[CPR-Zero] Multiple vulnerabilities in OMX ALAC decoder affecting Android devices based on MediaTek and Qualcomm chipsets that can lead to LPE and RCE via malformed audio file.
https://t.co/xheZqIWuCY
https://t.co/tzH2OUvJfH
https://t.co/s6DG0GR5TK
Wrote an article about #fuzzing the Linux kernel network stack externally with #syzkaller.
The article covers:
🧰 Introduction to syzkaller
💉 Using TUN/TAP for packet injection
👽 Integrating TUN/TAP via pseudo-syscalls
🏆 Showcases of found bugs
https://t.co/BlKeoWU7QP
Today Wiz Research (@shirtamari, @nirohfeld, @ronenshh and myself) published details on #ExtraReplica, a severe vulnerability that allowed anyone to access the databases of other #Azure customers.
Here’s how we did it: 🧵 (1/n)
https://t.co/4hNas25zIM
We (+@nirohfeld) just released the full technical blogpost regarding #ChaosDB - which we also presented today at #BlackHatEurope
https://t.co/4e9sBd4knX
Do you like reading books?
Then you’ll love hacking Amazon’s Kindle.
https://t.co/7MHrGFqWB9
Read all the technical details here:
https://t.co/2zB0mQw3hI
[CPR-Zero] CVE-2021-31179 (Outlook, Office): Improper parsing of TLV records leading to Use-After-Free and Heap Corruption in graph.exe https://t.co/AvnUHn0L37
We have recently discovered 4 security issues applicable in most MS-Office products.
Read all the details here:
https://t.co/KxPiOnCxeq
cc @sagitz_@NetanelBenSimon
Woohoo! https://t.co/73TA5AzhlQ "Another great feature of Jackalope is that it is easily customizable and hackable. The process of adding a custom mutator to the fuzzer was pretty straight-forward and increased our fuzzing effectiveness with very little development cost."
Our researchers found that CVE-2017-0005, a 0-Day attributed to the Chinese APT31, is a replica of an Equation Group 0-Day, that was caught and repurposed by APT31 during 2014, 3 years before the Shadow Brokers leak.
Read the complete story on our blog.
https://t.co/sz3bAxrbYJ
Gamers Beware
We recently turned our eyes to a major networking library used by a sizeable chunk of online gaming - Valve’s "Steam Sockets".
Here is our report on the library, and the vulnerabilities we found in it.
https://t.co/gnT6Ho3BkQ
CVE-2020-1350: A cool Windows DNS Server vulnerability (2003->2019) we found at @_CPResearch_
and got patched today #PatchTuesday
https://t.co/OapPwEYPvp
We discovered a 17-year-old vulnerability in all of Windows DNS Servers.
SIGRed (CVE-2020-1350) is a wormable, critical vulnerability that can be used to achieve full Domain Administrator privileges.
https://t.co/giebs7WIhp