Security-driven Rapid Release - Pwn2Own Documentary (Part 4)

LiveOverflow·20K views · 5 months ago

Firefox JIT Bug - Pwn2Own Documentary (Part 3)

LiveOverflow·26K views · 5 months ago
OtherWeLiveSecurity·5 months ago

This month in security with Tony Anscombe – February 2026 edition

Threat actors are actively exploiting weak authentication mechanisms and unmanaged exposures to compromise systems, while also leveraging popular AI tools for malicious purposes. This opportunistic approach highlights ongoing vulnerabilities in common security practices that organizations continue to struggle with.

VulnerabilityGoogle Project Zero·6 months ago

A Deep Dive into the GetProcessHandleFromHwnd API

Google Project Zero researcher Jann Horn examines the evolution of the GetProcessHandleFromHwnd API across Windows versions, revealing critical security flaws that allow opening protected processes when UIPI is enabled. The API's journey from a hook-based implementation in Vista through a kernel function in Windows 10 introduced dangerous access bypasses, particularly affecting restricted token sandboxes and protected processes that opened windows. Windows 11 24H2 introduced significant hardening including permanent UIPI enforcement and protection level checks, though older versions remain vulnerable to exploitation through process handle duplication and memory manipulation attacks.

The First Exploit - Pwn2Own Documentary (Part 2)

LiveOverflow·31K views · 6 months ago
RansomwareThe DFIR Report·6 months ago

Apache ActiveMQ Exploit Leads to LockBit Ransomware

A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, ultimately leading to LockBit ransomware deployment. The DFIR Report provides a detailed analysis of this intrusion chain, including insights into the attacker's techniques and methodology.

The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)

LiveOverflow·47K views · 6 months ago
MalwareWeLiveSecurity·6 months ago

PromptSpy ushers in the era of Android threats using GenAI

ESET researchers have identified PromptSpy, marking the first documented Android malware to leverage generative AI within its attack mechanism. The discovery indicates an emerging threat vector where threat actors are integrating AI capabilities into mobile malware operations.

Tracking Program Execution with a Little Known Registry Key

13Cubed·2.9K views · 6 months ago

In this episode, we’ll take a look at another obscure, registry-based execution artifact that may help you fill in yet another piece of the puzzle. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 00:33 - About Registry Hives 02:10 - Demo 🛠 Resources FeatureUsage — Evidence of Execution:

VulnerabilityGoogle Project Zero·6 months ago

Bypassing Administrator Protection by Abusing UI Access

Google Project Zero researcher has documented five root causes behind nine discovered bypasses of Windows Administrator Protection, all of which have now been fixed. The vulnerabilities primarily exploited weaknesses in the UI Access feature—originally designed to allow accessibility applications to function across privilege boundaries—including insecure directory checks, token manipulation, DLL hijacking through environment variables, and TOCTOU race conditions in the RPC process creation mechanism. While all reported issues have been patched, the researcher emphasizes that the underlying architectural reliance on UI Access processes remains a potential vector for future attacks if code execution can be achieved in a High integrity level process.

MalwareBitdefender Labs·6 months ago

LummaStealer Is Getting a Second Life Alongside CastleLoader

Bitdefender researchers have identified a resurgence in LummaStealer activity, demonstrating how this prolific information-stealing malware persisted despite near-disruption by law enforcement within the past year. Operating as a malware-as-a-service since late 2022, LummaStealer has established itself as one of the most widely deployed information stealers through its highly scalable architecture. The malware's renewed distribution alongside CastleLoader indicates continued evolution and adaptation by the threat actors behind the operation.

Load more