Mac Malware MacStealer Spreads as Fake P2E Apps

We detected Mac malware MacStealer spreading via websites, social media, and messaging platforms Twitter, Discord, and Telegram. Cybercriminals lure victims to download it by plagiarizing legitimate play-to-earn (P2E) apps’ images and offering jobs as …

March 30, 2023
Read More >>

Clarification on bug bounties

Do sites like bug crowd or Hackerone only take 0 days?

I’ve been getting back into cyber sec for the last few years and have found several known CVEs in the wild (no 0days). I have approached all the people affected by these directly and they either all ignore me or tell me they dont care. In every case this has happened.
Once I even found full read write access in a database that contained medical information , dox and surgery pictures online.
This medical DB was in another country from my own.
The people who owned the box, the people who owned the medical clinic, the forigen governments intel and cyber sec agency all gave me 100% radio silence .
I eventually contacted CERT of the US, they apparently dealt with the issue and I got nothing out of it .

Some general guidance on what I should do when I find non 0 day CVE would be appreciated.

submitted by /u/zeekertron
[link] [comments]

March 30, 2023
Read More >>