Black Hat
Stratus Red Team: Open-source tool for adversary emulation in the cloud
In this Help Net Security video, Christophe Tafani-Dereeper, Cloud Security Researcher and Advocate at DataDog, talks about Stratus Red Team, an open-source project for …
What Black Hat USA 2022 attendees are concerned about
Black Hat released its Supply Chain and Cloud Security Risks Are Top of Mind survey. The report highlights important findings from more than 180 of experienced cybersecurity …
MI-X: Open source project helps you understand whether you are exploitable
In this Help Net Security video, Ofri Ouzan, Security Researcher at Rezilion, talks about MI-X (Am I Exploitable?), an open source tool aimed at effectively determining …
Sparrow’s new solutions and features help users identify vulnerabilities in source code and web applications
At Black Hat USA 2022, Sparrow is announcing its newly upgraded Sparrow Cloud and open-source management solution, Sparrow SCA. Sparrow Cloud is a single platform for managing …
SimpleRisk: Enterprise risk management simplified
In this Help Net Security video, CEO/CISO Josh Sokol, showcases SimpleRisk, a fully integrated GRC platform that can be used for all of your governance, risk management, and …
Black Hat USA 2022: Schedule for Las Vegas hybrid event
Black Hat released the schedule including in-person and virtual programs for Black Hat USA 2022. Taking place in Las Vegas at the Mandalay Bay Convention Center and virtually, …
Black Hat announces keynote lineup for Black Hat USA 2022
Black Hat USA 2022 announced Chris Krebs, Founding Partner of Krebs Stamos Group, and Kim Zetter, Journalist and Author, as keynote speakers for the Black Hat USA 2022 hybrid …
ProxyShell vulnerabilities actively exploited to deliver web shells and ransomware
Three so-called “ProxyShell” vulnerabilities are being actively exploited by various attackers to compromise Microsoft Exchange servers around the world, the …
Kubestriker: A security auditing tool for Kubernetes clusters
Kubestriker is an open-source, platform-agnostic tool for identifying security misconfigurations in Kubernetes clusters. It performs a variety of checks on a range of services …
SniperPhish: An all-in-one open-source phishing toolkit
SniperPhish is an all-in-one open-source phishing toolkit that pentesters and other security professionals can use for setting up and executing email and web-based spear …
Cloud Sniper: Manage and automate cloud security operations
Cloud Sniper is an open-source platform for managing cloud security operations that aims to make it easy for cloud teams to deal with security incidents. “One of our …
Microsoft sets up isolated environment for bug hunters to test attacks against Azure
Microsoft has some very good news for bug hunters: not only has the company doubled the top bounty reward for vulnerabilities discovered in its Azure cloud computing service, …
Featured news
Resources
Don't miss
- AI agent deception moves from theory to reality in UK cyber tests
- Code review used to be the only way to catch these bugs
- 15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
- Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
- Future AGI: Open-source platform for shipping self-improving AI agents