NEW: Amnesty International has documented two cases where Serbian authorities used Cellebrite to unlock the phones of a journalist and an activist.
And then they installed spyware on the devices.
In a way, this is a return to the old days of government spyware, where remote attacks were rare and impractical, and cops needed to get their hands on target's computers.
Platform.sh team finds auth bypass in Go SSH package https://platform.sh/blog/uncovered-and-patched-golang-vunerability/
as a sysadmin this so much. It’s one thing to say “oopsie something went wrong” and provide a button for the professionals to see where it went wrong and it’s another to just not provide any diagnostic information so I get to debug a black box.
Just returned from #BHEU. I presented my research on how server-side HTML sanitization is a security nightmare due to the mess that is HTML parsing.
If you are interested in learning more on that topic, please check out the following resources:
Github: https://github.com/ias-tubs/HTML_parsing_differentials
Our S&P '24 Paper: https://www.ias.cs.tu-bs.de/publications/parsing_differentials.pdf
Slides will be available shortly.
Or get in touch :)
Huge thanks to @BlackHatEvents, @InfosecVandana, and all the other great folks who made this such an amazing experience.
Good and interesting presentation by Joe Bialek:
Pointer Problems – Why We’re Refactoring the Windows Kernel:
@nsg650 Technically yes, but the system would immediately crash if you enabled it since user mode access happens constantly from ring 0. They are working to enable it for real some time in the future.
Important news: Microsoft is working to bring SMAP into Windows
Can you find an ITW 0-day from crash logs? Project Zero finds out
Yearlong supply-chain attack targeting security pros steals 390K credentials https://arstechnica.com/security/2024/12/yearlong-supply-chain-attack-targeting-security-pros-steals-390k-credentials/
Looking at legacy NeXT source:
Quoting from the OS X man page for execvp():
"Historically, the default path for the execlp() and execvp() functions was ``:/bin:/usr/bin''. This was changed to place the current directory last to enhance system security."
JOURNALISM 101 RULE: If someone says it’s raining, and another person says it’s dry, it’s not your job to quote them both. Your job is to look out of the fucking window and find out which is true. — Now more than ever.