This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
I want to talk about 3 upcoming events which Scott Helme and I are going to be running our Hack Yourself First workshop at starting with this one: NDC Security Australia, 26-27 March, AU$800 This is an extra special event that we've only just decided to run. The website is up and running and you can go and register right now.
As part of that, I've begun lining up remote workshops which will help keep me at home whilst still being able to run my Hack Yourself First course. He'd done a very focused workshop on TLS and had absolutely knocked it out of the park - 100% positive feedback on all metrics from all attendees.
Indeed, as a technologist who studies complex systems and their security , I believe the very idea of representative government is a hack to get around the technological limitations of the past. In December 2022, I organized a workshop to discuss these and other questions. Again, we have more technology and therefor more options.
It's the Hack Yourself First UK Tour! Last year, I asked good friend and fellow security person Scott Helme to help me out running my Hack Yourself First workshops. I was overwhelmed with demand and he was getting sensational reviews for the TLS workshops he was already running.
I spend a good quarter hour at the start of this video talking about what I'll be doing, namely getting on with business and running a bunch of public workshops remotely in conjunction with Scott Helme. References You can register to do Scott Helme's and my "Hack Yourself First" workshop at NDC Copenhagen on April 1-2 right now!
Did I do the Aussie workshops last week? I actually lost track of what week it was at the start of this video. Or the week before? I know I was at home so. it's just all becoming a blur. But be that as it may, life marches on and this week like every other one before it was full of interesting cyber-things.
The simple stuff first - I'm back in Norway running workshops and getting ready for my absolute favourite event of the year, NDC Oslo. I'm also talking about Scott's Hack Yourself First UK Tour where he'll be hitting up Manchester, London and Glasgow with public workshops. Well this was a big one.
References I'm going to be in Oslo next week (Hack Yourself First workshop and NDC Security conference) Then in London the week after that (Hack Yourself First workshop and NDC conference) And I'll be in Denver for SnowFROC in March (cyber-something keynote ??)
Which brings us back to Aadhaar and some rather unpleasant headlines of late, particularly the likes of The World's Largest Biometric ID System Keeps Getting Hacked. They claim that they're hack-proof. But claiming the service is "hack-proof", that's something I definitely have an issue with. Can you prove otherwise?
Last week, I hosted a two-day workshop on reimagining democracy. I want to create a system that is resilient against hacking : one that can evolve as both technologies and threats evolve. I hope this is only the first of an ongoing series of similar workshops. Limit financial and military power?
This has been an absolutely flat-out week between running almost 3 hours of our free Cyber-Broken talk with Scott Helme, doing an hour of code with Ari each day (and helping get up to speed with remote schooling) then running our Hack Yourself First workshop on Aussie time zones the last couple of days.
Chinese researchers discovered tens of vulnerabilities in a Mercedes-Benz E-Class, including issues that can be exploited to remotely hack it. The experts said that they did not manage to hack any critical safety functions of the tested vehicles. SecurityAffairs – hacking, Mercedes). ” the paper concluded.
Today on sources and sinks, we talk to IoT hacker Aaron Guzman about his work in IoT security, his experience hacking Subaru cars, and how we can improve IoT security through regulation, policies, and education. The post Hacking IoT Security with Aaron Guzman appeared first on Security Boulevard. Follow Aaron on Twitter @scriptingxss.
Scott and I are running our workshops remotely which we've done many times before, but this is the first time the public has been able to sign up (for a fraction of the usual price too, I might add), plus we're doing our favourite talk as a free for all on Monday which to be honest, I'm really looking forward to.
Enough about that, this week I'm also talking about Scott's upcoming public Glasgow workshop, more data breaches, Namecheap's faux pas and EVE Online's great security work they've very generously shared publicly.
References Scott Helme is running my Hack Yourself First workshop in Amsterdam on Dec 9 & 10 (he's getting awesome reviews on these too) Apparently, FinecoBank in Italy reckons you should Google your password and not use it if it appears 10 times or more (no, just don't) You'll also need to pay FinecoBank € 0.95
We're talking about the event, upcoming ones, Scott's Hack Yourself First UK tour, some funky default values in EV certs and then we head off down a rabbit hole of 2FA and people getting fired for failing simulated phishing tests. References We've launched a bunch of hotel packages with the Hack Yourself First UK tour!
References The next public "Hack Yourself First" workshop Scott Helme and I are doing is "in" Melbourne later next month (ok, so it's online like everything else now, but it's at an Asia Pacific friendly time) You should see the size of the data breach that literally landed on my doorstep!!!
We hosted two editions of bugSWAT for training, skill sharing, and, of course, some live hacking in August, we had 16 bug hunters in attendance in Las Vegas, and in October, as part of our annual security conference ESCAL8 in Malaga, Spain , we welcomed 40 of our top researchers. workshops ( Las Vegas , So Paulo , Paris , and Malaga ).
It's Minnesota this week and I've just wrapped up a couple of days of Hack Yourself First workshop followed by the opening keynote at NDC followed by PubConf. After a mammoth 30-hour door-to-door journey, I'm back in the USA!
References I'm doing a free user group in Brisbane for NDC on Thursday 28 Feb (this will be a really casual presentation, Q&A and fun night out) Speaking of NDC, the show will be on in my home town of the Gold Coast in late April (that's a dedicated security event which Scott Helme will be down for too) Speaking of NDC, I'll also be at NDC Minnesota (..)
On February 20 th , we kicked off our very first Human Hacking Conference (HHC). The conference centered around training workshops that allow attendees to learn skills from professionals of various fields. Joe Navarro, a former FBI special agent , specializ ing in behavioral assessment , hosted a Nonverbal Communications workshop.
Scott Helme is now running my "Hack Yourself First" workshop in Europe (he's the perfect person for this and it'll help me spend more time at home). "The Dark Web" sounds kinda scary (but it's not - but that's what some people want you to think - but yeah, it's not!). I've now got a CSP on this blog! (it
While they are grassroots, volunteer-run, and operate independently from the main DEF CON event they share the common goal of fostering collaboration in the hacking community. 2600 groups meet to discuss hacking, security, and technology. University hacking societies University hacking societies are flourishing.
In order to empower the next generation of Android security researchers, Google has collaborated with industry partners including HackerOne and PayPal to host a number of Android App HackingWorkshops. If you get stuck and need a hint on solving a challenge, the solutions for each are available in the Android App HackingWorkshop here.
One program, for instance, puts on workshops for Congressional staffers and other federal employees on how to recognize and avoid nation-state backed hackers looking to interfere in elections. So we’ve boiled the NIST framework down into a very focused workshop exercise. A large retailer may spend millions on cyber security.
I run a workshop titled Hack Yourself First in which people usually responsible for building web apps get to try their hand at breaking them. When I show the hash approach in my workshops, I often have people ask "but does this mean I need to recalculate the hash every single time I change the script?"
The researchers disclosed the tsuNAME flaw during the DNS OARC35 workshop and shared their findings with impacted organizations giving 90 days to address it before the vulnerability was disclosed. SecurityAffairs – hacking, TsuNAME). queries/s).” ” reads the research paper published by the experts. Pierluigi Paganini.
The findings about the two attacks will be presented by two research teams at this year’s 15th IEEE Workshop on Offensive Technologies (WOOT’21). SecurityAffairs – hacking, AMD). Follow me on Twitter: @securityaffairs and Facebook. Pierluigi Paganini.
The DHS warning came in advance of a workshop to be held this weekend at the DEFCON security conference in Las Vegas, where a security researcher is slated to demonstrate multiple weaknesses in the nationwide alert system. According to the EAS wiki, in February 2013, hackers broke into the EAS networks in Great Falls, Mt. and Marquette, Mich.
When I run my Hack Yourself First workshop , that's one of the first questions I ask - "what's the correct minimum password length?" However, there was nothing on minimum required lengths , and that got me thinking - what's the correct number?
Malicious actors use emotions in human hacking with a high success rate. Learn More About Emotions and Human Hacking. The Human Hacking Conference is happening March 11-13, 2021. We just added day tickets, giving you the option of attending whatever day you want and choosing your preferred workshops!
The portal of the FBI’s InfraGard US Critical Infrastructure Intelligence was hacked, and data is available for sale on a cybercrime forum. The hack revealed the poor level of cybersecurity implemented by the FBI, the US agency told Krebs that it is aware of a potential false account associated with InfraGard. Pierluigi Paganini.
Maybe on hack-yourself-first.com 🤣 Clearly, I didn't forget and I also didn't forgive and he probably should have expected me (sorry, couldn't help myself!) But I can make mistakes. Coding mistakes. Configuration mistakes.
2020 was the kickoff of our first annual Human Hacking Conference (HHC) , and unless you’ve been living under a rock (or you don’t follow us on social media ), you’ve heard us discussing our flagship event ever since. We were excited to be hosting our second annual event, The Human Hacking Conference — Year Beta! Track 1 – Nonverbals.
As many followers know, I run a workshop titled Hack Yourself First where I spend a couple of days with folks running through all sorts of common security issues and, of course, how to fix them.
Among them were Michael Veenstra, our Web Security Research Analyst, who gave an excellent talk on The Anatomy of a Hacked Site , and Cj, our new (and awesome) Social Media Specialist. The Anatomy Of A Hacked Site. This was a weekend of not only single sessions, but workshops as well. Shayda Torabi. Nathan Ingram @nathaningram.
Then there's the authentication process itself and it reminds me of a discussion I had with a bank's CISO during a recent workshop. I'd just spent two days with his dev team hacking themselves first and I raised the bollocking they were getting on social media due a new password policy along the lines of those in the tweets you see above.
NewPassword: passw0rd ConfirmPassword: passw0rd This is a real request from my Hack Yourself First website I use as part of the workshops Scott Helme and I run. Way back in 2010 I was writing about this as part of the OWASP Top 10 for ASP.NET series and a near decade on, it's still a problem.
Maritime Attacks : Andrew Tierney examined potential remote hacks on ships and thoroughly discreted claims that the MV Dali was hacked before it collided with the Francis Scott Key bridge. Workshops : Hands-on sessions learning to pilot large ships in constrained harbours, also teaching aviation security. The focus this year?
“The identified use cases that emerged from the workshops Europol carried out with its experts are by no means exhaustive. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini ( SecurityAffairs – hacking, ChatGPT) The post Europol warns of criminal use of ChatGPT appeared first on Security Affairs.
We organize all of the trending information in your field so you don't have to. Join 28,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content