Obfuscated javanoscript, scam emails, and American Express
http://bit.ly/2Tu9Pab
Submitted February 04, 2019 at 09:04AM by JonLuca
via reddit http://bit.ly/2WFf0G0
http://bit.ly/2Tu9Pab
Submitted February 04, 2019 at 09:04AM by JonLuca
via reddit http://bit.ly/2WFf0G0
JonLuca’s Blog
Scams, American Express, and obfuscated Javanoscript
Whenever I get a scam email that manages to circumvent both my and gmail’s email filters, I like to take a closer look at how it did it and what it’s trying to accomplish.
Alternative job board dedicated to InfoSec jobs
http://bit.ly/2Tom4VJ
Submitted February 04, 2019 at 01:39PM by infosec-jobs
via reddit http://bit.ly/2tcTqeN
http://bit.ly/2Tom4VJ
Submitted February 04, 2019 at 01:39PM by infosec-jobs
via reddit http://bit.ly/2tcTqeN
infosec-jobs.com
Your prime source of cyber security jobs | infosec-jobs.com
infosec-jobs.com is the prime InfoSec job board serving the cyber security community with fresh career opportunities and a platform to attract great talent
My Forensic and Incident Response Note Taking Methodology
http://bit.ly/2DRz5Bw
Submitted February 04, 2019 at 01:35PM by skygrip
via reddit http://bit.ly/2HQ42dF
http://bit.ly/2DRz5Bw
Submitted February 04, 2019 at 01:35PM by skygrip
via reddit http://bit.ly/2HQ42dF
IronMoon
My Forensic and Incident Response Note Taking Methodology
Why You Should Take Good Notes During Forensic and Incident Response
Even if you use HTTPS, your browsing habits can still be tracked by observing your DNS queries.
http://bit.ly/2GnhG5m
Submitted February 04, 2019 at 03:39PM by judit_k
via reddit http://bit.ly/2DSz54m
http://bit.ly/2GnhG5m
Submitted February 04, 2019 at 03:39PM by judit_k
via reddit http://bit.ly/2DSz54m
Avatao
How to avoid issues with DNS security and privacy - Avatao
DNS security & DNS privacy: problems that can arise from the lack of these attributes & tips on how to remedy them.
Exploiting SSRF in AWS Elastic Beanstalk - NotSoSecure
http://bit.ly/2MNwefU
Submitted February 04, 2019 at 05:49PM by anantshri
via reddit http://bit.ly/2WOcduq
http://bit.ly/2MNwefU
Submitted February 04, 2019 at 05:49PM by anantshri
via reddit http://bit.ly/2WOcduq
NotSoSecure
Exploiting SSRF in AWS Elastic Beanstalk - NotSoSecure
Checkout how an ssrf vulnerability can lead to a complete compromise of your aws infrastructure hosted using the elastic beanstalk service
Multiple Vulnerabilities Found in Mobile Device Management Software
http://bit.ly/2RyrD21
Submitted February 04, 2019 at 04:09PM by digitalinterruption
via reddit http://bit.ly/2t29rnw
http://bit.ly/2RyrD21
Submitted February 04, 2019 at 04:09PM by digitalinterruption
via reddit http://bit.ly/2t29rnw
Digitalinterruption
Multiple Vulnerabilities Found in Mobile Device Management Software | Digital Interruption Research
A few months ago during a penetration test, we stumbled upon a Windows based mobile device management [MDM] system named SureMDM. MDM systems aim to provide ...
GDPR Compliance: How Continuous Vulnerability Scanning is Key
http://bit.ly/2FX9UQv
Submitted February 04, 2019 at 07:48PM by nandodelgado
via reddit http://bit.ly/2Bi5gbS
http://bit.ly/2FX9UQv
Submitted February 04, 2019 at 07:48PM by nandodelgado
via reddit http://bit.ly/2Bi5gbS
Hackmetrix Blog
GDPR Compliance: How Continuous Vulnerability Scanning is Key - Hackmetrix Blog
Even months after interest in GDPR compliance peaked, some companies are struggling to make sure they comply with this new set of regulations aimed at protecting the privacy and security of European citizens. The regulation applies to businesses anywhere…
A crypto exchange can't repay $190 million it owes customers because its CEO died with the only password
http://bit.ly/2SbaAbu
Submitted February 04, 2019 at 10:53PM by wavetranscender
via reddit http://bit.ly/2UDspMY
http://bit.ly/2SbaAbu
Submitted February 04, 2019 at 10:53PM by wavetranscender
via reddit http://bit.ly/2UDspMY
Business Insider Nederland
A crypto exchange can't repay $190 million it owes customers because its CEO died with the only password
QuadrigaCX's founder and CEO, Gerald Cotten, who reportedly died in December, is believed to have had the sole ability to access the crypto exchange.
TEMPEST - We see your secrets
http://bit.ly/2GbbsGJ
Submitted February 04, 2019 at 11:35PM by digitalinterruption
via reddit http://bit.ly/2UDVB6E
http://bit.ly/2GbbsGJ
Submitted February 04, 2019 at 11:35PM by digitalinterruption
via reddit http://bit.ly/2UDVB6E
Digital Interruption
TEMPEST - We see your secrets | Digital Interruption
In this post we discuss how practical TEMPEST attacks are whether it's something most companies should worry about when considering cyber security.
3 Billion Yahoo Accounts Hacked
http://bit.ly/2WHt7L6
Submitted February 05, 2019 at 12:14AM by PreciousPresley
via reddit http://bit.ly/2Biebdp
http://bit.ly/2WHt7L6
Submitted February 05, 2019 at 12:14AM by PreciousPresley
via reddit http://bit.ly/2Biebdp
Surfshark
3 Billion Hacked Yahoo Accounts, and Other Biggest Data Breaches - Surfshark
261 499 every hour or 73 per second - the number of data records lost or stolen every hour. A considerable part of the leaks is sensitive information - like credit card details, home addresses or social security numbers.
Exploit Walkthrough: Java XML Object Deserialization in OpenMRS Healthcare Software
http://bit.ly/2RFKuIm
Submitted February 05, 2019 at 12:10AM by SilentEcho
via reddit http://bit.ly/2TxBaIy
http://bit.ly/2RFKuIm
Submitted February 05, 2019 at 12:10AM by SilentEcho
via reddit http://bit.ly/2TxBaIy
Bishop Fox
OpenMRS - Insecure Object Deserialization - Bishop Fox
OpenMRS is a collaborative open-source project through which users can develop software to support healthcare in developing countries. In 2017, OpenMRS was implemented on more than 3,000 sites and stored information for over 8.7 million active patients. A…
Hacking an Aftermarket Remote Start System (CarLinkBT Series - Part 2)
http://bit.ly/2Wzlt5k
Submitted February 05, 2019 at 12:06AM by marketingversprite
via reddit http://bit.ly/2GnNW8L
http://bit.ly/2Wzlt5k
Submitted February 05, 2019 at 12:06AM by marketingversprite
via reddit http://bit.ly/2GnNW8L
VerSprite | Integrated Security Services and Consulting
Hacking an Aftermarket Remote Start System (Part 2) | VerSprite Research
In part two of this series, we’ll dive deeper into the technical specifications of the CarLinkBT module. and walkthrough expoitation.
Report: CEOs the Weakest Link with Security Measures
http://bit.ly/2Wwu6Og
Submitted February 05, 2019 at 12:05AM by token_app
via reddit http://bit.ly/2UEfJFB
http://bit.ly/2Wwu6Og
Submitted February 05, 2019 at 12:05AM by token_app
via reddit http://bit.ly/2UEfJFB
Securitymagazine
Report: CEOs the Weakest Link with Security Measures
A new report from The Bunker has highlighted that senior executives are still often the weakest link in the corporate cybersecurity chain and that cybercriminals target this vulnerability to commit serious data breaches.
Examining Pointer Authentication on the iPhone XS
http://bit.ly/2UDk4cp
Submitted February 04, 2019 at 10:29AM by wxor
via reddit http://bit.ly/2GnOivP
http://bit.ly/2UDk4cp
Submitted February 04, 2019 at 10:29AM by wxor
via reddit http://bit.ly/2GnOivP
reddit
r/netsec - Examining Pointer Authentication on the iPhone XS
1 vote and 0 comments so far on Reddit
Phishing U2F-Protected Accounts
https://www.youtube.com/watch?v=rPTI9e-9tBE
Submitted February 03, 2019 at 07:21AM by FarSide792
via reddit http://bit.ly/2WGUKE3
https://www.youtube.com/watch?v=rPTI9e-9tBE
Submitted February 03, 2019 at 07:21AM by FarSide792
via reddit http://bit.ly/2WGUKE3
YouTube
E 03 Phishing U2F Protected Accounts Nikita Mazurov Kenny Brown
These are the videos from BSides Tampa 2019: http://www.irongeek.com/i.php?page=videos/bsidestampa2019/mainlist Patreon: https://www.patreon.com/irongeek
Creating High Entropy Passwords on Linux
http://bit.ly/2t56L8L
Submitted February 05, 2019 at 06:43AM by weej
via reddit http://bit.ly/2HP9kpC
http://bit.ly/2t56L8L
Submitted February 05, 2019 at 06:43AM by weej
via reddit http://bit.ly/2HP9kpC
Cjbarker
CJ Barker | Creating High Entropy Passwords on Linux
CJ Barker - Husband, Father, Software Craftsman, InfoSec Enthusiast, Drummer and a gorilla in a man suit trying to make his way in life.
Why All Users Should Change Passwords Today
http://bit.ly/2G4yb7m
Submitted February 05, 2019 at 04:57PM by el_programmer
via reddit http://bit.ly/2SvqblA
http://bit.ly/2G4yb7m
Submitted February 05, 2019 at 04:57PM by el_programmer
via reddit http://bit.ly/2SvqblA
Infosecurity Magazine
Why All Users Should Change Passwords Today
Change Your Password Day is a good time to switch to a password manager.
Reverse RDP attack: Code Execution on RDP clients
http://bit.ly/2BlpgdH
Submitted February 05, 2019 at 08:41PM by eyalitki
via reddit http://bit.ly/2WHGFpT
http://bit.ly/2BlpgdH
Submitted February 05, 2019 at 08:41PM by eyalitki
via reddit http://bit.ly/2WHGFpT
Check Point Research
Home - Check Point Research
Latest Research by our Team
Exploiting Google "dot" Email Accounts for Fun and for Profit. But mostly for profit
http://bit.ly/2DldReb
Submitted February 05, 2019 at 10:15PM by iHeartMalware
via reddit http://bit.ly/2ULZkPL
http://bit.ly/2DldReb
Submitted February 05, 2019 at 10:15PM by iHeartMalware
via reddit http://bit.ly/2ULZkPL
Agari
BEC Actors Exploit Gmail “Dot Accounts” to Scale Activity | Agari
Cybercriminals are taking advantage of a Gmail feature to scale fradulent activity, including filing fake tax returns, credit card applications, and more.
Cisco Identity Services Engine: from unauth stored XSS to RCE as root
http://bit.ly/2t4jYyB
Submitted February 05, 2019 at 09:00AM by jose_boneh
via reddit http://bit.ly/2HVKlRx
http://bit.ly/2t4jYyB
Submitted February 05, 2019 at 09:00AM by jose_boneh
via reddit http://bit.ly/2HVKlRx
reddit
r/netsec - Cisco Identity Services Engine: from unauth stored XSS to RCE as root
1 vote and 1 comment so far on Reddit
Introducing tmpnix - an alternative to static binaries for post exploitation
http://bit.ly/2t5jBDM
Submitted February 05, 2019 at 10:46PM by alech_de
via reddit http://bit.ly/2HQPE4I
http://bit.ly/2t5jBDM
Submitted February 05, 2019 at 10:46PM by alech_de
via reddit http://bit.ly/2HQPE4I
shiftordie.de
Introducing tmpnix - an alternative to static binaries for post exploitation - shift or die
Introducing tmpnix - an alternative to static binaries for post exploitation
Feb ...
Feb ...