Found 34370 bookmarks
Newest
New Dysphoria DDoS botnet spreads to 200k devices worldwide
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
·bleepingcomputer.com·
New Dysphoria DDoS botnet spreads to 200k devices worldwide
New Certighost PoC exploit lets attackers hijack Windows domains
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.
·bleepingcomputer.com·
New Certighost PoC exploit lets attackers hijack Windows domains
Coca-Cola confirms data theft in Fairlife ransomware attack
Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month.
·bleepingcomputer.com·
Coca-Cola confirms data theft in Fairlife ransomware attack
International law enforcement initiate hunt on malware group SocGholish
International law enforcement initiate hunt on malware group SocGholish
In Operation Endgame, a major operation this week disrupted a key infection chain used by cyber criminals. Within an international cooperation, 14.971 websites infected with SocGholish malware were remediated. This malware is used by a criminal group that plays a pivotal role in international cybercrime, namely: Evil Corp.
·politie.nl·
International law enforcement initiate hunt on malware group SocGholish
Ernst & Young data breach claimed by ShinyHunters extortion gang
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.
·bleepingcomputer.com·
Ernst & Young data breach claimed by ShinyHunters extortion gang
NIS2 e supply chain: le nuove FAQ ACN cambiano la gestione del rischio fornitori
NIS2 e supply chain: le nuove FAQ ACN cambiano la gestione del rischio fornitori
ACN aggiorna le FAQ sulla supply chain dei soggetti NIS: le quattro fasi della gestione del rischio fornitori, i criteri minimi di valutazione e la proporzionalità dei requisiti nei contratti misti. Una guida operativa per il percorso di conformità NIS2
·cybersecurity360.it·
NIS2 e supply chain: le nuove FAQ ACN cambiano la gestione del rischio fornitori
Shadow AI agents are multiplying. Here's how to find and secure them.
Shadow AI agents are multiplying. Here's how to find and secure them.
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks.
·bleepingcomputer.com·
Shadow AI agents are multiplying. Here's how to find and secure them.
Debugging C on the CANPico
Debugging C on the CANPico
The Raspberry Pi Pico is an excellent embedded platform, noted for its excellent documentation (and also the RP2040 microcontroller, one of the few that is currently not made from unobtainium). But one of the great features of this board is how it gets more and more support over time. And that’s why we used it as the basis for the CANPico.
·kentindell.github.io·
Debugging C on the CANPico
Getting started with CryptoCAN on the CANPico
Getting started with CryptoCAN on the CANPico
CryptoCAN is an encryption scheme for CAN messaging developed by Canis Labs. It’s designed to fit the publish/subscribe method of communication that CAN was designed for, and has a simple job: take a plaintext CAN frame, convert it into two ciphertext frames for broadcast on CAN, and at receivers, push these frames through a decoder to get back to the plaintext frame.
·kentindell.github.io·
Getting started with CryptoCAN on the CANPico
Running high speed signals through CAN bus wiring
Running high speed signals through CAN bus wiring
CAN bus wiring has a big effect on how fast data can go on CAN. CAN bits are normally 2000ns (2 microseconds, or 500kbit/sec) or longer for slower buses (a J1939 CAN bus runs at 250kbit/sec and can be up to 40m long). But CAN FD has the promise of much faster speeds on conventional CAN bus wiring, up to 8Mbit/sec (i.e. 125ns bit times). Yet most of the automotive industry is using CAN FD at just 2Mbit/sec or even slower. Why is this?
·kentindell.github.io·
Running high speed signals through CAN bus wiring
CAN Quiz Question #2
CAN Quiz Question #2
This is the second CAN Quiz Question on the CAN protocol. This one is quite hard and not only tests knowledge of the dark corners of the CAN protocol, it also highlights a couple of important system design issues.
·kentindell.github.io·
CAN Quiz Question #2
CAN Quiz Question #2: Answer
CAN Quiz Question #2: Answer
The question: There is a CAN node that’s acting very strangely on a 500kbit/sec CAN bus. What is happening?
·kentindell.github.io·
CAN Quiz Question #2: Answer
CAN Injection: keyless car theft
CAN Injection: keyless car theft
This is a detective story about how a car was stolen - and how it uncovered an epidemic of high-tech car theft. It begins with a tweet. In April 2022, my friend Ian Tabor tweeted that vandals had been at his car, pulling apart the headlight and unplugging the cables.
·kentindell.github.io·
CAN Injection: keyless car theft
Get your app to Mars!
Get your app to Mars!
This is a blog post about firmware updates, and I was inspired to write it by the news that NASA’s Curiosity rover on Mars has got an OTA update. The firmware image was about 21MB and took 11 days to send it over-the-air (or in this case, over-the-vacuum: Mars is currently 242 million kilometres from Earth).
·kentindell.github.io·
Get your app to Mars!
Inferring the sender of a CAN frame
Inferring the sender of a CAN frame
The latest update of the open source can2 protocol decoder is able to automatically infer the sender of a CAN frame. It uses the method of deterministic distortion of CAN signals that result in frames from a given node on the bus having consistently shortened or lengthened recessive pulses. The differences can be quite small - just 10 or 15 nanoseconds - but they can be picked up by a suitably accurate logic analyzer.
·kentindell.github.io·
Inferring the sender of a CAN frame
GitHub Honeypot Scam: sOLarFLaMEPyL/Arbitrage_Mev_BOT
GitHub Honeypot Scam: sOLarFLaMEPyL/Arbitrage_Mev_BOT
Reverse engineering a fund-draining honeypot smart contract disguised as a MEV arbitrage bot on GitHub, exposing the hidden backdoor and withdrawal mechanism.
·derp.ca·
GitHub Honeypot Scam: sOLarFLaMEPyL/Arbitrage_Mev_BOT
PureLogs: Reverse Engineering a .NET RAT From the PureCoder Ecosystem
PureLogs: Reverse Engineering a .NET RAT From the PureCoder Ecosystem
Technical analysis of two PureLogs variants from the PureCoder MaaS ecosystem -- a plugin stager and a monolithic crypto-stealing fat client -- recovered from a multi-stage intrusion tracked as SERPENTINE#CLOUD.
·derp.ca·
PureLogs: Reverse Engineering a .NET RAT From the PureCoder Ecosystem
VioletWorm v4.7 (Violet RAT): The Most Dangerous Payload in a 9-RAT Toolkit
VioletWorm v4.7 (Violet RAT): The Most Dangerous Payload in a 9-RAT Toolkit
Technical analysis of VioletWorm v4.7 (also tracked as Violet RAT) -- a .NET RAT with ransomware, HVNC, USB spreading, crypto clipping, and 120 command branches dispatched through C2-delivered plugin DLLs -- recovered from a multi-stage intrusion with tooling overlap to SERPENTINE#CLOUD.
·derp.ca·
VioletWorm v4.7 (Violet RAT): The Most Dangerous Payload in a 9-RAT Toolkit
PureCrypter: Reverse Engineering a .NET Loader From the PureCoder Ecosystem
PureCrypter: Reverse Engineering a .NET Loader From the PureCoder Ecosystem
Technical analysis of PureCrypter, a builder-generated .NET crypter from the PureCoder malware-as-a-service ecosystem, recovered from a multi-stage intrusion tracked as SERPENTINE#CLOUD. Two builds fully reversed.
·derp.ca·
PureCrypter: Reverse Engineering a .NET Loader From the PureCoder Ecosystem