HashWick V8 Vulnerability
https://ift.tt/2ByBdPA
Submitted September 20, 2018 at 03:35PM by fagnerbrack
via reddit https://ift.tt/2xE6FXI
https://ift.tt/2ByBdPA
Submitted September 20, 2018 at 03:35PM by fagnerbrack
via reddit https://ift.tt/2xE6FXI
reddit
r/netsec - HashWick V8 Vulnerability
2 votes and 0 comments so far on Reddit
Researching The FAX Machine Attack Surface
https://ift.tt/2xB8OU1
Submitted September 20, 2018 at 05:04PM by nibblesec
via reddit https://ift.tt/2QLXs8o
https://ift.tt/2xB8OU1
Submitted September 20, 2018 at 05:04PM by nibblesec
via reddit https://ift.tt/2QLXs8o
X41 D-SEC GmbH
Researching The FAX Machine Attack Surface
X41 Researched into the security of FAX machines and identified remotely exploitable vulnerabilities.
The CLIP OS Project - a secure multi-level OS
https://clip-os.org/en/
Submitted September 20, 2018 at 06:06PM by guedou
via reddit https://ift.tt/2xzOiTz
https://clip-os.org/en/
Submitted September 20, 2018 at 06:06PM by guedou
via reddit https://ift.tt/2xzOiTz
reddit
r/netsec - The CLIP OS Project - a secure multi-level OS
1 vote and 0 comments so far on Reddit
NCIX Data breach (EVERYTHING)
https://ift.tt/2MQsVmq
Submitted September 20, 2018 at 10:27PM by heishnod
via reddit https://ift.tt/2OF1GNC
https://ift.tt/2MQsVmq
Submitted September 20, 2018 at 10:27PM by heishnod
via reddit https://ift.tt/2OF1GNC
Privacyfly
NCIX DATABREACH
The following editorial will take you inside the dark world of data brokering, as we expose the backroom deals in which fifteen years of customer data from defunct Canadian retailer NCIX were sold.
Increased Use of a Delphi Packer to Evade Malware Classification
https://ift.tt/2xplCgQ
Submitted September 21, 2018 at 12:50AM by EvanConover
via reddit https://ift.tt/2PViVun
https://ift.tt/2xplCgQ
Submitted September 21, 2018 at 12:50AM by EvanConover
via reddit https://ift.tt/2PViVun
FireEye
Increased Use of a Delphi Packer to Evade Malware Classification « Increased Use of a Delphi Packer to Evade Malware Classification
The concept of "packing" or "crypting" a malicious program is widely popular among threat actors looking to bypass or defeat analysis by static and dynamic analysis tools.
Mass WordPress compromises redirect to tech support scams
https://ift.tt/2xpIv3S
Submitted September 21, 2018 at 01:11AM by EvanConover
via reddit https://ift.tt/2DjbfRc
https://ift.tt/2xpIv3S
Submitted September 21, 2018 at 01:11AM by EvanConover
via reddit https://ift.tt/2DjbfRc
Malwarebytes
Mass WordPress compromises redirect to tech support scams
Thousands of WordPress sites have been injected with the same malicious redirection. We review the infection details and the malicious traffic leading to browser lockers.
Is serverless insecure? Let's find out...
https://ift.tt/2nOIYHF
Submitted September 21, 2018 at 04:03AM by sprkyco
via reddit https://ift.tt/2QLiUds
https://ift.tt/2nOIYHF
Submitted September 21, 2018 at 04:03AM by sprkyco
via reddit https://ift.tt/2QLiUds
NSS Labs lawsuit takes aim at CrowdStrike, Symantec and ESET
https://ift.tt/2xni66q
Submitted September 21, 2018 at 06:00AM by Taur3an
via reddit https://ift.tt/2NrpCHQ
https://ift.tt/2xni66q
Submitted September 21, 2018 at 06:00AM by Taur3an
via reddit https://ift.tt/2NrpCHQ
SearchSecurity
NSS Labs lawsuit takes aim at CrowdStrike, Symantec and ESET
An NSS Labs lawsuit accused major antimalware vendors, including CrowdStrike and Symantec, as well as the Anti-Malware Testing Standards Organization, of unfair play.
Understanding PGP by Simulating it
https://ift.tt/2OH9C0O
Submitted September 21, 2018 at 10:57AM by tejaas_solanki
via reddit https://ift.tt/2O4zBC6
https://ift.tt/2OH9C0O
Submitted September 21, 2018 at 10:57AM by tejaas_solanki
via reddit https://ift.tt/2O4zBC6
Medium
Understanding PGP by Simulating it!
As the name suggests, PGP, the acronym for Pretty Good Privacy is an encryption program that actually provides good privacy. The “pretty…
Introducing SharpSploit: A C# Post-Exploitation Library
https://ift.tt/2xz2Na4
Submitted September 21, 2018 at 11:53AM by 0xdea
via reddit https://ift.tt/2QM8LNR
https://ift.tt/2xz2Na4
Submitted September 21, 2018 at 11:53AM by 0xdea
via reddit https://ift.tt/2QM8LNR
Posts By SpecterOps Team Members
Introducing SharpSploit: A C# Post-Exploitation Library
Today, I’m releasing SharpSploit, the first in a series of offensive C# tools I have been writing over the past several months.
Cloudflare adopts Google's Roughtime protocol to make certificate expiration checks more secure
https://ift.tt/2QNUWhK
Submitted September 21, 2018 at 07:13PM by Natanael_L
via reddit https://ift.tt/2popvye
https://ift.tt/2QNUWhK
Submitted September 21, 2018 at 07:13PM by Natanael_L
via reddit https://ift.tt/2popvye
The Cloudflare Blog
Roughtime: Securing Time with Digital Signatures
When you visit a secure website, it offers you a TLS certificate that asserts its identity. Every certificate has an expiration date, and when it’s passed due, it is no longer valid.
(0Day) Microsoft Windows Jet Database Engine Out-Of-Bounds Write Remote Code Execution Vulnerability
https://ift.tt/2pr1bf1
Submitted September 21, 2018 at 08:16PM by -vozER
via reddit https://ift.tt/2DjoscD
https://ift.tt/2pr1bf1
Submitted September 21, 2018 at 08:16PM by -vozER
via reddit https://ift.tt/2DjoscD
Zerodayinitiative
thezdi
Virobot Ransomware with Botnet Capability Breaks Through
https://ift.tt/2xDUNEU
Submitted September 21, 2018 at 09:02PM by EvanConover
via reddit https://ift.tt/2O6pRrm
https://ift.tt/2xDUNEU
Submitted September 21, 2018 at 09:02PM by EvanConover
via reddit https://ift.tt/2O6pRrm
Trendmicro
Virobot Ransomware with Botnet Capability Breaks Through - TrendLabs Security Intelligence Blog
We have recently observed the Virobot ransomware (detected as RANSOM_VIBOROT.THIAHAH) which has botnet capabilities, affecting users in the United States.
EE 4GEE Mini Local Privilege Escalation Vulnerability (CVE-2018-14327)
https://ift.tt/2xGbsrp
Submitted September 21, 2018 at 09:22PM by EvanConover
via reddit https://ift.tt/2NZGZyU
https://ift.tt/2xGbsrp
Submitted September 21, 2018 at 09:22PM by EvanConover
via reddit https://ift.tt/2NZGZyU
🔐Blog of Osanda
EE 4GEE Mini Local Privilege Escalation Vulnerability (CVE-2018-14327)
I brought a 4G modem from EE to browser internet when I’m outside. It’s a portable 4G WiFi mobile broadband modem as seen below. You can find this 4G modem from these websites: One day I had a look…
Another XSS in Google Colaboratory
https://ift.tt/2pulPeo
Submitted September 21, 2018 at 12:29PM by 6793746895F62C0E447A
via reddit https://ift.tt/2MSBoFH
https://ift.tt/2pulPeo
Submitted September 21, 2018 at 12:29PM by 6793746895F62C0E447A
via reddit https://ift.tt/2MSBoFH
blog.bentkowski.info
Another XSS in Google Colaboratory
Three months ago, I wrote a blog post in which I described an XSS I found in Google Colaboratory . In this post, I will expand the topic and...
Speeding up AFL's QEMU mode by 1.5x-3x through TCG instrumentation and block chaining
https://ift.tt/2PRLysf
Submitted September 21, 2018 at 09:17PM by anbiondo
via reddit https://ift.tt/2OHIC1g
https://ift.tt/2PRLysf
Submitted September 21, 2018 at 09:17PM by anbiondo
via reddit https://ift.tt/2OHIC1g
0x41414141 in ?? ()
Improving AFL’s QEMU mode performance
Block chaining to the rescue.
Static Analysis of Client-Side JavaScript for pen testers and bug bounty hunters
https://ift.tt/2I5Fytc
Submitted September 22, 2018 at 11:42AM by diaanasxsw
via reddit https://ift.tt/2OKDJEu
https://ift.tt/2I5Fytc
Submitted September 22, 2018 at 11:42AM by diaanasxsw
via reddit https://ift.tt/2OKDJEu
Appsecco
Static Analysis of Client-Side JavaScript for pen testers and bug bounty hunters
JavaScript has become one of the most ubiquitous technologies in the modern web browsers. Applications built using client-side JavaScript…
There is no longer any such thing as Computer Security
https://ift.tt/2QOPDyM
Submitted September 22, 2018 at 06:28PM by PRIVACYx05i4shUl
via reddit https://ift.tt/2O14hV6
https://ift.tt/2QOPDyM
Submitted September 22, 2018 at 06:28PM by PRIVACYx05i4shUl
via reddit https://ift.tt/2O14hV6
Codinghorror
There is no longer any such thing as Computer Security
Remember "cybersecurity"?
GPG Suite Now Charging Subnoscription Fee
https://ift.tt/2Nx4kZd
Submitted September 22, 2018 at 08:17PM by MTUhusky
via reddit https://ift.tt/2xDRdvx
https://ift.tt/2Nx4kZd
Submitted September 22, 2018 at 08:17PM by MTUhusky
via reddit https://ift.tt/2xDRdvx
gpgtools.org
GPG Suite
Everything you need to get started with secure communication and encrypting files in one simple package leveraging the power of OpenPGP/GPG
Introducing the Librem Key
https://ift.tt/2MPTkRs
Submitted September 22, 2018 at 08:55PM by PRIVACYx05i4shUl
via reddit https://ift.tt/2xIGdw1
https://ift.tt/2MPTkRs
Submitted September 22, 2018 at 08:55PM by PRIVACYx05i4shUl
via reddit https://ift.tt/2xIGdw1
reddit
r/netsec - Introducing the Librem Key
4 votes and 0 comments so far on Reddit
GPGTools GPGSuite Update 2018.4 Adds Fee for GPGMail
https://ift.tt/2xGKS1f
Submitted September 22, 2018 at 09:45PM by MTUhusky
via reddit https://ift.tt/2QS2LmQ
https://ift.tt/2xGKS1f
Submitted September 22, 2018 at 09:45PM by MTUhusky
via reddit https://ift.tt/2QS2LmQ
Tenderapp
Support Plan / Feedback / Discussion Area - GPGTools Support
GPGTools, GPGMail, Support, Customer, Issues, Troubleshooting, Problem, GPGServices, GPG Keychain Access, GKA, MacGPG, MacGPG2, GPGPreferences, MacGPG1, Mobile OpenPGP