@SwiftOnSecurity While FIDO2 would do the job by preventing the attack during the authentication phase, we still need a standardized method to bind the already established sessions to the device that originated them
@KacperSzurek Było nawet takie pojęcie jak „reklamacja” tasm (dziwna kalka językowa od reclaim), gdzie przepisywało się fragmenty taśm na inne, kiedy dane w połowie taśmy expirowaly :) moje czasy LTO3 :)
🎬Phishing LinkedIn and bypassing MFA demo created for the upcoming Evilginx Pro post 🔥
💡Evilginx uses a background browser to capture the secret token from legitimate website and inject it back into the reverse proxy phishing session.
P.S. Enjoy that Cyberpunk tune I made 🎵
BREAKING: Announcing Evilginx Mastery course price & release date!
🗓️Date: May 10th 2023
💳Price: 399 EUR (359 EUR with -10% release discount)
📝Sign up here: https://t.co/ks7MQwQVha
⭐️Evilginx 3.0 & online documentation will also be released on the same day!
I made a VGP (very good program) that makes it so it looks like I’m typing on slack whenever anyone else is typing, and stops when they stop.
Everyone loves it so far and doesn’t find it annoying at all!
https://t.co/W8e2EKuVXX
THREAD with a couple of interesting bits from @AmnestyTech's new report on what they learned from looking for NSO Group's spyware on phones https://t.co/CG60vx7cRg
#FIDO is amazing, it just wasn't designed to replace CAPTCHA ;) That Cloudflare's experiment seems to be doomed (https://t.co/GNMeBtKMGC)
#u2f#fido2#yubico
Wow, we (+@h0t_max and @_Dmit) have found two undocumented x86 instructions in Intel CPUs which completely control microarchitectural state (yes, they can modify microcode)
Infosec fail thread:
So, in the last couple of weeks I've been looking into a product we were thinking of offering to our customers.
This time, we were looking into the FootfallCam 3D plus. A counter system to measure how many people are in a building.
1/n