hex nomad retweeted
Introduction to Windows Cryptographic Services RCE CVE-2024-29050 v-v.space/2024/08/23/CVE-202…
6
13
3,677
hex nomad retweeted
Micropatches were released for Windows Cryptographic Services Remote Code Execution Vulnerability (CVE-2024-29050)
1
4
6
1,041
hex nomad retweeted
I’m thrilled to share my latest blog post! This one focuses on the bug hunting process: inspiration, approach, and execution. I also provide a retrospective on how the bug was introduced and analyze the insufficient “patch”. Check it out: securityintelligence.com/x-f…
32
254
850
170,823
hex nomad retweeted
In the wake of the CrowdStrike crash event, some interesting articles have been published that explore some perspectives of security vendors in the Windows kernel. I penned a blog for another perspective. @Sean_Endicott_ @happygeek @AndrewWrites fieldeffect.com/blog/the-bra…
3
14
31
2,915
My take on this: “… appears to be starting a conversation about…” is corporate speak for “there’s nothing we can do about this and we’re waiting this out”. There’s currently no alternative to running Windows EDRs in kernel mode and there’s not going to be one any time soon.
via @verge – due to the recent CrowdStrike incident Microsoft is discussing migrating security products away from the Windows kernel and into other spaces such as VBS Enclaves or Microsoft Azure Attestation CrowdStrike accidentally leveled the playing field for Threat Actors
7
7
83
14,599
After over a decade in cybersecurity I sometimes forget that a lot of tech probably has never heard of Crowdstrike (as is now apparent by all the posts) You’ve probably also not heard of @fieldeffectsoft so here is your chance (no I don’t work for them) fieldeffect.com/blog/recover…
2
4
532
Maybe companies shouldn’t have gotten rid of QA teams because “devs can write unit tests and that’s basically the same thing”?
6
15
117
8,887
hex nomad retweeted
kernel driver dev is hard!! this is why the osr guys are so mean
11
30
355
32,456
RT @_snagg: RCE in SSH, this is a thing of beauty qualys.com/2024/07/01/cve-20…
12
Thanks to everyone who attended my @reconmtl and @BlueHatIL talks! The exploit and slides are here: github.com/gabriellandau/Its… If you took any photos during either of the talks, please share them here. Also, please don't hesitate to stop me to say hi!
10
59
178
30,471
When embarking on a new vulnerability research project it is important to perform extensive background research into the area to gather as much info as possible to supplement and guide @j00ru describes these learning resources for the Windows Registry: googleprojectzero.blogspot.c…
10
55
5,071
Sassy, tongue-in-cheek, but honest recounting of the recent Mitre MDR evaluations:
Very happy to share some thoughts and an inside look at the Field Effect experience of our first participation in a MITRE Engenuity ATT&CK Managed Services Evaluation. So proud of the team, details here: fieldeffect.com/blog/recover…
3
354
hex nomad retweeted
The cynic in me is saying that if you are a secret agent on a counterterrorism mission, it's kinda your job not to have your secret equipment confiscated by the mall cop on the segway, so I think the lady doth protest too much. (Random subtweet)
3
8
66
11,853
hex nomad retweeted
New blog post "Google: Stop Burning Counterterrorism Operations" My reflection on an incident where Project Zero and TAG knowingly shut down an active Western counterterrorism cyber operation, and the real-world harm that could have resulted from it. poppopret.org/2024/06/24/goo…
63
128
537
481,564
Great bug, great talk! I’m sure I’m not the only one who looked at the binder code and missed this :)
Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938 An article by @abc_sup, Gulshan Singh, and @vxradius about exploiting a vulnerability in the Android Binder device driver that leads to a slab use-after-free. androidoffsec.withgoogle.com…
5
810
Replying to @guhe120
This happened. It turns out maintaining consistency at 4x-6x the previous volume is a really hard problem. Honestly, a misc CVE field is the least of my worries- inconsistencies in what's considered an "Important" vulnerability is what keeps me up at night 🥲
1
1
5
2,922
hex nomad retweeted
microsoft: Exploit Code Unporoven me: i literally gave you a compiled PoC and also exploit code m$: No exploit code is available, or an exploit is theoretical. me:
90
343
2,566
413,321
hex nomad retweeted
Hey, for anyone who wanted to see this slide deck, it was a keynote about the 0day market, but it commented on public research vs saleable products. I have put it here: github.com/mdowd79/presentat… // cc @chompie1337 @bsdaemon
Replying to @chompie1337
Yeah. I touched on this in a talk I gave at blue hat last year. It isn't publicly available though
10
128
400
102,172