Hak5
Hak5
  • 1 880
  • 69 278 446
Is Elon Musk a Security Expert? - ThreatWire
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️
@endingwithali →
Twitch: twitch.tv/endingwithali
Twitter: endingwithali
UA-cam: youtube.com/@endingwithali
Everywhere else: links.ali.dev
Want to work with Ali? endingwithalicollabs@gmail.com
[❗] Join the Patreon→ patreon.com/threatwire
0:00 Intro
00:10 1 - NextJS Vulnerabilities Discovered
02:06 2 - New Technique Allows VPN Bypass
04:31 3 - FIDO2 Flaw Exposes MITM Attack
05:51 4 - Signal Vs Telegram
08:24 5 - Outro
LINKS
🔗 Story 1: NextJS Vulnerabilities Discovered
portswigger.net/web-security/request-smuggling/advanced/response-queue-poisoning
github.com/advisories/GHSA-77r5-gw3j-2mpf
github.com/advisories/GHSA-fr5h-rqp8-mj6g
cybersecuritynews.com/next-js-server-compromise/
🔗 Story 2: New Technique Allows VPN Bypass
www.leviathansecurity.com/blog/tunnelvision
cybersecuritynews.com/tunnelvision/
🔗 Story 3: FIDO2 Flaw Exposes MITM Attack
www.silverfort.com/blog/using-mitm-to-bypass-fido2/
gbhackers.com/fid02-mitm-vulnerability/
🔗 Story 4: Signal Vs Telegram
www.city-journal.org/article/signals-katherine-maher-problem
www.ccn.com/news/technology/telegram-vs-signal-elon-musk-claims-vulnerabilities/
www.businessinsider.com/elon-musk-encrypted-messenger-app-wars-telegram-signal-2024-5
elonmusk/status/1787589564917490059
news.ycombinator.com/item?id=40341716
nitter.poast.org/matthew_d_green/status/1789687898863792453
____________________________________________
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
Переглядів: 17 713

Відео

Malicious Cable Detector by O.MG
Переглядів 11 тис.16 годин тому
Get O.MG gear: hak5.org/omg o.mg.lol Music by KANGA (kanga.bandcamp.com/) Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
LockBitSupp Revealed? - ThreatWire
Переглядів 14 тис.21 годину тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali UA-cam: youtube.com/@endingwithali Everywhere else: links.ali.dev [❗] Join the Patreon→ patreon.com/threatwire 0:00 Intro 00:00:08 1 - CISA and FBI Release New Developer Warning 00:01:42 2 - GitLab Vuln is Leading to Account Takeovers 00:03:02 3 - Ministry of Defenc...
AntiVirus is a Virus - ThreatWire
Переглядів 17 тис.14 днів тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali UA-cam: youtube.com/@endingwithali Everywhere else: links.ali.dev [❗] Join the Patreon→ patreon.com/threatwire 0:00 Intro 00:07 1 - Net Neutrality is BACK 01:12 2 - Ivanti Connect Secure Zero Days Still Hitting Hard 02:32 3 - AntiVirus is A Virus 04:13 4 - UK has ou...
New PuTTY Vulnerability - ThreatWire
Переглядів 29 тис.21 день тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali UA-cam: youtube.com/@endingwithali Everywhere else: links.ali.dev [❗] Join the Patreon→ patreon.com/threatwire 0:00 Sophia d’Antoine 0:36 - Potential T-Mobile Directory Leak 2:32 - Palo Alto Networks Firewall Python Backdoor 4:20 - Twitter Hosted the Phishing Olympi...
New OMG Cable - Woven & Unmarked
Переглядів 13 тис.Місяць тому
Now Available: hak5.org/omg - - ☆ ☆ ☆ ☆ ☆ ☆ ☆ ☆ ☆ ☆ Our Site → www.hak5.org Shop → hakshop.myshopify.com/ Subscribe → ua-cam.com/users/Hak5Darren Support → www.patreon.com/threatwire Contact Us → hak5 ☆ ☆ ☆ ☆ ☆ ☆ ☆ ☆ ☆ ☆ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive c...
A New Kind of Phishing Attack - ThreatWire
Переглядів 53 тис.Місяць тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ Support ThreatWire → patreon.com/threatwire @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali UA-cam: youtube.com/@endingwithali Everywhere else: links.ali.dev If you want to help Ali with her research project email her at endingwithaliresearch@gmail.com → Please include (1️⃣) the size of your company and (2️⃣) wha...
OWASP Oopsies and Calling XZ What It Is - ThreatWire
Переглядів 16 тис.Місяць тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ Support ThreatWire → patreon.com/threatwire @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali UA-cam: youtube.com/@endingwithali Everywhere else: links.ali.dev @0xTib3rius Twitter: 0xTib3rius Twitch: www.twitch.tv/0xTib3rius UA-cam: ua-cam.com/users/Tib3rius Everywhere else: tib3rius.com/ @TracketPacer ...
Introducing the new Threat Wire
Переглядів 19 тис.Місяць тому
Order today at Hak5.org Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
Apple’s Unfixable Vulnerability - ThreatWire
Переглядів 20 тис.Місяць тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ Support ThreatWire → patreon.com/threatwire @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali Everywhere else: links.ali.dev [❗] ThreatWire Patreon has moved to → patreon.com/threatwire 0:00 - Intro 0:13 - US Cyber Trust Mark is Now Official 2:24 - Apple’s Unfixable Vulnerability 4:23 - Another Python Supply Chain ...
CVEs ARE DYING - ThreatWire
Переглядів 23 тис.Місяць тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ Support ThreatWire → patreon.com/threatwire @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali Everywhere else: links.ali.dev [❗] ThreatWire Patreon has moved to → patreon.com/threatwire 0:00 Intro 0:12 - The NVD is MIA 2:09 - Linux Foundation CVE Reporting Changed 4:16 - Cisco Acquires Splunk 4:20 - It’s Literally ...
Encryption Market Heating Up - ThreatWire
Переглядів 30 тис.2 місяці тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ Support ThreatWire → patreon.com/threatwire @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali Everywhere else: links.ali.dev [❗] ThreatWire Patreon has moved to → patreon.com/threatwire 0:00 Intro 0:10 - Encryption market is heating up 2:07 - Toddler Aged Malware Found 3:11 - Admitting to human error 4:08 - Outro L...
White House said to use Rust - ThreatWire
Переглядів 16 тис.2 місяці тому
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ Support ThreatWire → patreon.com/threatwire @endingwithali → Twitch: twitch.tv/endingwithali Twitter: endingwithali Everywhere else: links.ali.dev [❗] ThreatWire Patreon has moved to → patreon.com/threatwire 0:00 - Intro 0:11 - LockBit Update 1:23 - White House recommends Rust 2:54 - Apple Quantum Safe 4:03 - Outro LINKS 🔗 Story 1: Lock...
I-S00N China File Drop - ThreatWire
Переглядів 26 тис.2 місяці тому
I-S00N China File Drop - ThreatWire
DEF CON was actually cancelled?! - ThreatWire
Переглядів 27 тис.3 місяці тому
DEF CON was actually cancelled?! - ThreatWire
China is able to trace your Airdrops - ThreatWire
Переглядів 16 тис.3 місяці тому
China is able to trace your Airdrops - ThreatWire
Cyber Kidnapping & Carta's Controversial Cap Table Tactics Exposed! - ThreatWire
Переглядів 13 тис.4 місяці тому
Cyber Kidnapping & Carta's Controversial Cap Table Tactics Exposed! - ThreatWire
Insane iPhone Exploit & Zombie Cookies Hijack Google Accounts - ThreatWire
Переглядів 36 тис.4 місяці тому
Insane iPhone Exploit & Zombie Cookies Hijack Google Accounts - ThreatWire
GTA Hacker Sentenced - ThreatWire
Переглядів 44 тис.4 місяці тому
GTA Hacker Sentenced - ThreatWire
Twitter/X Bug Bounty Blunder - ThreatWire
Переглядів 14 тис.4 місяці тому
Twitter/X Bug Bounty Blunder - ThreatWire
PAYLOAD: DuckyLogger 2.0 - Keylogger for USB Rubber Ducky [PAYLOAD MINUTE]
Переглядів 16 тис.4 місяці тому
PAYLOAD: DuckyLogger 2.0 - Keylogger for USB Rubber Ducky [PAYLOAD MINUTE]
PAYLOAD: ICMP Data Exfiltration - USB Rubber Ducky/Exfiltration [PAYLOAD MINUTE]
Переглядів 12 тис.5 місяців тому
PAYLOAD: ICMP Data Exfiltration - USB Rubber Ducky/Exfiltration [PAYLOAD MINUTE]
Hax 4 BIOS, WordPress & Counter-Strike, oh my! - ThreatWire
Переглядів 11 тис.5 місяців тому
Hax 4 BIOS, WordPress & Counter-Strike, oh my! - ThreatWire
Windows Fingerprint Sensors Spoofable - ThreatWire
Переглядів 10 тис.5 місяців тому
Windows Fingerprint Sensors Spoofable - ThreatWire
A New USB Worm On The Loose - ThreatWire
Переглядів 31 тис.5 місяців тому
A New USB Worm On The Loose - ThreatWire
Hackers Reported Themselves to the SEC? - ThreatWire
Переглядів 14 тис.5 місяців тому
Hackers Reported Themselves to the SEC? - ThreatWire
17 Hacker Tools in 7 Minutes - ALL Hak5 Gear
Переглядів 362 тис.5 місяців тому
17 Hacker Tools in 7 Minutes - ALL Hak5 Gear
Python risks system takeover & Lockbit prompts USB trades - ThreatWire
Переглядів 21 тис.6 місяців тому
Python risks system takeover & Lockbit prompts USB trades - ThreatWire
Stealth Payload Tips - Obfuscation & Lock key triggers - Hak5
Переглядів 10 тис.6 місяців тому
Stealth Payload Tips - Obfuscation & Lock key triggers - Hak5
DaaS Bypasses Android Security, and Farewell Shannon - ThreatWire
Переглядів 29 тис.6 місяців тому
DaaS Bypasses Android Security, and Farewell Shannon - ThreatWire

КОМЕНТАРІ

  • @linuxliaison
    @linuxliaison 7 годин тому

    Kudos to you for being able to read out those numbers over and over :P

  • @jaybrooks1098
    @jaybrooks1098 10 годин тому

    Let me let everybody in on a secret. There's no such thing as a secure chat.

  • @HomeBurger
    @HomeBurger 12 годин тому

    Notice how Ali speaks slowly and uses smaller words when talking to the javascript viewers. Gotta know your audience. disclaimer: this is a joke

  • @mohamedissa9760
    @mohamedissa9760 13 годин тому

    The story about VPN DHCP bug was written by an AI

  • @enesylmaz8311
    @enesylmaz8311 13 годин тому

    Hello from THM :)

  • @cjlowe1650
    @cjlowe1650 16 годин тому

    You are so cute! But seriously, can someone get my wifi SSID if i don't broadcast it?

  • @stevenpugh5412
    @stevenpugh5412 16 годин тому

    I think the Elon Musk story was AI: absolutely idiotic for him to get involved. How’s that quote go “better to be thought a fool than tweet and remove all doubt”. Of course the same could be said about this comment…

  • @LP-fy8wr
    @LP-fy8wr 17 годин тому

    The entire dam thing sounds like AI.

  • @WickdPerfekT
    @WickdPerfekT 18 годин тому

    Defcon is canceled.

  • @marcharrison9847
    @marcharrison9847 20 годин тому

    God you post some shite on here

  • @lossless4129
    @lossless4129 День тому

    Getting better every single show, loving it. Keep it rolling!

  • @azryelkelly7851
    @azryelkelly7851 День тому

    Nice ASMR hair rubbing the microphone throughout the whole video. 😜 Guessing there's no MIT sound tech on staff. Love the videos!

  • @itzdm0r3
    @itzdm0r3 День тому

    I think the story about signal is the "fake" one.

  • @Private-GtngxNMBKvYzXyPq
    @Private-GtngxNMBKvYzXyPq День тому

    nolE has it bass ackwards.

  • @carsonjamesiv2512
    @carsonjamesiv2512 День тому

    TECHNOLOGY IS 😃 == 😡

  • @Iac8
    @Iac8 День тому

    can the packet squirrel exploit a printer?

  • @tech1238
    @tech1238 День тому

    Good vid thanks

  • @asksearchknock
    @asksearchknock День тому

    Great job on standing up for yourself and I hope that the community will support you I’m telling anyone who makes inappropriate comments where to go. I’m 100% behind you - Us rats 🐀 got to stick together

  • @aboselaiman
    @aboselaiman День тому

    With these Dimples I can't pay attention to what she is saying.

    • @asksearchknock
      @asksearchknock День тому

      I assume then you also missed the part where she reminded you she’s an MIT educated software engineer and your comments are not welcome or appropriate.

  • @Tech-NO-City
    @Tech-NO-City День тому

    I need your help plugging in my ethernet cable

  • @IshaqIbrahim3
    @IshaqIbrahim3 День тому

    Timeline: 5:35 Man in the MIDDLE! 🤣

  • @S.C.D.
    @S.C.D. День тому

    💓

  • @loves2tinker
    @loves2tinker День тому

    Might be interesting to see you and chstgpt 4o have a discussion about the security landscape (instead of reporting important news. That way you can flex your knowledge so people see more of your career side.

  • @paulw3182
    @paulw3182 День тому

    Great video, mom's advice still rings true ' Be humble, and take compliments while you can' - Its wonderful your making Threatwire your own, keep up the excellent work - Your coding channel is interesting.

  • @knghtbrd
    @knghtbrd День тому

    The dude behind Telegram is spewing the kind of complete BS that causes me to *not* trust that platform in the least. Guess what: Your Signal messages are decrypted on your phone so that you can see them. That means if you get pinched and the government gets your phone, they get your messages. That's Android's garbage encryption, not Signal's. Meanwhile Telegram has censored certain groups in order to be allowed on Apple's CrapStore. How does anyone know what's in that group to censor it? Because they're not encrypted! The fact the dev is trying to make Telegram sound safe vs. safe if you're careful and Signal UNsafe … nope, I don't trust Telegram as a result.

  • @THEMithrandir09
    @THEMithrandir09 День тому

    Telegrams encryption was made by 5 math dudes and isn't opensource, so insecure by default. If you're worried use matrix.

  • @VikTortor
    @VikTortor День тому

    telegram is a snitch just google the court cases where they collaborated with gov :D

  • @CedroCron
    @CedroCron День тому

    People that want and known what E2E encryption is, know that Signal is the only trust worthy option between these 2 messengers. There are other options as well.

  • @frankey3732
    @frankey3732 День тому

    How about plaintext messages saved locally? Signal has transport encryption; messages on clients are not encrypted. This means you can read and exfiltrate messages if you get to the machine. Or if your machine gets compromised.

  • @projectsspecial9224
    @projectsspecial9224 2 дні тому

    Cybersecurity is an illusion as digital is an abstraction layer of analog signals. There are always backdoors, exploits, and zero days.

  • @rsilters
    @rsilters 2 дні тому

    You had a better video about this before. Can't find the link

  • @kitsune7919
    @kitsune7919 2 дні тому

    I can't believe how Elons has to worm his way into everything tech related and spout his idiotic nonsense im so tired of this fucking guy

  • @bertblankenstein3738
    @bertblankenstein3738 2 дні тому

    Elon is a dipstick. That is all.

  • @christopherjosephsimmons
    @christopherjosephsimmons 2 дні тому

    I'm your 711

  • @Proxyone444
    @Proxyone444 2 дні тому

    ALI is LOVE

  • @chadddada
    @chadddada 2 дні тому

    Thanks for the heads up on NextJS!

  • @somethingelse25
    @somethingelse25 2 дні тому

    Found the signal and telegram story interesting and also the VPN one too. Thank you! Hopefully I'll be able to do a career in Cyber Security. ☕

  • @AnonMedic
    @AnonMedic 2 дні тому

    I used AI to write part of an article on my news website, and asked friends to guess what part AI wrote. So I absolutely love that you're doing the same thing with threatwire.

  • @Nichrysalis
    @Nichrysalis 2 дні тому

    Elon Musk is a security threat. He went from wanting to buy twitter to rid it of bots, to encouraging an environment where bots can thrive and camouflage amongst genuine users to boost its user numbers and thusly, charge advertisers more with the boosted user metrics. When he isn't directly insulting his advertising partners.

  • @Nichrysalis
    @Nichrysalis 2 дні тому

    I've only ever used Telegram, so knowing me, Signal is probably better, hands down.

  • @davidholliday6772
    @davidholliday6772 2 дні тому

    I deleted Signal over 2 years ago .

  • @herauthon
    @herauthon 2 дні тому

    Bummr.. there is DHCP/DNS noise - i have to check my cave

  • @flmadero
    @flmadero 2 дні тому

    I get it, now on duty

  • @jsaenzMusic
    @jsaenzMusic 2 дні тому

    So glad I found your channel! You're news is the ish!

  • @andrefriedelnyc
    @andrefriedelnyc 2 дні тому

    seriously - can't you guys find a girl who can read properly and doesn't seem like they have no idea what they are talking about?? Awful...

  • @debugin1227
    @debugin1227 2 дні тому

    Signal for the win

  • @QR5-cyber-exp
    @QR5-cyber-exp 2 дні тому

    Showing my age here….. but back in the 90’s (in Australia) we weren’t allowed to release a communications service unless it was “interceptable” by the Signals Directorate (with appropriate authorization). Seems like an eon ago now.

    • @asksearchknock
      @asksearchknock День тому

      I was about to say, the apple App Store T&Cs requires something similar I believe when releasing any app that has encryption. It’s been a while since I read them but I recall being forced to fill out a form saying what encryption was being used and that it could be exempt if it were in certain categories.

  • @QR5-cyber-exp
    @QR5-cyber-exp 2 дні тому

    Great summary. I love the connect back to previous research.

  • @jmr
    @jmr 2 дні тому

    Fido story is AI. I think what I've learned from the one AI story a week game is not that I can't tell them apart but that OUR HOST IS ALSO AI! Duh, duh, duh! 😆 /teasing.

  • @brettlaw4346
    @brettlaw4346 2 дні тому

    Signal - The assumption that the app source code is that app being installed is a big one. There are also host device compromises like the keyboard, general hacking, etc. Not sure if signal uses a secure terminal and trusted execution environment, otherwise you could have some buffer reads from other applications.