Latest Articles
Introducing IOXY: an open-source MQTT intercepting proxy
Uncategorized
TL;DR: IOXY is an open source MQTT intercepting proxy, developed by NVISO for our IoT pentest needs, and now available…
IoT hacking field notes #2: Using bind mounts to temporarily modify read-only files
Uncategorized
TL;DR: The second of our short, IoT-related posts shares a simple trick we use in IoT pentests to temporarily change…
Backdooring Android Apps for Dummies
Uncategorized
TL;DR - In this post, we'll explore some mobile malware: how to create them, what they can do, and how…
Smart Home Devices: assets or liabilities? – Part 1: Security
Uncategorized
This blog post is part of a series, keep an eye out for the following parts! TL;DR - Smart home…
Smart Home Devices: assets or liabilities? – Part 2: Privacy
Uncategorized
TL;DR - Part two of this trilogy of blog posts will tackle the next big topic when it comes to…
Smart Home Devices: assets or liabilities? – Part 3: Looking at the future
Cyber Strategy
This blog post is the last part of a series, if you are interested in the security or privacy of…
Navigating the impact of Wi-Fi FragAttacks: users, developers and asset owners
Uncategorized
Wi-Fi devices are affected by a series of new attacks on the Wi-Fi protocol, known as FragAttacks and released in…
Another spin to Gamification: how we used Gather.town to build a (great!) Cyber Security Game
Awareness
CSI Game hosted on Gather.town platform Let's recap October. Cyber Security Awareness Month. For a cyber awareness enthusiast, it is…
Vulnerability Management in a nutshell
Vulnerability
Introduction Vulnerability Management plays an important role in an organization's line of defense. However, setting up a Vulnerability Management process…
CVE Farming through Software Center – A group effort to flush out zero-day privilege escalations
Red Team
Intro In this blog post we discuss a zero-day topic for finding privilege escalation vulnerabilities discovered by Ahmad Mahfouz. It…
