RSSAmplifier

Blog

MalwareTech

A mix of in-depth nuanced takes on current events and highly technical original research by Marcus Hutchins. I cover a wide array of topics such as vulnerability research, threat intelligence, national security, reverse engineering, and Windows internals.

malwaretech.comRSS feed ↗10 posts

Latest posts

ComoDoS - Exploiting a Remote Kernel Vulnerability in Comodo Internet Security

Sometimes firewall stops attackers, sometimes attackers stop firewall. analyzing a zero-day vulnerability in Comodo Internet Security's Firewall driver.

Passively Downloading Malware Payloads Via Image Caching

Detailing an improved Cache Smuggling technique to turn 3rd party software into passive malware downloader.

Every Reason Why I Hate AI and You Should Too

maybe it's anti-innovation, maybe it's just avoiding hype. But one thing is clear, I'm completely done with hearing about AI.

The US Needs A New Cybersecurity Strategy: More Offensive Cyber Operations Isn't It

For a long time Chinese hackers have been operating in the grey area between espionage and warfare. The US has been struggling to defend its networks, but increasing offensive cyber operations in unlikely to help.

CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6

Performing a root cause analysis & building proof-of-concept for CVE-2024-38063, a CVSS 9.8 Vulnerability In the Windows Kernel IPv6 Parser

Bypassing EDRs With EDR-Preloading

Evading user mode EDR hooks by hijacking the AppVerifier layer

Silly EDR Bypasses and Where To Find Them

Abusing exception handlers to hook and bypass user mode EDR hooks.

An Introduction to Bypassing User Mode EDR Hooks

Understanding the basics of user mode EDR hooking, common bypass techniques, and their limitations.

It might Be Time to Rethink Phishing Awareness

Phishing awareness can be a powerful security tool, or a complete disaster. It all hinges on how you implement it.

A Realistic Look at Implications of ChatGPT for Cybercrime

Analyzing ChatGPT's capabilities and various claims about how it will revolutionize cybercrime.