Posts
2431
Following
590
Followers
1309
A drunken debugger

Heretek of Silent Signal
repeated

Running an ARM Linux machine but still want to do RE? Or maybe you're a sad apple silicon user who misses running native VMs you could use your regular tooling in. With Binary Ninja 4.1, our stable branch includes ARM Linux support!

https://binary.ninja/2024/07/17/4.1-elysium.html#linux-arm-builds

0
1
0
repeated

In the trenches, security and IT teams are the real heroes. The CrowdStrike incident crashed 8.5M Windows devices, and IT worked around the clock to restore systems. But did they get the recognition they deserved from leadership? Too often, their efforts go unnoticed while facing unrealistic expectations. As leaders, we must have their backs - publicly appreciate their work, ensure they have resources, and advocate for them to the C-suite. That's how we build resilient, high-performing teams.

2
13
0
repeated
Edited 6 months ago

Progress Telerik security advisories (edit: plural):

  • Insecure Deserialization Vulnerability - CVE-2024-6327 (9.9 critical, disclosed 24 July 2024) In Progress Telerik Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.
  • Object Injection Vulnerability - CVE-2024-6096 In Progress Telerik Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

No mention of exploitation.

Why you should care about CVE-2024-6327: FIVE Telerik vulnerabilities are known exploited vulnerabilities, TWO specifically called Progress Telerik. One in particular, CVE-2019-18935, is a deserialization of untrusted data vulnerability. This is the same one exploited against the U.S. government last year as noted by CISA on 15 June 2023: Threat Actors Exploit Progress Telerik Vulnerabilities in Multiple U.S. Government IIS Servers. Patch your Teleriks.

cc: @cR0w @tas50 @campuscodi

1
1
0
[RSS] Pwn2Own Automotive: Popping the CHARX SEC-3100

https://blog.ret2.io/2024/07/24/pwn2own-auto-2024-charx-exploit/
0
0
0
[RSS] On ColdFusion Administrator Access Control Bypass Techniques

https://www.hoyahaxa.com/2024/07/on-coldfusion-administrator-access.html
0
0
0
repeated
repeated

Anyone can Access Deleted and Private Repository Data on GitHub â—† Truffle Security Co.
https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github

0
2
0
EU MEP accusing #Hungary for trying to infect his phone with spyware:

https://www.politico.eu/newsletter/brussels-playbook/orban-critic-mep-targeted-with-spyware/

Hungarian news talk about Pegasus, but this seems wrong as the Politico article mentions #Candiru (tech journalism at its best...).

Also the accusation is not supported by evidence, and frankly I wouldn't expect that even our gov is this stupid.
1
0
2
repeated

Congrats @nachoskrnl for being nominated @pwnieawards for his 3-episode research work on Windows paths - well deserved (yes, I nominated it:)).
https://x.com/PwnieAwards/status/1815894380789592298

https://bird.makeup/@pwnieawards/1815894380789592298

0
1
0
In case you don't feel like untangle the #CrowdStrike post-mortem, this is the gist of it:

"Based on the testing performed before the initial deployment of the Template Type (on March 05, 2024), trust in the checks performed in the Content Validator, and previous successful IPC Template Instance deployments, these instances were deployed into production."

In other words they simply didn't do e2e tests on the problematic update data that triggered the bug in their parser, because prev updates worked fine.

We still don't know how the malformed Template Instances were produced.
2
2
7
repeated

Something I've had on my list for quite some time and finally got around to now: updating the HowFuzzilliWorks document: https://github.com/googleprojectzero/fuzzilli/blob/main/Docs/HowFuzzilliWorks.md

Besides a number of smaller changes (e.g. new mutators), the design of the HybridEngine has changed considerably since the document was initially written.

Happy fuzzing!

0
4
0
repeated

that the uses something called a „COBRA seal“ to seal relevant objects against manipulation. One type of these seals works by using a multi-core optical cable. When the seal is locked a random number of cores are cut. This creates a unique optical pattern that can be verified simply by shining a light into the cable and can’t be recreated.

2
8
0
repeated
repeated

Do I know anyone with a mail address on a mail server managed by barracuda networks who would help me with something? I'd like to test a few things (just sending you a few test mails and see if they arrive).

0
1
0
repeated

Wild, true story from the security awareness and training company KnowBe4 that details how they inadvertently hired a North Korean hacker who was posing as a Western tech worker.

Kudos to them for publishing this. If it can happen to a security awareness company, it can happen to anyone (full disclosure: they've been an advertiser on my site for ages).

https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us

4
19
0
repeated

I've published a little blog on binary patching Golang produced assembly to alter the stdlib net/http functionality. and frens maybe interested! https://pulsesecurity.co.nz/articles/golang-patching

0
2
0
repeated

We're proud our testing helps ensure the security of Thinkst's OSS Canary Tokens! As part of their transparency efforts, you can read the results of our latest round of testing here:

https://www.doyensec.com/resources/Doyensec_ThinkstCanaryTokensOSS_Report_Q22024_WithRetesting.pdf

1
4
1
Show older