Guidelines will assist the supply chain in their duty of care to other network users
Managed Health Services of Indiana Health Plan announced two security incidents.
KoiPhish is a simple yet beautiful relay proxy idea.
The idea for this little project goes back many years. Since I started learning Golang I figured it would be good exercise to finally go ahead an implement it. So, last December during the 35C3 (which is always inspiring congress) I wrote it up.
I...
A cybersecurity firm reportedly aided progressive group of Democrats in spreading fake news to take down Roy Moore.
A hardware-agnostic page cache attack targets operating systems.
Just a list of useful notes when dealing with Macs. I’m pretty new to Macs and there might be other, better solutions to the challenges I had to sovle but these worked for me and I’m learning. :)
Pivoting between accounts and keychain issues After pivoting on a target host and elevating to root it s...
Expired web certificates expose users to man-in-the-middle attacks
Confectionary maker Mondelez is claiming $100m
This year for CSAW CTF, Trail of Bits contributed two cryptography problems. In the first problem, you could combine two bugs to break DSA much like the Playstation 3 firmware hackers. The other challenge–-weirder and mathier–-was split into two parts: one for the qualifiers, one in finals. This cha...
Exposed database spilled huge volume of sensitive data online
Phishing attacks are made easy with a pen testing tool, says security researcher.
With 2019 a day away, let’s reflect on the past to see how we can improve. Yes, let’s take a long look back 30 years and reflect on the original fuzzing paper, An Empirical Study of the Reliability of UNIX Utilities, and its 1995 follow-up, Fuzz Revisited, by Barton P. Miller. In this blog post, […]
Hackers are believed to have accessed names, addresses and credit card information.
Hyatt invites global security researchers to search for vulnerabilities.
The Trail of Bits SummerCon Fellowship program is now accepting applications from emerging security researchers with excellent project ideas. Fellows will explore their research topics with our guidance and then present their findings at SummerCon 2019. We will be reserving at least 50% of our fundi...
Attacks seek to harvest log-ins from Middle East government users
Consultant helped Feds listen in on ‘secret’ chats
The Trail of Bits cryptographic services team contributed two cryptography CTF challenges to the recent CSAW CTF. Today we’re going to cover the easier one, titled “Disastrous Security Apparatus – Good luck, ‘k?” This problem involves the Digital Signature Algorithm (DSA) and the way an apparently s...
Possible credential stuffing attack prompts investigation
More than 100 businesses were impacted by a malware strain targeting Android devices, says The Media Trust.