ZERO DAILY
Hacking, AppSec, and Bug Bounty newsletter
2018-09-10 | Adware Doctor Mac App secretly logging browser history, New malware persistence method using universal windows platform apps, and Black cat hackers
Monday, September 10
TOP STORY
-
Patrick Wardle published new research on Adware Doctor, a top paid utility app in the Mac App Store that secretly logs the browser history of users, and is sending the data to a server in China. Apple has reportedly now removed the app.
TWEET OF THE DAY
-
Does it really matter, in the end, to us humble blue teamers on Twitter if WannaCry was DPRK or someone else?
Does that change the mitigations? Does it change how you triage? Does it change how you patch? - @r0wdy
OTHER ARTICLES WE’RE READING
-
How US authorities tracked down the North Korean hacker behind WannaCry by ZDNet’s Catalin Cimpanu
-
Synacktiv published PoC for an RCE flaw in the popular WordPress Duplicator plugin
-
New malware persistence method found by Norwegian researcher Oddvar Moe: Persistence using universal windows platform apps (appx). ZDNet has a high-level summary
-
Who controls your data? - Engadget’s Chris Ip requested his personal information from dozens of companies, and got a lot back.
-
Story time with Marcus: halting a DDoS attack by asking nicely to stop.
-
Can’t stop those black cat hackers
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com
42 year old me wishes 21 year old me hadn’t been talked into doing a PhD in AI and machine learning. I’d really like to be excited about all the AI/ML work going on at the moment, but all I’m seeing is the same problems/mistakes of 20 years ago, but with more CPU resources.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.