We care about
your security.
Nethemba is a leading Slovak IT security firm specialized in web security, penetration testing, and RFID security audits. Since 2007, we’ve been securing businesses with cutting-edge research and expertise, trusted by companies worldwide.
We care about
your security.
Nethemba is a leading Slovak IT security firm specialized in web security, penetration testing, and RFID security audits. Since 2007, we’ve been securing businesses with cutting-edge research and expertise, trusted by companies worldwide.
Our Services
Application Security
Network and System Security
BLOG
Summer news: Hacker discount of 13.37% on all our services + great educational hacker videos + see you at WHY2025!
For our loyal and new customers, we are offering a 13.37% discount on all penetration tests and security audits, provided the binding order is received by August 31, 2025, and the work commences before this date. If you are planning penetration testing or security audits this year, consider rescheduling them for the summer. Not only […]
Read MoreHow to maximize anonymity when accessing the Internet on mobile
The problem of mobile anonymity Dystopia is in full swing in Europe, and achieving true anonymity from mobile devices is a big problem. The picture below shows that most countries require mandatory registration of SIM cards on the national ID or passport. This means that all mobile operators in a given state (and, of course, […]
Read MoreDiscovery of CVE-2022-24833
When on a security audit for a client it was discovered that a key component – the open-source private paste service PrivateBin contained a previously undocumented flaw. Cross-site-scripting is nothing new. I actually feel there must be prehistoric cave paintings and markings somewhere in the world containing some variation of <script>alert(1)</script>. Although XSS payloads embedded […]
Read Morehttps://www.cape.co/
We're drafting an open protocol for this: CANARY; coercion-resistant spoken verification. Rotating words derived from a shared secret (like TOTP but human-spoken), with three layers designed for real-world threat models:
· Rotating verification words; deterministic, offline-capable, burn-after-use. Not a static family safe word that one compromise burns forever.
· Silent duress signalling; if you're coerced into revealing your word, speaking a different word silently alerts the group without tipping off the attacker. Per-member duress tokens mean the group knows who is under duress.
· Dead man's switch / liveness; if a member stops checking in, the group is alerted. Covers the scenario where someone can't even speak a duress word…. they've gone silent entirely.
Spec: https://github.com/TheCryptoDonkey/canary-kit/blob/main/CANARY.md
Nostr binding (6 event kinds): https://github.com/TheCryptoDonkey/canary-kit/blob/main/NIP-CANARY.md
Interactive demo: https://canary.trotters.cc
The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.
https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
