We break things, build things... sometimes before anyone else. Defensive & offensive security R&D and skunkworks projects since ~2006. Silent until we are not.
Subreption releases research exposing critical security flaws in FIPS/Common Criteria certified enterprise network switches. (subreption.com/press-release…)
FLAPPYSWITCH abuses CVE-2024-50604, CVE-2024-50605, CVE-2024-50606 and CVE-2024-50607, for breaking out of the management "cli", executing a modular loader and achieving persistence in the underlying Linux-based OS through classic ELF infection techniques.
Vendor patches quietly released (Jan 2025) insufficiently addressed the issues, and misrepresented them as requiring physical access. Vulnerabilities remain exploitable.
Our research hopes to bring proper attention to the state of the art in enterprise network equipment security, as it is often overlooked, in the wake of the Salt Typhoon incident.
Available at:
github.com/subreption/FLAPPY…
Stay tuned for updates.
#FLAPPYSWITCH#salttyphoon
End of Sales is not End of Life. This is one understated PSA from law enforcement that will go sadly unnoticed and repeat for a few iterations well into the future. FLAPPYBIRD lives on!
The FBI has released a PSA warning that Russian FSB cyber actors are targeting end-of-life networking devices across critical infrastructure sectors. Click for technical details and further information on the FSB Center 16 unit conducting this activity: ic3.gov/PSA/2025/PSA250820
ALT Public Service Announcement dated August 20, 2025, warning of Russian government cyber actors targeting networking devices and critical infrastructure.
The FBI has released a PSA warning that Russian FSB cyber actors are targeting end-of-life networking devices across critical infrastructure sectors. Click for technical details and further information on the FSB Center 16 unit conducting this activity: ic3.gov/PSA/2025/PSA250820
ALT Public Service Announcement dated August 20, 2025, warning of Russian government cyber actors targeting networking devices and critical infrastructure.
Subreption releases research exposing critical security flaws in FIPS/Common Criteria certified enterprise network switches. (subreption.com/press-release…)
FLAPPYSWITCH abuses CVE-2024-50604, CVE-2024-50605, CVE-2024-50606 and CVE-2024-50607, for breaking out of the management "cli", executing a modular loader and achieving persistence in the underlying Linux-based OS through classic ELF infection techniques.
Vendor patches quietly released (Jan 2025) insufficiently addressed the issues, and misrepresented them as requiring physical access. Vulnerabilities remain exploitable.
Our research hopes to bring proper attention to the state of the art in enterprise network equipment security, as it is often overlooked, in the wake of the Salt Typhoon incident.
Available at:
github.com/subreption/FLAPPY…
Stay tuned for updates.
#FLAPPYSWITCH#salttyphoon
FLAPPYSWITCH against a remote Ruckus ICX switch running latest 9.x firmware, in FIPS/Common Criteria mode, gaining code execution and persistence in under 20 seconds. Thanks to our collaborating researcher for both excellent code and comedy! #physicalaccessonly#notreally#FLAPPYSWITCH#securitymyth
Pending a more formal announcement, we are excited to introduce you to our research since fall 2024 into enterprise network security. Here comes FLAPPYSWITCH. "What can an incident like Salt Typhoon do to telco infrastructure at a hardware level?" needn't be an academic question anymore. Grab your answers! github.com/subreption/FLAPPY…@DistrictCon@CISACyber
Added a set of CVEs currently reported and in process of disclosure and remediation/mitigation: CVE-2024-50604, CVE-2024-50605, CVE-2024-50606, CVE-2024-50607, in Ruckus Networks/CommScope products. Underhyped research during the #SaltTyphoon aftermath! A throwback at @redballoonsec
Releasing hackrf_sweeper (reimplementation of HackRF's hackrf_sweep as a library), along demo applications (including a ZMQ CURVE client and publisher of FFT bins for remote sweeping). github.com/subreption/hackrf…
Finally proper YARA support for Ghidra without the suck: GhidraYara (github.com/subreption/ghidra…). Analyzer extension plugin for rule generation and management, rolled up in one. More features to come, including integration with ProgramDB (for in-DB storage of rules and artifacts).
It's never too late for a post about #chatgpt, finally. How well does it work for cryptography-related questions and challenges? Here's a short experiment just about that: subreption.com/blog/gpt-capa…#chatgpt#HackTheBox (TL;DR Not terrible)
While everyone was busy having a #crowdstroke, we have published a short primer about hardware and firmware reverse engineering of a video sensor used in IPC devices and FPV drones, fresh out of the labs: subreption.com/blog/fpv-ipc-…#re#ghidra
ALT IPC/video module on a custom test assembly with Sensepeek probes
A short blog post: IEEE 802.11 wireless spectrum coverage metrics (improving probability of intercept with traditional wireless adapters, with actual numbers per configuration and optimized channel hopping) subreption.com/blog/wireless…
On a different note, amidst the widespread plagiarism of original research in proactive defenses in Linux & other projects for the last decade, OpenBSD employs Machiavellian tactics: marc.info/?l=openbsd-tech&m=… "Release broken code, let them Ctrl C/Ctrl V, write sploits, ???"
IR: While the case is being investigated, and based off the data available at Censys and other sources, we kindly ask any user of VPN services coming across this page to contact us, should you encounter emailAddress=kamil.inal@comodo.com or O=ComodoAnkaraGumus in SSL warnings.
IR: We are investigating a possible ongoing MITM against/perpetrated by a major VPN provider, the fraudulent certificates served have OU=ComodoAnk O=ComodoAnkaraGumus (Ankara, Turkey). The targeted CNs have their legitimate certificates listed in CRTs from non-regional CAs.
In today's climate of CDNs and load-balancing services, it is tough to accurately detect fraudulent certificates but almost invariably they share characteristics: regional CA (cooperative with state actor or compromised), lack of CRT listing, duration under 12 months, no pinning.