Hacking, AppSec, and Bug Bounty newsletter
2017-12-20 | Alteryx S3 blunder is a big deal, Count the cybers, and S is for Security
Wednesday, December 20
Possibility to view subdepartments for arbitrary domain [2 upvotes] - $500 bounty for this report to Mail.Ru by @ruvlol.
UniFi Video v3.2.2 (Windows) Local Privileges Escalation due to weak default install directory ACLs [2 upvotes] - $500 bounty for this report to Ubiquiti Networks by @mrtuxracer.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
TWEET OF THE DAY
The “S” in IoT stands for security. - @DEFCON
OTHER ARTICLES WE’RE READING
Count the “cyber” references: National Security Strategy updated 12/18/17
Krebs explores and explains the market for stolen account credentials
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
It is a period of cyber war. In an effort to sustain commerce during these challenging times, the Galactic Trade Federation has required the Empire retain the services of a consultancy (a best-value provider, and only 12 parses away) to assess the state of their security before signing off on the newly-constructed DEATH STAR campus.