As promised - after the first part discussing the nitty-gritty details of the research, here comes the juicy vulnerability report! Here's everything that could go wrong with your 2,000 ILS smart lock, culminating with a complete wireless takeover!
https://t.co/0iexc6qZFi
As per the Linux embargo policy, a potential LPE Linux kernel vulnerability @Gr33nh4t discovered was made public today, 14 days after disclosure. Here are the details. https://t.co/OmHsekoU6j
During the pandemic @Gr33nh4t & @waveburst decided to improve our own office wireless equipment by finding vulnerabilities in them. Check out our new blog post about that! @ArubaNetworks https://t.co/12aYOcuIQq
We're thrilled to publish our last #homograph#phishing attack post by @tzachyh. This time we found various implementation flaws in instant messaging clients. https://t.co/fI9JDPTXfv
@Gr33nh4t has found a new Ubuntu LPE, he found a way to #exploit@ubuntu's "Apport" crash handler to achieve privilege escalation. Check out his new research.
@ubuntu_sec
https://t.co/FPnEMuEmzD
Last week I've finished a vulnerability disclosure with @ubuntu_sec of a few vulnerabilities I discovered in Ubuntu, they did an awesome job providing reliable fixes very quickly.
I'll share more details about these vulnerabilities soon on @alephsecurity.
https://t.co/TQ53QuuViu
Graphic framebuffer support! After a long while, found time for the iOS QEMU project and finally got graphics working on iOS 14! There's still a lot of work to arrange it but hope to release it soon with iOS 14 support.
We are thrilled to present our follow-up research on Ruckus Wireless devices. @waveburst found new critical vulnerabilities and managed to overcome the previous research fix.
https://t.co/HiToFdEpFs
After some delay, here's the 2nd part of our Homograph research in which we show how we bypassed browsers IDN policy and take a deep dive into Unicode definitions.
https://t.co/Ob42I9hpLd
#Ruckus has confirmed six additional CVEs for my latest research. I will present new RCEs on Ruckus devices using these vulnerabilities at #defcon28#DEFCONSafeMode
New features added to our project's repository!
* iOS on QEMU KVM support
* ASLR disabled for user mode
* TFP0 for user apps
* CoreTrust patched - no need for static trust cache
Check it out and feel free to contribute!
https://t.co/uClu4PGVva
Our recent update enables communication with iOS on QEMU via TCP sockets, including SSH! @levaronsky explains the inner workings of our solution: https://t.co/fBLbaq94TK