Protecting against SWAPGS Attack via Hypervisor Introspection

Bypassing KPTI Using the Speculative Behavior of the SWAPGS Instruction

Bitdefender senior researchers Dan Horea Luțaș and Andrei Vlad Luțaș recently uncovered a new speculative-execution vulnerability and demonstrated how it can be exploited via a side-channel style attack, dubbed SWAPGS Attack. The ...
GandCrab: The most popular Multi-Million Dollar Ransomware of the Year

GandCrab: The most popular Multi-Million Dollar Ransomware of the Year

Ransomware has been around for years and has inflicted financial losses estimated in the billions of dollars. As one of the most lucrative types of malware, from a financial perspective, ransomware developers ...
Education & InfoSec

Education & InfoSec

| | Miscellaneous
Yesterday the question was asked, "do you see a bump in pay-grade commensurate with the cost of a Masters?"  This got me thinking. There are numerous blog posts on how to break into ...
"Hacking Back" is a Bad Idea

Lessons Learned: Speaking at a Security Conferance

| | Miscellaneous
SOURCE Boston was kind enough to take a chance on me and on April 17, 2013 I gave my first talk at a security conference.  The video was finally released this week so I ...

A developer’s story about passion for Open Source and Security

This story is definitely a first for me. Not just because every story is unique in itself, but that it’s one of personal matter. The thing is, I quit my well-paid job, ...

Achieving Security Goals

Achieving your personal goals can be already a serious challenge for one in the day to day activities. However, when it comes to achieving corporate security goals, you might feel things are ...
This Blog is Dead, Long Live This Blog

This Blog is Dead, Long Live This Blog

| | Miscellaneous
When I originally started this blog I struggled for a name. After brainstorming over a long weekend I came up with a handful of possibilities. Unfortunately, all were taken. Not finding an ...
Vote for the Four Horsemen of the Apocalypse

Vote for the Four Horsemen of the Apocalypse

| | Miscellaneous
The InfoSec community frequently debates over the value of industry certifications. A frequent point of contention has been (ISC)2, an organization best known for the Certified Information Systems Security Professional (CISSP) certification ...
Thoughts on Conficker

Thoughts on Conficker

| | conficker, Miscellaneous
well, if you can call them thoughtsLong time since my last post. There has been a lot going on in the personal aspects of my life. One of the things that I ...
Loading...