VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-20869) by Alexander Zaviyalov (@NCCGroupInfosec)
https://t.co/qAKnS15RLn
#infosec
Check Point Research demonstrates how generative AI can speed up reverse engineering from days to hours by exporting IDA data to ChatGPT for deep static analysis. https://t.co/nhfXopg5vw
Following their presentation at @hexacon_fr, Mehdi & Etienne detail how they exploited CVE-2023-40129, a critical vulnerability affecting the Bluetooth stack in Android ⬇️
https://t.co/OS63LQ4tJE
Sharp Robotics of Singapore has officially unveiled SharpaWave, an impressively dexterous hand. The 1:1 life-size model boasts 22 degrees of freedom, with over 1,000 tactile sensors per fingertip. It can crack eggs, play the piano, or use scissors, combining strength, speed, and dexterity once thought impossible.
We opened the iOS sandbox like a museum vault—carefully, layer by layer—and found the rulebook written in runes. So @yarden_ha revived an old decompiler (dev CPR 🫀🛠️), added modern iOS support, and turned noise into readable signals. Now the policies aren’t “mystery beach sand,” they’re a map you can navigate: what’s allowed, what’s fenced, why that API says “no.” Research → faster. Insights → deeper. Clarity → finally. Only at #OBTS 🍏 do tools get resurrected and upgraded in one talk.
Wrote a blogpost today on how to write a harness for Lucid. This is the harness I'll be using to fuzz `nftables`. Some overlap with last blogpost, but everything is explained step-by-step. First blog entry into my earnest attempt to find bugs with Lucid for the 1st time: 👇
#exploit
Windows Heap Exploitation -
From Heap Overflow to Arbitrary R/W
https://t.co/2RzNvsoBtU
]-> PoC - https://t.co/nxqsSQoxRz
// vulnerability exists in the add/update function where it re-uses the previous size of the record to read the new data
🐞Bug Spotlight: CVE-2025-10200 – Use-after-Free in Chrome Service Worker [bounty $43000]
One-shot renderer RCE to sandbox escape with a deep iterator invalidation
Issue: 🔒440454442 (currently private)
Reported by Looben Yang
Reverse engineering & PoC exploit by @alisaesage
A great write-up of a VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-
20869) exploit by Alex Zaviyalov has just been published!