<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>GRIMM — Blogs + PR</title><description>GRIMM is a cybersecurity research and consulting firm. We harden critical systems, fortify corporate networks, and innovate across industries.</description><link>https://grimmcyber.com/</link><item><title>Hack the capitol 2023</title><link>https://grimmcyber.com/hack-the-capitol-2023/</link><guid isPermaLink="true">https://grimmcyber.com/hack-the-capitol-2023/</guid><description>GRIMM is a founding sponsor of ICS Village and we’re working on a ton of cool stuff for Hack the Capitol 6.0!</description><pubDate>Wed, 19 Apr 2023 00:00:00 GMT</pubDate><category>AMA</category><category>Critical Infrastructure</category><category>Cyber-Threats</category><category>Cybersecurity</category><category>Events &amp; Conferences</category></item><item><title>Embracing a Culture of Cybersecurity</title><link>https://grimmcyber.com/embracing-a-culture-of-cybersecurity/</link><guid isPermaLink="true">https://grimmcyber.com/embracing-a-culture-of-cybersecurity/</guid><description>Authors: GRIMM CEO Jennifer Tisdale and Senior Principal ResearcherMatt Carpenter Cyber adversaries are becoming more skilled -- and more ruthless.</description><pubDate>Wed, 12 Apr 2023 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>CyPhy™</category><category>Cyber-Threats</category><category>Cybersecurity</category><category>News at GRIMM</category></item><item><title>Questions to ask your penetration testing partner</title><link>https://grimmcyber.com/questions-to-ask-your-penetration-testing-partner/</link><guid isPermaLink="true">https://grimmcyber.com/questions-to-ask-your-penetration-testing-partner/</guid><description>Contributor: Skip Duckwall A penetration test doesn&apos;t stop at simply uncovering vulnerabilities: it goes the next step to actively exploit those vulnerabilities to prove…</description><pubDate>Thu, 30 Mar 2023 00:00:00 GMT</pubDate><category>CyPhy™</category><category>Cybersecurity</category><category>Penetration Testing</category></item><item><title>GRIMM and Ampere Form Alliances and Pledge to Secure Critical Infrastructure</title><link>https://grimmcyber.com/grimm-and-ampere-form-alliances-and-pledge-to-secure-critical-infrastructure/</link><guid isPermaLink="true">https://grimmcyber.com/grimm-and-ampere-form-alliances-and-pledge-to-secure-critical-infrastructure/</guid><description>CEDAR RAPIDS, MI – February 1, 2023 – GRIMM, a forward-looking cybersecurity organization led by industry experts, and Ampere, a security consulting firm specializing in…</description><pubDate>Wed, 01 Feb 2023 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Press Release</category></item><item><title>Does ChatGPT Change Infosec?</title><link>https://grimmcyber.com/does-chatgpt-change-infosec/</link><guid isPermaLink="true">https://grimmcyber.com/does-chatgpt-change-infosec/</guid><description>Author: Sylvia Killinen | Security Engineer | GRIMM It’s been widely commented that ChatGPT generates bullshit.</description><pubDate>Thu, 26 Jan 2023 00:00:00 GMT</pubDate><category>ChatGPT</category></item><item><title>6 Cybersecurity predictions for 2023</title><link>https://grimmcyber.com/6-cybersecurity-predictions-for-2023/</link><guid isPermaLink="true">https://grimmcyber.com/6-cybersecurity-predictions-for-2023/</guid><description>The world is rapidly changing, and with it, so is how we approach and protect ourselves from cybersecurity threats.</description><pubDate>Wed, 04 Jan 2023 00:00:00 GMT</pubDate><category>CyPhy™</category><category>Cyber-Threats</category><category>News</category></item><item><title>Professional evil: a glimpse into the tactics and motivations of malicious threat actors</title><link>https://grimmcyber.com/professional-evil-threat-actors/</link><guid isPermaLink="true">https://grimmcyber.com/professional-evil-threat-actors/</guid><description>There are plenty of articles detailing the uses of patience, creativity, and above all, learning from your failures.</description><pubDate>Wed, 07 Dec 2022 00:00:00 GMT</pubDate><category>CyPhy™</category><category>Cyber-Threats</category></item><item><title>Why You Should Care About Infrastructure Security Month</title><link>https://grimmcyber.com/why-you-should-care-about-infrastructure-security-month/</link><guid isPermaLink="true">https://grimmcyber.com/why-you-should-care-about-infrastructure-security-month/</guid><description>November is Critical Infrastructure Security &amp; Resilience Month, a nationwide effort to raise awareness and reaffirm the commitment to keep our nation&apos;s critical infrastructure secure and resilient.</description><pubDate>Wed, 09 Nov 2022 00:00:00 GMT</pubDate><category>CyPhy™</category><category>Cyber-Threats</category><category>News</category></item><item><title>The power of public-private partnerships</title><link>https://grimmcyber.com/the-power-of-public-private-partnerships/</link><guid isPermaLink="true">https://grimmcyber.com/the-power-of-public-private-partnerships/</guid><description>By: Jennifer Tisdale Public-Private Partnerships (P3) are often thought of in terms of large-scale, long-term relationships between a government agency and a private…</description><pubDate>Wed, 02 Nov 2022 00:00:00 GMT</pubDate><category>CyPhy™</category><category>Cyber-Threats</category><category>News</category><category>Vulnerability Research</category></item><item><title>Ask me anything: what is ransomware?</title><link>https://grimmcyber.com/ask-me-anything-what-is-ransomware/</link><guid isPermaLink="true">https://grimmcyber.com/ask-me-anything-what-is-ransomware/</guid><description>What is &quot;ransomware&quot;? This came up a couple of times for me this morning, so I thought there might be folks who would benefit from an answer.</description><pubDate>Tue, 01 Nov 2022 00:00:00 GMT</pubDate><category>AMA</category><category>CyPhy™</category><category>Cyber-Threats</category></item><item><title>Inside a Quality Assurance Mindset</title><link>https://grimmcyber.com/inside-quality-assurance-mindset/</link><guid isPermaLink="true">https://grimmcyber.com/inside-quality-assurance-mindset/</guid><description>Test Mindset It’s a bit cliche that security testing is just really aggressive QA. However, there’s enough truth there to make it worthwhile for security engineers to…</description><pubDate>Tue, 11 Oct 2022 00:00:00 GMT</pubDate><category>Vulnerability Research</category></item><item><title>No Hardware, No Problem: Emulation and Exploitation</title><link>https://grimmcyber.com/no-hardware-no-problem-emulation-and-exploitation/</link><guid isPermaLink="true">https://grimmcyber.com/no-hardware-no-problem-emulation-and-exploitation/</guid><description>Vulnerability Hunting for Sport If you&apos;ve been following our blog, you might notice some favoritism when it comes to embedded targets...</description><pubDate>Fri, 22 Apr 2022 00:00:00 GMT</pubDate><category>Vulnerability Research</category></item><item><title>Connecting the Dots for Connected Security</title><link>https://grimmcyber.com/connecting-the-dots-for-connected-security/</link><guid isPermaLink="true">https://grimmcyber.com/connecting-the-dots-for-connected-security/</guid><description>By: Naki Carter It is undeniable that organizations, government agencies, and critical infrastructure providers face evolving cyber threats with increased volume and complexity.</description><pubDate>Tue, 05 Apr 2022 00:00:00 GMT</pubDate><category>CyPhy™</category><category>Cyber-Threats</category><category>Hardware</category></item><item><title>Seamlessly Discovering Netgear Universal Plug-and-Pwn (UPnP) 0-days</title><link>https://grimmcyber.com/seamlessly-discovering-netgear-universal-plug-and-pwn-upnp-0-days/</link><guid isPermaLink="true">https://grimmcyber.com/seamlessly-discovering-netgear-universal-plug-and-pwn-upnp-0-days/</guid><description>A Vulnerability Researcher’s Favorite Stress Relief Continuing in our series of research findings involving Netgear1 products,2 this blog post describes a…</description><pubDate>Tue, 16 Nov 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Escalating XSS to Sainthood with Nagios</title><link>https://grimmcyber.com/escalating-xss-to-sainthood-with-nagios/</link><guid isPermaLink="true">https://grimmcyber.com/escalating-xss-to-sainthood-with-nagios/</guid><description>If you’re running a big enough network, chances are you have a monitoring server tucked away somewhere, silently watching and waiting to let you know if something goes wrong.</description><pubDate>Tue, 02 Nov 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Mama Always Told Me Not to Trust Strangers without Certificates</title><link>https://grimmcyber.com/mama-always-told-me-not-to-trust-strangers-without-certificates/</link><guid isPermaLink="true">https://grimmcyber.com/mama-always-told-me-not-to-trust-strangers-without-certificates/</guid><description>This blog post details a vulnerability, the exploitation of which results in Remote Code Execution (RCE) as root, that impacts many modern Netgear Small Offices/Home Offices (SOHO) devices.</description><pubDate>Tue, 21 Sep 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Geeking Out on IBM i - Part 2</title><link>https://grimmcyber.com/geeking-out-on-ibm-i-part-2/</link><guid isPermaLink="true">https://grimmcyber.com/geeking-out-on-ibm-i-part-2/</guid><description>(This is part 2 of a three part series. To view part 1, click here) Network Configuration This part in the three-part &quot;Geeking Out on IBM i&quot; series focused on network…</description><pubDate>Thu, 09 Sep 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Geeking Out On IBM i - Part 1</title><link>https://grimmcyber.com/geeking-out-on-ibm-i-part-1/</link><guid isPermaLink="true">https://grimmcyber.com/geeking-out-on-ibm-i-part-1/</guid><description>I remember the first time I tried to work on Linux. Having spent most of my computer-time on DOS, Windows, and OS/2, many things on Linux were foreign to me.</description><pubDate>Tue, 03 Aug 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Old dog, same tricks</title><link>https://grimmcyber.com/old-dog-same-tricks/</link><guid isPermaLink="true">https://grimmcyber.com/old-dog-same-tricks/</guid><description>Introduction When enterprise software gets old, should we consider it tried-and-true, or decrepit and a threat, like the superglue holding the soles of my running shoes together?</description><pubDate>Wed, 07 Jul 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>The walls have ears</title><link>https://grimmcyber.com/the-walls-have-ears/</link><guid isPermaLink="true">https://grimmcyber.com/the-walls-have-ears/</guid><description>Modern business often relies heavily on the Internet and software resources such as Zoom or Skype to support daily operations.</description><pubDate>Tue, 08 Jun 2021 00:00:00 GMT</pubDate><category>Vulnerability Research</category></item><item><title>Pulse Secure April Attack</title><link>https://grimmcyber.com/pulse-secure-april-attack/</link><guid isPermaLink="true">https://grimmcyber.com/pulse-secure-april-attack/</guid><description>Pulse Connect Secure vulnerability CVE-2021-22893 and other old vulnerabilities are being actively exploited.</description><pubDate>Tue, 20 Apr 2021 00:00:00 GMT</pubDate><category>Cyber-Threats</category></item><item><title>Time for an upgrade</title><link>https://grimmcyber.com/time-for-an-upgrade/</link><guid isPermaLink="true">https://grimmcyber.com/time-for-an-upgrade/</guid><description>Cleaning your domain clock Sometimes we grow to like the old software we’ve become familiar with over the years, but because as users we only see the facade of an…</description><pubDate>Tue, 06 Apr 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>GET AHEAD OF THE UNKNOWN</title><link>https://grimmcyber.com/get-ahead-of-the-unknown/</link><guid isPermaLink="true">https://grimmcyber.com/get-ahead-of-the-unknown/</guid><description>GRIMM is pleased to announce the launch of their new Private Vulnerability Disclosure (PVD) program.</description><pubDate>Mon, 29 Mar 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>New Old Bugs in the Linux Kernel</title><link>https://grimmcyber.com/new-old-bugs-in-the-linux-kernel/</link><guid isPermaLink="true">https://grimmcyber.com/new-old-bugs-in-the-linux-kernel/</guid><description>Dusting off a few new (old) vulns Have you ever been casually perusing the source code of the Linux kernel and thought to yourself &quot;Wait a minute, that can’t be right&quot;?</description><pubDate>Fri, 12 Mar 2021 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Patrick Miller joins GRIMM as Director of Software Security</title><link>https://grimmcyber.com/patrick-miller-joins-grimm-as-director-of-software-security/</link><guid isPermaLink="true">https://grimmcyber.com/patrick-miller-joins-grimm-as-director-of-software-security/</guid><description>Patrick Miller was brought into GRIMM because he has the experience to help organizations understand what they need to do to stay safe, and help them do it.</description><pubDate>Thu, 31 Dec 2020 00:00:00 GMT</pubDate><category>News at GRIMM</category></item><item><title>Automated Struct Identification with Ghidra</title><link>https://grimmcyber.com/automated-struct-identification-with-ghidra/</link><guid isPermaLink="true">https://grimmcyber.com/automated-struct-identification-with-ghidra/</guid><description>At GRIMM, we do a lot of vulnerability and binary analysis research.</description><pubDate>Wed, 04 Nov 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Launching the GRIMM Red Team</title><link>https://grimmcyber.com/launching-the-grimm-red-team/</link><guid isPermaLink="true">https://grimmcyber.com/launching-the-grimm-red-team/</guid><description>Since GRIMM’s inception, our dedicated teams have helped build confidence in clients’ underlying security posture -- largely through demonstrating the business impact of vulnerable systems during client engagements.</description><pubDate>Tue, 04 Aug 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>DJI Privacy Analysis Validation</title><link>https://grimmcyber.com/dji-privacy-analysis-validation/</link><guid isPermaLink="true">https://grimmcyber.com/dji-privacy-analysis-validation/</guid><description>Given the recent controversy with DJI drones, a defense and public safety technology vendor sought to investigate the privacy implications of DJI drones within the Android DJI GO 4 application.</description><pubDate>Fri, 31 Jul 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>IBM i Security Demystified Blog, Episode 1</title><link>https://grimmcyber.com/ibm-i-security-demystified-blog-episode-1/</link><guid isPermaLink="true">https://grimmcyber.com/ibm-i-security-demystified-blog-episode-1/</guid><description>I. Introduction “Nobody Can Hack an AS/400.” “Never in my 40 years in the business has anyone hacked an AS/400!” “AS/400’s don’t have hacking problems like Windows computers.” “AS/400’s are bullet-proof.</description><pubDate>Tue, 23 Jun 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>While teleworking work/life balance are in conflict - a personal story</title><link>https://grimmcyber.com/while-teleworking-work-life-balance-are-in-conflict-a-personal-story/</link><guid isPermaLink="true">https://grimmcyber.com/while-teleworking-work-life-balance-are-in-conflict-a-personal-story/</guid><description>The corona-virus pandemic has fundamentally changed the way many people and organizations operate.</description><pubDate>Fri, 19 Jun 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>GRIMM 2020 Summer Internships</title><link>https://grimmcyber.com/grimm-2020-summer-internships/</link><guid isPermaLink="true">https://grimmcyber.com/grimm-2020-summer-internships/</guid><description>Program History The GRIMM Intern program began three years ago. Interns work on billable client and research projects.</description><pubDate>Mon, 15 Jun 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>SOHO Device Exploitation</title><link>https://grimmcyber.com/soho-device-exploitation/</link><guid isPermaLink="true">https://grimmcyber.com/soho-device-exploitation/</guid><description>After a long day of hard research, it’s fun to relax, kick back, and do something easy.</description><pubDate>Mon, 15 Jun 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Trike</title><link>https://grimmcyber.com/trike/</link><guid isPermaLink="true">https://grimmcyber.com/trike/</guid><description>Sparked from a question on our public discord channel What does GRIMM&apos;s threat modeling process look like?</description><pubDate>Wed, 20 May 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Maritime CyberThreats</title><link>https://grimmcyber.com/maritime-cyberthreats/</link><guid isPermaLink="true">https://grimmcyber.com/maritime-cyberthreats/</guid><description>Hacking Floaty Things In July 2019 the U.S. Coast Guard issued a safety alert urging civilian mariners to get their cyber-poop in a group, encouraging the most basic of cyber-opsec on ships and supporting computer systems.</description><pubDate>Mon, 23 Mar 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Analyzing SUID Binaries</title><link>https://grimmcyber.com/analyzing-suid-binaries/</link><guid isPermaLink="true">https://grimmcyber.com/analyzing-suid-binaries/</guid><description>In our spare time, we hunt for bugs in various pieces of software.</description><pubDate>Tue, 17 Mar 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Analyzing the Linux Kernel in Userland with AFL and KLEE</title><link>https://grimmcyber.com/analyzing-the-linux-kernel-in-userland-with-afl-and-klee/</link><guid isPermaLink="true">https://grimmcyber.com/analyzing-the-linux-kernel-in-userland-with-afl-and-klee/</guid><description>At GRIMM we do a lot of vulnerability research and one of our favorite techniques for finding bugs in software is to repurpose or extend security tools from one area of research to another.</description><pubDate>Fri, 31 Jan 2020 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Power Architecture Research Collaboration</title><link>https://grimmcyber.com/power-architecture-research-collaboration/</link><guid isPermaLink="true">https://grimmcyber.com/power-architecture-research-collaboration/</guid><description>The National Motor Freight Traffic Association, Inc. (NMFTA), NXP® Semiconductors and GRIMM, a cybersecurity research firm, recently partnered to conduct an R&amp;D project…</description><pubDate>Tue, 03 Sep 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>IOT is even more of a risk than you thought</title><link>https://grimmcyber.com/iot-is-even-more-of-a-risk-than-you-thought/</link><guid isPermaLink="true">https://grimmcyber.com/iot-is-even-more-of-a-risk-than-you-thought/</guid><description>GRIMM purchased a GeoVision camera that arrived off-the-shelf with security vulnerabilities like most consumer IOT devices.</description><pubDate>Mon, 01 Jul 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Know Your Enemy: Botnet Command and Control Architectures</title><link>https://grimmcyber.com/know-your-enemy-botnet-command-and-control-architectures/</link><guid isPermaLink="true">https://grimmcyber.com/know-your-enemy-botnet-command-and-control-architectures/</guid><description>What would you do if your company’s IT devices were discovered to be part of a botnet?</description><pubDate>Thu, 06 Jun 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>SCYTHE Goes Atomic</title><link>https://grimmcyber.com/scythe-goes-atomic/</link><guid isPermaLink="true">https://grimmcyber.com/scythe-goes-atomic/</guid><description>The SCYTHE team is excited to announce that our latest release gives you the power of Atomic Red Team with all the automation and ease of use of the SCYTHE platform.</description><pubDate>Mon, 06 May 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Modern Authentication Bypasses</title><link>https://grimmcyber.com/modern-authentication-bypasses/</link><guid isPermaLink="true">https://grimmcyber.com/modern-authentication-bypasses/</guid><description>Introduction hacker voice “I’m in” is a Hollywood-esque phrase you’ve probably heard before.</description><pubDate>Tue, 02 Apr 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Five Cybersecurity Questions for Boards or Investors</title><link>https://grimmcyber.com/five-cybersecurity-questions-for-boards-or-investors/</link><guid isPermaLink="true">https://grimmcyber.com/five-cybersecurity-questions-for-boards-or-investors/</guid><description>Boards of Directors and investors do not need to be technical experts to oversee or discover cybersecurity risk in organizations.</description><pubDate>Thu, 21 Mar 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>The Purple Team - Organization or Exercise</title><link>https://grimmcyber.com/the-purple-team-organization-or-exercise/</link><guid isPermaLink="true">https://grimmcyber.com/the-purple-team-organization-or-exercise/</guid><description>As the cybersecurity industry continues to evolve, the use of certain terminology is changing and becoming more prevalent; such as the increased mention of Red Teams and Blue Teams inside boardrooms and IT departments.</description><pubDate>Fri, 15 Feb 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>DNI Threat Assessment - Practical Guidance for your Company</title><link>https://grimmcyber.com/dni-threat-assessment-practical-guidance-for-your-company/</link><guid isPermaLink="true">https://grimmcyber.com/dni-threat-assessment-practical-guidance-for-your-company/</guid><description>Last week the Director of National Intelligence released a Worldwide Threat Assessment.</description><pubDate>Mon, 04 Feb 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>SCYTHE: Starting 2019 with Linux and ATT&amp;CK™￼￼￼</title><link>https://grimmcyber.com/scythe-starting-2019-with-linux-and-attck/</link><guid isPermaLink="true">https://grimmcyber.com/scythe-starting-2019-with-linux-and-attck/</guid><description>The SCYTHE team has been hard at work on our new release and we are proud to present the next major evolution of the SCYTHE Continuous Red Team Automation platform.</description><pubDate>Fri, 18 Jan 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Fileless Malware and the Threat of Convenience</title><link>https://grimmcyber.com/fileless-malware-and-the-threat-of-convenience/</link><guid isPermaLink="true">https://grimmcyber.com/fileless-malware-and-the-threat-of-convenience/</guid><description>Many of the conveniences brought via modern tools, operating systems, and applications also bring means for an adversary to execute actions while under the guise of a valid service.</description><pubDate>Wed, 16 Jan 2019 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Paintball at the WMCAT Hub Debut</title><link>https://grimmcyber.com/paintball-at-the-wmcat-hub-debut/</link><guid isPermaLink="true">https://grimmcyber.com/paintball-at-the-wmcat-hub-debut/</guid><description>Paintball with a purpose. That was the theme for the 6th Annual Purple Event, hosted by the West Michigan Cyber Security Consortium (WMCSC) on October 10th at the West…</description><pubDate>Mon, 03 Dec 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Don’t Get Comfortable Yet - The Declining Fear of Ransomware</title><link>https://grimmcyber.com/dont-get-comfortable-yet-the-declining-fear-of-ransomware/</link><guid isPermaLink="true">https://grimmcyber.com/dont-get-comfortable-yet-the-declining-fear-of-ransomware/</guid><description>With the news that ransomware attacks are on the decline, in favor of crypto-mining (aka “crypto-jacking”), it is tempting to now reshuffle your enterprise’s defensive priorities based on the adversary trends.</description><pubDate>Tue, 16 Oct 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>What is SCYTHE&apos;s origin story?</title><link>https://grimmcyber.com/what-is-scythes-origin-story/</link><guid isPermaLink="true">https://grimmcyber.com/what-is-scythes-origin-story/</guid><description>When I started GRIMM, I had a vision to tackle the greatest cybersecurity challenges that face our clients, industry and the greater business and government communities.</description><pubDate>Wed, 03 Oct 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>SCYTHE Announces $3 Million in Initial Financing Round Led by Gula Tech Adventures</title><link>https://grimmcyber.com/scythe-announces-3-million-in-initial-financing-round-led-by-gula-tech-adventures/</link><guid isPermaLink="true">https://grimmcyber.com/scythe-announces-3-million-in-initial-financing-round-led-by-gula-tech-adventures/</guid><description>Earlier today we announced that we raised $3 million in an initial funding round led by the co-founder of Tenable, Ron Gula of Gula Tech Adventures.</description><pubDate>Mon, 17 Sep 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Malicious Command Execution via bash-completion (CVE-2018-7738)</title><link>https://grimmcyber.com/malicious-command-execution-via-bash-completion-cve-2018-7738/</link><guid isPermaLink="true">https://grimmcyber.com/malicious-command-execution-via-bash-completion-cve-2018-7738/</guid><description>Note: This was a parallel discovery where we found the bug and later found out it already had a CVE from Tenable.</description><pubDate>Fri, 14 Sep 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>ALPC Task Scheduler 0-Day</title><link>https://grimmcyber.com/alpc-task-scheduler-0-day/</link><guid isPermaLink="true">https://grimmcyber.com/alpc-task-scheduler-0-day/</guid><description>On Monday (August 27, 2018) a Local Privilege Escalation (LPE) 0-day was released which reportedly affects Windows 10 and Server 2016, at a minimum.</description><pubDate>Thu, 30 Aug 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Breach Reality Check: Get More Realistic with the Latest in Attack Simulation</title><link>https://grimmcyber.com/breach-reality-check-get-more-realistic-with-the-latest-in-attack-simulation/</link><guid isPermaLink="true">https://grimmcyber.com/breach-reality-check-get-more-realistic-with-the-latest-in-attack-simulation/</guid><description>Today, SCYTHE unveiled unique enhancements to the SCYTHE attack simulation platform.</description><pubDate>Wed, 29 Aug 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>GRIMM Announces Cyber Partnership with Michigan Educational Non-Profit, Square One Focused on New High School Curriculum for Automotive Cybersecurity</title><link>https://grimmcyber.com/grimm-announces-cyber-partnership-with-michigan-educational-non-profit-square-one-focused-on-new-high-school-curriculum-for-automotive-cybersecurity/</link><guid isPermaLink="true">https://grimmcyber.com/grimm-announces-cyber-partnership-with-michigan-educational-non-profit-square-one-focused-on-new-high-school-curriculum-for-automotive-cybersecurity/</guid><description>Earlier this month, GRIMM’s embedded security team joined Michigan’s Governor, Rick Snyder, (pictured above) along with SAE, Michigan educational non-profit, Square One…</description><pubDate>Wed, 01 Aug 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Getting ready for Black Hat?</title><link>https://grimmcyber.com/getting-ready-for-black-hat/</link><guid isPermaLink="true">https://grimmcyber.com/getting-ready-for-black-hat/</guid><description>August is right around the corner, our favorite time of the year – Black Hat and DEF CON!</description><pubDate>Wed, 25 Jul 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Crash Triage Process</title><link>https://grimmcyber.com/crash-triage-process/</link><guid isPermaLink="true">https://grimmcyber.com/crash-triage-process/</guid><description>People tend to think that when a fuzzer finds a bunch of crashes that it’s exciting and fun, and it is… the first time.</description><pubDate>Wed, 18 Jul 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Delta Debugging</title><link>https://grimmcyber.com/delta-debugging/</link><guid isPermaLink="true">https://grimmcyber.com/delta-debugging/</guid><description>Have you ever been fuzzing a program and received a crash, only to find the input file was huge?</description><pubDate>Wed, 20 Jun 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>GRIMM’s New Michigan Cybersecurity Research Lab</title><link>https://grimmcyber.com/grimms-new-michigan-cybersecurity-research-lab/</link><guid isPermaLink="true">https://grimmcyber.com/grimms-new-michigan-cybersecurity-research-lab/</guid><description>GRIMM has been a long time advocate of building Connected and Automated Vehicles (CAV) with a security-by-design approach.</description><pubDate>Wed, 23 May 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Guided Fuzzing with Driller</title><link>https://grimmcyber.com/guided-fuzzing-with-driller/</link><guid isPermaLink="true">https://grimmcyber.com/guided-fuzzing-with-driller/</guid><description>At GRIMM, we are always trying out new tools to build our capabilities in vulnerability research.</description><pubDate>Wed, 16 May 2018 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>These Scars Must Be Worth Something</title><link>https://grimmcyber.com/these-scars-must-be-worth-something/</link><guid isPermaLink="true">https://grimmcyber.com/these-scars-must-be-worth-something/</guid><description>A summary of wisdom from years of learning the hard way. Excerpted from a keynote I gave at Rochester Institute of Technology to the RC3 Security Club.</description><pubDate>Sun, 15 Apr 2018 00:00:00 GMT</pubDate></item><item><title>See you in San Francisco for RSAc!</title><link>https://grimmcyber.com/see-you-in-san-francisco-for-rsac/</link><guid isPermaLink="true">https://grimmcyber.com/see-you-in-san-francisco-for-rsac/</guid><description>GRIMM and SCYTHE are packing our bags and heading to the RSA Conference. We have a busy week planned and are excited to see new and familiar faces.</description><pubDate>Tue, 10 Apr 2018 00:00:00 GMT</pubDate></item><item><title>Heap overflow in the necp_client_action syscall</title><link>https://grimmcyber.com/heap-overflow-in-the-necp_client_action-syscall/</link><guid isPermaLink="true">https://grimmcyber.com/heap-overflow-in-the-necp_client_action-syscall/</guid><description>One of the things that is important to us at GRIMM is making sure there is time to experiment, and explore new ways of approaching problems.</description><pubDate>Fri, 06 Apr 2018 00:00:00 GMT</pubDate></item><item><title>HAX goes International</title><link>https://grimmcyber.com/hax-goes-international/</link><guid isPermaLink="true">https://grimmcyber.com/hax-goes-international/</guid><description>The eyes of the world were recently focused on PyeongChang, South Korea for the 2018 Winter Olympics.</description><pubDate>Thu, 08 Mar 2018 00:00:00 GMT</pubDate></item><item><title>Jennifer Tisdale joins GRIMM as a Cyber Advocate for Connected Mobility and Infrastructure</title><link>https://grimmcyber.com/jennifer-tisdale-joins-grimm-as-a-cyber-advocate-for-connected-mobility-and-infrastructure/</link><guid isPermaLink="true">https://grimmcyber.com/jennifer-tisdale-joins-grimm-as-a-cyber-advocate-for-connected-mobility-and-infrastructure/</guid><description>Connected Mobility and Infrastructure are taking Detroit by storm; timing is critical for adopting strong security practices at this nascent point in the technology and the industry.</description><pubDate>Wed, 28 Feb 2018 00:00:00 GMT</pubDate></item><item><title>Understanding the Real Cost of Pen Testing, Red Teaming and Blue Teaming</title><link>https://grimmcyber.com/understanding-the-real-cost-of-pen-testing-red-teaming-and-blue-teaming/</link><guid isPermaLink="true">https://grimmcyber.com/understanding-the-real-cost-of-pen-testing-red-teaming-and-blue-teaming/</guid><description>The void in the cybersecurity workforce is compounding the level of risk faced by enterprises.</description><pubDate>Thu, 18 Jan 2018 00:00:00 GMT</pubDate></item><item><title>Practical advice for real world problems</title><link>https://grimmcyber.com/practical-advice-for-real-world-problems/</link><guid isPermaLink="true">https://grimmcyber.com/practical-advice-for-real-world-problems/</guid><description>Introduction Have you ever been trying to solve a systemic problem, like users getting infected by malware, and the only advice you get is completely impractical, such…</description><pubDate>Thu, 21 Dec 2017 00:00:00 GMT</pubDate></item><item><title>Blockchain Technology</title><link>https://grimmcyber.com/blockchain-technology/</link><guid isPermaLink="true">https://grimmcyber.com/blockchain-technology/</guid><description>Financial technology (Fintech) has a long history of innovation, but there have been interesting changes now that Bitcoin has demonstrated the possibility of having a trustworthy system even when dealing with untrusted parties.</description><pubDate>Thu, 09 Nov 2017 00:00:00 GMT</pubDate></item><item><title>The Launch of SCYTHE and CROSSBOw</title><link>https://grimmcyber.com/the-launch-of-scythe-and-crossbow/</link><guid isPermaLink="true">https://grimmcyber.com/the-launch-of-scythe-and-crossbow/</guid><description>When I started GRIMM, I had a vision to tackle the greatest cybersecurity challenges that face our clients, industry, and the greater business and government communities.</description><pubDate>Mon, 16 Oct 2017 00:00:00 GMT</pubDate></item><item><title>#BestTechWorkCulture</title><link>https://grimmcyber.com/besttechworkculture/</link><guid isPermaLink="true">https://grimmcyber.com/besttechworkculture/</guid><description>Last night, GRIMM attended the 3rd Annual DC Timmy Awards.</description><pubDate>Fri, 29 Sep 2017 00:00:00 GMT</pubDate></item><item><title>HAX and GRIMM’s Internship Program&apos;s</title><link>https://grimmcyber.com/hax-and-grimms-internship-programs/</link><guid isPermaLink="true">https://grimmcyber.com/hax-and-grimms-internship-programs/</guid><description>One of the reasons I chose to come to GRIMM after leaving federal service earlier this year was because of one of the core principles held by the rest of the GRIMM Leadership team.</description><pubDate>Fri, 22 Sep 2017 00:00:00 GMT</pubDate></item><item><title>A Three-Step Approach to Threats: What All Organizations Should Know (but Equifax Doesn&apos;t)</title><link>https://grimmcyber.com/a-three-step-approach-to-threats-what-all-organizations-should-know-but-equifax-doesnt/</link><guid isPermaLink="true">https://grimmcyber.com/a-three-step-approach-to-threats-what-all-organizations-should-know-but-equifax-doesnt/</guid><description>Within the context of historical cyber breaches, this can be classified as a massive attack: Equifax, one of the “big three” credit-rating agencies, announced earlier…</description><pubDate>Mon, 18 Sep 2017 00:00:00 GMT</pubDate></item><item><title>GRIMM Named Finalist for the DC Timmy Awards: Best Tech Work Culture</title><link>https://grimmcyber.com/grimm-named-finalist-for-the-dc-timmy-awards-best-tech-work-culture/</link><guid isPermaLink="true">https://grimmcyber.com/grimm-named-finalist-for-the-dc-timmy-awards-best-tech-work-culture/</guid><description>GRIMM is excited to be named a finalist in the Best Tech Work Culture category for the DC Timmy Awards.</description><pubDate>Thu, 31 Aug 2017 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>“Howdy Neighbor” Smart House</title><link>https://grimmcyber.com/howdy-neighbor-smart-house/</link><guid isPermaLink="true">https://grimmcyber.com/howdy-neighbor-smart-house/</guid><description>“Howdy Neighbor” is GRIMM’s Internet of Things (IoT) Capture the Flag (CTF)-like challenge.</description><pubDate>Fri, 21 Jul 2017 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>What is “3PO”?</title><link>https://grimmcyber.com/what-is-3po/</link><guid isPermaLink="true">https://grimmcyber.com/what-is-3po/</guid><description>“3PO” is GRIMM’s mobile car hacking lab.</description><pubDate>Mon, 17 Jul 2017 00:00:00 GMT</pubDate><category>Uncategorized</category></item><item><title>Lisa Wiswell is a Young AFCEA 40 Under 40 Winner</title><link>https://grimmcyber.com/lisa-wiswell-is-a-young-afcea-40-under-40-winner/</link><guid isPermaLink="true">https://grimmcyber.com/lisa-wiswell-is-a-young-afcea-40-under-40-winner/</guid><description>GRIMM is excited to announce that Lisa Wiswell, Principal for Security Consulting, was selected as a Young AFCEA 40 Under 40 winner for 2017.</description><pubDate>Tue, 20 Jun 2017 00:00:00 GMT</pubDate><category>Uncategorized</category></item></channel></rss>