Researcher @olearysec found privilege-escalation vuln in Azure Backup for AKS and reported to @microsoft. CERT validated it but Microsoft rejected it and asked Mitre not to give it CVE. Then he says Microsoft silently patched it without telling users https://t.co/CL1Jn8vyKL
Yippie
Two new Microsoft Windows 0days. The exploits have cool and badass mysterious names to be extra spoopy
- GreenPlasma: Windows CTFMON Arbitrary Section Creation Elevation of Privileges Vulnerability
- YellowKey: Bitlocker Bypass Vulnerability
https://t.co/VaWFtW5lFi
We’ve been through all kinds of situations: exploits failing, vendors turning off services during demos, patches being released the night before a demo, and more but we happily accepted and continue to play.
And if you don’t participate in the game, who cares about your opinion?
As a team that has participated in Pwn2Own twice every year since 2020, We’d like to say this clearly: getting rejected is just another part of the game. Calling player to "revenge” and releasing 0-day exploits is irresponsible and harmful.
@b1ack0wl I agree.
While the rapid advancement of AI can be exhausting at times, people should still make an effort to adopt the technology.
Of course, a final review by a human eye is essential.
Beatrice Pro Edition has been updated!
-New flag to obfuscate Import Address Table
-Improved alternative encodings
-Evasion with Cobalt Strike added to the guide
Check out Beatrice Pro edition:
https://t.co/sXG3Zk6hQW
It’s been 10 years since I published my first book(LTR101), so to celebrate I’m giving 10% off my red team course, Malwareless Adversarial Emulation (MAE).
MAE focuses on practical, real-world offensive tradecraft including malwareless operations, tunnelling, AD CS abuse, cloud pivoting, and detection-aware operations.
Check it out here: https://t.co/gvGwReAfK5
Discount code: LTR101-10Y
Valid until the end of August 2026.
Thanks to everyone who has supported my work over the years. I genuinely appreciate it.
#RedTeam #CyberSecurity #InfoSec #OffensiveSecurity #AdversaryEmulation #RedTeaming #CyberTraining #Malwareless
This was supposed to be my PoC for a Claude Code RCE aimed at Pwn2Own Berlin 2026, but ZDI never got back to me about my entry registration. It looks like I won't be able to register it at all...
When practicing on a VM crackme recently, I created a devirtualizer which lifts the virtual machine to LLVM to defeat the protection. LLVM-based devirtualisation is a lot of fun and I wrote down my experience and lessons learned on my blog:
https://t.co/LiWNIj31uK