@stonybrooku researchers uncovered a new #Blockchain vulnerability, showing how cybercriminals exploit human error in naming systems. Led by Prof. Nick Nikiforakis, they won bronze at eCrime 2024 in Boston! #CyberSecurity
Now that I was able to get my hands on a picture, I am happy to announce that @_Uticensis won second place in the "social impact" category of the 2024 NYU @CSAW_NYUTandon competition, out of 194 submissions!
In 2017, with @EnricoMariconti @gianluca_string @jerryola and other collaborators, we studied the problem of changing profile names on Twitter and how any links from the general web to Twitter/X become "dangling" allowing attackers to claim old profile names and the corresponding incoming links. Apparently this exact vector was used 7 years later, as part of crypto social-engineering scam which ended up with the victim losing $245K of funds. Paper: https://t.co/wI4xLNiWpS
⏰ The submission deadline for ISC 2024 is June 6, AoE. Only a week left to get your submissions in! More info at the conference website: https://t.co/RfsPPX7uYB
And the #secweb best paper award goes to "Manufactured Narratives: On the Potential of Manipulating Social Media to Politicize World Events" by Chris Tsoukaladelis (@_Uticensis) and Nick Nikiforakis (@nicknikiforakis) from @stonybrooku !
Congrats to the authors! 🎉
CC @jpolakis
Thanks for your inspiring keynote today @briankon116. We are still celebrating your National Security Agency award with @NickNikiforakis and Johnny So.
"Uninvited Guests" Wins National Security Agency Award
Link: https://t.co/fWQ3HrHpMS
@CEASSBU@AI_SBU@stonybrooku
How do bots attack websites? How can a web browser trust an organization’s public key cryptographic credential? NSA awarded the authors of a paper who dove into these questions and came up with some intriguing answers. Learn more: https://t.co/PHadfRszb6
Happy to announce that @briankon116 and Johnny So's 2022 USENIX Security paper on Certificate Transparency bots was selected as the winner of the 11th NSA Annual Best Scientific Cybersecurity paper competition!
Looking forward to giving this talk next week! I will be presenting our work on crypto scams from NDSS 2023, as well as our upcoming work on how attackers target crypto users on video platforms (NDSS 2024).
Next to all the cryptocurrency-specific topics, we will also cover DNS security, Certificate Transparency, and how scammers split their attacks across platforms (social media -> instant messaging -> crypto) in a way that makes it difficult to piece together the whole story.
The talk will be streamed online. I hope many of you can make it!
Today at Usenix Security 2023 #usesec23 Track 1 (10:45AM), I will present our work on attack surface reduction for web applications aka debloating. In the first paper titled Minimalist, @0xRasoul and I build a static analysis tool to generate the call graphs of PHP applications.
Following up my first talk at Usenix Security 2023 #usesec23 Track 1 (10:45AM), I present AnimateDead🪦, which is a distributed concolic execution engine for PHP applications. AnimateDead leverages a PHP emulator to execute applications in a symbolic environment.
2 papers from PragSec are in the running for the SpringerOpen 2023 Cybersecurity Award. First paper is on evading Android sandboxes. Second one is on building honeypots for Certificate Transparency. If you liked the papers, we would appreciate your vote! https://t.co/AkgDeSNKhb
Why don't robust models enjoy much adoption in the real world?
In my student's (@PratikV79260717) first @USENIXSecurity paper, we argue that reduction in natural accuracy and the increased training cost are the two culprits and tackle the second challenge head-on. (1/3)
In one week, @briankon116 will present our paper with Johnny So titled “Uninvited Guests: Analyzing the Identity and Behavior of Certificate Transparency Bots” at @USENIXSecurity . Let me tell you a bit about this work 🧵 https://t.co/A0oQVI8xYj
Tomorrow (May 25), Johnny will be presenting our work titled "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust" at @IEEESP 2022 #SP22 https://t.co/kQigFBbzCB
Later, on June 10, @briankon116 and I will present our recent "Catching Transparent Phish" work on identifying new generations of MITM phishing kits in the wild. https://t.co/U2LkyZQT6n
Ever realized that online articles can change *after* you read them? Together with @Jacky_Xingzhi, @briankon116, and @StevenSkiena, we explore this phenomenon in our WWW '22 paper "Verba Volant, Scripta Volant: Understanding Post-publication Title Changes in News Outlets"