Sorry, Adobe Reader, We're Not Letting You Phone Home Without User's Consent (0day)
http://bit.ly/2TQqFjm
Submitted February 11, 2019 at 10:01PM by dielel
via reddit http://bit.ly/2Bvdygt
http://bit.ly/2TQqFjm
Submitted February 11, 2019 at 10:01PM by dielel
via reddit http://bit.ly/2Bvdygt
0Patch
Sorry, Adobe Reader, We're Not Letting You Phone Home Without User's Consent (0day)
by Mitja Kolsek, the 0patch Team Today we'll look at a fairly simple vulnerability in Adobe Reader DC that allows a PDF document automati...
New Offensive USB Cable Allows Remote Attacks over WiFi
http://bit.ly/2GoTr7Q
Submitted February 11, 2019 at 11:10PM by Nynir
via reddit http://bit.ly/2RYZlhu
http://bit.ly/2GoTr7Q
Submitted February 11, 2019 at 11:10PM by Nynir
via reddit http://bit.ly/2RYZlhu
BleepingComputer
New Offensive USB Cable Allows Remote Attacks over WiFi
Like a scene from a James Bond or Mission Impossible movie, a new offensive USB cable plugged into a computer could allow attackers to execute commands over WiFi as if they were using the computer's keyboard.
Russia considers unplugging from Internet
https://bbc.in/2I6bm4J
Submitted February 11, 2019 at 11:22PM by Hobscob
via reddit http://bit.ly/2Gzgaxk
https://bbc.in/2I6bm4J
Submitted February 11, 2019 at 11:22PM by Hobscob
via reddit http://bit.ly/2Gzgaxk
BBC News
Russia considers 'unplugging' from internet
Russia may briefly disconnect from the internet as part of a test of its cyber-defences.
Abusing SUDO Advance for Linux Privilege Escalation - RedTeam Tips
http://bit.ly/2N2UCds
Submitted February 12, 2019 at 08:14AM by sandeep1337
via reddit http://bit.ly/2SOu70G
http://bit.ly/2N2UCds
Submitted February 12, 2019 at 08:14AM by sandeep1337
via reddit http://bit.ly/2SOu70G
Penetration Testing and CyberSecurity Solution - SecureLayer7
Abusing SUDO Advance for Linux Privilege Escalation – RedTeam Tips
Abusing SUDO Advance for Linux Privilege Escalation If you have a limited shell that has access to some programs using thesudocommand you might be able to escalate your privileges. here I show some of the binary which helps you to escalate privilege using…
Post Exploitation
http://bit.ly/2UVEo8H
Submitted February 12, 2019 at 03:25PM by mstfknn
via reddit http://bit.ly/2E4D9Ph
http://bit.ly/2UVEo8H
Submitted February 12, 2019 at 03:25PM by mstfknn
via reddit http://bit.ly/2E4D9Ph
PRISMA CSI
6 - Post Exploitation • PRISMA CSI
Post Exploitation, Domain Exploitation, Meterpreter, Crackmapexec, Empire, Local Privilege Escalation, Persistence, Pivoting
Collection #1-5 analysis, 8 billion unique account with password, 301Gb of passwords. French blog
http://bit.ly/2GFqMun
Submitted February 12, 2019 at 04:37PM by rmsisme
via reddit http://bit.ly/2N2shUX
http://bit.ly/2GFqMun
Submitted February 12, 2019 at 04:37PM by rmsisme
via reddit http://bit.ly/2N2shUX
Advens
2019 sera forte en mots de passe volés – le record est battu !
2019 commence par un record battu ! Des compilations de plusieurs centaines de Giga sont apparues, d’abord en vente sur le darknet puis échangées par torrents à partir de plusieurs forums, sous les noms :« Collection #1 à 5 » ou « bigDB ». Essayons de voir…
IoT security group
http://bit.ly/2trhxGJ
Submitted February 12, 2019 at 04:25PM by v33ruiot
via reddit http://bit.ly/2SKFdnw
http://bit.ly/2trhxGJ
Submitted February 12, 2019 at 04:25PM by v33ruiot
via reddit http://bit.ly/2SKFdnw
Telegram
IoTsecurity101
It is particularly on IoT security.. please ask your question and share your knowledge
Simple Social Buttons 2.0.4-2.0.21 - Authenticated Option Injection (40K+ sites affected)
http://bit.ly/2DsjTJZ
Submitted February 12, 2019 at 05:23PM by ded1cated
via reddit http://bit.ly/2N1YhIH
http://bit.ly/2DsjTJZ
Submitted February 12, 2019 at 05:23PM by ded1cated
via reddit http://bit.ly/2N1YhIH
WebARX
WordPress Plugin 'Simple Social Buttons' Critical Security Bug
WebARX researcher found a vulnerability in popular WordPress plugin Simple Social Buttons. Read more to find out what vulnerability allows.
oss-sec: CVE-2019-5736: runc container breakout (all versions)
http://bit.ly/2N25Rmp
Submitted February 12, 2019 at 05:43PM by sidcool1234
via reddit http://bit.ly/2TKmnKD
http://bit.ly/2N25Rmp
Submitted February 12, 2019 at 05:43PM by sidcool1234
via reddit http://bit.ly/2TKmnKD
seclists.org
oss-sec: CVE-2019-5736: runc container breakout (all versions)
Xiaomi M365 scooter - Lack of security, enables an attacker to flash malicious firmware or maliciously use the scooter features
http://bit.ly/2thtTAO
Submitted February 12, 2019 at 07:31PM by IamNullByte
via reddit http://bit.ly/2N2xsUK
http://bit.ly/2thtTAO
Submitted February 12, 2019 at 07:31PM by IamNullByte
via reddit http://bit.ly/2N2xsUK
Zimperium Mobile Security Blog
Don't Give Me a Brake - Xiaomi Scooter Hack Enables Dangerous Accelerations and Stops for Unsuspecting Riders | Zimperium Mobile…
This proof-of concept (PoC) is released for educational purposes and evaluation by researchers, and should not be used in any unintended way. Furthermore, this PoC and any other related material has been published only after disclosing it to Xiaomi Researcher:…
Tough day for VFEmail....
http://bit.ly/2SIStJf
Submitted February 12, 2019 at 07:27PM by NaCledHash
via reddit http://bit.ly/2WZC9mE
http://bit.ly/2SIStJf
Submitted February 12, 2019 at 07:27PM by NaCledHash
via reddit http://bit.ly/2WZC9mE
reddit
r/sysadmin - Tough day for VFEmail....
2 votes and 1 comment so far on Reddit
Make It Rain with MikroTik
http://bit.ly/2USRUtR
Submitted February 12, 2019 at 07:22PM by chicksdigthelongrun
via reddit http://bit.ly/2E7D5ye
http://bit.ly/2USRUtR
Submitted February 12, 2019 at 07:22PM by chicksdigthelongrun
via reddit http://bit.ly/2E7D5ye
Medium
Make It Rain with MikroTik
Not a Coinhive Writeup
Omnipresence on the web: browse through many locations concurrently with Docker, VPN & Squid
http://bit.ly/2GB71Eo
Submitted February 12, 2019 at 07:51PM by eloquinees_husband
via reddit http://bit.ly/2tjJwI3
http://bit.ly/2GB71Eo
Submitted February 12, 2019 at 07:51PM by eloquinees_husband
via reddit http://bit.ly/2tjJwI3
reddit
r/netsec - Omnipresence on the web: browse through many locations concurrently with Docker, VPN & Squid
1 vote and 1 comment so far on Reddit
PowerShell netsec noscripts I wrote for other sysadmins
http://bit.ly/2Bw43gZ
Submitted February 12, 2019 at 08:38PM by WorkLotus
via reddit http://bit.ly/2E64iB4
http://bit.ly/2Bw43gZ
Submitted February 12, 2019 at 08:38PM by WorkLotus
via reddit http://bit.ly/2E64iB4
GitHub
thom-s/netsec-ps-noscripts
Collection of PowerShell network security noscripts for system administrators. - thom-s/netsec-ps-noscripts
Practical Enclave Malware with Intel SGX
http://bit.ly/2SOGxpi
Submitted February 12, 2019 at 10:03PM by Bl00dsoul
via reddit http://bit.ly/2SspY3q
http://bit.ly/2SOGxpi
Submitted February 12, 2019 at 10:03PM by Bl00dsoul
via reddit http://bit.ly/2SspY3q
reddit
r/netsec - Practical Enclave Malware with Intel SGX
1 vote and 0 comments so far on Reddit
Docker image security scanning in a few simple steps
http://bit.ly/2GE6Vfl
Submitted February 12, 2019 at 11:14PM by weighanchore
via reddit http://bit.ly/2E5RdYK
http://bit.ly/2GE6Vfl
Submitted February 12, 2019 at 11:14PM by weighanchore
via reddit http://bit.ly/2E5RdYK
Anchore
Docker Image Security in 5 Minutes or Less
The Anchore Engine is an open source project that provides a centralized service for deep inspection, analysis and certification of container images. It is provided as a Docker container image that can be run standalone or on an orchestration platform such…
Autocert - use TLS to access internal kubernetes services from anywhere
http://bit.ly/2TLngmd
Submitted February 12, 2019 at 11:54PM by mjmalone
via reddit http://bit.ly/2DCQZGS
http://bit.ly/2TLngmd
Submitted February 12, 2019 at 11:54PM by mjmalone
via reddit http://bit.ly/2DCQZGS
GitHub
smallstep/certificates
An online certificate authority and related tools for secure automated certificate management, so you can use TLS everywhere. - smallstep/certificates
New Ubuntu Linux privilege escalation exploit and technical write-up (dirty_sock)
http://bit.ly/2BvvrMo
Submitted February 12, 2019 at 11:50PM by initstring
via reddit http://bit.ly/2thtIWl
http://bit.ly/2BvvrMo
Submitted February 12, 2019 at 11:50PM by initstring
via reddit http://bit.ly/2thtIWl
Shenanigans Labs
Privilege Escalation in Ubuntu Linux (dirty_sock exploit)
In January 2019, I discovered a privilege escalation vulnerability in default installations of Ubuntu Linux. This was due to a bug in the snapd API, a default service. Any local user could exploit this vulnerability to obtain immediate root access to the…
IoT security resources
http://bit.ly/2Dver96
Submitted February 13, 2019 at 12:14AM by v33ruiot
via reddit http://bit.ly/2RXVAIO
http://bit.ly/2Dver96
Submitted February 13, 2019 at 12:14AM by v33ruiot
via reddit http://bit.ly/2RXVAIO
GitHub
V33RU/IoTSecurity101
From IoT Pentesting to IoT Security . Contribute to V33RU/IoTSecurity101 development by creating an account on GitHub.
There are Two Types of Hackers
http://bit.ly/2I6cDJ2
Submitted February 13, 2019 at 01:01AM by neverforgetdream
via reddit http://bit.ly/2GCVfcO
http://bit.ly/2I6cDJ2
Submitted February 13, 2019 at 01:01AM by neverforgetdream
via reddit http://bit.ly/2GCVfcO
reddit
r/netsec - There are Two Types of Hackers
1 vote and 2 comments so far on Reddit
Hacking Laws are Silly, Don’t click this link.
https://breakthelaw.xyz
Submitted February 13, 2019 at 04:02AM by Evil1337
via reddit http://bit.ly/2TS3FAV
https://breakthelaw.xyz
Submitted February 13, 2019 at 04:02AM by Evil1337
via reddit http://bit.ly/2TS3FAV
breakthelaw.xyz
Hacking Laws are Silly. Seriously. Don't view this page.
As somebody who is in the Infosec/Cybersecurity industry, it is common knowledge that the laws relating to Hacking and Cybersecurity are laughably out-of-date, and as a result, it is technically prosecute somebody just for visiting a website and clicking…