Wednesday, February 14
TOP STORY
Olympic Destroyer modifies itself to include harvested credentials. Talos updated their initial blog post to reflect the new finding. Endgame wrote a brief overview on their analysis and how to stop #OlympicDestroyer.
HACKTIVITY
Improper markup sanitisation in Simplenote Android application. [8 upvotes] - $300 bounty for this report to WordPress by @edoverflow.
Prototype pollution attack (Hoek) [2 upvotes] - no bounty for this report to Node.js third party modules by @holyvier.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
TWEET OF THE DAY
Yes, let's - @helenvholmes
OTHER ARTICLES WE’RE READING
Skype bug too hard to fix. Technical security debt is so fun.
Georgia State Senate passed S.B 315 (without Senator Jennifer Jordan’s improvements)
How goes the vote-protection efforts? Not as good as one would hope.
Intel’s bug bounty goes public (and ups bounties)
Lukasz Olejnik analyzes the French cybersecurity strategy
Equifax: More private data was stolen in 2017 breach than first revealed
Want to see a photo of a single atom?
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com
Get this email forwarded to you? Click here to subscribe to the Zero Daily
The credentials have not been hardcoded into the binary by the attackers themselves. The malware dynamically updates this list after using the password stealers. A new version of the binary is generated with the newly discovered credentials. This new binary will be used on the new infected systems via the propagation. This feature explains why we discovered several samples with different sets of credentials that were collected from previously infected systems.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.