It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”
https://palant.info/2024/07/15/how-insecure-is-avast-secure-browser/
Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.
TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.
Some highlights:
Enjoy!
We love Open Source contributors.
If you are a significant contributor to an Open Source project, DM us, and we will give you a full briefings pass to BlackHat USA (absolutely free).
__
* Tickets handed out totally at our discretion;
** We only have a few tickets left;
fq 0.12.0 released 🥳 nothing fancy, REPL and jpeg fixes otherwise mostly update of dependencies.
Spent the last four days coordinating incident response for the Squarespace domain hijackings with @tay and @AndrewMohawk. Now that it seems to be resolved, we wrote a little postmortem/retrospective
Starting from v0.10 (the next version), HyperDbg uses @keystone_engine as its assembler. ❤️
Thanks to our new team member @AbbasMasoumiG for adding it.
The following commands are added to assemble virtual and physical memory:
Clever & fun technique to dump #Windows LSA secrets bypassing #EDR by @sensepost
Dumping LSA secrets: a story about task decorrelation
https://sensepost.com/blog/2024/dumping-lsa-secrets-a-story-about-task-decorrelation/
Introduction to the Wild West of Proof of Concept #Exploit Code (#PoC) aka SSHing the Masses
https://santandersecurityresearch.github.io/blog/sshing_the_masses.html
Everyone complains about meetings, but rarely anybody puts time before the meeting to do the work needed for the meeting to be useful.
CCC researchers had live access to 2nd factor SMS of more than 200 affected companies - served conveniently by IdentifyMobile who logged this sensitive data online without access control.
You had one job.
Does anyone have a technical reference (assuming it is public) for the hardware additions to ARMv8 which Apple made in Apple Silicon to support Rosetta 2?