🚨MAJOR DATA BREACH🚨888 has allegedly leaked data belonging to Accenture. Revenue: $64.5 Billion
In June 2024, Accenture suffered a data breach from a third party that exposed 32,826 employees/former employees.
The Compromised Data Includes: Email Addresses, Full Names and Broadcast Dates.
🚨Outlook Zero-Click🚨TLDR; Recommended Steps for Microsoft 365 Admins can be seen in this blog post.
https://t.co/KFqwnc5Ejv
The CVE-2024-30103 vulnerability leverages a flaw in how Microsoft Outlook handles specific types of email content.
An attacker can embed malicious code within the body of an email, which gets executed as soon as the email is opened. This can lead to unauthorized access, data breaches, and further network compromise.
Automate Your XSS Detection: Top 5 Tools and Unique Commands for Pentesters and Bug Hunters
💻 These top 5 automation tools that can help make your pentesting and bug hunting easier and more efficient.
Thread 🧵 : 👇
If you want to master hacking JWT tokens, open this thread!
JWT tokens are often used to authenticate logged-in users. They do this by signing the data so that the server can verify forged tokens. But in some cases, we can bypass this protection! 🤯
A Thread 🧵👇
🥽 The Anti-Recon Recon Thread 🥽
Recon is important, but some people hate it. I get it.
When you're in the zone & ready to pounce on a target, you just want to start hacking.
Want the best of both worlds? Quick/complete recon, WITH great coverage?
(a long thread)
🧵⬇️
👮 Hacking into several Prisons 👮
Here's how I did it (legally), and what I learned along the way!
A thread for security testers and cyber security pros
🧵👇
Total loss of digital assets and compromise of every account is a terrible terrible way to learn.
Never click any links (even sponsored links) you are not absolutely sure of. And if you must, do it in a SandBox or such.
@nft_god, we can all learn sth from your thread...
Last night my entire digital livelihood was violated.
Every account connected to me both personally and professionally was hacked and used to hurt others.
Less importantly, I lost a life changing amount of my net worth
Don't get blinded by a new 'innovation' that is proprietary. If it was done inhouse and proprietary, it can also be done FREE, #opensource!
The community just needs to work together. "Together we hit harder" like @Hacker0x01 says. There is power in unity!
@fsf#infosec
As long as the code behind "smart" home devices is proprietary, these companies are free to spy on us as much as they like. Help us fight back: tell your friends about free software and urge then to join the FSF! Support #FreeSoftware. https://t.co/AAgaQ2wiBF
342 million views of "flipper zero" content on TikTok, and millions more on YouTube... apparently it can be used to change prices on gas pump displays... (script) https://t.co/VRnzeOC9jb picture src (not me) from reddit. This is going end in tears when someone gets arrested.
There's been a lot of chit-chat regarding the "Twitter DB leak". If you're curious how Threat Actors were able to get information on users via the API please see the attached images below.
Have a nice day.
tl;dr returns information if e-mail or phone number is valid
If you're interested in bluetooth low level hacking take a look at this cool project by Matheus Eduardo Garbelini (@MatheusGarbelin)
Active Bluetooth BR/EDR Sniffer/Injector: https://t.co/23zJgxEXvq
#bluetooth#esp32#espressif#hacking#infosec
If you want to master SSRF, open this thread!
Server-Side Request Forgery vulnerabilities are attacks that allow attackers to send arbitrary requests from the server often resulting in gaining authorized access to data!🤯
A Thread 🧵👇
🚨FREE TRAINING:
16-week Network Security course for anyone trying to break into cybersecurity or learn more about network security.
🔗https://t.co/KBtFLSr7A4
#Infosec#Tech#Course#TheSecureEdge
Kali Linux 2022.4 is out!
* New platforms (Azure, Generic Cloud/OpenStack, QEMU & Vagrant libvirt)
* NetHunter Pro - Kali Linux on the @thepine64 PinePhone / PinePhone Pro
* New tools
* And more
Download now! https://t.co/WrWuezbo4H
Big update! #nuclei just got a major update, adding URL Fuzzing and many new features 🧵
Release Blog –– https://t.co/23lW4w4JZz
Release CL –– https://t.co/4iPwaEZ1My
Fuzzing Templates –– https://t.co/Sk4ICb1agL
#hackwithautomation#dast#opensource#cybersecurity#bugbounty
Note that the above might not be necessary as NUCLEI currently automatically checks for and does updates, unless you've disabled that explicitly via:
nuclei -duc [-disable-update-check]
#infosec#bugbounty