ZERO DAILY
Hacking, AppSec, and Bug Bounty newsletter
2019-01-18 | MSFT Azure DevOps bug bounty, Cybersecurity and hacking book club on Discord, and Unit42’s research on Rocke group malware
Friday, January 18
TOP STORY
-
Upgaurd researchers found an open end point via Shodan of the Oklahoma Office of Management and Enterprise Services (OMES) that contained terabytes of confidential government data including information relating to FBI investigations. More from ZDNet.
TWEET OF THE DAY
-
Was bored today and created http://bugbounty.link/ ! It's a URL Shortening service, useful for generating redirects on the fly when testing for SSRF's, etc. You can redirect to any protocol: file, gopher, etc. - @hacker_
OTHER ARTICLES WE’RE READING
-
MSFT Azure DevOps bug bounty offering up to $20K per bug.
-
Stanford rolling out a bug bounty program. Only current students can participate, however.
-
Unit42 research on the evolution of malware used by “Rocke” group that can evade detection by cloud security products
-
You’re invited: cybersecurity and hacking book club on @apiratemoo’s discord.
-
Attending a con? Nervous AF? You’re not alone - solid advice from @daeken, if you’re at #shmoocon, say wassup
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com
I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo