Why North Korea Is Planning a Second Korean War and How to Stop It
My deep-dive with @andreilankov and @DrRadchenko into North Korean regime, foreign policy, daily life, surveillance state, hackers and much more!
youtu.be/hqTbLkdysBo
@ionescu.bsky.social
Windows Internals Author, Developer, Reverse Engineer, Security Researcher, Speaker, Trainer, and most recently Nation State Hacker. Core OS Platform Developer at Apple, Hyper-V Vendor at Microsoft, Chief Architect at CrowdStrike and now Director at CSE.
Why North Korea Is Planning a Second Korean War and How to Stop It
My deep-dive with @andreilankov and @DrRadchenko into North Korean regime, foreign policy, daily life, surveillance state, hackers and much more!
youtu.be/hqTbLkdysBo
www.gofundme.com/f/support-ma...
CJ is an old friend and a longtime cDc NSF member. He suffered a fall and broke his neck -- his insurance refused to pay for an MRI, which led to the break going undiagnosed for a couple of weeks, until his vertebrae had degraded to the point of quadriplegia.
The One Factor That Could Crash the Russian Economy
A new Geopolitics Decanted episode with a deep-dive into the Russian economy and how it's faring in 2025 and what leverage Ukraine might get to negotiate an acceptable peace deal with Putin
www.youtube.com/watch?v=VOYl...
This was a phenomenal breakdown of some novel Linux malware techniques.
www.elastic.co/secur...
Positive Technologies has developed a new attack that exploits the SD Express standard to gain access to a device's memory through its SD card reader
The DaMAgeCard attack exploits the fact that the new SD Express standard can operate in both SDIO and NVMe
swarm.ptsecurity.com/new-dog-old-...
ost2.fyi/Sponsorship....
Gold Sponsors & Windows Security Track sponsor Winsider Seminars & Solutions (@yardenshafir.bsky.social & @ionescu.bsky.social)
๐
Long time coming and a cast of hundreds (and a very deep tech stack) but CONGRATS to the team - it's the FIRST ARM64 for Windows build of Git!
25.11.2024 22:25 โ ๐ 235 ๐ 36 ๐ฌ 5 ๐ 3There is glory in the unexpressed thought.
22.11.2024 22:00 โ ๐ 13611 ๐ 835 ๐ฌ 628 ๐ 75www.whitehouse.gov/briefing-roo...
23.11.2024 17:15 โ ๐ 1 ๐ 1 ๐ฌ 1 ๐ 0Now I kind of want to write an mIRC plugin
22.11.2024 20:30 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0I have a legitimate question โ given the incredible progress made by Windows on ARM64, it baffles the mind that this is running on an Intel SoC. Especially if itโs meant to be cheap and sustainable. Seriously โ why?
19.11.2024 21:39 โ ๐ 12 ๐ 1 ๐ฌ 0 ๐ 0As far as intelligence scandals come, and whatโs comingโฆ Iโd take this scandal over any other, any time.
15.11.2024 15:56 โ ๐ 4 ๐ 0 ๐ฌ 0 ๐ 0I think itโs ยซย Mahalo, ัะพะฒะฐัะธัย ยป
14.11.2024 12:00 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0This awesome fuzzing blog post by @r00tkitsmm.bsky.social covers a super reliable macOS kernel binary rewriting to instrument any KEXT or XNU at BB or edge level. Mandatory reading for anyone interested in fuzzing whether you use MacOS or not. So many good system internals and fuzzing references!
10.11.2024 02:21 โ ๐ 37 ๐ 15 ๐ฌ 2 ๐ 0Brought back memories ๐ฅฒ
09.11.2024 16:04 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0LSASS now runs as PPL by default, and that DLL doesnโt have the appropriate signature. Unless youโre relying on Bonjour for AD auth youโre probably fine. Microsoft launched LSA PPL signing for 3rd parties back in Windows 8.1 in 2013: learn.microsoft.com/en-us/window...
Itโs only been 11 years ;-)
Very excited to finally see this live! An incredible shift in cloud computing.
08.11.2024 19:28 โ ๐ 4 ๐ 0 ๐ฌ 0 ๐ 0alright folks, the app code is now public
https://github.com/bluesky-social/social-app
I own tools.zip and am trying to figure out what I should serve
16.05.2023 07:23 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Normally I would use a kernel debugger to look at the wait block and see what object itโs attached to. Is there an ETW event that might log that?
10.05.2023 10:31 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0User Mode โ into some sort of Ring 3 (non-kernel) service
09.05.2023 20:04 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Iโm guessing this is an EDR or similar product thatโs calling into UM for a responseโฆ
09.05.2023 00:29 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0So first MSI has been found to ship their Secure Boot policy in โAlwaysExecuteโ mode on 300+ motherboards, and now they had their BootGuard private key leaked from their source repo (WHY is in their repo? ๐คฆ๐ปโโ๏ธ๐คฆ๐ปโโ๏ธ๐คฆ๐ปโโ๏ธ).
Between this and the DBX running out of space, UEFI firmware security needs a reboot.
Windows now has VBS/TPM protected token binding and you can finally now store private keys in hardware and make them truly non-exportable even by a privileged kernel attacker.
Great stuff from Dwizzzle: https://gist.github.com/dwizzzle/a1c4cf4b669053dbeda4a4b24a9aca0f
@ washingtonpost dot com you read that right
03.05.2023 16:23 โ ๐ 631 ๐ 81 ๐ฌ 69 ๐ 34Probably one of the best pieces of reporting on the Solarwinds supply-chain attack. Excellent piece by Kim Zetter.
Highly recommended reading.
Thereโs still a UI bug, when writing a draft the blue button to save the draft still says โReplyโ ๐
02.05.2023 11:27 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Shitposting about other peopleโs security products/detection logic is the natural evolution/side trip of this.
02.05.2023 11:22 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Binge-watched BEEF last night on Netflix and everything from the soundtrack to the experience of being a first generation millennial immigrant from a similar cultural background was cathartic. I cried for hours. I can only imagine how much more this speaks to Asian Americans/Canadians.
02.05.2023 11:19 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 00%
01.05.2023 07:29 โ ๐ 13 ๐ 1 ๐ฌ 2 ๐ 0