#informationsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #informationsecurity, aggregated by home.social.
-
A "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF:
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#cybersecurity #infosec #informationsecurity #lpe #linux #kernelctf #exploitation
-
Two new preprints from my #research center!
"Is Cleaning Costly? Evaluating the -fret-cleanAnti-Return-Oriented Programming Mitigation from the OpenBSD Operating System" — an evaluation and critique of #cybersecurity #engineering: https://briancallahan.net/preprints/Callahan_Shaikh_IEEE_CARS_2026.pdf (and #blog post about it: https://briancallahan.net/blog/20260811.html)
"Write Your Way to Better Cybersecurity Awareness Training with Active Word Games" — about identifying creating cybersecurity training as a site of learning worthwhile of studying: https://briancallahan.net/preprints/Wroblewski_et_al_IEEE_CARS_2026.pdf
#academic #academia #professor #freebsd #openbsd #netbsd #dragonflybsd #unix #linux #illumos #solaris #compiler #compilers #cybersec #cyber #informationsecurity #infosec
-
It is with great pleasure that I announce I am a co-author of the Seventh Edition of Gray Hat Hacking, alongside outstanding cybersecurity minds such as Stephen Sims, Valentina Palmiotti, Natalie Silvanovich, Luna Tong, Pavel Yosifovich, Moses Frost, and Huascar Tejeda!
We are undoubtedly living through exciting times, and I hope readers appreciate this complete overhaul of modern, completely updated content. Stay tuned!
#cybersecurity #hacking #exploitation #exploit #programming #informationsecurity #infosec
-
AI-assisted tool helped secure satellite communication system after 2022 Russian hacking
WASHINGTON (AP) — On the same day it invaded Ukraine in 2022, Russia disable…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Artificialintelligence #AI #AnjanaRajan #ArtificialIntelligence #cybercrime #EmilMichael #Generalnews #GregShannon #hacking #informationsecurity #iran #Iranwar #Mathematics #NickSaunders #Software #Technology #Ukraine #Washingtonnews
https://www.newsbeep.com/us/819419/ -
For the interested, you can read a preprint of our latest #research on the #OpenBSD -fret-clean flag here:
https://briancallahan.net/preprints/Callahan_Shaikh_IEEE_CARS_2026.pdf
#freebsd #netbsd #dragonflybsd #bsd #linux #unix #solaris #illumos #compiler #compilers #llvm #gcc #rop #cybersecurity #cybersec #cyber #security #infosec #informationsecurity
-
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day:
#cybersecurity #infosec #informationsecurity #rootkit #vulnerability
-
New article: Digital Signatures and Watermarks — Defending Authenticity in the Era of Generative AI.
As generative AI makes convincing fakes easier, robust authenticity tools become essential. This piece explains how digital signatures and watermarking work, where they fit in compliance and risk strategies, and what organizations should consider when implementing them. Read the full article: https://wix.to/XM8P8vJ
#AI
#Watermarking
#ContentIntegrity
#DigitalSignatures
#RiskManagement
#InformationSecurity -
Weekly output: DDoS attacks, Ed Zitron at Ai4, Delta WiFi spoofing, security perspectives from Black Hat’s NOC, AT&T’s Turbo Live
Having zero in-person work events on my calendar this week was a real treat after spending the prior week in Vegas bouncing between two conferences. That downtime also allowed me to finish two stories from those events.
8/11/2026: Major DDoS Attacks Are Booming, But US No Longer the Most Targeted Country, PCMag
I wrote up a Cloudflare report on trends in distributed denial-of-service attacks and closed it out with a reminder of how efforts to set security standards for the connected gadgets that are often enlisted into DDoS botnets continue to lag.
8/11/2026: This Tech Expert Thinks It’s ‘Time to Call Bullshit on the AI Industry’, PCMag
The easier thing to do with Ed Zitron’s talk at Ai4 would have been to write a scaffold of a post around his most memorable lines, but I wanted to provide some context for the numbers he threw out. The required research started feeling like an exercise in yak shaving, in part because the AI data-center news cycle did not stop.
8/12/2026: Delta Passenger Spoofs Wi-Fi in the Air (Pro Tip: Don’t Do This), PCMag
After seeing so many other places jump on this story, I decided I should do my part–and make sure that my own post, unlike so many others, would feature a photo of 757 in Delta colors instead of some other plane in DL’s fleet.
8/14/2026: At Black Hat, AI is helping security pros find threats—and creating new ones, Fast Company
This was a Black Hat meeting request that I enthusiastically obliged, because Black Hat network admins don’t hold back when they’re talking about unwise behavior they’ve seen on the conference’s WiFi. James Pope (outside this information-security conference, senior director of security product research at Corelight) had some forceful advice for people using AI to vibe-code their own software: “Stop having janky apps.”
8/15/2026: At Rush Concert, AT&T’s Turbo Live Rocked, With Dazzling Download Speeds, PCMag
This story ran almost a month after the concert in question; first I had to field various bits of breaking news, then I had to tell my AT&T PR contact to set aside my questions about this data-only power-up and instead answer a query about a round of retroactive rate hikes, then Ai4 and Black Hat monopolized my journalistic bandwidth. I may or may not have also needed additional time to see how many Rush song-title references I could sneak into this post.
#AI #AIHype #Ai4 #ATT #BlackHat #Cloudflare #cybersecurity #dataCenters #DDoS #Delta #DeltaWiFi #DeltaWiFi #DL #EdZitron #informationSecurity #infosec #NetworkOperationsCenter #NOC #Rush #TurboLive #UnitedCenter #vibeCoding -
Losing your phone is no longer just an annoyance.
Read the blog: https://marshsecurity.org/protecting-against-lost-stolen-mobile-microsoft-security/Losing your phone when it contains access to your email, Microsoft 365, MFA, corporate data, personal accounts, banking, photos and potentially your entire digital identity is a little more serious than "annoyance".
I’ve published a new post looking at what you can do to reduce the impact of a lost or stolen mobile device, both from a personal perspective and also within a business. This blog covers some of the practical protections available through Microsoft and modern device management, as well as the steps worth taking before a device disappears.
Because realistically, the best time to think about how you’d respond to a lost phone probably isn’t five minutes after realising it’s no longer in your pocket.
Read the blog: https://marshsecurity.org/protecting-against-lost-stolen-mobile-microsoft-security/
Tags:
#Microsoft #Security #Cyber #Tech #Technology #CyberSecurity #MicrosoftSecurity #MicrosoftIntune #Intune #Microsoft365 #EntraID #IdentitySecurity #MobileSecurity #InformationSecurity #DataProtection -
Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse
https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse
-
Linux Bridge STP Timer Use-After-Free:
https://ssd-disclosure.com/linux-bridge-stp-timer-use-after-free/
#linux #exploit #exploitation #vulnerability #informationsecurity #cve #patch #cybersecurity
-
💰 Webinar Gratuito: "Fundamentos de Finanzas Empresariales" 🏢 Miércoles 19 de Agosto 2026. De 11:00 am a 11:45 am (UTC -05:00) 🎆 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLScesLnXuVWAIjM5liWUZ5A06BUHghVL0G6GZnWjANCvA9ssBg/viewform #cybersecurity #infosec #informationsecurity #cyber #cyberrisk #cyberresilience -
A wild #blog post appears!
I discuss a new #research publication: an empirical evaluation of the #OpenBSD -fret-clean flag. We examine the history of the mitigation, measure its costs, and deliberate whether or not it is worth keeping.
Worth the read if you like security and/or compilers.
https://briancallahan.net/blog/20260811.html
#freebsd #netbsd #dragonflybsd #bsd #linux #unix #solaris #illumos #compiler #compilers #llvm #gcc #rop #cybersecurity #cybersec #cyber #security #infosec #informationsecurity
-
Weekly output: generative AI in enterprises, Trump cybersecurity policy (x2), Docusign’s designs for AI, AT&T’s kid-optimized tablet
I wrapped up this year’s fourth and final business trip to Las Vegas on Friday, and now I’m looking forward to having almost five months without the City of Bad Decisions in my schedule before CES inevitably draws me back there.
8/4/2026: The Generative AI Playbook: Setting Your Enterprise Up for Success, Ai4
The first of two panels I moderated at this conference for artificial-intelligence professionals (or aspiring professionals) was budgeted for 45 minutes. That could have been an intimidating amount of time to fill. But with four erudite and outgoing people on stage with me–Pankaj Jain, CIO for international operations at General Motors Financial; Murad Dikeidek, head of cybersecurity at UI Health; Max Gokhman, head of artificial intelligence and digital asset solutions at Franklin Templeton; and Kathryn Harrison, global vice president for strategy and business operations at Concentrix–the time flew by fast enough that I had to leave out a question or two in my outline. For a recap, see my friend Shashi Bellamkonda’s recap on his blog.
8/5/2026: Three takeaways from Black Hat’s opening keynote, PCMag
Previous years of Black Hat didn’t feature any main-stage programming on the afternoon and evening before its show floor opens, but this year’s event had an onstage interview of national cyber director Sean Cairncross followed by a panel featuring three other information-security higher-ups from Washington: Nick Andersen, acting director of the Cybersecurity & Infrastructure Security Agency; Katherine Sutton, assistant secretary for cyber policy and principal advisor for cyber policy at the Department of Defense; and Brett Leatherman, assistant director of the FBI’s cyber division. I took extensive notes, then met up with PCMag’s social-media manager Caroline Gilbert to do a quick standup video that she posted to PCMag’s Instagram (along with my client’s accounts on X, TikTok, Threads and Facebook later that night.
8/5/2026: US Cyber Director Promises Not to ‘Strangle’ Industry With Regulations, PCMag
Writing up a post on those opening talks–one that focused on the things that Cairncross left out of his banter–took a little longer. It did help that Wednesday didn’t involve any commuting up and down the Strip for me.
8/6/2026: What It Takes to Build an Agent Platform for Customers, Ai4
I didn’t get asked to do this second panel at Ai4 until the week before the conference. But my Black Hat schedule looked open enough Thursday morning, and the topic–how Docusign has put AI to work–looked interesting enough for me to take the gig and its added speaking fee. And then I saw Tabrez Mohammed, VP of AI at that firm, give some detailed and actionable advice that I hope had attendees taking careful notes.
8/6/2026: AT&T Adds a New Kid-Optimized 5G Android Tablet to Its Lineup, PCMag
One of my colleagues asked Monday if I could write up this announcement we’d gotten in advance from AT&T PR. I said I could but warned that the odds were against my having copy filed before AT&T would publish this news Tuesday morning… which was a good thing, because the advance copy of the release had one data point about this tablet’s battery life exceedingly wrong. We updated the post Saturday to add a couple of specs about this device’s battery that did make the final version of the press release.
#AI #Ai4 #ATTAmiGoJrTab2 #BlackHat #CISA #computersForKids #cybersecurity #Docusign #genAI #generativeAI #informationSecurity #kidsTablets #SeanCairncross #TrumpCybersecurity -
🆓 Webinar Gratuito: "Secretos para una Presentación Exitosa de Ciberseguridad" 💂 Miércoles 12 de Agosto 2026. De 11:00 am a 11:45 am (UTC -05:00) 🚁 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLScR624fU_3w9gmw5fNmXHxn4-5Ulhd3RpTiMqWQKcYdC7MU7w/viewform #cybersecurity #cybersecurity #security #cyber #informationsecurity