Media giant and US city latest victims of email fraud
Customers’ personal info may have been compromised
Parsing is hard, even when a file format is well specified. But when the specification is ambiguous, it leads to unintended and strange parser and interpreter behaviors that make file formats susceptible to security vulnerabilities. What if we could automatically generate a “safe” subset of any file...
Low confidence and a toxic workplace culture put women off cybersecurity jobs
Cybersecurity should be taught in the same way as reading and writing
TL;DR: x86_64 decoding is hard, and the number and variety of implementations available for it makes it uniquely suited to differential fuzzing. We’re open sourcing mishegos, a differential fuzzer for instruction decoders. You can use it to discover discrepancies in your own decoders and analysis to...
Inadequate recruitment practices in cybersecurity are a threat to national security
Duo’s extortion attempts worked only with ride-hailing giant
Recently, security researchers discovered that Apple was sending safe browsing data to Tencent for all Chinese users. This revelation has brought the underlying security and privacy guarantees of the safe browsing protocol under increased scrutiny. In particular, safe browsing claims to protect user...
Social media platform aims to clean up its act
The next generation need to create "digital identity" security capabilities
A few weeks ago I had the inspiring experience of attending the annual Grace Hopper Celebration (GHC), the world’s largest gathering of women in technology. Over four days in Orlando, Florida, GHC hosted a slew of workshops and presentations, plus a massive career fair with over […]
UK watchdog set to work on statutory code of practice
Supply chain attacks continue to be a reality for businesses
MITRE just updated the ATT&CK Framework to include Cloud TTPs.
The update includes techniques for stealing cookies from machines and using them for lateral movement. These are the two techniques I helped contribute to the matrix:
Credential Access - Steal Web Session Cookie Lateral Movement - We...
William McRaven tells cybersecurity professionals to take risks and expect failures
2019 ISLA Americas winners collect gongs at conference
As a summer intern at Trail of Bits, I used the PlusCal and TLA+ formal specification languages to explore Ethereum’s CBC Casper consensus protocol and its Byzantine fault tolerance. This work was motivated by the Medium.com article Peer Review: CBC Casper by Muneeb Ali, Jude […]
Lack of understanding leaves phenomenal security resource untapped
What to look for when building a threat hunting team