@Davedittrich, do you know of anyone who would have a database or data set of email phishing messages? I've got a doctoral student that I'm working with that needs data to validate a model he is working on for his dissertation.
Tech domination? Apple, Microsoft, Amazon, Facebook and Google's parent now account for nearly 18% of the S&P 500 index by market value. Read: @stanchoe https://t.co/XHH45fCYM9
Global #Ransomware Damage Costs Predicted To Reach $20 Billion (USD) By 2021. Ransomware is expected to attack a business every 11 seconds by the end of 2021. REPORT: https://t.co/cAY1WBuDyJ - by Cybersecurity Ventures @CybersecuritySF, Sponsored by @KnowBe4
Lateral phishing uses a compromised account inside an organisation to send out further phishing emails. Ho et al. investigate how widespread this is, and the modus operandi and success rates of attackers. https://t.co/BluDbPMef2
We talked to @Hacker0x01 CEO Marten Mickos about the bug bounty landscape - Including the EU rolling out bounties for 14 open source projects. Full video coming today on Threatpost. #bugbounty
Excited about the release of fastai v1! fastai is the 1st deep learning library to provide a single consistent (& state-of-the-art) interface to:
- vision
- text
- tabular data
- time series
- collaborative filtering
https://t.co/shHEz1tEsR
Some updates to the free Kali Linux Revealed PDF with a handy PDF table of contents. Did I mention free? And awesome? :-) https://t.co/Bwtm5Hkxh8 @kalilinux
1977: Alice and Bob became a thing. Ron Rivest first introduced Alice and Bob in the paper "A Method for Obtaining Digital Signatures and Public-Key Cryptosystems".
My advice to IT pros is to become a 'pull' learner versus waiting for information to be pushed on to you if you want to keep up against the modern attacker. Often the mitigating controls are already in your technology stack, if you investigate how it works and think creatively.
TL;DR on the KRACK WPA2 stuff - you can repeatedly resend the 3rd packet in a WPA2 handshake and it'll reset the key state, which leads to nonce reuse, which leads to trivial decryption with known plaintext. Can be easily leveraged to dump TCP SYN traffic and hijack connections.