Sensitive data captured in screenshots taken by Air Canada mobile application
http://bit.ly/2TsUMNi
Submitted January 05, 2019 at 07:41PM by kahunalu
via reddit http://bit.ly/2AyLGaT
http://bit.ly/2TsUMNi
Submitted January 05, 2019 at 07:41PM by kahunalu
via reddit http://bit.ly/2AyLGaT
New Town of Salem breach - already 27% cracked hashes available publicly
http://bit.ly/2LUe4IM
Submitted January 05, 2019 at 08:54PM by s3inlc
via reddit http://bit.ly/2RayVxI
http://bit.ly/2LUe4IM
Submitted January 05, 2019 at 08:54PM by s3inlc
via reddit http://bit.ly/2RayVxI
hashes.org
Hashes.org - Leak 'Blankmediagames.com (Town of Salem)'
Hashes.org is a community recovering password from submitted hashes.
HackTheBox — Mischief Writeup
http://bit.ly/2CRZVcs
Submitted January 05, 2019 at 11:57PM by TheShahzada
via reddit http://bit.ly/2Ty4hel
http://bit.ly/2CRZVcs
Submitted January 05, 2019 at 11:57PM by TheShahzada
via reddit http://bit.ly/2Ty4hel
Medium
HackTheBox — Mischief Writeup
This is one of my favorite Machine. And it’s my first CTF & HackTheBox write-up. If you read this please give me feedback, How was the…
Tool release: Universal Phishing Reverse Proxy "Modlishka" (2FA support)
http://bit.ly/2GQxEa6
Submitted January 06, 2019 at 03:36PM by piotrd_
via reddit http://bit.ly/2C5Arqj
http://bit.ly/2GQxEa6
Submitted January 06, 2019 at 03:36PM by piotrd_
via reddit http://bit.ly/2C5Arqj
GitHub
drk1wi/Modlishka
Modlishka. Reverse Proxy. Phishing NG. Contribute to drk1wi/Modlishka development by creating an account on GitHub.
Vidar and GandCrab: stealer and ransomware combo observed in the wild - Malwarebytes Labs
http://bit.ly/2F90nob
Submitted January 07, 2019 at 12:43AM by Papopoulis
via reddit http://bit.ly/2C6UG79
http://bit.ly/2F90nob
Submitted January 07, 2019 at 12:43AM by Papopoulis
via reddit http://bit.ly/2C6UG79
Malwarebytes
Vidar and GandCrab: stealer and ransomware combo observed in the wild
Threat actors combine new stealer Vidar and GandCrab ransomware in one-two punch.
PVS-Studio and Bug Bounties on Free and Open Source Software with the total bounty amount of about €850,000
http://bit.ly/2SExfJr
Submitted January 07, 2019 at 01:23AM by Muscat1992
via reddit http://bit.ly/2TrUypC
http://bit.ly/2SExfJr
Submitted January 07, 2019 at 01:23AM by Muscat1992
via reddit http://bit.ly/2TrUypC
Medium
PVS-Studio and Bug Bounties on Free and Open Source Software
n January, the EU is launching another big hunt for bugs in open-source software projects with the total bounty amount of about €850,000…
Pass the Cookie (Cloud Pivot) - Cheat Sheet
http://bit.ly/2VxENPQ
Submitted January 07, 2019 at 08:51AM by tomiknocker24
via reddit http://bit.ly/2C8UN2a
http://bit.ly/2VxENPQ
Submitted January 07, 2019 at 08:51AM by tomiknocker24
via reddit http://bit.ly/2C8UN2a
reddit
r/netsec - Pass the Cookie (Cloud Pivot) - Cheat Sheet
7 votes and 1 comment so far on Reddit
Australian Emergency Warning System hack leads to potential phishing message broadcast to thousands
https://ab.co/2CV8raz
Submitted January 07, 2019 at 03:48PM by Sgt_Splattery_Pants
via reddit http://bit.ly/2H1iKOk
https://ab.co/2CV8raz
Submitted January 07, 2019 at 03:48PM by Sgt_Splattery_Pants
via reddit http://bit.ly/2H1iKOk
ABC News
Emergency text and email service hacked, thousands receive warning messages about their personal data
A hacker sends malicious messages via text, email, and landline to tens of thousands of people across Australia after an emergency warning alert service, used by councils, is hacked.
SlackPirate - The Slack Enumeration and Extraction Tool
http://bit.ly/2TzbDOr
Submitted January 07, 2019 at 04:30PM by emtunc
via reddit http://bit.ly/2SNbUNK
http://bit.ly/2TzbDOr
Submitted January 07, 2019 at 04:30PM by emtunc
via reddit http://bit.ly/2SNbUNK
GitHub
emtunc/SlackPirate
Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace - emtunc/SlackPirate
Adding security checks to Continous Integration pipelines
http://bit.ly/2H2u2Sv
Submitted January 07, 2019 at 09:30PM by alexksak
via reddit http://bit.ly/2FgSrRZ
http://bit.ly/2H2u2Sv
Submitted January 07, 2019 at 09:30PM by alexksak
via reddit http://bit.ly/2FgSrRZ
alxk's blog
Effective Security Pipeline
Building an effective DevSecOps pipeline to catch security issues both during development and continuously in production.
ON CALL NIGHTMARES: Episode 4 - Tanya Janca - Podcast
http://bit.ly/2QjxFD6
Submitted January 07, 2019 at 10:13PM by shehackspurple
via reddit http://bit.ly/2Rj65eE
http://bit.ly/2QjxFD6
Submitted January 07, 2019 at 10:13PM by shehackspurple
via reddit http://bit.ly/2Rj65eE
Podomatic
Episode 4 - Tanya Janca - Microsoft
There's on-call in nearly every aspect of the tech industry, in this episode we will focus on Security.
Tanya Janca is a senior cloud advocate for Microsoft, specializing in application and cloud security; evangelizing software security and advocating…
Tanya Janca is a senior cloud advocate for Microsoft, specializing in application and cloud security; evangelizing software security and advocating…
ChinaZ Revelations: Revealing ChinaZ Relationships with other Chinese Threat Actor Groups
http://bit.ly/2TvPII4
Submitted January 07, 2019 at 11:48PM by ulexec
via reddit http://bit.ly/2s9RCma
http://bit.ly/2TvPII4
Submitted January 07, 2019 at 11:48PM by ulexec
via reddit http://bit.ly/2s9RCma
reddit
r/netsec - ChinaZ Revelations: Revealing ChinaZ Relationships with other Chinese Threat Actor Groups
1 vote and 0 comments so far on Reddit
Few ideas how to maintain security while building a remote company.
http://bit.ly/2Fea2KO
Submitted January 08, 2019 at 12:29AM by ded1cated
via reddit http://bit.ly/2Fk2mGt
http://bit.ly/2Fea2KO
Submitted January 08, 2019 at 12:29AM by ded1cated
via reddit http://bit.ly/2Fk2mGt
WebARX
Remote Work Security Guide - WebARX Security Blog
Working in a remote team comes with its own challenges. To make sure your company data is protected and secure you need to know about remote work security.
XSS Account Persistence With Oauth
http://bit.ly/2RwNnPX
Submitted January 07, 2019 at 02:38PM by wifihack
via reddit http://bit.ly/2FkblaF
http://bit.ly/2RwNnPX
Submitted January 07, 2019 at 02:38PM by wifihack
via reddit http://bit.ly/2FkblaF
GitHub
dxa4481/XSSOauthPersistence
Maintaining account persistence via XSS and Oauth. Contribute to dxa4481/XSSOauthPersistence development by creating an account on GitHub.
Office 365 secure score
http://bit.ly/2RenchC
Submitted January 08, 2019 at 03:54AM by svotso
via reddit http://bit.ly/2CaIr9M
http://bit.ly/2RenchC
Submitted January 08, 2019 at 03:54AM by svotso
via reddit http://bit.ly/2CaIr9M
Docs
Office 365 Secure Score
Ever wonder how secure your organization really is in Office 365? Secure Score is here to help. Secure Score analyzes your organization's security based on your regular activities and security settings in Offic 365, and assigns a score.
Ethereum Classic (ETC) is currently being 51% attacked
http://bit.ly/2CUeYCf
Submitted January 08, 2019 at 08:36AM by sluglord14
via reddit http://bit.ly/2Ty0Y6T
http://bit.ly/2CUeYCf
Submitted January 08, 2019 at 08:36AM by sluglord14
via reddit http://bit.ly/2Ty0Y6T
The Coinbase Blog
Deep Chain Reorganization Detected on Ethereum Classic (ETC)
On 1/5/2019, Coinbase detected a deep reorg of the Ethereum Classic blockchain that included a double spend. In order to protect customer…
Buffer Overflow Practical Examples , metasploit , gdb and objdump !
http://bit.ly/2LXrq7l
Submitted January 08, 2019 at 07:18PM by Ahm3d_H3sham
via reddit http://bit.ly/2AAqpNT
http://bit.ly/2LXrq7l
Submitted January 08, 2019 at 07:18PM by Ahm3d_H3sham
via reddit http://bit.ly/2AAqpNT
0xRick Owned Root !
Buffer Overflow Practical Examples , metasploit , gdb and objdump ! - protostar stack3
Introduction Hey I’m back again with another article , today I’m going to solve protostar stack3 but this time it’s going to be a bit different , In the last two articles I solved stack0 , stack1 and stack2 and I used the source code of the binaries to identify…
Engineering Security (2014) by Peter Guttman
http://bit.ly/1itm1mL
Submitted January 08, 2019 at 10:34PM by nickpsecurity
via reddit http://bit.ly/2LWLfvy
http://bit.ly/1itm1mL
Submitted January 08, 2019 at 10:34PM by nickpsecurity
via reddit http://bit.ly/2LWLfvy
Reddit
From the netsec community on Reddit: Engineering Security (2014) by Peter Guttman
Posted by nickpsecurity - 24 votes and 3 comments
Adware Disguised as Game, TV, Remote Control Apps Infect 9 Million Google Play Users
http://bit.ly/2Tvfaxk
Submitted January 08, 2019 at 10:16PM by EvanConover
via reddit http://bit.ly/2shmGQY
http://bit.ly/2Tvfaxk
Submitted January 08, 2019 at 10:16PM by EvanConover
via reddit http://bit.ly/2shmGQY
Trendmicro
Adware Disguised as Game, TV, Remote Control Apps Infect 9 Million Google Play Users - TrendLabs Security Intelligence Blog
We recently discovered an active adware family (AndroidOS_HidenAd) disguised as 85 apps on the Google Play store with a total of 9 million downloads.
LeakLooker — Find open databases in a second
http://bit.ly/2sitr56
Submitted January 08, 2019 at 11:21PM by Mysterii8
via reddit http://bit.ly/2CbmfvW
http://bit.ly/2sitr56
Submitted January 08, 2019 at 11:21PM by Mysterii8
via reddit http://bit.ly/2CbmfvW
Medium
LeakLooker — Find open databases in a second
TL;DR With LeakLooker you can find publicly open MongoDB, CouchDB and Elasticsearch database, it also includes Kibana instances. Script…
TCP SYN Packet Denial Of Service Vulnerability on the WIFI interface of Samsung devices
http://bit.ly/2wKYQzU
Submitted January 08, 2019 at 11:20PM by hemorro
via reddit http://bit.ly/2Rknljp
http://bit.ly/2wKYQzU
Submitted January 08, 2019 at 11:20PM by hemorro
via reddit http://bit.ly/2Rknljp
reddit
r/netsec - TCP SYN Packet Denial Of Service Vulnerability on the WIFI interface of Samsung devices
1 vote and 0 comments so far on Reddit