ZERO DAILY
Hacking, AppSec, and Bug Bounty newsletter
2018-07-12 | Neatly bypassing CSP, Buying airport security system intel for $10 on the dark web, and Axios’ guide to reading the cybersecurity news
Thursday, July 12
TOP STORY
-
Axios' guide to reading the cybersecurity news in the latest Codebook. Good tips to share with friends and family!
TWEET OF THE DAY
-
#BugBountyTip When you are dealing with XSS try to change the device or user-agent to Mobile you might get it work, in my case the homepage is different in devices the XSS is in username and the payload is Unicode UTF-16 - @RenwaX23
OTHER ARTICLES WE’RE READING
-
IBM reports the cost of data breaches is on the rise, up to $350 million price tag
-
Cisco patches critical VoIP bug CVE-2018-0341 and also shipped fixes for two medium-severity flaws in the Cisco FireSIGHT System Software
-
Juniper Research reports IoT security spending will reach $6 billion by 2023
-
What will $10 buy you on the dark web? Access to major airport's security system reports the McAfee Advanced Threat Research team.
-
Wallarm blogs about neatly bypassing CSP
-
Bitcanal gets the boot Brian Krebs reports
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com
Get this email forwarded to you? Click here to subscribe to the Zero Daily
When companies fix security flaws, that's good: If a headline says that a product has a security flaw, that usually it means that product just got more secure — it was announced because it has just been patched. Don't take it to mean that product is less secure than its competition. All products have vulnerabilities.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.