The Mandiant Advanced Practices team recently discovered a new malware family we have named PRIVATELOG and its installer, STASHLOG. In this post, we will share a novel...
Read moreThe Mandiant Advanced Practices team recently discovered a new malware family we have named PRIVATELOG and its installer, STASHLOG. In this post, we will share a novel...
Read moreZero-Click iPhone Exploits
September 1 2021Citizen Lab is reporting on two zero-click iMessage exploits, in spyware sold by the cyberweapons arms manufacturer NSO Group to the Bahraini government. These are particularly scary exploits, since they...
Read moreRecursion [noun]: see recursion.
Read moreMore Military Cryptanalytics, Part III
August 31 2021Late last year, the NSA declassified and released a redacted version of Lambros D. Callimahos’s Military Cryptanalytics, Part III. We just got most of the index. It’s hard to...
Read moreExcellent Write-up of the SolarWinds Security Breach
August 30 2021Robert Chesney wrote up the Solar Winds story as a case study, and it’s a really good summary.
Read moreFriday Squid Blogging: Tentacle Doorknob
August 27 2021It’s pretty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Read my blog posting guidelines here.
Read moreDetails of the Recent T-Mobile Breach
August 27 2021Seems that 47 million customers were affected. Surprising no one, T-Mobile had awful security. I’ve lost count of how many times T-Mobile has been hacked.
Read moreBig bad decryption bug in OpenSSL – but no cause for alarm
August 27 2021The buggy code's in there, alright. Fortunately, it's hard to get OpenSSL to use it even if you want to, which mitigates the risk.
Read moreLatest episode - listen now!
Read more
Recent Comments