The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)

LiveOverflow·47K views · 6 months ago
MalwareWeLiveSecurity·6 months ago

PromptSpy ushers in the era of Android threats using GenAI

ESET researchers have identified PromptSpy, marking the first documented Android malware to leverage generative AI within its attack mechanism. The discovery indicates an emerging threat vector where threat actors are integrating AI capabilities into mobile malware operations.

Tracking Program Execution with a Little Known Registry Key

13Cubed·2.9K views · 6 months ago

In this episode, we’ll take a look at another obscure, registry-based execution artifact that may help you fill in yet another piece of the puzzle. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 00:33 - About Registry Hives 02:10 - Demo 🛠 Resources FeatureUsage — Evidence of Execution:

VulnerabilityGoogle Project Zero·6 months ago

Bypassing Administrator Protection by Abusing UI Access

Google Project Zero researcher has documented five root causes behind nine discovered bypasses of Windows Administrator Protection, all of which have now been fixed. The vulnerabilities primarily exploited weaknesses in the UI Access feature—originally designed to allow accessibility applications to function across privilege boundaries—including insecure directory checks, token manipulation, DLL hijacking through environment variables, and TOCTOU race conditions in the RPC process creation mechanism. While all reported issues have been patched, the researcher emphasizes that the underlying architectural reliance on UI Access processes remains a potential vector for future attacks if code execution can be achieved in a High integrity level process.

MalwareBitdefender Labs·6 months ago

LummaStealer Is Getting a Second Life Alongside CastleLoader

Bitdefender researchers have identified a resurgence in LummaStealer activity, demonstrating how this prolific information-stealing malware persisted despite near-disruption by law enforcement within the past year. Operating as a malware-as-a-service since late 2022, LummaStealer has established itself as one of the most widely deployed information stealers through its highly scalable architecture. The malware's renewed distribution alongside CastleLoader indicates continued evolution and adaptation by the threat actors behind the operation.

PhishingCybereason Blog·6 months ago

Cybereason TTP Briefing Q4 2025: Diverse Phishing Tactics and RATs on the Rise

Cybereason's Q4 2025 TTP Briefing highlights emerging threat trends observed across their incident response engagements, with particular emphasis on diversifying phishing tactics and increased remote access trojan (RAT) activity. The report synthesizes frontline intelligence gathered from global IR investigations and security operations center detections to provide actionable insights into current attacker techniques. Security teams can use these findings to understand and prepare for evolving threat landscapes based on real-world incident data.

MalwareCybereason Blog·6 months ago

Fake Installer: Ultimately, ValleyRAT infection

Cybereason Security Services analyzed a fake installer campaign leading to ValleyRAT infections, identifying previously undocumented findings and new threat intelligence insights from the malware. The report investigates this repeatedly observed attack vector and provides practical recommendations for organizations to defend against it. The analysis contributes updated threat intelligence on this infection method to help security teams better protect their environments.

MalwareWeLiveSecurity·6 months ago

DynoWiper update: Technical analysis and attribution

ESET researchers have conducted a technical analysis of DynoWiper, a data destruction tool used in an incident targeting a Polish energy sector company. The analysis includes attribution findings that provide insight into the threat actor behind the attack and the malware's capabilities.

VulnerabilityGoogle Project Zero·6 months ago

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

Google Project Zero researchers have detailed the exploitation of CVE-2024-54529, a type confusion vulnerability in macOS's coreaudiod system daemon that affects the CoreAudio framework's com.apple.audio.audiohald Mach service. The exploit required sophisticated techniques including heap feng shui with property lists, leveraging uninitialized memory in ngne objects, and crafting a ROP chain to achieve arbitrary code execution in the privileged coreaudiod process. The research demonstrates how a seemingly simple type confusion crash can be transformed into a working exploit through creative problem-solving, custom tooling for heap analysis, and careful manipulation of the memory allocator's behavior across process restarts.

MalwareWeLiveSecurity·7 months ago

Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

ESET researchers have identified a targeted Android spyware campaign in Pakistan that leverages a fake dating app as a social engineering lure, exploiting romance scam tactics to deceive users. The discovery reveals connections to a wider surveillance operation, highlighting how threat actors combine dating app fraud with malware distribution to compromise mobile devices in the region.

VulnerabilityGoogle Project Zero·7 months ago

Bypassing Windows Administrator Protection

Google Project Zero researcher discovered nine separate vulnerabilities in Windows 11's new Administrator Protection feature, including one complex bypass that exploits the lazy initialization of per-logon-session DOS device directories to hijack the system drive of elevated processes. Microsoft patched all reported issues either before the feature's official release via optional update KB5067036 or through subsequent security bulletins, though the feature itself was later disabled in December 2025 due to unrelated application compatibility issues. While Administrator Protection represents a meaningful security improvement over legacy User Account Control by establishing a more defensible boundary against silent privilege escalation, the researcher notes that it still carries forward nearly two decades of unfixed UAC bypasses due to Microsoft's conservative approach prioritizing app compatibility over a more radical redesign.

Load more