Hey guys I have 2 extra general admission tickets for the BST Hyde Park - Mumford and sons concert on 4 July. Let me know if you are interested #mumfordandsons#hydepark
☁️ Token theft playbook
Microsoft has been published a Token Theft playbook which includes investigation checklist, hunting queries, response/recovery task lists, and an accompanying decision tree.
https://t.co/ann5TZcHAY
Today we're publishing a detailed technical writeup of FORCEDENTRY, the zero-click iMessage exploit linked by Citizen Lab to the exploitation of journalists,
activists and dissidents around the world. https://t.co/RYsqpTHF5j
Ubuntu LPE exploit from Pwn2Own
@flatt_sec_en published a whitepaper on exploiting Linux kernel eBPF vuln leading to OOB RW primitive.
They used it against Ubuntu Desktop 20.10 at Pwn2Own 2021.
https://t.co/99UjKbwiQ8
Hey @nnwakelam thanks for the suggestion around the mod_proxy SSRF. We've updated the glossary to contain the Apache mod_proxy SSRF PoC, affected versions and reference blog post: https://t.co/su4gpZpPuk
Happy to maintain this resource for the community.
In this post I'll go through 3 bugs in the Qualcomm NPU driver that I reported, which allowed me to execute arbitrary kernel code from the untrusted app domain in Android, disable SELinux and bypass task cred protection to gain root on a Samsung phone: https://t.co/SInC9rADXq
Zoom Client logic flaw (yes, logic != boomer overflows your fuzzer will find): "This means we can spoof the “trusted TCP channel with our “untrusted” UDP channel” "all we need to do is send the magical “give desktop control” packet to the target attendee. "
Play CTF.
If anyone is starting out, I would strongly recommend to complete the binexp category from @picoctf. It has a decent difficulty curve and you can always read writeups if you get stuck. Complete the binexp challenge sets from 2019 and this year, you will learn tons.
I and @rootxharsh found and exploited a 0Day RCE in Apple's Travel Portal and were rewarded with $50K. Here's the write-up for that:
https://t.co/zMpw2QOEvP
For red teams and pentesters, and defenders wanting to know attacks to look for and protect against, I've written down the techniques I would use to attack AWS environments.
https://t.co/8lehoTzY7X
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
Blog post available soon on: https://t.co/2SDRm6PZaQ
Google Security Research Repository: https://t.co/0HolidyWvV
Intel Security Advisory: https://t.co/kfGj3MWajy
Video: https://t.co/sE35AoD0V4