-

Twitter avatar for @AlexH_Johnson
Alex Johnson @AlexH_Johnson
OMFG

Wells Fargo gets into huge legal trouble so often that it has started talking about it as a category of regular operational expense in its earnings.

Here's the CFO explaining how operating losses due to legal problems were down $2.3 billion between September and December.

Image

-

Twitter avatar for @DhiyaneshDK
Dhiyaneshwaran @DhiyaneshDK
CVE-2022-47966: ManageEngine RCE 🔥

Nuclei Template : github.com/projectdiscove… @pdnuclei

Shodan Query: title:"ManageEngine"

#pdresearch #nuclei #hackwithautomation #bugbounty

Image

-

Twitter avatar for @mdowd
mdowd @mdowd
Finding bugs that turn out to be useless can be demoralising but usually finding those means you’re on the right track!

Remember: The road to exploitable bugs is paved with unexploitable bugs

-

Twitter avatar for @ncdinglis
Chris Inglis @ncdinglis
Today I welcomed members of the cybersecurity research community to the White House.  These subject matter experts are key to addressing cybersecurity threats and their contributions to our defense are valuable and valued.   

-

Twitter avatar for @ihackbanme
Zuk @ihackbanme
The recent WhatsApp accounts takeover is simple and genius.

This is how it works: You're sleeping. A "hacker" tries to login to your account via WhatsApp. You get a text message with a pincode that says "Do not share this".

You don't share it, yet you still get hacked.

How?

Twitter avatar for @ihackbanme
Zuk @ihackbanme
The attacker clicks on the option that the SMS didn't arrive and asks for a verification by phone.

WhatsApp call you. You're sleeping. It goes to Voicemail. The voicemail stores the automated voice with the pincode that the attackers are trying to obtain.

Twitter avatar for @ihackbanme
Zuk @ihackbanme
Twitter avatar for @JBurnsKoven
J. Burns Koven @JBurnsKoven
After years of back-to-back record-setting ransomware payouts, 2022 stands apart. 

Our data shows a steep – 40% — drop in ransomware payments. 

There’s multiple factors to consider: 🧵 https://t.co/cUwYDoA8lR

-

This was clever. A programmatic ad company bought ad slots in mobile apps to abuse. They pushed JavaScript to the ad slot which loaded and played 25 video ads stacked on top of each other in that one slot. So they got paid 25x for each ad slot they bought. Which was a lot. Targeting 1700 apps across 11 million devices and peaking at 12 billion ads per day.


-

Don't miss what's next. Subscribe to the grugq's newsletter: