CK's Technology News · @CKsTechNews
1833 followers · 3303 posts · Server cktn.todon.de
DarkOperator 🚀 · @DarkOperator
1242 followers · 1898 posts · Server infosec.exchange

Alrighty nerds, strap in - got another vulnerability write up, hot off the press!
 
You may remember the vulnerability disclosed by the and to Microsoft about (CVE-2022-34689) which can lead to masquerading as legitimate entities (such as google or Microsoft.)
 
We analyzed and exploited it. Pretty neat.

in the PoC, you can see the source code for how it could be exploited in the wild using an old version of Chrome.
 
Link to write-up: akamai.com/blog/security-resea

Link to github repo: github.com/akamai/akamai-secur

#microsoft #ncsc #nsa #cryptoapi

Last updated 2 years ago

Clerton · @clerton
27 followers · 43 posts · Server fosstodon.org

Is there something in the wild that encrypts/decrypts data to push/pull on using browser’s ?

#indexeddb #cryptoapi #frontend #frontenddevelopment #javascript

Last updated 2 years ago

· @AdaPlanet
53 followers · 2261 posts · Server botsin.space
ace36 · @aaronco36
11 followers · 214 posts · Server fosstodon.org


:windows: 👺
"Windows 10 has a dangerous flaw discovered by NSA, Microsoft rushed to patch it" bit.ly/30rzNza

Wonder what particular "businesses" (or governments) the is *really* worried about here?

#windows #cryptoapi #nsa

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

NSA and Github ‘rickrolled’ using Windows CryptoAPI bug - We said, "Assume that someone will find out how to do it pretty soon," and that's exactly what hap... more: nakedsecurity.sophos.com/2020/ -2020-0601

#nsa #windows #exploit #rickroll #cryptoapi #microsoft #cryptography #cve #vulnerability

Last updated 5 years ago

’s for -2020-0601 introduces a call to in when a faked certificate is detected.
Didier Stevens wrote a script that will write a Windows event entry in the Application event log.

blog.didierstevens.com/2020/01

#microsoft #patch #cve #CveEventWrite #cryptoapi #test #alert #blueteam

Last updated 5 years ago