Search/defcon
Vendor

defcon

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
def con 27 firmware
Connections
7 relationships
Una RCE in Apple CarPlay consente l’accesso root ai sistemi di infotainment dei veicoli
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comSep 11, 2025extracted
Hacker Alleges Russian Government Role in Kaseya Cyber-Attack
A hacker involved in the supply chain attack that targeted IT service provider Kaseya in July 2021 has claimed that he was coerced by the Russian government. Yaroslav Vasinskyi, a former affiliate of the REvil ransomware syndicate known as ‘Rabotnik,’ serves a sentence of over 13 years in US federal prison at the Federal Correctional Institution, Danbury (FCI Danbury), Connecticut. In a six-month conversation with Jon DiMaggio, chief security strategist at Analyst1 and author of the ‘Ransomware Diaries’ series, where he investigates the ransomware ecosystem, Vasinskyi revealed he tried to leave REvil several times for “moral” reasons but was blackmailed into preparing the Kaseya attack before leaving. Vasinskyi claimed REvil has ties with the Russian government and that the people who blackmailed him to keep conducting cyber-attacks were likely from Kremlin-linked government institutions. DiMaggio unveiled his findings during a talk he gave alongside Trellix’s head of threat intelligence, John Fokker, at the DEFCON 33 event in Las Vegas on August 9. The full written version of his investigation was published in the Ransomware Diaries Volume 7 report on August 9. REvil Recruitment, Moral Crisis and Attempted Exit Vasinskyi started working for REvil in early 2019 when he was “recruited” by a member of the group known as ‘Lalartu’ after finding a vulnerability in a ConnectWise server that was linked to around 1000 compromised PCs with various command-and-control (C2) functions. He operated out of Poland, with a few trips to Ukraine while working with REvil. During his email and phone conversations with DiMaggio, Vasinskyi claimed he attempted to leave REvil in March 2020 out of the belief that the deaths of this girlfriend's father and his grandmother were sanctioned against him for conducting cybercrime activities. Additionally, Vasinskyi told DiMaggio that he “grew uneasy” and felt moral regrets after alleged REvil cyber-attacks against a Baptist church and a hospital, the latter reportedly led to a patient dying. After asking REvil’s kingpin, an individual using the moniker UNKN, about this alleged death, Vasinskyi was told that although it was not an intended consequence, it ended up with “good publicity” for the ransomware gang. While further investigation by DiMaggio seemed to indicate that the deadly cyber-attack against a hospital was likely conducted by Ryuk instead of REvil, “the casual dismissal of human death as good advertising’ disgusted Vasinskyi,” the security researcher wrote. “It confirmed what he already feared, that the operation he had once rationalized as transactional had evolved into something colder, more detached, and more dangerous. Grieving, exhausted, and angry, Vasinskyi stepped away from REvil.” Surveillance and Blackmail However, Vasinskyi said his entire life was then under surveillance by some high-level institution. When he travelled to Kyiv’s Boryspil airport in January 2021, he was stopped at passport control by customs, searched and driven out of the airport. According to Vasinskyi, he was under pressure from someone connected to Ukrainian law enforcement who held leverage over him. He later disclosed that one of these contacts was a powerful, high-ranking former intelligence officer. The blackmail, Vasinskyi claimed, was politically motivated, not financial. The handler’s influence stretched far beyond Ukraine, hinting at either deep international intelligence ties or a sprawling cross-border corruption network. “Vasinskyi’s worst fear had been confirmed. His ‘old friends’ leveraged their reach and power to create his legal troubles in Kyiv, and now they were using them to control him,” DiMaggio wrote. What they wanted, Vasinskyi said, was for him to continue working with REvil. If he refused, they allegedly threatened to make sure he would go to jail, be tortured and even do harm to his girlfriend and family members. Back in Poland, where Vasinskyi was based, the surveillance continued and his “handlers,” as he called the people pressuring him, were everywhere he went. Kaseya, A Strategic Target According to Vasinskyi, his “handlers” chose Kaseya as his next target “specifically for the cascading access its software provided, seeing an opportunity to inflict maximum damage through the company’s software distribution capabilities to thousands of downstream clients,” DiMaggio wrote. Vasinskyi admitted to DiMaggio that he had entirely prepared the attack himself, from initial access to testing the final payload. However, he did not want to launch it himself and handed the payload delivery phase over to REvil. He also tried several ways to show that he did not execute the attack himself, including: Sending a letter to the FBI before the attack Using speakerphone during conversations with the REvil leadership team so that investigators potentially surveilling him could hear the conversations Showing his face to CCTV cameras while leaving Poland for Ukraine on the day the attack was executed However, none of these pieces of evidence were used in Vasinskyi’s defence and he ultimately submitted a guilty plea. UNKN, the persona behind which someone was running REvil, disappeared after the Kaseya attack, which compromised over 1500 companies across 17 countries and forced schools, pharmacies and entire supermarket chains offline. Kaseya: Three-Tiered Operation with State-Level Handlers While the Kaseya attack was attributed to REvil and a $70m ransom was demanded, Vasinskyi’s account suggests that the ransomware gang’s true role was strictly as a technical contractor, not an operational commander. According to Vasinskyi in DiMaggio’s reporting, REvil was only responsible for the build as an .exe file, nothing more, nothing less. “They provided the weapon, but his handlers gave the order and pulled the trigger. This testimony lays out a three-tiered operational structure, separating REvil’s role as the ransomware provider from Vasinskyi’s as the technical lead tasked with preparing the attack and a third party, his state-level handlers, as the execution team,” DiMaggio explained. “This wasn’t supposed to be about extortion. It was about disruption: crippling downstream systems, collecting intelligence, and gaining access to critical infrastructure,” the researcher added. Additionally, Vasinskyi claimed that while REvil had connections to Russian government authorities, his own handlers were more powerful – operating at a level even the ransomware group couldn’t reach. This suggested that his troubles stemmed not just from cybercriminal ties, but from entanglement with high-ranking figures whose influence eclipsed even that of REvil’s government-linked associates. A theory on Russian cybercrime forums suggested that UNKN might have been Aleksandr Ermakov, a former Russian police officer arrested in July 2021 shortly after UNKN vanished. However, Vasinskyi disputed this, confirming Ermakov was part of REvil but not the only one associated to UNKN. He believes that two people controlled the UNKN account: Ermakov, who took orders, and one who gave them. The true leader, Vasinskyi insisted, remained "Unknown." During his DEFCON talk, Analyst1’s DiMaggio highlighted that, while cybercriminals tend to lie a lot, Vasinskiy seemed to have never lied about things the researcher tested him on. “At this point, he didn't have much to lose. There wasn't really a reason for him to lie to me. He's been sentenced to 13 years and seven months in prison, he's got $16m in restitution to pay and he has no chance of parole," conclude DiMaggio. Photo credits: Felix Mizioznikov / mundissima / Shutterstock.com
infosecurity-magazine.comAug 12, 2025extracted
Online portal exposed car and personal data, allowed anyone to remotely unlock cars
A carmaker’s online dealership portal has been found leaking the private information and vehicle data of its customers. This also meant that anyone with access could remotely break into a car. Researcher Eaton Zveare shared his discovery with TechCrunch. Although he said he has chosen not to disclose the vendor’s name, he revealed that it is a well-known automaker with several popular sub-brands and more than 1,000 dealerships across the United States. Zveare says it wasn’t easy to find the flaw, but once he did, it allowed him to modify the code at the portal’s login page so he could bypass the login security checks. This permitted him to create a new national administrator account. Not only did this allow him to access all the data of these dealerships, he also found a national consumer lookup tool that allowed any logged-in portal user to look-up the vehicle and driver data of that carmaker. Real life tests learned that taking a vehicle’s unique identification number (VIN) from the windshield of a car allowed anyone with access to the portal to look up the name of the owner. It was also possible to pair any vehicle with a mobile account which could then be used to remotely control a car’s functions, such as unlocking the vehicle. Since both a VIN or someone’s first and last name were enough to find and transfer ownership of an account to one under control of an attacker, they would—at least—be able to open the car and steal everything inside. The researcher did not test whether he was able to drive away in it. Although he found no evidence of anyone else exploiting the flaw, the portals were a security nightmare waiting to happen. It even allowed administrator accounts, such as the one he was able to create, access to other dealer systems as if they were that user without needing their logins, and found personally identifiable customer data, some financial information, and telematics systems that allowed the real-time location tracking of rental or courtesy cars. As we have said before, this is exactly the sort of thing the Federal Communications Commission (FCC) wants car manufacturers to make harder for stalkers, not easier. Zveare will be presenting his findings at Defcon. He reported the bugs he found to the car maker, and says it took them a week to fix them. Tips to keep a stalker from tracking your car Not all cars offer these options, and the tips may not apply to your situation, but here are some general tips for people that are afraid they are the target of a stalker: Use the navigation app on your phone (such as Google Maps, Waze, etc), rather than the one built into your car. Do not store places you visit regularly in the car’s navigation. Consider using a VPN when you connect to your car’s hotspot. Find out which devices can access the car or its location data using any “remote access” apps for the car, and remove the devices that are not under your control. Familiarize yourself with the car manufacturer’s privacy policy so you know where your data might be sent. To give you an idea, data might end up with advertisers, law enforcement, service providers, the car manufacturer and its dealers, tech giants like Apple, Google, and Amazon, connected service providers, and government agencies. Keep the software updated to make sure your car is equipped with the latest protection against potential intrusions. If a suspected stalker has been near your vehicle, inspect it thoroughly for trackers and other unfamiliar hardware. Try not to travel alone and always park in a well-lit, busy area if you are concerned about your physical safety. If you have a dashcam that uses cloud storage, check who has access to the images. They can be used to track your movements. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comAug 11, 2025extracted
#DEFCON: AI Cyber Challenge Winners Revealed in DARPA’s $4M Cybersecurity Showdown
After two years of competition, the winners of the AI Cybersecurity Challenge (AIxCC) were revealed at the DEFCON 33 hacking event on August 9. Team Atlanta was revealed as the winning team. The group is a powerhouse collaboration of experts from the Georgia Institute of Technology (Georgia Tech), Samsung Research, the Korea Advanced Institute of Science & Technology and the Pohang University of Science and Technology. They won a $4m prize. Trail of Bits, a New York-based cybersecurity firm specializing in cutting-edge security research, came in second, securing a $3m prize in the high-stakes AI Cyber Challenge. The third best-performing team was Theori, a group of AI researchers and security professionals spanning the US and South Korea, rounding out the podium in Defense Advanced Research Projects Agency’s (DARPA) competitive showcase, with a prize of $1.5m. The three cyber reasoning systems developed by the trio are part of a set of four models that have been open-sourced and are already available for all to use. “The three other models will be made available over the next few weeks,” DARPA director Stephen Winchell said during the announcement session at DEFCON 33. AIxCC: Two Years in the Making Announced at Black Hat 2023 by Perri Adams, program manager at DARPA, AIxCC was a competition for computer scientists, AI experts, software developers and other cybersecurity specialists to create a new generation of AI-powered cybersecurity tools for securing US critical infrastructure and government services. Specifically, DARPA and the Advanced Research Projects Agency for Health (ARPA-H), another US government agency, funded this project to explore whether AI can help find and fix software vulnerabilities more effectively and usher in a future where attacks can be stopped as fast as they are detected. The seven finalists (Team Atlanta, Trail of Bits, Theori, All You Need IS A Fuzzing Brain, Shellphish, 42-b3yond-6ug and Lacrosse) were announced at DEFCON 32 in August 2024 and were awarded $2m each. Tech giants Google, Microsoft, Anthropic, and OpenAI collectively backed the competition with over $1m each in AI model credits, ensuring teams had the computational firepower needed to tackle critical infrastructure security challenges. Speaking before the winners' announcement, Winchell said that DARPA and ARPA-H will inject an additional $1.4m on top of the $29.5m planned for prize money. During a post-announcement press conference, Andrew Carney, program manager for AIxCC, revealed that the additional funding will support finalists in refining their tools for real-world deployment. The distribution of these additional funds will occur in phased increments, subject to the winning teams demonstrating measurable adoption of their tools by key infrastructure organizations. AI-Powered Approaches Patch Flaws Faster at $152 Per Fix During the final phase of AIxCC, conducted over the past year, participating teams were mandated to deploy their systems within a controlled, simulated environment deliberately seeded with flaws introduced by the competition organizers. The seven finalist teams uncovered 54 of the 70 synthetic vulnerabilities intentionally embedded in the challenge, representing a 77% detection rate. This is a significant improvement compared to last year's semifinal round, during which teams discovered only 37% of the known vulnerabilities. They were able to patch 43 of these 54. The seven finalist teams also detected 18 previously unknown real-world flaws that were not planted by organizers and patched 11 of those. These zero-day discoveries highlight the models’ ability to identify critical weaknesses beyond controlled test environments. “We are now in the process of disclosing [these real-world zero-day vulnerabilities] to maintainers,” Carney said on stage. Speed and efficiency were defining strengths. On average, the AI systems patched vulnerabilities in just 45 minutes, a dramatic improvement over traditional manual processes. Jennifer Roberts, director of resilient systems at ARPA-H, told the press that these capacities are particularly important in the healthcare sector, where it takes 491 days on average to patch a vulnerability, compared to 60 to 90 days in other sectors. Additionally, the unit cost for task completion in the competition was quantified at $152, demonstrating a marked cost advantage over traditional human workforce expenditures. “This is the new floor – it will rapidly improve. "To make ourselves safer, we need to make everyone safer. This is the way,” said Carney. Winchell added, “We’re living in a world right now that has ancient digital scaffolding that’s holding everything up. A lot of the code bases, a lot of the languages, a lot of the ways we do business and everything we’ve built on top of it is all incurred huge technical debt over the years.” Prize Money Fuels Future AI Security Research for Top Teams The winning team, Team Atlanta, has achieved success in several hacking competitions and academic conferences. For AIxCC, they mostly used traditional vulnerability discovery methods (e.g. dynamic analysis, static analysis, fuzzing) with OpenAI’s large language models (LLMs), such as o4-mini, GPT-4o and o3. They topped all but one category and discovered the most real-world vulnerabilities out of the seven teams. Asked what his team would do with the money, Taesoo Kim, the team’s chief leader and a Professor at Georgia Tech, said they agreed to offer a big part of the prize money to the institute to help support future developments in AI-powered vulnerability research. The silver medal winner, Trail of Bits, is a small business made up of 10 engineers with deep experience in developing novel software security tools, including their own cyber reasoning system, Buttercup. One of their most notable partners is the UK’s AI Security Institute. For AIxCC, Trail of Bits combined Buttercup and traditional vulnerability discovery methods with LLMs like Anthropic’s Claude Sonnet 4, GPT-4.1 and GPT-4.1 mini. Their achievements include the highest number of unique vulnerability categories, also known as Common Weaknesses and Enumeration categories (CWEs). The third winner, Theori, has a long history of winning security competitions, including eight wins at DEFCON capture the flag finals. While the other two teams combined traditional vulnerability discovery methods like fuzzing, Tyler Nighswander, the team’s Chief Leader, told the press that the majority of their methods were LLM-powered. The team mainly used Claude Sonnet 4, o3 and o4 mini. “Even if you took out the non-AI part of our cyber reasoning system, it would still function,” he explained. Theori’s approach was very cost-efficient – Carney called it “thrifty” – as they achieved the least money spent per vulnerability patched. They also discovered the most Java real-world vulnerabilities. Both Trail of Bits and Theori said the prize money will help support the ventures’ future projects and developments. From Skeptics to Believers: AI Transforms Vulnerability Hunting During the press conference, the three chief leaders of the winning teams emphasized that, while traditional vulnerability discovery methods are still critical to their work, the AIxCC experience has taught them AI could really augment human expertise in ways they hadn’t fully anticipated -despite some of the contenders being skeptical of AI at first. “We hear this word a lot, but what the seven teams have achieved really is groundbreaking,” Theori’s Nighswander said. “Imagine what we could achieve if we combined all of our approaches, it could have significant impact,” Taesoo added. Kathleen Fisher, the director of DARPA’s Information Innovation Office told reporters: “Today, the world is different, because [AIxCC] has fundamentally changed our understanding of what is possible in terms of automatically finding or really, more importantly, fixing vulnerabilities in software.”
infosecurity-magazine.comAug 9, 2025extracted
161: mg
In this episode we talk with MG (https://x.com/MG), the brilliant (and notorious) hacker and hardware engineer behind the OMG Cable. A seemingly ordinary USB cable with extraordinary offensive capabilities. Learn more about MG at: O.MG.LOL Sponsors Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. Support for this show comes from Axonius. Axonius transforms asset intelligence into intelligent action. With the Axonius Asset Cloud, customers preemptively tackle high-risk and hard-to-spot threat exposures, misconfigurations, and overspending. The integrated platform brings together data from every system in an organization’s IT infrastructure to optimize mission-critical risk, performance, and cost measures via actionable intelligence. Covering cyber assets, software, SaaS applications, identities, vulnerabilities, infrastructure, and more, Axonius is the one place to go for Security, IT, and GRC teams to continuously drive actionability across the organization. Bring truth to action with Axonius. Learn more at axonius.com. Attribution Darknet Diaries is created by Jack Rhysider. Assembled by Tristan Ledger. Episode artwork by odibagas. Mixing by Proximity Sound. Theme music created by Breakmaster Cylinder. Theme song available for listen and download at bandcamp. Or listen to it on Spotify. Transcript [START OF RECORDING] JACK: Hey, hey, it’s Jack, host of the show. I am feeling good. I am feeling healthy, strong, fit. I’m in the game. So, I’m coming at you with a second episode this month. Let’s go! Defcon is coming up in a few weeks. I’ll be there. I wouldn’t miss it. You know me. If you don’t know, it’s the premiere hacking conference in Vegas, and I love going because every year something crazy happens. You don’t always know what it’ll be, but you know something is going down somewhere. Like, maybe someone will drop a zero-day live on stage, which will suddenly make us all panic and call home; shut everything down! Or maybe the FBI breaks into someone’s hotel room and arrests someone who they’ve been chasing for a decade. Or maybe someone gives a talk that makes history.
darknetdiaries.comJul 15, 2025extracted