Annual fundraising event hosted by TV presenter Nick Knowles
Big Brother Watch claims many were obtained illegally
Each year, Trail of Bits runs a month-long winter internship “winternship” program. This year we were happy to host 4 winterns who contributed to 3 projects. This is the first in a series of blog posts covering the 2019 Wintern class. Our first report is from Vaibhav Sharma (@vbsharma), a PhD studen...
Password misuse resulted in hackers gaining control of Nest security cameras.
Financial services executives say concerns about cyber risk will grow over the next two years.
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Mutation Testing Introducing one bug by hand (as we did in Part 1) is fine, and we could try it again, but “the plural of anecdote is not data.” However, this is not strictly true. If we...
A new campaign delivers malware via PDF file decoys, says Netskope.
VeryMal campaign uses steganography techniques
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Using DeepState, we took a handwritten red-black tree fuzzer and, with minimal effort, turned it into a much more fully featured test generator. The DeepState fuzzer, despite requiring no...
UK-based Fidus Information Security was targeted by angler phishing
Latest ONS survey estimates one million annual incidents in England and Wales
C++ programs using exceptions are problematic for binary lifters. The non-local control-flow “throw” and “catch” operations that appear in C++ source code do not map neatly to straightforward binary representations. One could allege that the compiler, runtime, and stack unwinding library collude to...
A new interactive online game teaches cybersecurity skills to Girls Scouts.
Parliament Street report reveals most want mandatory licensing system
On December 12, over 150 attendees joined a special, half-day Empire Hacking to learn about pitfalls in smart contract security and how to avoid them. Thank you to everyone who came, to our superb speakers, and to BuzzFeed for hosting this meetup at their office. Watch the presentations again It’s h...
McAfee says new discovery was created by highly skilled hands
Swedish regulator request more info on Android location data collection
We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post covers intercepting system calls from within the Linux kernel, via a plain old kernel module. We’ll...
Bancolombia is among the trove of financial and banking institutions with leaky Elasticsearch databases.
Last year saw both an increased awareness of and a decrease in the number of ransomware attacks