Trellix: When Guardians Become Predators: How Malware Corrupts the Protectors
A malware campaign drops a legitimate Avast Anti-Rootkit driver (BYOVD) to terminate security processes, disable protective software, and seize control of the infected system. Indicators of compromise provided.
#byovd #avast #ioc #threatintel #infosec #cybersecurity #cyberthreatintelligence #cti
In an ideal world for reverse engineering, every function would have a name, and every variable would be correctly typed. Take a step towards that world, learn to build your own custom Ghidra Data Types in my latest post: https://medium.com/@clearbluejar/everyday-ghidra-ghidra-data-types-creating-custom-gdts-from-windows-headers-part-2-39b8121e1d82
here at macrosoft we offer only the most bloated software for your SSD to fight for its life over. Because it’s not as funny when your PC isn’t on the verge of bursting into flames when it boots
the c2.com wiki (the very first wiki) now requires javascript to render. the web i knew is dead
What's your favorite file format challenge / trick / bug / surprise / work / art ?
Bonus point if it's underrated or obscure!
Happy 37th anniversary of the Max Headroom Incident, to those who celebrate.
#Adobe released a surprise update for InDesign that addresses a single OOB Read reported by ZDI security researcher Mat Powell. It's not under active attack, so it's odd to see it released outside of Patch Tuesday. https://helpx.adobe.com/security/products/indesign/apsb24-91.html
A lovely review and takedown of Microsoft's lackadaisical approach to NTLM issues.
At the very least, please disable outbound SMB from your environment, and get signing/encryption (v2/3) going wherever possible.
Got nerd sniped today by Qualys's 5 Linux LPE 0days
https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
Did a PoC for CVE-2024-10224
The blog post (and tooling) on my Apple kernel extension fuzzing technique that I used to find several AppleAVD AV1 decoder bugs is now public at https://googleprojectzero.blogspot.com/2024/11/simple-macos-kernel-extension-fuzzing.html