Extracting Embedded MultiMediaCard (eMMC) contents in-system. ZDI researcher Dmitry Janushkevich details how to interact with an eMMC chip and notes some pitfalls you may encounter on the way. https://t.co/S4vupgDL5V
Understand ARM64 reversing and exploitation with a breakdown of the ARM instruction set, registers, and a step-by-step simple heap overflow exploit. Read more: https://t.co/aO3uSe4QqN
Learn all about ARM assemble and exploitation from our course at https://t.co/BGduUr6sIY
#ARM64 #CyberSecurity #MobileSecurity #ReverseEngineering
🔬 Read #Team82's analysis of a new cyberweapon called #IOCONTROL that's been uncovered and used in attacks against the U.S. and Israel. The weapon is custom-built and its modular configuration allows it to be used against #IoT, #OT, and #SCADA systems. https://t.co/ddA5ssNpnD
Yesterday @DragosInc unveiled 'FrostyGoop' an ICS (Industrial Control System) malware suspected to be developed by Russia's infamous sandworm team.
FrostyGoop successfully shut off the electricity of 600 apartment buildings in the midst of sub-zero temperatures (sub -17C temperatures) in January, 2024. It took Ukrainian officials almost 2 days to restore electricity of individuals impacted by FrostyGoop.
Dragos successfully identified the payload April, 2024.
This is the 9th ICS specific malware in history. This sort of malware is exceptionally rare, exceptionally difficult to develop, exceptionally difficult to test, and exceptionally difficult to deploy.
We do not have any malware samples for this payload. If one of you have this malware sample and would be willing to donate it to us, please do.
Check out the intelligence brief here:
https://t.co/kFMJf2RVar
We’re sharing our discovery and analysis of multiple high-severity vulnerabilities in the CODESYS V3 SDK that could put OT infrastructure at risk of attacks like RCE and DoS. Learn how we reported and worked with CODESYS to address the vulnerabilities: https://t.co/oUcCs321EV
Microsoft cyberphysical systems researchers continue to develop and add more tools to the open-source Microsoft ICS forensics framework we released last year for analyzing industrial programmable logic controller (PLC) metadata and project files: https://t.co/drERXG1jRv
Tenable was one of a handful of experts pre-notified by Rockwell Automation, in collaboration with the U.S. government, to provide awareness on these new #operationaltechnology vulnerabilities. (CVE-2023-3595) and (CVE-2023-3596) https://t.co/hRXcUBhh0H
👉The ransomware attack on Colonial Pipeline—2 years ago today—was a watershed moment in cybersecurity. Since then, we’ve learned a lot & made great strides w/our partners, but lots more to do to strengthen our collective cyber defense. A brief reflection: https://t.co/ajp0NunrI9
🔥New Challenge Released -> BlackEnergy🔥
Your enterprise was hit by a cyber attack using a variant of the #BlackEnergy#malware you have never seen before. Analyze the memory dump using #Volatility & investigate the intrusion.
https://t.co/sslZRNPEiN
#DFIR#BlueTeam#InfoSec
Disclosing our latest research findings of critical architectural vulnerabilities in the Siemens SIMATIC and SIPLUS S7-1500 series that allow for bypass of all protected boot features. (CVE-2022-38773)
Read more on our blog post: https://t.co/AHnN91ClQl