tomchop

@tomchop.me

Cybersecurity nerd; #DFIR @ Google by day; FOSS, threat intel and malware analysis by night. Investigator, coder, terrible sense of humor. https://yeti-platform.io and more (github.com/tomchop) views are my own • he/him • tomchop.me

Also, I dropped out of bsky before most of infosec twitter joined, so my feed is quite empty (or flooded by US politics...); are there any lists of cybersec nerds I'm missing?

I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission. The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable.

Filippo Valsorda@filippo.abyssdomain.expert · 2y ago

This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library. Looks like this got caught by chance. Wonder how long it would have taken otherwise.

For 25+ yrs police, military, intel agencies and critical infrastructure around the world relied on the TETRA radio standard to secure critical communications. But now Dutch researchers have examined secret algorithms used in TETRA and found something startling - an intentional backdoor, and more

Code Kept Secret for Years Reveals Its Flaw—a Backdoor

A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isn’t pretty.

wired.com

Hey DFIR folks: we released a new version of Timesketch today. - OpenSearch queries in DFIQ - Preserve user defined filters - Support event list sorting - Rework comments - Analyzer results in the CLI - Sketch attributes in the CLI https://github.com/google/timesketch/releases/tag/20230721

Release 20230721 · google/timesketch

What's Changed fixes #2809 UI bug by @jkppr in #2810 Timeline and Scenarios fixes + small UI fixes by @berggren in #2808 Show selected event in context view by @berggren in #2811 Consitent forms a...

github.com

ICYMI, yesterday Microsoft reported on CVE-2023-36884 a vulnerability which myself and @r00tbsd.bsky.social reported earlier on this month. At the time we put together a nice infographic which explained our understanding of the execution chain that led to the installation of the malware involved.

Bild