Researcher Assaulted By A Vendor After Disclosing A Vulnerability
http://bit.ly/2UKfEjT
Submitted February 06, 2019 at 11:55AM by ayn0r
via reddit http://bit.ly/2t7nXdN
http://bit.ly/2UKfEjT
Submitted February 06, 2019 at 11:55AM by ayn0r
via reddit http://bit.ly/2t7nXdN
Secjuice.com
Researcher Assaulted After Disclosure
Following a serious vulnerability disclosure to Atrient, the security researcher who disclosed the vulnerability was assaulted by their COO at ICE.
Poppin’ Calc: Web Studio Edition
http://bit.ly/2Bxvo2H
Submitted February 06, 2019 at 07:04PM by chicksdigthelongrun
via reddit http://bit.ly/2HXLx6Z
http://bit.ly/2Bxvo2H
Submitted February 06, 2019 at 07:04PM by chicksdigthelongrun
via reddit http://bit.ly/2HXLx6Z
Medium
Poppin’ Calc: Web Studio Edition
What Even Are You?
APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
http://bit.ly/2DbrFrr
Submitted February 06, 2019 at 08:49PM by campuscodi
via reddit http://bit.ly/2HULkBn
http://bit.ly/2DbrFrr
Submitted February 06, 2019 at 08:49PM by campuscodi
via reddit http://bit.ly/2HULkBn
Recorded Future
APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
In this report, Insikt Group shares insight into a sustained cyberespionage campaign assessed to be conducted by Chinese state-sponsored threat actor APT10.
The Curious Case of Convexity Confusion
http://bit.ly/2Tt77l4
Submitted February 06, 2019 at 08:47PM by albinowax
via reddit http://bit.ly/2t9rYyf
http://bit.ly/2Tt77l4
Submitted February 06, 2019 at 08:47PM by albinowax
via reddit http://bit.ly/2t9rYyf
reddit
r/netsec - The Curious Case of Convexity Confusion
4 votes and 0 comments so far on Reddit
Virtual Reality - a stealthy backdoor for windows
http://bit.ly/2Txz23i
Submitted February 06, 2019 at 06:46PM by rokups
via reddit http://bit.ly/2Bmloco
http://bit.ly/2Txz23i
Submitted February 06, 2019 at 06:46PM by rokups
via reddit http://bit.ly/2Bmloco
GitHub
rokups/virtual-reality
Stealthy backdoor for Windows operating systems. Contribute to rokups/virtual-reality development by creating an account on GitHub.
BACNet javanoscript Injection -Persistent XSS in BACNet devices CVE-2019–7408
http://bit.ly/2TBCytI
Submitted February 06, 2019 at 12:46AM by bertinjoseb
via reddit http://bit.ly/2BhyhEz
http://bit.ly/2TBCytI
Submitted February 06, 2019 at 12:46AM by bertinjoseb
via reddit http://bit.ly/2BhyhEz
Medium
BACNet javanoscript Injection -Persistent XSS in BACNet devices CVE-2019–7408
Santiago Chile Feb 2019
Inception, a tool written in go lang that detects configuration files and more on web server.
http://bit.ly/2De60yK
Submitted February 06, 2019 at 10:06PM by Abiral111
via reddit http://bit.ly/2Spu4sj
http://bit.ly/2De60yK
Submitted February 06, 2019 at 10:06PM by Abiral111
via reddit http://bit.ly/2Spu4sj
GitHub
proabiral/inception
A highly configurable tool to check for whatever you like against any number of hosts. - proabiral/inception
JellyHive - Set up Let's Encrypt certificate solution on Azure (xpost /r/dotnet)
http://bit.ly/2TzWGw5
Submitted February 06, 2019 at 11:26PM by smatsson
via reddit http://bit.ly/2BlWKbI
http://bit.ly/2TzWGw5
Submitted February 06, 2019 at 11:26PM by smatsson
via reddit http://bit.ly/2BlWKbI
JellyHive
Set up Let's Encrypt certificate solution on Azure
IntroductionIt’s 2019 and your site needs a SLL/TLS certificate. These can be quite expensiv, but fear not, there are solutions that are free!Enter Let’s Encrypt. Scenario and prerequisiteThe scenari
Open source hardware vs next generation hacking
http://bit.ly/2Add91v
Submitted February 07, 2019 at 01:19AM by edsonarantes2
via reddit http://bit.ly/2Gctqsk
http://bit.ly/2Add91v
Submitted February 07, 2019 at 01:19AM by edsonarantes2
via reddit http://bit.ly/2Gctqsk
PONDERWALL
Open Source Hardware Could Defend Against Next Generation Hacking
Making open-source hardware systems more available increases regular people’s security by giving them verifiable secure options.
Researcher Assaulted By A Vendor After Disclosing A Vulnerability
http://bit.ly/2UKfEjT
Submitted February 07, 2019 at 01:08AM by Titokhan
via reddit http://bit.ly/2TEvRHm
http://bit.ly/2UKfEjT
Submitted February 07, 2019 at 01:08AM by Titokhan
via reddit http://bit.ly/2TEvRHm
Secjuice.com
Researcher Assaulted After Disclosure
Following a serious vulnerability disclosure to Atrient, the security researcher who disclosed the vulnerability was assaulted by their COO at ICE.
Red team hackers crack DOD's MHS Genesis electronic heath records system -- FCW
http://bit.ly/2Shr95u
Submitted February 07, 2019 at 04:18AM by mc_security
via reddit http://bit.ly/2UECXLQ
http://bit.ly/2Shr95u
Submitted February 07, 2019 at 04:18AM by mc_security
via reddit http://bit.ly/2UECXLQ
FCW
Red team hackers crack DOD's MHS Genesis electronic heath records system -- FCW
The $5.5 billion commercial health record system is 'not survivable in a cyber-contested environment,' according to an internal Pentagon report.
OSCP Write-up Leaked By “Cyb3rsick “
http://bit.ly/2DhUYIG
Submitted February 07, 2019 at 10:56AM by icssindia
via reddit http://bit.ly/2UJY7ID
http://bit.ly/2DhUYIG
Submitted February 07, 2019 at 10:56AM by icssindia
via reddit http://bit.ly/2UJY7ID
reddit
r/netsec - OSCP Write-up Leaked By “Cyb3rsick “
1 vote and 0 comments so far on Reddit
Cache Deception at Medium (reported and fixed)
http://bit.ly/2Diuozv
Submitted February 07, 2019 at 11:05AM by HUCK45
via reddit http://bit.ly/2GrHXjg
http://bit.ly/2Diuozv
Submitted February 07, 2019 at 11:05AM by HUCK45
via reddit http://bit.ly/2GrHXjg
freeCodeCamp.org
Cache Deception: How I discovered a vulnerability in Medium and helped them fix it
In my previous post, I tried to demonstrate how powerful and cool reverse engineering Android apps can be. I did this by showing how to…
Yet another plea against using public WiFi
http://bit.ly/2SCa71e
Submitted February 07, 2019 at 03:37PM by atomlib_com
via reddit http://bit.ly/2Si1vh8
http://bit.ly/2SCa71e
Submitted February 07, 2019 at 03:37PM by atomlib_com
via reddit http://bit.ly/2Si1vh8
Habr
Yet another plea against using public WiFi
The thoughts I’m going to relate in this post may seem obvious and even trivial to some of you, but my experience with water cooler chats with my workmates s...
LOLbins and trojans: How the Ramnit Trojan spreads via sLoad in a cyberattack
http://bit.ly/2C2Ywye
Submitted February 07, 2019 at 10:34PM by Eliad-Cybereason
via reddit http://bit.ly/2GfXvHE
http://bit.ly/2C2Ywye
Submitted February 07, 2019 at 10:34PM by Eliad-Cybereason
via reddit http://bit.ly/2GfXvHE
Cybereason
LOLbins and trojans: How the Ramnit Trojan spreads via sLoad in a cyberattack
Cybereason detected an evasive infection technique used to spread a variant of the Ramnit banking Trojan as part of an Italian spam campaign. We investigate this attack, its use of sLoad, and its adoption of LOLbins to minimize discovery.
Open sourcing ClusterFuzz
http://bit.ly/2t9OKpF
Submitted February 07, 2019 at 11:17PM by halbface
via reddit http://bit.ly/2Djnwlm
http://bit.ly/2t9OKpF
Submitted February 07, 2019 at 11:17PM by halbface
via reddit http://bit.ly/2Djnwlm
Google Open Source Blog
Open sourcing ClusterFuzz
The latest news from Google on open source releases, major projects, events, and student outreach programs.
Write-up from a CTF with OSINT, social engineering, physical intrusion & hacking
http://bit.ly/2WGXlxI
Submitted February 07, 2019 at 11:35PM by navlys
via reddit http://bit.ly/2TDdNgq
http://bit.ly/2WGXlxI
Submitted February 07, 2019 at 11:35PM by navlys
via reddit http://bit.ly/2TDdNgq
ClusterFuzz: A scalable fuzzing infrastructure which finds security and stability issues in software
http://bit.ly/2WLFVjy
Submitted February 08, 2019 at 01:50AM by Titokhan
via reddit http://bit.ly/2GcwOnb
http://bit.ly/2WLFVjy
Submitted February 08, 2019 at 01:50AM by Titokhan
via reddit http://bit.ly/2GcwOnb
CipherSweet: Searchable Encryption Doesn't Have to be Bitter
http://bit.ly/2Ujaueg
Submitted February 08, 2019 at 02:07AM by sarciszewski
via reddit http://bit.ly/2tcQeiZ
http://bit.ly/2Ujaueg
Submitted February 08, 2019 at 02:07AM by sarciszewski
via reddit http://bit.ly/2tcQeiZ
Paragonie
CipherSweet: Searchable Encryption Doesn't Have to be Bitter - Paragon Initiative Enterprises Blog
CipherSweet is a PHP library that provides searchable encryption for the most common cases a web developer is likely to encounter.
WSC2 - Websockets C2 PoC
http://bit.ly/2yYhzuJ
Submitted February 08, 2019 at 02:04AM by Agadius
via reddit http://bit.ly/2tb4qcg
http://bit.ly/2yYhzuJ
Submitted February 08, 2019 at 02:04AM by Agadius
via reddit http://bit.ly/2tb4qcg
GitHub
Arno0x/WSC2
A WebSocket C2 Tool. Contribute to Arno0x/WSC2 development by creating an account on GitHub.
Providing Applications Secure Access to AWS S3 - a comparison of 4 approaches
http://bit.ly/2WP2Drd
Submitted February 08, 2019 at 02:38AM by jalamok
via reddit http://bit.ly/2I1BLki
http://bit.ly/2WP2Drd
Submitted February 08, 2019 at 02:38AM by jalamok
via reddit http://bit.ly/2I1BLki
Hedgehoglab
AWS S3 security best practices - Part 2
In the second part of his guide to AWS S3 security, hedgehog lab's Joe Keilty evaluates four methods for securely providing applications with access to your S3 resources.