Skip To main content

DrupalCon Europe 2024

Við erum spennt að segja frá því að stofnandi okkar og framkvæmdastjóri, Theódór Ragnar Gíslason, flutti hvetjandi erindi á hinni virtu ráðstefnu, DrupalCon Europe sem haldin var í Barcelona í ár. Þar lagði Teddi áherslu á framtíðarsýn og vegferð Defend Iceland! Vegferðin frá því að vera ungur hakkari yfir í að stofna netöryggisfyrirtæki eins og Syndis og Defend Iceland var ekki alltaf auðveld! Kærar þakkir til Baddy Sonja Breidert og flotta teymisins hjá 1xINTERNET fyrir ómetanlegan stuðning. 

Drupal samfélagið sýnir kraft samvinnunar, sýnir hvað hægt er að áorka þegar við sameinumst krafta okkar í átt að sameiginlegu markmiði. Þessi gildi tengjast okkar markmiðum um að byggja upp öruggari stafræn samfélög. 

Vertu með í þessari vegferð: “Come for the Bounty - Stay for the Community!” 

Aðrar fréttir

Sjá allar fréttir

Is Your CTO Vibe-Coding?

Most of the conversation about AI and security runs in one direction: the barrier to entry for attackers is collapsing. A teenager with a chatbot can now scan, probe, and exploit at a level that used to require years of practice. That's a real problem, and it deserves the attention it gets.
Lesa meira

Scraping GitHub for Secrets in Icelandic Bug Bounty - Community Blog

The idea for this project came during bug bounty work on Icelandic companies. One of the first things I always do in recon is search for the target on GitHub and Gists, looking for leaked credentials, API keys, internal URLs, anything useful. But the reality is, interesting stuff almost never comes from just searching the company name.
Lesa meira

Multiple Landspitali Employee Domain Accounts at Risk of Compromise

This report details a critical security vulnerability discovered within Landspitalinn's systems through the Defend Iceland bounty program. A series of chained vulnerabilities and misconfigurations were identified, allowing attackers to compromise multiple employee credentials and register multi-factor authentication (MFA) to themselves.
Lesa meira

Public disclosure for a healthier cybersecurity culture

Landspitali is the leading hospital in Iceland and the largest workplace for employees in health care. It is funded by the Ministry of Welfare, supervised by the Directorate of Health and provides specialised and general care and has the capacity of approx. 700 beds. To say that it is an important organisation in Iceland is an understatement and almost every Icelander relies on their services in some way.
Lesa meira

How I found all corporate usernames in Iceland

One of my favorite methods to gain initial access to companies is finding valid credentials. If your target is just one employee, this might be near impossible. But what if you have hundreds, or even thousands of targets? What if the target victim is anyone in Iceland? Then gaining valid credentials goes from near impossible to near certain.
Lesa meira

When Retired Domains Come Back to Haunt: The Hidden Risk of Legacy Corporate Assets

Organizations evolve through mergers, acquisitions, and rebranding. Old domains get retired, but what happens when those domains can still receive password resets or act as the login email for third-party services for the previous owner? This post reveals an overlooked vulnerability we've seen through Defend Iceland's bug bounty platform: expired corporate domains that remain deeply embedded in third-party SaaS accounts. When these domains become available for registration, attackers can inherit access to SaaS accounts that still use the retired email domain for login or recovery. We'll show you exactly how this happens and why "just let it expire" is a dangerous domain retirement strategy.
Lesa meira

Þessi vefsíða notar vefkökur (e. cookies) til að bæta upplifun notenda af síðunni.