At @defcon 33, George Hughey (@ecthr0s) and Rohit Mothe (@rohitwas), Senior Security Research Managers at MSRC, took us back to the 90s with their talk on the ghost of Internet Explorer in Windows: MapUrlToZone.
They uncovered how this legacy API, used by Outlook, Office,…
At @defcon, the MSRC team had a great time connecting with the security community and cheering on Microsoft employees, MVRs, and other Microsoft security researchers as they shared their expertise through presentations and hands-on collaboration.
#DEFCON#DEFCON33
To help protect against NTLM relay attacks, we’ve enabled Extended Protection for Authentication (EPA) by default in Windows Server 2025. This update strengthens key services like Exchange Server, Active Directory Certificate Services (AD CS), and LDAP, making identity compromise…
CanSecWest Presentation:
Rolling in the Dough: How Microsoft Identified and Remediated a Baker’s Dozen of Security Threats in the Windows DNS Server
George Hughey, Microsoft
secwest.net
Tuesday saw the release of fixes for four vulnerabilities I discovered (CVE-2022-26801, CVE-2022-26802, CVE-2022-26803, CVE-2022-24536). Go check them out! msrc.microsoft.com/update-guide/r…
It's long been assumed that there are no nontrivial reflected amplification attacks using TCP—prior attacks are UDP or simply TCP SYNs. In our just-now-accepted @USENIXSecurity 2021 paper, we apply a genetic algorithm to discover 5 reflected TCP amplification attacks + variants.
Just posted our slides from BlueHat IL 2020 at github.com/Kkevsterrr/con…! Huge thank you to @tom41sh and the rest of the BlueHat team, we were really honored to be there :)
8K Followers 151 FollowingFor contact in the security community. NOTE: All the tweets are totally my personal opinions, not about any of my current employer stuff.
5K Followers 1K Followingsome security stuff, opinions are based on experimental thought patterns resulting in delusional yet fun life choices. @[email protected]
19 Followers 600 FollowingBug hunter | CTF player | Cybersecurity enthusiast | Exploring AI & hacking the world, one challenge at a time 🚀 | Sharing exploits, CTF write-ups & security i
3K Followers 495 FollowingLeader of the Zero Day Initiative. Pwn2Own organizer and adjudicator. Trafficker of export-controlled intrusion software. Bug Hunter.
26K Followers 1K FollowingSenior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
8K Followers 151 FollowingFor contact in the security community. NOTE: All the tweets are totally my personal opinions, not about any of my current employer stuff.
5K Followers 1K Followingsome security stuff, opinions are based on experimental thought patterns resulting in delusional yet fun life choices. @[email protected]
61K Followers 804 FollowingSecurity Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
49K Followers 339 FollowingSecurity researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
44K Followers 3K FollowingChoose disfavour where obedience does not bring honour.
I do math. And was once asked by R. Morris Sr. : "For whom?"
@[email protected]
5K Followers 469 FollowingSenior principal scientist@AWS & emeritus prof@UMD. Programming languages and security. Cedar https://t.co/5X4WKErcqQ. Inactive: see my WWW for new location
47K Followers 2K FollowingChief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
3K Followers 495 FollowingLeader of the Zero Day Initiative. Pwn2Own organizer and adjudicator. Trafficker of export-controlled intrusion software. Bug Hunter.
333 Followers 736 Followinghacker | hardware builder | researcher | DEF CON Goon
Opinions are mine.
I do vuln research and embedded security. Sometimes with a dash of crypto. | They/them
674 Followers 1K FollowingSecurity Research at Microsoft, in my spare time I try to ████████████ but █████ has done ████ to it. Making beats drop and calc.exe's pop. :)
873K Followers 84 Followingcelebrating wins, wholesome, funny, and girly things :) waking up every day is a win, be proud of yourself 🫶 @jasminericegirl
57K Followers 874 FollowingBuilding communities one event at a time. Thirteen years, over eight hundred events, and we're just getting started.
@[email protected]
732 Followers 2K FollowingI'm a security guy, and a proponent of the rule of law. Nothing is perfect, but better is better. #infosec #security #secdevops
425 Followers 677 FollowingSr. Game Designer on Disney Lorcana. Formerly WotC, Funko, ~
About me: Even numbers, cool toned colors, major chords, streamlined designs. (he/him)