peter bassill · operator
home
$ grep -l "category: threats" articles/*.txt

Threats.

Threats 31 articles
2021·08·17 Pegasus, and the question for UK boards we have been pretending not to face The Pegasus Project disclosures last month confirmed what specialists have privately known for years: commercial spyware is a mature, well-funded industry, and its customer list includes governments most UK firms do business with. The board question is what to do about it. 7 min 2021·07·17 From the embedded browser to a shell on a smart TV Part 3 of 4. From the AIT-triggered page load to a shell prompt. CVE-2020-6383, shell.js, SMACK, and the public Samsung Q60T root chain. 11 min 2021·06·19 The lab rig: re-broadcasting HbbTV into a test bench Part 2 of 4. What I built on the bench to study HbbTV attacks safely. Hardware, software, the AIT injection step, and the legal bit (do not transmit DVB into open air). 9 min 2021·06·10 Colonial Pipeline: the CNI lesson the UK should not need to learn the hard way Five weeks after the DarkSide ransomware attack on Colonial Pipeline shut down 45% of US East Coast fuel supply, what UK critical national infrastructure boards should be doing about it. 7 min 2021·05·22 The TV in the corner: what HbbTV actually is Part 1 of 4. A primer on HbbTV from a security researcher's bench. Why I think the smart TV mounted on the meeting-room wall is the most under-considered attack surface in any UK office in 2021. 7 min 2021·04·06 Hafnium and the patch-window asymmetry Five weeks after the Microsoft Exchange ProxyLogon disclosure, the dust is settling on what may turn out to be the most consequential mass-exploitation event of the decade. What it teaches us is structural, not tactical. 7 min
← prev
1 2
next →

full archive  ·  ai · policy · defence · privacy · opinion