January 26, 2024
January 26, 2024
https://www.reuters.com/business/aerospace-defense/aviation-sector-seeks-urgent-solutions-gps-interference-2024-01-24/https://www.theregister.com/2024/01/24/microsoft_latest_breach_cozy_bear/?td=rt-3a
https://www.usenix.org/conference/usenixsecurity23/presentation/schepers
Lmfao imagine being an Imperial Japanese conscript ordered to forage because the Americans keep sinking all the supply ships while US sailors are getting two cans of beer per day and they have barges dedicated to making ice cream https://t.co/m35RS1uzE5
β Sam (ABeardedPanda) (@ABeardedPanda) January 24, 2024
Today is Beer Can Appreciation Day! During WWII, the U.S. Navy tried to have enough beer at all installations to give each sailor two cans a day. With rapid demobilization following V-J Day, the beer supply piled up to the point that there was enough to give each sailor 92 cans a⦠pic.twitter.com/klAvqgcBoE
β U.S. Naval Institute (@NavalInstitute) January 24, 2024
I present to you, the unshootable plane. pic.twitter.com/VdXhrbVq1W
β Lachlan Phillips e/πΎ (@bitcloud) January 25, 2024
In Indonesia generative AI/deepfake tech has been used to "resurrect" a former (late) president/dictator Suharto. Elections next month. The video was posted by a politician from Suharto's party. "Suharto" called to vote on the party (he's dead since 2008) https://t.co/GwlVbHO1O7 pic.twitter.com/C02Lg7ks2B
β Lukasz Olejnik, βοΈπ₯ (@lukOlejnik) January 22, 2024
Stay humble, you are someone's weird coworker.
β Granite Man π΄σ §σ ’σ ³σ £σ ΄σ Ώ (@GraniteDhuine) January 22, 2024
for those who missed the context of this week's drama in the Russian-speaking criminal underground community pic.twitter.com/TV5frKMCWV
β π―πππππ πΎπππππππππ (@ddd1ms) January 25, 2024
This story is wild: a teenager joked in a private group chat βOn my way to blow up the plane (I'm a member of the Taliban).β Message was intercepted over airport WiFi, reported to Spanish intel which scrambled jets, heβs now on the hook for $120k pic.twitter.com/CBVqzT9hcr
β Cate Hall (@catehall) January 25, 2024
Brazilian police raid Bolsonaro allyβs home over illegal spying allegations https://t.co/MhU6qHScNu
β Dr. Dan Lomas (@Sandbagger_01) January 25, 2024
Alternatively.... I would work under the understanding that this is not going to be the last huge bug in SharePoint....so consider the idea that patched systems are also vulnerable and should not be exposed to untrusted users. https://t.co/eJrKyLTnKi
β Dave Aitel (@daveaitel) January 25, 2024
CISA recently issued a warning that threat actors are exploiting a critical Microsoft SharePoint Server vulnerability in the wild. Although the #vulnerability was patched in June, unpatched systems can still be exploited. Patch now! Read more: https://t.co/fVUPstoYrm #infosec
β Sherri Davidoff (@SherriDavidoff) January 25, 2024
ASLRnβt: How memory alignment broke library ASLR https://t.co/xSS9qWkoZw
β ringzerΓΈ.training && @ringzer0@infosec.exchange (@_ringzer0) January 25, 2024
Whatβs most pernicious about scientific fraud is that, while itβs relatively rare in absolute terms, every bad act empowers the know-nothings of the world to dismiss the work of thousands of honest scientists. pic.twitter.com/77XsIEKVPf
β Matthew Green (@matthew_d_green) January 24, 2024
As an aside, I used to work in an industry research lab. For those who think science is flawed because βacademic incentivesβ, sure maybe. But I watched dozens of brilliant researchers get laid off by industry because it had zero incentive to fund them. Go fix that.
β Matthew Green (@matthew_d_green) January 25, 2024
Thatβs a wrap for Day 2 of #Pwn2Own Automotive. Weβve already awarded over $1,000,000 in prizes this week (Β₯150 million!) Tune back in tomorrow here or at the ZDI blog for the final day of the contest! Here are the current standings leading into the final day: pic.twitter.com/BZ5jopem9X
β Zero Day Initiative (@thezdi) January 25, 2024
https://x.com/haifeili/status/1750603788849942796
Notepad.exe is working on sandboxing, this is a moment in my career.
β David Weston (DWIZZZLE) (@dwizzzleMSFT) January 25, 2024
for the past 8 months, my team at @trailofbits has been building a new, pure-Rust X.509 validator for the Python ecosystem, and we're announcing it today!
β William Woodruff (1.3.6.1.4.1.55738) (@8x5clPW2) January 25, 2024
read more here: https://t.co/z1kgxf4KJb
Leaks and Revelations: A Web of IRGC Networks and Cyber Companies https://t.co/DvsdglEvAu
β switched (@switch_d) January 25, 2024
Analysis of the execution flow of a MSF Meterpreter payload
β 0xor0ne (@0xor0ne) January 25, 2024
Great research work by @DaniLJ94
Slides: https://t.co/eemNi4h65Z#redteam #infosec pic.twitter.com/qWLsBQPS8S
Interesting article on the CSAM detection software offered by Thorn. Despite public claims to the contrary, it apparently requires sending plaintext to servers, since the use of homomorphic encryption is too expensive. https://t.co/QyfvtZjuRu pic.twitter.com/pxyiECnfrM
β Matthew Green (@matthew_d_green) January 25, 2024
Another detail: the false positive rate for CSAM images is 1 in 1000 (99.9% accuracy) which sounds good. But in practice means vast numbers of false positives, given the huge volume of images being transmitted. pic.twitter.com/dg1RZ2bceB
β Matthew Green (@matthew_d_green) January 25, 2024
inside .githttps://t.co/EgXbXrvDoD pic.twitter.com/KmoJuiOt5E
β πJulia Evansπ (@b0rk) January 24, 2024
A few days ago folks were speculating whether the SVR's email stealing intrusion at Microsoft was really as bad as MS's filing with the SEC/blog post made it sound to some of us.
β Brian in Pittsburgh (@arekfurt) January 26, 2024
It's not.
It's even worse: https://t.co/uIY6QoD9II pic.twitter.com/Is334Ayl3Y
Additional analysis from the Microsoft Threat Intelligence teams from our ongoing analysis and investigation of the Midnight Blizzard activity, includes guidance for defenders and relevant TTPs - https://t.co/YLum8MFXgP
β Matt Zorich (@reprise_99) January 26, 2024
getting gpt to draw a grandfather without a beard is, apparently, impossible pic.twitter.com/wxIZguuKTj
β rob (@rob_mcrobberson) January 24, 2024
New impact from 404 Media: YouTube deletes 1,000 videos of in which Taylor Swift, Steve Harvey, and Joe Rogan pitch Medicare scams. Comes after we reported the practice, which was operating at a massive scale. Many still remain.https://t.co/hXcI69tHdm pic.twitter.com/qPaRev3ZK6
β Joseph Cox (@josephfcox) January 25, 2024
Two new 1950s comics aimed at young women added to the collection at https://t.co/k5ppYzHTse ("Confessions of the Lovelorn #56: Communist Kisses!" and "Girls in Love #54: My Wrong Boyfriend"). pic.twitter.com/6EIUUVsKEB
β lcamtuf (@lcamtuf@infosec.exchange) (@lcamtuf) January 26, 2024
We hebben een serieus probleem https://t.co/yClhHmgwTv
β thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) January 26, 2024
A new OAuth app created by the intruder gets approved by a new user account created by the intruder and gets given rights to access all email accounts at MS by a test account.
β Brian in Pittsburgh (@arekfurt) January 26, 2024
π
My last message before my Slack was deactivated pic.twitter.com/WXc7bAYfn8
β Jorge Murillo π (@TheHornetsFury) January 25, 2024
https://www.nytimes.com/2024/01/25/us/politics/nsa-internet-privacy-warrant.html
First, I want to compliment @Microsoft for being forthright with details. Some of the problems I see in this report, I SEE EVERYWHERE due to VULNERABLE DEFAULTS.
β typedef struct _IAMERICA{ (@EricaZelic) January 26, 2024
Let's start with creating malicious OAuth applications. By default, ANY USER can create app registrations and⦠pic.twitter.com/2BIUzO8xfF
Thread by @EricaZelic on Thread Reader App β Thread Reader App
@EricaZelic: First, I want to compliment @Microsoft for being forthright with details. Some of the problems I see in this report, I SEE EVERYWHERE due to VULNERABLE DEFAULTS. Let's start with creating malicious OAut...β¦
Following a requirement to be compatible with EU Digital Markets App, users on iOS/iPad will be able to use web browsers of other vendors (only in EU). So far it was only Safari/WebKit - even if the user used a different browser, the engine was the same. https://t.co/2HHgG4VJBH pic.twitter.com/76rOU4jpjJ
β Lukasz Olejnik, βοΈπ₯ (@lukOlejnik) January 26, 2024
The security and privacy requirements are the key here. Security management (prompt vulnerability fixes). The entitlement is available only to web browsers blocking third-party cookies (etc. - this is a good decision!). So soon to all web browsers. https://t.co/ToyotXfauI pic.twitter.com/P973ql0Lh3
β Lukasz Olejnik, βοΈπ₯ (@lukOlejnik) January 26, 2024
The interesting consequence is that web browsers that won't phase out third-party cookies won't be eligible to be installed on iOS/iPhone/iPad/etc. What a coincidence, eh? Stakes just went up. https://t.co/O1U8mq6JRB
β Lukasz Olejnik, βοΈπ₯ (@lukOlejnik) January 26, 2024