Security News

NCC Group admits its training data was leaked online after folders full of CREST pentest certification exam notes posted to GitHub
2020-08-11 14:58

British infosec biz NCC Group has admitted to The Register that its internal training materials were leaked on GitHub - after folders purporting to help people pass the CREST pentest certification exams appeared in a couple of repositories. CREST offers a certification called CRT: CREST Registered Tester.

Ever wonder how a pentest turns into felony charges? Coalfire duo explain Iowa courthouse arrest debacle
2020-08-05 23:08

The pair were performing a routine penetration test at the Dallas County courthouse at night when they tripped an alarm, were collared by deputies, and, ultimately, charged with felony trespassing - a crime that can lead to up to seven years behind bars. Part of the problem, the two professional attackers told the Black Hat online conference today, was the imprecise terms of the penetration tests Coalfire was hired to perform at the request of the US state of Iowa.

Ever wondered how a pentest turned into felony charges? Coalfire duo explains Iowa courthouse arrest debacle
2020-08-05 23:08

The pair were performing a routine penetration test at the Dallas County courthouse at night when they tripped an alarm, were collared by deputies, and, ultimately, charged with felony trespassing - a crime that can lead to up to seven years behind bars. Part of the problem, the two professional attackers told the Black Hat online conference today, was the imprecise terms of the penetration tests Coalfire was hired to perform at the request of the US state of Iowa.

Communication, communication – and politics: Iowa saga of cuffed infosec pros reveals pentest pitfalls
2019-11-07 19:35

Tales from the coal face as experts reflect on what can possibly go wrong on the job Analysis It has been six weeks since Coalfire's Gary Demercurio and Justin Wynn were nabbed in Dallas County,...

Pentest secures contract with global techn corp, Xcina Consulting becomes preferred supplier
2019-09-17 22:30

Shearwater Group, the organizational resilience group, announces that its group company, Pentest has secured a one-year contract with a global technology corporation worth in excess of US$1...

BitDam’s new PenTest helps determine the effectiveness of an organization’s security tools
2019-04-18 02:00

BitDam, provider of cybersecurity solutions that protect enterprise communications from advanced threats hidden in files and links, announced the availability of a new, free data security...

New Settings Let Hackers Easily Pentest Facebook, Instagram Mobile Apps
2019-03-26 14:18

Facebook has introduced a new feature in its platform that has been designed to make it easier for bug bounty hunters to find security flaws in Facebook, Messenger, and Instagram Android...

2FA codes can be phished by new pentest tool
2019-01-11 12:25

A researcher has published a tool called Modlishka, capable of phishing 2FA codes sent by SMS or authentication apps.

CompTIA PenTest+ certification now available worldwide
2018-07-31 19:52

CompTIA launched CompTIA PenTest+, its newest credential for cybersecurity professionals around the world. CompTIA PenTest+ provides an assessment of the knowledge and skills needed to run a...

Sn1per: Automated pentest recon scanner (Help Net Security)
2016-08-18 13:15

Sn1per is an automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities. “I originally created Sn1per because I didn’t want to run 10 different security...