sans.org – SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking is designed as a logical progression point for those who have completed SANS SEC560: Network Penetration Testing and Ethical… Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1262470531133198338
SANS@MIC Schedule
sans.org – SANS@MIC talks are special, bonus sessions open to everyone and focused on the hottest topics in cybersecurity. Here is a list of upcoming and archived talks in the series. May 18, 2020 at 3:30pm EDT… Tweeted by @SANSInstitute
Threat Hunting & Incident Response Summit & Cyber Security Training | New Orleans, LA | SANS
sans.org – Summit: Sep 10-11 | Co-Chairs: Phil Hagen and Matt Bromiley | Summit CPE Credits: 16 Training: Sep 12-17 Chances are very high that hidden threats already exist inside your organization’s networks. N… Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1262525906477875204
Tech Tuesday Workshop – O Hacker, Where Art Thou?: A Hands-On Python Workshop for Geolocating Attackers – SANS Institute
sans.org – Law enforcement is in the business of putting bad guys in jail. To do that you have to know where they are hiding. Today attackers use various techniques to obfuscate their location including hiding … Tweeted by @SANSInstitute
Lenny Zeltser
sans.org – A tech leader with extensive cybersecurity expertise, Lenny tackles foundational IT and security challenges as VP of Product at Axonius. Earlier, he helped build anti-malware software at an innovativ… Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1262057829101441026
SANS @MIC Talk – Tricking modern endpoint security products – SANS Institute
sans.org – The current endpoint monitoring capabilities we have available to us are unprecedented. Many tools and our self/community-built detection rules rely on parent-child relationships and command-line arg… Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1262368616256765954
SSD Advisory – MyLittleAdmin PreAuth RCE – SSD Secure Disclosure
ssd-disclosure.com – Find out how we managed to execute arbitrary commands on MyLittleAdmin management tool using unauthenticated RCE vulnerability. MyLittleAdmin is a web-based management tool specially designed for MS … Tweeted by @TheHackersNews https://twitter.com/TheHackersNews/status/1262328627225559041
DOM-Based XSS at accounts.google.com by Google Voice Extension.
missoumsai.com – This universal DOM-based XSS was discovered accidentally, it is fortunate that the google ads’ customer ID is the same format as American phone number format. I opened Gmail to check my inbox and the… Tweeted by @TheHackersNews https://twitter.com/TheHackersNews/status/1262328186559508481
Andreessen Horowitz Wins VC Sweepstakes To Back Clubhouse, Voice App Still In Beta, At $100 Million Valuation
forbes.com – Paul Davison, the creator of Clubhouse, seen here in 2012, just closed one of 2020’s hottest startup … [+] funding rounds. BLOOMBERG NEWS Clubhouse is a voice-based social media app with less than … Tweeted by @ComplexD https://twitter.com/ComplexD/status/1261691029494906881
Zooming Ahead Safely and Securely: SANS Interviews Zooms Head of Product Security – SANS Institute
sans.org – The COVID-19 pandemic has caused many organizations to quickly jump into increased or even first-time dependence on remote work, often relying on teleconferencing and collaboration products that they… Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1261658010478395392
Frank Kim
sans.org – Frank was also executive director of cybersecurity at Kaiser Permanente where he built an innovative security program to meet the unique needs of the nation’s largest not-for-profit health plan and i… Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1261676556155486211
Level Up – Cyber Webcasts, Posters, and More
sans.org – If you’re not able to attend one of our live events or the Level Up Roadshow, SANS always offers you the chance to attend one of our many world-class webcasts. You can find a list of some of
Opportunist Hackers “Zoom-Bombing” and Infiltrating Videoconferences Amid Coronavirus Pandemic | All About eDiscovery
allaboutediscovery.com – With much of the American workforce (and educational systems) working remotely, reliance upon videoconferencing software for workplace and educational collaboration has increased significantly. One o… Tweeted by @ComplexD https://twitter.com/ComplexD/status/1262005021958340608
SANS 2020 Automation and Integration Survey Panel Discussion – SANS Institute
sans.org – This webcast takes a deeper dive into the results of the SANS 2020 Automation and Integration Survey. A panel of sponsor representatives, led by survey author Don Murdoch and survey advisor Barbara F… Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1261642930189676545
New York’s New Data Breach Notification Law: What Businesses Should Know | JD Supra
jdsupra.com – As the COVID-19 pandemic continues to demand the attention of corporate leaders and the public at large, businesses have likely had little time to get up to speed on New York’s new data breach notifi… Tweeted by @ComplexD
Google Blocks 18 Million COVID-19 Related Scam Emails Each Day
securitymagazine.com – Google says that Gmail blocks more than 100 million phishing emails per day. Now, Google is seeing 18 million daily malware and phishing emails related to COVID-19. This is in addition to more than 2… Tweeted by @NetDiligence
Washington Governor Signs Facial Recognition Law Curbing Use
insurancejournal.com – Washington Gov. Jay Inslee has signed the first U.S. state law that sharply curbs law enforcement’s use of facial recognition technology, while civil rights activists said the measure did not go far … Tweeted by @NetDiligence https://twitter.com/NetDiligence/status/1260950836999585792
DISC – SANS ICS Virtual Conference Highlights
sans.org – If you missed the Conference or the CTF, please register here to get access to the recording sessions and to get notified when CTF content be available for download. On May 1, 2020 SANS and Dragos, I… Tweeted
RubyGems typosquatting attack hits Ruby developers with trojanized packages
csoonline.com – Over 700 malicious packages with names similar to legitimate ones have been uploaded to RubyGems, a popular repository of third-party components for the Ruby programming language. The upload took pla… Tweeted by @NetDiligence https://twitter.com/NetDiligence/status/1261279410570887170
Survey: General Counsels Too Busy With COVID-19 to Focus on Cybersecurity
ridethelightning.senseient.com – Law.com (sub.req.) reported on April 3 the results of the COVID-19 Impact Survey by Morrison & Foerster. Not a surprise, but of the 110 in-house leaders at global companies who took part in the surve… Tweeted by @ComplexD