THE KNOWLEDGE IS THE WORK.
Resources(82)
Continuous Assessment: Adversarial Exposure Testing Across A Changing Estate
CENSUS
Traditional penetration testing only proves security on the day it runs. CENSUS Continuous Assessment combines the Golden Eagle platform with Tiger Team operators to deliver ongoing adversarial testing, mapping attack paths as your estate changes.
Securing UAV Communications In Contested Spectrum | RF Threat Defense, SDR Resilience And C2 Integrity
CENSUS
UAV communications face growing RF threats including GPS spoofing, jamming, and signal interception. This whitepaper covers COMSEC pillars, SDR-based attacks, and AI-driven RF security strategies for contested electromagnetic environments.
Cybersecurity For AI Systems: Protecting Data, Models and Interfaces
CENSUS
Discover how to protect AI systems from cybersecurity threats including data poisoning, prompt injection, model theft, and API vulnerabilities. CENSUS's whitepaper covers AI security best practices for data, models, interfaces and platform resilience.
The Next Layer of Sovereignty is Cybersecurity Engineering
Anestis Bechtsoudis
Sovereign infrastructure is expanding fast, but control isn't security. Anestis Bechtsoudis of CENSUS explains why AI-powered systems must be secure by design, governable in operation, and resilient through disruption — turning sovereignty into trusted, dependable operations.
CyberSecurity for Defense & Mission Critical Infrastructure | Middle East
Census
CENSUS provides cybersecurity engineering and intelligence for state and private defense. Key engagements include unmanned platforms (UxV), Zero Trust architectures for autonomous systems, and sovereign secure communications under contested RF.
Operationalizing Confidential Computing: Verifiable Attestation in Practice
CENSUS
IDC's November 2025 white paper [1], based on its July 2025 study of 600 global IT leaders, shows that confidential computing has moved beyond early adoption. 75% of organizations are already using it, with 18% in production and 57% piloting, and participants are directly involved in systems that process confidential...
Quantum-Resilient Security: PQC Migration and Future-Proofing Cryptographic Systems
CENSUS
Quantum computers pose an existential threat to modern cryptography, as algorithms like Shor's will break RSA, ECC, and Diffie-Hellman, the foundations of TLS, PKI, VPNs, and SSH. While large-scale quantum machines don't yet exist, "Store Now, Decrypt Later" attacks mean adversaries are already harvesting encrypted...
Challenging the Boundaries of Confidential Computing for AI
CENSUS
CENSUS has conducted an in-depth technical evaluation of Confidential AI workloads on Google Cloud Platform (GCP), focusing on the integration of Intel Trust Domain Extensions (TDX) and NVIDIA H100 GPUs within Confidential Virtual Machines (CVMs). The assessment explored whether hardware-based attestation could be...
Zenoh Protocol Security Analysis
CENSUS
Zenoh is a communication protocol designed to efficiently facilitate data exchange, storage, and computation across diverse computing environments — from powerful servers in data centers to resource-constrained microcontrollers in IoT devices. Its primary objective is to enable seamless integration and operation of...
Weak SVG asset filtering mechanism in Squidex
Charalampos Maraziaris
CENSUS has discovered a stored cross site scripting (XSS) vulnerability in the Squidex "headless" open source CMS framework. The vulnerability affects all versions of Squidex prior to 7.9.0 and enables privilege escalation affecting authenticated victim users. The Squidex development team has addressed the issue in...
Race condition in key creation and key rotation exposes private keys of Tang server
Brian McDermott
The Tang open source software is used to bind data to network presence. It is commonly used along with Clevis clients to provide for unattended LUKS decryption of server storage volumes within the realms of a network, where a trusted Tang server is situated. CENSUS identified that the Tang software in versions 11, 12...
Reflected XSS vulnerabilities in Squidex "/squid.svg" endpoint
Ioannis Christodoulakos
Reflected XSS vulnerabilities were discovered in Squidex (versions before 7.4.0) in the "/squid.svg" endpoint. Attackers can craft malicious links containing injected JavaScript that executes in victims' browsers when opened, potentially leading to session hijacking and account takeover. The issue was fixed in version...
Multiple vulnerabilities in Snipe-IT
Charalampos Maraziaris
Multiple security vulnerabilities were found in Snipe-IT (versions before 6.0.14), including a stored Cross-Site Scripting (XSS) flaw and a username enumeration issue. The XSS vulnerability allows attackers to inject malicious code that executes in other users' browsers, potentially leading to privilege escalation....
Introducing Janus: a hierarchical multi-blockchain access control system for policy based access to shared resources
CENSUS
It is very often the case that critical data or critical devices are co-managed by stakeholders from different domains. Any access to such resources should ideally be transparent to all stakeholders involved, and the access itself should comply with any policies set by the resource owner(s). However, this is not what...
Securing the building blocks of embedded software
CENSUS, Sofia Tsagiopoulou
Embedded systems are special purpose systems that cover a wide range of applications, from home electronics and industrial control systems, to medical devices and avionics. The remote management & telemetry features of the so called "Internet of Things" family of embedded devices, have made them quite popular and...
Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027)
Chariton Karamitas
CENSUS has been investigating for some time now the exploitation potential of Man-in-the-Disk (MitD) vulnerabilities in Android. Recently, CENSUS identified two such vulnerabilities in the popular WhatsApp messenger app for Android. The first of these was possibly independently reported to Facebook and was found to be...
Canary Mail and MailCore2 library missing certificate validation check on IMAP STARTTLS
Rayd Debbas
CENSUS identified that the Canary Mail software in versions 3.20 and 3.21 (and possibly previous versions) is missing a certificate validation check when performing an IMAP connection configured with STARTTLS.
Microchip cryptoauthlib atcab_sign_base buffer overflow
George Poulios
CENSUS identified a buffer overflow vulnerability in the atcab_sign_base function of the cryptoauthlib library. This library is part of the standard SDK provided by Microchip and is used to drive the operation of cryptographic co-processors sold by the vendor, such as the ATECC608A.
Emulating Hypervisors: a Samsung RKP case study (OffensiveCon 2020)
Aris Thallas
Hello, I'm Aris Thallas, a computer security researcher working at CENSUS. Back in February 2020 I had the pleasure of presenting my work on proprietary hypervisor emulation and bug discovery at the OffensiveCon 2020 conference.
Hitting the Gym: The Anatomy of a Killer Workout (TROOPERS 2019)
Ioannis Stais
On March 18th 2019 myself and Dimitrios Valsamaras delivered a presentation on cybersecurity vulnerabilities of "smart" fitness equipment, entitled "Hitting the Gym: The Anatomy of a Killer Workout" at the TROOPERS 2019 conference (NGI track).
Vs com.apple.security.sandbox (CanSecWest 2019)
Patroklos Argyroudis
On March 20th 2019 I presented at the 2019 CanSecWest conference a talk on reverse engineering the Apple iOS sandbox kernel extension entitled Vs com.apple.security.sandbox. I really enjoyed the conference, traveling to Vancouver, and meeting a lot of people interested in my research.
Windows 10 RS2/RS3 GDI data-only exploitation tales (OffensiveCon 2018)
Nikos Sampanis
Hello, I'm Nikos Sampanis, a security researcher working at CENSUS. On February 16th, 2018 I presented at OffensiveCon a talk with the title "Windows 10 RS2/RS3 GDI data-only exploitation tales". The presentation focused on a mitigation introduced in the Win32k component of Microsoft Windows to prevent the...
The Known Beacons Attack (34th Chaos Communication Congress)
George Chatzisofroniou
The recent key reinstallation attacks (KRACK) against the WPA2 protocol revealed how an adversary can easily eavesdrop, and in some cases tamper, a Wi-Fi connection secured by the WPA2 protocol. At the same time, Wi-Fi automatic association attacks achieve a similar result (man-in-the-middle position) not by attacking...
iOS kernel exploitation archaeology (34th Chaos Communication Congress)
Patroklos Argyroudis
On December 27th 2017 I presented at the 34th Chaos Communication Congress (34C3) a talk on the technical details and the process of reverse engineering and re-implementation of the evasi0n7 jailbreak's main kernel exploit, titled "iOS kernel exploitation archaeology". Actually, I gave the same talk at the WarCon...
Examining the value of SafetyNet Attestation as an Application Integrity Security Control
Anestis Bechtsoudis
Google promotes the SafetyNet Attestation API as a tool to query and assess the integrity status of an Android device. The official documentation, leaves no doubt that the main purpose of the SafetyNet Attestation API is to provide device integrity information to the server counterpart of mobile applications. The...
e2openplugin OpenWebif saveConfig remote code execution
John Torakis
OpenWebif is a Web application that is used in IP TVs and media boxes to provide an easy-to-use Web Interface. It is written mostly in Python (Backend) and JavaScript (Frontend). It can be found in DreamBox devices. A vulnerability was identified in the saveConfig() function.
Shadow v2 public release
Patroklos Argyroudis
About four months ago (April 2017), Vasilis Tsaousoglou and myself presented our work on exploiting Android's libc allocator at the 2017 INFILTRATE conference (Miami, Florida). Since version 5.0, Android has adopted the jemalloc allocator as its default libc malloc(3) implementation. For our talk we extended our...
Lure10: Exploiting Windows Automatic Association Algorithm
George Chatzisofroniou
Lure10 is a novel technique presented at the Hack-in-the-Box 2017 conference in Amsterdam that enables an attacker to automatically achieve a man-in-the-middle position against wireless devices running the Windows operating system. The attack requires no user interaction and exploits the "Wi-Fi Sense" feature found in...
Android stagefright impeg2d_vld_decode stack buffer overflows
Anestis Bechtsoudis
Android provides a media playback engine at the native level called Stagefright. CENSUS engineers have discovered that the MPEG-2 software decoder invoked by libstagefright has multiple stack buffer overflows at the impeg2d_vld_decode() procedure.
Android stagefright impeg2d_dec_pic_data_thread integer overflow
Anestis Bechtsoudis
Android provides a media playback engine at the native level called Stagefright that comes built-in with software-based codecs for several popular media formats. Stagefright features for audio and video playback include integration with OpenMAX codecs, session management, time-synchronized rendering, transport...
Getting the most out of Evil Twin with wifiphisher — BSides Athens 2016
George Chatzisofroniou
My last year's talk at BSides London introduced to the public Wifiphisher, a security tool that mounts the Evil Twin attack against Wi-Fi networks. The tool has since seen some heavy use by the wireless hacking community which has inspired further research into ways of making the Evil Twin attack more effective. This...
Android stagefright ih264d_read_mmco_commands libavc heap overflow
Anestis Bechtsoudis
Android provides a media playback engine at the native level called Stagefright that comes built-in with software-based codecs for several popular media formats. Stagefright features for audio and video playback include integration with OpenMAX codecs, session management, time-synchronized rendering, transport...
Android stagefright libavc ih264d_decode heap overflow
Anestis Bechtsoudis
Android provides a media playback engine at the native level called Stagefright that comes built-in with software-based codecs for several popular media formats.CENSUS engineers have discovered that the libavcodec H.264 software decoder invoked by libstagefright has an OOB write heap overflow at the...
Android stagefright libmpeg2 impeg2d_dec_user_data heap overflow
Anestis Bechtsoudis
Android provides a media playback engine at the native level called Stagefright that comes built-in with software-based codecs for several popular media formats. CENSUS engineers have discovered that the MPEG-2 software decoder invoked by libstagefright has an out-of-bounds read at the impeg2d_dec_user_data()...
GDCM buffer overflow in ImageRegionReader :: ReadIntoBuffer
Stelios Tsampas
A flaw in GDCM versions before 2.6.2 allows an integer overflow in the ImageRegionReader::ReadIntoBuffer function, causing a buffer overflow that attackers can trigger using specially crafted DICOM image dimensions. Because the overflow bypasses internal size checks, it can lead to memory corruption, denial of...
Introducing Choronzon: an approach at knowledge-based evolutionary fuzzing
Nikolaos Naziridis
CENSUS researchers Nikolaos Naziridis and Zisis Sialveras have recently presented their research on knowledge-based evolutionary fuzzing, at ZeroNights 2015 in Moscow, Russia. The talk introduced a cross-platform evolutionary fuzzing framework, that will be released as a free and open-source tool.
The road to efficient Android fuzzing
Anestis Bechtsoudis
In the aftermath of the recent Android stagefright vulnerabilities, efficient fuzz testing techniques and tools for the Android ecosystem are again in the spotlight. In this post we would like to share some of the fuzz testing experience we have gained through our projects and show how it can be applied in the Android...
Introducing wifiphisher - BSides London 2015
George Chatzisofroniou
Hello. My name is George Chatzisofroniou (@_sophron) and I work as a security engineer at CENSUS. This summer I gave a talk at BSides London. The talk was called 'Introducing wifiphisher, a tool for automated WiFi phishing attacks' and revolved around the recently published tool.
Fuzzing Objects d'ART — Hack In The Box 2015 Amsterdam
Anestis Bechtsoudis
Hello, my name is Anestis Bechtsoudis and I'm a security engineer at CENSUS. I recently gave a talk on Android ART runtime fuzzing techniques at the Hack-in-the-Box 2015 Amsterdam security conference. The talk entitled "Fuzzing Objects d'ART — Digging Into the New Android L Runtime Internals", analyzed a series of DEX...
OR'LYEH? The Shadow over Firefox (INFILTRATE 2015)
Patroklos Argyroudis
About two months ago (April 15th 2015) I visited Miami and presented at the INFILTRATE Security Conference a talk on Firefox heap exploitation, titled "OR'LYEH? The Shadow over Firefox". The organization of the conference was flawless and the people I met there were amazing. A special thank you to the Immunity team...
DTrace talk at CONFidence 2015
Andrzej Dyjak
Hello, my name is Andrzej Dyjak and I'm part of the research team here at CENSUS. A few weeks ago (on May 26th) I gave a talk titled "DTrace + OS X = Fun" at CONFidence 2015 in which I have described how DTrace can be used in order to ease various tasks within the realm of dynamic analysis on the OS X platform.
Project Heapbleed
Patroklos Argyroudis
I recently presented a talk on heap exploitation abstraction at two conferences, namely ZeroNights 2014 (Moscow, Russia) and BalCCon 2014 (Novi Sad, Serbia). The talk titled "Project Heapbleed", collected the experience of exploiting allocators in various different target applications and platforms. The talk focused...
Using SystemTap to determine the exploitability of unbound memory overflows
Nikolaos Naziridis
Hello, my name is Nikos Naziridis and I am a security researcher at CENSUS. In this post, I will present how SystemTap and kernel instrumentation in general, could be used to aid the process of determining the exploitability of unbound memory overflows and the detection of thread race condition bugs.
Oracle WebCenter information exposure vulnerability
CENSUS
An information exposure flaw in Oracle WebCenter (Fusion Middleware 11.1.1.7 and 11.1.1.8) allows an unauthenticated attacker to access user profile data — including usernames, emails, phone numbers, and files — by abusing a default WebCenter account. Tracked as CVE‑2014‑0450, the issue enables full enumeration of...
Heap Exploitation Abstraction by Example - OWASP AppSec Research 2012
Patroklos Argyroudis
This year's OWASP AppSec Research conference took place in Athens, Greece and we were planning to be there as participants. However, the day before the conference, Konstantinos Papapanagiotou (General Chair) asked if we could do a presentation to replace a cancelled talk. Myself and Chariton Karamitas agreed to help...
Black Hat USA 2012 update
Patroklos Argyroudis
This year we have presented our jemalloc exploitation research work at Black Hat USA 2012, the leading information security conference. Our researchers Patroklos Argyroudis and Chariton Karamitas visited Caesar's Palace at Las Vegas, Nevada and delivered the talk.
libpurple OTR information leakage
CENSUS
A design flaw in libpurple causes the plaintext of OTR messages to be broadcast over DBus, exposing private conversations to any process running under the same user account. Because libpurple does not propagate "no‑log" or privacy flags to third‑party listeners, applications such as widgets or notification systems may...
The Linux kernel memory allocators from an exploitation perspective
Patroklos Argyroudis
In anticipation of Dan Rosenberg's talk on exploiting the Linux kernel's SLOB memory allocator at the Infiltrate security conference and because I recently had a discussion with some friends about the different kernel memory allocators in Linux, I decided to write this quick introduction. I will present some of the...
Netvolution referer header SQL injection vulnerability
CENSUS
A blind SQL injection flaw in Netvolution v2.5.8 (ASP) allows attackers to inject arbitrary SQL commands through the HTTP Referer header. Because the CMS fails to sanitize this header, an unauthenticated attacker can extract database contents, modify site data, inject malicious JavaScript, harvest CMS usernames and...
FreeBSD kernel NFS client local vulnerabilities
Patroklos Argyroudis
.3‑RELEASE, and 8.0Short description:** Two improper input‑validation flaws in the FreeBSD NFS client (versions 7.2‑RELEASE, 7.3‑RELEASE, and 8.0‑RELEASE) allow local unprivileged users to trigger kernel stack and kernel heap overflows through crafted arguments to the mount(2) and nmount(2) system calls when...
FreeBSD kernel exploitation mitigations
Patroklos Argyroudis
In my recent Black Hat Europe 2010 talk I gave an overview of the kernel exploitation prevention mechanisms that exist on FreeBSD. A few people at the conference have subsequently asked me to elaborate on the subject. In this post I will collect all the information from my talk and the various discussions I had in the...
Black Hat Europe 2010 update
Patroklos Argyroudis
Black Hat Europe 2010 is now over and after a brief ash cloud caused delay I am back in Greece. It has been a great conference, flawlessly organised and with many outstanding presentations. I would like to thank everyone that attended my presentation but also all the kind people that spoke to me before and afterwards....
Monkey HTTPd improper input validation vulnerability
Patroklos Argyroudis
A flaw in Monkey HTTPd versions 0.9.2 and earlier allows remote attackers to crash worker threads by sending HTTP requests with malformed Connection headers. Due to improper input validation and incorrect buffer‑end calculations in Request_Find_Variable(), certain crafted request bodies trigger signedness and...
CoreHTTP web server off-by-one buffer overflow vulnerability
Patroklos Argyroudis
A flaw in the CoreHTTP web server (versions 0.5.3.1 and earlier) allows remote attackers to trigger an off‑by‑one stack buffer overflow during parsing of malformed HTTP method names or URIs. Because the server's sscanf() call writes a full 256 bytes into 256‑byte buffers without ensuring NULL‑termination, crafted...
Linux kernel SUNRPC off-by-two buffer overflow
Patroklos Argyroudis
An off‑by‑two stack buffer overflow in the Linux SUNRPC subsystem (kernel versions 2.6.32 through 2.6.32‑rc7) allows out‑of‑bounds writes in the function rpc_uaddr2sockaddr() when processing universal address strings of maximum length. Because the function writes two bytes past the end of a fixed‑size stack buffer, a...
gif2png command line buffer overflow
Patroklos Argyroudis
A stack‑based buffer overflow in gif2png (versions 2.5.1 and earlier) allows attackers to overwrite memory by supplying an overly long filename on the command line. Because the program uses an unsafe strcpy() into a fixed‑size buffer, crafted input can cause a crash or potentially enable remote code execution when...
CVE-2008-3531: FreeBSD kernel stack overflow exploit development
Patroklos Argyroudis
About four months ago I developed a reliable exploit for vulnerability CVE-2008-3531, which is also addressed in the advisory FreeBSD-SA-08:08.nmount. In this post I will use this vulnerability to provide an overview of the development process for FreeBSD kernel stack exploits.
Rasterbar libtorrent arbitrary file overwrite vulnerability
CENSUS
A path‑sanitization flaw in Rasterbar libtorrent (versions 0.14.3 and earlier) allows attackers to craft malicious multi‑file .torrent metadata that includes directory components containing embedded relative paths (e.g., "../../"). Because libtorrent only checks for exact ".." matches, these malformed elements bypass...
Static SSP canary in Debian libc6
CENSUS
A vulnerability in older Debian GNU libc (libc6 ≤ 2.7) caused stack protection (SSP / -fstack-protector) to use a fixed, predictable canary value (0xff0a0000) instead of a random one. Normally, stack canaries are randomized at runtime to prevent attackers from guessing them during buffer overflow attacks. However,...