July 16, 2022
Excited to announce the inaugural DHS CISA Cyber Safety Review Board’s findings on the Log4j event of 2021. There are important lessons here for the government, and the cybersecurity/software community as we come together to solve the big issues. 1/x
macOS malware often (ab)uses APIs such as NSCreateObjectFileImageFromMemory, NSLinkModule etc) to execute in-memory payloads.
Apple has recently updated dyld3 (+these APIs), such that the in-memory payload is now first/always written out to disk 💾
See: github.com/apple-oss-dist… We created guidance to clearly characterize threats and risks to custom microelectronic components used in Department of Defense systems. Read more on how to apply three levels of hardware assurance to protect applicable DoD systems. https://t.co/q7wmf8bUZG https://t.co/9BcOGjeQRI
The longer write up is here:
https://hackd.net/posts/macos-reflective-code-loading-analysis/-
This is how I have spent the last 6 months of my life. I am really excited with the results. Wine fraud is a much more pervasive problem than most people realize, and it is affects all types of wine drinkers. I'd love to hear your thoughts on the research.
-
-
-
Ukraine’s cyber agency tracks ‘significant increase’ in malware-directed attacks bit.ly/3c9CO17 #cybersecurity #infosec
-
I'm late on learning about Firebloom but it's really cool - saaramar.github.io/iBoot_firebloo… Yes, Rust and memory safe systems languages are the hotness but you can do a lot to make an existing C-based measurably safer @AmarSaar @radian
-
I wanted to read the new Council for Foreign Relations report about the fragmented Internet (cfr.org/report/confron…). For reasons that are too annoying to get into, I was using a proxy in Amsterdam. This is what got served up. A bit on the nose, eh?
-
Worth a read for the methodology and a sobering example of an AF1 threat model.
- Encrypted Comms are LoA3 (extremely grave consequences; existential risk to the USG)
- Flight Controls are LoA2 (grave consequences; redundant capabilities available for continuity of operations)😬
NSA Cyber @NSACyber
-
-
Dave Barry: Fellow Floridians, beware of toilet lizards and rising iguana aggression
https://www.miamiherald.com/living/liv-columns-blogs/dave-barry/article263508388.html-
-
OPSEC
-
This week I wrote a basic explainer on a few fundamental topics in cryptography. While this might be useful to people staring out, I think that even advanced cryptographers might also notice something very interesting with this post. Let me know if see it.
-
FLUNKING THE NEW YORK TIMES TEST: MAKING SENSE OF RUSSIAN “COVERT” ACTION
https://mwi.usma.edu/flunking-the-new-york-times-test-making-sense-of-russian-covert-action/-
-
the conclusion... 🤔 "Cybersecurity solutions have seen major progress over the years and are in great shape to face what is yet to come." trustwave.com/en-us/resource…-
Rob Joyce, director of cybersecurity at NSA, used his official account to tweet a formula joke about Ghidra. This is what community outreach looks like and it is weird.
Don't miss what's next. Subscribe to the grugq's newsletter: