Abusing X.509 Digital Certificates to establish a covert data exchange channel

Haythem Elmir

Researcher at Fidelis Cybersecurity devised a new technique that abuses X.509 Digital Certificates to establish a covert data exchange channel Last year, during the Bsides conference in July 2017, the security researcher at Fidelis Cybersecurity Jason Reaves demonstrated how to covertly exchange data using X.509 digital certificates, now the same expert published the […]

Stripe.com – Phishing

Haythem Elmir

A new entry to the phishing scams list today.  This is asking for credentials for a new Online Payments Processor – Stripe.com. I haven’t previously heard of this company before or seen any phishing attempts against it. However a quick Google search does bring up a very small handful of […]

Almost all WordPress websites could be taken down due to unpatched CVE-2018-6389 DoS flaw

Haythem Elmir

The Israeli security researcher Barak Tawily a vulnerability tracked as CVE-2018-6389 that could be exploited to trigger DoS condition of WordPress websites. The expert explained that the CVE-2018-6389 flaw is an application-level DoS issued that affects the WordPress CMS and that could be exploited by an attacker even without a massive amount of malicious […]