The European Commission will award bounties in the third round of its free and open source software audit.
After targeting Chromecast, TheHackerGiraffe grew scared of getting caught.
This year for CSAW CTF, Trail of Bits contributed two cryptography problems. In the first problem, you could combine two bugs to break DSA much like the Playstation 3 firmware hackers. The other challenge–-weirder and mathier–-was split into two parts: one for the qualifiers, one in finals. This cha...
The attacker is demanding a payment of one Bitcoin within five days.
Experts sound note of caution as extorters ramp up the hyperbole
With 2019 a day away, let’s reflect on the past to see how we can improve. Yes, let’s take a long look back 30 years and reflect on the original fuzzing paper, An Empirical Study of the Reliability of UNIX Utilities, and its 1995 follow-up, Fuzz Revisited, by Barton P. Miller. In this blog post, […]
Users urged to switch off UPnP in latest campaign
Abine admits millions of Blur customers may have been affected
The Trail of Bits SummerCon Fellowship program is now accepting applications from emerging security researchers with excellent project ideas. Fellows will explore their research topics with our guidance and then present their findings at SummerCon 2019. We will be reserving at least 50% of our fundi...
Work details of 30,000 Victorian government employees was stolen in the data breach.
The Department of Health and Human Services released voluntary cybersecurity best practices for the healthcare sector.
The Trail of Bits cryptographic services team contributed two cryptography CTF challenges to the recent CSAW CTF. Today we’re going to cover the easier one, titled “Disastrous Security Apparatus – Good luck, ‘k?” This problem involves the Digital Signature Algorithm (DSA) and the way an apparently s...
Robert Lee calls for calm and patience in the aftermath of malware attack on Tribune Publishing.
Brussels wants a more coordinated response to security challenges
Web Applications and Services use cookies to authenticate sessions and users. An adversary can pivot from a compromised host to Web Applications and Internet Services by stealing authentication cookies from browsers and related processes. At the same time this technique bypasses most multi-factor au...
Repressive legislation came into force on January 1
Pyongyang suspected of retaliation
Sophisticated campaign attempts to dupe Amazon shoppers with fake order confirmation email
First cybersecurity graduate for Southern University
Startup aims to return control of data to users