Reading view
DEFCON: New Red Team Tactic
Evil Fonts deceive a viewer by rendering a different letter than is actually on the disk. Evil Fonts can poison HTML, DOCX, PDFs, and anywhere else you can bring your own fonts. Works great in Windows corporate networks for bypassing security tooling, initial access through JavaScript free click fix (beats mitm web security tooling), and leaving traps around the network to harvest shells.
Imagine thinking you are copying whoami but what is actually on the disk is rm -rf \~
Demos:
(Use desktop)
https://doctoreww.github.io/EvilFontTool/
For the demos, copy and paste the HTML/DOCX to a notepad to remove the evil fonts. For the AI ones imagine your security tooling inspects the benign text on disk, but shows the obviously malicious extortion to the user.
Labs:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2FREADME.md
Lab Walkthrough:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2Fwalkthrough.md
Some evil font uses:
Tamper homework to make it so students poison AI queries
Poison help desk documentation
Bypass email filters
Clickfix
Beat resume AI filters
[link] [comments]
Analyzing a Multi-Stage PowerShell Payload Chain
I recently analyzed a multi-stage PowerShell payload delivery chain involving heavily obfuscated PowerShell loaders and remotely hosted payloads.
The analysis covers PowerShell deobfuscation, hidden execution, Base64/XOR decoding, a decoy “Verification complete!” prompt, payload delivery, and IOCs.
Initial indicators:
203[.]188[.]171[.]166
dorenzaa[.]com
[link] [comments]
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
Write once, shell everywhere. Sun Microsystems didn't mean it like this.
Talk from today at DEF CON's Bug Bounty Village. Full technique catalog graded for distroless containers, an errno path oracle for black-box target fingerprinting, and three minimal-guessing techniques: bash fd/255, Rails schema_cache.yml deserialization, and a Node.js worker path overwrite without process restart.
[link] [comments]
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab
Yes, given that the legacy SCT protocol has known security vulnerabilities such as sctphantom, the industry strongly recommends deprecating it and migrating to more secure modern standards to ensure system security.
[link] [comments]
OpenAI pledges to add Astra security as Anthropic loosens Fable's leash
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
The meetingscollection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator's email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps.
I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains.
[link] [comments]
I ditched T-Mobile for Mint after 10 years of service - now I'm saving $120/month
Ransomware attacks spike as world distracted by AI
TrustFall: When the Trusted Execution Environment Cannot Be Trusted
ByteRay researchers have published a blog on a set of vulnerabilities they are calling TrustFall, and the findings land hard for any company that treats the Trusted Execution Environment as the part of a device you do not have to worry about.
OP-TEE is the walled-off Secure World that phones, TVs, cars, and industrial gear lean on to guard keys, DRM, and identity, and the whole point of paying for that hardware isolation is the promise that even a compromised operating system cannot reach inside.
TrustFall shows that promise was not as solid as buyers assumed. The researchers found several flaws that let the untrusted side reach into or knock over the Secure World, which is exactly the outcome the design exists to prevent. The bugs have since been fixed upstream, so patched builds are available, but the uncomfortable takeaway for vendors is that the vault they were told to trust had a way in, and "it runs in the TEE" is no longer an answer on its own.
[link] [comments]
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs