FBI notifies victims of Joanap malware
Unauthorized access incident affected commercial aircraft business
Each year, Trail of Bits runs a month-long winter internship “winternship” program. This year we were happy to host 4 winterns who contributed to 3 projects. This is the first in a series of blog posts covering the 2019 Wintern class. Our first report is from Vaibhav Sharma (@vbsharma), a PhD studen...
Consumers can now complain to the fraudster's bank
Discover, Allen Chern and Verity Medical Foundation report unauthorized third-party access to customer data.
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Mutation Testing Introducing one bug by hand (as we did in Part 1) is fine, and we could try it again, but “the plural of anecdote is not data.” However, this is not strictly true. If we...
The vulnerability exploited in Equifax breach is still being used nearly two years later.
Almost all IT executives feel vulnerable to attack, according to Thales
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Using DeepState, we took a handwritten red-black tree fuzzer and, with minimal effort, turned it into a much more fully featured test generator. The DeepState fuzzer, despite requiring no...
New cyber risk report paints doomsday scenario
The xDedic site enabled an illegal trade in server credentials
C++ programs using exceptions are problematic for binary lifters. The non-local control-flow “throw” and “catch” operations that appear in C++ source code do not map neatly to straightforward binary representations. One could allege that the compiler, runtime, and stack unwinding library collude to...
Last year's DDoS attack at GitHub, surpasses all previous attacks, says Imperva.
Underground hacking forums recommend a new version of FormBook for hosting and serving malware.
On December 12, over 150 attendees joined a special, half-day Empire Hacking to learn about pitfalls in smart contract security and how to avoid them. Thank you to everyone who came, to our superb speakers, and to BuzzFeed for hosting this meetup at their office. Watch the presentations again It’s h...
Total Donations was abandoned by its developers, leaving little hope for a fix.
Using FaceTime today won't keep eavesdroppers away.
We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post covers intercepting system calls from within the Linux kernel, via a plain old kernel module. We’ll...
Wants nation to be a leader in hardware security
DoJ alleges Chinese firm stole trade secrets and tricked banks into breaking sanctions