-
Mar 3, 2020
A brief update regarding the Ghostcat vulnerability that affects Apache Tomcat servers.… read more »
-
Feb 28, 2020
A research tried to quantify how often false activations happen and what the devices hear when they do… read more »
-
Feb 26, 2020
The researchers who disclosed the #aLTEr attack last year (David Rupprecht, Thorsten Holz, and Christina Pöpper), have found new ways to exploit the lack of integrity protection on the 4G/5G user plane in a new attack called #Imp4Gt
… read more »
-
Feb 25, 2020
Recently, a new vulnerability on Apache Tomcat AJP connector was disclosed.… read more »
-
Feb 21, 2020
In order to avoid #sourveillance, privacy invasion or information theft you must be sure that the data on your devices are secure, and the only way to do that in this day and age is to make sure they are… read more »
-
Feb 20, 2020
Social engineering techniques are frequently part of an overall security penetration test because also the "human network" need to be tested.… read more »
-
Feb 19, 2020
Most #Docker images build on full Linux distributions containing a lot of unnecessary complexity that affects application security. … read more »
-
Feb 18, 2020
There's no rest for the (bluetooth) wearables!
A team of security researchers have discovered numerous vulnerabilities in the Bluetooth Low Energy (BLE) implementations of major vendors.
… read more »
-
Feb 14, 2020
Coss-Site Request Forgery (CSRF) is a type of attack that cuses a user’s web browser to perform an unwanted action on a trusted site, when the user is authenticated.… read more »
-
Feb 13, 2020
Security researchers at ERNW disclosed a vulnerability in Android bluetooth stack that lets attackers deliver malware to and steal data from nearby phones… read more »
-
Feb 12, 2020
A vulnerability, discovered by Adam Thorn from the University of Cambridge, may allows attacker to abuse internet-facing Jenkins servers to mount and amplify reflective DDoS attacks… read more »
-
Feb 11, 2020
The #OWASP #Amass Project is tool developed to help information security professionals during the mapping process of attack perimeter.
#penetrationtesting #golang #cybersecurity… read more »
-
Feb 7, 2020
SpiderFoot is an OSINT automation tool for reconnaissance process, written in Python 3 and GPL-licensed. Recently, Steve Micallef released on GitHub [1] a new version (3) of SpiderFoot, with a lot of interesting enhancements. Web based UI or CLI Over 170 modules (see… read more »
-
Feb 6, 2020
Recently, developers of famous messaging app acknowledged and patched a major vulnerability that gave malicious users the ability to access files on a victim's computer. A target user may fall prey to this attack simply clicking a disguised link preview… read more »
-
Feb 5, 2020
Is it really possible to create a fake traffic jam on Google Maps? According to ArsTechnica [1] and TheRegister [2], the german artist Simon Wecker realized a performance art piece, named "Google Maps Hacks", walking around the roads of Berlin… read more »
-
Jan 31, 2020
Some funny thoughts about information technology on a post-apocalyptic environment, and some info about a more serious project! When most people think about what to do after an apocalyptic event, the first time that comes to mind is food and… read more »
-
Jan 30, 2020
Last December, in a talk at 36th Chaos Communication Congress, Samuel Groß presented a technical report about the infamous iOS vulnerability that allowed remote code execution on all iDevices up to iOS 12.4, within a couple of minutes and without… read more »
-
Jan 29, 2020
A team of researchers from University of Michigan (Stephan van Schaik, Marina Minkin, Andrew Kwong and Daniel Genkin) and University of Adelaide (Yuval Yarom) recently presented a new attack technique that targets Intel CPUs. The attack, dubbed CacheOut (CVE-2020-0549), is… read more »
-
Jan 28, 2020
Just few words (and links) about this hot topic. The Amazon billionaire Jeff Bezos had his mobile phone “hacked” in 2018 after receiving a WhatsApp message that had apparently been sent from the personal account of the crown prince of… read more »
-
Jan 24, 2020
The SIM hijacking, also know as SIM swapping, is an attack where a criminal contacts the cell phone provider of a target user, and convinces it (sometimes involving employees of the phone company) to switch target's account to a SIM… read more »