Hacking, AppSec, and Bug Bounty newsletter
2018-06-15 | Tapplock smart lock pwnage, ADB.miner malware affecting Amazon Fire devices, and CloudScraper tool
Friday, June 15
China-linked cyber espionage group (LuckyMouse, Emissary Panda, APT27 and Threat Group 3390) has targeted a national data center in Central Asia. Kaspersky Lab researchers identified the attack in March.
TWEET OF THE DAY
I think we can all agree that YOLO should be used more often when processing reports on HackerOne. - @jackhcable
OTHER ARTICLES WE’RE READING
PenTest Partners blogs about their pwnage of the Tapplock smart lock. The only thing needed to unlock the lock is to know the BLE MAC address that is broadcast by the lock. Not to mention the physical security gaps.
Phishing attack compromised 23,000 in HealthEquity Data Breach.
ADB.miner Android malware affecting Amazon Fire devices
Tool: CloudScraper supporting AWS, Azure, Digital Ocean
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: email@example.com
Get this email forwarded to you? Click here to subscribe to the Zero Daily
They’ve gone for the “AES 128-bit encryption” with an inference that their security is on a parallel with the military. It must be secure! This is a red flag to a IoT hacker though – it ignores pairing, key exchange, key sharing… and most importantly, makes no mention of authentication. Time and time again we see AES-128 used in manners that make it entirely insecure.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.