After more than 6 months of hard work, we are thrilled to disclose #AhoiAttacks that break confidential computing offered by AMD SEV-SNP and Intel TDX with malicious interrupts.
https://t.co/FtDkvnk8m3
See how Google's security engineering team handles rollouts at scale, so we can safely enforce Strict CSP, Trusted Types and other security features on 100s new services yearly.
https://t.co/pMcX7UZRAg
#io_uring: runs fast, but in the wrong direction?
"io_uring vulnerabilities were used in all submissions which bypassed mitigations"
ChromeOS: disabled io_uring
Android: restricted io_uring
GKE: disabling io_uring
disabled on Google servers
io_uring LTS vulns no longer accepted
Google will phase out third-party cookies for a testing group of 1% users at the beginning of 2024. Full deprecation of third party cookies in Q4 of 2024. The entire ecosystem is shifting. https://t.co/oiZ910BjzP
You can’t make this shit up.
Sophos sales: if the ransomware’d hospital had use Sophos it wouldn’t have happened.
Hospital CIO: well we *do* use Sophos.
I think the situation at @LastPass may be worse than they are letting on.
On Sunday the 18th, four of my wallets were compromised. The losses are not significant.
Their seeds were kept, encrypted, in my lastpass vault, behind a 16 character password using all character types.
"How security professionals are being attacked: A study of malicious CVE proof of concept exploits in GitHub"
This research paper found that ~10% PoC repositories on Github were malicious 😬
https://t.co/Bl02pjFF6c
#infosec#cybersecurity#bugbounty#bugbountytips
Yanluowang ransomware group was ransomed (?). Their onion site was breached, displaying a message that says "time's up"[sic] and linking downloads of their leaked internal communications
* Image 1 is their onion site defaced
* Image 2 is all of their known public posts
It's a pleasure to announce the release of open-obfuscator: a free and open-source solution
for obfuscating Android and iOS applications (Java/Kotlin, C/C++/Objective-C)
https://t.co/nBYleNkcdA
https://t.co/epzNK1fqKW
Dans l'exercice Polaris 21, une frégate de la force Bleue à été détruite par la force Rouge suite à une volée (14) de missiles envoyée sur une position trouvée sur le compte Snapchat d'un marin de la frégate (selon @amiralVandier)
Nouvel exercice Polaris prevu en 2023 #euronaval
Today, we are publishing several practically-exploitable cryptographic vulnerabilities in the Matrix (@matrixdotorg) standard and their flagship client Element, with Daniel Jones (@djwj_), Benjamin Dowling (@dowlingbj) and Martin R. Albrecht (@martinralbrecht).
Every now and then I remember that client who got hit by Ransomware and lost multiple VMs because they had no backup.
Then realized that TAs had exfil'd the VMs. They didn't pay the ransom, waited for their data to be leaked and downloaded the VMs to restore the lost data.
I've ported the OpenBSD pledge() system call to Linux. I think it's the fastest, simplest, most lightweight way to sandbox programs to date. https://t.co/AW7YbkuXf0
We're seeing many iOS attacks in the wild recently. 0-clicks and 1-clicks are actively circulated out there. Sophisticated payloads.
Stay alert: watch out for issues using Microphone/Camera and sudden reboots.
DMs are open.
https://t.co/m5p0vF17S2
CVE-2022-26925, the bug marked as "actively exploited" in today's Patch Tuesday is the PetitPotam vuln fixed back in Aug 2021...and seems to have been reintroduced.
Not sure yet whether to treat this as #itw0days & have some discussions I want to have first. WDYT?