If you're ever wondering what the newest vulnerability to worry about is, check out our trending CVE blog series - updated weekly here - https://t.co/qXpYkRQTxb #nopsec#TrendingNow#CyberSecurity#vulnerability
@nopsec is currently looking for pen testers / red teamers in NYC or remote. Python coding and senior experience as pen tester required. Ping us if interested / pls retweet.
Remember the Cisco Router vulnerabilities (CVE-2019-1652, CVE-2019-1653) that were trending back in January? It turns out the patch was incomplete. No fix at the moment. https://t.co/zAUpHcdvsx …
NEW BLOG POST: The trending CVE for this week is...
drumroll please...
NOT an iPhone Facetime vulnerability!
[crowd boos]
Hey, this one (CVE-2019-1653) is still a big deal! Sanja Nadic (@nsanja) fills us in on all the details here:
https://t.co/VCcV4Fa2vu
Microsoft will be using Chromium to make their own browser. With a more homogenous ecosystem, Chrome 0-days become much more significant:
"the two vulnerabilities were being chained together to escape the Chrome browser sandbox and execute malicious code"…https://t.co/TSqCpyQd21
Loving this paper on misuse and inadequacy of the CVSS score:
https://t.co/Qrgw9b1KEk
"Misuse of CVSS as a risk score means you are not likely learning what you thought you were learning from it, while the formula design flaw means that the output is unreliable regardless."
NIST Teams up with IBM Watson AI System to Score Vulnerabilities, but Hold your Excitement!
Read our new blog post to find out why
https://t.co/AtQdohKSsh