September 25, 2021 at 12:29PM

■■■■■ Researchers compile list of vulnerabilities abused by ransomware groups. So, we are up to 42 vulnerabilities across 17 technologies (with 1 pending) that ransomware groups exploit for initial access. This is why preaching “just patch” isn’t good enough. I don’t know what the answer is, but what we’re doing clearly isn’t working. https://t.co/oYBRUwTWf3 —…

September 25, 2021 at 12:25PM

■■■■■ This is one of the entries to the BGGP 2021 Polyglot File challenge. It uses a novel technique of directly embedding data within the compressed image data stream of a PNG. This means you can literally see the bytes of the embedded files! ● It literally took about a minute for me to understand.…

September 25, 2021 at 11:38AM

■■■■□ CVE-2021-37973: Chrome Update Released to Patch Actively Exploited Zero-Day Vulnerability. Use after free in Portals. Reported by Clément Lecigne from Google TAG, with technical assistance from Sergei Glazunov and Mark Brand from Google Project Zero on 2021-09-21 (https://bugs.chromium.org/p/chromium/issues/detail?id=1251727) https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_24.html https://thehackernews.com/2021/09/urgent-chrome-update-released-to-patch.html https://t.me/cKure/9491