
Spennandi áfangi hjá Defend Iceland
Við fórum í loftið í febrúar á þessu ári og erum stolt af því að vera komin í samstarf við 26 frábæra viðskiptavini. Þessir aðilar spanna öll svið samfélagsins, frá stórum hluta fjármálageirans til lykilaðila í orku- og heilbrigðisgeiranum - og nú Alþingi Íslendinga.
Það að leiðandi fyrirtæki og stofnanir nýti fremstu aðferðir í forvirkum netöryggisaðgerðum, bregðist ekki bara við árásum heldur komi í veg fyrir þær, er til fyrirmyndar. Við erum ánægð með að vera treyst fyrir því að vernda það sem skiptir mestu máli í okkar sítengda stafræna samfélagi.
Aðrar fréttir
Sjá allar fréttirIs Your CTO Vibe-Coding?
Most of the conversation about AI and security runs in one direction: the barrier to entry for attackers is collapsing. A teenager with a chatbot can now scan, probe, and exploit at a level that used to require years of practice. That's a real problem, and it deserves the attention it gets.
Lesa meiraScraping GitHub for Secrets in Icelandic Bug Bounty - Community Blog
The idea for this project came during bug bounty work on Icelandic companies. One of the first things I always do in recon is search for the target on GitHub and Gists, looking for leaked credentials, API keys, internal URLs, anything useful. But the reality is, interesting stuff almost never comes from just searching the company name.
Lesa meiraMultiple Landspitali Employee Domain Accounts at Risk of Compromise
This report details a critical security vulnerability discovered within Landspitalinn's systems through the Defend Iceland bounty program. A series of chained vulnerabilities and misconfigurations were identified, allowing attackers to compromise multiple employee credentials and register multi-factor authentication (MFA) to themselves.
Lesa meiraPublic disclosure for a healthier cybersecurity culture
Landspitali is the leading hospital in Iceland and the largest workplace for employees in health care. It is funded by the Ministry of Welfare, supervised by the Directorate of Health and provides specialised and general care and has the capacity of approx. 700 beds. To say that it is an important organisation in Iceland is an understatement and almost every Icelander relies on their services in some way.
Lesa meiraHow I found all corporate usernames in Iceland
One of my favorite methods to gain initial access to companies is finding valid credentials. If your target is just one employee, this might be near impossible. But what if you have hundreds, or even thousands of targets? What if the target victim is anyone in Iceland? Then gaining valid credentials goes from near impossible to near certain.
Lesa meiraWhen Retired Domains Come Back to Haunt: The Hidden Risk of Legacy Corporate Assets
Organizations evolve through mergers, acquisitions, and rebranding. Old domains get retired, but what happens when those domains can still receive password resets or act as the login email for third-party services for the previous owner? This post reveals an overlooked vulnerability we've seen through Defend Iceland's bug bounty platform: expired corporate domains that remain deeply embedded in third-party SaaS accounts. When these domains become available for registration, attackers can inherit access to SaaS accounts that still use the retired email domain for login or recovery. We'll show you exactly how this happens and why "just let it expire" is a dangerous domain retirement strategy.
Lesa meira