Researcher told card maker about problem in August 2013
The automated tool mounts a social engineering campaign and a man-in-the-middle attack to capture credentials.
We need to do more to protect ourselves. 2014 overflowed with front-page proof: Apple, Target, JPMorgan Chase, etc, etc. The current, vulnerable status quo begs for radical change, an influx of talented people, and substantially better tools. As we look ahead to driving that change in 2015, we’re pr...
Bristolians miffed by incongruous web defacement
USBs likely to have introduced “low risk” worm, says energy minister
This is part two of a two-part blog post that shows how to use KLEE with mcsema to symbolically execute Linux binaries (see the first post!). This part will cover how to build KLEE, mcsema, and provide a detailed example of using them to symbolically execute an existing binary. The binary we’ll be s...
Project Zero’s strict 90-day deadline branded ‘irresponsible'
An unpatched privilege escalation flaw in Windows 8.1 opens the door for network infiltration.
At THREADS 2014, I demonstrated a new capability of mcsema that enables the use of KLEE, a symbolic execution framework, on software available only in binary form. In the talk, I described how to use mcsema and KLEE to learn an unknown protocol defined in a binary that has never been seen before. In...
The popular online gaming outlet has been infiltrated to push credential-stealing malware.
Activists urge tech giants to revoke certificates.
Feds want more tech experts in their crime-fighting ranks.
The people behind Backoff have been using surveillance cameras to verify that machines are in fact POS devices.
The attack makes use of the laptops’ physical Thunderbolt interface to achieve persistent boot rootkits.
War torn country sucked into Beijing’s South Asian strategy
Russian cyber-criminals target internal banking systems
Hot topics will include cloud security and mobility—and the intersection between them.
A citizen media group critical of ISIS was recently targeted in a customized digital attack designed to unmask their location.
A variant of the Alina malware, used to scrape credit card (CC) data from point of sale (POS) software, has been rampaging its way through the wild lately.
Bitdefender claims cyber-criminals will look to new channels to spread malware in 2015