Sunday Round up: 25th of October 2015 - Fitbits Hacked!
Here's the week in review.
0-day race condition in Parallels Desktop for Mac (Local Privilege Escalation On Host): https://beistlab.wordpress.com/2015/01/08/0day_race_condition_parallels_desktop/
Practice of Android Reverse Engineering: http://www.slideshare.net/jserv/practice-of-android-reverse-engineering
New Javascript Deobfuscator Tool: http://www.kahusecurity.com/2015/new-javascript-deobfuscator-tool/
Btproxy - Man In The Middle Analysis Tool For Bluetooth: http://www.kitploit.com/2015/10/btproxy-man-in-middle-analysis-tool-for.html
Tricky new malware replaces your entire browser with a dangerous Chrome lookalike: http://www.networkworld.com/article/2994803/security/tricky-new-malware-replaces-your-entire-browser-with-a-dangerous-chrome-lookalike.html
Fitbit Vulnerability Means Your Tracker Could Spread Malware: http://www.darknet.org.uk/2015/10/fitbit-vulnerability-means-your-tracker-could-spread-malware/
How to Solve Caching Conundrums: http://www.sitepoint.com/solve-caching-conundrums/
Hacking ZigBee Networks: http://resources.infosecinstitute.com/hacking-zigbee-networks/
Automating Forensic Artifact Collection with Splunk and GRR: http://informationonsecurity.blogspot.com.au/2015/10/automating-forensic-artifact-collection.html
Hackers Can Wirelessly Upload Malware to a Fitbit in 10 Seconds: http://gizmodo.com/hackers-can-wirelessly-upload-malware-to-a-fitbit-in-10-1737880606
C++ Turns 30 – Looking Forward to the Future http://t.co/34DzbLqRvq
— The Security Sleuth (@Security_Sleuth) October 18, 2015
Connected kettles boil over, spill WiFi passwords over London http://t.co/U97seBZ6qo
— The Security Sleuth (@Security_Sleuth) October 19, 2015
BlackBerry says it has fixed Android's rampant security issues with Priv http://t.co/E0O4DJTUO4
— The Security Sleuth (@Security_Sleuth) October 19, 2015
Adversary Manifesto https://t.co/63XlHYq0Ri
— The Security Sleuth (@Security_Sleuth) October 19, 2015
In honor of Snorty's 2016 Calendar release, we're giving away some Snort swag to 3 lucky winners! Snort On! pic.twitter.com/ARWHno8YSS
— Snort (@Snort) October 19, 2015
Handbook on Securing Cyber-Physical Critical Infrastructure https://t.co/aIiJ5aVFzs #InfoSec #CyberSecurity #Tech pic.twitter.com/5ufl7XkNOk
— CyberWarrior (@CyberDomain) October 20, 2015
Firefox will warn you when your password will be exposed https://t.co/n6j6xNBYTs
— The Security Sleuth (@Security_Sleuth) October 21, 2015
Closed Circuit Cameras, NAS Devices Enrolled in Botnet https://t.co/T7YVuHAUgQ
— The Security Sleuth (@Security_Sleuth) October 22, 2015
Security Slice: Beneficial Botnets? https://t.co/FwupLvTEvl
— The Security Sleuth (@Security_Sleuth) October 22, 2015
DDoS scammers collect $20,000 with Ashley Madison extortion https://t.co/CXUplm0AEE
— The Security Sleuth (@Security_Sleuth) October 22, 2015
Learning Android Forensics A hands-on guide to Android foren https://t.co/XHW7LBggfP #InfoSec #CyberSecurity #Tech pic.twitter.com/HJCZ5D4lYf
— CyberWarrior (@CyberDomain) October 24, 2015
Read last weeks round up here
If you found some other interesting stuff this week feel free to leave a link to it in the comments section.