Online businesses targeted by two new carding bots as holiday season shopping starts
AT&T survey finds enterprises haven’t fully considered 5G’s impact on their cybersecurity
Imagine reducing the amount of code and time needed to test software, while at the same time increasing the efficacy of your tests and making your debugging tasks easier—all with minimal human effort. It seems too good to be true, but we’re going to explain how test-case reduction can do all this (a...
Texas Health Commission fined for exposing personal information of 6,617 people online
Varying amounts of money can be earned from an exploit broker, the dark web or from bug bounty programs
The Trail of Bits Assurance practice has received an influx of Go projects, following the success of our Kubernetes assessment this summer. As a result, we’ve been adapting for Go projects some of the security assessment techniques and tactics we’ve used with other compiled languages. We started by...
Restrictive legislation will force device makers to pre-install local apps
Over 440,000 customers may have been affected
Parsing is hard, even when a file format is well specified. But when the specification is ambiguous, it leads to unintended and strange parser and interpreter behaviors that make file formats susceptible to security vulnerabilities. What if we could automatically generate a “safe” subset of any file...
Politicians already spreading misinformation on social network
Aventura Technologies allegedly passed off Chinese-made equipment with known cybersecurity flaws as its own
TL;DR: x86_64 decoding is hard, and the number and variety of implementations available for it makes it uniquely suited to differential fuzzing. We’re open sourcing mishegos, a differential fuzzer for instruction decoders. You can use it to discover discrepancies in your own decoders and analysis to...
Companies can practice responding to cyber-attacks at three new centers
Miami-Dade cops are making eyes at Pinellas County Sheriff's FACES
Recently, security researchers discovered that Apple was sending safe browsing data to Tencent for all Chinese users. This revelation has brought the underlying security and privacy guarantees of the safe browsing protocol under increased scrutiny. In particular, safe browsing claims to protect user...
FOI figures come from just 23 forces
London is taking aerial threats seriously
A few weeks ago I had the inspiring experience of attending the annual Grace Hopper Celebration (GHC), the world’s largest gathering of women in technology. Over four days in Orlando, Florida, GHC hosted a slew of workshops and presentations, plus a massive career fair with over […]
Remediation lag linked to increase in heart attacks
A vulnerability made it possible to intercept Wi-Fi network credentials