Entering and Breaking the Avast Antivirus Sandbox Part 2

safateam 110 points 30 comments September 25, 2026
www.safateam.com · View on Hacker News

Discussion Highlights (3 comments)

x-complexity

Chalk another one up for "Antiviruses causing more problems than solving them". They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them. Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.

wzdd

That's an impressively tight TOCTOU exploit!

fathermarz

I have lost faith in signature AV and CVE feeds for that matter. Attackers test against scanners until they come back clean and avoid known fingerprints. The only way I see to catch things now is behaviour diffing through static analysis. Disclosure: I build Vigilance, which does this.

Semantic search powered by Rivestack pgvector
7,702 stories · 71,417 chunks indexed