CIA

InfoSec Week 45, 2018

A default VirtualBox virtual network device has a vulnerability allowing an attacker with root privilege to escape guest OS, execute commands in ring3 on a host. All operating systems affected.

Posted

#Weekly-News

InfoSec Week 20, 2018

Major (probably not only) US cell carriers are selling access to the real-time phone location data. Because, you know the Electronic Communications Privacy Act only restricts telecommunication companies from disclosing data to the government, it doesn't restrict disclosure to other companies. Which can resell back to the gov. Hacker News discussion on a topic is quite informative.

Posted

#Weekly-News

InfoSec Week 18, 2018

Multiple tech giants like Apple, Microsoft, Google and others formed an industry coalition and have joined security experts in criticizing encryption backdoors, after Ray Ozzie's CLEAR key escrow idea was widely derided. He basically proposed a scheme where the users have no control over their own devices, but the devices can be securely forensically analyzed by the government agencies.

Posted

#Weekly-News

InfoSec Week 45, 2017

Researchers exploited antivirus software quarantine mechanism to gain privileges by manipulating the restore process from the virus quarantine. By abusing NTFS directory junctions, the AV quarantine restore process can be manipulated, so that previously quarantined files can be written to arbitrary file system locations.

Posted

#Weekly-News

InfoSec Week 32, 2017

The lone Nigerian guy is responsible for an attack against at least 4000 gas, oil, banking, infrastructure organizations using phishing and NetWire trojan for remote access.

Posted

#Weekly-News

InfoSec Week 27, 2017

WikiLeaks has published documents detailing two alleged CIA implants, BothanSpy and Gyrfalcon, designed to steal SSH credentials from Windows and Linux.

Posted

#Weekly-News

InfoSec Week 22, 2017

Notoriously known Gh0st RAT spyware is spreading through the same SMB vulnerability as a WannaCry ransomware.

Posted

#Weekly-News

InfoSec Week 17, 2017

A team of researchers from New York University said they identified a severe flaw in General Electric Multilin protection relays, which are widely deployed in the US energy sector.

Posted

#Weekly-News

InfoSec Week 13, 2017

The tale of a misunderstood malware author who has released banking malware - NukeBot- source code on a GitHub to get a track.

Posted

#Weekly-News

InfoSec Week 12, 2017

Good article about Zeus GameOver botnet take down and chasing of Evgeniy Mikhailovich Bogachev aka Slavik, author of the Zeus malware family.

Posted

#Weekly-News