One week after launch and we've clocked 1,681 clones/downloads from the #golang community. Busy on enhancements, thanks for all the feedback, support, and getting the word out! #praetorianlabs
https://t.co/ZV1beBF849
Over 700 Ruby Gems contain BTC stealing malware! Discovery & analysis by @ap0x of @ReversingLabs https://t.co/D7MizYjUx2
+1 Self-extracting executables crafted w/ https://t.co/lFCtsgbJXl are disguised as aaa.png extension file and triggered by use extconfig.rb
-1 target logic
Over 700 Ruby Gems contain BTC stealing malware! Discovery & analysis by @ap0x of @ReversingLabs https://t.co/D7MizYjUx2
+1 Self-extracting executables crafted w/ https://t.co/lFCtsgbJXl are disguised as aaa.png extension file and triggered by use extconfig.rb
-1 target logic
Outstanding research & excellent writeup (explanation, technical details, POCs)!
Last mitigation strategy's Irony is strong as post is about abuse of HP Support Assistant to exploit Windows.
"Another method of updating is to install the latest Assistant from HP’s website" LOL
My report for the bug is now public: https://t.co/3C2KZYIoYT. This PoC directly turns the bug into type confusions, the exploit technique is then basically https://t.co/OtFVFMv0f2