■■■■■ #GoodRead #News #Politics #CyberWar #Israel #Iran #Natanz #Kaspersky #Siemens #Dutch #nuclear #IAEA #StuxNet #OlympicGames #AIVD
https://news.yahoo.com/revealed-how-a-secret-dutch-mole-aided-the-us-israeli-stuxnet-cyber-attack-on-iran-160026018.html;_ylt=AwrXgSOzPW1d41oADijQtDMD;_ylu=X3oDMTByb2lvbXVuBGNvbG8DZ3ExBHBvcwMxBHZ0aWQDBHNlYwNzcg--
https://news.yahoo.com/revealed-how-a-secret-dutch-mole-aided-the-us-israeli-stuxnet-cyber-attack-on-iran-160026018.html;_ylt=AwrXgSOzPW1d41oADijQtDMD;_ylu=X3oDMTByb2lvbXVuBGNvbG8DZ3ExBHBvcwMxBHZ0aWQDBHNlYwNzcg--
Yahoo News
Revealed: How a secret Dutch mole aided the U.S.-Israeli Stuxnet cyberattack on Iran
For years, an enduring mystery has surrounded the Stuxnet virus attack that targeted Iran’s nuclear program: How did the U.S. and Israel get their malware onto computer systems at the highly secured uranium-enrichment plant?
■■■□□ #China #CyberWar #APT target #FortiNet #PulseSecure #VPN
https://www.zdnet.com/article/a-chinese-apt-is-now-going-after-pulse-secure-and-fortinet-vpn-servers/
https://www.zdnet.com/article/a-chinese-apt-is-now-going-after-pulse-secure-and-fortinet-vpn-servers/
ZDNET
A Chinese APT is now going after Pulse Secure and Fortinet VPN servers
Security researchers spot Chinese state-sponsored hackers going after high-end enterprise VPN servers.
■■□□□ #Fine on #YouTube by #USA government.
https://thehackernews.com/2019/09/youtube-kids-privacy-fine.html
https://thehackernews.com/2019/09/youtube-kids-privacy-fine.html
■■■□□ #Claim #Research by #Tide
https://www.darkreading.com/operations/new-technique-makes-passwords-14m-percent-harder-to-crack-nonprofit-claims/d/d-id/1335748
https://www.darkreading.com/operations/new-technique-makes-passwords-14m-percent-harder-to-crack-nonprofit-claims/d/d-id/1335748
Dark Reading
New Technique Makes Passwords 14M Percent Harder to Crack, Nonprofit Claims
Tide's method for protecting passwords splinters them up into tiny pieces and stores them on distributed nodes.
■■■□□ #GoodRead
https://medium.com/@linasvaliukas/by-the-way-the-list-of-ssl-tls-certificates-issued-to-you-including-subdomains-is-public-5537ef1f11f5
https://medium.com/@linasvaliukas/by-the-way-the-list-of-ssl-tls-certificates-issued-to-you-including-subdomains-is-public-5537ef1f11f5
Medium
By the way, the list of SSL/TLS certificates issued to you (including subdomains) is public!
Are you comfortable with the fact that others can find out about your production environment simply by querying a public database?
■■■■■ #BreakDown of #iPhone #hack
#GoodRead #Muslim #Uighur #CyberWar #opression #China #Google #P0
https://www.wired.com/story/ios-hacks-apple-response/amp
#GoodRead #Muslim #Uighur #CyberWar #opression #China #Google #P0
https://www.wired.com/story/ios-hacks-apple-response/amp
WIRED
Apple Defends iOS Security a Week After Hacking Campaign
In its first public statement since Google revealed a sophisticated attack against iOS devices, Apple defended its security measures.
■■■■□ #PDF #HTTP Request Smuggling #HRS Document Dated: 2005
https://www.cgisecurity.com/lib/HTTP-Request-Smuggling.pdf
https://www.cgisecurity.com/lib/HTTP-Request-Smuggling.pdf
■■■□□ #GoodReport
#xh3n1
https://hackerone.com/reports/638635
Disclosed at: 2019-09-08 09:55:04 UTC+0
Created at: 2019-07-09 23:30:54 UTC+0
#xh3n1
Insecure Zendesk SSO implementation by generating JWT client-side https://hackerone.com/reports/638635
Disclosed at: 2019-09-08 09:55:04 UTC+0
Created at: 2019-07-09 23:30:54 UTC+0
HackerOne
Trint Ltd disclosed on HackerOne: Insecure Zendesk SSO...
## Summary:
app.trint.com implements SSO to Zendesk, it does this by using JWT as described at...
app.trint.com implements SSO to Zendesk, it does this by using JWT as described at...