Not everything that Newag does is bad.
For instance, we would like to congratulate them on making the shortlist of the European SLAPP Contest 2025!
www.the-case.eu/latest/the-p...
@mkow.bsky.social
reverse-engineering / low-level security Dragon Sector CTF vice-captain, Invisible Things Lab Mastodon: @redford@infosec.exchange Also known as Redford
Not everything that Newag does is bad.
For instance, we would like to congratulate them on making the shortlist of the European SLAPP Contest 2025!
www.the-case.eu/latest/the-p...
A disgusting and abject betrayal by the US. A decision that will save the US approximately zero dollars and will very directly kill countless Ukrainians
05.03.2025 12:21 — 👍 1134 🔁 356 💬 24 📌 6Snooper's Charter realized. "The British government’s undisclosed order, issued last month, requires blanket capability to view fully encrypted material, not merely assistance in cracking a specific account, and has no known precedent in major democracies."
Huge story from @joemenn.bsky.social
This looks huge, a bug allows loading custom microcode into AMD CPUs! Great for reversing CPU internals, but also breaks AMD-SEV and others...
03.02.2025 23:48 — 👍 4 🔁 2 💬 0 📌 0"[...] representatives of this group of hackers, commonly referred to as "ethical hackers", though theft and home invasion have nothing to do with ethics—but well, I understand, ethical hackers, because that's what they call themselves [...]" (a certain Polish MP)
"Hacker", as we in the bizz know well, carries different meanings for different people, and this can cause hilarious misunderstandings. Yesterday, the second part of an ongoing documentary about issues in NEWAG trains that were analyzed by Dragon Sector was aired. [...] gynvael.coldwind.pl?id=799
30.01.2025 19:28 — 👍 10 🔁 2 💬 2 📌 0The second part of the TVN24 reportage about the train locks will air today 20:30 CET! (Polish only, unfortunately)
www.facebook.com/czarnonabial...
If you're following NEWAG vs Dragon Sector suits: Citizens Network Watchdog Poland ("independent, apolitical and non-profit organization in the form of a watchdog & think-do-tank") filed an amicus brief with the court urging the court to dismiss the case as a SLAPP
siecobywatelska.pl/od-niedziala...
Sieć Obywatelska Watchdog wydała ciekawy komentarz dotyczący naszej sprawy, analizując ją pod kątem bycia SLAPP-em - siecobywatelska.pl/od-niedziala...
26.01.2025 12:24 — 👍 1 🔁 0 💬 0 📌 0From sabotaging trains to conquering Tricore: Michał Kowalczyk ( @mkow.bsky.social ) and Jakub Stepniewicz (MrTick) take you on a deep dive into RE challenges—500KB of machine code, Ghidra bugs, and embedded adventures. https://re-verse.sessionize.com/session/778969 #REverse2025 #HardwareHacking
22.01.2025 20:34 — 👍 3 🔁 1 💬 0 📌 0Newag just sued the Polish parliament member who was investigating the train case 🤡
wiadomosci.onet.pl/krakow/nowa-...
Exact quote of Polish ex-Minister for Infrastructure about Dragon Sector: (translation mine) "representatives of the group of hackers, so called "ethical hackers", despite that stealing and robbing houses has nothing to do with ethics" (???)
22.11.2024 15:43 — 👍 3 🔁 0 💬 1 📌 0Good summary of yesterday's Infrastructure Committee meeting in Polish Parliament (PL only, but translation should work). We were compared to house burglars (because we're **hackers**) and the meeting was closed without giving us and other guests a chance to speak.
[PL] www.onet.pl/informacje/o...
6. Custom feeds on Bluesky are the first implementation of algorithmic choice. Instead of using a single black-box For You algorithm, you can create and subscribe to your own.
Now, there are over 50k+ custom feeds on the network! Check them out:
bsky.app/feeds
We are kicking things off with a series on the spies, crooks and hit-men released back to Moscow in the recent prisoner swap.
Let's start with the improbable identification process of the Russian illegals posing as an Argentine family in Slovenia: youtu.be/3TTFrYqZFZo?...
NEW: Biden's approval for Ukraine to use the powerful ATACMS long-range weapon for limited strikes inside Russia is in response to North Korea's deployment of thousands of troops to aid Moscow's war effort & is a significant reversal of U.S. policy.
www.washingtonpost.com/national-sec...
One of the best summaries of the train case legal proceedings is now available in English!
rys.io/en/175.html
Chcecie być objęci nadzorem ABW? Zapraszamy na Oh My H@ck 2024! Nie pożałujecie ;)
omhconf.pl
Z pozwu przeciwko członkom Dragon Sector: NEWAG zwrócił się do ABW o usunięcie artykułów oraz "objęcie szczególnym nadzorem wszystkich uczestników konferencji Oh my Hack"
Some notes from analyzing the bash part obfuscation of the xz/liblzma part – link leads to the part I found most interesting – it was added in 5.6.1:
gynvael.coldwind.pl?lang=en&id=7...
This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library.
Looks like this got caught by chance. Wonder how long it would have taken otherwise.
I've written a piece setting the amazing work by 3 guys investigating NEWAG's digital sabotage of its Impuls trains in the wider railway context.
I try to explain *why* NEWAG behaved as it did, and what the rail industry can learn now the problem has been discovered jonworth.eu/newags-digit...