Introduction I have had the pleasure to work with PSCORE for quite some time now and we recently did a talk at RightsCon together about the cyber security dynamics for human rights in Korea . PSCORE's work spans to many angles surrounding from child labour abuse to internet freedoms
Threat intelligence today is a commodity. It is monetized, gated, and shaped to fit the needs of commercial clients before communities. It's a product, collected and tracked to be baked into security products & to protect share holders. Before it defends anybody, it has to turn a profit.
Yeah that's me, up there, on a stage. Beige all around me, repping McModernism. As a conference speaker and attendee for the better part of a decade, I’ve learned to brace for the usual: soulless, windowless auditoriums and a thick fog of corporate greenwashing and rights-
This research will be discussed at RightsCon 2025: Unveiling North Korea’s cyber threats: safeguarding human rights Sections: Executive Summary Introduction Methodology Sample submission Auditing Malware analysis Email Content analysis Passive DNS & open-source threat intelligence Data Overview Cluster analysis MITRE ATTACK framework Analysis of pre & primary
In my previous two posts about Android emulator bypassing ( Android Network Emulator Bypassing for high security apps - Cashapp, Revolut, Banking, Healthcare, Government etc. & Advanced Android Emulator Bypass Techniques for High-Security Apps: CashApp, Revolut, Healthcare & More ), I discussed methodologies to bypass emulator detection in high-security banking and
There's snow outside today as winter closes in, and it's feeling pretty cozy. I'm sitting here with a coffee, starting to write some proposals for civic society groups, and it's been on my mind to write about the WhatToExpect palaver. In my
A high level summary of this issue is provided below. A deep technical breakdown of the vulnerabilities is provided later on to supporters of my work. Executive Summary This research reveals several critical vulnerabilities in the WhatToExpect application, exposing users’ sensitive personal and reproductive health information to potential misuse
Learn to bypass emulator detection in high-security Android apps using network techniques like SSL unpinning, IP spoofing, and request modification. This guide offers practical methods for intercepting traffic and making emulators look like real devices.
Introduction Apps handling our most sensitive data—whether managing financial transactions in CashApp , Revolut , or other banking platforms, or safeguarding personal records in healthcare applications—often employ robust emulation detection mechanisms . These defenses are designed to thwart unauthorized tampering, reverse engineering, and porting across unapproved environments,…
This is a repost of some critical research I performed back in 2023 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it's owner and thus shut down the website, I'm posting it here to ensure the research I ( solely
This is a repost of some critical research I performed back in 2023 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it's owner and thus shut down the website, I'm posting it here to ensure the research I performed
This is a repost of some critical research I performed back in 2022 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it's owner and thus shut down the website, I'm posting it here to ensure the research I performed