Chrome

InfoSec Week 51, 2018

Google Project Zero published a blog about the FunctionSimSearch open-source library which is capable to find similar functions in the assembly. They are using it to detect code statically-linked vulnerable library functions in executables.

Posted

#Weekly-News

InfoSec Week 24, 2018

Yet another high severity attack against the Intel CPUs. Unpatched systems can leak SIMD, FP register state between privilege levels. These registers are used for private keys nowadays. The cost of a patch is more expensive context switches because the fix has to unload and reload all SIMD, FP state.

Posted

#Weekly-News

InfoSec Week 22, 2018

Google Pixel 2 devices implement insider attack resistance in the tamper-resistant hardware security module that guards the encryption keys for user data. It is not possible to upgrade the firmware that checks the user's password unless you present the correct user password.

Posted

#Weekly-News

InfoSec Week 6, 2018

A buffer overflow vulnerability in older Starcraft version enabled modders to create new maps, so Blizzard tasked reverse engineer to safely emulate the bug in the newer, fixed version. The author says it all: 'This is a tale about what dedication to backward compatibility implies.'

Posted

#Weekly-News

InfoSec Week 45, 2017

Researchers exploited antivirus software quarantine mechanism to gain privileges by manipulating the restore process from the virus quarantine. By abusing NTFS directory junctions, the AV quarantine restore process can be manipulated, so that previously quarantined files can be written to arbitrary file system locations.

Posted

#Weekly-News

InfoSec Week 43, 2017

Researchers from the Masaryk University finally published full paper of the practical cryptographic attack against the implementation of RSA in the widely used trusted platform modules / crypto tokens. 'The Return of Coppersmith’s Attack: Practical Factorization of Widely Used RSA Moduli'

Posted

#Weekly-News

InfoSec Week 38, 2017

The ZNIU Android malware is exploiting Linux kernel 'Dirty COW' vulnerability to install itself on a device and collect money through the SMS-enabled payment service.

Posted

#Weekly-News

InfoSec Week 11, 2017

MalwareMustDie analyzed new APT Campaign with the Poison Ivy RAT payload. Malware is using obfuscated VBScript, Power Shell to finally drop well known RAT. 'The concept of infection is fileless, it's avoiding known signature for detection by multiple encodings and wraps, and it is also 100% avoiding the original attacker's working territory.'

Posted

#Weekly-News

InfoSec Week 6, 2017

A new malware called MacDownloader, attributed to the Iran, targeting macOS systems spotted in the wild. Spreading as an Adobe Flash installer or a Bitdefender Adware Removal Tool, depend on social engineering. After installation, it attempts to exfiltrate OS X keychain database as well as the other system information.

Posted

#Weekly-News

InfoSec Week 3, 2017

Trustwave released the Carbanak gang campaign threat report called 'Operation Grand Mars'. The paper explains the modus operandi of the Carbanak group, malware distribution techniques, attack vectors. The interesting point is that the group uses Google Apps, Sheets and Forms as a part of their Command & Control infrastructure. But Trustware is not the only one reporting about this.

Posted

#Weekly-News