SANS ISC: Ancient TP-Link Backdoor Discovered by Attackers
@jullrich did you want to report this vulnerability to MITRE (or be credited)? Using CWE-912: Hidden Functionality and sekurak's entry as vulnerability details, this should be a quick CVE submission.
It’s finally landed! You can now watch “Listen to the whispers: web timing attacks that actually work” on YouTube: https://youtube.com/watch?v=zOPjz-sPyQM
Hey #infosec folks, if you've bridged your account to #Bluesky using BridgyFed (https://fed.brid.gy/) let me know so I can add that bridged account to a starter pack there. 👍
Would be great to highlight the infosec people who are here, over there.
Boost around so I can nab everyone! 🚀
- Why was ollydbg discontinued?
- Not enough ollyfans
NEW: WhatsApp forced a judge to release previously non-public court documents, which include a ton of details on how NSO's spyware works.
The documents show how NSO targeted WhatsApp, the number of customers the company had to cut off because of abuse, and more.
Here are the biggest revelations.
Just registered the 38c3 assembly "ITAR Violators". Hope to see your ITAR controlled items!
Google Security: Retrofitting Spatial Safety to hundreds of millions of lines of C++
Google is retrofitting secure-by-design principles to their existing C++ codebase wherever possible, including bringing spatial memory safety into as many codebases. It has already made a noticeable impact, from preventing exploits, reducing crashes and improving code reliability/easier debugging.
#google #security #securebydesign #memorysafety #vulnerability #memory #infosec #cybersecurity
Missed out on the action at #r2con2024 in Barcelona? #NowSecure researcher and #radare2 co-creator @pancake put together a recap of all three days, including all the recordings, slides, and GitHub repositories. Check it out here: https://www.nowsecure.com/blog/2024/11/15/nowsecure-at-r2con2024-top-takeaways-and-mobile-security-highlights/?utm_source=mastodon
A huge thanks to everyone who joined us and made this comeback event a success after a 5-year break! #r2con #radare #frida
Pandoc compiled to Wasm (WebAssembly), which enables live conversions in the browser.
• Live demo: https://tweag.github.io/pandoc-wasm/
• Repository: https://github.com/tweag/pandoc-wasm
Amazing work by @terrorjack and the ghc-meta-wasm folks!
Unpatched 0day in an enterprise firewall management interface? Must be Friday https://www.rapid7.com/blog/post/2024/11/15/etr-zero-day-exploitation-targeting-palo-alto-networks-firewall-management-interfaces/