Will post more later but: please check out @theori_io's landing page for AIxCC! We've got source code, agent traces, and blog posts to understand the system we built!
https://t.co/7IXCuj37EP
@PlaidCTF, @theori_io (The Duck), and @maplebaconctf are joining forces to play DEFCON as Maple Mallard Magistrates. Some PPP members also play on The Duck & Maple Bacon, so this allows all of us to keep playing on the same team. See you all at DEFCON finals!
PlaidCTF is proud to announce visionary innovation and the actualization of experience in the hacking space. We’re moving beyond the ordinary to usher in a new paradigm of pwning. Welcome to the future. Welcome to Plaidiverse.
Join us on April 8 at https://t.co/AZhLDcNKGo!
😀 I am starting a fundraise for @picoctf. PicoCTF is free to everyone, and costs about $500k a year (🙀) to run. If you've had a positive experience with pico, please reply or DM. I'll use it in my fundraise pitch.
Pls RT for awareness. #ctf#hacking
The exploit for Safari is quite complex and massive. I really wanted to understand exactly what the vulnerability was and how it was mitigated, so I dived into the world of browser exploits for a few days and tried to explain how leaking object addresses was possible.
#ESETresearch uncovers new Mac malware DazzleSpy, delivered using watering hole on a pro-democracy Hong Kong radio station website. Payload was launched as root without user interaction, using exploits for Safari and macOS. @marc_etienne_@cherepanov74 https://t.co/oihDVHaCa3 1/7
Google uncovered a sophisticated attack that leveraged both iOS & macOS exploits (n-/0-days) to infect Apple users! 👀
Interested in a triage of the macOS implant (named OSX.CDDS), including:
▫️ Installation
▫️ Persistence
▫️ Capabilities
📝 Have a read:
https://t.co/VHBGcAk3GW
New: In August Google caught hackers using an old Mac exploit together with a zero-day that was published by a research group at a Chinese cybersecurity conference in April.
The hackers were targeting Hong Kong users.
https://t.co/DJOq3ppvRS
More technical details from @eryeh and the team on last months exploit and the associated campaign.
https://t.co/XLrQed3E6T
TAG discovered watering hole attacks targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political group.
Glad to be able to share some additional details on the campaign leveraging the macOS privesc (CVE-2021-30869) to install a new macOS backdoor
https://t.co/2CcTLDenid
0day privilege escalation for macOS Catalina discovered in the wild by @eryeh
https://t.co/yvCWPo45fL
We saw this used in conjunction with a N-day remote code execution targeting webkit.
Thanks to Apple for getting patch out so quickly.
After an EPIC battle for @defcon CTF, with MULTIPLE lead changes throughout 32 hours of competition,
A*0*E REMAINS VICTORIOUS 👑
PPP takes second place, behind by two points
Learn how found and exploited SockPuppet for iOS 12.4, featuring a bonus collaboration with LiveOverflow! https://t.co/5sE7GKwSbb https://t.co/Rl2WaVBlO4
We disabled 210 channels on YouTube when we discovered channels in this network behaved in a coordinated manner while uploading videos related to the ongoing protests in Hong Kong. https://t.co/gpcfcXvu3c