Category: Mix

yet another Bug Bounty Reconnaissance Framework – honoki
23
Aug
2023

yet another Bug Bounty Reconnaissance Framework – honoki

An example use case of bbrf, here integrating with subfinder from projectdiscovery.io Like anyone involved in bug bounty hunting, I…

WILSON Cloud Respwnder – honoki
22
Aug
2023

WILSON Cloud Respwnder – honoki

If you’re a Burp Suite user, you’ll be familiar with Burp Collaborator: a service that allows you to monitor out-of-band…

Axel Springer National Media & Tech launches a public bug bounty program on Intigriti
22
Aug
2023

Axel Springer National Media & Tech launches a public bug bounty program on Intigriti

Axel Springer has long been a pioneer in the digital publishing industry, with a vast portfolio of brands, such as…

Take Care of Orphan APIs with Wallarm
21
Aug
2023

Take Care of Orphan APIs with Wallarm

The Wallarm API Discovery module has been further enhanced to enable customers to identify Orphan APIs and bring them under…

ATHI — An AI Threat Modeling Framework for Policymakers
20
Aug
2023

ATHI — An AI Threat Modeling Framework for Policymakers

My whole career has been in Information Security, and I began thinking a lot about AI in 2015. Since then…

API4:2023 Unrestricted Resource Consumption
19
Aug
2023

API4:2023 Unrestricted Resource Consumption

Welcome to the 5th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…

Impact of the New SEC Cyber Incident Reporting Rules on the C-Suite and Beyond
18
Aug
2023

Impact of the New SEC Cyber Incident Reporting Rules on the C-Suite and Beyond

We recently hosted a compact and very engaging panel discussion about the new SEC Cyber Incident Reporting Rules due to…

Be a Hype Man For Your Friends · rez0
18
Aug
2023

Be a Hype Man For Your Friends · rez0

Explaining the benefits of hyping up your friends’ ideas. Amplify (ˈam·pləˌfī) verb: To make larger, greater, or stronger; enlarge; extend….

Hackerone logo
18
Aug
2023

How Ethical Hackers Help the CISO Budget [4 Takeaways from CISOs]

Over the course of a few weeks, we had conversations with 50+ CISOs and security leaders from a wide range…

[tl;dr sec] #195 - Kubernetes Exposed, SBOMs, Elastic's Vuln Management
17
Aug
2023

[tl;dr sec] #195 – Kubernetes Exposed, SBOMs, Elastic’s Vuln Management

I hope you’ve been doing well! Hacker Summer Camp This year was my first time in Vegas since the pandemic,…

Unsupervised Learning NO. 394
16
Aug
2023

Unsupervised Learning NO. 394

Unsupervised Learning is a Security, AI, and Meaning-focused podcast that looks at how best to thrive as humans in a…

feedback
16
Aug
2023

OAuth and PostMessage

Tl;DR; An OAuth misconfiguration was discovered in the redirect_uri parameter at the target’s OAuth IDP at https://app.target.com/oauth/authorize, which allowed attackers…