Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Author

 Paul Makowski
RSS
E-Mail

Profile of Paul Makowski

CTO, PolySwarm
Member Since: 3/26/2019
Author
News & Commentary Posts: 1
Comments: 1

Paul Makowski's interests include exploitation, program analysis, vulnerability research, reverse engineering and cryptography.

Prior to co-founding PolySwarm, Paul reverse engineered implants and wrote bespoke malware disinfection tools for Fortune 100 clients. Paul authored many of the autonomous program analysis challenges in DARPA's Cyber Grand Challenge, researched partial homomorphic encryption as it applies to protecting programs and network signatures (DARPA CFT), and has co-designed a confidentiality system for a public/private hybrid blockchain for identity management (US DHS). Paul served at the National Security Agency (NSA) for two years as a Global Network Exploitation and Vulnerability Analyst (GNEVA). Paul has competed in and won DEF CON's CTF competition.

Paul holds a patent on detecting exploitation of memory corruption vulnerabilities using symbolic constraints and has two patents pending on XOM as a basis to defeat ASLR defeats as well as a system for establishing disjoint privilege domains in a single process space.

Articles by Paul Makowski
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23443
PUBLISHED: 2021-09-21
This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), even if {{ }} are used.
CVE-2021-23444
PUBLISHED: 2021-09-21
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.
CVE-2021-39230
PUBLISHED: 2021-09-21
Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are recommend to update to the Trinity kernel. There are no workarounds.
CVE-2021-40868
PUBLISHED: 2021-09-21
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
CVE-2021-29831
PUBLISHED: 2021-09-21
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 204775.