Joined September 2010
12 Photos and videos
Pinned Tweet
I've shifted over primarily to Infosec Exchange on #Mastodon given the uncertainty around Twitter's future... I'll still be lurking here, but with ~90% of the folks I interact with having moved on, I probably won't be very active. @Andrew@Infosec.Exchange infosec.exchange/@andrew
East of Foss Lake, OK
25
Hey @NordicTrack... Waiting 7-10 days for a replacement tablet on a brand new treadmill (that I've only been able to use once (on manual)) and is now dead after troubleshooting update failures with customer service is completely unacceptable.
1
1
217
Genuinely regret purchasing your product at this point. The 1 year @iFit subscription code that was shipped with the product is "no longer accepted," and now half or more of the 30-day trial that card gave me instead is going to be spent with an unusable machine.
2
1
186
I've always known @NordicTrack as a quality brand - my family had 2 different machines as I grew up that never failed. That's why I bought this machine - good reviews, good price... Boy do I regret that right now. So... can we fix this @NordicTrack, or should I just return it.
30
Rather than addressing the community concerns by something other than doubling down on the plan to kill SMS support... Signal has added Snapchat-esque stories! -_-
@signalapp plans to drop SMS support for the Android app... This change is nothing but detrimental IMO. If you use Signal on Android as your default SMS app, PLEASE speak out against this change.
VK was a legend in the information security and CTI communities, and will be sorely missed. My deepest condolences go out to his family, friends, and colleagues in this time of mourning.
#UPDATE5/#FINAL Mr. Vitali Kremez's body was recovered by local authorities Wednesday. "We'd like to express our deepest condolences to the loved ones of Mr. Kremez," said CWO Edgardo Insignares, a Sector Miami command duty officer. #SAR
1
Andrew Nowlin retweeted
🚨 Today, we are publishing our Cybersecurity Performance Goals which list high-priority cybersecurity outcomes and associated actions intended to help CI organizations voluntarily reduce risk from malicious cyber activity: cisa.gov/cpgs
16
59
108
Andrew Nowlin retweeted
25 Oct 2022
🚦 TLP 2.0 is a week away! Beginning Nov 1, @CISAgov will adopt @FIRSTdotOrg’s #TrafficLightProtocol Version 2.0 to further enhance the sharing of potentially sensitive information and effective collaboration. More at cisa.gov/tlp #cybersecurity #InfoSec
1
34
55
Andrew Nowlin retweeted
25 Oct 2022
Phew
24 Oct 2022
The code and blogpost for getting Ring 0 using VBA Macro Office Doc is finally up! - disrel.com/posts/Ring0VBA-Ge… Sorry for the delay, been dealing with life!
2
11
46
Andrew Nowlin retweeted
Because we all need VBA macro's enabled in our docs by default. This is bloody brilliant research and also makes me incredibly sad that we still aren't building a defendable Internet
24 Oct 2022
The code and blogpost for getting Ring 0 using VBA Macro Office Doc is finally up! - disrel.com/posts/Ring0VBA-Ge… Sorry for the delay, been dealing with life!
2
4
12
Andrew Nowlin retweeted
24 Oct 2022
The code and blogpost for getting Ring 0 using VBA Macro Office Doc is finally up! - disrel.com/posts/Ring0VBA-Ge… Sorry for the delay, been dealing with life!

6 Jul 2022
Using Office VBA Macro to exploit a vulnerable driver (zam64.sys) using DeviceIoControl, to get NT AUTHORITY\SYSTEM TL;DR - Ring 0 using Office Doc} Blogpost incoming soon lol Thanks to @Coldzer0x0 @kasua02 for the encouragement and help.
9
269
701
Andrew Nowlin retweeted
You may remember during @defcon I was tweeting about hacking someone through their reused passwords (or passwords we cracked) — well my target was @donie (he asked me to, I promise lol)

29
235
1,131
Andrew Nowlin retweeted
Really bad call here imo. Making it your normal text solution was the main thing keeping Signal alive with most folks. I have to imagine signal adoption drops significantly with this stance.
12 Oct 2022
In the interest of privacy, security, and clarity we’re beginning to phase out SMS support from the Android app. You’ll have several months to export your messages and either find a new app for SMS or tell your friends to download Signal.  signal.org/blog/sms-removal-…
23
28
176
Andrew Nowlin retweeted
yeah, if this isn't an option i won't be able to use this with my parents. And as a result, i know it's not much, but i'll stop doing my annual donation of 100 $ it's the only way i can clearly indicate this is not helpful to me and my family
7
4
165
Andrew Nowlin retweeted
12 Oct 2022
Anyone got any alternatives to replace Signal? Signal plans to stop providing SMS Support on android devices in the next several months...
12 Oct 2022
In the interest of privacy, security, and clarity we’re beginning to phase out SMS support from the Android app. You’ll have several months to export your messages and either find a new app for SMS or tell your friends to download Signal.  signal.org/blog/sms-removal-…
2
1
5