‘Shadow Brokers’ dump of NSA tools includes new Windows exploits

Earlier this year “The Shadow Brokers” — an entity claiming to have stolen hacking tools from the NSA then offering them for sale — seemed to pack up shop, but the group has continued on. Today, it made a new post that contained a number of working exploits for Windows machines running everything from XP […]

WikiLeaks won’t share CIA exploits unless companies meet terms

WikiLeaks offered to work with tech companies to patch the CIA’s leaked security exploits, but there has been a whole lot of silence ever since. Why? That depends on who you ask. Motherboard sources claim that WikiLeaks “made demands” of the companies before it would hand over necessary details of the vulnerabilities, including a requirement […]

Google says it’s already fixed many exploits from WikiLeaks’ CIA document dump

Google has fixed many of the vulnerabilities in its Chrome and Android platforms identified in yesterday’s WikiLeaks dump of CIA documents, the company said today. In a statement provided to Recode by Heather Adkins —Google’s Director of Information Security and Privacy — Google said that it was “confident that security updates and protections in both […]

New ASLR-busting JavaScript is about to make drive-by exploits much nastier

(credit: xxdigipxx) For a decade, every major operating system has relied on a technique known as address space layout randomization to provide a first line of defense against malware attacks. By randomizing the computer memory locations where application code and data are loaded, ASLR makes it hard for attackers to execute malicious payloads when exploiting […]