PSA: If you haven’t yet patched your #Exchange, don’t bother. It's too late. You’ve demonstrated that you are not capable of managing the difficulties of running on-prem infra. Migrate immediately to a cloud-email service (O365/Google) and deprovision your compromised Exchange
New blog post from TAG with details of a North Korean campaign targeting security researchers working on vulnerability research and development.
https://t.co/Ec2TaMMXeQ
Stay safe out there everyone!
One bug was introduced by iOS 6. Another one was introduced by iOS 3. That is, this grandpa bug also affects the very first generation of iPhone. It has survived more than 10 years. Honestly I don’t believe that I’m the first one who found this.
#VMware patched 6 CVEs on Tuesday. Today, ZDI’s @renorobertr dishes the details on two of them (Incl PoC) in his 1st blog for us. Read the top notch analysis of CVE-2020-3981/3982 at https://t.co/WjIw8rI2JB
PANGOLIN: Hybrid fuzzing, but instead of getting a single input from SymExec , get an over-approximation of the path condition of interest. Then fuzz by sampling randomly from that approx. The approx can also speed up solving of other path conditions. https://t.co/T0VFU59I0K
Advisory for the two vulnerabilities found by @OnlyTheDuck and @BrunoPujos is now public! CVE-2020-3962 and CVE-2020-3969 impact the SVGA 3D component of VMware hypervisors and were reported to @thezdi during #Pwn2Own 2020. Stay tuned for more details!
https://t.co/xPh2nDGxmz
I've compiled a summary of every original public iOS kernel exploit from app context since iOS 10, describing the high-level exploit flow to get stable kernel read/write. The trends of how these exploits have evolved over time are quite interesting: https://t.co/bmXwdzWywU
We've just presented at @sstic how a 1-day vulnerability in Samsung Trustzone can be used to rewrite the Shannon baseband memory and install a debugger on a Galaxy S7 phone.
The PDF 🇬🇧 and talk 🇫🇷 are here:
https://t.co/Kdfc3xO7TF
The tools are here:
https://t.co/NGznogNTDX
iOS Security is fucked. Only PAC and non-persistence are holding it from going to zero...but we're seeing many exploits bypassing PAC, and there are a few persistence exploits (0days) working with all iPhones/iPads. Let's hope iOS 14 will be better.
https://t.co/39Kd3OQwy1