Failure to Encrypt ePHI Costs Cancer Treatment and Research Center $4.34 Million - NetSec.News
https://ift.tt/2VdwJ5M
Submitted February 24, 2019 at 03:30PM by chincuntry12
via reddit https://ift.tt/2EsX4Hu
https://ift.tt/2VdwJ5M
Submitted February 24, 2019 at 03:30PM by chincuntry12
via reddit https://ift.tt/2EsX4Hu
NetSec.News
Failure to Encrypt ePHI Costs Cancer Treatment and Research Center $4.34 Million - NetSec.News
The HHS’ Office for Civil Rights has announced its third HIPAA financial penalty of 2018 - The 4th largest HIPAA penalty ever issued.
Novel Phishing Scam Uses Custom Web Fonts to Evade Detection
https://ift.tt/2BQpjOZ
Submitted February 24, 2019 at 06:59PM by mamavapa
via reddit https://ift.tt/2Eut3Ya
https://ift.tt/2BQpjOZ
Submitted February 24, 2019 at 06:59PM by mamavapa
via reddit https://ift.tt/2Eut3Ya
SpamTitan
Novel Phishing Scam Uses Custom Web Fonts to Evade Detection - SpamTitan
A new technique is being used by scammers to hide their phishing websites. This novel phishing attack uses a custom web font to render ciphertext as plaintext. The tactic is being used in phishing scams impersonating major U.S. banks.
Bug Allows Bypass of Face ID and Touch ID Authentication of WhatsApp iOS version
https://ift.tt/2BZC3Tx
Submitted February 24, 2019 at 06:47PM by ashique789
via reddit https://ift.tt/2VapBXY
https://ift.tt/2BZC3Tx
Submitted February 24, 2019 at 06:47PM by ashique789
via reddit https://ift.tt/2VapBXY
SecureReading
Bug Allows Bypass of Face ID and Touch ID Authentication of WhatsApp iOS version | SecureReading
A Reddit user has discovered a method to bypass recently introduced Face ID and Touch ID authentication for WhatsApp iOS version
"How a chain of multiple hacks leads me to database compromise"
https://ift.tt/2GHBxNY
Submitted February 24, 2019 at 11:57PM by logic_bomb_1
via reddit https://ift.tt/2Xmtg75
https://ift.tt/2GHBxNY
Submitted February 24, 2019 at 11:57PM by logic_bomb_1
via reddit https://ift.tt/2Xmtg75
Medium
Chain of hacks leading to Database Compromise!
Hi Guys, This is yet another a security vulnerability writeup about a chain of security vulnerabilities that linked up to compromise one…
New flaws in 4G, 5G allow attackers to intercept calls and track phone locations
https://ift.tt/2XuRFYe
Submitted February 25, 2019 at 01:10AM by lightlimegreen
via reddit https://ift.tt/2NpIoMh
https://ift.tt/2XuRFYe
Submitted February 25, 2019 at 01:10AM by lightlimegreen
via reddit https://ift.tt/2NpIoMh
TechCrunch
New flaws in 4G, 5G allow attackers to intercept calls and track phone locations
A group of academics have found three new security flaws in 4G and 5G, which they say can be used to intercept phone calls and track the locations of cell phone users. The findings are said to be the first time vulnerabilities have affected both 4G and the…
The Stoic Approach To conducting dedicated OSINT engagements
https://ift.tt/2GZJkpE
Submitted February 25, 2019 at 06:08AM by hp777us
via reddit https://ift.tt/2H5dGal
https://ift.tt/2GZJkpE
Submitted February 25, 2019 at 06:08AM by hp777us
via reddit https://ift.tt/2H5dGal
Infosec Writers Club
The Stoic Approach To OSINT
The deep thinkers approach to OSINT. What if all you had was a search engine? A complete and total focus on observable evidence linked by inferences.
whori.sh: Zone transfers for rwhois
https://ift.tt/2XnV3Ei
Submitted February 25, 2019 at 09:50AM by ShadowHatesYou
via reddit https://ift.tt/2GGTaxb
https://ift.tt/2XnV3Ei
Submitted February 25, 2019 at 09:50AM by ShadowHatesYou
via reddit https://ift.tt/2GGTaxb
GitHub
ShadowHatesYou/whori.sh
Zone transfers for rwhois. Contribute to ShadowHatesYou/whori.sh development by creating an account on GitHub.
How to break PDF Signatures
https://ift.tt/2NrU4hH
Submitted February 25, 2019 at 01:20PM by hannob
via reddit https://ift.tt/2BQ1ZAW
https://ift.tt/2NrU4hH
Submitted February 25, 2019 at 01:20PM by hannob
via reddit https://ift.tt/2BQ1ZAW
reddit
r/netsec - How to break PDF Signatures
0 votes and 0 comments so far on Reddit
Manipulating top-sites rankings
https://ift.tt/2EwU79b
Submitted February 25, 2019 at 12:15PM by tomvangoethem
via reddit https://ift.tt/2TgyIcl
https://ift.tt/2EwU79b
Submitted February 25, 2019 at 12:15PM by tomvangoethem
via reddit https://ift.tt/2TgyIcl
Aaronlocker - a set of PowerShell noscripts that makes creating/maintaining AppLocker policies a breeze
https://ift.tt/2PGCmqh
Submitted February 25, 2019 at 06:24PM by snackoverflow
via reddit https://ift.tt/2XoYuuq
https://ift.tt/2PGCmqh
Submitted February 25, 2019 at 06:24PM by snackoverflow
via reddit https://ift.tt/2XoYuuq
GitHub
GitHub - microsoft/AaronLocker: Robust and practical application control for Windows
Robust and practical application control for Windows - GitHub - microsoft/AaronLocker: Robust and practical application control for Windows
CRXcavator a new free web tool to scan Chrome extensions and provide risk scores
https://ift.tt/2T4uCUO
Submitted February 25, 2019 at 08:12PM by lyoko37
via reddit https://ift.tt/2EefpHd
https://ift.tt/2T4uCUO
Submitted February 25, 2019 at 08:12PM by lyoko37
via reddit https://ift.tt/2EefpHd
Duo Security
CRXcavator: Democratizing Chrome Extension Security
To provide users and IT teams with actionable intelligence about Chrome extensions, Duo Labs is excited to announce the public beta of CRXcavator (rhymes with “excavator”), a free service that analyzes Chrome extensions and produces comprehensive security…
"Building Virtual Machine Labs" is now free!
https://ift.tt/2ICsxvj
Submitted February 25, 2019 at 11:33PM by BenjaminFlankin
via reddit https://ift.tt/2EvRWCL
https://ift.tt/2ICsxvj
Submitted February 25, 2019 at 11:33PM by BenjaminFlankin
via reddit https://ift.tt/2EvRWCL
Leanpub
Building Virtual Machine Labs
Learn everything there is to know about building and maintaining your own home or workplace virtual lab environment on the most popular hypervisors today!
Experiments, growth engineering, and the perils of not disguising your API routes: Part 1
https://ift.tt/2ICqU0F
Submitted February 25, 2019 at 11:27PM by JonLuca
via reddit https://ift.tt/2VjGQWO
https://ift.tt/2ICqU0F
Submitted February 25, 2019 at 11:27PM by JonLuca
via reddit https://ift.tt/2VjGQWO
JonLuca’s Blog
Experiments, growth engineering, and the perils of not disguising your API routes: Part 1
JonLuca’s Blog - A blog about tech, programming, and information
Investigating WinRAR Code Execution Vulnerability (CVE-2018-20250) at Internet Scale
https://ift.tt/2VjVy0g
Submitted February 26, 2019 at 03:13AM by ga-vu
via reddit https://ift.tt/2NuIUbV
https://ift.tt/2VjVy0g
Submitted February 26, 2019 at 03:13AM by ga-vu
via reddit https://ift.tt/2NuIUbV
reddit
r/netsec - Investigating WinRAR Code Execution Vulnerability (CVE-2018-20250) at Internet Scale
0 votes and 0 comments so far on Reddit
Digital extortionist offer high six figure salaries to accomplices | SC Media
https://ift.tt/2EwUDns
Submitted February 26, 2019 at 03:12AM by KeyDutch
via reddit https://ift.tt/2GJrJ63
https://ift.tt/2EwUDns
Submitted February 26, 2019 at 03:12AM by KeyDutch
via reddit https://ift.tt/2GJrJ63
SC Media
Digital extortionist offer high six figure salaries to accomplices | SC Media
Cybercriminals are promising salaries of up to $360,000 a year to accomplices who seek to extort high networth individuals such as C-Level executives, lawyers, and doctors.
Get valid HTTPS certificates for dev & pre-prod using step
https://ift.tt/2XpM71c
Submitted February 26, 2019 at 06:15AM by sourishkrout
via reddit https://ift.tt/2BV1ZiO
https://ift.tt/2XpM71c
Submitted February 26, 2019 at 06:15AM by sourishkrout
via reddit https://ift.tt/2BV1ZiO
Smallstep
Almost 80% of web page loads now use TLS. But almost no one uses TLS in development and pre-production. Why? Because it's hard. That sucks. When dev and staging don't match prod, bad things happen. Today's step release, version 0.8.6, makes using TLS in dev…
Malvertisers using polyglot BMP images to avoid detection and spread malicious redirects on mobile devices.
https://ift.tt/2SYpmCX
Submitted February 26, 2019 at 11:03AM by ascetik
via reddit https://ift.tt/2E77NGc
https://ift.tt/2SYpmCX
Submitted February 26, 2019 at 11:03AM by ascetik
via reddit https://ift.tt/2E77NGc
DEVCON | Ad Fraud Security®
Hacking group using Polyglot images to hide malvertsing attacks
What happens when an image is also javanoscript? And when that Image does not even need a payload to extract the malware from the image.. Well then you have a polyglot!
Retaining beacon source IPs with HAproxy relays
https://ift.tt/2Ef4xsp
Submitted February 26, 2019 at 12:37PM by _d3vzer0
via reddit https://ift.tt/2T4BUZz
https://ift.tt/2Ef4xsp
Submitted February 26, 2019 at 12:37PM by _d3vzer0
via reddit https://ift.tt/2T4BUZz
d3vzer0
Retaining beacon source IPs with HAProxy relays
During a red team exercise it's common to set up a relaying infrastructure to separate your external facing footprint from the actual command and control backend. Some of the popular light-weight options are to set up either HAProxy or NGINX on disposable…
New Malspam Campaign Targets WinRAR ACE Flaw to Deliver Malware
https://ift.tt/2GQpspN
Submitted February 26, 2019 at 02:19PM by ashique789
via reddit https://ift.tt/2tE4SjN
https://ift.tt/2GQpspN
Submitted February 26, 2019 at 02:19PM by ashique789
via reddit https://ift.tt/2tE4SjN
SecureReading
New Malspam Campaign Targets WinRAR ACE Flaw to Deliver Malware | SecureReading
Security researchers have discovered a new Malspam campaign exploiting the recently discovered WinRAR ACE flaw to install malware on the computer
Metasploit is adding a browser exploit for iOS 10
https://ift.tt/2EobuI3
Submitted February 26, 2019 at 03:21PM by strongheadwu
via reddit https://ift.tt/2EceAP7
https://ift.tt/2EobuI3
Submitted February 26, 2019 at 03:21PM by strongheadwu
via reddit https://ift.tt/2EceAP7
GitHub
Initial commit of CVE-2018-4233 for iOS 10 by timwr · Pull Request #11477 · rapid7/metasploit-framework
The demonstrates CVE-2018-4233 on iOS. This should work on all 64bit iOS 10 devices but currently the kernel exploit has kernel offsets hardcoded for an iPod7,1 10.1.1 until I manage to add liboffs...
Critical Remote Execution Flaw Discovered in WinRAR Impacting all Versions
https://ift.tt/2U000B3
Submitted February 26, 2019 at 07:10PM by ashique789
via reddit https://ift.tt/2H1zcfX
https://ift.tt/2U000B3
Submitted February 26, 2019 at 07:10PM by ashique789
via reddit https://ift.tt/2H1zcfX
SecureReading
Critical Remote Execution Flaw Discovered in WinRAR Impacting all Versions | SecureReading
Security researchers have discovered a critical remote execution vulnerability in WinRAR software affecting all versions.