I managed to RCE Fortune 500 companies and made over $50,000 with this technique.
A new npm supply chain technique we just disclosed. The trick is dumb-simple.
We call it npx Confusion.
🧵
Le CTF Jeopardy a rendu son verdict ! 🏁💻
Le chrono s'est arrêté et la tension retombe enfin au Grand Palais : entre criminalistique, exploitation web et rétro-ingénierie, cette seconde épreuve de l'EC2 a poussé les candidats dans leurs derniers retranchements techniques.
Bravo à l'équipe Esnarcotrafiquants de l'ESNA qui s'impose sur ce challenge de haut vol orchestré par notre partenaire @hackthebox_eu ! 🏆🔍
Félicitations à eux pour cette victoire méritée ! 👏
#INCYBERFORUM
🚨 Google wants to force every Android developer to register with them, even if you never touch the Play Store. We signed the open letter opposing this alongside EFF, Proton, F-Droid, Tor Project, and 30+ others. Android's openness is non-negotiable.
https://t.co/vzlPdOc5Sa
Hi, I just pushed an update on OdinLdr.
I have added an EAF Bypass to resolve function addresses, NtApi calls are now made with indirect syscall and synthetic stackframe.
Majority of code is rewritted to be more clean
https://t.co/BaJjQ55HyY
Ludushound shows the power of community driven innovation in cybersecurity. @bagelByt3s created an awesome tool to convert bloodhound data into a working lab in 🏟️ Ludus. Replicate complex live environments with automation - and get back to the fun stuff!
https://t.co/19qfjRwaOA
🔥Introducing Arion🔥
A high-performance C++ framework for emulating executable binaries.
Based on Unicorn and inspired by Qiling, Arion offers an easy-to-use interface and super low execution times making it a great ally for fuzzing or other applications.
https://t.co/EdIIaJqt91
Recent #ClickFix style distribution of #LummaStealer continues to evolve. From newly registered domains that mimic legitimate services to using data binaries that run as PowerShell script, these campaigns try various tricks to avoid detection. More info at https://t.co/5w1R8a1Fyd
Une proposition de loi votée par le Sénat aujourd’hui suscite de sérieuses inquiétudes pour la sécurité numérique des citoyens et des entreprises en France.
Un immense merci à @Synacktiv, @epsilon_sec et @rootme_org pour leur soutien lors d’Ambrosia 🙏
Merci à tous les participants et speakers, c’est grâce à vous que cet événement existe ! 🏴☠️
On a une annonce de merch pour vous si vous n’étiez pas là.. Vous en pensez quoi ? 👀
La billetterie est officiellement ouverte ! 🎉
Nous vous attendons nombreux, et Steakoverflow n'attend que vous ! 😎
Restez à l'affût, nous vous communiquerons très bientôt les talks à venir… 👀
🎟️ Vous pouvez retrouver la billetterie ici: https://t.co/NohQNsiooH
🎉RCE Pre-Auth sur SPIP <= 4.3.2 🎊
Trouvée en collab avec @TheLaluka il y a quelques jours !
Ref:
- https://t.co/BTqioYSFP3
- https://t.co/4raDc9hyMS
JULIAN ASSANGE IS FREE
Julian Assange is free. He left Belmarsh maximum security prison on the morning of 24 June, after having spent 1901 days there. He was granted bail by the High Court in London and was released at Stansted airport during the afternoon, where he boarded a plane and departed the UK.
This is the result of a global campaign that spanned grass-roots organisers, press freedom campaigners, legislators and leaders from across the political spectrum, all the way to the United Nations. This created the space for a long period of negotiations with the US Department of Justice, leading to a deal that has not yet been formally finalised. We will provide more information as soon as possible.
After more than five years in a 2x3 metre cell, isolated 23 hours a day, he will soon reunite with his wife Stella Assange, and their children, who have only known their father from behind bars.
WikiLeaks published groundbreaking stories of government corruption and human rights abuses, holding the powerful accountable for their actions. As editor-in-chief, Julian paid severely for these principles, and for the people's right to know.
As he returns to Australia, we thank all who stood by us, fought for us, and remained utterly committed in the fight for his freedom.
Julian's freedom is our freedom.
[More details to follow]
Durant le mois de juin, L'ESN'HACK organisera à nouveau les nocturnes ! 🔥
Au programme : du partage, des barbecues, des paninis et des bières 🍻
Rendez-vous le : 17 juin et le 27 juin pour des soirées rumps
Plus d'infos sur Discord : https://t.co/F3fyfXJarv
Merci à tous les participants pour Ambrosia ainsi qu'aux rumpers 🔥
Merci encore aux sponsors ❤️
La sortie de notre nouveau merch sur le thème de "Disassembly your worst nightmare" est là😎 !!
Plus d'infos sur notre Discord : https://t.co/F3fyfXICBX