Do you realize:
someone listening to you, rolling up their sleeves and fixing things
is a really rare occurance, outside open source, once you are through puberty?ππ»ββοΈ
Do you realize:
someone listening to you, rolling up their sleeves and fixing things
is a really rare occurance, outside open source, once you are through puberty?ππ»ββοΈ
CapLoader 1.9.7 Released!
π Community ID's for flows
π Retransmission ratios
πΎ Detection of malware C2 protocols
π£ Decapsulation of Teredo, GTP-U and more...
h/t Lenny Hansson, @naranek and @ckreibich
https://netresec.com/?b=2499359
A new release of CapLoader has been published! Some of the changes can be seen directly in the user interface, such as Community ID values for flows and a few other new columns in the Flows and Services tabs. Other improvements are more subtle, like improved detection of remote management protocols[...]
The 2024 Verizon Data Breach Investigations Report (#DBIR) is out this morning, and I make sense of it in my new post: https://kellyshortridge.com/blog/posts/shortridge-makes-sense-of-verizon-dbir-2024/
I focused on what felt like the most notable points, from #ransomware to MOVEit to web app pwnage to #GenAI and more.
I have insights, quibbles, and hot takes as always β but the fact remains itβs our best source of empirical data on cyberattack impacts. If youβre a #cybersecurity vendor, please consider contributing data to it.
Today we got what must be the most alarming first line in a newly file sec issue to #curl:
"To replicate the issue, I have searched in the Bard about this vulnerability"
... followed by a complete AI hallucination where Bard has dreamed up a new issue by combining snippets from several past flaws. Creative, but hardly productive.
Closed as bogus.
Another fun snippet from this exhibit: the 5,250,000 FTT that was supposedly in the insurance fund was just hardcoded in the frontend.
(This amount of FTT was priced at ~$100 million at the time of the FTX tweet screenshotted in the OP, though FTT was not highly liquid.)
me: I finished the first draft! maybe it's actually ok
me, three minutes later:
I just learned that my Threat Modeling Designing for Security is on a one-day sale for $4.99 for the Kindle edition. This is the lowest price I've ever seen it.
(Boosts appreciated.)
https://www.amazon.com/Threat-Modeling-Designing-Adam-Shostack-ebook/dp/B00IG71FAS
Getting JTAG on the iPhone 15