[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Modern Attacks Include Supply Chain "Hopping" and Reversing Agile Environments
Modern attacks use supply chain island hopping and target digitally transformed businesses
> Albion Online Forum Breach Exposes User Info
Admins says hacker got hold of emails and hashed passwords
> What does an offensive security team actually do?
There is a lot of discussion around terms such as red team, attack team, pentest, adversarial engineering or offensive security team and similar ones. I typically stay away from the (sometimes passionate) discussions that ensue whenever this topic comes up. Personally, I think a good strategy is to...
> #InfosecurityOnline: The Role of Data in Predicting Human Behaviors
How far can data go in identifying, understanding and predicting human behaviors?
> US Indicts GRU Officers for NotPetya, Olympics Attacks and More
DoJ lists Sandworm team’s destructive attacks since 2015
> CVE 2020-16977: VS Code Python Extension Remote Code Execution
While building “Husky AI” I started working a lot with Microsoft’s VS Code Python extension. It is a super convinient way to edit Jupyter Notebooks. I just use VS Code’s Remote SSH feature to get to my Linux host and work on modeling and testing there. When threat modeling “Husky AI” I identified ba...
> UK: Russian GRU Hackers Targeted Tokyo Olympics
NCSC reveals Sandworm hackers may have been planning sabotage
> Cyber-Attack on Mississippi Schools Costs $300,000
Board of Yazoo County School District votes to pay company $300,000 to recover files encrypted by threat actors
> Osquery: Using D-Bus to query systemd data
During my summer internship at Trail of Bits I worked on osquery, the massively popular open-source endpoint monitoring agent used for intrusion detection, threat hunting, operational monitoring, and many other functions. Available for Windows, macOS, Linux, and FreeBSD, osquery exposes an operating...
> Instagram's Handling of Children's Data Under Investigation
EU’s leading GDPR regulator investigates Instagram for allegedly failing to protect children’s data
> Waze Vulnerability Lets Attackers Track and Identify Users
Flaw in traffic-dodging app allows threat actors to track users and find out where they are going
> Machine Learning Attack Series: Stealing a model file
This post is part of a series about machine learning and artificial intelligence. Click on the blog tag “huskyai” to see related posts. Overview: How Husky AI was built, threat modeled and operationalized Attacks: The attacks I want to investigate, learn about, and try out We talked about creating a...
> Attacks on WAFs Triple in Size as Ransom Demands Re-Emerge
Large attacks on web application firewalls re-emerge in 2020
> Government Spooks Urge Firms to Patch SharePoint Bug
CVE-2020-16952 is critical RCE flaw, says NCSC
> Coming up: Grayhat Red Team Village talk about hacking a machine learning system
Excited to announce that I will be presenting at Grayhat - Red Team Village on October 31st 2020. The presentation is about my machine learning journey and how to build and break a machine learning system. If you follow my blog, you can guess that there will be lots of discussion around “Husky AI”....
> US CEO Charged with $2bn Tax Evasion Scheme
Robert Brockman also accused of defrauding investors
> Google Reveals it Was Hit by 2.5Tbps DDoS
Largest ever attack to date came in 2017, tech giant reveals
> Detecting Iterator Invalidation with CodeQL
Iterator invalidation is a common and subtle class of C++ bugs that often leads to exploitable vulnerabilities. During my Trail of Bits internship this summer, I developed Itergator, a set of CodeQL classes and queries for analyzing and discovering iterator invalidation. Results are easily interpret...
> DDoS Attacks Disrupt Massachusetts Schools
Cyber-attacks interrupt remote learning for Sandwich and Tyngsboro students
> Iran Reports Two Major Cyber-Attacks
Iran’s ports and government institutions targeted in large-scale cyber-attacks