China Presses Nvidia Over Alleged Backdoors in H20 Chips Amid Tech Tensions
02.08.2025 22:43 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0@ocdsec.bsky.social
๐ดโโ ๏ธ ๐ ๐บ๐ฆ computer tester | 603,628 kmยฒ
China Presses Nvidia Over Alleged Backdoors in H20 Chips Amid Tech Tensions
02.08.2025 22:43 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0New Batavia spyware targets Russian industrial enterprises
07.07.2025 20:05 โ ๐ 2 ๐ 2 ๐ฌ 0 ๐ 0Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User
06.06.2025 23:44 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 0Powershell: after 5 "type .\5\test.txt" calls, the test.txt file is a symlink to win.ini CMD: A single "type .\6\test.txt" call results in every single file being printed, including the final win.ini symlink
From over at the Bad Place:
There's an interesting NTFS symlink attack outlined here:
https://dfir.ru/2025/02/23/symlink-attacks-without-code-execution/
Basically, if an NTFS filesystem is corrupted in a way to provide duplicate file names, Windows will [โฆ]
[Original post on infosec.exchange]
This is what I personally did back when I was involved in cybercrime. We'd host all our servers in Russia, transfer payments via Russian banks, and route all our traffic through Russian residential ISPs, which typically resulted in most authorities not even bothering to investigate further. 7/?
15.04.2025 19:37 โ ๐ 32 ๐ 3 ๐ฌ 1 ๐ 0cybercrime zeroday faded tee
cybercrime
but its bigger
and on both sides.
Well there are lots of people who have been treating Google and many others like that for ages, and this is why the solutions are already out.
You lose convenience the deeper you go, but the solutions are there.
well they exist ^^
01.03.2025 21:51 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0VulnCheck has extracted and made a list of all the CVEs mentioned in a recent leak from the internal Matrix chat server of the BlackBasta ransomware group.
The list includes 62 vulnerabilities.
VulnCheck says the group focuses on CVEs with already public exploits
vulncheck.com/blog/black-b...
I cannot overstate the value of being in community with other activists right now. It is what gives me the strength to get up in the morning and fight fascism.
24.02.2025 20:53 โ ๐ 1852 ๐ 205 ๐ฌ 64 ๐ 20"Over the course of the GitVenom campaign, the threat actors behind it have created hundreds of repositories on GitHub that contain fake projects with malicious code"
Campaign delivers an infostealer, obviously. The threat-du-jour these days
securelist.com/gitvenom-cam...
I just finished our #shmoocon talk on container security. Here's my seccomp bpf disassembler and diffing tool.
github.com/antitree/sec...
Diving into ADB protocol internals:
part 01: www.synacktiv.com/publications...
part 02: www.synacktiv.com/en/publicati...
#adb #mobile #protocol #informationsecurity #cybersecurity #reverseengineering
These are some really nice blog posts regarding algo confusion bugs in JWT by @pentesterlab.com pentesterlab.com/blog/jwt-alg... & pentesterlab.com/blog/another... nice one @snyff.pentesterlab.com!
22.12.2024 19:06 โ ๐ 20 ๐ 5 ๐ฌ 1 ๐ 0Ruble to fall to 200 per dollar: Russian economist warns of approaching catastrophe โ media
ัะธัะฐะนัะต ะฟะพะดัะพะฑะฝะตะต ะฝะฐ ัะฐะนัะต "ะะธะฐะปะพะณ.UA": www.dialog.ua/business/306...
Wow, a fairly serious auth bypass in Next.js, a super popular frontend framework:
"If a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed."
securityonline.info/...
The #OpenBSD Foundation is currently at ~$230,280 (65%) raised of the $350,000 goal for their 2024 Fundraising Campaign, and it's nearly the end of December. ๐ก
www.openbsdfoundation.org/campaign2024...
www.openbsdfoundation.org/donations.html
Donations fund events for developers, infra. costs.
I did a blog instead of working on my projects again. This time a maldev blog talkin' about PE runtime decryption and other ways to be an asshole to the analyst. amethyst.systems/blog/posts/v... #infosec #malware
07.12.2024 20:18 โ ๐ 29 ๐ 11 ๐ฌ 0 ๐ 0The #OBTS day 2 livestream is on!
www.youtube.com/watch?v=Nm0z...
Decrypting CryptProtectMemory without code injection:
blog.slowerzs.net/posts/cryptd...
#crypto #decryption #cybersecurity #informationsecurity #rdp #windows #programming
"We can now share that our latest investigation also found links between some of Doppelgangerโs activities and individuals associated with MGIMO (Moscow State Institute of International Relations)."
via Meta/PDF: scontent.fotp7-2.fna.fbcdn.net/v/t39.8562-6...
NTLM Relaying โ Making the Old New Again
labs.jumpsec.com/ntlm-relayin...
Great article on ESC15 especially after you realise PKInit won't work to auth but there is a workaround supplied too.
medium.com/@offsecdeer/...