I am so excited to announce that I have received my first CVE (CVE-2022-4310)! This is a huge milestone for me and I am looking forward to many more in the future. Check out the details at https://t.co/OyJs9GZKMk #BugBounty#cve#infosec
We've run a bug bounty program on Muse since early in development. Today it becomes public, with published payout guidelines. We pay by the impact demonstrated. More details at https://t.co/zd3EJhrtgm.
Today we published WeWorm, our zero-click worm that spreads across iOS and Android.
All it takes is one phone call. You don't have to answer. Seconds later, your WeChat account is compromised, calling your friends and spreading the attack.
We reported the bug to Tencent, and it's now mitigated for all users.
We hope this sets an example. The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them.
AI gives us a chance to find and fix these bugs faster than ever. We should work together to make the world safer for everyone.
Our story and demos: https://t.co/YsoYFduv60
wp2root as promised :-)
https://t.co/jo9Ny7u71l
Our chain is nothing fancy. Its value is in showing what real-world PHP hacking actually looks like, and how far AI has come. Cooking up a chain like this would usually take a skilled operator a few weeks; we did it with Codex in under an hour.
The slow part was writing this article, explaining each step for readers without that background. This is how hacking is becoming. You write clear English prose describing what to do, and the model does it. Feed our article to your favorite model and it will happily reproduce the whole chain.
But that raises a harder question. Directing the model takes knowing what is possible, and that knowing usually comes from having done the work yourself. If the model does the work from now on, where does it come from? We learned it the slow way, by hand, over years. How the next person learns it, once the slow way is optional, we honestly do not know.
We do know one thing, though. You can outsource the hacking, but not the understanding.
Things are getting weird (or interesting?) in the vulnerability research space. I published some of my personal thoughts on what we're seeing and what our broad strategy is here:
https://t.co/C229t5ryeK
#Syria: a Security source confirms the US troops were attacked in area of #Palmyra.
2 Government fighters and several US soldiers were wounded (and evacuated via helicopters to Al-Tanf base).
The attacker was killed.
Give it up for the four teams headed to the next round of the #AmbassadorWorldCup! 🏆 👏
The teams from Greece 🇬🇷, Egypt 🇪🇬, Spain 🇪🇸 and The Netherlands 🇳🇱 dominated the Elite 8 round and will move on to go head-to-head as the final four.
Who do you think will make it to the #1 spot and take home the gold?🥇
🎉 As we embark on a new year, we're excited to share our 2024 Meta Bug Bounty end-of-year blog post! 🚀 Dive into our key achievements, see how our bug bounty program has grown, and relive the highlights from our events throughout the year.
https://t.co/kS498EysvM