What’s new in Android Privacy https://android-developers.googleblog.com/2021/05/android-security-and-privacy-recap.html
Android Developers Blog
What’s new in Android Privacy
Posted by Sara N-Marandi, Product Manager, Android Platform Product People want an OS and apps that they can trust with the...
Vulnerability Spotlight: Heap-based buffer overflow in Google Chrome could lead to code execution https://blog.talosintelligence.com/2021/05/vuln-spotlight-google-chrome-heap.html
Cisco Talos Blog
Vulnerability Spotlight: Heap-based buffer overflow in Google Chrome could lead to code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Google Chrome.
Google Chrome is a cross-platform web browser — and Chromium…
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Google Chrome.
Google Chrome is a cross-platform web browser — and Chromium…
Great tips » Guy's 30 Reverse Engineering Tips & Tricks https://blog.whtaguy.com/2020/04/guys-30-reverse-engineering-tips-tricks.html
Mav Levin Security Research
Mav's 30 Reverse Engineering Tips & Tricks
During April I challenged myself to tweet 1 reverse engineering tip every day. For your viewing pleasure, here I aggregated all 30 tips.Be sure to follow me ...
Students detect security breaches in popular apps https://cs.au.dk/news-events/pages/2021/students-detect-security-breaches-in-popular-apps/
cs.au.dk
Students detect security breaches in popular apps
How Flubot targets Android phone users and their money https://www.nortonlifelock.com/blogs/norton-labs/flubot-targets-android-phone-users
Nortonlifelock
How Flubot targets Android phone users and their money
Malware steals login credentials for banking and cryptocurrency apps — and it could spread around the world
What is Rootkit? https://computer0virusology.bloggi.co/rootkit-anatomy-1
Computer0Virusology
What is Rootkit ?
In our definition of "Rootkit" the key word is "undetectable"
The term rootkit has been around for more than 10 years. A rootkit is a "kit" consisting of small and useful programs that allow an attacker to maintain access to "root," the most powerful user…
The term rootkit has been around for more than 10 years. A rootkit is a "kit" consisting of small and useful programs that allow an attacker to maintain access to "root," the most powerful user…
A Practical Approach to Attacking IoT Embedded Designs (II) https://labs.ioactive.com/2021/02/a-practical-approach-to-attacking-iot_23.html
Ioactive
A Practical Approach to Attacking IoT Embedded Designs (II)
by Ruben Santamarta In this second and final blog post on this topic, we cover some OTA vulnerabilities we identified in wireless commun...
How to Kerberos? its components and function https://sheerazali.com/how-to-kerberos-its-components-and-function/
Sheeraz ali
How to Kerberos? its components and function - Sheeraz ali
Kerberos is used in windows authentication and the active directory. It is an authentication protocol that is if implemented is more secure ..
Vulnerability Spotlight: Information disclosure vulnerability in macOS SMB server https://blog.talosintelligence.com/2021/05/vuln-spotlight-smb-information-disclosure.html
Cisco Talos Blog
Vulnerability Spotlight: Information disclosure vulnerability in macOS SMB server
Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an exploitable integer overflow vulnerability in Apple macOS’ SMB server that could lead to information disclosure.
Server Message Block…
Cisco Talos recently discovered an exploitable integer overflow vulnerability in Apple macOS’ SMB server that could lead to information disclosure.
Server Message Block…
Exploit Development: CVE-2021-21551 - Dell ‘dbutil_2_3.sys’ Kernel Exploit Writeup https://connormcgarr.github.io/cve-2020-21551-sploit/
Connor McGarr’s Blog
Exploit Development: CVE-2021-21551 - Dell ‘dbutil_2_3.sys’ Kernel Exploit Writeup
Analysis and writeup on weaponizing CVE-2021-21551 without a data-only attack and the importance of Virtualization-Based Security, Hypervisor-Protected Code Integrity, Kernel Control-Flow Guard, and other modern mitigations.
Hacking a Roku TV to Control Lights https://blog.ammaraskar.com/roku-tv-philips-hues/
Ammar's Blog
Hacking a Roku TV to Control Lights
My blog, mostly about programming
CVE-2021-31166: A Wormable Code Execution Bug in HTTP.sys https://www.zerodayinitiative.com/blog/2021/5/17/cve-2021-31166-a-wormable-code-execution-bug-in-httpsys
Zero Day Initiative
Zero Day Initiative — CVE-2021-31166: A Wormable Code Execution Bug in HTTP.sys
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Kc Udonsi and Yazhi Wang of the Trend Micro Research Team detail a recent code execution vulnerability in the Microsoft Internet Information Services (IIS) for Windows.…
CERT Kaiju: binary analysis framework extension for the Ghidra software reverse engineering suite https://securityonline.info/kaiju-binary-analysis-framework/
Daily CyberSecurity
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
LNew sophisticated email-based attack from NOBELIUM https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/
Microsoft News
New sophisticated email-based attack from NOBELIUM
Microsoft Threat Intelligence Center (MSTIC) has uncovered a wide-scale malicious email campaign operated by NOBELIUM, the threat actor behind the attacks against SolarWinds, the SUNBURST backdoor, TEARDROP malware, GoldMax malware, and other related components.…
API Management and DevOps: Integrate a flawless API DevOps lifecycle with these tips https://medium.com/devops-dudes/api-management-and-devops-1ffd1b5b88ae
Medium
API Management and DevOps
Integrate a flawless API DevOps lifecycle with these tips
Decompiling Node.js in Ghidra https://swarm.ptsecurity.com/decompiling-node-js-in-ghidra/
Nice tips » Common Security Issues in Financially-Oriented Web Applications: A guideline for penetration testers https://www.nccgroup.com/globalassets/our-research/uk/images/common_security_issues_in_financially-orientated_web.pdf.pdf
Highly recommended! » FAQ: Difference between vulnerability, exploit and CVE https://gynvael.coldwind.pl/?lang=en&id=734
gynvael.coldwind.pl
FAQ: Difference between vulnerability, exploit and CVE
Hacker's guide to deep-learning side-channel attacks: the theory https://elie.net/blog/security/hacker-guide-to-deep-learning-side-channel-attacks-the-theory
elie.net
Hacker's guide to deep-learning side-channel attacks: the theory | blog post
Learn the concepts behind deep-learning side-channels attack, a powerful cryptanalysis technique, by using it to recover AES cryptographic keys from a hardware device.