@mindcrypt

Offensive Hacker & Cryptographer/Stego | AI cybersec guy | Speaker @blackhat @ekoparty @rootedcon... | Founder @criptored - https://nitter.cf/t.co/TU1PnWdvX3

github.com/mindcrypt
Joined February 2013
Acabo de publicar mi nuevo libro "Criptografía Ofensiva 2. Atacando y defendiendo organizaciones: Criptografía aplicada para programadores, analistas, cripto-agilistas y hackers éticos". 400 páginas y más de 1.100 referencias. Lo tenéis disponible en el siguiente enlace. Se agradece difusión - amazon.es/Criptograf%C3%ADa-…
3
92
8
255
35,163
👉 "Crypto & Privacy Watch" Sept 2026 newsletter - criptored.com Crypto & Privacy Watch is an observatory where I will periodically publish a newsletter featuring news of interest on cryptography, post-quantum cryptography, quantum computing, AI, privacy, advanced computing, and digital rights. Subscribe and feel free to share any suggestions - linkedin.com/pulse/crypto-pr…
1
322
Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes - ddropattack.eu/
2
326
Alfonso Muñoz, Phd retweeted
Si quieren escuchar el mejor podcast sobre servicios de Inteligencia en español, aquí lo tienen. Con @VicenteVallesTV Buenísimo. ondacero.es/podcast/original…
8
32
2
195
7,761
Querida comunidad de ciberseguridad española. Echádle un vistazo, firmad y compartid :)
2
14
19
2,221
I've just released my book "Stegomalware — Evading Antivirus and Perimeter Security Using Steganography: Concealing Advanced Cyber Threats and Malware" for free, now translated into English. I think it could be useful to the #infosec community. I'd really appreciate you sharing it so it can reach as many people as possible #cybersecurity #malware #steganography #apt - github.com/mindcrypt/libros/…
1
4
9
496
This book will give you a quick and straightforward understanding of the mechanisms that cybercriminals are using to infect systems and steal information from businesses, governments, and individuals. It highlights how steganography and covert channels have been used in cyberattacks involving "modern" malware (APT32, APT37, Ursnif, Powload, LightNeuron/Turla, Platinum APT, Waterbug/Turla, Lokibot, The Dukes (Operation Ghost), Titanium, etc.) to evade detection measures based on antivirus technology or network-level protections. The text includes more than 200 references, where you will find full analyses of the attack campaigns and the APTs examined. In addition, for your convenience, the book delves into the concepts behind the underlying steganographic techniques and should — that, at least, is my intention — leave you better equipped to face these new challenges, especially if you work in information security, reverse engineering, computer forensics/DFIR, or as a malware analyst. And of course, if you work in offensive security, you will learn better techniques for staying hidden.
1
126
Libros de #ciberseguridad gratuitos en mi repo de Github. Por si no los conocías :) #crypto #stego #hacking #IA - Seguridad del protocolo SSL/TLS. Ataques criptoanalíticos modernos - github.com/mindcrypt/libros/… - Esteganografía y canales encubiertos. Esteganografía lingüística - github.com/mindcrypt/libros/… - ESTEGOMALWARE. Evasión de antivirus y seguridad perimetral usando esteganografía. Ocultando ciberamenazas avanzadas y malware - github.com/mindcrypt/libros/… - Seguridad ofensiva en machine learning. +100 prompts injections en ChatGPT. Atacando y defendiendo organizaciones con prompt engineering - github.com/mindcrypt/libros/…
1
57
1
218
16,013
"Quantum Computers Will Never Break RSA, Says Oxford Physicist..." - profwoodward.substack.com/p/…
2
2
7
1,028
👏 BANCO SABADELL: Reflexiones desprendidas de un programa de Criptoagilidad Desde hace años, a través de @criptored , colaboro con organizaciones de muy diverso perfil en la resolución de retos complejos de ciberseguridad, entre ellos los vinculados a la criptografía. En un momento en el que la criptografía postcuántica y la criptoagilidad ocupan buena parte del debate del sector, el nuevo número de la revista SIC —decana de la prensa especializada y lectura obligada para cualquier profesional de la ciberseguridad— (página 118, lnkd.in/eRT_Y4X9) publica algo del detalle del programa de Criptoagilidad diseñado para Banco Sabadell, fruto de casi dos años de trabajo discreto. En este proyecto, PwC ha aportado su conocimiento, profesionales de raza y su solvencia contrastada en el acompañamiento a grandes clientes, mientras que mi buen amigo @patowc y yo hemos contribuido con nuestra experiencia en arquitecturas seguras, criptografía y criptoagilidad. Mi enhorabuena a Banco Sabadell por su compromiso con la construcción de una entidad cada vez más segura, analizando en detalle los ataques más avanzados; y también al equipo de PwC y a Román, sin cuya implicación este hito no habría sido posible. Si tienes una problemática parecida, escríbeme ;)
2
6
19
1,509
Alfonso Muñoz, Phd retweeted
Oooof wow fuck. "YubiKey authentication is extracted from Windows Event Log and replayed against Microsoft Entra ID using Passkey Injector."
When I showed that event logs are full of leaked kernel pointers, available for anyone who can find them, I said that there are many other useful things hiding there. But I didn't know it was this bad. Amazing find @MGrafnetter!
18
145
8
1,500
171,559
No es fácil encontrar un buen libro de criptoanálisis simétrico moderno. Lectura de esta semana ;)
1
20
986