Send e-mail to ACROS SecurityACROS Security's public PGP key  
     

ACROS News

3/26/2020.0patch blog: Micropatching Unknown 0days in Windows Type 1 Font Parsing
1/21/2020.0patch blog: Micropatching a Workaround for CVE-2020-0674
1/6/2020.0patch blog: 0patch Central: We are Now Ready to Micropatch Your Enterprise
9/20/2019.0patch blog: Micropatching Keeps Windows 7 and Windows Server 2008 Secure After Their End-Of-Support
2/11/2019.0patch blog: Sorry, Adobe Reader, We're Not Letting You Phone Home Without User's Consent (0day)
1/22/2019.0patch blog: One... Two... Three Micropatches For Three Windows 0days
12/12/2018.A new 0patch Agent is released
10/12/2018.0patch blog: Patching, Re-Patching and Meta-Patching the Jet Database Engine RCE (CVE-2018-8423)
10/3/2018.0patch blog: Words "Patching" and "Instantly" Now in the Same Phrase
9/24/2018.0patch blog: Outrunning Attackers On The Jet Database Engine 0day (CVE-2018-8423)
9/11/2018.0patch blog: Comparing Our Micropatch With Microsoft's Official Patch For CVE-2018-8440
8/31/2018.0patch blog: How We Micropatched a Publicly Dropped 0day in Task Scheduler (CVE-2018-8440)
5/30/2018.0patch blog: 0patching Foxit Reader Buffer... Oops... Integer Overflow (CVE-2017-17557)
5/15/2018.0patch blog: Windows Updates Broke Your Networking? Free Micropatches To The Rescue (CVE-2018-8174)
3/30/2018.Security Patching is Hard - Survey Results 2017
2/19/2018.0patch blog: Two Interesting Micropatches For 7-Zip (CVE-2017-17969 and CVE-2018-5996)
1/16/2018.0patch blog: Micropatching Brings The Abandoned Equation Editor Back To Life
12/13/2017.0patch blog: 42 Days After Our Micropatch, The Office DDE Vulnerability Gets An Official Fix
12/1/2017.ACROS presented "We're micropatching 0days and so can you" at the InfoSek Conference 2017. Slides are here
11/23/2017.0patch blog: Microsoft's Manual Binary Patch For CVE-2017-11882 Meets 0patch
11/17/2017.0patch blog: Did Microsoft Just Manually Patch Their Equation Editor Executable? Why Yes, Yes They Did. (CVE-2017-11882)
11/9/2017.0patch blog: 0patching a Pretty Nasty Microsoft Word Type Confusion Vulnerability (CVE-2017-11826)
11/3/2017.0patch blog: Office DDE Exploits and Attack Surface Reduction
10/25/2017.0patch blog: 0patching the Office DDE / DDEAUTO Vulnerability... ehm... Feature
10/4/2017.0patch blog: Micropatching a Hypervisor With Running Virtual Machines (CVE-2017-4924)
9/21/2017.0patch blog: Exploit Kit Rendezvous and CVE-2017-0022
9/1/2017.0patch blog: 0patching the RSRC Arbitrary NULL Write Vulnerability in LabVIEW (CVE-2017-2779)
8/24/2017.0patch blog: 0patching Foxit Reader's saveAs "0day" (CVE-2017-10952)
7/10/2017.0patch blog: 0patching the Quick Brown Fox of CVE-2017-0283
5/15/2017.0patch blog: 0patching the 'Worst Windows Remote Code Execution Bug in Recent Memory' CVE-2017-0290
3/29/2017.0patch blog: 0patching the 'Immortal' CVE-2017-7269
3/9/2017.0patch blog: 0patching another 0-day: Internet Explorer 11 Type Confusion (CVE-2017-0037)
2/28/2017.0patch blog: 0patching a 0-day: Windows gdi32.dll memory disclosure (CVE-2017-0038)
2/28/2017.ACROS presented "Fixing the fixing" at the RSA Conference 2017 In San Francisco. Slides are here
12/8/2016.ACROS will present "Fixing the fixing" at the RSA Conference in San Fransicso on February 16, 2017.
11/3/2016.ACROS presented "0patch: Be Your Own Software Doctor" at Hack.lu 2016.
9/2/2016.0patch blog: Patch to Self - The Birth of the World's First Self-Healing Micropatch
7/26/2016.0patch blog: 0patching Foxit Reader's Heap Buffer Overflow Vulnerability CVE-2016-3740
6/17/2016.0patch blog: Writing a 0patch for Acrobat Reader's Use-After-Free Vulnerability CVE-2016-1077
6/7/2016.ACROS launched 0patch open beta.
3/3/2016.ACROS presented CROWDPATCHING - It’s Time to Take Vulnerability Fixing into Our Own Hands at the RSA Conference In San Francisco. Slides are here
2/23/2016.ACROS will present CROWDPATCHING - It’s Time to Take Vulnerability Fixing into Our Own Hands at the RSA Conference In San Francisco on Thursday, March 3rd.
1/20/2016.0patch blog: Bridging the "Security Update Gap" With 0patch
1/12/2016.0patch blog: 0patch: Fixing The Fixing
11/19/2015.0patch, an overdue revolution in patching, was revealed at DeepSec 2015. Slides are available here.
9/1/2015.After 2 years of stealth development, ACROS will publicly reveal 0patch, an overdue revolution in patching, at DeepSec 2015 in Vienna (November 19th).
3/1/2014.Anyperk, the leading US one-stop shop for employee perks, has entrusted ACROS with a thorough security review of their code.
11/5/2013.ACROS contributed to the IsTrueCryptAuditedYet? project.
6/6/2013.ACROS blog: Winning An Online Lottery In Just 6 Tries
4/9/2013.Mozilla launched Beta 2 of Mozilla Persona, which ACROS was hired to perform a security analysis of.
10/20/2012.ACROS presented "How To Rob An Online Bank And Get Away With It" at RSA Conference Europe 2012 in London. Slides are here.
7/23/2012.ACROS will present "How To Rob An Online Bank And Get Away With It" at RSA Conference Europe 2012 in London (October 9th)
5/3/2012.ACROS blog: Anatomy Of An Online Bank Robbery
5/3/2012.ACROS blog: User-in-the-Middle
4/24/2012.ACROS presented "How To Rob An Online Bank And Get Away With It" at Source Boston 2012. Slides are available here.
4/10/2012.ACROS blog: Adobe Reader X (10.1.2) msiexec.exe Planting
3/9/2012.ACROS presented "Advanced (Persistent) Binary Planting" at RSA Conference USA 2012. Slides are available here.
2/10/2012.ACROS will present "How To Rob An Online Bank And Get Away With It" at Source Boston 2012 in April.
1/27/2012.Information Commissioner of Slovenia awarded ACROS the title Ambassador of Privacy for 2011 for our privacy project "SLED".
1/27/2012.ACROS will present "Advanced (Persistent) Binary Planting" at RSA Conference USA 2012 in San Francisco. Teaser podcast is now available.
1/9/2012.ACROS blog: Is Your Online Bank Vulnerable To Currency Rounding Attacks?
12/13/2011.ACROS awarded a bug bounty from Google for a high-impact "URL bar spoofing" bug in Chrome.
11/21/2011.ACROS presented "Advanced (Persistent) Binary Planting" at Source Barcelona 2011. A new binary planting attack vector was demonstrated for the first time.
11/21/2011.ACROS presented "How To Rob An Online Bank And Get Away With It" at DeepSec 2011. A lot of controversy about breaking the bank without breaking the law.
11/2/2011.ACROS will present "Advanced (Persistent) Binary Planting" at RSA Conference USA 2012 in San Francisco.
10/17/2011.ACROS delivered a talk on "Remote Binary Planting" at RSA Conference Europe 2011 in London. Slides are available here.
9/27/2011.Stanka Salamun of ACROS presented "Tracking Mary Smith" ("Belezenje Marije Novak") at the national ISACA conference, revealing the results of our extensive privacy research in Slovenia.
9/12/2011.ACROS will present "Advanced (Persistent) Binary Planting" at Source Barcelona 2011 in November
8/18/2011.ACROS will present "How To Rob An Online Bank And Get Away With It" at DeepSec 2011, Vienna, in November
8/4/2011.ACROS CEO's article in PenTest Magazine: "Turning a Nation Off With Binary Planting" (subscription required)
6/21/2011.ACROS awarded a bug bounty from Mozilla for a critical remote binary planting bug in Firefox.
6/14/2011.ACROS will present an advanced version of "Remote Binary Planting" at RSA Conference Europe 2011, London, in October.
5/19/2011.ACROS demonstrated binary planting attacks against IE8 on Windows XP and IE9 on Windows 7 at Hack In The Box 2011 Amsterdam. Slides are available here.
5/9/2011.ACROS will demonstrate binary planting attacks against IE9 at Hack In The Box 2011 Amsterdam in May.
3/8/2011.ACROS will deliver a talk on "Remote Binary Planting" at Hack In The Box 2011 Amsterdam in May.
2/28/2011.ACROS delivered a talk on "Remote Binary Planting" at RSA Conference 2011 in San Francisco. Slides are available here.
12/9/2010.ACROS delivered a talk on "Remote Binary Planting" at an OWASP Meeting in Maribor
11/26/2010.ACROS delivered a talk on "Remote Binary Planting" at DeepSec 2010 Europe, Vienna, in November
11/3/2010.ACROS will deliver a talk on "Remote Binary Planting" at RSA Conference 2011, San Francisco, in February 2011.
10/19/2010.ACROS delivered a talk on "Remote Binary Planting" at the Hack In The Box conference in October. Slides are available here.
9/9/2010.ACROS will deliver a talk on "Remote Binary Planting" at Hack In The Box, Kuala Lumpur, in October.
8/20/2010.ACROS Security is announcing the existence of a comprehensive security research on remotely exploitable "Binary Planting" vulnerabilities affecting a large percentage of Windows applications and often allowing for trivial exploitation. ~520 remotely exploitable bugs in ~200 widely-used Windows applications. Visit www.binaryplanting.com for more information.
8/19/2010.ACROS will deliver a talk on "Remote Binary Planting" at DeepSec 2010 Europe, Vienna, in November
6/12/2010.ACROS presented the "Race Condition: When the turtle bets on luck, the rabbit bets on a symlink attack" at OWASP Slovenia joining OTS 2010.
5/11/2010.On June 16 2010 ACROS will present the "Race Condition: When the turtle bets on luck, the rabbit bets on a symlink attack" at OWASP Slovenia joining OTS 2010.
5/11/2010.ACROS is presenting the paper and the slides of Application Security Strategy Model (MASS) together with Slovenian public tenders analysis 2009 results.
4/13/2010. ACROS presented the MASS (CANV/OANV) Application Security Strategy Model at DSI 2010.
4/13/2010.ACROS presented the "White Hat confession: How I got that precious file from your computer" at SirIKT 2010.
4/12/2010.ACROS is presenting the MASS (CANV/OANV) Application Security Strategy Model at DSI 2010.
4/12/2010.ACROS is presenting the "White Hat confession: How I got that precious file from your computer" at SirIKT 2010.

. ACROS in the Media