Tim (Wadhwa-)Brown :donor:

push(@fediverse, "Adversarial Engineer"); # i hack in Perl

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-07-03

Research project on "Practical detections for telecoms" signed off yesterday.

Looking forward to working with our partners on documenting achievable approaches to gathering security telemetry in the transport, core and radio access domains.

One I'm particularly interested in is how we can make better use of NetFlow for signalling.

#detection, #engineering, #telecoms

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-07-01

Talked about my categorisation work on existing TI and RT reporting as well as development of detection use cases in the firewall, AAA, MPLS and telecom signalling (SS7, GTP, Diameter) domains. We looked at categorisation, behaviour prediction and anomaly detection.

Tim (Wadhwa-)Brown :donor: boosted:
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-29

Interesting links of the week:

Strategy:

* enisa.europa.eu/publications/t - EU's 2024 cyber security index
* assets.publishing.service.gov. - HMG cyber security sectoral analysis 2025
* nao.org.uk/wp-content/uploads/ - NAO paper on making UK more resilient
* ncsc.gov.uk/collection/securit - NCSC ideas on protecting data
* wired.com/story/how-to-protest - protest early, protest safely, protest often

Threats:

* ncsc.gov.uk/static-assets/docu - NCSC exposes UMBRELLA STAND
* ncsc.gov.uk/static-assets/docu - ... and SHOE RACK
* cloud.google.com/blog/topics/t - GOOG reports on how Russia is targetting academics

Exploitation:

* sud0ru.ghost.io/windows-inter- - a nice set of posts on Windows IPC's attack surface
* eprint.iacr.org/2025/1042 - whacking Falcons with a hammer
* forums.oracle.com/ords/r/apexd - had your caffeine? seamlessly injecting into Java

Hard hacks:

* skemman.is/handle/1946/50456 - emulating icey routers

Hardening:

* best.openssf.org/Compiler-Hard - calling cc safely
* spiffe.io/docs/latest/spiffe-a - better authentication primitives for bots
* workos.com/blog/mcp-authorizat - bring OAuth to MCP

Nerd:

* metoffice.gov.uk/forms/name-ou - so you want to work in marketing for storms
* activitypub.academy - so you want to learn about how the Fediverse works?

#security, #research

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-28

I was doing some Googling and it looks like people have been playing with CVE => technique in one form or another since about 2017.

Early precursor of mine from 2020:

gist.github.com/timb-machine/4

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-27

Interesting Git repos of the week:

Strategy:

* github.com/timb-machine/securi - I started releasing Portcullis' old security research governance toolkit

Detection:

* github.com/sandflysecurity/san - @SandflySecurity have release scripts for collecting Linux artefacts

Exploitation:

* github.com/stealth/injectso - @steaith demonstrates how to inject .so files into running processes at will
* github.com/NeffIsBack/wsuks - have you ever wanted to MITM WSUS?

Data:

* github.com/public-api-lists/pu - does what it says on the tin

Development:

* github.com/sapdragon/syscalls- - headers for direct syscall invocation

#security, #research, #code

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-26

Interesting links of the week:

Strategy:

* enisa.europa.eu/publications/t - EU's 2024 cyber security index
* assets.publishing.service.gov. - HMG cyber security sectoral analysis 2025
* nao.org.uk/wp-content/uploads/ - NAO paper on making UK more resilient
* ncsc.gov.uk/collection/securit - NCSC ideas on protecting data
* wired.com/story/how-to-protest - protest early, protest safely, protest often

Threats:

* ncsc.gov.uk/static-assets/docu - NCSC exposes UMBRELLA STAND
* ncsc.gov.uk/static-assets/docu - ... and SHOE RACK
* cloud.google.com/blog/topics/t - GOOG reports on how Russia is targetting academics

Exploitation:

* sud0ru.ghost.io/windows-inter- - a nice set of posts on Windows IPC's attack surface
* eprint.iacr.org/2025/1042 - whacking Falcons with a hammer
* forums.oracle.com/ords/r/apexd - had your caffeine? seamlessly injecting into Java

Hard hacks:

* skemman.is/handle/1946/50456 - emulating icey routers

Hardening:

* best.openssf.org/Compiler-Hard - calling cc safely
* spiffe.io/docs/latest/spiffe-a - better authentication primitives for bots
* workos.com/blog/mcp-authorizat - bring OAuth to MCP

Nerd:

* metoffice.gov.uk/forms/name-ou - so you want to work in marketing for storms
* activitypub.academy - so you want to learn about how the Fediverse works?

#security, #research

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-26

This is now a thing. I spent some time developing the idea into predictive analytics last night.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-26
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-26

No surprise that they've been on Warp.

Fun fact, they used to run a BBS.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-26

Can't remember who recommended them, but really enjoying The Black Dog:

en.wikipedia.org/wiki/The_Blac

Old school techno and ambient from Sheffield.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-24

Today's unrelated discovery... we have trees on our property with preservation orders ❤️ .

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-24

Was somewhat amused that the new one forces everyone to have different alarm codes. Not sure telling people that the code is already in use makes too much sense but \o/.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-24

Spent the day installing a new security system for my Mum. I wish I'd known earlier that the old one was on 433MHz. She was somewhat horrified with what I could do with it.

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-22

God sighed...

"echo 'DELETE USER trump; DROP TABLE earth_v7686786' | mysql; sync && sync && reboot" they typed.

And the experiment was over, LLMs didn't make good Presidents of any world, free or otherwise.

#microfiction

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-22

"%SecureBoot-A-board_type: Secure boot - Board detected as a DEVELOPMENT board. Images signed with a DEVELOPMENT KEY are supported on this board" 👀

Tim (Wadhwa-)Brown :donor: boosted:
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-22

Interesting links of the week:

Strategy:

* gov.uk/government/publications - HMG strategic defence review
* gitlab.gnome.org/GNOME/libxml2 - libxml2 vulnerability disclosure takes a new twist
* ncsc.gov.uk/report/impact-ai-c - NCSC look at the impact of AI
* ncsc.gov.uk/blog-post/sausages - is modern tech just a sausage fest?
* eur-lex.europa.eu/legal-conten - EU details the TLPT approach you should be adopting as part of DORA

Detection:

* cradle.sh/ - FOSS TI platform with orchestration
* cisa.gov/sites/default/files/2 - SOC playbooks for IR and VA
* bluevoyant.com/knowledge-cente - sample IR plans
* incidentresponse.com/mini-site - sample IR playbooks

Bugs:

* synacktiv.com/en/publications/ - attacking a Tesla by abusing charging protocols
* coderush.me/hydroph0bia-part1/ - defeating SecureBoot from @CodeRush
* blog.redteam-pentesting.de/202 - reflections on trusting KRB5 from @RedTeamPentesting
* proofnet.de/publikationen/kons - yay, someone has poked KDE's IO slaves once more
* labs.watchtowr.com/is-b-for-ba - @watchtowrcyber poke SiteCore

Exploitation:

* perldoc.perl.org/perlsec#Algor - attacking Perl
* blog.trailofbits.com/2025/06/1 - shooting yourself in the foot with Go

Hard hacks:

* openpa.net/qemu_pa-risc_emulat - emulating PA-RISC
* research.birmingham.ac.uk/en/p - beware the SIM in your pocket

Hardening:

* ainfosec.com/tnok-next-generat - knock, knock, who is there?

#security, #research

Tim (Wadhwa-)Brown :donor: boosted:
2025-06-22

The aliens who mined the far side of the moon were kind of apologetic when we called them on it. In their words “If you liked it, you should have put a base on it”.

We’re out the ore, but their planet has become a lucrative fan of our pop music.

#Tootfic #MicroFiction #PowerOnStoryToot

Tim (Wadhwa-)Brown :donor: boosted:
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-22

Interesting Git repos of the week:

Detection:

* github.com/hdm/ctail - tail CA transparency logs with @hdm
* github.com/sgInnora/sharpeye - another Linux EDR
* github.com/HullaBrian/COMmander - enrich Windows RPC events

Exploitation:

* github.com/e-ago/bitcracker - BitLocker cracker
* github.com/Moopinger/smugglefu - HTTP downgrade fuzzer
* github.com/Ignitetechnologies/ - Windows LPE playbook
* github.com/giuliano108/SeBacku - elevate/collect via SeBackupPrivilege
* github.com/adgaultier/caracal - sneaky bees
* github.com/v-p-b/xer - encoding h3x with @buherator

Hard hacks:

* github.com/zhuowei/cheese - PoC for CVE-2025-21479, affecting Adreno A7xx (Snapdragon 8 Gen 1 / XR2 Gen 2 and newer) devices
* github.com/tomasz-lisowski/sim - evaluate SIM card security

#security, #code, #research

Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2025-06-21

As usual, @haxrob's reporting on Linux malware really is excellent:

* haxrob.net/bpfdoor-past-and-pr
* haxrob.net/bpfdoor-past-and-pr

More proof if it were needed that Linux targetting threat actors have been hanging around for the last decade or two but largely avoided the limelight.

#threatintel, #linux, #ebfdoor

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst