marcograss’ blog
-
1
php 5.6.24 one liner fixed null pointer memory access
-
2
[CVE-2016-6828] Linux kernel tcp related read Use After Free
-
3
A simple bug in Wickr Android I disclosed in 2014
-
4
[CVE-2016-7425] Linux Kernel SCSI arcmsr driver: buffer overflow in arcmsr_iop_message_xfer()
-
5
[CVE-2016-7799/7800/7906] 2 ImageMagick bugs and 1 GraphicsMagick bug
-
6
[NO-CVE] cJSON JSON parser buffer out of bound read
-
7
[CVE-2016-5328/5329] Multiple VMWare Fusion kernel infoleaks (1 in the OS X Host and 1 in the OS X Guest)
-
8
[CVE-2016-4673] Apple CoreGraphics macOS/iOS JPEG memory corruption
-
9
Filetype Classifier with CNN
-
10
squid-cache proxy Out of Bound Write in Gopher
Michael Coppola’s Blog
-
1
NETGEAR unsquashfs.c version 1.3
-
2
DEF CON 20 Presentation
-
3
Anatomy of a SCADA Exploit: Part 2 – From EIP to Shell
-
4
MIT/LL CTF Writeup (Ticket Server)
-
5
Suterusu Rootkit: Inline Kernel Function Hooking on x86 and ARM
-
6
Summercon 2013: Hacking the Withings WS-30
-
7
CSAW CTF 2013 Kernel Exploitation Challenge
-
8
Reverse Engineering a Furby
-
9
CSAW CTF 2015 Kernel Exploitation Challenge
-
10
Google: Stop Burning Counterterrorism Operations
Objective-See’s Blog
-
1
Detecting (Evil) Dylibs
-
2
It's Turtles All The Way Down
-
3
The Mac Malware of 2023
-
4
Analyzing DPRK's SpectralBlur
-
5
Why Join The Navy If You Can Be A Pirate?
-
6
Apple Gets an 'F' for Slicing Apples
-
7
This Meeting Should Have Been an Email
-
8
The Hidden Treasures of Crash Reports
-
9
Restoring Reflective Code Loading on macOS
-
10
The Mac Malware of 2024
Push the Red Button
-
1
Paper and Slides Available for "Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection"
-
2
What I Did on My Summer Vacation
-
3
Virtuoso – Initial Code Release
-
4
Announcing PANDA: A Platform for Architecture-Neutral Dynamic Analysis
-
5
Prebuilt VM for PANDA Now Available
-
6
PANDA, Reproducibility, and Open Science
-
7
Breaking Spotify DRM with PANDA
-
8
PANDA VM Updated
-
9
Replaying Regin in PANDA
-
10
Reproducible Malware Analyses for All
Secunia Research
-
1
Prioritize vulnerability assessment more easily with these simple steps— and intelligence—from Secunia Research
-
2
Application specialist and vulnerability management leaders forge partnership for secure patching process
-
3
Understanding the complexities of vulnerability management
-
4
Avoid missing crucial vulnerability intelligence amid NVD backlog
-
5
Stay secure with top tips to navigate NIS2 compliance
-
6
Cyber-Resilience regulations are here—is your organization ready?
-
7
5 tips to achieve DORA compliance efficiently
-
8
Cybersecurity on the brink: MITRE’s urgent appeal for continuous CVE coverage
-
9
4 lessons on software vulnerabilities from Verizon’s 2025 Data Breach Investigations Report
-
10
Decoding likely exploited vulnerabilities (LEV)— A new metric from NIST
SensePost
-
1
SensePost’s 2026 Artwork
-
2
Process Parameter Poisoning
-
3
Masquerading Windows processes like a DoubleAgent.
-
4
Hack-From-Home Challenge Walk Through
-
5
Making the Perfect Red Team Dropbox (Part 1)
-
6
Being Stubborn Pays Off pt. 2 – Tale of two 0days on PRTG Network Monitor
-
7
The hunt for Chromium issue 1072171
-
8
Resurrecting an old AMSI Bypass
-
9
Multiple Android User Profiles
-
10
Making the Perfect Red Team Dropbox (Part 2)