You Suck at Cybersecurity

January Firmware Threat Report

| | threat report
2022 managed to kick off with a bang. Under pressure from the United States, the Russian FSB detained 14 people tied to the REvil ransomware operation, seizing $600,000 of computer equipment and ...
Don’t Let Cyber Criminals Steal Your Connections: Securing Internet-Accessible Systems

December Firmware Threat Report

| | threat report
What a December! Let’s see if we can write a threat report without mentioning log4j. Possible? Let’s find out! While everyone else is writing about it and you are completely overwhelmed, over-vendored, ...
November Firmware Threat Report

November Firmware Threat Report

| | threat report
On November 18th, earthlings experienced the longest duration Lunar eclipse in a stretch of over 1000 years. The moon was covered by Earth’s umbral shadow for over six hours. The next time ...
OST2 Architecture 2001: x86-64 OS Internals Trailer

October Firmware Threat Report

| | threat report
Among the tricks and treats you had, emerges a new Below the Surface to make you glad. So keep on reading to hear what we think, feel free to relax and pour ...
September Firmware Threat Report

September Firmware Threat Report

| | threat report
Spyware found embedded in UEFI and MBR firmware - ran undetected for years ...
Scott Scheferman’s August “Below the Surface” Hot-Take

August Firmware Threat Report

| | threat report
Patch, patch, patch your firmware. Active attacks in the wild are occurring within days of disclosure ...
Scott Scheferman’s July “Below the Surface” Hot-Take

July Firmware Threat Report

| | threat report
Check out Scott’s hot-take video for this month’s Threat Report. July came in hot. Really hot. Not more than a few hundred miles from our Portland, OR headquarters, the Bootleg fire continues ...
June Firmware Threat Report

June Firmware Threat Report

| | threat report
Not just one, but four. That’s how many vulnerabilities Eclypsium researchers discovered in Dell’s BIOSConnect feature. Taken together, this chain of vulnerabilities has a CVSS score of 8.3 (High) because it allows ...
All Our Devices Aren't Belong 2 Us - Scott Scheferman - RSA21

May Firmware Threat Report

| | threat report
Sometimes it takes a thunderstorm before seeing positive outcomes and real change: Cyber May Flowers, if you will. The SolarWinds and related supply chain attacks put our government through the crucible of ...
April Firmware Threat Report

April Firmware Threat Report

| | threat report
April has been a month of awakening. The highest levels of government and some of the most influential tech companies in the industry have made it clear: we have crossed a threshold ...