Complaint alleges two employees accessed user info on massive scale
(ISC)2 report claims a 145% increase in global workforce is needed
Parsing is hard, even when a file format is well specified. But when the specification is ambiguous, it leads to unintended and strange parser and interpreter behaviors that make file formats susceptible to security vulnerabilities. What if we could automatically generate a “safe” subset of any file...
Insider attacks are harder to detect following migration to the cloud
"Why the f*ck was I breached?" generates comic responses to use after a cybersecurity breach
TL;DR: x86_64 decoding is hard, and the number and variety of implementations available for it makes it uniquely suited to differential fuzzing. We’re open sourcing mishegos, a differential fuzzer for instruction decoders. You can use it to discover discrepancies in your own decoders and analysis to...
Over 3,000 drivers affected by long-running Golden State DMV data breach
Groups API wasn’t properly restricted, says social network
Recently, security researchers discovered that Apple was sending safe browsing data to Tencent for all Chinese users. This revelation has brought the underlying security and privacy guarantees of the safe browsing protocol under increased scrutiny. In particular, safe browsing claims to protect user...
Cisco Talos uncovers microcosm of the threat landscape
Next year could see weaponization of airspace around corporate buildings
A few weeks ago I had the inspiring experience of attending the annual Grace Hopper Celebration (GHC), the world’s largest gathering of women in technology. Over four days in Orlando, Florida, GHC hosted a slew of workshops and presentations, plus a massive career fair with over […]
Focus more on hygiene, less on zero-days
Texan cybersecurity start-up JASK acquired by Sumo Logic
MITRE just updated the ATT&CK Framework to include Cloud TTPs.
The update includes techniques for stealing cookies from machines and using them for lateral movement. These are the two techniques I helped contribute to the matrix:
Credential Access - Steal Web Session Cookie Lateral Movement - We...
Nunavut is working to restore its communications network after a ransomware attack
Neighbourhood Watch starts community cyber-safety initiative
As a summer intern at Trail of Bits, I used the PlusCal and TLA+ formal specification languages to explore Ethereum’s CBC Casper consensus protocol and its Byzantine fault tolerance. This work was motivated by the Medium.com article Peer Review: CBC Casper by Muneeb Ali, Jude […]
FireEye also finds organizations lacking in breach response plans
Rights groups want a moratorium ahead of UK elections