7 ms·
So these vulns weren't needed any more by some 3 letter agency? Or were they being used by someone a 3 letter agency didn't like? Or were about to be? Security
by dlsa 5y ago
So these vulns weren't needed any more by some 3 letter agency? Or were they being used by someone a 3 letter agency didn't like? Or were about to be?
Security warfare is fascinating to watch from the mud huts.
- Waterluvian 5y agoInteresting. Are you conspiracy theorizing or is there a reputable basis for this?
- taylorfinley 5y agoA reputable basis for three letter agencies failing to report zero days? Yeah, it's called Zerodium.
- xvector 5y ago> is there a reputable basis for this? Yes. The NSA has disclosed hoarded zero-days to Microsoft when they have fallen into the hands of people they did not like. See the Shadow Brokers incident [1]: > the critical vulnerabilities for four exploits previously believed to be zero-days were patched in March, exactly one month before a group called Shadow Brokers published Friday's latest installment of weapons-grade attacks Obviously, the problem with this is that the NSA were unaware their zero-days had fallen into enemy hands until the Shadow Brokers very publicly advertised the fact that they had them. [1]: https://arstechnica.com/information-technology/2017/04/purported-shadow-brokers-0days-were-in-fact-killed-by-mysterious-patch/ https://arstechnica.com/information-technology/2017/04/purpo...
- waste_monk 5y agoTake the EternalBlue exploit [1] as an example, NSA had been aware of the vulnerability for years, but only informed Microsoft once it slipped out of their control: "The NSA did not alert Microsoft about the vulnerabilities, and held on to it for more than five years before the breach forced its hand. The agency then warned Microsoft after learning about EternalBlue's possible theft, allowing the company to prepare a software patch issued in March 2017,[19] after delaying its regular release of security patches in February 2017.[20] On Tuesday, March 14, 2017, Microsoft issued security bulletin MS17-010,[21] which detailed the flaw and announced that patches had been released for all Windows versions that were currently supported at that time ... Many Windows users had not installed the patches when, two months later on May 12, 2017, the WannaCry ransomware attack used the EternalBlue vulnerability to spread itself" [1] https://en.wikipedia.org/wiki/EternalBlue#Details https://en.wikipedia.org/wiki/EternalBlue#Details
- sebow 5y agoI chuckle whether i hear that supposedly agencies don't use 0days, especially when we've already had the vault leak to look at.Often times they're the ones putting them out there, researching and exploiting these vulnerabilities. The impressive thing is that they cover almost every device that can be bought.
- Thorrez 5y ago–CVE-2021-33742, a remote code execution bug in a Windows HTML component. Acknowledgements: Clément Lecigne of Google’s Threat Analysis Group –CVE-2021-31955, an information disclosure bug in the Windows Kernel Acknowledgements: Boris Larin (oct0xor) of Kaspersky Lab –CVE-2021-31956, an elevation of privilege flaw in Windows NTFS Acknowledgements: Boris Larin (oct0xor) of Kaspersky Lab –CVE-2021-33739, an elevation of privilege flaw in the Microsoft Desktop Window Manager Acknowledgements: Jinquan(@jq0904) with DBAPPSecurity Lieying Lab
- whereistimbo 5y agoAn interesting tidbits is Google's Project Zero was known to discover zero day used by Western government agencies for counterterrorism operation and made such vulnerability patched.
- atatatat 5y agoAny chance you have a source handy? P.S. your tgs link is 404