<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Chrome - malgregator</title>
    <link>https://malgregator.com/tags/chrome/</link>
    <description>Recent content in Chrome on malgregator</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>you@example.com</managingEditor>
    <webMaster>you@example.com</webMaster>
    <lastBuildDate>Thu, 20 Dec 2018 08:41:00 +0000</lastBuildDate>
    
        <atom:link href="https://malgregator.com/tags/chrome/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>InfoSec Week 51, 2018</title>
      <link>https://malgregator.com/post/week-51-2018/</link>
      <pubDate>Thu, 20 Dec 2018 08:41:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-51-2018/</guid>
      <description>Google Project Zero published a blog about the FunctionSimSearch open-source library which is capable to find similar functions in the assembly.   They are using it to detect code statically-linked vulnerable library functions in executables.</description>
    </item><item>
      <title>InfoSec Week 24, 2018</title>
      <link>https://malgregator.com/post/week-24-2018/</link>
      <pubDate>Fri, 15 Jun 2018 11:34:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-24-2018/</guid>
      <description>Yet another high severity attack against the Intel CPUs. Unpatched systems can leak SIMD, FP register state between privilege levels. These registers are used for private keys nowadays.   The cost of a patch is more expensive context switches because the fix has to unload and reload all SIMD, FP state.</description>
    </item><item>
      <title>InfoSec Week 22, 2018</title>
      <link>https://malgregator.com/post/week-22-2018/</link>
      <pubDate>Fri, 01 Jun 2018 10:04:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-22-2018/</guid>
      <description>Google Pixel 2 devices implement insider attack resistance in the tamper-resistant hardware security module that guards the encryption keys for user data.   It is not possible to upgrade the firmware that checks the user&#39;s password unless you present the correct user password.</description>
    </item><item>
      <title>InfoSec Week 6, 2018</title>
      <link>https://malgregator.com/post/week-06-2018/</link>
      <pubDate>Fri, 09 Feb 2018 19:20:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-06-2018/</guid>
      <description>A buffer overflow vulnerability in older Starcraft version enabled modders to create new maps, so Blizzard tasked reverse engineer to safely emulate the bug in the newer, fixed version.   The author says it all: &#39;This is a tale about what dedication to backward compatibility implies.&#39;</description>
    </item><item>
      <title>InfoSec Week 45, 2017</title>
      <link>https://malgregator.com/post/week-45-2017/</link>
      <pubDate>Thu, 16 Nov 2017 07:20:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-45-2017/</guid>
      <description>Researchers exploited antivirus software quarantine mechanism to gain privileges by manipulating the restore process from the virus quarantine. By abusing NTFS directory junctions, the AV quarantine restore process can be manipulated, so that previously quarantined files can be written to arbitrary file system locations.</description>
    </item><item>
      <title>InfoSec Week 43, 2017</title>
      <link>https://malgregator.com/post/week-43-2017/</link>
      <pubDate>Wed, 01 Nov 2017 22:57:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-43-2017/</guid>
      <description>Researchers from the Masaryk University finally published full paper of the practical cryptographic attack against the implementation of RSA in the widely used trusted platform modules / crypto tokens.    &#39;The Return of Coppersmith’s Attack: Practical Factorization of Widely Used RSA Moduli&#39;</description>
    </item><item>
      <title>InfoSec Week 38, 2017</title>
      <link>https://malgregator.com/post/week-38-2017/</link>
      <pubDate>Wed, 27 Sep 2017 22:30:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-38-2017/</guid>
      <description>The ZNIU Android malware is exploiting Linux kernel &#39;Dirty COW&#39; vulnerability to install itself on a device and collect money through the SMS-enabled payment service.</description>
    </item><item>
      <title>InfoSec Week 11, 2017</title>
      <link>https://malgregator.com/post/week-11-2017/</link>
      <pubDate>Sun, 19 Mar 2017 21:20:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-11-2017/</guid>
      <description>MalwareMustDie analyzed new APT Campaign with the Poison Ivy RAT payload. Malware is using obfuscated VBScript, Power Shell to finally drop well known RAT.   &#39;The concept of infection is fileless, it&#39;s avoiding known signature for detection by multiple encodings and wraps, and it is also 100% avoiding the original attacker&#39;s working territory.&#39;</description>
    </item><item>
      <title>InfoSec Week 6, 2017</title>
      <link>https://malgregator.com/post/week-06-2017/</link>
      <pubDate>Sun, 12 Feb 2017 14:30:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-06-2017/</guid>
      <description>A new malware called MacDownloader, attributed to the Iran, targeting macOS systems spotted in the wild. Spreading as an Adobe Flash installer or a Bitdefender Adware Removal Tool, depend on social engineering. After installation, it attempts to exfiltrate OS X keychain database as well as the other system information.</description>
    </item><item>
      <title>InfoSec Week 3, 2017</title>
      <link>https://malgregator.com/post/week-03-2017/</link>
      <pubDate>Sat, 21 Jan 2017 16:45:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-03-2017/</guid>
      <description>Trustwave released the Carbanak gang campaign threat report called &#39;Operation Grand Mars&#39;. The paper explains the modus operandi of the Carbanak group, malware distribution techniques, attack vectors. The interesting point is that the group uses Google Apps, Sheets and Forms as a part of their Command &amp; Control infrastructure. But Trustware is not the only one reporting about this.</description>
    </item>
  </channel>
</rss>