Hacking, AppSec, and Bug Bounty newsletter
2018-03-12 | Elegant Slingshot malware, TLS 1.3 debates, and Web Hacking 101
Monday, March 12
TWEET OF THE DAY
I am doing a research for #BHUSA CFP. In order to convince my research works, I just finished a beautiful exploit chain that chained 5 bugs to RCE on a big vendor. I can promise this is more awesome than the chain in my GitHub SSRF to RCE case(http://blog.orange.tw/2017/07/how-i-chained-4-vulnerabilities-on.html …) Hint: Java - @orange_8361
OTHER ARTICLES WE’RE READING
Don’t call it a comeback… New traces of Hacking Team in the wild
Newest version of Web Hacking 101 by @yaworsk is out
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
For years I have struggled to remember names, conversations and encounters. I always thought it was because I was forgetful, turns out I’m just #GDPR compliant.