Posts
3641
Following
724
Followers
1593
"I'm interested in all kinds of astronomy."
Cisco Talos issued a ton of TP-Link advisories, check @talosvulns for more details!

RE: https://infosec.place/objects/3c67cba4-e40f-42c2-8c4b-284816d64d00
0
0
1
Edited 3 days ago
[RSS] Qihoo 360's AI Product Leaked the Platform's SSL Key, Issued by Its Own CA Banned for Fraud

https://blog.barrack.ai/qihoo-360-ssl-key-leak-wotrus-ca-fraud/

https://crt.sh/?id=24937759962
https://crt.sh/?id=24937755996

Ouch...
0
0
1
repeated

πŸ¦€ Looking for Rust malware samples to practice analyzing? Our Rust Malware Sample Gallery just received a major update, with 20 new families added! https://github.com/decoderloop/rust-malware-gallery

The Sample Gallery collects links to articles about malware written in Rust, organizes them by malware family, and includes a download link to a publicly available sample for every malware family. This is a resource for any malware analyst who wants to get hands-on with real Rust malware.

The last time the Sample Gallery was updated was almost 2 years ago, in January 2024. Since then, there's been an explosive growth in new Rust malware, including all of the following families that are now in the Sample Gallery:

SPICA, KrustyLoader, RustDoor, SSLoad, Fickle Stealer, Cicada3301 Ransomware, RustyClaw, Embargo Ransomware, RustyAttr, Akira Ransomware (both the Akira_v2 and Megazord variants), Banshee (Rust variant), RALord Ransomware, RustoBot, Tetra Loader, EDDIESTEALER, Myth Stealer, Rustonotto, RustyPages, ChaosBot

This is nearly one new Rust malware family observed in the wild, every month. Rust as a programming language for malware is here to stay!

1
6
0
The leaked exploit toolkit for various iOS versions (Coruna)

https://github.com/khanhduytran0/coruna
0
7
7
@Viss

I may be wrong but assuming users don't know what files are helped me resolve a number of family techsupport situations.

@krypt3ia @decryption @jpm @da_667 @sassdawe
1
0
1
@schrotthaufen

SmartScreen windows got increasingly hard to unblock over time "and for a while, it was good". Then I went to a client where the sysadmin unblocked the freshly downloaded executable from the properties window so fast I had to ask him to show me once more what he just did because I couldn't follow.

Life finds a way.

@decryption @jpm @da_667 @sassdawe @Viss
0
0
1
@Viss As I see with the rise of smart phones companies successfully convinced users that files and directories are low level magic they are not supposed to know or care about. From this point doing stuff with files in a file manager is sorcery indistinguishable from copying 5 pages of sorcery into the sorcery manager. Confirmation windows never stopped any attacks because users click Yes faster than the blink of an eye.

In essence users are expected to make critical decisions about a system that is hidden from them in every other aspect of working with computers.

@sassdawe @da_667 @jpm @decryption
3
1
5
repeated
repeated

Fresh scan: "The UNIX System - a Sun Microsystems Technical Report" (1985)

https://drive.google.com/file/d/1dW6l6cFAiqTKj3bmTulynKQuOHeHMx0u/view?usp=sharing

0
4
0
repeated

I reported a bug in RenderDoc and it got fixed within 45 minutes (!!!) neocat_aww

0
2
0
repeated

TotalRecall - Reloaded.

Invested some time again into Windows Recall. Microsoft redesigned the entire architecture with VBS enclaves after the original TotalRecall. Took a closer look at the new defenses. This time going through MSRC.

0
4
0
repeated

The dream of a fast and reliable binary analysis framework is now a reality.

Today, we’re open sourcing http://VulHunt.RE πŸŽ‰
code: https://github.com/vulhunt-re/vulhunt
docs: https://vulhunt.re/docs

A huge kudos to the entire REsearch team!
https://bird.makeup/users/matrosov/statuses/2025997688437874893

0
5
0
repeated
Edited 3 days ago

> If you understand neither your program, nor your computer, you will succumb to every bug

~ Sun Tzu*

*not really

0
1
0
@bluedevil I seriously don't get why we can't have proper error messages in 2026...
1
0
0
repeated

Meanwhile Pro: "Oops! internal error 1783 occurred."

1
2
1
[RSS] [video] RE//verse 2026: Hacking the Xbox One

https://www.youtube.com/watch?v=FTFn4UZsA5U
0
0
0
repeated

@jwz What I'm taking away from this right now is that for the extremely narrow case of a problem that humans have documented well and written strong tests for, a robot can be competitive with a human expert. And then also today I got an LLM slop bug report that entirely misrepresented the code in question and had entirely fake conclusions. I'm still solidly team human.

0
2
0
Show older