Publiquei minha pesquisa sobre uma vulnerabilidade de RCE em visualizadores PDF Linux como Atril, Evince e Xreader, resultando na CVE-2026-46529.
Abrindo o PDF, e clicando qualquer parte da pagina um comando arbitrário é executado no sistema
O artigo:
https://t.co/NgkUNYmhHJ
Dialed in! Nikolaos Mourousias (@deltaclock), Caue Obici (@caueobici) & Bruno Halltari (@BrunoModificato) of OtterSec used a Code Injection bug to exploit LM Studio in the second round, earning $20,000 and 4 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
CVE-2025-6554: in-the-wild V8 the_hole based vulnerability analysis and exploit
Bug analysis by @r3tr074:
https://t.co/XwOJY0GD62
PoC by @mistymntncop:
https://t.co/biGiS60sIt
#infosec
A comunidade de Bug Bounty Brasileira está fazendo um evento GRATUITO e trazendo gringo para palestrar.
Você de São Paulo ou q pode está nessa data em SP simplesmente VÁ nesse evento.
#Bolhasec
Maiores detalhes aqui neste tweet.
🚀 Orgulho nacional! 🇧🇷
Parabenizamos todos os envolvidos por essa conquista histórica! Vocês levaram o nome do Brasil ao topo e mostraram que nossa comunidade de CTF está cada vez mais forte e preparada para desafios globais!
🔗 Assista o vídeo em https://t.co/21PUgIfSek
https://t.co/xaLgRIBDaT
Obrigado @mentebinaria !
Não foi dessa vez mas DEFCON que nos espere ano que vem!
Até lá, como todos devem fazer sempre, estudaremos!
Obrigado novamente ao @hackaflag por nos receber!
Brazil made history last weekend, and of course, ELT was a part of it!
Thanks @GaneshICMC , @boitatech , @gris_ufrj and #hawksec_unifei for partnership! We got 17th place, the best brazilian result, at #DEFCONCTF Quals as "pwn de queijo"!
Thanks @hackaflag for hosting us!
Where there’s bug bounty, there’s #Bugcrowd. 😉✨
We’re honored to have supported the @BugBountyBr at H2HC in #Brazil, big thanks to @bsysop! Seeing the hacker community come together with such passion was nothing short of amazing (as always). 🥲
Huge thanks to the organizers, sponsors, and everyone who joined—you made it unforgettable! 🎉💚
NEW blog post: Netfilter Universal Root 1-day
Our latest blog dives deep into the state of Linux kernel security and the open-source patch-gap, exploring how we monitored new bug fixes and achieved 0day-like capabilities by exploiting a 1-day vulnerability.
Read more here →
Seeing that Pwn2Win isn't happening this year, here's an unreleased beginner-level XSS challenge I created for it (shouldn't be too difficult).
https://t.co/jHJ5leyBBx
@jobertabma I think it's cool, but I would put this in a mutual-only (the first reporter can see the name of the person who took dup and the dup see the name of the first reporter) and also as an optional flag and only allow to be shared if both sides have this enabled(just like WhatsApp)
The results are in!🥇
Congratulations to these 32 teams who will move on to the Group Round of the 2024 #AmbassadorWorldCup! 🙌
The next round kicks off at the end of August! Stay tuned for the latest info, and read more about the AWC here. https://t.co/ZKBzjgwKWv
Today at #Troopers24 we released Certiception – the ADCS honeypot we always wanted to have.
Blog: https://t.co/2NCzLTtItc
Source code: https://t.co/WLSMq2Bl8m
Slide deck, including our guide to deception strategy: https://t.co/xEAUPhqaGR