Flaw is patched in Docker version 19.03.1
Chicago man allegedly tried to help group spread propaganda
“If privacy matters, it should matter to the phone your life is on.” So says Apple in their recent ads about Privacy on the iPhone and controlling the data you share—but many of the security features they highlight are opt-in, and users often don’t know when or how to activate them. But hey… we got...
Domestic surveillance apps a growing problem
Chicago cybersecurity and technology firms to create 2,000 new jobs in 2020
At Trail of Bits, we make a significant effort to stay up to date with the academic world. We frequently evaluate our work through peer-reviewed conferences, and we love to attend academic events (see our recent ICSE and Crypto recaps). However, we consistently see one recurring issue at these acade...
Most of America’s top retailers don’t set their DMARC policy to protection mode
Mobile payments provider failed to follow data storage security protocols
Imagine reducing the amount of code and time needed to test software, while at the same time increasing the efficacy of your tests and making your debugging tasks easier—all with minimal human effort. It seems too good to be true, but we’re going to explain how test-case reduction can do all this (a...
IDC report warns the sector is hardest hit
Hackers stole personal and payment details in October
The Trail of Bits Assurance practice has received an influx of Go projects, following the success of our Kubernetes assessment this summer. As a result, we’ve been adapting for Go projects some of the security assessment techniques and tactics we’ve used with other compiled languages. We started by...
State responded quickly to contain the threat
Disney’s streaming service hacked within a week of being launched
Parsing is hard, even when a file format is well specified. But when the specification is ambiguous, it leads to unintended and strange parser and interpreter behaviors that make file formats susceptible to security vulnerabilities. What if we could automatically generate a “safe” subset of any file...
Global crime-fighting force concerned that encryption conceals child sexual exploitation
CyberCon Power & Utilities CISO Summit expands to three events in 2020
New attacks sent from legitimate but compromised domains
DDoS-for-hire services were responsible for millions of attacks
Human error leaves AWS bucket without protection