ZERO DAILY
Hacking, AppSec, and Bug Bounty newsletter
2018-09-21 | Hacktivity highlights, White House releases National Cyber Strategy, and AV complexity is the enemy of security
Friday, September 21
HACKTIVITY HIGHLIGHTS
-
Unauthenticated access to Zendesk tickets through [redacted] Okta bypass [26 upvotes] - $5,000 bounty for this report to Shopify by @rijalrojan
-
Remote Command execution due to image tragick [26 upvotes] - Great PoC and find published by @alyssa_herrera
-
Brave Browser unexpectedly allows to send arbitrary IPC messages [6 upvotes] - $300 bounty for this report to Brave Software by @masatokinugawa
OTHER ARTICLES WE’RE READING
-
Washington Post reports that The White House authorizes ‘offensive cyber operations’ to deter foreign adversaries. See the full “National Cyber Strategy” document published by the White House.
-
New York Attorney General published report of the inner workings of 10 popular cryptocurrency exchanges. MIT Tech review has a the high-level review.
-
NSO Group’s iPhone sypware up close and personal view by Motherboard
-
AV complexity is the enemy of security thoughts by Beau Woods in Axios
-
Happy Friday! Japan lands bouncing robots on asteroid
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com
We are all standing knee deep in tinder and soaked in gasoline
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.