KeySteal could allow someone to steal your Apple Keychain passwords

The researcher says it works without root or administrator privileges and without password prompts. But he’s not revealing how it works to Apple because there’s no money for him in its invite-only/iOS-only bounties. Continue reading KeySteal could allow someone to steal your Apple Keychain passwords

Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors

More companies are looking to adopt “safe harbor” language in their bug bounty programs to build trust with participants. Continue reading Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors

Jason Haddix, Bugcrowd – Paul’s Security Weekly #564

As the Vice President of Trust & Security, Jason works with clients and security researchers to create high value, sustainable, and impactful bug bounty programs. Full Show Notes Subscribe to YouTube Channel
The post Jason Haddix, Bugcrowd –… Continue reading Jason Haddix, Bugcrowd – Paul’s Security Weekly #564

Jeff Man, Recap of RSAC – Paul’s Security Weekly #557

This week in the Topic Segment, our very own Jeff Man gives us a recap on the 2018 RSA Conference! He discusses HackerOne CEO talking Bug Bounty programs, DevSecOps day at RSA demonstrates how the thinking around secure software has evolved, if it’s ti… Continue reading Jeff Man, Recap of RSAC – Paul’s Security Weekly #557

Topic: Bug Bounties – Application Security Weekly #6

This week, Keith and Paul discuss Data Security and Bug Bounty programs! They mention the lessons learned from the Uber breach and why Google paid 2.9 million in Bug Bounties in 2017! Full Show Notes Subscribe to our YouTube channel: https://www.youtub… Continue reading Topic: Bug Bounties – Application Security Weekly #6

Critical Flaw in Apache, Wikileaks Unveils Project Protego, and Linux 4.13 – Paul’s Security Weekly #529

The nightmare that is patching IoT devices, essential bug bounty programs, controlling voice assistants, flaws in Apache Struts2, and more security news! Paul’s Stories Fixing, upgrading and patching IoT devices can be a real nightmare Critical Flaw in Apache Struts2 Lets Hackers Take Over Web Servers Hackers Can Silently Control Siri, Alexa & Other Voice […]

The post Critical Flaw in Apache, Wikileaks Unveils Project Protego, and Linux 4.13 – Paul’s Security Weekly #529 appeared first on Security Weekly.

Continue reading Critical Flaw in Apache, Wikileaks Unveils Project Protego, and Linux 4.13 – Paul’s Security Weekly #529