3 Google Play Store Apps Exploit Android Zero-Day Used by NSO Group

Watch out! If you have any of the below-mentioned file managers and photography apps installed on your Android phone—even if downloaded from the official Google Store store⁠—you have been hacked and being tracked.

These newly detected malicious Androi… Continue reading 3 Google Play Store Apps Exploit Android Zero-Day Used by NSO Group

Landry’s Restaurant Chain Suffers Payment Card Theft Via PoS Malware

Landry’s, a popular restaurant chain in the United States, has announced a malware attack on its point of sale (POS) systems that allowed cybercriminals to steal customers’ payment card information.

Landry’s owns and operates more than 600 bars, resta… Continue reading Landry’s Restaurant Chain Suffers Payment Card Theft Via PoS Malware

LNK Toolmarks

Matt posted a blog article a while back, and I took interest in large part because it involved an LNK file.  Matt provided a hash for the file in question, as well as a walk-through of his “peeling of the onion”, as it were.  However, one of … Continue reading LNK Toolmarks

Posted in Uncategorized

What is "best"?

A lot of times I’ll see a question in DFIR-related social media, along the lines of, “what is the best tool to do X?”  I’ve seen this a couple of times recently, perhaps the most recent being, “what is the best carving tool?”  Nothing was sta… Continue reading What is "best"?

Posted in Uncategorized

Apple Opens Its Invite-Only Bug Bounty Program to All Researchers

As promised by Apple in August this year, the company today finally opened its bug bounty program to all security researchers, offering monetary rewards to anyone for reporting vulnerabilities in the iOS, macOS, watchOS, tvOS, iPadOS, and iCloud to the… Continue reading Apple Opens Its Invite-Only Bug Bounty Program to All Researchers

Google Offers Financial Support to Open Source Projects for Cybersecurity

Besides rewarding ethical hackers from its pocket for responsibly reporting vulnerabilities in third-party open-source projects, Google today announced financial support for open source developers to help them arrange additional resources, prioritizing… Continue reading Google Offers Financial Support to Open Source Projects for Cybersecurity

LifeLabs Paid Hackers to Recover Stolen Medical Data of 15 Million Canadians

LifeLabs, the largest provider of healthcare laboratory testing services in Canada, has suffered a massive data breach that exposed the personal and medical information of nearly 15 million Canadians customers.

The company announced the breach in a pr… Continue reading LifeLabs Paid Hackers to Recover Stolen Medical Data of 15 Million Canadians