This iMessage exploit is crazy. TrueType vulnerability that has existed since the 90s, 2 kernel exploits, a browser exploit, and an undocumented hardware feature that was not used in shipped software:
https://t.co/YJdY6alLbV
At release, Purple Llama includes:
- CyberSecEval
- Llama Guard model
- Tools for insecure code detection & testing for cyber attack compliance
We're also publishing two new whitepapers outlining this work.
Get Purple Llama ➡️ https://t.co/YSSBNXUiZm
Announcing Purple Llama — A new project to help level the playing field for building safe & responsible generative AI experiences.
Purple Llama includes permissively licensed tools, evals & models to enable both research & commercial use.
More details ➡️ https://t.co/k4ezDvhpHp
[#CVE-2022-27969] – Leaks list of decoy users. Touching a decoy user might end your red teaming exercise, unless you can find an unauthenticated endpoint that reveals what decoy users are currently in place and on which domain. 2/5
Our offensive security group at Meta just published a blogpost about safeguarding a stack smashing protection:
https://t.co/VwzJP7anIb
This also prompted GCC to create a vulnerability disclosure process, which we LOVE!
Many of us enjoy CTF’s and now we are finally hosting SRLabs-original hacking challenges.
Put in a lot of effort – one of the challenged simulates a telco network.
See if it was worth it on Aug 21 when we go live 👾 🚩
#ctf
📚 Excited to announce the publication of "Challenges of Software Verification"! 🎉 Honored to have co-authored the chapter "How to Make Taint Analysis Precise" in this comprehensive book.
https://t.co/F6NGMjdxVj
I have published a blog post on how to utilize built-in functions in Oracle and PostgreSQL DBMSes to bypass WAFs when exploiting SQL Injection vulnerabilities (based on real-life cases from bug bounty programs):
https://t.co/uUC0FbyBqr
Meta's Bug Bounty Program in 2022
- Bug Bounty Awards Issued: $2 million
- Number of Bug Bounty Report Received: 10,000+
- Number of Bug Bounty Reports Paid: 750
- Top 3 countries bug bounties awarded in 2022:
India, Nepal and Tunisia.
https://t.co/QrR8BGvUdY
T-2 days for @Blackhatmea. Very excited to be presenting about the evolution of @Meta static analysis tools. How we protect ~2.9B users across our family of apps. The talk is going to be technical and very fun. Looking forward to seeing you there https://t.co/JykvnfydZs
If you liked our blog post on exploiting Telerik CVE-2017-9248, (https://t.co/A5NuNJcBZz) but were missing a tool: someone created one based on our post.
Now that it's out, maybe we should publish our version as well... :)
[CVE-2022-27967] – Leaks exclusion rules. Would it trigger an alert if I run a powershell command? It would be nice to see what processes or files are excluded from monitoring. Here is an endpoint that leaks the exclusion profiles in place. 3/5
New blog: "Abusing forgotten permissions on computer objects in Active Directory".
The post is a dive into permissions that are set when you pre-create computer accounts the wrong way, why BloodHound missed those and how to abuse, fix, or monitor for this. https://t.co/T8WmiIoL53