Security News

Cybersecurity Firm FireEye Got Hacked; Red-Team Pentest Tools Stolen
2020-12-10 08:36

FireEye, one of the largest cybersecurity firms in the world, said on Tuesday it became a victim of a state-sponsored attack by a "Highly sophisticated threat actor" that stole its arsenal of Red Team penetration testing tools it uses to test the defenses of its customers. Red Team tools are often used by cybersecurity organizations to mimic those used in real-world attacks with the goal of assessing a company's detection and response capabilities and evaluating the security posture of enterprise systems.

Pentest-as-a-Service Company Cobalt Raises $29 Million
2020-08-20 15:36

Pentest-as-a-Service company Cobalt announced on Thursday that it has raised $29 million in a Series B funding round. Founded in 2013, Cobalt has designed a platform that connects vetted ethical hackers with organizations looking to test the security of their products.

NCC Group admits its training data was leaked online after folders full of CREST pentest certification exam notes posted to GitHub
2020-08-11 14:58

British infosec biz NCC Group has admitted to The Register that its internal training materials were leaked on GitHub - after folders purporting to help people pass the CREST pentest certification exams appeared in a couple of repositories. CREST offers a certification called CRT: CREST Registered Tester.

Ever wonder how a pentest turns into felony charges? Coalfire duo explain Iowa courthouse arrest debacle
2020-08-05 23:08

The pair were performing a routine penetration test at the Dallas County courthouse at night when they tripped an alarm, were collared by deputies, and, ultimately, charged with felony trespassing - a crime that can lead to up to seven years behind bars. Part of the problem, the two professional attackers told the Black Hat online conference today, was the imprecise terms of the penetration tests Coalfire was hired to perform at the request of the US state of Iowa.

Ever wondered how a pentest turned into felony charges? Coalfire duo explains Iowa courthouse arrest debacle
2020-08-05 23:08

The pair were performing a routine penetration test at the Dallas County courthouse at night when they tripped an alarm, were collared by deputies, and, ultimately, charged with felony trespassing - a crime that can lead to up to seven years behind bars. Part of the problem, the two professional attackers told the Black Hat online conference today, was the imprecise terms of the penetration tests Coalfire was hired to perform at the request of the US state of Iowa.

Communication, communication – and politics: Iowa saga of cuffed infosec pros reveals pentest pitfalls
2019-11-07 19:35

Tales from the coal face as experts reflect on what can possibly go wrong on the job Analysis It has been six weeks since Coalfire's Gary Demercurio and Justin Wynn were nabbed in Dallas County,...

Pentest secures contract with global techn corp, Xcina Consulting becomes preferred supplier
2019-09-17 22:30

Shearwater Group, the organizational resilience group, announces that its group company, Pentest has secured a one-year contract with a global technology corporation worth in excess of US$1...

BitDam’s new PenTest helps determine the effectiveness of an organization’s security tools
2019-04-18 02:00

BitDam, provider of cybersecurity solutions that protect enterprise communications from advanced threats hidden in files and links, announced the availability of a new, free data security...

New Settings Let Hackers Easily Pentest Facebook, Instagram Mobile Apps
2019-03-26 14:18

Facebook has introduced a new feature in its platform that has been designed to make it easier for bug bounty hunters to find security flaws in Facebook, Messenger, and Instagram Android...

2FA codes can be phished by new pentest tool
2019-01-11 12:25

A researcher has published a tool called Modlishka, capable of phishing 2FA codes sent by SMS or authentication apps.