Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) – Microsoft Security Response Center
http://bit.ly/2JknhvG
Submitted May 15, 2019 at 01:42AM by raincan
via reddit http://bit.ly/2WJLGOa
http://bit.ly/2JknhvG
Submitted May 15, 2019 at 01:42AM by raincan
via reddit http://bit.ly/2WJLGOa
reddit
r/netsec - Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) – Microsoft Security Response Center
0 votes and 1 comment so far on Reddit
John the Ripper 1.9.0-jumbo-1 password cracker is out
http://bit.ly/2HC49Gr
Submitted May 15, 2019 at 02:38AM by solardiz
via reddit http://bit.ly/2VAw4jy
http://bit.ly/2HC49Gr
Submitted May 15, 2019 at 02:38AM by solardiz
via reddit http://bit.ly/2VAw4jy
reddit
r/netsec - John the Ripper 1.9.0-jumbo-1 password cracker is out
0 votes and 0 comments so far on Reddit
SSDD - Remote desktop RCE CVE-2019-0708.
http://bit.ly/2HkzZIF
Submitted May 15, 2019 at 05:14AM by SpecialistFagazine
via reddit http://bit.ly/2Hpprqq
http://bit.ly/2HkzZIF
Submitted May 15, 2019 at 05:14AM by SpecialistFagazine
via reddit http://bit.ly/2Hpprqq
reddit
r/netsec - SSDD - Remote desktop RCE CVE-2019-0708.
0 votes and 1 comment so far on Reddit
WhatsApp flaw used to install spyware by simply calling the target - Help Net Security
http://bit.ly/2W06qEp
Submitted May 15, 2019 at 01:34PM by DuckGuy528
via reddit http://bit.ly/2vYXxw9
http://bit.ly/2W06qEp
Submitted May 15, 2019 at 01:34PM by DuckGuy528
via reddit http://bit.ly/2vYXxw9
Help Net Security
WhatsApp flaw used to install spyware by simply calling the target - Help Net Security
A zero-day flaw in WhatsApp allowed attackers to install spyware on smartphones without any user interaction, Financial Times has reported.
DEFCON Quals 2019 Veryandroidoso Solution with Frida
http://bit.ly/2VoFmuk
Submitted May 15, 2019 at 02:24PM by eybisi_
via reddit http://bit.ly/30lnnIH
http://bit.ly/2VoFmuk
Submitted May 15, 2019 at 02:24PM by eybisi_
via reddit http://bit.ly/30lnnIH
Ahmet Bilal Can
DEF CON Quals 2019 : VERYANDROIDOSO
Here is my writeup for VERYANDROIDOSO task. Ofcourse with frida :D App takes input from us and checks if it is correct flag. Length of flag should be 23 enclosed with OOO{..}. Also inside of brackets
RIDL, FALLOUT and ZombieLoad
http://bit.ly/2HqIdxJ
Submitted May 15, 2019 at 05:02PM by thatstevelord
via reddit http://bit.ly/2VpVQSL
http://bit.ly/2HqIdxJ
Submitted May 15, 2019 at 05:02PM by thatstevelord
via reddit http://bit.ly/2VpVQSL
blog.cygenta.co.uk
RIDL, FALLOUT and ZombieLoad
So three(3) new hardware based vulnerabilities were released and whilst we all
remember Spectre or Meltdown from last year these ones, these new
vulnerabilities show that hardware based attacks are not going to go away any
time soon, not only that but the…
remember Spectre or Meltdown from last year these ones, these new
vulnerabilities show that hardware based attacks are not going to go away any
time soon, not only that but the…
Open Source/Hardware JackPair p2p speech encrypting device
http://bit.ly/2LFPhvB
Submitted May 15, 2019 at 07:13PM by EquityMSP
via reddit http://bit.ly/2WIaNRr
http://bit.ly/2LFPhvB
Submitted May 15, 2019 at 07:13PM by EquityMSP
via reddit http://bit.ly/2WIaNRr
GitHub
gegel/jackpair
p2p speech encrypting device with analog audio interface suitable for GSM phones - gegel/jackpair
The NSO WhatsApp Vulnerability - This is How It Happened - Check Point Research
http://bit.ly/2JHrlWb
Submitted May 15, 2019 at 08:03PM by fizzbuzzwiz
via reddit http://bit.ly/2EckTmv
http://bit.ly/2JHrlWb
Submitted May 15, 2019 at 08:03PM by fizzbuzzwiz
via reddit http://bit.ly/2EckTmv
Check Point Research
The NSO WhatsApp Vulnerability - This is How It Happened - Check Point Research
Earlier today the Financial Times published that there is a critical vulnerability in the popular WhatsApp messaging application and that it is actively being used to inject spyware into victims phones. According to the report, attackers only need to issue…
Is MIME Sniffing XSS a real thing? [The story of weird Google bug bounties]
http://bit.ly/2W3k2ik
Submitted May 15, 2019 at 06:38PM by zoh4rs
via reddit http://bit.ly/2LLx005
http://bit.ly/2W3k2ik
Submitted May 15, 2019 at 06:38PM by zoh4rs
via reddit http://bit.ly/2LLx005
Komodo_Prod_25_March
Is MIME Sniffing XSS a real thing? [The story of weird Google bug bounties] | Komodo_Prod_25_March
Let’s start at the end. This one got me seriously confused. It all started a few months ago when a colleague was hacking away at some Google website. After some poking around, he detected a persistent XSS vulnerability – the attacker’s payload is stored on…
Falco Vulnerability – CVE-2019-8339
http://bit.ly/2LUiSS6
Submitted May 15, 2019 at 08:52PM by LucyMor
via reddit http://bit.ly/2QaE0SU
http://bit.ly/2LUiSS6
Submitted May 15, 2019 at 08:52PM by LucyMor
via reddit http://bit.ly/2QaE0SU
Twistlock
Falco Vulnerability - CVE-2019-8339 | Twistlock
As part of our initiative to contribute to and improve CNCF projects, I’ve recently found a bypass vulnerability in Sysdig – CVE-2019-8339. This allows bypassing its syscall detection and as a result, allows bypassing Falco rules and running any system calls…
Find hidden friends and communities for any Facebook user (tool and demo)
http://bit.ly/2YABXdP
Submitted May 15, 2019 at 08:48PM by 0xdea
via reddit http://bit.ly/2Q6ikac
http://bit.ly/2YABXdP
Submitted May 15, 2019 at 08:48PM by 0xdea
via reddit http://bit.ly/2Q6ikac
reddit
r/netsec - Find hidden friends and communities for any Facebook user (tool and demo)
0 votes and 1 comment so far on Reddit
ATT&CK: Re-play APT3 Adversarial Techniques
http://bit.ly/2HqlrpR
Submitted May 15, 2019 at 10:58PM by digicat
via reddit http://bit.ly/2VI0gcD
http://bit.ly/2HqlrpR
Submitted May 15, 2019 at 10:58PM by digicat
via reddit http://bit.ly/2VI0gcD
GitHub
Cyb3rWard0g/mordor
Re-play Adversarial Techniques. Contribute to Cyb3rWard0g/mordor development by creating an account on GitHub.
The Persistence of Chaos, a laptop running 6 pieces of malware that have caused financial damages totaling $95B.
http://bit.ly/2HjPwIF
Submitted May 15, 2019 at 11:46PM by cenpon
via reddit http://bit.ly/2Yug27R
http://bit.ly/2HjPwIF
Submitted May 15, 2019 at 11:46PM by cenpon
via reddit http://bit.ly/2Yug27R
Twitch
PersistenceChaos - Twitch
http://thepersistenceofchaos.com, a laptop running 6 pieces of malware that have caused financial damages totaling $95B
Close to 735K Fraudulently Obtained IP Addresses Have Been Uncovered and Revoked, ARIN Reveals
http://bit.ly/2LLiAgF
Submitted May 16, 2019 at 02:47AM by modelop
via reddit http://bit.ly/2Q92dZQ
http://bit.ly/2LLiAgF
Submitted May 16, 2019 at 02:47AM by modelop
via reddit http://bit.ly/2Q92dZQ
Circleid
Close to 735K Fraudulently Obtained IP Addresses Have Been Uncovered and Revoked, ARIN Reveals
The American Registry for Internet Numbers, Ltd. (ARIN) has won a legal case against an elaborate multi-year scheme to defraud the Internet community of approximately 735,000 IPv4 addresses, the organization has revealed. While the specifics of the findings…
Not sure if this fits here
http://bit.ly/2HmzMok
Submitted May 16, 2019 at 02:40AM by SeductiveComrade
via reddit http://bit.ly/2YxU8Rf
http://bit.ly/2HmzMok
Submitted May 16, 2019 at 02:40AM by SeductiveComrade
via reddit http://bit.ly/2YxU8Rf
TheHill
Trump signs order aimed at protecting US networks from Chinese tech
President Trump on Wednesday signed an executive order declaring a "national emergency" that would empower his administration to block foreign tech companies from doing business in the U.S. if they
Frida 12.5 released
http://bit.ly/2Jp1AL5
Submitted May 16, 2019 at 07:03AM by oleavr
via reddit http://bit.ly/2EaCuve
http://bit.ly/2Jp1AL5
Submitted May 16, 2019 at 07:03AM by oleavr
via reddit http://bit.ly/2EaCuve
Frida • A world-class dynamic instrumentation framework
Frida 12.5 Released
Inject JavaScript to explore native apps on Windows, macOS, GNU/Linux, iOS, Android, and QNX
0day "In the Wild" Spreadsheet by Google Project Zero
http://bit.ly/2HrQrFU
Submitted May 16, 2019 at 12:58PM by Fugitif
via reddit http://bit.ly/2LMIyA7
http://bit.ly/2HrQrFU
Submitted May 16, 2019 at 12:58PM by Fugitif
via reddit http://bit.ly/2LMIyA7
reddit
r/netsec - 0day "In the Wild" Spreadsheet by Google Project Zero
0 votes and 0 comments so far on Reddit
Researches Utilize Machine Learning to Perform Fingerprinting Attacks on Tor
http://bit.ly/2JGnQPK
Submitted May 16, 2019 at 02:00PM by TheProgrammar89
via reddit http://bit.ly/2Wd1sV6
http://bit.ly/2JGnQPK
Submitted May 16, 2019 at 02:00PM by TheProgrammar89
via reddit http://bit.ly/2Wd1sV6
RIT
RIT cyber fighters go deep on Tor security
Recognizing that the internet is not always secure, millions of people are turning to the Tor anonymity system as a way to browse the World Wide Web more privately. However, Tor has been found to have its own vulnerabilities. This has a team of faculty and…
Breaking UC Browser
http://bit.ly/2HqFPIJ
Submitted May 16, 2019 at 04:44PM by atomlib_com
via reddit http://bit.ly/2LNcI6u
http://bit.ly/2HqFPIJ
Submitted May 16, 2019 at 04:44PM by atomlib_com
via reddit http://bit.ly/2LNcI6u
Habr
Breaking UC Browser
Introduction At the end of March we reported on the hidden potential to download and run unverified code in UC Browser. Today we will examine in detail how it...
Thrangrycat, Cisco command Injection Vulnerability of http server & secure boot tampering
http://bit.ly/2WIvblt
Submitted May 16, 2019 at 04:12PM by Z3t4
via reddit http://bit.ly/2EfqKaJ
http://bit.ly/2WIvblt
Submitted May 16, 2019 at 04:12PM by Z3t4
via reddit http://bit.ly/2EfqKaJ
reddit
r/netsec - Thrangrycat, Cisco command Injection Vulnerability of http server & secure boot tampering
0 votes and 0 comments so far on Reddit
A Simple and Comprehensive Vulnerability Scanner for Containers, Compatible with CI
http://bit.ly/2VDXyVE
Submitted May 16, 2019 at 05:36PM by knqyf263
via reddit http://bit.ly/2Hu0J8m
http://bit.ly/2VDXyVE
Submitted May 16, 2019 at 05:36PM by knqyf263
via reddit http://bit.ly/2Hu0J8m
GitHub
knqyf263/trivy
A Simple and Comprehensive Vulnerability Scanner for Containers, Compatible with CI - knqyf263/trivy