Drastically Reduced Xiaomi Bootloader Unlock Policy Raises Questions Over Device Ownership

Xiaomi has further restricted bootloader unlocking to just one device per user per year, significantly hindering custom ROM development and reinforcing user dependence on its proprietary HyperOS ecosystem. Android Police reports: Roughly a year ago, Xi… Continue reading Drastically Reduced Xiaomi Bootloader Unlock Policy Raises Questions Over Device Ownership

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger a denial-of-service (DoS) condition.
The out-of-bounds reads vulnerability is tracked a… Continue reading LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

Posted in Uncategorized

New ‘All-Optical’ Nanoscale Sensors of Force Access Previously Unreachable Environments

ZipNada shares a report from Phys.org: In a paper published today in Nature, a team led by Columbia Engineering researchers and collaborators report that they have invented new nanoscale sensors of force. They are luminescent nanocrystals that can chan… Continue reading New ‘All-Optical’ Nanoscale Sensors of Force Access Previously Unreachable Environments

Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

Microsoft has announced that it’s making an “unexpected change” to the way .NET installers and archives are distributed, requiring developers to update their production and DevOps infrastructure.
“We expect that most users will not be directly affected… Continue reading Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

Posted in Uncategorized

SwaetRAT Delivery Through Python, (Fri, Jan 3rd)

We entered a new year, but attack scenarios have not changed (yet). I found a Python script with an interesting behavior[1] and a low Virustotal score (7/61). It targets Microsoft Windows hosts because it starts by loading all libraries required to call Microsoft API Calls and manipulate payloads:

Continue reading SwaetRAT Delivery Through Python, (Fri, Jan 3rd)

Posted in Uncategorized