Success! Synacktiv was able to execute a heap-based buffer overflow in the kernel triggered via WiFi and leading to RCE against the Wyze Cam v3. They earn $15,000 and 3 Master of Pwn points. #Pwn2Own
Our team published a post about the #3cx supply chain attack. We describe the Windows & the MacOS backdoors. The timeline: the GitHub repo on December 7 & the infrastructure in November... Few months later a malicious update was sent to the customers : https://t.co/FCb4fTmnXy
Watchout! CVE-2023-22809 on Sudo was patched today to prevent a privilege escalation on sudoedit. Read the security advisory by @aevy__ and @v1csec: https://t.co/w2uco4PGhh
I published a new article about an ESXi encryptor we found during a case. Let me know if you found a similar sample and are willing to share!
#dfir#Ransomware
If you see two guys wearing Synacktiv t-shirts with big antennas, you should turn around with your @Tesla! 0-click RCE demonstration on a real vehicle, with CAN messages sent to switch on headlights, wipers and trunk 😎 #Pwn2Own
Hey :)
New blog post detailing Raccoon V1 management infrastructure (victim storage location, Telegram update server, etc), MaaS infrastructure location + link to CC2BTC marketplace.
Once again, feedback warmly-welcomed 😄
Remote Admin tools are being more and more abused by threat actors. In our latest blogpost, @ektoplasma_ wondered what traces could be leveraged during investigations regarding some usual suspects: TeamViewer, AnyDesk, Atera, and SplashTop.
https://t.co/0aABBoMTzF
Ever wanted to exploit a PHP file inclusion without having a file upload? Follow @_remsio_'s journey to discover PHP filter chains, ensuring they work properly, and transforming them into a tool. You can now convert almost any file inclusion to RCE! https://t.co/yKMPu5guh7
Our paper on Earth Berberoka is finally out ! It contains analysis of multiple Windows, Linux and Mac malware families (PuppetLoader, oRAT, PlugX, gh0st, Xnote, Hellobot, Pupy, Reptile...), 3 different infection vectors, links to multiple known #APT groups https://t.co/VIrpbCUOI9
The slides of our Botconf talk are now online. They contain infection vectors, a focus on a complex malware family sharing a flawed RC4 implementation with TigerPlug malware, victimology and attribution hints. Let me to know if you track this #APT group https://t.co/RgbHIan0Sv