Advertisement · 728 × 90

Posts by Alex Ionescu

Why North Korea Is Planning a Second Korean War and How to Stop It
Why North Korea Is Planning a Second Korean War and How to Stop It YouTube video by Dmitri Alperovitch

Why North Korea Is Planning a Second Korean War and How to Stop It

My deep-dive with @andreilankov and @DrRadchenko into North Korean regime, foreign policy, daily life, surveillance state, hackers and much more!

youtu.be/hqTbLkdysBo

1 year ago 62 13 0 3
Preview
Donate to Support Marc Rogers' Road to Recovery, organized by Katie Vogel cjunkie (Marc Rogers) is an invaluable and beloved member of our hacker community: a… Katie Vogel needs your support for Support Marc Rogers' Road to Recovery

www.gofundme.com/f/support-ma...

CJ is an old friend and a longtime cDc NSF member. He suffered a fall and broke his neck -- his insurance refused to pay for an MRI, which led to the break going undiagnosed for a couple of weeks, until his vertebrae had degraded to the point of quadriplegia.

1 year ago 40 33 2 1
The One Factor That Could Crash the Russian Economy
The One Factor That Could Crash the Russian Economy YouTube video by Dmitri Alperovitch

The One Factor That Could Crash the Russian Economy

A new Geopolitics Decanted episode with a deep-dive into the Russian economy and how it's faring in 2025 and what leverage Ukraine might get to negotiate an acceptable peace deal with Putin
www.youtube.com/watch?v=VOYl...

1 year ago 105 24 6 5
Preview
Declawing PUMAKIT — Elastic Security Labs PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with command-and-control servers.

This was a phenomenal breakdown of some novel Linux malware techniques.

www.elastic.co/secur...

1 year ago 27 12 3 1
Post image

Positive Technologies has developed a new attack that exploits the SD Express standard to gain access to a device's memory through its SD card reader

The DaMAgeCard attack exploits the fact that the new SD Express standard can operate in both SDIO and NVMe

swarm.ptsecurity.com/new-dog-old-...

1 year ago 59 24 4 4

ost2.fyi/Sponsorship....
Gold Sponsors & Windows Security Track sponsor Winsider Seminars & Solutions (@yardenshafir.bsky.social & @ionescu.bsky.social)

👇

1 year ago 2 2 1 0

Long time coming and a cast of hundreds (and a very deep tech stack) but CONGRATS to the team - it's the FIRST ARM64 for Windows build of Git!

1 year ago 235 36 5 3

There is glory in the unexpressed thought.

1 year ago 13561 830 625 75

www.whitehouse.gov/briefing-roo...

1 year ago 1 1 1 0

Now I kind of want to write an mIRC plugin

1 year ago 1 0 0 0
Advertisement

I have a legitimate question — given the incredible progress made by Windows on ARM64, it baffles the mind that this is running on an Intel SoC. Especially if it’s meant to be cheap and sustainable. Seriously — why?

1 year ago 12 1 0 0

As far as intelligence scandals come, and what’s coming… I’d take this scandal over any other, any time.

1 year ago 4 0 0 0

I think it’s « Mahalo, товарищ »

1 year ago 3 0 0 0
Pishi: Coverage guided macOS KEXT fuzzing. This blog post is the result of some weekend research, where I delved into Pishi, a static macOS kernel binary rewriting tool. During the weekdays, I focus on Linux kernel security at my job and would...

This awesome fuzzing blog post by @r00tkitsmm.bsky.social covers a super reliable macOS kernel binary rewriting to instrument any KEXT or XNU at BB or edge level. Mandatory reading for anyone interested in fuzzing whether you use MacOS or not. So many good system internals and fuzzing references!

1 year ago 37 15 2 0

Brought back memories 🥲

1 year ago 1 0 0 0
Preview
LSA and UEFI file signing - Windows drivers Local Security Authority (LSA) plug-in and Unified Extensible Firmware Interface (UEFI) firmware signing.

LSASS now runs as PPL by default, and that DLL doesn’t have the appropriate signature. Unless you’re relying on Bonjour for AD auth you’re probably fine. Microsoft launched LSA PPL signing for 3rd parties back in Windows 8.1 in 2013: learn.microsoft.com/en-us/window...
It’s only been 11 years ;-)

1 year ago 4 0 1 0

Very excited to finally see this live! An incredible shift in cloud computing.

1 year ago 4 0 0 0

alright folks, the app code is now public

https://github.com/bluesky-social/social-app

2 years ago 1091 398 99 100

I own tools.zip and am trying to figure out what I should serve

2 years ago 0 0 0 0
Advertisement

Normally I would use a kernel debugger to look at the wait block and see what object it’s attached to. Is there an ETW event that might log that?

2 years ago 0 0 1 0

User Mode — into some sort of Ring 3 (non-kernel) service

2 years ago 0 0 1 0

I’m guessing this is an EDR or similar product that’s calling into UM for a response…

2 years ago 1 0 1 0

So first MSI has been found to ship their Secure Boot policy in “AlwaysExecute” mode on 300+ motherboards, and now they had their BootGuard private key leaked from their source repo (WHY is in their repo? 🤦🏻‍♂️🤦🏻‍♂️🤦🏻‍♂️).

Between this and the DBX running out of space, UEFI firmware security needs a reboot.

2 years ago 6 0 0 0

Windows now has VBS/TPM protected token binding and you can finally now store private keys in hardware and make them truly non-exportable even by a privileged kernel attacker.

Great stuff from Dwizzzle: gist.github.com/dwizzzle/a1c4cf4b669053d...

2 years ago 5 0 0 0

@ washingtonpost dot com you read that right

2 years ago 629 79 69 34
SolarWinds: The Untold Story of the Boldest Supply-Chain Hack | WIRED

Probably one of the best pieces of reporting on the Solarwinds supply-chain attack. Excellent piece by Kim Zetter.

Highly recommended reading.

2 years ago 12 6 1 0
Advertisement

There’s still a UI bug, when writing a draft the blue button to save the draft still says “Reply” 🙄

2 years ago 1 0 0 0

Shitposting about other people’s security products/detection logic is the natural evolution/side trip of this.

2 years ago 0 0 0 0

Binge-watched BEEF last night on Netflix and everything from the soundtrack to the experience of being a first generation millennial immigrant from a similar cultural background was cathartic. I cried for hours. I can only imagine how much more this speaks to Asian Americans/Canadians.

2 years ago 3 0 0 0

0%

2 years ago 13 1 2 0