Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Zero-Day Defense: Tips for Defusing the Threat

Because they leave so little time to patch and defuse, zero-day threats require a proactive, multilayered approach based on zero trust.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Druva Introduces the Data Resiliency Guarantee of up to $10 Million

The new program offers robust protection across all five data risk categories: cyber, human, application, operation, and environmental.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Netskope Acquires Infiot, Will Deliver Fully Integrated, Single-Vendor SASE Platform

Converged SASE platform provides AI-driven Zero trust security and simplified, optimized connectivity to any network location or device, including IoT.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CompTIA CEO Outlines Initiative to Create the Pre-eminent Destination to Start, Build and ‘Supercharge’ a Tech Career

Todd Thibodeaux uses ChannelCon 2022 state of the industry remarks to unveil CompTIA’s Project Agora; invites broad industry participation in the effort to fight for tech talent.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
ShiftLeft Appoints Prevention-First, Cybersecurity Visionary and AI/ML Pioneer Stuart McClure as CEO

Serial entrepreneur, cybersecurity leader, and industry veteran joins ShiftLeft to drive growth and AI/ML innovation globally.
Dark Reading: Attacks/Breaches
Cyberattackers Drain Nearly $6M From Solana Crypto Wallets

So far, the ongoing attack has impacted nearly 8,000 Solana hot wallets.
Dark Reading: Attacks/Breaches
School Kid Uploads Ransomware Scripts to PyPI Repository as 'Fun' Project

The malware packages had names that were common typosquats of a legitimate widely used Python library. One was downloaded hundreds of times.
Dark Reading: Attacks/Breaches
Critical RCE Bug in DrayTek Routers Opens SMBs to Zero-Click Attacks

SMBs should patch CVE-2022-32548 now to avoid a host of horrors, including complete network compromise, ransomware, state-sponsored attacks, and more.
hacking: security in practice
DefCon 2022 Ticket

A family emergency came up and I'm no longer able to attend. My airfare and lodging was refunded/given credit but my DefCon 30 ticket is non-refundable. However, it is transferrable. I'm looking to give it to someone that's deserving and is able to use it. I am not supplying your airfare nor room and board, just the DefCon Ticket ($360 value).

State why you deserve the ticket over everyone else and the most upvoted comment will get the ticket. Again, please don't comment if you can't attend.

UPDATE: This ticket is just for DefCon 30, not BlackHat.

submitted by /u/honcohi
[link] [comments]
hacking: security in practice
How does Twitter know?

How does Twitter know that I'm starting a new account after being banned?

I use Linux, Firefox and a VPN. I register using email. Before I register the new account I purge Firefox from the system and reinstall it. I get a new email account from a free email service. All using the VPN. No similar identifiers from the last account, no cookies left over. I logged into a different country on the VPN. And still, twitter knew my new account was bogus and wouldn't complete the registration. How do they know? Can a browser reveal a machine serial number or some such?

I've succeeded doing this in the past, so I wonder what's going on.

submitted by /u/Just-10247-LOC
[link] [comments]
Dark Reading: Attacks/Breaches
How IT Teams Can Use 'Harm Reduction' for Better Cybersecurity Outcomes

Copado's Kyle Tobener will discuss a three-pronged plan at Black Hat USA for addressing human weaknesses in cybersecurity with this medical concept — from phishing to shadow IT.
Dark Reading: Attacks/Breaches
New Startup Footprint Tackles Identity Verification

Early-stage startup Footprint's goal is to provide tools that change how enterprises verify, authentication, authorize, and secure identity.
Sudomy-A Subdomain Enumeration And Analysis Tool

Sudomy is a subdomain enumeration tool for collecting subdomains and performing advanced automated reconnaissance on domains (framework)…Continue reading on Medium »
Read more...
Sudomy is a subdomain enumeration tool for collecting subdomains and performing advanced automated reconnaissance on domains (framework)…Continue reading on Medium » (https://medium.com/@nixiebytes/sudomy-a-subdomain-enumeration-and-analysis-tool-e2521e544344?source=rss------bug_bounty-5)
hacking: security in practice
Best hackers on Twitter?

Hello everyone,

Who are the best hackers that you know of on Twitter? Hackers that will respond with questions you have for them.

Thank you,

submitted by /u/Koolji
[link] [comments]
Django web applications with enabled Debug Mode, DB accounts information and API Keys of more than 3,100 applications were exposed on internet, many of which are of either Oauth or RESTfull API
https://www.reddit.com/r/redteamsec/comments/wfuosi/django_web_applications_with_enabled_debug_mode/

submitted by /u/Late_Ice_9288 (https://www.reddit.com/user/Late_Ice_9288)
[link] (https://blog.criminalip.io/2022/07/20/api-key-leak/) [comments] (https://www.reddit.com/r/redteamsec/comments/wfuosi/django_web_applications_with_enabled_debug_mode/)
Hard coded Google API keys. Pardon my ignorance here but I’m fairly new to bug bounties. Should a find like this be reported? The security on this app looks like a train wreck. I don’t even know where to start.
https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/

submitted by /u/Montanacybergrizz (https://www.reddit.com/user/Montanacybergrizz)
[link] (https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/) [comments] (https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/)