Search
09.14.2021 | 5'' read
Legal trouble for ex-NSA mercenary hackers
According to publicly available data, there have been 66 documented zero-day attacks so far in 2021. The bulk of those target code from Microsoft, Google and Apple. Plus, ex-NSA mercenary hackers in legal crosshairs for security work in Dubai.
Read05.27.2021 | 22'' read
Q&A: Heather Adkins, director of information security, Google
What follows is the transcript of a Security Conversations podcast interview with Google security leader Heather Adkins. We discuss her role at the search advertising giant, the priorities around securing the software supply chain, expanding the concept of zero-trust and the future of modern desktop computing. It has been edited for brevity and clarity.
Read04.12.2021 | 6'' read
Sandboxing and that Zoom zero-click exploit chain
My latest piece SecurityWeek piece on the economics (and narrow shelf life) of memory corruption mitigations has kickstarted an active discussion on the future of sandboxing to disrupt the economy of software exploitation. Plus, that Pwn2Own Zoom zero-click exploit chain should scare us all.
Read03.29.2021 | 6'' read
On disrupting .gov malware attacks
A major scoop by MIT Technology Review confirms what I've suspected all along -- Google's public flex came long after intense conversations about disruting and outing a "friendly" FEYE counter-terrorism campaign. Plus, a new podcast with Nico Waisman and a surge in firmware attacks.
Read03.23.2021 | 5'' read
Dark holes and apex threat actors
Google published a remarkable report on a true apex APT actor that burned through 11 zero-days in less than a year, but the absence of basic information to help defenders leads to a dark hole of balkanized research output. Plus, Kim Zetter's new journalism project.
Read03.15.2021 | 5'' read
Chrome, monoculture and the boll weevil
Chromium is a monoculture in browsers and the risks are being amplified via a surge in zero-day Chrome attacks. Have we learned enough from the lessons of the boll weevil? Plus, Microsoft's business ambitions are starting to clash with assurance realities.
Read