manipulation and some JavaScript
https://ift.tt/2NnqZX0
Submitted September 07, 2018 at 03:36PM by ajinabraham
via reddit https://ift.tt/2CvnVDV
https://ift.tt/2NnqZX0
Submitted September 07, 2018 at 03:36PM by ajinabraham
via reddit https://ift.tt/2CvnVDV
OpSecX
Bypassing Hotstar Premium with DOM manipulation and some JavaScript
Hotstar is a premium streaming platform like Netflix and Amazon Prime Videos. The security controls for restricting premium content were implemented at client side as frontend React JS logic. We were able to bypass these access controls and view paid premium…
Why Chrome and Firefox will soon block sites with certain SSL certificates
https://ift.tt/2wRpxCD
Submitted September 07, 2018 at 11:36PM by iamcoolc
via reddit https://ift.tt/2QaopCi
https://ift.tt/2wRpxCD
Submitted September 07, 2018 at 11:36PM by iamcoolc
via reddit https://ift.tt/2QaopCi
Templarbit Inc.
The story of why Chrome and Firefox will soon block sites with certain SSL certificates
In the near future, Google Chrome and Mozilla Firefox will...
Open Source Intelligence Gathering 201
https://ift.tt/2QbMdpr
Submitted September 08, 2018 at 06:38AM by diaanasxsw
via reddit https://ift.tt/2NsbeOr
https://ift.tt/2QbMdpr
Submitted September 08, 2018 at 06:38AM by diaanasxsw
via reddit https://ift.tt/2NsbeOr
Appsecco
Open Source Intelligence Gathering 201 (Covering 12 additional techniques)
This post is the second in a series of technical posts we are writing about Open Source Intelligence(OSINT) gathering.
British Airways hacked as data belonging up to 400,000 customers is stolen
https://ift.tt/2oLjD1t
Submitted September 08, 2018 at 11:15AM by Arnox
via reddit https://ift.tt/2wSM0PK
https://ift.tt/2oLjD1t
Submitted September 08, 2018 at 11:15AM by Arnox
via reddit https://ift.tt/2wSM0PK
#BugBounty — How Naaptol (India’s popular home shopping company) Kept their Millions of User Data at Risk!
https://ift.tt/2M9nte8
Submitted September 08, 2018 at 09:28AM by security_blogs
via reddit https://ift.tt/2oWFZNX
https://ift.tt/2M9nte8
Submitted September 08, 2018 at 09:28AM by security_blogs
via reddit https://ift.tt/2oWFZNX
Medium
#BugBounty — How Naaptol (India’s popular home shopping company) Kept their Millions of User Data at Risk!
Hi Guys,
CyStack - A web security platform that can scan vulnerabilities/malwares, monitor availability and serve as a firewall
https://app.cystack.net
Submitted September 08, 2018 at 04:49PM by everping
via reddit https://ift.tt/2QcXcil
https://app.cystack.net
Submitted September 08, 2018 at 04:49PM by everping
via reddit https://ift.tt/2QcXcil
Wi-Fi Gets More Secure: Everything You Need to Know About WPA3
https://ift.tt/2M9uHPy
Submitted September 08, 2018 at 08:37PM by yo91
via reddit https://ift.tt/2NrVivS
https://ift.tt/2M9uHPy
Submitted September 08, 2018 at 08:37PM by yo91
via reddit https://ift.tt/2NrVivS
IEEE Spectrum: Technology, Engineering, and Science News
Wi-Fi Gets More Secure: Everything You Need to Know About WPA3
WPA3, Enhanced Open, Easy Connect: The Wi-Fi Alliance's trio of new protocols explained
Detecting Hypervisor Introspection from Unprivileged Guests
https://ift.tt/2Lxg0Gp
Submitted September 08, 2018 at 09:10PM by ranok
via reddit https://ift.tt/2Md8Oi0
https://ift.tt/2Lxg0Gp
Submitted September 08, 2018 at 09:10PM by ranok
via reddit https://ift.tt/2Md8Oi0
DNS over TLS - Thoughts and Implementation
https://ift.tt/2MbrSgE
Submitted September 09, 2018 at 02:41AM by kedmi
via reddit https://ift.tt/2CwLTi4
https://ift.tt/2MbrSgE
Submitted September 09, 2018 at 02:41AM by kedmi
via reddit https://ift.tt/2CwLTi4
sagi.io
DNS over TLS - Thoughts and Implementation
A week or so I discovered that Android P has DNS over TLS
support! It piqued my curiousity - could it finally be that DNS encryption goes mainstream?
In this post we’ll survey DNS over TLS, implement a client and share some thoughts!
support! It piqued my curiousity - could it finally be that DNS encryption goes mainstream?
In this post we’ll survey DNS over TLS, implement a client and share some thoughts!
need to find location of an particular cloudflare CDN IP
https://ift.tt/2McnQ7C
Submitted September 09, 2018 at 09:24AM by funk-it-all
via reddit https://ift.tt/2Qgys8Y
https://ift.tt/2McnQ7C
Submitted September 09, 2018 at 09:24AM by funk-it-all
via reddit https://ift.tt/2Qgys8Y
reddit
r/techsupport - need to find location of an particular cloudflare CDN IP
1 vote and 5 comments so far on Reddit
"Big Star Labs" spyware campaign affects over 11,000,000 people
https://ift.tt/2NGdKxi
Submitted September 09, 2018 at 07:41PM by sacrednumber_108
via reddit https://ift.tt/2oPZJCK
https://ift.tt/2NGdKxi
Submitted September 09, 2018 at 07:41PM by sacrednumber_108
via reddit https://ift.tt/2oPZJCK
AdGuard Blog
"Big Star Labs" spyware campaign affects over 11,000,000 people
In the previous article about the Unimania spyware campaign I promised to tell you more about the privacy issues discovered during our automated scan of many Google Chrome extensions. This took me a while, and I apologize for the delay. The reason for the…