Acabo de lanzar Brash, una vulnerabilidad crítica que encontré en Blink, el motor de renderizado que impulsa los navegadores basados en Chromium propiedad de Google.
Permite colapsar cualquier navegador Chromium entre 15 y 60 segundos explotando una falla arquitectónica en la forma en que se gestionan ciertas operaciones del DOM.
I’m excited to share IFA: A proof of concept (PoC) that exposes a severe vulnerability in the IndexedDB API of popular web browsers. This vulnerability allows for a disk flooding attack, rapidly consuming storage space and potentially crashing systems. IFA leverages the lack of restrictions in IndexedDB, injecting hundreds of MBs per second into your disk space.
▪️ Open Source (PoC): https://t.co/uQwMSBz5hS
Los invito a ver Turbit, mi reciente creación! 🚀
Hace pocos días lancé esta librería de Node.js, diseñada para maximizar el rendimiento en operaciones intensivas mediante el procesamiento paralelo en múltiples núcleos de la CPU, permitiendo gestionar grandes volúmenes de datos, ejecutar simulaciones científicas y procesar algoritmos complejos de manera más eficiente.
🔗GitHub Code: https://t.co/31hQ2Ur3hU
En ciberseguridad, facilita la creación de herramientas avanzadas y procesos de fuerza bruta.
Inspiración
Como investigador, me resultaba difícil encontrar una solución sencilla para el procesamiento paralelo en Node.js. Las opciones disponibles eran complicadas y difíciles de manejar, lo que limitaba el uso eficiente de la CPU en tareas de alto rendimiento. Además, mi gusto por la fuerza bruta me llevó a buscar una manera de optimizar estos procesos. Esto me inspiró a crear Turbit, para simplificar el procesamiento paralelo en aplicaciones y procesos, permitiendo a los devs aprovechar fácilmente todo el potencial de su hardware sin complicarse con los detalles de implementación.
#javascript #nodejs #cpu
Introducing Turbit: High-speed computing for the multicore era. This advanced Node.js library is designed to boost performance in intensive operations by leveraging parallel processing across multiple CPU cores, empowering you to create powerful applications, scripts, and automations with improved efficiency.
▪️ Open Source (Library): https://t.co/31hQ2UrB7s
Excited to introduce temcrypt: The next-gen encryption! Designed to protect highly sensitive data, it's an advanced multi-layer evolutionary encryption mechanism that offers scalable complexity factor over time, and maintains resistance to common brute force attacks.
▪️ Open Source (framework): https://t.co/d0eBlHhX5J
▪️ Website: https://t.co/qP0FqfjDeC
As a cybersecurity researcher, I have noticed a great lack of innovation in encryption algorithms in more than two decades. But in January 2023, an event changed everything, after Chinese researchers managed to crack the 2048-bit RSA algorithm with just 372 qubits. This fact highlights the urgent need to evolve our cryptography against the power of quantum computing.
Source: https://t.co/KzADbhI5n8
After learning about the above, being inspired by Moore's Law and the concept of #bitcoin halving, I envisioned a future with crypto that would adapt over time. Thus was born temcrypt, designed to protect highly sensitive data.
Create a Scalable Complexity Factor incorporating 18-month cycles to increase the complexity of temcrypt and a custom clock that advances and adds one hour every 6 months.
The dependency to decrypt the data is based on a unique key, the time it was encrypted, and the processing power of your machine. If you don't apply the exact key at the exact time (hour and minute) in later days, decrypting the information becomes “impossible”.
You can read more in the following repository paths:
▪️Readme: https://t.co/R6Bw8e78yM
▪️Knowledge: https://t.co/3eW17Bejyx
With temcrypt, you can have many use cases. Some I can mention include protection for your seed phrases (cryptocurrency wallets), business data, military data, medical data, and much more.
I hope you enjoy #temcrypt and share it with your friends, coworkers, developers, lawyers, journalists, and people around the world who deserve to protect their most sensitive data.
This is a big step for a new era of new ways to encrypt and protect data.
🔵Hoy!
🕗22:30hs
Para nuestro público en español les contamos que @famato va a participar del programa de @bysepatw sobre #ciberseguridad. Imperdible!
Nos vemos en Twitch
🔗https://t.co/PBh5gSlNWB
Gracias por la confianza y apoyo que nos brinda nuestro patrocinador @Segtics_SAS para realizar la 8 versión del #DragonJARCON 2021 que se muestra en https://t.co/gZAVUQ7XTL, visitalos en https://t.co/pxbPpKg3TR.
Importante entender que no existen las plataformas "seguras". Cuando un actor de amenazas pone en la mira a un objetivo, siempre buscará la manera de comprometerlo sin importar el Sistema Operativo que utilice 👇🏻 https://t.co/gZIxnGxcem
@AeroCivilCol como siempre @Avianca con sus retrazos sin justificación y de mal en peor. Que pésimo servicio y no se tiene entidad que escuche a los pasajeros o ayude a resolver estos problemas.
¡Eres el afortunado ganador de un #sorteo en el que no has participado! ¿Suerte? Desde @osiseguridad analizamos con detenimiento cómo funciona este tipo de #fraude tan común en #RedesSociales.
https://t.co/qhCpUT0Qw0