SKS Keyserver Network Under Attack
Uh, the GPG aspect means a risk of supply chain attack for all linux distros using GPG armoring on their package management/deployment architectures. Which is NOT GOOD. Also, Tor Browser Developer cert is now poisoned, so the supply chain attack has started...
PGP  OpenPGP  GnuPG  GPG  keyserver  network  spam  attack  poison  certificate  poisoning  DoS  security  exploit  hacking  pentesting 
july 2019 by asteroza
rowhammer is back with a vengence...
DRAM  RAM  ECC  memory  attack  exploit  rowhammer  security  hacking  pentesting 
june 2019 by asteroza
Faxsploit – Exploiting A Fax With A Picture | Hackaday
Sure this is about an all-in-one fax/printer rigs, but don't forget a lot of companies now also use fax to email gateways as well...
fax  exploit  OOB  attack  security  hacking  pentesting 
may 2019 by asteroza
[1901.01161] Page Cache Attacks
This is kinda bad, since it leverages software caches and can be hardware agnostic, allowing write once malware that works well all over (javascript?)
shadow  page  cache  side  channel  attack  exploit  security  hacking  pentesting 
january 2019 by asteroza
ECCploit: ECC Memory Vulnerable to Rowhammer Attacks After All - VUSec
DD3, but they think the same timing sidechannel is present in DDR4...
rowhammer  attack  exploit  timing  side  channel  DDR3  ECC 
november 2018 by asteroza
test tool for arbitrary javascript payloads to test DNS rebinding attacks
DNS  rebinding  attack  javascript  payload  test  service 
june 2018 by asteroza
Blue team test framework to check their detection capabilities
attack  threat  simulation  MITRE  framework  software  python  security  hacking  pentesting  defense 
may 2018 by asteroza
ChipWhisperer® – NewAE Technology Inc.
Hardware hacking, using stuff now available on Mouser. Which means hardware attacks are now consumer grade, no nation state needed...
hacking  hardware  electronics  devices  chip  debug  reverse  engineering  security  pentesting  attack  exploit  firmware  analysis 
march 2018 by asteroza
[1712.09665] Adversarial Patch
Designing adversarial sticker patches to mess with machine/computer vision systems
adversarial  patch  sticker  camouflage  machine  learning  attack  security  research  computer  vision 
january 2018 by asteroza
Use a demo to see how ASR can help protect your devices | Microsoft Docs
The custom demo tool lets you create sample malware infection scenarios so you can see how ASR would block and prevent attacks
windows  sercurity  attack  surface  reduction  test  testing  prevention  defense  audit  antiexploit 
december 2017 by asteroza
