April 3, 2023
Our Q1 selection
OpenSSH Pre-Auth Double Free CVE-2023-25136 jfrog.com/blog/openssh-p…
Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game decoded.avast.io/janvojtesek/do…
BlackLotus UEFI bootkit welivesecurity.com/2023/03/01/bla…
aCropalypse: Recovering Truncated PNGs
-
Wwow it's so cool and sustainable that the most annoying ppl now know how to make their posts even more algorithm friendly AND can generate text/pics with AI for free AND can pay to boost AND it's getting harder to determine whether or not info is coming from an official source
-
Lazarus Heist: The intercontinental ATM theft that netted $14m in two hours
https://www.bbc.com/news/world-65130220
-
“Landmark”, the product bought here, is not a hacking tool. It is a surveillance tool based on SS7 (see our coverage here vice.com/en/article/m7v…). Sounds pedantic, but it’s a key distinction when governments are clamping down on commercial spyware. Landmark is not that. https://t.co/VOCzvATL2W
Mark Mazzetti @MarkMazzettiNYT
-
-
This last was a reply to another @lawfareblog commentary on UK cyber strategy, by @DrAndrewDwyer and @ciaranmartinoxf, which is also well worth reading lawfareblog.com/frontier-witho… 7/7
-
An unknown individual has compromised the email system for Equifax. They have sent out an email with the subject matter as "Free Pompompurin".
Image 1. email extended header information
Image 2. email itself
-
My dear old friend @VladislavZubok1 and I have a new piece in @ForeignAffairs on the Cuban Missile Crisis, everyone's favourite subject, which you will want to read because it literally has new stuff we did not know about (what, still?): foreignaffairs.com/cuba/missile-c….
-
-
every european election:
🔵 The People's Democrats (center-right) - 31%
🔴 Soviet Worker's Party (center/center-left) - 22%
⚫️ Citizen's Forum (fascist) - 19%
🟠 Wow! (center) - 11%
🟣 Friendship Is Magic (left) - 9%
🟢 Green Party - 8%
-
#ICYMI We’re bringing HITBSecConf to Phuket this August with keynotes by
@joegrand and @thegrugq conference.hitb.org/hitbsecconf202… #HITB2023HKT
-
A sort of compare and contrast by the British army showing how the Provos train and operate compared to the British Army. It’s very strange.
-
Fight Circus lives up to the name. It’s a glorious mess.
-
Probably the best thing you'll see today.
In 2017, a group of developers hilariously competed for who could create worst volume control interface in the world.
The results 🧵
1/22
-
Lessons from Russia’s Unconventional Operations During the Russo-Ukrainian War. To a great degree information/psychological operations & use of digital tools. "significant part of Russia’s agents in Ukraine and in other countries continue to operate" static.rusi.org/202303-SR-Unco…
-
Listen to @Infosecjen !
BH Europe 22 - Keynote - Cybersecurity: The Next Generation - YouTube
vid: youtu.be/uPM_IgTdHCk
slides: blackhat.com/eu-22/briefing…
-