Skip to main content

Security

World’s top 25 CTF teams to battle for $100,000 at HITB PRO CTF

posted onSeptember 24, 2019
by l33tdawg
Credit: Help Net Security

In less than a month, Hack In The Box is launching its biggest global event: HITB+CyberWeek 2019. It is a week-long gathering (October 12-17, 2019, at Emirates Palace, Abu Dhabi) that will bring together the world’s top cyber security experts to share and discuss their latest knowledge, ideas and techniques with security professionals and students.

Malindo Air identifies employees of e-commerce contractor behind data breach

posted onSeptember 24, 2019
by l33tdawg
Credit: SoyaCincau

Two rogue employees of Malaysian e-commerce services provider GoQuo have been identified as the culprits behind a security breach that compromised the personal data of Malindo Air and Thai Lion Air passengers. The Malaysian and Thai airlines are subsidiaries under Indonesia's low-cost carrier group, Lion Air.

Apple's iOS 13 iPhone software brings bugs and leaves phone vulnerable to hackers

posted onSeptember 24, 2019
by l33tdawg
Credit: Flickr

 Apple has been forced to rush out an update to the latest version of its iOS operating system today after bugs left users with a number of problems, including one that could allow hackers to access contacts on locked phones.

The new operating system launched alongside the iPhone 11 and 11 Pro phones last week, bringing a new dark mode, redesigned Photos app, and security features reflecting the company's recent focus on privacy.

Busy North Korean hackers have new malware to target ATMs

posted onSeptember 24, 2019
by l33tdawg
Credit: Arstechnica

Hackers widely believed to work for North Korea’s hermit government have developed a new strain of malware that steals data used at automatic teller machines in India, researchers from Kaspersky Lab said on Monday.

WordPress XSS Bug Allows Drive-By Code Execution

posted onSeptember 15, 2019
by l33tdawg
Credit: Threat Post

A just-patched stored cross-site scripting (XSS) vulnerability in WordPress allowed drive-by remote code-execution, according to an analysis.

The bug exists in the built-in editor Gutenberg, which is found in WordPress 5.0 and above. Zhouyuan Yang, a threat-researcher at FortiGuard Labs, said that Gutenberg fails to filter a post’s JavaScript/HTML code if there’s a “Shortcode” error message.

I Could Have Hacked All Uber Accounts- But I Chose to Report it Instead

posted onSeptember 15, 2019
by l33tdawg
Credit: HackerNoon

This post is about an account takeover vulnerability on Uber which allowed attackers to take over any other user’s Uber account (including riders, partners, eats) account by supplying user UUID in the API request and using the leaked token in the API response to hijack accounts. I was able to enumerate any other Uber’s user UUID by supplying their phone number or email address in another API request.

SIM card exploit could be spying on over 1 billion mobile phone users globally

posted onSeptember 15, 2019
by l33tdawg
Credit: Phone Arena

Researchers at a security firm named AdaptiveMobile Security have issued a report (via TNW) about a new vulnerability nicknamed Simjacker that uses your phone's SIM card to spy on you. Because all makes and models of mobile phones can be used with Simjacker, over 1 billion handsets might be affected globally. The research firm says that it believes the vulnerability was developed by a private company that works with governments to monitor the locations of individuals around the world. The exploit also can help the attackers obtain the unique IMEI number belonging to each phone.