Hacking, AppSec, and Bug Bounty newsletter
2019-01-18 | MSFT Azure DevOps bug bounty, Cybersecurity and hacking book club on Discord, and Unit42’s research on Rocke group malware
Friday, January 18
Upgaurd researchers found an open end point via Shodan of the Oklahoma Office of Management and Enterprise Services (OMES) that contained terabytes of confidential government data including information relating to FBI investigations. More from ZDNet.
TWEET OF THE DAY
Was bored today and created http://bugbounty.link/ ! It's a URL Shortening service, useful for generating redirects on the fly when testing for SSRF's, etc. You can redirect to any protocol: file, gopher, etc. - @hacker_
OTHER ARTICLES WE’RE READING
MSFT Azure DevOps bug bounty offering up to $20K per bug.
Stanford rolling out a bug bounty program. Only current students can participate, however.
Unit42 research on the evolution of malware used by “Rocke” group that can evade detection by cloud security products
You’re invited: cybersecurity and hacking book club on @apiratemoo’s discord.
Attending a con? Nervous AF? You’re not alone - solid advice from @daeken, if you’re at #shmoocon, say wassup
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.