The slides and the code for my @reconmtl talk “Seeing Through Themida’s Code Mutation” are available:
- Slides: https://t.co/xkUKQCQX8L
- Deobfuscator Code: https://t.co/3S8Y8zxTSm
Took some time to improve a few things on WinDiff (added permalinks, filtered out empty results) and added a Claude skill to use WinDiff to produce quick security-oriented diff analyses between binary/OS versions. Feel free to try!
https://t.co/PGZn1TcN1I
🚨 NEW 🚨 In late October, Kamala Harris' security team had evidence of spyware on at least two staff iPhones.
They asked Apple for help getting deeper access to the iPhones.
Apple declined.
Harris and her team still have no idea if they were hacked.
https://t.co/inT60xWIo0
My blog post is now live alongside @amnesty 's joint release, providing remarkable insight into an ITW exploitation campaign!
https://t.co/O3niXxtT6O
Turns out that you can find out quite a bit with just some kernel stacktraces ;)
From Amnesty:
https://t.co/4CeJynhwZ6
New: Cellebrite is being used as doorway to install malware. Amnesty finds multiple cases where police used Cellebrite to unlock phone; cops then used that access to infect with spyware which takes screenshots, turns on mic, etc, give phone back to target https://t.co/0TraqagAX5
What happens when Random() isn’t random?
Here’s how popular projects, including Proton Wallet and the Dart SDK were all affected by the same underlying weakness we uncovered in the Dart/Flutter ecosystem.
All issues found were responsibly disclosed with the vendors.
Let’s go 🧵👇
There are some new MBA obfuscation papers:
Poster: E-Graphs and Equality Saturation for Term-Rewriting in MBA Deobfuscation: An Empirical Study (https://t.co/HrKByjptAV)
X-MBA: Towards Heterogeneous Mixed Boolean-Arithmetic Deobfuscation (https://t.co/dS8zUJSxUD)
🔬NEW: efiXplorer v6.1 [#BHEU Edition]
- [plugin] annotations/quality of pseudocode
- [plugin] detection of variables based on Hex-Rays
- [loader] UEFI firmware unpacking
- [loader] updated deps.json and images.json formats
- support for IDA SDK v9.0
https://t.co/o1cLkMNslH
#ESETResearch is hiring a senior malware researcher for our 🇨🇦office. If you’d like to track some of the most impactful APTs/cybercrime campaigns, don’t wait and apply here 👇
https://t.co/YDZQeUH0nn 1/3
HyperDbg v0.11 is released! ✨
This version comes with bug fixes, improvements, and two new commands for viewing Local APIC (XAPIC/X2APIC) and IO APIC.
Big shoutout to @0Xiphorus for joining the team for bringing PCIe support to HyperDbg!
https://t.co/lyMhKiq4g8
Special thanks to @_nnaci who last Friday gave a presentation at the https://t.co/BpzWlLVmIo hour (our weekly technical meeting) about Mergen, its LLVM-based deobfuscation project.
Interesting stuff, check it out!
https://t.co/5lI5CoUmOI
We're deep diving on vulnerabilities in ClipSp, the driver at the core of Windows' Client License Platform. Read the latest research here: https://t.co/QdDwspYCHI