This morning a #security advisory was published by Zyxel, with CVE-2023-5593, of a memory corruption vulnerability found during a research conducted by me and @bytevsbyt3 on their VPN client for Windows.
https://t.co/iQG7RrbnUO
Have read about caller ID spoofing several times, but I always doubted it would work in 2023 until I set it up on my own. It is not a piece of cake, but it can be done with a suitable VoIP provider (with SIP trunk), a customized PBX (e.g. Asterisk) and a softphone (e.g. ZoiPer).
🔥 Brace yourself #LocalPotato is out 🥔
Our new NTLM reflection attack in local authentication allows for arbitrary file read/write & elevation of privilege.
Patched by Microsoft, but other protocols may still be vulnerable.
cc @decoder_it
Enjoy! 👇
https://t.co/3Lge45hb7L