Hacking, AppSec, and Bug Bounty newsletter
2018-06-11 | Windows red team profile, Comsec best practices for journalists, and Live Overflow asks what’s going on with zip files?
Monday, June 11
South Korean cryptocurrency exchange, Coinrail, was the victim of a cyber attack with the criminals reportedly stealing $40 million worth of cryptocurrency. Skittish markets reacted, and $45 billion in crypto market value was wiped out over the weekend reports Quartz.
TWEET OF THE DAY
Well this was an unexpected piece of mail… - @jstnkndy
OTHER ARTICLES WE’RE READING
Reuter’s reports the recovery cost of the Atlanta cyber attack is over $9.5 million. The ransom requested back in March was about $51,000 in BTC.
Tool: Archaeologit scans the history of a user's GitHub repositories for a given pattern to find sensitive things.
Wired story on the Windows red team
Opsec, Comsec, OSINT: Julian Sanchez’s advice for journalists on comsec best practices “Secure communications in 2018 are a core professional ethics obligation for journalists”.
Live Overflow asks “what’s going on with .zip files?”
"Zero Click" Remote Code Execution in Mycroft AI vocal assistant
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
We want to emulate the kinds of things we’ve seen in the wild and then take it to the next level.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.