Finally, it is published 😁 Making Vulnerable Drivers Exploitable Without Hardware - my latest research on driver vulnerability hardware-gating, explaining the concept of hardware-dependent code and diving deep into creative deployment techniques - software-emulated phantom devices, driver restacking, and forced driver replacement — all explored through the lens of Bring Your Own Vulnerable Driver (BYOVD) attacks:
atos.net/wp-content/upl…
My new article is out - Anatomy of Access: Windows Device Objects from a Security Perspective
atos.net/en/lp/cybershi…
I wish I had this resource 5 months ago 😉
I find it frustrating that none of these "guardians" of Linux and open source have reacted to the OS-level age verification law:
- Linux Foundation
- Open Source Initiative
- Free Software Foundation
- Software Freedom Conservancy
We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security and freedom on mobile to avoid it. Companies selling phones should not be deciding which operating systems people are allowed to use for apps.
uattest.net
Important: We have revised our license to include additional jurisdictions implementing the age verification laws. Residents of Brazil are no longer authorized to use MidnightBSD.
We will not implement ID checks as Brazil requires. (not just attesting age)
My second public acknowledgement for a kernel-mode vulnerability:
nvidia.com/en-us/security…
😉
This one is for a pool overflow in NVIDIA Install Helper Service (NVI2SystemService64.sys). Because at the time I had discovered and reported the issue the product had already reached EOL, the vendor will not assign a CVE number to it. In other words, this vulnerability did not make it to CVE because it stayed unreported for too long. This policy approach to EOL products is quite common among vendors and exemplifies one of numerous scenarios for which CVE as a tool for vulnerability and risk management is not sufficient. For anyone interested in such scenarios, I recommend reading my article dedicated to this subject:
hackingiscool.pl/slipping-throu….
The entire world is moving to criminalize privacy.
We can't let them do that.
Privacy is the foundation of a free society.
Privacy is protection against powerful people.
Privacy is normal.
We were contacted by a journalist at Le Parisien newspaper with this prompt:
> I am preparing an article on the use of your secure personal data phone solution by drug traffickers and other criminals. Have you ever been contacted by the police? Are you aware that some of your
Do you want to be de-banked over digital ID rules?
Vietnam is terminating bank accounts without a linked digital ID.
We are not exaggerating when we say this is what could happen in the UK. It is already happening elsewhere.
The people must remain in control, we must reject Digital ID.
OSCP is no job experience, it does not even teach actual pentesting and its passing criteria are based on collecting the flags, not on "how pretty the report is". Also, the part about no sleep and no food is BS. Seeing a trend of non-technical juniors without actual passion for infosec believing that OSCP makes one a "senior".
The UK is rolling out a national digital ID, the “Brit Card," despite 2.7M+ signatures against it. Tied to borders, benefits, and public services, it’s the spine of a new surveillance state.
Combined with the Online Safety Act, identity verification is becoming mandatory to live, work, and speak.
Isn’t she the person who proposed chat control?
Seems like a weird behavior for someone who proposed the regulation.
It’s not so fun when you are the one getting your messages analyzed is it now?
Hypocrite.
🚨 Denmark keeps pushing for Chat Control - but we keep pushing back!
Join us in our fight for #privacy ✊
Check why #Germany is the deciding factor 🇩🇪 and learn how to stop #Chatcontrol (including email addresses of German politicians): 👉 tuta.com/blog/chat-cont…
Americans have absolutely no idea how bad things are in Europe
They are going into a totalitarian dictatorship the likes of which Orwell thought were too insane to come up with
ChatControl will allow the EU to use keyword filters to probe into what every private citizen says to friends and family about private topics, using AI and machine learning models to create heatmaps of dissidents. Combined with hate speech laws, it’s a recipe for utter disaster.
As long as vendors can hide vulnerabilities by bullying researchers and their own clients with NDAs and SLAPP, it doesn't really matter what system we use to exchange information about issues. Also, there's many other scenarios in which this just doesn't work as it should:
hackingiscool.pl/slipping-throu…
4K Followers 3K FollowingInfosec writer| Musician| Poet| Personal Tweets| @bugcrowd ambassador | Ran Nepsec Sydney | Ex One of the Top Mozilla Nepal Localiser | @PvJRedCell Staff!
4K Followers 4K FollowingSecurity Researcher @Infoblox // former @UNODC Official // Interests in all things #DNS #threatintel, #privacytech & the @Arsenal 🏆 // @UCDCCI
387K Followers 1K FollowingIQ 150+ polymath. Founder of all Brighteon platforms, mass spec food lab director, #1 bestselling author of "Food Forensics," AI developer
2K Followers 1 FollowingTrain on raw telemetry from actual breaches. Investigate malware and reconstruct the kill chain from process creation to exfiltration and beyond.
91K Followers 713 FollowingClimate Reality
My prior account from 2011 to 2020 was @Tony__Heller
My beautiful wife @kiryenet was born in Japan and loves Wyoming!
https://t.co/ghALjWY3qy
130K Followers 178 FollowingProfessor of computer science at UW and author of '2040' and 'The Master Algorithm'. Into machine learning, AI, and anything that makes me curious.
68K Followers 18 FollowingExploring what AI actually is. Building @shapeworkspace, prev @standardnotes. Talking at https://t.co/814DpgwSzr and https://t.co/vlHyF3gEjn.
10K Followers 2K FollowingThreat Researcher | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer | I'm Everywhere and Nowhere - BSG.
38K Followers 260 FollowingWe help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
12K Followers 1 FollowingWe strive to reimagine vulnerability research, program analysis, and security education as it exists today. An @RPISEC corporation.
10K Followers 17 Following501(c)3 Nonprofit providing Open Source and Open Access computer security training material. #OST2 re-launched July 2021! [email protected]
183K Followers 581 FollowingTeach the children quietly
For someday sons and daughters
Will rise up and fight
Where we stood still
╔╗╔╦══╗
║║║║══║
║╚╝║╔╗║BOSS
╚══╩╝╚╝