The number of memory safety vulnerabilities in Android dropped from 223 in 2019 to 85 in 2022
First used as botnets, their lucrative nature turned them into independent criminal enterprises
After reading this post about ChatGPT imitating Linux, I wanted it to be a database server.
Let’s try it out!
Imagine you are a Microsoft SQL Server. I type commands, and you reply with the result, and no other information or descriptions. Just the result. Start with exec xp_cmdshell ‘whoami’;
Wow,...
HP's latest report suggests 44% of malware was delivered via archive files in Q3 2022
The coalition outlined the need to refine SBOM requirements before making it an obligation for defense contractors
Introduction You’ve probably enjoyed my previous post about bypassing Intel DCM’s authentication mechanism to gain unauthorized access. This gave us the lowest possible “Guest” privileges in the DCM console. The second part will now show you a possible way to get Remote Code Execution on the underly...
Annual Cyber Coalition effort helps nations develop and share best practice
Number of US victims has doubled over the past year
Zero-knowledge (ZK) proofs are useful cryptographic tools that have seen an explosion of interest in recent years, largely due to their applications to cryptocurrency. The fundamental idea of a ZK proof is that a person with a secret piece of information (a cryptographic key, for instance) can prove...
"Schoolyard Bully" has been active since 2018
The attack disrupted IT operations, websites and scheduling of medical appointments
DotHouse Health experienced a data breach due to suspicious activity on their computer systems, potentially impacting patient information. The breach occurred between October 31, 2022, and November 27, 2022. It was claimed under the Alphv/BlackCat brand on July 26th, 2023.
The claims come from Google’s Threat Analysis Group, which published an advisory about the threat
The list went on sale for four days and is now being distributed for free among dark web users
La société Prophete, fabricant de vélos, a été victime d'une cyberattaque le 25 novembre 2022, qui a paralysé sa production, sa facturation et ses livraisons pendant environ trois semaines, contribuant ainsi à sa faillite. L'attaque a été immédiatement signalée au Landeskriminalamt (police criminell...
The UK strengthens its regulations on Network and Information Systems (NIS) to better prevent software supply chain attacks
Defendants allegedly used insider to obtain personal information
Common misconfigurations of resource-based policies and how they can be abused.
Akamai reveals how a simple syntax error stopped it sending commands
Incident is second this year, although company says passwords are safe