Part 2 of one of our craziest episodes so far, with an insane amount of tips you can start applying right now on every target you hack on, thanks @brutecat for sharing everything with the community!
Episode 178, part 2
‼️ Nightmare Eclipse is back on GitHub under a new alias and has released a new Windows Defender vulnerability zero-day called RoguePlanet.
PoC: https://t.co/n0xF6uGt4u
New GitHub Account: https://t.co/qwU93VedpH
“Bug bounty is dying” is noise.
Lock in. Make money. Use AI to 10x your output. If it eventually dries up, you’ll have enough capital to start that biz or enough experience to land a job.
Simple as that.
Yes @Rhynorater, you read it right!
Our triage team is comprised exclusively of security engineers with mandatory OSCP & OSWE certs + deep CVSS expertise. They know their stuff 🔥
Since Justin brought them up in this clip, should we do an interview with our triagers? We’d cover their workflows, top submission tips, and some funny report memories!
Let us know in the replies 👇
@ekoparty WE ARE COMING🚀
Este es el team de Faraday que va a estar representándonos durante estos días.
Charlas, demos, AI, automatización y nuevas formas de entender la seguridad ofensiva.
Si estás por la Eko, pasá a saludarnos, no te lo vas a querer perder 😉
#Faraday
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
Running a Figma plugin is enough to land cross-platform zero-click RCE on Figma Desktop...
Read the writeup on the Critical Research Lab https://t.co/16w1iiWEmF
And thanks @Dav3nn for the incredible post, what an amazing chain! =)
And this makes sense given how many CTFs are held per year.
However, the ideal CTF challenge, in my opinion, should follow this formula:
"The author conducted a mini-research project and instead of publishing it, turned it into a challenge."