ZERO DAILY

Hacking, AppSec, and Bug Bounty newsletter

2018-07-12 | Neatly bypassing CSP, Buying airport security system intel for $10 on the dark web, and Axios’ guide to reading the cybersecurity news

Thursday, July 12

TOP STORY

TWEET OF THE DAY

  • #BugBountyTip When you are dealing with XSS try to change the device or user-agent to Mobile you might get it work, in my case the homepage is different in devices the XSS is in username and the payload is Unicode UTF-16 - @RenwaX23

OTHER ARTICLES WE’RE READING

ABOUT ZERO DAILY

Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.

Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?

Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com

Get this email forwarded to you? Click here to subscribe to the Zero Daily

When companies fix security flaws, that's good: If a headline says that a product has a security flaw, that usually it means that product just got more secure — it was announced because it has just been patched. Don't take it to mean that product is less secure than its competition. All products have vulnerabilities.

Joe Uchill

 


HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.