@MrAndrewDear If an endpoint is already compromised and malware is running under the user context, also encrypred data like cookies/bookmarks can be decrypted. So I don't get your point.
Bybit Hack Forensics Report
As promised, here are the preliminary reports of the hack conducted by @sygnia_labs and @Verichains
Screenshotted the conclusion and here is the link to the full report: https://t.co/3hcqkXLN5U
Cloudflare itself can be used to bypass Cloudflare WAFs.
Read more about this vulnerability in our blogpost. Research by @fschweitzer and Stefan Porksch.
https://t.co/9gileyESBZ
We proactively took over subdomains of large vulnerable organizations (CNN, Stanford University, US states, governments, the australian foreign ministry, banks and insurances, FPÖ, ...) to protect them from malicious actors. Audit your DNS records!
Skynet wants your passwords! - A blog series about social engineering using AI. In the first post, we explore what is currently possible and what the future might hold: https://t.co/kIezjuWuTS
Sicherheitsforscher von Certitude konnten zwei kritische Schwachstellen bei der SPÖ-Mitgliederbefragung identifizieren. Manipulation von Stimmen wäre mit einfachen Mitteln möglich gewesen. (1/7)
https://t.co/d7HQ5qNQX3
https://t.co/iPh1Ni61zK reports on the warning from Certitude Consulting of a current wave of CEO-fraud-like attacks on the clearing departments of companies in the DACH region.
https://t.co/ulX9rsMBNA
Certitude notices increase in online fraud against accounting of companies in DE and AT in recent weeks. Attackers make customers change supplier IBAN. Damages often > 100.000€.
https://t.co/84ZCBvMiyA
There are web vulnerabilities beyond the @owasp top 10. The SOP should protect users by isolating different websites. This isolation is not entirely waterproof. See our recent blog post.
#security#pentesting#owasp
https://t.co/kIFqSJN2gP
In the current issue of the news magazine Profil, @FSchweitzer, Ulrich Kallausch and @nimmerrichterm from Certitude Consulting provide information about cyber weapons and vulnerability trading.
https://t.co/7sRQBBBOST
Scammers try their luck with well-disguised phishing emails. Giulian Guran (@deep_rooted ), IT security expert at Certitude Consulting, provides information about a current campaign to the Austrian newspaper derstandard (German).
https://t.co/PxD7ycIsGc
Do not browse the web in in-app browsers (e.g. in apps like Facebook, Instagram, TikTok). Experience is bad. Those apps also INJECT TRACKING INSTRUCTIONS. They control every interaction, all that is typed, clicked... Browse with normal web browsers. https://t.co/DKYbf9EkI9
A neat approach for invisible backdoors in legitimate JavaScript source code. Can you spot it? Hint: unlike #TrojanSource, it does not use Unicode bidirectional-trickery! https://t.co/SVxcUfKdbj