06/14

Project Zero: Driving forward in Android drivers

https://googleprojectzero.blogspot.com/2024/06/driving-forward-in-android-drivers.html
Project Zero: Driving forward in Android drivers

Pentagon ran secret anti-vax campaign to incite fear of China vaccines

https://www.reuters.com/investigates/special-report/usa-covid-propaganda/
Pentagon ran secret anti-vax campaign to incite fear of China vaccines

Microsoft delays Windows Recall amid privacy and security concerns

https://www.bleepingcomputer.com/news/microsoft/microsoft-delays-windows-recall-amid-privacy-and-security-concerns/
Microsoft delays Windows Recall amid privacy and security concerns

justCTF 2024 [teaser]

http://2024.justctf.team
justCTF 2024 [teaser]

OffensiveCon24- Charles Fol- Iconv, Set the Charset to RCE - YouTube

https://youtu.be/dqKFHjcK9hM?si=rzsdc2qHamPzREiP
OffensiveCon24- Charles Fol- Iconv, Set the Charset to RCE - YouTube

Arid Viper poisons Android apps with AridSpy

https://www.welivesecurity.com/en/eset-research/arid-viper-poisons-android-apps-with-aridspy/
Arid Viper poisons Android apps with AridSpy

CISA warns of Windows bug exploited in ransomware attacks

https://www.bleepingcomputer.com/news/security/cisa-warns-of-windows-bug-exploited-in-ransomware-attacks/
CISA warns of Windows bug exploited in ransomware attacks

Ascension hacked after employee downloaded malicious file

https://www.bleepingcomputer.com/news/security/ascension-hacked-after-employee-downloaded-malicious-file/
Ascension hacked after employee downloaded malicious file

UnpacMe PIVOT!

https://blog.unpac.me/2024/06/13/introducing-unpacme-pivot/
UnpacMe PIVOT!

Binary type inference in Ghidra | Trail of Bits Blog

https://blog.trailofbits.com/2024/02/07/binary-type-inference-in-ghidra
Binary type inference in Ghidra | Trail of Bits Blog

Truist bank confirms data breach | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/06/truist-bank-confirms-data-breach
Truist bank confirms data breach | Malwarebytes

The Stanford Internet Observatory is being dismantled

https://www.platformer.news/stanford-internet-observatory-shutdown-stamos-diresta-sio/
The Stanford Internet Observatory is being dismantled

Insurance giant Globe Life investigating web portal breach

https://www.bleepingcomputer.com/news/security/insurance-giant-globe-life-investigating-web-portal-breach/
Insurance giant Globe Life investigating web portal breach

Truist Bank confirms breach after stolen data shows up on hacking forum

https://www.bleepingcomputer.com/news/security/truist-bank-confirms-data-breach-after-stolen-data-shows-up-on-hacking-forum/
Truist Bank confirms breach after stolen data shows up on hacking forum

London hospitals cancel over 800 operations after ransomware attack

https://www.bleepingcomputer.com/news/security/london-hospitals-cancel-over-800-operations-after-ransomware-attack/
London hospitals cancel over 800 operations after ransomware attack

Q&A with Valentina Palmiotti, aka Chompie

https://securityintelligence.com/x-force/question-answer-valentina-palmiotti-chompie/
Q&A with Valentina Palmiotti, aka Chompie

Google's Privacy Sandbox Accused of User Tracking by Austrian Non-Profit

https://thehackernews.com/2024/06/googles-privacy-sandbox-accused-of-user.html
Google's Privacy Sandbox Accused of User Tracking by Austrian Non-Profit

Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces – Horizon3.ai

https://www.horizon3.ai/attack-research/disclosures/exploiting-file-read-vulnerabilities-in-gradio-to-steal-secrets-from-hugging-face-spaces/
Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces – Horizon3.ai

North Korean Hackers Target Brazilian Fintech with Sophisticated Phishing Tactics

https://thehackernews.com/2024/06/north-korean-hackers-target-brazilian.html
North Korean Hackers Target Brazilian Fintech with Sophisticated Phishing Tactics

Microsoft Delaying Recall Feature to Improve Security - SecurityWeek

https://www.securityweek.com/microsoft-delaying-recall-feature-to-improve-security/
Microsoft Delaying Recall Feature to Improve Security - SecurityWeek

talk-slides/so_you_wanna_find_bugs_in_the_linux_kernel.pdf at main · sam4k/talk-slides · GitHub

https://github.com/sam4k/talk-slides/blob/main/so_you_wanna_find_bugs_in_the_linux_kernel.pdf
talk-slides/so_you_wanna_find_bugs_in_the_linux_kernel.pdf at main · sam4k/talk-slides · GitHub

Edge Devices: The New Frontier for Mass Exploitation Attacks - SecurityWeek

https://www.securityweek.com/edge-devices-the-new-frontier-for-mass-exploitation-attacks/
Edge Devices: The New Frontier for Mass Exploitation Attacks - SecurityWeek

Former head of NSA joins OpenAI board - The Verge

https://www.theverge.com/2024/6/13/24178079/openai-board-paul-nakasone-nsa-safety
Former head of NSA joins OpenAI board - The Verge

Life360 Says Personal Information Stolen From Tile Customer Support Platform - SecurityWeek

https://www.securityweek.com/life360-says-personal-information-stolen-from-tile-customer-support-platform/
Life360 Says Personal Information Stolen From Tile Customer Support Platform - SecurityWeek

ZKTeco Biometric System Found Vulnerable to 24 Critical Security Flaws

https://thehackernews.com/2024/06/zkteco-biometric-system-found.html
ZKTeco Biometric System Found Vulnerable to 24 Critical Security Flaws

City of Cleveland still working to fully restore systems impacted by a cyber attack

https://securityaffairs.com/164506/hacking/city-of-cleveland-cyberattack.html
City of Cleveland still working to fully restore systems impacted by a cyber attack

Former IT employee gets 2.5 years for wiping 180 virtual servers

https://www.bleepingcomputer.com/news/security/former-it-staff-gets-25-years-for-wiping-180-virtual-servers/
Former IT employee gets 2.5 years for wiping 180 virtual servers

Former IT employee gets 2.5 years for wiping 180 virtual servers

https://www.bleepingcomputer.com/news/security/former-it-employee-gets-25-years-for-wiping-180-virtual-servers/
Former IT employee gets 2.5 years for wiping 180 virtual servers

PWA Phishing Demo

https://pwa-phishing-demo.com/
PWA Phishing Demo

AWS Announces Authentication and Malware Protection Enhancements - SecurityWeek

https://www.securityweek.com/aws-announces-authentication-and-malware-protection-enhancements/
AWS Announces Authentication and Malware Protection Enhancements - SecurityWeek

Two Ukrainians accused of spreading Russian propaganda and hack soldiers' phones

https://securityaffairs.com/164516/cyber-warfare-2/ukrainians-accused-russian-propaganda.html
Two Ukrainians accused of spreading Russian propaganda and hack soldiers' phones

Payoff from AI projects is 'dismal', biz leaders complain • The Register

https://www.theregister.com/AMP/2024/06/12/survey_ai_projects/
Payoff from AI projects is 'dismal', biz leaders complain • The Register

Microsoft removes Copilot app ‘incorrectly’ added on Windows PCs

https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-copilot-app-incorrectly-added-on-windows-pcs/
Microsoft removes Copilot app ‘incorrectly’ added on Windows PCs

Toronto District School Board hit by a ransomware attack

https://www.bleepingcomputer.com/news/security/toronto-district-school-board-hit-by-a-ransomware-attack/
Toronto District School Board hit by a ransomware attack

DISGOMOJI Malware Used to Target Indian Government | Volexity

https://www.volexity.com/blog/2024/06/13/disgomoji-malware-used-to-target-indian-government/
DISGOMOJI Malware Used to Target Indian Government | Volexity

City of Cleveland Scrambling to Restore Systems Following Cyberattack - SecurityWeek

https://www.securityweek.com/city-of-cleveland-scrambling-to-restore-systems-following-cyberattack/
City of Cleveland Scrambling to Restore Systems Following Cyberattack - SecurityWeek

Microsoft Delays AI-Powered Recall Feature for Copilot+ PCs Amid Security Concerns

https://thehackernews.com/2024/06/microsoft-delays-ai-powered-recall.html
Microsoft Delays AI-Powered Recall Feature for Copilot+ PCs Amid Security Concerns