# infosec

Information security (INFOSEC) is the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and availability.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64

DevFeed: [Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64](<https://devfeed.tech/articles/competing-in-pwn2own-ics-2022-miami-exploiting-a-zero-click-remote-memory-corruption-in-iconics-genesis64-39716.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2023/05/05/competing-in-pwn2own-ics-2022-miami-exploiting-a-zero-click-remote-memory-corruption-in-iconics-genesis64/>)

Author: Axel "0vercl0k" Souchet

Published: 2023-05-05T15:00:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [infosec](<https://devfeed.tech/topics/infosec.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [0-click-remote-code-execution](<https://devfeed.tech/tags/0-click-remote-code-execution.md>), [cve-2022-33318](<https://devfeed.tech/tags/cve-2022-33318.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [genbroker64-exe](<https://devfeed.tech/tags/genbroker64-exe.md>), [genesis64](<https://devfeed.tech/tags/genesis64.md>), [iconics](<https://devfeed.tech/tags/iconics.md>), [iconics-genesis64](<https://devfeed.tech/tags/iconics-genesis64.md>), [ics](<https://devfeed.tech/tags/ics.md>), [icsa-22-202-04](<https://devfeed.tech/tags/icsa-22-202-04.md>), [memory](<https://devfeed.tech/tags/memory.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [paracosme](<https://devfeed.tech/tags/paracosme.md>), [pwn2own](<https://devfeed.tech/tags/pwn2own.md>), [pwn2own-2022](<https://devfeed.tech/tags/pwn2own-2022.md>), [pwn2own-miami](<https://devfeed.tech/tags/pwn2own-miami.md>), [remote](<https://devfeed.tech/tags/remote.md>), [zdi-22-1041](<https://devfeed.tech/tags/zdi-22-1041.md>), [zero-click](<https://devfeed.tech/tags/zero-click.md>)

### AI overview

A participant recounts preparing for and demonstrating a winning zero-click remote entry at the 2022 Pwn2Own ICS competition in Miami. The article focuses on exploiting a memory-corruption vulnerability in ICONICS Genesis64 software running on Windows.

### Source excerpt

🧾 Introduction After participating in Pwn2Own Austin in 2021 and failing to land my remote kernel exploit Zenith (which you can read about here), I was eager to try again. It is fun and forces me to look at things I would never have looked at otherwise. The one thing I ...

## Threat Modeling for UX Designers: Human-Centered Security

DevFeed: [Threat Modeling for UX Designers: Human-Centered Security](<https://devfeed.tech/articles/human-centered-security-36833.md>)

Original publisher: [Read original article](<https://shostack.org/blog/human-centered-podcast/>)

Author: Adam

Published: 2022-12-14T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [User experience (UX)](<https://devfeed.tech/topics/ux.md>), [Security](<https://devfeed.tech/topics/security.md>), [Usability](<https://devfeed.tech/topics/usability.md>), [infosec](<https://devfeed.tech/topics/infosec.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Mastodon](<https://devfeed.tech/topics/mastodon.md>)

Tags: [mastodon](<https://devfeed.tech/tags/mastodon.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [security](<https://devfeed.tech/tags/security.md>), [usability](<https://devfeed.tech/tags/usability.md>), [ux](<https://devfeed.tech/tags/ux.md>)

### AI overview

Adam Shostack discusses human-centered security and threat modeling for UX designers on Heidi Trost's podcast. The article argues that usability expertise can improve security, including the discoverability and default setup of MFA and 2FA.

### Source excerpt

Threat Modeling for UX Designers with Adam Shostack on Heidi Trost's podcast

## (Technical) Infosec Core Competencies

DevFeed: [(Technical) Infosec Core Competencies](<https://devfeed.tech/articles/technical-infosec-core-competencies-30199.md>)

Original publisher: [Read original article](<https://www.netmeister.org/blog/infosec-competencies.html>)

Published: 2021-06-10T03:08:05Z

Content type: article

Language: en

Sources: [Signs of Triviality](<https://devfeed.tech/sources/signs-of-triviality.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [core](<https://devfeed.tech/tags/core.md>), [information](<https://devfeed.tech/tags/information.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

An incomplete list of technical competencies that people working in information security would benefit from knowing.

### Source excerpt

An incomplete list of things just about anybody working in Information Security would benefit from knowing.

## Lost Infosec Battles

DevFeed: [Lost Infosec Battles](<https://devfeed.tech/articles/lost-infosec-battles-30212.md>)

Original publisher: [Read original article](<https://www.netmeister.org/blog/lost-infosec-battles.html>)

Published: 2020-11-06T15:44:27Z

Content type: opinion

Language: en

Sources: [Signs of Triviality](<https://devfeed.tech/sources/signs-of-triviality.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>)

Tags: [infosec](<https://devfeed.tech/tags/infosec.md>)

### AI overview

The article discusses seven information-security battles that have been lost but continue to receive effort.

### Source excerpt

7 battles #infosec has lost but we keep wasting efforts on trying to fight again and again nonetheless.

## The Uber CSO indictment

DevFeed: [The Uber CSO indictment](<https://devfeed.tech/articles/the-uber-cso-indictment-37012.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-uber-cso-indictment/>)

Author: Adam

Published: 2020-08-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>), [ftc](<https://devfeed.tech/tags/ftc.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [law](<https://devfeed.tech/tags/law.md>)

### AI overview

An analysis of the Uber CSO indictment and Mark Rasch's essay on concealing and failing to report a data breach. The article emphasizes due process for Joe Sullivan and argues that the case may make organizations and lawyers more cautious about breach disclosures, potentially reducing their usefulness for learning from mistakes.

### Source excerpt

Thoughts on Mark Rasch's essay, Conceal and Fail to Report - The Uber CSO Indictment

## Threat Modeling Thursday: The Human Element

DevFeed: [Threat Modeling Thursday: The Human Element](<https://devfeed.tech/articles/threat-modeling-thursday-the-human-element-37087.md>)

Original publisher: [Read original article](<https://shostack.org/blog/tmt-the-human-element/>)

Author: Adam

Published: 2020-01-09T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>)

Tags: [infosec](<https://devfeed.tech/tags/infosec.md>), [podcast](<https://devfeed.tech/tags/podcast.md>)

### AI overview

The author joined Caroline Wong on the Humans of Infosec Podcast to discuss the human element of threat modeling.

### Source excerpt

I joined Caroline Wong on the Humans of Infosec Podcast to discuss The Human Element of Threat Modeling.

## Resources for Infosec Skillbuilding

DevFeed: [Resources for Infosec Skillbuilding](<https://devfeed.tech/articles/resources-for-infosec-skillbuilding-36955.md>)

Original publisher: [Read original article](<https://shostack.org/blog/resources-for-infosec-skillbuilding/>)

Author: Adam

Published: 2018-12-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>)

Tags: [book](<https://devfeed.tech/tags/book.md>), [featured](<https://devfeed.tech/tags/featured.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [list](<https://devfeed.tech/tags/list.md>), [resources](<https://devfeed.tech/tags/resources.md>)

### AI overview

The author thanks Digital Guardian for featuring The Threat Modeling Book in its list of resources for InfoSec skillbuilding and notes that the book has remained useful over time.

### Source excerpt

The Threat Modeling Book has been featured on a list of resources by Digital Guardian.

## Threat Modeling and Architecture

DevFeed: [Threat Modeling and Architecture](<https://devfeed.tech/articles/threat-modeling-and-architecture-37024.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-and-architecture/>)

Author: Adam

Published: 2017-09-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [software-architecture](<https://devfeed.tech/tags/software-architecture.md>)

### AI overview

The article examines how threat modeling and software architecture both use system models to reason about properties, tradeoffs, design choices, and potential problems. It presents a four-step threat-modeling process and discusses how the two practices can inform each other.

### Source excerpt

[no description provided]