dr.chaos

~/blog

Articles

Every transmission from the lab — adversarial AI research, offensive security tutorials, threat analysis, and the legacy Dr. Chaos archive.

231 articles

Coaches Corner with Brandon Robinson

Brandon Robinson discusses the next steps for the IT professional to elevate their career. Listen to his tips on how to think outside the box and map your career to the next level.Listen on Soundcloud: https://soundcloud.com/drchaos-podcast/coaches-corner-with-brandon-robinson

Aamir Lakhani1 min read

Your vendor is making AI better

On this week's podcast, my co-host Tony G is back! Join us as we interview Jack Chan product manager at Fortinet. Jack discusses his thoughts on how we have seen artificial intelligence and machine learning evolve in products offered by OEMs and other vendors in the last year and what benefits we ca

Aamir Lakhani1 min read

Interview with a new CISO, Keith Rayle

Keith Rayle left his perfect job to take on the role of a CISO. What could possibly go wrong in a brand new city, brand new job, and a worldwide pandemic impacting every part of their organization.Listen to our latest podcast on Soundcloud: https://soundcloud.com/drchaos-podcast/podcast-the-new-cis

Aamir Lakhani1 min read

Study Finds One-Quarter of All Coworking Employees' Data Is Threatened

Coworking spaces offer remote workers a comfortable and productive atmosphere, but they may be unsafe. A recent survey from Clutch showed that 23% of coworking employees said they face safety and security issues in their workspace.A coworking space is an area where employees from various companies c

Aamir Lakhani3 min read

Being a CISO - The Right Place

Being a CISO - The Right PlaceWritten by Keith RayleLinkedIn: https://www.linkedin.com/in/keith-rayle-1aa8241/I was recently brought on board to lead the security effort for a company, and the choice was not easy from a personal perspective. I would have to leave warm, sunny Florida for Illinois, an

Aamir Lakhani6 min read

Walking Around the RSA 2020 USA Conference

The RSA USA Conference was one of the first cybersecurity conferences I ever attended years ago. I still feel nostalgic walking through the innovation sandbox, attending keynotes delivered from the top thinkers in the industry, and listening to sessions covering every major topic.Star Trek’s very ow

Aamir Lakhani4 min read

Pegasus - Hacker software to attack you

Pegasus (also known as Trident) is a red team tool (software package) that some people have classified as malware and/or spyware. Basically it empowers the offense security team with very strong capabilities and was created by the Israeli cyber-security firm NSO Group.The software primary targets Ap

Aamir Lakhani2 min read

3 Cybersecurity Trends To Look Forward to in 2020

Closing out 2019, one of the worst years so far for data breaches which saw nearly 8 billion records exposed. Going into 2020, cybersecurity workers are dealing with more threats than ever and often handling greater quantities of cloud-stored data, all while strained by a growing skills gap that s

Aamir Lakhani3 min read

Wyze Data Breach Affects 2.4 Million People

Wyze, a brand best known for their budget security cameras, announced in a post on the brand’s forums that it had suffered what is likely to be the last major data breach of the 2010s. According to the company, more than 2.4 million records were exposed after a database containing user information w

Aamir Lakhani3 min read

5 Mistakes to Avoid When Disclosing Your Data Breach

It's a nightmare scenario, one that's more and more common every year as data becomes more valuable — despite your best defenses, some of the confidential data your company holds on to was accessed by hackers or cyber criminals. While the breach is in the past, there's a lot your company can still

Aamir Lakhani3 min read

A Walk Down Adversary Lane – ColdFusion V8

As I continue my OSCP journey I have popped a few more boxes since my last blog. It’s been about a month or two so I figure I would write another one describing how I went from initially exploiting a directory traversal vulnerability to eventually getting shell access as system on a Windows box ru

Aamir Lakhani5 min read

Installing Silent Trinity (0.4.6)

Silent Trinity is a command and control tool dedicated to hacking into Microsoft Windows systems. The primary function is to remotely control Windows in order to simulate attack scenarios. Silent Trinity can be used for penetration testing, network connection, and vulnerability testing, and would

Aamir Lakhani5 min read