Modern attacks use supply chain island hopping and target digitally transformed businesses
Admins says hacker got hold of emails and hashed passwords
There is a lot of discussion around terms such as red team, attack team, pentest, adversarial engineering or offensive security team and similar ones.
I typically stay away from the (sometimes passionate) discussions that ensue whenever this topic comes up.
Personally, I think a good strategy is to...
How far can data go in identifying, understanding and predicting human behaviors?
DoJ lists Sandworm team’s destructive attacks since 2015
While building “Husky AI” I started working a lot with Microsoft’s VS Code Python extension. It is a super convinient way to edit Jupyter Notebooks. I just use VS Code’s Remote SSH feature to get to my Linux host and work on modeling and testing there.
When threat modeling “Husky AI” I identified ba...
NCSC reveals Sandworm hackers may have been planning sabotage
Board of Yazoo County School District votes to pay company $300,000 to recover files encrypted by threat actors
During my summer internship at Trail of Bits I worked on osquery, the massively popular open-source endpoint monitoring agent used for intrusion detection, threat hunting, operational monitoring, and many other functions. Available for Windows, macOS, Linux, and FreeBSD, osquery exposes an operating...
EU’s leading GDPR regulator investigates Instagram for allegedly failing to protect children’s data
Flaw in traffic-dodging app allows threat actors to track users and find out where they are going
This post is part of a series about machine learning and artificial intelligence. Click on the blog tag “huskyai” to see related posts.
Overview: How Husky AI was built, threat modeled and operationalized Attacks: The attacks I want to investigate, learn about, and try out We talked about creating a...
Large attacks on web application firewalls re-emerge in 2020
CVE-2020-16952 is critical RCE flaw, says NCSC
Excited to announce that I will be presenting at Grayhat - Red Team Village on October 31st 2020. The presentation is about my machine learning journey and how to build and break a machine learning system.
If you follow my blog, you can guess that there will be lots of discussion around “Husky AI”....
Robert Brockman also accused of defrauding investors
Largest ever attack to date came in 2017, tech giant reveals
Iterator invalidation is a common and subtle class of C++ bugs that often leads to exploitable vulnerabilities. During my Trail of Bits internship this summer, I developed Itergator, a set of CodeQL classes and queries for analyzing and discovering iterator invalidation. Results are easily interpret...
Cyber-attacks interrupt remote learning for Sandwich and Tyngsboro students
Iran’s ports and government institutions targeted in large-scale cyber-attacks